Loading Your Rhythm

Ostina helps practical teams reduce repetitive admin pressure and build steady progress with clear human control.

Search Ostina
Contact Ostina
Email ai@ostina.ai
Service area United Kingdom
Follow Us
Search Ostina
Contact Ostina
Email ai@ostina.ai
Service area United Kingdom
Follow Us

AI Readiness Checklist for UK Small Businesses

UK small-business team completing an evidence-led AI readiness checklist

Score one workflow across seven readiness gates before you invest

Dan Clarke
Authored by
Dan Clarke
Date Released
15 February 2026
Category
AI readiness

A small business is ready to pilot AI when it can name one valuable outcome, describe the workflow and its exceptions, provide reliable information, involve the people doing the work, define human approval and stop rules, protect access and data, and measure whether the change actually helps. Use the seven-gate checklist below on one workflow. Do not score the company as a whole or treat a high number as permission to ignore a serious risk.

Readiness is not a technology shopping exercise. A business can already use several AI tools and still be unready to connect them to customer, employee, financial or operational work. Equally, a small team with modest systems may be ready for a contained pilot because its process, knowledge, ownership and safeguards are clear.

Originally published 15 February 2026. Substantially expanded and reviewed 13 August 2026. This educational self-check is not a certification or a substitute for legal, data-protection, employment, cyber-security or sector-specific advice.

What does AI readiness mean for a small business?

AI readiness is the ability to introduce an AI-supported workflow with a clear purpose, usable inputs, accountable people, proportionate controls and evidence-based review. It is narrower than general digital maturity. You do not need to modernise everything before you begin. You do need enough clarity around the chosen workflow to recognise a correct result, catch an unsafe one and return to a dependable manual route.

That is why this checklist scores a workflow rather than a company. Enquiry capture may be ready while pricing decisions are not. Meeting follow-up may have reliable inputs while the shared inbox still has unclear ownership. If you have not chosen the workflow yet, use our first-process scorecard before completing this assessment.

Why readiness matters in 2026

The latest Office for National Statistics analysis found that self-reported AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% in June 2026. Yet adoption remained relatively shallow: the average number of AI technologies used by adopting businesses increased only from around 1.4 to 1.6, and only 10% of AI-using businesses with 10 or more employees described their use as extensive. These measures are early, depend on survey definitions and should not be treated as a maturity benchmark.

The UK Business Data Survey 2026 provides another useful warning. Among businesses reporting AI use, 21% said the tools were integrated into existing business systems and 17% said the business had formal or informal AI policy or guidance. The figures measure different things, but both show the gap between trying a feature and establishing a dependable operating practice. The separate UK SME AI workflow evidence hub shows the denominators, business-size breakdown and downloadable evidence table behind these figures.

A separate Department for Science, Innovation and Technology study found marketing and administration were the most commonly reported current or planned business areas for AI, at 72% each among the relevant respondents. It also found 84% of businesses currently using AI reported at least some human input or checking. These are self-reported survey results, not proof that any particular control is effective. They do, however, support assessing the people, workflow and review arrangements around the technology.

The seven readiness gates at a glance

GateEvidence of readinessFix before a pilot
1. Business outcomeOne defined problem, affected people, current cost or pressure and a useful outcome.The plan starts with a tool or broad ambition rather than a business need.
2. Workflow and exceptionsA trigger, owner, steps, handoffs, completion state and known exceptions.Staff describe different processes or no one owns the final result.
3. Information and dataApproved sources, an owner, access rules, quality checks and missing-data behaviour.Answers depend on memory, conflicting files or information with unclear rights.
4. Systems and securityRequired connections, least-privilege access, logging, recovery and supplier review.Shared accounts, unknown data flows, unnecessary access or no manual fallback.
5. People and capabilityStaff involvement, training, feedback routes, realistic capacity and a change owner.The workflow is being designed around staff without their operational knowledge.
6. Governance and human controlPermitted use, prohibited use, approval, escalation, pause, incident and review rules.The system is expected to make sensitive or unusual decisions without accountable review.
7. Measurement and improvementA baseline, target, quality measures, review date, exit criteria and decision owner.Success means only that the tool launched or produced impressive examples.

How to score the checklist

Choose one named workflow. For every question below, give 0 when there is no reliable answer or evidence, 1 when it is partly defined, and 2 when it is clear, current and owned. Each gate has three questions and a maximum of six points. The overall maximum is 42.

  • Record the evidence beside the score; do not award points for an assumption.
  • Ask the people who perform the work, not only the manager buying the system.
  • Write down disagreements and exceptions instead of averaging them away.
  • Apply the hard-stop check after the total because some risks should not be traded for points elsewhere.
Free tool · about 8 minutes

Calculate your AI readiness score

Choose one real workflow and answer all 21 questions using evidence from the people who operate it. Your result highlights the strongest foundations, the gates that need work and any unresolved issue that should pause a pilot.

Your answers stay in this browser. They are not submitted, stored or used to make an automated decision.
0 of 21 questions answered Current score: 0/42

    Gate 1: business outcome and use-case fit

    A credible first use case starts with repeated pressure and a defined outcome. “Use AI in sales” is not an outcome. “Reduce the time valid website enquiries wait for a named owner while keeping qualification human-led” is specific enough to assess.

    1. Can we state the current problem and who experiences it? Collect examples of delay, rework, missed service or staff pressure.
    2. Does the workflow happen often enough to learn from? A rare task may not generate enough evidence for a useful pilot.
    3. Can we name one result that matters? Link it to response, completion, quality, cash flow, customer experience or protected staff time.

    Evidence: recent volumes, waiting time, rework examples, current handling cost, complaints, missed actions and a written outcome statement.

    Gate 2: workflow clarity and exceptions

    AI cannot repair an undefined operating model by itself. Map where the work begins, what happens next, who owns each handoff, how completion is recognised and where reality departs from the happy path. The difference between a tool and an integrated workflow is especially important here.

    1. Can two people describe the normal route consistently? Compare their accounts using recent real examples.
    2. Are ownership and handoffs explicit? Every live item needs one current owner and a visible next action.
    3. Are the important exceptions known? Include complaints, vulnerability, missing consent, unusual scope, duplicate records, disputed facts and supplier failure.

    Evidence: a one-page workflow map, sample cases, exception list, service rules, ownership matrix and agreed completion state.

    Small-business team mapping one workflow, its evidence and exceptions for an AI readiness review
    Workflow owner and colleague confirming human approval, security and pilot measurement controls

    Gate 3: information and data readiness

    The selected workflow needs reliable inputs, not perfect company-wide data. Identify the approved source for services, prices, policy, customer facts or operational status. Name the person responsible for keeping each source current. Decide what happens when information is missing, old, conflicting or outside scope.

    1. Is there an approved source set? Separate maintained knowledge from inbox history, personal notes and superseded documents.
    2. Do we understand sensitivity, rights and retention? Record personal, confidential, regulated and third-party information before choosing a supplier or connection.
    3. Can poor inputs be detected and stopped? The workflow should ask, pause or escalate rather than fill a gap with a plausible answer.

    The ICO AI and data-protection risk toolkit is designed to help organisations reduce risks to individuals' rights and freedoms. It is a useful specialist companion where personal data is involved; a general readiness score is not a data-protection assessment.

    Gate 4: systems, suppliers and security

    List every system the workflow reads from or writes to. Give it only the access required for the approved task. Confirm how changes are logged, what happens during failure, who can stop the connection and how the existing process continues. Review supplier terms, data locations, retention, sub-processors, service availability and exit arrangements in proportion to the risk.

    1. Are the connections and permissions documented? Avoid personal credentials and broad access “just in case”.
    2. Can important actions be traced and recovered? Keep useful logs, version history, reconciliation and a tested manual fallback.
    3. Has the supplier and failure route been reviewed? Know what the provider does, where responsibility remains with you and how data or service can be removed.

    The National Cyber Security Centre guidelines organise secure AI system development across secure design, development, deployment, and operation and maintenance. Their coverage of supply-chain security, documentation, incident management, logging and monitoring reinforces why readiness must continue beyond launch.

    Gate 5: people, skills and change capacity

    The people performing the work know where customers depart from the script, which shortcuts are unsafe and what a useful output looks like. Involve them early, explain the business problem, protect time for testing and make feedback visible. The ONS reports training or retraining existing staff as a common response among businesses citing a lack of AI expertise; readiness therefore includes the capacity to learn, not simply current expertise.

    1. Have affected staff helped map the workflow and exceptions? Record what changed because of their input.
    2. Do people know what the system can and cannot do? Training should cover checks, escalation, stop authority and the manual route.
    3. Is there time and ownership for adoption? A pilot added on top of an overloaded day will produce weak feedback and inconsistent use.

    Acas explains that consultation can build trust, identify problems early, improve solutions and give people a voice in changes affecting them. That is both a people-first principle and a practical way to expose workflow risk.

    Gate 6: governance and human control

    Write down the permitted purpose, information, users and outputs. Define what the workflow must never do, which actions need approval, when it must escalate, who can pause it, how incidents are reported and when the rules will be reviewed. Human oversight is useful only when the reviewer has enough context, authority and time to intervene.

    1. Are permitted and prohibited uses clear? Include sensitive decisions, claims, prices, complaints and exceptional customer promises.
    2. Does every material outcome have accountable ownership? “A human is in the loop” is too vague without a named role and action.
    3. Can the system be paused, investigated and changed? Record incidents, recurring corrections, rule changes and review dates.

    The UK government's current AI Management Essentials consultation guidance describes a self-assessment focused on internal processes, managing risks and communication. It says the tool is intended as an accessible starting point rather than certification or a replacement for the standards that inform it. Use Ostina's AI governance checklist to turn this gate into an operating record.

    Gate 7: measurement and continuous improvement

    Measure the current workflow before changing it. Pair speed or cost with quality, customer and staff measures so an apparent efficiency does not hide rework or poor service. Decide when the pilot will be reviewed, what evidence supports expansion, what triggers correction and what would stop it.

    1. Do we have a usable baseline? Record enough recent volume, time, quality and exception evidence to compare like with like.
    2. Are benefits and harms measured together? Include corrections, escalations, complaints, opt-outs, reopened work and staff feedback.
    3. Are the decision date and exit criteria agreed? Name who decides to continue, change, pause or retire the workflow.

    Use our automation ROI guide to compare time, quality, risk and total cost without inventing a universal return.

    Interpret the total without hiding risk

    ScoreWorking interpretationNext action
    0 to 13Foundations are unclear.Do not connect AI to live work. Map the workflow, ownership, information and outcome first.
    14 to 27Preparation is under way but important gaps remain.Create a readiness action plan, then rescore using evidence.
    28 to 35A narrow assisted pilot may be possible.Resolve all hard stops, use extra review and define strong fallback and exit criteria.
    36 to 42A strong pilot candidate.Complete specialist checks, test exceptions and launch only within the approved scope.

    These bands are an Ostina planning aid, not an industry standard, assurance opinion or prediction of success. A workflow scoring 40 with an unresolved data-rights question is not ready. A workflow scoring 30 with low-risk information and an excellent fallback might support a tightly contained learning exercise after the gap is addressed.

    Hard stops that override the score

    • No accountable owner for the workflow, customer outcome or incident response.
    • Unclear lawful basis, rights, confidentiality or permitted use of important information.
    • No safe route for complaints, vulnerable people, emergencies or other high-impact exceptions.
    • The system would make a legal, employment, credit, safety, clinical or similarly significant decision without appropriate specialist review.
    • Staff or customers could reasonably be misled about an AI interaction or the route to a person.
    • No tested way to pause the workflow or continue essential work during failure.
    • No baseline, quality test or person authorised to decide whether the pilot should continue.

    Build a small readiness evidence pack

    EvidenceMinimum useful contentOwner
    Outcome briefProblem, affected people, current pressure, intended result and excluded aims.Business sponsor
    Workflow mapTrigger, steps, owners, handoffs, completion state and manual route.Workflow owner
    Exception registerKnown unusual, sensitive and failure cases with required escalation.Practitioner and owner
    Information registerSources, owner, sensitivity, rights, retention, quality and update frequency.Information owner
    System and supplier recordConnections, permissions, terms, sub-processors, logging, recovery and exit.System owner
    Control sheetPermitted use, approval, escalation, pause, incident and review rules.Accountable lead
    Measurement planBaseline, target, quality measures, review cadence and exit criteria.Outcome owner

    Worked example: website enquiry acknowledgement

    Imagine a small service business wants valid website enquiries acknowledged promptly and assigned to the correct owner. It is not asking AI to qualify the lead, promise availability or close a sale. The table shows how evidence, not confidence, changes the score.

    GateEvidence foundScorePreparation action
    OutcomeMonthly volume and current first-response time are known; owner wants faster useful acknowledgement.6/6Keep the pilot limited to valid website enquiries.
    WorkflowNormal route is mapped, but duplicate and existing-customer exceptions are inconsistent.4/6Agree the duplicate check and support-customer route.
    InformationService descriptions are maintained; service-area source is outdated.4/6Assign and update the approved service-area source.
    Systems and securityForm and CRM use named accounts; rollback is defined but reconciliation is untested.4/6Test failure, duplicate and recovery cases.
    PeopleSales administrator and owner helped map the flow and have pilot time.6/6Schedule short daily exception reviews.
    GovernanceDraft approval is required; complaints and sensitive messages escalate; incident owner is named.6/6Document the pause route beside the CRM queue.
    MeasurementResponse, ownership and correction measures exist; stop threshold is not agreed.5/6Set the correction and complaint thresholds before launch.
    TotalStrong candidate after specific preparation work and no unresolved hard stop.35/42Recheck the three gaps, then run an assisted-mode pilot.

    The score does not justify automatic sending on day one. It identifies a bounded learning opportunity. For more options, compare the 18 practical AI automation examples for small businesses.

    Move from readiness into a controlled pilot

    Before live useEvidence to approve
    ScopeOne workflow, user group, information set, permitted actions and explicit exclusions.
    Acceptance testsNormal, missing-data, duplicate, sensitive, adversarial, failure and manual-fallback cases.
    Human operationNamed owner, reviewer, escalation recipient, stop authority and customer route.
    Baseline and targetCurrent performance, intended improvement and quality or harm guardrails.
    FallbackTested manual process, reconciliation method and recovery owner.
    ReviewShort-cycle exception review plus a dated continue, change, pause or stop decision.

    The AI automation implementation timeline guide explains the gates from discovery to stable operation. The people-first adoption playbook covers discover, design, pilot, review and scale. Both assume that people retain the authority to correct, pause and improve the workflow.

    Use external frameworks proportionately

    A small-business checklist should be usable, but it should not pretend to replace mature governance or specialist assurance. The OECD SME AI Readiness Tool is currently labelled as a pilot for SME owners and managers in G7 countries and includes digital foundations as a baseline. The UK AIME material focuses on organisational management practices. ICO and NCSC guidance addresses data-protection and security risks in much more detail. Use the source that matches the risk, sector and stage of the project.

    For a low-risk internal drafting pilot, the proportionate record may be short. For customer decisions, employee monitoring, special-category data, safety, finance or regulated professional work, widen the review and obtain qualified advice. Readiness means recognising when the business should not decide alone.

    Frequently asked questions

    How do I know if my small business is ready for AI?

    Score one repeatable workflow across its business outcome, process clarity, information, systems and security, people, governance and measurement. A strong score plus no unresolved hard stop makes it a plausible pilot candidate, not a guarantee of success.

    Does a small business need perfect data before using AI?

    No. The selected workflow needs a limited, reliable and owned source set. Missing, outdated or conflicting information must be detectable, and the workflow must stop or escalate rather than invent an answer.

    Do we need an AI policy before starting a pilot?

    You need proportionate rules before real staff or customer information is used. At minimum, record approved tools, permitted information, prohibited uses, human approval points, incident reporting, ownership and review dates. Higher-risk or regulated work needs specialist checks.

    Who should complete an AI readiness assessment?

    Include the workflow owner, at least one person who performs the work, someone responsible for information or systems, and the person accountable for risk and customer outcomes. A technology-only review will miss operational exceptions and staff concerns.

    What happens after an AI readiness checklist?

    Turn weak gates into a preparation plan. If the workflow is a credible candidate, define a contained pilot with approved inputs, test cases, human controls, a fallback, baseline measures, exit criteria and a review date before wider rollout.

    Sources and further reading

    The practical next step

    Print or copy the seven gates, choose one workflow and complete the score with the people who operate it. Turn every zero and unresolved disagreement into a named action. Use our future of AI for UK SMEs guide to separate durable capabilities from short-lived technology bets. If you need an independent, evidence-led review, Ostina's AI readiness assessment and automation audit maps the workflow, risks, opportunities and practical priorities before investment. Our AI automation consultancy can then turn that evidence into a controlled roadmap.

    Want help applying this in your business?

    Business team planning next steps