Skip to content
> ./aidex.sh_

Readiness Baseline

Where do we actually stand?

Who asks

The executive who has to answer for it usually asks for this one, most often after a board or a customer security questionnaire has put a question about AI governance to someone who could not answer it in writing.

What we look at

Assessments run at executive, department, and individual level, and a person's role determines which of those levels reaches them. We read the responses against what actually exists: the policy documents, who has read them, which controls somebody can demonstrate, and which are described but never practiced. Completion matters as much as content, so we watch which departments answered thinly and say so in the record rather than letting a sparse response set pass as a finding. A consultant then scores independently of the model, and the two readings are kept apart.

What you get

Key deliverables

  • A readiness baseline decomposed into govern, map, measure, and manage
  • A gap register with a severity on every gap
  • A roadmap of phased items categorized as security, governance, operations, technology, or training
  • A board brief carrying its NIST references

What this does not cover

A baseline measures what was reported. It does not discover what is running, so if the real question is which tools are already in use and what data has gone into them, that is the Exposure Review and it belongs first. The roadmap names the training that needs to happen and stops there. Running that training in one department and scoring the result is the Department Pilot.

What lands in the platform

The baseline is stored as a dated score with its four function sub-scores, and with the model's reading and the consultant's reading both kept. Each assessment carries the level it was run at, executive, department, or individual, while the score itself is one figure for the organization. The gap register lives in the platform, where a gap can be marked addressed and the record keeps who marked it and when. The roadmap and the board report stay there too, the report exportable as a PDF with its NIST references intact, so the next reading has a dated predecessor to be read against.

Next step

Name the departments that would be in scope and the person in each one who would answer for it, and we will build the assessment against that list.