The AI readiness assessment: a two-week diagnostic before you buy anything
A genuine AI readiness assessment is a short, structured diagnostic — roughly two weeks — that answers one question before you spend a dollar on tools: is your business actually ready to get value from AI, and where? It examines four things — your data, your workflows, a single scoped use-case, and your compliance obligations (PIPEDA and, in Quebec, Law 25) — and ends with an honest go / no-go recommendation. Done right, it stops you buying software that has nothing to attach to, and it turns "we should do something with AI" into a concrete, costed first project.

Most AI projects that fail didn't fail at the technology. They failed because nobody checked, up front, whether the business was ready — whether the data existed, whether the workflow was defined, whether anyone owned the outcome. An AI readiness assessment is the cheap insurance against that. It's a short, structured diagnostic you run before you buy anything, and its job is to replace enthusiasm with evidence.
At ALMA Intelligence we run these for Canadian small and mid-market businesses, and the shape is consistent: about two weeks, four areas of inquiry, and a clear recommendation at the end. Here's the framework, laid out so you can run a version of it yourself.
What "readiness" actually means
Readiness is not "do we have a smart team" or "are we open to innovation." It's narrower and more useful: can a specific, valuable task be handed to an AI system reliably, safely, and measurably — right now, with what we have? A business can be very ready for one use-case (answering repetitive inbound calls) and completely unready for another (forecasting demand off data it doesn't collect). The assessment's value is telling those two apart.
The context is worth naming. Statistics Canada reported that 19.2% of Canadian businesses used AI in Q2 2026, up from 6.1% in Q2 2024 — roughly a tripling in two years. Of the businesses using AI, 28.2% used virtual agents or chatbots. Adoption is climbing fast, which means the competitive question is shifting from "should we?" to "where, and are we ready?" A diagnostic answers the second question honestly.
The four things a real assessment examines
1. Data — do you have it, and can you use it?
AI attaches to data. If your customer records live half in a booking tool, half in someone's inbox, and half in memory, no model will fix that — it'll just automate the mess. The assessment inventories what data you actually hold, where it lives, how clean and complete it is, and — critically — whether you're allowed to use it the way you intend. That last point is a compliance question as much as a technical one (more below). The output is a plain map: data you can use today, data that needs cleanup, and data you don't have and would need to start collecting.
2. Workflows — is the task defined enough to hand over?
An AI system can only take over a process you can describe. Part of the assessment is sitting with the people who do the work and writing down the actual steps, the exceptions, the "it depends" moments, and the point where a human must stay in the loop. Vague processes ("we just handle it") are a red flag — not because AI can't help, but because you'll never be able to tell whether it's helping. Well-defined, high-volume, repetitive workflows are where AI pays off first.
3. A single scoped use-case — not a platform
The most common failure mode is buying a broad "AI platform" and then hunting for something to point it at. We invert that. The assessment identifies one use-case with a clear boundary, a measurable outcome, and a realistic cost, and pressure-tests it: What does success look like in numbers? What breaks if it's wrong? Who owns it? For many service businesses the honest first candidate is front-desk load — missed calls, after-hours enquiries, repetitive booking questions — which is why we built ALMATalk as a productized AI receptionist. But the right first use-case is whatever scores highest on value-over-effort for your business, and sometimes the answer is "not that, start here instead."
4. Compliance — PIPEDA, and in Quebec, Law 25
This is where a Canadian assessment differs from a generic one, and where cutting corners gets expensive. A quick note first: the following is general information, not legal advice — confirm your obligations with a qualified professional.
Federally, the operative private-sector privacy law remains PIPEDA (enforced by the Office of the Privacy Commissioner, priv.gc.ca). It's worth being precise about the legislative landscape, because a lot of outdated commentary is circulating: Bill C-27 — which contained the proposed Artificial Intelligence and Data Act (AIDA) — died when Parliament was prorogued in January 2025. AIDA is not law. As of 2026 the federal privacy reform vehicle is Bill C-36, which is a bill, not passed law. So plan around PIPEDA as it stands today, and watch C-36 rather than assuming AIDA-style rules apply.
Cross-border processing is the question that trips up the most people, so here is the honest position: PIPEDA does not prohibit processing personal information outside Canada. The OPC treats a transfer for processing as a "use" of the information, governed by the accountability principle — meaning your organization stays accountable for that data, must ensure a comparable level of protection through contractual and other measures, and must be transparent with individuals that their information may be processed outside Canada (and could therefore be accessible to foreign courts or authorities). It is a matter of accountability and transparency, not prohibition. Many capable AI tools run on infrastructure outside Canada; the assessment's job is to make sure that's handled correctly and disclosed, not to pretend it isn't happening.
In Quebec, Law 25 adds specific obligations enforced by the Commission d'accès à l'information (the CAI). Two points matter for AI:
- Automated decision-making (section 12.1). If a business makes a decision based exclusively on automated processing of someone's personal information, it must inform the person and, on request, let them submit observations. Routine scheduling or booking generally isn't an "exclusively automated" decision with legal or similar effect — but automated screening or scoring of people is much more likely to fall in scope. The assessment flags which of your intended use-cases cross that line.
- Penalties are real and large. Law 25 has two enforcement tracks — administrative monetary penalties and penal fines. For the penal offences, the fine range runs from $15,000 up to $25,000,000, or, if greater, an amount corresponding to 4% of worldwide turnover for the preceding fiscal year. The point isn't the exact figure — it's that penalties can reach the tens of millions, or a percentage of global turnover if that's greater, so compliance is a board-level concern, not a footnote.
One more Quebec dimension: the Charter of the French Language (Bill 96) creates a general right for people to be served and informed in French. It does not impose a specific rule about, say, answering the phone in French — but bilingual capability in any customer-facing AI supports those French-language service obligations, and the assessment notes where that applies.
The deliverable: a go / no-go, not a sales pitch
A readiness assessment that always says "yes, buy the thing" isn't a diagnostic — it's a sales funnel. A genuine one produces a written recommendation with three possible shapes:
- Go — the data, workflow, and compliance picture support a specific scoped use-case; here's the costed first project and how we'll measure it.
- Go, but fix these first — the opportunity is real, but data cleanup, a workflow definition, or a consent/transparency gap has to be closed before implementation.
- No-go (for now) — the value isn't there yet, or the compliance risk outweighs it; here's what would need to change.
You should be able to act on the report whether or not you ever hire the firm that wrote it. That's the test of an honest assessment.
Why two weeks
Long enough to look at real data and talk to the people doing the work; short enough that it doesn't become a consulting project in its own right. Roughly: a few days scoping data and workflows, a few days pressure-testing the candidate use-case and mapping compliance, and a couple of days writing a recommendation you can put in front of a decision-maker. You come out the other side knowing exactly what to buy, what it should cost, and what it needs to succeed — or knowing, cheaply, that now isn't the time.
That clarity is the entire point. AI spending goes wrong when it starts with a tool and works backwards to a problem. A readiness assessment makes you start with the problem — and only buy once you know the answer is real.
ALMA Intelligence is a Canadian AI implementation partner. We run readiness assessments for SMB and mid-market businesses and build the productized AI receptionist ALMATalk. This article is general information, not legal advice.
Frequently asked questions
About two weeks. That's long enough to examine real data and interview the people who do the work, but short enough that it doesn't become a consulting project of its own. A typical split is a few days scoping data and workflows, a few days pressure-testing the candidate use-case and mapping compliance, and a couple of days writing a recommendation a decision-maker can act on.
Four things: your data (what you have, where it lives, how usable it is, and whether you're permitted to use it that way), your workflows (whether the target task is defined enough to hand over), a single scoped use-case (one bounded, measurable, costed candidate rather than a broad platform), and your compliance obligations under PIPEDA and, in Quebec, Law 25. It ends with a written go / no-go recommendation.
No. PIPEDA does not prohibit processing personal information outside Canada. The Office of the Privacy Commissioner treats a transfer for processing as a 'use' of the information, governed by the accountability principle: your organization stays accountable, must ensure a comparable level of protection through contractual measures, and must be transparent that data may be processed outside Canada and could be accessible to foreign courts or authorities. This is general information, not legal advice.
Under section 12.1 of Law 25, if a business makes a decision based exclusively on automated processing of someone's personal information, it must inform the person and, on request, allow them to submit observations. Routine scheduling or booking generally isn't an 'exclusively automated' decision with legal or similar effect, but automated screening or scoring of people is more likely to fall within scope. Penalties under Law 25 are significant, so an assessment flags which use-cases cross that line. This is general information, not legal advice; confirm your obligations with a qualified professional.
No. AIDA was part of Bill C-27, which died when Parliament was prorogued in January 2025 — so AIDA is not law. As of 2026 the federal privacy reform vehicle is Bill C-36, which is a bill rather than passed legislation. PIPEDA remains the operative federal private-sector privacy law, so plan around it while monitoring C-36.