Look for diagnosis before prescription
A consultant should ask how work happens now, where customers or staff wait, which exceptions consume management time, what data is reliable and how success will be measured. Be cautious when the answer is a platform, AI agent or full migration before the current-state problem is understood.
The OECD’s SME work emphasises that digitalisation varies by sector, function, skills, resources and infrastructure. A credible proposal should reflect that context rather than applying one transformation template to every business.
Demand clear role and commercial boundaries
Ask what is consulting, what is mentorship, what is implementation, what is licensed software and what requires another specialist. The proposal should state who owns configuration, data migration, training, security review, vendor management, support and post-launch operations.
Request the assumptions and exclusions in plain language. A low advisory fee can become an expensive programme if integration, data cleanup, licences, change management and ongoing administration were never included in the comparison.
- Named deliverables and acceptance evidence.
- Decision rights for the owner, team, consultant and vendors.
- Pricing basis, third-party costs and change-control process.
- Data access, confidentiality, retention and deletion terms.
- Pilot, rollback, support and escalation responsibilities.
- Ownership of accounts, documentation, configurations and exported data.
Test the approach with a real workflow
Give the consultant one representative workflow and ask how they would investigate it. A useful answer should distinguish facts from assumptions, identify affected users and systems, propose a baseline and show how a small pilot can produce decision-quality evidence.
Ask what would make them recommend no project, a smaller project or another specialist. Independent judgement is difficult to trust when every diagnosis leads to the same product or large implementation.
Evaluate adoption and internal ownership
Software can pass a technical test and still fail operationally. Ask who will champion the change, how staff concerns will be handled, what operating documentation will change and how managers will know whether the new route is actually used.
The World Bank’s Viet Nam case study found that sustained ERP use was challenging even after initial interest, free access and training. An empowered internal point person with management support was associated with more successful take-up in that setting. A consultant should treat those adoption conditions as delivery work, not as a customer problem discovered after launch.
Keep security and recovery inside the evaluation
Ask how access is granted and removed, how sensitive data is handled, how changes are logged, how failures are detected and what the recovery route is. These questions matter even for a small automation because a single integration can connect customer messages, contact data, payments or internal approvals.
NIST’s small-business CSF guide is voluntary, but its Govern, Identify, Protect, Detect, Respond and Recover structure provides a useful way to test whether a proposal treats risk as an operating responsibility rather than a footer disclaimer.