What is an AI readiness audit, and what does it ask?
A plain definition of an AI readiness audit, how it differs from a website scan, and the six pillars and 30 questions our free version actually asks.
By Carl Chessum
An AI readiness audit is a structured assessment of whether your business, not your website, is in a fit state to get value from AI. It examines the things that determine whether an AI project survives contact with your organisation: the quality of your data, the consistency of your processes, the capability and attitude of your people, the state of your technology, the clarity of your strategy, and whether anyone is accountable for governance. It produces a position, not a plan. It tells you where you actually stand before you commit budget.
The free version on this site is 30 questions across six pillars, five questions per pillar, and takes 7 minutes. Every answer is self-reported by the person taking it. At the end you get a readiness score out of 120, a band for each of the six pillars, and a short synopsis. No sales call is booked unless you ask for one. That is deliberately the whole of it. A diagnosis is worth more when it is not attached to a pitch.
What an AI readiness audit is not
Search “free AI readiness assessment” and a good number of the results will ask you for a website URL. What comes back grades your site: how a crawler reads it, how your content is structured, whether an AI assistant could summarise your services page. That is a legitimate thing to measure. It is not an AI readiness audit. Your site could score perfectly while your finance team still reconciles three systems by hand every Friday afternoon.
It is also not a systems audit. Nobody connects to your CRM, reads your database schema, or runs a script against your data warehouse. If you want that, it is a different, longer, more expensive exercise and you should buy it from someone who will do it properly. A readiness audit is a self-assessment instrument. Its accuracy depends entirely on how honestly you answer, which is one reason the free version does not ask for anything more than your answers.
And it is not a tooling inventory. It will not tell you which of the licences you bought in 2024 are still being used. That question matters, but it belongs in a procurement review, not a readiness assessment.
The difference between an AI readiness assessment and an AI audit
These two terms get used interchangeably and they should not be. An AI audit, in the sense most auditors and regulators mean it, is a backward-looking examination of AI systems you already run: what they do, what data they consume, what decisions they influence, whether you can evidence any of it. It assumes deployment has happened.
A readiness assessment is forward-looking and assumes it has not. It asks whether the conditions exist for deployment to work at all.
Most organisations need the second one first, and a surprising number discover they need both at once. Grant Thornton’s 2026 AI Impact Survey found that 78% of business executives lack strong confidence they could pass an independent AI governance audit within 90 days. That is not a statistic about laggards. Those are executives whose organisations are already using AI, saying out loud that they could not evidence how it is governed if someone credible asked them to. Readiness and governance stopped being sequential a while ago.
The six pillars, and what each one is looking for
Data
The first question is the one that does most of the work: if you needed a clean, accurate list of your best 500 customers right now, how confident are you in what you would get? People answer that question faster than any of the other 29, and the speed is informative. The rest of the pillar asks how complete your decision-making data is, whether your key systems exchange data without someone manually exporting and importing spreadsheets, how often reliable data actually drives an important decision, and who owns data quality by name.
That last one is the quiet killer. Plenty of businesses can describe their data problems in detail and cannot name a single person responsible for fixing them. If this pillar bands low, everything downstream is theoretical. I have written before about why dirty data is the cheapest AI mistake to fix first, and it remains true: it is cheaper to fix before you buy a tool than after.
Process
Five questions on documentation, consistency, review cadence, bottleneck visibility and ownership. The sharpest of them: if you asked three different people in your business to complete the same task, how similar would their approach be?
Run that as an actual test before you take the audit. Pick your most important process, ask three people to describe how they do it, separately, in writing. Compare. If the three descriptions do not match, you do not have a process, you have three habits that happen to produce roughly similar output. AI applied to that will automate the variance and speed it up.
People
Attitude, capability, leadership modelling and formal investment in understanding. This pillar catches the gap between what a leadership team believes about its workforce’s AI enthusiasm and what is actually true. It also asks how actively you, personally, are modelling adoption. Trying it, talking about it, normalising it. Leaders often score their team harshly and themselves generously here, and the pillar band tends to expose that.
Technology
The practical constraints. Whether systems can talk to each other, whether the estate is stable enough to build on, whether the business could support something new without breaking something old. You do not need an in-house engineering function to score well. There is a version of this that works without a tech team, and plenty of businesses with large IT departments band poorly because the estate is a museum of past decisions.
Strategy
Whether there is a defined reason to use AI beyond competitive anxiety. Grant Thornton’s survey found competitor moves were the biggest external pressure driving adoption, with many leaders motivated by fear of falling behind rather than a clear view of where AI creates value in their specific business model. Strategy is the pillar where that shows up. If you cannot articulate the commercial outcome, the tooling decision is arbitrary.
Governance
Policy, risk, accountability, oversight. Who signs off. Who would answer if a regulator, a customer or your insurer asked how a decision was made.
This pillar exists partly because ownership is genuinely unresolved in most organisations, not just badly communicated. Pearl Meyer surveyed corporate leaders and got four different answers: 32% said the C-suite as a group is accountable, 27% pointed to individual business leaders, 22% to the group one level below the C-suite, and 17% said AI sits with functional heads. Those are leaders in the same room describing different accountability structures. If your governance pillar bands low, this is usually why, and it is not solved by appointing a chief AI officer to a business that has not decided what it wants owned.
What the score actually means
Six pillars, five questions each, scored out of 120 with a band per pillar. The composite number is the least useful part. The bands are where the value is.
A business scoring evenly at a middling level across all six is in a different position from one that scores strongly on Technology and Strategy and collapses on Data and Process. The first has a broad capability gap. The second has a specific, expensive failure waiting to happen, because it has the ambition and the infrastructure to start building on foundations that will not hold. In my experience the second profile is far more common in the 200 to 2,000 employee range, and far more costly.
That is the whole argument for measuring before buying. PwC’s 29th Global CEO Survey covered 4,454 leaders across 95 countries and found 56% reported neither higher revenues nor lower costs from AI over the past 12 months, with only 12% reporting both. Those are not businesses that failed to buy AI. They bought it. The decision most leaders think they are making, which vendor, sits downstream of the one they skipped.
The free result gives you the score, the bands and a short synopsis. It does not give you an action plan. If you want one, the £97 Full Report is a more robust version with action plans attached, and the £497 Deep Dive is a 30/60/90-day plan for closing the gaps before you spend on AI. Both sit on the same diagnosis. You can also take the free version, read your bands, and do nothing else with us, which is a perfectly reasonable outcome and the reason no call is booked automatically.
Who this is for, and who it is not
It is built for the person who has to sign the cheque or defend the decision: CEO, MD, COO, CFO, CIO, CTO, IT director. Businesses roughly between 50 and 10,000 people. It works because that person can answer all 30 questions from their own knowledge of the business, without needing to convene anyone.
It is less useful if you have already deployed AI at scale across multiple functions and need a formal governance audit with evidence trails. Different instrument, different purpose.
It is also less useful if you want it to tell you what you already believe. The questions are blunt enough that they are difficult to game unless you are deliberately trying, and there is no reward for a high score. Nobody sees it but you.
Where to start
Before you take anything, run the two tests in this article yourself. The 500-customer question, answered honestly. The three-people process test, run for real. Those two answers will tell you more in an afternoon than most vendor discovery calls tell you in a quarter, and they overlap with several of the signs a business is not ready for AI.
Then, if you want a structured read across all six pillars rather than two of them, the free AI readiness audit is 30 questions and 7 minutes. Score out of 120, a band per pillar, a short synopsis. Nobody calls you unless you ask.