AI Readiness Audit

Where AI delivers value across product, process, operations and delivery, and where it does not.

Start here
Book thirty minutes

thirty minutes · we will say if another rung fits better

Rung
01 · Way in
Duration
4 weeks
Investment
£44k–£44k fixed price
Who turns up
A senior operator and a build engineer alongside James Rooney, who leads every audit personally. The engineer is on the engagement to build the prototypes, not to advise on them.
How it endsFixed price, fixed deliverable
What this costs, and where the number comes from
£44k–£44k fixed price. Derived from the published rate card at 20 billable days a month.
check the arithmetic →
Is there a build engineer
Yes. This engagement ends in working code, not only in a document, so an engineer is on it rather than on call: two or three candidate workflows are built against your real data inside your own tenancy. James Rooney leads every audit personally at the published partner rate of £1,560 a day, and the engineer is someone he has already delivered alongside, at the published senior rate of £1,250.
The exit, in detail
On a date, with a fixed-price deliverable: the working prototypes, the board readout and the costed plan. The code is in your repositories from day one. Nothing rolls on.
Assurance
James Rooney provides partner oversight on every engagement, and leads the audits personally. Every person on your engagement is senior, with no pyramid of juniors behind them.

Large consultancies typically price an equivalent assessment at £150k–£500k, our estimate rather than a published figure. How the comparison works. Access, data handling and screening are on the security page.

On this page
In one paragraph

The AI Readiness Audit is a fixed-price, four-week engagement that finds exactly where AI will and will not create value across four areas of your organisation: the product your customers touch, the internal processes that run the business, your operations, and the software development process itself. It does not stop at a document. Two or three candidate workflows are built as working prototypes against your real data inside your own tenancy, and you keep the code whether or not you continue with us. You also get a costed, outcome-driven plan in three-month increments, capped at twelve months. It is £44,000, fixed, and it is one of two ways most clients start.

Month one of our live specialty insurance engagement was an audit run this way, inside the estate rather than as a readout exercise, and it is written up in full. Read the month-one write-up

That is the short answer. The call is where it gets specific to your estate.

Book thirty minutes
Deliverables

What you get

In scope for the £44k–£44k fixed price.

  • Two or three candidate workflows built as working prototypes against your real data, inside your own tenancy, with a measured accuracy and confidence read on each. The code is yours whether or not you continue with us
  • Heat-map across all four domains: external product, internal process, operations, and the software development process itself, ranked by return and feasibility
  • Where AI is constrained here: data quality, risk appetite, regulation
  • What your engineering organisation would gain from AI-native delivery, measured against how it ships today rather than against a vendor benchmark
  • Where your workforce is ready, and where it demonstrably is not
  • Where culture and incentives will block adoption, and the specific unblocks
  • A costed, outcome-driven plan in three-month increments, capped at twelve months
  • An estimated run cost per candidate workflow, so you know the operating cost before you commit to it
  • The investment case, written so your board can act on it

If you need something in this list shaped differently, say so on the call and we will tell you whether it moves the price.

Book thirty minutes
The deliverable

What the board readout contains

Seven sections, in this order. What each one says depends on what four weeks inside your organisation finds.

  1. 01

    Heat map by domain and workflow

    Every candidate workflow examined across the four domains, external product, internal process, operations and the software development process, ranked by expected return against feasibility, with the evidence behind each placement named rather than scored out of five. Domains are ranked against each other as well as within themselves, because the question a board asks first is which of the four to fund.

  2. 02

    Constraint register

    Where AI is blocked here: data quality and availability, risk appetite, regulatory position, and which constraints are permanent against which are a piece of work with a cost attached.

  3. 03

    Decision inventory

    Which decisions in the workflows examined could move to an agent, which must stay with a person, and the consequence and reversibility test behind each answer.

  4. 04

    Workforce readiness read

    Where your people are ready and where they demonstrably are not, by function, alongside where culture and incentives will block adoption and the specific unblocks.

  5. 05

    Outcome-driven plan in three-month increments, costed, max twelve months

    What to do first, second and third, with build cost and estimated run cost per workflow, dependencies, and the decision points where the plan should be re-tested.

  6. 06

    The investment case

    The value stated in currency with the assumptions exposed, the confidence attached to each figure, and the arithmetic laid out so your finance function can rework it with their own numbers.

  7. 07

    The do-not-do list

    What is not worth doing here and why, including where the recommendation is to stop. Clients tell us this is usually the most valuable page.

There are no sample findings on this page: a worked heat map with plausible rows in it would be an invented result for an organisation we have not audited.

If one of these is the part you are actually stuck on, bring it to the call.

Book thirty minutes
The sequence

How the engagement runs, week by week

4 weeks, drawn to scale so you can see how long each part actually takes.

  1. 01
    Week 1

    Embed and observe, across all four domains. We sit with the teams doing the work and trace real workflows end to end in the product your customers touch, the internal processes that run the business, your operations, and your own software development process, and we pull the delivery data rather than relying on what the org chart claims happens. Covering delivery is not a courtesy to the engineering function: it is usually the domain with the shortest path from a decision to a measurable result, because it is the one place the organisation already instruments itself. This is also where the inventory gets built: which AI tools are genuinely in use across the business, sanctioned or not, what each was bought to do, where two of them cover the same job, and which workflows have quietly come to depend on something nobody in the centre knows about.

  2. 02
    Weeks 2–3

    Build the frontier rather than describe it. Two or three candidate workflows are built as working prototypes against your real data, inside your own tenancy, rather than demonstrated on ours. Each one produces a measured accuracy and confidence read, an estimated run cost per unit of work so the ongoing cost is known before anything is committed, and working code you keep whether or not you continue with us. It is the part of the engagement that grounds the week-four sequencing in evidence rather than in opinion. How many workflows are built is agreed in writing before the engagement starts.

  3. 03
    Week 4

    Model the operating impact and cost it. Which roles change, which decisions move, what governance is required, and what the realistic adoption curve looks like, then the board readout: a sequenced, costed plan presented to your leadership with the assumptions and the risks set out, and the prototypes running behind it.

Timelines move with scope. Thirty minutes is enough to tell you which week yours would start.

Book thirty minutes
Fit test

Is this the right rung for you?

We would rather tell you now than three weeks in.

Right for you if

  • Boards that have asked for an AI plan and received slideware
  • Engineering organisations under pressure to adopt AI in the development process with no measured read on what it is currently worth to them
  • Product teams deciding whether AI belongs in the customer-facing product or only behind it
  • Organisations whose Copilot or Gemini rollout has stalled, with no diagnosis of why
  • Businesses where shadow AI has spread across functions and nobody holds an inventory
  • Estates carrying tool and vendor sprawl: overlapping point solutions bought independently by different functions
  • Executive teams with no shared view of their AI maturity, and a different answer from every function
  • Anyone who needs AI due diligence before an acquisition, an investment or a board review
  • Leadership teams who need a defensible investment case before committing budget
  • Anyone quoted a seven-figure programme who wants to sanity-check the scope first

Not right if

  • Teams looking for a tooling procurement exercise
  • Organisations that have already completed a credible readiness assessment
  • Anyone wanting a rubber stamp on a decision already taken

Not sure which side of that you fall on? That is exactly what the call is for.

Book thirty minutes
Is this the right engagement for us?it will say if another one fits better
Describe where you are and I will tell you whether AI Readiness Audit is the right starting point, or which engagement is. If you are not ready for this one, I will say so.

Prefer to talk it through? Ask us on a discovery call →

If you would rather ask a person than a panel, the call answers the follow-ups too.

Book thirty minutes
What you take to the board

A costed, outcome-driven sequence in three-month increments, capped at twelve months. Not a maturity model.

£44k–£44k·4 weeks·Rung 01

  • Which of the four domains to fund first, and which to leave alone this year
  • The three things worth doing first, with expected return and confidence
  • The things not worth doing, and why, usually the most valuable page
  • A clear-eyed view of what your organisation cannot yet safely automate
  • A recommendation to stop, where that is what the evidence says, with the plan yours to keep either way

We will help you build that board case on the call, whether or not you buy this rung.

Book thirty minutes
Book a call

Talk it through before you commit.

Thirty minutes with James. We will tell you honestly whether AI Readiness Audit is the right rung for where you are, and you will leave with a rough scope whether you engage us or not.

30 minutesWith James personally£44k–£44kNo obligation
Booking about AI Readiness Audit (£44k–£44k · 4 weeks)

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.

Can't see the calendar? Open it in a new tab.

Also searched for

What this engagement is called elsewhere

An audit is a piece of work, not a person on your org chart. It is the work a new Head of AI would spend their first quarter doing, which is why it is often bought instead of a search, or just before one.

Head of AI, first quarter

Also advertised as: Head of AI, AI strategy lead, Chief AI Officer, diagnostic phase

The audit does what a newly appointed Head of AI would spend their first three months doing: finding where AI delivers value across the product, the internal processes, the operations and the development process itself, where data quality and risk appetite genuinely stop you, and what to do first. Four weeks at a fixed price instead, and you finish able to write the job specification against evidence rather than against whatever the market is currently saying.

An engagement, not a hire and not a placement

Every role here is supplied as an engagement, not a permanent hire or a staffing agency placement. The person is someone James Rooney has already delivered alongside, screened to BS7858 standard before they touch your estate, contracted to written confidentiality and data-handling terms, and accountable to James Rooney as well as to you. They are senior throughout, with no pyramid of juniors behind them. There is no introduction fee and no permanent-placement conversion clause, and notice is thirty days either way. If what you need is a permanent Head of AI on your own payroll, hire one; an interim holds the seat while you run that search, and writes the specification you recruit against.

How the associate pool is selected and screened is set out on our team page, and the day rates behind every figure here are on the rate card.

Whatever your organisation calls it, the call is the same thirty minutes.

Book thirty minutes

AI Readiness Audit: your questions

What is an AI readiness audit?

An AI readiness audit is a structured assessment of where AI can create measurable value in an organisation, where it is constrained by data, risk or regulation, and whether the workforce and culture are ready to adopt it. Tenhaw's version examines four domains rather than one: the external product a customer touches, the internal processes that run the business, operations, and the software development process itself. It runs 4 weeks at a fixed price of £44,000 and produces a sequenced, costed plan rather than a maturity score.

What does the audit actually look at?

Four domains, in this order. The external product your customers touch, and whether AI belongs in it or only behind it. The internal processes that run the business, traced end to end rather than taken from a process map. Operations, including the run cost of anything already live. And your own software development process, which is usually the domain with the shortest path from a decision to a measurable result, because it is the one place an organisation already instruments itself. Each is ranked against the others as well as within itself, because the first question a board asks is which one to fund.

How much does an AI readiness assessment cost in the UK?

Tenhaw prices the AI Readiness Audit at £44,000 as a fixed fee, whatever the size of the organisation. Large consultancies typically price equivalent assessments between £150,000 and £500,000, our estimate rather than a published figure. The fixed price means the scope is agreed before the work starts and does not expand mid-engagement, and the number does not move once it is in writing.

Should we start with the audit or a proof of concept?

Start with the audit if the question is where to invest across the organisation and you need a board-ready case. Start with a proof of concept if you already know which workflow you want to attack and the question is whether it can actually be done. Some clients run the proof of concept first because a working thing persuades internal sceptics that a plan does not.

Who from Tenhaw actually does the work?

James Rooney leads every audit personally. Where specialist input is needed, it comes from an associate he has already delivered alongside, screened to BS7858 standard before any client access, and every person on your engagement is senior. Tenhaw does not sell work that someone else then delivers, and there is no pyramid of junior consultants.

Should we hire a Head of AI or run an audit first?

A permanent Head of AI search runs six to nine months, and the specification usually gets written from market narrative. The audit takes four weeks at £44,000 and gives whoever you hire a sequenced, costed plan to arrive into rather than a blank page. If you have already made the hire, the audit is the fastest way to give them a defensible first hundred days. It is not a substitute for the permanent role.

What is included in the £44,000 audit price?

Everything the four weeks produce. Two or three candidate workflows built as working prototypes against your real data, inside your own tenancy, with the code yours to keep. A heat map across all four domains, the constraints that would block you, an estimated run cost per candidate workflow, and a costed plan in three-month increments capped at twelve months, presented to your board at the end. The number is fixed in writing before the engagement starts and does not move with scope.

Can the audit sort out the AI tools we have already bought?

It can tell you which of them are earning their keep. Weeks one and two inventory what is actually in use across the business, sanctioned or not, map each tool to the workflows it touches, and show where two or three of them cover the same job. That overlap, and what each costs to run, then sits in the sequenced plan alongside everything else, and consolidation decisions usually land on the do-not-do list. Nothing on the ladder involves us selling you a licence, so this is an assessment rather than a procurement exercise.

What does an AI readiness audit deliver in four weeks?

Working prototypes and a costed plan, not a slide pack. Two or three candidate workflows are built against your real data inside your own tenancy, each with a measured accuracy and confidence read and an estimated run cost per unit of work. Alongside them you get a heat map of where AI will and will not pay across product, internal process, operations and your own software delivery, the constraints that would block you, and a sequenced plan in three-month increments capped at twelve months.

How do you assess whether a data estate is ready for agentic AI?

By building on it rather than surveying it. We trace real workflows end to end, pull your delivery data instead of relying on what the org chart claims happens, and then prototype two or three candidates directly against your data. Readiness shows up fast that way: retrieval quality, how much of the context an agent actually needs is reachable, where provenance breaks, and which workflows quietly depend on a system nobody in the centre knows about.

How do you work out where AI will not deliver value?

The same way we work out where it will, which is why it comes out of the same four weeks. A workflow fails the test when the data is not there, when the risk appetite will not carry an automated decision, when the volume is too low for the run cost to make sense, or when the real constraint is a process problem that agents would simply do faster. Those land on a do-not-do list, with the reason attached, so the plan is defensible in both directions.

Which stakeholders need to be involved in an AI readiness audit?

Fewer than you would expect, and less of their time than a survey-based assessment. The method works by sitting with the people who actually do the work, so it needs access to those teams rather than to a data room. Beyond that: an executive sponsor who can make decisions inside the agreed scope, someone from risk or the second line to agree a risk classification before anything is built, and whoever owns the platform the prototypes run on.

How do you baseline current operating costs so AI savings can be measured later?

In currency, per workflow, before anything is built. Volume, elapsed time, people involved and rework, measured on the workflow as it runs today rather than as it is documented. That baseline is what the prototypes are then measured against, and it is what makes a later claim of saving checkable rather than asserted. It also sets the run cost side, an estimated cost per unit of work, so the operating cost is known before you commit to it.

What security constraints are examined before an AI build starts?

Where the data can go, who can reach it, and what an agent is allowed to touch. Prototypes are built inside your own tenancy on your own contracts, so the constraints examined are the real ones: identity and access, least-privilege scoping for agent permissions, where model inference is allowed to run, what your data-handling requirements mean for retrieval corpora, and what the second line needs to see before a risk classification is agreed.

Can an audit tell us whether our engineering team can build AI-native?

Yes, and it is one of the four domains rather than an afterthought. We measure how your organisation ships today, against its own delivery data rather than against a vendor benchmark, and the prototypes are pair-programmed with your engineers, which is the most direct test there is. Software delivery is usually the domain with the shortest path from a decision to a measurable result, because it is the one place an organisation already instruments itself.

How does this compare with an AI strategy engagement from a large consultancy?

Ours ends in working code and a fixed £44,000. An equivalent large-firm assessment is an estimated £150,000 to £500,000 and typically ends in a document. The difference is the shape of the team rather than the day rate, and ours is a partner, a senior operator and a build engineer for four weeks, with no pyramid to fund. Every figure we publish is on the pricing page with the competitors' own published framework rates beside it.

How do you make sure an audit ends in engineering work rather than slides?

The engineering starts inside the audit itself. By the end of week three, two or three workflows are running against your data and the code is in your repositories. The plan that follows is written against things that already exist, with sequencing grounded in what the prototypes measured rather than in what a workshop guessed. If you stop after the audit, you still keep the prototypes.

What is the return on £44,000 spent before committing to a build?

It is the cheapest way to find out that a workflow does not work. The alternative is discovering it inside a six or twelve month build, where the same finding costs the whole run rate rather than four weeks. The audit produces a measured accuracy read per candidate workflow, an estimated run cost, and a baseline in currency to measure against later. It is priced to be approved without a committee for exactly that reason.

Can the audit be used as AI due diligence before an acquisition?

Yes, scoped to the target or to the business unit under review, at the same fixed price over the same four weeks. The method works by sitting with the people doing the work, so it needs access to them rather than to a data room alone, and four weeks now fits inside most exclusivity periods, where six to eight did not. Both are worth raising on the first call. It is an operational read on what is real, not legal, financial or regulatory due diligence, and it replaces none of those.

Is an agent readiness audit the same as an AI readiness audit?

Same engagement, wider scope. This started life as an agent readiness audit. Agents turned out to be one answer rather than the question, so the rename was a widening rather than a relabel, and the four weeks now cover the product your customers touch, the internal processes that run the business, operations, and your own software development process. The agent-specific part is a decision inventory in the board readout: which decisions in the workflows we examine could move to an agent, which must stay with a person, and the consequence and reversibility test behind each call. Two or three candidates are then built as working prototypes against your real data, at a fixed £44,000.

Can you audit a programme our current AI supplier is already building?

Yes, and it is one of the reasons the audit gets bought. A seven-figure programme is on the table and someone wants the scope sanity-checked before it is signed. Nothing needs to pause while it runs, because the method is sitting with the teams doing the work and tracing real workflows end to end rather than reviewing a data room. What comes back is evidence rather than an opinion: two or three of the candidate workflows built against your real data, each with a measured accuracy read and an estimated run cost, a heat map ranked by return and feasibility, and a do-not-do list. We sell no licences, so nothing in that recommendation is a sale.

What happens in the weeks after the audit readout?

Nothing by default, and that is deliberate. The engagement ends on the date it said it would, nothing rolls on, and the prototype code has been in your repositories since it was written, so there is no handover to wait for. The costed plan is yours to keep even where the recommendation is to stop. It comes in three-month increments capped at twelve months, with decision points marked where it should be re-tested against what you learn, so your own team can start the first increment without us. If you want us for part of it, that is a separate contract: a proof of concept at £20,000 to £55,000, a design team, or programme and delivery management.

How many hours a week does the audit ask of our teams?

Most of it lands on the engineers pairing in weeks two and three, and Tenhaw shapes the rest of the four weeks to sit inside normal work rather than in workshops. Week one is observation, spent sitting with the teams doing the work and tracing real workflows end to end, so the time goes on being watched rather than on preparing material for us. Weeks two and three are the heaviest, because the two or three candidate workflows are pair-programmed with your engineers against your real data. Week four needs your leadership for the readout. How heavy those two weeks get depends on how many of your own engineers you want in the pairing.

Is the readout a document or a session with our board?

Both, and Tenhaw runs the session rather than sending a pack over. The week four readout is presented to your leadership with the prototypes running behind it, so the board watches the two or three workflows work rather than reads about them, and the written deliverable runs to seven sections in a fixed order, from the heat map through the constraint register and the decision inventory to the do-not-do list. The prototype code has been in your repositories since it was written, so nothing is handed over on the day. Who needs to be in that session depends on which of the four domains your board is closest to funding.

Is the heat map a score out of five, or is there evidence behind it?

Evidence, named against each placement. Tenhaw ranks the candidate workflows by expected return against feasibility and writes what sits behind each placement into the readout rather than scoring it out of five, because a maturity model is not something a board can fund from. The same rule keeps sample findings off this page. A worked heat map with plausible rows in it would be an invented result for an organisation nobody has audited. The two or three workflows built as prototypes each carry a measured accuracy and confidence read, which is the hardest evidence in the pack. Which placements get argued over depends on how much of your delivery data is already instrumented.

Is four weeks long enough for an organisation our size?

Yes, because the scope is bounded before the clock starts rather than stretched to fit. Tenhaw agrees how many workflows get built in writing before the engagement starts, and scoping settles which parts of the business the four domains are examined across, so the four weeks go deep on those instead of shallow everywhere. Two or three candidates are then built as working prototypes against your real data, and that depth is the test a timebox has to pass. What four weeks cannot do is cover every operating company in a large group at once, so where to point the four domains is the first conversation rather than a detail settled later.

What if our board challenges the numbers in the investment case?

Then they can rework them in the room. Tenhaw states the value in currency with the assumptions exposed, a confidence level attached to each figure and the arithmetic laid out, so your finance function can run its own numbers through it rather than take a benefit figure on trust. James Rooney leads every audit personally, so the person answering the challenge is the person who did the work, and the two or three prototypes are running behind the readout with a measured accuracy read on each rather than screenshotted into a slide. Which figures get pushed on hardest usually turns on how your finance team already values the time a workflow consumes.

If the audit says do not proceed, do we still pay the £44,000?

Yes, and a recommendation to stop is one of the outcomes Tenhaw builds the four weeks to produce rather than a failure of them. The £44,000 buys four weeks of work, and the finding is the work. You keep the do-not-do list with the reason attached to each entry, the measured accuracy read on each prototype, the constraint register and the costed plan, whether or not you act on any of it. Clients tell us the do-not-do list is usually the most valuable page. More often a stop recommendation reorders which of the four domains to fund and which to leave alone this year, rather than meaning stop everything.

Does the costed plan go stale if we sit on it for six months?

Parts of it do, and Tenhaw writes it to show you which. The plan comes in three-month increments capped at twelve months, with decision points marked where it should be re-tested, so a pause leaves you at a marked point rather than at the top of a document nobody trusts. The estimated run cost per workflow ages fastest, because model pricing moves under it. The constraint register, the operating-cost baseline in currency and the do-not-do list hold longer, because they describe your organisation rather than the market. How much has actually moved depends on what changed in your estate while you waited.

Do the prototypes cost us anything to run after the audit ends?

Only what your own tenancy charges, because that is where they were built. Tenhaw builds the two or three candidate workflows against your real data inside your own infrastructure on your own contracts, so inference and compute sit on your bill during the four weeks and after them, and you can switch them off the day the engagement ends without asking us. An estimated run cost per unit of work for each candidate is part of the deliverable precisely so that number is known before anything is committed. What it would cost at production volume depends on the volumes you would actually put through it.

Can we put the audit prototypes straight into production?

No, and Tenhaw calls them prototypes for that reason. The two or three candidate workflows built in weeks two and three run against your real data inside your own tenancy and produce a measured accuracy and confidence read, which is what grounds the week four sequencing, but four weeks buys evidence rather than a hardened system. The code sits in your own repositories either way, so your engineers can take it forward without us, and the costed plan carries the build cost and the dependencies for doing that properly. What hardening actually costs turns on the volumes and the error tolerance the workflow has to hold.

What if our data access is not ready when week two starts?

It is the dependency most likely to squeeze a fixed four weeks, so Tenhaw front-loads it. Identity and access scoping sits in week one, alongside the risk classification your second line agrees before anything is built, because the prototypes run against your real data inside your own tenancy rather than on ours. How many candidate workflows get built is agreed in writing before the engagement starts, and that scoping conversation is where reachable data gets checked rather than assumed. The price stays £44,000 and the end date stays where it was agreed. Your own provisioning lead time for an account with production-level read access is the number worth confirming first.