AI Readiness Benchmark

A measurable answer to “are we ready for AI?”

The Keelix AI Readiness Benchmark scores an organisation's environment against 38 controls across 6 weighted domains, out of 100. It is a Keelix measurement instrument — not a certification.

Version v1.0.0Released 2026-086 domains · 38 controlsScored out of 100
What it is

One instrument, applied the same way every time

Most AI readiness conversations end in an opinion. This one ends in a number, a band and a named list of what to fix — produced the same way for every organisation we assess, so the result is comparable over time and defensible to a board.

◈

Weighted, not averaged. Each of the 6 domains carries a fixed weight totalling 100, so the areas that actually cause exposure count for more than the areas that are merely tidy.

◈

Evidence-scored. Every control is scored against evidence on the four-level maturity scale below — configuration exports, policy documents, review records — not against a self-assessment questionnaire.

◈

Anchored to the frameworks you are already held to. The control set is mapped to ISO/IEC 42001, the NIST AI Risk Management Framework, the ASD Essential Eight and the Privacy Act 1988. The benchmark measures readiness against those reference points; it is not an audit against any of them.

◈

What we publish here. Domain, weight, control count and what each domain examines. The individual control statements and their evidence requirements are part of the assessment itself and are provided to clients in their report, not published on this page.

⊘

Not a certification. Version 1.0.0 is a Keelix measurement instrument. It does not confer, replace or imply certification against any standard. Keelix de-risks your path to certification — we never issue it.

The 6 domains

Where readiness is won or lost

38 controls, grouped into 6 domains. The weights below are fixed and sum to 100 — they are not tuned per client.

Benchmark domains with their weight, control count and scope
DomainWeightControlsWhat it examines
A Identity & access boundaries20 / 1007Who can reach what, and whether those boundaries are deliberate.
B Data classification & sensitivity20 / 1006Whether the organisation knows which of its data is sensitive, and marks it.
C Oversharing & exposureCritical20 / 1007Whether enabling AI would surface content to people who should not see it. Any control scored 0 here caps the overall band at Conditionally ready.
D Data lifecycle & quality15 / 1005Whether what AI reads is current, owned and appropriately retained.
E AI governance & policy15 / 1007Whether AI use is governed, accountable and defensible to a regulator.
F Monitoring, audit & assurance10 / 1006Whether the organisation would notice if AI behaved badly.
Maturity scale

How each control is scored

Every control receives one of 4 scores. A control is only credited for what can be evidenced — intent and work-in-progress score below what is applied consistently.

The maturity scale applied to every control
ScoreLevelWhat it means
0AbsentNo evidence the control exists
1PartialExists informally or in part; not consistently applied
2SubstantialApplied consistently; gaps are known and bounded
3EmbeddedApplied, monitored, and reviewed on a defined cadence
Readiness bands

What the final score permits

Weighted domain scores roll up to a single result out of 100, which lands in one of 4 bands. The band is a decision, not a grade — it says what you can safely switch on next.

Readiness bands across the full 0-100 range
ScoreBandWhat it means
0–39Not readyMaterial risk of data exposure. Do not enable broad AI access.
40–59Conditionally readyScoped pilot only, with named controls and a restricted user group.
60–79Ready with conditionsBroad rollout viable once the named remediations are closed.
80–100ReadyProceed. Focus shifts to monitoring, adoption and optimisation.

The critical-fail rule. Domain C — Oversharing & exposure — is scored as a critical domain. If any control in it scores 0, the overall result is capped at Conditionally ready regardless of how strong the other domains are. A strong average must never mask a single catastrophic exposure hole.

Find out where you actually score

The readiness assessment applies this benchmark to your environment and returns your score, your band and the named remediations that move it. Fixed-price, two to three weeks.

See what the AI readiness service covers →
Book a readiness assessment

Keelix AI Readiness Benchmark version 1.0.0 (released 2026-08). The benchmark is a Keelix measurement instrument and is not a certification, accreditation or audit against ISO/IEC 42001, the NIST AI Risk Management Framework, the ASD Essential Eight or the Privacy Act 1988; it is aligned to them as reference frameworks. Keelix de-risks your path to certification — we never issue it. Nothing on this page is legal advice.