| Strategic fit | Which operating decision does the AI pilot support? | Use-case brief names one support triage workflow and excludes regulated advice. | Green | Keep scope locked for the next review cycle. | Do not describe this as enterprise-wide AI transformation. |
| Reliability | What evidence shows outputs are acceptable for controlled use? | Small evaluation set exists, but regression cadence and failure taxonomy are incomplete. | Yellow | Define acceptance threshold, sample refresh and retest owner. | Do not claim accuracy superiority or autonomous production readiness. |
| Data/privacy | What sensitive or customer data touches the workflow? | Source list exists; retention, region and vendor-processing answers remain adviser-needed. | Red | Route open questions to privacy/security/legal owners before scale. | Do not claim compliance, privacy approval or regulated-use readiness. |
| Human override | When can a human pause or override the AI workflow? | Escalation route is documented; outage fallback owner is not named. | Yellow | Name fallback owner and rehearse stop/pause workflow. | Do not claim safe operation without override evidence. |
| Cost exposure | What happens to cloud/LLM cost if volume doubles? | Usage estimate exists, but unit-cost threshold and finance review trigger are missing. | Yellow | Add cost-per-workflow ceiling and budget alert owner. | Do not claim cost savings or ROI from pilot activity. |
| Rollback readiness | Can the team restrict, remediate or pause without customer harm? | Draft rollback checklist exists; customer communication trigger is unresolved. | Yellow | Connect rollback trigger to incident log and communications owner. | Do not claim production resilience until tested. |