Blog

2026.09.08

AI Consulting Company Selection | RFP, Contract and 12-Week Acceptance in Thailand

AI Consulting Company Selection | RFP, Contract and 12-Week Acceptance in Thailand

When selecting AI consulting, a polished proposal and a fast demo do not tell you whether your team can operate the solution after launch. Leaders in Thailand and ASEAN need a contract that leaves behind a connected body of evidence: the business objective, data terms, evaluation set, operating ownership, stop conditions and internal transfer. This guide shows how to split AI implementation support into four layers, compare vendors with an RFP and a proposed 100-point score, structure TCO without inventing market prices, and define a proposed 12-week acceptance plan and clear PoC exits.

The short answer | Buy evidence, not merely an AI consulting PoC

A sound AI consulting engagement is not a contract to make a PoC run once. It should convert a management problem into measurable operating outcomes, establish usable data and permissions, create a reproducible evaluation set, assign production responsibilities and stop conditions, and deliver evidence that the internal team can reproduce.

Evaluate these seven points as one chain:

  1. Is the business problem explained together with a non-AI alternative?
  2. Are inputs, outputs, purpose, retention, transfer, deletion and access agreed?
  3. Is there an evaluation set and acceptance criteria beyond the sales demo?
  4. Are wrong answers, suspension, escalation and human approval assigned to owners?
  5. Who decides GO, REWORK or STOP after the PoC, and from which evidence?
  6. Are prompts, settings, code, evaluations, logs and runbooks delivered reproducibly?
  7. When the vendor changes, are data return, deletion, handover and termination defined?

If these points are left to separate meetings, the result is often “high accuracy but impossible to put into work,” a late legal stop, a build only one consultant can reproduce, or quality regression after a model change. The same evidence register should follow the engagement from RFP through acceptance.

Split the AI consulting company scope into four layers

The label “AI consulting company” does not reveal what the provider will deliver. Break the scope into STRATEGY, WORKFLOW, BUILD and ADOPTION, then buy the combination your organization lacks.

AI Consulting Company Selection | RFP, Contract and 12-Week Acceptance in Thailand - figure 1
LayerPrimary questionExample required deliverablesClient owner
STRATEGYWhich business outcome matters, and why AI?Problem hypothesis, target work, non-AI option, value formula, priorityBusiness executive
WORKFLOWHow will work between people and AI change?As-Is/To-Be, exceptions, approvals, stop rules, RACI, training planProcess owner
BUILDHow will data, models and systems be implemented?Data contract, architecture, code, configuration, evaluation, monitoring, threat controlsIT and data owner
ADOPTIONCan quality be sustained and capability transferred?Runbook, change control, SLA boundary, training, handover, exit packOperations owner

A board-level concept exercise may primarily need STRATEGY. If the use case, data platform and internal developers are ready, targeted BUILD support may be enough. Conversely, buying BUILD alone for a workflow change may produce a functioning screen while approvals, exceptions, training and daily operations remain unresolved. One provider does not have to perform all four layers, but one provider or the client PMO must own the handoffs.

Our guide to four types of AI adoption advisers helps at the earlier stage of deciding whom to consult. This article begins after external help is considered and focuses on what to receive and how to accept it.

Fix a one-page brief before requesting AI implementation support

Before issuing an RFP, create a one-page internal engagement definition. It is not a complete specification. It is the baseline that makes proposals address the same problem.

ItemWhat to recordRisk if left vague
Business outcomeTime, quality, loss, lead time or capacity to improveDemo convenience becomes the objective
Target usersCountry, site, function, role, language and numberTraining, access and UI needs disappear
Decision scopeDecision AI assists and final decision people retainAccountability becomes unclear
Current baselineCurrent value, period, population and exclusionsBenefits cannot be compared
Data classesPersonal, customer, confidential, IP and cross-border questionsPermission may be reversed late
Non-negotiablesHosting, language, stop, audit and existing systemsProposals become incomparable
Decision dateWho decides the next stage, when and from what evidenceThe PoC keeps extending

The measurement design connects to our AI adoption impact measurement guide for Thailand. When many ideas compete, use generative-AI use-case prioritization to compare value, feasibility and risk before outsourcing the decision itself.

Make the RFP ask for deliverables and acceptance evidence

Questions about “extensive experience,” “the latest model” or “hands-on partnership” produce answers on different scales. Convert requirements into deliverables, evidence, accountable owners, dates and assumptions.

Number every deliverable from the start

The following deliverable register is an example. Adjust the number of items to the engagement.

IDDeliverableMinimum contentsAcceptance evidence
D01Problem and value definitionTarget work, baseline, value formula, non-AI optionBusiness-owner approval
D02Data contractFields, purpose, access, retention, deletion, location, transferData-owner approval
D03To-Be workflowNormal, exception, approval, stop, resume and escalationFrontline scenario review
D04Technical designModel, retrieval, integration, identity, logs, monitoring and switchingDesign review and rebuild record
D05Evaluation packDataset, expectations, graders, thresholds and regression resultsIndependent rerun result
D06Risk and control registerRisk, impact, control, residual risk and ownerRisk acceptor sign-off
D07Operations packRunbook, incident, change, SLA boundary and monthly reviewSimulation and recovery drill
D08Transfer and exit packSource, settings, asset list, training, return, deletion and handoverInternal reproduction and deletion evidence

For each ID, ask not whether a template exists but when the draft arrives, who maintains it, which acceptance test it must pass and which format is delivered at termination. If definitions differ across the contract, statement of work, plan and acceptance register, specify precedence and change control.

Ask for reproducible conditions, not customer logos

Logos and project counts do not establish fit. Within confidentiality limits, ask about similarity of the process, languages, data volume, existing systems, applicable controls, user training, stop conditions, duration in production and the provider’s actual responsibility. Review the named project manager, process designer, data lead, security lead and transfer lead—and their planned allocation—not only the people presenting the demo.

Compare proposals with a 100-point score and critical gates

The following weights and thresholds are a proposed comparison design, not an external statistic or industry standard. Change them to match the impact of your engagement.

Scoring layerExample pointsWhat to assess
STRATEGY25Problem understanding, non-AI option, value formula, priority, decision design
WORKFLOW25Observation, exceptions, approvals, language, training and ownership
BUILD25Data contract, evaluation, security, reproducibility, integration and monitoring
ADOPTION25Operations, SLA boundary, change control, internal transfer and exit
Total100Overall comparison

One proposed gate is at least 75 points overall and at least 60% in every layer. But conditions the client defines as critical—such as unauthorized removal of confidential data, inadequate separation of duties, leaked evaluation data, inability to stop, or unresolved IP ownership—must not be offset by points elsewhere. A vendor with 80 points but a critical failure is held or disqualified.

Score from multiple perspectives, including business, frontline, IT and data, security and privacy, and procurement. Record the proposal page or response ID behind each score. Give every candidate the same scenario and questions. If clarification changes a condition, share the same information with all candidates.

Compare cost with a blank TCO structure, not invented market rates

AI consulting cost varies with workflow, data preparation, integration, model use, quality responsibility, language, local support and contract terms. Instead of quoting an unsupported “market rate,” require each vendor to populate the same TCO structure with price, unit, assumption, cap and change condition.

TCO layerVendor amountUnit and assumptionsCost driversCap, alert and stop
Initial designWorkflows, sites, languages
Data and integrationData quality, APIs, migration
Model and platform usageTokens, retrieval, storage, GPU, network
Operations and improvementSupport, evaluation, change frequency
Training, transfer and exitPeople, materials, onsite work, data return

Separate year one from following years, and distinguish fixed, consumption-based, third-party, tax, exchange-rate, travel and after-hours costs. Clarify what “included in the monthly fee” means, excess units, who observes usage, alerts near the budget cap, treatment of model price changes, and costs that remain after suspension. A TCO sheet is not just a lowest-price ranking; it exposes uncertainty.

Finalize the data contract and access before the PoC starts

A data contract is not only legal prose. It is an implementable register. For each dataset, record the owner, purpose, source, confidentiality class, personal-data status, storage location, cross-border considerations, retention, deletion, backup, roles, logs, subprocessors, model-training use and secondary use.

For Thailand engagements, do not decide from a slogan about whether a dedicated AI law exists. Confirm the PDPA and other applicable laws at the time of the engagement, contractual duties, ETDA guidance, and internal information-security, HR and IP controls for the particular use. Employee assessment, customer communication, health and safety, and confidential manufacturing data may require different reviewers and limits. Obtain legal conclusions from internal counsel or qualified specialists.

The Expanded ASEAN Guide for Generative AI groups six risk areas: mistakes; factual inaccuracy and disinformation; impersonation; intellectual property; privacy and confidentiality; and embedded bias. Do not merely copy these into a checklist. Map them to your inputs, outputs, users, affected parties and existing controls. For factual inaccuracy, for example, define source display, refusal conditions, human approval, correction and evaluation cases.

Vendor data terms differ by product, contract, endpoint and setting. As a product-specific example, OpenAI states that API data is not used to train models unless the customer explicitly opts in and that default abuse-monitoring logs may be retained for up to 30 days. These are OpenAI API conditions, not a general rule for every vendor or arrangement. Confirm current contracts, DPA terms, retention controls, region and exceptions for every candidate.

Build the evaluation set first and turn the demo into acceptance testing

Generative-AI quality cannot be reduced to one “accuracy” number. The voluntary NIST AI RMF organizes work into GOVERN, MAP, MEASURE and MANAGE, while the Generative AI Profile provides lifecycle guidance for GenAI risks. They do not state a legal obligation for a particular company, but they help expand evaluation from model accuracy to context, impact, measurement and response.

As a proposal example, start with 120 evaluation cases. This is not an external benchmark; change it for the workflow and risk.

Case groupExample countContents
Normal60Frequent representative inputs, languages, forms and questions
Edge25Missing, ambiguous, long, mixed-language and outdated inputs
Policy and confidential20Personal, confidential, unauthorized, refusal and approval cases
Adversarial and recovery15Prompt injection, misleading context, outages and model switching
Total120Proposed example

Each case needs an input, expected properties, tolerance, prohibitions, evidence, scoring method, critical condition and reviewer. When there is no single model answer, combine graders such as “contains required fields,” “evidence is traceable,” “does not reveal confidential data,” and “escalates uncertainty.” As of 8 September 2026, OpenAI’s current product example for reproducible evaluation is Datasets with graders. Its official guide says that the legacy Evals platform is scheduled to become read-only on 31 October 2026 and to shut down on 30 November 2026, so a new evaluation design should not depend on that legacy platform. This is an OpenAI-specific example, not a mandatory procurement choice. A spreadsheet, test code or another platform is sufficient if versions are controlled and reruns are possible.

A proposed quality gate is at least 90% overall task acceptance, zero defined critical violations, and no more than 2 points of regression against the approved baseline. These are proposed values. Keep critical cases outside the average, and save model, prompt, retrieval corpus, rules and grader versions with each result.

Convert AI adoption consultation into a 12-week acceptance plan

The following is a proposed 12-week plan, not a standard duration or success guarantee. Adjust it for data readiness, procurement, security review, frontline availability and integration complexity.

AI Consulting Company Selection | RFP, Contract and 12-Week Acceptance in Thailand - figure 2
WeeksMain workEnd-of-period evidence gate
1–2BASELINE: problem, current workflow, baseline, non-AI option and decision ownerD01 approved; scope, exclusions and formula fixed
3–4DATA: data contract, access, subprocessors, design and threatsD02 and D04 draft; prohibited uses clear
5–6EVAL: proposed 120 cases, graders, critical conditions and baselineClient can independently rerun D05 v1
7–9PILOT: representative users, production-like data, exceptions, failures and trainingDaily logs, issue register, change history and observation
10–11TRANSFER: runbook, monitoring, rollback, monthly evaluation and handoverThree internal operators reproduce the procedures
12DECIDE: residual risk, TCO, contract and GO/REWORK/STOPDecision record with next-stage scope and conditions

Three internal operators is also a proposed value. The intent is to cover process, IT and data, and operations rather than depend on one person. In the reproduction test, internal staff should not merely watch the vendor. They build the environment from delivered assets, run the evaluation, identify failure, perform rollback and prepare the monthly review.

Contract the PoC exit as GO, REWORK or STOP

PoCs become indefinite when “move to production if successful” is the only exit. Agree three outcomes and their evidence before starting.

AI Consulting Company Selection | RFP, Contract and 12-Week Acceptance in Thailand - figure 3
DecisionExample conditionNext action
GOBusiness, evaluation, control, operations and TCO gates all passApprove limited-production scope, budget, responsibility and reevaluation date
REWORKValue is visible but a correctable defect or uncertainty remainsContract only named fixes, date, additional-cost cap and retest
STOPCritical failure, insufficient value, unusable data, unclear ownership or invalid TCOSuspend use, return and delete data, receive assets and record lessons

STOP is not necessarily failure. It proves non-viability at small scale and avoids larger fixed cost or risk. REWORK is not an open-ended extension; limit it to issue IDs, retest cases, owner, date and cost cap. GO does not necessarily mean enterprise rollout. Limit the function, users, data and operating hours, then set the next evaluation date.

Check these 12 contract topics

These are general working considerations, not legal advice. Ask procurement, legal, privacy, security and HR specialists to review them for the governing law, data, IP and employment impact.

  1. Deliverable register: Format, version, date, acceptance and correction rounds for D01–D08 or equivalents.
  2. IP and reuse: Pre-existing assets, engagement-specific work, generic components, prompts, code and evaluation data.
  3. Data removal: Hosting region, cross-border transfer, devices, development systems and support access.
  4. Subprocessors: Provider, role, change notice, objection and equivalent duties.
  5. Logs: Contents, viewers, retention, integrity, deletion and audit access.
  6. Model switching: Notice, regression test, approval, emergency switch and rollback criteria.
  7. Confidential information: Prohibited input, masking, output handling and incident notice.
  8. Reproducibility: Versioned code, settings, dependencies, prompts, corpus and results.
  9. Handover: Materials, language, training, question period and internal reproduction test.
  10. Termination and exit: Early termination, data return and deletion, asset format, migration support and fees.
  11. SLA boundary: Responsibility across model, cloud, network, client integration and human approval.
  12. Change and acceptance: Scope change, additional fees, retesting and a process that avoids accidental acceptance.

For SLAs in particular, separate “the AI answer is correct” from “the service responds.” If the team cannot observe whether a failure sits in the external model, retrieval layer, internal identity, ERP, network or human approval, the parties can only dispute responsibility. Align contract language with actual telemetry.

Make AI adoption partnership end in internal transfer

If “hands-on support” means joining meetings indefinitely, dependency remains. Accept transfer when internal staff can reproduce these tasks:

  • Add new data and workflow cases to the evaluation set.
  • Compare model, prompt, retrieval-corpus and rule changes before and after release.
  • Stop critical violations and escalate them to named owners.
  • Add and revoke access, then verify it in logs.
  • Decide degradation, suspension, rollback and restart during an incident.
  • Review monthly quality, use, cost, exceptions and risk.
  • Export assets and explain them to a replacement provider.

ISO/IEC 42001:2023 specifies requirements to establish, implement, maintain and continually improve an AI management system. It does not mean certification is mandatory for every engagement. Its useful lesson is to treat policy, roles, process, controls and improvement as organizational capability rather than as a one-off PoC. ISO/IEC 42005:2025 provides context for a repeatable AI system impact-assessment process, which can inform reassessment after change.

In Thailand, ETDA’s Generative AI Governance Guideline organizes benefits, limitations, risks and governance. ETDA’s 2026 “Driving Trust AI Governance” direction adds local context spanning government, SMEs and citizens. Do not convert a policy direction into a project-specific legal obligation; confirm the latest guidance and applicability for each engagement.

Review the same evidence every month

After launch, user growth alone is not success. A proposed monthly review lets business, frontline, IT and risk owners inspect the same evidence.

ViewEvidenceDecision
ValueDifference from baseline, used outputs, rework, non-use reasonsContinue, change target or stop
QualityRerun of 120 cases, new failures, language gaps and regressionChange prompt, data or model
ControlCritical events, confidentiality, access, approvals and incidentsRestrict, remediate or accept
OperationsResponse, incidents, degradation, support and staff effortImprove SLA, runbook or training
CostFixed, variable, third-party and internal effort, budget alertAdjust cap, design or contract
TransferInternal changes, vendor dependency and how current the delivered assets remainDefine next handover scope

The evaluation set must evolve. Add new products, rules, languages, input formats and failures while retaining earlier critical cases for regression. Run the same set before and after change, checking that an improved average does not hide more critical failures.

Common AI consulting selection failures

Scoring the demo impression

Answers to prepared inputs are not representative operations. Compare vendors on the same anonymized normal, edge, confidential, adversarial and failure cases.

Accepting a screen as the PoC deliverable

A screen without the data contract, evaluations, logs, runbook, source and settings cannot be operated or transferred. Link receipt of D01–D08 to acceptance and payment.

Reducing quality to one percentage

Even a 90% average is unacceptable if confidential data leaks, approvals are wrong or unsafe instructions remain. Separate normal quality from critical conditions.

Outsourcing every decision

Business truth, risk tolerance and final accountability remain with the client. A provider can produce evidence but cannot replace management responsibility.

Offering only production or continued study

Without STOP and limited REWORK, the PoC extends. Include termination, asset return, deletion and lesson capture in the exit.

Deferring local language and time-zone needs

Specify Thai UI, frontline training, mixed-language data, after-hours incidents and cross-site ASEAN ownership early. Accept on whether actual users complete exception handling, not on a translated demo.

AI implementation support RFP checklist

Before issue

  • [ ] Put the business problem, non-AI option, baseline, scope and exclusions on one page.
  • [ ] Choose the needed STRATEGY, WORKFLOW, BUILD and ADOPTION layers.
  • [ ] Number D01–D08 or equivalent deliverables and acceptance evidence.
  • [ ] Assign reviewers for data class, access, transfer, retention and deletion.
  • [ ] Approve the proposed 100-point weights and critical gates for this engagement.
  • [ ] Give every candidate the same blank TCO structure.

During comparison and the proposed 12-week acceptance

  • [ ] Give every candidate the same scenarios, questions and clarifications.
  • [ ] Split the proposed 120 cases into normal, edge, policy/confidential and adversarial/recovery.
  • [ ] Validate the proposed gates: 90% overall, zero critical and no more than 2 points regression.
  • [ ] Define evidence for weeks 1–2 BASELINE, 3–4 DATA, 5–6 EVAL, 7–9 PILOT, 10–11 TRANSFER and 12 DECIDE.
  • [ ] Name the decision maker, date, cost and treatment for GO, REWORK and STOP.
  • [ ] Schedule reproduction by three internal operators as a proposed transfer gate.

Before contract and production

  • [ ] Review IP, reuse, subprocessors, logs and model switching.
  • [ ] Review confidentiality, reproducibility, handover, exit and SLA boundaries.
  • [ ] Confirm legal, PDPA, privacy, security and HR requirements for the use.
  • [ ] Schedule monthly value, quality, control, operations, cost and transfer review.
  • [ ] Agree asset formats, data return and deletion evidence for a vendor change.

FAQ | AI consulting and adoption consultation

How should we choose an AI consulting company?

Compare which STRATEGY, WORKFLOW, BUILD and ADOPTION responsibilities it owns and how you can accept deliverables such as D01–D08. The 100-point structure is a proposal example; the key is that critical conditions cannot be offset by a high average.

How many weeks does a generative AI consulting PoC need?

There is no universal answer. The 12-week structure here is a proposal example to cover BASELINE, DATA, EVAL, PILOT, TRANSFER and DECIDE. Adjust it for readiness and manage by evidence gates rather than elapsed time.

What is the typical cost of AI implementation support?

It depends too heavily on the engagement to offer a defensible rate here. Ask all candidates to populate the same TCO layers—initial design, data and integration, model and platform, operations and improvement, and training, transfer and exit—with amounts, units, assumptions, drivers and caps.

Must all data be prepared before consulting about AI adoption?

No, but you need owners who can determine purpose, confidentiality, personal-data status, storage, cross-border issues, access, retention and deletion. Test missing data and access constraints rather than deciding from a clean sample alone.

When can an AI adoption partnership end?

Use a transfer gate: internal staff reproduce evaluation, change, monitoring, suspension, rollback, monthly review and asset export. Three internal operators is a proposed value and should match your size and roles.

Which laws and guidance should a Thailand AI engagement check?

Do not conclude from the presence or absence of one dedicated AI law. Review the PDPA and other applicable law at the time, contracts, ETDA guidance, and internal security, IP and HR controls. Seek qualified advice for specific legal conclusions.

Does a STOP decision leave any value from the PoC?

Yes. Problem and value definitions, a data contract, evaluation set, failed results, risk register, design, assets, and return and deletion evidence can inform an internal build or another vendor selection. STOP must be a normal contractual exit.

Conclusion | Judge AI consulting by evidence your company retains

Choose an AI consulting company by its ability to turn the business problem, data contract, evaluation set, operating responsibility, stop conditions and internal transfer into reproducible evidence—not by demo polish. Define the required combination of STRATEGY, WORKFLOW, BUILD and ADOPTION, then put D01–D08 into the RFP and contract. The 100 points, 75-point gate, 60% per layer, 120 cases, 90% acceptance, zero critical violations, 2-point regression limit, 12 weeks and three internal operators are all proposal examples. Adjust them to impact, and agree GO, REWORK and STOP before work starts.

TOMAS TECH can help Thailand and ASEAN teams structure workflows, RFPs, evaluation sets, PoC acceptance, operations and transfer. You are welcome to contact us while products and providers are still undecided, or when an existing proposal needs clearer deliverables and contract boundaries.

References

*This article is a general practical guide based on public information available on 8 September 2026. The 12 weeks, 100 points, 75 points, 60% per layer, 120 cases, 90%, zero critical violations, 2-point regression limit and three internal operators are proposed values—not external statistics, legal requirements or a guarantee of success. Confirm legal, contractual, PDPA and privacy, information-security, IP, HR and tax decisions with responsible internal teams and qualified specialists for the specific engagement.*