AI & Automation · Governance

Your AI Readiness Checklist: 10 Things to Sort Before You Deploy

Most AI readiness advice stops at the IT department. This checklist does not, because the risk does not either. It covers data, vendors, and staff, and it covers the board, using Singapore's own PDPC guidelines, the Singapore Institute of Directors' new AI guide, and the NIST AI Risk Management Framework as the reference points, not opinion.

📅 August 2026 ⏱ 9 min read By Hitan Mehta

Start with what is already running

Before any readiness checklist is useful, it needs an honest starting point. Most businesses evaluating AI readiness already have AI in daily use: staff pasting client information into ChatGPT to draft an email, a salesperson using Copilot to summarise a call, a finance assistant using an AI tool to reconcile a spreadsheet. None of it went through procurement. None of it is on a register anywhere.

This is shadow AI, and it is the actual starting point for readiness, not the vendor pitch you are about to sit through. Before working through the ten items below, spend an hour asking department heads a single question: what AI tools is your team already using, and what are they putting into them? The answer is usually larger and more informal than anyone expects, and it changes what the rest of this checklist needs to prioritise.

The 10 things to sort before you deploy

01
Inventory what is already running

Turn the shadow AI question above into a simple list: tool, department, what data goes into it, who approved it (if anyone did). This becomes the baseline for every other item on this list. You cannot govern, secure, or write a policy for something you have not written down.

02
Map where personal data enters an AI workflow

Singapore's Personal Data Protection Commission finalised advisory guidelines on generative AI on 20 July 2026, and the core message is blunt: liability for personal data cannot be contracted away by using a third-party AI vendor. For every AI workflow on your inventory, identify where personal data enters it and document the PDPA legal basis for that use. This is covered in more depth further down, under what the PDPC actually wants.

03
Read the vendor contract, not just the pitch

Ask directly: does the vendor train its models on your data. Where is that data processed and stored. What happens to your data if you cancel the contract. Standard vendor sales material rarely answers these clearly, and the answers matter more than any feature comparison, because your organisation carries the liability regardless of what the vendor promises.

04
Check the data feeding the model

Whether you are fine-tuning a model or feeding a chatbot your internal documents, the output is only as reliable as the input. Before deployment, confirm the data is accurate, reasonably current, and that you have the right to use it for this purpose. Poor data quality is the most common reason a pilot looks promising and a production rollout does not.

05
Assess hallucination and bias risk for each use case

Not every use case carries the same risk. An AI tool drafting a first pass of a marketing email carries very different consequences to one influencing a hiring decision or a credit assessment. Rate each use case by what happens if the output is wrong, and put the highest scrutiny where the consequences of a confident, wrong answer are most serious.

06
Name one person accountable for AI risk

The NIST AI Risk Management Framework's Govern function is explicit on this point: accountability has to sit somewhere specific, not be assumed to be everyone's job. For a business without a dedicated AI or risk team, this does not need to be a new hire. It needs to be a named person, usually in IT, operations, or compliance, who owns the inventory, the policy, and the escalation path described below.

07
Write the one-page policy before the wider rollout

It does not need to be a legal document. It needs to say, in plain language, which tools staff are allowed to use, what categories of data must never go into them, and who to ask when a new tool or use case comes up. A one-page policy that people actually read outperforms a comprehensive one that sits unread in a shared drive.

This is a starting point, not the finished article. A fuller AI policy, covering approval workflows for new tools, a one-page template, and how it interacts with your existing data handling rules, is worth building once the basics here are in place. That is its own piece of work: see How to Write an AI Policy for Your Company.

08
Train staff on what they can and cannot put into a tool

Most AI-related data incidents are not malicious. They are an employee pasting a client contract into a public chatbot to get a quick summary, without realising where that text then lives. A short, practical briefing on what counts as personal or confidential data, and a reminder that free public AI tools are not confidential by default, closes most of this gap on its own.

09
Put AI oversight on the board agenda

The Singapore Institute of Directors published a dedicated guide for boards on AI oversight in July 2026, developed with OpenAI and Microsoft and backed by Singapore's IMDA. Its core position is that AI governance has moved from a technology committee discussion to a director-level responsibility. If your board has not yet discussed what AI is running in the business, who is accountable for it, and what the collective board expertise on AI actually is, that gap sits above the operational checklist, not below it. More on this in the frameworks section below.

10
Build a recourse and escalation path

Decide, before you need it, what happens when an AI tool gets something wrong: who is told, how a customer or employee can contest an AI-influenced decision, and how the incident gets recorded so the same failure is not repeated. A tool without an escalation path is not ready for production use, regardless of how well it performed in testing.

Two frameworks worth knowing, not memorising

You do not need to read a 116-page board guide or the full NIST framework to be AI-ready. You need to know what each one is for, so you can borrow the parts that matter and skip the parts written for organisations far larger than yours.

The SID AI Guide for Boards

Launched in July 2026 by the Singapore Institute of Directors, developed jointly with OpenAI and Microsoft and supported by Singapore's Infocomm Media Development Authority, this is a practical companion for directors rather than a technical manual. Its central argument is that boards need to assess AI in the same way they assess any material business risk: with a defined framework, clear questions, and named accountability, not delegated wholesale to the technology team. For an ASEAN business without a large board or dedicated risk committee, the useful takeaway is narrower than the full guide: does the board (or, for a smaller company, the owner and senior leadership) know what AI tools the business runs, what the exposure is if one fails, and whether the current leadership has the AI literacy to ask the right questions. That is items 06 and 09 above, formalised at governance level.

The NIST AI Risk Management Framework

Published by the United States' National Institute of Standards and Technology, the AI RMF is built around four functions: Govern, Map, Measure, and Manage. Govern is the one that matters most for a business at the readiness stage, since it covers exactly the ground this checklist does: documented accountability, named risk owners, staff training, and a defined process for handling third-party AI vendors. Larger organisations, or those selling into regulated sectors like finance or healthcare, will eventually need to engage with Map, Measure, and Manage as well, which get into ongoing risk scoring and ongoing system monitoring. For most ASEAN SMEs at the deployment-readiness stage, treating Govern as the checklist and the rest as a future-state reference is a reasonable, defensible starting position.

Neither of these is a one-off exercise. Both are meant to sit inside a regular review cadence, not get read once and filed away. For a smaller organisation, once a year, timed to a board or leadership meeting, is a reasonable minimum. As the organisation grows, or as AI use spreads into more of the business, that interval typically needs to tighten, to every six months, or whatever is formally agreed with the accountable owner named in item 06. The right cadence is not fixed: it should be revisited as the organisation, and its AI footprint, changes.

ℹ️
Neither framework is a legal requirement in Singapore or ASEAN The SID AI Guide for Boards is a voluntary guide published by a professional membership body, not legislation. The NIST AI Risk Management Framework is voluntary even in the United States, where NIST is a federal standards agency with no regulatory authority in Singapore or ASEAN. Adopting either is a matter of good governance, not compliance. What is a binding legal requirement in Singapore is the PDPA itself, specifically the PDPC's generative AI guidelines covered next. The discipline both frameworks describe, named accountability, documented decisions, board-level visibility, is what regulators, insurers, and increasingly customers will expect to see evidence of regardless of which framework, if any, you formally adopt.

What the PDPC actually wants

Singapore's Personal Data Protection Commission finalised its advisory guidelines on generative AI and personal data on 20 July 2026, following a public consultation earlier that summer. The guidelines sit inside the existing PDPA rather than creating a separate AI law, and they resolve to four practical obligations.

PDPC obligationWhat it means in practice
Supply chain accountabilityYou remain liable for personal data handling even when a third-party vendor runs the AI model. This cannot be contracted away.
Legal basisA documented PDPA legal basis, such as consent or a permitted exception, is required for training, fine-tuning, or using a model with personal data.
Risk mitigationControls must address AI-specific risks, including hallucinated outputs and bias embedded in training data.
Individual transparencyPrivacy notices must disclose AI-assisted processing of personal data clearly, not bury it in general terms.
🔑
The line to remember "Liabilities cannot be contracted away" is the PDPC's own framing. Whatever a vendor's terms of service say about their responsibility, your organisation is still the one accountable under the PDPA for how personal data moves through an AI tool it deploys.

A 30-day plan to actually get started

A ten-item checklist and two governance frameworks can feel like more than a growing business has time for. It is not, if it is sequenced. This is a realistic order to work through it in a month, not a year.

WeekFocusWhat to actually do
Week 1Find out what is realAsk every department head what AI tools their team already uses. Build the inventory (item 01). This alone usually surfaces the biggest surprises.
Week 2Map the exposureIdentify where personal data enters each tool on the inventory and note the PDPA legal basis (item 02). Pull vendor contracts for the tools in wider use and check the data handling terms (item 03).
Week 3Put the basics in writingName the accountable owner (item 06). Draft the one-page policy (item 07). Run a 30-minute staff briefing on what not to paste into a public AI tool (item 08).
Week 4Take it upstairsPut a single AI item on the next board or leadership meeting agenda (item 09): what is running, who owns it, what the escalation path is if something goes wrong (item 10).

None of this requires a large budget or a new hire in most ASEAN businesses under a few hundred people. It requires the inventory to happen first, because every other item on this list is easier once you know, precisely, what you are actually governing. If the inventory alone turns up more than your team has the bandwidth to work through safely, that is the point at which ScaleASEAN's fractional CTO and technology advisory work is worth a conversation, particularly ahead of a board discussion on AI oversight.

Sources

Ready to find out what AI is actually running in your business?

30 minutes with someone who has built and governed technology across ASEAN for 15 years. No vendor agenda. No obligation.