The AI spending I see disappoint most often wasn’t a bad choice of tool. It was money committed before anyone checked whether the organization could use the tool safely and well. Licenses bought before permissions were cleaned up. A consultant hired to build something before anyone owned the data it needed. A pilot funded before anyone captured a baseline to prove it worked.
This AI readiness checklist is the set of questions to answer first. It’s the same 24 questions I use in the AI Readiness assessment, four in each of six dimensions: data, security, infrastructure, skills, use cases, and governance. Answer them honestly and you’ll know where you’re ready, where you’re not, and which spending should wait.
How to use the checklist
Each question has a five-level maturity ladder, from 0 to 4. For each question below I’ve shown what level 3 looks like, because level 3 on every question in a dimension puts it at 75 out of 100, inside the range the assessment rates as Ready. The full ladders for all 24 questions are public in the appendix of the sample report.
Three rules make the checklist useful rather than a box-ticking exercise:
- Answer with evidence. “We think so” isn’t an answer. For each question, write one line on how you know.
- Answer as a group. IT, security, and at least one business leader. Each will see things the others miss.
- Don’t wait for level 3 everywhere. You can start before you’re ready across the board. The spending gates further down say what has to come first.
Check the red flags first
Some answers matter more than the average suggests. In the assessment, red-flag answers go to the top of the risk list whatever your overall score. The two I see most often are unstructured content that’s broadly overshared (question D3) and employees using public AI tools with work data and no controls (question S1). Both turn into data exposure the moment an assistant is switched on or a new tool catches on.
The assessment also applies a floor rule: if security or governance scores below 40, the overall rating is capped at Emerging, however strong the other dimensions are. You can’t average your way past leaking data.
The 24 questions
Data Readiness
Overview: the data pillar guide.
- D1. Where does most of your core business data live today?
Level 3 looks like: A central warehouse or lakehouse covers some key domains. Guide - D2. Who is accountable for data quality?
Level 3 looks like: Named owners for most data domains, with documented quality standards. Guide - D3. How well organized and permissioned is your unstructured content (SharePoint, Google Drive, file shares, wikis, ticket history)?
Level 3 looks like: Most repositories have owners, retention rules, and reviewed permissions. Guide - D4. Can AI tools get to your data programmatically?
Level 3 looks like: Most key systems are reachable through APIs or standard connectors. Guide
Security & Privacy
Overview: the security pillar guide.
- S1. Which statement best describes employee use of AI tools today?
Level 3 looks like: We provide approved AI tools and discourage or block unapproved ones. Guide - S2. How do you classify and protect sensitive data?
Level 3 looks like: Labels plus DLP enforced on email, endpoints, and cloud storage. Guide - S3. How mature is your identity and access management?
Level 3 looks like: SSO, role-based access, and periodic access reviews. Guide - S4. Before adopting an AI tool or AI feature, do you review how the vendor handles your data?
Level 3 looks like: Vendor review includes AI questions (training on our data, retention, data residency). Guide
Infrastructure & Platforms
Overview: the infrastructure pillar guide.
- I1. Which best describes your infrastructure today?
Level 3 looks like: Majority cloud/SaaS with a defined cloud strategy. Guide - I2. What access does your organization have to enterprise AI platforms?
Level 3 looks like: An enterprise AI assistant licensed for at least one department. Guide - I3. How automated are your IT operations?
Level 3 looks like: Automation is standard: version control, runbooks, an integration platform. Guide - I4. Can you see and control what you spend on cloud and SaaS?
Level 3 looks like: Budgets, alerts, and tagging for most services. Guide
Skills & Talent
Overview: the skills pillar guide.
- K1. How hands-on is your IT team with AI tools?
Level 3 looks like: Most of the IT team has completed structured AI training. Guide - K2. How many of your IT staff hold current cloud or AI certifications?
Level 3 looks like: AI-related certifications held by people in key roles (cloud, security, data). Guide - K3. Does anyone on staff build with AI (APIs, automations, agents)?
Level 3 looks like: A named person or small team owns AI builds. Guide - K4. How much time and budget do you invest in AI upskilling?
Level 3 looks like: Dedicated AI training budget and protected learning time. Guide
Use Cases & Value
Overview: the use cases pillar guide.
- U1. How well defined are your AI use cases?
Level 3 looks like: A prioritized backlog with business owners. Guide - U2. How far has AI gone beyond experimentation?
Level 3 looks like: At least one use case in production with measured results. Guide - U3. What executive sponsorship and funding does AI have?
Level 3 looks like: Sponsor plus funded pilots. Guide - U4. How do you measure the value of AI?
Level 3 looks like: Business outcome metrics for some use cases (time saved, cost, quality). Guide
Governance & Operating Model
Overview: the governance pillar guide.
- G1. Do you have an AI acceptable use policy?
Level 3 looks like: Published, trained, and acknowledged by employees. Guide - G2. Who decides which AI tools and projects get approved?
Level 3 looks like: A cross-functional group (IT, security, legal, business). Guide - G3. How have you addressed the AI regulations and standards that apply to you?
Level 3 looks like: Applicable requirements mapped (e.g., EU AI Act, state AI laws, industry rules). Guide - G4. Do you keep an inventory of AI in use, including AI features inside your SaaS apps?
Level 3 looks like: Complete inventory with an owner and data types for each tool. Guide
Scoring it yourself
The scoring is simple enough to do in a spreadsheet. Each answer earns its level, 0 to 4. A dimension’s score is the points earned divided by the 16 points possible, times 100. The overall score is the plain average of the six dimension scores. The assessment then places the result in one of four bands: Not Ready (0 to 39), Emerging (40 to 59), Ready (60 to 79), or Leading (80 to 100). How the 0 to 100 scale works explains the bands and the floor rule in more detail.
The asset: spending gates
The point of the checklist is to decide what to spend money on, and when. These are the gates I recommend. Each names the questions that should reach a certain level before a type of spending goes ahead.
- Broad AI assistant licenses: wait until D3 (content permissions) is at 2 or above for your most sensitive sites, S3 (identity) is at 2 or above, and G1 (acceptable use policy) is published. A pilot for one team can start sooner.
- Building on cloud AI services: wait until I4 (cost visibility) is at 3, with budgets, alerts, and tagging, and a governed place to build exists.
- Hiring an AI specialist or paying for a custom build: wait until U1 (use cases) is at 3, a prioritized backlog with business owners, and U3 (sponsorship) is at 2 or above. Otherwise you’re paying someone to find out what to build.
- A data platform: wait until D2 (data ownership) is at 2 or above and a specific use case needs what the platform provides.
- AI training: no gate. Start now; it makes every other gate easier to pass.
Where to start
Fix any red flags first. Then look at your lowest-scoring dimension, not your lowest single question; a whole dimension that’s weak slows everything that depends on it. Within that dimension, pick the question where moving up one level is quickest. The level above your current answer is next quarter’s goal.
If you’d rather have the scoring, risks, and a 90-day plan worked out for you, that’s what the assessment is for. What an AI readiness assessment for IT teams covers explains the difference between a checklist and a scored assessment.
Where does your team actually stand?
The free AI Readiness Score uses 10 of these 24 questions, spread across all six dimensions, and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want all 24 questions with their full ladders? Flip through a complete 38-page sample report; the appendix has every one.
Related guides
- Data Readiness for AI: The Five-Question Audit
- Where Should Your Business Data Live Before AI?
- Who Should Own Data Quality? Why “Nobody” Breaks Your First AI Project
- Fix SharePoint Oversharing Before You Turn On Copilot
- APIs Before Agents: Giving AI Access to Your Systems Safely
Frequently asked questions
What questions are in an AI readiness checklist?
Twenty-four questions, four in each of six dimensions: data readiness, security and privacy, infrastructure and platforms, skills and talent, use cases and value, and governance and operating model. Each is answered on a 0 to 4 maturity ladder.
What score counts as ready?
Level 3 on every question in a dimension gives that dimension 75 out of 100, inside the Ready band of 60 to 79. So Ready roughly means most answers are at level 3: owned, documented, and reviewed rather than ad hoc.
Which checklist answers are red flags?
The two I see most often are broadly overshared unstructured content and employees using public AI tools with work data and no controls. Red flags go to the top of the risk list whatever the overall score, because both become data exposure quickly.
What should we not spend money on until the checklist says we're ready?
Broad assistant licenses before permissions, identity, and a policy are in place; building on cloud AI services before cost controls exist; custom builds or AI hires before you have a prioritized use-case backlog with owners. Training has no gate: start now.




