San Jose, Calif.-based robotic processing automation (RPA) company Automation Anywhere has raised more than $849.3 million in eight funding rounds, and is preparing for its initial public offering. Bank Automation News sat down with newly appointed Chief Information Officer Sumit Johar to discuss his approach to automation and information technology (IT).

The most common question Johar fields from customers about robotic process automation is simply, “Where do I even start?”
His answer? Start where traditional applications fail. It may be email, spreadsheet or a data application — but somewhere, the automation is incomplete.
“What we are trying to do is to provide you an experience and technology that helps you automate tasks that cover all aspects of your touchpoints across the board,” Johar told BAN. “That’s why RPA is getting so much acceptance in the market right now — because traditional technologies could not solve that problem.”
Bank Automation News: Automation Anywhere plans to automate at least 40% of all its manual, repetitive business processes. How does the company approach and prioritize automation internally?
Sumit Johar: We strongly believe that we want to be able to drink our own champagne; we want to be the best customer of our own technology. When I came here, I noticed that we are already using our technology for a number of areas, whether it is a typical IT operation, like how do you assign tickets to the right employees? How do these tickets get responded? Can we build some automation, so not every ticket has to be manually looked at, right? These are standard use cases for IT operations.
But there are some use cases that are not standard, and my favorite ones are actually in security and compliance function. So if you talk to any CIO who has security responsibility, or if you talk to a [chief security officer] they will tell you a lot has changed in the last couple of years. My team, every day, we get hundreds and hundreds of security alerts coming from different systems that we have invested in and, in general, I would say 99% of them are false alerts. And that’s not just us — that is the same everywhere. So my team had to manually sit and review every single alert and validate whether it’s a false alert or not, and act on the right ones. That’s a very, very laborious, error-prone, repetitive process.
What we’ve done now is we put some automation using our own technology, where we are able to validate whether it’s a false alert or not, using bots and with digital assistants that we have deployed internally. So my team is now able to look at the real ones, the critical ones that we need to see. It’s a huge, huge productivity gain for my employees. That’s one of my favorite cases.
BAN: Automation Anywhere recently launched a citizen developer role in Automation 360, which offers a dedicated software license for organizations to leverage business subject matter experts to create robots. Do you have citizen developers and use this internally?
SJ: Yes, we do. As a matter of fact, I’m in the process of expanding that model. Right now, we do have a center of excellence in a team internally that my team is leading, and there is participation from multiple departments internally, whether it is finance, legal, HR. All these teams have identified a few “bot champions, bot warriors” or whatever you want to call them, and they work very closely with this central team. These teams bring ideas to us. We collectively debate about what are the right use cases. We work with them, explain to them whether these are the right use cases for automation or not, where can you get the value faster than others? Then they are able to build their own bots by themselves. But once the bots are ready, they come back to work with us. We help them deploy in a way that is consistent with best practices and secure.
BAN: What innovative technology are you keeping your eye on?
SJ: It’s not just one technology. I mean, I’m representing a company that’s providing cutting-edge automation solutions to our customers. So clearly, the top of my focus right now is on that.
Since the pandemic started, and remote work became a reality for every company, whether you were prepared or not, everybody almost had to jump into this digital transformation journey. Right now a lot of investment is coming in the name of digital transformation, to make your employees more productive as they’re working remotely.
We are noticing a couple of changes with that. One is the number of apps that an employee has to use internally, the volume of these apps is increasing, because companies are trying to make more and more applications available to employees so they stay productive. Second, the effect of this is companies are embracing cloud as a platform of choice for deploying solutions, or new technologies, a lot faster than what we saw in the past.
The experience of employees is actually becoming more challenging because, to give you a data point today, for a company size of 1,000 employees — let’s talk about a technology company — you will easily find an average of 150 applications within a company of that size. Five years back, it was probably half of that.
That’s where the need for providing an automation experience and providing a digital experience to employees [comes in] — so they can have a central assistant that they can rely on. That digital assistant can deal with other touch points of the company. That’s a pattern that we are noticing: More companies are investing in providing a digital experience, central digital assistant to employees, and that, coupled with automation, is starting to make a difference.
BAN: You’re a proponent of a security model called ‘zero trust.’ Can you briefly explain what it is and why you prefer this model?
SJ: Let me give some background about why are we even talking about zero trust. For a long time, organizations were investing in security-related technologies, with the assumption that my employees are working on the company premises basically, right? Then pandemic changed everything — one fine day, all of us are working from home. And all the network traffic, the connectivity to your applications, now is bypassing your company network. The net result of that is the investments that you’ve made on securing this traffic is now sitting redundant because none of this traffic is going through your traditional firewalls.
So every organization has to look at security in different ways now because the devices, the applications, and your employees — all three are sitting outside your network perimeter. So how do you secure access to applications going forward? To do that, you need to look at the entire network architecture in a different way. If I’m an employee, and I need to connect to an application that’s sitting on the cloud, or in a [software as a service]. At every leg of that connection, you need to ensure that the connection is coming from the right person, the right identity in the right context. So the need to validate all these security checks has grown a lot more and it’s gotten a lot more complex. That’s where zero trust comes into picture. The basic concept is: Don’t trust the connection, no matter whether it’s coming from your network or not. Build a security model in a way where you don’t trust any connection from any point to any other point; check and verify at every level.
BAN: Is there a specific product or feature you are prioritizing this year?
SJ: First, as you know, we are a cloud-first company; we are really big on our cloud strategy. We have taken the company in last few years and invested a lot in building a cloud-native, web-based platform. We’re going to continue to double down on that as a strategy because it is helping our customers deploy RPA much faster. That’s going to continue to happen.
The second thing that’s happening — both from a product point of view and also internally — is one of my priorities is improving the digital assistance experience for employees. My goal is to provide a digital assistant to every single employee within the organization so they are able to control, manage and interact with other digital touchpoints and bots that we already deployed for them and improve their experience. So we’re going to continue to do more in these two areas.
The Bank Automation News webinar on automation technology for exceptional bank cybersecurity and ID verification takes place on Thursday, Sept. 9, at 11:30 a.m. ET. Register here. Attendees will be able to ask questions via chat.






