AI strategy7 min read
AI Readiness Checklist for Small and Mid-Sized Firms
An AI readiness checklist for SMEs covering goals, processes, data, tools, security, people, governance and budget, with a simple scoring method and next steps.
Published
An AI readiness checklist tells you whether your organisation has what it needs to use AI usefully and safely, and where the gaps are. For a small or mid-sized firm, readiness comes down to eight areas: clear goals, suitable processes, accessible data, the right tools, security and data protection, people and skills, governance, and a realistic budget. You do not need top marks everywhere to begin. You need the basics for one low-risk pilot, and a plan for the rest.
Use the checklist below with your team. Tick what is in place, score each area and focus your next steps on the lowest scores.
How to use this checklist
- Work through it with two or three people who know different parts of the business.
- Answer for the business as it is today, not as you plan it to be.
- Score each area from 0 to 3 using the scale below.
- Use the total to pick your next steps, not to grade yourselves.
| Score | Meaning |
|---|---|
| 0 | Not in place, not discussed |
| 1 | Discussed or done informally by some people |
| 2 | Mostly in place, with gaps |
| 3 | In place, documented and working |
1. Goals and use cases
- We can name the business problems we want AI to help with, in plain terms.
- We have a shortlist of concrete tasks, not just a general wish to "use AI".
- For at least one task, we know how long it takes today and how often it happens.
- We have agreed what success would look like for a first project.
- Someone senior supports the effort and will make decisions.
If you do not yet have a shortlist, which business tasks to automate with AI explains how to build and score one.
2. Processes
- The processes we want to improve are described, at least as a simple list of steps.
- We know who does each step and which systems they use.
- Exceptions and special cases are known.
- The process works reasonably well today; we are not automating chaos.
- We can measure the process, for example volume, time and errors.
AI accelerates whatever process it is placed in. If a process is unclear or inconsistent, fix that first.
3. Data and knowledge
- We know where the information needed for our use cases lives (email, shared drives, CRM, ERP, documents).
- Key documents such as policies, product data and templates are current and not contradictory.
- Information can be accessed digitally, not only on paper or in people's heads.
- We know which data is personal, confidential or commercially sensitive.
- Someone is responsible for keeping important knowledge sources up to date.
If you plan an assistant that answers questions from your documents, the quality of those documents determines the quality of the answers. See RAG vs. fine-tuning for why.
4. Tools and technology
- We know which AI tools staff already use, including free and personal accounts.
- We have decided which AI tools are approved for work use.
- Approved tools have business terms that fit our data needs (retention, training on inputs, location).
- Our core systems can export or connect data if an integration is needed.
- We know whether our existing software already includes AI features.
5. Security and data protection
- We have rules on which data may be entered into which AI tools.
- Personal data use in AI tools has been checked against data protection requirements, such as the GDPR in the EU.
- Accounts for AI tools use company log-ins with appropriate access control.
- We know how to handle a mistake, such as confidential data entered into an unapproved tool.
- For integrations: API keys are stored securely and spending limits are set.
6. People and skills
- Staff who use AI tools understand what they are good at and where they fail, including hallucinations.
- Staff know the company rules on data and approved tools.
- At least one person can write good prompts and help colleagues.
- Reviewers know what to check in AI output.
- Teams whose work will change are involved early.
In the EU, the AI Act requires providers and deployers of AI systems to take measures for sufficient AI literacy among staff. AI literacy under the EU AI Act explains what that means in practice.
7. Governance and accountability
- Someone is responsible for AI use overall, even if part-time.
- We have a written AI use policy. Our guide to an AI acceptable use policy includes an outline.
- Each AI use case has an owner.
- Customer-facing or consequential AI outputs are reviewed by a person.
- We have checked whether any planned use could fall into a regulated category, such as high-risk uses under the EU AI Act. The EU AI Act risk checker gives a first orientation.
- We keep a simple list of AI tools and use cases in the company.
8. Budget and business case
- We have a budget for a pilot, including staff time.
- We understand how the tools we consider are priced: per user, per usage or both.
- We have estimated running costs at realistic volume.
- We have compared costs with the expected time saved, including review time.
- We have agreed when we will decide whether to continue.
The AI ROI calculator estimates hours saved, net monthly benefit and payback for a task. For usage-based API costs, use the LLM API cost calculator.
Scoring and interpretation
Add your eight area scores for a total between 0 and 24.
| Total | What it suggests | Focus |
|---|---|---|
| 0–8 | Early stage | Set data rules, choose approved tools, pick one simple use case |
| 9–16 | Ready for pilots | Run a structured pilot, document processes, train key users |
| 17–24 | Ready to scale | Standardise prompts and reviews, monitor quality and costs, extend to more processes |
These bands are a rough guide, not a benchmark. More important than the total is the lowest-scoring area. A firm with strong tools but no data rules is not ready, whatever its total.
Minimum for a first pilot
If you want to start soon, make sure at least these points are covered:
- One clear, frequent, low-risk use case.
- A baseline: how long the task takes today.
- Data rules: what may and may not go into the tool.
- An approved tool with acceptable data terms.
- An owner who decides at the end of the pilot.
- A reviewer who checks every output during the pilot.
- A short briefing for everyone involved on how the tool works and where it fails.
The step-by-step plan in AI adoption for small business shows how to run the pilot from there.
Typical gaps and quick fixes
| Gap | Quick fix |
|---|---|
| Staff use personal AI accounts for work | Approve a business tool and explain why; set a date for switching |
| No rules on data | Write a one-page interim rule: no personal or confidential data until a policy is in place |
| Outdated documents | Assign owners to the five most-used documents and review them first |
| No baseline numbers | Time the task on ten cases over a week |
| Nobody responsible | Name one person as AI owner with a few hours per month |
| Unclear costs | Run the calculators with conservative assumptions |
Common mistakes
- Waiting for perfect readiness. Readiness grows through doing; start with something small and safe.
- Treating readiness as an IT topic only. Processes, people and governance matter as much as tools.
- Ignoring shadow AI. Staff are often already using AI tools. Find out which, and bring them under clear rules.
- No owner. Without accountability, pilots drift and decisions do not get made.
- One-off assessment. Repeat the checklist before each larger project and at least yearly.
Next steps
Score each area today, pick the two lowest, and assign one action to each with an owner and date. Then choose your first use case and calculate its business case with the AI ROI calculator.
FAQ
What does AI readiness mean?
AI readiness is how well an organisation is prepared to use AI usefully and safely: clear goals, suitable processes, accessible data, appropriate tools, security and data rules, skilled people and someone accountable.
Do we need to be fully ready before starting with AI?
No. You need the basics for a first low-risk pilot: a clear use case, data rules, an owner and a reviewer. Gaps in other areas can be closed step by step while you learn.
What is the most common readiness gap in small firms?
Often it is unclear rules on data and tools, followed by processes that are not documented well enough to improve. Both can be addressed quickly once they are recognised.
How often should we repeat an AI readiness assessment?
Repeat it before each larger AI project and at least once a year, because tools, regulation and your own use of AI change quickly.
Related articles
AI strategy9 min read
AI Adoption for Small Business: A Step-by-Step Guide
A practical seven-step plan for AI adoption in a small business: pick the right first use case, run a safe pilot, measure results and scale what works.
AI strategy8 min read
How to Choose an LLM for Your Business
How to choose an LLM for your business: define the task, build a test set, compare quality, cost, speed and data terms, then decide with a scorecard.
AI strategy7 min read
RAG vs. Fine-Tuning: Which Does Your Project Need?
RAG vs. fine-tuning explained for business: what each does, when to use which, costs, maintenance and data needs, plus a decision guide and hybrid options.