Key takeaways
- An assessment should examine named workflows, not AI readiness in the abstract.
- Seven areas decide the outcome: workflows, data, system access, security and governance, people, ownership and a measurement baseline.
- Expect interviews, walkthroughs of the real work, a review of systems and data, and then a ranked list of opportunities.
- The outputs should be a current-state assessment, prioritized opportunities, a recommended approach and an implementation roadmap.
- Be wary of any provider whose recommendations start with a tool they sell rather than a problem you have.
Most companies considering AI are not short of ideas. They are short of a reliable way to choose between them. A vendor demos an agent, a department head asks for a chatbot, finance wants a business case, and nobody can yet say which workflow is worth the effort, whether the data exists or who would own the result. An AI readiness assessment is how you answer those questions before you pay for a build.
What is an AI readiness assessment, and who needs one?
An AI readiness assessment is a structured review of specific workflows, the data and systems behind them and the people who run them, to decide where AI or automation will be useful and what has to be true first. It is narrower and more practical than a digital strategy. The subject is the work, not the technology.
The case for doing one is that most AI projects stumble on problems that are visible before anyone writes code. In a 2024 report, RAND notes that by some estimates more than 80 percent of AI projects fail, twice the failure rate of IT projects that do not involve AI. Its interviews with 65 experienced data scientists and engineers found five leading root causes: misunderstanding the problem to be solved, lacking the necessary data, focusing on the technology rather than the problem, inadequate infrastructure, and applying AI to problems too difficult for it. A good assessment tests for most of these up front.
You probably need one if several of these are true:
- You have more AI ideas than budget, and no agreed way to rank them.
- The information a workflow depends on is spread across email, spreadsheets, SharePoint and a system of record such as NetSuite or Salesforce.
- A previous pilot worked in a demo but never reached daily use.
- Leadership wants a business case before approving a build.
- The workflow touches customer, financial or employee data that needs clear access rules.
You probably do not need one if you have a single, well-understood workflow with an accountable owner, accessible data and an agreed measure of success. That can go straight to scoping. Nor do you need one to switch on AI features in software you already license.
What does an AI readiness assessment look at?
Seven areas decide whether an AI workflow will work in practice. The table shows what a reviewer should examine in each, and the warning signs that usually mean something must be fixed before building.
| Area | What gets reviewed | Warning signs |
|---|---|---|
| Workflows and pain points | Steps, handoffs, volumes, exceptions and where time is lost | Nobody describes the process the same way twice |
| Data availability and quality | Where the data lives, how complete and consistent it is, who approves its use | Key fields are free text, missing or kept in personal files |
| Systems and integration access | APIs, permissions, licenses and the admin for each system involved | The ERP has no usable API, or nobody knows who administers it |
| Security and governance | Data classification, where data may be processed, approval points, AI use policy | No rule on which data may be sent to an AI model |
| People and adoption | Who does the work today, their tools, training needs and concerns | End users first hear about the project at launch |
| Ownership and sponsorship | A named business owner, a process owner and someone who decides trade-offs | The project belongs to "the AI team" rather than a business leader |
| Measurement baseline | Current handling time, cycle time, rework and volumes | Nobody can say how long the work takes today |
Two of these areas are routinely underweighted. The first is people. BCG's 2024 survey of 1,000 senior executives found that around 70 percent of AI implementation challenges stem from people and process issues, 20 percent from technology and only 10 percent from the algorithms. The second is measurement. In Cisco's 2025 AI Readiness Index, the most prepared companies (about 13 percent of organizations) were far more likely to have a change management plan, 91 percent compared with 35 percent overall, and 95 percent of them track the impact of their AI investments.
For the governance area, a useful public reference is the NIST AI Risk Management Framework, a voluntary framework the US National Institute of Standards and Technology released in January 2023 and extended with a generative AI profile in July 2024.
What happens during an AI readiness assessment, step by step?
The details vary by provider, but a credible assessment follows roughly this sequence.
1. Scope and stakeholders
The sponsor and the reviewers agree which departments, workflows and systems are in scope, and who needs to be interviewed. Writing this down matters. An assessment with no named scope tends to produce conclusions with no named owner.
2. Interviews
Reviewers talk to the sponsor, the process owners, the people who do the work every day and the administrators of the systems involved. Frontline interviews are where the real exceptions, workarounds and spreadsheets appear. Leadership interviews set the priorities and the constraints.
3. Process walkthroughs
Someone shows the reviewers the work as it actually happens: the inbox, the shared drive, the screens in the ERP or CRM, the approval chain. A walkthrough usually reveals steps nobody mentioned in an interview, such as re-keying an order from a PDF or checking a contract clause by hand.
4. System and data review
Reviewers check whether each system can be connected (APIs, permissions, rate limits, licensing), where the relevant data lives and what condition it is in. They look at representative samples, with approval, rather than relying on descriptions. This is also where security questions get concrete: which data could be sent to a model provider such as OpenAI or Anthropic, and under what terms.
5. Prioritization
Each candidate opportunity is scored on business value, feasibility, risk and effort, including whether a person must approve the output before it takes effect. The aim is a short ranked list with reasons, not a long list where everything is high priority.
6. Readout
The findings are presented to the sponsor and the people who will act on them, with time to challenge the ranking before it becomes a plan.
What should a good assessment produce?
Four outputs are worth insisting on, each tied to named workflows:
- A current-state assessment. How the in-scope workflows run today, where time and effort are lost, the systems and data involved, and a baseline for the measures that will define success.
- Prioritized opportunities. For each: the workflow, its owner, rough volumes, the expected benefit and how it would be measured, the data and system dependencies, the risks and where human approval stays in place.
- A recommended approach. For each priority, whether to automate, add AI assistance, buy an existing product, integrate systems you already own, or fix the process first. "Do not use AI here" is a legitimate answer.
- An implementation roadmap. The order of work, the dependencies between items, what must be in place before each step and who is responsible.
Illustrative example: Consider a 150-person accounting firm whose partners want AI "somewhere in client onboarding." An assessment finds that the biggest delay is not reviewing documents but chasing missing ones: intake requests go out by email, and staff track responses in a spreadsheet. It also finds that the practice management system has a usable API but engagement letters sit in personal folders. The recommendation is to automate document requests and completeness checks first, with a staff member approving each client file, and to fix where engagement letters are stored before attempting any AI extraction from them.
The roadmap names the onboarding manager as process owner and sets turnaround time from engagement to complete file as the baseline measure.
How long does an AI readiness assessment take?
Scope drives duration more than anything else. A focused assessment of a few workflows in one department can usually be measured in weeks rather than months. A review that spans several departments, many systems or regulated data takes longer, because there are more people to interview and more access to approve.
The most common delays are practical rather than analytical: waiting for interview slots, for system access, or for security approval to share sample data. Agreeing those in advance shortens an assessment more than any method does. Be cautious of a quoted duration that does not change when the scope does.
How should you prepare for an assessment?
Preparation makes the review faster and the recommendations sharper. Before it starts:
- Name an executive sponsor who can make decisions and unblock access.
- Shortlist three to five workflows you suspect are costly, with a sentence on why.
- Identify a process owner and two or three frontline users for each workflow.
- List the systems involved and the administrator for each.
- Gather rough volumes, such as invoices a month or requests a week.
- Collect any existing data, security or AI use policies.
- Arrange approval to share representative, redacted samples of documents and records.
- Note past attempts, including pilots that stalled and why.
To see where you stand first, take the free AI readiness self-assessment, which scores workflows, data, systems, governance and people in twelve questions. The AI readiness checklist that accompanies this guide turns the list above into a working document for your team.
How do you judge an assessment provider?
What to demand
- Named teams, workflows and systems in the proposal, not "a review of your AI opportunities."
- Interviews with the people who do the work, not only leadership.
- The four outputs above listed as deliverables.
- A recommendation that can include buying, integrating or not using AI at all.
- Disclosure of any reseller, referral or platform partnership that could shape the advice.
- Deliverables you own and could hand to another team.
Red flags
- Generic slideware. Maturity scores, market trends and a framework diagram, with nothing specific to how your company works.
- No named workflows. If the findings could apply to any company in your industry, nobody looked closely at yours.
- Tool-first recommendations. When every answer is the platform the provider sells, the assessment was a sales process. RAND identifies focusing on technology over the real problem as one of the most frequent paths to failure.
- No data examined. Conclusions about feasibility without anyone opening a sample record or checking an API.
- No owners and no baseline. Opportunities with no accountable person and no current measure cannot be managed or evaluated later.
For a broader set of questions to put to any firm, see how to choose an AI implementation partner.
How Kastling approaches an AI readiness assessment
Kastling is an implementation partner, and our version of a readiness assessment is a paid audit that decides what is worth building and in what order. Engagements start with a free discovery call that commits you to nothing. For AI and operations work, the audit commonly comes next, scoped and billed separately. It is not mandatory for every project: a well-defined software brief can move straight from discovery to a scoped proposal.
In the audit, we interview the relevant people and review the agreed workflows, operations, systems and data pipelines to find where time, effort and money are being lost. The recommended outputs are a current-state assessment, prioritized opportunities, a recommended approach and an implementation roadmap. The audit proposal turns those into specific deliverables and names which teams, workflows and systems will be reviewed, so you know what you are buying before it starts.
We look at the work before the technology, prefer connecting existing systems to replacing them, keep a named person in control of consequential decisions and agree up front how success will be measured. If the right answer is a product you can buy, we say so. Work that follows usually sits within AI Integration & Automation. To go from a ranked list to a first project, read which business processes to automate first and how to calculate the ROI of AI automation.
AI readiness checklist
A practical AI readiness checklist covering workflow, data, systems, security, people and measurement, so you can see what to fix before an AI project starts.
Questions
Is an AI readiness assessment the same as a data audit?
No. A data audit looks at the quality and governance of data on its own. A readiness assessment looks at data only as it relates to specific workflows, alongside the systems, people, ownership and controls those workflows need. Data problems often surface in an assessment, but they are one input to the recommendation rather than the whole scope.
Do we need clean data before we start?
No. Part of the point of an assessment is to find out which data gaps matter for the workflows you care about and which do not. Many useful automations run on documents and emails rather than a tidy database. What you need is permission to let the reviewers look at representative samples.
Can we run a readiness assessment ourselves?
Yes, and a self-assessment is a sensible first step for ranking ideas and spotting obvious gaps. The limits are usually time and perspective: internal teams can find it hard to interview colleagues candidly, judge integration feasibility across systems they do not administer, or recommend against a project a senior leader already favors. An outside review is most useful when the stakes or the number of systems are high.
What happens if the assessment says we are not ready?
A useful "not yet" is specific. It should name what needs to change first, for example a missing process owner, a system without an API or no agreed policy on what data can be sent to an AI model, and it should say who could fix it. Often a smaller, lower-risk workflow can still go ahead while those foundations are put in place.
Does an assessment commit us to building with the same provider?
It should not. Ask for the deliverables to be yours and detailed enough that another team could act on them. A provider confident in its recommendations has no reason to make the roadmap usable only by itself.