AI Readiness Self-Assessment

A 25-question self-assessment to figure out where your organization stands on AI adoption. Five domains, five questions each, scored 0–2. Total possible: 50. The total matters less than seeing which domain scores lowest — that’s where to spend the next 90 days. Last reviewed: May 25, 2026.

How to Score

For each question, score:

One person can fill this out, but the assessment is more accurate if at least two people score separately and compare. Differences in scores are themselves useful data.

Domain 1: Governance

  1. We have a written AI Use Policy adopted by our board (or equivalent governing body).
  2. One named person is accountable for AI decisions in our organization.
  3. Staff know who to ask before using a new AI tool for organizational work.
  4. We have a written list of AI uses that are prohibited under any circumstances.
  5. Our board reviews AI use at least annually and is informed of incidents.

Domain 1 subtotal: ___ / 10

Domain 2: Data

  1. We can name our data classes (Public, Internal, Confidential, Sensitive / Regulated) and which kinds of organizational data fall into each.
  2. Staff know what they may and may not paste into a consumer-tier AI tool.
  3. Any AI tool used for Sensitive / Regulated data has a written data-handling commitment (BAA, DPA, or equivalent) on file.
  4. We have a documented retention period for AI inputs and outputs used in our work.
  5. If a participant asked us to delete all records that involved AI processing, we could identify and act on them.

Domain 2 subtotal: ___ / 10

Domain 3: Capacity

  1. At least one person on staff has used AI tools long enough to know their failure modes (hallucinations, plausible-but-wrong outputs, format drift).
  2. Staff who use AI in their work have received training on our AI Use Policy within the past year.
  3. We have a small prompt or workflow library (even informal) that another staff member could pick up and use.
  4. When something goes wrong with an AI output, staff know how to escalate.
  5. We have a defined human-review step for any AI-assisted work product that leaves the organization.

Domain 3 subtotal: ___ / 10

Domain 4: Compliance

  1. If we charge AI tool costs to a federal award, we have a written allocation methodology in place before the first charge (per 2 CFR 200.405).
  2. Any AI use that touches HIPAA, FERPA, or other regulated data has been reviewed against the applicable rule.
  3. We have a disclosure standard for telling participants when AI is used in work that affects them.
  4. If a monitor or auditor asked how an AI tool subscription benefits a specific funded activity, we could produce documentation within five minutes.
  5. We have a written incident-reporting procedure for AI-related issues.

Domain 4 subtotal: ___ / 10

Domain 5: Tool Selection

  1. We have a written list of approved AI tools, by use case and data class.
  2. Before approving a tool, we evaluate its data-handling commitments (training-on-inputs, retention, deletion, subprocessors).
  3. We have a written process for staff to request approval of a new tool, including timing expectations.
  4. We review vendor agreements with attention to AI-specific terms (training data, retention, deletion, indemnity).
  5. We periodically review whether tools on the approved list are still meeting their commitments.

Domain 5 subtotal: ___ / 10

Total Score: ___ / 50

Add the five domain subtotals.

Interpreting Your Score

90-Day Action Plan

Take the lowest-scoring domain and use the matching plan below.

If Governance scored lowest

If Data scored lowest

If Capacity scored lowest

If Compliance scored lowest

If Tool Selection scored lowest

After 90 Days

Re-score the assessment. Compare to your starting score. The point isn’t a perfect 50 — it’s a board, a staff, and a process that all match. Then pick the next lowest domain and repeat.


Use this assessment with the full Resources hub. Templates only — not legal advice.