Skip to content
Request an Architecture Assessment
AI for Business Decision framework

What should an AI initiative decide before it proceeds?

An AI readiness assessment should end in a decision, not a score: proceed within bounds, strengthen conditions first, or do not build yet.

By Ogwo Ijere Published Updated Verified 4 min read
AI readiness rubric connecting business consequence, owner, information, workflow, authority, recovery and measurement to three bounded decisions.
A readiness assessment turns seven operating inputs into a proceed, strengthen or do-not-build decision.
In this article

An AI readiness assessment should not tell an organisation that it is “72% ready”. It should decide what to do with one proposed initiative.

The three defensible outcomes are PROCEED — BOUNDED, STRENGTHEN CONDITIONS FIRST, or DO NOT BUILD YET. The decision depends on the business consequence, owner, information, workflow, authority, recovery and measurement—not on enthusiasm or a generic maturity score.

Assess a specific initiative

“Adopt AI” cannot be assessed. “Prepare a draft response to service enquiries for an adviser to approve” can. Name the affected decision, current workflow, intended user, expected improvement and plausible harm. Set the boundary tightly enough that stakeholders can inspect evidence rather than debate aspirations.

NIST AI RMF frames risk management through Govern, Map, Measure and Manage and stresses context across the lifecycle. ISO/IEC 42001 describes a management system for policies, objectives and processes around AI. These sources support structured, continuing governance. The following three-outcome rubric is netlinkE's decision method, not a NIST or ISO scoring model.

The seven readiness inputs

Input Ready evidence Warning Stop condition
Business consequence Outcome and affected parties are explicit Benefit is vague Material harm is unexamined
Owner One person owns outcome and intervention Committee ownership only Nobody can stop the initiative
Information Permitted sources, quality and provenance are known Material gaps need repair Use would be unlawful, prohibited or unknowable
Workflow Trigger, state, handoffs and exceptions are visible Exceptions are poorly measured No reliable system of record
Authority Allowed actions and approval thresholds are defined Review capacity is untested Consequential action has no boundary
Recovery Failures can be detected, contained and reconciled Manual recovery is slow Irreversible failure lacks treatment
Measurement Baseline, outcome and guardrails are agreed Proxy measures dominate Success cannot be distinguished from activity
AI readiness rubric connecting business consequence, owner, information, workflow, authority, recovery and measurement to three bounded decisions.
A readiness assessment turns seven operating inputs into a proceed, strengthen or do-not-build decision.

Decision one: PROCEED — BOUNDED

Proceed when the initiative has a named owner, a defined workflow slice, permitted and sufficiently reliable information, explicit authority, a workable recovery path and measures tied to the business outcome. “Bounded” means the initial scope, users, data, actions, duration and stop conditions are written down.

Proceeding does not mean risk is absent. It means uncertainty can be managed within an observable experiment. Use representative cases, preserve review for consequential actions and define what evidence is required before expansion.

Decision two: STRENGTHEN CONDITIONS FIRST

Choose this when the initiative is useful but its operating conditions are repairable and incomplete. Typical work includes clarifying ownership, cleaning a bounded information set, documenting exceptions, establishing an approval queue, creating a baseline or testing recovery.

This outcome needs a remediation plan with owners and evidence. “Do more discovery” is not enough. State which missing condition blocks the initiative and what will demonstrate that it has changed.

Decision three: DO NOT BUILD YET

Stop when the business problem is not important enough, the proposed use conflicts with a hard constraint, no accountable owner exists, the required information cannot be used responsibly, or the consequence cannot be recovered in proportion to the likely benefit.

This is not an anti-AI decision. It protects the organisation from turning an unresolved operating or policy problem into software. A later reassessment can be legitimate if the underlying condition changes.

Avoid arithmetic theatre

Do not average the seven inputs into a single number. A severe stop condition cannot be cancelled by six strong scores. Record evidence and apply decision rules:

  • Any unresolved hard stop leads to DO NOT BUILD YET.
  • No hard stop, but one or more material missing conditions leads to STRENGTHEN CONDITIONS FIRST.
  • All critical conditions evidenced at the proposed boundary leads to PROCEED — BOUNDED.

Add an expiry date to the decision. Information, providers, workflows and regulation can change. Readiness is a maintained operating judgment, not a permanent badge.

What to do next

Write a one-page initiative definition, gather the seven evidence sets and hold a decision review with the owner and the people responsible for information, workflow, risk and delivery. Record the outcome, conditions and reassessment trigger. Only then should detailed solution selection begin.

Sources and scope

NIST and ISO material provides external governance context. The seven-input, three-outcome rubric and its decision rules are original netlinkE analysis and recommendation. This is not an ISO/IEC 42001 certification assessment or legal advice.

Apply the architecture to a real operating constraint.

Start with the decisions, information, workflows, systems and authority boundaries that must work together.

Explore the related netlinkE capability

Sources and methodology

netlinkE decision rubric informed by NIST AI RMF, the NIST Playbook and ISO/IEC 42001 public material; not a certification assessment.

  1. External evidenceNIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)
  2. External evidenceNIST AI Risk Management Framework Playbook
  3. External evidenceISO/IEC 42001:2023 — AI management systems

Ogwo Ijere

AI Architect & Founder of netlinkE

Ogwo Ijere is the founder of netlinkE and an AI architect focused on designing AI-native operational infrastructure for businesses and institutions. His work connects AI architecture, operational design, agentic systems, workflow automation, digital authority and governed implementation—helping organisations turn fragmented processes, information and technology into coherent systems that can operate with AI.

Share this articleShare on LinkedInShare by email

Move from understanding to governed implementation.