FreeFind your cybersecurity gaps with a free GAPZe assessmentStart now

AI

AI Readiness Assessment: Find the Gaps Before You Buy AI Tools

Isometric illustration of an AI chip on a red pedestal, with steps and data blocks leading up to it, in Anvay's red and stone colours

An AI readiness assessment checks whether your organisation’s strategy, data, technology, people, governance and risk controls can support AI safely, before money goes into tools and licences. It tells you which use cases are worth pursuing now, which gaps would sink them, and who owns the fix. The practical next step is simple: build an inventory of the AI already in use and score it against six readiness dimensions.

TL;DR

  • Start with an AI inventory in the first week or two: ask every team which AI tools, features and browser plug-ins they already use. Shadow AI is usually the first finding.
  • Assess six dimensions – strategy and use cases, data, technology and security, skills and culture, governance and risk, legal and regulatory – and give each one a named owner.
  • Score each candidate use case on value, feasibility and risk, and pick no more than two or three pilots.
  • Put a short acceptable-use policy, simple risk tiers and a human-oversight rule in place before any pilot touches personal or confidential data.
  • A focused assessment for a small or mid-sized organisation typically takes 3 to 8 weeks; data quality and the number of systems in scope drive the effort most.

What is an AI readiness assessment and why does it matter?

An AI readiness assessment is a structured review of whether an organisation can adopt AI in a way that delivers value and stays within acceptable risk. It looks beyond the tool itself to the conditions around it: is there a clear business problem, is the data fit for purpose, can the systems integrate safely, do people know how to check the output, and is someone accountable when things go wrong?

It matters because AI tools are easy to buy and easy to trial, but hard to make stick. A pilot that impresses in a demonstration can stall in production because the underlying data is inconsistent, because legal or security teams were brought in late, or because staff never trusted the output. An assessment surfaces those blockers early, while they are still cheap to fix, and gives leadership a defensible basis for deciding where to invest.

It also gives you a starting point for AI governance. Most organisations find that AI is already in use in some form, through chat assistants, AI features switched on inside existing software, or tools staff signed up for themselves. Readiness work turns that informal activity into something visible and managed.

The AI readiness framework: six dimensions and maturity levels

A practical AI readiness framework covers six dimensions. Each needs an owner and a short list of questions you can answer with evidence rather than opinion.

  1. Strategy and use cases. Are AI ambitions tied to business outcomes, with a sponsor and a way to measure success? Or is the starting point “we should be doing something with AI”?
  2. Data. Data readiness for AI means the information a use case depends on is accurate, reasonably complete, accessible, classified and lawfully usable for that purpose. This is where many plans run into trouble.
  3. Technology and security. Can AI tools connect to your systems without exposing sensitive data? Are identity, access, logging and supplier controls strong enough? The NCSC’s guidelines for secure AI system development are a useful reference here.
  4. Skills and culture. Do people understand what AI can and cannot do, how to check its output and when to escalate? Is there appetite, or anxiety, that needs managing?
  5. Governance and risk. Is there a policy, an approval route for new tools, a way to classify risk and a named person accountable for AI decisions?
  6. Legal and regulatory. Have you considered UK GDPR, intellectual property, contractual terms with AI suppliers, sector rules and, where you sell into the EU, the EU AI Act?

Readiness levels in an AI maturity assessment

An AI maturity assessment usually places each dimension on a simple scale. The labels matter less than the descriptions, which should be specific enough for two people to agree on the same rating:

  • Ad hoc: individuals experiment on their own; there is no inventory, policy or owner.
  • Emerging: AI use is acknowledged, a basic policy exists and a few use cases are being explored, but data and controls are inconsistent.
  • Defined: there is an approval route, risk tiers, training and a governed pilot process; key data sources are understood.
  • Managed: AI systems are monitored, reviewed on a schedule and measured against agreed outcomes; governance is part of normal business.

Most organisations sit at different levels across the six dimensions. That unevenness is the most useful output: it shows exactly which gap to close first.

AI readiness checklist: a step-by-step approach

This AI readiness checklist can be run internally. Assign each step to an owner and give it a date.

  1. Confirm sponsorship and scope. Agree which business units, systems and types of AI are in scope, and who signs off the outcome.
  2. Build the AI inventory. Record every AI tool, feature and model in use or planned, with owner, purpose and the data it touches.
  3. Collect candidate use cases. Ask teams for problems, not tools: repetitive, time-consuming tasks where output is easy to check.
  4. Assess the six dimensions. Use interviews, document review and a short survey to rate each dimension against the maturity scale.
  5. Review data readiness for priority use cases. Check quality, location, classification, retention and the lawful basis for using it.
  6. Check security and supplier controls. Review data handling terms, where data is processed, whether inputs are used for training, and access controls.
  7. Score and shortlist use cases. Rank them on value, feasibility and risk (see below).
  8. Set governance foundations. Publish an acceptable-use policy, define risk tiers and agree where human oversight is mandatory.
  9. Plan skills and training. Match training to roles: general AI literacy for everyone, deeper guidance for pilot users and reviewers.
  10. Agree a roadmap. Document gaps, owners, pilots and review dates in a short report leadership can act on.

How to find shadow AI and score AI use cases

Shadow AI is AI used without the organisation’s knowledge or approval: a personal chatbot account used to summarise client documents, a browser extension that reads email, or an AI feature quietly enabled in a SaaS product. It is rarely malicious. It is usually people trying to work faster. But it can mean confidential or personal data leaving your control without a contract, an assessment or a record.

To build an honest AI inventory, combine three sources:

  • Ask. A short, non-judgemental survey of each team about the AI tools and features they use. Make clear the aim is visibility, not blame.
  • Look. Review SaaS and expense records, browser extension lists, single sign-on logs and network or proxy data for AI services.
  • Check suppliers. Ask key software vendors which AI features are on by default and how they handle your data. Our guide to third-party risk management covers how to fold this into supplier reviews.

Once you have a list of candidate use cases, score each one on three axes so that the decision is transparent:

Scoring AI use cases on value, feasibility and risk
AxisQuestions to askEvidence to gather
ValueWhat problem does it solve? How often does the task occur? How will you measure improvement?Baseline time or error rates, named business owner, success measure
FeasibilityIs the data available and good enough? Can it integrate with current systems? Do users have the skills?Data source review, integration notes, supplier documentation
RiskDoes it involve personal or confidential data? Does it affect decisions about people? What if the output is wrong?Data classification, DPIA screening, proposed risk tier and oversight

The best early pilots score high on value and feasibility and low to moderate on risk. A use case with high value but high risk is not ruled out; it simply needs stronger controls and should usually come later.

AI governance foundations: policy, risk tiers and oversight

You do not need a large framework to start. Three foundations cover most early risk:

  • An acceptable-use policy that says which tools are approved, what data must never be entered, how output must be checked and how to request a new tool. Our guide What should an AI policy include? sets out the essentials.
  • Risk tiers, for example low (drafting internal text), medium (customer-facing content, use of confidential data) and high (decisions that affect people’s rights, money or safety). Each tier sets the approval, testing and monitoring required.
  • Human oversight rules that name who reviews AI output, at what point, and with the authority to override it.

As you mature, recognised frameworks give structure. ISO/IEC 42001 specifies requirements for an AI management system and suits organisations that already run ISO/IEC 27001 or want an independently certifiable approach; certification is carried out by accredited certification bodies, not by consultants. The NIST AI RMF is voluntary and organised around four functions – Govern, Map, Measure and Manage – with a companion Generative AI Profile. NIST notes the framework is being revised, so check the current version.

In the UK, the ICO’s guidance on AI and data protection explains how UK GDPR applies to AI, including fairness, transparency and data protection impact assessments. The ICO states that this guidance is under review following the Data (Use and Access) Act, so check for updates.

If you place AI systems on the EU market, or the output of your AI is used in the EU, the EU AI Act can apply to UK organisations. According to the European Commission, prohibitions and AI literacy obligations have applied since February 2025 and general-purpose AI obligations since August 2025, while amendments agreed in 2026 moved many high-risk obligations to later dates. Phasing has changed before, so check the current position. This article is guidance, not legal advice; take specialist legal advice on your obligations.

How long does an AI readiness assessment take?

For a small or mid-sized organisation with a defined scope, an AI readiness assessment typically takes 3 to 8 weeks from kick-off to a prioritised roadmap. Larger or regulated organisations, or those assessing several business units, should expect longer. The main effort drivers are:

  • Scope: the number of business units, systems and use cases included.
  • Data landscape: how many data sources matter and how well they are documented and classified.
  • Existing governance: organisations with a working ISMS, data protection programme or risk register move faster because much of the evidence exists already.
  • Regulatory exposure: sector rules, EU market activity or high-risk use cases add legal and documentation work.
  • Stakeholder availability: interviews and workshops with busy leaders and specialists often set the pace.

Common AI readiness assessment mistakes

  • Starting with the tool. Choosing a platform first and then looking for problems for it to solve.
  • Treating it as an IT project. Readiness depends as much on process owners, legal, HR and data protection as on technology.
  • Ignoring shadow AI. Assessing only approved tools misses where most of the real exposure sits.
  • Overrating data quality. Assuming data is ready because it exists, without checking accuracy, access rights and lawful basis.
  • Writing policy no one reads. Long, legalistic policies that staff cannot apply day to day.
  • No owner after the report. A roadmap without named owners and review dates quickly goes stale.

How Anvay approaches an AI readiness assessment

We keep the work practical and proportionate. It runs in four steps, each with a clear output:

  1. Discover – AI inventory and use cases. We map the AI already in use, including shadow AI, and gather candidate use cases from the business.
  2. Assess – readiness across six dimensions. We rate strategy, data, technology and security, skills and culture, governance and risk, and legal and regulatory readiness, and score the shortlisted use cases.
  3. Govern – policy, risk tiers and oversight. We help you put an acceptable-use policy, risk tiers and human-oversight rules in place, aligned with ISO/IEC 42001 or the NIST AI RMF where that suits you.
  4. Adopt – pilots, training and review. We support governed pilots, role-based training and a review cycle so that what works can scale safely.
Anvay's four-step approach to AI readiness: 1. Discover – AI inventory and use cases; 2. Assess – readiness across six dimensions; 3. Govern – policy, risk tiers and oversight; 4. Adopt – pilots, training and review
Anvay’s AI readiness approach moves from visibility to assessment, governance and governed adoption.

Where AI security is a concern, we draw on our cyber assessment and GRC and risk work, and supplier questions can be covered through a vendor assessment.

One practical takeaway before you invest in AI tools

Before you sign any new AI contract, spend a week building your AI inventory. Ask every team what they already use, record the data each tool touches and name an owner for each. That single list will show you your real exposure, your quickest wins and which readiness gap to close first, and it costs nothing but time.

— Achal, Anvay

Anvay services for AI readiness

Anvay helps organisations adopt AI with confidence. Our AI readiness assessments give you an evidence-based view of where you stand across the six dimensions. Our AI governance support covers policy, risk tiers and alignment with ISO/IEC 42001 and the NIST AI RMF. AI risk and security reviews look at data exposure, supplier terms and secure deployment, and our responsible adoption work supports pilots, training and review. For wider planning, see our technology strategy service. To scope an assessment for your organisation, talk to us about AI readiness.

FAQ

What is included in an AI readiness assessment?

An AI readiness assessment typically covers six areas: strategy and use cases, data, technology and security, skills and culture, governance and risk, and legal and regulatory obligations. It usually includes an inventory of AI already in use, a maturity rating for each area, scored use cases and a prioritised roadmap with owners, so leadership knows where to invest first and which gaps to close.

What should an AI readiness checklist include?

A useful AI readiness checklist includes scope and sponsorship, an AI inventory, candidate use cases, a rating of the six readiness dimensions, data and supplier checks, use-case scoring on value, feasibility and risk, an acceptable-use policy, risk tiers, human oversight rules, role-based training and a roadmap with named owners and review dates.

What is the difference between AI readiness and AI maturity?

AI readiness asks whether you can adopt AI safely and usefully now, usually for specific use cases. An AI maturity assessment describes how established your AI capability is over time, from ad hoc experimentation to managed, monitored use. In practice the two overlap: a readiness assessment often uses a maturity scale to rate each dimension and show progress.

Does the EU AI Act apply to UK businesses?

It can. The EU AI Act applies to providers that place AI systems on the EU market and to providers and deployers outside the EU where the output of their AI system is used in the EU. Obligations are phased and some dates were amended in 2026, so check the current position and take legal advice. This is guidance, not legal advice.

Do we need ISO/IEC 42001 certification to use AI?

No. ISO/IEC 42001 is a voluntary standard for an AI management system. Some organisations pursue certification to show customers and regulators that AI is governed well, and certification is carried out by accredited certification bodies. Many smaller organisations start with a policy, risk tiers and oversight, and use ISO/IEC 42001 or the NIST AI RMF as a reference.

Sources

Primary references and standards: this article draws on ISO/IEC 42001, the NIST AI RMF, ICO and NCSC guidance, and European Commission material on the EU AI Act.

Back to all insights

Make your next step clearer.

Tell us what you are working on or where you feel unsure. We will talk it through with you and suggest practical support that fits.

Discuss your requirements