Contact Us

AI Readiness Assessment Checklist for Enterprises (2026)

Oct 7, 202611 min read
Banner card with the title: AI Readiness Assessment Checklist for Enterprises (2026)
ai readiness assessment ai readiness assessment tool ai readiness assessment framework ai readiness assessment services ai readiness assessment template microsoft ai readiness assessment

TL;DR

  • Microsoft (seven pillars), Cisco (six) and Google Cloud (six themes) cover the same ground: strategy, data, infrastructure, governance, people and culture.
  • Score each area against evidence you can point at, not opinion in a workshop.
  • The output that matters is a ranked list of fixes and first use cases, not a maturity level on a slide.

Last updated: 6 October 2026

Quick Answer: An AI readiness assessment scores whether your organization can deploy AI safely across strategy, infrastructure, data, governance, talent and culture. Those are the six pillars of Cisco's AI Readiness Index. A useful assessment ends with a scored gap list, a prioritized set of first use cases and a sequenced roadmap, not just a maturity label.

Most AI pilots stall on data access, ownership or governance, which a readiness review exists to find first.

A readiness review is cheap insurance: finding that three source systems have no documented owner costs far less now than mid-pilot. The public vendor tools take under an hour; a consultant-led review takes weeks and produces something you can fund. This page gives the areas to score, the evidence for each, a rubric, the tools you can run today, and what a paid engagement should deliver.

What is an AI readiness assessment?

It measures how prepared an organization is to build, deploy and operate AI, across a fixed set of areas, with a score per area. The score is a means to an end: what you are buying is a ranked list of the things blocking your first production use case.

The exercise exists because AI projects fail for organizational reasons more often than technical ones. A model that works in a notebook still needs a pipeline with an owner, an access policy security will sign, someone accountable for monitoring it, and a process willing to change. A review tests all four before budget is committed.

It is not a maturity model: that places you on a published curve for benchmarking, while this produces work items from your own estate.

What does an AI readiness checklist cover?

Seven areas cover almost every published framework: strategy and use cases, data, infrastructure, security and governance, talent and skills, culture and change, and model management. Treat the table below as your ai readiness assessment template. Each row gives what to check, the artifact that proves it, and the red flag that stops a pilot.

Area Check Evidence Red flag
Strategy and use cases Owner, baseline metric, the decision it changes Use-case list with baseline and owner No metric the first use case should move
Data Where it lives, who owns it, freshness, permitted use Source inventory, owner per system, retention terms A source system with no documented owner
Infrastructure Compute, where inference runs, environment parity Architecture diagram, environment list, quotas Production is the only place real data exists
Security and governance Access control, logging, model review, incident path Access matrix, audit logs, the provider's SOC 2 report No trail of who asked the model what
Talent and skills Who builds, reviews and operates it after go-live Skills matrix, on-call owner, training plan One person or one vendor carries the pilot
Culture and change Whether the affected team agreed to change the process Signed-off process map, escalation rules The process owner first hears of it at the demo
Model management Versioning, evaluation sets, drift monitoring, rollback Evaluation set, scoring method, rollback runbook No held-out evaluation set

Two rows do most of the damage. Data ownership silently blocks delivery: an unowned system has nobody to approve access. Culture and change kills value after launch, since a model nobody has to use produces nothing.

How do you score data, infrastructure, people and governance readiness?

Score every area on the same 1 to 5 scale and require an artifact for anything above a 2. That rule separates a usable ai readiness assessment framework from a workshop: an area scores 3 only when someone produces the document, dashboard or log sample.

Score Meaning Proof
1 Nothing in place, nobody accountable Nothing to show
2 Ad hoc, done by individuals, not repeatable Informal notes, tribal knowledge
3 Documented and owned for the pilot's scope The artifact exists, the owner is named
4 Repeatable across teams, controls tested Artifact plus evidence it was exercised
5 Measured and improved on a cycle Artifact, metric history, review cadence

Weight the areas. Data and governance gate whether a pilot can legally start, so a 1 in either is a stop, not an average. Culture and model management gate whether it survives production. A composite of 3.4 hiding a 1 in data governance is worse than none.

Two public models give external reference points. Cisco's tool buckets scores out of 100 into Pacesetters above 86, Chasers from 61 to 85, Followers from 31 to 60 and Laggards from 0 to 30, which is useful for board framing. Google Cloud's AI Adoption Framework uses three maturity phases instead, tactical, strategic and transformational, across six themes: Learn, Lead, Access, Scale, Automate and Secure. Gartner's five-stage model is widely cited, but its stage definitions are not documented publicly as of 6 October 2026.

Which public AI readiness assessment tools can you use?

Three vendor tools are open to anyone with a browser, and they are not interchangeable. None of the three pages calls itself free, so confirm access at sign-in.

Tool What it scores, and over what scope
Microsoft Learn assessment Seven pillars, organization-wide; personalized recommendations
Cisco assessment tool Six selectable pillars, organization-wide; a score out of 100 in one of four bands
ServiceNow AI readiness assessments Platform configuration, one ServiceNow instance

Capabilities as documented by each vendor on 6 October 2026.

What does the Microsoft AI readiness assessment cover?

The Microsoft Learn assessment covers seven pillars: Business Strategy, AI Governance and Security, Data Foundations, AI Strategy and Experience, Organization and Culture, Infrastructure for AI, and Model Management. The page gives the length as 45 with no unit, and the format as multiple choice and multiple response questions. It returns guidance rather than a public benchmark, so it is the better first pass.

How does the Cisco AI readiness assessment score you?

Cisco's tool scores six dimensions: Strategy, Infrastructure, Data, Governance, Talent and Culture. You pick which pillars to answer for, and the result lands in one of the four bands above, out of 100. The same six pillars sit behind Cisco's published AI Readiness Index, so the score is comparable with an external population. That is the stronger choice when a board wants a number.

Is the ServiceNow AI readiness assessment a general tool?

No. ServiceNow's assessment determines whether your organization's ServiceNow instance is ready to implement generative and agentic AI features, by inspecting its configuration and customization. Useful before turning those features on, silent on everything outside ServiceNow. ServiceNow renamed it to AI readiness assessments, leaving evaluation in the URL; the separately documented AI Readiness Evaluation app runs it.

Two further frameworks are not tools. Google Cloud's, above, is a whitepaper. The AWS Cloud Adoption Framework for AI organizes capabilities across business, people, governance, platform, security and operations, but AWS published it in February 2024 and now marks it for historical reference only.

Who runs consultant-led AI readiness assessments?

Three kinds of provider sell AI readiness assessment services. Large strategy and systems-integration consultancies, the Big Four and the global integrators among them, run the multi-country, multi-business-unit version with board reporting. Platform vendors and their partners run assessments scoped to their own stack. Specialist AI engineering firms run the narrower technical review that ends in an architecture and a first build.

Match the provider to the question you have. If it is whether a 40,000-person group has a coherent AI operating model, a large consultancy is the better choice: scale, change management and regulatory assurance are what they are built for. If it is whether your data and access model can support one production use case next quarter, a specialist firm gets there faster. Mid-market trade-offs are covered in our guide to AI consulting firms for mid-size companies. Ask who writes the report, and which artifacts they inspect rather than interview.

How long does an assessment take, and what drives the cost?

Scope drives both, and four variables drive scope: how many business units are included, how many source systems must be inventoried, how many stakeholder interviews are planned, and whether a technical review of code, pipelines and infrastructure is included. A single-business-unit review with no technical deep dive is small. A group-wide review across several countries with a security workstream is far larger.

Pricing models follow the rest of AI consulting: a fixed fee for a defined scope, time-and-materials where the estate is unknown, or a review folded into a larger implementation at no separate charge. Published rate cards are rare, and comparable figures sit in our breakdown of AI consulting cost. Be wary of a fixed fee quoted before anyone has seen the source-system inventory: it rests on an assumption about your data.

What should the assessment report give you, and what comes next?

An actionable report contains six things: a score per area with its evidence, a ranked gap list, two or three use cases with baseline metrics, the risks needing a decision, a sequenced roadmap, and a named owner per item. If the deliverable is a maturity level and recommendations with no owners, you bought a benchmark, not a plan.

What comes next is where most of this work is wasted, because the gap between pilot and production is operational rather than technical. Our analysis of how many AI pilots reach production covers the published numbers. The sequence that works: fix the blocking gaps in data access and governance, run one use case end to end with a real owner and evaluation set, then reuse that path.

What mistakes should you avoid when running an AI readiness assessment?

  1. Scoring on opinion. A 4 awarded because a team says access control is handled is fiction. Require the artifact.
  2. Averaging the score. A composite hides the one area that will stop you. Report per-area scores and treat data and governance as gates.
  3. Assessing everything at once. A 12-week group-wide review lands after the window it was meant to inform. Scope to the units behind the first two use cases.
  4. Leaving the process owner out. If the team whose workflow changes is absent, culture and change cannot be scored, and the pilot will have no user.
  5. Letting a vendor's tool set the scope. A platform-scoped assessment answers whether that platform is ready, not whether the systems holding your data are.

How Origins AI runs AI readiness and discovery

Origins AI (originshq.com) is a US-based AI-augmented engineering company, and it sells no readiness questionnaire. Its closest equivalent is AI Discovery Analysis, an engineering diagnostic rather than a score. According to that product page it analyzes requirements, user stories, system logs and technical documentation, maps dependencies across systems, APIs, data flows and business processes, and produces prioritized risk reports for executives. The company reports that this surfaces 30 to 40 percent of scope gaps in 48 hours. Those are its own figures, so test them against a sample report.

Where that fits the checklist is narrow. It is strongest on the infrastructure, data and model-management rows, which an engineering review can evidence from artifacts. It is weaker on culture and change, which needs the process owners in the room, and on board-level benchmarking, which is what the large consultancies and the public indices are for. On the people row, Origins AI states that it offers enterprise AI training programs, workshops and consulting covering AI strategy, data science and AI product deployment. It does not publish a rate card.

Talk to an engineer

If you have run the checklist and want a second opinion on the data, infrastructure and model-management rows before committing budget, book a call with an engineer who has shipped the pattern you are scoping.

Frequently Asked Questions

What are the five stages of AI readiness?
There is no industry-standard five-stage scale. The five-stage model usually meant is Gartner's, whose stage definitions are not documented publicly as of 6 October 2026. The readable public models use other shapes: Cisco scores four bands out of 100, Google Cloud uses three maturity phases.
What data problems show up most often in a readiness review?
Four, in rough order of frequency: a source system with no named owner, no record of what the data may lawfully be used for, a refresh cadence nobody has checked since the pipeline was built, and two systems both treated as the record. All four sit under Microsoft's Data Foundations pillar.
How is AI readiness different from AI maturity?
Readiness is a diagnostic on your own estate that produces a gap list with owners. Maturity is a position on a published curve: Cisco's AI Readiness Index is the maturity-style artifact, the checklist above is the diagnostic. The two share pillars, which is why they get conflated. Use readiness work to decide what to build next.
Who should be in the room for a readiness review?
At minimum: the owner of each source system in scope, a security or risk representative who can approve access, the process owner for every candidate use case, an engineer who knows production, and the budget holder. Culture, a pillar in both Microsoft's and Cisco's models, cannot be evidenced without the process owner.
How often should you reassess AI readiness?
Reassess after each use case reaches production, and at least annually. Infrastructure, skills and model management move fastest, because a first deployment changes all three. Governance moves in steps, when a policy or regulation lands. A full re-score is rarely needed: re-evidence whatever scored 3 or less.
Can a small team run a readiness review without a consultant?
Yes, and for a first use case that is often the better path. Run Microsoft's seven-pillar questionnaire or Cisco's six-pillar tool for a baseline, then work through the table above with your system owners and collect the artifacts. Bring in help when the blocker is a decision nobody internally owns.
Book a call

About the Author

Apoorva Kumar is Co-Founder and CEO of Origins AI (originshq.com), an AI engineering partner for product teams building AI workflows, AI agents and LLM integrations. A CSE graduate of IIT Kharagpur, Apoorva previously built and scaled technology at Sony, NuCash, YesMadam and FrontPage.