What an AI readiness assessment should cover before you hire anyone
6 minute read. Updated 2026-08-08.
An AI readiness assessment should check four things before you write a job spec: the state of your data, a measurable definition of success, who owns AI-specific risk, and what you already have in-house. In practice the finding is almost always the same: the data is not fit for the use case, and no specialist, however senior, can fix that on day one. Run the assessment first, hire second.
Do the assessment before you write the job spec
Most businesses write the job advert first. They decide they need a machine learning engineer, or a head of AI, and only discover once that person starts that the real problem sits somewhere else entirely. That is an expensive way to find out.
A readiness assessment is a short, structured look at your data, your use case and your governance gap, done before recruitment starts. It takes days, not months. It tells you what seniority you actually need, and sometimes tells you that you do not need a hire at all.
Check the data before you check anything else
In almost every assessment I have seen, the finding is the same. The AI problem turns out to be a data problem wearing an AI costume. Where does the data live. Who owns it. Is it labelled consistently. Are there multiple versions of the same customer record, each showing a different address.
This matters because no amount of model sophistication fixes broken data underneath it. A generative AI specialist, advertised at a median £550 a day over the six months to August 2026, cannot make a customer-facing tool reliable if the records it draws on are duplicated or stale. Fix the plumbing before you pay for the tap.
Write down what success means, in numbers you can check
Ask what 'it works' means before you recruit for it. A measurable outcome, not a feeling. Fewer support tickets, faster turnaround on a specific task, a defined accuracy threshold on a defined test set. If nobody can write this down, the assessment has already told you something: you are not ready to hire, you are ready to define the problem.
This step also tells you which discipline you need. A data quality and pipeline problem points to a data engineer, advertised at a median £500 a day. A model performance problem points to a data scientist or machine learning engineer, at median day rates of £600 and £575 respectively. Getting this wrong means paying a senior model specialist to spend months on data cleanup they are overqualified and overpriced for.
Name who owns the risk, not just who owns the model
Nothing is published for AI governance, or AI risk and compliance, as job titles in the UK advertised market. There is no median day rate to check yourself against, because the work is mostly bought under other titles: data scientist, ML engineer, head of data. That absence is itself a finding. It means your organisation has to decide explicitly who owns AI risk, because the market will not hand you a job title with a rate card attached.
The EU AI Act applies on a staged timetable, and UK GDPR and the Data Protection Act 2018 already govern anything touching personal data. An assessment should say plainly whether your intended use case sits inside either, and who in your organisation is accountable if it goes wrong. If the answer is 'nobody, yet', that is the most important line in the report.
Audit what you already have before you buy more
Before commissioning new work, check what infrastructure, licences and adjacent skills already exist inside the business. A cloud contract nobody is using properly. A data engineer already on staff who has never been pointed at this problem. Sometimes the assessment concludes that a few weeks of a fractional data engineer's time, at the rates above, fixes more than a permanent hire at a median salary of £70,000 would.
This is often the fastest win available. A short internal audit of existing platforms, paid-for licences and staff with adjacent skills who have never been asked to look at this problem regularly turns up more capacity than anyone expected. It is cheaper to redirect an existing data engineer for a short stretch than to recruit a new specialist before you know whether you need one.
Do not let the assessor mark their own homework
The person who runs the assessment should not be the person who then gets to recommend hiring themselves for the resulting work. Treat the assessment as a separate, priced engagement with its own end date. Bring in someone independent, get the report, then decide who does the delivery work, possibly including the same person, but as a second, distinct decision.
This is not a comment on anyone's honesty. It is a structural conflict: someone who stands to benefit from a large recommendation has every reason to see a large problem, even without meaning to. Test the recommendation against a fresh set of eyes before you commit budget to it.
What to do about it
- Run a readiness assessment before writing any job advert.
- Check data ownership, lineage and quality first; this is where most AI problems actually live.
- Write down a measurable definition of success before recruiting against it.
- Name a specific owner for AI risk, even though no job title in the advertised market carries that name.
- Audit existing infrastructure and in-house skills before commissioning new spend.
- Keep the assessment and the hiring decision as two separate pieces of work.
Questions people also ask
How long does an AI readiness assessment take?
Most run to a small number of days for a single, well-scoped use case, longer if the organisation is assessing readiness across several departments at once. The point is not an exhaustive audit; it is to surface the data, governance and success-criteria problems before you commit to a hire. If an assessment is taking months, it has stopped being an assessment and started being a delivery project with a different name.
Can we do this assessment ourselves, without bringing in anyone external?
You can, provided someone with genuine data and AI experience runs it, and provided they are not the same person angling for the resulting delivery work. Internal teams often struggle to be blunt about their own data quality, because they built or inherited the mess being assessed. An independent view tends to surface the uncomfortable findings faster.
What if the assessment says we're not ready to hire at all?
That is a legitimate and common outcome, and it saves you from hiring into a role that cannot succeed yet. The more usual finding is narrower: you need a data engineer for a few months before a model specialist, or you need to fix access and ownership questions before anyone can build anything reliable on top.
Does the assessment need to cover legal and compliance questions, or just technical ones?
Both. A technical assessment that ignores who owns AI-related risk under UK GDPR, the Data Protection Act 2018, or the EU AI Act's staged obligations is only half the job. The absence of a published market rate for AI governance roles means most organisations have not named an owner. An assessment should force that decision, not leave it for later.
Where the figures come from
Every rate and salary quoted in this article is a median or percentile of figures advertised in UK job postings over the six months to 8 August 2026. They are not rates paid, and the gap widens at the top of a range.
- IT Jobs Watch, UK contract rates, 6 months to 8 August 2026, read 2026-08-08.
- IT Jobs Watch, UK permanent salaries, 6 months to 8 August 2026, read 2026-08-08.