1. Describe the present process

Start with an input and an observable result. “Use AI in customer operations” is too broad to assess. “Prepare a draft reply from an approved policy document for a staff member to review” identifies a task, a source and an owner. Record where the request arrives, which information is consulted and which system receives the final answer.

Include exceptions rather than describing only the straightforward route. A missing attachment, disputed account detail or contradictory policy may require a different decision. Ask the people who handle those cases what they need to see. Their review requirements become part of the design, not an inconvenience added after a demonstration.

2. Compare the possible approaches

A deterministic rule produces a defined result when its conditions are met. It suits fixed routing, required-field checks and calculations. Search retrieves existing material. A generative model produces new text or other content from its inputs, but its output can be incorrect. These are different mechanisms and should not be treated as interchangeable forms of automation.

Compare a rules-only option, an improved search option and an AI-assisted option against the same task. A language model may help interpret varied wording, while a normal database query remains the appropriate way to retrieve an account balance. Combining the two does not remove the need to validate the retrieved record and the generated explanation.

3. Establish the data boundary

List the data the task genuinely requires. Identify personal information, confidential contracts, credentials and commercially sensitive material before selecting a service. For UK organisations, consider the UK GDPR and Data Protection Act 2018 alongside contractual restrictions. Determine whether a data protection impact assessment is required with your privacy lead or a qualified adviser.

Check provider terms for retention, model training, subprocessors, international transfers and deletion. A hosted API and a self-managed model create different operational responsibilities; neither is automatically the safer choice. Self-management still requires access control, patching, monitoring and someone able to maintain the deployment. Record the chosen boundary in the proposed scope.

4. Define a useful evaluation

An evaluation set is a collection of representative inputs with an agreed way to judge the outputs. Include routine requests, incomplete information, misleading instructions and cases where the system should decline to answer. Use data you are permitted to process. Separate development examples from the examples used for acceptance so that a polished demonstration does not become the sole evidence.

Choose checks that match the task. For a policy assistant, assess whether the answer is supported by the correct source and respects permissions. For document extraction, inspect each required field and its connection to the original page. Measure review effort as well as output quality. Faster generation is not useful if it creates more correction work.

5. Write the commissioning boundary

A proposal should distinguish discovery, implementation and ongoing operation. Identify the deliverables, systems to connect, access your organisation must provide and decisions that remain outside the project. State who approves changes, how acceptance is assessed and what happens if the evaluation shows the approach is unsuitable. A decision not to deploy can be a sound outcome.

Include recurring costs without assuming a fixed live price: model usage, storage, hosting, monitoring and maintenance may all matter. Consult the relevant supplier’s published pricing when preparing an estimate. Agree ownership of configuration, source code and documentation in writing. Migration and handover are easier to discuss before a dependency becomes embedded in daily work.

6. Prepare the first enquiry

Bring a process description, a list of relevant systems and a non-sensitive example of the input. Explain which mistakes have serious consequences and who would own the service after launch. Do not send live customer records or access credentials through an initial enquiry. We can discuss the handling requirements before any working data is shared.

For background, read the ICO’s artificial intelligence guidance and the NIST AI Risk Management Framework. These help frame questions about data and risk; they do not determine whether your particular process should use AI.