AI Readiness Assessment: An Evidence Scorecard
Assess AI readiness with evidence for one workflow: ownership, data access, decision limits, evaluation, permissions, monitoring and recovery.
What is an AI readiness assessment?
An AI readiness assessment checks whether one named workflow has enough evidence to be bought, built, or operated responsibly. Start with the workflow and its accountable owner. Then inspect its input and data access, decision boundary, acceptance artifact, evaluation set, permissions, escalation path, monitoring, and stop or recovery plan. Record each item as present, partial, or missing. Do not turn the result into a universal maturity percentage.
This operator definition is Jungle Roots' editorial method. It complements, but does not replace, formal risk work. NIST says its AI Risk Management Framework is voluntary and is intended to help organizations incorporate trustworthiness considerations into AI design, development, use, and evaluation (NIST AI RMF). Microsoft and HBS publish their own broader readiness dimensions; neither establishes a universal score (Microsoft; HBS Online).
What is the editorial verdict on AI readiness scores?
My editorial verdict is that evidence beats a vanity readiness percentage. This is my opinion, not the result of a portfolio experiment, and no portfolio experiment is claimed. A percentage can compress unlike gaps into one neat figure. An operator still needs to know whether the workflow has permission to read the source, who may approve an action, and what happens when the output fails.
Microsoft's wizard illustrates why a score must be read in context. Microsoft says its tool is based on its research and customer work, identifies five drivers of AI value, and asks ten questions before suggesting an area of focus (Microsoft). That is Microsoft's model. HBS uses another frame: strategic intent, data and technology foundations, people and culture, and governance and risk management (HBS Online).
Editorial call: Keep any vendor score as that vendor's summary. Keep the evidence packet as the operating record your team can inspect.
How do you measure AI readiness?
Measure readiness by checking inspectable evidence against one workflow, not by asking whether the organization feels ready. Name the workflow in plain language, such as “draft a proposal from approved source documents.” Name the person accountable for its result. Then ask to see the artifacts that define inputs, allowed actions, expected outputs, tests, access, and failure handling.
Use present only when a reviewer can open the artifact or observe the control. Use partial when the evidence exists but leaves a material question unanswered. Use missing when the team relies on memory or intent. These labels are Jungle Roots' editorial scoring method, not NIST ratings.
NIST's Playbook offers suggested actions across Govern, Map, Measure, and Manage and says the suggestions are not a checklist (NIST AI RMF Playbook). The packet below borrows that inspectable, action-oriented posture. It does not claim NIST endorsement or a product guarantee.
Measurement rule: A spoken assurance is context. A named, reviewable artifact is evidence.
What are the three pillars of AI readiness?
There is no universal set of three AI readiness pillars in the authorized sources. If a team needs a compact working model, Jungle Roots proposes workflow value, operating evidence, and responsible control. Those are editorial buckets, not a standard.
Workflow value asks which business decision or output the workflow serves and who owns it. Operating evidence covers data access, inputs, the decision boundary, the acceptance artifact, and the evaluation set. Responsible control covers permissions, escalation, monitoring, and stop or recovery.
Other publishers group the work differently. Microsoft's wizard names business strategy, technology and data strategy, AI strategy and experience, organization and culture, and AI governance & security as its drivers (Microsoft). HBS asks leaders to audit strategic intent, data and technology foundations, people and culture, and governance and risk management (HBS Online).
Pillar warning: Attribute a pillar count to its source. Do not present an editorial grouping as a law, benchmark, or consensus.
What evidence belongs in the readiness scorecard?
The scorecard should show the artifact, the question it resolves, and the status a reviewer can verify. The rows below are Jungle Roots' editorial evidence scorecard. They are not a NIST, Microsoft, HBS, or OECD scoring system.
| Evidence item | What the reviewer should be able to answer | Editorial status |
|---|---|---|
| Named workflow | What exact job begins and ends here? | Present / partial / missing |
| Accountable owner | Who accepts the result and owns the risk decision? | Present / partial / missing |
| Input and data access | Which sources are allowed, available, and fit for this workflow? | Present / partial / missing |
| Decision boundary | Which actions may the system take, and which stay human? | Present / partial / missing |
| Acceptance artifact | What file, record, or state proves the work is complete? | Present / partial / missing |
| Evaluation set | Which representative inputs and expected results test the workflow? | Present / partial / missing |
| Permissions | Which identities may read, write, approve, or send? | Present / partial / missing |
| Escalation | Who receives an exception, and with what context? | Present / partial / missing |
| Monitoring | Which observable record shows runs, errors, and changes? | Present / partial / missing |
| Stop and recovery | What stops action, and how is a safe state restored? | Present / partial / missing |
The decision boundary should agree with permissions. The acceptance artifact should agree with the evaluation set. Escalation should agree with the stop and recovery record. If these pairs conflict, mark the item partial and record the conflict instead of averaging it away.
Get the operations audit for an operator review of the evidence packet before a tool purchase or agent build.
What are common AI assessment questions?
Good assessment questions ask for a decision or artifact, not a hopeful yes or no. Use the scorecard while asking:
- What named workflow are we assessing, and who is accountable for its completed result?
- Which approved inputs and data sources may it access?
- Which decisions may it make, draft, recommend, or never take?
- What artifact proves acceptance, and who signs it off?
- Which evaluation cases represent normal work, edge cases, and unacceptable output?
- Which identity and permission does each action use?
- Where does an exception go, and what context travels with it?
- What record lets the owner inspect runs, errors, and system changes?
- Which condition stops the workflow, and how does the operator recover safely?
These are Jungle Roots' proposed questions. NIST's Playbook can be used as a separate source of voluntary risk-management actions across its four functions (NIST AI RMF Playbook). A business process automation brief can hold the workflow boundary and acceptance evidence.
How do you run the assessment?
Run the assessment as a review of one workflow and leave behind a dated evidence packet. A practical sequence is:
- Freeze the workflow name, start event, expected output, and accountable owner.
- Collect the current artifacts for data access, allowed decisions, acceptance, evaluation, permissions, escalation, monitoring, and recovery.
- Mark every scorecard row present, partial, or missing and add the evidence location.
- Test the evaluation set within the documented decision and permission boundaries.
- Record failures, assign each unresolved gap to an owner, and decide whether the workflow may proceed, must stay limited, or must stop.
The final decision is local to the organization and use case. The scorecard does not certify compliance, safety, or business value. NIST describes its RMF as voluntary; its page says the framework is meant to improve how trustworthiness considerations are incorporated, not to guarantee an outcome (NIST AI RMF).
Use the AI governance framework to place this workflow record inside wider roles and policies.
Which responsible-AI principles belong beside the scorecard?
Readiness evidence does not replace responsible-AI principles or legal review. The OECD's values-based AI principles include human rights and democratic values, fairness and privacy, transparency and explainability, robustness, security and safety, and accountability (OECD AI Principles). Use those principles to challenge the workflow's purpose and controls. Do not treat a completed scorecard as proof that every principle has been met.
NIST and OECD serve different roles here. NIST supplies a voluntary risk-management framework and Playbook actions (NIST AI RMF; NIST AI RMF Playbook). OECD publishes principles for trustworthy AI (OECD AI Principles). Neither source guarantees that a selected product, agent, or workflow is safe, effective, or compliant.
Boundary: Use the evidence packet to expose missing operating facts. Use qualified legal, security, privacy, and domain review where the workflow requires it.
What should happen after the assessment?
Resolve the missing evidence that can change the go, limit, or stop decision before comparing more tools. If ownership is missing, name the accountable person. If the decision boundary is vague, write allowed and prohibited actions. If the evaluation set has no expected results, define them with the people who can judge the work. If recovery is unknown, keep the workflow from taking the affected action.
This is an editorial recommendation, not a claim that one sequence produces a particular return. Preserve the dated packet, the decision, the unresolved gaps, and the owners. Reopen it when a material input, permission, action, model, provider, or acceptance condition changes. That is a change trigger, not an unsupported calendar rule.
Get the operations audit to turn one proposed workflow into an inspectable operating brief.
Written by Tileo, an operator who measures how AI assistants cite brands, on his own portfolio first.
What are the frequently asked questions?
How do you measure AI readiness?
Measure one named workflow by inspectable evidence. Check its accountable owner, input and data access, decision boundary, acceptance artifact, evaluation set, permissions, escalation path, monitoring, and stop or recovery plan. Mark each item present, partial, or missing. This is Jungle Roots' editorial method, not a universal maturity score.
What are the three pillars of AI readiness?
There is no universal three-pillar model in the sources used here. Jungle Roots proposes workflow value, operating evidence, and responsible control as editorial buckets. Microsoft and HBS publish different readiness dimensions, so any pillar count should be attributed to its source.
What are some common AI assessment questions?
Ask which workflow is in scope, who owns its result, which data and actions are allowed, what proves acceptance, which cases evaluate it, who may approve or send, where exceptions go, what monitoring remains, and what stops and restores the workflow. These are proposed operator questions, not a formal standard.
Does this scorecard certify that an AI workflow is safe or compliant?
No. The scorecard exposes operating evidence and gaps. It does not certify safety, compliance, performance, or business value. Legal, security, privacy, and domain review may still be required for the specific workflow.
Related reading
