This framework is for executives, operations leaders and technology leads who want to know whether their organization can put AI into real work, not only into demos. It is informational: a self-assessment you can run with your own team. If you want an external assessment and a prioritized plan, that is what the AI strategy and readiness service covers. For choosing and governing the first automated processes, read our AI automation for business operations guide.
What a readiness assessment is, and what it is not
A readiness assessment answers one question: which conditions must be true before AI can create value here safely, and which of them are missing? It looks at the organization, not at the model. It is not a vendor selection, a model benchmark or an ROI forecast. It produces a scored picture across six dimensions, a list of gaps and a sequence of actions.
There are three good reasons to run one before investing:
- AI pilots often succeed technically and then stall, because data, ownership or integration were never ready for production.
- Regulation increasingly expects organizations to know which AI systems they use and what risk each one carries.
- A shared picture stops the most enthusiastic team, or the most persuasive vendor, from setting the agenda alone.
The six dimensions
-
Strategy and use cases
- Question it answers
- Do we know which business problems AI should solve, and who owns them?
- Evidence to look at
- A ranked list of use cases with owners, measures and value logic
-
Data
- Question it answers
- Is the data for those use cases available, of known quality and lawful to use?
- Evidence to look at
- Data inventory, quality checks, access rights, retention rules
-
Technology and integration
- Question it answers
- Can AI outputs reach the systems where the work happens?
- Evidence to look at
- APIs, integration layer, identity, environments, logging
-
People and skills
- Question it answers
- Do staff understand what AI can and cannot do, and who builds and runs it?
- Evidence to look at
- Roles, training records, available engineering and data skills
-
Governance and risk
- Question it answers
- Are there rules for approving, monitoring and retiring AI systems?
- Evidence to look at
- AI inventory, risk classification, approval process, incident handling
-
Operations and measurement
- Question it answers
- Can we run AI in production and prove whether it works?
- Evidence to look at
- Monitoring, human review queues, baseline measures, cost tracking
Maturity levels
Score each dimension on four levels. Use evidence, not opinion: a level counts only if someone can show the artifact behind it.
-
Exploring
Interest and ad hoc experiments; no owner, no inventory, data untested
-
Piloting
One or two supervised pilots with named owners; data prepared by hand for each pilot
-
Operating
At least one AI use case in production with monitoring, human review where needed and a measured baseline
-
Scaling
Repeatable intake, shared data and integration services, and a governance process that approves new use cases in weeks rather than quarters
Most mid-sized organizations score unevenly: level 3 on technology because their core systems are modern, level 1 on governance because nobody has been asked to own it. That uneven profile is normal, and finding it is the point of the assessment.
How to run the assessment in six steps
-
Set the scope
Choose the business units and processes in scope. An enterprise-wide assessment done in one pass tends to become a survey; start with two or three functions.
-
Collect candidate use cases
Ask each function which problems it would like AI to help with. Record the process, the volume, the cost of an error and who would own the result.
-
Gather evidence per dimension
Use the evidence column in the table above. Interview owners, review documents and look at the systems themselves rather than relying on questionnaires.
-
Score and calibrate
Score each dimension from 1 to 4 per function, then review the scores in one session with business and technology leads, so that each level means the same thing across teams.
-
Classify risk
For each candidate use case, note whether it touches personal data, regulated decisions or customers directly, and which regulatory category it may fall into.
-
Decide the sequence
Turn the scores into actions with the decision table below, and pick one or two use cases that fit the current maturity.
Decision framework: what the scores tell you to do
| Score pattern | What it means | Next move |
|---|---|---|
| Strategy at 1 | No agreed problem to solve | Run use-case discovery before any build |
| Data at 1 or 2 for the top use case | The model will only be as good as untested data | Fix data access and quality for that use case first |
| Technology at 1 or 2 | Outputs cannot reach the systems where work happens | Build the integration path; start with a use case that touches few systems |
| Governance at 1 | Nobody can approve or stop an AI system | Name an owner, create an AI inventory and add an approval step before production |
| Operations at 1 or 2 | Nobody could tell whether a production system works | Define baselines and monitoring before go-live |
| Every dimension at 3 or above | Ready to scale | Build shared services (data, integration, review queues) and a use-case intake |
The rule behind the table is simple: the weakest dimension limits everything else. A strong model on weak data, or a strong pilot with no owner, rarely reaches production.
Frameworks and regulation to map against
You do not need to invent the governance dimension from scratch. Two public references help structure it:
- NIST AI Risk Management Framework. A voluntary framework released in January 2023 and organized into four functions: Govern, Map, Measure and Manage. NIST's Generative AI Profile (NIST AI 600-1, July 2024) adds guidance for risks specific to generative AI. Mapping your governance and operations dimensions to these functions gives the assessment a recognized structure.
- The EU AI Act. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies generally from 2 August 2026, with some obligations phased in on other dates. It takes a risk-based approach: some practices are prohibited, high-risk systems such as recruitment tools carry strict requirements, some systems carry transparency duties such as telling people they are interacting with AI, and most systems carry no specific obligations. If you serve EU customers or employ staff in the EU, classify each candidate use case against these categories in step 5 and check the European Commission's current timeline.
Neither reference certifies anything on its own, and this page is not legal advice.
Trade-offs in how you assess
| Choice | Option A | Option B | How to decide |
|---|---|---|---|
| Breadth | Enterprise-wide in one pass | Two or three functions first | Start narrow unless a regulator or the board asks for a full inventory |
| Method | Self-assessment | External assessment | Self-assessment costs less; an outside view helps when teams disagree or lack AI experience |
| Depth | Questionnaire | Evidence review and interviews | Questionnaires overstate maturity; ask for the artifact behind each level |
| Timing | Before any pilot | After a first pilot | Before is cleaner; after gives real evidence about data and integration |
| Output | Score report | Scores plus a sequenced plan | A score without a plan rarely changes a budget |
Readiness checklist
- A ranked list of use cases, each with an owner and a measure.
- A data inventory for the top use cases, with quality and access rights checked.
- An integration path from AI outputs to the systems where the work happens.
- Named roles for building, reviewing and running AI systems.
- An AI inventory with a risk classification for each system.
- An approval step before production and a tested way to switch a system off.
- Human review for high-impact outputs, with review capacity planned.
- Baseline measures taken before go-live.
- Security controls on AI data: access control, encryption and logging.
- A review date for the assessment itself.
Example: where a delivered AI step sits
The dimensions show up clearly in delivered work. For 4over4, an online printing business, Netbase built a recommendation engine inside an existing order flow, where the inputs already existed, the integration point was clear and the business tracked its results; the same project automated file conversion. As reported in the case study, design-file production time fell 40%, fulfilment time fell 50% and revenue grew 82% within six months. The figures cover the whole engagement, not the recommendation engine alone.
The lesson for an assessment: the AI step came last, where data, integration and measurement were already at a working level. Where those are missing, an AI step inside a rule-based flow is often the right first project; our AI agent vs workflow automation comparison explains when each approach fits. For commerce teams, commerce operations automation covers the order, file and fulfilment flows where such steps usually sit, and retail and e-commerce shows the wider industry context.
Plan the next step with a Netbase consultant
How Netbase approaches AI readiness
Netbase works across machine learning, natural language processing, computer vision, generative AI and AI with IoT. These are capability areas offered on request. The named AI work is 4over4's recommendation engine, and Netbase has also delivered AI for clients that are not named, kept as anonymised records. Delivery runs remote-first from Hanoi in English, with security designed in: secure code review, TLS in transit and AES at rest, role-based access control, MFA for admin dashboards, vulnerability scanning and disaster recovery planning, with NDAs and DPAs on request. These practices describe how Netbase works; they do not make a client's AI system compliant.
-
In delivered work
Product recommendation engine
Built for 4over4 from browsing and purchase history.
-
In delivered work
RAG knowledge assistant
Delivered for a client that is not named; this kind of use case tests the data dimension: owned, current sources with clear access rights.
-
In delivered work
Document AI platform
Delivered for a client that is not named; this kind of use case needs labelled sample documents and a review path.
-
In delivered work
MLOps pipeline
Delivered for a client that is not named; the operations and measurement dimension in practice: evaluation, release gates and monitoring.
-
Available capability
Machine learning, NLP, computer vision, generative AI and AI with IoT
AI capability areas Netbase offers; beyond the delivered projects above, not yet tied to a published case.
Limitations of this framework
- It is a practical framework drawn from delivery experience, not original research, and it has not been validated statistically.
- Maturity levels are qualitative. Two assessors can score the same evidence differently; calibration in step 4 reduces this but does not remove it.
- The regulatory summary is general and was checked on the access date. Regulation and its timelines change; rely on the official sources.
- No ROI figure is offered. Value depends on the use case, the baseline and adoption, and should be measured in your own pilot.
- AI capabilities and costs change quickly, so this page is reviewed quarterly.
Frequently asked questions
It depends on the scope and on how much evidence already exists. An assessment of two or three functions is far quicker than an enterprise-wide one.
Before, if you can. If a pilot is already running, assess now: it gives real evidence about data and integration.
A business executive, with technology, data and risk leads contributing. An assessment owned only by IT tends to overweight technology.
Possibly, if you place AI systems on the EU market or use them in the EU. Classify your use cases and take legal advice.
Next step
Send us your candidate use cases and the systems they touch, and we will book a solution review to score the six dimensions with you and name the first gap to close. You can also see the related service or browse more Netbase insights.
Related services and solutions
AI strategy and readiness: from a list of ideas to a governed roadmap
Netbase provides AI strategy consulting for leadership teams that need to decide where AI is worth the effort. We assess readiness across four areas (use cases, data, risk and value), rank the candidates and deliver a governed AI roadmap with first pilots, owners and measures. AI strategy is a capability we are growing, not a record of many past programmes.
Learn More
AI-assisted ecommerce operations automation: from paid order to delivered parcel
Ecommerce operations automation removes the manual order, production and fulfilment steps behind a storefront: routing, file preparation, status updates and back-office sync, with AI flagging risky orders and triaging exceptions. It is for merchants and online printers whose order volume has outgrown their staff. In delivered work, 4over4 cut design-file production time 40% and Geo-Tek cut average order processing time 30%.
Learn More
Discuss a project
Netbase JSC helps organizations design, build, modernize, and operate digital products and AI-enabled business systems.+84 937 869 689
91 Nguyen Chi Thanh, Dong Da, Hanoi, Vietnam
Get in touch
Tell us what you want to build, modernize, or operate.