Enterprise transformation is not simply about replacing legacy systems or adopting the latest technologies. It requires leaders to make deliberate decisions about what to retain, where to integrate modern capabilities, and when existing platforms have become barriers to growth.
In this PIECES interview, Subba Kethu, Head of Digital Technology at Kia North America, shares his approach to value-driven modernization, the foundations organizations need before scaling enterprise AI, and the leadership principles required to translate ambitious technology strategies into measurable business outcomes across regions and functions.
Q1. Many enterprises face pressure to modernize quickly while continuing to rely on stable legacy systems. What principles should leaders use when deciding what to retain, integrate, or replace?
I use a value-driven framework based on three questions: does this system create business value today, is it technically viable, and what's the risk-versus-reward of changing it? Modernization isn't a technology project — it's a business decision and treating it that way changes what you optimize for. The goal isn't to replace as much as possible; it's to maximize business value while reducing risk and increasing agility.
Here's the decision framework I use:
a. Retain what differentiates the business and still performs well.
If a system runs critical operations reliably, holds proprietary knowledge, meets performance and security requirements, and costs a reasonable amount to maintain — keep it. The test is simple: does this system create business value today without materially limiting our future? If yes, retain it.
b. Integrate when the core works but modern capabilities are needed.
Preserve stable transaction engines while exposing them through APIs, event-driven architecture, and cloud-based services. This lets you add AI, digital customer experiences, mobile, analytics, and automation without disrupting systems that already work.
c. Replace when the system becomes a strategic constraint.
Replace when a platform blocks growth, can't support new customer experiences, lacks required security, depends on disappearing skills, or simply costs more to maintain than modern alternatives. This is especially true when the business model has shifted or a SaaS platform offers an immediate strategic advantage — legacy CRM to Salesforce, legacy ERP to SAP S/4HANA, or custom-built applications to SaaS.
In large enterprises — including automotive organizations running ERP, dealer, manufacturing, and customer platforms — the winning strategy is rarely "replace everything." It's retaining what provides stability, integrating where innovation is needed, and replacing only where the legacy platform becomes a barrier to transformation.
2. As enterprise AI moves from isolated pilots into core business operations, what foundations must organizations establish across data, governance, cybersecurity, and accountability before scaling it?
The challenge is no longer proving that AI works. The challenge is building an organizational foundation that lets AI scale safely, consistently, and responsibly. AI readiness is primarily a governance and data challenge — not a technology challenge.
Data.
Before we consolidated 900+ data sets into a single enterprise data warehouse, teams across the business were often making decisions off different versions of the same numbers. That's the real cost of poor data — not an abstract risk, but decisions made on inconsistent ground. Data readiness and enterprise knowledge management must come before you scale AI usage, not after.
Governance.
We built governance at Kia to be the thing that lets us move faster with AI, not slower — covering privacy, accountability, transparency, security, lifecycle oversight, risk controls, and value measurement. When we deployed our RAG-based generative AI pipeline, having that structure already in place is what let us move from pilot to production without re-litigating security and access questions at every step.
Cybersecurity.
AI is a new attack surface, and it must be treated as one. Before scaling, organizations need data protection controls — encryption, access controls, data classification, usage policies — and AI-specific security controls: model security testing, prompt injection protection, agent monitoring, and third-party AI vendor assessments.
