Readiness is not a measure of how much technology an organisation owns. It is a measure of whether the organisation can absorb a change to how work is done. Those are different questions, and most published scorecards answer the first while appearing to answer the second.
Most free AI readiness scorecards ask about tooling, cloud maturity, data platform, headcount and whether a strategy document exists. They produce a number out of 100 and a maturity label. The number feels rigorous and tells a board almost nothing.
The first reason is that they measure inputs rather than absorption. Owning a modern data platform tells you nothing about whether the people who would have to change their working method are able to do so while continuing to run the business.
The second is that they are almost always produced by someone with something to sell, and the dimensions they choose are, by no coincidence, the ones their product improves. A scorecard that cannot return a low score on a dimension the sponsor does not sell into is not measuring anything.
The third is subtler and more damaging. A single composite number lets a strong dimension mask a fatal one. An organisation can score well on strategy, technology and data and still be entirely unable to land the change, because it has four major programs already in flight and no capacity for a fifth. Readiness does not average. The binding constraint governs.
The gap between stated intent and implemented practice is measurable in Australia, and it is wide. Fifth Quadrant, in partnership with the National AI Centre, surveyed 413 Australian organisations of 20 or more employees for the Australian Responsible AI Index 2024, published in September 2024. On average 78 per cent of organisations agreed their AI systems aligned with Australia’s AI Ethics Principles, while only 29 per cent had implemented the corresponding practices. The report describes the resulting 49-point gap as “a substantial say-do gap between the perception of responsible AI practices and their actual implementation”.
That is a governance finding, but the pattern generalises. Organisations consistently believe themselves more ready than their own practices demonstrate, which is exactly what an evidence-based assessment exists to correct.
On what actually causes failure, the strongest available evidence points at organisational rather than technical causes. RAND Corporation’s study of 13/08/2024, drawn from 65 practitioner interviews, found that failures driven by the decisions and expectations of business leadership were “far and away the most frequent causes of project failure”, with 84 per cent of interviewees citing one or more leadership-driven causes as the primary reason. McKinsey’s State of AI survey of 05/11/2025 found that organisations getting the most from AI were nearly three times as likely to have fundamentally redesigned the workflows the technology sits inside.
The National AI Centre’s adoption tracking for December 2025 to February 2026, published 07/05/2026 and conducted by Fifth Quadrant across a minimum of 400 SME decision-makers per wave, found the barriers among non-adopters to be almost entirely non-technical: around 65 per cent cited distrust of AI decision-making or a strong preference to maintain human control, 54 per cent said AI was not relevant to their business, and 19 per cent said they simply did not know how to use it.
Nothing in the evidence suggests organisations fail at AI because they chose the wrong technology. That is why, in the framework below, technology carries the lightest weight rather than the heaviest.
| # | Dimension | Weight | The question it answers |
|---|---|---|---|
| 1 | Strategic clarity and sponsorship | 15% | Does the organisation know what it wants AI to do, and is a named executive accountable for it? |
| 2 | Process maturity and workflow readiness | 20% | Are the processes an AI initiative would sit inside documented and stable enough to redesign? |
| 3 | Data quality and accessibility | 20% | Can the organisation answer questions about its own operation without manual assembly, and is the underlying data owned and accurate? |
| 4 | Technology foundations | 10% | Do the systems allow information to move between them without human retyping, and can new capability be introduced without disproportionate effort? |
| 5 | Governance and risk | 10% | Could the organisation answer a board or regulator on what AI it uses, who approved it and how it is controlled? |
| 6 | People and capability | 15% | Do the people who would use, question and maintain an AI-supported process have the skills and the standing to do so? |
| 7 | Change capacity | 10% | Given everything already underway, does the organisation have the bandwidth and the track record to land another change? |
The weightings are published here in full because a framework whose weights are hidden cannot be argued with, and a framework that cannot be argued with is not a method.
The test is not whether a strategy document exists. It is whether a named executive is accountable for AI outcomes, whether something is written down that constrains what will and will not be attempted, and whether that person’s accountability survives contact with a competing priority. RAND’s finding that leadership decisions dominate failure is the reason this dimension is weighted above technology and governance.
One of the two heaviest weights, and one of the two most often binding. The question is whether the processes an initiative would sit inside are documented, stable and understood well enough to be redesigned deliberately. A process that exists differently in three regions, or only in the heads of the people performing it, cannot be improved by automation. It can only be made faster in whichever of its forms happens to get encoded.
The other heaviest weight, and deliberately framed as an operational question rather than an architectural one. The test is whether someone can answer a question about the organisation’s own operation without a person assembling a spreadsheet first, whether the data has a named owner, and what happens when it is found to be wrong. Organisations with impressive data architecture frequently fail this test, and organisations with unglamorous systems frequently pass it.
Lightest weight, and the weighting is the argument. What is assessed is whether information moves between systems without human retyping, and whether new capability can be introduced without disproportionate effort. That is an integration and extensibility question, not a question about which platform was chosen. Weighting this dimension heavily would produce a score that flatters exactly the organisations most likely to stall.
The practical test is whether the organisation could answer a board or a regulator on three points: what AI it currently uses, including tools adopted by teams without approval, who approved each one, and how each is controlled. Most organisations discover during this dimension that the honest answer to the first point is longer than anyone expected.
Weighted equal to sponsorship, and frequently underestimated. The question is not whether staff have completed AI training. It is whether the people who would use, question and maintain an AI-supported process have both the skills and the standing to challenge a number a system produces. Standing matters as much as skill. An analyst who can see that an output is wrong but cannot get the process stopped is not a control.
The simplest question and the one most often skipped: given everything already underway, could this organisation land another change? It is assessed on current program load, on the track record of the last two or three significant changes, and on whether the people who would absorb this one are the same people absorbing the others. A high score everywhere else combined with no capacity here produces a clear and useful answer, which is not yet.
A maturity score is only as good as what it rests on, and in most assessments that provenance is invisible. Every score in a C-Insight readiness assessment carries an explicit rating noting whether it is supported by documents, by corroboration from multiple independent sources, or by a single uncorroborated account.
This has two effects worth naming. It stops a confident interviewee from setting a score on their own, which is otherwise the most common distortion in this kind of work. And it gives the organisation a defensible basis for disagreeing: a finding rated on a single account can be challenged on its evidence rather than on its conclusion, which is a much healthier argument to have in front of a board.
The assessment runs over two to three weeks and involves eight to sixteen interviews. The output that gets used is not the weighted score, it is the prioritised gap list: the ten to fifteen gaps that have to be closed, in the order they have to be closed. A score is a conversation opener. An ordered list is something an executive team can act on next quarter.
The boundary is as important as the method, and it is stated before the work starts rather than discovered afterwards. A readiness assessment looks inward at capability. It does not look outward at value. It does not identify AI opportunities, put a dollar value on anything, build a business case, or evaluate, score or recommend any technology, platform or supplier.
An organisation can be entirely ready and have nothing worth doing. It can have substantial opportunity and be entirely unable to execute. Selling those two as one product understates both, which is why C-Insight keeps them apart.
There is one further test, and it is worth applying to any readiness assessment regardless of who performs it. The assessment must be permitted to conclude that AI is not yet warranted. If the method cannot reach that conclusion, the conclusion it does reach carries no information, because it was determined before the work began. Publishing the dimensions and their weights before the engagement starts is the other half of the same principle.
Take the seven dimensions above. Score each one honestly out of five against your own organisation, then ignore the average entirely and look at the lowest two. Those are your binding constraints, and everything else is context.
In most organisations the lowest two are process and data. In most organisations they are not the two the leadership team expected, which is usually the most useful thing the exercise produces. If your own rough scoring and your executive team’s rough scoring disagree, that disagreement is the finding.
We will walk the seven dimensions with you and give an honest read, including telling you when an assessment is not warranted. Nothing to complete beforehand.