AI readiness for small-business managers — Part 5 of 5.

Four parts of evidence now sit on your desk: a boundary, an evaluation, an oversight test and an
operations plan. This part turns them into the one thing the whole method exists to produce — a
bounded launch decision, made by a named person, recorded on one page. It takes an hour, and the
rule that governs the hour is the checklist’s own: score evidence, not aspiration.

Step 1 — score the ten domains

Rate each domain Verified, Probable or Unverified, using the labels exactly as Part 1 defined
them. A No or Unknown is not a failure; an unlabelled hope is.

The ten-domain scorecard: Purpose and value · Users and affected people · Data · Architecture and supplier · Evaluation · Human oversight · Scale and operations · Monitoring and change control · Governance and compliance · Incidents, fallback and exit — with Verified / Probable / Unverified, blocking-gap, owner and date columns.

For each domain also answer: is any gap here blocking? The next step defines that word.

Step 2 — check the automatic blockers

From the diagnostic, a No or Unknown in any of these prevents an unrestricted Go, whatever the
rest of the scorecard says:

  • no named business owner accepting residual risk;
  • undefined purpose or prohibited-use boundary;
  • unknown sensitive-data flow or supplier use;
  • no severity-based evaluation of representative inputs;
  • consequential output without meaningful human intervention;
  • no workable pause, rollback or fallback;
  • no incident owner;
  • an unresolved high-impact safety, security, privacy or compliance gap.

Notice what the list is made of: every line is a part of this course. The blockers are not extra
requirements — they are the minimum version of Parts 1–4.

Step 3 — choose one of four decisions

Decision Meaning
Go Required evidence is complete; residual risks are accepted by the named business owner.
Conditional go Only bounded, low-impact gaps remain — each with an owner, a deadline and a compensating control.
Pilot only Evidence is insufficient for full production; use stays limited, supervised and reversible.
No-go A high-impact gap exists in purpose, data, evaluation, oversight, security, accountability or fallback.

Three disciplines from the training keep the choice honest:

  1. Cite three pieces of evidence supporting the decision — documents, not recollections.
  2. Name the residual-risk owner and state the fallback as part of the decision itself.
  3. No Conditional go without all three parts — an owner, a deadline and a compensating
    control. A condition missing any of them is a Go with decoration.

Two more words on the middle options, because they carry the traffic. Pilot only is a
respectable decision
— in the worked document-agent case it was the correct one, reached because
eight of ten domains were honestly Unverified. And a pilot is defined by its exit: limited scope,
supervision, reversibility, and a date on which this same assessment runs again with better
evidence.

Step 4 — write the minimum decision record

One page, from the checklist:

  • Service and version:
  • Approved purpose and users:
  • Decision and date:
  • Business owner accepting residual risk:
  • Specialist sign-offs:
  • Open conditions, owners and deadlines:
  • Monitoring thresholds:
  • Fallback and rollback route:
  • Next review date:
The record filled in for the worked example, decision: Pilot only.

This page is the artefact the whole course was building. When someone asks, a year from now, who
decided to run this system and on what evidence, the answer is a document, not an archaeology
project.

Step 5 — close the way the training closes

The session in the room ends with every participant completing one sentence, and the course ends
the same way. Write yours down:

Before this system becomes a production service, we still need evidence that…

Finish it with the missing evidence, its owner and a date. The training is explicit about the
alternative: do not close with a generic promise to use AI responsibly. A promise has no owner and
no date; a sentence naming its missing evidence has both, and it is the difference between a plan
and a mood.

Mine, for my own company, the week this course was finished: before the writing loop becomes a
production service, we still need evidence that the fully generated articles actually go anywhere
in Google. Nobody has checked. The owner is the AI side of my own company, which was given the job
on 6 September 2026. The review date is not set yet, which by the rule two paragraphs up makes this
a mood until it is. Until then, no. I would not approve them.

What you have at the end of the course

From Part 1: a use-case boundary, a data inventory and evidence labels. From Part 2: an evaluation
that could block a launch. From Part 3: oversight that can actually intervene. From Part 4: named
roles, owned thresholds and an incident plan. And from this part: a decision — Go, Conditional go,
Pilot only or No-go — recorded on one page with a named owner and a review date.

That page is production governance at small-business scale. The demo proved the system could work
once; the record is what proves you knew what you were switching on.


Authorship: HAC — human-directed, AI-assisted. The closing passage of Step 5 is the author’s own spoken words, transcribed and arranged, not generated. This part is converted from the 90-minute manager training “From AI prototype to production service” (segments 80–90 min and the participant worksheet), the Day 10 readiness checklist (launch decision and minimum decision record), and the readiness diagnostic (ten-domain assessment, automatic blockers, decision definitions). No new frameworks were created for it.

The AI readiness course: Part 1 — The prototype trap · Part 2 — Evaluation that can fail · Part 3 — Meaningful human oversight · Part 4 — Running it for real · Part 5 — The launch decision.