Semitora.

Open self-assessment · version 1.0 · 22 July 2026

AI Readiness Scorecard

Twenty-four questions to check whether an organisation is ready for a bounded AI proof of concept. The scorecard covers process, data, shadow AI, accountability, risk and governance. It does not select a tool for the team; it shows what needs attention before budget is committed.

Completion time: 20–30 minFormat: browser / print / PDFScale: 0–48 points
Important: this scorecard is not a certificate or an automated AI Act conformity assessment. The result is a starting point for discussing one specific use case.

How to complete it

Select one answer for every question and write the number in the final column. Score the current state, not the plan. If an answer depends on a team or use case, choose the lower score and add a note.

0It does not exist or nobody controls it.
1It exists partly, locally or without documentation.
2It is defined, used and can be demonstrated.
Organisation / team:
Use case:
Date:

24 questions

#Question012Score
A. Process and business value
1Does the process have one owner accountable for the outcome?
2Are the start, end and expected result of the process unambiguous?
3Do we know case volume, common exceptions and the current workload?
4Can success be expressed as a business measure independent of AI usage itself?
B. Data and access
5Do we know which data sources this use case requires?
6Is the data complete, current and consistent enough for representative cases?
7Are source owners and access rules known?
8Can we prepare a secure, representative sample for testing?
C. Shadow AI and current tools
9Do we know where employees already use AI tools in this process?
10Are there clear rules for entering company data into external tools?
11Can the team identify unauthorised accounts, integrations or data flows?
12Can an unsafe tool be withdrawn and the work moved to an approved environment?
D. Roles and accountability
13Are business, technical and risk-acceptance owners identified?
14Is it clear who approves access, changes and progression to the next stage?
15Does the operating team have time and skills to participate in the test?
16Do users know when to trust the output and when to hand the case to a person?
E. Risk and governance
17Have possible harms to customers, employees, the company and third parties been described?
18Are privacy, security and sector-specific obligations known?
19Are system boundaries and actions requiring human approval defined?
20Is there a process for reporting incidents, stopping use and naming a decision-maker?
F. Readiness for a bounded PoC
21Is the PoC limited to one process and a predefined sample of data?
22Will success, cost and time criteria be written down before work starts?
23Can the PoC run without irreversible actions or risk to live operations?
24Is a decision planned after the test: continue, improve or stop?

Result and next step

Total score:out of 48
0–15

Stabilise the foundations

Do not begin with a model. Name the process owner, outcome, data sources and principal risks. Next step: a scoping workshop or readiness audit.

16–31

Prepare one process

The foundations exist, but accountability or controls remain local. Next step: narrow the use case, close the gaps and write PoC criteria.

32–48

Consider a bounded PoC

The organisation has the conditions for a controlled test of one use case. Next step: choose the simplest suitable mechanism and test it on a representative sample.

A high score does not remove risk or replace analysis of the specific system. A low score does not rule out AI; it indicates the order of work.

To save a PDF: Print → Save as PDF