AI Readiness Assessment & Consulting
Before investing in AI tools, find out whether your organization, data, infrastructure, cybersecurity, governance and workforce are ready to support them.
LABUSA is a vendor-neutral technology advisor. We do not sell you an AI platform and then work backwards to a justification. We establish where AI can create measurable value in your organization, whether your environment can carry it, what it would put at risk, and what has to be true before you spend anything. Sometimes the most useful finding is that a proposed initiative should wait.
Is Your Organization Ready for AI?
Most organizations do not fail at AI because they chose the wrong product. They fail because the groundwork the product depends on was never in place, and nobody checked before the money was committed.
These are the conditions we find most often, and every one of them is ordinary rather than embarrassing:
- Staff are already using public AI tools, on their own initiative, because the tools are useful and no approved route exists.
- There is no AI governance position, so nobody can approve a tool and nobody can decline one.
- The use cases are general rather than specific. "We should be doing something with AI" is a sentiment, not a plan.
- Sensitive records are being pasted into AI platforms whose terms nobody has read.
- Legacy applications hold the relevant data and cannot be integrated, or can only be integrated at a cost nobody has estimated.
- Data quality is unknown. There are several versions of the truth and no agreement on which one is authoritative.
- Access controls are broad, and an AI service inherits the permissions of whoever runs it.
- Leadership is under pressure to act without agreement on what the organization is trying to achieve.
- Staff have had no training, so nobody is equipped to judge whether the output is right.
- Investment is being planned without a measurable objective, which makes the result impossible to evaluate.
None of these is a reason not to use AI. They are the list of things worth settling first, and settling them is far cheaper before a platform is chosen than after.
What Is an AI Readiness Assessment?
An AI readiness assessment is a structured review of your organization against the conditions AI actually depends on. It is not a product demonstration, not a procurement exercise, and not a security audit. It is the piece of work that tells leadership what is worth doing, in what order, and what has to change first.
We look at your objectives and who owns them, the processes that are candidates for AI, the data those processes depend on, the infrastructure and applications the work would run on, your cybersecurity and privacy position, your governance, and whether your people are equipped to use and check the output. We assess what is there, not what is planned.
You finish with a written report and a prioritized roadmap. A fuller explanation of the process, including what you will be asked to provide and how long it takes, is in our guide to what an AI readiness assessment is.
If you would like an initial benchmark before speaking to anyone, the AI Readiness Self-Assessment takes about eight minutes and scores you across the same seven dimensions.
Strategy & Leadership
Whether there is an agreed reason to use AI, a named executive accountable for it, and a budget attached. Without these the rest becomes a collection of tools nobody can evaluate. Read more.
AI Use Cases
Specific candidate processes, tested for business value, mission impact, feasibility, risk and expected return, rather than a general intention to adopt AI. Read more.
Data Readiness
Quality, accessibility, ownership, classification, governance and integration, across both structured records and the knowledge repositories staff actually rely on. Read more.
Technology & Infrastructure
Cloud and on-premises environments, network capacity, APIs, application integration, identity systems, CMS, and the ERP, SIS or CRM platforms holding the records in scope. Read more.
Cybersecurity & Privacy
Identity and access controls, sensitive data exposure, data loss risk, AI-specific attack surface, privacy obligations, logging, monitoring, third-party AI services and shadow AI. Read more.
Governance & Compliance
AI policy, acceptable use, oversight, procurement procedures, vendor risk, records retention, data governance, compliance obligations and where a human stays in the loop. Read more.
Workforce & Adoption
AI literacy, training, adoption, skills gaps, change management, role impact and user support. This is the dimension most often left out and it decides whether a deployment survives. Read more.
What LABUSA Evaluates
An assessment is evidence gathering followed by analysis. The proportions vary with the size of the organization, but the work is consistent.
What we do
- Stakeholder interviews. Leadership, the service owners whose processes are candidates, and the people who would use the output. An assessment that never leaves IT produces a technically sound answer to a question the organization did not ask.
- Technology and infrastructure review. What you run, where it runs, what it can carry, and what it would cost to run an AI service at realistic volumes rather than pilot volumes.
- Application and integration review. Whether the systems holding the relevant records can actually be read, through a documented interface or a supported export.
- Cybersecurity and privacy review. Identity and access, sensitive data exposure, logging, third-party AI services already in use, and the obligations that apply to the records in scope.
- Data maturity review. Quality, ownership, classification, and whether there is a single authoritative version of anything that matters.
- Governance review. Who approves a tool, what the acceptable-use position is, how suppliers are reviewed, and where a human has to stay in the loop.
- Current AI usage. What is already happening, which is almost always more than the organization expects.
- Use-case discovery. Candidates identified with the people who do the work, then tested for value, feasibility and risk rather than enthusiasm.
- Risk analysis. What could go wrong in each candidate, who it would affect, and what would have to be true to proceed safely.
- Organizational readiness. Skills, training, change impact and support.
The output is a set of recommended priorities: what to do first, what to defer, and what to stop.
AI Readiness Score
An overall score and a score for each of the seven dimensions, so progress can be measured again later against the same baseline.
Executive summary
A short written position for leadership and, where needed, for a board or governing body.
AI maturity assessment
Where the organization sits today, described in terms a non-technical decision maker can act on.
Readiness gap analysis
What is missing, what it would take to close each gap, and which gaps block which use cases.
Cybersecurity and privacy findings
Observations relevant to AI adoption. This is not a penetration test or a formal security audit, and it is not presented as one.
Data readiness findings
Where the information lives, who owns it, whether it can be read programmatically, and what would have to change.
Governance recommendations
Ownership, acceptable use, supplier review, human oversight and the records you would need to evidence a decision.
Prioritized AI use cases
Candidates ranked on value and feasibility, with the reasoning shown rather than asserted.
Quick-win opportunities
Where they genuinely exist. Where they do not, we say so.
Risk register
The risks each recommended initiative carries, and what would reduce them.
Recommended technology investments
What the roadmap depends on, separated into what is required and what is optional.
A six to twelve month AI roadmap
A sequence with dependencies, owners and decision gates. How this is built is set out in building an AI technology roadmap.
K-12 school districts
Student information systems, staff use of generative AI, teacher and administrative workload, acceptable-use policy, and the privacy obligations that attach to student records. See AI readiness for K-12 school districts.
Higher education
Distributed decision making across colleges and departments, research and administrative data, student services, and a workforce with widely varying AI literacy.
Cities and counties
Constituent services, records and document processing, internal knowledge search, public website search and administrative workflow. See AI readiness for cities and counties.
Public agencies
Legacy systems, records retention obligations, public disclosure, and procurement processes that need a defensible basis for a decision.
Emergency services
Conservative by necessity. The useful applications are administrative and analytical, with human oversight, reliability and data governance treated as constraints rather than features.
Nonprofit organizations
Small teams, constrained budgets, donor and beneficiary data, and a strong case for administrative automation where governance can be kept proportionate.
Healthcare and community organizations
Sensitive records, third-party obligations, and a need to separate administrative applications from anything that touches clinical decision making.
Churches and faith-based organizations
Congregational records, communications, volunteer coordination and limited technical staff, where the governance question is usually the first one to answer.
1. AI Readiness Assessment
Establish the baseline: strategy, use cases, data, technology, security, governance and workforce.
2. Identify gaps
What is missing, what it blocks, and what closing it would take.
3. Prioritize AI use cases
Rank candidates on value and feasibility, and agree what to defer.
4. Develop AI strategy
A short written position on where AI will and will not be used, what risk is acceptable, and what success looks like. See how to build an AI strategy.
5. Build the AI roadmap
Sequence the work around dependencies, with budget per phase, named owners and gates that can stop the next phase.
6. Pilot or proof of concept
Scoped so that it can be stopped, and measured against what was agreed in advance. See what happens after an assessment.
7. Production implementation
Integration, security, identity, monitoring and support, built to run rather than to demonstrate.
8. Managed infrastructure, security and support
The ongoing work that keeps it running. LABUSA offers managed IT services and cybersecurity services where an organization wants that handled.
Procurement Through TIPS
TIPS members may be able to streamline procurement of eligible LABUSA technology and consulting services through The Interlocal Purchasing System. Organizations should review the applicable LABUSA TIPS contract and their own purchasing requirements to determine eligibility and scope.
LABUSA holds awarded TIPS contracts covering IT consulting services, data center services and technology solutions. Which of them applies to a particular engagement depends on the work, and that is a determination for you and TIPS rather than something we can decide on your behalf. Our contracts page lists all three, and we are happy to talk through which is the right route before you raise anything.
For a fuller explanation aimed at public buyers, see AI readiness consulting for TIPS members, or start with how TIPS cooperative purchasing works.
Start With Evidence
Schedule an AI Readiness Assessment
Tell us what you are considering and we will tell you what it depends on. An initial conversation costs nothing and usually shortens the work that follows, because it establishes which questions actually matter for your organization.
Schedule an AI Readiness Assessment