AI readiness is not having a large database. It is having data that is appropriate for a defined purpose, permitted for that use, understandable, representative enough, and maintainable.
This decision connects to
Build an AI Strategy That Starts With Business Value and
Turn Company Priorities Into an AI Opportunity Portfolio, which provide the strategic direction and portfolio context.
Use this four-part leadership framework
Purpose and permission — State the decision or task and confirm allowed collection, use, sharing, and retention.
Ownership and meaning — Name accountable owners and define important fields, labels, and sources.
Quality and coverage — Measure completeness, accuracy, timeliness, duplication, and missing groups or cases.
Access and maintenance — Control access, lineage, updates, deletion, monitoring, and fallback.
A practical decision example
A support assistant finds that historical resolutions mix outdated policies with current guidance. The team creates an approved source set, dates every policy, assigns owners, and blocks unsupported sources before model testing. This is a hypothetical example; use your own baseline, constraints, and evidence.
Evidence, governance, and responsible use
Use the
NIST AI Risk Management Framework to connect the initiative to governance, context, measurement, and ongoing management. The companion
NIST AI RMF Playbook turns those functions into questions leaders can assign and review.
The
GAO AI Accountability Framework is useful for examining governance, data, performance, and monitoring across the system life cycle. Compare the plan with the
OECD AI Principles, particularly transparency, robustness, accountability, and respect for people affected by the system.
For generative AI, review the
NIST Generative AI Profile and test representative cases using
OpenAI’s evaluation guidance. Use the
OWASP Top 10 for LLM Applications to discuss application threats before a model can access sensitive information or take actions.
Check performance statements against the
FTC’s guidance on AI claims, and review information handling with the
FTC’s privacy and security resources. For a broader organizational management approach, study the
ISO/IEC 42001 overview.
Take this to the next leadership meeting
Choose one use case and complete a data card: purpose, sources, owner, permissions, sensitive elements, quality findings, coverage gaps, update cycle, access, retention, and stop conditions.
Record the owner, evidence source, decision date, and what would cause the company to stop. The goal is not to make the document look complete. The goal is to make the next decision explicit, measurable, and accountable.
Continue with
Create a Minimum Viable AI Governance System. Use
Run a Quarterly AI Portfolio Review: Keep, Fix, Scale, or Stop to revisit the decision with current evidence.