Free tools · 4 minutes · Updated 2026-08-26

AI readiness assessment for companies with no IT department

An AI readiness assessment tells you whether your company can get value out of an AI project before you pay for one. A good one checks six things: whether there is a number the work is meant to move, who owns the process, whether the answers a machine would need are written down anywhere, who can see what, what the running cost is capped at, and who trains the people who have to use it. This one asks 12 questions, takes about four minutes, and gives you a score out of 100 plus the single gap most likely to stall your first build. It's free, there's no signup, and nothing you click leaves your browser.

Every other AI readiness assessment we could find assumes a CIO, a data team and a governance board. This one is written for a 20-50 person company where the person asking “where do I start” also signs the invoice. It writes you a one-pager you can forward to your board.

By Ashutosh Upadhyay, founder of Cognio Labs. The scoring below is built from the three things that actually stall a first attempt across our deployments, ranked by how often we hit them.

Score your readiness

Twelve questions across the six things that decide whether a first build survives: the target, where your answers live, ownership, access and approvals, cost control, and training. Answer honestly — the score is only useful if it is unflattering.

12 questions · instant score · no email · nothing leaves your browser

What an AI readiness assessment should include

Six areas. None of them is your infrastructure. At 20-50 people the answer almost never turns on servers or data pipelines, so an assessment that spends half its questions there is measuring the wrong company.

  • A target. One named metric with a reading you could look up today, one area to start in, and an honest count of what the work costs in hours right now. Questions 1 to 3 below.
  • Knowledge. Where a person goes to find the answer when they do this work. If that place is a chat thread or somebody's memory, no software can reach it. Question 4.
  • Ownership. One named person who owns the process end to end and would notice when the output goes wrong. Question 5.
  • Access and approvals. Who can see what, what company data leaves the building, and who releases anything that cannot be undone. Questions 6 to 8.
  • Cost control. Who decides which model each task runs on, and whether there is a monthly ceiling anyone watches. Questions 9 and 10.
  • Training and sponsorship. Who teaches the team what to hand over and how to check the output, and whether anyone senior is going to use it themselves. Questions 11 and 12.

What it should leave out at this size: your data warehouse, your model risk committee, your centre of excellence. Those questions are real for a 4,000-person bank. For you they just produce a bad score on things you were never going to have.

How to assess whether your company is ready for AI

Assess one process, not the company. Get the person who does the work and the person who pays for it in the same room, pick the workflow you would automate first, and answer the six areas above about that one workflow. It takes an hour. Doing it at the company level produces an average that hides the only thing you needed to know.

  1. Name the process and the team. One team, one workflow. Sales and new prospects is the most common first pick, because the number is already on a dashboard somebody watches.
  2. Write down the metric and read it out loud. If nobody can say what it reads this week, stop here and spend two weeks measuring. That's the cheapest insurance in the whole project.
  3. Ask where the answers live. Open the wiki in the meeting. If the current answer is in a Slack thread instead, you have found your first phase and it is interviews, not models.
  4. Say the owner's name, then the approver's name. If either takes more than a few seconds, write that down as a gap.
  5. Set the money rules before anyone builds: a cheap default model, a short list of steps that justify an expensive one, a monthly cap, and an alert that lands in a real inbox.
  6. Decide who owns training and put it in a calendar. Then score every answer 0 to 3 and total it.

Sixty out of 100 is the practical floor for starting a scoped build on one process. Below 35, a vendor conversation is premature and every fix on your list is free.

AI readiness checklist vs AI readiness assessment

A checklist is a list of things you should have. An assessment scores what you actually have and tells you which missing thing to fix first. The difference matters because most published AI readiness checklists run to 40-odd items with no weighting, so every gap reads as equally urgent and the reader closes the tab. The 12 questions further down work as an AI readiness checklist too. Paste them into a doc and run them in a meeting if you'd rather not use the tool.

A paid audit is a third thing again: someone else does the looking, inside your actual stack, and signs their name to the verdict.

ChecklistThis assessmentPaid readiness audit
What it isA list you tick by hand12 questions, scored 0-100Two weeks of our time inside your stack
What you get outA list of gaps, all looking equally urgentA score, a band, the failure mode you would hit first, and a board one-pagerProcess and tooling map, data-readiness report, ranked roadmap, and a build-or-don't-build verdict
Time20 minutesAbout 4 minutesAbout two weeks, roughly two hours of yours
CostFreeFree, no email$1,500, credited in full against a build
Best forA meeting where everyone needs to see the same listDeciding whether to start at all, and what to fix firstDeciding what to build, when you're about to commit real money

Why the existing AI readiness assessments do not fit

Real assessments exist. The accounting firms, the big consultancies and the major cloud vendors all publish one, and several are genuinely good. They are also all scoped for the enterprise: they ask about your data governance board, your CIO's roadmap, your model risk committee and your centre of excellence. Answer those as a 32-person company and you score badly on questions that were never about you.

The gap is not sophistication. It is scope. At 20-50 people, readiness is decided by scoping, ownership and training — not by infrastructure. You do not have a data team to be ready or unready. You have one person who knows how the invoicing actually works, a shared drive nobody has audited since 2023, and a board or an investor asking what you are doing about AI. So this assessment asks about the things you can change this month.

The three things that actually stall a first attempt

This is the ranking we work from, ordered by how often we run into it. It is not a survey. It is what we have watched happen across our own builds, and it is why the scoring weights the questions it does.

  1. 1. Model-choice cost blowup

    The biggest model gets used for every task and the token bill balloons. It is the most common way a first attempt dies in our deployments, and it never shows up in week one — it shows up when finance asks what this line is.

    The fix: Before anything is built, write down two things: a cheap default model for routine steps, and the short list of steps that justify an expensive one. Then set a monthly cap and a threshold alert that lands in someone's inbox.

  2. 2. No clarity on the target

    There is no defined outcome or KPI going in, so nobody can see the ROI coming out. This is a scoping failure, not a technical one, and the build can be perfectly good and still get cancelled.

    The fix: Pick one area and one metric with a current reading. Sales and new prospects is the most common first pick for a reason: the number is already on a dashboard somebody watches. Then log two weeks of the hours the work costs today.

  3. 3. No employee training

    The system is set up, the people using it do not know what to hand over or how to check the output, and the results are bad in a way that gets blamed on the software.

    The fix: Name the person who owns training and put time in the calendar: a session at launch, a written guide, and a follow-up at week three when people have hit their first real problem. Have an exec use it first and say so.

Notice what is missing. None of the three is a technology problem. That matches what the research community found when it took apart retrieval systems that failed in production: Barnett and colleagues catalogued seven failure points across three case studies, and the first one is missing content — the answer simply is not in the documents, and the system answers anyway.

The AI readiness checklist: all 12 questions and how they score

Here is the entire assessment as a checklist, so you can run it in a meeting without the tool. Each answer scores 0 to 3. Twelve questions, 36 raw points, rescaled to 100. Copy it, argue about it, change the wording to match how your company actually talks.

  1. 1. Is there one number this is supposed to move?

    Not a goal. A number, with a value you could read today.

    • 3 ptsYes — a named metric, and I know what it reads this week
    • 1 ptsWe know the area, not the number
    • 1 ptsSeveral numbers, across different teams
    • 0 ptsWe want to see where AI helps

    If the bottom answer is yours: Wanting to see where AI helps is a research project wearing a build's clothes. It is the second most common reason a first attempt stalls in our experience, and the whole cost is invisible until someone asks for the ROI.

  2. 2. Have you picked the one area to start in?

    One team, one process. Sales and new prospects is the most common first pick.

    • 3 ptsYes — one team, one process
    • 2 ptsTwo or three candidates, not decided
    • 1 ptsNot yet
    • 0 ptsWe want it company-wide from day one

    If the bottom answer is yours: Company-wide from day one is the rollout shape that burned a 20-50 person client roughly $3,000-$5,000 a month before they killed the programme inside two months. Everyone got an agent. Few used one.

  3. 3. Has anyone measured what this work costs today?

    Hours per week, from the people actually doing it.

    • 3 ptsYes — hours per week, from the people doing the work
    • 2 ptsA rough estimate somebody gave in a meeting
    • 1 ptsNo, but two weeks of logging would give us one
    • 0 ptsNo, and nobody would know where to start

    If the bottom answer is yours: Nobody can say what the work costs today. Any savings you claim later will be unverifiable, which is exactly the position you do not want to be in when someone asks you to justify the spend.

  4. 4. When someone needs the answer to do this work, where do they find it?

    • 3 ptsIn one system, and it is current
    • 2 ptsAcross a few systems, mostly current
    • 1 ptsIn Slack or WhatsApp threads, and in two people's heads
    • 0 ptsIn documents that contradict each other

    If the bottom answer is yours: Contradicting documents are worse than missing ones. An assistant pointed at them answers confidently and wrongly, and the person who asked has no way to tell.

  5. 5. Does one named person own this process end to end?

    • 3 ptsYes — I could say their name right now
    • 2 ptsA team owns it
    • 1 ptsIt moves between people depending on the week
    • 0 ptsNobody. That is part of why we want AI

    If the bottom answer is yours: No owner at all. Every dead automation we have been called in to rescue started exactly here, and adding software to an unowned process just makes the confusion faster.

  6. 6. Could you list today who has access to what?

    • 3 ptsYes — access is scoped per role and gets reviewed
    • 2 ptsRoughly — someone could reconstruct it in a day
    • 1 ptsNo — people got added over the years and nothing was removed
    • 0 ptsEveryone can see everything in the main drive

    If the bottom answer is yours: Open access to everything means any assistant you connect inherits open access to everything. One client asked us for an AI policy only after an employee reached something they should not have had, and it ended up published externally.

  7. 7. Do you know what company data would leave the building, and is anything written down about it?

    The AI policy question. Also the shadow AI question.

    • 3 ptsYes — a written AI policy, and we know which tools staff use
    • 2 ptsWe know what the data is. Nothing is written down
    • 1 ptsThere is a policy, but people use their own AI tools anyway
    • 0 ptsNo idea what staff are pasting into which tool

    If the bottom answer is yours: Nobody knows what is being pasted where. Fixing that is a week of asking, and it is the one item on this list that can hurt you before you build anything at all.

  8. 8. Who approves an action that cannot be undone?

    Money out, a message to a customer, a deletion.

    • 3 ptsA named person, and there is a step in the process for it
    • 2 ptsThe manager of whoever did it, informally
    • 1 ptsDepends who is around
    • 0 ptsNothing like that exists

    If the bottom answer is yours: With no approval step at all, everything irreversible has to ship in draft state and stay there until one exists. That is a design constraint on day one, not a phase two.

  9. 9. Who decides which model each task runs on?

    The single most expensive mistake we see.

    • 3 ptsWe would set it per task, cheap model by default
    • 1 ptsWhoever builds it decides
    • 1 ptsNo idea what that means yet
    • 0 ptsWe would use the best available model for everything

    If the bottom answer is yours: Using the biggest model for every task is the number one reason first attempts blow up on cost in our deployments. It is invisible for about six weeks and then it is the only thing anyone talks about.

  10. 10. Is there a monthly ceiling on AI spend, and would anyone notice if it tripled?

    • 3 ptsYes — a cap, and an alert someone actually reads
    • 2 ptsThere is a budget. No alert
    • 1 ptsIt goes on a card and gets reviewed at some point
    • 0 ptsNo ceiling, and no, nobody would notice

    If the bottom answer is yours: No ceiling and no alert means the cost failure mode has nothing to stop it. This is the cheapest item on this list to fix and the most expensive to skip.

  11. 11. Who trains the team on what to hand over and how to check the output?

    • 3 ptsA named person, with time set aside over the first month
    • 2 ptsA written guide plus a session at launch
    • 1 ptsOne session at launch
    • 0 ptsPeople will pick it up

    If the bottom answer is yours: Expecting people to pick it up is the third of the three things that stall first attempts. The system works, the rollout still fails, and the build gets blamed for a training gap.

  12. 12. Is anyone on the founder or exec team going to use this themselves, weekly?

    • 3 ptsYes — I will, and I have said so out loud
    • 2 ptsOne exec is interested
    • 1 ptsIt is being delegated to whoever has time
    • 0 ptsNo — this is for the team, not for us

    If the bottom answer is yours: Bought for the team and used by nobody senior is the flat rollout again. Staff read that signal accurately and act on it.

What each score band means

Sixty is the practical floor for starting a scoped build on one process. Below 35, a vendor conversation is premature and every fix on the list is free.

ScoreBandWhat it means
0-34Not readyFoundations missing: no named number, no owner, or answers that live in people's heads.
35-59One thing is readyA real candidate process exists, with two or three gaps that would sink it.
60-79Ready for one scoped buildTarget, owner and enough governance to start safely on a single process.
80-100Ready to roll outEverything in place. Remaining risk is sequencing, not readiness.

How the scoring works

Each of the 12 questions scores 0, 1, 2 or 3, giving 36 raw points rescaled to a score out of 100. No question is weighted more heavily than another. The weighting is in the question set itself: five of the twelve sit on the three failure modes above, which is deliberate.

The named failure mode is chosen by averaging the questions in each of the three groups and picking the lowest. Cost control is questions 9 and 10. Target clarity is 1, 2 and 3. Training is 11 and 12. Ties break toward cost, because that is the one we hit most often. Two more checks run on top: if your answers live in heads or in contradicting documents, you get the knowledge warning; if access, data policy or approvals score 1 or below, you get the governance warning. Those two do not change the failure mode. They change what you do first.

On governance vocabulary: the four-function structure that NIST uses in its AI Risk Management Framework is GOVERN, MAP, MEASURE and MANAGE, with GOVERN cutting across the other three. Our access, data-out and approval questions are the smallest useful version of GOVERN for a company with no risk committee — who can see what, what leaves, and who approves the things you cannot take back. If you need the full framework later, that is where it lives.

How to tell whether one specific role is ready for an agent

The company can be ready while a particular role is not, and the reverse happens too. Three questions settle it. Does the role have clearly determined KPIs? Does it have clearly determined SOPs? Is the work mostly digital?

Three yeses and an agent can very likely do that work much better than it is being done now, or take a large part of it off someone's desk. A missing yes is not a no. It tells you which document to write first. This test matters more than your headcount or your budget, and it's the one we use before we agree to build anything. If you want to see what a whole company built this way looks like, that is the Agentic OS programme.

The usual failing answer is the SOP one. Not because the work is unclear, but because it lives as habit rather than as a document. Write the SOP the way you would write it for a new hire on their first Monday. If a person could follow it without asking you a question, an agent has something to work from.

Is there a free AI readiness assessment? And when is the paid one worth it?

Yes. This one, and it stays free: no email, no signup, no drip sequence afterwards. We publish it because two of its four score bands tell you to spend a month on things that cost nothing and involve no vendor, and saying that out loud earns a better conversation than pretending everyone is ready.

Our paid AI readiness audit is $1,500 and adds four things a self-assessment cannot: a process and tooling map built from a working session and read-only access to your real stack, a data-readiness check on whether your knowledge can actually be retrieved, a ranked roadmap with the arithmetic for each candidate workflow, and a written build-or-don't-build verdict with our name on it. About two weeks end to end, roughly two hours of your time. The $1,500 comes off the invoice in full if you go on to build with us.

When it's worth paying: you scored 60 or above, you're about to commit $20,000 or more, and you want the workflow ranking and the failure arithmetic done by someone who has watched this go wrong before. When it isn't: you scored under 35. Everything on your fix list is free, needs no vendor, and paying us to write it down would be a waste of $1,500. Run the free version, fix the two lowest scores, and come back.

If you're about to talk to any agency, ours included, take the questions to ask an AI agency into the call with you. Half of them are questions we'd rather not be asked, which is how you know they're the right ones.

How the board-safe one-pager works, and why it exists

The most honest description of this problem we have read came from a CIO writing in a peer community: I know we're not ready, but I can't be the person who says no to the board. That is the real job. Nobody needs a score. They need language they can send upward without it reading as resistance.

So the output is a plain-text page with four headings, generated from your answers: what we are ready for, built from every question you scored 2 or 3 on. What we are not ready for, from everything at 1 or below. What it would take, which is the specific fix for your named failure mode plus any knowledge or governance warning you triggered. And what happens if we start anyway, which is the section that changes the conversation. It reframes the ask from permission to sequence. You are not saying no. You are saying: here is the order, and here is what the first item costs, which in most cases is a month and no budget.

It is deliberately plain text with no logo and no branding, because the version that gets forwarded is the one that does not look like a vendor wrote it.

Who should skip this, and when a low score is fine

If you are a small team that is new to all of this, do not commission a build and do not run an assessment to justify one. Build your own automations, or set yourself up on our open-source agent tooling and learn what breaks. The moment worth paying for arrives when the problems become repeatable — you know what is missing from your workflows and what needs doing at regular intervals. Before that point we tell people directly not to hire us.

A low score is also fine in two specific cases. If you have one repeatable workflow and one motivated ops person, you do not need readiness — you need an afternoon in a no-code tool, and the readiness questions about training and sponsorship are noise. And if you are deliberately running a two-month experiment with a capped budget and an explicit agreement that it might produce nothing, a low score is the correct starting condition for an experiment. What a low score should stop is a funded programme with a deadline attached.

One thing this assessment cannot see: your people. A 65-year-old lawyer in Minnesota, not technical at all, got more out of a personal agent team than any founder we have set up — three to five agents, self-sufficient in about two weeks, saving five to ten hours a week. He would not have scored especially well on infrastructure questions. He had deep domain expertise and already knew how to manage a team of people, which turned out to be the thing that mattered. Being technical was never the requirement.

What happens if you're not ready for AI, and what to fix first

Nothing dramatic happens. You're not losing a race. What you do is fix the documentation first, because that's the constraint sitting underneath most low scores. Not more than 25% of the clients who come to us arrive with knowledge a machine could retrieve, so three in four spend their first phase on capture and ownership instead of on models. That phase is interviews, deciding which of two contradicting documents is right, and giving each area an owner. Skip it and you get an assistant that answers confidently and wrongly, which is worse than one that says nothing.

Then the rest, in order. Everything in this list is free and none of it needs a vendor. Pick one area and one metric with a current reading. Log two weeks of the hours that work costs today. Put one named person on the process. Write a one-page AI policy naming who owns information going out of a tool and coming in — and while you are at it, ask people which AI tools they already use, because shadow AI is almost certainly already happening and sanctioning two good tools beats banning all of them. Set a monthly spend ceiling and an alert. Decide that cheap models are the default and expensive ones are the exception. Then run this again.

If the knowledge warning came up, the knowledge readiness audit is the longer version of that phase, and Company Second Brain is what we build once the knowledge is in a state worth indexing. If you scored 60 or above and want to see how a first build actually runs from pilot to production, that programme is here. More free tools are in our resources library.

Frequently asked questions

What is an AI readiness assessment?

An AI readiness assessment checks whether the conditions for a first AI project to succeed are in place before anyone spends money: a named target, a process owner, knowledge that can actually be retrieved, access and approval rules, cost control, and a plan for training the people who will use it. It is not a technology audit. At the 20-50 person size the answer almost never turns on infrastructure, and almost always turns on scoping, ownership and training.

How long does an AI readiness assessment take?

About four minutes on your own with this tool. Closer to an hour if you run the same 12 questions as a meeting with the person who does the work and the person who pays for it, which is the version worth doing, because the arguments that break out are the finding. A paid readiness audit where someone external looks inside your stack takes about a week end to end and roughly two hours of your time. If a vendor tells you their assessment needs six weeks, they are selling you the assessment rather than the answer.

Who should run the AI readiness assessment?

Two people, in the same room. Whoever does the work every day, because they're the only person who knows where the answers actually live and what the process really is. And whoever signs the invoice, because four of the twelve questions are about money and training, and those aren't the daily person's to answer. Sending a form round the company and averaging the results gives you a number nobody argued about, which is the wrong kind of comfortable.

We already use ChatGPT at work. Does that mean we are ready?

No, and it can point the other way. Staff using their own AI tools with no written policy is the shadow AI answer on question 7, and it scores low for a reason: nobody can say what company data is being pasted where. It's a useful signal that people want the help, and it's not the same as readiness. Sanction two tools, make them the easy path, write one page naming who owns information going out and coming in, and you have turned the lowest-scoring answer into a decent one in about a week.

What is the difference between an AI readiness assessment and an AI maturity model?

A maturity model places you on a ladder from ad-hoc to optimised and describes what each rung looks like across a whole organisation. A readiness assessment answers a narrower and more useful question at this size: can we start this one project without wasting the money? Maturity models are built for companies with enough moving parts that a shared vocabulary is worth having. With 30 people you don't need a rung. You need to know which two things to fix before you sign anything.

Is my company too small for an AI readiness assessment?

No, but most published assessments are built for companies that are much larger. The well-known scorecards from the big consultancies assume a CIO, a data team and a governance board, so a 30-person company scores badly on questions that do not apply to it. This one asks only about things a company with no IT department can actually control, which is why it has questions about who approves a refund and none about your data warehouse.

What score do I need before I start an AI project?

Sixty out of 100 is the practical floor for a scoped first build on one process. Below 35 the sensible move is a month of foundation work with no vendor involved. Between 35 and 59 you usually have one viable process and two or three gaps that would sink it, and closing those gaps typically moves the score 15-25 points without anyone writing code.

What actually stops small companies from succeeding with AI?

Three things, in this order, from our own builds. Model choice: people reach for the biggest model for every task and the token cost balloons. No clarity on the target: no defined outcome or KPI going in, so nobody can see the ROI coming out. And no employee training: the system is set up correctly and the people using it do not know what to hand over, which produces bad results that get blamed on the software.

How do I explain to my board that we are not ready?

Give them a decision, not a refusal. The one-pager this tool produces has four sections for that reason: what we are ready for, what we are not, what it would take, and what happens if we start anyway. That last section is the one that changes the conversation, because it moves the discussion from whether you are being cautious to what the specific cost of impatience would be.

Do I need my data cleaned up before using AI?

Usually yes, and by more than people expect. Not more than 25% of the clients who come to us have their knowledge in a state you can point retrieval at, so roughly three in four need remediation first. The problem is rarely volume. It is answers that live in chat threads and senior people's heads, plus documents that contradict each other and have no owner.

Does this tool store my answers or ask for my email?

No email, no signup, and nothing you type or click is sent anywhere. The whole assessment runs in your browser and the one-pager is generated on your machine. We record only which of the four score bands was shown, so we can tell whether the tool is behaving the way we expect.

How is this different from a vendor's AI readiness assessment?

Most vendor assessments are lead capture with a score attached, and every route through them ends at a demo. Two of the four bands here tell you to spend a month on things that cost no money and involve no vendor. We publish it because telling someone they are not ready is a faster way to earn a real conversation than pretending everyone is.

Sources

Want the score pressure-tested?

Thirty minutes, no pitch. Bring your score and the one-pager, and we will tell you which gap we would close first — including when the answer is that you should not hire anyone yet.