Methodology · version 1.1.0
Transparent rules, conservative safeguards.
The diagnostic turns one self-reported answer set into a reproducible directional profile. It does not use generative AI, secret scoring, sector benchmarking or commercial qualification.
What this method can and cannot say
The result is a practical, self-reported profile of current evidence. It is designed to help a decision-maker or process owner choose a safer next action. It is not a formal audit, legal assessment, certification, procurement approval or representative sector benchmark.
Profile answers help match useful next moves without changing the numerical readiness score. The optional workflow label only labels the report; it does not influence scoring or pilot matching. No consequential automated decision is recommended.
24 current-evidence checks
A. Strategy and leadership · 15%
- A1 — Have you written down one important business result you want AI to improve?
- A2 — Is one named person in charge of your AI work?
- A3 — Have you set aside time or money for one small AI test?
- A4 — Have you written down what success looks like for one AI test?
B. Processes and opportunities · 20%
- B1 — Have you listed the repetitive jobs that take too much time?
- B2 — Have you written down the steps for one of those jobs?
- B3 — Have you measured how much time, money or rework that job costs today?
- B4 — Have you picked one small, low-risk job to test first?
C. Data readiness · 20%
- C1 — Is the information for that job already digital and easy to find?
- C2 — Have you checked a small sample to make sure it is correct and up to date?
- C3 — Is one person responsible for each important source of information?
- C4 — Have you marked which information is safe to share and which must stay private?
D. Technology and integration · 15%
- D1 — Can you get the information you need from your current tools with permission?
- D2 — Does everyone have their own login and only the access they need?
- D3 — Do you have a safe way to test without affecting daily work?
- D4 — Is someone already assigned to set up and fix the technology?
E. People and adoption · 15%
- E1 — Have staff been told how to use public AI tools safely?
- E2 — Are the people who do the job helping choose or shape the AI tool?
- E3 — Has someone been given time and resources to train and support staff?
- E4 — Is there one clear place to report AI mistakes or concerns?
F. Governance and risk · 15%
- F1 — Do you have simple, approved rules for using AI at work?
- F2 — Is a named person required to check and approve AI work before an important decision is made?
- F3 — Do you check how the company behind a new AI tool will protect your information?
- F4 — Do you have a written plan to watch the test and stop it if needed?
Scoring and stages
Each check scores 0–4. “Not sure” contributes a disclosed conservative value of 1 and also creates a specific verification task. Each dimension is converted to a whole-number percentage. The weighted overall result is rounded to a whole number.
| Stage | Score | Action |
|---|---|---|
| Discover | 0–24 | Understand the work |
| Prepare | 25–44 | Put foundations in place |
| Pilot | 45–64 | Run a controlled test |
| Expand | 65–79 | Extend proven value |
| Govern at scale | 80–100 | Maintain controls at scale |
Assessment clarity is separate
Unknown information is not hidden inside the score. It changes how confidently the stage can be interpreted and produces a verification list.
- High: 0–2 unknown answers.
- Moderate: 3–5 unknown answers; the effective stage cannot exceed Expand.
- Low: 6 or more unknown answers; the result is labelled provisional and cannot exceed Pilot.
Hard safeguards run after scoring
A high average cannot cancel a serious weakness. These rules cap the effective stage or remove unsuitable pilots after the weighted score is calculated.
- Governance below 35, or weak or unknown human review, caps the effective stage at Prepare and permits only low-risk assistive recommendations.
- Process below 40 makes workflow discovery the primary next move.
- Data below 35 excludes data-intensive and predictive pilots.
- Technology below 30 permits only standalone or sandboxed pilots.
- Weak or unknown supplier review adds vendor assessment as a prerequisite.
- Consequential automated decisions are never recommended in version 1.
Deterministic pilot matching
The catalogue is ranked by operational priority, sector relevance, prerequisites, solution mode, risk, containment and measurable value. Exclusions and safeguards run before ranking. A stable catalogue order breaks ties, so identical valid answers always produce identical results.
The primary recommendation may be process clarification or conventional rules automation. AI is not treated as the right first move when the evidence points elsewhere. Selecting one of the three returned options updates only the deterministic 30-day plan; it never changes the readiness score.
Reference frameworks
The methodology was cross-checked against responsible-AI themes in Malaysia's national governance guidance and the NIST AI Risk Management Framework. This does not imply endorsement, compliance, certification or affiliation.
- Malaysia National Guidelines on AI Governance and Ethics
- NIST AI Risk Management Framework
- Malaysia personal-data protection principles
Any future wording, threshold, safeguard, pilot-catalogue or report-copy change will receive a new methodology version rather than silently changing an existing result.