Score one workflow across seven readiness gates before you invest
A small business is ready to pilot AI when it can name one valuable outcome, describe the workflow and its exceptions, provide reliable information, involve the people doing the work, define human approval and stop rules, protect access and data, and measure whether the change actually helps. Use the seven-gate checklist below on one workflow. Do not score the company as a whole or treat a high number as permission to ignore a serious risk.
Readiness is not a technology shopping exercise. A business can already use several AI tools and still be unready to connect them to customer, employee, financial or operational work. Equally, a small team with modest systems may be ready for a contained pilot because its process, knowledge, ownership and safeguards are clear.
Originally published 15 February 2026. Substantially expanded and reviewed 13 August 2026. This educational self-check is not a certification or a substitute for legal, data-protection, employment, cyber-security or sector-specific advice.
What does AI readiness mean for a small business?
AI readiness is the ability to introduce an AI-supported workflow with a clear purpose, usable inputs, accountable people, proportionate controls and evidence-based review. It is narrower than general digital maturity. You do not need to modernise everything before you begin. You do need enough clarity around the chosen workflow to recognise a correct result, catch an unsafe one and return to a dependable manual route.
That is why this checklist scores a workflow rather than a company. Enquiry capture may be ready while pricing decisions are not. Meeting follow-up may have reliable inputs while the shared inbox still has unclear ownership. If you have not chosen the workflow yet, use our first-process scorecard before completing this assessment.
Why readiness matters in 2026
The latest Office for National Statistics analysis found that self-reported AI use among UK businesses with 10 or more employees rose from around 12% in late 2023 to around 35% in June 2026. Yet adoption remained relatively shallow: the average number of AI technologies used by adopting businesses increased only from around 1.4 to 1.6, and only 10% of AI-using businesses with 10 or more employees described their use as extensive. These measures are early, depend on survey definitions and should not be treated as a maturity benchmark.
The UK Business Data Survey 2026 provides another useful warning. Among businesses reporting AI use, 21% said the tools were integrated into existing business systems and 17% said the business had formal or informal AI policy or guidance. The figures measure different things, but both show the gap between trying a feature and establishing a dependable operating practice. The separate UK SME AI workflow evidence hub shows the denominators, business-size breakdown and downloadable evidence table behind these figures.
A separate Department for Science, Innovation and Technology study found marketing and administration were the most commonly reported current or planned business areas for AI, at 72% each among the relevant respondents. It also found 84% of businesses currently using AI reported at least some human input or checking. These are self-reported survey results, not proof that any particular control is effective. They do, however, support assessing the people, workflow and review arrangements around the technology.
The seven readiness gates at a glance
| Gate | Evidence of readiness | Fix before a pilot |
|---|---|---|
| 1. Business outcome | One defined problem, affected people, current cost or pressure and a useful outcome. | The plan starts with a tool or broad ambition rather than a business need. |
| 2. Workflow and exceptions | A trigger, owner, steps, handoffs, completion state and known exceptions. | Staff describe different processes or no one owns the final result. |
| 3. Information and data | Approved sources, an owner, access rules, quality checks and missing-data behaviour. | Answers depend on memory, conflicting files or information with unclear rights. |
| 4. Systems and security | Required connections, least-privilege access, logging, recovery and supplier review. | Shared accounts, unknown data flows, unnecessary access or no manual fallback. |
| 5. People and capability | Staff involvement, training, feedback routes, realistic capacity and a change owner. | The workflow is being designed around staff without their operational knowledge. |
| 6. Governance and human control | Permitted use, prohibited use, approval, escalation, pause, incident and review rules. | The system is expected to make sensitive or unusual decisions without accountable review. |
| 7. Measurement and improvement | A baseline, target, quality measures, review date, exit criteria and decision owner. | Success means only that the tool launched or produced impressive examples. |
How to score the checklist
Choose one named workflow. For every question below, give 0 when there is no reliable answer or evidence, 1 when it is partly defined, and 2 when it is clear, current and owned. Each gate has three questions and a maximum of six points. The overall maximum is 42.
- Record the evidence beside the score; do not award points for an assumption.
- Ask the people who perform the work, not only the manager buying the system.
- Write down disagreements and exceptions instead of averaging them away.
- Apply the hard-stop check after the total because some risks should not be traded for points elsewhere.
Calculate your AI readiness score
Choose one real workflow and answer all 21 questions using evidence from the people who operate it. Your result highlights the strongest foundations, the gates that need work and any unresolved issue that should pause a pilot.
Gate 1: business outcome and use-case fit
A credible first use case starts with repeated pressure and a defined outcome. “Use AI in sales” is not an outcome. “Reduce the time valid website enquiries wait for a named owner while keeping qualification human-led” is specific enough to assess.
- Can we state the current problem and who experiences it? Collect examples of delay, rework, missed service or staff pressure.
- Does the workflow happen often enough to learn from? A rare task may not generate enough evidence for a useful pilot.
- Can we name one result that matters? Link it to response, completion, quality, cash flow, customer experience or protected staff time.
Evidence: recent volumes, waiting time, rework examples, current handling cost, complaints, missed actions and a written outcome statement.
Gate 2: workflow clarity and exceptions
AI cannot repair an undefined operating model by itself. Map where the work begins, what happens next, who owns each handoff, how completion is recognised and where reality departs from the happy path. The difference between a tool and an integrated workflow is especially important here.
- Can two people describe the normal route consistently? Compare their accounts using recent real examples.
- Are ownership and handoffs explicit? Every live item needs one current owner and a visible next action.
- Are the important exceptions known? Include complaints, vulnerability, missing consent, unusual scope, duplicate records, disputed facts and supplier failure.
Evidence: a one-page workflow map, sample cases, exception list, service rules, ownership matrix and agreed completion state.


Gate 3: information and data readiness
The selected workflow needs reliable inputs, not perfect company-wide data. Identify the approved source for services, prices, policy, customer facts or operational status. Name the person responsible for keeping each source current. Decide what happens when information is missing, old, conflicting or outside scope.
- Is there an approved source set? Separate maintained knowledge from inbox history, personal notes and superseded documents.
- Do we understand sensitivity, rights and retention? Record personal, confidential, regulated and third-party information before choosing a supplier or connection.
- Can poor inputs be detected and stopped? The workflow should ask, pause or escalate rather than fill a gap with a plausible answer.
The ICO AI and data-protection risk toolkit is designed to help organisations reduce risks to individuals' rights and freedoms. It is a useful specialist companion where personal data is involved; a general readiness score is not a data-protection assessment.
Gate 4: systems, suppliers and security
List every system the workflow reads from or writes to. Give it only the access required for the approved task. Confirm how changes are logged, what happens during failure, who can stop the connection and how the existing process continues. Review supplier terms, data locations, retention, sub-processors, service availability and exit arrangements in proportion to the risk.
- Are the connections and permissions documented? Avoid personal credentials and broad access “just in case”.
- Can important actions be traced and recovered? Keep useful logs, version history, reconciliation and a tested manual fallback.
- Has the supplier and failure route been reviewed? Know what the provider does, where responsibility remains with you and how data or service can be removed.
The National Cyber Security Centre guidelines organise secure AI system development across secure design, development, deployment, and operation and maintenance. Their coverage of supply-chain security, documentation, incident management, logging and monitoring reinforces why readiness must continue beyond launch.
Gate 5: people, skills and change capacity
The people performing the work know where customers depart from the script, which shortcuts are unsafe and what a useful output looks like. Involve them early, explain the business problem, protect time for testing and make feedback visible. The ONS reports training or retraining existing staff as a common response among businesses citing a lack of AI expertise; readiness therefore includes the capacity to learn, not simply current expertise.
- Have affected staff helped map the workflow and exceptions? Record what changed because of their input.
- Do people know what the system can and cannot do? Training should cover checks, escalation, stop authority and the manual route.
- Is there time and ownership for adoption? A pilot added on top of an overloaded day will produce weak feedback and inconsistent use.
Acas explains that consultation can build trust, identify problems early, improve solutions and give people a voice in changes affecting them. That is both a people-first principle and a practical way to expose workflow risk.
Gate 6: governance and human control
Write down the permitted purpose, information, users and outputs. Define what the workflow must never do, which actions need approval, when it must escalate, who can pause it, how incidents are reported and when the rules will be reviewed. Human oversight is useful only when the reviewer has enough context, authority and time to intervene.
- Are permitted and prohibited uses clear? Include sensitive decisions, claims, prices, complaints and exceptional customer promises.
- Does every material outcome have accountable ownership? “A human is in the loop” is too vague without a named role and action.
- Can the system be paused, investigated and changed? Record incidents, recurring corrections, rule changes and review dates.
The UK government's current AI Management Essentials consultation guidance describes a self-assessment focused on internal processes, managing risks and communication. It says the tool is intended as an accessible starting point rather than certification or a replacement for the standards that inform it. Use Ostina's AI governance checklist to turn this gate into an operating record.
Gate 7: measurement and continuous improvement
Measure the current workflow before changing it. Pair speed or cost with quality, customer and staff measures so an apparent efficiency does not hide rework or poor service. Decide when the pilot will be reviewed, what evidence supports expansion, what triggers correction and what would stop it.
- Do we have a usable baseline? Record enough recent volume, time, quality and exception evidence to compare like with like.
- Are benefits and harms measured together? Include corrections, escalations, complaints, opt-outs, reopened work and staff feedback.
- Are the decision date and exit criteria agreed? Name who decides to continue, change, pause or retire the workflow.
Use our automation ROI guide to compare time, quality, risk and total cost without inventing a universal return.
Interpret the total without hiding risk
| Score | Working interpretation | Next action |
|---|---|---|
| 0 to 13 | Foundations are unclear. | Do not connect AI to live work. Map the workflow, ownership, information and outcome first. |
| 14 to 27 | Preparation is under way but important gaps remain. | Create a readiness action plan, then rescore using evidence. |
| 28 to 35 | A narrow assisted pilot may be possible. | Resolve all hard stops, use extra review and define strong fallback and exit criteria. |
| 36 to 42 | A strong pilot candidate. | Complete specialist checks, test exceptions and launch only within the approved scope. |
These bands are an Ostina planning aid, not an industry standard, assurance opinion or prediction of success. A workflow scoring 40 with an unresolved data-rights question is not ready. A workflow scoring 30 with low-risk information and an excellent fallback might support a tightly contained learning exercise after the gap is addressed.
Hard stops that override the score
- No accountable owner for the workflow, customer outcome or incident response.
- Unclear lawful basis, rights, confidentiality or permitted use of important information.
- No safe route for complaints, vulnerable people, emergencies or other high-impact exceptions.
- The system would make a legal, employment, credit, safety, clinical or similarly significant decision without appropriate specialist review.
- Staff or customers could reasonably be misled about an AI interaction or the route to a person.
- No tested way to pause the workflow or continue essential work during failure.
- No baseline, quality test or person authorised to decide whether the pilot should continue.
Build a small readiness evidence pack
| Evidence | Minimum useful content | Owner |
|---|---|---|
| Outcome brief | Problem, affected people, current pressure, intended result and excluded aims. | Business sponsor |
| Workflow map | Trigger, steps, owners, handoffs, completion state and manual route. | Workflow owner |
| Exception register | Known unusual, sensitive and failure cases with required escalation. | Practitioner and owner |
| Information register | Sources, owner, sensitivity, rights, retention, quality and update frequency. | Information owner |
| System and supplier record | Connections, permissions, terms, sub-processors, logging, recovery and exit. | System owner |
| Control sheet | Permitted use, approval, escalation, pause, incident and review rules. | Accountable lead |
| Measurement plan | Baseline, target, quality measures, review cadence and exit criteria. | Outcome owner |
Worked example: website enquiry acknowledgement
Imagine a small service business wants valid website enquiries acknowledged promptly and assigned to the correct owner. It is not asking AI to qualify the lead, promise availability or close a sale. The table shows how evidence, not confidence, changes the score.
| Gate | Evidence found | Score | Preparation action |
|---|---|---|---|
| Outcome | Monthly volume and current first-response time are known; owner wants faster useful acknowledgement. | 6/6 | Keep the pilot limited to valid website enquiries. |
| Workflow | Normal route is mapped, but duplicate and existing-customer exceptions are inconsistent. | 4/6 | Agree the duplicate check and support-customer route. |
| Information | Service descriptions are maintained; service-area source is outdated. | 4/6 | Assign and update the approved service-area source. |
| Systems and security | Form and CRM use named accounts; rollback is defined but reconciliation is untested. | 4/6 | Test failure, duplicate and recovery cases. |
| People | Sales administrator and owner helped map the flow and have pilot time. | 6/6 | Schedule short daily exception reviews. |
| Governance | Draft approval is required; complaints and sensitive messages escalate; incident owner is named. | 6/6 | Document the pause route beside the CRM queue. |
| Measurement | Response, ownership and correction measures exist; stop threshold is not agreed. | 5/6 | Set the correction and complaint thresholds before launch. |
| Total | Strong candidate after specific preparation work and no unresolved hard stop. | 35/42 | Recheck the three gaps, then run an assisted-mode pilot. |
The score does not justify automatic sending on day one. It identifies a bounded learning opportunity. For more options, compare the 18 practical AI automation examples for small businesses.
Move from readiness into a controlled pilot
| Before live use | Evidence to approve |
|---|---|
| Scope | One workflow, user group, information set, permitted actions and explicit exclusions. |
| Acceptance tests | Normal, missing-data, duplicate, sensitive, adversarial, failure and manual-fallback cases. |
| Human operation | Named owner, reviewer, escalation recipient, stop authority and customer route. |
| Baseline and target | Current performance, intended improvement and quality or harm guardrails. |
| Fallback | Tested manual process, reconciliation method and recovery owner. |
| Review | Short-cycle exception review plus a dated continue, change, pause or stop decision. |
The AI automation implementation timeline guide explains the gates from discovery to stable operation. The people-first adoption playbook covers discover, design, pilot, review and scale. Both assume that people retain the authority to correct, pause and improve the workflow.
Use external frameworks proportionately
A small-business checklist should be usable, but it should not pretend to replace mature governance or specialist assurance. The OECD SME AI Readiness Tool is currently labelled as a pilot for SME owners and managers in G7 countries and includes digital foundations as a baseline. The UK AIME material focuses on organisational management practices. ICO and NCSC guidance addresses data-protection and security risks in much more detail. Use the source that matches the risk, sector and stage of the project.
For a low-risk internal drafting pilot, the proportionate record may be short. For customer decisions, employee monitoring, special-category data, safety, finance or regulated professional work, widen the review and obtain qualified advice. Readiness means recognising when the business should not decide alone.
Frequently asked questions
How do I know if my small business is ready for AI?
Score one repeatable workflow across its business outcome, process clarity, information, systems and security, people, governance and measurement. A strong score plus no unresolved hard stop makes it a plausible pilot candidate, not a guarantee of success.
Does a small business need perfect data before using AI?
No. The selected workflow needs a limited, reliable and owned source set. Missing, outdated or conflicting information must be detectable, and the workflow must stop or escalate rather than invent an answer.
Do we need an AI policy before starting a pilot?
You need proportionate rules before real staff or customer information is used. At minimum, record approved tools, permitted information, prohibited uses, human approval points, incident reporting, ownership and review dates. Higher-risk or regulated work needs specialist checks.
Who should complete an AI readiness assessment?
Include the workflow owner, at least one person who performs the work, someone responsible for information or systems, and the person accountable for risk and customer outcomes. A technology-only review will miss operational exceptions and staff concerns.
What happens after an AI readiness checklist?
Turn weak gates into a preparation plan. If the workflow is a credible candidate, define a contained pilot with approved inputs, test cases, human controls, a fallback, baseline measures, exit criteria and a review date before wider rollout.
Sources and further reading
- Office for National Statistics: Artificial intelligence in UK businesses, 2023 to 2026.
- Department for Science, Innovation and Technology: AI Adoption Research.
- UK Business Data Survey 2026.
- UK Government: guidance for using the AI Management Essentials tool.
- Information Commissioner's Office: AI and data-protection risk toolkit.
- National Cyber Security Centre: guidelines for secure AI system development.
- Acas: consulting employees and representatives.
- OECD: SME AI Readiness Tool (pilot).
The practical next step
Print or copy the seven gates, choose one workflow and complete the score with the people who operate it. Turn every zero and unresolved disagreement into a named action. Use our future of AI for UK SMEs guide to separate durable capabilities from short-lived technology bets. If you need an independent, evidence-led review, Ostina's AI readiness assessment and automation audit maps the workflow, risks, opportunities and practical priorities before investment. Our AI automation consultancy can then turn that evidence into a controlled roadmap.
