SHORT ANSWER
An AI readiness assessment scores your organisation from 1 to 4 on six dimensions: strategy and use cases, data quality and access, platform, governance and security, skills, and operating model. A total below 12 out of 24 usually means you should fix data access and governance before funding AI projects. A focused assessment takes two to four weeks and ends with a ranked use-case backlog.
Your leadership wants AI results, and you have a folder of demos that never reached production. An AI readiness assessment tells you whether your organisation can move AI from demos into daily use, and what to fix first if it can’t. It rates six dimensions on a simple 1 to 4 scale and gives you a score, a gap list and a short, ranked backlog of use cases worth funding.
Use the checklist below for a self-assessment or as the structure for an external review. Answer honestly. A low first score is a normal starting point, not a verdict.
1. Strategy and use cases
Is there a named executive sponsor with a budget for AI, not only interest?
Do you have a written list of candidate use cases, each with an owner, a baseline metric and an expected value?
Have use cases been ranked by value and feasibility, rather than by who asked loudest?
Is there a clear rule for when to buy a product, use a copilot or build a custom solution?
Are success criteria agreed before a pilot starts (for example, 30 percent less handling time, or 90 percent answer accuracy on a test set)?
2. Data quality and access
Can you name the owner of each dataset the top three use cases depend on?
Are key business terms (customer, order, active user, margin) defined once and used consistently? A semantic layer helps here.
Is document content (policies, contracts, manuals) stored somewhere searchable, with permissions that can be enforced at query time?
Do you measure data quality (completeness, freshness, duplicates) for critical tables?
Can a new project get governed access to data in days rather than months?
3. Platform
Do you have a central data platform, such as a data lakehouse, rather than dozens of disconnected extracts?
Is there an approved way to call large language models (enterprise agreements, private endpoints, data residency settings)?
Can you deploy, version and monitor models and prompts through a pipeline?
Are there logging and cost controls for AI workloads, including token usage per application?
4. Governance and security
Is there an AI policy that says which data may be sent to which models?
Is there an inventory of AI systems in use, including tools employees adopted on their own?
Have you classified use cases by risk, for example against the EU AI Act categories?
Do security teams test for AI-specific risks such as prompt injection and data leakage?
Is there a process to review model outputs for accuracy and bias before and after launch?
This checklist is general information, not legal advice. Confirm regulatory obligations with your legal or compliance team.
5. Skills
Do you have, or can you access, data engineers, ML or AI engineers and a product owner for each use case?
Do business teams understand what current AI can and cannot do reliably?
Is there a plan for training end users, not only developers?
6. Operating model
Is it clear who owns an AI system after launch (support, retraining, cost)?
Is there a central team or centre of excellence that sets standards while business units deliver?
Is there a stage gate from proof of concept to production, with budget attached? See from AI proof of concept to production.
Do you track value delivered after launch, not only projects started?
How do you score your AI readiness?
Give each dimension a score from 1 to 4 using the descriptions below, then add them up for a total out of 24.
Dimension | 1: Initial | 2: Developing | 3: Established | 4: Scaled |
|---|---|---|---|---|
Strategy and use cases | Ad hoc ideas | List of use cases, no ranking | Ranked backlog with owners and metrics | Portfolio managed with value tracking |
Data quality and access | Data in silos, no owners | Some owners, manual access | Governed access for key domains | Self-service, measured quality |
Platform | Local scripts and extracts | Pilot environment | Shared platform with CI/CD | Platform with monitoring and cost controls |
Governance and security | No AI policy | Policy drafted | Policy, inventory and risk review | Continuous testing and audit trail |
Skills | No AI skills in house | A few enthusiasts | Core team plus partners | Skills across business and IT |
Operating model | No owner after launch | Project-based | Clear ownership and stage gates | Product teams run AI systems |
Total score | What it usually means | Typical next step |
|---|---|---|
6 to 11 | Foundations missing | Fix data access and governance, then run one low-risk pilot |
12 to 17 | Ready for targeted pilots | Fund two or three use cases with clear metrics and a production path |
18 to 24 | Ready to scale | Standardise the platform, reuse components, manage AI as a portfolio |
What we see in delivery: agree the scope before you build
On a supply chain analytics proof of concept for a global consumer goods company, we started with a three-day Lean Inception workshop with the client’s team. Both sides left with a written list of requirements and a four-month plan. Because scope and success criteria were agreed up front, the team delivered in three months, and the proof of concept ran queries 10x faster, and more in some cases, than the software it was meant to replace.
That project wasn’t an AI project, but the readiness lesson carries over. In our experience, pilots stall when nobody agreed what success looks like before the build started. Write the baseline metric and the target down first.
What should you fix first?
The lowest score isn’t always the first thing to fix. Start with the gaps that block your highest-value use case. In our experience, the order is usually:
Data access for the first use cases. Name owners, document definitions and set up governed access for the two or three datasets that matter.
A basic AI policy and inventory. Decide which data can go to which models and list the AI tools already in use.
One production-grade pilot. Pick a use case with a measurable baseline, a willing business owner and data you can already reach. Plan it for 8 to 12 weeks.
Evaluation and monitoring. Build a test set and track accuracy, latency and cost from day one. The LLM evaluation guide covers how.
Ownership after launch. Agree who runs, pays for and improves the system before it goes live.
Skills gaps usually close fastest when an internal team pairs with an experienced partner for the first one or two projects and then takes over ownership.
How RUBICON helps with AI readiness
Our architects run readiness assessments that combine stakeholder interviews, data and platform checks, and a Lean Inception or Design Sprint workshop to agree the first use case. You get a scored report, a ranked backlog and a roadmap your team can act on, plus a partner for the first build through our AI and machine learning services if you want one.
We’re about 55 people, 40+ engineers, ISO 27001:2022 certified, a Microsoft Solutions Partner for Cloud & AI Platforms and a Databricks Partner. If you’re deciding which AI use case to fund first, we can score your readiness with you.
Frequently asked questions
What is an AI readiness assessment?
It's a structured review of whether your organisation can build, run and govern AI systems. It looks at strategy, data, platform, governance, skills and operating model, scores each area and produces a gap list plus a ranked set of use cases. The point is to decide where AI investment will pay off and what you need to fix first.
How long does an AI readiness assessment take?
A focused assessment for one business unit usually takes two to four weeks. That's one week of interviews and document review, one to two weeks of data and platform checks, and a final week to score, rank use cases and agree a roadmap. Group-wide assessments across several divisions can take six to eight weeks.
What is the most common gap in AI readiness?
Data access. Many companies have the data they need, but it sits in systems with no documented owner, inconsistent definitions or no governed way for an AI system to query it. Fixing access, ownership and quality for the top two or three use cases usually unblocks more than any choice of model.
Do we need a data platform before starting with AI?
Not a complete one, but you need a governed path to the data your first use cases require. A pilot can start with a small, well-defined dataset. Scaling beyond pilots without a platform (a lakehouse, a catalogue and access controls) leads to duplicated pipelines, security exceptions and results nobody trusts.
Related case study

Real Time Operations Analytics: A Proof of Concept
RUBICON Develops a Proof of Concept (POC) for a Custom Real-Time Operation Analytics Supply Chain Management (SCM) Platform
More resources
