Data
Connect the systems of record AI has to reach, so a full picture stops depending on someone pulling from three or four places.
Process
Document, version, and assign an owner to the core processes first. A firm cannot automate a process it cannot describe.
Governance
Name one accountable AI owner with budget and authority, and tie this year’s AI spend to named business outcomes with leadership checkpoints.
Security
Provision AI access through IT, enforce your data-usage guardrails technically rather than on paper, and log what flows through which model.
Adoption
Get a real number on what you own versus what people use, then move enablement from tool demos to workflow redesign by role.
Measurement
Baseline the metric you expect to move (cost, cycle time, or revenue) before the next rollout, and review it on a cadence.
Where does the data AI would need to work from actually live?
In connected systems of record, or scattered across spreadsheets, inboxes, and people’s heads at {company}?
Mostly in people’s heads and local files. There is no single place you would point to.
In systems, but siloed. Getting a full picture means someone manually pulling from three or four places.
Core systems of record are in place and current, though some functions still run on side spreadsheets.
Connected systems of record with governed access, and we can reach the data without a person in the middle.
How well documented are your core processes today?
If a key person left tomorrow, how much could someone else pick up from documentation alone?
Very little. The process is whatever that person does.
Some documentation exists, but it is out of date and nobody uses it day to day.
Core processes are documented and mostly followed, with variation between teams.
Documented, versioned, owned by someone, and actually used when we onboard people.
Who owns AI within the firm?
Is there a single accountable person, or is it spread across whoever happens to be interested?
Nobody. It comes up in conversation, and then it does not.
A few interested people pushing it in their own corners, with no mandate.
Someone owns it informally, on top of their real job, without budget or authority.
A named owner with a mandate, a budget, and a seat where decisions get made.
How is AI showing up in your budget and plans this year?
{first_name}, this one tells us the most: a funded priority tied to specific goals, or a leadership conversation with nothing behind it yet?
It is a conversation. There is no line item and no owner.
Some discretionary spend on tools, nothing tied to a stated business goal.
There is budget this year, though the goals it is tied to are still broad.
Funded, tied to named outcomes, with checkpoints leadership actually reviews.
How much of the AI capability you already pay for is actually being used?
Do you know what you own versus what people actually touch?
We would have to go find out. Nobody tracks that.
We know what we bought. We do not know who uses it, or how often.
We can see usage data, and a meaningful share of seats sit idle.
We track utilization by team, and we reallocate or cut seats based on it.
What does it look like today for a staff member to access an AI model?
Is it sanctioned and provisioned, or are people quietly using personal accounts?
Personal accounts, often on personal devices, with no visibility on our end.
A mix. Some sanctioned tools, plus whatever people signed up for themselves.
Provisioned through IT, though it sits beside the systems people actually work in.
Provisioned, access controlled, and integrated into the tools people already use.
Do you have data usage guardrails and safe usage policies your staff have actually been trained on?
Or do they exist mostly on paper at {company}?
Neither exists yet.
A policy exists somewhere, and most people have not read it.
Policy is written and communicated, though enforcement depends on people remembering.
Policy is enforced technically, with controls that stop the wrong data from moving.
When client or regulated data touches an AI system, can you reconstruct what flowed through which model, and who touched it?
Think logging, retention, and whether anyone actually reviews it.
No. We would not know where to start.
Partially, and only for the tools we officially provisioned.
Yes for sanctioned tools. Logging exists, though it is rarely reviewed.
Yes, logged, retained, and reviewed on a schedule. It would hold up to an audit.
Is your training getting people past surface level usage?
Past drafting an email, and into actually redesigning how their work gets done?
No training. People figure it out on their own, or they do not.
One time tool demos. Usage is mostly drafting and summarizing.
Role specific training, with a handful of people redesigning real workflows.
Ongoing enablement by role, workflow redesign as the expected outcome, champions spreading what works.
Do you have internal benchmarks that measure the business outcome shift from AI?
Not just adoption numbers like seats used.
No measurement of any kind.
We track adoption, seats and logins, and nothing downstream.
We have anecdotes and rough time saved estimates, without a baseline to compare against.
Baselined metrics tied to cost, cycle time, or revenue, reviewed on a cadence.
Nascent
AI is likely already in use whether or not it was sanctioned, with no line of sight into where or with what data. That exposure is the immediate risk, ahead of any question about value.
Find out what is actually in use today, and put a data-usage boundary around it before anything else gets built.
Developing
Real activity driven by a few motivated people, none of it connected to a plan. The firm pays for capability it cannot account for, and the wins stay stuck with the person who found them.
Name an owner, get a real number on what is owned versus used, and pick one function to do properly instead of five halfway.
Operational
The basics are in place: policy exists, access is provisioned, someone is accountable. What is missing is depth. Usage is still mostly surface level, and the firm cannot yet prove the business is different because of it.
Move from tool training to workflow redesign in one function, and baseline the metric you expect to move before you start.
Advanced
The firm has the foundation most are still missing: documented process, reachable data, real governance, people going past drafting emails. The gap now is consistency across functions, not capability.
Take what is working in the strongest function and make it the pattern the rest of the firm is held to.
AI Forward
Past adoption and into advantage. Data is reachable, guardrails are enforced rather than written, and leadership can point at what changed in the business. Most firms never get here.
The frontier is what you build rather than what you buy: custom systems on top of the foundation already in place.