How I would build and mature KPFF's AI program.
Prepared for the KPFF Consulting Engineers team
The posting describes a firm where AI work is already happening across offices and Reporting Centers, and a role meant to bring structure and momentum to it — a practical front door, coordinated governance, records that hold up, pilots that reach a decision, and reporting leadership can act on.
This is my proposal for how I would do that. It is built from the public posting and uses fictional example data throughout. It assumes nothing about how KPFF works today; the first ninety days are for finding that out.
A short operating proposal, readable in about five minutes, with two worked examples behind it. Not a description of KPFF's environment, and not a claim to know what is already in place.
The operating model
Every request takes the same seven stages. Triage is the only place they diverge, and what it decides is how much review the rest of the route carries.
| No. | Stage | The decision made here | Owner | Typical timing |
|---|---|---|---|---|
| 01 | Discover | Is there a problem here worth someone's time? | AI Program Manager, with practice group and shared services leaders | Continuous |
| 02 | Intake | Is this complete enough to triage? | Requester, supported by the AI Program Manager | Same week |
| 03 | Triage | Standard enablement, structured review, or elevated review? | AI Program Manager, with reviewers able to challenge the assignment | Weekly triage, within five business days of submission |
| 04 | Review | Proceed to pilot, proceed with conditions, reduce scope, or decline. | Functional reviewers — Security, Risk, Legal, Privacy, Data, HR as applicable | Standard: days. Structured: two to three weeks. Elevated: four to six weeks. |
| 05 | Pilot | Is the pilot operating within its guardrails? | Business owner | 8 to 16 weeks |
| 06 | Measure | Did this produce the value it promised, and what did we learn? | Business owner, with the program coordinating collection | Final four weeks of the pilot |
| 07 | Scale, modify, pause, or retire | Scale, modify, pause, or retire. | AI Governance Committee or the accountable functional owner | At the scheduled governance meeting |
Set at triage, applied from Review on
| No. | Pathway | What it is for | Target timing |
|---|---|---|---|
| 01 | Standard enablement | Get out of the way. These requests are answered with guidance, not review — the goal is same-week resolution. | Answered in the weekly triage, typically within five business days |
| 02 | Structured review | One coordinated review with the two or three functions that actually have a stake, held on a scheduled date rather than routed through separate queues. | Two to three weeks from complete submission to decision |
| 03 | Elevated review | Slow down on purpose. These use cases can affect people's livelihoods, rights, safety, money, or the firm's professional standing, and the review has to be able to withstand scrutiny later. | Four to six weeks, longer if the evidence a reviewer needs does not exist yet |
How I read this role
Five things the posting makes clear, what each one would change about how I work, and — for three of them — the record it produces.
- RR-01
In a decentralized firm, the front door has to be easier than the workaround.
Intake stays short enough to complete between meetings, with published timelines so people know what to expect. Requests come back the same day with specific questions, never a bare rejection. Nothing here can be mandated, so the process has to be worth using — if people route around it, the process is the defect, not the people.
The posting is explicit that KPFF is decentralized and that success depends on relationships and influence rather than formal authority.
- RR-02
The work started before the program did.
The lifecycle starts at Discover, not Intake. The first inventory covers what already exists — tools in use, informal practices, pilots nobody registered, the people who have quietly become the local expert. A program that behaves as though the work began the day it arrived loses the people already doing it, and those are exactly the people it needs.
The role is described as bringing structure and momentum to AI efforts already underway across the firm.
- RR-03
Coordination with real accountability, and no approval authority.
I would operate underneath existing policy, not author it. My responsibility matrix has no approval mark in the program manager column — every decision record names the owner who made it. What I am accountable for is that the right people saw the right material in time, that the decision got written down with its reasoning, and that the conditions attached to it are tracked to closure. Exhibit B is one of those records.
The role reports to the Director of Technology and escalates policy, risk, budget, security, legal, vendor, and strategic decisions to the appropriate functional owner or governance body. AI policy and the Six Prescriptions are already in place.
Exhibit BDecision logDEC-2026-04AI Governance CommitteeAutomated resume screening and candidate ranking
2026-05-18- Decision owner
- Grace Lin, People & Culture Director, with Risk, Legal & Privacy concurrence
What was decided
Not approved as proposed. Automated screening, scoring, ranking, and shortlist generation are declined for the current recruiting cycle.
The vendor could not produce adverse-impact testing documentation, and the firm has no internal capability to validate the model's effect on protected groups. Without that, a ranked shortlist would shape employment outcomes on reasoning nobody in the firm can explain.
What was rejected, and why
- Approve with human review of the ranked list — rejected; reviewing a ranking still inherits the ranking
- Approve for a single office as a test — rejected; the harm and the evidence gap do not shrink with scope
- Defer entirely — rejected in favor of separating the logistics problem, which is real and solvable
- Conditions
- Reconsideration requires vendor adverse-impact documentation and a defined validation approach
- People & Culture owns any future reconsideration, not the program
- Linked records
- UC-004 TL-04
- Review on
- 2027-02-01
Notice the owner field: People & Culture, not the AI Program Manager. The program wrote this record; it did not make this call. - RR-04
Review effort matched to risk, published so anyone can see why.
Three pathways rather than one queue. A meeting summary should never wait behind a recruiting workflow, and a recruiting workflow should never move at the speed of a meeting summary. The triage questions are published, and every classification shows which answers put it there — so a requester who disagrees has something specific to argue with. Exhibit A shows a classification and the answers behind it.
The posting names the higher-risk categories that need coordinated review: HR and recruiting, public-facing content, sensitive data, business-system actions, and autonomous or semi-autonomous agents.
Exhibit ATriage resultUC-004Use-case registerEarly-career recruiting screening and interview support
People & Culture · submitted 2026-03-04
- Classification
- Elevated reviewFour to six weeks, longer if the evidence a reviewer needs does not exist yet
- Answers that decided it
- R-01Yes — affects decisions about individualsraises to elevated review
- R-02Yes — restricted data classificationraises to elevated review
- R-07Yes — new or unreviewed toolraises to structured review
- Not recorded
- A score. There is no arithmetic here to disagree with. Run it yourself.
Notice that the result is a list of answers, not a score — each one is something a requester can argue with individually. - RR-05
Records and reporting that hold up when someone asks later.
One register that every other view derives from, so a leadership number cannot contradict the underlying record. Decision entries capture what was rejected and why — the field that makes a program defensible a year later. Every reported figure carries an evidence label, because leadership can only act on a number when they know how good it is. Exhibit C is one that did not clear its threshold.
The posting calls for an inventory, use-case register, decision log, exception log, and AI-use records sufficient for a defensible audit trail, plus leadership reporting on adoption, risks, decisions, and outcomes.
Exhibit CPilot measurementPIL-003Pilot registerStandards knowledge search
2026-04-13 — 2026-09-15Citation accuracy on the 100-question test set
Evidence: measuredthreshold to scale 95%measured 91%Measuring against the scale threshold. Accuracy 91% against a 95% target; the library cleanup that would close the gap is scheduled.
- Also measured
- Median time to locate a current standard1.8 minutes against Under 2 minutes, from a 6.5-minute baseline · measured
- Weekly active users among pilot participants41 of 60 against 60% of 60 licensed users · measured
- What the gap is
- The accuracy gap is mostly a records problem. Eight of the nine failing questions cite documents that should have been retired years ago.
- Decision available
- Scale, extend the measurement window, or hold pending library cleanup
Notice that the threshold was set before the pilot ran, and the measured result is under it. The recommendation is not to scale.
The first ninety days
Listen before organizing, organize before piloting. The sequence matters more than the contents — a program that arrives with a framework instead of questions spends the rest of the year recovering from it.
Find out what is already true before proposing anything. In a decentralized firm the program's credibility in month six depends almost entirely on whether people felt heard in month one.
Meet the people who will make or break this
Structured conversations across Technology, Security, Risk and Legal, Data, HR, Marketing, Finance, Operations, and every practice group. Same five questions each time so patterns are comparable: what are you already doing with AI, what would help, what worries you, who else should I talk to, and what has been tried before that did not work.
Inventory what exists
Tools in use and tools quietly expensed, active pilots, informal practices, existing policy language, training already delivered, contracts and renewal dates, and the people who have appointed themselves the local expert. The informal practices matter most — they show where the real demand is.
Map decision rights as they actually work
Not the org chart. Who genuinely decides on security exceptions, vendor contracts, client data handling, and employment process changes — and where those decisions get made. Governance that ignores the real path gets routed around.
Deliverables
- Stakeholder map with decision rights and escalation paths
- Initial AI tool and vendor inventory, including tools nobody formally approved
- Draft use-case register seeded from what is already happening
- Baseline measurement snapshot with the date it was taken
What good looks like
- Every function has met the program manager and knows what the role does and does not decide
- A written inventory exists where none did
- No surprises: anything risky is already with its owner
What could go wrong in this phase
- Arriving with a framework instead of questions
- Being read as an auditor — the first conversations set that perception for a year
Days 1–30 — Listen and map
Find out what is already true before proposing anything. In a decentralized firm the program's credibility in month six depends almost entirely on whether people felt heard in month one.
Deliverables
- Stakeholder map with decision rights and escalation paths
- Initial AI tool and vendor inventory, including tools nobody formally approved
- Draft use-case register seeded from what is already happening
- Baseline measurement snapshot with the date it was taken
Days 31–60 — Organize and align
Turn what exists into something navigable. The test for every artifact in this phase: would a busy project manager use it without being told to?
Deliverables
- Published intake form and triage model with pathway timelines
- Responsibility matrix confirmed with each function
- Live use-case register, tool inventory, decision log, and exception log
- Two to four pilot charters ready for review
Days 61–90 — Pilot and measure
Prove the model works on real work, and report honestly — including where the value was smaller than hoped.
Deliverables
- Active pilots with baselines, guardrails, and scheduled decision dates
- First leadership program review delivered
- Documented scale, modify, pause, or retire recommendation for each pilot
- Next-quarter roadmap with owners and dates
How I operate
Start with the business problem, not the tool.
A request that cannot name the problem is not ready for review, and saying so early saves everyone a cycle.
Match the review to the risk.
Most requests should take the short path. The pathway model only pays off if the short path is genuinely short.
Name the owner before anything starts.
If nobody will own the outcome, the pilot does not begin.
Keep people accountable for consequential output.
Oversight means a named role, a specific check, a defined frequency, and the authority to override. Anything less is a claim, not a control.
Write down the reasoning, not just the decision.
Including the options that were considered and rejected.
Measure honestly, including when the answer is smaller than hoped.
Baselines before the tool arrives, thresholds set before results are known, and self-reported benefits labeled as such.
What I would need to learn first
Everything above is a starting proposal. The structure is what I would bring on day one; the specifics should change once I know how KPFF actually operates. These are the questions I would be asking in week one — and a few of them are questions I would want to ask in an interview.
- What AI work is underway right now, formally and informally, and who is doing it?
- Who genuinely decides today on security exceptions, vendor contracts, client data handling, and changes to employment processes?
- What do client agreements say about processing project material in third-party services, and how much does it vary?
- What has already been tried that did not work, and why do people believe it failed?
- How do offices outside the largest ones actually get information, and what feels decided without them?
- What does leadership see today, and which of it do they act on?
Two worked examples sit behind this page: how a request gets classified, and one request that was declined and re-scoped into something safer and more useful.
The measure of this program is not how much it reviews. It is whether the people doing the work choose to use the front door, and whether the records still explain themselves a year later.