Repetition shows you where the work is, but it takes four sharper questions to decide what deserves automating, and in what form.

Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027, thanks to escalating costs, unclear business value or inadequate risk controls.

That's a lot of budget wasted for enterprises trying to make smart investments. 

Most automation programmes start with the same instruction: find the repetitive work. It sounds sensible. Then come the bots that break and the "quick wins" that never repay the build.

The trouble usually starts with the process itself. Respondents to Deloitte's fourth Global Robotics Survey named process fragmentation as the biggest barrier to scaling RPA (32%). A lack of clear RPA vision and a lack of IT readiness trailed at 17% each.

em360tech image

So the better question is whether a process should be automated at all. And if it should, in what form. In this article, we'll give you a way to answer both before you commit your budget.

Why Repetition Won't Find Your Best Candidates

Repetition tells you volume but it won't tell you whether the process holds still, or what happens when it goes wrong.

The failures are well documented. When Pega surveyed 509 decision makers at businesses using RPA in 2019, 87% reported some level of bot failure.

Forrester's Craig Le Clair has offered a "rule of five" for RPA: fewer than five decisions, fewer than five applications and fewer than 500 clicks.

Forrester's report on the rule comes with a pointed subtitle, too: "But Beware Of Freezing Essential Process Improvement". Simply put, if you automate a bad process and you lock the bad bits in.

AI doesn't make this problem go away. In the same Gartner release, analyst Anushree Verma puts it bluntly:  "Many use cases positioned as agentic today don't require agentic implementations."

Gartner's 2026 data and analytics predictions go further. By 2030, it expects half of AI agent deployment failures to come down to insufficient AI governance platform runtime enforcement.

But the technical side is only part of the picture. McKinsey's analysis of automation potential found that analysing work activities is the most accurate way to judge feasibility. It treats the cost of developing and deploying automation as a separate factor entirely.

There's no agreed rulebook for choosing processes. A 2024 paper by Neelam Yadav and Supriya Panda on RPA selection criteria notes that "there are no set standards for evaluating and analyzing a certain process or its tasks."

Four Questions Before A Process Makes The Shortlist

The research does share some common ground. A literature review by Wellmann and colleagues examined 21 papers on RPA process selection. Standardisation came up in 20 of them, execution frequency in 18 and number of systems in 17.

We've grouped these, and the wider evidence, into four questions.

1. Can You See The Process Clearly?

It’s relatively simple: a process either passes or it waits.

To pass, it needs a named owner. It also needs a measurable baseline, backed by a documented picture of how the process behaves today.

If nobody owns the process, nobody fixes it when automation breaks it. If you can't measure current performance, you'll never know whether automation helped.

Mapping a process properly is its own discipline. Here, we only ask whether that map exists.

2. What Kind Of Work Is It?

Now you're looking at the nature of the work itself. How consistent are the rules, and how often do cases leave the standard path? Where does judgement sit? Has the process held steady over time, and what state is the input data in?

Assess it step by step. Parasuraman, Sheridan and Wickens proposed that automation can apply to four classes of function, each at different levels:

  • information acquisition
  • information analysis
  • decision and action selection
  • action implementation

In practice, the judgement in an invoice process might sit in a single step (reading a messy document), while everything around it is mechanical.

Measure exceptions as the share of cases that leave the standard path, and what each one costs to resolve.

Then check the data. In early 2025, Gartner predicted that through 2026 organisations would abandon 60% of AI projects unsupported by AI-ready data.

That figure is scoped to AI. Rule-based automation has its own demands, though. Wellmann and colleagues found that data must be at least semi-structured for RPA, and that unstructured or hard-to-access data gets in the way.

3. What Happens When It Goes Wrong?

This is where you weigh up the cost of a mistake, and whether you can undo it. Ultimately, it sets the ceiling on autonomy, however capable the technology is.

A miscategorised internal ticket can be fixed in a minute. A payment released to the wrong account can't.

In the UK, the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, in force from 5 February 2026. A decision counts as solely automated where there's no meaningful human involvement in it.

Where a significant decision is solely automated, controllers must have safeguards that let people:

  • get information about the decision
  • make representations about it
  • obtain human intervention
  • contest it

Decisions involving special category data face tighter restrictions still. The ICO consulted on draft guidance on the new rules earlier this year.

In the EU, GDPR Article 22 still gives people the right not to be subject to solely automated decisions with legal or similarly significant effects. There are exceptions for contracts, authorisation by law and explicit consent.

The AI Act separately requires high-risk AI systems to be designed for effective human oversight. Following the Digital Omnibus, those obligations for stand-alone high-risk systems apply from 2 December 2027.

Check your current obligations with legal counsel for your jurisdiction.

Then think about who's left holding the system. Lisanne Bainbridge's paper, Ironies of Automation, warns that physical skills deteriorate when they aren't used. So an operator who has spent years monitoring may have become an inexperienced one. And when they do need to take over, "there is likely to be something wrong with the process."

4. Is It Worth The Build And The Upkeep?

This is where the commercial inputs belong:

  • volume and frequency
  • implementation effort
  • integration complexity
  • change management

They're cost and value inputs. Suitability gets settled by questions two and three. A high-volume process can still be a terrible candidate, because volume amplifies whatever the process does. Errors included.

Are you enjoying the content so far?

Be careful with the number of systems, because it cuts both ways. Wellmann and colleagues report that 17 of the 21 papers they examined describe tasks spanning several systems as suitable for RPA. Forrester's rule of five treats more applications as a risk.

So count how the systems connect, and how stable they are, rather than just how many there are.

Value needs its own line, too. The literature is split, according to the same review. Some papers see automation potential in low-value processes, while others favour low-frequency, high-value ones.

Record value separately from suitability, so a valuable process doesn't get waved through on enthusiasm alone.

Picking The Right Automation Route

Each route  suits a different shape of work, and a human-led process can be exactly the right design.

 For more on why predictable, rule-bound workflows matter once agents get involved, see our look at deterministic automation and agentic AI.

Deterministic Automation

Suited to work with stable rules, structured inputs, few exceptions and steps that can be written down. It can handle high-consequence work, provided every rule can be traced and audited. Before committing, check how stable the applications it relies on are.

AI-Assisted Work

Suited to processes where judgement is concentrated in one step, often interpreting unstructured input, and a person makes the final decision. It can support moderate to high error costs if someone with real authority owns the outcome. Check whether reviewers are genuinely assessing outputs or simply approving them, and whether they will retain the skill to override.

Agentic Or Autonomous Execution

Suited to work where the path varies case by case and some run-to-run variation is acceptable. It should be limited to low-consequence work, or to actions that are reversible and bounded. Before committing, measure consistency across repeated runs on your own cases.

Human Execution

Suited to high-judgement, high-consequence, low-volume work, processes dominated by exceptions, or decisions the law requires a person to make. It applies at any level of error cost, particularly where mistakes are severe or irreversible. Confirm whether this is a deliberate design choice or a temporary position, and revisit it as conditions change.

Fix First

A process with no owner, unstable steps, poor data or no baseline is not ready for any route. Simplify, standardise or retire it, then reassess.

Most real processes contain several routes at once. If you want to go deeper, we've broken down robotic process automation and intelligent process automation in their own guides, along with when to use human-in-the-loop at the decision stage.

Start With The Process, Then Pick The Technology

The pressure to automate isn't going anywhere and neither is the temptation to hand every repetitive process an automation target, or to assume newer technology makes more of them fit for autonomous execution..

But ultimately, the processes worth automating are the ones you can see clearly, and whose failures you can afford.