Business Workflows
What Malaysian SMEs Should and Should Not Automate With AI
Start with repeated, permitted and reversible work whose output a person can verify; retain human authority for high-impact or hard-to-reverse actions.
Ask which process step is slow or repetitive, what could go wrong and who remains accountable before asking which AI tool to buy. AI can draft, classify and summarise; it can also multiply inaccuracies or disclose information to an unsuitable service.
1. Separate assistance from autonomous action
| Mode | System role | Human role |
|---|---|---|
| Template | Consistent starting format | Completes and sends |
| AI-assisted draft | Produces a suggestion | Reviews, edits and decides |
| Controlled automation | Performs defined steps | Reviews exceptions and monitors |
| Autonomous action | Decides and executes | May see the result only afterwards |
2. Apply five gates before automating
- Clear and repeated: the trigger, inputs and useful output are agreed.
- Permitted and necessary data: unnecessary fields are removed and the vendor and processing path are assessed.
- Verifiable output: a reviewer sees the source, can edit or reject and has authority to disagree.
- Reversible and contained action: permissions are smaller than the operator's full access.
- Named owner and stop path: monitoring, exceptions, disable steps and a review date exist.
3. Start with drafts, classifications and internal tasks
| Candidate | Safer starting mode | Human boundary |
|---|---|---|
| Turn approved notes into a first draft | AI-assisted draft | Author verifies every fact |
| Summarise a non-sensitive meeting | AI-assisted draft | Attendee checks decisions and owners |
| Classify enquiries by stated service | Controlled suggestion | Staff confirms unusual cases |
| Extract standard supplier fields | Controlled draft | Staff compares critical fields with source |
| Suggest FAQ updates | AI-assisted analysis | Owner approves facts and publication |
| Create test cases from requirements | AI-assisted draft | QA owner adds risk and domain cases |
4. Keep high-impact actions human-approved
- Binding quotes, contracts and legal commitments.
- Money transfers, material refunds and bank-detail changes.
- Legal, medical, financial or safety advice.
- Hiring, discipline, termination and customer eligibility decisions.
- Public factual claims, prices and crisis statements.
- Record deletion, account closure and serious complaint responses.
- Sensitive personal-data processing in a general AI tool.
5. Score consequence and reversibility
| Consequence | Easy to reverse | Difficult to reverse |
|---|---|---|
| Low | Pilot with sampling and monitoring | Approve before execution |
| Moderate | Review exceptions with recovery | Approve every action; consider rules |
| High | Constrained support with qualified ownership | Usually keep the final action manual |
6. Prefer rules when the decision is a rule
A due-date reminder does not need AI to decide whether an approved date has passed. Use deterministic checks for amounts, required fields, permissions and prohibited actions. Reserve AI for language or pattern interpretation that genuinely benefits from it.
7. Use draft, review, approve, execute and log
- Draft: AI proposes content, classification or fields.
- Review: a person sees the source and proposal.
- Approve: an authorised role edits, accepts, rejects or escalates.
- Execute: a limited system performs only the approved action.
- Log: the workflow records the action, approver and exception appropriate to the risk.
8. Apply the boundary to real SME work
- Cafe: suggest booking, menu, event or other from an enquiry; staff checks availability and replies. Never promise a table without authoritative availability.
- Consultancy: draft proposal structure from permitted notes; the consultant verifies scope, fee, claims and deadline before sending.
- Online order: use required-field rules first and route ambiguous delivery notes to staff. Do not refund or reject from AI interpretation alone.
9. Run one controlled pilot
| Record | Decision to write down |
|---|---|
| Boundary | Exact input and output in one sentence |
| Data | Allowed sources and prohibited fields |
| Approval | Who reviews which output before which action |
| Evidence | Baseline, quality sample and correction effort |
| Exception | What routes to a person |
| Stop condition | Disclosure, wrong external action or unacceptable correction burden |
| Review date | Continue, change or stop |
Measure handling time including review, accepted versus edited output, exceptions, correction burden, unwanted actions and operating cost. Drafts generated are not value delivered. A successful pilot supports only the tested boundary, not every adjacent task.
