An AI readiness assessment answers a single question: what can this business safely do with AI in the next ninety days? It is deliberately unglamorous — a scorecard, not a strategy — and it is the step most often skipped, which is why so many AI programs begin with a tool purchase and end without a workflow.
This guide covers the five dimensions to assess, the questions that reveal the real answer, how to score the result, and what to do with it. It is the companion to How to Adopt AI in a Small Business.
Readiness is not enthusiasm. It is whether the data, the process, the people and the rules can support a workflow this quarter.
Why assess before you choose
Choosing a use case before assessing readiness is how businesses end up automating on top of a problem. If the data is fragmented, the workflow will surface the fragments. If nobody owns output quality today, they will not own it with AI involved. If there is no policy, the first useful tool becomes the first unmanaged risk.
The assessment takes an afternoon and produces three outputs: the use cases that are safe now, the gaps that must be closed first, and the order in which to proceed. That is a better return than any tool comparison.
The five dimensions
Readiness has five dimensions, each scored independently.
| Dimension | The question | What a low score means |
|---|---|---|
| Data | Can you name the source of the figures and text your work depends on? | AI will amplify existing data problems |
| Process | Is the work you want to change documented? | You cannot design or verify a process you cannot describe |
| People | Is someone accountable for the quality of output today? | Accountability becomes less clear, not more |
| Policy | Do you know which tools are approved and what data is permitted? | You have unmanaged exposure today |
| Measurement | Can you quantify the current cost of the work? | You will not be able to demonstrate a return |
The dimensions are weighted equally, because a weak dimension caps what the others can achieve.
The questions that reveal the answer
Scorecards fail when they ask for opinions. These questions ask for facts.
Data
- For your most important recurring report or document, can you name the source of each headline figure?
- Are there two versions of any key metric in circulation?
- Where a figure changed last quarter, could you say why?
Process
- Could a new team member follow your current process from a written description?
- How long does the task take now, end to end, including review?
- Where does it most often go wrong?
People
- Who is accountable if a figure in that output is wrong?
- Is there a reviewer other than the preparer?
- Does anyone currently own tool selection?
Policy
- Which AI tools are approved for use on company work?
- Is there a written rule about what data may be entered into a tool?
- Has anyone been asked to confirm they read it?
Measurement
- How many hours per cycle does the task consume?
- What does an error cost in rework or reputation?
- What would count as a successful outcome in ninety days?
The pattern in the answers usually identifies the gap immediately. In EOG’s synthesis of small-business research, 44% of small businesses have AI acceptable-use policies (GTIA, 2026) — meaning the majority score low on the policy dimension while already using AI.
Scoring and interpreting the result
Score each dimension from 1 (weak) to 5 (strong). The total is less informative than the pattern.
- Any dimension at 1 or 2 caps the program. Close that gap before scaling, regardless of the total.
- A total of 18–25: proceed with a contained use case immediately.
- 13–17: proceed, but schedule the policy and data work in parallel with the pilot.
- 8–12: fix ownership and data first; the pilot will fail for reasons unrelated to AI.
- Below 8: the business has a reporting and process problem that AI will expose rather than solve.
Two interpretations matter most. A low policy score is urgent and cheap to fix. A low data score is a program risk and requires either a source fix or a use case that does not depend on the unreliable data. See AI Governance for Small Business.
From assessment to a starting point
The assessment output should be a short list, not a strategy document.
- The gap to close first, with an owner and a date.
- The use case to attempt now, chosen from those the gaps do not block.
- The baseline to measure, captured before anything changes.
- The rules to publish, so the pilot starts inside a policy rather than outside one.
That output is deliberately small. Its purpose is to make the first ninety days produce evidence rather than a deck. See Choosing Your First AI Use Case and A 90-Day AI Adoption Plan.
A worked scoring example
A twelve-person firm scores itself before adopting AI.
- Data: 2. Two versions of the monthly revenue figure are in circulation, and nobody could say last quarter why the margin moved. The source problem is real.
- Process: 4. The reporting workflow is documented, and a new joiner can follow it.
- People: 4. The finance lead owns the numbers; the reports are reviewed before issue.
- Policy: 1. No approved-tool list, no data rule, and staff are already using consumer tools.
- Measurement: 3. The cycle time is known, but the error cost is not.
The total is 14, which in isolation reads as “proceed with caution”. The pattern says something more useful: the policy gap is urgent and cheap, and the data gap blocks any use case that depends on the revenue figure.
The resulting plan is small and specific: publish a one-page policy this week, pick a use case that does not depend on the disputed metric — drafting the narrative commentary from frozen figures, for example — and fix the revenue source in parallel. The firm does not need a strategy document. It needs a policy and a narrower first use case.
The most common readiness gap
In small businesses, two gaps recur more than the others.
- Policy. The business is already using AI with no written position. It is the cheapest gap to close and the most exposed to leave open. A one-page document closes most of it.
- Data. The figures used in reporting are not traceable to an agreed source. This is the gap that most often delays an AI program, because it is a fix rather than a decision.
The encouraging part is that both are addressable within weeks. The discouraging part is that a business which skips them will run a pilot that fails for reasons unrelated to the tool — and conclude the wrong lesson.
See Data Quality for Reporting for the data-side fix.
Common mistakes
- Assessing enthusiasm rather than readiness. The most willing team is not always the safest starting point.
- Scoring on opinion. “We think our data is fine” is not a score.
- Ignoring the policy dimension. It is the cheapest gap to close and the most expensive to leave.
- Treating the assessment as a one-off. Re-score after each use case; readiness changes.
- Producing a strategy instead of a shortlist. The output should be actionable this quarter.
Frequently asked questions
What is an AI readiness assessment?
A structured evaluation of whether a business can safely adopt a given AI use case now, scored across data, process, people, policy and measurement.
How long should an AI readiness assessment take?
An afternoon for a small business, if the questions are answered with facts rather than opinions. Re-scoring after the first use case takes an hour.
What are the dimensions of AI readiness?
Data, process, people, policy and measurement. A weak score in any one caps what the others can deliver, which is why they are assessed separately.
What if we score low on data?
Choose a use case that does not depend on the unreliable data, and fix the source in parallel. Do not automate on top of a known data problem.
Who should complete the assessment?
The person accountable for the work being assessed, with input from finance or operations on the measurement dimension. A committee produces a softened result.
Should we re-run the assessment?
Yes — after the first use case, and before each subsequent one. Readiness is a moving picture, and the second use case usually faces a higher bar rather than a lower one.
Can readiness be improved quickly?
Two dimensions can. Policy is a document and a decision, which is an afternoon’s work. Process is documentation, which follows the workflow you are about to change. Data takes longer, and it is the usual reason a program takes a quarter rather than a month.
What if the answers are contested?
Then you have found the gap. Where two people give different answers about the source of a figure or the owner of an output, that disagreement is the finding, and it should be resolved before the pilot rather than during it.
Next step
Score the five dimensions honestly for one workflow, close the weakest gap, and pick a use case the gaps do not block. See Choosing Your First AI Use Case next, or download the AI Readiness Checklist to run it today. To have the assessment run with your team, book an AI adoption call.
Sources
- GTIA (2026): 44% of small businesses have AI acceptable-use policies; 24% cite data security and compliance as a top AI barrier.
Figures are cited from their sources and dated. Where a source is a vendor survey, the sample size is stated where published.