What should an AI readiness assessment actually include?
20 July 2026
What should an AI readiness assessment actually include?
A serious AI readiness assessment should tell you three things: where AI can genuinely help, what would make it risky or wasteful, and what needs fixing before you spend money on tools or automation. For a UK business, that means checking data protection, security, staff skills, operational processes, governance, supplier contracts, likely costs and measurable value.
What should the assessment answer first?
The first output should be a clear answer to this question: should you use AI here at all? A useful assessment starts with business value, not technology. It should list the workflows where AI could save time, improve quality, reduce risk, increase capacity or create a better customer experience. Then it should rank those opportunities by value, difficulty, risk and time to benefit.
This matters because most businesses do not need a huge AI transformation programme. They need to know which three or four use cases are worth testing first. For many UK SMEs, those will be practical areas such as sales follow-up, customer support triage, proposal writing, internal knowledge search, finance admin, compliance evidence gathering or operations reporting.
The assessment should also identify the cases where AI is a bad idea. If the process is unclear, the data is poor, the decision has a legal effect on people, or staff do not trust the output, adding AI can make the problem worse. The UK government's AI Adoption Research found that only 16% of UK businesses were using AI, while 80% were neither using it nor planning to adopt it. That is a useful reminder: readiness is not about chasing the market. It is about knowing whether your business has a strong enough reason to act.
A good readiness report should therefore include a scored use-case register. Each entry should show the business problem, the people affected, expected benefit, data required, risk level, implementation difficulty, likely cost range and recommended next action. Without that, the assessment is just commentary.
What data and process checks should be included?
Data readiness is usually where optimistic AI plans meet reality. The assessment should check what data exists, where it lives, who owns it, whether it is accurate, whether it can legally be used, and whether the proposed AI system needs access to personal data, confidential commercial data or regulated information.
For each priority use case, the assessor should map the process before recommending tooling. That means documenting the trigger, inputs, decisions, exceptions, hand-offs, systems used, outputs and current pain points. If a process is inconsistent between staff members, AI will not magically standardise it. You usually need to fix the process first, then automate the repeatable parts.
The assessment should include a data inventory at a practical level. You do not need a 400-line enterprise data catalogue for a small business, but you do need to know whether key information sits in Google Drive, Microsoft 365, HubSpot, Xero, Slack, email inboxes, spreadsheets, a CRM, a line-of-business system, or someone's head. You also need to know which records are stale, duplicated, incomplete or mixed with sensitive information.
For generative AI, the assessment should ask whether retrieval is needed. If staff want an AI assistant to answer questions from company documents, you need clean source material, permission controls and a way to keep answers grounded in current documents. If the AI is writing customer messages, you need brand examples, approval rules and a check for factual claims. If it is summarising calls, you need consent, retention rules and access controls.
The practical output should be a readiness table for each use case: data available, data quality, lawful basis concern, integration requirement, human review point and expected clean-up effort. If that table is blank, the assessment has not done its job.
What should it cover on UK GDPR, security and governance?
For a UK business, an AI readiness assessment must cover data protection and security before implementation. This is not box-ticking. If staff are pasting customer records, employee data, contracts or financial details into public tools, the organisation may already have an unmanaged AI risk.
The assessment should review whether each use case involves personal data, special category data, automated decision-making, profiling, biometric data, children's data, employment decisions or customer vulnerability. The ICO's AI guidance points organisations towards AI and data protection guidance, explaining AI-assisted decisions, biometric recognition guidance and an AI data protection risk toolkit. A readiness assessment should not replace legal advice, but it should flag where a Data Protection Impact Assessment, policy update or specialist review is needed.
Security should be just as concrete. The assessment should cover access controls, supplier security, audit logs, retention, model output review, prompt injection risk, data leakage, backup and incident response. The NCSC Guidelines for secure AI system development are written for providers of AI systems, including systems built on third-party tools. Even if you are buying rather than building, the same mindset applies: secure design, secure development, secure deployment, and secure operation.
Governance should be simple enough to use. A good assessment should recommend who approves AI use cases, who owns risk, who reviews vendors, who signs off prompts and knowledge sources, who monitors outputs, and what staff are allowed to do without permission. DSIT's AI Management Essentials tool consultation describes AIME as a self-assessment tool to help organisations assess and implement responsible AI management systems and processes. That is exactly the territory a readiness assessment should cover, but in the context of your actual workflows.
The minimum governance deliverables should be an AI acceptable-use policy, use-case approval workflow, vendor review checklist, data handling rules, human oversight requirements and an escalation route for incidents or bad outputs.
How should it assess people, skills and adoption?
AI readiness is not only technical. Staff behaviour is usually the deciding factor. The assessment should find out who is already using AI, what tools they use, what data they enter, how often they rely on outputs, whether managers know, and whether there is any informal sharing of prompts or automations.
DSIT's AI Adoption Research found that among businesses already using AI, 30% of staff were using AI on average, and 84% reported at least some human input or checking of AI outputs or decisions. Those numbers are useful because they point to two different readiness questions. First, is adoption broad enough to matter? Second, is human oversight real, or just assumed?
A good assessment should include staff interviews or surveys, not just a leadership workshop. Leadership often believes AI use is lower than it is. Staff often believe their tool use is harmless because they are only trying to save time. Both can be true, and both need evidence.
The skills review should separate basic AI literacy, tool-specific skill, process knowledge, data handling, judgement and management capability. Someone can be good at prompting but poor at spotting a privacy problem. Someone can understand compliance but have no idea how to design an AI-assisted workflow. The report should say what training is needed for different groups, not simply recommend one generic AI workshop.
The adoption section should also cover change management. Which teams will resist? Which team has a visible pain point and a willing manager? Which workflow could produce a quick, low-risk win? Which use case needs board approval before anyone touches it? This is where the assessment becomes useful, because it turns AI from an abstract strategy into a sequence of decisions people can act on.
What should the financial section include?
The financial section should be blunt. It should estimate the cost of assessment, pilots, tooling, implementation, training, governance, support and ongoing monitoring. It should also be honest about where the return is likely to show up. Some AI projects reduce hours. Some improve consistency. Some increase speed. Some mainly reduce operational risk. Not every successful AI project increases revenue quickly.
DSIT's research found that 75% of businesses using AI reported improved workforce productivity, but 77% had not yet seen a change in revenue. That is the point many sellers gloss over. Productivity gains can be real without immediately appearing as sales growth. A readiness assessment should therefore define the benefit carefully: hours saved, turnaround time reduced, error rate reduced, customer response time improved, content throughput increased, management visibility improved, or compliance evidence gathered faster.
For UK SMEs, a focused readiness assessment commonly sits somewhere around £2,000 to £7,500 depending on depth, number of teams, workshops, technical review and whether policies or implementation plans are included. A light diagnostic might be cheaper. A larger multi-site review with security, data protection and integration analysis can go well above £10,000. The important thing is not the exact price. It is whether the output helps you avoid spending £20,000 on the wrong tool, or six months trying to automate a broken process.
The report should include a prioritised roadmap with cost bands. For example: a low-risk internal knowledge pilot might cost £3,000 to £10,000 to set up properly. A CRM-integrated sales assistant might sit in the £8,000 to £25,000 range depending on systems and data quality. A regulated decision-support workflow may require legal review, data protection work, auditability and much more testing before implementation.
If the assessment cannot explain what to spend next, what not to spend, and what return to measure, it is unfinished.
What deliverables should you expect at the end?
You should expect practical artefacts, not just a presentation. At minimum, the assessment should produce an executive summary, prioritised use-case list, data and process findings, risk register, governance recommendations, training needs, vendor considerations, costed roadmap and next-step plan.
The risk register should be readable by non-technical leaders. It should name the risk, affected workflow, likelihood, impact, current control, recommended action and owner. It should cover data protection, cyber security, inaccurate outputs, staff over-reliance, supplier lock-in, hallucinations, poor source data, reputational risk, intellectual property concerns and operational failure.
The use-case list should be ranked, not dumped. A good format is: do now, test next, fix first, park for later, do not pursue. That final category matters. A readiness assessment earns trust when it tells you not to do something.
The roadmap should turn recommendations into phases. Phase one might be policy, staff guidance and two low-risk pilots. Phase two might be data clean-up and system integration. Phase three might be a more ambitious automation once evidence exists. Each phase should have success measures, owner, estimated cost, expected time, dependency and review point.
Finally, you should receive a decision session, not just the report by email. The useful part is often the conversation where leadership agrees what to do, what not to do, who owns it and what will be measured. If you want a deeper view of implementation after assessment, our AI implementation timeline guide is a useful next read.
When this does not apply
You do not need a broad AI readiness assessment for every AI decision. If you are choosing between two simple meeting transcription tools for internal use, you may only need a light vendor, privacy and security check. If you are a solo consultant using AI for drafting your own notes, a policy and workflow review may be enough.
You should also avoid readiness assessments that are really sales funnels in disguise. If the provider already knows which platform you should buy before they have seen your data, processes and risks, the assessment is not independent. If the output is only a score out of five with no implementation detail, it will not help your team make better decisions.
This does not apply if your main issue is not AI readiness. If the business has no clear process ownership, poor basic cyber hygiene, no CRM discipline, unmanaged file storage or weak data protection practice, the honest recommendation may be to fix those foundations first. That is still useful. Sometimes the best AI advice is to pause, clean up the basics and come back when the business can absorb the change.
Is This Right For You?
An AI readiness assessment is right for you if you are considering AI tools, automation, agents or custom systems and you need to know where to start without wasting budget. It is especially useful for UK SMEs with messy processes, sensitive customer data, manual admin, multiple SaaS tools, or staff already experimenting with ChatGPT, Copilot, Gemini or Claude without clear rules.
It is not right if you only want a one-hour inspiration workshop, a generic AI trends presentation, or a pre-written maturity score. If you already have an experienced internal AI governance team, a documented data inventory, security review process, approved use-case pipeline and board-level AI risk reporting, you probably need a focused independent review rather than a broad readiness assessment.
Frequently Asked Questions
How long should an AI readiness assessment take?
A focused SME assessment usually takes one to three weeks. A deeper review involving several departments, sensitive data, technical architecture and governance can take four to eight weeks.
Who should be involved in the assessment?
Include leadership, operations, IT or managed service providers, data protection responsibility, finance, and the teams doing the work. Do not only interview directors, because front-line staff often know where AI is already being used.
Should an assessment include a Data Protection Impact Assessment?
Not always. It should identify whether a DPIA is likely to be needed. If a use case involves personal data, automated decision-making, profiling, vulnerable people, employment decisions or sensitive information, a DPIA may be required before implementation.
Is an AI readiness assessment the same as an AI audit?
Not exactly. An audit usually reviews current use and risk. A readiness assessment looks at whether the business is prepared to adopt or scale AI, including opportunities, blockers, costs, skills and governance.
Should the assessment recommend specific AI tools?
It can, but tool recommendations should come after use-case, data, risk and integration analysis. If a provider starts with the tool, they may be solving the wrong problem.
What is a red flag in an AI readiness assessment?
Red flags include no discussion of UK GDPR, no staff interviews, no costed roadmap, no risk register, no security review, and no willingness to say that a use case should not proceed.
Can a small business do this internally?
Yes, for low-risk use cases. Use a simple checklist covering business value, data, process, privacy, security, staff capability, approval and measurement. Bring in external help when personal data, integrations, customer impact or significant spend are involved.