Strategy

AI readiness assessment: the framework we run inside SMEs

What an AI readiness assessment covers, the six dimensions we score, and what a 10 to 250 person business should get out of one.

The short answer

An AI readiness assessment is a structured review of whether a business can actually deploy and sustain AI, not just buy it. A useful one scores six dimensions: strategic clarity, workflow suitability, data access, systems and integration, workforce capability, and governance. For a business of 10 to 250 people it should take two to three weeks and end with a ranked list of use cases carrying cost, effort and expected return, not a maturity badge.

Key takeaways

  • Readiness is about deployment capability, not enthusiasm or tooling spend.
  • Score six dimensions: strategy, workflow, data, systems, people, governance.
  • The output that matters is a ranked, costed use-case roadmap you own.
  • Two to three weeks is normal for an SME. Anything longer is usually theatre.
  • The most common blocker in SMEs is workforce capability, not data quality.

Most AI programmes in mid-sized businesses do not fail at the model. They fail because nobody established, before the spending started, whether the business could absorb the change. An AI readiness assessment is the diagnostic that answers that question honestly.

This is the framework we use at brep when we run an AI Operating Review for businesses of 10 to 250 people in the UK and US. You can run a lighter version of it yourself.

What an AI readiness assessment actually measures

Enterprise maturity models score you against a five-level ladder and hand back a number. That is useless to an operations director with a quarter to show something. Readiness for an SME is practical: can this specific business get a specific AI workflow into production and keep it there.

DimensionThe question it answersCommon SME failure
Strategic clarityDo we know which business outcomes AI is meant to move?Adopting tools with no target metric
Workflow suitabilityWhich processes are repetitive, rule-shaped and high volume?Automating the visible work, not the expensive work
Data accessCan a system reach the information a human uses to decide?Assuming a warehouse is required before anything can start
Systems and integrationDo our tools have APIs, and who owns them?Discovering the CRM is locked down after the build starts
Workforce capabilityCan our people specify, use and challenge AI output?Deploying to a team that was never trained
GovernanceWho signs off, who monitors, what is off limits?No owner once the consultant leaves

The six dimensions, and how to score them

1. Strategic clarity

Ask the leadership team to name the three business numbers they want to move in the next twelve months. Cost to serve, sales cycle length, gross margin, time to hire, churn. If AI is not attached to one of them, it is a hobby. Score low if the answer is a tool name rather than a metric.

2. Workflow suitability

Sit with the people doing the work and map a week. You are looking for tasks that are repetitive, judgement-light or judgement-bounded, text or voice heavy, and frequent enough that automating them compounds. A task done twice a month rarely justifies a build. A task done forty times a day usually does.

3. Data access

The bar is lower than most vendors imply. You do not need a data warehouse. You need the information a competent human would use to make the decision, reachable by a system. That is often a CRM record, a shared drive of contracts, an inbox and a pricing sheet. Score access and permissions, not tidiness.

4. Systems and integration

List every system the target workflow touches and mark three things for each: does it have an API, who administers it, and is the contract yours to change. Legacy line-of-business software without an API is the single most common reason a promising use case moves down the roadmap.

5. Workforce capability

In our experience this is the binding constraint in SMEs far more often than data. Survey your teams on two things: how often they currently use AI in their role, and whether they could write a clear brief for a task they would hand to it. If the second answer is no across a department, training has to come before deployment.

6. Governance

Name the accountable person for every deployed workflow, the review cadence, the data that must never leave your tenancy, and the escalation path when the system is wrong. In the UK and US alike, the practical requirement for an SME is defensible process and record keeping, not a compliance department.

What the assessment should produce

A readiness assessment that ends in a maturity level has failed. The deliverables that earn the fee are:

  1. A workflow map of how work actually moves, drawn from observation rather than the org chart.
  2. A ranked list of candidate use cases, each with estimated build effort, running cost and expected annual return.
  3. A sequencing plan showing which use case goes first and what has to be true before the second one starts.
  4. A capability plan naming who needs training, on what, and by when.
  5. An honest list of what not to do this year, with reasons.

You should own all of it, in a form you can hand to any supplier. If the roadmap only works with the firm that wrote it, that is a sales document.

How long it should take, and what it should cost

For a business of 10 to 250 people, two to three weeks of elapsed time is right: roughly a week of interviews and observation, a week of analysis and costing, and a readout. Longer engagements in this size band usually reflect the supplier's process, not your complexity.

On price, the market is wide. Free assessments from tooling vendors exist and are qualification calls in disguise. Independent reviews at the SME end typically land in the low five figures in pounds or dollars, and the number should be defensible against the value of the top-ranked use case. If the roadmap's first item is worth less than the review that found it, do not buy the review.

Ten questions to ask before you commission one

  • Who will you interview, and will you observe the work or only ask about it?
  • Do you cost every use case, including running cost, or only build effort?
  • How do you rank use cases when the returns are uncertain?
  • What do we own at the end, and in what format?
  • Will you tell us not to build something if the numbers do not work?
  • How do you assess our team's capability, and what do you do about gaps?
  • Which of our systems have you integrated with before?
  • Who from your team does the work, and are they the people we met?
  • What is your view on where humans should stay in the loop?
  • If we take the roadmap to another builder, does it still work?

Doing a lighter version yourself

If you are not ready to commission anything, run this in a fortnight internally. Pick three departments. Ask each manager to log every recurring task their team does for one week, with rough time per instance and frequency. Multiply out the annual hours. Mark each task as judgement-heavy or judgement-light. Sort the judgement-light tasks by annual hours. You now have a candidate list that is more grounded than most vendor decks.

What you will not have is the costing, the integration reality check or the sequencing. That is the part worth paying for.

Frequently asked questions

How do I assess my organisation's AI readiness?
Score six dimensions from 1 to 5: strategic clarity, workflow suitability, data access, systems and integration, workforce capability, and governance. Gather the evidence by observing a week of real work in two or three departments rather than surveying opinion. Your lowest-scoring dimension sets the ceiling for the whole programme, so fix that first.
Do we need clean data before an AI readiness assessment?
No. The assessment tells you what data condition actually blocks your top use cases, which is usually narrower than a full clean-up. Most SME workflows need access to a handful of systems, not a data warehouse.
How long does an AI readiness assessment take?
Two to three weeks for a business of 10 to 250 people: about a week of interviews and observation, a week of analysis and costing, then a readout. Enterprise engagements run longer because of stakeholder count, not because the method is different.
What is the difference between an AI readiness assessment and an AI audit?
An audit usually reviews AI you already run, covering usage, risk and compliance. A readiness assessment looks forward and answers whether you can deploy successfully, and where to start. Businesses with no AI in production want the readiness assessment.
Which companies offer AI readiness assessments?
Three groups: large consultancies pricing for enterprise, tooling vendors offering free assessments that qualify you for their product, and independent AI firms that build as well as advise. For an SME, the third group is usually the best fit because the roadmap is written by people who will have to make it work.

Work through this with us

brep runs AI operating reviews, workforce training and agent deployment for businesses of 10 to 250 people in the UK and US. One diagnosis, one workflow, someone accountable for keeping it working.

Related reading

Strategy10 min

AI adoption strategy: a 90 day plan for a 10 to 250 person business

Read
Use cases11 min

30 AI use cases for small and medium businesses, ranked by payback

Read
Buying guide10 min

How to choose an AI automation agency, and how to spot a bad one

Read