Most large consultancies now sell a generative AI readiness assessment, and enough Indian enterprises have bought one that a pattern is visible. Some engagements genuinely change what an organisation does next. Many produce a maturity score, a heat map, and a recommendation to invest more — conclusions that were available before the engagement started.
The difference is rarely the framework. It is whether the assessment interrogates the things that actually block deployment.
The five dimensions that decide outcomes
1. Data readiness, assessed concretely
Not “do you have a data strategy” but: can you actually retrieve the documents this use case depends on? Are they current? Who owns them? What is their access-control model, and is it machine-readable?
We have watched more GenAI pilots die on document access than on model quality. An assessment that never opens the actual content repositories is producing an informed guess.
2. Use-case economics, including the costs people leave out
For each candidate: what does the current process cost, what fraction is plausibly automatable, and what does the AI system cost including human review, exception handling and maintenance?
A surprising number of proposed use cases turn net-negative once review costs are counted honestly — particularly where review requires more senior judgement than the original task. Far better to discover that during assessment than in month nine.
3. Regulatory position, mapped to named frameworks
For Indian enterprises this is now dated and concrete rather than abstract:
- DPDP Act and Rules — Rules notified November 2025; full enforcement expected 13–14 May 2027; penalties to ₹250 crore per violation. Using AI for sizeable decision-making or profiling is among the indicative criteria for Significant Data Fiduciary status, which brings independent audits and DPIAs from Q1 2027.
- RBI FREE-AI (August 2025) — for financial services: seven guiding sutras, six pillars, 26 recommendations covering explainability, disclosure, grievance redressal and drift monitoring.
- SEBI — Regulation 16C (February 2025) and the June 2025 consultation on responsible AI/ML in securities markets.
An assessment that treats governance as a generic checklist, rather than mapping you against the frameworks that actually bind you and the dates on which they bite, is not doing the work.
4. Engineering capability, measured by evidence
Can the organisation deploy, monitor and roll back a production service today? Is there version control, CI, observability, on-call?
Teams without these fundamentals will not succeed with AI regardless of model access. AI systems fail in subtler ways than conventional software — degrading quietly rather than erroring — and therefore demand more operational maturity, not less.
5. Evaluation capability, the dimension most often skipped
If nobody can articulate what a good output looks like for a use case, that use case is not ready. The organisation will have no way to tell whether the deployed system works, and no basis for deciding whether a change made things better.
This is not hypothetical. LangChain’s 2026 State of AI Agents report finds 57% of organisations now run agents in production and identifies quality as the primary barrier to deployment. Not access to models. Quality — which is unmeasurable without evaluation.
What a useful deliverable contains
A maturity score is a conversation starter, not a deliverable. What actually changes decisions:
- A ranked use-case portfolio with honest effort and value estimates — explicitly including the candidates you should not pursue, and why.
- A named list of specific blockers: this dataset is inaccessible, this process has no owner, this workflow has no acceptance criteria.
- A sequenced plan where each step unblocks the next, rather than parallel workstreams that all stall on the same dependency.
- A clear statement of what the organisation should not attempt yet, and what must become true before it can.
- A regulatory gap analysis tied to dates, not to a generic control list.
Questions to ask before commissioning one
- Will you examine our actual data and systems, or interview stakeholders and score a framework?
- Will the output include use cases you recommend against, with reasons?
- How do you assess evaluation readiness specifically?
- Which regulatory frameworks will you map us against by name, and against which dates?
- Will you assess whether we are likely to be designated a Significant Data Fiduciary?
- What does the deliverable let us do on the Monday after it lands?
An assessment that cannot answer these will produce a document that reads well and changes nothing. The test is not the elegance of the diagnosis but whether the organisation does something different afterwards.
Frequently asked questions
What should a GenAI readiness assessment include?
Five dimensions: concrete data accessibility rather than data strategy; use-case economics including review and maintenance costs; regulatory position mapped to named frameworks and dates; engineering capability evidenced by existing deployment practice; and evaluation capability — whether anyone can define what good output looks like.
How long does a GenAI readiness assessment take?
Engagements that genuinely inspect systems and data typically run several weeks rather than several days. An assessment completed purely through stakeholder interviews can be delivered faster, but it is scoring perceptions rather than reality.
Why do GenAI pilots fail after a positive readiness assessment?
Most commonly because the assessment scored strategy and intent rather than testing document accessibility, defining evaluation criteria, or costing human review honestly. Pilots then fail on exactly those points.