What an AI readiness assessment actually is
An AI readiness assessment is a structured review of whether an organisation is set up to adopt AI safely and productively — a check on the decisions, data, and controls that sit underneath any AI product, not the product itself. Done properly, it answers a narrower question than "should we do AI": it answers "what, specifically, should we build, buy, change, or stop, and what's actually stopping us."
It is not a maturity-model questionnaire that could be reskinned for any technology, and it is not a sales pitch wearing a diagnostic's clothes. The output should be specific to your organisation — grounded in your actual data, tools, and team, not a generic five-stage curve with your logo on the cover slide.
What a good assessment should cover
Five areas come up in almost every credible assessment. A provider that skips more than one of them is giving you a partial picture and pricing it as a full one.
Strategy and use-case prioritisation
Which problems are actually worth solving with AI, ranked by value and feasibility rather than by novelty. A good assessment separates the use case someone is excited about from the use case that will actually move a number, and says so plainly even when they're different.
Data readiness
Whether the data the use case depends on exists, is accessible, is accurate enough, and is legally usable for the purpose intended. This is where most AI projects actually die — not in the model, but in data that turns out to be siloed, stale, or off-limits once someone checks.
Tools and architecture
What's already in place, what integrates cleanly, and where a new tool would create more operational debt than it removes. This should include an honest view of build-vs-buy, not a default recommendation toward whatever platform the assessor happens to resell.
Skills and operating model
Who would actually own, run, and improve the thing after it ships — not just who builds it. A team that can commission a build but can't maintain, evaluate, or retrain what they get is buying a liability with a nice demo attached.
Governance, risk, and compliance
Data protection, model risk, explainability where it's required, and who signs off before something touches production or customer data. For regulated sectors this usually needs to be more than a checkbox — it needs a named owner and a documented decision trail.
Red flags of a bad one
- A generic questionnaire with no evidence gathered from your actual systems, data, or team interviews.
- No named deliverable. "We'll assess you and let you know" is not a scope — ask exactly what document or artefact you get, and when.
- A recommendation that happens to be their own product. An assessment that concludes you need the assessor's platform is not independent.
- A score with no reasoning shown. A number out of 100 with no evidence behind it isn't a finding, it's a marketing device.
- One template reused across every client. Ask to see (a redacted version of) a real output before you commit.
- No engagement with your actual data or systems — a desk review based entirely on a stakeholder questionnaire misses the risks that only show up when someone actually looks.
What it should cost in the UK market
Pricing varies a lot by scope and depth, and it's worth understanding roughly where the bands sit before you take a call.
| Shape | Typical UK range | What drives it |
|---|---|---|
| Rapid / self-serve scorecard | Free – low hundreds | Structured questionnaire, no direct system access, quick baseline only. |
| SMB-focused fixed-price assessment | Roughly £500 – £5,000 | Single team or single decision, a few stakeholder interviews, a written report with a prioritised action plan. |
| Enterprise / Big-4-style engagement | £50,000+ | Multiple business units, formal governance workshops, board-facing deliverables, and follow-on advisory scoped in. |
The main cost drivers are scope (one team versus the whole organisation), depth (a desk review versus hands-on access to real data and systems), the deliverable format (a slide deck versus an evidence-backed written report with a prioritised roadmap), and whether implementation is bundled in or kept separate. Be wary of any fixed price that doesn't specify which of these it actually includes.
Questions to ask a provider before you sign
- What exactly will I receive, in what format, and by when?
- Will you look at our actual data and systems, or only interview our team?
- How many of our stakeholders will you talk to, and for how long?
- Do you sell an implementation service, and if so, how do you keep the assessment's recommendations independent of it?
- Can I see an example of a real (redacted) output before I commit?
- Who signs off the findings, and what's the correction process if we disagree with a conclusion?
- Does the assessment cover governance and compliance, or only the technical and data layers?
- What happens after the report — is there a bounded follow-up window for questions?
DIY vs hire: a decision framework
DIY usually works when you have one team, a low-risk use case, no regulated data involved, and enough internal AI literacy to be honest with yourselves about the answers. A structured self-assessment or a free scorecard is often genuinely enough at this stage — spending money to confirm what you already suspect is a poor trade.
Hiring an independent assessor earns its cost when the decision touches regulated or sensitive data, needs board or cross-functional sign-off, involves more than one competing use case that needs ranking, or when you need evidence you can defend to a regulator, auditor, or sceptical stakeholder rather than an internal opinion. Independence matters most exactly when the stakes are highest — an assessor with no product to sell you has less reason to shade the conclusion.
Start with the free scorecard
Appaya publishes a free AI readiness scorecard at /scorecard/ — a fast, structured baseline across the same five areas covered above, without needing to commit budget first. It won't replace a full assessment if the decision is high-stakes, but it's a genuinely useful starting point: it tells you roughly where the gaps are before you spend anything.
If the scorecard surfaces something worth digging into properly, that maps to Appaya's AI Codebase Audit — an evidence-backed opportunity map and prioritised action plan, not a slide deck. Pricing is fixed, quoted after a free fit check, so you know the number before anything starts.