Skip to main content
AI strategy

Is Your Company Ready for AI? A 25-Point Readiness Assessment

Score your company across workflow, data, technology, people and governance before funding an AI pilot or enterprise rollout.

By Jayson Hao10 min read
Tactile paper and metal editorial artwork for Is Your Company Ready for AI? A 25-Point Readiness Assessment
Editorial field noteITL / № 05

Key takeaways

  • Score five dimensions from zero to five: workflow, data, technology, people and governance.
  • A pilot can start at 15 points if no dimension scores zero and the use case is low or moderate risk.
  • Cybersecurity and privacy are the most reported AI adoption barrier among Canadian businesses.
  • Readiness improves through a focused pilot; waiting for perfect data often delays useful learning.

What AI readiness actually means

Readiness is the ability to run a controlled experiment and make a credible decision from the result. A company with excellent cloud infrastructure but no workflow owner is less ready than a smaller company with clean support records, a clear escalation process and a manager who owns resolution time.

Statistics Canada reported that cybersecurity or privacy concerns were the leading AI barrier in the second quarter of 2026 at 13.4%, followed by cost at 10.6%. The useful response is not a longer vision deck. It is a bounded use case, approved data, a cost ceiling and evidence requirements.

1. Workflow readiness: can you describe the work?

Award one point for each condition: the workflow repeats at least weekly; inputs and outputs are identifiable; a person owns the result; common exceptions are documented; and success has a measurable business definition. A workflow scores five when a new employee could follow its written path and an experienced reviewer could explain why exceptions occur.

A vague goal such as “improve customer service with AI” scores poorly. “Draft an evidence-linked reply for delivery-status tickets and route low-confidence cases to tier two” is testable. Narrow language exposes the systems, policies and decisions the product must handle.

2. Data readiness: is representative evidence accessible?

Give one point each for representative historical examples, known outcomes, documented access rights, usable data quality and a refresh process. Data does not have to sit in one warehouse. It must be retrievable, interpretable and legally usable for the defined purpose.

Inspect 50 to 100 real cases before selecting a tool. Look for missing fields, inconsistent labels, scanned documents, stale policies and outcomes recorded only in employee memory. That sample often changes the architecture and the expected automation rate.

3. Technology readiness: can the system fit the environment?

Score identity and access control, usable APIs or exports, a safe test environment, logging and a deployment owner. Avoid giving a model broad credentials because an integration is inconvenient. A pilot should use the same permission boundaries expected in production, even when the interface is temporary.

A five does not require custom infrastructure. A managed product can score highly when it supports required data controls, exportable logs and dependable integration. Custom engineering becomes valuable when the workflow, proprietary context or customer experience creates differentiation.

4. People readiness: who teaches, checks and changes the work?

Give points for an executive sponsor, workflow owner, domain reviewers, technical owner and employee learning time. One person may cover several roles in a smaller company, but the responsibilities must remain explicit. The process owner, not the vendor, decides what an acceptable outcome means.

Microsoft’s 2026 Work Trend Index found organizational factors such as culture, manager support and talent practices accounted for more than twice the reported AI impact of individual factors. Training power users while managers preserve the old metrics creates frustration rather than transformation.

5. Governance readiness: can you say no, pause and investigate?

Award points for an approved purpose, data rule, risk classification, human escalation and incident process. These controls can fit on two pages for a low-risk pilot. Their value comes from use during design and release, not document length.

The team should know which actions require approval, who can suspend the system and which records are preserved after a failure. Public-facing, high-impact or personal-data use cases require stronger privacy, legal, security and accessibility review before testing.

How to interpret your score

A score below 10 means the use case needs discovery before software selection. From 10 to 14, run a short data and workflow study. From 15 to 20, a low- or moderate-risk pilot can begin if no dimension is zero. From 21 to 25, focus on production evaluation and change management rather than more readiness workshops.

Treat a zero as a stop sign. An unavailable data source, absent owner or undefined privacy basis cannot be repaired by a better model. Fix the missing condition or choose a different workflow with stronger foundations.

Turn the assessment into a two-week action plan

Choose the highest-value use case scoring at least three in workflow and data readiness. Assign owners, inspect 100 cases, record the baseline, approve permitted data and write ten failure tests. End the second week with a pilot brief containing scope, evidence, budget ceiling, approval points and a decision date.

About the author

Jayson Hao

Founder of Innovation Trigger Lab and a University of Toronto Computer Science graduate with an AI/ML focus. He designs and ships production RAG systems, AI chatbots, web platforms and mobile products.

View profile

Frequently asked questions

What score means a company is ready for AI?

For this assessment, 15 out of 25 is enough for a bounded low- or moderate-risk pilot if every dimension scores at least one. Higher-risk uses need stronger governance, data and evaluation evidence.

Does a company need perfect data before using AI?

No. It needs representative, accessible and legally usable data for one defined workflow. A pilot can expose quality gaps, but missing outcomes or unknown access rights must be resolved first.

Who should own an AI pilot?

The business process owner should own the outcome, supported by a technical owner and domain reviewers. Security, privacy or legal specialists join according to the use-case risk.

Sources and further reading

  1. 1.
  2. 2.
  3. 3.
    How enterprises are scaling AIOpenAI, May 11, 2026