Is Your Small Business Ready for AI Automation? A 25-Point Checklist
Readiness is not whether the owner has tried ChatGPT. A business is ready when one workflow has stable inputs, named owners, explicit rules, safe escalation, and an outcome the team can measure.
By Dane · Published · Updated
Short answer
A small business is ready to test AI when it can describe one repeatable workflow, produce representative inputs, distinguish rules from judgment, name the human owner, protect sensitive data, and connect the output to a business outcome. It is not ready when the goal is simply to use AI, the process changes by employee, required data lives in private inboxes, nobody owns exceptions, or success means that the demo worked once. Use the 25 questions below to find the constraint before choosing a vendor.
Key takeaways
- Readiness is workflow-specific; a company may be ready for document summarization but not automated pricing.
- A clear manual process is easier to improve than a chaotic process hidden behind a chatbot.
- Data quality, permissions, security, and source ownership matter before prompt quality.
- Every automated action needs a human owner, exception path, audit trail, and rollback.
- The first test should be cheap enough to disprove the idea without organizational damage.
Facts with boundaries
What the evidence can—and cannot—tell you.
17–20%
reported overall business AI use in recent BTOS periods
Census data from December 2025 through May 2026 show meaningful but far from universal adoption. Being later than a competitor is not evidence that your first workflow is ready.
U.S. Census Bureau57%
of adopting firms used AI in three or fewer functions
The 2026 Census working paper found adoption was usually limited in scope. Focused deployment is normal; company-wide transformation is not the required starting point.
U.S. Census Bureau4 functions
in the NIST AI RMF core
Govern, Map, Measure, and Manage organize AI risk work. The framework is voluntary, but its structure is a useful antidote to buying a tool without ownership or evaluation.
National Institute of Standards and TechnologyPrivate reader poll
What is the biggest blocker to your first useful AI workflow?
Choose the closest answer. This runs only in your browser; no vote total or invented community result is displayed.
Readiness belongs to a workflow, not an entire company
An owner can be highly capable with AI and still have a business that is unready for automation. The opposite is also true: a team with little prompt experience may have an excellent candidate because the workflow is stable, repetitive, well measured, and already governed by clear rules. Readiness should be assessed for a named job such as classifying inbound requests, drafting a quote summary, or extracting fields from vendor documents—not for AI in general.
Different workflows in the same company deserve different autonomy. Drafting an internal meeting summary is reversible and low consequence. Confirming a price, sending a marketing text, changing a reservation, approving a refund, or giving safety advice can create direct harm. The controls, evidence, and review required should rise with consequence and uncertainty. A green score for one use case does not transfer automatically to another.
The 25-point checklist is intentionally operational. Score each statement yes only when you can show the evidence, not when the team believes it probably happens. Partial means the practice exists inconsistently or cannot be demonstrated. No means the capability is absent. The objective is not a perfect score. It is to find the lowest-cost prerequisite that could invalidate or unlock the test.
Sources: U.S. Small Business Administration, National Institute of Standards and Technology
1–5: The workflow is specific and stable
A model cannot compensate for an undefined operating process. Start by drawing the workflow from trigger to outcome, including the quiet work that happens in spreadsheets, inboxes, phone calls, and employee memory. Use actual examples to uncover variants. If every employee handles the same request differently, decide which variation is legitimate and which is drift before automating it.
Stable does not mean unchanging. It means the team knows the current states, owners, and approved paths and can intentionally update them. The best early candidate has frequent volume and a recognizable structure, while exceptions are uncommon enough to route to people. A rare process with unique judgment may be intellectually interesting but commercially weak.
1. Named trigger
You can state exactly what event starts the workflow and distinguish it from similar events.
2. Defined finish
The successful outcome, failed outcome, and canceled outcome are recorded rather than inferred.
3. Known states
The steps and decision states between trigger and finish are visible and consistently named.
4. Measurable volume
You know how often the workflow runs and how volume changes by day, season, source, or service.
5. Bounded exceptions
Common exceptions are known, detectable, and safe to send to an accountable person.
6–10: Inputs and systems of record are trustworthy
AI performance is constrained by the information it receives. A beautifully written assistant will still fail if customer status is stale, two systems disagree on availability, policy lives in an old PDF, or staff enter the same field five ways. Build an inventory of inputs, source owners, update frequency, access permissions, retention, and quality problems. Identify which source wins when records conflict.
Do not make every document available just because retrieval technology can index it. Limit the source set to information required for the task. Separate approved public facts, internal operating guidance, customer records, and sensitive data. Determine whether the vendor retains prompts or outputs, uses them for training, supports deletion, encrypts data, and lets you control access. Free tools may have different terms and controls from enterprise products.
6. Representative examples
You can provide enough sanitized good, bad, edge, and adversarial examples to design and test the workflow.
7. Source ownership
Every policy, price, service area, field, and knowledge source has an owner and review date.
8. Conflict rule
The team knows which system wins when the CRM, calendar, website, and employee notes disagree.
9. Minimum data
The workflow collects and exposes only the information needed to complete the bounded task.
10. Vendor diligence
Security, retention, training use, access, deletion, subprocessors, portability, and incident handling are reviewed.
Sources: Federal Trade Commission, Cybersecurity and Infrastructure Security Agency
11–15: Rules, AI responsibilities, and human judgment are separated
Some decisions should not depend on generated language. Service-area eligibility, approved price tables, business hours, refund limits, required disclosures, opt-outs, and account permissions are usually better represented as deterministic rules. AI is stronger at classification, extraction, summarization, drafting, and ranking where inputs vary and a plausible output can be reviewed or bounded.
Write a responsibility matrix before choosing the model. For each step, state whether a rule, AI, or person acts; what evidence it receives; the confidence or condition required; what it writes; and who can reverse it. Treat low confidence, conflicting data, missing information, and customer frustration as explicit states. Human-in-the-loop means the person has context, authority, and time—not a review button nobody monitors.
11. Deterministic rules
Consequential promises and eligibility decisions come from approved rules or people, not model improvisation.
12. Bounded AI job
The AI task can be stated as classify, extract, summarize, draft, or recommend with an observable output.
13. Confidence policy
The system knows when to proceed, ask a bounded question, pause, or escalate instead of masking uncertainty.
14. Human authority
A named person can approve, reject, edit, override, and stop the workflow with the required context.
15. Prohibited actions
The team has written what the system must never promise, expose, decide, or send automatically.
16–20: Failure handling and operations exist before launch
A workflow is not production-ready because it succeeds on the happy path. Test what happens when an API times out, the system of record is unavailable, a required field is blank, the model output is malformed, a customer asks for a person, or a vendor changes behavior. The safe fallback should reduce scope, preserve a traceable record, and alert someone. It should not silently drop the lead or continue using stale information.
Operational ownership includes monitoring, incident response, content updates, access review, cost review, and vendor changes. Decide which failures page an owner immediately, which create a daily queue, and which belong in weekly analysis. Keep a manual path and a rollback. If the team cannot operate the system when Dane or the implementer is unavailable, the design has created dependency rather than leverage.
16. Failure states
Integration, retrieval, model, delivery, permission, and handoff failures are detectable and logged.
17. Safe fallback
The fallback makes fewer promises, captures only essential information, and tells users the truth.
18. Monitoring owner
A person reviews alerts, exceptions, quality samples, costs, and unresolved tasks on a defined schedule.
19. Audit trail
Inputs, source versions, decisions, outputs, delivery, human edits, and final outcomes can be reconstructed.
20. Rollback
The team can return to a known manual or rules-based process without losing customer work.
21–25: The experiment can produce a business decision
A pilot needs a question that can be answered. Replace improve efficiency with a measurable hypothesis such as reducing median time from missed-call capture to qualified human contact without increasing complaints or staff rework. Establish a baseline from the same workflow, define the eligible cohort, and decide how long or how many cases are needed. If seasonality is strong, a short before-and-after test may mislead.
Count full costs and downstream outcomes. Model tokens are often the smallest component compared with integration, cleanup, review, monitoring, training, exception handling, and vendor minimums. Revenue must be collected and attributable; booking value is not profit. Guardrails such as errors, complaints, opt-outs, customer abandonment, and employee rework can invalidate an apparent gain.
21. Baseline
Current time, cost, error, conversion, and outcome metrics exist for the same eligible workflow.
22. Testable hypothesis
The pilot names the expected change, cohort, duration, sample, and guardrails before it begins.
23. Outcome connection
Outputs connect to booked, paid, resolved, retained, or other business states in a trusted system.
24. Full cost
Setup, software, usage, integration, review, rework, security, and ongoing ownership are included.
25. Kill criteria
The team will stop for specific harms, weak economics, low accuracy, excessive rework, or poor adoption.
How to interpret your score
Score yes as one, partial as one-half, and no as zero. A total above 20 suggests the workflow may be ready for a limited test, not full autonomy. A score from 14 to 20 usually means the opportunity is plausible but prerequisite work should be completed first. Below 14, focus on process, data, ownership, or measurement. The absolute score matters less than any no in a safety-critical category.
Use hard gates regardless of total. Do not launch if consequential actions lack deterministic controls, sensitive data use is unreviewed, no human owns exceptions, failures disappear silently, or no outcome can be measured. A low-risk internal drafting assistant can tolerate more manual friction than an external system speaking for the business. Scale readiness standards with customer impact.
The readiness exercise should reduce vendor shopping. Once the workflow, sources, rules, controls, and measures are visible, many products can be evaluated against the same brief. That preserves negotiating power and prevents a vendor's demo from defining your process. The durable asset is the operating specification and evidence, not the first model selected.
Sources: U.S. Small Business Administration, National Institute of Standards and Technology
Use this tool
The 25-point AI readiness scorecard
Mark every numbered statement above yes, partial, or no. Attach evidence for each yes and identify the owner and date for every prerequisite you decide to fix.
- 01Choose exactly one workflow and write its trigger, finish, volume, states, and exceptions.
- 02Score questions 1–5 for workflow clarity and stability.
- 03Score questions 6–10 for input quality, source ownership, data minimization, and vendor diligence.
- 04Score questions 11–15 for rules, bounded AI duties, uncertainty, human authority, and prohibitions.
- 05Score questions 16–20 for failures, fallbacks, monitoring, auditability, and rollback.
- 06Score questions 21–25 for baseline, hypothesis, outcome attribution, full cost, and kill criteria.
- 07Treat privacy, safety, permission, human ownership, and silent failure as hard gates regardless of total.
- 08Select the cheapest prerequisite or shadow test that could disprove the workflow before a larger build.
Output: A readiness score, hard-gate list, prerequisite backlog, and smallest reversible test for one named workflow.
Source-backed trivia
According to the 2026 Census diffusion paper, how broadly did most AI-using firms deploy it?
FAQ
Questions owners ask before acting.
What score means we are ready?
Use 20 as a planning signal, not certification. Any missing hard gate—human ownership, privacy review, safe fallback, or measurable outcome—can block a test regardless of total.
Do we need clean data before using AI?
You need data that is sufficiently accurate, representative, permitted, and owned for the task. A small approved source set is often better than indexing everything.
Can a vendor run the readiness assessment for us?
A vendor can help, but it is financially motivated to find a fit. Keep the business objective, evidence, rules, and acceptance criteria under owner control.
Should we wait until AI is more mature?
Wait when the workflow is high consequence or prerequisites are absent. For a low-risk, reversible task with human review, a small test can create useful evidence now.
Does readiness require an IT department?
No, but it requires named ownership and access to appropriate security, privacy, legal, and technical help when the workflow warrants it.
Sources and evidence boundaries
Sources support the specific claims attributed to them. They do not prove that the same result will occur in your business. Rules and guidance can change; verify current legal, privacy, accessibility, and vendor requirements before implementation.
- 1. Large Firms With at Least 20 Employees Biggest AI Users — U.S. Census Bureau. Nationally representative BTOS estimates describe reported business use, not the return from a specific tool or workflow.
- 2. The Microstructure of AI Diffusion — U.S. Census Bureau. The working paper measures adoption across firms and business functions; it does not establish that adoption causes profit.
- 3. Monitoring AI Adoption in the U.S. Economy — Federal Reserve Board. The note compares surveys with different units and question wording and warns that headline adoption rates are not directly interchangeable.
- 4. AI for small business — U.S. Small Business Administration. General federal guidance recommends starting small and human review; it does not endorse any vendor or promise savings.
- 5. Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. The AI RMF is voluntary risk-management guidance, not a certification or substitute for legal requirements.
- 6. Generative AI Profile, NIST AI 600-1 — National Institute of Standards and Technology. The profile describes risks and suggested actions across many contexts; controls should be scaled to the actual use case.
- 7. AI companies: uphold privacy and confidentiality commitments — Federal Trade Commission. The FTC discussion focuses on provider commitments and data practices; buyers still need vendor-specific diligence.
- 8. Small and Medium-Sized Business Resources — Cybersecurity and Infrastructure Security Agency. Cybersecurity guidance is a baseline. Sensitive or regulated workflows may require additional controls.