2 July 2026 · Updated: 13 August 2026
AI readiness audit: what exactly we check and what you get at the end
An AI readiness audit is a paid, 2–4-week diagnosis that settles three things: where AI will genuinely help in your processes, whether your data is fit for it, and what the EU AI Act requires of you. The output is a working document — an AI-system inventory, a risk classification and a prioritised implementation roadmap — not a slide deck. Below is the exact scope: what we check, in what order, and what you receive at the end.
Why audit at all, instead of “just implementing”
Most failed AI projects don’t fail on the model — they fail earlier: on picking the wrong process, on data that can’t be used safely, or on legal obligations discovered after the fact. An audit costs a fraction of an implementation and turns “we want something with AI” into a list of concrete projects with a viability and risk assessment. For companies already using off-the-shelf tools (ChatGPT, Copilot), the audit also answers which of them fall under the AI Act — most provisions apply from 2 August 2026.
What exactly we check
- Processes. We map the places where AI has a measurable effect: repetitive document work, handling enquiries, knowledge search. Each candidate gets a score: impact, feasibility, risk.
- Data. We check sources, quality, permissions and freshness — the things RAG projects actually fail on. The detailed checklist is in data readiness for RAG.
- Shadow AI. We inventory the AI tools used outside IT’s knowledge — private accounts, plugins, automations. Without that register, neither compliance nor data security can be quantified.
- Roles and risk under the AI Act. Each system gets your company’s role (deployer / provider) and a risk category — the method is shown step by step here.
- Architecture and costs. We recommend an AWS option and estimate delivery and running costs. The Region and inference mode determine where processing may occur. Application and logging configuration determine where additional copies are created. KMS controls encryption and keys, while network design controls the transport path. The shared responsibility model identifies which settings and evidence remain the customer’s responsibility. Our guide to AI architecture on AWS for GDPR and AI Act requirements sets out the checks required before deployment. We separately explain what drives the cost of a RAG system or an agent.
- Funding. A fit check against grant programmes (FENG/SMART Path, Dig.IT, KFS) — if the project qualifies, we prepare the technical part of the application.
What you get at the end
The final report records decisions in five working artefacts. We adapt ownership to the organisation; the matrix below shows the accountability that must be assigned before the audit closes.
| Artefact | Owner | Decision / next step |
|---|---|---|
| AI-system and shadow-AI register | AI portfolio owner or nominated coordinator | confirm scope, missing systems and the next review date |
| Risk matrix | risk / compliance owner with legal input | identify cases that require further qualification and controls |
| Project list scored for impact and feasibility | business sponsor | select a PoC and defer or reject the remaining candidates |
| Architecture recommendation | technical owner | approve data, security, integration and cost constraints |
| Roadmap | sponsor and action owners | agree sequence, dependencies, dates and go/no-go gates |
Optionally, the audit closes with a PoC on the client’s real data. The board, IT, compliance and legal teams then use these artefacts instead of reconstructing decisions from a slide deck.
What an audit is not
It is not a sales pitch in disguise, nor a “free consultation”. It is also not a guarantee of full AI Act compliance — gaps are closed later with implementations and documentation. The audit and register do not provide an automated legal classification, legal advice or a conformity certificate. They provide the material for a decision: what to deploy, in what order, and how to tell whether it works.
What next
If you want to assess the organisation before starting a project, complete the free AI Readiness Scorecard. Its 24 questions show whether the next step is to stabilise the foundations, prepare one process or consider a bounded PoC.
The scope of the three engagement levels — audit, implementation, retainer — is described on the services page. What a system that grew out of such an audit looks like is shown in mojApteczka — a production GenAI system in healthcare. Book an AI readiness audit — we reply within one business day.