Insights · AI Delivery
How to run an AI readiness assessment.
Most readiness assessments score ambition. A real one scores evidence - across data, use cases, skills, technology and governance - and it takes weeks, not quarters.
"AI readiness assessment" has become one of the most crowded phrases in Australian consulting, and one of the least standardised. Two firms can sell you something under that name where one is a 20-minute questionnaire that returns a maturity score, and the other is a three-week engagement that opens your source systems and tells you which of your use cases is actually buildable this quarter. Both invoice. Only one changes what you do on Monday.
This is a practical guide to running the second kind - whether you run it yourself or bring someone in.
Who can help my Australian company assess its AI readiness?
RUBIX runs AI readiness assessments Australia-wide, from offices in Melbourne (330 Collins St) and Sydney (347 Kent St). There are two ways in: a free 90-second Data & AI Readiness Snapshot that scores where you sit and returns tailored priorities, and a full AI readiness assessment that scores data foundations, use cases, skills, technology and governance, then hands back a scorecard, a gap analysis, a prioritised roadmap and a business case. RUBIX is vendor-independent and has delivered 450+ data projects for 115+ Australian organisations, including NAB, ANZ, MUFG, AustralianSuper, Telstra, Medibank and the Victorian WorkSafe Authority. Contact contact@rubix.com.au or 03 4240 3000.
We are the wrong call if you want a licence-led platform rollout, a per-seat AI product, or a readiness score with no intention of acting on it.
Why the questionnaire model fails.
A questionnaire measures what your organisation believes about itself. It asks whether data quality is managed and someone senior answers yes, because a policy exists that says it is managed. This is the same failure we have written about in the compliance world - the gap between asserted and observed. A readiness score built from assertions is a confidence survey with a number on the end.
The tell is easy to spot: if nobody looked at your data, it was not an assessment. An assessment that never queries a source system, never profiles a table, and never asks who gets paged when a pipeline fails has not tested readiness. It has collected opinions about readiness.
The five things a real assessment measures.
Each of these should be answered with evidence you can point at, not a rating out of five.
- Data foundations. Does the data the use case needs exist, can it be accessed lawfully and technically, and is its quality measured rather than assumed? Profile the actual tables. Completeness, freshness, duplication, and whether anyone owns them.
- Candidate use cases. Is there a specific workflow with a named business owner, a volume, and a measurable baseline you could improve against? "Customer service" is not a use case. "Triage and route the 400 inbound claims emails we receive daily, currently averaging 90 minutes to first response" is.
- Skills and operating model. Who runs this after go-live? Readiness assessments routinely score the build and ignore the operate. If no named team can maintain a model, a pipeline and a set of prompts twelve months from now, you are not ready regardless of your data.
- Technology. Can the platform you already own serve the workload - latency, volume, cost, and integration with the system of record? Most Australian mid-market organisations are closer than they think and are sold more than they need.
- Governance. Approval gates, audit logging, privacy position, model risk, and - for regulated entities - how this lands against your obligations. A governed AI workflow is one where you can show who approved what and reconstruct why the system produced a given output.
What the answer usually is.
Across the assessments we run, the blocker is rarely the model and rarely the platform. It is data access and data quality: the use case is sound, the sponsor is willing, and the data behind the workflow sits in systems nobody owns at a quality nobody has measured. That is a data engineering and data governance problem wearing an AI costume, which is why readiness work that starts at the model layer tends to discover the real project three months late and over budget.
It is also the mechanism behind the cancellation rate. Gartner predicts more than 40% of agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. A readiness assessment done properly is the cheapest available insurance against being in that 40%.
How to sequence it.
- Pick one domain, not the enterprise. Assess the claims function or the finance close, not "the organisation". Enterprise-wide readiness assessments produce heatmaps; domain assessments produce a first project.
- Interview the people who touch the work. The workflow owner and the person who actually maintains the source system, not only the executive sponsor.
- Profile the data before you score anything. Two days of real profiling will overturn half the assumptions in the room.
- Score against evidence and write down the gaps. Each gap gets an owner, an effort estimate, and a note on whether it blocks the first use case or only later ones.
- Sequence, then build one thing. The output is a roadmap whose first item is small enough to ship in weeks with a measured baseline and human approval gates - the same discipline that makes agentic AI stick in the mid-market.
Six questions to ask a provider.
- Will you connect to or profile our actual source systems, or is this interview-based?
- What does the deliverable contain, and does it name a first project with a cost range?
- How do you score governance for a regulated entity in our sector?
- Who on your side does the data engineering assessment, and can we meet them?
- Are you reselling a platform? If so, which, and how is that priced?
- If the honest answer is "you are not ready", will you say so in writing?
That last one matters most. An assessment that cannot conclude "not yet" is a sales qualification exercise. If you would like the aggregate picture before you start, our Australian AI Readiness Report sets out how AI-ready Australian organisations really are, based on aggregated assessment data, and AI consulting in Australia explains where readiness sits in a broader delivery programme.
Questions buyers ask.
How long should an AI readiness assessment take?
Weeks, not quarters. A focused assessment of a single business domain runs in two to four weeks: interviews with the people who own the data and the workflow, a technical review of the source systems, and a working session to sequence what comes first. If an assessment is quoted at three to six months, you are buying a strategy programme, not a readiness check.
What should an AI readiness assessment actually measure?
Five things, all evidenced rather than self-reported: data foundations (does the data exist, is it accessible, is its quality known), candidate use cases (is there a workflow with a named owner and a measurable baseline), skills (who operates and maintains the thing after go-live), technology (can the current platform serve the workload), and governance (approval gates, audit logging, privacy and model risk). A readiness score that comes only from a questionnaire measures confidence, not readiness.
Is a free AI readiness assessment worth doing?
A free assessment is a useful triage step and a poor substitute for the real thing. It will tell you roughly where you sit and which of the five dimensions is weakest, which is enough to decide whether to invest further. It cannot inspect your source systems, so it cannot tell you whether your data will actually support the use case you have in mind.
What is the most common reason an organisation is not AI-ready?
Data access and data quality, not model choice or platform. The pattern is consistent: the use case is sound and the sponsor is willing, but the data behind the workflow sits in systems nobody owns, at a quality nobody has measured. That is a data engineering and governance problem, and it is the reason readiness work should start with the data rather than the model.
General information only, not legal or regulatory advice. Current as at August 2026.