Is my business ready to implement AI? Your business is ready for a controlled pilot when it can define one valuable workflow, measure the current process, access the required data lawfully, integrate with narrow permissions, assign an accountable owner, test real exceptions and operate monitoring and recovery after launch. You do not need perfect enterprise maturity. You do need enough clarity and control for the risk of the specific use case.
This assessment is deliberately practical. Score what is true today, supported by evidence—not what a vendor could eventually provide. A low result does not mean “do nothing.” It tells you whether to fix foundations, run a low-risk assisted pilot or prepare for a controlled production workflow.
How to score the 30-point assessment
For each statement, assign 0 when it is absent, 1 when it is partly true or informal, and 2 when it is documented, owned and demonstrated. The maximum is 60. Record the evidence and the action required for every zero or one.
1. Strategy
- 1. We can name a business problem, not only an AI tool.
- 2. The intended outcome has an accountable executive or process owner.
- 3. The use case supports a current operating priority.
- 4. We have a measurable baseline and a decision threshold.
- 5. We know what would make us stop the initiative.
2. Process
- 6. The trigger, inputs, steps and outcome are documented.
- 7. Rules are separated from judgment and exceptions.
- 8. Volume and variation are understood from real cases.
- 9. Human approval points and escalation owners are explicit.
- 10. A manual fallback can keep the business operating.
3. Data
- 11. Authoritative sources and data owners are identified.
- 12. Required records are sufficiently complete, current and accessible.
- 13. Permissions match the proposed purpose and users.
- 14. Sensitive data classes, retention and deletion are defined.
- 15. We can create representative test cases without contaminating production.
4. Technology
- 16. The systems of record offer a safe integration path.
- 17. The agent or workflow can use narrow, least-privilege identities.
- 18. Validation and business rules can run outside the model.
- 19. Actions can be logged, monitored and reconciled.
- 20. Deployment, rollback and credential revocation are feasible.
5. People
- 21. A business owner has time and authority to make decisions.
- 22. Front-line users helped map the real workflow and exceptions.
- 23. Users will be trained to verify output and report problems.
- 24. Technical support is available for integration and incidents.
- 25. The operating team can absorb the change without hiding extra work.
6. Governance
- 26. Risk is assessed per action, data class and affected person.
- 27. Consequential actions require meaningful human approval.
- 28. Acceptance tests include normal, edge, hostile and failure cases.
- 29. Monitoring, incident response and change ownership are funded.
- 30. Applicable contractual, sector and legal duties will be reviewed.
Interpret the score without false precision
| Score | Readiness signal | Recommended next step |
|---|---|---|
| 0–20 | Foundations are too uncertain for production automation. | Map the process, assign ownership, clean the minimum data path and establish digital controls. Use AI only for low-risk personal assistance meanwhile. |
| 21–35 | A narrow assisted experiment may be useful. | Choose read-only, classification, preparation or drafting work. Keep every consequential action human-controlled. |
| 36–49 | Ready for a controlled pilot. | Run one workflow with explicit limits, a documented evaluation set and day-30 expand, revise or stop criteria. |
| 50–60 | Strong initial readiness for the assessed use case. | Validate the score with operators and security owners, then pilot before scaling. High readiness does not remove use-case-specific risk. |
The ranges are a prioritization aid, not a certification or compliance finding. A single critical gap—such as no legal data access, no owner, uncontrolled payment authority or no recovery path—can block a project regardless of the total.
What usually holds SMEs back
OECD's 2026 D4SME survey reports rapid use of AI among its non-representative sample of more than 2,000 SMEs across 12 OECD countries, but most surveyed adopters remained novices using off-the-shelf tools for isolated tasks. The report says targeted, secure integration remains uneven and identifies time, maintenance cost, skills and cybersecurity as continuing constraints. That distinction matters: access to an AI tool is not the same as readiness to redesign an operational workflow.
Skills readiness also extends beyond coding. Business owners must define outcomes and risk; operators must explain exceptions; data owners must decide access and freshness; implementers must build safe integrations; users must verify results; and someone must own incidents and improvement. OECD's 2026 work on AI and skills notes that many firms, especially SMEs, identify skills shortages as a barrier, while most workers need broad digital and data interpretation capabilities rather than advanced model development.
Fix the lowest dimension first
- Low strategy: use the automation audit and select one measurable problem.
- Low process: map real cases and convert the SOP with the workflow-design method.
- Low data: identify authoritative sources, owners, permissions, quality and retention before building retrieval.
- Low technology: choose read-only assistance first and review the vendor-neutral stack.
- Low people: appoint the owner and involve operators before asking them to adopt the result.
- Low governance: apply the 25-point agent security checklist and the autonomy ladder.
Move from score to a controlled decision
Select one candidate workflow and re-score only for that use case. Broad company readiness can hide critical local gaps, while a generally immature organization may still be able to run a safe, low-risk pilot. Convert every partial answer into an owner, action and due date. Then write the pilot charter: problem, workflow, baseline, users, data, tools, limits, acceptance measures and stop criteria.
NIST's AI RMF offers a useful operating structure: govern responsibilities, map context and risk, measure performance and trustworthiness, and manage prioritized risks through deployment and change. The 30-day pilot plan turns those ideas into a bounded SME implementation sequence.
Primary sources checked for this guide
Checked 26 August 2026. OECD survey results are reported with their stated sampling limitation.
- OECD — Empowering SMEs in the age of AI: 2026 D4SME Survey
- OECD — AI and skills
- NIST — Artificial Intelligence Risk Management Framework
- NIST AI RMF Core
- NIST AI Resource Center
Turn readiness into action
Complete the assessment for one workflow
I help SME leaders score the real process, close critical gaps and choose a pilot whose value and risk can be measured.
Assess AI readiness