AI-Ready #3. Assessing Enterprise AI Readiness: 30 Questions Across Six Capabilities

Many enterprises know that their data and operating model are not fully prepared for AI.

The harder question is:

Where exactly is the constraint — and what should we improve first?

A company may already have a data lake, MDM, APIs and governance policies but still struggle to deploy enterprise AI.

Another company may have weaker enterprise architecture overall but enough trusted data and controls to operate one narrowly defined AI use case successfully.

That is why AI readiness should not be reduced to a single technology checklist.

The purpose of an AI-Ready assessment is not to rank the company. It is to identify the specific data, architecture, governance and operating-model gaps that constrain real AI use cases.

This article provides a practical self-assessment using 30 questions across six diagnostic capabilities.

The score is intended as an internal baseline for repeated assessment. It is not an industry benchmark, certification model or external maturity ranking.

How This Assessment Relates to the Five AI-Ready Capabilities

The next article in this series organizes AI readiness into five core enterprise capabilities.

This assessment uses six diagnostic dimensions instead.

The two structures serve different purposes.

Framework Purpose Why the Structure Differs
#3 — Six Diagnostic Capabilities Assess current enterprise readiness and identify gaps. Separates areas such as freshness and operating model so operational weaknesses are visible.
#4 — Five Core Capabilities Design the higher-level AI-Ready operating system. Groups related capabilities into a simpler architecture and management framework.

They should therefore be read as complementary frameworks rather than competing maturity models.

The Six Diagnostic Capabilities

# Diagnostic Capability Core Question
1 Data Architecture & Retrieval Can AI access the required structured and unstructured information through appropriate interfaces?
2 MDM & Master Identity Are customers, products, materials, suppliers and other critical entities consistently identified and governed?
3 Data Quality & AI Evaluation Can the organization measure whether critical data and AI outputs are reliable enough for the use case?
4 Data Delivery & Freshness Does AI receive required data at the speed and reliability demanded by the business decision?
5 Governance, Security & Compliance Are data access, agent actions, human oversight, evidence and regulatory requirements operationalized?
6 Operating Model & Skills Are ownership, stewardship, AI product management and operational capabilities clear enough to sustain production AI?

How to Score the 30 Questions

Each question is scored from 1 to 5.

Score Interpretation
1 Not defined. Work depends largely on individual knowledge, manual activity or ad hoc decisions.
2 Partially practiced in individual teams or domains, but standards and ownership remain inconsistent.
3 A defined process, technology capability and accountable owner exist for important use cases.
4 The capability operates across multiple domains or use cases and is monitored through evidence or KPIs.
5 The capability is repeatable at enterprise scale, auditable and continuously improved using operational evidence.

Scores of 2 and 4 represent intermediate states between the anchors above.

Do not assign a score without evidence.

Possible evidence includes:

  • architecture diagrams,
  • system configurations,
  • data-quality reports,
  • API logs,
  • MDM workflows,
  • evaluation results,
  • access policies,
  • audit trails,
  • incident reports, and
  • named accountable owners.

The difference between “we have this capability” and “we think we have this capability” is evidence.

Capability 1 — Data Architecture & Retrieval

This dimension asks whether AI can obtain the right information through the right technical pattern.

A mature architecture does not necessarily mean that every dataset is moved to one platform.

It means structured data, documents, APIs, search and tool access are connected according to actual AI requirements.

ID Assessment Question 1 3 5
1-1 Are priority AI use cases mapped to their required data sources? No dependency map Mapped for selected pilots Dependencies maintained across production AI portfolio
1-2 Are structured facts accessed through authoritative queries, APIs or governed data products? Ad hoc extracts Defined interfaces for key systems Reusable governed services across use cases
1-3 Are keyword, vector and hybrid retrieval selected according to the information need? One search method used by default Alternative retrieval methods tested Retrieval strategy continuously evaluated by use case
1-4 Can AI retrieve enterprise content with the required metadata and authorization context? Limited metadata or security trimming Key metadata and access filtering implemented Metadata, authorization and provenance integrated into retrieval
1-5 Are agent tool and API interfaces bounded according to business purpose? Broad or unmanaged access Selected tools use defined permissions Tool registry, policy, authorization and audit operate consistently

Capability 1 subtotal: ____ / 25

Capability 2 — MDM & Master Identity

This dimension evaluates whether enterprise AI can determine which business entity it is actually dealing with.

This becomes particularly important when AI combines information across ERP, CRM, SCM, commerce, service or external systems.

ID Assessment Question 1 3 5
2-1 Are critical master domains and authoritative systems defined? Unclear source of truth Defined for major domains Domain authority, ownership and consumption contracts maintained enterprise-wide
2-2 Are matching, duplicate resolution and survivorship rules governed? Manual / inconsistent Rules operate in selected domains Rules, exceptions, stewardship and performance are continuously managed
2-3 Are hierarchies and relationships managed as governed business context? Mostly isolated records Important relationships maintained Relationships are reusable context for analytics and AI
2-4 Do material master-data changes have appropriate validation, approval, audit and recovery controls? Manual / inconsistent Controls exist for critical changes Risk-based controls, evidence and recovery are systematically operated
2-5 Is agent authority differentiated for master-data Read, Recommend, Submit and Execute actions? No explicit distinction Read / write controls for selected use cases Action-level authority, approval and audit policy consistently enforced

Capability 2 subtotal: ____ / 25

SAP MDG provides capabilities such as validation rules, quality evaluation, governance workflows and master-data controls that can support this type of foundation.

SAP Help Portal — MDG Data Quality Management

Capability 3 — Data Quality & AI Evaluation

This capability connects Data Quality with actual AI outcomes.

The goal is not to create one generic “AI-Ready Data Quality Score.”

The goal is to determine whether the data and evidence required for a specific AI decision are sufficiently reliable.

ID Assessment Question 1 3 5
3-1 Are critical data elements defined for priority AI use cases? Generic DQ only Critical fields identified for pilots Critical data linked systematically to use cases, risk and controls
3-2 Are Data Quality thresholds derived from business consequences rather than arbitrary enterprise-wide percentages? No thresholds or generic targets only Risk-based targets for important use cases Thresholds recalibrated using operating evidence and failure impact
3-3 Are representative evaluation datasets and expected outcomes defined? Demo-based evaluation Evaluation sets for major pilots Versioned evaluation sets and regression tests operate continuously
3-4 Can AI failures be traced to data, retrieval, model, tool or workflow causes? Root cause unclear Manual root-cause analysis Cross-layer observability and structured failure analysis
3-5 Are human overrides and production exceptions used to improve data and AI controls? Not captured Captured for selected workflows Exceptions feed a systematic evaluation and improvement loop

Capability 3 subtotal: ____ / 25

Capability 4 — Data Delivery & Freshness

AI does not require every enterprise dataset to be real time.

It requires data to be fresh enough for the business decision.

An inventory agent and a corporate-policy assistant may have completely different latency requirements.

ID Assessment Question 1 3 5
4-1 Are freshness requirements defined from the AI business decision? No explicit requirement SLAs for priority use cases Decision-specific freshness policies consistently monitored
4-2 Are batch, API, event and CDC patterns selected according to actual latency needs? One integration pattern dominates Multiple patterns used appropriately Delivery architecture is standardized but use-case driven
4-3 Can consumers determine when critical data was last updated or verified? Freshness unclear Timestamp / metadata for key data Freshness and validity metadata consistently available to AI consumers
4-4 Are delivery failures, latency and stale-data conditions monitored? Reactive troubleshooting Monitoring for important flows End-to-end SLO / SLA monitoring and incident processes
4-5 Does AI have defined fallback behavior when critical data is unavailable or stale? AI continues without explicit control Fallback for selected high-risk cases Continue / warn / HITL / block behavior is policy-driven by risk

Capability 4 subtotal: ____ / 25

Capability 5 — Governance, Security & Compliance

AI governance becomes meaningful only when it changes how systems behave.

A policy that says “use AI responsibly” is not enough.

Governance must influence data access, retrieval, agent authority, approval, logging, monitoring and escalation.

NIST's AI Risk Management Framework is designed as a voluntary, use-case-agnostic framework for integrating trustworthiness and risk management into AI design, development, deployment, use and evaluation.

Its Playbook explicitly states that it is not a checklist that must be followed in its entirety; organizations are expected to select practices appropriate to their context.

NIST — AI Risk Management Framework

NIST AIRC — AI RMF Playbook

ID Assessment Question 1 3 5
5-1 Are AI data-access permissions aligned with user, agent, purpose and data sensitivity? Broad access RBAC / policy for key use cases Least-privilege and context-aware controls consistently enforced
5-2 Are agent action permissions differentiated by consequence? No explicit authority model Read / write distinction for important systems Read / Recommend / Submit / Execute authority controlled by policy
5-3 Is human oversight defined according to risk, reversibility and ambiguity? Ad hoc review Defined HITL for selected use cases Risk-based approval and escalation consistently operated
5-4 Can important AI decisions and actions be reconstructed after the event? Limited logs Application and tool logs retained Source, model, tool, policy, approval and outcome evidence correlated end to end
5-5 Are applicable legal and regulatory requirements mapped to AI use cases? Handled after deployment Risk / legal review for important projects Requirements integrated into lifecycle, controls, documentation and monitoring

Capability 5 subtotal: ____ / 25

For organizations operating in or serving the European Union, the EU AI Act also applies a risk-based approach to AI and creates different obligations according to system characteristics and use.

European Commission — AI Act

Regulatory applicability should be determined for the specific organization, jurisdiction and AI use case rather than inferred from this assessment score.

Capability 6 — Operating Model & Skills

Enterprise AI can fail even when the technology works.

Common operating-model questions include:

  • Who owns the business outcome?
  • Who owns the data?
  • Who approves master-data rules?
  • Who owns evaluation?
  • Who decides whether the agent receives additional authority?
  • Who investigates incidents?

If those questions have no clear answer, the organization is not operationally ready to scale AI.

ID Assessment Question 1 3 5
6-1 Does each priority AI use case have an accountable business owner? Technology team owns everything Business owner defined for important pilots Business outcome accountability consistently assigned across portfolio
6-2 Are Data Owner and Data Steward responsibilities explicit for critical domains? Unclear ownership Owners and stewards named Decision rights, KPIs, escalation and change governance operate consistently
6-3 Is there clear accountability for AI product quality, evaluation and production behavior? No single accountable role AI product / technical ownership defined End-to-end product, evaluation and operational accountability institutionalized
6-4 Can cross-functional teams investigate data, AI and business-process failures together? Siloed escalation Cross-functional review for major incidents Integrated operating process with clear incident and improvement ownership
6-5 Are skills and reusable practices available beyond a small group of experts? Key-person dependency Training and reusable patterns exist Shared standards, enablement and communities support enterprise scale

Capability 6 subtotal: ____ / 25

The Assessment Summary

Each capability has a maximum of 25 points, and the complete assessment has a maximum of 150.

But the total score should not become the main management metric.

Capability Score Business Impact Risk AI Demand Feasibility
1. Architecture & Retrieval ___ / 25 H / M / L H / M / L H / M / L H / M / L
2. MDM & Master Identity ___ / 25 H / M / L H / M / L H / M / L H / M / L
3. Data Quality & Evaluation ___ / 25 H / M / L H / M / L H / M / L H / M / L
4. Delivery & Freshness ___ / 25 H / M / L H / M / L H / M / L H / M / L
5. Governance & Security ___ / 25 H / M / L H / M / L H / M / L H / M / L
6. Operating Model & Skills ___ / 25 H / M / L H / M / L H / M / L H / M / L
Total ___ / 150 Use as an internal baseline. Prioritize individual gaps rather than maximizing the total score.

Why the Lowest Score Is Not Automatically Priority #1

Suppose the assessment produces:

  • Architecture & Retrieval — 18 / 25
  • MDM & Master Identity — 12 / 25
  • Data Quality & Evaluation — 15 / 25
  • Delivery & Freshness — 20 / 25
  • Governance & Security — 11 / 25
  • Operating Model & Skills — 14 / 25

It may be tempting to invest in Governance first because it has the lowest numerical score.

That could be correct.

It could also be wrong.

If the company's highest-value production AI initiative is a supplier-risk agent and duplicate supplier identities are causing incorrect risk aggregation, the MDM gap may deserve the first investment even though Governance scored slightly lower.

Low Score ≠ Automatic Priority

I would evaluate each gap against four additional factors.

Factor Decision Question
Business Impact Does the gap materially affect revenue, cost, service, productivity or operational performance?
Risk Could the gap create financial, regulatory, security, safety or customer harm?
AI Demand Do actual production or near-production AI use cases require this capability now?
Feasibility Can the capability be materially improved with available ownership, technology, budget and time?

Do Not Turn the Assessment into a Fake Mathematical Formula

A prioritization formula such as:

Priority = Gap × Business Impact × Risk × AI Demand ÷ Effort

can be useful as a discussion aid.

But the numbers assigned to these factors are usually judgment-based.

Therefore the formula should not create a false impression of statistical precision.

A better executive process is:

Assessment Evidence
↓
Business Impact & Risk Review
↓
AI Portfolio Dependency
↓
Feasibility
↓
Investment Decision

Use the Assessment at the Use-Case Level as Well as the Enterprise Level

An enterprise-wide score can hide significant differences between AI initiatives.

Consider two use cases.

Use Case A — Internal Policy Assistant

Important dimensions may be:

  • Architecture & Retrieval,
  • Data Quality & Evaluation, and
  • Governance & Security.

MDM may be a secondary dependency.

Use Case B — Supplier Master Change Agent

Important dimensions may be:

  • MDM & Master Identity,
  • Data Quality,
  • Delivery & Freshness,
  • Governance & Security, and
  • Operating Model.

The organization can therefore have a reasonable enterprise average while still being unprepared for one high-impact agentic workflow.

Enterprise readiness tells you what reusable capabilities exist. Use-case readiness tells you whether a specific AI system can safely and effectively go into production.

Evidence Should Be Recorded with Every Score

A practical assessment worksheet should include more than the numerical score.

Question Score Evidence Gap Owner Next Action
2-3 Relationships & Hierarchies 3 Supplier parent relationship maintained for key regions Coverage incomplete globally Supplier Data Owner Prioritize relationships required by risk agent

This turns the assessment into an improvement instrument rather than a presentation score.

Reassess Based on Material Change — Not a Fixed Ritual

A repeated assessment is useful because AI architectures, business priorities and operating risks change.

Possible reassessment triggers include:

  • a major new AI use case,
  • deployment of agents with greater authority,
  • a new enterprise data platform,
  • material regulatory changes,
  • a major AI or data incident,
  • significant MDM modernization, or
  • a change in business ownership or operating model.

A quarterly or semiannual cycle may be useful for some organizations, but there is no universal frequency requirement.

An Illustrative 90-Day Improvement Cycle

Period Primary Work Output
Days 0–30 Complete the 30-question assessment using evidence. Map gaps to production and near-production AI use cases. Baseline and Evidence Register
Days 31–60 Select a small number of high-impact gaps using Business Impact, Risk, AI Demand and Feasibility. Prioritized Improvement Backlog
Days 61–90 Implement improvements on real AI workflows and compare data, AI and business evidence with the baseline. Continue / Scale / Revise Decision

The 90-day period is illustrative.

The important element is the closed loop:

Assess → Prioritize → Improve → Measure → Reassess

Five Assessment Mistakes to Avoid

1. Comparing the Score with an Unverified Industry Average

This framework does not have a statistically validated industry benchmark.

Use the score to compare the organization's own baseline and progress.

2. Giving Every Question Equal Strategic Importance

The questionnaire uses equal scoring for simplicity.

Investment decisions should still reflect business impact and risk.

3. Treating Level 5 as the Objective for Everything

Some capabilities do not need enterprise-wide maximum maturity.

A narrow low-risk use case may operate effectively with a lower level of infrastructure and control.

4. Scoring Technology but Ignoring the Operating Model

AI does not become operational because a platform has been installed.

Ownership, evaluation, incident management and improvement processes are equally important.

5. Completing the Assessment Once and Filing It Away

The value of the assessment comes from linking gaps to implementation decisions and then measuring whether those decisions improved outcomes.

My Practical Takeaway

The 30-question assessment is not designed to answer:

“Are we an AI-Ready company — yes or no?”

It is designed to answer more useful questions:

Which AI use cases are currently constrained?

Is the constraint architecture, master identity, Data Quality, freshness, governance or operating model?

What evidence supports that conclusion?

Which gap creates the largest business or risk impact?

Which capability can be improved now?

What evidence will demonstrate that the improvement actually worked?

The total score can help establish a baseline.

But the real management value comes from the relationship between:

Gap
×
Business Impact
×
Risk
×
AI Demand
→
Investment Priority

This relationship should be treated as a decision framework rather than a statistically precise formula.

A useful AI-Ready assessment does not tell executives how mature the company looks. It tells them which capability must improve next for an important AI use case to become more reliable, governable and scalable.

Sources & Further Reading

Editorial Note
The six diagnostic capabilities, 30 assessment questions, 1–5 scoring method, assessment summary, prioritization approach and 90-day improvement cycle in this article are Digital Future & Strategy practitioner frameworks. They are not official Gartner, PwC, Deloitte, IDC, Forrester, NIST, SAP or regulatory maturity models, certification criteria or statistically validated industry benchmarks. Scores should be used as internal baselines supported by evidence. Investment priorities should be determined from actual AI use cases, business impact, risk, AI demand, feasibility and applicable regulatory requirements rather than from the total score alone.

Reviewed: September 2026


AI-Ready Strategy Series

Part 1 — Why AI-Ready Now / Readiness Assessment

AI-Ready #2. Global AI-Ready Trends in 2026: From Model-Centric AI to Trusted Enterprise Context
AI-Ready #3. Assessing Enterprise AI Readiness: 30 Questions Across Six Capabilities
AI-Ready #4. Five Core Capabilities for Enterprise AI Readiness

Previous: Global AI-Ready Trends in 2026: From Model-Centric AI to Trusted Enterprise Context

Next: Five Core Capabilities for Enterprise AI Readiness

Comments

Popular posts from this blog

AI Strategy #1. AI Agents: Chatbots, RPA and Agentic AI Explained

MDM #9. Why Enterprise MDM Governance Fails After Go-Live — and How to Make Ownership Real

AI Strategy #17. Hybrid Cloud and GenAI: Designing Enterprise AI Infrastructure