AI readiness checklist for business owners
A business is ready for a specific AI workflow when the work is defined, the baseline is measurable, required systems and data are accessible, exceptions and escalation are mapped, and someone owns monitoring and rollback.
1. Is one workflow clearly defined?
Yes means the trigger, inputs, outputs, owner, systems, supported cases, prohibited actions, and completion condition are written down. 'Improve customer service' is not a workflow; 'answer after-hours estimate calls, collect required fields, and create a callback task' is.
Not ready yet: different staff describe the process differently, the desired output is unclear, or the proposed agent is expected to solve several unrelated workflows at once.
2. Is there a measurable baseline?
Record current volume, queue time, labor touch time, completion, abandonment, rework, error, transfer, and outcome for a representative period. Document data sources, exclusions, and known quality problems.
Not ready yet: expected savings or revenue are based only on a vendor benchmark, the current process is not measured, or the team cannot agree what success means.
3. Are exceptions mapped?
List common and high-impact exceptions, required judgment, identity failures, unavailable systems, ambiguous requests, emergencies, disputes, sensitive cases, and requests for a person. Define what the agent should do in each case.
Not ready yet: the plan assumes every case follows the happy path or the agent is expected to improvise policy.
4. Are systems and data accessible?
Identify each system of record, required fields, APIs or exports, test environment, identifiers, permissions, and ownership. Verify data quality and decide whether the workflow may read, create, update, or only recommend.
Not ready yet: the source data is contradictory, credentials are shared, no test path exists, or the business cannot limit access to the records and actions the workflow needs.
5. Are sensitivity and permissions documented?
Classify personal, financial, health, legal, employee, and confidential information. Document authentication, consent, disclosure, recording, retention, deletion, vendor, access-review, and incident requirements for the configured workflow.
Not ready yet: the implementation relies on a blanket compliance claim or nobody owns legal, privacy, security, or contract review.
6. Is human escalation operational?
Define who receives each escalation, during which hours, with what context, and what the caller sees when the person is unavailable. Test transfers, callbacks, notifications, and acknowledgement rather than assuming they work.
Not ready yet: escalation means leaving an unowned message, the agent can block access to a person, or staff have not agreed to the handoff process.
7. Are acceptance and stop criteria written?
Set thresholds for task completion, accuracy, booking or routing correctness, correction, transfer, abandonment, complaint, security events, system reliability, cost, and staff-review effort. Include edge-case tests and prohibited outcomes.
Not ready yet: the only goal is to launch, success is subjective, or no threshold would cause the pilot to pause.
8. Are monitoring and rollback owned?
Name the person who reviews performance, approves prompt and workflow changes, responds to incidents, and can pause or roll back the system. Preserve version, change, and test evidence so behavior can be traced to a release.
Not ready yet: monitoring is only a dashboard, production changes have no review, or the team cannot restore the prior working configuration.
9. Is value estimated from your own inputs?
Use actual volume, labor cost, delay, error, conversion, and job-value inputs. Separate recovered capacity, avoided future cost, at-risk revenue, and realized cash. State assumptions and run conservative as well as expected scenarios.
Not ready yet: the business case treats all saved time as cash, all unanswered calls as lost sales, or a planning target as a guaranteed result.
10. Final yes-or-no gate
Proceed to a bounded pilot only if the workflow, baseline, systems, permissions, exceptions, human escalation, acceptance criteria, monitoring owner, rollback, and value hypothesis are all documented well enough to test.
If several answers are no, fix those gaps first. This checklist adapts the NIST AI Risk Management Framework's govern, map, measure, and manage structure to a bounded workflow decision. Readiness work is not delay for its own sake; it prevents a model demonstration from becoming an unsupported production process.
Sources
Sources support the nearby legal, risk-management, or advertising guidance. Illustrative calculations use stated assumptions and are not client-result claims.