Self-assessment
AI readiness assessment: is your business ready for AI?
For engineers and risk teams: the scoring model and framework mapping
What this assessment checks
An AI readiness assessment checks whether an organisation has what it needs before it spends money building with AI: someone senior who owns the outcome, a clear idea of the value, data and systems that can support the work, and the controls to run it safely. The gaps it finds are cheapest to fix before anything is built.
This one scores 13 questions across five areas. The areas follow the discovery method we use in our AI Opportunity & Feasibility Sprint, checked against two public sources: the NIST AI Risk Management Framework, and the UK government's consultation on AI Management Essentials. Your answers are scored on this page. Nothing is sent to us.
- Ownership and value
- One senior person owns the outcome, and the value is written down as a number. 2 questions.
- The work today
- The process AI would change is mapped as it really runs, and it is measured. 2 questions.
- Data and systems
- The data exists in usable shape, access to it is controlled, and the systems involved can be reached. 3 questions.
- Choosing what to build
- Ideas are compared on value, feasibility and risk, and buying has been weighed against building. 2 questions.
- Controls and people
- Staff use of AI is known and governed, sign-off is agreed early, live systems are watched, and users are trained. 4 questions.
The assessment: 13 questions
Pick the answer closest to where you are today, not where you plan to be. Your result appears at the end.
Ownership and value
One senior person owns the outcome, and the value is written down as a number.
The work today
The process AI would change is mapped as it really runs, and it is measured.
Data and systems
The data exists in usable shape, access to it is controlled, and the systems involved can be reached.
Choosing what to build
Ideas are compared on value, feasibility and risk, and buying has been weighed against building.
Controls and people
Staff use of AI is known and governed, sign-off is agreed early, live systems are watched, and users are trained.
Your result
0 of 13 questions answered. Your score, what it means and your next step appear here once every question is answered. If this page is not scoring for you, add up your answers (0, 1 or 2 each, in the order shown) and use the bands below.
What your score means
- Each question has three answers, scored 0, 1 and 2 in the order shown. The most you can score is 26.
- Your total sets your band: 0 to 9 is Not ready to build yet, 10 to 18 is Ready to plan, and 19 to 26 is Ready to build.
- One rule overrides the total. If nobody senior owns the outcome (the first answer to question 1), the result is Not ready to build yet, whatever the total. No outside team can stand in for an owner who is not there.
- Every answer that scores below 2 is listed in your result as a gap, with the next action for it.
| Dimension | Score | What it means | Sensible next step |
|---|---|---|---|
| Not ready to build yet | 0 to 9 | The basics are missing: an owner, a number for the value, or a clear view of the work and the data. Money spent building now is likely to stall. | Fix your gaps yourselves before paying anyone to build: name an owner, pick one process and measure it, and find out where its data lives. Outside help is rarely the answer at this stage. |
| Ready to plan | 10 to 18 | Parts of the ground are in place. What is missing is a plan: which use case comes first, whether the data holds up, and what sign-off will need. | Run a short, fixed-scope discovery that ranks your use cases against your real data and systems and ends in a costed plan. You can run it in-house if someone can judge the business case and the engineering together, or buy one. Our AI Opportunity & Feasibility Sprint is one option. |
| Ready to build | 19 to 26 | You have an owner, a valued use case, workable data and agreed controls. The next risk is building something that never reaches the people who do the work. | Build one real workflow end to end, in your own systems and against your own data, and measure it against the baseline. Your own team, a product that fits, or an outside team can do this; the point is a working system, not a demonstration. |
The Sprint is one route among several. If your band is Ready to plan and you want an outside view, see the AI Opportunity & Feasibility Sprint, or compare our services with the four checks to run on any supplier.
For engineers and risk teams
For engineers and risk teams: the scoring model, framework mapping and limits
The model is deliberately unweighted: 13 questions, three ordinal answers each, summed to a total out of 26. Weighting would imply a precision a self-reported score does not have. The single override is ownership, because no outside team can stand in for an absent owner, however good the data is.
Most questions map to a step of the Sprint's discovery method and, where one fits, to subcategories of the NIST AI RMF 1.0 core. The mapping is our reading of the framework. It is not a NIST conformity check, and NIST does not endorse this assessment. The systems-access question has no direct RMF equivalent; it is kept because the Sprint's feasibility step establishes which systems would have to be touched.
Three questions are not from the Sprint. Question 4 asks for a baseline, because the value in question 2 cannot be checked without one. Questions 12 and 13 come from two gaps respondents named in the UK AI Management Essentials consultation. Those gaps were monitoring AI systems after deployment, and building AI skills across the organisation.
Respondents also noted that organisations using AI as a service often cannot see a vendor's internal processes. If you buy rather than build, ask the vendor what they will disclose.
Limits: answers are self-reported and unchecked, and nothing here tests your data or systems. The bands are cut points we chose, not a benchmark against other organisations.
| Dimension | Where it comes from | NIST AI RMF 1.0 |
|---|---|---|
| 1. Is one senior person accountable for what AI should achieve here, with the authority to release budget? | Leadership sessions | GOVERN 2.1, GOVERN 2.3 |
| 2. Can you say, in money or hours, what the first AI project should change? | Leadership sessions | MAP 1.4, MAP 3.1 |
| 3. Is the work you want AI to help with written down as it actually happens, including the spreadsheets and manual steps? | Workflow analysis | MAP 1.1 |
| 4. Do you measure that work today: how long it takes, what it costs, or how often it goes wrong? | Added: needed to check the value in question 2 | MAP 3.1 |
| 5. Do you know where the data for that work lives, and what state it is in? | Data and systems feasibility | MAP 2.3 |
| 6. Is it clear who may see that data, and could an AI tool be held to the same rules? | Data and systems feasibility | MAP 1.6 |
| 7. Can the systems involved be connected to, and does someone own that connection? | Data and systems feasibility | No direct equivalent |
| 8. Do you have a shortlist of possible AI uses, compared on value, how hard each is to deliver, and risk? | Opportunity map | MAP 3.1, MAP 3.2 |
| 9. For the top idea, have you checked whether a product you could buy already does it? | Build versus buy | GOVERN 6.1, MAP 4.1 |
| 10. Do you know which AI tools your staff already use, and is there a written rule on what data may go into them? | Governance review | GOVERN 1.4, GOVERN 1.6 |
| 11. Is it agreed what your legal, security and risk teams need to see before an AI system goes live? | Governance review | GOVERN 1.1, MAP 1.5 |
| 12. Once an AI system is live, is it agreed who checks its work and what happens when it gets something wrong? | Added: AIME consultation gap | MANAGE 4.1, MEASURE 3.1 |
| 13. Have the people who will use AI been trained on what it does well, where it goes wrong, and the rules for using it? | Added: AIME consultation gap | GOVERN 2.2, MAP 3.4 |
Frequently asked questions
What is an AI readiness assessment?
An AI readiness assessment is a structured check of whether an organisation can start using AI productively: whether someone owns the outcome, the value is defined, the data and systems can support the work, and the controls to run it are agreed. It is done before money is committed to building, so the gaps are found while they are cheap to fix.
What is the difference between AI readiness and AI maturity?
Readiness asks whether you can start. Maturity asks how well you already run AI across the organisation. This assessment is a readiness check: it is most useful before the first or second AI project, and questions 10 to 13 cover the controls a more mature organisation would already have in place.
Is there a UK government-backed AI readiness assessment?
Yes. Innovate UK's BridgeAI programme offers the AI Adoption Assessment Toolkit, built by Digital Catapult for UK startups, scaleups and small and medium-sized businesses. It covers digital maturity, AI readiness, data readiness, data ethics and MLOps maturity. Separately, the Department for Science, Innovation and Technology consulted on a self-assessment tool called AI Management Essentials from 6 November 2024 to 29 January 2025. In its response, published on GOV.UK on 6 February 2026, it said it will not publish that tool, and plans guidance on foundational AI governance aimed at small and medium-sized businesses.
How much does a paid AI readiness assessment cost?
It depends on the scope. One published example is Gartner's G-Cloud 14 pricing document, published in 2024, which lists an AI Capability Maturity Assessment at £142,400 as a fixed-price service. This self-assessment is free, and it is not a substitute for a review of your actual data and systems. Our AI Opportunity & Feasibility Sprint is fixed scope and typically takes two to four weeks; it is not priced on this page.
Do we need outside help to become ready for AI?
Often not for the early gaps. Naming an owner, putting a number on the value, mapping the current process and listing the AI tools staff already use are internal jobs. Outside help earns its fee where the business case and the engineering have to be judged together: ranking use cases against real data and systems, and designing the controls.
Is this assessment an audit or a certification?
No. It is a self-assessment: the score is only as accurate as your answers, and nobody checks them. It does not test your data or systems, and it is not a conformity assessment against the NIST AI Risk Management Framework or any standard.
What happens to my answers?
They stay in your browser. The score is worked out on this page, there is no sign-up or email, and the answers are not stored, so refreshing the page clears them.
Sources
- [1]1AYM, AI strategy and roadmap: the AI Opportunity & Feasibility Sprint and its discovery method
- [2]NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023 (read 29 September 2026)
- [3]Department for Science, Innovation and Technology, AI Management Essentials tool: consultation and outcome, GOV.UK, updated 6 February 2026 (read 29 September 2026)
- [4]Department for Science, Innovation and Technology, Government response to the consultation on AI Management Essentials (read 29 September 2026)
- [5]Innovate UK Business Connect, AI Adoption Assessment Toolkit from Digital Catapult, Innovate UK BridgeAI programme (read 29 September 2026)
- [6]Digital Catapult, AI Adoption Toolkit (read 29 September 2026)
- [7]Gartner, G-Cloud 14 pricing document, 2024 (read 29 September 2026)
Further
- AI Opportunity & Feasibility Sprint · The fixed-scope discovery most of these questions come from, typically two to four weeks.
- AI consulting services · The nine areas we work in, from strategy to engineers in your programme.
- How to choose an AI supplier · Four checks to run on any firm before you buy, with published UK prices.
- Data platform & AI enablement · Where to look if your gaps are in the data and systems questions.
- Agent proposes, verifier gates · The control pattern behind the monitoring and sign-off questions.
Want a second opinion on your result?
Bring your score and your gaps to a 30-minute call. We will tell you honestly whether you need outside help yet.
Last reviewed · 1AYM