AI Readiness
AI Readiness Assessment - Find the Gaps Before They Find Your Budget
An AI readiness assessment measures whether your organization can actually execute an AI initiative, scoring four dimensions: data (quality, access, legality), technology (integration, cloud, identity), people (skills, adoption ownership), and governance (policy, risk, oversight). It ends with a scored gap analysis and a prioritized remediation plan.
The Four Dimensions We Score
Most failed AI projects were never failures of the model. They failed because the data was incomplete, the system had no API, nobody owned adoption, or legal stopped the rollout two weeks before launch. Every one of those is discoverable in advance - cheaply. That’s the entire economic argument for a readiness assessment: three to six weeks of scrutiny to protect quarters of build.
Data Readiness
Data readiness. Does the data exist, is it accurate and complete enough for the intended use, who owns it, where does it live, and are you legally permitted to use it that way? Data lineage and consent questions surface here - long before a regulator or customer raises them.
Technology Readiness
Technology readiness. Integration points and API reality (not API documentation), cloud and identity posture, environment hygiene, and whether your systems of record can actually be reached by an AI system. An AI tool that cannot touch your systems is an expensive suggestion box.
People & Process Readiness
People and process readiness. Who uses the system daily, what changes in their workflow, who owns adoption after launch, and what skills need building. Adoption is the most under-budgeted line item in AI programs, and the most decisive one.
Governance Readiness
Governance readiness. Acceptable-use policy, human-oversight requirements, logging and audit trails, model risk ownership, and alignment to frameworks like the EU AI Act and the NIST AI Risk Management Framework. Governance built after launch is remediation; governance built before is design.
What You Receive
A scored assessment across all four dimensions, with evidence for each score
A gap register ranked by how badly each gap blocks your intended use cases
A remediation plan sequenced so the fastest-unblocking work comes first
A shortlist of use cases you can start now with the readiness you already have - because the honest answer is rarely “you’re not ready,” it’s “you’re ready for these three, not those seven”
The Questions We Actually Ask
Readiness sounds abstract until it becomes a specific list. These are the questions that decide whether a use case is buildable - and they’re worth working through internally even if you never engage anyone:
On data - Does the data this use case needs already exist, or would it have to be created? - How complete and accurate is it, measured rather than assumed? - Who owns it, and can they authorize its use for this purpose? - Are there consent, contractual, or residency restrictions on using it this way?
On technology - Can the systems involved be reached programmatically, or is a person the current integration layer? - Do the APIs exist in reality, not just in the vendor’s documentation? - How is identity handled, and will the AI system inherit permissions correctly?
On people and process - Whose daily work changes, and by how much? - Who owns adoption after launch - by name, not by department? - What happens to the people currently doing this work, and has anyone told them?
On governance - Is there an acceptable-use policy, and does anyone follow it? - Who signs off on an AI system that makes consequential decisions? - Can you produce an audit trail if a customer or regulator asks how a decision was made?
Find Out Where You Actually Stand.
Three to six weeks. Scored, evidenced, and mapped to the use cases you care about.
The Gaps We Find Most Often
Across readiness work, four gaps recur far more than any others:
Data that exists but isn’t reachable - locked in a system with no API, or in a format that requires manual export. Solvable, but it’s engineering work nobody budgeted for.
No named adoption owner. The project has a sponsor and a technical lead, and nobody responsible for whether people actually use the thing.
Shadow AI already in use. Staff are using consumer AI tools with company data, usually without policy or visibility. This is now near-universal, and it’s a governance finding before it’s a security one.
Governance treated as a launch task. Policy, logging, and oversight designed after the system works, which means retrofitting controls into architecture that didn’t anticipate them.
Reading Your Own Score Honestly
A low readiness score is not a verdict on your organization; it’s a map. What matters is the pattern. Weak data with strong governance means you have a remediation project. Strong data with weak governance means you can build now but shouldn’t deploy widely yet. Weak on people means the technology will work and the initiative will still fail - and that combination is the one leaders most consistently under-weight.
Frequently Asked Questions
Data that exists but isn’t programmatically reachable; no named owner for adoption after launch; unmanaged shadow AI use by staff; and governance treated as a launch task rather than a design input. Each is fixable, and each is far cheaper to fix before a build than during one.
Yes, and the question list above is a reasonable starting point. Internal assessments tend to struggle in two places: honest scoring of your own data quality, and surfacing shadow AI use that people are reluctant to disclose internally. If you run it yourself, get someone outside the owning team to score the data dimension.
Three to six weeks for most organizations, depending on size and data complexity. A single-department assessment can be completed in two.
A maturity model tells you where you sit on a generic scale. A readiness assessment tells you whether your specific planned initiatives can succeed with your current data, systems, and governance - and what to fix first. The second is actionable; the first is a benchmark.
No. Readiness is per use case, not global. Nearly every organization has at least a few use cases their current data and systems can support today. The assessment’s most useful output is often that shortlist.
We need a few hours each from data owners, IT/security, and the operational leads whose work the AI would touch. We do the analysis; you supply access and honesty.
Then it’s saved you a build. You’ll get a remediation plan with effort and sequence - usually data access, integration, and governance work - plus interim use cases that don’t depend on the gaps.