Skip to content
Tools

AI readiness assessment

Ten questions on data, governance, appetite and constraints. It returns one named engagement, a scoped build, or no engagement at all, and it shows the rule that produced the answer. Four of the fourteen rules recommend buying nothing.

Ten questions

Answer them about the situation you are actually in rather than the one in the plan. Nothing is sent anywhere: the result is worked out in your browser and the only record is the link in the address bar.

0 of 10 answered.

01Appetite

What exists today?

The honest current state, not the state of the plan.

02Data

What state is the content in that the system would have to read?

Contracts, policies, claims files, case law, manuals, tickets: whatever holds the answers.

03Data

For a typical question, is there a right answer somebody could mark?

This decides whether the system can be evaluated at all. Without it there is no build gate and no audit.

04Data

How do you know how often the system is wrong?

If nothing is deployed, answer for what you would do.

05Governance

Who signs off that an output is correct before it is used?

A named role, not a team. If the answer is nobody, that is a real and common answer.

06Governance

Is there a written AI use policy staff can actually follow?

Followable means it has approval routes and exception routes, not just prohibitions.

07Constraints

Do you put AI outputs in front of people in the EU, or plan to within twelve months?

Customers or staff. Where your company is based does not decide this; where the people are does.

08Constraints

Has a customer, insurer or regulator asked you for an attestation?

SOC 2 Type II, ISO/IEC 42001, or a security questionnaire that names one of them.

09Appetite

What happens when the answer is wrong?

The specific consequence, and who carries it.

10Constraints

Who runs this after it is handed over?

Every AI system is an operated system. Content goes stale and models get deprecated.

The address bar updates as you answer, so the result is shareable by sending it.

Recommendation

Nothing answered yet

Ten answers produce one recommendation, and sometimes that recommendation is to buy nothing.

Nothing is inferred on your behalf and no answer is pre-selected. A partial result would be a guess with a confident typeface on it, which is the exact failure mode this whole site is about.

The possible outcomes are one of nine fixed-scope engagements between $2,500 and $8,900, a scoped build from $18,000, or no engagement at all. Four combinations of answers return the last one, and two of those tell you to stop and fix something cheaper first.

What is being asked

Four dimensions, ten questions, no filler.

Readiness questionnaires are usually long because length reads as rigor. These ten are the ones whose answers change the recommendation; anything that could not change it was cut.

Data

Questions 2, 3 and 4

Whether the content is machine-readable, whether a typical question has a right answer somebody could mark, and how you currently know how often the system is wrong. This dimension decides whether anything downstream is possible at all: a corpus that cannot be read cannot be retrieved from, and a system with no markable answer cannot be evaluated, audited or gated.

Governance

Questions 5 and 6

Whether a named person signs off that an output is correct before it is used, and whether staff have a policy they can actually follow. Two questions rather than ten, because the rest of a governance program is downstream of these and inspecting the rest first tells you very little.

Appetite

Questions 1 and 9

How far along you already are, and what it costs when the answer is wrong. Stakes are the load-bearing input on this whole page. They are what pays for accuracy work rather than merely wanting it, and they are the reason two organizations with identical architectures get different recommendations.

Constraints

Questions 7, 8 and 10

EU exposure, whether anyone has demanded an attestation, and who operates the system after handover. The first two create deadlines that outrank everything voluntary. The third is the one people skip: an unowned system degrades quietly, because content goes stale and models get deprecated whether or not anyone is watching.

The rule set

Every rule, in the order it is evaluated.

The first rule that matches produces the answer. There is no weighted score deciding anything behind this, and nothing here is different from what the tool runs. If your scripts are blocked, you can read your own answer straight off this table.

The fourteen rules the AI readiness assessment evaluates, in order, with the recommendation each produces and the reasoning behind it.
RuleWhenRecommendationReasoning
01You are about to buy an AI system from a vendorVendor AI assessment, $2,500, three daysThe signature is the deadline, not the launch. This is the smallest thing we sell and it is the only moment the questions are cheap to ask.
02Nothing is deployed, nothing happens when the answer is wrong, no EU exposure, no attestation demandedNo engagementAssurance work prices risk. Where there is no consequence there is no risk to price, and a build has no saving to pay it back.
03Nothing is deployed and the content is scanned paper, handwriting, photographs, or nobody has lookedNo engagementRetrieval reads text. Every engagement we could sell would spend its first week discovering that, at our day rate. This is an ingestion problem with its own vendors.
04A customer or regulator has named an attestation, and governance is already strongISO/IEC 42001 gap assessment, $8,900, two to three weeksA named owner and a current policy mean the foundations the standard assumes exist, so a control-by-control gap list will be short enough to act on.
05A customer or regulator has named an attestation, and governance has gapsAttestation readiness scoping, $3,900, one weekFind out what the certification actually costs in weeks and money before committing to it. Starting a program on weak governance is how they run over.
06You put AI outputs in front of people in the EU today, and something is deployedEU AI Act readiness assessment, $4,900, one weekThe Act attaches to the system in use, not to where the company is registered. This is the obligation with a date on it, so it outranks voluntary framework work.
07You run agents that take actions in other systemsAgent governance review, $7,900, two weeksThe failure mode is no longer a wrong answer, it is a wrong action that has already happened. Kill switches, audit trails, human decision boundaries, model change control.
08A live retrieval system whose error rate is not measuredHallucination and grounding audit, $5,900, two weeksTuning an unmeasured system is not engineering, because every change looks like an improvement to whoever made it. This produces a rate and a golden set you keep.
09A live retrieval system that is already measured against a golden setRAG system diagnostic, $5,500, one to two weeksThe question is no longer whether it fails but where: chunking, embedding, index, retrieval, reranking or generation. Each has a different fix and they are routinely confused.
10A pilot, and a wrong answer harms someone or moves moneyAI security assessment, $6,500, two weeksA security review is the next gate between that pilot and production, and it is where these projects stall for months. Prompt injection, data exfiltration, agent authority.
11A pilot, and a wrong answer is an annoyanceNo engagementHave an expert mark fifty real answers and write down how many were wrong. That number decides everything after it, and you can produce it more cheaply than we can.
12Nothing deployed, real stakes, machine-readable content, a markable right answerA scoped build, from $18,000The consequence pays for accuracy work and the golden set can exist, which is what turns accuracy from an opinion into a build gate. We decline builds with no evaluation set.
13Something deployed, no external deadline, governance has gapsNIST AI RMF alignment review, $7,500, two weeksGovern, map, measure and manage, scored against current practice rather than intent. A framework that organizes the work, since nothing is forcing a specific standard.
14Anything else: deployed, owned, policied, and nobody is asking for a standardNo engagementNone of the nine engagements has an obvious question to answer, and we would rather say so than pick the nearest one.
Two things we will not do

We do not issue certifications

ISO/IEC 42001 certificates come from accredited certification bodies and SOC 2 attestations from licensed CPA firms. No consultancy issues either, and any that implies it can is telling you something useful about itself. Our work is gap assessment, control design and evidence preparation, which prepares you for those audits and does not replace one. MetaMinds does not itself hold SOC 2 Type II or ISO/IEC 42001.

We do not take builds with no way to prove they work

Rule 12 requires a markable right answer for a reason. Without an evaluation set there is no way to show a system is correct, no way to catch it degrading, and no honest way to sign off the handover. That is a scope we would rather decline than deliver.

Questions

About the assessment itself.

These answers are the same ones in the structured data on this page, so an answer engine quoting us quotes this.

What is an AI readiness assessment?
A structured check of whether an organization can build or operate an AI system responsibly, covering four things: whether the data is machine-readable and evaluable, whether a named person owns the output, how much a wrong answer costs, and what external obligations and operating capacity exist. This tool asks ten questions across those four dimensions and returns a specific next step rather than a score.
Can this assessment tell me not to buy anything?
Yes, and four of the fourteen rules do exactly that. Nothing deployed and no consequence when the answer is wrong returns no engagement. Content that is not machine-readable returns no engagement, because retrieval reads text and no audit changes that. A pilot with low stakes returns no engagement. A well-governed deployed system with no external deadline returns no engagement. In each case the page says what to do instead and what would change the answer.
How is the recommendation calculated?
By fourteen named rules evaluated in a fixed order, not by a weighted score. Rules are ordered by urgency: an imminent vendor signature outranks everything, then hard blockers, then a named attestation demand, then live EU exposure, then the architecture you have deployed. The first rule that matches produces the recommendation. The four dimension percentages shown alongside are a readout of where you are thin; they do not select the outcome.
Does MetaMinds certify ISO/IEC 42001 or SOC 2?
No. ISO/IEC 42001 certificates are issued by accredited certification bodies and SOC 2 attestations by licensed CPA firms. No consultancy can issue either. MetaMinds delivers gap assessment, control design and evidence preparation, which prepares you for those audits. MetaMinds does not itself hold SOC 2 Type II or ISO/IEC 42001, which is stated here rather than left to be discovered in diligence.
Which engagement does the assessment recommend most often?
It depends entirely on what you have deployed. A live retrieval system with no measurement routes to the hallucination and grounding audit at $5,900. The same system with a golden set routes to the RAG system diagnostic at $5,500, because the question changes from whether it is failing to which pipeline stage causes it. Agents that take actions route to the agent governance review at $7,900. An imminent vendor purchase routes to the vendor AI assessment at $2,500.
Are my answers sent to MetaMinds?
No. The assessment runs entirely in your browser, with no server call and no database. Your answers are encoded in the query string of your own address bar, which is what makes a result shareable by sending the link. Nothing reaches us unless you choose to send it.
What does it cost to act on the recommendation?
The nine fixed-scope engagements run from $2,500 for a three-day vendor AI assessment to $8,900 for an ISO/IEC 42001 gap assessment. Scoped builds start at $18,000 for retrieval and document intelligence, $22,000 for AI agent and workflow automation, and $24,000 for a guardrail and evaluation platform. Every price is published on the services page.

Two more tools alongside this one: the chatbot ROI calculator and the AI stack builder. Both work the same way: client-side, shareable by link, and willing to tell you to do nothing.

Start here

Send us the ten answers, including the ones you did not like.

If the assessment recommended nothing, that is still a useful thirty minutes: what would have to change, and roughly when, is a shorter conversation than a proposal and a more honest one.

Typical reply within one business day · Fixed-scope engagements $2,500 to $8,900