Most companies we talk to are somewhere in the same spot. Somebody on the leadership team has been told AI should be doing something here. A few people are already using it on their own. A vendor or two has sent a quote. And nobody can say, with any confidence, where it would actually pay, where it would be a liability, or what to do first.
That is the question an AI audit is supposed to answer. The industry calls it an AI readiness assessment, and the name has been stretched to cover everything from a survey with a score at the end to a months-long consulting engagement. So it is worth being specific about what a useful one looks at, and what you should walk away holding.
It starts with the work, not the tools
The most common mistake in AI spending is starting with a tool somebody demoed. A good assessment starts with the work instead: what arrives, who touches it, how often it comes back wrong, and how many hours it quietly eats.
That means time with the people who actually do the job, not just the people who manage it. The opportunity is almost never where the org chart suggests. It tends to hide in the handoffs, the re-typing between systems, the report somebody assembles every week because nobody ever automated it, and the follow-up that only happens when someone remembers.
The output of this step is a map: the repeatable work, roughly what it costs today, and what a mistake in it would cost.
Then the data
An agent can only act on what it can see. So the next question is whether the information each task depends on actually exists, where it lives, what shape it is in, and what a system would need access to in order to use it.
This is where most stalled pilots stall. Not on the model, but on the fact that the customer history is split across three systems, or the pricing lives in one person’s spreadsheet, or the records are complete for the last two years and patchy before that. A useful assessment names those problems plainly, because they decide which opportunities are real this quarter and which ones need groundwork first.
Then the limits
This is the part that separates an audit from a sales pitch. Before anything is scoped, somebody has to write down what AI must never touch in your business.
That list usually includes regulated data, client contracts, anything that speaks for you in a hard moment, and any decision where a wrong answer is expensive. If you work in a regulated field, it also means understanding what your regulator, your insurer, and your clients would expect, which we covered in more depth in AI and compliance.
Naming the limits early is not caution for its own sake. A guardrail added after something goes wrong is an incident report. A guardrail written first is just a design decision.
Then the team
Every agent changes somebody’s day. The assessment should say whose, and how. Who owns the output? Who reviews the exceptions? Who notices if it drifts? If nobody has an answer, the pilot will die quietly no matter what it cost to build.
This is also where an honest assessment sometimes concludes that a company is not ready yet. The data is not there, the process is still changing every month, or nobody has the time to own the result. That is a legitimate finding, and a cheaper one to hear before a build than after.
What you should walk away with
Not a deck of maturity curves. A decision you can defend to a board, a partner, or yourself. In practice that means three things.
A ranked list, with a number. Every opportunity found, ordered by payback, with what the first one should cost and return. Just as important, the ones that were deliberately left alone, and why.
A sequence. First, next, later, and what has to be true before each one starts. Not a shopping list of tools.
The guardrails, in writing. Scope, approval, retention, and audit, defined before anything runs.
If an assessment hands you a score and a list of tools to buy, it answered a different question.
How Wave runs it
Our AI Readiness Assessment follows exactly that order: the work, the data, the limits, and the team. It is fixed in scope and price, it takes weeks rather than quarters, and it is run by the same in-house team that would build whatever comes next. That last part is why the answer is sometimes that you should not build anything yet.
What we need from you is time with the people who do the work and a look at the systems it happens in, not a data export on day one. What you get is the ranked list, the sequence, and the guardrails, and you own those findings whether or not you ever work with us again. An assessment you can only act on with one vendor is a sales document.
Afterward there are three doors. Build it, and we scope the first piece for our AI Workforce to run. Get a leader, and a Fractional CAIO owns the sequence for a while. Or do nothing yet, and leave with the reasoning and the number.
If you are weighing where AI fits in your business, book a call with a senior member of the team. We will tell you honestly whether an assessment is worth running at all.



