The AI Readiness Assessment for IT Teams: What It Covers and Why Scores Beat Opinions

A friendly robot assistant and two IT leaders of different backgrounds reviewing a glowing hexagon-shaped radar chart floating between them

Ask five people in an organization whether it’s ready for AI and you’ll get five answers. The enthusiast says yes, obviously; people are already using it. The security lead says absolutely not; look at the permissions. The CFO says it depends what it costs. Each of them is partly right, and none of them can settle the question, because they’re all offering opinions built on different evidence.

An AI readiness assessment replaces those opinions with a shared picture. It asks a fixed set of questions, scores the answers the same way every time, and turns the result into a ranked list of risks and a plan. This post explains what the AI Readiness assessment for IT teams covers, how it’s scored, what you get out of it, and why a score is more useful than a debate.

Why scores beat opinions

  • A shared language. “We’re at level 1 on data ownership” means the same thing to everyone in the room. “Our data is kind of a mess” doesn’t.
  • Specificity. Scoring forces a choice between defined answers, which exposes vague optimism and vague pessimism alike.
  • Disagreements surface. When IT scores a question at 3 and a business leader scores it at 1, you’ve found something worth discussing.
  • Progress you can measure. Scores can be compared quarter to quarter. Opinions just change.
  • A credible answer for leadership. A board can follow six numbers and an average far more easily than a collection of views.

Scores don’t replace judgment. They separate the facts, where you stand, from the judgment, what to do about it, so each can be discussed on its own terms.

Why assess before you spend

The most expensive AI mistakes I see at mid-size organizations aren’t bad tool choices. They’re sequencing mistakes: licenses rolled out before permissions were cleaned up, a pilot funded before anyone captured a baseline, a builder hired before anyone agreed what to build. Each of those would have been caught by a simple question asked in advance. An assessment is really a structured way of asking all of those questions at once, so that the order of spending follows the order of readiness. The checklist turns that into specific spending gates.

What the assessment covers

Twenty-four questions, four in each of six dimensions. Each dimension has a detailed guide in this series.

  • Data readiness: where core data lives, who owns its quality, how well documents are permissioned, and whether AI can reach data safely. See data readiness for AI.
  • Security and privacy: shadow AI, data classification and DLP, identity and access, and AI vendor review. See AI security readiness.
  • Infrastructure and platforms: cloud posture, access to enterprise AI, operations automation, and cost visibility. See is your infrastructure ready for AI?
  • Skills and talent: hands-on skill, certifications, builders, and investment in upskilling. See the AI skills gap on IT teams.
  • Use cases and value: how well use cases are defined, how far AI has gone beyond experimentation, executive sponsorship, and how value is measured. See picking your first AI use case.
  • Governance and operating model: the acceptable use policy, who decides, regulatory mapping, and the AI inventory. See AI governance for mid-size IT.

All 24 questions are listed in the AI readiness checklist, and the full maturity ladders are public in the appendix of the sample report.

How it’s scored

Each question has five answers describing maturity levels from 0 to 4. A dimension’s score is the points earned divided by the points possible, and the overall score is the plain average of the six dimensions. The result falls into one of four bands: Not Ready, Emerging, Ready, or Leading. One rule overrides the average: if security or governance scores below 40, the rating can’t be higher than Emerging. The scoring is deterministic, so the same answers always give the same result. How the 0 to 100 scale works goes through the math with a worked example.

What comes out of it

The score is the start, not the product. A complete assessment produces:

  • A scorecard across the six dimensions.
  • Ranked risks, with red-flag answers first, each with its impact and a specific fix.
  • Quick wins, where the next level is weeks of work rather than quarters.
  • A 90-day plan, sequenced so risks close before a pilot starts.
  • Budget guidance, success measures, and a skills plan.

What a real AI readiness report looks like walks through a complete example.

Who it’s for

It’s designed for IT leaders at mid-size organizations, roughly 200 to 5,000 employees, who are being asked about AI and want an honest picture before committing money. Frameworks built for large enterprises assume specialist teams and budgets that mid-size organizations don’t have; this one assumes a small IT team that also keeps everything else running.

Three ways to take it

  1. The free score: 10 of the 24 questions, spread across all six dimensions, with a score in a few minutes.
  2. Do it yourself: run all 24 questions with your own team using this two-week process.
  3. The full report: all 24 questions plus your context, turned into a written report with risks and a 90-day plan. What an AI readiness assessment should cost covers the options and prices.

How it differs from a maturity model

A maturity model describes stages an organization moves through over years. A readiness assessment asks a narrower, more urgent question: what stands between you and your next AI step, and what should you fix first? They’re complementary, and AI maturity model vs. AI readiness assessment explains when you need each.

How often to assess

Treat the first assessment as a baseline, not a verdict. Re-score every quarter during the first year, when things change quickly and the plan needs adjusting, then twice a year after that. Also re-assess before any major rollout, such as licensing an AI assistant for the whole organization, after a significant reorganization, and after any security incident involving AI. Each re-assessment is faster than the first, because the evidence sources and the framework are already familiar, and the change in scores is often the most useful thing you can show leadership.

The asset: what to gather before any assessment

Whichever route you take, these pieces of evidence make the answers faster and more honest:

  1. Sharing and permission reports from your collaboration platform.
  2. MFA and SSO coverage reports.
  3. Web or DNS logs showing use of AI services.
  4. The status of your AI acceptable use policy.
  5. A list of AI tools and AI features in use.
  6. Training records and current certifications for the IT team.
  7. Any list of AI ideas or pilots, with owners.
  8. Cloud budget and alert configuration.

And the context: your industry, size, main productivity suite and cloud, the regulations that apply, what you most want AI to do in the next year, your biggest concern, and your rough budget. Every recommendation should trace back to that context, so write it down before you start rather than reconstructing it afterward.

Where does your team actually stand?

The quickest way to start is the free score: 10 questions across all six dimensions, with a result in a few minutes.

Get your free AI Readiness Score →

Want to see the complete deliverable first? Flip through a complete 38-page sample report.

Related guides

Frequently asked questions

What is an AI readiness assessment?

A fixed set of questions that scores an organization's preparedness for AI the same way every time, then turns the gaps into ranked risks and a plan. The AI Readiness assessment uses 24 questions across data, security, infrastructure, skills, use cases, and governance.

Why are readiness scores better than opinions?

Scores give everyone a shared language, force specific answers, surface disagreements worth discussing, show progress quarter to quarter, and give leadership a picture they can follow. They separate where you stand from what to do about it.

How often should we reassess AI readiness?

Quarterly during the first year, then twice a year. Also reassess before major rollouts, such as licensing an assistant for everyone, after significant reorganizations, and after any security incident involving AI.

What should we gather before an AI readiness assessment?

Sharing reports, MFA and SSO coverage, logs of AI service use, the status of your AI policy, a list of AI tools in use, training and certification records, any list of AI ideas or pilots, and cloud budget settings, plus your organization's context and goals.

Scroll to Top