Enterprise AI Readiness Assessment
Bottom line: Assess enterprise AI readiness across six dimensions: business goal, target audience, work processes, data and access, rules and accountability, and measurement. An organization does not need every answer before starting, but it needs someone who will lead the work, a first audience, and a testable work process to choose between awareness, a focused pilot, or implementation guidance.
- Home
- Enterprise AI Readiness Assessment
How do you assess enterprise AI readiness?
AI readiness is not a technology score. It combines goals, people, work processes, access, rules and accountability, and measurement. The useful outcome is a next-step decision, not a generic maturity label.
Six dimensions of organizational AI readiness
1. Business goal
What problem or capability matters?
2. People
Who is the first audience, and who will lead the work?
3. Work processes
Which task can the team test?
4. Data and access
Which sources and permissions are allowed?
5. Rules and accountability
What are the responsible-use and escalation rules?
6. Measurement
How will the organization continue, revise, or stop?
This is Eyal Marcus’s recommended readiness framework. It is not a certified review or validated comparison standard.
A short enterprise AI readiness checklist
- Has the organization named someone who can make the decision?
- Is the first audience defined?
- Is one work process testable?
- Are data and access boundaries clear?
- Are basic responsible-use rules available?
- Is there a metric and a stated limitation?
Three outcomes: awareness, focused pilot, or hands-on guidance
Choose awareness when the organization needs shared understanding. Choose corporate AI training or a focused pilot when the audience, task, and rules are clear. Choose enterprise AI consulting when ownership, decisions, or implementation process are the constraint.
What you do not need to solve before starting
You do not need to select every tool, map every function, or build an annual plan. You do need a safe boundary for the first test. Start small, but do not start vague.
Warning signs that the organization is starting too early
- Nobody has responsibility for the decision
- No approved tool or required access
- No basic rule for sensitive information
- A goal of “doing AI” without a work process
- The organization buys broad training before it defines the audience
For procurement, use the guide on how to choose a corporate AI training provider.
My recommendation for the next step
I recommend naming the first audience and selecting one testable work process before surveying every tool on the market. If ownership, access, or responsible-use rules are missing, address them before hands-on delivery. Use a keynote for understanding, a workshop for practice, and hands-on guidance for decisions and implementation process.
Frequently asked questions
Does an organization need to select a tool first?
Not always. Start by defining the goal, audience, workflow, and information boundaries. Choose the tool when those requirements are clear.
What does the team need before a focused pilot?
Someone to lead the work, a defined work process, access, responsible-use rules, and a basic measure. The team should go deeper when the risk or systems are more complex.
Is this a certified readiness review?
No. This is a professional guide for making the decision, not a certified maturity score or comparison standard.
Turning readiness into a decision
A short decision example
Consider a service team that wants to prepare complex responses faster. Define one work process: collect facts, retrieve an approved source, draft, review, and send. The process lead sets the information boundaries. The manager selects a limited group and captures a starting point for time and quality.
If the approved source is inaccessible, training is not the next step. Access is the constraint. If access exists but outputs vary, a focused workshop can test a working template. If two people succeed but others cannot reproduce the method, assess documentation, role differences, and manager support before scale.
The same reasoning applies in technology and non-technology organizations. Details differ, but enterprise procurement should not answer a business question that has not yet been defined.
Who needs to be in the room?
You do not need every stakeholder in every meeting. Start with the person who owns the problem, the person who can make the decision, and someone who understands the information boundaries. Bring in security, privacy, legal, or procurement when the question touches their responsibility. This keeps the work moving without bypassing anyone.
HR or L&D matters when the decision is about a keynote, workshop, or learning path. IT matters when access, setup, or integration is the issue. Leadership matters when teams are competing for time or priority.
What changes when the tool is Microsoft Copilot?
Readiness still starts with the work, not the license. Identify the first audience, the Microsoft 365 apps they use, the content they can access, and what they may do with the result. Microsoft’s official setup guide explains technical requirements, licensing, and rollout preparation. I use it here to separate technical setup from people and process readiness. It does not prove that an organization is ready for regular use.
Choose scenarios that already exist in Word, PowerPoint, Outlook, Teams, or another part of the actual work. Then check permissions, source quality, human review, and language differences. If the team cannot access the information, or policy does not allow its use, a better prompt will not fix the problem.
A readiness questionnaire for decision owners
A review of readiness is not a scored test. It is a focused conversation about the problem, the first team, the task, the information people may use, the rules, and the way you will judge the next step. Include the person who leads the work process, a business leader, IT or security, and HR or L&D. The output is a next decision and the condition that is still missing.
- Which recurring problem should change?
- Who is the first audience, and what should they do differently?
- Which work process can the team observe from start to finish?
- Which information enters it, and who may access it?
- Which tool has the organization approved for the group?
- Who handles privacy, security, and legal questions?
- How does the team do the work today?
- Who decides whether the test scales, changes, or stops?
If the first three questions have no answer, it is too early to choose a syllabus. If information boundaries are unclear, do not practice on real material. An awareness keynote may still help, but do not describe it as an impact pilot.
Select the format that addresses the constraint
Leadership keynote
Use this for an understanding gap, shared language, or a direction decision. It does not show that employees can carry out a new work process.
Focused workshop
Use this when an audience, approved tool, and practice tasks exist. Participants test execution and produce outputs. Without access and information rules, hands-on work will stall.
Work process pilot
Use this to test a process change. It needs a starting point, someone to lead it, a limited group, and a decision date. A pilot tests assumptions. It does not guarantee rollout.
Implementation guidance
Use this when ownership, rules, priorities, or measurement is the constraint. More tool training will not resolve a management problem.
Common failure modes
One score hides a critical gap
A high average can conceal missing permission or ownership. Show each dimension and the specific gap that blocks the next step.
A tool list replaces the problem
Comparing platforms before defining a work process produces a feature discussion disconnected from work. Return to task, audience, and information before selecting a tool.
A pilot has no end decision
Set a date, metric, and three possible outcomes before launch: scale, revise, or stop.
Training is too broad
If everyone is the audience, examples may fit no role. Begin with a group that enables learning, then expand based on evidence.
Organizational change is ignored
A tool can work while regular use fails because managers protect no time and support is absent. The OECD AI Principles are international guidelines for responsible AI. I cite them here because they make accountability, transparency, and risk management part of regular use, not an afterthought.
What should be clear before you begin?
Start with things you can actually check. What is the problem? Who makes the decision? Which team goes first, and how do they do the task today? Then clarify approved information, the basic usage rules, who handles exceptions, and the number that will help you decide what happens next.
The NIST AI RMF is a voluntary AI risk management framework from the US National Institute of Standards and Technology. I use it here because it connects governance, context, measurement, and management, which helps teams assess readiness beyond tool selection. It does not validate Eyal’s readiness score or prove that an organization is ready to deploy AI.
International organizations should examine local evidence too. Permissions, documents, languages, and regulation can differ between units. A work process that performs in English does not establish equal quality in Hebrew or another language.
Limitations and what happens next
This guide is not an audit, standard, certification, or validated maturity model. It organizes decision questions and does not support scientific comparisons between organizations. Answers also expire as tools, people, and policies change.
The RMF is NIST’s AI risk management framework. Its Playbook offers suggested questions and actions for applying it. It is not a mandatory checklist, certification, or maturity score. It does not replace security, privacy, legal, or procurement experts.
Finish with a short decision note: the goal, first audience, task, information boundaries, who will lead the work, the measure, the chosen format, and the one gap that still needs work. At review, ask whether the step addresses the constraint, whether participants have access, whether examples are approved, and whether a reassessment date exists.
A useful review does not end with a score. It ends with a next-step decision, someone who will lead it, and a clear statement of what should not happen yet. A keynote may fit a leadership team that needs shared understanding. A workshop or pilot fits a defined audience with an approved work process. Hands-on guidance fits an organization whose constraint is ownership, policy, or prioritization.
Do not settle for a general feeling that the organization is ready. Write down the problem, the first team, the task being tested, the information people may use, who owns the usage rules, and the number that will guide the next decision.
| Dimension | Minimum evidence | Warning sign |
|---|---|---|
| Goal | Defined problem or decision | “Do AI” |
| People | First audience and named lead | Everyone is the audience |
| work process | Task and frequency | A tool list |
| Data | Source and permission | Unmapped sensitive data |
| Rules and accountability | Basic responsible-use rule | No escalation path |
| Measurement | description of the current state and its caveat | Generic ROI claim |
An organization does not need maximum maturity in every dimension. It does need to know which gap makes a test unsafe and which gap the team can explore through a limited pilot. Tool selection for the whole enterprise can wait, but the organization still needs to approve a tool for the first group and set clear information boundaries.
Readiness differs by organization
A technology company may have strong building capability but weak business prioritization. A non-technology organization may have clear work processes but limited technical support. An international organization also faces differences in language, access, and regulation. The framework provides common questions, not a universal score.
This review is not a security audit or legal approval. Internal experts remain accountable for privacy, security, procurement, and policy. The purpose is to connect those decisions to the right learning or implementation format.
Since late 2022, I have worked with many dozens of organizations and delivered hundreds of lectures and workshops.
Not sure what the first step should be?
A short call can identify whether the gap is understanding, practice, or a management decision, then match it to a keynote, workshop, or hands-on guidance support.