Semitora.

2 July 2026 · Updated: 13 August 2026

AI readiness audit: what exactly we check and what you get at the end

An AI readiness audit is a paid, 2–4-week diagnosis that settles three things: where AI will genuinely help in your processes, whether your data is fit for it, and what the EU AI Act requires of you. The output is a working document — an AI-system inventory, a risk classification and a prioritised implementation roadmap — not a slide deck. Below is the exact scope: what we check, in what order, and what you receive at the end.

Why audit at all, instead of “just implementing”

Most failed AI projects don’t fail on the model — they fail earlier: on picking the wrong process, on data that can’t be used safely, or on legal obligations discovered after the fact. An audit costs a fraction of an implementation and turns “we want something with AI” into a list of concrete projects with a viability and risk assessment. For companies already using off-the-shelf tools (ChatGPT, Copilot), the audit also answers which of them fall under the AI Act — most provisions apply from 2 August 2026.

What exactly we check

What you get at the end

The final report records decisions in five working artefacts. We adapt ownership to the organisation; the matrix below shows the accountability that must be assigned before the audit closes.

ArtefactOwnerDecision / next step
AI-system and shadow-AI registerAI portfolio owner or nominated coordinatorconfirm scope, missing systems and the next review date
Risk matrixrisk / compliance owner with legal inputidentify cases that require further qualification and controls
Project list scored for impact and feasibilitybusiness sponsorselect a PoC and defer or reject the remaining candidates
Architecture recommendationtechnical ownerapprove data, security, integration and cost constraints
Roadmapsponsor and action ownersagree sequence, dependencies, dates and go/no-go gates

Optionally, the audit closes with a PoC on the client’s real data. The board, IT, compliance and legal teams then use these artefacts instead of reconstructing decisions from a slide deck.

What an audit is not

It is not a sales pitch in disguise, nor a “free consultation”. It is also not a guarantee of full AI Act compliance — gaps are closed later with implementations and documentation. The audit and register do not provide an automated legal classification, legal advice or a conformity certificate. They provide the material for a decision: what to deploy, in what order, and how to tell whether it works.

What next

If you want to assess the organisation before starting a project, complete the free AI Readiness Scorecard. Its 24 questions show whether the next step is to stabilise the foundations, prepare one process or consider a bounded PoC.

The scope of the three engagement levels — audit, implementation, retainer — is described on the services page. What a system that grew out of such an audit looks like is shown in mojApteczka — a production GenAI system in healthcare. Book an AI readiness audit — we reply within one business day.