An AI readiness assessment is a structured audit of whether an organisation can actually adopt AI: what its data allows, what its tools permit, what its governance covers, and what its people can already do.
It measures the organisation, not the technology and not the individuals in it. It does not tell you which tools to buy, does not rank your staff, and does not hand you a plan. What it produces is a diagnosis: which of those four is blocking you, and by how far.
That is the reason to run one. Most leadership teams arrive with a theory about what is holding them back, and the assessment exists to test that theory rather than confirm it. The blocker is rarely where people expect. A single overall readiness score, which is what most free tools return, hides the one thing you needed to find out.
What does an AI readiness assessment measure?
There are four, and they fail independently. That independence is the whole point: a company can be badly unready on data and still get real value from training its people next month, because these are not four stages of a sequence. They are four separate questions that happen to share a report.
1. Data
Whether the information AI would need to work on is findable, current and permitted to be used. In practice: where the documents actually live, whether anyone can say which version is authoritative, whether access is governed by role or by whoever set up the folder in 2019, and whether the terms under which customer data was collected allow it to be used this way.
You can test the first part this week. Pick a real question the business asks often, and time how long it takes someone to assemble the underlying material by hand. If nobody can find it, no model will either.
2. Tool access
What the organisation has actually licensed, what IT and security permit, and what the gap is between those two. This is the dimension most often assumed rather than checked. Firms routinely discover during an assessment that the tool everyone believes is approved was never signed off, or that a tool cleared a year ago has since changed its data handling.
The check is a conversation with whoever administers the tenancy: which AI tools are licensed, which are blocked, which are neither, and who decides.
3. Governance
Whether there are written rules about who may use what, on which data, with what oversight, and whether anyone follows them. A policy that exists but nobody can recall is a governance failure of a different kind from having no policy, and the two need different fixes.
The checkable version: ask three people in different teams which AI tools they are allowed to use and what they are not allowed to put into them. If you get three different answers, the policy is not the problem, distribution is. If you get three blank looks, you have found your blocker, and it is the cheapest of the four to clear.
There is an established vocabulary here worth borrowing rather than inventing. The NIST AI Risk Management Framework, published in January 2023 and voluntary across sectors, organises this work into four functions: Govern, Map, Measure and Manage. Most assessments are a shallower version of that structure, and knowing so tells you what a thorough one would look like.
4. People
Whether anyone can build with the tools, and whether the organisation knows who. This one is measured badly almost everywhere. In ivee's survey of 500 UK AI decision makers in August 2026, 75% said either that they had no idea, or that fewer than 1% of their workforce knew how to build and deploy an AI automation. The "no idea" half is the finding that matters for readiness: the people holding the budget could not state the capability of the workforce they were budgeting for.
Note the boundary. This dimension asks whether the organisation has capability and knows where it sits. It does not assess individuals, which is a different exercise covered by what to assess before you train a team, or by ivee's AI fluency quiz for a single person.
What separates a real assessment from a lead-generation quiz?
Three things: named criteria published before you start, evidence collected rather than opinions gathered, and a result that is capable of coming back bad.
The third one is where most free tools give themselves away. A large share of free readiness assessments are scored so that nobody fails, because their purpose is to produce a follow-up call rather than a finding. If you cannot work out from the questions what a poor answer would look like, you are filling in a contact form with extra steps.
The evidence test is the practical one. An assessment that asks "how mature is your data governance, on a scale of one to five" is collecting a feeling. An assessment that asks to see the access list, the retention policy and the last three months of tool usage is collecting evidence. Only the second kind survives a follow-up question.
Free does not mean worthless, though. The Department for Science, Innovation and Technology publishes AI Management Essentials, a voluntary self-assessment tool for organisations implementing responsible AI management, released in November 2024 with the government response following in February 2026. Nobody is selling you anything at the end of it. Vendor-run assessments such as Microsoft's AI readiness assessment are useful too, as long as you read them knowing that a tool built by a platform tends to measure the things that platform sells.
ivee sells a readiness diagnostic. Take the paragraph above as applying to us as much as anyone.
Who has to be involved?
Four people, and one of them is the one most often left out. You need whoever owns the commercial outcome, usually a COO or transformation lead. You need someone from the function whose work is actually in scope, not a representative of all functions. You need whoever holds the data, which in most organisations is a specific person rather than a department.
And you need someone from IT or security with the authority to say what is permitted. Assessments run without that person produce a readiness score and a list of recommendations that turn out to be disallowed, which is worse than not running one, because it burns the credibility you would need to run it again.
Nobody needs to be in the room for the whole thing. The data conversation and the governance conversation are different meetings with different people, and trying to hold them together is how assessments become week-long workshops nobody will repeat.
What should the output look like?
Four scored dimensions with the evidence behind each, a named blocker, and a stated confidence level. Not one number.
The test is whether it survives a board follow-up. If a director asks "why are we a three on data", the answer has to be a specific thing somebody looked at, not a summary of what the room felt. That means the output needs to carry what was examined, who said it, and when, in enough detail that a sceptic could go and re-check one item.
It should also say what it did not look at. An assessment that covers four dimensions and lets you assume it covered everything is the kind that gets discredited by the first thing it missed.
What does it take to run one properly?
Around three days of internal effort, spread over a fortnight or so of calendar time and across more people than you expect. Most of that fortnight is waiting: for the tenancy administrator to pull a licence list, for someone to find the retention policy, for a diary to open.
The effort splits unevenly across the four. Tool access is the cheapest to establish and often takes an hour with the right person. Governance is a document review plus two conversations. People needs a real sample of work rather than a survey. Data is the expensive one, because the only reliable test is asking someone to actually go and assemble something and watching how long it takes.
Budget for the evidence, not the workshop. The failure mode is an assessment that consumes a day of everyone's time in a room and produces opinions, when the same finding was available from three access lists and a usage export. Where the duration question is the one you need answered in more detail, the frameworks comparison sets out how long each published framework takes to complete in full, because they differ by more than a week.
How this differs from a maturity score and a skills assessment
A readiness assessment asks whether you can start. A maturity model asks how far along you are, which is a different question and a less useful one when the true answer is "we have not started". A skills assessment measures people rather than the organisation.
The distinction that costs money is between an assessment and a framework. A framework is the structure you assess against; the assessment is what happens when somebody collects the evidence and commits to a verdict. Choosing between the published frameworks is a real decision with real trade-offs, and the six main AI readiness frameworks compared works through which suits a private UK company, along with how long each takes to complete properly.
What to do when the result comes back bad
Read which dimension failed before doing anything, because the four have different remedies and different timescales. Governance is the fastest to fix and the one most often mistaken for a large project. Data is the slowest and the one most often underestimated. Tool access is usually an afternoon with the right administrator. People is the one where work starts immediately and compounds.
The mistake is treating a poor overall score as a reason to wait. Because the dimensions are independent, a company that scores badly on data can start on people the same month and lose nothing, and will be in a better position when the data work finishes because it will have people who know what to ask for.
What a score cannot do is tell you what to spend. That is a separate calculation, and if what is being argued about is whether training is worth the money, the free AI training ROI calculator turns team size, hours saved per person and industry into an annual figure. Worth having before the conversation rather than after, given that 96% of the decision makers in ivee's research could not show the numbers on their organisation's AI spend.
A score is a diagnosis. It is not a plan, it does not commit you to a sequence, and its only real job is to stop you solving the wrong problem well.
Where to start
Pick the dimension your leadership team is most confident about, and check it first. Confidence is where assessments find their surprises, and the fastest way to establish whether an assessment is worth running properly is to have one comfortable assumption turn out to be wrong.
If your real position is the one we hear most often, which is some version of "I am kind of flying blind", that is a reason to run the assessment rather than a reason to delay it. ivee runs readiness diagnostics with leadership teams, and will tell you when the answer is that you do not need one. Book a call and bring the assumption you are most sure of.




