EU AI Act high risk obligations are now enforceable. Check your exposure
Insights About us Careers
Contact us
AI Strategy & Consulting

AI Readiness Assessment

A two week AI readiness assessment that scores whether your organisation can support the AI you want to build, and tells you exactly what to fix first.

2 weeks
Elapsed duration
5 dimensions
Scored independently
Fixed fee
No hourly billing
Yours to keep
Full report and scoring model

An AI readiness assessment answers one question before you commit engineering budget: can this organisation actually support the system you have in mind? Not in principle, and not after an eighteen month data programme. Now, with the data, permissions, skills and systems you have today.

In one paragraph

An AI readiness assessment is a structured audit of an organisation's data, systems, governance, skills and unit economics, scored against the specific AI use cases it intends to build. The output is a viability verdict for each use case and a prioritised list of the gaps that have to close before work starts.

Why AI projects fail before anyone writes code

The post-mortems are remarkably consistent. A customer service assistant is scoped, funded and staffed, and four months later it stalls because the knowledge base it depends on was last reviewed in 2021 and contradicts itself in about a fifth of articles. A document extraction pilot clears accuracy testing and then waits eleven weeks for a security exception because nobody checked what the data classification policy said about sending scanned contracts to a third party.

None of these are modelling problems. Every one of them was visible in advance to anyone who went looking. That is the entire purpose of an AI readiness assessment: to find the constraints while they still cost a conversation rather than a quarter.

What an AI readiness assessment measures

We score five dimensions. Each is graded against the specific use cases you are considering rather than against a generic industry ladder, because readiness is not a single number. An organisation can be entirely ready for internal document classification and nowhere near ready for an autonomous agent with write access to a billing system. Scoring them together produces a figure that describes neither.

DimensionWhat we examineMost common blocker
DataCoverage, quality, lineage, labelling, refresh frequency, and whether the fields your use case needs exist at the granularity it needs them.Required field exists but is free text, inconsistently filled, or only accurate for recent records.
SystemsIntegration surface, API availability, authentication model, rate limits, and how much of your stack can be reached programmatically at all.A core system with no API, where the only integration path is a nightly export.
GovernanceDecision rights, risk appetite, existing policy, EU AI Act and sector exposure, and who signs off on a model going live.No named approver, so the system is built and then cannot be launched.
PeopleIn-house skills, who owns the system after launch, and whether the affected teams have been told this is coming.No post-launch owner identified, which means no one maintains it in month four.
EconomicsRealistic build and run cost including inference, monitoring, retraining, and the internal review time nobody counts.Human review of exceptions consumes most of the projected saving.

Data readiness

We examine the data itself, not the data dictionary. Those two disagree more often than not, and the disagreement is usually where the project dies. For each candidate use case we check whether the required fields exist, whether they are populated consistently across the period the model would learn from, how quickly they refresh, and whether there is a documented basis for using them for this purpose. Personal data, data acquired under restrictive licence terms and data held under customer contracts with narrow use clauses all get flagged here rather than during legal review six weeks before launch.

Systems and integration readiness

An AI system is only as deployable as the systems it has to reach. We map every touchpoint your use case requires and grade each on how reachable it actually is: modern API, legacy API, database access, file export, or screen only. We also look at authentication, rate limits and what a service account can and cannot do, because a permissions model that blocks automated access will surface late and expensively.

Governance and regulatory readiness

We establish who decides that a model is safe to deploy, what evidence they will require, and how long that takes. In parallel we classify each candidate use case for regulatory exposure. Under the EU AI Act, classification determines documentation, testing and human oversight obligations, and those obligations materially change both cost and timeline. Discovering a high risk classification after the build is one of the more expensive ways to learn this.

People and ownership readiness

Two questions matter more than headcount. Who owns this system in month six, and have the people whose work it changes been told? A system without a named owner degrades quietly. A system announced to its users at launch meets resistance that no amount of accuracy will overcome.

Economic readiness

We build a rough cost envelope covering build, inference at projected volume, platform and monitoring, retraining cycles, and human review of the cases the system cannot handle. That last line is the one optimistic business cases omit, and it is frequently the largest. A process automated to ninety percent still routes ten percent to a person, and if that reviewer did not previously exist the saving is smaller than the slide claimed.

How readiness is scored

Each dimension receives one of four grades against each use case. We publish the scoring rubric with the report so the grades can be challenged and, more usefully, re-run by your own team in six months.

GradeMeaningWhat it implies
ReadyNo material gap. Work can start.Proceed to pilot.
Ready with conditionsWorkable, with a known constraint to manage.Proceed, with the constraint written into scope.
Not readyA real gap that remediation can close.Fix first. The plan says what and in what order.
BlockedA legal, contractual or architectural obstacle that will not clear soon.Do not build this. Pick a different use case.

A use case is only as ready as its weakest dimension. Strong data does not compensate for a blocked integration, and we do not average the scores to produce a more comfortable number.

How this differs from an AI maturity model

Maturity models benchmark you against an industry percentile and place you on a five stage curve. That is useful for a board narrative and almost useless for a build decision, because knowing you are at stage two tells you nothing about whether the specific project in front of you will work.

An AI readiness assessment is narrower on purpose. It answers a build question about named use cases with a named verdict and a costed remediation path. If you need both, run this first and let the maturity narrative follow from the evidence rather than the other way round.

What it costs and what we need from you

Fixed fee, quoted before the engagement starts and unaffected by what we find. Ten working days elapsed. Your total time commitment is usually six to ten hours: an initial scoping call, four to six interviews of forty five minutes each, and the closing readout.

  • Read access to representative data samples for the candidate use cases.
  • Named contacts who own the relevant data and the relevant process.
  • Whatever documentation exists, including the outdated documentation.
  • Any existing AI policy, data classification policy and security requirements.
  • One hour with whoever signs off on production deployment.

We work under NDA and can operate entirely inside your environment where data cannot leave it. No production write access is required at any point.

Worth knowing

We will tell you not to proceed

A meaningful share of assessments should end with a recommendation to fix data foundations before touching AI. That verdict is in scope and costs nothing extra. An adviser who always finds you ready for the expensive project is not assessing anything.

Process

How the
engagement runs

Every stage produces a defined output, so you always know what is being made and when it lands.

Days 1 to 2

Scoping and access

We agree which use cases are in scope, identify the people who hold the answers, and get read access to representative data. Narrow scope produces sharper findings, so we would rather assess three use cases properly than eight superficially.

Days 3 to 6

Evidence gathering

Structured interviews with data and process owners, hands on inspection of the actual data, review of integration surfaces and existing policy. We test what documentation claims against what the systems contain.

Days 7 to 8

Scoring and gap analysis

Each use case is graded across the five dimensions. Every gap is recorded with a severity, a cause and an estimate of what it takes to close. Remediation work is sequenced so that clearing one item unblocks the next.

Day 9

Draft and challenge

You receive the draft two days before the readout. This is deliberate. Findings get corrected, context gets added, and nobody is surprised in front of their leadership team.

Day 10

Readout and handover

Ninety minute session with the decision makers, followed by handover of the final report, the gap register and the scoring model in editable form.

Deliverables

What you
receive

Everything is handed over in editable formats. Full IP transfers on final payment, including any scoring models, rubrics and templates produced along the way.

01

Scored readiness report

All five dimensions graded per use case, with the evidence behind every score and the rubric used to produce it.

02

Gap register

Every blocker recorded with severity, root cause, estimated effort to close and the dependency chain it sits in.

03

Ranked use case shortlist

Candidates ordered by feasibility against your current state rather than your aspirational state.

04

Sequenced remediation plan

What to fix, in what order, at roughly what cost, arranged so each item unblocks the next.

05

Regulatory classification

EU AI Act and sector exposure per use case, with the obligations that attach and when they bite.

06

Written viability verdict

For each use case: build now, build after remediation, or do not build. Stated plainly, in one line, at the top.

Fit check

Is this the
right engagement?

Worth being direct. AI readiness assessment is a poor use of budget in some situations, and those are listed on the right rather than buried.

Good fit if

  • Leadership has approved AI budget but nobody agrees what to spend it on.
  • A previous AI project stalled and the real cause was never diagnosed.
  • You need an evidence base before a board, investor or regulator conversation.
  • You are about to select a vendor and want to know which constraints rule options out.
  • Several departments are proposing AI projects with no way to compare them.
  • You suspect your data is not as good as the last presentation claimed.

Choose something else if

  • You already have one narrow use case with clean data and a named owner. Go straight to a proof of concept.
  • You need a working prototype for a specific deadline. Assessment will not produce software.
  • The real question is which vendor to pick, not whether to build. Start with vendor selection.
  • You want a maturity score for a board slide. A benchmarking exercise fits that better.
  • Nobody internally is able to act on the findings. Fix ownership first.
Questions

Frequently
asked questions

Marked up with FAQPage schema so these answers can surface directly in search results and inside AI assistant responses.

What is an AI readiness assessment?

It is a structured audit of your data, systems, governance, skills and unit economics, scored against the specific AI use cases you intend to build. Unlike a maturity model, it produces a build or do not build verdict for each named use case, plus a costed plan for closing whatever gaps it finds.

How long does an AI readiness assessment take?

Ten working days from kickoff to final readout. Your own time commitment is usually six to ten hours across a scoping call, four to six interviews and the closing session. Larger scopes take longer, though we would rather narrow the use case list than extend the clock.

How much access do you need to our systems?

Read access to representative data samples and visibility of the systems your candidate use cases would touch. We work under NDA and can operate entirely inside your environment if data cannot leave it. No production write access is needed at any stage.

Can you assess readiness if we have not defined any use cases yet?

Partly. We can grade data, systems and governance in general terms, but the useful findings come from testing against concrete candidates. If you have none, run a use case discovery workshop first. The two together take about four weeks and produce a far sharper result.

What happens if the assessment says we are not ready?

You have saved the cost of a build that would have failed. The remediation plan sets out what to fix, in what order and at roughly what cost. It is written to be usable by anyone, including your internal team or another provider, and nothing in it is dependent on hiring us.

Does this commit us to working with you afterwards?

No. It is a standalone fixed fee engagement. The report, gap register and scoring model transfer to you in full and are deliberately written so another provider could act on them without translation.

Is this the right engagement?

Tell us what you are trying to decide. If a different service fits better, or if you do not need us at all, we will say so.