AI readiness assessment: a first pass for Australian businesses
Twenty-four yes-or-no questions across six areas. Score your AI readiness in ten minutes, then close the gaps that matter most.
Short answer: An AI readiness assessment checks whether your business has the ownership, data awareness, workflows, risk controls, skills and policies to use AI responsibly. Below is a free self-assessment: 24 yes-or-no questions across six areas, mapped to the Australian Government's Guidance for AI Adoption.1 It takes about ten minutes.
Most Australian businesses are already using AI in some form. The question is rarely whether to adopt it. The question is whether the structures around that use, the ownership, the data rules, the risk controls, are in place or missing. A readiness assessment answers that before you spend money on tools, training or consultants.
This guide is for the operations lead, general manager, or compliance officer at an Australian business of 20 to 200 people who needs to assess where their organisation's AI governance stands.
This is not a vendor questionnaire. It does not score you on how much AI you have bought. It scores you on whether the foundations are in place to use AI safely and get value from it. If you are still deciding where to start with AI, the readiness assessment and your first project can run in parallel.
What an AI readiness assessment covers

The six areas below map to the Australian Government's Guidance for AI Adoption, published in October 2025 by the Department of Industry, Science and Resources.1 That document consolidates the earlier Voluntary AI Safety Standard's 10 guardrails2 into six essential practices for responsible AI use. Each area of the assessment corresponds to at least one of those practices.
1. Accountable owner
Every AI governance structure starts with one person. Not a committee, not a shared inbox. One named person who is responsible for AI decisions, approvals and incidents. In a business of 20 to 50 people, this is usually the operations lead or the general manager. In a business of 50 to 200, it is often someone in risk, compliance or IT.
This maps to the Guidance's first essential practice: "Decide who is accountable."1 If nobody owns AI decisions in your business, nobody is managing the risk.
2. Data and systems
Where does your customer and personal data sit when it enters an AI tool? The Australian Privacy Principles apply to all uses of AI involving personal information, including where information is used to train, test or use an AI system.3 If your team pastes a customer complaint into ChatGPT to draft a reply, that is a disclosure of personal information under APP 6. If the complaint contains health information, stricter consent requirements apply.
This area checks whether you know which AI tools access personal data, where that data goes, and what the vendor's retention and handling terms are. It maps to the Guidance's second essential practice: "Understand impacts and plan accordingly."1
3. Workflows and use-case register
Which AI tools is your team actually using, and for what? Most businesses that run their first honest survey find tools nobody sanctioned and uses nobody anticipated. A use-case register captures every AI tool, its purpose, the data it touches, and who owns it. This is the foundation that everything else, risk tiering, policy, records, builds on.
This also maps to "Understand impacts and plan accordingly."1 You cannot manage what you have not catalogued.
4. Risk tiers
Not every AI use carries the same risk. A model that drafts internal meeting agendas is not the same as one that triages customer complaints or scores job applicants. Tiering your register by risk, low, medium and high, lets you apply controls proportionate to the stakes rather than treating every use case as though it were high-risk. Our AI governance framework sets out the three tiers and what controls each one needs.
This maps to the third essential practice: "Measure and manage risks."1
5. People and skills
Can your team use AI tools competently, and do they know the boundaries? Two questions matter here: whether a named human reviews every AI output used in decisions that affect individuals, and whether staff know which data must never be entered into an AI tool. Training does not need to be elaborate. It needs to be specific to the tools your team actually uses and the data rules that apply.
This maps to two essential practices: "Maintain human control" and "Test and monitor."1
6. Policy and records
Do you have a written AI acceptable-use policy, and are you keeping records of decisions, approvals and incidents? From 10 December 2026, the Privacy and Other Legislation Amendment Act 2024 requires organisations to disclose in their privacy policies how personal information is used in substantially automated decisions.4 If you do not have a policy by then, you are not just exposed to risk. You are non-compliant.
Our AI policy template for Australian businesses is a free starting point. This area maps to the fourth essential practice: "Share essential information."1
The self-assessment
Twenty-four yes-or-no questions. Answer honestly. If you are unsure whether the answer is yes, the answer is no. Count the total and check the scoring band at the end.
| # | Area | Question |
|---|---|---|
| 1 | Accountable owner | Has your business named one person responsible for AI decisions? |
| 2 | Accountable owner | Can every employee identify who to ask when they are unsure about AI use? |
| 3 | Accountable owner | Does your accountable owner report to leadership or the board on AI at least quarterly? |
| 4 | Accountable owner | Is AI governance on the agenda at board or leadership meetings? |
| 5 | Data and systems | Do you know which AI tools in your business access customer data? |
| 6 | Data and systems | Have you classified which of your data is personal information under the Privacy Act? |
| 7 | Data and systems | Do you know where customer data is stored when entered into a third-party AI tool? |
| 8 | Data and systems | Have you reviewed the data handling and retention terms of every AI tool your team uses? |
| 9 | Workflows | Do you have a register of every AI tool in use across your business? |
| 10 | Workflows | Does each entry in your register name the tool, the use case, the data involved and the owner? |
| 11 | Workflows | Do you know which AI uses your team adopted without formal approval? |
| 12 | Workflows | Is your use-case register reviewed at least quarterly? |
| 13 | Risk tiers | Is each AI use case in your register assigned a risk tier (low, medium, high)? |
| 14 | Risk tiers | Are high-risk AI uses subject to additional controls such as impact assessments and mandatory human review? |
| 15 | Risk tiers | Do you have a documented approval process for new AI use cases before they go live? |
| 16 | Risk tiers | Have you identified which AI uses will need disclosure under the automated decision-making transparency requirement from December 2026? |
| 17 | People and skills | Is a named human reviewing every AI output used in decisions that affect individuals? |
| 18 | People and skills | Has your team received training on the AI tools they are expected to use? |
| 19 | People and skills | Do staff know which data must never be entered into an AI tool? |
| 20 | People and skills | Is there a clear escalation path when an AI output looks wrong or produces an unexpected result? |
| 21 | Policy and records | Does your business have a written AI acceptable-use policy? |
| 22 | Policy and records | Are you logging AI use decisions, approvals and incidents? |
| 23 | Policy and records | Does your privacy policy address the use of AI in automated decisions? |
| 24 | Policy and records | Has your AI policy been reviewed in the last six months? |
Scoring
| Score | Band | What it means |
|---|---|---|
| 20 to 24 | Strong foundation | The structures are in place. Focus on maintaining your review cadence and keeping the register current as new tools and use cases appear. |
| 13 to 19 | Partial readiness | The basics are there, but gaps in documentation, training or oversight need closing before you scale AI use further. Identify the area with the most "no" answers and start there. |
| 7 to 12 | Early stage | Your team is probably using AI already, but without the structures to manage it safely. Start with naming an accountable owner and building the use-case register. |
| 0 to 6 | Starting from scratch | That is normal for many Australian businesses. The Privacy Act's automated decision-making transparency requirement takes effect in December 2026. Begin with the AI policy template and work outward from there. |
The scoring is directional, not diagnostic. It tells you which areas need attention first, not whether your business will pass a compliance audit. If you scored below 13 and your business already uses AI across multiple teams, the gap between your current use and your current governance is the risk.
What a good external assessment produces
The self-assessment above is a first pass. It tells you where you stand. A thorough external assessment goes further and produces artefacts you can act on:
- A ranked use-case register: every AI tool and use case in your business, catalogued with the data it touches, the owner, and the risk tier. Not what you planned. What is actually happening.
- Risk tiers mapped to your actual data and workflows: which uses are low-risk internal efficiencies, which ones touch personal information, and which ones substantially support decisions affecting individuals.
- A 90-day plan: what to fix first, what to formalise, and what to defer. Prioritised by risk and regulatory deadline, not by how interesting the technology is.
- The policy and framework artefacts: an AI acceptable-use policy customised to your approved tools and data rules, and an AI governance framework that sets the review cadence, the approval path and the records you keep.
What a bad assessment looks like
Several of the pages currently ranking for "AI readiness assessment" are vendor questionnaires dressed up as assessments. You answer 10 questions about your cloud infrastructure and your data maturity, and the result, regardless of what you answer, is that you need the vendor's platform.
A good assessment is vendor-neutral. It does not care which AI tools you buy. It cares whether the structures around those tools, the ownership, the data rules, the risk tiers, the policy, are fit for purpose. If the output of an assessment is a product recommendation rather than a governance plan, it was a sales call with a questionnaire in front of it.
When to do it yourself and when to get help
The self-assessment above is designed to be run internally. If your business has fewer than 50 people and limited AI use, it may be all you need to identify your gaps and close them. Pair it with the AI policy template and the governance framework, and you have a working structure.
External help makes sense when:
- Your business is already using AI across multiple teams or departments, and nobody has a complete picture of what is in use.
- You handle personal information at scale: customer data, health records, financial data.
- You operate in a regulated industry where APRA, the TPB, or another sector regulator has issued AI-specific guidance.5
- You need the artefacts, the register, the risk tiers, the policy, the framework, built to a standard you can show to a board, a regulator, or a client.
The sector matters too. An accounting practice handling client tax data faces different AI governance questions from a construction firm using AI for project scheduling. Our guides for accountants, construction, law firms, real estate and logistics cover what AI adoption looks like in each of those industries.
At Bulletproof, we help Australian businesses build the governance structures that sit around AI, not just the AI itself. If the self-assessment surfaced gaps you are not sure how to close, that is a good starting point for a conversation.
Frequently asked questions
What is an AI readiness assessment?
An AI readiness assessment is a structured check of whether your business has the ownership, data awareness, workflows, risk controls, skills and policies to adopt AI responsibly. It does not evaluate specific tools or vendors. It evaluates the structures around AI use: who owns decisions, where personal data flows, how risk is tiered, and whether there is a policy your team can follow.
What is the difference between an AI audit and an AI readiness assessment?
A readiness assessment checks whether the foundations are in place before you scale AI use: ownership, data handling, risk controls, skills and policy. An AI audit is broader and deeper. It examines what AI your business is already using, whether those uses comply with your obligations under the Privacy Act and any sector-specific regulation, and where the gaps and risks sit. A readiness assessment is the first step. An audit is what follows.
How long does an AI readiness assessment take?
The self-assessment on this page takes about ten minutes. A thorough external assessment for a business of 20 to 200 people typically takes two to four weeks, depending on how many AI use cases are already in play and how well documented your data flows are. The first week is usually discovery: finding out what your team is actually using.
Do Australian businesses legally need an AI readiness assessment?
No Australian law requires a readiness assessment by name. But the Privacy Act 1988 already governs how personal information is used in AI systems, and from 10 December 2026, organisations must disclose automated decision-making in their privacy policies.4 A readiness assessment is one practical way to find out where you stand before that deadline arrives.
What does 'AI in audit' mean?
AI in audit refers to how auditors and accountants use AI tools within their professional practice, such as using AI to analyse financial statements or flag anomalies. It is a different topic from assessing a business's readiness for AI. If you are an auditor or tax practitioner, our guide to AI for accountants in Australia covers the tools, the TPB guidance and the compliance considerations relevant to your work.