Client onboarding for SME AI deployments: six phases
For a European SME bringing an AI system into production, the onboarding phase is where most deployments succeed or fail. Not at the model-training step, not at the server-installation step — at the point where the provider and the SME align on what the system will actually do, who owns which piece, and how acceptance will be measured. A loose onboarding produces a technically-correct system that the SME does not use. A tight onboarding produces a deployment that the SME runs on day 31 without phoning J4SGON. This post walks through the six phases J4SGON uses for edge-AI engagements — including the Spanish-market anchors like Article 43 classification, Kit Digital voucher mechanics, and AESIA inspection readiness that each phase produces on the way to go-live.
Phase 1 — Initial contact and qualification
The first two business days cover qualification. Goals:
- Fit check. Is the SME’s use case inside J4SGON’s three divisions — Consulting (Docebo/LMS), Edge AI for SMEs, Government Sovereign Nodes? If not, the engagement either fits a partner or declines politely.
- Regulatory classification. A 20-minute conversation covers EU AI Act exposure: is this a prohibited practice (Article 5), a high-risk use case (Annex III), a limited-risk chatbot (Article 50), or a minimal-risk internal tool? The classification shapes the rest of the engagement.
- Funding posture. For Spanish SMEs, is a Kit Digital voucher available and under which segment? The answer determines whether the engagement is voucher-funded, cash, or mixed.
Deliverable: a one-page qualification memo with divisional routing, AI-Act classification, funding posture, and next-step recommendation. An SME that does not pass qualification gets a clear “not now / not us” plus a redirect — not a long sales dance.
Phase 2 — Discovery workshop
The discovery workshop runs 1–3 days, remote or on-site depending on complexity. The format is scoped by division: a Docebo deployment’s discovery is LMS integration patterns; an edge-AI deployment’s discovery is document corpus, user roles, data flows, and oversight model; a government-node deployment’s discovery is ENS RD 311/2022 category and sector overlays.
Outputs from discovery:
- Process map. The as-is workflow the AI system will augment, with the current human touch points and failure modes.
- Data inventory. Document repositories, databases, and streams the system will read or write, with classification (personal data, sensitive category, confidential, public).
- Acceptance criteria (draft). First cut at the measurable outcomes — latency, accuracy, coverage, override rate — the system has to hit for the SME to accept delivery.
- Regulatory scope. Final AI-Act classification, GDPR Article 35 DPIA trigger assessment, any sector overlays (ENS, DORA, healthcare).
The discovery output is the source document for the proposal. Changes after sign-off go through a change-control log rather than quietly into the build.
Phase 3 — Proposal and SOW
Proposal and Statement of Work takes 5–10 business days. The document covers:
- Scope. Bounded by the discovery’s process map. In-scope items named; out-of-scope items named. No fuzzy middle.
- Milestones and payments. Tied to the validation-pipeline stages from the Quality Management System — technical validation, privacy review, peer review, client acceptance.
- Acceptance criteria. Measurable, dated, and owned. If accuracy on the holdout set has to be ≥ 0.85 by day X, that is in the SOW.
- Regulatory deliverables. For high-risk systems under Article 43, the SOW lists the Annex IV technical file, the Article 17 QMS records, the Article 14 human-oversight design, and the post-market monitoring plan as named deliverables.
The SME’s signature on the SOW assigns the Kit Digital voucher where applicable and triggers the technical build.
Phase 4 — Technical setup and configuration
The technical phase runs 2–6 weeks depending on division. Week-by-week milestones:
| Week | Focus |
|---|---|
| 1 | Environment provisioning, hardware delivery, network configuration |
| 2–3 | Data ingestion, embedding generation, model deployment |
| 3–4 | Orchestration, RBAC, monitoring, logging middleware |
| 4–6 | Integration with SME systems, testing, Annex IV documentation |
For an edge-AI deployment this means a physical device — a Jetson Orin Nano or Mac Mini M4 per the developer.nvidia.com/embedded/jetson-orin and apple.com/mac-mini hardware profiles — arriving at the SME’s office, being placed behind their firewall, and booting into the J4SGON image. The SME’s IT owner is involved from day one; the device never becomes a surprise black box.
For Docebo engagements the phase covers Connect recipes, SSO integration, and role mapping. For government-node engagements it covers ENS HIGH-category hardening and air-gap verification.
Phase 5 — User training and documentation
Training runs 1–2 weeks — formally a short phase, but critical. Under Article 4 the AI-literacy obligation applies to staff with AI-related duties; under Article 14 the named oversight owner needs deeper training on the system’s capacities and limits. J4SGON’s training package includes:
- General AI-literacy session for all affected staff — what the system does, what it does not do, who to ask when it behaves oddly.
- Oversight-role deep dive for the named owner — how the review queue works, what an override looks like, how to trigger the stop switch, what to log.
- Admin runbook for the SME’s IT owner — how to restart services, how to rotate credentials, how to read the monitoring dashboard.
- Documentation package — user guide, admin guide, oversight procedure, incident runbook, Annex IV technical file copy for the SME’s compliance records.
Phase 6 — Pilot deployment and UAT
Pilot deployment and UAT runs 1–3 weeks. The system runs on real data and real users under close observation. The SME’s oversight owner runs through the acceptance criteria with the J4SGON peer-reviewer present. Findings split into must-fix-before-sign-off, fix-in-first-retainer-month, and defer-to-QBR.
Sign-off produces:
- Client acceptance record — the Article 14 handshake.
- CE marking file (for high-risk systems) — Article 47 declaration of conformity, EU-database registration entry, Annex IV technical file version 1.0.
- Fase 2 handover — maintenance cadence, monitoring review rhythm, support channel, QBR schedule.
At this point the deployment transitions from project to retainer. The SME owns day-to-day oversight. AESIA supervision sits in the background — if it shows up as an inspection, the QMS, the technical file, and the monitoring log are the artefacts that answer the visit.
Ready to get started?
Working on this yourself? J4SGON S.L. delivers Docebo Connect, HRIS, SSO and migration work for European organisations — see what a scoped engagement covers or describe your project and we will reply with a written scope.
Tell us what you are integrating or migrating
Send the platform, the systems involved and where you are stuck. You get a written scope back — phases, deliverables and what is out of scope — before anything is billed.