Capability audit

    An independent read on what your organisation can actually do.

    A standalone, commissionable assessment of AI readiness across people, process, data and governance — delivered as a written report you can take to a board, a budget, or another implementer.

    Written AI capability audit report open on a desk during a leadership review
    The instrument

    A single, finite piece of work with a document at the end of it.

    Most organisations approaching AI are trying to make a decision under conditions where nobody internally has enough perspective to make it. Leadership hears competing claims. The IT function has an opinion shaped by systems risk. The marketing team has an opinion shaped by whatever they already tried. Nobody has looked across the whole organisation with the same lens on the same week.

    The capability audit is that look. It is scoped, time-boxed and priced as its own engagement, and it finishes with a report rather than a proposal for further work. That distinction matters: a diagnostic produced by the party who wants to sell the treatment is not a diagnostic. The audit is written so it can be handed to your own team, to a different consultancy, or to nobody, and still hold up.

    It also gives internal sponsors something they usually lack — evidence. A head of operations who believes a reporting cycle could be halved cannot easily fund that belief. A written assessment with named processes, measured effort and stated assumptions can be taken to a finance committee.

    What gets assessed

    Four dimensions, assessed together.

    Readiness fails at its weakest dimension, so all four are examined in the same engagement rather than treated as separate reviews.

    People

    Actual capability by function, not a company-wide average. Who is already using AI informally, what for, and how well. Where the internal champions are. Where resistance is genuine caution and where it is unfamiliarity. This determines whether the plan needs training, hiring, or neither.

    Process

    The recurring work: what happens, in what order, how often, and how long it takes. We look for high-volume, rules-heavy, text-dominated processes because that is where current AI capability creates real recovery — and we identify the approval and handover points that would swallow any gain.

    Data and content

    What information the organisation holds, where it lives, whether it is retrievable, and whether it is trustworthy enough to build on. A large proportion of stalled AI initiatives are data-access problems wearing an AI costume.

    Governance

    Existing policy, current exposure through unmanaged personal tool use, confidentiality and client obligations, disclosure practice, and what human review means in your context. For regulated organisations this section is usually the one the board reads first.

    Process & timeline

    Two to four weeks, with limited demand on your team.

    Week 0 — scoping
    A 30-minute discovery call establishes which functions are in scope, who should be interviewed, and what decision the audit needs to inform. Scope and fee are confirmed in writing before anything begins.
    Week 1 — discovery
    Interviews of 45 to 60 minutes with a representative from each function in scope, plus a working session with the sponsor. Existing documentation and samples of recurring output are reviewed alongside. No new material needs to be produced for us.
    Week 2 — analysis
    Findings are consolidated into the current-state map, capability baseline and opportunity register. Each opportunity is estimated, sequenced and dependency-checked.
    Week 3 — readout
    A 90-minute session with the sponsor and, where relevant, the leadership team or board. The written report is delivered at or before the readout so it can be read in advance, and revised once after feedback.
    The deliverable

    What you actually receive.

    Executive summary
    Two pages written for a board: the position, the three things that matter, the risk exposure, and the recommended first move. Readable by someone who will never open the appendix.
    Current-state map
    Documented workflow for each function in scope, with volumes and effort where they could be established.
    Capability baseline by function
    A per-function rating with the evidence behind it, so the assessment can be repeated in twelve months and compared.
    Prioritised opportunity register
    Named opportunities with estimated recovery, effort, dependencies and a recommended sequence. Includes an explicit 'do not pursue' list with reasoning.
    Governance position
    Current exposure, the minimum viable policy position, and where the organisation's obligations to clients or regulators bear on tool choice.
    Ninety-day plan
    What to do first, who owns it, what it costs, and what evidence would show it is working.
    Scope by size

    How the engagement changes with the organisation.

    Small — under 25 staff

    One or two functions, three to five interviews, two weeks. Usually commissioned by an owner-manager and focused on recovering the founder's own time. From $1,500 USD.

    Mid-sized — 25 to 150 staff

    Three to four functions, eight to twelve interviews, three to four weeks, board-ready readout. This is the most common shape. Typically $3,000 to $6,000 USD.

    Large or regulated

    Multi-department scope, expanded governance section, alignment with existing policy and risk frameworks, and often a second readout for the audit committee. Five to six weeks, quoted after discovery.

    Every scope is confirmed in writing before work starts, with a proposal returned within 48 hours of discovery. All pricing is quoted in USD.

    What happens next

    Where organisations usually go after the readout.

    Roughly half of audits lead to a capability programme — the report identifies which functions need training and on what, which is exactly what a scoped corporate engagement is built to deliver. A smaller group proceeds to implementation of one or two specific opportunities, usually a reporting or content workflow. Some organisations take the report and execute internally, which is a legitimate and reasonably common outcome. A few discover the honest answer is "not yet", and the value of the engagement is the money not spent.

    Where the audit sits inside a longer advisory relationship, it typically becomes the first artefact of a wider AI consulting engagement and is revisited annually as a benchmark.

    FAQ

    Before you commission an audit.

    What does an AI capability audit cost?

    From $1,500 USD for a small organisation with one or two functions in scope. Mid-sized organisations typically fall between $3,000 and $6,000 USD, and multi-department or regulated engagements are quoted after discovery. Pricing is driven by the number of functions assessed and the number of people interviewed, not by revenue.

    How long does it take?

    Two to four weeks end to end. Week one is discovery and interviews, week two is analysis and drafting, and the readout is scheduled in the following week. Larger scopes with more than four functions run closer to six weeks.

    How much of our team's time does it consume?

    Less than most people expect. Typically 45 to 60 minutes per interviewee, one working session with the sponsor at the start, and a 90-minute readout at the end. We work from existing documentation rather than asking teams to produce new material for us.

    Is the audit tied to buying anything else?

    No. It is deliberately sold and delivered as a standalone piece of work. The report is yours, it names its assumptions, and it can be executed by your own team, by another implementer, or not at all. That independence is the reason boards accept it.

    Will you tell us not to adopt AI in some areas?

    Frequently. A useful audit rules things out. Where a process is low volume, highly judgement-dependent, or blocked by a data problem that would cost more to fix than the opportunity is worth, the recommendation is to leave it alone and say so in writing.

    Do you need access to our systems?

    No system access is required. The audit works from interviews, process documentation, samples of recurring output and a description of your toolset. Everything is handled under NDA.

    Commission the audit as its own piece of work.

    Thirty minutes of discovery is enough to confirm scope, timeline and fee. The report is yours regardless of what you do next.

    Talk to us about scopeSee advisory engagements

    We use cookies to improve your experience and analyse site traffic. See our Cookie Policy for details.