Skip to content

Guide · 9 min read · Sep 18, 2026

What happens in an AI readiness assessment

An AI readiness assessment is a structured review of specific workflows, the data and systems behind them and the people who run them, to decide where AI or automation will help, what must be fixed first and in what order to act. A good one ends with named, prioritized opportunities and a roadmap, not a maturity score or a deck of industry trends.

Tuaha JawaidFounder, business lead

Key takeaways

  • An assessment should examine named workflows, not AI readiness in the abstract.
  • Seven areas decide the outcome: workflows, data, system access, security and governance, people, ownership and a measurement baseline.
  • Expect interviews, walkthroughs of the real work, a review of systems and data, and then a ranked list of opportunities.
  • The outputs should be a current-state assessment, prioritized opportunities, a recommended approach and an implementation roadmap.
  • Be wary of any provider whose recommendations start with a tool they sell rather than a problem you have.

Most companies considering AI are not short of ideas. They are short of a reliable way to choose between them. A vendor demos an agent, a department head asks for a chatbot, finance wants a business case, and nobody can yet say which workflow is worth the effort, whether the data exists or who would own the result. An AI readiness assessment is how you answer those questions before you pay for a build.

What is an AI readiness assessment, and who needs one?

An AI readiness assessment is a structured review of specific workflows, the data and systems behind them and the people who run them, to decide where AI or automation will be useful and what has to be true first. It is narrower and more practical than a digital strategy. The subject is the work, not the technology.

The case for doing one is that most AI projects stumble on problems that are visible before anyone writes code. In a 2024 report, RAND notes that by some estimates more than 80 percent of AI projects fail, twice the failure rate of IT projects that do not involve AI. Its interviews with 65 experienced data scientists and engineers found five leading root causes: misunderstanding the problem to be solved, lacking the necessary data, focusing on the technology rather than the problem, inadequate infrastructure, and applying AI to problems too difficult for it. A good assessment tests for most of these up front.

You probably need one if several of these are true:

  • You have more AI ideas than budget, and no agreed way to rank them.
  • The information a workflow depends on is spread across email, spreadsheets, SharePoint and a system of record such as NetSuite or Salesforce.
  • A previous pilot worked in a demo but never reached daily use.
  • Leadership wants a business case before approving a build.
  • The workflow touches customer, financial or employee data that needs clear access rules.

You probably do not need one if you have a single, well-understood workflow with an accountable owner, accessible data and an agreed measure of success. That can go straight to scoping. Nor do you need one to switch on AI features in software you already license.

What does an AI readiness assessment look at?

Seven areas decide whether an AI workflow will work in practice. The table shows what a reviewer should examine in each, and the warning signs that usually mean something must be fixed before building.

AreaWhat gets reviewedWarning signs
Workflows and pain pointsSteps, handoffs, volumes, exceptions and where time is lostNobody describes the process the same way twice
Data availability and qualityWhere the data lives, how complete and consistent it is, who approves its useKey fields are free text, missing or kept in personal files
Systems and integration accessAPIs, permissions, licenses and the admin for each system involvedThe ERP has no usable API, or nobody knows who administers it
Security and governanceData classification, where data may be processed, approval points, AI use policyNo rule on which data may be sent to an AI model
People and adoptionWho does the work today, their tools, training needs and concernsEnd users first hear about the project at launch
Ownership and sponsorshipA named business owner, a process owner and someone who decides trade-offsThe project belongs to "the AI team" rather than a business leader
Measurement baselineCurrent handling time, cycle time, rework and volumesNobody can say how long the work takes today

Two of these areas are routinely underweighted. The first is people. BCG's 2024 survey of 1,000 senior executives found that around 70 percent of AI implementation challenges stem from people and process issues, 20 percent from technology and only 10 percent from the algorithms. The second is measurement. In Cisco's 2025 AI Readiness Index, the most prepared companies (about 13 percent of organizations) were far more likely to have a change management plan, 91 percent compared with 35 percent overall, and 95 percent of them track the impact of their AI investments.

For the governance area, a useful public reference is the NIST AI Risk Management Framework, a voluntary framework the US National Institute of Standards and Technology released in January 2023 and extended with a generative AI profile in July 2024.

What happens during an AI readiness assessment, step by step?

The details vary by provider, but a credible assessment follows roughly this sequence.

1. Scope and stakeholders

The sponsor and the reviewers agree which departments, workflows and systems are in scope, and who needs to be interviewed. Writing this down matters. An assessment with no named scope tends to produce conclusions with no named owner.

2. Interviews

Reviewers talk to the sponsor, the process owners, the people who do the work every day and the administrators of the systems involved. Frontline interviews are where the real exceptions, workarounds and spreadsheets appear. Leadership interviews set the priorities and the constraints.

3. Process walkthroughs

Someone shows the reviewers the work as it actually happens: the inbox, the shared drive, the screens in the ERP or CRM, the approval chain. A walkthrough usually reveals steps nobody mentioned in an interview, such as re-keying an order from a PDF or checking a contract clause by hand.

4. System and data review

Reviewers check whether each system can be connected (APIs, permissions, rate limits, licensing), where the relevant data lives and what condition it is in. They look at representative samples, with approval, rather than relying on descriptions. This is also where security questions get concrete: which data could be sent to a model provider such as OpenAI or Anthropic, and under what terms.

5. Prioritization

Each candidate opportunity is scored on business value, feasibility, risk and effort, including whether a person must approve the output before it takes effect. The aim is a short ranked list with reasons, not a long list where everything is high priority.

6. Readout

The findings are presented to the sponsor and the people who will act on them, with time to challenge the ranking before it becomes a plan.

What should a good assessment produce?

Four outputs are worth insisting on, each tied to named workflows:

  1. A current-state assessment. How the in-scope workflows run today, where time and effort are lost, the systems and data involved, and a baseline for the measures that will define success.
  2. Prioritized opportunities. For each: the workflow, its owner, rough volumes, the expected benefit and how it would be measured, the data and system dependencies, the risks and where human approval stays in place.
  3. A recommended approach. For each priority, whether to automate, add AI assistance, buy an existing product, integrate systems you already own, or fix the process first. "Do not use AI here" is a legitimate answer.
  4. An implementation roadmap. The order of work, the dependencies between items, what must be in place before each step and who is responsible.

Illustrative example: Consider a 150-person accounting firm whose partners want AI "somewhere in client onboarding." An assessment finds that the biggest delay is not reviewing documents but chasing missing ones: intake requests go out by email, and staff track responses in a spreadsheet. It also finds that the practice management system has a usable API but engagement letters sit in personal folders. The recommendation is to automate document requests and completeness checks first, with a staff member approving each client file, and to fix where engagement letters are stored before attempting any AI extraction from them.

The roadmap names the onboarding manager as process owner and sets turnaround time from engagement to complete file as the baseline measure.

How long does an AI readiness assessment take?

Scope drives duration more than anything else. A focused assessment of a few workflows in one department can usually be measured in weeks rather than months. A review that spans several departments, many systems or regulated data takes longer, because there are more people to interview and more access to approve.

The most common delays are practical rather than analytical: waiting for interview slots, for system access, or for security approval to share sample data. Agreeing those in advance shortens an assessment more than any method does. Be cautious of a quoted duration that does not change when the scope does.

How should you prepare for an assessment?

Preparation makes the review faster and the recommendations sharper. Before it starts:

  1. Name an executive sponsor who can make decisions and unblock access.
  2. Shortlist three to five workflows you suspect are costly, with a sentence on why.
  3. Identify a process owner and two or three frontline users for each workflow.
  4. List the systems involved and the administrator for each.
  5. Gather rough volumes, such as invoices a month or requests a week.
  6. Collect any existing data, security or AI use policies.
  7. Arrange approval to share representative, redacted samples of documents and records.
  8. Note past attempts, including pilots that stalled and why.

To see where you stand first, take the free AI readiness self-assessment, which scores workflows, data, systems, governance and people in twelve questions. The AI readiness checklist that accompanies this guide turns the list above into a working document for your team.

How do you judge an assessment provider?

What to demand

  • Named teams, workflows and systems in the proposal, not "a review of your AI opportunities."
  • Interviews with the people who do the work, not only leadership.
  • The four outputs above listed as deliverables.
  • A recommendation that can include buying, integrating or not using AI at all.
  • Disclosure of any reseller, referral or platform partnership that could shape the advice.
  • Deliverables you own and could hand to another team.

Red flags

  • Generic slideware. Maturity scores, market trends and a framework diagram, with nothing specific to how your company works.
  • No named workflows. If the findings could apply to any company in your industry, nobody looked closely at yours.
  • Tool-first recommendations. When every answer is the platform the provider sells, the assessment was a sales process. RAND identifies focusing on technology over the real problem as one of the most frequent paths to failure.
  • No data examined. Conclusions about feasibility without anyone opening a sample record or checking an API.
  • No owners and no baseline. Opportunities with no accountable person and no current measure cannot be managed or evaluated later.

For a broader set of questions to put to any firm, see how to choose an AI implementation partner.

How Kastling approaches an AI readiness assessment

Kastling is an implementation partner, and our version of a readiness assessment is a paid audit that decides what is worth building and in what order. Engagements start with a free discovery call that commits you to nothing. For AI and operations work, the audit commonly comes next, scoped and billed separately. It is not mandatory for every project: a well-defined software brief can move straight from discovery to a scoped proposal.

In the audit, we interview the relevant people and review the agreed workflows, operations, systems and data pipelines to find where time, effort and money are being lost. The recommended outputs are a current-state assessment, prioritized opportunities, a recommended approach and an implementation roadmap. The audit proposal turns those into specific deliverables and names which teams, workflows and systems will be reviewed, so you know what you are buying before it starts.

We look at the work before the technology, prefer connecting existing systems to replacing them, keep a named person in control of consequential decisions and agree up front how success will be measured. If the right answer is a product you can buy, we say so. Work that follows usually sits within AI Integration & Automation. To go from a ranked list to a first project, read which business processes to automate first and how to calculate the ROI of AI automation.

AI readiness checklist

A practical AI readiness checklist covering workflow, data, systems, security, people and measurement, so you can see what to fix before an AI project starts.

Questions

Is an AI readiness assessment the same as a data audit?

No. A data audit looks at the quality and governance of data on its own. A readiness assessment looks at data only as it relates to specific workflows, alongside the systems, people, ownership and controls those workflows need. Data problems often surface in an assessment, but they are one input to the recommendation rather than the whole scope.

Do we need clean data before we start?

No. Part of the point of an assessment is to find out which data gaps matter for the workflows you care about and which do not. Many useful automations run on documents and emails rather than a tidy database. What you need is permission to let the reviewers look at representative samples.

Can we run a readiness assessment ourselves?

Yes, and a self-assessment is a sensible first step for ranking ideas and spotting obvious gaps. The limits are usually time and perspective: internal teams can find it hard to interview colleagues candidly, judge integration feasibility across systems they do not administer, or recommend against a project a senior leader already favors. An outside review is most useful when the stakes or the number of systems are high.

What happens if the assessment says we are not ready?

A useful "not yet" is specific. It should name what needs to change first, for example a missing process owner, a system without an API or no agreed policy on what data can be sent to an AI model, and it should say who could fix it. Often a smaller, lower-risk workflow can still go ahead while those foundations are put in place.

Does an assessment commit us to building with the same provider?

It should not. Ask for the deliverables to be yours and detailed enough that another team could act on them. A provider confident in its recommendations has no reason to make the roadmap usable only by itself.

Sources

  1. RAND: The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed (2024)
  2. BCG: AI Adoption in 2024, 74% of Companies Struggle to Achieve and Scale Value
  3. Cisco: AI Readiness Index 2025 press release
  4. NIST: AI Risk Management Framework

Guide · 14 min read

AI workflow automation: a practical guide for operations teamsAI workflow automation puts AI models inside a defined business process to read, classify and prepare work, while fixed rules, integrations and named people handle the steps that must be predictable. It suits repetitive, document-heavy or request-heavy work such as intake, routing, document checks and approvals. Start with one measurable workflow, keep consequential approvals with an accountable person, and expand only once the numbers show it works.Read

Article · 9 min read

AI document processing for invoices, contracts and formsAI document processing combines three techniques: OCR to turn images into text, layout models to understand where values sit on a page, and language models to extract and interpret fields that vary between documents. The technique matters less than what surrounds it: validation rules that check extracted values against your own records, confidence thresholds that decide what a person sees, and a review queue somebody owns. Measure field level accuracy and the share of documents that pass without a human touch, not a single headline accuracy number.Read

Article · 8 min read

Building an AI assistant on your company knowledgeAn AI knowledge assistant answers questions using your own approved documents rather than general model training, a pattern called retrieval-augmented generation. The work is less about the model and more about choosing which sources count as authoritative, enforcing the permissions those sources already carry, showing citations people can check, and deciding what happens when information is missing or two documents disagree. Buy Microsoft 365 Copilot, Gemini for Workspace or Glean when your knowledge lives in one mainstream suite, and build when it is spread across line of business systems or the answers must trigger work.Read

One useful email a month.

New guides, tools and practical notes on putting AI to work. No sales sequences.

Bring us a workflow.

Tell us where the work slows down. We will help you see where to start.

Book a discovery call