General

The AI Framework for the Enterprise: Scaling from Pilots to Governed Deployment

· By AIHQ Team

Malaysian senior leaders reviewing an AI adoption roadmap in a corporate boardroom

Most SMEs are running three AI pilots and no AI plan

A chatbot on the website, a few ChatGPT seats, and one manager who quietly built a spreadsheet macro that summarises weekly reports. That is the typical AI footprint of a Malaysian SME that has been "doing AI" for a year. None of it connects. None of it has an owner. And when the founder asks what it has saved, nobody has a number.

An AI framework for the enterprise is not a strategy document. It is a sequence of stages, each with a specific criterion that tells you whether you have earned the right to start the next one. Below are seven stages, written for SME founders and owners: what each stage actually is, the entry criterion, the rough effort in money and months, and who it suits. Skip a stage and you will usually pay for it later.

Stage 1: Use-Case Inventory (2 to 4 weeks, under RM5,000)

Entry criterion: You can name at least three tasks your staff repeat every week.

A structured AI innovation bootcamp or a half-day workshop with department heads gets you here. This stage is a workflow audit, not a technology exercise. Sit with HR, finance, operations, sales and customer service, and list every recurring task: quotations, meeting minutes, tender responses, onboarding checklists, enquiry replies, monthly reporting packs.

For each task, record three things: volume per week, who does it, and how long it takes. That is your entire deliverable. Use-case discovery at this stage is cheap because you are only buying attention, not tools.

Who it suits: Every SME. If you cannot complete this stage, any AI spend is a guess.

Stage 2: Feasibility Screening and Guardrails (3 to 6 weeks, RM5,000 to RM25,000)

Entry criterion: You have a prioritised list of 8 to 15 candidate use cases.

This is where most SME AI programmes quietly die, and the failure is almost always data access or permissions rather than model quality. Screen each use case against four questions:

  • Can the data be accessed without breaking your systems of record?
  • Does it involve personal data covered by the Personal Data Protection Act 2010 (PDPA), customer financials, or HR records?
  • Is there a person who can review the output before it leaves the department?
  • Can you describe a measurable outcome in one sentence?

Use cases that fail the third or fourth question should be parked, not cancelled. Those four questions also give you the first draft of your internal AI use policy — typically one page covering what staff may paste into public tools, which data categories are off-limits, and who approves exceptions.

Who it suits: SMEs with 30 to 300 staff, and any organisation handling customer or employee personal data. For a deeper look at why this middle stage causes the most failures, see why AI adoption frameworks stall at stage two.

Stage 3: Leadership Alignment Before Spend (1 to 2 sessions, RM3,000 to RM15,000)

Entry criterion: You have a shortlist and you can name the budget holder.

Leadership alignment sessions are the cheapest lever in this entire framework and the most commonly skipped. The purpose is not inspiration. It is to settle four decisions in writing: who owns AI adoption, what the first-year budget ceiling is, which data cannot leave the organisation, and what "good" looks like in 12 months.

Practically, this is usually a half-day executive briefing with the founder, the finance lead and two or three department heads. In larger groups, a company secretary or legal advisor should attend because decision rights and records matter. An AI leadership briefing is enough to produce a one-page charter.

Who it suits: Any SME where more than one department is involved, and any family-owned business where siblings or second-generation leaders hold different views on AI.

Stage 4: Capability Building Tied to Roles (4 to 12 weeks, RM20,000 to RM80,000)

Entry criterion: Leadership has signed the charter and named an owner.

General AI awareness training produces polite feedback forms and very little behaviour change. Role-based AI training produces workflow change because every exercise uses the participant's own queue of work. Finance teams learn to reconcile and draft commentary. Operations teams learn to turn SOPs into searchable answers. Customer service teams learn to draft replies that a human still approves.

Two design rules matter more than content volume. First, train by role and by process, not by tool. Second, put a named AI champion in each department who owns one workflow after the session ends. If you are scoping the budget for this stage, the HRDC claimable data and AI certifications guide explains how Malaysian employers can structure funded programmes — subject to eligibility, grant approval and HRD Corp submission requirements.

AIHQ itself is a registered HRD Corp training provider, and programmes can be structured to be claimable on those same conditions. Do not assume approval; budget as though you are paying, and treat any claim as a recovery.

Who it suits: SMEs whose bottleneck is people rather than technology. If your staff genuinely do not know what to do with the tool in front of them, spend here before buying anything else.

Stage 5: First Governed Pilot (6 to 12 weeks, RM15,000 to RM60,000, mostly opportunity cost)

Team documenting a baseline metric on printed process maps at a small project table

Write the baseline before the pilot starts — quotation time, response time, reporting hours.

Entry criterion: You have trained users, an owner, and a measurement definition.

Choose one use case from stage two. A good first pilot touches one department, produces a countable output, and can be reversed in a week. Common picks for Malaysian SMEs: quotation turnaround time, monthly management reporting, customer enquiry first-response, and internal policy Q&A.

Write down the baseline before you start. If quotations take an average of two days across 40 quotations a month, record that. Then run the pilot for eight weeks with a weekly 30-minute review. The review question is never "is the AI good?" It is "did the metric move, and did quality hold?"

Where the workflow involves documents, SOPs or customer queries, a custom AI workflow may be more appropriate than another seat licence, because the bottleneck is usually retrieval and permissions rather than text generation.

Who it suits: SMEs that have completed stages 1 to 4. Skipping to a pilot without an owner and a baseline is how pilot purgatory starts.

Stage 6: Standardise, Then Extend (one quarter, RM30,000 and above depending on scope)

Entry criterion: The pilot moved its metric and quality held for at least six consecutive weeks.

Now convert the pilot into an operating routine: a documented prompt library, a named reviewer, a data-handling rule, and a monthly report line that goes to leadership. Only after that should you extend the same use case to a second department — reuse is where the return lives, not novelty.

This stage is also where the review workload becomes visible. Many SMEs discover they need a lightweight dashboard showing adoption by department, hours saved per workflow, and exception rates. That visibility is a governance tool as much as a management one.

Who it suits: SMEs with at least one clearly measurable win and a leadership team willing to fund the second wave.

Stage 7: Scale with Governance (ongoing, 5 to 10 per cent of annual AI spend)

Entry criterion: At least two workflows are running as routine operations.

Scaling means repeating a known pattern, not adding tools. Governance at this point becomes concrete and mostly boring: a quarterly review of the use policy against actual practice, an annual PDPA-aware review of where personal data flows, a refresh of role-based training for new joiners, and a short register of AI systems with an owner for each.

Responsible AI and governance training is worth repeating here, not because the principles change but because staff turnover does. A responsible AI training session for new managers is usually more useful than another tool demo.

Who it suits: SMEs past the RM50 million revenue mark, or any organisation in a regulated sector — manufacturing with export customers, healthcare-adjacent services, financial advisory, or professional services subject to audit.

A note on what this framework will not do

Two things need to be said plainly. First, a framework does not guarantee outcomes. Results depend on your data, your adoption, your review habits and how honestly you measure. Second, off-the-shelf tools will cover perhaps 60 per cent of the workflows an SME actually has. The remaining 40 per cent — knowledge retrieval across your own documents, approval routing, quoting logic — usually needs a custom AI solution, which is a different kind of project with a different budget profile.

There is a useful precedent for what disciplined sequencing produces. AIHQ supported Media Prima through a structured 12-month capability journey spanning awareness, fundamentals, intermediate LLM skill-building and advanced application workshops. Across that cohort, 98 per cent of participants reported satisfaction, 90 per cent reported increased practical knowledge and skills, and 92 per cent found the training relevant and applicable to their work. Those figures describe one programme, not a universal result — but they suggest that sequencing and role relevance matter more than tool coverage.

Where SME owners usually get the order wrong

  • Buying licences before mapping workflows. Tool spend without a use-case inventory produces unused seats.
  • Running training before leadership alignment. Without a charter, managers quietly opt out and adoption becomes personal preference.
  • Treating the pilot as the finish line. A pilot that is not standardised into a routine disappears within two quarters.
  • Deferring data rules until after rollout. PDPA obligations do not pause for the pilot phase, and retrofitting permissions is slower than designing them once.
  • Measuring activity instead of output. Number of prompts used is not a metric. Quotation turnaround time is.

FAQ

What is the first step in an AI framework for the enterprise if we are a small company?

Start with a use-case inventory. Two to four weeks of listing recurring tasks by department, with volume and time per task, tells you where AI is worth testing. It costs very little and it prevents you from buying licences before you know what problem they solve.

Do we need AI governance before we run a pilot?

You need the basics, not a full policy suite. A one-page rule covering which data cannot be entered into public tools, who approves exceptions, and who reviews output is enough to start. Malaysian organisations handling personal data should also consider their obligations under the Personal Data Protection Act 2010 before scaling usage.

How long does it take to move from a pilot to organisation-wide adoption?

Typically two to three quarters. Six to twelve weeks for the first governed pilot, then a quarter to standardise it into a routine, then a further period to extend it to a second department. Attempting to skip the standardisation quarter usually results in the pilot quietly fading.

Is HRDC claimable training available for AI upskilling?

AIHQ is a registered HRD Corp training provider and programmes can be structured to be HRDC claimable, subject to client eligibility, grant approval and HRD Corp submission requirements. Employers should plan budgets as though they are paying and treat any claim as a recovery, not a certainty.

Will off-the-shelf AI tools cover everything we need?

No. General tools handle drafting, summarising and analysis well. Workflows that depend on retrieving answers from your own SOPs, policies or systems, or that require approval routing, often need custom AI solutions or workflow automation with proper permissions.

How do we measure whether AI adoption is working?

Pick one countable output per workflow before you start — quotation turnaround time, first-response time, reporting cycle length — and record the baseline. Then review it weekly during the pilot and monthly once it is standardised. Activity measures such as number of prompts used do not indicate value.

← Back to all articles