Max HumphreyFractional CTO, GRC & PMO
Book a call LinkedIn ↗
Services Experience Case Studies Free Assessment Contact LinkedIn Book a call →
Free Tool

AI Readiness Assessment

See where your organization actually stands before you invest in AI.

AI Readiness Assessment

Ten questions across the three things that actually determine whether AI works for your business: how well your processes and data are mapped, how mature your security posture is, and how clear your AI strategy actually is. About 2 minutes.

Process Discovery Security Maturity AI Strategy
See all 10 questions
Process Discovery
  1. How well-defined are your core business processes and workflows?

    • They mostly exist in people's heads, not written down.
    • Some are documented, but inconsistently and often out of date.
    • Our core processes are documented, consistent, and followed.
    • They're documented, followed, and reviewed and improved on a regular basis.
  2. Are your workflows mapped to the specific systems and applications that support them?

    • We don't have a clear picture of which systems support which workflows.
    • We have a rough idea, but nothing documented.
    • We've mapped our core workflows to the systems and applications behind them.
    • Every workflow is mapped end-to-end to its systems, and that map is kept current.
  3. Is there one authoritative source of truth for your key records and workflow/IT documentation?

    • Records and documentation live in scattered spreadsheets, inboxes, and people's heads.
    • We have some central records, but multiple versions or copies float around.
    • We maintain a single source of truth for our key records and documentation.
    • That source of truth is actively maintained, access-controlled, and used company-wide.
Security Maturity
  1. Are your security-relevant terms and data clearly defined — what counts as sensitive data, who owns what?

    • No shared definitions exist.
    • Some informal understanding exists, but nothing written down.
    • We have written definitions for our data classifications and ownership.
    • Definitions are documented, trained on, and consistently applied across the business.
  2. Do you follow a defined set of security standards — password policy, device management, access control?

    • We don't have any formal security standards.
    • We have some informal habits, but nothing written or enforced.
    • We have written security standards that are generally followed.
    • We follow a recognized framework (like NIST or CIS Controls) and audit against it regularly.
  3. Do you have defined security processes — for access onboarding/offboarding, patching, or incident response?

    • No, security tasks happen ad hoc, if at all.
    • Some processes exist informally, but they're inconsistent.
    • We have documented processes for our key security tasks.
    • Processes are documented, followed consistently, and tested or reviewed regularly.
  4. Do you maintain a risk register — a living list of known security risks and how you're addressing them?

    • We don't track security risks anywhere.
    • We're aware of some risks, but nothing is written down or tracked.
    • We maintain a risk register that we update occasionally.
    • We maintain and actively review a risk register as part of ongoing operations.
AI Strategy
  1. Does your business have clear, specific goals for what AI should accomplish?

    • We haven't defined any specific goals for AI.
    • We have a general interest in AI, but no specific goals.
    • We have specific goals for AI tied to business priorities.
    • Our AI goals are specific, tied to priorities, and we measure progress against them.
  2. Are expectations about what AI can and can't do clearly set across your team and leadership?

    • There's no shared understanding of what AI can realistically do for us.
    • Expectations vary a lot depending on who you ask.
    • We have a reasonably shared, realistic understanding of AI's capabilities and limits.
    • Expectations are explicitly documented, communicated, and revisited as things change.
  3. Do you have a way to manage the risks that come with using AI — accuracy, bias, data privacy, over-reliance?

    • We haven't thought about AI-specific risks.
    • We're aware AI carries risks, but we don't manage them formally.
    • We have some guardrails in place for how AI is used.
    • We have a defined process for evaluating and managing AI-specific risk before and after adoption.