Score each statement 0, 1 or 2: zero means no; one means partly or informally; two means yes with evidence. The maximum score is 50. Complete the checklist for one use case, not “AI across the business.”

Our operating view: a business with modest technology and a clear, well-owned process is often more ready than a business with many apps and no reliable definition of done.

Process and value

  1. We can name the exact task and its trigger.
  2. We know current volume, cycle time and error/rework rate.
  3. We know who receives and uses the output.
  4. We can explain why AI is preferable to a form, rule or ordinary workflow.
  5. The expected benefit is large enough to measure.

Data and examples

  1. We have representative normal and edge-case examples.
  2. Required fields are available and sufficiently consistent.
  3. We know which inputs contain personal, confidential or regulated information.
  4. We have authority to use the information for this purpose.
  5. Retention, deletion and export requirements are understood.

Ownership and workflow

  1. One business owner is accountable for the outcome.
  2. A knowledgeable employee can test output quality.
  3. Exceptions have a named destination.
  4. The human approval point is explicit.
  5. We can operate temporarily if the AI or vendor is unavailable.

Privacy, security and risk

  1. Vendor data-use and model-training terms have been reviewed.
  2. Access uses named accounts, least privilege and strong authentication.
  3. Sensitive information is removed or minimized where possible.
  4. We have considered inaccurate, biased or harmful outputs.
  5. An incident or material error has an escalation path.

Testing and change

  1. Acceptance criteria are written before configuration.
  2. A test set includes ordinary, edge and deliberately poor inputs.
  3. We can run beside the current process before replacing it.
  4. Staff affected by the change will participate in testing and training.
  5. There is a stop, rollback and post-pilot review decision.

Interpret the score

0-19 Redesign the process first
20-34 Prepare a narrow, low-risk experiment
35-43 Ready for a controlled pilot
44-50 Ready to pilot; controls still apply

Do not let a high total hide a zero in privacy, authority, human oversight or rollback. Those are gating items.

Worked example: customer email triage

An illustrative 14-person GTA service company scores 37. It has a measurable inbox backlog, a clear service coordinator and good historical emails. It loses points because customer messages include addresses and account details, vendor terms have not been reviewed, and nobody has defined how low-confidence cases will be handled.

The right next move is not launch. It is to remove unnecessary fields, review the vendor arrangement, create confidence thresholds, route exceptions and assemble a labeled test set. Those actions may take a week and dramatically improve the quality of the pilot.

NIST organizes AI risk work around govern, map, measure and manage. Canada's privacy commissioners emphasize necessity, proportionality, transparency, data minimization and meaningful safeguards. The checklist translates those principles into small-business operating questions; it does not replace a privacy impact assessment or legal review.

Turn gaps into owned work

Load the failed checklist items into Pathway with an owner, acceptance test and due date.

Open Pathway →

Readiness is evidence, not enthusiasm

A company becomes pilot-ready when it can show a stable process owner, a usable baseline, accessible data, defined exceptions and a person authorized to stop the workflow. A team saying “we use ChatGPT all the time” is not evidence of operational readiness. A clean sample of 100 historical cases with known outcomes is.

Do not scale a decision you cannot defend

Naval Ravikant describes leverage as a force multiplier for judgment. That is useful and dangerous. If the business cannot explain why a request receives a particular category, priority or response, AI can distribute the inconsistency faster and more confidently.

Historical emails tested100
Correctly routed by current rule86
Incorrect or unclear14
Maximum safe automatic-routing rateNot yet established

Do not call this 86% ready. Study the 14 cases, distinguish bad rules from bad data, and define which categories require human judgment. Scale only the decision the company can defend.

Book framework: Eric Jorgenson, The Almanack of Naval Ravikant, Part I, “Building Wealth,” sections “Get Paid for Your Judgment” and “Find a Position of Leverage.”

Classify the data before selecting the tool

Separate public, internal, confidential and highly restricted information. Identify personal information, financial records, employee data, customer contracts and regulated material. Then determine what may enter a vendor system, where it is stored, how long it remains and how it can be deleted. The pilot should use the least sensitive data capable of proving the workflow.

Book framework: Eric Jorgenson's The Book of Elon, “Think Like a Physicist,” section “Obsess over Truth,” is useful here: measure the process that exists rather than the one described in the meeting.

A practical readiness gate

Named process owner and decision authority Required
At least 50-100 representative historical cases Required
Baseline time, cost or error rate Required
Defined human review and escalation path Required
Approved data classification and vendor use Required

Missing one required item does not mean the company is “bad at AI.” It identifies the preparation project. For customer-email triage, that might mean exporting 100 resolved messages, agreeing on five categories, recording current handling time and naming the person who reviews uncertain cases. That small package is more valuable than a company-wide AI strategy deck.

Sources and methodology

  1. NIST AI Risk Management Framework.
  2. Office of the Privacy Commissioner of Canada: responsible, privacy-protective generative AI principles.
  3. Office of the Privacy Commissioner: PIPEDA requirements in brief.
  4. Canadian Centre for Cyber Security: top measures for small and medium organizations.

Score one real use case together.

Bring the process, examples and concern that is slowing you down. We will use the checklist to identify the next responsible step.

Book a free call →

This checklist is general operational guidance. Privacy, employment, sector and provincial requirements vary; obtain qualified advice where appropriate.