Start with what is already running
Before any readiness checklist is useful, it needs an honest starting point. Most businesses evaluating AI readiness already have AI in daily use: staff pasting client information into ChatGPT to draft an email, a salesperson using Copilot to summarise a call, a finance assistant using an AI tool to reconcile a spreadsheet. None of it went through procurement. None of it is on a register anywhere.
This is shadow AI, and it is the actual starting point for readiness, not the vendor pitch you are about to sit through. Before working through the ten items below, spend an hour asking department heads a single question: what AI tools is your team already using, and what are they putting into them? The answer is usually larger and more informal than anyone expects, and it changes what the rest of this checklist needs to prioritise.
The 10 things to sort before you deploy
Turn the shadow AI question above into a simple list: tool, department, what data goes into it, who approved it (if anyone did). This becomes the baseline for every other item on this list. You cannot govern, secure, or write a policy for something you have not written down.
Singapore's Personal Data Protection Commission finalised advisory guidelines on generative AI on 20 July 2026, and the core message is blunt: liability for personal data cannot be contracted away by using a third-party AI vendor. For every AI workflow on your inventory, identify where personal data enters it and document the PDPA legal basis for that use. This is covered in more depth further down, under what the PDPC actually wants.
Ask directly: does the vendor train its models on your data. Where is that data processed and stored. What happens to your data if you cancel the contract. Standard vendor sales material rarely answers these clearly, and the answers matter more than any feature comparison, because your organisation carries the liability regardless of what the vendor promises.
Whether you are fine-tuning a model or feeding a chatbot your internal documents, the output is only as reliable as the input. Before deployment, confirm the data is accurate, reasonably current, and that you have the right to use it for this purpose. Poor data quality is the most common reason a pilot looks promising and a production rollout does not.
Not every use case carries the same risk. An AI tool drafting a first pass of a marketing email carries very different consequences to one influencing a hiring decision or a credit assessment. Rate each use case by what happens if the output is wrong, and put the highest scrutiny where the consequences of a confident, wrong answer are most serious.
The NIST AI Risk Management Framework's Govern function is explicit on this point: accountability has to sit somewhere specific, not be assumed to be everyone's job. For a business without a dedicated AI or risk team, this does not need to be a new hire. It needs to be a named person, usually in IT, operations, or compliance, who owns the inventory, the policy, and the escalation path described below.
It does not need to be a legal document. It needs to say, in plain language, which tools staff are allowed to use, what categories of data must never go into them, and who to ask when a new tool or use case comes up. A one-page policy that people actually read outperforms a comprehensive one that sits unread in a shared drive.
This is a starting point, not the finished article. A fuller AI policy, covering approval workflows for new tools, a one-page template, and how it interacts with your existing data handling rules, is worth building once the basics here are in place. That is its own piece of work: see How to Write an AI Policy for Your Company.
Most AI-related data incidents are not malicious. They are an employee pasting a client contract into a public chatbot to get a quick summary, without realising where that text then lives. A short, practical briefing on what counts as personal or confidential data, and a reminder that free public AI tools are not confidential by default, closes most of this gap on its own.
The Singapore Institute of Directors published a dedicated guide for boards on AI oversight in July 2026, developed with OpenAI and Microsoft and backed by Singapore's IMDA. Its core position is that AI governance has moved from a technology committee discussion to a director-level responsibility. If your board has not yet discussed what AI is running in the business, who is accountable for it, and what the collective board expertise on AI actually is, that gap sits above the operational checklist, not below it. More on this in the frameworks section below.
Decide, before you need it, what happens when an AI tool gets something wrong: who is told, how a customer or employee can contest an AI-influenced decision, and how the incident gets recorded so the same failure is not repeated. A tool without an escalation path is not ready for production use, regardless of how well it performed in testing.
Two frameworks worth knowing, not memorising
You do not need to read a 116-page board guide or the full NIST framework to be AI-ready. You need to know what each one is for, so you can borrow the parts that matter and skip the parts written for organisations far larger than yours.
The SID AI Guide for Boards
Launched in July 2026 by the Singapore Institute of Directors, developed jointly with OpenAI and Microsoft and supported by Singapore's Infocomm Media Development Authority, this is a practical companion for directors rather than a technical manual. Its central argument is that boards need to assess AI in the same way they assess any material business risk: with a defined framework, clear questions, and named accountability, not delegated wholesale to the technology team. For an ASEAN business without a large board or dedicated risk committee, the useful takeaway is narrower than the full guide: does the board (or, for a smaller company, the owner and senior leadership) know what AI tools the business runs, what the exposure is if one fails, and whether the current leadership has the AI literacy to ask the right questions. That is items 06 and 09 above, formalised at governance level.
The NIST AI Risk Management Framework
Published by the United States' National Institute of Standards and Technology, the AI RMF is built around four functions: Govern, Map, Measure, and Manage. Govern is the one that matters most for a business at the readiness stage, since it covers exactly the ground this checklist does: documented accountability, named risk owners, staff training, and a defined process for handling third-party AI vendors. Larger organisations, or those selling into regulated sectors like finance or healthcare, will eventually need to engage with Map, Measure, and Manage as well, which get into ongoing risk scoring and ongoing system monitoring. For most ASEAN SMEs at the deployment-readiness stage, treating Govern as the checklist and the rest as a future-state reference is a reasonable, defensible starting position.
Neither of these is a one-off exercise. Both are meant to sit inside a regular review cadence, not get read once and filed away. For a smaller organisation, once a year, timed to a board or leadership meeting, is a reasonable minimum. As the organisation grows, or as AI use spreads into more of the business, that interval typically needs to tighten, to every six months, or whatever is formally agreed with the accountable owner named in item 06. The right cadence is not fixed: it should be revisited as the organisation, and its AI footprint, changes.
What the PDPC actually wants
Singapore's Personal Data Protection Commission finalised its advisory guidelines on generative AI and personal data on 20 July 2026, following a public consultation earlier that summer. The guidelines sit inside the existing PDPA rather than creating a separate AI law, and they resolve to four practical obligations.
| PDPC obligation | What it means in practice |
|---|---|
| Supply chain accountability | You remain liable for personal data handling even when a third-party vendor runs the AI model. This cannot be contracted away. |
| Legal basis | A documented PDPA legal basis, such as consent or a permitted exception, is required for training, fine-tuning, or using a model with personal data. |
| Risk mitigation | Controls must address AI-specific risks, including hallucinated outputs and bias embedded in training data. |
| Individual transparency | Privacy notices must disclose AI-assisted processing of personal data clearly, not bury it in general terms. |
A 30-day plan to actually get started
A ten-item checklist and two governance frameworks can feel like more than a growing business has time for. It is not, if it is sequenced. This is a realistic order to work through it in a month, not a year.
| Week | Focus | What to actually do |
|---|---|---|
| Week 1 | Find out what is real | Ask every department head what AI tools their team already uses. Build the inventory (item 01). This alone usually surfaces the biggest surprises. |
| Week 2 | Map the exposure | Identify where personal data enters each tool on the inventory and note the PDPA legal basis (item 02). Pull vendor contracts for the tools in wider use and check the data handling terms (item 03). |
| Week 3 | Put the basics in writing | Name the accountable owner (item 06). Draft the one-page policy (item 07). Run a 30-minute staff briefing on what not to paste into a public AI tool (item 08). |
| Week 4 | Take it upstairs | Put a single AI item on the next board or leadership meeting agenda (item 09): what is running, who owns it, what the escalation path is if something goes wrong (item 10). |
None of this requires a large budget or a new hire in most ASEAN businesses under a few hundred people. It requires the inventory to happen first, because every other item on this list is easier once you know, precisely, what you are actually governing. If the inventory alone turns up more than your team has the bandwidth to work through safely, that is the point at which ScaleASEAN's fractional CTO and technology advisory work is worth a conversation, particularly ahead of a board discussion on AI oversight.
Sources
- AI Guide for Boards in Singapore · Singapore Institute of Directors, July 2026
- AI Risk Management Framework · NIST, official framework overview
- AI RMF Playbook: Govern · NIST AI Resource Center
- PDPC's Final Advisory Guidelines on Generative AI · Alder, summarising PDPC guidance of 20 July 2026
- Singapore's PDPC issues new advisory guidance on use of personal data in generative AI · Stephenson Harwood
- SID's new guide helps boards assess the value and risks of AI · Yahoo Finance Singapore