When leadership asks “are we ready for AI?”, the instinct at many organizations is to hire someone to find out. Sometimes that’s the right call. But a consulting engagement takes weeks of meetings and a significant budget, and much of what it produces is information your own team already has or can get. The part that’s genuinely hard to do yourself isn’t gathering the facts. It’s structuring them so they add up to an honest answer.
Here’s how to measure AI readiness with your own team in about two weeks. It needs three things: a fixed framework so you’re not inventing criteria as you go, evidence rather than opinions, and a small group willing to be honest about what they find.
What you need before you start
- A framework. Use a fixed set of questions with defined answers, so the result doesn’t depend on who’s in the room. The 24 questions in the AI readiness checklist cover six dimensions, each with a 0 to 4 maturity ladder. The full ladders are in the appendix of the public sample report.
- Four to six people. The IT leader, whoever owns security, one or two business leaders, and ideally someone from finance or operations. A group that’s all IT will score business questions generously and miss what the business sees.
- Two weeks of part-time effort: most of it evidence gathering, plus one 90-minute workshop.
The asset: a two-week measurement process
Day 1: assign dimensions
Give each person one or two of the six dimensions to gather evidence for: data, security, infrastructure, skills, use cases, and governance. The owner of a dimension doesn’t decide its score; they bring the facts to the workshop.
Days 2 to 7: gather evidence
For each question, find something concrete. Examples of useful evidence:
- Data: the sharing reports from your collaboration platform; a list of which systems hold customer, product, and employee data; whether each has a named owner.
- Security: web proxy or DNS logs showing AI site usage; MFA and SSO coverage reports; whether any sensitivity labels are actually applied; your vendor review questionnaire.
- Infrastructure: which enterprise AI tools are licensed; whether budgets and alerts exist on cloud accounts; where scripts and automations are stored.
- Skills: training records; a list of current certifications; the names of anyone building with AI.
- Use cases: any list of AI ideas; pilots underway and whether they had baselines; who sponsors AI at the leadership level.
- Governance: the acceptable use policy, if one exists, and whether employees acknowledged it; who approved the last AI tool; any inventory of AI in use.
The evidence for shadow AI is often the most revealing. Auditing your own logs shows how to get it.
Day 8: the 90-minute scoring workshop
- Score independently first. Everyone answers all 24 questions alone before the meeting, choosing the ladder level that matches today, not the plan.
- Compare. Put everyone’s answers side by side. Where people agree, move on quickly.
- Discuss the disagreements. This is where the value is. If IT scores a question at 3 and a business leader scores it at 1, one of them is seeing something the other isn’t. The dimension owner presents the evidence, and the group settles on the answer the evidence supports.
- When in doubt, score lower. An honest low score leads to a useful plan. An optimistic score leads to surprises.
Day 9: calculate
Each dimension’s score is the points earned divided by the 16 points possible, times 100. The overall score is the average of the six. Then apply the floor rule: if security or governance is below 40, the overall rating can’t be higher than Emerging, however good the average looks. How the 0 to 100 scale works covers the bands in detail.
Days 10 to 14: prioritize and write it up
Sort what you found into three lists:
- Red flags: answers that create exposure now, such as broadly overshared content or unmanaged use of public AI tools. These come first, whatever the score.
- Quick wins: low-scoring questions where the next level up takes weeks, not quarters. Publishing a drafted policy is the classic example.
- Foundations: your weakest dimension overall, which will need sustained work.
Then write a one-page summary: the six dimension scores, the overall score and band, the red flags, three quick wins, and the priorities for the next 90 days, each with an owner.
The one-page summary
Keep the write-up to a single page, in this order, so a busy executive can read it in two minutes:
- The headline: overall score, band, and one sentence on the shape, such as “infrastructure is ahead of our guardrails.”
- The six dimension scores, with the weakest one called out.
- Red flags, each with an owner and a date.
- Three quick wins for the next 30 days.
- Priorities for the next 90 days, each with an owner.
- What we’re not doing yet, and why, such as holding off on broad licensing until permissions are cleaned up.
Presenting it to leadership
Lead with the plan, not the score. Leaders react to a low number by asking whose fault it is; they react to a clear plan by asking what it needs. Show the score as the reason for the plan, name the owners, and ask for the specific decisions or resources the first 90 days require. And be candid about the red flags. A leadership team that hears about a risk from IT, with a fix already in motion, trusts IT’s judgment on everything that follows.
Biases to watch for
Paper maturity. “We have a policy” often means a document nobody has read. Score what’s in practice, not what’s written down.
Counting pilots as production. A pilot with enthusiastic users isn’t a use case in production with measured results.
Averaging away the red flags. A good overall score with one red flag is still a problem. List red flags separately so they can’t be diluted.
IT scoring for the business. Questions about use cases, sponsorship, and value need business voices in the room.
When a do-it-yourself assessment is enough
For internal prioritization, deciding what to work on first and tracking progress quarter to quarter, this process is usually enough. Your team knows your environment better than any outsider, and the framework keeps the result honest.
Outside help earns its cost in a few specific situations: when you need a document to put in front of the board or a CFO, when you want recommendations benchmarked against how other organizations handle the same gaps, when the team is too close to the problem to score it candidly, or when nobody has the time to write it up. Consultant vs. assessment product vs. DIY compares the options, and what a real AI readiness report looks like shows what a finished deliverable contains.
Measure again next quarter
The first measurement is a baseline. The second is where it gets useful, because you can see which dimensions moved and whether the priorities you chose actually changed anything. Re-run the workshop each quarter with the same people and the same framework. After the first round, it takes about half the time.
Where does your team actually stand?
If you want a quick starting point before running the full exercise, the free AI Readiness Score uses 10 of the 24 questions, spread across all six dimensions, and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see every question and ladder first? Flip through a complete 38-page sample report.
Related guides
- The AI Readiness Checklist: 24 Questions to Answer Before Spending a Dollar
- Shadow AI Statistics Are Scary. Your Own Logs Are Scarier
- What’s Your AI Readiness Score? How the 0–100 Scale Works
- AI Readiness Consultant vs. Assessment Product vs. DIY
- What a Real AI Readiness Report Looks Like (38-Page Example)
Frequently asked questions
Can we measure AI readiness without a consultant?
Yes, for internal prioritization. You need a fixed framework such as the 24-question checklist, four to six people including business leaders, evidence rather than opinions, and about two weeks of part-time effort with one 90-minute scoring workshop.
Who should take part in an AI readiness self-assessment?
The IT leader, whoever owns security, one or two business leaders, and ideally someone from finance or operations. A group made up only of IT tends to score business questions generously and miss what the business sees.
How do we avoid bias when scoring ourselves?
Have everyone score independently before the workshop, discuss only the disagreements, back every answer with evidence, and score lower when in doubt. Watch for paper maturity, pilots counted as production, and red flags averaged away.
When is outside help worth paying for?
When you need a document for the board or CFO, want recommendations benchmarked against how other organizations handle the same gaps, need an outside view because the team is too close to the problem, or don't have time to write it up.




