Operational data integrity·Process maturity transformation
Bad data does not announce itself. It just spreads.
We find what is silently broken underneath. Then we build the workflow that runs on top of it.
Before anything is built on top
Automation does not fix a broken process. It multiplies it.
A process you have not examined can be automated exactly as it is. The result runs faster. It is also faster at whatever the process already gets wrong. We establish what is there first, in writing. We repair nothing until you have decided what matters.
The system you specify
- Intake
- Making
- Proofing
- Authorisation
- Custody
- Tracking
- Scorekeeping
What it runs on
records a month
One record
700148223874
03/04/2026
Read month first, this invoice is thirty days older. That decides whether anybody chases it.
D03
Five of your seven stages are standing on them.
There is no patch for this. Somebody reads the file first and writes down what is actually in it. Then you decide what to build.
Automating this does not change the number. It changes how quickly you reach it.
Ten seconds, with a date from your own records
Your ageing report may be a month out, on dates that look correct.
Day, month and year, written in numbers. Nothing typed here leaves your browser.
A month written in words cannot be misread. Type the date in numbers.
30 days apart. Read month first, this record is 30 days older. That decides its ageing bucket, and whether anybody chases it.
You write day first. Your tool reads month first. The dates compute wrong. Nothing in the value says which convention was typed. Where both readings work, only you can settle it. Where both orders sit in one column, no single convention repairs it.
One delivery, read end to end
Synthetic delivery — shapes real, content inventedA file can reconcile cleanly and still be wrong.
This delivery was accepted.
- entity-a-ap-jul.xlsx 12 → 15 → 16 columns across three deliveries APX-D04 · shape drifted
- entity-a-ap-aug.xlsx 16 rows · the file being scanned scanned
- entity-b-remit-aug.zip 3 members · one encrypted APX-D08 · listing needs no password, reading does
Four records that do not exist
APX-D06 · the summary was typed once. The rows moved on.
| # | vendor_ref | counterparty | no header — this column carries the entity code | invoice_date | amount | status |
|---|---|---|---|---|---|---|
| 01 | 4500911144450 | Tenaga Selatan Sdn Bhd | ENT-A04 | 12/03/2026 | 48,200.00 | settled |
| 02 | 700148223391 | Melur Logistics Bhd | ENT-B11 | 19/03/2026 | 7,915.40 | settled |
| 03 | 33201884007412 | Kilang Damai Sdn Bhd | ENT-C02 | 21/03/2026 | 126,400.00 | settled |
| 04 | 88001100220000001→ 88001100220000000 | Arus Murni Enterprise | ENT-D01 | 24/03/2026 | 3,180.00 | settled |
| 05 | 4500911144683 | Sri Wangsa Trading | ENT-A04 | 27/03/2026 | 19,640.00 | settled |
| 06 | 33201884007509 | Bina Utara Sdn Bhd | ENT-C02 | 02/04/2026 | 88,050.00 | pending |
| 07 | 8.80011002200005E+16 | Selat Timur Sdn Bhd | ENT-D01 | 14/04/2026 | 61,900.00 | settled |
| 08 | 33201884007633 | Nusa Kirana Bhd | ENT-C02 | 17/04/2026 | 33,700.00 | pending |
| 09 | sub-total, rows 01–08 | 388,985.40 | ||||
| 10 | 4500911144902 | Harmoni Steel Sdn Bhd | ENT-A09 | 22/04/2026 | 75,220.00 | settled |
| 11 | 700148223874 | Pinnacle Freight Bhd | ENT-B11 | 03/04/20263 Apror4 Mar | 52,140.00 | settled |
| 12 | 33201884007788 | Batu Emas Resources | ENT-C02 | 06/05/2026 | 118,900.00 | settled |
| 13 | 4500911145037 | Anggerik Retail Sdn Bhd | ENT-A09 | 04/13/2026 | 16,275.00 | settled |
| 14 | 700148224120 | Puncak Aman Sdn Bhd | ENT-B11 | 24/05/2026 | 143,600.00 | settled |
| 15 | sub-total, rows 10–14 | 406,135.00 | ||||
| 16 | 33201884007915 | Wira Cemerlang Bhd | ENT-C02 | 27/05/2026 | 21,050.00 | settled |
Defect register
- D01Identifier damaged by precisionrow 04Still in the file. Up to 10 references would match once stored
- D02Collapsed to scientific textrow 07Unrecoverable — a fresh extract is the only route
- D03Date order unresolvablerow 11Thirty days apart. It decides the ageing bucket
- D04Delivery shape drifted3 deliveriesAmounts are read from the wrong column
- D05Data under no headercolumn 4Postings land against the wrong entity
- D06Summary disagrees with the rows18 v 14
- D07Rows that are not recordsrows 09, 15Processed volume is overstated by two
- D08Archive member will not openunrecoverableThe batch fails mid-run, after the window has closed
Scan complete
This delivery was accepted. Eight of the ten faults were in it.
Two of the eight cannot be recovered from this copy. Those need a fresh extract from the source.
See where your own operation sitsWhere does yours sit
Every operation runs the same seven stages.
Work arrives, gets made, gets checked, gets approved, gets filed, gets kept, and gets counted. One question per stage. Answer all seven, tell us where to send the result, and it appears here and in your inbox. Apex keeps a copy.
The ladder: every stage sits on it. These seven questions reach L4.
- L1Ad hocDepends on who is on shift. No defined method.
- L2RepeatableA method exists, informally. Results vary by person.
- L3DefinedDocumented, published, actually followed.
- L4InstrumentedThe process emits data about itself.
- L5Self-improvingThat data drives change on a cadence.
- –Intake
- –Making
- –Proofing
- –Authorisation
- –Custody
- –Tracking
- –Scorekeeping
Answer all seven to see an indicative level.
Which door do you want to talk about?
Your address, your seven answers and the door you picked go to Apex Performance, and a copy of the result goes to you. Nothing else is kept, and none of it is passed on.
Sent.
Built on public maturity-model norms: the CMMI level structure and ISO 9001 process discipline. The custody standard is read against published data-protection law: the PDPA 2010 in Malaysia, the GDPR in Europe, and HIPAA where health information is held. It reproduces no vendor's instrument and no client's material. We do not quote peer benchmarks we do not hold.
What stands behind it
Kudrat Lokman
Bank Negara Malaysia·The Wharton School·COO, building the world's first AI-native takaful operator
- Ten named faults
- Each on a permanent code. Codes are never reused and findings are never renumbered. A report written today still reads correctly in two years.
- A library of broken files
- One file for every fault. If a fault stops being caught, the build fails. The files were written to the detectors, so this is not an independent test.
- Three house rules
- We report what is wrong and never change your file. We assert no finding the data cannot support. A fault is never quietly dropped from the tests.
- Eight controls for letting AI near your data
- In development and not yet issued. Each control states whether it is in force today, built at engagement start, or still on the roadmap.
- Seven stages every operation runs
- The same seven the Assessment scores you against.
The codes, the files and the rules hold regardless of who reads the report.
Two ways in
Find out where you actually stand. And what to move first. Whether or not you do it with us.
The Assessment
You leave with a level you can defend. You leave knowing which of the seven stages is weakest, and why it is the one to move first. And where your reporting and your data disagree, if they do. Ninety minutes with whoever actually runs the operation. The gauge above takes your word for it. This one does not.
Guided, by invitation. Not self-serve.
The Blueprint
The thing you have been meaning to build, designed as if you were starting today. It starts with three days inside the operation and two weeks inside the data. That ends in an implementation plan: what to build, and in what order. Then it gets built, with named human approval points.
Starts with the seven free questions above. Either door stands alone.