01Readiness
What an AI readiness assessment inspects
AI readiness is a set of preconditions in data, systems, people and governance, and an assessment is worth paying for only if it may report which are missing.

02The essay
AI readiness is usually asked about in the hope of a particular answer: leadership wants to hear that the organisation is close, so that the pilot can start on schedule. Readiness is duller than that. It is a set of preconditions that can be inspected, most of which have nothing to do with which model to choose, and an assessment is worth commissioning only if it is allowed to report that some of them are absent.
The inspection starts with data, and with its meaning before its volume. For each dataset a proposed use case depends on, an assessor wants to know whether a data dictionary exists and whether it matches the tables; whether the same customer, patient or supplier appears once or three times across systems; whether the fields that matter are filled consistently or left blank after the second screen of a form; whether the history goes back far enough to learn from; and whether the records are structured at all or are scanned documents, Arabic and English mixed, that will need extraction before anything else. It also asks who owns each dataset, which is a governance question in a data question’s clothes. Messy data does not disqualify an organisation. It changes what the first project should be, and it is often the first project.
Systems come next, because a model that cannot reach the data or be reached by its users is a demonstration. The questions are practical: whether there is an interface to the system of record or only a nightly export; whether the organisation has an identity provider a new application can authenticate against; whether there is an environment a pilot can run in, with the security team’s approval path for a new system already known; whether compute can run inside the Kingdom at the level the data’s classification requires, or whether that has to be procured first; and whether the existing systems produce logs, because without logs there is no audit trail, and without an audit trail there is no defensible AI system. For government entities the NCA’s Essential Cybersecurity Controls already set expectations on identity, logging and hosting, and readiness means those controls are in force in the environment where the pilot will live.
People are assessed for capacity and for ownership. Capacity means an engineer or analyst on the client side who works alongside the build and takes the system over at handover, with the hours genuinely freed in their week. Ownership means a named business owner for each use case, who decides what a good output looks like and is accountable for what the system produces once it is live. Sponsorship sits above both: an executive who will still be answering questions about the pilot in its fourth month, when the launch attention has moved on and the unglamorous fixes are what remains. A technically sound pilot without that person stalls.
Governance is the area organisations most often skip, because it is less interesting than model selection and because it is assumed to belong to another department. The inspection is concrete: whether an AI policy exists and names who approves a system before it goes live; whether there is a model inventory, or nobody could list the AI systems already running; whether a data protection officer has been appointed where PDPL requires one, and whether an impact assessment has been done for any use case that touches personal data; and whether a human override exists, with an escalation path that ends at a named person. SDAIA’s AI ethics principles set out what is expected on accountability, transparency and human oversight, and a readiness assessment checks whether the organisation’s structure could meet them for this specific system. Immature governance does not disqualify anyone either, but the gap has to be named before launch rather than discovered after it.
Sometimes the finding is that the organisation should wait. The signs are recognisable: a dispute over who owns the underlying data that nobody has resolved; a use case nobody will be accountable for; a workflow that a well-built spreadsheet or a scheduled report would serve better than a model; a data pipeline that has to be repaired before any model could learn from it. Naming these before the engagement starts is the job. A use-case portfolio worth the name scores each candidate for value, feasibility and risk, and records the ones we advise against alongside the ones we recommend.
What an assessment should produce is a staged plan the organisation can stop at any phase, with each phase priced for what it costs and the preconditions for the next one stated. If the finding is that six months of data work come before any model, that is the plan, and it is worth more than a pilot that launches on schedule and is quietly retired a year later.
- 01
When to configure an ERP and when to build around it
The choice between configuring a product, extending it and building around it is settled by which decision an organisation can still live with in five years.
Read the essay - 02
What data residency requires of an AI system
Data residency is a property of everywhere an AI system puts data, from the retrieval index to logs, backups and weights; the server address settles only one.
Read the essay - 03
When you do not need an agent
An agent holds state, chooses its next action and acts in your systems with permissions; most automation requests are a fixed workflow a script serves better.
Read the essay
04Start here
If an essay left a question open, ask it.
Write to us with the question. If it can be answered in a reply, we answer it in the first one; if it needs a meeting, we will propose one.
Start a conversation