The short answer

Readiness is about constraints, not enthusiasm.

An AI readiness assessment measures whether a company can actually deliver and operate AI systems, across the things that decide it: the state of your data, the systems it lives in, the security and compliance posture around it, the skills on your team, the process ownership, and the governance that says who may decide what. It produces a score per dimension and a ranked list of gaps. The score is not the point. The order to fix things in is the point.

Every company I assess is ready for something. The useful output is knowing what: some are ready to put agents into a customer-facing workflow, and some need six weeks of unglamorous data work before the first sensible use case is even possible. Telling those two apart before the budget is committed is worth considerably more than the fee.

This is the first half of my AI Diagnostic, offered on its own for companies that want the honest read before they commit to a roadmap. The AI readiness framework I use is published: you can run the whole thing yourself for free, and plenty of teams do. I charge for the version where an outsider asks the uncomfortable questions and nobody has to score their own department.

Also known as: AI readiness assessment framework, AI readiness assessment for companies, AI readiness assessment tool, AI readiness checklist, AI maturity assessment, AI readiness for companies, enterprise AI readiness review.

Why it matters

The four ways a build
dies on a gap nobody named.

None of these are model problems. All of them are findable in advance.

The data wasn't what you thought

Three systems disagree about the same customer, and the field everyone planned to use is filled in about half the time.

No definition of correct

The team ships something, and there's no agreed way to tell whether the output is good, so quality becomes a debate rather than a number.

Nobody owns the process

The workflow crosses three departments and belongs to none of them, so every decision goes to committee and the pilot ages out.

Security stops it at the gate

The build is done and then legal asks where the data goes. That conversation costs a quarter when it happens last instead of first.

The framework

Six dimensions,
each scored one to five.

The same six every time, so the second assessment a year later is comparable to the first.

01

Data

Whether the data you'd need exists, is accessible, and is trustworthy enough to act on.

  • Coverage and completeness on the fields that matter
  • Whether systems agree on the same entity
  • History depth, and whether it's clean enough to evaluate against
  • Access: who can get it, how fast, and through what
02

Systems & architecture

Whether anything can be integrated without a six-month project first.

  • APIs and integration surface on the systems of record
  • Environments, deployment and how quickly a change ships
  • Where the ugly manual bridges are today
  • Existing AI and automation already running, including shadow use
03

Security, privacy & compliance

The constraints that decide what may leave your network and what may not.

  • Data classification and residency requirements
  • Contractual and regulatory obligations, including customer commitments
  • Vendor review process and how long it really takes
  • Current posture on tools people already paste data into
04

People & skills

Who can build it, who can operate it, and who is quietly doing it already.

  • Engineering capacity and current AI fluency
  • Whether operations staff can supervise an agent's output
  • Leadership bandwidth for the decisions this creates
  • The gap between the team you have and the team the roadmap needs
05

Process ownership

Whether the workflows you want to change have a named owner who can change them.

  • Who owns each candidate process end to end
  • How exceptions are handled today and by whom
  • Baseline metrics: volume, cycle time, error rate
  • Appetite for changing how the work is done, not just tooling it
06

Governance & decision rights

Who decides what an AI system is allowed to do, and who answers when it's wrong.

  • Existing policy, and whether anyone follows it
  • Approval path for a new AI use case
  • Incident handling when output causes a real problem
  • Board and executive reporting on AI risk
See the governance work
The engagement

Three weeks,
start to report.

Roughly ten hours of your team's time in total, mostly in interviews.

Week 1

Evidence

  • Interviews across leadership, engineering, operations and security
  • Read-only access to the systems and a sample of real data
  • Inventory of AI already in use, including the unsanctioned tools
  • Baseline metrics on the processes you care about
Week 2

Scoring & pressure-testing

  • Each dimension scored against the published rubric
  • Gaps sized: what it costs and how long to close each one
  • Findings tested against two or three candidate use cases
  • Draft reviewed with the executive who commissioned it
Week 3

The report and the plan

  • Scorecard with evidence behind every number
  • Ranked remediation list, sequenced by what unblocks the most
  • What you could build now, and what has to wait
  • A readout for the board or the executive team

Every company is ready for something. The assessment tells you which something, and saves you from the twelve months you'd otherwise spend finding out.

Oshri Cohen
Pricing

Quoted to scope.

The assessment is a fixed-fee engagement, quoted once I know how many systems are in play and how many people I need to interview. Two companies of the same headcount can differ by a factor of three on both, so a single published number would be wrong for most of the people reading it.

What is fixed is the shape: a defined scope agreed before we start, a fixed fee against it, and a report you keep regardless of what happens next. If the assessment leads into a roadmap or an ongoing engagement, the fee comes off the next piece of work.

If you would rather not pay for any of it, the framework is published in full and free to run yourself. Plenty of teams do, and I would rather they ran it than skipped the exercise.

Want a number before a conversation? The Fractional CAIO page publishes the rates for ongoing leadership, and the AI consultant cost guide covers the market. Email me for a quote ↗

Common questions

About the assessment.

What is an AI readiness assessment?

An AI readiness assessment is a structured review of whether a company can build and operate AI systems successfully. It scores six dimensions: data, systems and architecture, security and compliance, people and skills, process ownership, and governance. The output is a scorecard with evidence, a ranked list of gaps, and a sequence for closing them. It answers what you can build now and what has to be fixed first.

What does an AI readiness framework include?

Mine includes a rubric that scores each of the six dimensions from one to five with defined criteria, an interview guide for leadership, engineering, operations and security, a data-quality check run against real records rather than documentation, an inventory of AI already in use including unsanctioned tools, and a remediation list sized by cost and time. The framework is published, so you can run it internally without hiring anyone.

Is there a free AI readiness checklist?

Yes. The full framework is published on this site as the AI Diagnostic, including the rubric and the questions. Teams run it themselves regularly and I'd rather they did that than skip the exercise. The paid version buys three things a self-assessment struggles with: an outsider asking the uncomfortable questions, evidence gathered from the actual data rather than from what people believe about it, and nobody having to score their own department.

How long does an AI readiness assessment take?

Two to three weeks end to end, and about ten hours of your team's time. Week one is interviews and evidence gathering, week two is scoring and pressure-testing the findings against candidate use cases, week three is the report and the executive readout. Larger organizations with more systems in scope run closer to four weeks.

We're a small company. Is this overkill?

The assessment scales down well because smaller companies have fewer systems and shorter interview lists, and the fee scales with scope. Below roughly $10M in revenue I'd usually suggest running the published framework yourself first and calling me only if the results are ambiguous. Paying for an assessment that confirms what you already suspect is not a good use of money.

What happens after the assessment?

You have a scorecard, a gap list and a sequence, and that's a complete deliverable. From there companies usually do one of three things: close the top gaps with their own team, move into an opportunity assessment to build the use-case portfolio, or bring me in as a fractional Chief AI Officer to own the whole program. The assessment fee comes off the next engagement if there is one.

Want the honest read
before the budget?

Three weeks, fixed fee, and a scorecard you can hand to your board. Or run the published framework yourself and call me if the answer is unclear.

hello@oshricohen.me(514) 777-3883Fort Lauderdale · Montreal