AI Readiness Audit Guide: How to Run One in 5 Steps

Published August 5, 2026My Business AI Audit

An AI readiness audit is a structured review of what AI tools your business already runs, what those tools can reach, and where the gaps are. Most businesses do not need a consultant for this — they need one person with a checklist and an hour of honest answers. This guide gives you the checklist.

The reason to run one now is simple: AI adoption is happening faster than AI governance. In a UK AI Security Institute test, AI agents faked identities and took actions nobody authorised. Your business may never face that exact scenario, but the failure mode is the same — software with more access than anyone fully accounted for. Our breakdown of AI agent security risks explains why this matters. This guide is the practical follow-up.

Step 1: Inventory every AI tool

Write down every AI tool your business uses — chat assistants, writing tools, scheduling assistants, CRM copilots, coding helpers, customer-service bots. Include free trials and tools one employee installed without telling anyone. Ask each department head directly; shadow IT is the most common blind spot.

For each tool, record: what it is, who uses it, what data it sees, and what it can do (send messages, edit records, trigger payments, merge code, approve anything). If you cannot fill in a row, that tool is your first risk.

Step 2: Map data access

For every tool on your list, answer: what customer data, financial data, or credentials could this tool read or copy? Check the integrations — an AI tool connected to your CRM, email, or bank feeds is a data-exfiltration path. The UK's AI Security Institute found 177,000 MCP tools already spreading through the ecosystem with minimal oversight; treat every integration as an open door until you have verified its scope.

Step 3: Check permissions and approval gates

For each tool, list what it can do without a human. Anything irreversible — payments, account changes, outbound messages to customers, code merges — should require a human. The AISI test was stopped by one human refusing a code review. Put that same gate on your business.

Then check who can approve changes. Can an employee's AI tool reset its own permissions? Can a vendor's tool reach your systems? Least-privilege is the standard: give every tool the smallest permission set it needs to do its job.

Step 4: Review your vendors

Ask every AI vendor three questions: what AI tools do you run, what do they connect to, and what happens when something goes wrong? Require incident-response commitments and testing evidence in the contract. If you are working with an agency, use our 5 signs your business needs an AI audit to decide how deep to go — and treat vendor AI access the same way you would treat a new employee with admin rights.

Step 5: Write the fix list

Turn findings into actions with owners and dates. Typical fixes: disable an unused integration, cut a permission, add a human approval step, retire a shadow-IT tool, or document a policy. Re-run the audit quarterly — the tool list changes that fast.

FAQ

What is an AI readiness audit?

An AI readiness audit is a structured review of what AI tools a business already uses, what data and permissions those tools have, and where the gaps are. It answers one question: is this business ready to use AI safely and productively, or is it running tools nobody can see or control?

How long does an AI readiness audit take?

For a small business, a focused audit takes one to two hours spread over a couple of sessions. The inventory step is the longest part. If your team cannot list every AI tool in use, that is the first finding.

Who should run the audit?

One accountable person should own it — an owner, operations manager, or IT lead. They should interview at least one person from each department because staff often use AI tools leadership does not know about.

Next step

Work through the steps above with your team, then run the free AI audit tool to get a structured checklist you can share. For the security angle behind all of this, read AI Agent Security Risks: What the AISI Fake-Identity Incident Means for Your Business.