A UK AI readiness assessment should show whether a specific task has usable data, the right access controls, capable staff and an affordable operating model. Its output should be a decision to pilot, narrow the scope or repair a named problem. The government’s generative AI framework supports assessing goals, human control, skills and commercial involvement together. For a small business, that means checking the work around the licence before committing to it.
Key pointers
- Choose the process you want to improve and name the person who will judge the results.
- Ask for evidence that the proposed records are understandable, usable and accessible to the intended users.
- Separate mandatory product requirements from recommended preparation and optional consultancy work.
- Check mailbox location before planning Copilot email tasks, because mailbox grounding requires Exchange Online.
- Budget for agent consumption separately where applicable, because Copilot Chat agents using organisational data can incur metered charges.
- Request an itemised GBP quotation covering assessment, remedial work, training and ongoing operation, with VAT treatment stated.

What AI readiness means for a UK SME
Readiness belongs to a proposed use case. An assessment should explain which work the business can attempt with its existing records, systems and staff, and which dependencies remain unresolved.
The government dataset guidance published in January 2026 explains a practical problem. Government data has often been collected for operational delivery, reporting or compliance. Reusing it for AI introduces questions about its structure, documentation and suitability for a different purpose.
For a UK business using government datasets, that means checking more than whether a file downloads or an application programming interface, or API, returns records. Ask what the fields mean, where the data came from and what limitations accompany it. Those checks follow the guidance’s concern that raw data without quality or provenance information can be misunderstood.
A small business can apply that reasoning to its own records. CTC recommends asking the person who maintains the proposed source data to explain it to someone outside their team. Any missing definitions, uncertain dates or unresolved ownership questions become assessment findings with named owners.
The government guidance is written for public-sector datasets. Using its approach provides a useful reference for a private company’s assessment; it does not establish that the company or its chosen product has government approval.
Follow one task from source record to finished work
A useful assessment traces the proposed task through the people and systems needed to complete it. This connects data preparation to operating decisions.
Consider an illustrative UK wholesaler evaluating AI to draft replies about delayed orders. The assessment should establish which record contains the delivery date and whether that date is an estimate or a confirmed commitment. It should then identify who may read the record and who approves a promise made to the customer.
These questions produce different remedies. An unexplained date field needs documentation. An incorrect access permission needs correction. An unassigned approval step needs a business owner. Buying additional licences would leave each problem unresolved.
CTC recommends recording the current process before testing an assistant. Include the staff effort needed to find information, prepare the response and check it. Compare the pilot against completed, acceptable work, including corrections, rather than measuring only how quickly a draft appears.
The government framework’s principles on choosing the right tool, human control and lifecycle management provide a basis for this approach. Keep an improvement to the existing process among the options: the assessment should be able to recommend better source records or clearer procedures when those address the problem.
Separate product requirements from preparation work
A technical assessment should state which conditions prevent the chosen product from working and which measures improve its deployment.
Microsoft’s minimum requirements, updated on 8 September 2026, provide a concrete example. Its table contains 5 required categories and 3 strongly recommended measures.
| Classification | What Microsoft lists | What the buyer should establish |
|---|---|---|
| Required prerequisites | Licensing, Exchange Online mailbox, Entra ID account, supported operating systems and browsers, network endpoints | Whether each intended pilot user meets the applicable requirements |
| Strongly recommended preparation | SharePoint governance, Purview labelling and phased rollout | What work is proposed, who will do it and how it affects the pilot |
These counts describe the checklist’s structure. They do not measure an organisation’s readiness or the relative importance of each item.
The mailbox requirement shows why precise scope matters. Microsoft explains that mailbox grounding, meaning the use of emails, calendar events and metadata to inform responses, is supported only when the primary mailbox resides in Exchange Online. On-premises and hybrid mailboxes do not support that grounding. Microsoft’s mailbox requirements therefore give the assessor a specific dependency to investigate.
For a small company, the practical question is whether the intended email task can work for the proposed users. Request that finding before accepting a broader migration proposal, and ask the assessor to show which additional changes the chosen scope requires.
Technical eligibility also leaves questions about data management unanswered. Microsoft’s adoption guide separately recommends evaluating governance maturity and security controls before deployment. A purchasing brief should cover both technical requirements and preparation, with separate findings and costs.
An agent adds authority and spending decisions
An agent assessment must describe what the proposed system is allowed to do. Microsoft describes agents as extending Copilot’s knowledge and automating workflows, and tells organisations to consider objectives, technical requirements, costs and responsible AI factors before deployment. Its agent prerequisites also recommend using the least privileged administrative role needed for the task.
Applied to the wholesaler example, CTC recommends treating drafting a reply, sending it and changing an order record as separate permissions. The assessment should specify the proposed boundary and identify the person who approves consequential actions.
Ask the implementer to demonstrate that boundary with representative tasks. Include an attempted action the pilot should refuse, alongside a permitted action. Require a named support owner and an explanation of how access can be withdrawn.
Agent costs need the same precision. Microsoft’s documentation says Copilot Chat is available at no additional cost to Microsoft Entra account users with a Microsoft 365 or Office 365 subscription. It separately describes metered consumption for agents incorporating organisational data. The licensing distinction means an existing chat entitlement is insufficient evidence that the proposed agent workload carries no additional charge.
Before approving that workload, ask which activities incur charges, who can enable them and who will monitor spending.
Compare assessment scopes before choosing a supplier
An organisation-wide assessment and a product deployment assessment answer different questions.
NCS London’s readiness guide covers business objectives, data maturity, internal skills, leadership and use-case prioritisation. Kontain’s readiness description similarly spans data, infrastructure, skills, strategy and governance. Microsoft’s product-specific material focuses on preparing an organisation to deploy its own offering.
Those descriptions help distinguish scope; they do not establish comparative delivery quality. If the business is still deciding which task merits AI investment, commission work that can question the use case and delivery approach. If the task and product are already selected, request evidence against that product’s requirements and the proposed operating process.
CTC recommends making the following outputs explicit in any assessment brief.
| Area | Deliverable to request | Cost question |
|---|---|---|
| Use case and data | Defined task, approved sources and documented quality gaps | Does the fee include correcting records or only identifying problems? |
| Technical preparation | Requirements check and a dependency list | Are migration, permissions work and configuration priced separately? |
| People and operation | Named owners, review responsibilities and training needs | How much staff time and ongoing support will the pilot require? |
| Licences and agents | Required subscriptions and applicable usage charges | Which costs are recurring, committed or consumption-based? |
| Pilot decision | Test findings, unresolved issues and a recommendation | What further work is needed before the business can proceed? |
For UK procurement, request the quotation in GBP with its date, VAT treatment, billing commitment and exclusions. Keep the assessment fee separate from the cost of implementing its recommendations.
The supplied evidence does not establish a comparable UK market price for these assessment scopes. An itemised quotation is therefore more useful than a price attached to an unspecified workshop.
Editorial analysis
CTC’s view is that a readiness report earns its fee when it changes a decision. “Proceed” should identify the permitted task, users, data and spending. A narrower recommendation should show exactly what has been excluded. A pause should assign the remedial work and state what evidence would allow the proposal to return.
For the wholesaler, a defensible result might be a proposed pilot limited to drafting replies from approved records, with staff retaining responsibility for delivery promises. That is an illustrative design, not a claim about a tested deployment.
Ask for findings that another provider or the internal team can use. The business needs to retain the source list, requirements findings, test materials and operating responsibilities after the assessment ends.
Sources
- Central Digital and Data Office, Generative AI framework for HM Government, version 1.0, February 2024
- GOV.UK, Guidelines and best practices for making government datasets ready for AI, published 19 January 2026
- Microsoft Learn, Minimum requirements to deploy Microsoft Copilot in your organisation, updated 8 September 2026
- Microsoft Learn, Prerequisites for managing agents in Microsoft 365
- Microsoft Learn, Microsoft Copilot adoption guide and overview for IT admins, updated 18 August 2026
- NCS London, AI Readiness Assessment Guide for UK Businesses, published 1 May 2025
- Kontain, AI Readiness for UK Businesses