The 6-Dimension AI Readiness Framework, Explained

A friendly robot assistant fitting the sixth glowing hexagonal tile into a small honeycomb of five others while a young woman guides it into place

Most organizations think about AI readiness as one question with one answer: are we ready or not? In practice, readiness is uneven. An organization can have an excellent cloud platform and no AI policy. It can have a well-trained team and badly overshared documents. The sample report’s fictional manufacturer scores 50 on infrastructure and 25 on governance; a single “ready or not” answer would hide exactly the information that matters.

That’s why the AI readiness framework behind the AI Readiness assessment has six dimensions rather than one score. This post explains the dimensions, how the questions and maturity ladders work, why the dimensions are weighted equally, and how the pieces fit together into a plan.

The design principles

  • Built for mid-size organizations. It assumes a small IT team with broad responsibilities, not specialist AI, data, and risk departments.
  • Behavior, not intention. Each answer describes what an organization actually does, not what it plans. “A policy exists on paper only” and “published, trained, and acknowledged” are different levels.
  • Four questions per dimension. Enough to be meaningful, few enough to answer honestly in one sitting.
  • Equal weights and a plain average. Simple enough that anyone can check the math.
  • A floor rule for the dimensions that carry the most risk. If security or governance scores below 40, the overall rating is capped, whatever the average.
  • Deterministic scoring. The same answers always produce the same score.

The six dimensions

1. Data readiness

The question it asks: can AI find, trust, and safely use your data? Its four questions cover where core data lives, who owns quality, how well unstructured content is permissioned, and whether AI can reach data programmatically. The usual weak spot is overshared documents. See data readiness for AI.

2. Security and privacy

The question it asks: can you control what AI sees and where your data goes? Shadow AI, classification and DLP, identity and access, and AI vendor review. The usual weak spot is unmanaged use of public AI tools. See AI security readiness.

3. Infrastructure and platforms

The question it asks: do you have governed places for people to use and build AI? Cloud posture, enterprise AI access, operations automation, and cost visibility. Often the strongest dimension at mid-size organizations. See is your infrastructure ready for AI?

4. Skills and talent

The question it asks: can your people use, secure, support, and build AI? Hands-on skill, certifications, builders, and investment. The usual weak spot is enthusiasm without structure. See the AI skills gap on IT teams.

5. Use cases and value

The question it asks: do you know what AI is for, and can you prove it’s working? Use-case definition, progress beyond experimentation, sponsorship, and value measurement. The usual weak spot is pilots without baselines. See picking your first AI use case.

6. Governance and operating model

The question it asks: who decides, under what rules, with what visibility? Acceptable use policy, decision rights, regulatory mapping, and the AI inventory. Usually the weakest dimension. See AI governance for mid-size IT.

The asset: how to read any maturity ladder

Every one of the 24 questions has its own five-level ladder, but the levels follow a consistent pattern. Once you see it, you can place yourself on any question quickly:

  • Level 0, absent: nothing is in place, or nobody knows.
  • Level 1, aware or individual: the need is recognized, or a few individuals act on their own, but nothing is organized.
  • Level 2, partial: something exists but covers only part of the problem, or exists without follow-through.
  • Level 3, standard: it’s owned, documented, and applied across most of the organization.
  • Level 4, managed: it’s measured, reviewed on a schedule, and backed by technical controls or automation.

That pattern also tells you what “next quarter” looks like on any question. Moving from 1 to 2 usually means starting something. From 2 to 3, it means giving it an owner and making it standard. From 3 to 4, it means measuring and automating it. The complete ladders for all 24 questions are in the appendix of the sample report.

How the dimensions depend on each other

The six dimensions aren’t independent. Security and data overlap heavily, since permissions and classification belong to both. Skills enable nearly everything, because someone has to configure the controls and build the integrations. Governance ties the others together by deciding what’s allowed. Use cases are where the other five turn into business results. And infrastructure, usually the strongest, can’t compensate for weakness elsewhere: a mature cloud platform doesn’t make overshared documents safe.

Those dependencies suggest an order of work. Clear security and governance red flags first. Then fix the data your first use case depends on. Build skills alongside. Run the first use case with a baseline. Scale infrastructure as proven use cases need it.

Why equal weights

It would be possible to weight security more heavily than skills, or use cases more heavily than infrastructure. The framework deliberately doesn’t, for two reasons. Equal weights keep the math transparent, so anyone can check a score. And the real asymmetry, that security and governance gaps create risks the other dimensions can’t offset, is handled more directly by the floor rule than by weights. The result is simple to calculate and still honest about risk. How the 0 to 100 scale works covers the bands and the floor rule.

What the framework deliberately leaves out

A framework is defined as much by what it excludes as by what it includes. This one doesn’t compare AI products or models; which assistant is best changes every few months, and readiness shouldn’t depend on it. It doesn’t include industry-specific questions; industry, regulations, and platforms are captured as context alongside the 24 questions, so the recommendations can reflect them without the score becoming incomparable across industries. It isn’t a technical architecture review, although several questions touch architecture. And it doesn’t try to settle broad ethical questions in the abstract; those show up concretely, as policy, decision rights, and regulatory mapping in the governance dimension. Keeping the scope tight is what lets it be answered honestly in one sitting.

How this relates to risk management frameworks

A readiness framework and an AI risk management framework, such as the NIST AI Risk Management Framework, answer different questions. Readiness asks what stands between you and your next AI step. Risk management asks how you’ll govern AI risk on an ongoing basis. They fit together: the governance dimension of this framework is where adopting a risk management framework shows up, and a mid-size organization can use both without duplicating effort.

Using the framework

Score yourself with the AI readiness checklist, set next quarter’s target as one level above your current answer on the questions that matter most, and re-score every quarter. Or start with the free score to see roughly where you stand, then decide whether the full set of questions is worth running with your team.

Where does your team actually stand?

The free AI Readiness Score uses 10 of the 24 questions, spread across all six dimensions, and gives you a score in a few minutes.

Get your free AI Readiness Score →

Want every question and ladder in one place? Flip through a complete 38-page sample report.

Related guides

Frequently asked questions

What are the six dimensions of AI readiness?

Data readiness, security and privacy, infrastructure and platforms, skills and talent, use cases and value, and governance and operating model. Each has four questions scored on a 0 to 4 maturity ladder.

How do the 0 to 4 maturity levels work?

Level 0 is absent, level 1 is aware or individual effort, level 2 is partial, level 3 is standard, meaning owned, documented, and applied across most of the organization, and level 4 is managed, meaning measured, reviewed, and backed by controls or automation.

Why are the six dimensions weighted equally?

Equal weights keep the math transparent so anyone can check a score. The real imbalance, that security and governance gaps create risks other dimensions can't offset, is handled by the floor rule rather than by weights.

How is an AI readiness framework different from the NIST AI RMF?

They answer different questions. A readiness framework asks what stands between you and your next AI step. The NIST AI Risk Management Framework describes how to govern AI risk on an ongoing basis. They fit together, and adopting one shows up in the governance dimension of the other.

Scroll to Top