What a readiness audit actually is
A readiness audit isn’t a strategy engagement. It doesn’t produce a five-tier roadmap. It produces a written diagnosis: where the company stands across six dimensions of AI readiness, what’s blocking progress, and what the next 90 days of work should look like.
The audit takes 2 weeks. The first week is data gathering and interviews. The second week is synthesis, write-up, and the readout meeting. Below is what week one covers, in roughly the order it happens.
Day 1: The existing AI surface
The first task is making the inventory. Every mid-market company has an AI surface — vendors, internal tools, employee-driven experimentation, half-finished pilots. The surface is usually larger and messier than anyone realizes.
What we collect:
- Every approved AI tool the company has paid for in the last 18 months.
- Every internal project labeled “AI” or “ML” that’s in progress or paused.
- Every customer-facing surface that uses AI in any way (including features that quietly added AI without any announcement).
- Every employee tool with AI built in (Slack, Notion, etc. — most have AI features now).
The artifact is a spreadsheet. The interesting outputs aren’t the spreadsheet itself but the gaps: things that should be on the list and aren’t, things on the list that nobody can explain, vendors that nobody remembers approving.
In every audit we’ve run, the inventory has surprised the executive team. They didn’t know one of three things. They didn’t know how many active surfaces exist. They didn’t know how much was spent. They didn’t know one specific high-risk surface existed at all.
Day 2: Data infrastructure
The biggest constraint on AI capability is almost never the model. It’s the data. Day 2 looks at:
- The data warehouse / lake / sources. Where customer data lives. Where operational data lives. What’s joined and what isn’t.
- Data quality: completeness, consistency, freshness.
- The catalog (if it exists). The lineage (if it exists).
- The PII handling: what’s tagged, what’s protected, what flows where.
The diagnostic question: can a new AI initiative get the data it needs within two weeks without a multi-month data engineering effort? For most mid-market companies the honest answer is no. The data work is the gating dependency, and it’s almost always undersized in the AI roadmap.
A frequent finding: the company has been told for two years that “the data is fine.” It is not fine. The data engineering investment is the first work that needs to happen before most AI initiatives become real.
Day 3: Talent and team shape
The talent assessment covers three things:
- Who currently owns AI initiatives. Often nobody, or a director who inherited the responsibility. Often not someone with engineering authority.
- The engineering team’s AI capability. Have any of the engineers shipped production AI? Is anyone comfortable operating it? Who would be the AI on-call if something broke?
- The non-engineering team’s AI literacy. Can product, ops, support reason about what’s possible? Where are the literacy gaps that will block initiatives?
The output is a talent shape recommendation: what role to hire (or whether to use fractional capacity), what literacy work to run, what internal capabilities to develop.
A frequent finding: the company has been talking about hiring “an AI engineer” for a year without writing the JD or filtering candidates against the right rubric. The hire is paused because nobody has the shape clear in their head.
Day 4: Vendors and contracts
The vendor review covers:
- Every AI vendor under contract. Total spend. Renewal dates.
- DPAs, BAAs, and other regulatory paper. Is it real, or is it the vendor’s standard service terms with a cover page?
- Lock-in exposure: how cleanly can the company exit each vendor.
- Whether the twelve contract clauses are in place or not.
This day often produces the most actionable findings in the audit. Two or three contracts almost always have material problems — usually a missing exit term, an unbounded fair-use clause, or a DPA that doesn’t actually meet GDPR/HIPAA flow-down requirements.
A frequent finding: the company is exposed to substantial lock-in on at least one vendor and didn’t know it. Renegotiation at renewal becomes the priority work coming out of the audit.
Day 5: Governance and controls
The controls assessment covers what’s actually in place runtime, not what’s in policy. Specifically:
- The five governance documents we look for (acceptable use, system inventory, data boundary, incident response, vendor register).
- The three runtime controls (kill switch, cost ceilings, audit logs).
- Whether the controls have been tested in the last 90 days.
This day is usually the shortest because most companies don’t have most of these. The finding is “build the minimum-viable governance stack” and the work is scoped against the governance post.
A frequent finding: the company has an “AI policy” that’s 40 pages, was written by external counsel, has not been read by any engineer, and corresponds to none of the actual controls in production. The doc is shelfware; the gap is real.
Day 6: Strategy posture
This is a longer day. It covers:
- The executive team’s current mental model of AI strategy. What they believe about competitive positioning, ROI timelines, talent strategy.
- The current strategic AI initiatives (if any) and their state.
- The board’s view of AI risk and opportunity.
- The competitive landscape: what competitors are doing, what the company is doing in response.
The diagnostic question: does the executive team have a shared model of where AI sits in the strategy, or are they each carrying a different map? Often the maps differ substantially, and the misalignment is the structural reason initiatives don’t ship.
A frequent finding: the CEO thinks AI is about cost reduction. The COO thinks it’s about scaling without hiring. The CTO thinks it’s about competitive features. The CFO thinks it’s an expense problem. They’re all partly right and not aligned. Aligning them is a major component of the audit’s value.
Day 7: Synthesis prep
The final day of week one is preparing the synthesis. We organize the findings into:
- A maturity scorecard across six dimensions (inventory, data, talent, vendor, governance, strategy).
- A heat map of the highest-risk gaps.
- The top 5 actions that would move the needle in the next 90 days.
- The top 3 risks that need immediate attention.
This becomes the spine of the written deliverable, which lands at the end of week two.
What the readout usually surprises people with
After dozens of audits, the patterns of surprise are remarkably consistent. The executive team almost always learns:
- They have more AI exposure than they realized (more vendors, more pilots, more surfaces).
- One specific high-risk surface they weren’t tracking.
- The data work is the gating dependency, not the model work.
- The talent question is more about staff-level engineering than entry-level AI engineering.
- The governance gap is real and bigger than they thought.
- The vendor contracts are worse than their procurement function realizes.
- Their five-tier roadmap from a previous consultancy isn’t executable and needs to be rewritten.
These findings are not surprising to us. They are nearly universal at mid-market scale. The audit’s job is to make them visible to the team that owns them, with enough specificity that the next 90 days of work is clear.
What the audit doesn’t do
Worth being explicit about scope:
- We do not write the roadmap. We give you enough to start writing it.
- We do not build the system. We tell you what to build.
- We do not run the procurement renegotiation. We tell you which contracts need attention.
- We do not become the AI leader. We tell you what kind of leader you need.
The audit is the diagnostic. The implementation work is separate and is what an engagement after the audit might look like — either continued with us or done internally.
The take
A readiness audit produces a clear written diagnosis in two weeks. Week one is data gathering across six dimensions. Week two is synthesis. The findings are usually consistent — most mid-market companies fail in similar ways on similar dimensions — and the corrective work is bounded. The diagnostic itself is small. The cost of operating without it is large, because every AI decision is being made with partial information.
The AI Readiness Audit is a two-week engagement that produces a written diagnostic. If you want a second-opinion read on your current posture, schedule a call.