Free tools · 4 minutes · Updated 2026-08-24
AI readiness assessment for companies with no IT department
Twelve questions, a score out of 100, and the one failure mode most likely to stall you. Every other AI readiness assessment we could find assumes a CIO, a data team and a governance board. This one is written for a 20-50 person company where the person asking “where do I start” is also the person who signs the invoice. Free, no email, and it writes you a one-pager you can take to your board.
By Ashutosh Upadhyay, founder of Cognio Labs. The scoring below is built from the three things that actually stall a first attempt across our deployments, ranked by how often we hit them.
Score your readiness
Twelve questions across the six things that decide whether a first build survives: the target, where your answers live, ownership, access and approvals, cost control, and training. Answer honestly — the score is only useful if it is unflattering.
12 questions · instant score · no email · nothing leaves your browser
Why the existing AI readiness assessments do not fit
Real assessments exist. The accounting firms, the big consultancies and the major cloud vendors all publish one, and several are genuinely good. They are also all scoped for the enterprise: they ask about your data governance board, your CIO's roadmap, your model risk committee and your centre of excellence. Answer those as a 32-person company and you score badly on questions that were never about you.
The gap is not sophistication. It is scope. At 20-50 people, readiness is decided by scoping, ownership and training — not by infrastructure. You do not have a data team to be ready or unready. You have one person who knows how the invoicing actually works, a shared drive nobody has audited since 2023, and a board or an investor asking what you are doing about AI. So this assessment asks about the things you can change this month.
The three things that actually stall a first attempt
This is the ranking we work from, ordered by how often we run into it. It is not a survey. It is what we have watched happen across our own builds, and it is why the scoring weights the questions it does.
1. Model-choice cost blowup
The biggest model gets used for every task and the token bill balloons. It is the most common way a first attempt dies in our deployments, and it never shows up in week one — it shows up when finance asks what this line is.
The fix: Before anything is built, write down two things: a cheap default model for routine steps, and the short list of steps that justify an expensive one. Then set a monthly cap and a threshold alert that lands in someone's inbox.
2. No clarity on the target
There is no defined outcome or KPI going in, so nobody can see the ROI coming out. This is a scoping failure, not a technical one, and the build can be perfectly good and still get cancelled.
The fix: Pick one area and one metric with a current reading. Sales and new prospects is the most common first pick for a reason: the number is already on a dashboard somebody watches. Then log two weeks of the hours the work costs today.
3. No employee training
The system is set up, the people using it do not know what to hand over or how to check the output, and the results are bad in a way that gets blamed on the software.
The fix: Name the person who owns training and put time in the calendar: a session at launch, a written guide, and a follow-up at week three when people have hit their first real problem. Have an exec use it first and say so.
Notice what is missing. None of the three is a technology problem. That matches what the research community found when it took apart retrieval systems that failed in production: Barnett and colleagues catalogued seven failure points across three case studies, and the first one is missing content — the answer simply is not in the documents, and the system answers anyway.
The 12 questions, in full
Here is the entire assessment as a checklist, so you can run it in a meeting without the tool. Each answer scores 0 to 3. Twelve questions, 36 raw points, rescaled to 100.
1. Is there one number this is supposed to move?
Not a goal. A number, with a value you could read today.
- 3 ptsYes — a named metric, and I know what it reads this week
- 1 ptsWe know the area, not the number
- 1 ptsSeveral numbers, across different teams
- 0 ptsWe want to see where AI helps
2. Have you picked the one area to start in?
One team, one process. Sales and new prospects is the most common first pick.
- 3 ptsYes — one team, one process
- 2 ptsTwo or three candidates, not decided
- 1 ptsNot yet
- 0 ptsWe want it company-wide from day one
3. Has anyone measured what this work costs today?
Hours per week, from the people actually doing it.
- 3 ptsYes — hours per week, from the people doing the work
- 2 ptsA rough estimate somebody gave in a meeting
- 1 ptsNo, but two weeks of logging would give us one
- 0 ptsNo, and nobody would know where to start
4. When someone needs the answer to do this work, where do they find it?
- 3 ptsIn one system, and it is current
- 2 ptsAcross a few systems, mostly current
- 1 ptsIn Slack or WhatsApp threads, and in two people's heads
- 0 ptsIn documents that contradict each other
5. Does one named person own this process end to end?
- 3 ptsYes — I could say their name right now
- 2 ptsA team owns it
- 1 ptsIt moves between people depending on the week
- 0 ptsNobody. That is part of why we want AI
6. Could you list today who has access to what?
- 3 ptsYes — access is scoped per role and gets reviewed
- 2 ptsRoughly — someone could reconstruct it in a day
- 1 ptsNo — people got added over the years and nothing was removed
- 0 ptsEveryone can see everything in the main drive
7. Do you know what company data would leave the building, and is anything written down about it?
The AI policy question. Also the shadow AI question.
- 3 ptsYes — a written AI policy, and we know which tools staff use
- 2 ptsWe know what the data is. Nothing is written down
- 1 ptsThere is a policy, but people use their own AI tools anyway
- 0 ptsNo idea what staff are pasting into which tool
8. Who approves an action that cannot be undone?
Money out, a message to a customer, a deletion.
- 3 ptsA named person, and there is a step in the process for it
- 2 ptsThe manager of whoever did it, informally
- 1 ptsDepends who is around
- 0 ptsNothing like that exists
9. Who decides which model each task runs on?
The single most expensive mistake we see.
- 3 ptsWe would set it per task, cheap model by default
- 1 ptsWhoever builds it decides
- 1 ptsNo idea what that means yet
- 0 ptsWe would use the best available model for everything
10. Is there a monthly ceiling on AI spend, and would anyone notice if it tripled?
- 3 ptsYes — a cap, and an alert someone actually reads
- 2 ptsThere is a budget. No alert
- 1 ptsIt goes on a card and gets reviewed at some point
- 0 ptsNo ceiling, and no, nobody would notice
11. Who trains the team on what to hand over and how to check the output?
- 3 ptsA named person, with time set aside over the first month
- 2 ptsA written guide plus a session at launch
- 1 ptsOne session at launch
- 0 ptsPeople will pick it up
12. Is anyone on the founder or exec team going to use this themselves, weekly?
- 3 ptsYes — I will, and I have said so out loud
- 2 ptsOne exec is interested
- 1 ptsIt is being delegated to whoever has time
- 0 ptsNo — this is for the team, not for us
What each score band means
Sixty is the practical floor for starting a scoped build on one process. Below 35, a vendor conversation is premature and every fix on the list is free.
| Score | Band | What it means |
|---|---|---|
| 0-34 | Not ready | Foundations missing: no named number, no owner, or answers that live in people's heads. |
| 35-59 | One thing is ready | A real candidate process exists, with two or three gaps that would sink it. |
| 60-79 | Ready for one scoped build | Target, owner and enough governance to start safely on a single process. |
| 80-100 | Ready to roll out | Everything in place. Remaining risk is sequencing, not readiness. |
How the scoring works
Each of the 12 questions scores 0, 1, 2 or 3, giving 36 raw points rescaled to a score out of 100. No question is weighted more heavily than another. The weighting is in the question set itself: five of the twelve sit on the three failure modes above, which is deliberate.
The named failure mode is chosen by averaging the questions in each of the three groups and picking the lowest. Cost control is questions 9 and 10. Target clarity is 1, 2 and 3. Training is 11 and 12. Ties break toward cost, because that is the one we hit most often. Two more checks run on top: if your answers live in heads or in contradicting documents, you get the knowledge warning; if access, data policy or approvals score 1 or below, you get the governance warning. Those two do not change the failure mode. They change what you do first.
On governance vocabulary: the four-function structure that NIST uses in its AI Risk Management Framework is GOVERN, MAP, MEASURE and MANAGE, with GOVERN cutting across the other three. Our access, data-out and approval questions are the smallest useful version of GOVERN for a company with no risk committee — who can see what, what leaves, and who approves the things you cannot take back. If you need the full framework later, that is where it lives.
How the board-safe one-pager works, and why it exists
The most honest description of this problem we have read came from a CIO writing in a peer community: I know we're not ready, but I can't be the person who says no to the board. That is the real job. Nobody needs a score. They need language they can send upward without it reading as resistance.
So the output is a plain-text page with four headings, generated from your answers: what we are ready for, built from every question you scored 2 or 3 on. What we are not ready for, from everything at 1 or below. What it would take, which is the specific fix for your named failure mode plus any knowledge or governance warning you triggered. And what happens if we start anyway, which is the section that changes the conversation. It reframes the ask from permission to sequence. You are not saying no. You are saying: here is the order, and here is what the first item costs, which in most cases is a month and no budget.
It is deliberately plain text with no logo and no branding, because the version that gets forwarded is the one that does not look like a vendor wrote it.
Who should skip this, and when a low score is fine
If you are a small team that is new to all of this, do not commission a build and do not run an assessment to justify one. Build your own automations, or set yourself up on our open-source agent tooling and learn what breaks. The moment worth paying for arrives when the problems become repeatable — you know what is missing from your workflows and what needs doing at regular intervals. Before that point we tell people directly not to hire us.
A low score is also fine in two specific cases. If you have one repeatable workflow and one motivated ops person, you do not need readiness — you need an afternoon in a no-code tool, and the readiness questions about training and sponsorship are noise. And if you are deliberately running a two-month experiment with a capped budget and an explicit agreement that it might produce nothing, a low score is the correct starting condition for an experiment. What a low score should stop is a funded programme with a deadline attached.
One thing this assessment cannot see: your people. A 65-year-old lawyer in Minnesota, not technical at all, got more out of a personal agent team than any founder we have set up — three to five agents, self-sufficient in about two weeks, saving five to ten hours a week. He would not have scored especially well on infrastructure questions. He had deep domain expertise and already knew how to manage a team of people, which turned out to be the thing that mattered. Being technical was never the requirement.
What to do with a low score, in order
Everything in this list is free and none of it needs a vendor. Pick one area and one metric with a current reading. Log two weeks of the hours that work costs today. Put one named person on the process. Write a one-page AI policy naming who owns information going out of a tool and coming in — and while you are at it, ask people which AI tools they already use, because shadow AI is almost certainly already happening and sanctioning two good tools beats banning all of them. Set a monthly spend ceiling and an alert. Decide that cheap models are the default and expensive ones are the exception. Then run this again.
If the knowledge warning came up, the knowledge readiness audit is the longer version of that phase, and Company Second Brain is what we build once the knowledge is in a state worth indexing. If you scored 60 or above and want to see how a first build actually runs from pilot to production, that programme is here. More free tools are in our resources library.
Frequently asked questions
What is an AI readiness assessment?
An AI readiness assessment checks whether the conditions for a first AI project to succeed are in place before anyone spends money: a named target, a process owner, knowledge that can actually be retrieved, access and approval rules, cost control, and a plan for training the people who will use it. It is not a technology audit. At the 20-50 person size the answer almost never turns on infrastructure, and almost always turns on scoping, ownership and training.
Is my company too small for an AI readiness assessment?
No, but most published assessments are built for companies that are much larger. The well-known scorecards from the big consultancies assume a CIO, a data team and a governance board, so a 30-person company scores badly on questions that do not apply to it. This one asks only about things a company with no IT department can actually control, which is why it has questions about who approves a refund and none about your data warehouse.
What score do I need before I start an AI project?
Sixty out of 100 is the practical floor for a scoped first build on one process. Below 35 the sensible move is a month of foundation work with no vendor involved. Between 35 and 59 you usually have one viable process and two or three gaps that would sink it, and closing those gaps typically moves the score 15-25 points without anyone writing code.
What actually stops small companies from succeeding with AI?
Three things, in this order, from our own builds. Model choice: people reach for the biggest model for every task and the token cost balloons. No clarity on the target: no defined outcome or KPI going in, so nobody can see the ROI coming out. And no employee training: the system is set up correctly and the people using it do not know what to hand over, which produces bad results that get blamed on the software.
How do I explain to my board that we are not ready?
Give them a decision, not a refusal. The one-pager this tool produces has four sections for that reason: what we are ready for, what we are not, what it would take, and what happens if we start anyway. That last section is the one that changes the conversation, because it moves the discussion from whether you are being cautious to what the specific cost of impatience would be.
Do I need my data cleaned up before using AI?
Usually yes, and by more than people expect. Not more than 25% of the clients who come to us have their knowledge in a state you can point retrieval at, so roughly three in four need remediation first. The problem is rarely volume. It is answers that live in chat threads and senior people's heads, plus documents that contradict each other and have no owner.
Does this tool store my answers or ask for my email?
No email, no signup, and nothing you type or click is sent anywhere. The whole assessment runs in your browser and the one-pager is generated on your machine. We record only which of the four score bands was shown, so we can tell whether the tool is behaving the way we expect.
How is this different from a vendor's AI readiness assessment?
Most vendor assessments are lead capture with a score attached, and every route through them ends at a demo. Two of the four bands here tell you to spend a month on things that cost no money and involve no vendor. We publish it because telling someone they are not ready is a faster way to earn a real conversation than pretending everyone is.
Sources
- NIST, AI Risk Management Framework (AI RMF 1.0) — the GOVERN, MAP, MEASURE, MANAGE structure our governance questions are cut down from.
- Barnett, Kurniawan, Thudumu, Brannelly and Abdelrazek, Seven Failure Points When Engineering a Retrieval Augmented Generation System (arXiv:2401.05856) — the missing-content failure point behind our knowledge question.
- Everything marked “from our deployments” is our own first-hand count across Cognio Labs builds, anonymised. It is observation, not research.
Want the score pressure-tested?
Thirty minutes, no pitch. Bring your score and the one-pager, and we will tell you which gap we would close first — including when the answer is that you should not hire anyone yet.