AI Workflow Agency
AI5 min read

AI Readiness Assessment Services: What They Cover and How to Run One

What a credible AI readiness assessment covers, what it costs, how long it takes, and how to tell a real engagement from a slideware exercise

By AI Advisory team

Most organisations asking about AI readiness assessment services have already tried something. A pilot that did not make it past the demo. A ChatGPT Enterprise rollout that nobody uses. A workflow automation initiative that hit a data quality wall. The assessment is the point where leadership decides to stop guessing and get an honest look at what is actually buildable, what the data and process gaps are, and where the money is.

This article covers what a proper readiness assessment includes, what it should cost, how long it should take, and the warning signs that you are about to buy a slide deck rather than a roadmap. It is written for the buyer - usually a CTO, COO, or Head of Transformation - who needs to scope the work and justify it internally.

What an AI readiness assessment actually is

An AI readiness assessment is a structured evaluation of whether an organisation has the data, processes, infrastructure, governance, and skills to deploy AI systems that produce measurable business outcomes. The output is a prioritised, costed plan - not a maturity score on a five-point scale.

The distinction matters because the market is full of frameworks that produce colourful radar charts and stop there. A useful assessment answers four concrete questions: which processes are worth automating first, what has to be true about your data and systems before you can do it, how much it will cost, and how long it will take. Anything that does not answer those four questions is theatre.

The McKinsey State of AI 2024 report found that 72% of organisations have adopted AI in at least one function, but only a small minority report meaningful EBIT impact. The gap is rarely about the models - it is about readiness. Process documentation, data accessibility, identity and access management, and the operating model around AI ownership are the failure points. A real assessment digs into these, not into whether your CEO has heard of transformers.

What a credible assessment covers

A complete engagement covers six areas. Skipping any of them produces a roadmap that breaks contact with reality the moment you try to execute it.

1. Business and process audit

Interviews with function heads and the people doing the work. Process mapping for the top 10-20 candidate workflows, including volumes, cycle times, exception rates, and current cost. The point is to find the processes where AI or automation has a defensible payback, not to produce a wishlist. A workflow that runs 40 times a year is rarely worth automating, regardless of how interesting it looks.

2. Data audit

Where the data lives, who owns it, what state it is in, and what it would take to make it usable. This includes structured systems (CRM, ERP, finance, support platforms) and unstructured sources (SharePoint, shared drives, email, contract repositories). Data quality is the most common reason pilots fail to scale. If your customer records are duplicated across three systems with no master, no amount of model selection fixes that.

3. Technical and infrastructure review

Current stack, integration patterns, identity and SSO, API availability on key systems, hosting posture, and what the organisation can realistically operate. A team running everything in Microsoft 365 with no developers should not be sold a self-hosted Kubernetes RAG stack. A team with a working data platform and engineering capacity should not be sold a no-code prototype as the end state.

4. Governance, risk, and compliance

UK GDPR obligations, ICO guidance on AI and data protection, sector-specific rules (FCA for financial services, MHRA for medical devices, SRA for legal), and the EU AI Act if the organisation operates in the EU. The ICO's guidance on AI and data protection sets out specific requirements around DPIAs, lawful basis, transparency, and accuracy that apply to most AI use cases. An assessment that does not address these by name is not fit for purpose in the UK.

5. Operating model and skills

Who will own AI inside the organisation once the consultants leave. This is the area most often handwaved. Centre of excellence, federated model, embedded specialists, or fully outsourced operation - each has cost and capability implications. The assessment should recommend one and explain why, based on the actual headcount and skills available.

6. Prioritised, costed roadmap

A 12-month plan with sequenced initiatives, each with a scope, expected outcome, cost range, dependencies, and owner. The first three to six months should be specific enough to start executing the day the engagement ends.

What it should cost and how long it should take

For a mid-market organisation (50-1000 employees), a credible readiness assessment runs two to six weeks and costs between £10,000 and £40,000 depending on scope. The variables are the number of functions in scope, the number of systems to audit, and whether the engagement includes a working prototype.

Two-week engagements work when scope is narrow - a single function, a defined process area, a clear hypothesis to test. Six-week engagements are appropriate for cross-functional reviews where data and systems are fragmented and the operating model question is genuinely open.

Be cautious at both extremes. Sub-£5,000 assessments are usually template exercises that produce a generic report with the client name swapped in. £100,000+ engagements from large consultancies often include extensive benchmarking and change management theatre that does not change the answer. The work that matters - interviewing your people, looking at your data, mapping your processes, pricing the builds - has a fairly fixed cost.

According to Gartner, around 30% of generative AI projects will be abandoned after proof of concept by the end of 2025, with poor data quality, inadequate risk controls, and unclear business value cited as the main reasons. A serious assessment is the cheapest way to avoid being in that 30%.

How to tell a real engagement from slideware

The market is crowded with firms offering AI readiness assessments. Some are excellent. Many sell strategy without the ability to build, which means their recommendations are not stress-tested against execution reality. A few signals separate the two.

They ask to see your systems, not just your slides. A real assessment involves looking at your CRM, your data warehouse, your ticket queues, your contract repository. If the engagement is entirely interview-based and slide-based, the recommendations will be generic.

They write code or build something. Not always - some assessments are correctly scoped as discovery only. But the firms that can build something small during the engagement (a working RAG prototype against your actual documents, a process automation that runs end-to-end) produce roadmaps that are markedly more accurate, because they have evidence rather than assumption.

They name technologies and price them. A roadmap that says "implement a generative AI solution for customer support" is useless. A roadmap that says "deploy a RAG assistant on Azure OpenAI with retrieval against Zendesk and Confluence, estimated £45-65k build plus £2-3k/month run cost, 10-week delivery" is actionable. The second requires the firm to have actually built things.

They are honest about what not to do. A good assessment will tell you which of your ideas are not worth pursuing yet and why. If everything in the roadmap is green-lit, the assessment is selling, not advising.

They address governance specifically. Vague references to "responsible AI" are a tell. References to specific ICO guidance, DPIA requirements, your sector regulator, and how data flows will be handled under UK GDPR show the firm has done this in regulated environments before.

What the deliverables should look like

A defensible assessment produces five artefacts. If you are buying one, write these into the statement of work.

  1. Process and opportunity register. A spreadsheet or database of every candidate use case identified, with volume, current cost, expected benefit, technical complexity, data readiness, and a priority score. This is the working document, not the headline.
  2. Data and systems map. Where data lives, what state it is in, what integrations exist, and what would need to be built. Includes a frank assessment of master data and data quality issues.
  3. Risk and governance review. Mapped against UK GDPR, ICO guidance, sector regulation, and (where relevant) the EU AI Act. Identifies DPIAs that will be needed and lawful basis questions to resolve.
  4. 12-month roadmap. Sequenced, costed, with dependencies and decision points. The first quarter should be detailed enough to start.
  5. Operating model recommendation. How AI will be owned, governed, and operated once initial builds ship. Includes headcount or vendor recommendations.

A slide deck summarising these for the executive audience is fine and expected. A slide deck instead of these is not.

Common mistakes buyers make

Buying the assessment from a firm that cannot build. Strategy-only consultancies produce roadmaps that look reasonable on paper and fall apart at procurement. The estimates are wrong because the firm has never priced the work it is recommending. The architecture is wrong because the firm has never operated the systems it is recommending. Buy assessment from a firm that ships, even if you intend to build internally.

Scoping too broadly. An organisation-wide assessment across 12 functions in four weeks produces shallow findings everywhere. Pick the two or three functions where AI is most likely to pay back and do a deep assessment there. The methodology then transfers.

Excluding the people who do the work. Process maps built from interviews with directors are wrong. The people doing the work daily know where the exceptions, workarounds, and informal systems are. Skip them and your roadmap will collide with reality in week two of execution.

Treating the roadmap as a contract. A 12-month AI roadmap written today will be partially wrong in six months because the underlying technology is moving quickly. Treat it as a plan with quarterly checkpoints, not a fixed delivery schedule.

Skipping the operating model question. Organisations regularly commission three or four AI builds and then have no clear owner once delivery ends. The systems decay. The operating model question - who runs this on Tuesday morning when something breaks - matters more than the technology choices.

When to skip the assessment entirely

Not every organisation needs a formal readiness assessment. If you have a clearly scoped, high-value use case with obvious data sources and a single function sponsor, going straight to a discovery sprint for that specific build is usually faster and cheaper. A four-week discovery for a defined RAG assistant or a specific workflow automation costs roughly the same as a broad assessment and produces a working prototype.

The assessment is worth its cost when there are multiple competing priorities, when data and systems are genuinely fragmented, when there is no internal consensus on what AI should do, or when governance and risk concerns need resolving before any build can start. In those cases, two to four weeks of structured assessment saves months of false starts.

Frequently asked questions

How long does an AI readiness assessment take?

For a mid-market organisation, two to six weeks is the realistic range. Two weeks suits a narrow scope - one function, one process area, a defined hypothesis. Four weeks is typical for cross-functional reviews covering three or four business areas. Six weeks is appropriate when systems and data are fragmented, when multiple regulators are in scope, or when the engagement includes a working prototype. Assessments that drag beyond eight weeks usually do so because scope was poorly defined at the start, not because the work genuinely needs that long. Push back on any proposal that quotes three months for discovery alone.

How much should an AI readiness assessment cost?

Expect £10,000 to £40,000 for a credible mid-market engagement, depending on scope and whether a prototype is included. Sub-£5,000 offers are typically template exercises with limited interview time and no real data audit. £100,000-plus engagements from large consultancies often include benchmarking and change management workstreams that do not change the core answer. The work that actually drives the recommendations - process interviews, data audit, systems review, roadmap pricing - has a fairly fixed cost regardless of who delivers it. Pay for the depth of the work, not the brand on the cover slide.

Do we need an external assessment or can we run one internally?

Internal assessments work when you have a senior person with both AI delivery experience and the political standing to challenge sacred cows. They tend to fail on the second criterion - it is hard to tell the COO that her favourite workflow is not worth automating. External assessment also brings pattern recognition from other engagements, which shortens the path to the right answer. The honest middle ground is an external assessment with heavy internal participation, so the knowledge transfers and the recommendations have internal ownership before the consultants leave.

What about UK GDPR and ICO requirements?

Any assessment touching personal data needs to address UK GDPR specifically. The ICO has published detailed guidance on AI and data protection, including expectations around DPIAs, lawful basis, transparency, accuracy, and the rights of data subjects when automated decision-making is involved. A credible assessment identifies which use cases require a DPIA, flags lawful basis questions, and references the ICO guidance by name. Sector-specific rules also apply - FCA for financial services, SRA for legal practices, MHRA for medical devices. Assessments that handwave compliance with generic "responsible AI" language are not safe to rely on.

How does an AI readiness assessment differ from a digital transformation audit?

Digital transformation audits are broader and shallower. They cover technology strategy, application portfolio, infrastructure, ways of working, and digital skills across the organisation. An AI readiness assessment is narrower and deeper, focused specifically on whether AI use cases are buildable and worth building. The two overlap on data and infrastructure but diverge sharply on output. Transformation audits typically recommend multi-year programmes. AI readiness assessments recommend specific builds that can start within weeks. If you already have a recent transformation strategy, the readiness assessment focuses only on the AI-specific layer and is much faster.

What happens after the assessment?

The roadmap should be specific enough that the first one or two initiatives can move to build immediately. Typically the organisation either contracts the assessing firm to deliver the first build, runs a competitive procurement against the roadmap, or builds internally with the roadmap as the brief. Whichever route is chosen, the operating model recommendation should be implemented in parallel - assigning an owner, defining governance, setting up the tooling and processes that will run the systems after launch. Roadmaps that sit on a shelf for three months lose half their value, because the underlying technology and the organisation's priorities will have shifted.

Can we run an assessment if our data is in a mess?

Yes, and this is usually the right time to do one. The assessment will identify which use cases are blocked by data quality and what the remediation looks like. In many cases the remediation is narrower than expected - you do not need a perfect data platform to run a customer support RAG assistant, you need clean access to a specific knowledge base. The assessment separates "we need to fix everything before we can do anything" (rarely true) from "these three data issues block these four use cases and here is what to do about each" (almost always the real picture).

How often should we redo the assessment?

Full reassessment every 12-18 months is reasonable for organisations actively building AI systems, because the technology landscape and the organisation's own capabilities shift meaningfully in that window. A lighter quarterly review of the roadmap, looking at what shipped, what changed, and what new use cases have emerged, keeps the plan current without the cost of a full engagement. Organisations that treat the original roadmap as fixed for 12 months almost always end up executing against an out-of-date plan by month nine.

Closing thought

The point of a readiness assessment is to replace opinion with evidence before you commit budget to AI builds. Done well, it pays for itself many times over by killing the wrong projects early and accelerating the right ones. Done badly, it produces a glossy report that nobody opens after the readout. The difference is almost entirely about whether the firm running it can actually build the things it recommends.

If you are scoping a readiness assessment and want to discuss how AI Advisory approaches the work - including the specific deliverables, the prototype option, and how we handle UK GDPR and sector compliance - get in touch.

Ready to put this into production? book a discovery call.

Get started

Ready to automate your operations?

Walk away with a prioritised list of automation and AI wins, costed, sequenced, and yours. The call is 30 minutes, free, and binds you to nothing. The shortest path to knowing whether AI Workflow Agency is the right fit.