AI-Ready #3. Assessing Enterprise AI Readiness: 30 Questions Across Six Capabilities
Many enterprises know that their data and operating model are not fully prepared for AI.
The harder question is:
A company may already have a data lake, MDM, APIs and governance policies but still struggle to deploy enterprise AI.
Another company may have weaker enterprise architecture overall but enough trusted data and controls to operate one narrowly defined AI use case successfully.
That is why AI readiness should not be reduced to a single technology checklist.
The purpose of an AI-Ready assessment is not to rank the company. It is to identify the specific data, architecture, governance and operating-model gaps that constrain real AI use cases.
This article provides a practical self-assessment using 30 questions across six diagnostic capabilities.
The score is intended as an internal baseline for repeated assessment. It is not an industry benchmark, certification model or external maturity ranking.
How This Assessment Relates to the Five AI-Ready Capabilities
The next article in this series organizes AI readiness into five core enterprise capabilities.
This assessment uses six diagnostic dimensions instead.
The two structures serve different purposes.
| Framework | Purpose | Why the Structure Differs |
|---|---|---|
| #3 — Six Diagnostic Capabilities | Assess current enterprise readiness and identify gaps. | Separates areas such as freshness and operating model so operational weaknesses are visible. |
| #4 — Five Core Capabilities | Design the higher-level AI-Ready operating system. | Groups related capabilities into a simpler architecture and management framework. |
They should therefore be read as complementary frameworks rather than competing maturity models.
The Six Diagnostic Capabilities
| # | Diagnostic Capability | Core Question |
|---|---|---|
| 1 | Data Architecture & Retrieval | Can AI access the required structured and unstructured information through appropriate interfaces? |
| 2 | MDM & Master Identity | Are customers, products, materials, suppliers and other critical entities consistently identified and governed? |
| 3 | Data Quality & AI Evaluation | Can the organization measure whether critical data and AI outputs are reliable enough for the use case? |
| 4 | Data Delivery & Freshness | Does AI receive required data at the speed and reliability demanded by the business decision? |
| 5 | Governance, Security & Compliance | Are data access, agent actions, human oversight, evidence and regulatory requirements operationalized? |
| 6 | Operating Model & Skills | Are ownership, stewardship, AI product management and operational capabilities clear enough to sustain production AI? |
How to Score the 30 Questions
Each question is scored from 1 to 5.
| Score | Interpretation |
|---|---|
| 1 | Not defined. Work depends largely on individual knowledge, manual activity or ad hoc decisions. |
| 2 | Partially practiced in individual teams or domains, but standards and ownership remain inconsistent. |
| 3 | A defined process, technology capability and accountable owner exist for important use cases. |
| 4 | The capability operates across multiple domains or use cases and is monitored through evidence or KPIs. |
| 5 | The capability is repeatable at enterprise scale, auditable and continuously improved using operational evidence. |
Scores of 2 and 4 represent intermediate states between the anchors above.
Do not assign a score without evidence.
Possible evidence includes:
- architecture diagrams,
- system configurations,
- data-quality reports,
- API logs,
- MDM workflows,
- evaluation results,
- access policies,
- audit trails,
- incident reports, and
- named accountable owners.
The difference between “we have this capability” and “we think we have this capability” is evidence.
Capability 1 — Data Architecture & Retrieval
This dimension asks whether AI can obtain the right information through the right technical pattern.
A mature architecture does not necessarily mean that every dataset is moved to one platform.
It means structured data, documents, APIs, search and tool access are connected according to actual AI requirements.
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 1-1 | Are priority AI use cases mapped to their required data sources? | No dependency map | Mapped for selected pilots | Dependencies maintained across production AI portfolio |
| 1-2 | Are structured facts accessed through authoritative queries, APIs or governed data products? | Ad hoc extracts | Defined interfaces for key systems | Reusable governed services across use cases |
| 1-3 | Are keyword, vector and hybrid retrieval selected according to the information need? | One search method used by default | Alternative retrieval methods tested | Retrieval strategy continuously evaluated by use case |
| 1-4 | Can AI retrieve enterprise content with the required metadata and authorization context? | Limited metadata or security trimming | Key metadata and access filtering implemented | Metadata, authorization and provenance integrated into retrieval |
| 1-5 | Are agent tool and API interfaces bounded according to business purpose? | Broad or unmanaged access | Selected tools use defined permissions | Tool registry, policy, authorization and audit operate consistently |
Capability 1 subtotal: ____ / 25
Capability 2 — MDM & Master Identity
This dimension evaluates whether enterprise AI can determine which business entity it is actually dealing with.
This becomes particularly important when AI combines information across ERP, CRM, SCM, commerce, service or external systems.
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 2-1 | Are critical master domains and authoritative systems defined? | Unclear source of truth | Defined for major domains | Domain authority, ownership and consumption contracts maintained enterprise-wide |
| 2-2 | Are matching, duplicate resolution and survivorship rules governed? | Manual / inconsistent | Rules operate in selected domains | Rules, exceptions, stewardship and performance are continuously managed |
| 2-3 | Are hierarchies and relationships managed as governed business context? | Mostly isolated records | Important relationships maintained | Relationships are reusable context for analytics and AI |
| 2-4 | Do material master-data changes have appropriate validation, approval, audit and recovery controls? | Manual / inconsistent | Controls exist for critical changes | Risk-based controls, evidence and recovery are systematically operated |
| 2-5 | Is agent authority differentiated for master-data Read, Recommend, Submit and Execute actions? | No explicit distinction | Read / write controls for selected use cases | Action-level authority, approval and audit policy consistently enforced |
Capability 2 subtotal: ____ / 25
SAP MDG provides capabilities such as validation rules, quality evaluation, governance workflows and master-data controls that can support this type of foundation.
SAP Help Portal — MDG Data Quality Management
Capability 3 — Data Quality & AI Evaluation
This capability connects Data Quality with actual AI outcomes.
The goal is not to create one generic “AI-Ready Data Quality Score.”
The goal is to determine whether the data and evidence required for a specific AI decision are sufficiently reliable.
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 3-1 | Are critical data elements defined for priority AI use cases? | Generic DQ only | Critical fields identified for pilots | Critical data linked systematically to use cases, risk and controls |
| 3-2 | Are Data Quality thresholds derived from business consequences rather than arbitrary enterprise-wide percentages? | No thresholds or generic targets only | Risk-based targets for important use cases | Thresholds recalibrated using operating evidence and failure impact |
| 3-3 | Are representative evaluation datasets and expected outcomes defined? | Demo-based evaluation | Evaluation sets for major pilots | Versioned evaluation sets and regression tests operate continuously |
| 3-4 | Can AI failures be traced to data, retrieval, model, tool or workflow causes? | Root cause unclear | Manual root-cause analysis | Cross-layer observability and structured failure analysis |
| 3-5 | Are human overrides and production exceptions used to improve data and AI controls? | Not captured | Captured for selected workflows | Exceptions feed a systematic evaluation and improvement loop |
Capability 3 subtotal: ____ / 25
Capability 4 — Data Delivery & Freshness
AI does not require every enterprise dataset to be real time.
It requires data to be fresh enough for the business decision.
An inventory agent and a corporate-policy assistant may have completely different latency requirements.
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 4-1 | Are freshness requirements defined from the AI business decision? | No explicit requirement | SLAs for priority use cases | Decision-specific freshness policies consistently monitored |
| 4-2 | Are batch, API, event and CDC patterns selected according to actual latency needs? | One integration pattern dominates | Multiple patterns used appropriately | Delivery architecture is standardized but use-case driven |
| 4-3 | Can consumers determine when critical data was last updated or verified? | Freshness unclear | Timestamp / metadata for key data | Freshness and validity metadata consistently available to AI consumers |
| 4-4 | Are delivery failures, latency and stale-data conditions monitored? | Reactive troubleshooting | Monitoring for important flows | End-to-end SLO / SLA monitoring and incident processes |
| 4-5 | Does AI have defined fallback behavior when critical data is unavailable or stale? | AI continues without explicit control | Fallback for selected high-risk cases | Continue / warn / HITL / block behavior is policy-driven by risk |
Capability 4 subtotal: ____ / 25
Capability 5 — Governance, Security & Compliance
AI governance becomes meaningful only when it changes how systems behave.
A policy that says “use AI responsibly” is not enough.
Governance must influence data access, retrieval, agent authority, approval, logging, monitoring and escalation.
NIST's AI Risk Management Framework is designed as a voluntary, use-case-agnostic framework for integrating trustworthiness and risk management into AI design, development, deployment, use and evaluation.
Its Playbook explicitly states that it is not a checklist that must be followed in its entirety; organizations are expected to select practices appropriate to their context.
NIST — AI Risk Management Framework
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 5-1 | Are AI data-access permissions aligned with user, agent, purpose and data sensitivity? | Broad access | RBAC / policy for key use cases | Least-privilege and context-aware controls consistently enforced |
| 5-2 | Are agent action permissions differentiated by consequence? | No explicit authority model | Read / write distinction for important systems | Read / Recommend / Submit / Execute authority controlled by policy |
| 5-3 | Is human oversight defined according to risk, reversibility and ambiguity? | Ad hoc review | Defined HITL for selected use cases | Risk-based approval and escalation consistently operated |
| 5-4 | Can important AI decisions and actions be reconstructed after the event? | Limited logs | Application and tool logs retained | Source, model, tool, policy, approval and outcome evidence correlated end to end |
| 5-5 | Are applicable legal and regulatory requirements mapped to AI use cases? | Handled after deployment | Risk / legal review for important projects | Requirements integrated into lifecycle, controls, documentation and monitoring |
Capability 5 subtotal: ____ / 25
For organizations operating in or serving the European Union, the EU AI Act also applies a risk-based approach to AI and creates different obligations according to system characteristics and use.
Regulatory applicability should be determined for the specific organization, jurisdiction and AI use case rather than inferred from this assessment score.
Capability 6 — Operating Model & Skills
Enterprise AI can fail even when the technology works.
Common operating-model questions include:
- Who owns the business outcome?
- Who owns the data?
- Who approves master-data rules?
- Who owns evaluation?
- Who decides whether the agent receives additional authority?
- Who investigates incidents?
If those questions have no clear answer, the organization is not operationally ready to scale AI.
| ID | Assessment Question | 1 | 3 | 5 |
|---|---|---|---|---|
| 6-1 | Does each priority AI use case have an accountable business owner? | Technology team owns everything | Business owner defined for important pilots | Business outcome accountability consistently assigned across portfolio |
| 6-2 | Are Data Owner and Data Steward responsibilities explicit for critical domains? | Unclear ownership | Owners and stewards named | Decision rights, KPIs, escalation and change governance operate consistently |
| 6-3 | Is there clear accountability for AI product quality, evaluation and production behavior? | No single accountable role | AI product / technical ownership defined | End-to-end product, evaluation and operational accountability institutionalized |
| 6-4 | Can cross-functional teams investigate data, AI and business-process failures together? | Siloed escalation | Cross-functional review for major incidents | Integrated operating process with clear incident and improvement ownership |
| 6-5 | Are skills and reusable practices available beyond a small group of experts? | Key-person dependency | Training and reusable patterns exist | Shared standards, enablement and communities support enterprise scale |
Capability 6 subtotal: ____ / 25
The Assessment Summary
Each capability has a maximum of 25 points, and the complete assessment has a maximum of 150.
But the total score should not become the main management metric.
| Capability | Score | Business Impact | Risk | AI Demand | Feasibility |
|---|---|---|---|---|---|
| 1. Architecture & Retrieval | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| 2. MDM & Master Identity | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| 3. Data Quality & Evaluation | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| 4. Delivery & Freshness | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| 5. Governance & Security | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| 6. Operating Model & Skills | ___ / 25 | H / M / L | H / M / L | H / M / L | H / M / L |
| Total | ___ / 150 | Use as an internal baseline. Prioritize individual gaps rather than maximizing the total score. | |||
Why the Lowest Score Is Not Automatically Priority #1
Suppose the assessment produces:
- Architecture & Retrieval — 18 / 25
- MDM & Master Identity — 12 / 25
- Data Quality & Evaluation — 15 / 25
- Delivery & Freshness — 20 / 25
- Governance & Security — 11 / 25
- Operating Model & Skills — 14 / 25
It may be tempting to invest in Governance first because it has the lowest numerical score.
That could be correct.
It could also be wrong.
If the company's highest-value production AI initiative is a supplier-risk agent and duplicate supplier identities are causing incorrect risk aggregation, the MDM gap may deserve the first investment even though Governance scored slightly lower.
I would evaluate each gap against four additional factors.
| Factor | Decision Question |
|---|---|
| Business Impact | Does the gap materially affect revenue, cost, service, productivity or operational performance? |
| Risk | Could the gap create financial, regulatory, security, safety or customer harm? |
| AI Demand | Do actual production or near-production AI use cases require this capability now? |
| Feasibility | Can the capability be materially improved with available ownership, technology, budget and time? |
Do Not Turn the Assessment into a Fake Mathematical Formula
A prioritization formula such as:
can be useful as a discussion aid.
But the numbers assigned to these factors are usually judgment-based.
Therefore the formula should not create a false impression of statistical precision.
A better executive process is:
↓
Business Impact & Risk Review
↓
AI Portfolio Dependency
↓
Feasibility
↓
Investment Decision
Use the Assessment at the Use-Case Level as Well as the Enterprise Level
An enterprise-wide score can hide significant differences between AI initiatives.
Consider two use cases.
Use Case A — Internal Policy Assistant
Important dimensions may be:
- Architecture & Retrieval,
- Data Quality & Evaluation, and
- Governance & Security.
MDM may be a secondary dependency.
Use Case B — Supplier Master Change Agent
Important dimensions may be:
- MDM & Master Identity,
- Data Quality,
- Delivery & Freshness,
- Governance & Security, and
- Operating Model.
The organization can therefore have a reasonable enterprise average while still being unprepared for one high-impact agentic workflow.
Enterprise readiness tells you what reusable capabilities exist. Use-case readiness tells you whether a specific AI system can safely and effectively go into production.
Evidence Should Be Recorded with Every Score
A practical assessment worksheet should include more than the numerical score.
| Question | Score | Evidence | Gap | Owner | Next Action |
|---|---|---|---|---|---|
| 2-3 Relationships & Hierarchies | 3 | Supplier parent relationship maintained for key regions | Coverage incomplete globally | Supplier Data Owner | Prioritize relationships required by risk agent |
This turns the assessment into an improvement instrument rather than a presentation score.
Reassess Based on Material Change — Not a Fixed Ritual
A repeated assessment is useful because AI architectures, business priorities and operating risks change.
Possible reassessment triggers include:
- a major new AI use case,
- deployment of agents with greater authority,
- a new enterprise data platform,
- material regulatory changes,
- a major AI or data incident,
- significant MDM modernization, or
- a change in business ownership or operating model.
A quarterly or semiannual cycle may be useful for some organizations, but there is no universal frequency requirement.
An Illustrative 90-Day Improvement Cycle
| Period | Primary Work | Output |
|---|---|---|
| Days 0–30 | Complete the 30-question assessment using evidence. Map gaps to production and near-production AI use cases. | Baseline and Evidence Register |
| Days 31–60 | Select a small number of high-impact gaps using Business Impact, Risk, AI Demand and Feasibility. | Prioritized Improvement Backlog |
| Days 61–90 | Implement improvements on real AI workflows and compare data, AI and business evidence with the baseline. | Continue / Scale / Revise Decision |
The 90-day period is illustrative.
The important element is the closed loop:
Five Assessment Mistakes to Avoid
1. Comparing the Score with an Unverified Industry Average
This framework does not have a statistically validated industry benchmark.
Use the score to compare the organization's own baseline and progress.
2. Giving Every Question Equal Strategic Importance
The questionnaire uses equal scoring for simplicity.
Investment decisions should still reflect business impact and risk.
3. Treating Level 5 as the Objective for Everything
Some capabilities do not need enterprise-wide maximum maturity.
A narrow low-risk use case may operate effectively with a lower level of infrastructure and control.
4. Scoring Technology but Ignoring the Operating Model
AI does not become operational because a platform has been installed.
Ownership, evaluation, incident management and improvement processes are equally important.
5. Completing the Assessment Once and Filing It Away
The value of the assessment comes from linking gaps to implementation decisions and then measuring whether those decisions improved outcomes.
My Practical Takeaway
The 30-question assessment is not designed to answer:
It is designed to answer more useful questions:
Which AI use cases are currently constrained?
Is the constraint architecture, master identity, Data Quality, freshness, governance or operating model?
What evidence supports that conclusion?
Which gap creates the largest business or risk impact?
Which capability can be improved now?
What evidence will demonstrate that the improvement actually worked?
The total score can help establish a baseline.
But the real management value comes from the relationship between:
×
Business Impact
×
Risk
×
AI Demand
→
Investment Priority
This relationship should be treated as a decision framework rather than a statistically precise formula.
A useful AI-Ready assessment does not tell executives how mature the company looks. It tells them which capability must improve next for an important AI use case to become more reliable, governable and scalable.
Sources & Further Reading
- NIST — AI Risk Management Framework
- NIST AIRC — AI RMF Playbook
- SAP Help Portal — MDG Data Quality Management
- European Commission — AI Act
The six diagnostic capabilities, 30 assessment questions, 1–5 scoring method, assessment summary, prioritization approach and 90-day improvement cycle in this article are Digital Future & Strategy practitioner frameworks. They are not official Gartner, PwC, Deloitte, IDC, Forrester, NIST, SAP or regulatory maturity models, certification criteria or statistically validated industry benchmarks. Scores should be used as internal baselines supported by evidence. Investment priorities should be determined from actual AI use cases, business impact, risk, AI demand, feasibility and applicable regulatory requirements rather than from the total score alone.
Reviewed: September 2026
AI-Ready Strategy Series
Part 1 — Why AI-Ready Now / Readiness Assessment
AI-Ready #2. Global AI-Ready Trends in 2026: From Model-Centric AI to Trusted Enterprise Context
AI-Ready #3. Assessing Enterprise AI Readiness: 30 Questions Across Six Capabilities
AI-Ready #4. Five Core Capabilities for Enterprise AI Readiness
Previous: Global AI-Ready Trends in 2026: From Model-Centric AI to Trusted Enterprise Context
Comments
Post a Comment