AI Readiness Assessment: A Practical Checklist for Leaders

A scored AI readiness assessment checklist covering strategy, data, technology, people and governance, with a simple rubric and guidance on what to fix first.

AI Readiness Assessment: A Practical Checklist for Leaders: Sunday Labs

An AI readiness assessment is a structured review of whether your organisation can build, deploy and run AI that delivers measurable value. It scores six areas: strategy, data, technology, people, governance and operations. The output is a prioritised list of gaps to close and use cases you can start now, not a generic maturity score.

Done well, it takes a few weeks and saves months of pilots that stall for predictable reasons. This article gives you a checklist you can run internally, a simple scoring rubric and guidance on how to turn the results into a plan.

Why run an AI readiness assessment at all

Most AI initiatives that fail do not fail because the model was wrong. They fail because the data was not accessible, nobody owned the outcome, security review took six months, or the system was never integrated into the workflow people actually use.

An assessment surfaces those blockers before you commit budget. It also forces a useful conversation between business, technology and risk teams, who often hold very different assumptions about what AI will do and what it will cost.

It is especially worth doing if you have run one or two pilots that went nowhere, if leadership is asking for an "AI strategy" without a clear problem to solve, or if you are about to choose an AI consulting partner and want to brief them properly.

The six dimensions to assess

Keep the assessment grounded. For each dimension, look for evidence (documents, systems, named owners), not opinions.

Dimension What you are really asking Typical evidence
Strategy Do we know which problems AI should solve and how we will measure success? Prioritised use cases, business owners, baselines
Data Can we access clean, relevant, permitted data for those use cases? Data inventory, quality checks, access paths, consent records
Technology Can our platforms support building, deploying and monitoring AI? Cloud setup, pipelines, CI/CD, observability
People Do we have the skills and the time to build and adopt it? Team roles, capacity, training plans
Governance Can we manage risk, privacy and accountability? Policies, review processes, model inventory
Operations Can we run AI systems reliably once they are live? Support model, incident process, cost tracking

The AI readiness assessment checklist

Score each item from 1 to 4 using the rubric in the next section. Be honest: a score of 2 with a plan is more useful than an inflated 4.

Strategy

  1. We have a short list of AI use cases tied to specific business outcomes, such as reduced handling time or improved forecast accuracy.
  2. Each priority use case has a named business owner who will be accountable for adoption.
  3. We have a current baseline for the metric each use case is meant to improve.
  4. Leadership has agreed a realistic budget that covers running costs, not just the build.

Data

  1. We know where the data for each priority use case lives and who owns it.
  2. That data can be accessed programmatically, not only through manual exports.
  3. We have checked data quality: completeness, duplication, freshness and labelling.
  4. We know whether we are permitted to use the data for this purpose, including personal data consent.
  5. Unstructured content (documents, emails, call notes) is stored somewhere searchable and permissioned.

Technology

  1. We have a cloud or on-premise environment where AI workloads can run securely.
  2. Data pipelines are automated and monitored rather than maintained by hand.
  3. We have CI/CD and environment separation (development, staging, production).
  4. Core systems expose APIs so AI outputs can flow back into daily workflows.

People

  1. We have, or can access, data engineering, ML or GenAI engineering and product skills.
  2. The people who will use the system have been involved in defining it.
  3. Teams have time allocated to the programme rather than squeezing it around day jobs.

Governance

  1. We have a policy on acceptable AI use, including which external AI services staff may use.
  2. There is a review process for new AI use cases covering privacy, security and fairness.
  3. We keep an inventory of AI models and applications in use, with owners.
  4. We understand our obligations under relevant regulation, such as the DPDP Act 2023 in India and any sector rules that apply to us.

Operations

  1. There is a clear owner for running each AI system after launch.
  2. We can monitor output quality, latency, errors and cost in production.
  3. We have an incident process that covers AI-specific failures, such as incorrect or harmful outputs.
  4. Someone reviews cloud and model usage costs every month.

On item 20: this is general information, not legal advice. Involve your legal and compliance teams in interpreting what applies to your organisation.

A simple scoring rubric

Use a four-point scale. Avoid a five-point scale, because people default to the middle.

Score Meaning Example (data access)
1 Not in place and no plan Data sits in spreadsheets on individual laptops
2 Partly in place or planned Data is in a central database, but access needs manual approval each time
3 In place for some use cases Governed access exists for core systems, but not documents or third-party data
4 In place, working and owned Automated, permissioned access with monitoring and a named owner

Average the scores within each dimension. As a rough guide, a dimension averaging below 2 is a blocker for most production use cases. Between 2 and 3, you can usually proceed with a focused pilot while fixing gaps in parallel. Above 3, you are ready to scale.

Do not average across all six dimensions into one headline number. A strong technology score cannot compensate for a data dimension that scores 1.

How to run the assessment in four steps

  1. Pick two or three candidate use cases first. Readiness is always relative to something. Assessing "our readiness for AI" in the abstract produces vague answers. Assessing readiness for, say, automated invoice matching produces specific ones.
  2. Interview and gather evidence (about one to two weeks). Speak to business owners, data owners, IT, security, compliance and a handful of end users. Ask to see systems and documents rather than accepting descriptions.
  3. Score and validate. Score each checklist item, then play the scores back to stakeholders. Disagreements are useful: they usually reveal hidden dependencies.
  4. Build the action plan. For each blocker, name an owner, a fix and a date. Then decide which use case can start now and which must wait.

For a mid-size organisation, the whole exercise typically takes two to four weeks, depending on how many teams are involved and how quickly people can make time.

Common gaps and what to do about them

A few patterns come up repeatedly in our experience.

Data is there but not reachable

The data exists, but it lives in a legacy system with no API, or access requires a ticket to another team. The fix is often a modest data engineering project: a governed pipeline into a central platform. This is less exciting than a model but more valuable.

No business owner

IT is enthusiastic, but no business leader has agreed to own the outcome. Pause until someone does. A system without an owner will not be adopted, however good it is.

Governance by blanket ban

Some organisations respond to AI risk by blocking all external AI services. Staff then use personal accounts anyway. A better approach is a clear policy with approved tools and a lightweight review path for new use cases.

Nobody owns the run

Pilots are built by a project team that disbands after launch. Plan the operating model early, whether that is an internal platform team or a managed service covering monitoring, support and cost control.

Turning results into a roadmap

Group your findings into three horizons. First, what you can start now: use cases where readiness is already adequate. Second, what needs foundation work first: typically data access, platform or governance fixes that unblock several use cases at once. Third, what to revisit later: ideas that depend on capabilities you do not yet have.

Attach an indicative budget to each horizon. If you need help estimating it, our guide to AI implementation cost explains the main cost drivers. Revisit the assessment every six to twelve months, because readiness changes as you build.

Frequently asked questions

What is an AI readiness assessment?

It is a structured review of whether your organisation has the strategy, data, technology, skills, governance and operational capability to deliver value from AI. It produces a list of gaps, their priority and the use cases you can start with now.

How long does an AI readiness assessment take?

For a mid-size organisation, two to four weeks is typical when it is focused on a small number of candidate use cases. Larger or more regulated organisations may need longer because more stakeholders and systems are involved.

Can we do an AI readiness assessment ourselves?

Yes, and the checklist above is designed for that. An external reviewer can help by challenging optimistic scores and bringing patterns from other organisations, but internal ownership of the findings matters more than who runs the exercise.

What comes after an AI readiness assessment?

Usually a short roadmap with two or three prioritised use cases, a list of foundation fixes and a budget. The next step is often a focused pilot on the most ready use case, run in parallel with data or platform work.

Is there a standard AI readiness framework?

Several frameworks exist from vendors, consultancies and industry bodies, and they broadly cover the same ground. The specific framework matters less than assessing against real use cases and gathering evidence rather than opinions.

How Sunday Labs can help

Sunday Labs runs focused AI readiness assessments tied to real use cases, not generic maturity scores. Every engagement is led personally by our founder, with senior engineers who have built data platforms and production AI systems reviewing your data, architecture and operating model directly. You get a clear, prioritised plan you can act on with or without us. If that would be useful, start a conversation.

Share LinkedIn X Email

Want this working in your business?

Talk to a founder, not a sales team. We reply within one business day.