What Is an AI Readiness Assessment and What Does It Involve?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for What Is an AI Readiness Assessment and What Does It Involve?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for What Is an AI Readiness Assessment and What Does It Involve?

An AI readiness assessment is a structured check of whether your business can use AI safely and profitably right now, and what to fix first. It involves reviewing your processes, data, software and licences, security settings, staff skills and policies, then scoring each area and producing a short, prioritised list of first projects and gaps.

Readiness is always readiness for something. A business can be ready to use AI for drafting product descriptions and nowhere near ready to let it answer customers about refunds. A useful assessment therefore names specific jobs and grades readiness for each, instead of handing you one overall score out of 100 that nobody can act on.

Follow me on Instagram@sagnikteaches

The six areas an assessment examines

Frameworks differ in wording, but almost all of them look at the same six things. For each one, here is what gets checked and the kind of finding that holds a small business back.

Connect on LinkedInSagnik Bhattacharya
AreaWhat gets checkedA typical red flag
ProcessesWhich jobs are repeated, how often, how long they take, whether anyone has written the steps downThe job exists only in one person's head
DataWhere the information each job needs lives, how complete and consistent it is, who can reach itThree versions of the price list, none marked current
Tools and licencesWhich software you use, which AI features it already includes, who holds the admin logins, whose name accounts are inThe admin login belongs to someone who left
Security and permissionsMulti-factor sign-in, shared logins, file-sharing settings, what an AI assistant could see on someone's behalfFolders shared with "anyone with the link" that hold customer or salary data
People and skillsWho already uses AI (officially or not), confidence levels, who could own a projectStaff pasting customer emails into personal free accounts
Rules and policyAn AI use policy, data-protection duties, what customers are told when AI is involvedNo written rule on what may be pasted into an AI tool

Many assessments add a seventh line for budget and ownership: who will pay for and look after whatever gets built. A project with no owner is not ready, however good the data.

Subscribe on YouTube@codingliquids

The security row catches owners out most. AI assistants built into office software work on behalf of the signed-in user, so they can find anything that person can open. If a folder of staff contracts is shared with the whole company by accident, nobody notices while finding it needs a search in the right place; an assistant that answers "summarise what we pay the warehouse team" makes it visible in seconds. Cleaning up sharing settings is often the first practical fix, and for Microsoft 365 users cleaning up SharePoint permissions before turning on Copilot walks through it.

How an assessment runs, from first call to report

For a business of 5 to 30 people, a provider-led assessment usually runs over one to three weeks of calendar time, with most of the effort on the assessor's side. The stages:

  1. A short questionnaire about your tools, team and goals, so interviews don't waste time on basics.
  2. Interviews of 30 to 45 minutes with three to six people who do the repeated work, not only the owner. The person who answers the customer emails knows where the time really goes.
  3. A systems inventory: every tool, its plan, its admin, whether it has AI features switched on or available.
  4. Data sampling: pulling 20 to 50 real records for the jobs under consideration and checking how complete they are.
  5. A permissions and sign-in check: multi-factor sign-in, shared logins, sharing settings on the main drives.
  6. A quick trial of one or two candidate jobs on real examples, to test that the scores are right, not just plausible.
  7. Scoring, a written report and a readout meeting with a prioritised action list.

Good interview questions are concrete. Five an assessor might put to whoever prices commissions at a small furniture maker:

  • Walk me through the last three enquiries you priced. Where did each number come from?
  • Which questions do you ask every customer, and which only sometimes?
  • Where do you look things up, and how often is that source out of date?
  • What would you never want software to send without you seeing it first?
  • If you were away for two weeks, who could price a dining table, and how?

At that furniture maker, the answers showed the price guide existed only in the owner's head: every quote started from memory of similar past jobs. That single finding moved "AI drafts quotes" from "ready after fixes" to "not yet" and put "write a one-page price guide" at the top of the action list, because no AI can apply a pricing rule nobody has written down.

Your side typically gives an hour per interviewee, an hour or two gathering access and samples, and the readout meeting. Fees vary widely by provider and depth, so they're covered separately in what an AI readiness assessment costs.

A scored assessment for an e-commerce homeware brand

To see what a finished assessment contains, consider a nine-person online homeware brand selling around 1,200 products (cushions, ceramics, lighting) through a Shopify store, with Google Workspace Business Standard for email and documents and a separate helpdesk for customer service. The owner wanted to know whether AI could help with product descriptions, customer service and supplier ordering. The scorecard, graded 1 (not ready) to 5 (ready now):

AreaScoreEvidence foundFix first
Processes3Customer service steps written down; product listing done by one person from memoryRecord the listing steps while the person does five listings
Data2Product details split across the store, a supplier spreadsheet and a Google Sheet; 18% of products missing material or care informationFill the gaps for the 200 best-selling products first
Tools and licences4Gemini already included across Gmail, Docs and Sheets on the Workspace plan; store and helpdesk both have admin access on fileSwitch on and try the included features before buying anything
Security2Multi-factor sign-in off for 4 of 9 staff; two shared logins; supplier price lists in folders open to anyone with the linkTurn on multi-factor sign-in; close the open links
People35 of 9 staff already use free AI chat tools on personal accounts, two of them for customer emailsProvide a business account and a one-page rule on customer data
Policy1No AI use policy; returns wording differs between the website, the helpdesk macros and the packing slipWrite a one-page policy; make the returns wording match everywhere

Readiness per job, which is the part the owner acted on:

  • Product descriptions: ready in about two weeks, once the top 200 products have complete details. Low risk, because a person reviews every listing before it's published.
  • Drafted customer-service replies: ready after the policy and business accounts are in place, around three weeks, with staff approving every draft.
  • An AI agent answering customers on its own: not ready. Shopify Inbox now includes a free AI agent that replies to customers by itself on the Basic plan and above (Shopify's help pages list the other requirements), and it can use web search as a secondary source. With three different versions of the returns policy in circulation, it would be answering from contradictory material. Fix the wording first, then test the agent on the brand's own policy questions before letting it loose.
  • Supplier reorder suggestions: not ready. Stock data is updated weekly by hand and is often out of date; any suggestions would be built on sand.

The report's action list had five items, each with an owner and a date: multi-factor sign-in (IT-minded staff member, this week), close open sharing links (owner, this week), one-page AI policy (owner, two weeks), complete top-200 product data (listings lead, two weeks), unify returns wording (customer service lead, two weeks). None of the five needed new software.

What vendor readiness reports check, and what they skip

Software vendors offer their own readiness tools, and they are useful within limits. Microsoft's Copilot readiness report, found in the Microsoft 365 admin centre under Reports, then Usage, then Microsoft Copilot, shows how many users hold the prerequisite licences, how many are on an update channel that supports Copilot (Current Channel or Monthly Enterprise Channel), and how many Copilot licences are assigned or available. For customers who buy Copilot licences, it also flags the top 25% of unlicensed users by usage of apps such as Outlook and Teams as suggested candidates.

That is technical eligibility. It says nothing about whether the finance folder is shared too widely, whether your team knows what not to ask, or whether any job is worth automating. Microsoft's own set-up guidance lists wider readiness work alongside licences: pilot testing with a small group, a communication plan, reviewing sign-in policies and using SharePoint's management tools to prevent oversharing. A full readiness assessment covers the business side the licence report can't see.

Here is how that gap can show up. A catering company assigned Copilot licences to six staff because the report showed all six as eligible. Within a week, an events coordinator asked Copilot to "list upcoming weddings with special requirements" and got back guests' medical notes from a client folder that had been shared with the whole company years earlier. Nothing had been hacked; the assistant simply found what the coordinator's account could already open. A permissions check would have caught it before any licence was bought.

Doing it yourself, hiring an assessor, or using a vendor's check

RouteWhat you getBest forWatch for
Self-assessment with a checklistA quick score and a list of obvious gapsVery small teams; a first look before paying anyoneScoring your own homework kindly
Independent assessor or consultantInterviews, evidence, a trial on real data, a prioritised planBusinesses about to spend real money on tools or buildsReports heavy on frameworks and light on evidence
Vendor or reseller's free assessmentTechnical prerequisites for that vendor's productChecking licences and settings before a specific purchaseRecommendations that always end in that vendor's product

A self-assessment is a sensible first step whatever you decide next; the 20-minute AI readiness checklist gives you a scored starting point. For a very small business the self-check may be all you need. A two-truck food business, for instance, can cover all six areas in an evening: its processes are the enquiry inbox and the weekly social posts, its data is a menu and an allergen sheet, and its biggest readiness gap is usually one rule, that allergen answers always come from the signed-off sheet and never from an AI draft.

Running a first-pass self-assessment with an AI assistant

An AI assistant can structure a self-assessment, provided you make it ask for evidence. Set it up as an interview:

Act as an AI readiness assessor for a [type of business] with
[number] staff. Interview me one question at a time about six
areas: processes, data, tools and licences, security and
permissions, people and skills, rules and policy.

For each area, ask for evidence (numbers, examples, settings),
not opinions. After all six, score each area 1-5 and quote the
evidence behind each score. If I gave no evidence for an area,
score it "unknown", not a number. Then list the three fixes that
would most improve readiness for these jobs: [list 2-3 jobs].

Two answers from a subscription box company's session show the risk (illustrative):

"Data: 4/5. You described your subscriber data as 'pretty clean and all in one system'. Security: 3/5. You mentioned staff have their own logins."

Both scores need fixing. "Pretty clean" is an opinion, and the prompt said to score opinions as unknown; when the owner checked, 7% of active subscribers had no delivery phone number and the skip history lived partly in a spreadsheet. And "own logins" says nothing about multi-factor sign-in or sharing settings. The fix is to answer again with numbers: how many records you checked, how many were incomplete, which settings you looked at. For the data area specifically, the data clean-up checklist tells you what to count.

Misreadings of what "ready" means

  • "We need perfect data before we start." You need adequate data for the first job, not all jobs. The homeware brand fixed 200 products, not 1,200.
  • "Ready means we've bought the licences." Licences are one row of six. The catering company above was licensed and not ready.
  • "A good score means go ahead with everything." Scores are per job. Being ready for drafts with human review says little about readiness for AI that acts on its own.
  • "It's a one-off exercise." Readiness decays. New staff join, folders get shared, vendors change defaults. Re-check the security and policy rows at least yearly and whenever you add a major tool.
  • "An assessment and an audit are the same thing." They overlap, but an audit usually examines AI already in use or hunts for opportunities, while readiness asks whether you can start. AI audit versus readiness assessment sets out the difference.

If you sell to customers in the EU, one more reason the people row matters: the EU AI Act's AI-literacy duty has applied since 2 February 2025, and since the July 2026 changes it asks organisations using AI to take measures supporting their staff's AI literacy rather than guarantee a particular level. A readiness assessment that records who has been shown what is a practical start on that duty; for anything beyond the basics, ask a qualified adviser.

What the report should hand you

Whoever does the assessment, including you, the output should be short and usable. Check for:

  • A score for each area with the evidence behind it, not adjectives
  • Readiness graded per candidate job, with "ready now", "ready after fixes" or "not yet"
  • No more than five to eight actions, each with an owner, a date and an estimate of effort
  • The list of tools and AI features you already have, and which to switch on first
  • Any security or policy issue that should be fixed regardless of AI
  • A suggested date to re-check

If a report runs to 40 pages of maturity models and ends by recommending one product, it has assessed the seller's pipeline more than your readiness. A good one fits on a few pages and changes what you do next week.

Further reads

Sources: Microsoft Learn, Microsoft Copilot readiness report and Copilot set-up guidance; Google Workspace pricing and Gemini help pages; Shopify help on Shopify Inbox.

Want an outside view of how ready you are?

On a 1:1 call we can go through your tools, data and team, grade your readiness for the specific jobs you have in mind, and agree the first fixes.

Book a 1:1 call with me