Back

6 AI Readiness Frameworks Compared: Which One to Use

Cisco, Microsoft, NIST, ISO 42001, AIME and Oxford Insights, on identical criteria. None of the six was built for a mid-sized private company.

Date

Reading time

12

min

Amelia Miller

Co-founder and CEO

An AI readiness framework is a structured set of questions an organisation answers about itself, usually grouped into pillars covering strategy, data, infrastructure, governance, skills and culture, to establish what would have to change before AI spending returns anything.

Pick the shortest one your leadership team will actually finish. Six credible frameworks are compared below, and the differences between them matter far less than whether anybody collects real evidence against the questions. A rigorous framework abandoned at pillar three tells you less than a short one answered with the documents open.

There is a second thing worth knowing before you choose, and the comparison articles tend to skip it. Every framework on this list was built by an organisation with an interest in the result. One measures governments. Two are published by cloud vendors whose products appear in the recommendations. One is a survey instrument that exists partly to produce a statistic for a press release. None of that makes them useless. It does decide which questions each one forgot to ask.

How the six frameworks compare

Identical criteria across all six, including the one nobody publishes.

Framework

Built to assess, and for whom

Free

How long it takes

What you get out

Whose interest it also serves

Cisco AI Readiness Index

Enterprise readiness across six pillars, benchmarked against companies of 500+ employees

Yes, including a self-assessment tool

Not published

A score and a band: Pacesetter, Chaser, Follower or Laggard

Cisco, whose infrastructure sits behind the pillar weighted most heavily

Microsoft AI Readiness Assessment

Organisational readiness across seven pillars, for any size

Yes, on Microsoft Learn

45 minutes, per Microsoft

A score you can re-take, plus recommendations

Microsoft, since the recommendations route to Azure and Copilot

NIST AI Risk Management Framework 1.0

AI risk, not readiness, for developers and deployers of AI systems

Yes

Not a questionnaire. It is a document you apply

Four functions to organise work around: Govern, Map, Measure, Manage

Nobody commercial. A US federal agency with no product to sell

ISO/IEC 42001:2023

Whether your AI management system meets an auditable standard

No. The standard must be bought

Months, if you are certifying

Requirements to conform to, and a certificate if you pass

Certification bodies and the consultancies that prepare you for them

DSIT AI Management Essentials (AIME)

Your AI management processes, aimed at UK start-ups and SMEs

Yes

Not published

A self-assessment of your own processes. Not a certification

The UK government, which is exploring using it in public procurement

Oxford Insights Government AI Readiness Index

The AI readiness of 195 national governments

Yes, after registration

You do not complete it. You read it

A country ranking and a methodology worth borrowing

Nobody selling to you, but it was never about your company

What is actually inside an AI readiness framework?

Six areas, and they are close to identical wherever you look: strategy, data, infrastructure, governance, talent and culture. The convergence is real rather than lazy, which is the first useful thing to know, because it means the framework you pick is not going to surprise you with a category the others missed.

Cisco's AI Readiness Index measures exactly those six pillars, broken into 49 indicators, with each pillar weighted by its assessed importance to overall readiness. Microsoft's AI Readiness Assessment uses seven, splitting business strategy from AI strategy and adding model management. Most consultancy versions run five to eight and cover the same ground with different labels.

What differs is not the categories. It is the evidence each one asks you to produce. A framework that asks "is your data governed?" and accepts a yes has told you nothing. One that asks which systems hold customer data, who approved the last access change, and when the retention schedule was reviewed has made you go and look. The second kind takes four times as long and is the only kind worth running.

Which of these was built for a private company?

Two of the six, and neither was built for a mid-sized one. This is the finding that does most of the work, and it survives however you cut the list.

The Oxford Insights Government AI Readiness Index assesses 195 governments on their capacity to use AI in public services and to regulate it, and describes itself as "the only global index focused specifically on the role of government". It has run since 2017 and its methodology is worth reading whoever you are. It is also measuring national data infrastructure, digital public services and legislative capacity. A 200-person professional services firm in Leeds does not have legislative capacity, and any score it produces against this index is a category error with a number attached.

The NIST AI Risk Management Framework, released on 26 January 2023 with a Generative AI Profile added in July 2024, is the most respected document on the list and is not a readiness framework at all. Its four functions, Govern, Map, Measure and Manage, organise how you handle AI risk once you are building or deploying systems. Use it when you have something in production. It will not tell you whether to start.

Cisco's index and Microsoft's assessment are the two aimed at companies. Cisco's benchmark population is organisations with 500 or more employees, so a 60-person business comparing itself to that band is reading someone else's mirror. Microsoft's has no size floor, which makes it the most broadly usable instrument here, and it is also the one most obviously pointed at a product catalogue.

That leaves the interesting one. AI Management Essentials, from the UK Department for Science, Innovation and Technology, is explicitly aimed at start-ups and SMEs, is free, and was drawn from ISO/IEC 42001, the NIST framework and the EU AI Act. It went to consultation on 6 November 2024, closed on 29 January 2025, and the government published its response to the 65 submissions on 6 February 2026. It assesses your management processes rather than your AI systems, and it is not a certification. For a UK company under a few hundred people it is the closest thing on this list to a fit, and almost nobody comparing frameworks mentions it.

Who benefits if your score comes back low?

In four of the six cases, the organisation that wrote the questions. This belongs in every comparison table and appears in none of them, so it is worth being blunt about, including where it points at us.

A vendor readiness assessment is a qualification tool wearing a diagnostic's clothes. That is not an accusation of bad faith. Microsoft's assessment is well built, the seven pillars are sensible, and 45 minutes for a scored baseline is a fair trade. But its recommendations resolve towards Azure, Microsoft Foundry and Copilot, because those are the products the authors have. Ask it whether you should be on Google Cloud and see what happens.

Cisco's index has a subtler version of the same tilt. It is conducted by an independent third party as a double-blind survey, most recently of 7,985 senior business leaders across 30 markets, which is a serious piece of research by any standard. It also weights infrastructure heavily, and Cisco sells infrastructure. Its headline finding, that around 13% of organisations qualify as Pacesetters and that the figure has barely moved in three years, is a good statistic and it is also a statistic that makes the case for buying more networking.

ISO/IEC 42001:2023, published in December 2023 as the first international standard for AI management systems, has no vendor behind it, but a certification ecosystem in front of it. The standard has to be purchased, conformity is assessed by an accredited body, and an industry of readiness consultancies exists to prepare you for that audit. That is a legitimate market. It is still a market, and "you are not yet certifiable" is what it sells.

Our own position: ivee runs a paid AI diagnostic, so we have the same interest as everyone else on this list. Which is why the recommendation below sends most readers to something free.

How long does an AI readiness assessment take?

Between 45 minutes and several months, and the honest answer is that only one of these six publishes a figure. Microsoft says 45 minutes for its assessment. Cisco and DSIT publish no completion time. ISO/IEC 42001 certification runs over months because it involves an external audit rather than a questionnaire.

The published number is also the least interesting one, because it measures typing rather than finding out. Forty-five minutes of a single person guessing at seven pillars produces a score about that person's confidence. The same seven pillars answered with the admin console open, the data map to hand and three department heads in the room takes most of a day and produces something you can act on.

Plan for two to three weeks of elapsed time for anything worth having. Most of that is not analysis. It is waiting for someone in IT to confirm what the retention policy actually says, and discovering that the person who knew has left. A parallel skills baseline across the team runs on roughly the same clock and answers the questions the readiness framework will ask about talent, so it is worth starting both in the same week.

Should you write your own instead?

For most companies under about 250 people, yes, and it takes four questions rather than 49 indicators. This is the answer no framework publisher can give you, so it is worth stating plainly.

The four:

  • What decision are we trying to make? If the answer is not a specific decision with a budget line attached, stop here. A readiness score with no pending decision is a document.

  • What would have to be true for that to work? Name three or four things. Usually access to a system, a clean-enough dataset, someone who owns it, and permission to change what a team is measured on.

  • Which of those is not true today, and who knows? Go and ask them. This is the whole assessment.

  • What would we have to see in twelve weeks to keep going? Decide it now, in writing, while nobody is invested in the answer.

Borrow the pillar list from Cisco or Microsoft so you do not miss a category, then throw away the scoring. The scoring is the part that looks rigorous and does the least, and there is a reason so many UK companies stall after the assessment stage: a band label is not a plan, and the gap between "you are a Chaser" and "here is what to do on Monday" is where these programmes go to sleep.

Write your own if you are under 250 people, have a specific decision pending, and can get three department heads in a room. Use a published framework if you need something a board or an auditor recognises, if you are regulated, or if the assessment has to be defensible to somebody who was not in the room.

Which one should you choose?

Match the framework to the decision you have to defend, not to how thorough it looks.

  • You need a fast, scored baseline and you already run Microsoft. The Microsoft AI Readiness Assessment. Forty-five minutes, seven sensible pillars, re-takeable, and the product bias costs you little because you were buying Microsoft anyway.

  • You are a UK SME and want something a public sector buyer will recognise. AI Management Essentials. Free, built for your size, and the government is exploring using it in procurement, which makes it the only one on this list that might one day be worth points on a bid.

  • You have AI in production and need to manage the risk. The NIST AI Risk Management Framework. Not a readiness tool, but the right document once something is live and somebody asks who is accountable.

  • A customer or regulator is asking for assurance. ISO/IEC 42001. Expensive and slow, and the only one that ends in a certificate somebody else will accept.

  • You want to benchmark against large enterprises. The Cisco AI Readiness Index, if you have 500+ employees. Below that, read it for the pillar structure and ignore the band.

  • You are writing a policy paper or a national strategy. Oxford Insights. Otherwise it is a fascinating read that will not help you.

What people get wrong about picking a readiness framework

The most common error is treating framework selection as the decision, when it is roughly the least consequential choice in the process. Four more, in the order they cost you money.

Completing it from memory. A framework answered by one person from what they believe to be true measures that person. Every question worth asking has a document or a console behind it, and the assessment is the act of going to look.

Citing a framework its author has retired. The AWS Cloud Adoption Framework for AI, ML and generative AI, published on 13 February 2024, is still quoted in consultancy decks. AWS now heads that whitepaper with a notice that it is "for historical reference only" and that some of its content may be outdated. Check the top of the page before you build a slide on it.

Comparing your score to a published average. Cisco's 13% is drawn from companies of 500 or more employees across 30 markets, using Cisco's own weightings and indicators. Your self-assessed score against a different instrument is not the same measurement, and putting the two on one slide is how a board gets a confident answer to a question nobody asked.

Stopping at the score. The band is the cheapest output and the one most likely to be presented. What matters is the list of things that were not true, who owns each one, and what changes if they stay untrue. If the assessment did not produce that list, it has not finished, and no amount of re-scoring will produce it. The same trap catches the measurement that comes afterwards, which is why the metric you pick after the rollout deserves as much argument as the framework you pick before it.

Start with the decision, not the framework

The framework question is usually a symptom. Somebody has been asked to demonstrate rigour before spending, a search produced four plausible models, and the choice between them has become a substitute for the harder conversation about what the money is meant to change.

If that sounds close to the mark, the fastest route is to skip the selection problem entirely and start from the decision waiting on it. ivee's AI strategy and governance work begins by mapping what is already in use across the business, including the tools nobody approved, then turns that into a roadmap with the governance attached. Bring us the decision you are stuck on and who has to sign it off, and we will tell you which of these six frameworks, if any, is worth your afternoon.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.