← Back to the journal

Operating Intelligence

AI Readiness Assessment: Measure Whether Your Business Is Ready

By Dean Fribence, Sales, Catalyst Systems·27 August 2026· 6 min read
A graphite calibration bench testing process, data and human control supports with a precise terracotta plumb line before AI installation.

An AI readiness assessment measures whether a business has the conditions to use AI for a defined purpose. It should test goals, workflows, information, people and governance, then turn the gaps into an ordered plan.

It should also be allowed to produce an inconvenient answer: not yet.

Readiness is not a count of software subscriptions. It is not whether a few staff use a chatbot, or whether a vendor can run an impressive demonstration. A business can be technically capable and still be unready because the problem is vague, the process changes by person, the information is unreliable or nobody owns the result.

The point of assessment is to avoid making those weaknesses faster.

Assess a use case, not “AI” in general

A company-wide question such as “Are we ready for AI?” is too broad to answer honestly. Readiness changes by use case.

A team may be ready to draft internal meeting summaries with review, but not ready to automate client advice. The same business may have clean service records and poor customer consent records. Risk, information and oversight differ with the work.

Start with one sentence:

We want to improve this process for these people, using this information, measured by this outcome.

The National AI Centre's Get ready for AI guidance asks businesses to connect AI to business goals, support people, establish accountability, ensure data is fit for purpose and review end-to-end processes. That is a useful structure because it keeps the assessment tied to operating conditions.

If the problem cannot be stated clearly, do not score the tool. Map the work first. Our guide to systemising a small business helps identify the ownership, inputs and exceptions hidden inside repeat work.

Measure five kinds of readiness

A practical AI readiness assessment should cover five connected areas.

1. Goal readiness

Can the team name the burden, target outcome, affected people and baseline? “Use AI to improve productivity” is not measurable. “Reduce the time between a complete enquiry and first reviewed response, without increasing corrections” is.

Look for a named owner, an in-scope process and a measure that matters to the person receiving the work.

2. Workflow readiness

Is the current process visible? Are its trigger, finish, owners, exceptions and decision rights understood? AI often changes roles and handoffs, not just the task itself.

A workflow is not ready when each person follows a different path, senior staff catch errors informally or important decisions happen in private messages. That is the pattern behind workflows that make AI adoption too hard.

3. Information readiness

Is the required information accurate, accessible, current and permitted for the purpose? Which source wins when records conflict? Can access be limited to what the use case needs?

The Office of the Australian Information Commissioner says privacy obligations apply to personal information entered into AI and to AI outputs containing personal information. Its commercial AI guidance calls for due diligence, human oversight and privacy-by-design controls.

4. People readiness

Do the people doing and receiving the work understand the change? Can reviewers detect a plausible but wrong result? Is there time for training, feedback and adjustment?

The assessment should include frontline evidence, not only leadership confidence. People know where workarounds live and which errors matter. The National AI Centre says meaningful worker consultation and practical training are central to readiness, not optional change activities.

5. Governance readiness

Who approves the use case, owns the outcome, reviews incidents and can stop the system? What uses are prohibited? How will performance and risk be monitored?

The National AI Centre's Guidance for AI Adoption foundations recommends accountable owners, risk screening, an AI register, testing, monitoring and human override points.

Three readiness foundations labelled process, data and control.
A useful AI pilot rests on understood work, usable context and a clear review mechanism.

Score evidence, not confidence

Use a simple zero-to-three scale for each question:

  • Score: 0; Evidence: Unknown or not started
  • Score: 1; Evidence: Discussed, but dependent on individual effort
  • Score: 2; Evidence: Documented and tested in a limited setting
  • Score: 3; Evidence: Repeatable, owned and measured

Do not average away a critical zero. A high overall score cannot compensate for no lawful basis to use the information, no owner or no way to pause a consequential workflow.

Ask for artefacts: a process map, sample records, baseline measures, role descriptions, risk decisions, access rules and test results. Interviews reveal how people think the work happens. Artefacts show what the business can repeat.

Three assessment outcomes labelled ready, fix first and human only.
An assessment should distinguish a bounded pilot from foundation work and decisions that should remain human.

This makes an AI maturity assessment useful rather than ceremonial. Australia's AI Impact Navigator similarly asks cross-functional participants to justify ratings with evidence and revisit them through a continuing plan, act and adapt cycle.

Turn gaps into a sequence

The output should not be a coloured score alone. Give each gap an owner, next action and decision date.

Use four result bands:

  1. Do not proceed: purpose, information rights or risk is unacceptable or unknown.
  2. Prepare first: improve the process, records, ownership or training before selecting a tool.
  3. Pilot with controls: scope one reversible use case, define review and collect evidence.
  4. Ready to expand carefully: repeat what worked, monitor performance and reassess when the use changes.

Often the first action is not AI. It may be a better intake form, a clear approval threshold, removal of duplicate records or capture of knowledge held by one person. Systemising a small business creates the repeatable base. Knowledge management reduces the risk that essential context leaves with an employee.

For a viable pilot, use the discipline in how to scope phase one AI automation: one outcome, clear boundaries, visible review and a measure that can prove whether the work improved.

Note

Turn this framework into a decision about your own business. In five minutes, get an honest on-screen view of what is ready now, what needs work and whether AI should be the next move.

Take the AI readiness assessment

Reassess when the use changes

AI readiness is not a certificate. A new information source, wider user group, automated action or higher-impact decision changes the conditions.

Reassess after the pilot, before expanding scope and whenever the workflow or tool changes materially. Track corrections, incidents, user feedback, time saved and work created by supervision. The Australian Cyber Security Centre's guidance for engaging with AI also treats security as an ongoing organisational responsibility, especially when third-party systems handle business information.

A good AI readiness assessment narrows the question until the evidence is clear. It may approve a small pilot, prescribe preparation or tell the business not to buy. All three are useful results when they prevent an expensive guess.