Methodology · version 1.1.0

Transparent rules, conservative safeguards.

The diagnostic turns one self-reported answer set into a reproducible directional profile. It does not use generative AI, secret scoring, sector benchmarking or commercial qualification.

What this method can and cannot say

The result is a practical, self-reported profile of current evidence. It is designed to help a decision-maker or process owner choose a safer next action. It is not a formal audit, legal assessment, certification, procurement approval or representative sector benchmark.

Profile answers help match useful next moves without changing the numerical readiness score. The optional workflow label only labels the report; it does not influence scoring or pilot matching. No consequential automated decision is recommended.

24 current-evidence checks

A. Strategy and leadership · 15%

  1. A1Have you written down one important business result you want AI to improve?
  2. A2Is one named person in charge of your AI work?
  3. A3Have you set aside time or money for one small AI test?
  4. A4Have you written down what success looks like for one AI test?

B. Processes and opportunities · 20%

  1. B1Have you listed the repetitive jobs that take too much time?
  2. B2Have you written down the steps for one of those jobs?
  3. B3Have you measured how much time, money or rework that job costs today?
  4. B4Have you picked one small, low-risk job to test first?

C. Data readiness · 20%

  1. C1Is the information for that job already digital and easy to find?
  2. C2Have you checked a small sample to make sure it is correct and up to date?
  3. C3Is one person responsible for each important source of information?
  4. C4Have you marked which information is safe to share and which must stay private?

D. Technology and integration · 15%

  1. D1Can you get the information you need from your current tools with permission?
  2. D2Does everyone have their own login and only the access they need?
  3. D3Do you have a safe way to test without affecting daily work?
  4. D4Is someone already assigned to set up and fix the technology?

E. People and adoption · 15%

  1. E1Have staff been told how to use public AI tools safely?
  2. E2Are the people who do the job helping choose or shape the AI tool?
  3. E3Has someone been given time and resources to train and support staff?
  4. E4Is there one clear place to report AI mistakes or concerns?

F. Governance and risk · 15%

  1. F1Do you have simple, approved rules for using AI at work?
  2. F2Is a named person required to check and approve AI work before an important decision is made?
  3. F3Do you check how the company behind a new AI tool will protect your information?
  4. F4Do you have a written plan to watch the test and stop it if needed?

Scoring and stages

Each check scores 0–4. “Not sure” contributes a disclosed conservative value of 1 and also creates a specific verification task. Each dimension is converted to a whole-number percentage. The weighted overall result is rounded to a whole number.

StageScoreAction
Discover024Understand the work
Prepare2544Put foundations in place
Pilot4564Run a controlled test
Expand6579Extend proven value
Govern at scale80100Maintain controls at scale

Assessment clarity is separate

Unknown information is not hidden inside the score. It changes how confidently the stage can be interpreted and produces a verification list.

  • High: 0–2 unknown answers.
  • Moderate: 3–5 unknown answers; the effective stage cannot exceed Expand.
  • Low: 6 or more unknown answers; the result is labelled provisional and cannot exceed Pilot.

Hard safeguards run after scoring

A high average cannot cancel a serious weakness. These rules cap the effective stage or remove unsuitable pilots after the weighted score is calculated.

  • Governance below 35, or weak or unknown human review, caps the effective stage at Prepare and permits only low-risk assistive recommendations.
  • Process below 40 makes workflow discovery the primary next move.
  • Data below 35 excludes data-intensive and predictive pilots.
  • Technology below 30 permits only standalone or sandboxed pilots.
  • Weak or unknown supplier review adds vendor assessment as a prerequisite.
  • Consequential automated decisions are never recommended in version 1.

Deterministic pilot matching

The catalogue is ranked by operational priority, sector relevance, prerequisites, solution mode, risk, containment and measurable value. Exclusions and safeguards run before ranking. A stable catalogue order breaks ties, so identical valid answers always produce identical results.

The primary recommendation may be process clarification or conventional rules automation. AI is not treated as the right first move when the evidence points elsewhere. Selecting one of the three returned options updates only the deterministic 30-day plan; it never changes the readiness score.

Reference frameworks

The methodology was cross-checked against responsible-AI themes in Malaysia's national governance guidance and the NIST AI Risk Management Framework. This does not imply endorsement, compliance, certification or affiliation.

Any future wording, threshold, safeguard, pilot-catalogue or report-copy change will receive a new methodology version rather than silently changing an existing result.