An AI readiness assessment is a structured, time-boxed review that tells you three things: which parts of your business have work worth automating or augmenting, whether your data and systems can actually support that work, and what has to be fixed before you spend money. For a Singapore SME of 15–500 staff, a credible assessment takes about two weeks of part-time effort from three or four people, and it ends with a scored baseline across six dimensions, a shortlist of two or three ranked use cases, and a costed 90-day plan. If an assessment produces a slide deck about “AI opportunity” but no named process owner, no baseline metric and no data gap list, it was not an assessment.
This guide sets out the exact dimensions to score, the rubric to score them against, who runs it and at what cost in time, the Singapore regulatory checks that apply, a worked example with the arithmetic shown, and the two-week schedule to run it without stopping operations.
What an AI readiness assessment actually measures
Most readiness questionnaires circulating online over-weight strategy and under-weight plumbing. In practice, SME AI projects fail on data access, process instability and ownership — not on model choice. Score these six dimensions separately, because a strong average hides a fatal weakness in one of them.
| Dimension | What you are really testing | Typical SME failure |
|---|---|---|
| Business case clarity | Can you name the process, its volume, its cycle time and its cost today? | “We want to use AI” with no process named |
| Data readiness | Is the data digital, accessible via export or API, reasonably complete and labelled? | Key data sits in PDFs, WhatsApp threads or one person’s spreadsheets |
| Process stability | Is the work done the same way each time, with documented exceptions? | Three staff each do it differently; no written steps |
| Systems and integration | Can your core systems (ERP, accounting, CRM, WMS) push and pull data? | Legacy on-premise system with no API and no vendor support |
| People and ownership | Is there a named internal owner with time allocated, and will frontline staff use it? | Owner is the MD, who has four hours a month |
| Governance and risk | Do you know what personal data is involved and who approves the outputs? | No record of what data goes into third-party tools |
Score each dimension on a 0–4 scale, and record evidence — a file path, a screenshot, a named system — for every score above 1. Scores without evidence are opinions.
The rubric
| Level | Meaning | Evidence you should be able to show |
|---|---|---|
| 0 | Absent | Nothing exists; nobody owns it |
| 1 | Ad hoc | It happens, undocumented, dependent on one person |
| 2 | Defined | Written down, followed most of the time |
| 3 | Measured | Documented and tracked with a number you review monthly |
| 4 | Optimised | Measured, reviewed and improved on a cycle, with a named owner |
How to read your scores
The scores are gates, not a grade. Apply them in this order:
- Governance and risk below 2 blocks everything. It is the fastest dimension to fix — a written tool inventory and a named approver can be done in a week — so fix it rather than waiting for it.
- An average below 2 blocks production deployment: anything running unattended, touching customers, or feeding a decision that is not checked by a person.
- A bounded pilot is still allowed with an average below 2, provided every output is reviewed by a named person before use, and provided the weak dimensions do not touch the chosen use case. A data readiness score of 1 driven by missing sales-outcome data does not block a document-handling pilot on files that export cleanly today.
- Any dimension at 0 stops that use case outright until the zero is lifted.
This is the distinction most readiness templates miss. A low average tells you not to automate at scale; it does not tell you to sit still for six months.
Who runs the assessment, and what it costs in time
The assessment should be run by someone who can compel a data export and interrupt a supervisor — in most SMEs that is an operations manager or the finance lead, not the IT vendor. The most common structural mistake is handing it to a prospective supplier, who will reliably discover that your problem matches their product.
| Role | Time over two weeks | What they do |
|---|---|---|
| Assessment lead (ops or finance manager) | 20–25 hours | Interviews, scoring, writing the six-page output |
| Sponsor (MD or director) | 3–4 hours | Sets scope, approves the shortlist, commits the owner’s time |
| Systems person (internal or outsourced IT) | 6–8 hours | Runs the export tests, confirms API and access reality |
| Two or three function heads | 2 hours each | Interview, walkthrough, validation of volumes and handling times |
That is roughly 40 hours of internal effort in total. If an external party runs it, insist on the same artefacts — scored dimensions with evidence, the export test results, the baseline plan — and insist that the evidence stays in your hands afterwards. An assessment you cannot re-run yourself in six months has limited value, because readiness is a moving number.
How to score data readiness without a data team
Data readiness is where assessments get hand-wavy. Make it concrete by testing extraction rather than asking about it. For each candidate use case, attempt to pull 12 months of the relevant records into a single spreadsheet or database table within one working day. What happens during that day tells you more than any questionnaire.
Use this checklist for each data source:
- The data can be exported without a vendor support ticket (CSV, API or direct database access)
- Records carry a reliable timestamp and a stable unique identifier
- Free-text fields are in a consistent language mix you can handle (English, Mandarin, Malay, Tamil, Singlish abbreviations)
- Fewer than one in ten records is missing a field the use case depends on
- Duplicates can be detected by a rule you can state in one sentence
- You know which fields contain personal data (NRIC/FIN, contact details, salary, medical or biometric data)
- Someone can confirm whether historic outcomes were recorded (did the quote convert, was the invoice disputed, did the delivery arrive late)
- You have retention and deletion rules, or you know that you do not
That last pair matters more than most SMEs expect. A model that predicts an outcome needs historical outcomes to learn from; if your system records quotes sent but not quotes won, prediction is off the table until you start capturing it. Document-handling and drafting use cases, by contrast, need far less historic data and are usually the better first move.
Screening use cases: value against feasibility
Once the six dimensions are scored, generate a long list of candidate use cases by walking the floor rather than brainstorming in a room. Ask each team the same two questions: what do you do repeatedly that feels mechanical, and where do you wait for someone else? Then score each candidate on the six criteria below, 1 to 5, using the anchors given. Maximum score is 30.
| Criterion | Score 1 | Score 3 | Score 5 |
|---|---|---|---|
| Volume | A few times a month | Weekly | Daily or hourly |
| Time per instance | Under 5 minutes | 5–30 minutes | Over 30 minutes |
| Data availability | Paper or scanned only | Digital but locked in a system | Exportable today |
| Consequence of an error | Safety, regulatory or contractual harm that cannot be caught | Error surfaces downstream, days later | Error is caught immediately by the reviewer |
| Process consistency | Every case is bespoke | Mostly consistent | Templated and rule-bound |
| Owner availability | No owner | Owner with limited time | Owner with weekly time allocated |
Anything scoring 24 or above belongs on the shortlist. Anything below 15 should be parked with a note explaining what would need to change — often a system upgrade or a process rewrite that has value on its own. Scores between 15 and 23 are candidates for the second round, after the first pilot has reported.
Be deliberate about the first use case. The best first project is internal, high-volume, low-risk, and reviewed by a human before anything leaves the company. Customer-facing chat, pricing decisions and anything touching employment decisions are second-round projects, because they carry governance obligations you will not be ready to meet in month one.
Worked example: a 40-person logistics firm
Consider a 40-person freight forwarding and warehousing firm in Singapore with a 12-person operations team, three customer service staff, and a two-person finance function. The managing director wants “AI for quoting”. The assessment runs over two weeks and produces the following picture.
Dimension scores: business case clarity 2, data readiness 1, process stability 2, systems and integration 2, people and ownership 3, governance and risk 1. That is 11 out of 24, an average of 1.83.
What the data test revealed: quotations are produced in Excel from a rate card that is updated monthly and emailed around. Won and lost quotes are not recorded anywhere; the only trace is the operations manager’s memory and the accounting system, which shows invoices but not the quotes that preceded them. Customs documentation arrives as PDF attachments and is retyped into the forwarding system. The warehouse management system can export CSV but has no API.
What this rules out: an AI quoting engine that learns from win/loss history. There is no win/loss history. Building it would require six months of disciplined capture first.
What this rules in: document extraction from commercial invoices, packing lists and delivery orders, which arrive as PDFs and images in predictable formats from a stable set of counterparties and are retyped by staff. Scored on the screening criteria: volume 5 (daily), time per instance 3 (8–15 minutes), data availability 5 (files export cleanly), consequence of an error 5 (an operations executive checks every field before submission), process consistency 5 (fixed document types, fixed target fields), owner availability 4 (an operations executive with half a day a week). Total 27.
Why a pilot is allowed despite an average of 1.83: the two weak dimensions are addressable and do not both touch this use case. Data readiness scores 1 because of the missing quote outcomes — irrelevant to document extraction, where the source files export today. Governance at 1 is a blocker and is fixed first: before the pilot starts, the firm writes the tool inventory, names the approver, and confirms with its provider whether inputs are used for training. Every output is human-reviewed, so nothing runs unattended.
The 90-day plan that follows: pilot document extraction on the three highest-volume document types with one operations executive as owner; measure handling time per document against a two-week manual baseline taken before the pilot starts; and in parallel add two mandatory fields to the quoting spreadsheet — outcome and reason — so that a quoting use case becomes possible next year. Governance work runs alongside: list the personal data appearing in shipping documents (names, contact numbers, occasionally passport or FIN numbers on customs paperwork), decide whether that data may be sent to an external model provider, and write down who approves an output before it is filed.
That is what a readiness assessment is for. It converted a vague ambition into one funded project, one data-capture fix, and one governance task, and it prevented six months of work on a model that had nothing to learn from.
Singapore-specific checks to build into the assessment
Singapore SMEs have a clearer regulatory path than firms in many markets, because the guidance is published and readable rather than buried in enforcement actions. Build these checks into the governance dimension rather than treating them as a separate legal exercise.
Personal data
The Personal Data Protection Act applies to AI systems exactly as it applies to any other processing. The PDPC’s Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems set out how consent, the business improvement exception and the research exception apply when organisations use personal data to train, test and deploy such systems. For an SME, the practical questions are: what personal data enters the system, on what legal basis, what is told to individuals, and what happens to that data after processing.
If you are sending data to a third-party model provider, treat that provider as a data intermediary and check the contract for training-on-your-data clauses, data residency and deletion commitments. Many enterprise tiers disable training on customer data by default while consumer tiers do not — verify which tier your staff are actually using, because shadow adoption on free accounts is common and it is the single most likely source of an inadvertent disclosure.
Governance frameworks
The Model AI Governance Framework published by PDPC and IMDA gives a structure for internal governance, human oversight, operations management and stakeholder communication. The companion Model AI Governance Framework for Generative AI from the AI Verify Foundation and IMDA extends this to generative systems across dimensions including accountability, data, incident reporting and content provenance. You do not need to implement either in full as a 40-person firm. Take the internal governance and human oversight sections, write a two-page policy, and revisit it when your deployment moves from internal to customer-facing.
For testing, the AI Verify Foundation’s Project Moonshot offers open-source tooling for evaluating and red-teaming large language model applications. Even if your team does not run it directly, knowing that structured testing tools exist changes the conversation you have with a vendor who claims their system “has been tested”.
Security
The Cyber Security Agency of Singapore’s Guidelines on Securing AI Systems cover the AI lifecycle from planning through to end-of-life, including supply chain and incident response considerations. The SME-relevant items are access control on the data you are feeding the system, logging of prompts and outputs where personal data is involved, and a plan for what happens if a vendor is breached.
Sector overlays
Financial institutions should map their assessment to the MAS Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the use of AI and data analytics, which carry specific expectations around justifiability, accuracy and internal accountability. Healthcare, legal and education providers have their own sector expectations; check with your regulator before a customer-facing deployment rather than after.
Governance checklist
- Written list of every AI tool in use, including free accounts staff signed up for themselves
- For each tool: what data goes in, where it is processed, whether it trains on your inputs
- Named human approver for every output that reaches a customer, a regulator or an employment decision
- Acceptable use policy covering confidential client data, personal data and code
- Logging sufficient to reconstruct what the system was asked and what it answered
- Vendor contract reviewed for data residency, deletion and breach notification
- Incident route: who is told, within what time, if an output causes harm or data is exposed
- Review date set — quarterly for the first year
Funding, skills and the commercial layer
Assess your access to support alongside your technical readiness, because it changes what you can afford to attempt. Enterprise Singapore’s Enterprise Development Grant supports projects in innovation and productivity, including digital and technology adoption, subject to eligibility and assessment. The Productivity Solutions Grant supports adoption of pre-approved IT solutions and equipment, which suits SMEs buying rather than building. On the skills side, SkillsFuture Singapore and the SkillsFuture Enterprise Credit support enterprise-level training and transformation.
Four things to verify on those pages before you build a business case on them, because parameters change:
- Whether your entity meets the local shareholding and registration conditions
- Whether the specific solution you want appears on the pre-approved list, if you are going the PSG route
- Whether the application must be approved before you sign the vendor contract or pay a deposit
- What evidence of outcomes is required at claim stage, and who inside your firm will produce it
Two practical points. First, grant timelines rarely match project timelines; assume your first pilot is self-funded and treat support as a way to scale what worked. Second, a grant application forces you to articulate baseline metrics and expected outcomes, which is useful discipline even if you never submit it.
Build, buy or configure
| Option | When it fits | What it demands of you |
|---|---|---|
| Buy a vertical SaaS product | A well-defined, common problem with an established vendor in your sector | Vendor due diligence, data export rights, change management |
| Configure a horizontal platform | Document handling, drafting, internal search across mixed sources | Someone internal who can own configuration and prompts |
| Build on a model API | Workflow is specific to you and tied to your systems | Development capability, evaluation discipline, ongoing maintenance |
| Do nothing yet | Data readiness below 2 on the rubric for the use case in question | Honest communication that the fix is process and data, not software |
Most SMEs under 100 staff should start in the first two rows. The marginal advantage from a bespoke build is small when the underlying models are available to everyone; the advantage comes from your data and your workflow, which favours configuration over construction.
Seven questions to put to any vendor on the shortlist
- On what data was this evaluated, and can we see the accuracy figures for documents or cases like ours?
- What happens to our inputs — stored where, for how long, used for training or not, and which contract clause says so?
- Can we run a paid pilot on our own files, with a defined exit, before signing an annual term?
- If we leave, what do we get back and in what format?
- Who configures it, and what does it cost when our process changes in six months?
- How does a user correct a wrong output, and does the system learn from that correction?
- What is your incident notification commitment and your support response time in Singapore hours?
A vendor who cannot answer the first two in writing should not reach a proof of concept.
Setting the baseline before you start
The most common omission is failing to measure the current state before deployment, which makes any later claim of improvement unprovable. For two weeks before the pilot begins, capture:
- Volume: how many instances of the task per week
- Handling time: minutes per instance, sampled across at least three staff
- Rework rate: how often the output is corrected or returned
- Cycle time: elapsed time from trigger to completion, including waiting
- Cost: fully loaded hourly cost of the staff involved, multiplied by handling time
Then define the success threshold before you see any results. A reasonable first-pilot target is a material reduction in handling time with no increase in rework rate. If rework rises, the tool is shifting work rather than removing it, and the honest response is to stop.
The two-week assessment schedule
| Days | Activity | Output |
|---|---|---|
| 1–2 | Interview function heads; walk the floor; list candidate tasks | Long list of 15–30 candidate use cases |
| 3–4 | Data extraction test on top five candidates | Evidence of what can and cannot be exported |
| 5 | Score the six dimensions with evidence | Scored baseline with named gaps |
| 6–7 | Screen use cases on value and feasibility | Shortlist of two or three |
| 8 | Governance and personal data review | Completed governance checklist with gaps |
| 9 | Vendor and build-versus-buy review for the shortlist | Two quotes or configuration estimates, seven questions answered |
| 10 | Baseline measurement design; owner and time commitment confirmed | 90-day plan with named owner and metric |
Keep the assessment to two weeks deliberately. Longer reviews drift into strategy documents, lose the attention of the operators whose cooperation you need, and rarely produce better decisions.
Failure modes, and the test that catches each one
| Failure mode | The test | The fix |
|---|---|---|
| No named owner with real time | Ask the owner to show the recurring block in their calendar | Four protected hours a week, or park the project |
| Scored by survey, not evidence | Ask for the export file behind any score above 1 | Re-score after the one-day extraction test |
| Most exciting use case chosen first | Check whether the output reaches a customer in month one | Move it to round two; pick an internal task |
| Shadow adoption ignored | Check expense claims and browser sign-ins for consumer AI accounts | Sanction a reviewed tool rather than issuing a ban nobody follows |
| Adoption measured instead of outcomes | Ask what the handling time was before | Reinstate the two-week manual baseline |
| Assessment treated as one-off | Diary the re-score before closing the report | Re-score the six dimensions every six months |
The last row is the one most SMEs skip. Data readiness in particular improves quickly once a team starts capturing outcomes deliberately, and use cases that were impossible in January often become viable by July.
What good looks like at the end
A finished AI readiness assessment fits on six pages: the six dimension scores with evidence, the long list and how it was screened, the shortlist with its screening totals and estimated effort and cost, the governance checklist with open items and owners, the baseline metrics to be captured before the pilot, and a 90-day plan naming who does what by when. Anyone in the company should be able to read it and explain what happens next. If your assessment cannot do that, it is a discussion document, and the work has not started.
Run it in two weeks, score honestly, fix governance first, and let the evidence pick your first project rather than the other way round.
Related articles
- The AI readiness checklist for Singapore enterprises
- Building an AI governance framework for Singapore enterprises
- Measuring AI ROI in operations: what to track and when
Want help applying this? See how Fetch helps teams put AI to work.