Enterprise AI readiness is the combined ability to deliver a defined business outcome, control non-deterministic behavior, operate the workload, protect data, investigate failures, and recover verified business state.
11.1 Assessment method
Complete the review with business, product, architecture, AI engineering, operations, security, data, legal or compliance, and support representatives. Score the current production candidate rather than the intended target state.
Critical rule: a high average cannot override missing identity enforcement, unresolved data exposure, unverified high-impact action, legal prohibition, or absent recovery.
Business and use-case readiness
Business case, workflow map, baseline metrics, success thresholds, autonomy statement.
The use case is described only as productivity improvement without an owner or measurable task.
Ownership, governance, and lifecycle
RACI, asset registry, risk register, approval record, lifecycle and retirement policy.
A pilot has become business-critical but has no permanent owner or support model.
Architecture and integration readiness
Architecture diagrams, capability catalog, integration contracts, ADRs.
One agent loop owns permissions, workflow state, tools, and final business execution.
Data, grounding, and knowledge readiness
Data inventory, source contracts, retrieval tests, lineage, retention and deletion evidence.
The model can retrieve data outside the initiating user's access.
Security, privacy, and threat readiness
Threat model, identity design, policy tests, red-team results, DLP and incident playbook.
Security controls exist only in prompts or the model has broad raw system access.
Evaluation, testing, and quality readiness
Evaluation dataset, metric definitions, report, reviewer guide, canary and monitoring plan.
Quality approval depends on a few hand-selected demonstrations.
Reliability, continuity, and recovery readiness
SLOs, failure analysis, resilience tests, DR exercise, compensation and rollback evidence.
A timeout can trigger an unverified retry of a high-impact action.
Operations and GenAIOps readiness
Dashboards, alerts, trace example, runbooks, deployment pipeline and on-call readiness.
The team can observe only the final response and cannot reconstruct an incident.
Performance, capacity, and scale readiness
Capacity model, load-test report, quota dashboard, scaling and saturation behavior.
Production estimates extrapolate from a single-user demonstration.
Cost, efficiency, and value readiness
Unit economics, budget policy, cost dashboard, scenarios and finance sign-off.
The business case counts token cost but ignores integration and operating cost.
People, process, and change readiness
Training, user guidance, support model, communications, approval UX and feedback workflow.
Users are expected to control risk without training, evidence, or escalation authority.
Production launch decision
Signed readiness record, risk acceptance, canary plan, rollback plan and review date.
The launch relies on monitoring closely without measurable stop conditions or rollback authority.
11.2 Readiness scorecard
| Decision | Meaning | Required action |
|---|---|---|
| Ready | Critical gates meet target scores and no blockers remain. | Launch through the approved canary plan. |
| Conditionally ready | Noncritical gaps have owners, deadlines, and compensating controls. | Limit scope and track conditions to closure. |
| Pilot only | Controls support a restricted, reversible use but not target scale or impact. | Keep population and autonomy bounded. |
| Not ready | One or more critical blockers remain. | Do not launch; remediate and repeat the review. |
11.3 Minimum production evidence pack
The evidence pack must be versioned and tied to the exact agent, model, policy, connector, source, and evaluation versions covered by approval.
readiness_review:
workload: enterprise-contract-assistant
release: 2.4.0
decision: conditional_ready
approved_scope:
users: legal-operations-eu
autonomy: recommend_and_create_draft
data_classification: confidential
critical_gates:
security: 3
evaluation: 3
reliability: 2
conditions:
- owner: Platform Operations
action: complete secondary-region recovery exercise
due: 2026-09-15
evidence:
architecture: ADR-set-2.4
threat_model: TM-2026-08
evaluation_report: EV-2.4.0
rollback_test: RB-42
next_review: 2026-10-0111.4 Chapter summary
An enterprise AI workload is ready only when the organization can define its purpose, constrain its authority, evaluate its behavior, observe its operation, and recover verified business state after failure.
Core conclusion: production readiness is the ability to operate uncertainty with evidence, ownership, and reversible control.
Reference foundations
- Microsoft Azure Well-Architected Framework — AI workload documentation, assessment, operations, and architecture patterns.
- NIST AI Risk Management Framework: Generative AI Profile.
- AetherStaff Enterprise AI Integration Chapters 1–10.