Booking Q4 deliveryevery engagement starts with the free assessment Denver · Phoenix · Remote
← The Ampersand
The Ampersand · Aug 23, 2026

What an AI Readiness Audit Should Actually Find

An AI readiness audit exposes costly workflows, weak data, security gaps, and adoption risks before you spend money building the wrong system at scale.

— Founder, Main & MachineAug 23, 20268 min read
What an AI Readiness Audit Should Actually Find

A good AI readiness audit does not begin with a chatbot demo. It begins where work gets stuck: the coordinator copying information between systems, the owner waiting three days for a sales report, the office manager chasing incomplete forms, or the team answering the same customer questions for the hundredth time.

Those are operating costs, not minor annoyances. An audit should show which costs are worth removing, what must stay under human control, and whether your current data and software can support a working AI system. If it cannot answer those questions, it is not a readiness audit. It is a sales conversation dressed up as one.

01AI READINESS

An AI Readiness Audit Is a Build Decision

The purpose of an AI readiness audit is to decide what to build first, what not to automate, and what needs to change before implementation starts. For a small or mid-size business, this matters because the wrong project can consume budget, frustrate staff, and leave another disconnected tool in the stack.

The output should be an owned operational blueprint, not a vague recommendation to “use AI for efficiency.” It should identify the workflows carrying the highest labor cost or delay, map the systems and data involved, define the required human approvals, and establish a practical build sequence.

That sequence will look different for every business. A construction firm may need faster bid intake, document retrieval, and job-status reporting. An accounting practice may need structured client-document collection and a way to triage recurring questions before they reach senior staff. A retail operator may need inventory exceptions surfaced from several systems before they turn into missed sales.

The common denominator is not the technology. It is the work.

021 FIND

1. Find the Three Workflows Costing You the Most

Most businesses can name 20 things they would like to improve. That is not a useful implementation plan. The audit should narrow the field to the three workflows where repetitive work, slow handoffs, errors, or missed follow-up create the greatest economic drag.

Start with the full path of the work, not the person doing it. For example, “follow up with new leads” is too broad. A usable workflow description identifies how a lead arrives, where the information is stored, who reviews it, what qualifies it, when a response is sent, where the next action is recorded, and what happens when no one responds.

This is where many AI projects fail. Teams automate a visible step, such as drafting an email, while leaving the actual bottleneck untouched: duplicate records, missing intake fields, unclear ownership, or a sales process nobody follows consistently.

A serious audit measures the cost of the workflow in practical terms: staff hours, elapsed time, error rate, lost revenue, rework, and management attention. Not every problem needs AI. A poorly designed approval process may need one clear owner. A broken form may need to be fixed before any automation is considered. The audit earns its keep by separating those cases.

032 INSPECT

2. Inspect the Data Before Promising Automation

AI systems are only as dependable as the business information they can access and the rules that govern that access. That does not mean your data must be perfect before you begin. It does mean you need to know where it lives, who owns it, whether it is current, and whether the same customer, project, or case is represented differently across tools.

An audit should document the systems involved in each priority workflow. That can include a CRM, accounting platform, email inboxes, shared drives, scheduling software, practice-management tools, point-of-sale data, field-service apps, and spreadsheets maintained by one indispensable employee.

The key question is not, “Can AI connect to this?” The better question is, “What is safe and useful for the system to read, write, summarize, classify, or flag?”

For example, an AI agent may safely prepare a client follow-up draft using CRM history and meeting notes. It may not be authorized to send the message without review, change a financial record, make a legal determination, or advise a patient. Those limits are not signs that the project is less advanced. They are how accountable systems are built.

Data quality also affects project scope. If customer information is scattered across five tools with no reliable identifier, unifying records may be the first build. If the data is clean but staff spend hours searching for answers, a secure internal knowledge system may deliver value sooner. The audit should make that trade-off visible before anyone starts building.

043 DEFINE

3. Define Security, Authority, and Human Override

The fastest way to lose trust in an AI system is to make its behavior unclear. Employees need to know what the system can see, what it is allowed to do, what it cannot do, and who is responsible when an exception appears.

A readiness audit should set these controls at the workflow level. It should identify sensitive data, determine whether information can leave the organization, establish role-based access, and define retention requirements. In healthcare, finance, legal work, and insurance, those details are central. They also matter in every other business that stores customer information, employee records, pricing, or internal operating data.

Human ownership must be explicit. AI can prepare, retrieve, route, summarize, compare, and flag. A person should retain final judgment where decisions affect money, legal exposure, safety, customer commitments, or professional advice.

The audit should also identify failure paths. What happens when the system cannot find a reliable answer? What happens when two data sources conflict? Who receives the exception, and how is the correction captured so the same problem does not repeat? If nobody can answer those questions, the workflow is not ready for autonomous action.

054 TEST

4. Test Whether the Team Will Actually Use It

An AI system that sits outside the normal flow of work is a future cancellation request. Adoption is not solved by a training session alone. It depends on whether the new system saves time without asking staff to create more steps, duplicate records, or surrender judgment they are accountable for.

The audit should include the people closest to the work. They know which intake fields are routinely wrong, which exceptions happen every Friday, and which reports leadership requests but never uses. Their input exposes the gap between a process chart and the real operation.

It should also establish a baseline. If a team currently spends 25 hours each week preparing estimates, responding to common inquiries, or reconciling status updates, that number becomes the measure of success. “Better productivity” is not a result. Fewer preparation hours, faster first response, lower rework, and more completed follow-up are results.

A practical adoption plan names the workflow owner, the staff members who will use the system first, the training required, and the review cadence after launch. Small pilots can be useful, but only when they operate inside a real workflow and have a clear path to production. A proof of concept with no deployment plan is just a demo.

065 LEAVE

5. Leave With a Blueprint You Can Price and Build

At the end of the audit, leadership should be able to make a decision without guessing. The deliverable should specify the priority workflows, proposed systems, integration requirements, implementation phases, expected business impact, and constraints that could affect timing or cost.

At minimum, the blueprint should contain four things:

  • A ranked list of the highest-cost workflows and the baseline measures attached to each one.
  • A map of the software, business data, owners, and handoffs required for the proposed build.
  • Clear rules for access, approvals, exceptions, and human override.
  • A scoped implementation plan with concrete acceptance criteria, not open-ended hourly discovery.

This is also where pricing should become more honest. A workflow that requires one system connection, a defined approval step, and clean data may be a targeted build. A business that needs shared data across departments, custom agents, multiple integrations, permissions, reporting, and ongoing monitoring is a larger operating-system project. Both can be worthwhile. Pretending they are the same project is how budgets get blown.

07AI READINESS

What an AI Readiness Audit Is Not

It is not a generic workshop where everyone lists ideas on virtual sticky notes. It is not a vendor questionnaire designed to steer you toward a preselected platform. And it is not permission to automate every task simply because a model can generate an answer.

Main & Machine approaches the audit as the first phase of implementation: a way to reduce scope risk before fixed-price work begins. The goal is a system that can be put into production, used by the team, and measured against the work it was supposed to improve.

There are times to wait. If leadership cannot identify an owner for the workflow, if the process changes weekly, or if critical information is inaccessible and ungoverned, building immediately may create more confusion. In those cases, the right next step may be process cleanup, data ownership, or a simpler software fix.

The useful question is not whether your company is “ready for AI” in the abstract. Ask which expensive piece of work should be easier 90 days from now, who remains accountable for the outcome, and what evidence will prove the system is earning its place.

Where this shows upWhat we actually build

Main & Machine

Like how we think? Put it to work.

This is the kind of workflow the free assessment maps. Thirty minutes, no pitch.

The Ampersand / freeA few times a month

Read before you ever pick up the phone.

Free essays, a few times a month. One field. No sales pitches.

Delivered by beehiiv. No spam, unsubscribe anytime.

Why subscribe
  • Short essays you can read in one sitting
  • How we actually think about AI on Main Street
  • No pitches, no funnels. Leave whenever it stops paying
Full archive