AI Readiness Checklist¶
Purpose: Assess your organisation's preparedness for safe AI adoption Audience: Leadership, governance and technical teams | Time: 15-30 minutes
How to Use This Checklist
- Print or share this checklist with stakeholders
- Read through each section individually or as a team
- Discuss each section and tick boxes that apply to your organisation
- Document evidence for each checked item
- Tally your score using the guide below
- Identify priority gaps to address
- Create an action plan for unchecked items with owners and timeframes
This checklist helps Australian businesses decide if they are ready to adopt AI safely, responsibly and effectively.
This checklist supports practical work under the Australian Government’s Guidance for AI Adoption (AI6) and selected governance topics in ISO/IEC 42001:2023 and NIST AI RMF 1.0 (2023). It is a planning aid, not a conformity assessment.
Tick an item only when you can point to supporting evidence. Record unresolved or not-applicable items with a reason; do not count them as completed. The total tracks progress across this checklist and does not determine whether a particular AI use is safe to proceed.
Assessment Sections¶
1️⃣ Strategy & Governance¶
- Clear AI vision linked to business goals
- A designated senior executive accountable for AI initiatives
- An AI Use Policy covering acceptable use, privacy, and IP
- Approval process for new AI initiatives
- Change management plan for AI adoption
- Stakeholder communication strategy defined
2️⃣ Data & Privacy¶
- Up-to-date data inventory and quality checks
- Applicable privacy duties identified and the required controls documented, including the Privacy Act 1988 and APPs where they apply
- Protections for business IP and checks on data rights, copyright and licences
- Processes to anonymise or pseudonymise personal data, with re-identification risks assessed for the intended use
Pseudonymisation does not by itself make information legally de-identified. Use the OAIC’s de-identification guidance to assess whether people remain identifiable in context.
3️⃣ Risk & Impact¶
- Risk and impact assessments completed (bias, safety, rights)
- High-risk use cases identified and controlled
- Sign-offs recorded before deployment
4️⃣ People & Skills¶
- Human oversight for important decisions
- Staff trained on safe AI use and escalation paths
- Clear process for reporting incidents or issues
5️⃣ Testing & Monitoring¶
- Pre-deployment testing (performance, fairness, robustness)
- Ongoing monitoring for errors, drift and safety
- Records kept of models, prompts and key decisions
6️⃣ Suppliers & Partners¶
- Vendor evidence assessed against relevant VAISS (2024) guardrails, with gaps and responsibilities recorded
- Contracts cover privacy, IP and security requirements
- Regular review of vendor practices and updates
7️⃣ Financial & Resource Readiness¶
- AI budget allocated and approved
- ROI expectations and success metrics defined
- Resources identified for ongoing maintenance and updates
- Cost-benefit analysis completed
Interpreting Your Score¶
Count completed items out of 26. The bands below are indicative ways to organise follow-up work; they are not validated readiness thresholds.
Before starting a pilot or wider deployment: confirm an accountable owner, approved tools and permitted data, a use-case risk assessment, required privacy and IP controls, pre-deployment testing, human oversight, an incident escalation path and recorded approval. A high total cannot compensate for an unresolved requirement in these areas. Wider deployment also needs evidence that the controls work at the proposed scale.
Early Stage (0–10 items checked)
Status: Building foundations Recommendation: Prioritise governance and staff skills, and resolve the conditions above before any deployment
Priority actions:
- 📋 Draft an AI Use Policy
- 👥 Identify a senior executive to lead AI initiatives
- 🎯 Work through the AI Risk Assessment Checklist
Example: Organisation exploring AI but lacking formal processes
Mid Stage (11–20 items checked)
Status: Building evidence for a pilot decision Recommendation: Resolve the conditions above before authorising a controlled trial
Priority actions:
- 🧪 Define a small pilot’s scope, controls and approval conditions
- 📊 Set up an AI Project Register
- ⚠️ Conduct a risk assessment for each use case
Example: Organisation with basic governance preparing evidence for a controlled trial
Advanced Stage (21–26 items checked)
Status: Preparing for a scaling decision Recommendation: Review pilot results, remaining gaps and controls before approving wider deployment
Priority actions:
- 🚀 Assess whether successful pilots can operate safely at the proposed scale
- 📈 Implement AI Assurance practices
- 🔄 Establish regular governance reviews
Example: Organisation with established governance assessing wider use of its AI systems
Alignment with Australian Standards¶
These examples show how the checklist can support selected framework practices. They do not establish compliance with every requirement.
Framework Support
✓ Understand impacts and plan accordingly — Section 3 prompts risk and impact assessment
✓ Decide who is accountable — Section 1 prompts executive ownership and approval arrangements
✓ Test and monitor — Section 5 prompts testing and monitoring evidence
✓ Guardrail 1 – Accountability and governance — Section 1 prompts ownership and governance arrangements
✓ Guardrail 2 – Risk management — Section 3 prompts risk assessment and controls
✓ Guardrail 4 – Testing and monitoring — Section 5 prompts evaluation before and during use
✓ Guardrail 8 – Supply-chain information sharing — Section 6 prompts supplier evidence and review; information-sharing arrangements still need to be agreed
✓ Guardrail 9 – Records — Section 5 prompts records of models, prompts and decisions
Guardrail labels are shortened summaries of the published VAISS (2024) catalogue.
Next Steps¶
Where to go from here:
- ✅ Score 0–10? Start with: AI Use Policy
- ✅ Score 11–20? Set up: AI Project Register
- ✅ Score 21–26? Plan a scaling review with: AI Implementation Roadmap
Related templates:
- 📋 AI Risk Assessment Checklist — Evaluate specific AI systems
- 🔄 AI Change Management — Plan organisational rollout
- 📊 AI Vendor Evaluation — Assess third-party tools
Disclaimer & Licence
Disclaimer: This template provides best practice guidance for Australian organisations. SafeAI-Aus has exercised care in preparation but does not guarantee accuracy, reliability, or completeness. Organisations should adapt to their specific context and may wish to seek advice from legal, governance, or compliance professionals before formal adoption.
Licence: Licensed under Creative Commons Attribution 4.0 (CC BY 4.0). You are free to copy, adapt and redistribute with attribution: "Source: SafeAI-Aus (safeaiaus.org)"