AI Services · One-time · 3 weeks

AI Assessment

Know what an AI rollout would expose across your environment, what to close first, and where AI would genuinely save your people time — in one assessment, with one readout.

Copilot is one licence away. What it surfaces on day one is everything already overshared, unlabelled, and ungoverned in your environment. Copilot does not create that exposure; it makes it findable.
At the same time, the return on an AI rollout is decided by people rather than by configuration — by whether the work your teams actually do is work that AI can shorten, and by whether they will use it once it is there. Most assessments answer one of those questions. This one answers both, and ends with a costed plan rather than a list of findings.

What We Assess

Both halves of AI readiness — whether your people will adopt it, and whether your environment can safely carry it.

AI Readiness

Copilot security posture, Copilot data governance, identity and MFA coverage, and third-party application risk — the Copilot-specific layer that no security baseline framework covers.

Data Exposure

Where business data sits open today: external sharing site by site, unclassified content, ownership gaps, and stale data that an AI assistant would surface alongside everything current.

Governance Controls

The status of the controls that decide whether AI can be governed once deployed — data loss prevention, retention, sensitivity labels, unified audit logging, and insider risk.

Security Baseline

Your environment measured against the Microsoft Security Baseline and CIS Controls v8.1, with Microsoft Secure Score — across Entra ID, Exchange, Teams, Intune, SharePoint, Defender, and Purview.

Shadow AI and Agents

Every AI tool and agent already operating against your data, with its owner, what it can reach, and whether it ever went through an approval.

Employee Readiness

An interactive survey with working use-case demonstrations, establishing how ready your teams actually are and which workflows they would apply AI to first.

How It Works

Five steps from a read-only connection to an executive readout.

1. Connect

A read-only connection to your environment. No software is installed and no agents are deployed.

2. Scan

Automated evaluation against Microsoft best-practice baselines and the NIST AI Risk Management Framework, covering security posture and data governance together.

3. Survey

Your team completes a short AI readiness survey with live use-case demonstrations, so the recommendations reflect how your people work rather than assumptions about it. This step paces the engagement — the readout is scheduled once responses are in.

4. Reconcile

Findings are validated across both assessment engines before they reach you, so what you receive is verified rather than raw platform output.

5. Readout

An executive session covering the findings, the 90-day roadmap, and the decisions in front of you — written for leadership rather than for IT.

What You Receive

Seven deliverables, reconciled and presented in one readout.

  • AI Readiness Scan

    Copilot posture, data governance, identity coverage, app risk

  • Data Governance Assessment

    Control status and a site-by-site exposure view

  • Security Baseline Audit

    Secure Score, Microsoft Security Baseline, CIS Controls v8.1

  • Shadow AI and Agent Inventory

    What is already running, and under whose authority

  • Employee AI Readiness

    Survey results and a ranked use-case shortlist with hours attached

  • AI Acceptable Use Policy

    A complete policy document, published to your team

  • Executive Plan and 90-Day Roadmap

    Board-ready findings with named owners, and prioritized use cases phased across kickoff and two delivery phases

What Follows

The assessment is designed to end with decisions, not a document. Where it identifies gaps, remediation is scoped and quoted against the findings — we are always the ones who show you the gaps, and not always the ones who close them. Where you want the posture maintained rather than corrected once, it continues as a Managed AI Service.

Find out where you stand before you turn AI on.

Three weeks from connection to executive readout, once your team has completed the survey.

Request an AI Assessment