AI Readiness Assessment
Go through your organization one control at a time, across ten areas. Mark each as Met, Partial, or Gap, and the results roll up into a maturity score for each area and an overall picture. This is the in-depth version of the quick self-checks, scored the way a real engagement would. New to this? The five-minute AI Maturity Assessment is the gentler place to start. Nothing you enter leaves your browser.
See the control crosswalk for how these domains map across NIST AI RMF, ISO 42001, SOC 2, ISO 27001, NIST 800-171 / CMMC, and privacy.
1. Governance, Accountability & Policy
What good looks like: Someone clearly owns AI, a group oversees it, there is an approved policy on what is allowed, and everyone knows who gets to decide what.
2. AI System & Agent Inventory + Risk Classification
What good looks like: You keep a live list of every AI system and agent, including who owns it, what data and tools it can reach, and how risky it is.
3. Data Governance & Privacy
What good looks like: AI uses only the data it needs, that data is kept accurate and labeled by how sensitive it is, and personal information is handled with privacy built in.
4. Identity & Access Governance, incl. agentsFramework Domain 1
What good looks like: Every AI agent signs in as its own tracked identity, gets only the access it needs and only when it needs it, and its activity is logged separately from people.
5. Human Oversight & Decision RightsFramework Domain 2
What good looks like: For each important decision you have decided in advance whether AI can act on its own, only advise, or must wait for a person, and you track how often people overrule it.
6. AI / Agent Security & Tool-Use, MCPFramework Domain 3
What good looks like: Each agent can use only the tools you have approved and nothing else, every tool call is logged as a security event, its outputs are checked, and you test it against attempts to trick it (prompt injection).
7. Audit Trail, Logging & ExplainabilityFramework Domain 4
What good looks like: For decisions that matter you can see the AI's full reasoning, not just what went in and out; the record cannot be altered; and a non-technical person can follow it.
8. Monitoring: Bias, Fairness & PerformanceFramework Domain 6
What good looks like: You decide up front what fair looks like, then watch for unfair patterns and slipping accuracy over time, including bias picked up from the tools the AI relies on.
9. Incident Response & Resilience, autonomous failuresFramework Domain 5
What good looks like: Every agent has a clear off switch (who flips it, when, and what happens to work already in progress), your responders are trained on how the AI is built, you rehearse failures, and you review which control broke.
10. Regulatory Alignment & Third-Party / Supply ChainFramework Domain 7
What good looks like: Each AI use is matched to the rules that apply to it (such as the EU AI Act, HIPAA, or federal contracting rules), your AI vendors are risk-checked, and clearing those rules is required before you go live.
v1 draft: controls are at the family / criteria level and validated per engagement. The Met / Partial / Gap point values and the maturity thresholds are a sensible default, not a published standard. Editions referenced: NIST AI RMF 1.0 (2023), ISO/IEC 42001:2023, ISO/IEC 27001:2022, NIST SP 800-171 (r2/r3) and CMMC 2.0, ISO/IEC 27701, NIST Privacy Framework 1.0.