/ THE SHORT ANSWER
A team is ready when it can identify the authoritative sources, owners, users, permissions, update and deletion paths, representative questions, unacceptable answers, and a human escalation route. Documents do not need to be perfect, but the system must know which sources are trusted and what happens when they conflict, expire, or do not answer the question. If the organisation cannot maintain the knowledge base, the chatbot will expose rather than solve the problem.
- 01Name authoritative sources and owners before ingestion.
- 02Build the evaluation set from real user questions and failure cases.
- 03Design update, deletion, permissions, and escalation as first-class workflows.
/ dotSuper point of view
RAG readiness is source governance plus question governance. The model sits between them; it cannot invent a reliable operating discipline.
What the evidence says
The NIST Generative AI Profile identifies risks related to confabulation, information integrity, privacy, security, and human-AI configuration.
OWASP’s LLM application guidance highlights prompt injection, sensitive-information disclosure, vector and embedding weaknesses, excessive agency, and other system-level risks.
A practical decision framework
The following framework is dotSuper’s operating synthesis of the cited guidance. It is designed to make the decision inspectable, not to imitate a platform ranking formula, certification checklist, or legal test.
- Sources: authority, format, quality, version, owner, and permitted audience.
- Questions: user, job, frequency, decision consequence, and expected evidence.
- Answers: grounding, citation, refusal, uncertainty, and escalation.
- Operations: ingestion, deletion, evaluation, monitoring, incident response, and change control.
| Step | Decision to record |
|---|---|
| 01 | Sources: authority, format, quality, version, owner, and permitted audience. |
| 02 | Questions: user, job, frequency, decision consequence, and expected evidence. |
| 03 | Answers: grounding, citation, refusal, uncertainty, and escalation. |
| 04 | Operations: ingestion, deletion, evaluation, monitoring, incident response, and change control. |
How to put it into practice
Run a source workshop before selecting architecture. Resolve duplicates, unclear ownership, obsolete documents, and permission boundaries on the highest-value question set.
Create a golden set containing answerable, multi-source, conflicting, outdated, restricted, and unanswerable questions. Record the evidence expected and what a safe response should do.
- Name the accountable owner and the decision this work must enable.
- Record the current evidence, assumptions, exclusions, and next review trigger.
- Measure a useful outcome rather than treating publication or deployment as success.
What this page cannot conclude
- 01Passing a readiness checklist does not guarantee retrieval or answer quality.
- 02Sensitive, regulated, or safety-critical knowledge requires specialist controls and review.
- 03Publication, technical eligibility, or good practice cannot guarantee ranking, referral traffic, citation, adoption, or a business outcome.
Sources
- 01Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNational Institute of Standards and Technology · accessed Aug 30, 2026
- 02OWASP Top 10 for LLM Applications 2025OWASP GenAI Security Project · accessed Aug 30, 2026
- 03AI Risk Management FrameworkNational Institute of Standards and Technology · accessed Aug 30, 2026
Test the workflow before funding the solution.
The AI Readiness Sprint turns one operational constraint into a ranked decision, an accountable owner, and an implementation-ready first move.
Explore the readiness sprint