Quick answer
An AI readiness audit is a three week review of your data, systems, staffing and governance that ends with a ranked list of what an AI agent could safely do in your organisation now, what it could not, and what would have to change first. It is deliberately capable of concluding that you should not buy anything yet.
What is an AI readiness audit?
A structured review that answers one question: what could an AI agent safely do here, starting now, given the data you actually have, the systems you actually run and the people who actually have to use it.
It is not a technology assessment and it is not a vendor bake off. Most of what determines whether an agent deployment succeeds is organisational: whether someone owns it, whether the workflow it touches is documented, whether the data it needs is where people think it is. Those are the things the audit examines, because they are the things that fail.
The output is a ranked list with reasoning, a compliance gap list, and a recommended first project. If the honest recommendation is to wait, that is what the report says. We would rather write that than sell an implementation that will not work.
What exactly is assessed?
Five domains, each examined through interviews, documents and a look at the systems rather than through a questionnaire. The domains are chosen because they are where deployments fail, not because they are where vendors compete.
- Data. Whether the information a candidate use case needs exists, where it lives, who owns it and how clean it is. For a scribe that is audio conditions and note templates. For a denial agent it is whether remittance data is structured or arrives as PDFs.
- Systems. Your EHR and practice management estate, its version and hosting, the integration paths each vendor would use, and the length of your own integration queue. For an Epic site this is the conversation on the Epic page; for a practice it is which Marketplace or built in feature already exists.
- Staffing. Whether there is a person who can own each candidate tool, whether the clinicians who would use it want to, and what the front desk, billing and nursing teams say happens to their day. This is where the interviews earn their place.
- Governance. Whether a risk analysis exists and is current, how vendors are reviewed, whether a BAA process exists, who signs off on a tool touching patients, and which state AI and recording laws apply to your footprint. Mapped against the HIPAA Security Rule and the NIST AI Risk Management Framework.
- Appetite for change. How the last two technology changes went, who sponsored them, and whether the organisation measures anything after go live. Honest answers here predict success better than any feature list.
Each candidate use case is then assessed against all five, because a use case can be feasible in the data and impossible in the staffing. The output is a score per use case per domain, with the evidence for each score written down so it can be argued with.
How does the scoring model work?
Each candidate use case gets a score from one to five in each of the five domains, and a separate score for benefit and for risk. The domain scores are about readiness: five means the organisation could start next month, one means something structural has to change first. Benefit is measured in the organisation's own units, hours returned or dollars recovered or calls answered, using your volumes rather than a market average. Risk is the severity of the failure mode and how recoverable it is: a bad draft a clinician corrects scores low, an automated action nobody reviews scores high.
The ranking is not a weighted sum, and this is deliberate. A use case with a one in any readiness domain is not ready, whatever the others say, and a weighted average would hide that. The ranking is instead: readiness floor first, then benefit against risk, then the practical sequence. A modest first project that will finish and be measured usually ranks above a larger one that will not.
Every score comes with its evidence and its assumption, so that when a partner or a board member disagrees with a ranking they can see which number to change and what it does. The same discipline applies to the cost and benefit model, which prints its assumptions the way the free ROI calculator does, so you can substitute your own figures. A ranking without visible reasoning is an opinion, and you do not need to pay for one of those.
How is this different from the free readiness assessment?
The free AI readiness assessment is a self scored questionnaire that takes ten minutes and tells you which of the five domains is your weakest and roughly where you sit. It is honest about being a self assessment: it scores what you tell it, and organisations are reliably generous about their own data quality and governance. Use it first. If it says you are not close, you have saved the fee.
The audit differs in three ways. It is scored by someone who is not you, from interviews with the people who do the work rather than the people who commissioned it, which is where the difference between the self score and the real score usually lives. It examines specific candidate use cases against your specific systems, so the output is a ranked list of things to do rather than a maturity level. And it produces documents you can act on and show to an auditor: the compliance gap list, the integration feasibility note, the cost model and the stopping rule.
A fair summary is that the free tool answers "are we roughly ready" and the audit answers "for which project, in what order, at what cost, with what to fix first, and how will we know". If the first answer is clearly no, take it, do the fixes, and come back.
What happens during the three weeks?
Week one is discovery. Interviews with clinicians, front desk staff, billing and whoever administers the EHR, plus a look at the systems themselves. We ask where the day goes and where work piles up, which is not always where leadership expects.
Week two is analysis. We map the candidate workflows against feasibility, benefit and risk, and check the compliance position against the HIPAA Security Rule and the NIST AI Risk Management Framework. We also establish what integration would actually require in your estate, which for larger sites means a real conversation about your EHR integration queue.
Week three is the report and the conversation about it. The report goes to whoever has to approve the spend, and we present it rather than emailing it, because the questions in the room are the useful part.
What is the timeline, and who needs to be in the room?
Three weeks, and the calendar is the main constraint rather than the analysis. Week one is discovery, week two is analysis and the integration and compliance checks, week three is the report and its presentation. A site visit, where it happens, falls in week one. The elapsed time can stretch if the people below are hard to schedule, so book them before the engagement starts.
- The sponsor. The person who will approve the spend and who owns the outcome: a managing partner, a CMIO, a COO. One hour at the start, one at the end, available by message in between.
- Clinicians. Four to eight, across the specialties in scope, including at least one sceptic. Forty five minutes each.
- The front desk and billing leads. The people who know where the calls go unanswered and where the denials come from. Forty five minutes each.
- Whoever administers the EHR. In a practice that may be the office manager; in a health system it is the application analyst and someone from the integration team. One hour, with access to look at configuration together.
- Compliance or privacy. The person who signs BAAs and owns the risk analysis. One hour, plus the documents.
- IT or security, where a function exists. One hour on vendor review process and identity.
For a practice the whole list may be four people wearing several hats, and the audit is scoped and priced accordingly. For a health system, the work is the same and the diary is harder. We ask for the calendar slots before we start, because a readiness audit that cannot get forty five minutes with a clinician has already learned something about readiness.
What do you actually get at the end?
A document you can act on and a decision you can defend. The deliverables are listed above, but the two that matter most are the ranked shortlist and the stopping rule.
The ranked shortlist tells you which workflow to attack first and why, in terms of your organisation rather than the market's. For many practices that is documentation, because the benefit is felt by the people doing the work. For others it is the phone, or the denial queue, and the reasoning is written down so you can disagree with it.
The stopping rule tells you in advance what result would make you expand and what result would make you stop. Written before the pilot, it is the single cheapest piece of governance available.
What does the report contain?
Seven parts, in an order designed to be read by someone who has fifteen minutes and then by someone who has a day.
- The recommendation on one page. The first project, the reason, the cost, the expected benefit range, the stopping rule and the date to decide.
- The ranked shortlist. Every candidate use case with its domain scores, benefit, risk and the evidence behind each number.
- The readiness assessment by domain. What we found in data, systems, staffing, governance and appetite, quoting interviews where that is the evidence, and what would move each score.
- The compliance gap list. Each gap mapped to the Security Rule provision or NIST AI RMF function it relates to, with a severity and a fix, in the register your compliance officer already uses.
- The integration feasibility note. For each shortlisted use case, the integration path in your estate, who on your side owns it, and what the vendor would have to demonstrate.
- The cost and benefit model. With every assumption exposed and a range rather than a single number.
- The pilot design. Duration, participants, baseline measures, review cadence and the stopping rule, ready to run.
The report is presented rather than emailed, because the questions in the room are the useful part, and the presentation is to whoever has to approve the spend. Appendices carry the interview notes, anonymised, and the vendor questions we would send, drawn from the questions to ask AI vendors about HIPAA.
What does a finding look like?
A composite, with the details changed, from the kind of finding that changes a decision.
Finding. The ambient scribe shortlisted by the practice scores five for benefit and four for data, and one for systems. The practice is on a hosted EHR instance under a larger health system's Community Connect arrangement. The host has not approved the shortlisted vendor, its integration queue is measured in quarters, and it has already approved a different scribe for its own clinicians. The practice's plan assumed a write back integration that its host will not build for it.
Consequence. Either the practice runs the shortlisted vendor with a copy step, which is workable at its size and removes the systems blocker entirely, or it adopts the host's approved vendor and inherits the host's contract terms and timeline. The two options have different costs, different timelines and different retention terms, and the choice belongs to the partners, not to the vendor.
Recommendation. Pilot the shortlisted vendor with a copy step for one quarter, measuring documentation minutes and same day close rate, while asking the host in writing what its approval process and timeline for the vendor would be. Stopping rule: if the copy step is tolerated and the minutes move, continue; if the host approves the vendor within the quarter, move to the integrated path; if neither, evaluate the host's vendor. Decide on a named date.
That finding cost the practice nothing to act on and saved it from a contract whose value depended on an integration that was never going to happen. Most useful findings are like this: not a discovery about AI, but a discovery about the organisation that the vendor's process had no reason to surface.
Who is this for, and who is it not for?
It is for organisations that have decided to do something and want to be right about what. It is particularly useful where an evaluation has stalled, because a stalled evaluation is usually a sign that the wrong question is being asked.
It is not for organisations that have already chosen a vendor and want validation. We will give you an honest answer, which in that situation is often unwelcome and always expensive to ignore. It is also not for a solo clinician wanting to try an ambient scribe, where the sensible advice is to read the comparison page, pick one with published pricing, and try it. We would rather say that than take the fee.
How is this different from a vendor's assessment?
A vendor assessment is a sales qualification exercise, and a good one is genuinely useful. It is still asking whether you are a fit for their product, not whether their product is the right thing for you to buy.
We take no commissions, no referral fees and no paid placements, and we do not resell anything. That is not a claim to virtue, it is a description of the business model, and it is the only reason our answer can be that you should not buy anything this year. Where we do recommend a shortlist, the reasoning behind it is on the comparison pages where you can check it.
What happens after the audit?
Nothing automatically. There is no implementation obligation, and a report that recommends waiting is a complete piece of work rather than a failed sale.
If you do proceed, the natural next step is a sequenced plan that takes the first use case to production with controls and rollback defined up front, which is a separate engagement. Some organisations run that themselves from the report, which is a good outcome and we will say so.
Before any of it, if you want to sanity check the numbers yourself, the ROI calculator models the documentation case with its assumptions printed on the page.
What are the paths after the audit?
Three, and the report says which one it recommends. There is no implementation obligation on any of them.
Fix something first. Where a readiness domain scored one, the recommendation is to close that gap before buying anything: a current risk analysis, a named owner with time, an EHR upgrade, a BAA process. The report lists the fixes in order with an estimate of effort. Many organisations do this work themselves. Where the gap is governance, our hospital AI governance consulting engagement stands up the committee, the policy and the vendor review process so that the next audit scores differently.
Choose the vendor. Where the first project is ready and the shortlist has more than one candidate, vendor selection runs the questionnaire, the BAA read and the bake off from the pilot design in the report, and ends in a recommendation with the measured evidence behind it.
Take it to production. Where the vendor is chosen, the deployment roadmap sequences the first project to go live with controls, training, measurement and rollback defined up front, and it starts from the audit's pilot design rather than from a blank page.
Some organisations take the report and run all three themselves. That is a good outcome and we say so. The report is written to be usable without us, which is the only honest way to write it.
Why have this done independently?
Because the alternative is a readiness assessment run by someone who is paid when you buy. A vendor's assessment asks whether you are ready for its product. A readiness audit asks whether any product is the right thing for you to buy this year, and it is allowed to answer no. We take no commissions, referral fees or paid placements, and we do not resell or implement vendor software, so the ranking is built from your side of the table and the report can recommend waiting. Book a call to scope one; the call is free and it is often enough to tell you whether the audit is worth having.
What you are left holding
The engagement is finished when these are true, not when the calendar says so.
- A decision you can defend, with the reasoning written down
- A first project scoped small enough to finish and measurable enough to judge
- A compliance position you can show an auditor rather than describe
- A clear answer, sometimes, that the right move this quarter is to fix something else first
Questions we get asked
How much does an AI readiness audit cost?
It is a fixed fee agreed before the work starts, scaled to the size of the organisation rather than billed hourly. We quote after a short call, because a five clinician practice and a four hospital system need different amounts of work and should not pay the same. There is no charge for the call.
Do you need access to patient data?
No. The audit works from workflow descriptions, system configuration, volumes and aggregate reporting. Where any engagement would touch protected health information, we sign a business associate agreement first and work within it, but readiness assessment does not require it.
Can you do this if we have already started a pilot?
Yes, and this is one of the more useful moments to do it. A pilot with mixed results usually contains the answer to why, and the question is normally whether the problem was the tool, the workflow or the absence of an owner. Those need different responses.
Will you recommend a specific vendor?
We will recommend a shortlist and explain the reasoning, including where our knowledge stops. We will not tell you there is one right answer where there is not, and we have no commercial interest in which of them you choose.
What if the answer is that we are not ready?
Then the report says so, and says specifically what would have to change and in what order. That is a useful outcome, and considerably cheaper than the alternative, which is discovering it eight months into a contract.
How is the audit different from the free AI readiness assessment tool?
The free assessment is a ten minute self scored questionnaire that tells you your weakest domain. The audit is scored by us from interviews and documents, assesses specific use cases against your specific systems, and produces a ranked shortlist, a compliance gap list, a cost model and a pilot design you can run. Use the free tool first; if it says you are far off, you have saved the fee.
How long does an AI readiness audit take?
Three weeks elapsed: discovery in week one, analysis and the integration and compliance checks in week two, the report and its presentation in week three. The constraint is calendar access to clinicians, the EHR administrator and compliance, so those slots are booked before the engagement starts.
What happens after the audit?
One of three paths, and the report says which: fix a readiness gap first, sometimes with governance consulting; run vendor selection where the shortlist has more than one candidate; or take the chosen vendor to production with a deployment roadmap. None is obligatory, and the report is written to be usable without us.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion