A measurable answer to “are we ready for AI?”
The Keelix AI Readiness Benchmark scores an organisation's environment against 38 controls across 6 weighted domains, out of 100. It is a Keelix measurement instrument — not a certification.
One instrument, applied the same way every time
Most AI readiness conversations end in an opinion. This one ends in a number, a band and a named list of what to fix — produced the same way for every organisation we assess, so the result is comparable over time and defensible to a board.
Weighted, not averaged. Each of the 6 domains carries a fixed weight totalling 100, so the areas that actually cause exposure count for more than the areas that are merely tidy.
Evidence-scored. Every control is scored against evidence on the four-level maturity scale below — configuration exports, policy documents, review records — not against a self-assessment questionnaire.
Anchored to the frameworks you are already held to. The control set is mapped to ISO/IEC 42001, the NIST AI Risk Management Framework, the ASD Essential Eight and the Privacy Act 1988. The benchmark measures readiness against those reference points; it is not an audit against any of them.
What we publish here. Domain, weight, control count and what each domain examines. The individual control statements and their evidence requirements are part of the assessment itself and are provided to clients in their report, not published on this page.
Not a certification. Version 1.0.0 is a Keelix measurement instrument. It does not confer, replace or imply certification against any standard. Keelix de-risks your path to certification — we never issue it.
Where readiness is won or lost
38 controls, grouped into 6 domains. The weights below are fixed and sum to 100 — they are not tuned per client.
| Domain | Weight | Controls | What it examines |
|---|---|---|---|
| A Identity & access boundaries | 20 / 100 | 7 | Who can reach what, and whether those boundaries are deliberate. |
| B Data classification & sensitivity | 20 / 100 | 6 | Whether the organisation knows which of its data is sensitive, and marks it. |
| C Oversharing & exposureCritical | 20 / 100 | 7 | Whether enabling AI would surface content to people who should not see it. Any control scored 0 here caps the overall band at Conditionally ready. |
| D Data lifecycle & quality | 15 / 100 | 5 | Whether what AI reads is current, owned and appropriately retained. |
| E AI governance & policy | 15 / 100 | 7 | Whether AI use is governed, accountable and defensible to a regulator. |
| F Monitoring, audit & assurance | 10 / 100 | 6 | Whether the organisation would notice if AI behaved badly. |
How each control is scored
Every control receives one of 4 scores. A control is only credited for what can be evidenced — intent and work-in-progress score below what is applied consistently.
| Score | Level | What it means |
|---|---|---|
| 0 | Absent | No evidence the control exists |
| 1 | Partial | Exists informally or in part; not consistently applied |
| 2 | Substantial | Applied consistently; gaps are known and bounded |
| 3 | Embedded | Applied, monitored, and reviewed on a defined cadence |
What the final score permits
Weighted domain scores roll up to a single result out of 100, which lands in one of 4 bands. The band is a decision, not a grade — it says what you can safely switch on next.
| Score | Band | What it means |
|---|---|---|
| 0–39 | Not ready | Material risk of data exposure. Do not enable broad AI access. |
| 40–59 | Conditionally ready | Scoped pilot only, with named controls and a restricted user group. |
| 60–79 | Ready with conditions | Broad rollout viable once the named remediations are closed. |
| 80–100 | Ready | Proceed. Focus shifts to monitoring, adoption and optimisation. |
The critical-fail rule. Domain C — Oversharing & exposure — is scored as a critical domain. If any control in it scores 0, the overall result is capped at Conditionally ready regardless of how strong the other domains are. A strong average must never mask a single catastrophic exposure hole.
Find out where you actually score
The readiness assessment applies this benchmark to your environment and returns your score, your band and the named remediations that move it. Fixed-price, two to three weeks.
See what the AI readiness service covers →Keelix AI Readiness Benchmark version 1.0.0 (released 2026-08). The benchmark is a Keelix measurement instrument and is not a certification, accreditation or audit against ISO/IEC 42001, the NIST AI Risk Management Framework, the ASD Essential Eight or the Privacy Act 1988; it is aligned to them as reference frameworks. Keelix de-risks your path to certification — we never issue it. Nothing on this page is legal advice.