Digital & AI Readiness Methodology

A 100-point assessment built around five core pillars. Each pillar is scored out of 20. Evidence is reviewed and the final score is independently verified by TrustStanding.

Section 1 · 20 points

Systems & platforms

The business systems that capture, store and process core operations.

Questions

  • Core operations (finance, sales, operations, HR) are run on documented systems rather than spreadsheets or informal processes.

    Improvement: Map every core process to a single system of record and retire shadow spreadsheets.

  • Business data is backed up automatically, stored securely, and recoverable in a disaster scenario.

    Improvement: Implement automated, encrypted, off-site backup with a tested recovery plan.

  • Key systems are connected or share data through integrations, APIs or a central data store.

    Improvement: Prioritise integrations between CRM, finance and operations to remove manual re-entry.

  • User access to systems is controlled by role-based permissions and regularly reviewed.

    Improvement: Introduce role-based access control and schedule quarterly access reviews.

Evidence expected

ERP or accounting system screenshots, CRM licence, payroll/HRIS records, integration documentation.

Section 2 · 20 points

Data capture & quality

Whether the business collects clean, structured data that can be trusted for decisions.

Questions

  • There is a single source of truth for customer, product and financial data.

    Improvement: Designate one system of record per entity and sync changes through integrations only.

  • Data quality rules (deduplication, validation, completeness checks) are in place and monitored.

    Improvement: Add validation at the point of entry and run monthly data-quality reports.

  • Data ownership and accountability are assigned to named roles or owners.

    Improvement: Assign a data owner for each core dataset and include data quality in their objectives.

  • Data privacy, consent and retention policies are documented and followed.

    Improvement: Document your privacy policy, consent model and retention schedule, then train staff.

Evidence expected

Data dictionary, sample reports, deduplication rules, data quality dashboard, GDPR/privacy records.

Section 3 · 20 points

Measurement & reporting

How the business tracks performance and uses metrics to manage itself.

Questions

  • A documented set of KPIs is used to run the business and is reviewed at least monthly.

    Improvement: Define a small balanced scorecard of KPIs and review them in a monthly leadership rhythm.

  • Management reports are produced automatically from live data rather than rebuilt manually.

    Improvement: Replace manual report packs with automated dashboards refreshed from live data.

  • Metrics are linked to actions — underperformance triggers a known response plan.

    Improvement: For each KPI define the threshold and the action taken when it is missed.

  • Relevant performance data is accessible to the people who need it to make decisions.

    Improvement: Give frontline and functional teams self-service access to the metrics they own.

Evidence expected

Management dashboards, KPI definitions, monthly reporting pack, automated alerts.

Section 4 · 20 points

AI readiness

The extent to which the business can safely adopt and benefit from AI tools.

Questions

  • There is a documented policy for AI use, including approved tools and prohibited data inputs.

    Improvement: Publish a short AI acceptable-use policy and communicate it to all staff.

  • Data is clean, structured and accessible enough to be used safely with AI models or analytics.

    Improvement: Complete a data-readiness audit and fix the three highest-risk quality gaps.

  • AI outputs that affect customers, finance or compliance are reviewed by a human before use.

    Improvement: Define human-in-the-loop checkpoints for any AI-assisted customer or financial decision.

  • Staff who use AI tools are trained on risks, hallucinations, confidentiality and verification.

    Improvement: Run a short AI literacy and safety session for all users and record attendance.

Evidence expected

AI use policy, model access logs, data readiness checklist, AI training records, risk assessment.

Section 5 · 20 points

Governance & ownership

The board, management and ownership structures that make digital decisions accountable.

Questions

  • A digital or data strategy is documented and reviewed at leadership or board level.

    Improvement: Write a one-page digital strategy with three-year outcomes and review it annually.

  • Cybersecurity essentials are in place: MFA, endpoint protection, patching and incident response.

    Improvement: Enforce MFA on all business systems, patch critical vulnerabilities within 14 days and document incident response.

  • Digital and data risks are recorded in a risk register with owners and mitigations.

    Improvement: Add digital, data and AI risks to your risk register and assign owners.

  • There is a plan for building or buying the digital skills the business needs.

    Improvement: Map current vs. required digital skills and create a 12-month training or hiring plan.

Evidence expected

Board or management meeting minutes, digital strategy document, cyber insurance, risk register.

How scoring works

Self-assessment: the business answers each question with yes, partial or no. Each answer contributes a proportion of the section total.

Evidence review: supporting documents are submitted for each section. Our review team checks coverage and may request additional evidence.

Final score: the verified section scores are summed to a 0–100 score. The public profile and certificate display the total score and band.

Validity: certificates are valid for 12 months. Businesses are encouraged to re-assess annually to keep their score aligned with current systems and governance.

Ready to start?

Register your interest and our team will arrange a scoping call.

The Digital & AI Readiness Score reflects the evidence available at the stated assessment date. It indicates digital maturity and data capability at that point but does not guarantee future technology performance, security, investment outcomes or business value, and is not financial, investment, legal or technology-advice.