Tel: +44 203 916 6309128 City Road, London, United Kingdom EC1V 2NXRegistration No: 16843978
Free · Under 10 minutes · No obligation

Free AI Readiness Assessment

Is your organisation ready to use AI safely?

Complete the assessment in under 10 minutes and receive a personalised AI governance maturity report. Built for regulated and growing organisations that need to identify AI governance gaps, across strategy, data protection, security, oversight and compliance, before those gaps become regulatory exposure.

Maturity score across ten domains

A personalised IACAIP Shielded Framework Maturity Score across ten governance domains.

Strongest areas & urgent gaps

A clear view of your strongest areas and your most urgent gaps.

Where to focus first

A practical sense of where to focus first.

Mapped to leading frameworks

Mapped against ISO 42001, the EU AI Act, GDPR and the NIST AI RMF.

Confidential

Your responses are handled in a GDPR-aligned manner.

Take the assessment

Start the Free AI Readiness Assessment

Tell us about you and your organisation. All fields marked * are required.

Your responses are confidential and handled in a GDPR-aligned manner. We use your details to deliver your personalised report and (with your submission) to follow up about IACAIP services. We do not share your data with third parties.

What is an AI Readiness Assessment?

An AI readiness assessment evaluates how prepared your organisation is to use AI responsibly and safely. It measures the maturity of the governance, controls and practices that surround your AI use, so you can scale AI with confidence rather than uncertainty.

What AI readiness means

AI readiness is the extent to which your organisation can adopt and scale artificial intelligence safely, with the governance, controls, data protection, security and oversight needed to manage AI risk alongside AI opportunity.

Why assess before you scale

Scaling AI without assessing governance maturity exposes your organisation to regulatory, reputational and operational risk. An AI readiness assessment identifies where you are today and what must be in place before AI use broadens.

Why governance, security and compliance matter

AI introduces new obligations under the EU AI Act, UK GDPR and sector regulation. Governance, security, data protection, human oversight and regulatory compliance are the foundations that make AI use defensible and trustworthy.

Built for regulated and growing organisations

The assessment is designed for regulated industries and growing organisations that need a clear, evidence-based view of AI governance maturity, not a marketing score.

This AI readiness assessment is an indicative self-evaluation. It is not a formal certification, audit or assurance engagement, and completing it does not confer any IACAIP certification status.

What does the assessment measure?

The assessment evaluates your organisation's AI governance maturity across ten governance domains. Each domain is scored on a five-level maturity scale, from "not yet started" to "optimised". Your responses produce a personalised maturity score for each domain and an overall AI governance maturity score.

Domain 012 questions

AI Strategy & Governance Leadership

Whether AI use is governed by a board-endorsed strategy, accountable leadership and clear ownership.

Domain 022 questions

AI Risk Management

Whether AI risks are identified, assessed, prioritised and treated in a structured, repeatable process.

Domain 032 questions

Data Protection & Privacy

Whether personal data used by AI systems is protected in line with UK GDPR / EU GDPR requirements.

Domain 042 questions

AI Security & Model Protection

Whether AI systems, models and pipelines are protected against adversarial, supply-chain and access threats.

Domain 051 question

Transparency, Explainability & Documentation

Whether AI use and model decisions are transparent, documented and explainable to affected stakeholders.

Domain 061 question

Human Oversight & Accountability

Whether meaningful human oversight, intervention points and clear accountability are built into AI use.

Domain 071 question

AI Procurement & Third-Party Risk

Whether third-party AI systems, models and vendors are assessed before and during use.

Domain 081 question

AI Incident Management & Response

Whether AI failures, harm and incidents are detected, reported and responded to.

Domain 092 questions

Regulatory Compliance & Conformity

Whether obligations under the EU AI Act, UK GDPR and sector regulation are actively tracked and met.

Domain 101 question

Responsible AI & Ethics

Whether fairness, bias mitigation and responsible-AI principles are applied across the AI lifecycle.

Aligned with leading AI governance frameworks

Each of the ten assessment domains is mapped to established AI governance, data protection and risk frameworks. This means your maturity score reflects recognised expectations, not an arbitrary checklist.

ISO/IEC 42001

AI management system standard: leadership, risk, data governance and continual improvement.

EU AI Act

Risk-based regulation of AI systems: provider/deployer obligations, transparency and incident reporting.

UK / EU GDPR

Data protection principles, lawful basis, DPIAs, security of processing and automated decision rights.

NIST AI RMF

Govern, Map, Measure and Manage functions for trustworthy and responsible AI.

The IACAIP Shielded Framework® is a proprietary framework. External frameworks, including ISO/IEC 42001, the EU AI Act, GDPR and the NIST AI RMF, are referenced for alignment only and are not issued by or owned by IACAIP unless formally authorised.

Your personalised AI governance maturity report

After completing the assessment you receive a personalised report you can download and share. It translates your responses into a clear picture of your AI governance maturity.

Overall AI governance maturity score

A single IACAIP Shielded Framework Maturity Score out of 100, with a maturity level from Initial to Optimised.

Maturity scores across ten domains

A scored breakdown of all ten governance domains, each mapped to ISO 42001, the EU AI Act, GDPR and the NIST AI RMF.

Your strongest areas

The governance domains where your organisation is most mature, your foundations to build on.

Your most urgent gaps

The domains with the lowest maturity scores, your clearest exposure to AI governance risk.

Where to focus first

Practical, prioritised guidance for your lowest-scoring domains so you know what to do next.

A downloadable, shareable report

A branded PDF maturity report you can save, share with colleagues and use to plan your next steps.

Who should take the AI Readiness Assessment?

The assessment is built for regulated and growing organisations that need a clear, honest view of AI governance maturity. It is most valuable for the people accountable for AI risk, governance and compliance.

Compliance leaders

Heads of compliance and regulatory affairs preparing for the EU AI Act and sector regulation.

Risk leaders

Chief risk officers and risk teams integrating AI risk into enterprise risk management.

CISOs and security leaders

Security leaders accountable for AI system, model and pipeline protection.

Data protection & privacy teams

DPOs and privacy professionals managing GDPR obligations for AI processing.

AI leaders

Heads of AI, data and ML engineering responsible for responsible AI delivery.

CEOs, directors and boards

Executives and boards seeking assurance that AI use is governed and defensible.

If your organisation is preparing for AI regulation, particularly the EU AI Act, UK GDPR or sector-specific AI requirements, this assessment gives you a structured starting point.

AI readiness assessment: frequently asked questions

Common questions about the IACAIP Free AI Readiness Assessment, what it measures and how it can help your organisation.

Still have questions? See the main IACAIP FAQ or contact the IACAIP team.

Ready to move from readiness to certification?

The AI Readiness Assessment is an indicative self-evaluation. For a formal assessment of your organisation against the IACAIP Shielded Framework®, explore organisation certification, or learn about the framework itself and the public Shielded Registry®.