How the LABUSA AI Readiness Assessment Works
Most AI decisions are made without a clear picture of what the organization can actually support. A tool is selected, a pilot runs, and the constraints that decide whether it can go into production, where the data lives, who may grant access to it, who reviews the output, who pays for it next year, are discovered afterwards.
An AI readiness assessment is a structured way of finding those constraints first. This page explains how ours works: what it examines, how conclusions are reached, and which recognized frameworks inform it.
What Makes an Assessment Worth Commissioning
Any supplier can produce a questionnaire. What makes an assessment worth commissioning is whether its questions are the right ones, whether the answers are checked against evidence, and whether the reasoning behind a recommendation can be examined by the person receiving it.
Three commitments follow from that, and they are the reason this page exists at all.
Every question has a stated reason. Each topic the assessment covers is there because it predicts whether an AI initiative will work, and the rationale is written down rather than assumed. Where a topic is included that no external framework asks about, that is recorded too, along with why we ask it anyway.
The external references are real and checkable. Where this page says a framework informs part of the method, the mapping was built against the published framework, and the parts that do not map are recorded as not mapping. We would rather show an honest gap than a full grid.
The limits are stated as plainly as the findings. An assessment that is presented as more definitive than it is leaves an organization worse off, because decisions get made on it that it cannot carry.
A Practical Assessment Built Around Seven Readiness Dimensions
The assessment examines seven dimensions. They are not equally important to every organization, which is exactly why all seven are examined: the one that blocks you is rarely the one you were worried about.
Strategy and leadership
Whether there is an agreed reason to use AI, someone accountable for it who can also stop it, and money attached that includes the cost of running a service rather than only building one.
AI use cases
Whether specific processes have been named rather than a general intention to adopt AI, and whether each has been assessed for value, for feasibility, and for what a wrong output would affect.
Data readiness
Whether the information a candidate depends on exists in systems rather than in individual knowledge, has an identifiable owner, is classified by sensitivity, and can be retrieved by software rather than by hand.
Technology and infrastructure
Whether the environment can carry the workload, whether the relevant systems can be integrated through a documented interface, whether identity is managed centrally so access can be revoked in one place, and what the service costs at production volume.
Cybersecurity and privacy
Whether access is scoped to the minimum each role needs, which third-party AI services staff are already using, whether traffic to and from those services can be reviewed, and which privacy obligations attach to the records in scope.
Governance and compliance
Whether someone approves or declines AI tools before they are used, whether a written acceptable-use position exists that staff have actually seen, whether AI suppliers face the same review as other suppliers, whether a human reviews output that affects a person, and whether deployed tools are re-examined on a schedule.
Workforce and adoption
Whether the people expected to rely on AI output could recognize a wrong answer in their own subject matter, whether training was aimed at specific roles, whether affected staff were consulted before launch, and whether there is a route to report a problem.
The full public treatment of the model, including how the dimensions interact and what a low score in each one usually means in practice, is in the seven dimensions of AI readiness.
If you have seen an eight-domain version of this
LABUSA's consulting materials have described this model as eight domains, separating delivery and operating model from the rest. The published seven and the consulting eight are the same model described at different grain, and the mapping is one to one for seven of the eight.
The exception is worth stating plainly rather than smoothing over. Delivery and operating model, meaning who runs an AI service after it goes live, how its performance is monitored, and how it is withdrawn, is not scored as a separate dimension. Those questions are asked, inside governance, technology and security, because the topics belong there and because a separate dimension would imply a depth of post-deployment review that a readiness assessment performed before deployment cannot honestly claim. A consulting engagement for an organization that already runs AI in production goes considerably further into this than the self-assessment does.
How the Assessment Is Performed
An assessment runs in five stages. The scope of each varies with the engagement, and an organization with three hundred staff and one candidate use case is not put through the same exercise as a county with eleven departments.
Discover. Establish what is already happening. This almost always finds more AI in use than the organization expected, because staff adopt useful free tools without a procurement event. The discovery is not an enforcement exercise, and asking the question with consequences attached reliably produces a smaller number that is not true.
Assess. Examine each of the seven dimensions through interviews with the people who own the answers, and through the documents and system evidence that show whether the answer holds. Where the two disagree, that disagreement is the finding.
Identify. Surface candidate use cases from the operational problems people describe, rather than from a catalogue of what AI can do. The strongest first candidates are usually unglamorous and internally facing.
Prioritize. Score candidates on value and on feasibility separately, so that a high-value candidate that is not feasible this year lands on the roadmap instead of in the pilot.
Recommend. Produce a sequenced set of recommendations that names the gap, the work, the owner and the order. A recommendation without an owner is an observation.
Depending on scope, the work can include leadership and stakeholder interviews, review of policy and architecture documentation, technology and integration review, a data-management and access review, governance and supplier-review examination, and a risk review of the candidates identified. Not every engagement includes all of it, and a proposal says which.
Evidence-Based Assessment
Maturity conclusions in a consulting engagement are based on more than what people report about themselves. Self-report is where an assessment starts, not where it finishes, because the most common finding is not that an organization was wrong about a dimension but that it was confident about one it had never tested. Data accessibility and access scoping are where that happens most often.
Evidence that may be examined, depending on scope, includes documented policies and their approval history, architecture and integration documentation, technology and system inventories, data-management and retention practices, records of who can grant access to what, governance and approval records, supplier review and contract terms, training records and role definitions, evidence of existing AI use, and procurement practices.
The free self-assessment is a different instrument
The AI Readiness Self-Assessment on this site is a self-reported benchmark that takes about eight minutes and returns a score across the same seven dimensions, with recommendations for the weakest. It is genuinely useful for orienting a conversation and for finding out whether colleagues answer the same question the same way.
It is not a consulting assessment and does not pretend to be. Nothing in it is verified, no document is examined, and no interview takes place. Where the two disagree, the engagement is right and the questionnaire is wrong, because one of them looked.
Frameworks That Inform the LABUSA Approach
Four bodies of work inform this methodology, and a further three inform parts of it. Each is described below with what it actually is, because the differences between a voluntary framework, an auditable practice set and a certifiable management standard matter a great deal to a public body and are routinely blurred.
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1, January 2023) is the reference point most often named by public-sector organizations, and it is the framework this assessment draws on most heavily. It is organized into four functions.
GOVERN covers the culture, policies, accountability structures and third-party practices that surround AI work. It maps closely onto what the assessment examines under strategy and leadership, and under governance and compliance.
MAP establishes the context a risk sits in: the intended purpose of a system, the setting it will operate in, and who could be affected. That is the work the use-case dimension does.
MEASURE covers analysing and tracking risk, including security, resilience and privacy. It informs the cybersecurity and privacy dimension and the parts of the use-case dimension that ask how a good outcome would be recognized.
MANAGE covers acting on measured risk once a system is live: monitoring after deployment, responding to incidents, and being able to withdraw a system. This is the function a pre-deployment readiness assessment can speak to least, and saying so is more useful than implying otherwise.
The AI RMF is voluntary, is not sector-specific, and is not a certification. Following it does not establish compliance with any law or regulation, and no organization can be audited against it in the sense that word usually carries.
NIST Generative AI Profile
Where an organization is evaluating generative AI specifically, the NIST Generative AI Profile (NIST AI 600-1, July 2024) is the companion document. It identifies twelve risks that are unique to generative AI or made worse by it, and the ones that come up most often in public-sector work are these.
Confabulation is NIST's term for a system generating and confidently presenting content that is erroneous or false. It is the risk that most often decides whether a candidate use case needs a human reviewer, and NIST's framing is more useful than the colloquial one because it names the mechanism rather than the vibe.
Information integrity concerns whether output can be traced, verified and relied on, which is the question a public body faces when AI-assisted text becomes part of a record.
Data privacy and information security cover what an organization sends to a service it does not operate.
Human-AI configuration covers how people and systems are arranged around each other, including whether a reviewer is positioned to catch a wrong answer or merely to approve one.
Value chain and component integration concerns third-party models, datasets and libraries that an organization inherits without vetting, which is the supplier-review question.
The remaining risks in the profile, including intellectual property and environmental impacts, are real and are simply less often decisive in the engagements this practice runs.
GAO AI Accountability Framework
The GAO Artificial Intelligence Accountability Framework (GAO-21-519SP, June 2021) is the most directly useful document for government and institutional organizations, because it was written for entities that expect to be audited and it states what an auditor would look for. It sets out 31 key practices across four principles.
Governance covers clear goals, roles and responsibilities, values, workforce, stakeholder involvement, risk management, specifications, compliance and transparency.
Data covers sources, reliability, categorization, variable selection, dependency, bias, and security and privacy. This is the best-matched external treatment of the data-readiness dimension, better than the AI RMF's, and the crosswalk behind this page says so.
Performance covers documentation, metrics and assessment, at component and at system level.
Monitoring covers planning for continuous monitoring, acceptable drift, traceability of monitoring results, ongoing assessment of whether a system is still useful, and the conditions under which it may be scaled.
GAO's framework includes questions for entities, auditors and third-party assessors to consider. It is addressed to federal agencies and other entities; it is not a rule that binds a school district or a city, and nothing in it constitutes an endorsement of any supplier.
ISO/IEC 42001
ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, is the international standard that specifies requirements for an AI management system. Where the NIST and GAO documents describe practices, ISO/IEC 42001 describes the management system that would keep those practices operating: leadership commitment, a stated policy, defined roles, competence, documented processes, and review.
Its relevance to a readiness assessment is as a reference point for what a mature governance function looks like once it is more than a set of good intentions. Organizations that are heading toward certification find the governance dimension of an assessment maps onto the ground the standard covers.
Two things this does not mean. LABUSA does not reproduce the standard's text, and nothing on this site is a substitute for reading it. An AI readiness assessment is not an ISO certification, an ISO audit, a conformity assessment, or certification preparation. ISO/IEC 42001 certification is granted by an accredited third-party certification body against an organization's management system, and it is not something a consulting assessment confers.
Cybersecurity and Privacy Frameworks
Where the subject is cybersecurity maturity rather than AI risk specifically, the NIST Cybersecurity Framework 2.0 (NIST CSWP 29, February 2024) is the more appropriate reference, and it is used that way rather than being cited for AI questions the AI RMF answers better. Its six functions, GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER, are the structure most public bodies already report against, and the access, asset and monitoring questions in the assessment are recognizable in that structure.
The NIST Privacy Framework is used where privacy-risk management is materially in scope. It is at version 1.0; version 1.1 is currently an initial public draft.
CISA's artificial intelligence resources are the practical operational reference for securing AI deployments, and are the material most often already familiar to a public-sector security team.
The specific attack classes an assessment asks about are drawn from NIST's Adversarial Machine Learning taxonomy (NIST AI 100-2 E2025, March 2025) rather than from vendor threat marketing. The practical version, written for organizations rather than for researchers, is in AI cybersecurity risks to assess before deployment.
Other Sources That Inform Parts of the Method
Three further sources inform parts of the method without being central to it.
The OECD AI Principles, adopted in 2019 and updated in 2024, are the most widely adopted intergovernmental statement of what responsible AI means, and they are useful when an organization needs a vocabulary for its own position rather than a control set.
The UK Government AI Playbook (February 2025) is the clearest publicly available statement of how one government expects its own organizations to approach AI, and its ten principles are a useful external check on whether a governance position has gaps. It is guidance for UK public bodies and carries no weight in the United States; it is used here as a well-documented example, not as a requirement.
OMB memorandum M-25-21 (April 2025) sets out how United States federal executive agencies must govern their use of AI, including designating a Chief AI Officer, maintaining an AI use case inventory, and applying minimum risk management practices to high-impact AI. It binds federal agencies. It does not apply to school districts, cities, counties, universities, public authorities or nonprofit organizations. It is read here as a well-developed statement of governance practice, and several of its ideas, particularly the use-case inventory and scheduled reassessment, transfer usefully to organizations that are under no obligation to adopt them.
Where the Frameworks Map
The table below shows, at a summary level, which external guidance informs each area of the assessment. It is a reference map, not a compliance matrix, and the detailed version behind it records the places where nothing external maps at all.
| LABUSA readiness area | Representative external guidance |
|---|---|
| Strategy and leadership | NIST AI RMF GOVERN; GAO Governance |
| AI use cases | NIST AI RMF MAP; GAO Governance and Performance |
| Data readiness | NIST AI RMF MAP and MEASURE; GAO Data |
| Technology and infrastructure | NIST CSF 2.0 asset and access management; GAO Performance |
| Cybersecurity and privacy | NIST AI RMF MEASURE; NIST CSF 2.0; NIST Privacy Framework; CISA guidance |
| Governance and compliance | NIST AI RMF GOVERN; GAO Governance and Monitoring; ISO/IEC 42001 management-system principles |
| Workforce and adoption | NIST AI RMF GOVERN and MAP; GAO Governance |
| Delivery and monitoring | NIST AI RMF MANAGE; GAO Monitoring |
Two entries in that table are worth reading against each other. Governance and cybersecurity are the areas where external guidance is richest and the mapping is strongest. Technology and infrastructure is the area where it is thinnest, because none of these documents is an architecture framework, and an assessment that only asked what the frameworks ask would not find out whether the data can actually be exported.
What the Frameworks Do Not Cover
Some of what the assessment examines is not derived from any external framework, and it would be easy to leave that out of a page like this. Two examples, both of which are among the most predictive questions asked.
Whether data can be retrieved programmatically. No governance framework asks whether an export or an API exists, because governance frameworks assume the system can be built. In practice this is the single most common reason a well-chosen use case cannot proceed this year.
What the service costs at production volume. Pilot economics rarely survive real usage, and no framework in the list above asks the question. The evidence that it matters comes from elsewhere: GAO's 2026 review of federal AI acquisitions found agencies reporting difficulty understanding AI-related costs as a barrier in procurement.
Questions like these are kept because they predict outcomes, not because they improve a mapping. Removing them would make the crosswalk tidier and the assessment worse.
What This Assessment Is and Is Not
The LABUSA AI Readiness Assessment is an independent technology and management advisory service. References to NIST, GAO, ISO/IEC and other recognized frameworks indicate that those sources inform aspects of the methodology. They do not imply endorsement of LABUSA by those organizations.
Unless specifically contracted otherwise, the assessment is not an ISO certification audit, a regulatory audit, a penetration test, a legal determination, or a certification of compliance with any statute, regulation or contract. It does not constitute legal advice. Several findings in a typical assessment point at obligations that require a qualified legal or records opinion, and identifying them is not the same as answering them.
Where the assessment produces a numerical score, that score is a decision-support indicator rather than a measurement. A result of 67 out of 100 does not establish that an organization is 67 percent ready for AI. It means that across seven dimensions scored the same way, the average sat there, and the number that matters is almost always the lowest dimension rather than the average. Scores are reported alongside maturity categories and written findings for that reason.
Sources and Further Reading
Every source below was opened and read on 18 August 2026, and is cited only for statements found in it.
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023.
- NIST, AI RMF: Generative Artificial Intelligence Profile, NIST AI 600-1, July 2024.
- NIST, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2 E2025, March 2025.
- NIST, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29, February 2024.
- NIST, Privacy Framework, version 1.0, January 2020.
- U.S. Government Accountability Office, Artificial Intelligence: An Accountability Framework for Federal Agencies and Other Entities, GAO-21-519SP, June 2021.
- U.S. Government Accountability Office, Artificial Intelligence Acquisitions: Agencies Should Collect and Apply Lessons Learned to Improve Future Procurements, GAO-26-107859, April 2026.
- ISO/IEC, ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, Edition 1, December 2023.
- CISA, Artificial Intelligence.
- OECD, AI Principles, adopted 2019, updated 2024.
- UK Government Digital Service, Artificial Intelligence Playbook for the UK Government, February 2025.
- U.S. Office of Management and Budget, M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, April 2025. Applies to federal executive agencies.
Documented public-sector implementations, and what they suggest for organizations starting out, are collected in public-sector AI case studies.