Make Your Data AI-Ready: 10 Checks Before Buying AI Tools
Published 29 July 2026
The 10 checks
1. Data inventory
Do you have a list of the data sets the AI will use, where they live, and who maintains them? If not, the AI will be working blind across systems – and so will you when something goes wrong.
2. Duplicate records
What is your duplication rate in the top 3 data sets (customers, contacts, products)? If you do not know, run a simple match on name + email or name + postcode. Above 5% duplication, fix before AI amplifies it.
3. Access rights audit
AI tools usually need broad data access. Have you reviewed who currently has access to the target data? Excessive permissions become AI training data leaks the moment the tool is switched on.
4. Data quality rules
For each in-scope data set, can you state the basic quality rules (mandatory fields, format, range)? Even 3 rules per set is a foundation. None is a red flag.
5. Sensitive data tagging
Are personal, financial and commercial-confidential fields tagged? AI tools rely on tags to apply correct handling. Untagged data leaks into prompts and model training silently.
6. APIs and integration readiness
Can the AI tool read the data it needs over a documented API or connector? If integration is bespoke ETL pipelines, factor that into time, cost and ownership.
7. Documentation
Is the data documented well enough for a new joiner – or a model – to understand it? Field definitions, units, allowed values, source systems. Brief documentation beats none.
8. Ownership
Is there a named business owner per data set, with authority to approve changes? AI tool rollouts surface ownership conflicts that have been quietly avoided for years.
9. Retention
Are your retention periods defined and enforced? AI on top of decade-old expired data creates compliance exposure under UK GDPR. Clean old data before AI multiplies the risk.
10. Security baseline
Does your environment hold Cyber Essentials? AI tools inherit your existing weaknesses – MFA gaps, missing patches, account separation issues. Fix the baseline first, then the AI.
How to score yourself
Each item is pass/fail. 8+ green: ready to pilot. 5–7 green: ready with a remediation plan on the side. Below 5: pause the AI purchase, fix the foundations first.
The remediation order
- Ownership (everything else stalls without owners)
- Inventory (you cannot manage what you cannot list)
- Sensitive tagging (controls regulatory exposure)
- Quality rules and duplicate clean-up
- Security baseline – CE/CE+ as the floor
- Access review
- Documentation and retention
- APIs / integration approach
What "AI ready" does not mean
AI ready does not mean "all data perfect everywhere". It means "the specific data this AI will use is fit for purpose, owned, classified and secure". Scope the readiness to the use case, not the whole company.
Cost realism
Most UK SMEs underestimate readiness cost by 3x and the AI tool cost by 0.5x. The licence is usually the smaller line item. Plan for the people-time to clean, tag and document.
Next steps
With the 10 checks passed, write the AI governance one-pagerand adopt the staff GenAI policy before turning the tool on.
