Skip to main content
K4M2 AI

Practical guides

What an AI readiness assessment should include

Most readiness assessments audit technology and produce a maturity score. The useful version audits decisions and produces a shortlist.

By Subhash Trivedi8 min read

A readiness assessment is worth doing and easy to do badly. The failure mode is recognisable: eight weeks of interviews, a maturity model with five levels, a score somewhere in the middle, and no decision anyone can act on.

The purpose of an assessment is not to grade the organisation. It is to answer two questions. Which specific workflows would repay AI investment now, and what would have to be true for the first one to reach production. Everything in the exercise should serve those.

The UK government's AI adoption research found that among organisations already using AI, only about half felt ready to scale it. Readiness is not a precondition for starting. It is what most organisations discover they lack after they have started.

Six dimensions to cover

Weight these to your situation, but do not skip any. The weakest one determines the outcome.

01

Candidate workflows, named and sized

Not themes like customer service. Specific decisions with a monthly volume, a current cost or cycle time, and a known error rate. An assessment that cannot produce five of these has not looked hard enough.

02

Data reality, not data strategy

For each candidate, where the inputs live, who owns them, how clean they are, and what it takes to reach them. Ask to see a sample of the actual records. The gap between the data model and the data is where timelines go.

03

Business context, written down

The rules, exceptions, and precedents that a competent new joiner would need. If this exists only in people's heads, that is a finding: it is the work, and it is the subject of your agent is not confused, it was never told.

04

Ownership and authority

For each candidate, who is accountable for the number today, and whether they have the authority to change the process. A workflow with no owner is not a candidate, whatever its economics look like.

05

Governance and risk posture

Where the organisation sits on the NIST AI Risk Management Framework, what the EU AI Act implies for these use cases, and whether an approval path exists. If every AI decision needs a novel approval, that is the constraint, not the model.

06

Engineering and operating capability

Can the organisation run a service with a defined quality target, monitor for drift, and change a system safely? Existing software maturity predicts AI outcomes better than any AI-specific measure.

The questions that reveal each one

Assessments drift into self-report. These four questions resist it.

Show me the last one

Not the process for handling exceptions, the last actual exception and what happened. Documented process and lived process diverge, and the second one is what you are automating.

Who would notice if it broke

A workflow nobody monitors has no owner, whatever the org chart says. If the answer is the customer, that is your baseline error detection.

What does this cost today

A one-week deadline for the answer. Whether it arrives is more informative than the number itself.

What have you already tried

Previous attempts, why they stopped, and what was learned. This is usually the most valuable hour of the assessment and the one most often skipped.

An assessment that produces a score has graded you. An assessment that produces a shortlist and a first workflow has decided something.

What the output should contain

Four things, and preferably nothing else.

01

A ranked shortlist

Three to five candidate workflows, each with volume, current cost, expected effect, and the main uncertainty. Ranked by expected value net of the work required, not by enthusiasm.

02

One recommended first build

With the number it should move, the threshold that would justify scaling, the named owner, and the condition under which you stop. This is the same shape as a strategy, as we argued elsewhere.

03

A blockers list with owners and dates

Data access, approval paths, missing documentation. Each one assigned. A blocker without a name is a note.

04

An explicit not-now list

The candidates you considered and rejected, with reasons. This is the most reused page of any assessment, because the same ideas come back every quarter.

Length is a reasonable proxy for quality here, inverted. If the deliverable runs past twenty pages, the shortlist is probably buried in it.

How long it should take

Two to four weeks for most organisations. Longer than that and the assessment becomes the project.

The constraint is rarely analysis. It is calendar time waiting for data access and for the people who own the workflows. Both can be arranged in advance, and an assessment that starts without them arranged will take twice as long and produce a maturity score.

One more caution. An assessment run by a party that will also sell the build has an incentive problem, and the honest response is to make the not-now list a required deliverable. A firm that never recommends against building has not given you an assessment. We wrote about testing for that in how to choose an AI consulting firm, and our own version of the exercise is discovery.

Further reading

UK Government, AI adoption research ↗NIST, AI Risk Management Framework ↗European Commission, regulatory framework for AI ↗ISO/IEC 42001, AI management systems ↗McKinsey, The State of AI ↗

More from us

Discovery: how we scope work before buildingAI opportunity discoveryYour agent is not confused. It was never told.How to calculate ROI for an AI initiativeResponsible AI

Two weeks, a shortlist, and a not-now list.

That is what our discovery produces. If the honest answer is that nothing clears the threshold yet, you will hear it in the first fortnight.