General

AI Center of Excellence: A Guide for Consulting Firms Scaling Generative AI Services

· By AIHQ Team

Small consulting team reviewing an AI centre of excellence team structure and workflow charts in an office

Most Malaysian consulting and advisory firms have now delivered at least one generative AI project. Client demand is not the bottleneck — repeatability is. The practical reality: a boutique firm can run a credible AI center of excellence with four to six people, and the binding constraint is a written scoping checklist, not headcount. No do-not-repeat article on this site makes that argument, and it is the argument that decides whether your third GenAI engagement costs you as much effort as your first.

Why SME owners are asking for this now

If you own a consulting firm, the pattern is familiar. A client — often a GLC, a bank or a mid-market manufacturer — asks for an AI readiness assessment. You deliver it well. Then they ask for training. Then a chatbot for internal policies. Each request arrives through a different partner, gets scoped differently, and produces different pricing. Your margin depends on who happens to be free that month.

An AI center of excellence is simply the internal structure that stops this. It is a small, named group with agreed methods, agreed guardrails and agreed commercial bands, so the second, fifth and twentieth GenAI engagement follow the same spine.

The four-person core team (and who to borrow)

You do not need a data science department. For most Malaysian consulting firms under 60 staff, a CoE works with four permanent roles plus part-time support.

  • CoE lead / engagement principal. Owns client scoping, commercial bands and delivery quality. Typically a senior consultant, not a technologist.
  • Solution architect. Translates business workflows into technical designs. Practical knowledge of LLM limits, retrieval and integration patterns matters more than research pedigree.
  • AI governance and data lead. Owns data classification, retention and review rules. This is the role most firms skip and later regret.
  • Capability and enablement lead. Runs client training and internal upskilling, and maintains the reusable workshop materials.
  • Borrowed support: a data analyst, a UX or business analyst, and an external specialist for sector regulation questions.

Keep the CoE part-time-client-facing at first. The lead should still run engagements for the first 6 to 12 months so methods stay grounded in real delivery.

Governance: what Malaysian firms must actually write down

The Personal Data Protection Act 2010 (Act 709) is the operative constraint for most client work here, and its 2024 amendments added obligations — including breach notification duties — that affect how you handle client data during AI pilots. You do not need to be a lawyer to be useful. You do need four written rules the whole firm follows.

  1. Data classification before ingestion. A one-page table: public, internal, confidential, restricted. Nothing above "internal" enters a public AI tool, ever.
  2. Approved tool list. Enterprise or API-tier access only for client data, with data retention and training opt-out settings confirmed in writing.
  3. Human review gate. Named reviewer per deliverable type. AI-assisted findings are labelled as such.
  4. Incident path. Who is called within 24 hours if client data is exposed or a model output causes client harm.

If you want a structured starting point, AIHQ runs AI governance workshop sessions that help teams convert policy into day-to-day behaviour rather than a document nobody reads.

The delivery model: five stages you can reuse

Hand-drawn paper infographic showing five AI delivery stages: discover, frame, prove, embed and operate

The five reusable stages: discover, frame, prove, embed, operate.

A repeatable model is what converts a one-off project into a margin. The five stages below are deliberately business-first, because that is where client budgets actually sit.

  1. Discover (2–4 weeks). Workflow interviews, pain-point mapping, data availability check. Output: a prioritised use-case list with effort and risk scores.
  2. Frame (1–2 weeks). Pick one or two use cases and write the success measure before build. Clients who skip this step approve scope creep by default.
  3. Prove (4–8 weeks). A bounded pilot with real data, real users and a named reviewer. Budget a defined ceiling — do not run an open-ended experiment.
  4. Embed (4–12 weeks). Move the pilot into a workflow, add role-based training, document escalation paths.
  5. Operate (ongoing). Monitoring, prompt or retrieval maintenance, quarterly review. This is where recurring revenue sits.

Stage 1 and 2 are where most firms leave money on the table. A AI use-case discovery workshop style engagement is faster to sell than a build, and it de-risks the build that follows.

Pricing bands you can defend

MYR bands vary by sector and scope, so treat these as planning ranges for a Malaysian boutique, not quotations.

Stage Typical range (MYR) Duration
Discovery and use-case prioritisation 15,000 – 40,000 2–4 weeks
Framing and success measures 8,000 – 20,000 1–2 weeks
Pilot build (chatbot, copilot or automation) 40,000 – 120,000 4–8 weeks
Embed plus role-based training 20,000 – 60,000 4–12 weeks
Operate retainer 3,000 – 12,000 / month Ongoing

The credibility question clients raise is always the same: have you done this before. AIHQ has trained and engaged over 9,000 professionals and delivered a 12-month structured capability journey for Media Prima, where 90% of participants reported increased practical knowledge and skills. If your firm lacks that track record, partner for the first two engagements rather than overstate it.

Building your own people, not just hiring

The hardest part is not recruiting. It is getting a generalist consultant to the point where they can scope an AI engagement without a specialist in the room.

  • Run an internal monthly lab: one real client workflow, one hour, everyone attempts the same task.
  • Certify on a defined ladder: awareness, role-based usage, then scoping ability.
  • Rotate one consultant per quarter through delivery of a live pilot.
  • Keep a written library of past scoping memos — the single highest-return asset a CoE builds.

If your team needs structure here, role-based AI training can be designed around the specific workflows your consultants touch, rather than a generic prompting course.

Where off-the-shelf tools stop being enough

Half your engagements will be solved with existing tools plus better habits. The other half will not. Signs a client needs custom AI solutions rather than tool training: multi-document retrieval, sensitive data that cannot leave their environment, an approval workflow with escalation, or a requirement to log every answer for audit.

Recognising that boundary early protects your reputation. Promising a tool that cannot deliver is the fastest way to lose a client that was otherwise satisfied.

Six-month rollout sequence

  1. Month 1: appoint the CoE lead, write the four governance rules, agree pricing bands.
  2. Month 2: build the scoping checklist and the reusable use-case scoring template.
  3. Month 3: run one internal pilot on your own firm's workflow.
  4. Month 4: deliver a client discovery engagement using the checklist; capture lessons.
  5. Month 5: publish internal case notes, start the certification ladder.
  6. Month 6: review margins per stage and adjust bands.

Common mistakes SME owners make

  • Staffing the CoE with technical hires only, then failing to sell the work.
  • Writing an AI policy before running a single pilot — policy built in the abstract rarely matches real workflows.
  • Treating training as a one-off event rather than a recurring capability line.
  • Quoting per-project instead of per-stage, which hides where the profit actually sits.
  • Claiming a sector track record the firm does not have. Clients check.

FAQ

How big does an AI center of excellence need to be for a consulting firm?

For most boutique Malaysian consulting firms, four permanent roles plus part-time support is enough to start: a CoE lead, a solution architect, a governance and data lead, and a capability lead. Scaling headcount before you have a written scoping checklist usually adds cost without adding repeatability.

What governance rules should a Malaysian consulting firm write first?

Start with four: a data classification table, an approved tool list for client data, a named human review gate per deliverable type, and a 24-hour incident path. These sit under the Personal Data Protection Act 2010 (Act 709) and its 2024 amendments. Firm-specific interpretation should be confirmed with your legal advisor.

Should we sell AI discovery or a pilot first?

Discovery first, in most cases. A two-to-four week discovery and use-case prioritisation engagement is easier for clients to approve, produces a scored list they can act on, and reduces the risk of an open-ended pilot that runs past budget.

Can a small firm compete with larger consultancies on GenAI?

Yes, if the advantage is delivery specificity rather than scale. Boutiques tend to win when they can show sector-relevant workflows, fixed-scope stages and a named reviewer. Do not overstate a track record — clients verify, and credibility loss is expensive.

When does a client need a custom AI solution instead of tool training?

Look for sensitive data that cannot leave their environment, multi-document retrieval across internal policies, approval workflows with escalation, or an audit requirement to log answers. That is usually the line between better training and a custom build.

How do we measure whether our CoE is working?

Track three things: the share of engagements that reuse existing methods rather than being rebuilt, the gross margin per delivery stage, and the number of consultants who can scope an AI engagement without a specialist present. Those three move before revenue does.

← Back to all articles