Assessment

AI Readiness Assessment

Eight questions that separate organisations prepared to run AI in production from those prepared to talk about it, covering use cases, data, governance, risk, oversight, ownership, vendors and adoption.

AI initiatives rarely fail at the model. They fail at the unglamorous surroundings: data that cannot support the use case, governance nobody defined, and processes that simply ignore the output. Eight questions, fixed scoring, nothing uploaded.

Last reviewed 3 July 2026 · Free and ungated

Get independent perspectives

Put the AI initiative to selected senior operators who have run these systems in production, and receive a confidential report before committing budget.

Get independent perspectives

How a client brief works · What you receive

Fixed questions · no AI · nothing stored

Run the scorecard

Answer for the specific AI initiative closest to funding, not for your most polished pilot.

0–39 Low maturity 40–59 Developing maturity 60–79 Moderate maturity 80–100 Stronger maturity How our tools are scored
  1. Use-case clarity Is it defined what the AI is for and how success will be judged?
    • The mandate is "do something with AI"; use cases are still being hunted
    • Use cases are listed, but success measures are vague or aspirational
    • A specific use case exists with a measurable definition of better
  2. Data quality Can the data actually support the use case in production?
    • Nobody has examined whether the required data is complete or reliable
    • Data was good enough for a pilot, cleaned by hand for the occasion
    • Production data has been profiled against the use case and gaps are known
  3. Governance model Who is accountable when the system is wrong?
    • No one has been named as accountable for AI decisions or errors
    • A policy document exists but has not been tested against a live incident
    • Accountability, escalation and review are defined and have been exercised
  4. Risk controls Are failure modes identified with controls to match?
    • Risk discussion has not gone beyond general enthusiasm or general fear
    • Key risks are listed, but controls are promised rather than built
    • Specific failure modes are mapped to tested controls and thresholds
  5. Human oversight Where do people review, override or stop the system?
    • Oversight is assumed: someone will presumably notice if it misbehaves
    • A human checks outputs, but has no defined authority or time to intervene
    • Oversight points are designed in, with clear authority to override or halt
  6. Operating ownership Who runs it after the project team disbands?
    • Ownership ends at go-live; no one is named for the years after
    • IT will host it, but business ownership of outcomes is undefined
    • A business owner runs the system with budget for monitoring and retraining
  7. Vendor dependency How exposed are you if the provider changes terms, models or direction?
    • The capability lives entirely in one vendor and no exit has been considered
    • Dependency is recognised, but switching would be slow and painful
    • Dependencies are mapped, with contractual protections and a credible exit path
  8. Adoption readiness Will the people in the process actually use the output?
    • The affected teams have not been consulted about the change
    • Teams are informed and wary; the workflow change is still on paper
    • Users helped design the workflow and the incentive to use it is clear
Reading the score

What the result bands mean

0–39: Low maturity

These answers describe an organisation preparing an announcement, not a deployment. Committing serious budget now means paying to discover in production the gaps in data, ownership and oversight that could have been found on paper.

40–59: Developing maturity

There is genuine substance here (probably a working pilot and real intent) but the scaffolding for production is incomplete. This is the most dangerous band for AI specifically, because pilots create pressure to scale at exactly the moment governance and data readiness have not caught up.

60–79: Moderate maturity

The fundamentals for responsible deployment are largely present, and the remaining weaknesses are specific rather than structural. The risk now is uneven depth: governance that exists on paper but has never handled a live incident, or adoption that holds only while the project team is watching.

80–100: Stronger maturity

The organisation has done the unfashionable work: named owners, tested controls, adoption designed rather than hoped for. What a strong score cannot certify is judgement: whether this use case deserves AI at all, and whether the business case survives honest attribution.

What this assessment is checking

Not model quality, and not enthusiasm. It checks the eight conditions that decide whether an AI initiative survives contact with production: a defined use case, data that holds up outside the pilot, accountable governance, real risk controls, designed oversight, an owner for the long run, managed vendor exposure and users who will actually adopt the output.

Scoring, in one paragraph

Three answers per question, worth 0, 5 or 10 points; the total is normalised to a score out of 100 and mapped to four readiness bands. No free text, no interpretation layer and (deliberately, given the subject) no AI: the assessment is fixed arithmetic in your browser.

Signals you are announcing rather than deploying

  • The press release exists before the use-case definition does.
  • The pilot data was prepared by hand and everyone knows it.
  • Accountability for errors is "the governance committee", which has not yet met.
  • The business case attributes savings to AI that a process fix would deliver without it.

Where a low score is good news

Finding these gaps before commitment is cheap; finding them in production is not. An honest 35 today, acted on, beats a generous 70 that unravels in front of a regulator or a customer. The assessment exists to move the discovery earlier, when changing course costs a meeting rather than a write-down.

Frequently asked questions

Which AI initiative should we score if we have several?

Score the one closest to a funding or deployment decision, because that is where readiness gaps convert into losses. Scoring an average across the portfolio blurs exactly the differences that matter.

Does the assessment cover regulatory compliance?

Only indirectly, through the governance and risk-control questions. It cannot substitute for legal review under the regulations that apply to your sector and territory; treat compliance as a parallel workstream, not a question to average in.

Our vendor says their platform handles governance for us. Does that count?

Platform controls are useful, but accountability cannot be outsourced: when the system is wrong, the consequences land on your organisation, not the vendor. Score the governance question on what your organisation owns, exercises and can evidence.

AI answers arrive instantly. Judgement about them should not.

Get independent perspectives