AI Readiness Assessment
An evidence-backed read on where your AI estate sits today.
Who this is for
Organisations that have deployed AI in production but cannot yet answer 'what AI is running, where, against what data, with what risk?'. The output is what you take to your board, your auditors, or your CEO when they ask.
Typical buyers: CISO · CCO · Chief AI Officer · Head of Risk
What we do, week by week
No status decks. Every meeting ships an artefact.
Discovery
Stakeholder interviews · existing inventory pull · shadow-AI scan across cloud accounts + SaaS · evaluator-fleet baseline run.
Risk scoring
Score every discovered AI system across the six TSGRC&S pillars · map to your regulatory exposure (EU AI Act / NIST AI RMF / sector framework).
Roadmap synthesis
Prioritise gaps by risk × effort · draft 90-day roadmap · executive readout deck.
Delivery + handover
Walkthrough with your team + executive readout · Infrarails platform trial environment provisioned with your real baselines loaded.
What you receive
Concrete artefacts you can show your board, your auditors, your CEO.
AI Estate Map
PDF + interactive Infrarails dashboard. Every AI system in your org, where it lives, what data it touches.
Infrarails Trust Score baseline
Per-system + organisation-wide score across Trust / Safety / Governance / Security / Compliance.
Top-10 Gap Report
Each gap tied to a regulatory citation + risk impact + recommended remediation.
90-day Roadmap
Sequenced workstream plan, owners, dependencies, and success metrics.
Deliverables checklist:
- AI system inventory with shadow-AI discovery
- Infrarails Trust Score baseline across six TSGRC&S pillars
- Top-10 gap report mapped to your regulatory exposure
- 90-day prioritised roadmap
Frequently asked
How is this different from a vendor security audit?+
Vendor audits look at vendor security controls. We look at your AI behaviour: what models run where, what data they see, what verdicts they produce, where regulators will care. The two are complementary; we recommend running both.
Do I need to deploy Infrarails platform first?+
No. The assessment runs against your existing stack. The Infrarails platform trial environment is provisioned at handover so you can carry the baseline forward — but it's optional.
What if we have no AI in production yet?+
Then you don't need this package — you need the AI Governance Framework Design package, which builds the policies and controls before you ship.
Related packages
Often paired with AI Readiness Assessment.
AI Governance Framework Design
Design the policies, controls, thresholds, and approval workflows your organisation needs to operate AI responsibly at scale.
See packageRegulatory Readiness Program
End-to-end program to get audit-ready against EU AI Act, NIST AI RMF, ISO 42001, HIPAA-AI, SOC 2-AI, DPDPA, FCA, or your sector framework.
See packageReady to scope?
60-90 minute scoping call. Free. Walk through your situation; we'll tell you honestly whether this package fits or whether a different one would land better.