Home
Solutions
For Medium-Sized Business For Small Business & Individuals For Large & Enterprise (AI Governance) AI Readiness & Governance About Insights Case Studies Start Free Assessment
AI Readiness & Governance

Know exactly where your business stands with AI.

A structured assessment against the standards that actually apply to you — ISO/IEC 42001, ISO/IEC 23894, the NIST AI Risk Management Framework and the EU AI Act. Scored, evidenced, and finished with one recommended next step. Start free, in under 12 minutes.

42 questions · under 12 minutes · no account, no card, no sales call required to receive your report.

The assessment, end to end
STAGE 1

Scope

Eight questions establish your sector, size, EU exposure and whether AI touches decisions about people. This decides which standards are relevant to you and nobody else.

STAGE 2

Answer

42 plain-English questions across eight dimensions. Nothing to look up. “Not sure” is a valid answer — and a useful one.

STAGE 3

Score

Two scores — Readiness and Governance — each placed in one of four maturity bands, with the critical questions weighted double.

STAGE 4

Findings

Reviewed personally, not generated. Prioritised findings, in your language, with the regulator named if one applies to you.

STAGE 5

One next step

Exactly one recommendation. If the honest answer is “nothing, revisit in six months”, that is what the report says.

Which one of these sounds like you?

Five doors, one assessment behind all of them. Pick the one that sounds most like your week and it will take you to the detail that actually applies.

01 · SMALL BUSINESS, 5–50 PEOPLE

“My team is using AI tools and nobody’s really in charge of it.”

The situation

AI arrived in your business the way it arrives in most — one person tried something useful, it spread, and nobody ever decided it. It works well enough that stopping feels silly, and nobody has had the time to ask what it is actually touching.

What this usually means in practice

  • Staff pasting client information into free AI accounts, because it saves twenty minutes and nobody said not to.
  • Nobody who can say no to a new tool — not because the authority is disputed, but because it was never assigned.
  • No record of which decisions the AI influenced, so a complaint six months from now cannot be traced or defended.

What the assessment checks for you

  • Whether one named person owns AI use — and whether they could actually stop a tool if they needed to.
  • Whether the people using AI know what they are allowed to use it for.
  • Which tools can reach your business and customer data, and whether anyone has a list.
  • Whether anything has already gone wrong, and whether anything changed as a result.

What you get

A Readiness score and a Governance score, each in a named maturity band, an inventory prompt of what is actually in use, the findings that matter most for a business your size — and one recommended next step.

Where to start

The free self-assessment. If the findings cluster around one specific issue — and at this size they usually do — a Mini Scan from £297 takes about two hours remotely and gives you a one-page finding on that single named issue.

Start the free assessment
02 · REGULATED PRACTICES AND FIRMS

“We’re regulated. I need to know what my regulator expects.”

The situation

You are used to being inspected, and you are good at it — but the AI question is new and nobody has told you what good looks like yet. The absence of a specific rule is being read, across your sector, as the absence of an obligation.

That reading is wrong, and it is the most common mistake we see.
There is no dedicated UK AI statute in force — the Artificial Intelligence (Regulation) Bill [HL] remains a private member’s bill, not government policy. But the UK approach is regulator-led, and your regulator is already active: the ICO on personal data, and the CQC, GDC, MHRA or FCA on how you use it in practice. No new law is required for existing obligations to apply to a new tool.
Regulatory position verified: 3 September 2026

What this usually means in practice

  • An AI note-taker or triage tool processing patient or client information with no completed data protection assessment behind it.
  • No named regulator identified, so nobody has read the guidance that already exists for your sector.
  • No evidence trail — so if an inspector asks how a specific AI-assisted decision was made, the answer is a description rather than a record.

What the assessment checks for you

  • Whether you can name the regulator that would take an interest, and whether anyone has read their guidance.
  • Whether AI tools touching personal data have been assessed against UK GDPR — formally, informally, or not at all.
  • Whether a person always reviews or can override AI output before it takes effect.
  • Whether an AI-assisted decision could be evidenced to a regulator, not just described.

What you get

Both scores and bands, findings framed against what your named regulator actually expects, the gaps most likely to be asked about at inspection — and one recommended next step.

Where to start

The free self-assessment — it names your likely regulator in the report. From there, a Quick Scan from £950, scoped to your regulator rather than to AI in general: about a day’s work remotely, and a 3–5 page report you could hand to a partner or a practice manager.

Start the free assessment

Dental, healthcare or pharmacy? Dentix7 is our dedicated practice-side service, CQC and GDC-aligned.

03 · MID-MARKET, 50–250 PEOPLE

“We’ve got AI everywhere and no idea what’s actually running.”

The situation

You are past the point where one person could list what is in use, and several departments have bought their own tools without anybody joining it up. The problem is no longer whether to use AI — it is that nobody can currently answer what you are running, on whose data, and with whose approval.

What this usually means in practice

  • Shadow AI — free accounts and personal logins that never appear on an invoice, so procurement has no visibility of them at all.
  • Tools that update themselves, changing behaviour in production with nobody checking the impact before it takes effect.
  • A real operational dependency on at least one tool that has no documented fallback if it stops working tomorrow.

What the assessment checks for you

  • Whether a maintained inventory of AI tools exists — including the free and personal ones.
  • Whether there is a defined approval step before a new tool starts being used, and whether a record is kept.
  • Whether tool changes are impact-checked before they go live.
  • What AI actually costs you, all in, and whether a business number was ever named for it to move.

What you get

Both scores and bands, the inventory and approval gaps written up in a form you can take to a management meeting, the areas where findings cluster — and one recommended next step.

Where to start

At this size the free tier is the scoping exercise, not the answer. Expect to move to a Quick Scan from £950 — about a day, remote, focused on the one business area where the findings cluster, with a 3–5 page report.

Start the free assessment
04 · FACING DUE DILIGENCE OR A TENDER

“A customer, insurer or investor has asked about our AI governance.”

The situation

A questionnaire has landed, and it asks things nobody in the business has ever been asked before. You are not looking for a maturity journey — you are looking for defensible answers, and a date by which you can give them.

What this usually means in practice

  • Questions that assume a written AI policy exists, when what exists is a shared understanding nobody has put on paper.
  • A request to evidence how a specific AI-assisted decision was made — where the honest answer today is that you could describe it, not show it.
  • Supplier terms accepted without close reading, so how your data is handled by the AI vendors you buy from is genuinely unknown.

What the assessment checks for you

  • Whether an AI-assisted decision could be produced as a record on request.
  • Whether a written, current, followed AI policy exists — and whether risk appetite has ever been decided rather than discussed.
  • How your AI suppliers handle your data, and whether that is covered in a contract.
  • Whether AI use is reported to a board, owners or a management meeting on any regular basis.

What you get

Both scores and bands, the specific gaps a diligence questionnaire will land on, an honest read on which answers you can already evidence — and one recommended next step.

Where to start

Start free to get the shape of it, then a Full Audit from £2,000 — up to a week, on-site and remote, across the whole business, with a report and a live debrief. Diligence answers have to hold up when they are checked, and that is what the paid tier examines.

Start the free assessment
05 · BUILDING A GOVERNANCE FUNCTION

“We’re serious about this and want to do it properly, end to end.”

The situation

You have decided this needs an owner, a structure and a calendar rather than a one-off piece of work. The open question is not whether to build the function, but how much function your organisation can actually carry — and appointing too much, too early, is as damaging as appointing nobody.

What this usually means in practice

  • Governance work that starts as a project and quietly stops when the person driving it moves on to something else.
  • A policy written and circulated, but no approval gate behind it — so the policy describes a process nobody has to follow.
  • Certification named as the goal before anyone has established the baseline it would be measured from.

What the assessment checks for you

  • All eight dimensions, across both scores — this is the group that needs the whole picture, not a slice of it.
  • Whether ownership is written into somebody’s role, or merely understood.
  • Whether there is budget or leadership backing for governance work in the next twelve months.
  • Whether incidents and near misses lead to a recorded change, which is the difference between a function and a filing cabinet.

What you get

Both scores and bands across all eight dimensions, a maturity profile you can baseline against later, the sequence the work should happen in — and one recommended next step.

Where to start

A Full Audit from £2,000 to establish the baseline, then the governance build — policy, approval gate, controls, Statement of Applicability and internal review, scoped per engagement. Where the function needs a standing owner rather than a project, that is the fractional Chief AI Officer route.

Start the free assessment

The method behind all of this — the five-stage lifecycle, the standards crosswalk and the Chief AI Officer roadmap — is documented on mahdiseify.com, the site of the person who built it.

What does an AI readiness assessment actually measure?

Eight dimensions, grouped into two scores. Readiness asks whether your organisation can use AI well. Governance asks whether it can prove it. They are scored separately on purpose, because the gap between them is usually the finding.

Score one

Readiness

Can you use AI well? Five dimensions.

  • 1 · Strategy & Value
    Whether AI is solving a named problem against a number you can point at, and whether you know what it costs you.
  • 2 · Leadership & Accountability
    Whether one named person owns AI use, whether they can stop a tool, and whether anyone reports on it upward.
  • 4 · Data Foundations
    Which tools reach your data, where that data comes from, and when its accuracy was last checked.
  • 5 · Systems & Lifecycle
    Whether there is a maintained inventory, whether tool changes are impact-checked, and what happens if a tool stops working.
  • 7 · People & Capability
    Whether the people using AI know what they are allowed to use it for, and whether anyone has been trained to use it safely.
Score two

Governance

Can you prove it? Three dimensions.

  • 3 · Policy & Regulatory Alignment
    Whether a written policy and an approval gate exist, whether risk appetite was decided, whether you can name your regulator, and whether EU AI Act exposure has been looked at.
  • 6 · Trust, Risk & Human Oversight
    Accuracy, explainability, supplier data handling, UK GDPR assessment, fairness, the effect on people decisions are made about — and whether a human always reviews output before it takes effect.
  • 8 · Assurance & Evidence
    Whether an AI-assisted decision could be produced as a record, and whether anything that has already gone wrong led to a change that was written down.
The single highest-priority finding on the whole instrument sits in dimension 6: whether any AI output reaches a customer or a decision with nobody reviewing it. When that answer is no, it outranks the entire scoring model.

The four maturity bands

0–25
Foundational

AI is in use, but nothing about it has been decided, owned or written down yet.

26–50
Developing

Good instincts and some real practice, held informally — it works because of who is there, not because of what is in place.

51–75
Established

Written, followed and owned. The structure exists; the remaining gaps are specific rather than general.

76–100
Advanced

Evidenced, reviewed on a schedule, and improved when something goes wrong. Ready to be examined by someone else.

How does the assessment work?

Four steps. You answer, we score, we write the findings, and you get one recommended next step — by email, within two working days, whether or not you ever speak to us.

1

Answer

42 questions, under 12 minutes, no jargon and nothing to look up. “Not sure” is a valid answer to every one of them.

2

Score

Two scores across eight dimensions, with the critical questions weighted double, each placed in one of four maturity bands.

3

Findings

Reviewed personally by Dr. Mahdi Seify — not generated automatically — and written for an organisation of your sector and size.

4

One next step

Exactly one recommendation. If it is “nothing, revisit in six months”, the report says that instead.

Most AI maturity tools hand you a list of twenty things to fix. This one ends with a single recommended next step. A business given ten priorities has been given none.

How much does an AI audit cost in the UK?

Ours are published, in text, below. The self-assessment is free. Beyond that, a Mini Scan is from £297, a Quick Scan from £950, and a Full Audit from £2,000. Governance build and certification readiness work is scoped per engagement, because honestly quoting it before seeing the baseline would be guessing.

Tier What’s included How long Who’s involved What you receive Price
Free AI Readiness Self-Assessment All 42 questions, across eight dimensions and both scores. Under 12 minutes You. Reviewed personally before the report is issued. Scored report, maturity bands, prioritised findings, one recommended next step. Free
Mini Scan One named issue, examined rather than self-reported. ~2 hours, remote You and Dr. Seify, remotely. One-page finding on the single named issue, with the action attached to it. From £297
AI Readiness Quick Scan One business area — or, for regulated practices, scoped to your named regulator. ~1 day, remote You, the relevant area lead, and Dr. Seify. 3–5 page report with prioritised findings and quick wins. From £950
Full AI & Business Analytics Audit The whole business, all eight dimensions, evidence examined. Up to a week, on-site and remote Multiple stakeholders across the business, led personally by Dr. Seify. Detailed prioritised roadmap, plus a live debrief. From £2,000
Governance build Policy, approval gate, controls, Statement of Applicability, internal review. Scoped per engagement Your owner or council, supported by Dr. Seify. A working governance framework, not a document set. Scoped per engagement
Certification readiness Gap assessment against ISO/IEC 42001 ahead of engaging an accredited body. VisionXY7 does not certify. Scoped per engagement Your team, with independent review by Dr. Seify. Gap report and remediation plan, ready to take to a certification body. Scoped per engagement
Fractional Chief AI Officer One to four days a month. Chairs the AI Leadership Council, owns the governance calendar. Ongoing retainer Dr. Seify, as your standing AI owner. A function that keeps running between projects. See mahdiseify.com →
What the paid tiers actually buy you.
The free assessment is scored on what you tell us. The paid tiers examine the evidence behind your answers — which is why a top score isn’t available on the free tier. That’s deliberate, and it’s the difference you’re paying for.

Delivered by Dr. Mahdi Seify — PhD in AI-Driven Business Analytics (University of Liverpool), ISO/IEC 27001 Lead Auditor and Lead Implementer.

And if the answer is something else entirely

Sometimes the assessment surfaces something that isn’t a governance problem at all. If the honest answer is “your admin is eating three days a week” or “nobody can find you”, we’ll say that instead — and there’s a good chance we can help with it.

This is context, not a menu. Your report still ends with exactly one recommendation.

What is this assessment grounded in?

Five reference frameworks, named plainly. Where a standard is mentioned anywhere on this site, you will find one clause saying what it is actually for — because a standard nobody can explain is decoration, not grounding.

ISO/IEC 42001

The management-system standard for AI — how an organisation governs AI on an ongoing basis, the way ISO/IEC 27001 does for information security.

ISO/IEC 23894

Guidance on managing AI risk — how to identify, assess and treat the risks a specific AI system creates.

ISO/IEC 42005

Guidance on AI system impact assessment — how to work out the effect on the people an AI-supported decision is about.

NIST AI RMF

The US risk-management framework built on four functions — Govern, Map, Measure, Manage — widely used as a practical structure regardless of jurisdiction.

EU AI Act

EU law that sorts AI systems into risk categories and attaches obligations to each. It can apply to a UK business whose AI output is used in the EU.

This is a readiness self-assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006.

Where the regulation currently stands

Regulatory position verified: 3 September 2026
  • EU AI Act GPAI obligations came into force on 2 August 2026.
  • EU AI Act high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package.
  • The UK Artificial Intelligence (Regulation) Bill [HL] remains a private member’s bill, not government policy. The UK approach is regulator-led — ICO, MHRA, FCA, CQC, GDC.
  • No UK AI statute does not mean no obligations. Sector regulators are already active, and existing duties apply to new tools without anyone needing to legislate again.

General information, not legal advice. This position is re-verified every 90 days.

Questions people actually ask

Do I need this if we only use ChatGPT?

Yes, and often more than organisations running bespoke systems. Most of the exposure we find sits in general-purpose tools used informally: client or patient information pasted into free accounts, no record of which decisions the output influenced, and nobody with the authority to say no to a new tool. A single widely used assistant, unmanaged, is a bigger governance gap than a well-documented custom system.

Does the EU AI Act apply to a UK business?

It can. The EU AI Act applies on the basis of where the output is used, not only where the provider is established — so a UK business whose AI output is used by people in the EU can fall in scope. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Two questions in the assessment appear only if you tell us you operate in, sell into or serve customers in the EU, and they establish whether this is worth your attention. Position verified 3 September 2026; general information, not legal advice.

What’s the difference between AI readiness and AI compliance?

Readiness is a measure of how well prepared your organisation is: whether AI use is owned, documented, reviewed and evidenced. Compliance is a formal determination against a specific standard or regulation, made by a body with the authority to make it. This assessment measures readiness — a score, a maturity profile and prioritised findings. It never states that an organisation is or is not compliant with anything, because that is not a claim we are in a position to make.

Will this tell me whether we’re compliant?

No. It tells you where you stand and what the standards actually ask of you, which is what most organisations are missing. Anyone selling you a compliance verdict from a questionnaire is selling you something they cannot deliver.

We’re a small clinic — is this overkill?

No. A small regulated practice usually has a shorter list of AI tools and a shorter route to fixing what matters, which makes the assessment quicker and the findings more actionable, not less. The free tier takes under twelve minutes and costs nothing. If you tell us you are regulated, the report names the regulator likely to take an interest in how you use AI — ICO, CQC, GDC or MHRA depending on what you do.

How long does it take, and what do you need from us?

The free self-assessment is 42 questions and takes most people under twelve minutes. Nothing needs looking up, no technical knowledge is required, and “Not sure” is a valid answer to every question — knowing what you don’t know is part of what this measures. Your scored report comes back by email within two working days. The paid tiers need more of your time: a Mini Scan is about two hours remote, a Quick Scan about a day, and a Full Audit up to a week combining on-site and remote work.

What happens after the assessment?

You receive a report with your readiness and governance scores, what they mean, the findings that matter most for an organisation like yours, and exactly one recommended next step. Sometimes that step is “nothing, revisit in six months” — and when it is, that is what the report says. Nothing else happens until you have read it. No sales call is required to receive it, and we send it whether or not you book anything.

Who sees our answers, and how is our data handled?

Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Data is encrypted in transit and at rest, hosted in the UK or EEA, and handled under ISO/IEC 27001-aligned practice. Consent to receive the report and consent to marketing are asked separately, and either can be withdrawn. We never ask for documents, and we ask you not to put personal, client or patient information in the free-text boxes. Records are kept for 24 months and then deleted or irreversibly anonymised, and you can ask for deletion at any time without logging in to anything. The full detail is in the assessment privacy notice.

Do you certify us against ISO/IEC 42001?

No — and no consultancy can. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What VisionXY7 does is prepare you for that assessment: a gap assessment against the standard, the policy and control framework to close what is missing, and an independent internal review before you engage an accredited body. If a consultancy offers to certify you against ISO/IEC 42001, they are describing something they are not able to do, and that is worth knowing before you sign anything.

Who is behind the assessment?

This instrument is new, so there is no assessment case study to show you yet — and inventing one would be a strange way to open a conversation about governance. What there is instead is the method, and the person who built it.

Dr. Mahdi Seify

  • PhD, AI-Driven Business Analytics, University of Liverpool.
  • ISO/IEC 27001 Lead Auditor & Lead Implementer — current. The assessment procedure is built on that audit methodology, which is why it asks for evidence rather than opinion.
  • Working knowledge of ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, the NIST AI Risk Management Framework and the EU AI Act, applied through that same methodology.
  • Originator of the Deep Business Analytics (DBA) framework, tested on Royal Liverpool University Hospital data. Separately, led an analytics programme across 15 million+ records for the German Federal Health System.

The full method — the five-stage lifecycle mapped to ISO/IEC 42001 clauses, the eight dimensions, the maturity and evidence scales, and the standards crosswalk — is documented on his own site.

“Mahdi turned our complex ideas into clear, actionable solutions and delivered precisely what we needed. Professional, fast and strategically sharp.”

Neal Maxwell
Neal Maxwell
Director · Changing Streams CIC

“Mahdi delivered a high-impact analytics and automation solution that improved our processes and added immediate operational value. Technically thorough and genuinely focused on embedding the solution.”

Matt Tynan
Matt Tynan
Automation & High Throughput Science Manager · Unilever
See the delivery track record behind this →

Find out where you actually stand.

42 questions, under 12 minutes. A scored report by email within two working days, reviewed personally, with one recommended next step. No account, no card, and no sales call required to receive it.

Start the free assessment
This is a readiness self-assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006.