Home
Solutions
For Medium-Sized Business For Small Business & Individuals For Large & Enterprise (AI Governance) Enterprise AI Governance About Insights Case Studies Start Free Assessment
Assessment one of two · free

AI Readiness & Maturity Assessment

Two questions, really. Can your organisation use AI well? And could it show anyone that it does? Forty-two plain-English questions answer both, scored separately, because the gap between the two is usually the finding.

42 questions · under 12 minutes · no account, no card, no sales call required to receive your report.

Been asked for ISO/IEC 42001 by name — in a tender, a customer questionnaire, or by an insurer? That is a different question, and there is a different assessment for it. Go to the ISO/IEC 42001 assessment →

The assessment, end to end
STAGE 1

Scope

Eight questions establish your sector, size, EU exposure and whether AI touches decisions about people. This decides which standards are relevant to you and nobody else.

STAGE 2

Answer

42 plain-English questions across eight dimensions. Nothing to look up. “Not sure” is a valid answer — and a useful one.

STAGE 3

Score

Two scores — Readiness and Governance — each placed in one of four maturity bands, with the critical questions weighted double.

STAGE 4

Findings

Prioritised findings, in your language, weighted so the ones that matter most come first, with the regulator named if one applies to you.

STAGE 5

One next step

Exactly one recommendation. If the honest answer is “nothing, revisit in six months”, that is what the report says.

What does an AI readiness assessment actually measure?

Eight dimensions, grouped into two scores. Readiness asks whether your organisation can use AI well. Governance asks whether it can prove it. They are scored separately on purpose, because the gap between them is usually the finding.

Score one

Readiness

Can you use AI well? Five dimensions.

  • 1 · Strategy & Value
    Whether AI is solving a named problem against a number you can point at, and whether you know what it costs you.
  • 2 · Leadership & Accountability
    Whether one named person owns AI use, whether they can stop a tool, and whether anyone reports on it upward.
  • 4 · Data Foundations
    Which tools reach your data, where that data comes from, and when its accuracy was last checked.
  • 5 · Systems & Lifecycle
    Whether there is a maintained inventory, whether tool changes are impact-checked, and what happens if a tool stops working.
  • 7 · People & Capability
    Whether the people using AI know what they are allowed to use it for, and whether anyone has been trained to use it safely.
Score two

Governance

Can you prove it? Three dimensions.

  • 3 · Policy & Regulatory Alignment
    Whether a written policy and an approval gate exist, whether risk appetite was decided, whether you can name your regulator, and whether EU AI Act exposure has been looked at.
  • 6 · Trust, Risk & Human Oversight
    Accuracy, explainability, supplier data handling, UK GDPR assessment, fairness, the effect on people decisions are made about — and whether a human always reviews output before it takes effect.
  • 8 · Assurance & Evidence
    Whether an AI-assisted decision could be produced as a record, and whether anything that has already gone wrong led to a change that was written down.
The single highest-priority finding on the whole instrument sits in dimension 6: whether any AI output reaches a customer or a decision with nobody reviewing it. When that answer is no, it outranks the entire scoring model.

If you have been asked for ISO/IEC 42001 specifically, there is a separate assessment mapped directly to the standard’s clauses and controls — eight domains, eight Stage 1 gates, and a control-by-control gap register. See the ISO/IEC 42001 assessment →

The four maturity bands

0–25
Foundational

AI is in use, but nothing about it has been decided, owned or written down yet.

26–50
Developing

Good instincts and some real practice, held informally — it works because of who is there, not because of what is in place.

51–75
Established

Written, followed and owned. The structure exists; the remaining gaps are specific rather than general.

76–100
Advanced

Evidenced, reviewed on a schedule, and improved when something goes wrong. Ready to be examined by someone else.

How does the assessment work?

Four steps. You answer, we score, the findings are written up, and you get one recommended next step — by email, immediately, whether or not you ever speak to us.

1

Answer

42 questions, under 12 minutes, no jargon and nothing to look up. “Not sure” is a valid answer to every one of them.

2

Score

Two scores across eight dimensions, with the critical questions weighted double, each placed in one of four maturity bands.

3

Findings

Scored against your sector and size, with the findings that carry the most weight named in plain language — and Dr. Mahdi Seify reads every submission personally afterwards.

4

One next step

Exactly one recommendation. If it is “nothing, revisit in six months”, the report says that instead.

Most AI maturity tools hand you a list of twenty things to fix. This one ends with a single recommended next step. A business given ten priorities has been given none.

And then what?

The free assessment is scored on what you tell us. Everything above it examines the evidence behind those answers. You are never moved up a rung by the report — it recommends one next step, and sometimes that step is “nothing, revisit in six months”.

You are here

Free self-assessment

Scored on what you report. Eight dimensions, two scores, one next step, emailed immediately.

Next rung

Mini Scan & Quick Scan

From £297 and from £950. Someone looks at the evidence behind one named issue, or one business area.

Whole business

Full audit & governance build

From £2,000. Up to a week, on-site and remote, report plus live debrief — then the policy, the approval gate and the controls if you want them built.

See the full ladder, with every price →

What is this assessment grounded in?

Five reference frameworks, named plainly. Where a standard is mentioned anywhere on this site, you will find one clause saying what it is actually for — because a standard nobody can explain is decoration, not grounding.

ISO/IEC 42001

The management-system standard for AI — how an organisation governs AI on an ongoing basis, the way ISO/IEC 27001 does for information security.

ISO/IEC 23894

Guidance on managing AI risk — how to identify, assess and treat the risks a specific AI system creates.

ISO/IEC 42005

Guidance on AI system impact assessment — how to work out the effect on the people an AI-supported decision is about.

NIST AI RMF

The US risk-management framework built on four functions — Govern, Map, Measure, Manage — widely used as a practical structure regardless of jurisdiction.

EU AI Act

EU law that sorts AI systems into risk categories and attaches obligations to each. It can apply to a UK business whose AI output is used in the EU.

This is a readiness self-assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006.

Where the regulation currently stands

Regulatory position verified: 3 September 2026
  • EU AI Act GPAI obligations came into force on 2 August 2026.
  • EU AI Act high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package.
  • The UK Artificial Intelligence (Regulation) Bill [HL] remains a private member’s bill, not government policy. The UK approach is regulator-led — ICO, MHRA, FCA, CQC, GDC.
  • No UK AI statute does not mean no obligations. Sector regulators are already active, and existing duties apply to new tools without anyone needing to legislate again.

General information, not legal advice. This position is re-verified every 90 days.

Questions people actually ask

Do I need this if we only use ChatGPT?

Yes, and often more than organisations running bespoke systems. Most of the exposure we find sits in general-purpose tools used informally: client or patient information pasted into free accounts, no record of which decisions the output influenced, and nobody with the authority to say no to a new tool. A single widely used assistant, unmanaged, is a bigger governance gap than a well-documented custom system.

Does the EU AI Act apply to a UK business?

It can. The EU AI Act applies on the basis of where the output is used, not only where the provider is established — so a UK business whose AI output is used by people in the EU can fall in scope. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Two questions in the assessment appear only if you tell us you operate in, sell into or serve customers in the EU, and they establish whether this is worth your attention. Position verified 3 September 2026; general information, not legal advice.

What’s the difference between AI readiness and AI compliance?

Readiness is a measure of how well prepared your organisation is: whether AI use is owned, documented, reviewed and evidenced. Compliance is a formal determination against a specific standard or regulation, made by a body with the authority to make it. This assessment measures readiness — a score, a maturity profile and prioritised findings. It never states that an organisation is or is not compliant with anything, because that is not a claim we are in a position to make.

Will this tell me whether we’re compliant?

No. It tells you where you stand and what the standards actually ask of you, which is what most organisations are missing. Anyone selling you a compliance verdict from a questionnaire is selling you something they cannot deliver.

We’re a small clinic — is this overkill?

No. A small regulated practice usually has a shorter list of AI tools and a shorter route to fixing what matters, which makes the assessment quicker and the findings more actionable, not less. The free tier takes under twelve minutes and costs nothing. If you tell us you are regulated, the report names the regulator likely to take an interest in how you use AI — ICO, CQC, GDC or MHRA depending on what you do.

How long does it take, and what do you need from us?

The free self-assessment is 42 questions and takes most people under twelve minutes. Nothing needs looking up, no technical knowledge is required, and “Not sure” is a valid answer to every question — knowing what you don’t know is part of what this measures. Your scored report arrives by email as soon as you finish. The paid tiers need more of your time: a Mini Scan is about two hours remote, a Quick Scan about a day, and a Full Audit up to a week combining on-site and remote work.

What happens after the assessment?

You receive a report with your readiness and governance scores, what they mean, the findings that matter most for an organisation like yours, and exactly one recommended next step. Sometimes that step is “nothing, revisit in six months” — and when it is, that is what the report says. Nothing else happens until you have read it. No sales call is required to receive it, and we send it whether or not you book anything.

Who sees our answers, and how is our data handled?

Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Data is encrypted in transit and at rest, hosted in the UK or EEA, and handled under ISO/IEC 27001-aligned practice. Consent to receive the report and consent to marketing are asked separately, and either can be withdrawn. We never ask for documents, and we ask you not to put personal, client or patient information in the free-text boxes. Records are kept for 24 months and then deleted or irreversibly anonymised, and you can ask for deletion at any time without logging in to anything. The full detail is in the assessment privacy notice.

Do you certify us against ISO/IEC 42001?

No — and no consultancy can. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What VisionXY7 does is prepare you for that assessment: a gap assessment against the standard, the policy and control framework to close what is missing, and an independent internal review before you engage an accredited body. If a consultancy offers to certify you against ISO/IEC 42001, they are describing something they are not able to do, and that is worth knowing before you sign anything.

Who is behind the assessment?

This instrument is new, so there is no assessment case study to show you yet — and inventing one would be a strange way to open a conversation about governance. What there is instead is the method, and the person who built it.

Dr. Mahdi Seify

  • PhD, AI-Driven Business Analytics, University of Liverpool.
  • ISO/IEC 27001 Lead Auditor & Lead Implementer — current. The assessment procedure is built on that audit methodology, which is why it asks for evidence rather than opinion.
  • Working knowledge of ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, the NIST AI Risk Management Framework and the EU AI Act, applied through that same methodology.
  • Originator of the Deep Business Analytics (DBA) framework, tested on Royal Liverpool University Hospital data. Separately, led an analytics programme across 15 million+ records for the German Federal Health System.

The full method — the five-stage lifecycle mapped to ISO/IEC 42001 clauses, the eight dimensions, the maturity and evidence scales, and the standards crosswalk — is documented on his own site.

“Mahdi turned our complex ideas into clear, actionable solutions and delivered precisely what we needed. Professional, fast and strategically sharp.”

Neal Maxwell
Neal Maxwell
Director · Changing Streams CIC

“Mahdi delivered a high-impact analytics and automation solution that improved our processes and added immediate operational value. Technically thorough and genuinely focused on embedding the solution.”

Matt Tynan
Matt Tynan
Automation & High Throughput Science Manager · Unilever
See the delivery track record behind this →

Find out where you actually stand.

42 questions, under 12 minutes. Your scored report arrives by email straight away — a maturity profile across eight dimensions, and exactly one recommended next step. No account, no card, and no sales call required to receive it.

Start the free assessment

Asked for ISO/IEC 42001 specifically? That assessment is here →

This is a readiness self-assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. VisionXY7 Ltd does not certify, and no consultancy can. VisionXY7 prepares organisations for certification and reviews their systems independently.