An AI readiness checklist for Queensland SMEs

Before buying AI software, check whether the business has the data, permissions and process clarity to make it work.

You don’t need a data science department to be ready for AI. Plenty of Queensland SMEs use it well with a small team and one focused problem.

The question worth asking is whether the business has enough process clarity, data access and sensible governance to make a first project actually useful.

A readiness check should be practical and help you decide what to do next. It shouldn’t turn into a thick report that sits in a folder. And it’s worth doing before the buying conversation, not after, because the software market is now optimised to skip it. Every product your team already uses is growing AI features, every vendor email has the word in the subject line, and the path of least resistance is to buy something and call that a strategy. Readiness is the difference between AI spend that compounds and AI spend that becomes a licence someone cancels next year. The checklist below takes an honest afternoon, and each step tells you something you’d otherwise learn expensively.

1. Name the business problem

Start with the pain, not the technology. Slow admin, the same questions over and over, document search, manual reporting, inbox triage, quote preparation, compliance checks, duplicate data entry. Any of those make a decent candidate. If you can’t describe the problem without saying the word AI, the scope is too vague.

The first project needs a clear owner and a baseline you can measure. Hours spent, turnaround time, error rate, backlog size. Those beat a general feeling that things could be better.

A quick test for whether you’ve actually named a problem: could you brief it to a contractor without mentioning any technology at all? “Our quotes take three days because someone has to find the last similar job and rebuild the pricing by hand” is a problem, and it happens to be one AI can help with. “We want to explore AI for quoting” is a mood. The first version also hands you the baseline for free, three days, and the owner, whoever owns quoting. If nobody in the business feels the pain personally, that’s a signal too: projects without a person who wants them die quietly, whatever the technology.

2. Check the data

A lot of AI projects fail because the data is scattered, stale or locked away. So ask the dull questions early. Where does the source material live, who owns it, how current is it, and do staff actually trust it? If the same document is duplicated across five folders, decide which copy wins. If records sit in a vendor platform, check there is an API or an export.

This step is boring. It’s also where the project stops being theatre.

Two findings come out of this check so often they’re worth pre-warning. First, the data exists but is dirtier than anyone admits: the customer list has fifteen years of duplicates, the job records changed format twice, half the site photos live in text message threads. That’s rarely fatal, but it changes the project plan, because cleanup becomes phase one and honest vendors will say so. Second, the data is hostage: it lives in a platform whose export produces a useless PDF, or whose API costs an enterprise tier you don’t have. Better to discover that now than after signing with a tool that assumed clean access. And note the scope discipline: you need adequate data for the one project you named in step one, not a clean data estate across the whole business. Don’t let this step balloon into a six-month cleansing program.

3. Sort sensitivity

Not all information carries the same risk. Pull apart public material, internal business information, commercially sensitive data, and records that come with legal or contractual controls. That sorting is what tells you whether cloud AI is fine, whether a private tenant covers it, or whether you need to think about local infrastructure.

For a first project, a simple data classification table usually does the job. Four rows, one afternoon: website-grade material, internal working documents, the commercially sensitive layer (pricing, customer lists, strategy), and the controlled layer (personal information under the Privacy Act, health records, anything a client contract restricts). Then match tools to rows, and notice how much friction disappears from every later decision: “can we use this tool for that job?” becomes a lookup instead of a meeting. Most SMEs discover their first project sits comfortably in the middle rows, where a paid business tier of a mainstream tool, with training switched off and retention understood, is honestly fine. The deployment questions get more serious only when the bottom row is involved, and now you know whether it is.

4. Set rules for staff use

Queensland SMEs don’t need a 40-page AI policy to start. They do need plain rules. Which tools are approved, what data can go into them, who reviews the output, and which uses are off limits. People should also know where to go for approval when a new use case turns up.

Governance is meant to make safe adoption easier. Write rules nobody can follow and staff will just work around them.

Assume, while you’re writing the rules, that AI use already exists in the business. It nearly always does: personal accounts, browser tabs, a tool someone connected to the company drive months ago. So the rollout matters as much as the rules. Send them with an amnesty attached, “reply with anything you’re already using, no trouble either way”, and the replies become your real audit. The one-page version of this policy is enough to start, and we’ve written out exactly what goes on the page: what can go where, a name against the decisions, an approved list, and a human sign-off wherever the output matters.

5. Pick the smallest useful build

The first project should prove value in weeks, not years. A private document assistant over one defined folder, a form extraction workflow, a reporting automation. Any of those teach the business a lot without locking you into a big platform.

The word “smallest” is load-bearing, and it’s the step where ambition creeps back in. The proposal that started as “answer questions over our procedures” grows a customer-facing mode and an integration wishlist by the third meeting, and suddenly the six-week project is a six-month one with six ways to fail. Hold the line: one workflow, one team, one measurable number, and a review four weeks after launch where you compare against the baseline from step one. If it worked, the second project will be obvious, and it’ll be picked by people who now trust the process. If it didn’t, you’ve learned on a small cheque, which is the entire point of starting small.

One more filter for choosing among small candidates: prefer the project whose output a human already checks. If someone currently reviews every quote before it goes out, then AI-drafted quotes slot into an existing safety net, and the worst case is a bad draft that gets caught the way bad drafts always were. Projects that need a brand-new review process bolted on are carrying two changes at once, and the review half is usually the one that fails.

Our AI readiness assessment works the same way. Find the next practical step, then move carefully.

The readiness signal

A business is ready when it can name a problem, get at the right data, put a name against it, set boundaries and measure the result. That’s enough to start. The heavier governance can come later, once the work shows it needs it.

Notice what’s not on the list: a big budget, a technical team, perfect data, or a strategy document. Readiness at SME scale is mostly clarity plus ownership, and both are free. If you’ve run through the five checks and want a second pair of eyes on where you stand, the assessment turns the answers into a ranked starting point, and if one of the checks came back ugly, scattered data, a hostage platform, no measurable baseline, that’s worth a conversation too, because fixing it is usually the highest-value project on the list.

All insights

Turn the thinking into a plan.

Send the process, risk or idea. We will help you work out what is worth doing first.