Most guidance on AI readiness is written for organizations with dedicated technical staff and a governance committee. If you have twenty people and no CIO, that guidance is not wrong so much as unusable.

The questions below are the ones that matter at that scale. They are deliberately answerable in an afternoon. If you cannot answer one, that is the work to do before adopting anything, not a reason to avoid adopting at all.

Data and Access

Question
Do you know what your AI tool can reach?

Assistants built into productivity suites inherit the permissions of the account using them. If a staff member has access to a shared drive they should not, the assistant will surface that content when asked a related question. Before enabling anything, audit what the average user can already reach.

Question
Is client or regulated information involved, and does your agreement cover it?

Consumer tiers of most AI products carry different data handling terms than business tiers. This is the single most common gap in small organizations: staff using a free account for work that is subject to a confidentiality obligation. Check the tier, not the brand.

Question
Do you know where the data is processed and how long it is retained?

You do not need a detailed technical answer. You need a documented one you can produce if a client, insurer, or agency asks. If nobody can point to it, that is the gap.

If you answer nothing else

Governance and Ownership

Question
Who owns the decision about what is allowed?

Not a committee. A person. At small scale, governance fails through diffusion rather than disagreement. Someone has to be able to answer whether a proposed use is acceptable without convening a meeting.

Question
Do staff know what is permitted?

In the absence of a stated policy, people apply their own judgment, and that judgment is usually more permissive than leadership expects. A single page covering what may and may not be put into an AI tool is sufficient. The failure is having nothing, not having something imperfect.

Question
Is AI-assisted output identified where it matters?

Decide in advance which categories of work require disclosure, internal review, or attribution. Client deliverables, regulatory submissions, and anything going on the record deserve an explicit answer before the situation arises rather than after.

Watch for

Shadow adoption. In most small organizations, staff are already using AI tools the organization has not evaluated. A policy written as though adoption has not started will be ignored by people who started six months ago. Ask what is already in use before writing anything.

Operational Fit

Question
Is the process you are applying this to actually understood?

AI applied to an unclear workflow produces faster ambiguity. If the steps, owners, and definition of a correct outcome are not written down, that is the prerequisite work.

Question
Who reviews the output, and do they have time to?

A verification step assigned to someone already at capacity is not a control. It is a formality that will be skipped in the first busy week. If nobody has the time, either make it or narrow the use case until review is realistic.

Reading Your Results

If you answered all eight comfortably, you are ready to adopt deliberately, starting with one use case rather than a broad rollout.

If the gaps were in access and data handling, resolve those first. They are the ones that create exposure rather than disappointment, and they are also the ones that get harder to fix once tools are in use.

If the gaps were in governance and ownership, you can proceed on a narrow use case while you close them, provided the named owner exists before the tool does.

Where to start

Answer questions one and two this week. They take under an hour between them and they surface the two problems most likely to matter: tools reaching more than they should, and staff working on a consumer account under a confidentiality obligation.