Home All services
Start a project → Call Now

AI automation services in India

Find out how much of a process AI can take on — and what stays with a person.

We measure your manual process first, then pilot on a real sample of your cases to find the share that still needs a person. Anything the system isn't sure about goes to a person, at a threshold you set.

  • Manual process measured first
  • Pilot on a real sample of your cases
  • You set the threshold
  • ISO/IEC 22989:2022
  • Process Mining Manifesto
  • BPI Challenge 2019
  • Google Rules of Machine Learning
Illustration: a conveyor carries document tiles through an AI core into three sorting trays, while one tile is lifted onto a review station for a person to check

In brief

What it is
AI and workflow automation for a process you already run: the system closes the cases it can and sends the rest to a person.
Why it matters
You can count the manual cost today. The share of cases that will still need a person stays unknown until a pilot measures it.
What you get
A measured baseline, pilot results from your own cases, and a system that routes uncertain items to a person at a threshold you control.

What stays with a person

Three kinds of case go to a person.

Cases outside the agreed conditions

An automation works only under the conditions it was built for: which cases, arriving in what shape, from which systems. We name those conditions with you, and every case outside them goes to a person.

Cases the system isn't sure about

Everything we build returns a confidence signal for each item: how sure the system is. Items below a cut-off, the threshold, go to a person, and you set the threshold, not us.

Steps a rule gives to people

Some rules settle this before any model exists. The Reserve Bank of India (RBI) lets a bank use AI in video-based customer identification (V-CIP), yet only specially trained bank officials may operate it.

The number you don't have yet

You can count the manual cost. The share that needs a person has to be measured.

Nothing in your current process shows that share, because no system has tried your cases yet.

ISO/IEC 22989:2022, the international standard for AI concepts and terms, defines automation in clause 3.1.7 as working without human intervention "under specified conditions". You can read its definitions on ISO's Online Browsing Platform. So an automation percentage means little unless it says which cases it covers.

Why your history is not enough

Your systems' record of each step is called an event log. The Process Mining Manifesto, from the IEEE Task Force on Process Mining, warns that a log holds only a sample of behavior. It adds that in lower-quality logs people can go around the system, and that outliers may be cleaned away as noise. Our conclusion, not the Manifesto's: a log also misses cases that haven't arrived yet, so the exceptions in your past records are the least to expect, not the real number.

Wrong answers are tested by our security team under generative AI security testing, part of AI security. Wiring the hand-off to a person into your ERP or CRM is on AI automation and integration, and the dependencies a hosted model adds to software you already run are on AI integration. Or see all AI development.

How we work

Measure first, then let the numbers decide.

Before any case skips a person, the pilot shows you how many still need one.

  1. Name the process and its conditions

    We agree with you which cases the system should handle.

  2. Measure the manual version

    Volume per week, time per item and error rate, starting from your own records.

  3. Pilot on a real sample

    We run the system on real cases and measure two things: accuracy, and the share that still needs a person.

  4. Start with a high threshold

    At first the threshold sits high, so almost everything routes to a person.

  5. Lower it as the numbers earn it

    You decide when it comes down. Where the work has real consequences, a person approves each item until the share they approve is high enough to relax that check, as AI agent development explains.

The evidence behind the method

What published sources say about cases a process can't close.

Quotes are each publisher's own. None of it describes SecWiz's work.

What can an event log show, and what does it miss?

The Process Mining Manifesto asks analysts to work under an "open world assumption": "the fact that something did not happen does not mean that it cannot happen".

  • Quality levels. At the middle level, events are recorded automatically but not systematically, as in ERP tables, CRM event logs and messaging transaction logs: a record to start from. One level down, people can bypass the information system. For the two lowest levels, the Task Force calls results "not trustworthy".
  • Challenge C1. Event data may be incomplete: events may not point to the case they belong to, which can often be derived, with considerable effort. One log can mix levels of granularity, and outliers ("noise") may be cleaned away.
  • Challenge C2. Of two logs of about ten thousand events, one with a hundred cases, each on a unique path, is "much more difficult to analyze" than one with a thousand similar cases. Variety is a difficulty separate from volume.
What does a real purchase-to-pay log look like?

The BPI Challenge 2019 page from the International Conference on Process Mining (ICPM) describes a real purchase-to-pay event log: 1,595,923 events across 42 activities, performed by 627 users, of whom 607 are human and 20 are batch users. Sometimes no user was recorded. One unblocking step can be done "by a user, or by a batch process at regular intervals". The data holds roughly four types of flow for line items, and the page warns the complexity "goes further". The case ID combines the purchase document and the purchase item.

What does Google advise before building with machine learning?

Google's Rules of Machine Learning (last updated 25 August 2025) open with "Rule #1: Don’t be afraid to launch a product without machine learning." Rule #2: design and implement metrics first, tracking as much as you can in your current system. Rule #3: a simple heuristic gets a product out the door, a complex one is unmaintainable, and machine learning comes once you have data.

Is there an Indian example of cases handled by hand?

NPCI, set up by the RBI and the Indian Banks’ Association to run retail payments and settlement in India, publishes a UPI Deemed Approved percentage: the share of transactions where credit confirmation from the beneficiary bank is not received online. NPCI adds that if the beneficiary account is not credited online, the beneficiary bank processes the transaction manually under RBI guidelines. For August 2026, NPCI's Top 50 Member Performance shows 0.00% to 0.76% across the top fifty beneficiary banks.

Which RBI rules already fix part of a process?

Each rule binds only the entity it names.

Digital Payments – E-mandate Framework, 2026 (RBI/DPSS/2026-27/396, April 21, 2026), for payment system providers and participants processing recurring transactions, domestic or cross-border, on cards, PPI or UPI. It repeals the earlier e-mandate circulars.

  • 8(a), 8(b): an additional factor of authentication (AFA) above ₹15,000 per transaction, or ₹1,00,000 for insurance premiums, mutual funds and credit card bills.
  • 4(a), 4(e), 5(a): AFA at registration, AFA validated by the issuer at any change to or withdrawal of a mandate, and AFA on the first transaction, whatever the amount.

Commercial Banks – Know Your Customer Directions, 2025 (RBI/DOR/2025-26/169, November 28, 2025, updated December 29, 2025), for commercial banks. Paragraph 27 applies only where a bank opts to undertake V-CIP:

  • 27(1)(vi), 27(2)(i): the bank may use AI to keep V-CIP robust, but only specially trained bank officials may operate it, under a clear workflow and standard operating procedure.
  • 27(2)(xv), 27(3)(ii): accounts go live only after concurrent audit, and the activity log keeps the official's credentials.

Paragraph 23, second proviso, applies to every commercial bank, but only for the e-KYC exceptions it describes: where e-KYC fails for a benefit or subsidy claimant under section 7 of the Aadhaar Act, 2016, through injury, illness or old age, an official carries out due diligence using offline verification or another officially valid document. The case joins the concurrent audit (paragraphs 12 and 13) and a centralised exception database.

RBI/2019-20/67, "Harmonisation of Turn Around Time (TAT) and customer compensation for failed transactions using authorised Payment Systems" (September 20, 2019, in effect October 15, 2019), for banks and other operators and system participants.

  • A failed transaction includes failures not attributable to the customer, credits not made for lack of full or proper information, and delays in initiating a reversal. The turnaround time is the outer limit, and compensation is paid without waiting for a complaint or claim.
  • UPI: where the beneficiary account can't be credited, the beneficiary bank must reverse the payment automatically by T + 1 day (T is the transaction day). A second type of UPI failure must be reversed within T + 5 days. Each deadline carries ₹100 compensation per day of delay beyond it.

FAQ

Questions about the share that stays with a person.

For anything else, ask us directly.

Not on their own. The Process Mining Manifesto, by the IEEE Task Force on Process Mining, says event logs contain only sample behavior and "should not be assumed to be complete". A record of past cases shows what did happen. It cannot show a kind of case that has not arrived yet, or a step people took around the system. Your records are still where the manual measurements start: volume, time per item and mistakes. The share that stays with a person comes from piloting on a real sample, as the steps above describe.

They route to a person. Which cases those are depends on a threshold you set. Keeping a person approving items one at a time, and deciding when that can stop, is covered on AI agent development.

Not by Google's account. Its Rules of Machine Learning tell readers "Don’t be afraid to use human editing either." Google advises launching without machine learning until there is data, and names human editing as acceptable. That is Google's advice about building with machine learning in general. It says nothing about which steps in your own process need a model.

Then the share is harder to measure, and the Process Mining Manifesto explains why. It lists incomplete event data among the hurdles, including events that do not point to the case they belong to and events with no time attached. At the lowest of its event log levels, recorded events "may not correspond to reality", and the Manifesto says logs "for which events are recorded by hand typically have such characteristics". A process with no record of its cases cannot have its share measured from history, so the numbers have to come from measuring the manual work and a pilot.

Yes, by our security team rather than the people who built the system. That work is described on generative AI security testing.

This page is about how many of your cases a system can close on its own. How much authority a system is given is covered on AI agent development.

Let's talk

Tell us which process you have in mind.

Tell us what the process is and how it runs today. Project work is delivered remotely from India during business hours. We reply within one working day.