AI readiness assessment

An AI readiness assessment is a structured evaluation of whether a business can support AI agents in its workflows: whether the processes are defined enough, the data clean enough, and the guardrails in place before anything autonomous touc

Michael Batko
Co-founder, Hourglass AI · 21 August 2026 · 4 min read
Share

An AI readiness assessment is a structured evaluation of whether a business can support AI agents in its workflows: whether the processes are defined enough, the data clean enough, and the guardrails in place before anything autonomous touches live systems. Its purpose is sequencing, finding out what must be fixed before automation, because deploying agents onto unready foundations produces failures that get blamed on the AI and paid for twice.

Operational and Process Clarity

The process half of the assessment answers three questions. Which tasks qualify: workflow bottleneck mapping identifies the repetitive, logic-based work, data entry, reporting, routing, that is stable and rule-bound enough for an agent, as distinct from the judgement-heavy work that is not. Whether the procedures exist: an agent follows the documented process, so the assessment checks whether standard operating procedures are explicit enough to execute without a human filling the gaps from experience, and undocumented tribal process is the most common readiness failure found. Where humans stay: human-in-the-loop design marks the steps where mandatory review precedes external actions or movements of live data, decided by consequence of error, so the automation's boundaries are set before the automation exists.

The assessment finding that surprises leadership every time: readiness is uneven inside the business, not absent from it. The classic audit picture is a team experimenting individually, some racing ahead, finance and accounts hanging back, and a founder without the technical depth to systematise what the enthusiasts discovered. That unevenness is the actual readiness problem, because an automation program built on the enthusiasts' workflows will be quietly rejected by the skeptics' departments. So ask your assessor to map capability per team, not per company. A single readiness score averages away exactly the information the rollout plan needs.

Data and Technical Readiness

The technical half runs two audits. Data hygiene: how clean, structured, and accessible the internal data is across the estate, Microsoft 365, the CRM, the ERP, because agents inherit every duplicate record, stale document, and inconsistent field, and answer from them confidently. Stack compatibility: whether current software connects safely through APIs, or whether automation would require expensive custom bridging, which materially changes the cost side of every subsequent business case. The output worth paying for is a ranked remediation list, what to fix, in what order, at what cost, rather than a maturity score, since a score describes the problem and a list starts solving it.

A method note on how modern assessment works, from our own audit practice: AI does the reading now. Our audit approach uses AI analysis to reduce the number of direct interviews required, the documents, the tickets, the process exhaust get analysed before anyone books a meeting, and the human interviews then target only what the analysis couldn't see. Two consequences for buyers. The assessment should be cheaper and faster than the consulting-era version, weeks of interviews is a legacy price for a legacy method. And the assessor's own tooling is a live demonstration: a consultant who assesses your AI readiness with a clipboard has told you something about their readiness.

Risk, Governance and Local Compliance

The governance half localises the assessment. Privacy: handling of personal information checked against the Australian Privacy Principles, including what data would reach which model providers and where it would be stored. Security alignment: confirmation that deploying agents will not breach internal governance or baseline security controls, so the automation program does not stall later in the IT review it should have passed first. Economic honesty: a cost-versus-return reality check that models token and usage costs at real volumes, protecting against the quiet failure mode where automation saves visible hours while accumulating invisible spend and administrative overhead. A good assessment is cheap relative to what it prevents, which is building the right automation on the wrong foundations.

The shadow-AI finding deserves its billing at the top of the risk register, because it's the one we find everywhere: staff already using free AI tiers that can train on whatever gets pasted in, in businesses that believe they haven't adopted AI yet. Your readiness assessment isn't evaluating a future state, it's surfacing a current one. And on the economics check, the market evidence for taking foundations seriously: the largest engagement shapes we see, $25K-plus first phases, are increasingly spent entirely on shared knowledge infrastructure before a single flashy agent, because sophisticated buyers have learned where the value sits. A readiness assessment that prices your foundation gap squarely is the cheapest strategic document you'll commission this year.

References

  • Australian Privacy Principles, OAIC - https://www.oaic.gov.au/privacy/australian-privacy-principles
  • Internal systems named on this page (triage, monitoring, dashboards, pipelines) are Hourglass internal tooling, not public. Class-b author-authority links (third-party press/podcast for Batko/Fin): OPEN - source at Pass 5.

Common questions

What can I automate with AI agents?

More than most audits expect: correspondence, document intake, reconciliation, reporting, scheduling, and pipeline upkeep. The constraint is rarely capability, it is process definition, an agent can only own a workflow the business can describe precisely.

What is the 30% rule in AI?

A rule of thumb, not a law: roughly a third of the tasks inside most roles are automatable with current AI, so target task-level automation rather than whole-job replacement. Its practical use is expectation-setting, automate the repetitive third, redeploy the time, and revisit the boundary as capability moves.

How to automate business processes with AI?

Four steps that survive contact: map the process as it actually runs, including workarounds, automate one bounded workflow with agents on the variable steps and rules on the fixed ones, add approval gates where an error is expensive, and measure against the pre-automation baseline. Then compound, one process at a time.

Where to start
$2,500flat, AI Audit
  • Every AI opportunity in your business, mapped in 7 to 14 days
  • Ranked roadmap with a spec and ROI figure for each build
  • The fee is credited toward your build, doubled to $5,000 if you build within 30 days
How the audit works

Turn this into real leverage.

We map where AI pays back in your business and build the agents that get you there.

Book a Discovery Call