/ THE SHORT ANSWER
A company is not simply ready or unready for AI. It may be ready to pilot a cited document assistant and unready to automate a production decision. Readiness belongs to a named workflow, user group, data boundary, risk level, and desired outcome. Assess seven connected dimensions—problem, process, data, technology, people, governance, and measurement—and require evidence for each. The result should be a scoped decision: prepare the foundations, pilot selectively, or scale with governance, with owners and actions attached.
- 01Readiness is scoped: an organization can be ready for one use case and unready for another.
- 02A credible assessment distinguishes documented evidence, partial evidence, assumptions, and unknowns.
- 03Data readiness is not the same as having data; access, quality, timeliness, meaning, permission, and ownership all matter.
- 04User pull, workflow fit, manager support, and role clarity are part of readiness, not post-launch extras.
- 05The output should be an owned action plan and a decision gate, not a flattering maturity score.
/ dotSuper point of view
AI readiness should be assessed as evidence around a specific workflow and decision, because enterprise-wide maturity labels hide the local constraints that determine whether a pilot can be useful, adopted, governed, and measured.
Replace “Are we AI ready?” with a scoped question
The broad question produces broad answers about leadership, data, talent, infrastructure, governance, and culture. Those subjects matter, but an enterprise average can conceal the decision a sponsor needs to make. One team may have approved content, a visible workflow, ownership, and a baseline; another may rely on paper records and person-dependent decisions. One corporate grade cannot describe both.
A useful assessment asks whether defined users can improve a named decision inside a named workflow, using identified data and systems, within an agreed risk boundary, and prove the outcome against a baseline. NIST's risk framework is contextual, while ISO/IEC 42001 provides organization-level management-system guidance. Organization-wide governance creates the environment; workflow-level evidence supports the specific decision.
- Which workflow and current pain are in scope?
- Which decision, task, or handoff should improve?
- Who performs the work and who owns the outcome?
- What data, systems, and permissions are required?
- What consequence follows if the system is wrong, stale, unavailable, or misused?
- What baseline and evidence will support the next decision?
Assess seven connected dimensions
The dimensions are connected. Accessible data creates little value if nobody trusts its meaning. Willing users cannot rescue an undefined objective. Strong policy does not compensate for the absence of a process owner.
Problem readiness asks whether the pain is material, specific, and owned. Process readiness asks whether the current work, exceptions, handoffs, and decision rights are visible enough to redesign. Data readiness asks whether the required information is available, understandable, timely, representative, permissioned, and maintained. Technology readiness covers integration, identity, access, performance, security, and operating support.
People and adoption readiness examines whether the users see the need, have a meaningful role, can judge the output, and receive manager support, training, and safe escalation. Governance readiness addresses purpose, accountability, privacy, security, impact, vendor, human oversight, incident, and recordkeeping controls proportionate to consequence. Measurement readiness asks whether the team has a credible baseline, success criteria, evaluation set, cost model, and decision gate.
| Dimension | Question | Useful evidence | Common gap |
|---|---|---|---|
| Problem | Is a material, owned problem defined? | Problem statement, owner, cost or delay evidence | Technology selected before the problem |
| Process | Can the current workflow and exceptions be explained? | Process map, handoffs, volumes, exception log | The documented process differs from real work |
| Data | Is required information usable and permitted? | Source inventory, quality sample, labels, access and retention rules | Data exists but lacks meaning, access, or ownership |
| Technology | Can the intervention operate securely and reliably? | System interfaces, identity model, latency and support constraints | A demo cannot integrate with the operating environment |
| People | Can users adopt, judge, and challenge the system? | User interviews, role design, training and feedback plan | Adoption is reduced to licenses or attendance |
| Governance | Are purpose, controls, accountability, and incidents covered? | RACI, risk review, approvals, logs, escalation and rollback | A policy exists but no workflow control does |
| Measurement | Can the team prove whether to continue? | Baseline, evaluation set, operating metrics, cost and decision gate | Success means that a prototype was delivered |
Score evidence, not confidence
One-to-five self-ratings can reflect optimism or familiarity rather than operating conditions. Record the claim, evidence, owner, date, confidence, and action needed to close the gap. Unknown is a valid result.
“We have maintenance data” is only a claim until a sample shows relevant asset coverage, joinable service and failure records, aligned timestamps, understood gaps, access, and permission. Use four evidence states: documented and tested; documented but untested here; partially evidenced or dependent on unresolved work; unknown or absent. The next action may be a data sample, not a model build.
- Record the exact scope to which the evidence applies.
- Link or name the source rather than relying on workshop memory.
- Give every gap an owner and review date.
- Separate a fact from an assumption and an assumption from a preference.
- Recheck evidence after process, vendor, model, data, or policy changes.
Use readiness to make one of three decisions
The assessment should produce a decision for the scoped workflow. Prepare means foundations are too weak for a responsible pilot. Pilot selectively means a bounded test is feasible with controls and unresolved assumptions turned into evaluation tasks. Scale with governance means the intervention has evidence across quality, use, operating outcome, risk, and economics and can be supported beyond the pilot.
These are decision states, not prestige levels. Prepare may be right for a high-value opportunity; scale is not permanent approval and requires monitoring. The assessment may also conclude that standard work, data capture, search, reporting, or rules automation is better than AI.
| State | Meaning | Next action | Gate |
|---|---|---|---|
| Prepare | Material gaps prevent a responsible, measurable pilot | Fix the smallest blocking process, data, ownership, or control gap | Reassess when named evidence exists |
| Pilot selectively | A bounded test is feasible with controlled assumptions | Run on approved scope with representative evaluation and users | Continue only if predefined thresholds are met |
| Scale with governance | The workflow has evidence and an operating owner | Integrate, monitor, support, and expand in stages | Retain, redesign, reduce, or retire based on live evidence |
How to run a readiness assessment that changes a decision
Begin with preparation, not a large survey. Name the sponsor, workflow, users, desired decision, access boundaries, confidentiality requirements, and what decision the assessment must enable. Ask for a small evidence pack in advance: process documents, representative records, volumes, performance measures, system list, known incidents, and existing policies where relevant.
Observe the work with the people who do it. Compare the formal process with real handoffs, workarounds, queues, judgment calls, language needs, and exception paths. Review a sample of the actual data rather than accepting a data catalogue as proof of usability. Identify where a human uses tacit knowledge and what would happen if an AI output were plausible but wrong.
Then describe several intervention options, including non-AI options. Assess them against the seven dimensions and record the evidence state. Prioritize one starting point by value, feasibility, time to evidence, user impact, and risk. The assessment should leave behind a current-state workflow, gap register, bounded solution hypothesis, owner map, measurement plan, and next decision—not a catalogue of tools.
- Interview the sponsor, process owner, data/system owner, risk owner, and representative users.
- Walk through normal cases and exceptions using real artifacts.
- Sample data for meaning, quality, access, and permission.
- Define a no-AI or lower-complexity alternative.
- Freeze baseline gaps and success criteria before building.
- Agree a dated decision gate and the evidence required there.
Adoption belongs inside readiness
Adoption cannot be postponed until after a technical pilot. The workflow may change what information people see, which decisions they make, how performance is judged, and where accountability sits. Users need a meaningful role in defining the task, testing representative cases, setting escalation, and interpreting the output.
Microsoft's 2026 Work Trend Index reports associations between organizational conditions and self-reported AI impact in its sample; it does not establish universal causation. The practical implication is limited but useful: individual enthusiasm cannot compensate for work that has not been redesigned and supported.
Readiness evidence should include user pull, manager sponsorship, role clarity, training on verification and exceptions, a non-punitive feedback route, and time to learn. Track edits, overrides, escalations, abandoned use, and operating outcomes alongside logins or task volume.
Pause when the foundations are not defensible
Pause when nobody owns the outcome, the baseline cannot be measured, the process cannot be observed, required data use is not approved, material vendor questions remain unanswered, representative evaluation is impossible, or users cannot challenge the system.
Also pause when the case depends on an unsupported percentage, unrestricted write access is requested before lower-risk value is proven, or launch itself defines success. The next deliverable may be an owner, process map, data sample, risk review, evaluation set, or simpler workflow. End with a narrow, dated statement: ready for what, for whom, with which data and systems, under which controls and unresolved assumptions.
What this page cannot conclude
- 01The seven dimensions are dotSuper synthesis and are not an official NIST, ISO, Microsoft, or UAE assessment instrument.
- 02ISO/IEC 42001 describes an AI management system; this article does not provide certification guidance or establish conformity.
- 03Readiness is time-bound and scope-bound; changes to data, vendors, models, users, integrations, or regulation can invalidate an earlier conclusion.
- 04Microsoft's cited research includes self-reported measures and Microsoft-product telemetry; associations should not be interpreted as universal causation.
- 05The article is educational and does not replace legal, privacy, security, safety, or sector-specific professional review.
Sources
- 01NIST AI Resource CenterNational Institute of Standards and Technology · accessed Aug 30, 2026
- 02NIST AI RMF PlaybookNational Institute of Standards and Technology · accessed Aug 30, 2026
- 03ISO/IEC 42001:2023 — AI management systemsInternational Organization for Standardization · accessed Aug 30, 2026
- 042026 Work Trend Index: Agents, human agency, and the opportunity for every organizationMicrosoft · accessed Aug 30, 2026
Turn a broad AI ambition into a defensible first decision
The AI Readiness Sprint examines the work, data, people, controls, and baseline around one material workflow, then recommends the smallest justified next step.
Explore the AI Readiness Sprint