Proposal  ·  for management review

A personal 24/7 AI assistant for SME Centre advisors

What it is, what it costs, what it does for the Centre's client knowledge, and the guardrails it needs before any client data touches it.

02What is proposed, and what is explicitly out of scope 03The problem in detail 04How the system works in plain terms 05Use cases: client knowledge, events, advisor day-to-day 06Costing 07Privacy, PDPA and guardrails 08Company-level AI SOPs required before implementation 09Implementation: a gated pilot 10The ask ASources and further reading
Prepared byLewis Ang, Senior Business Advisor Date1 October 2026 StatusFor decision: approve a six-week, single-machine pilot ScopeOne advisor's machine, one grant programme, defined data boundaries, with a written AI SOP before client data is introduced

Executive summary

01

This proposes a small, self-hosted AI assistant on one advisor's machine, at a running cost of about US$10 a month, to do three things: remove the meeting administration that consumes each advisor's day, turn the Centre's scattered client knowledge into one searchable record, and give the Centre an evidence base for events, workshops and the group-based upgrading work.

US$10
per month, measured
0
client records in a vendor cloud
6 weeks
proposed pilot, gated

The problem it answers

What is proposed

Why a decision is needed now

Client-facing AI is already in use informally. The choice is not whether advisors use AI at work; it is whether the Centre defines the boundaries and the approved tools, or leaves it to each individual's judgement.

SME Centre@SMF  ·  AI assistant proposal1 October 2026

What is proposed, and what is not

02

In scope

Explicitly out of scope

The one-line version

An advisor's assistant that removes administrative drag and makes the Centre's client knowledge cumulative, built so that client information stays on the machine rather than in a vendor's cloud.

SME Centre@SMF  ·  AI assistant proposal1 October 2026

The problem in detail

03

None of what follows is a complaint about individual workload. The routine administration around every meeting is a real cost, and it is quantified in section 06. These five are different: they are gaps in how the Centre holds what it knows about its clients, uses it, and governs it.

1. The shared record of a case is thin, and it is written from the wrong end of the meeting

The only shared account of an engagement is what the advisor typed into the Partners' Engagement Portal (PEP) afterwards. That entry may not capture the SME's real interests, the issues raised in the room, or the solution the client actually needed. A client can sit with one advisor this month and a different advisor from the same Centre the next: until someone opens PEP, the second advisor starts blind, and PEP is habitually read after the meeting rather than before it. Preparation therefore happens backwards.

The writing is the other half of it. The PEP case summary is composed from scratch every time, tedious and repetitive, and so are the meeting minutes. This is the clearest single use case for an assistant at the Centre: draft the summary into the PEP format for the advisor to check and paste, rather than compose it.

2. The Centre has no view of its own client base in aggregate

Contact and interest information is captured case by case and never assembled: point-of-contact name, designation, phone and email; each company's stated interests and pain points; whether it has any appetite for overseas expansion. Across all of an advisor's meetings, that is the Centre's best market research. Left in individual files, it answers nothing.

Three decisions then rest on judgement instead of evidence:

3. Mid-meeting, an advisor cannot say what the sector is doing

Clients ask, in the room, what the rest of their sector is doing right now and what comparable companies have applied for. Answering well needs a view across every company in that sector and its scheme history. That view does not exist today, and nothing can assemble it inside a one-hour call.

4. AI is already in use, with no SOP and no boundary

There is no AI utilisation SOP, so no black-or-white line for advisors to work inside. Advisors are using personal chatbots for Centre work, which transmits confidential client information to a service outside the Centre's control. That is not a discipline failure; it is what happens when a useful tool arrives before a policy.

Those personal tools also cannot help the Centre as a whole. Each chat is private to one advisor, so what is learned in one is invisible to the rest. Making the knowledge shared requires a common harness in which each advisor is tied to a named bot, and every bot reads and writes the same Centre facts corpus, so one advisor's questions sharpen a record the next advisor can use.

5. Nothing collected is rolled up

Whatever the Centre accumulates, a cleaned and aggregated portion can be reported to SMF. Today there is no consolidation, so there is nothing to roll up. Any such reporting is aggregate and de-identified: individual client detail does not leave the Centre, which is a design rule rather than a courtesy.

SME Centre@SMF  ·  AI assistant proposal1 October 2026

How the system works, in plain terms

04

Nothing here is exotic. It is ordinary software running on a laptop, with one deliberate design decision: the client material stays on that laptop.

ComponentWhat it isWhere it lives
The assistantOpen-source agent software that runs scheduled jobs, reads files, searches the web, and answers in a chat app.Local machine (free, open source)
The modelThe AI that does the thinking, rented by usage from a provider.Provider's servers; only the question and the answer cross the boundary
The memoryA folder of ordinary text notes: client facts, preferences, procedures.Local machine, readable and editable by a human
Meeting notesLocal transcription and summarising of meetings, with no bot joining the call.Local machine; audio never uploaded
The client recordOne searchable note per client, assembled from existing case history.Local machine, with an encrypted weekly archive
ReachResponses delivered in the chat tools the Centre already uses.A private connection, not a public web address

What leaves the machine, and what does not

Leaves the machineNever leaves the machine
  • The question the advisor types.
  • Web search queries.
  • The specific text the model needs to answer that question.
  • Meeting audio and transcripts.
  • The client fact base as a whole.
  • Source documents and identity documents.
  • Credentials, saved in an encrypted vault.

Design choices that follow from the PDPA, not from preference

SME Centre@SMF  ·  AI assistant proposal1 October 2026

Use cases

05

5.1 A consolidated fact corpus for the group-based upgrading work

The group-based upgrading project needs one reliable view of each participating company: registered name, UEN, industry, what they have applied for and when, the contact person, and the equipment or capability in scope. Today that view is assembled per advisor, per case.

5.2 Client pain points and interests, for events and workshop curation

Every engagement contains a sentence where the client describes what is actually hurting. Aggregated, those sentences are the Centre's best market research.

Boundary that applies here: aggregated insight is what the Centre uses. Individual client detail is never published, and any external output is de-identified. Aggregation is computed on the local machine, not by a third-party analytics service.

5.3 The advisor's day

SME Centre@SMF  ·  AI assistant proposal1 October 2026

Costing

06

The measured running cost of the working system is US$10 a month, about S$13 at the rate on 1 October 2026. No per-seat licence, no new hardware.

ItemMonthly, USDBasis
AI model usage (assistant)10.00US$10 a month for a plan that includes US$70 of model credit.
Web search0.00Free monthly credit (US$5). Beyond it, US$5 per 1,000 searches.
Assistant software0.00Open source, self-hosted.
Meeting transcription0.00Free community edition. Optional Pro tier at US$10 per user per month, billed annually, adds speaker labels and integrations.
Hardware0.00A Mac already owned, left running. Electricity only, no capital purchase.
Total10.00About S$12.80 a month

Measured consumption, for credibility

From the provider's ledger on 1 October 2026, for the current billing period: 2,046 runs, 172.5 million tokens, 4.41 of the 70 included credits consumed, 100% completion. The working system is using about 6% of what US$10 buys in a month.

What happens as more advisors join

DeploymentMonthly, USDYearly, USDNote
One advisor, one machine (pilot)10120What is proposed now
Ten advisors, machine each1001,200Full independence, per-person data boundary
Ten advisors, one shared machine10 to 30120 to 360Marginal cost of the tenth advisor is near zero; requires a shared-data decision
Rented equivalent, ten seats200 to 3002,400 to 3,600ChatGPT Business at US$25, Claude Team at US$25, Otter Pro at US$17, per user per month

Assumptions, and what would change the number

SME Centre@SMF  ·  AI assistant proposal1 October 2026

Privacy, PDPA and guardrails

07

Client personal data (names, contact details, NRIC in some documents) means the Personal Data Protection Act applies to whatever we build. The design principle here is subtraction: keep client material on the machine so that most obligations are removed rather than managed.

7.1 How the design answers each PDPA obligation

ObligationWhat it requiresHow this system answers it
ConsentConsent before collecting, using or disclosing personal data for a purpose.Client data is used for the advisory purpose it was collected for. No use for model training. Cloud models are used under zero-data-retention terms.
Purpose limitationUse only for purposes a reasonable person would consider appropriate.The corpus serves advisory support, programme design and reporting. Access is scoped to that.
NotificationTell individuals the purposes of collection and use.Existing advisory communications cover the purpose. An AI-processing notice is added to the client-facing privacy statement before any centre-wide rollout.
Access and correctionIndividuals may access and correct their data.The record is plain files on disk, readable and correctable by hand. No request needs a vendor's cooperation.
AccuracyReasonable effort to keep data accurate.Derived facts are traceable to source case records; a human reviews anything relied upon.
ProtectionReasonable security arrangements against unauthorised access, use, disclosure or loss.Full-disk encryption, a login on the machine, no public exposure (a private tunnel only), an access key on services, credentials in an encrypted vault, no client detail in group channels.
Retention limitationStop retaining when the purpose is served and retention is no longer necessary.Source submissions are purged after extraction. The derived corpus carries a defined retention period in the SOP. Weekly encrypted archive, with a stated retention horizon.
Transfer limitationComparable protection for personal data transferred overseas.Local-first design keeps client material in Singapore on the machine. Where a cloud model is used, the transfer is limited to the question text and is governed by the vendor's zero-data-retention terms, documented in the SOP.
Breach notificationAssess whether a breach is notifiable (typically within 30 days of awareness) and notify the Commission within 3 calendar days of that assessment.A single-machine surface is bounded and auditable. An incident runbook names who assesses, who notifies and within what clock.
AccountabilityDesignate a data protection officer and put policies and practices in place.The AI SOP, a named system owner, and a quarterly review of logs, incidents and the approved tool list.

7.2 The Generative AI guidance

The PDPC, with IMDA, issued its Advisory Guidelines on the use of Personal Data in Generative AI on 20 July 2026. Three points matter here:

SME Centre@SMF  ·  AI assistant proposal1 October 2026

Residual risk register

07.2

Every control leaves a residue. These are the honest ones, with what we do about each.

RiskWhy it existsMitigation
The model provider sees the questionWhatever the advisor types is sent to a model endpoint. A question containing a client name is a disclosure.Zero-data-retention terms on every endpoint; a written rule that client identifiers are not typed into prompts; the client record answers by reference to the local note, not by pasting client detail into a prompt.
The machine is the single point of failureOne laptop holds the working record.Encrypted weekly archive, an off-machine backup of text, and a rehearsed restore. The record is designed to be reconstructible.
The machine is the single point of exposureEverything sits on one device.Disk encryption, login required, no public address, services behind an access key, credentials in a vault, automatic re-closing of any temporary open lane.
Advisor error in what is askedAn advisor may paste client detail into a prompt.Training at onboarding, a visible prompt convention, and periodic spot checks in the quarterly review.
Derived facts are wrongExtraction from documents can misread.Facts are traceable to sources; nothing client-facing is sent without human review; corrections are made in the note itself.
Vendor change of termsModel providers change pricing, retention and training policies.The provider is a swappable component by design. Annual review of terms, with a stated fallback provider.
Scope creepCapability invites mission creep toward client-facing automation.Written out-of-scope list, revisited only by management decision, not by default.

What we would never do

SME Centre@SMF  ·  AI assistant proposal1 October 2026

AI SOPs required before implementation

08

The technology is the easy part. What determines whether this ends well is whether the Centre writes down the rules before, not after. Ten items, all of them short documents.

PolicyWhat it must sayOwner
1. Approved toolsThe list of AI tools permitted for work, and which data class each may handle. Everything else is unapproved by default.Management
2. Data classificationFour buckets (public, internal, client-confidential, restricted) with an explicit rule for each: what may enter a prompt, what may be stored, what may never leave the machine.DPO + Management
3. Acceptable useNo client personal data into consumer accounts; no personal subscriptions used for Centre work; no client material in unsupervised tools.Management
4. Human in the loopAI output is a draft. A named human approves anything client-facing, financial, or interpretive. The advisor remains accountable for the advice given.Team leads
5. Meeting captureParticipants are told when a meeting is recorded or transcribed, how the transcript is stored, and how long it is kept. Recording is opt-out-able on request.DPO
6. Retention and deletionA retention period per data type, a deletion method, and a rule that source documents are purged once extracted.DPO
7. Access and credentialsWho may access the system and its record, how keys are held (encrypted vault), device encryption mandatory, and how access is revoked on team change.IT + DPO
8. Incident responseHow a suspected breach is assessed, who decides whether it is notifiable, the 3-day notification clock, and the notification template for affected individuals.DPO
9. Vendor and model assessmentA checklist before any model or tool is approved: zero-data-retention terms, training opt-out, data residency, sub-processors, and contract terms.DPO + IT
10. Training and reviewEvery advisor signs the AI use policy at onboarding; annual refresher; quarterly review of the approved list, logs and incidents.Management

The four rules that apply from day one

SME Centre@SMF  ·  AI assistant proposal1 October 2026

Implementation: a gated pilot

09

Six weeks, one machine, four gates. Each gate is a decision to continue, not a formality.

PhaseDurationActivityGate to pass
0. FoundationWeek 1Management approves scope and the out-of-scope list. Draft SOP v0.1 and the data classification rule. Name the system owner and the DPO contact.SOP and classification signed. No client data involved yet.
1. Dry runWeek 2Install on one machine. Run with public and internal material only. Time the meeting-administration workflow and record a baseline.System stable; baseline measured; zero incidents.
2. Client data, boundedWeeks 3 to 5Complete a DPIA covering the intended processing. Introduce one grant programme's client corpus. Local meeting capture under the stated notice. Produce one aggregated insight pack (industry and pain-point counts).DPIA completed; no notifiable incident; corpus accuracy spot-check passed; aggregation produced without exposing individual client detail.
3. DecisionWeek 6Evidence pack to management: time saved per meeting, corpus quality, incidents, cost against budget, and the recommendation on per-advisor machines versus a shared one.Management decision on rollout scope.

What success looks like, stated so it can be measured

What we need from management

SME Centre@SMF  ·  AI assistant proposal1 October 2026

The ask, and sources

10

The ask, in one paragraph

Approve a six-week pilot of a self-hosted AI assistant on one advisor's machine, at a running cost of about US$10 a month, subject to an AI SOP and a DPIA being completed before any client data is introduced, and with a management decision at the end on whether to extend it to the team.

Sources

SubjectSource
PDPA obligationsPDPC Advisory Guidelines on Key Concepts in the PDPA (consent, purpose limitation, notification, retention, protection, transfer, breach notification); PDPA Parts 3 to 6A.
Generative AI and personal dataPDPC and IMDA, Advisory Guidelines on the use of Personal Data in Generative AI, issued 20 July 2026; PDPC Advisory Guidelines on use of Personal Data in AI Recommendation and Decision Systems.
Breach notification clocksPDPA Part 6A: assess as soon as practicable (typically within 30 days of awareness); notify the Commission no later than 3 calendar days after the assessment that a breach is notifiable.
Assistant softwareHermes Agent documentation: installation, messaging platforms, Bot Mode. Open source.
Meeting transcriptionMeetily (MIT licence): local Whisper and Parakeet transcription, local or bring-your-own-key summarising, community edition free, Pro at US$10 per user per month billed annually. Compare with local-first alternatives and with cloud services including Otter, Fireflies and HappyScribe.
Cost figuresThe model provider's own plan and usage ledger, read 1 October 2026. Exchange rate US$1 = S$1.279 on the same date.
Technical guardrailsFull-disk encryption on the host machine; private tunnel instead of public exposure; access key on hosted services; credentials in an encrypted vault; a scheduled exposure check that asserts the surface every 15 minutes.

Companion material

A separate Business Advisor session covers the practical half: the seven assistants compared, the four bot platforms compared, six transcription tools compared, and copy-paste setup guides for the assistant, Telegram, Slack and the meeting transcriber.

Prepared by Lewis Ang, Senior Business Advisor, 1 October 2026. Prices, features and legal references verified on that date. This document contains no client names and no client data.

SME Centre@SMF  ·  AI assistant proposal1 October 2026