Skip to main content

    Losing leads after hours or waiting too long to follow up? Find out where revenue may be slipping through the cracks. Get a Missed-Revenue Assessment

    Blkfriars LLC
    Calculators and Assessments

    A Practical AI Readiness Checklist for SMBs

    Assess your small business's AI readiness across strategy, processes, data, systems, security, people, governance, and measurement before investing in implementation.

    Calculators and Assessments Small Business Owners 12 min read Last updated: August 2026
    By Jason / Blkfriars

    A business does not become “AI ready” because employees have ChatGPT accounts or because the company has budget for a new platform.

    Readiness means the organization has enough clarity, data, process discipline, technical access, security, governance, employee capacity, and measurement capability to implement a defined AI use case without creating more problems than it solves.

    That distinction matters for SMBs. OECD's 2026 D4SME survey found rapidly growing AI uptake among participating SMEs, but most AI-using respondents remained “AI novices” relying on relatively simple off-the-shelf tools for isolated tasks. Strategic, targeted, and secure integration remained uneven, while maintenance costs, limited training time, and skills gaps continued to hinder implementation. U.S. Census data likewise show that business AI adoption remains concentrated: 57% of AI-using firms reported deployment in three or fewer business functions.

    This checklist is designed to answer a practical question:

    Is your business ready to pilot AI in a specific workflow—and if not, what needs to be fixed first?

    It is not an industry certification or regulatory standard. It is a Blkfriars practical readiness framework informed by current SME adoption evidence and NIST risk-management principles.

    How to Score the Checklist

    Score each statement:

    • 0 = No / not established
    • 1 = Partly / inconsistent
    • 2 = Yes / clearly established

    There are eight readiness areas with five questions each, for a maximum of 80 points.

    A high score does not override a serious risk issue. For example, a company can have excellent systems and data but still be unready for a use case involving sensitive information if access controls and governance are weak.

    Interactive Readiness Assessment

    Use the interactive assessment below to score each question. Your running total and readiness band update automatically. No contact information is required to view your results.

    Your Readiness Score
    0 / 80
    0 of 40 questions answered
    Do not rush the implementation

    The technology is likely to outrun the operating environment. Start with business-process and digital-readiness work.

    1. Strategy and Business Value

    0 / 10

    We can name the specific business problem AI is intended to improve.

    We know why AI may be preferable to ordinary automation or process redesign for this use case.

    We have a measurable target such as time, cost, quality, response, conversion, or capacity.

    The use case has an identifiable owner responsible for the business outcome.

    The expected value is meaningful enough to justify implementation and maintenance.

    Strong readiness signal: The project begins with an operating problem, not a tool demo.

    NIST's “Map” function emphasizes defining intended purpose, context, expected users, benefits, risks, and system boundaries before deployment.

    2. Process Readiness

    0 / 10

    Employees can consistently explain the current workflow.

    We know the trigger, inputs, handoffs, approvals, exceptions, and desired output.

    The process is reasonably stable rather than changing every week.

    We know which steps are deterministic and which require judgment.

    We have identified the smallest safe portion of the workflow to pilot.

    Strong readiness signal: The business can draw the process before asking software to automate it.

    Poorly understood or constantly changing processes often need redesign before automation.

    3. Data and Knowledge Readiness

    0 / 10

    The information required for the use case is accessible and current enough.

    Data fields and terminology are reasonably consistent.

    We know who owns the data and who is allowed to use it.

    We know whether the use case includes personal, confidential, regulated, or proprietary information.

    Customer-facing knowledge has an approved source of truth.

    Strong readiness signal: The AI will not have to guess which document, spreadsheet, or employee memory is authoritative.

    NIST recommends mapping data and third-party software risks, documenting controls, and evaluating the quality and suitability of information used by AI systems.

    4. Systems and Integration Readiness

    0 / 10

    We have inventoried the CRM, calendar, phone, email, forms, accounting, storage, and other systems involved.

    We know which systems provide APIs, webhooks, or reliable integrations.

    System owners and required credentials are identified.

    We know which systems the AI may read from and which it may write to.

    We have a fallback if an integration or vendor becomes unavailable.

    Strong readiness signal: The business understands the complete workflow architecture, not only the model.

    5. Security, Privacy, and Access Readiness

    0 / 10

    AI access follows least-privilege principles.

    Sensitive data is clearly identified and handled under defined rules.

    We know where AI inputs, outputs, logs, and transcripts are stored.

    Vendor data-retention and model-training practices have been reviewed.

    We have logging, monitoring, credential-revocation, and incident-response procedures appropriate to the use case.

    Strong readiness signal: The system has only the access it actually needs.

    For agentic AI, CISA and international partners recommend limiting autonomy and sensitive-system access, using strong identity management, performing threat modeling, and continuously monitoring behavior.

    6. People and Change Readiness

    0 / 10

    Employees understand why the AI project is being introduced.

    The people closest to the workflow have participated in process mapping or testing.

    Training time and ownership are built into the implementation plan.

    Employees know when to rely on the system and when to override or escalate.

    The redesigned workflow gives employees a clear role rather than leaving responsibility ambiguous.

    Strong readiness signal: The team can explain how work will change after implementation.

    OECD research identifies skills gaps and lack of time for training as persistent SME implementation barriers. U.S. Census data also show that most AI-using firms currently use AI primarily to augment tasks rather than as a simple replacement for workers.

    7. Governance and Human Oversight Readiness

    0 / 10

    A person or role is accountable for the AI system after launch.

    Approval and escalation thresholds are documented.

    We know which decisions the system is not allowed to make independently.

    Third-party providers and model dependencies are documented.

    There is a process for reporting, reviewing, correcting, and learning from AI errors.

    Strong readiness signal: Human oversight is defined as a process, not merely promised.

    NIST's Govern, Map, Measure, and Manage functions treat accountability, oversight, third-party risk, testing, monitoring, incident response, and continual improvement as lifecycle responsibilities.

    8. Measurement and ROI Readiness

    0 / 10

    We have baseline metrics for the current process.

    We have defined what success will look like after the pilot.

    We can distinguish hard savings, capacity released, cost avoidance, and revenue impact.

    We will measure errors, exceptions, and human corrections—not only successful runs.

    We have a review date for deciding whether to expand, revise, or stop the system.

    Strong readiness signal: The company can measure the process before and after AI.

    Without a baseline, ROI becomes a story rather than an analysis.

    Not Sure What to Automate First?

    Use your own business assumptions rather than somebody else's headline statistic.

    Request My AI Opportunity Audit

    Critical Red Flags That Override the Score

    Even a high total score should not produce an automatic “go” decision when a serious issue exists.

    Examples include unclear permission to use sensitive data, unrestricted agent access to financial or customer systems, no human escalation for consequential decisions, no owner accountable for system behavior, no reliable source of truth, or no way to disable the system when it behaves incorrectly.

    NIST's risk-management approach is context-based for exactly this reason: not every risk can be averaged into a single score.

    What to Do With the Results

    Do not begin by fixing every low score across the company.

    Choose the specific workflow you want to improve and focus readiness work there. A business may be unready for an autonomous customer-service agent but perfectly ready for a contained internal workflow that summarizes meetings and creates draft CRM notes for human review.

    The goal is not “become an AI-ready company” all at once.

    The goal is to create enough readiness around one valuable use case that the business can pilot it safely, measure it honestly, and learn from the result.

    A 30-Day Readiness Sequence

    A practical first month can look like this:

    Week 1Identify candidate processes and define measurable problems.
    Week 2Map the leading process, data sources, integrations, and exceptions.
    Week 3Evaluate vendors/architecture, security, human oversight, and pilot scope.
    Week 4Establish baseline metrics, test cases, training plan, and go/no-go criteria.

    At the end of that sequence, the business should know whether it is ready to implement—or whether the next investment should be process cleanup instead.

    The Bottom Line

    AI readiness is not one thing.

    It is the combined readiness of the business problem, process, data, technology, security, people, governance, and measurement system around a specific use case.

    The strongest SMB implementation starts when the company can answer four questions clearly:

    What are we trying to improve? What information and systems does the solution need? Where must humans remain responsible? How will we know whether the process actually improved?

    If those answers are strong, AI can be evaluated as a practical operating tool. If they are weak, the most valuable first project may be process redesign, data cleanup, better integrations, training, or ordinary automation.

    That is not a delay in AI strategy. It is the foundation of one.

    Turn the Scorecard Into an Implementation Roadmap

    Identify which workflows are actually worth automating, where AI adds value, where conventional automation is enough, and where human oversight should remain.

    Explore Workflow Automation

    Automate the Right Process First

    Blkfriars helps small and midsize businesses identify where AI, automation, and process improvement can produce measurable business value.

    Sources & References

    OECD, Empowering SMEs in the Age of AI: The 2026 D4SME Surveyhttps://www.oecd-ilibrary.org/en/publications/empowering-smes-in-the-age-of-ai_bf5a9816-en.html
    U.S. Census Bureau, The Microstructure of AI Diffusionhttps://www.census.gov/library/working-papers/2026/adrm/CES-WP-26-25.html
    U.S. Census Bureau, Large Firms With at Least 20 Employees Biggest AI Usershttps://www.census.gov/library/stories/2026/05/ai-use-businesses.html
    NIST, AI Risk Management Framework Corehttps://airc.nist.gov/airmf-resources/airmf/5-sec-core/
    NIST, AI Use Taxonomy: A Human-Centered Approachhttps://www.nist.gov/publications/ai-use-taxonomy-human-centered-approach