Before you sign that AI contract or launch your next pilot, ask yourself: Is your information environment ready to support it?
Most organizations rush to evaluate vendors, compare features, and budget for licenses. That's backward. Only 7% of enterprises say their data is completely ready for AI, while 73% are still struggling to prepare it. The problem isn't the technology. It's the governance foundation underneath.
This checklist helps you assess whether your information environment can support AI tools safely and effectively. Each item represents a control point where AI can either amplify good governance or expose critical gaps.
Prerequisites
Before you begin this assessment, you need:
- Access to your current governance documentation: Records Control Schedule, business classification schemes, security frameworks, and disposition authorities
- Visibility into your repositories: Where your organization's information lives, who owns it, and how it's managed
- A cross-functional assessment team: Include records managers, legal, IT security, business unit representatives, and compliance staff
- Honest baseline metrics: Duplication rates, retention compliance levels, metadata coverage, and user adoption data for existing systems
You're not looking for perfection. You're identifying gaps that AI will make worse.
AI Readiness Checklist
Governance Controls
1. Decision rights are documented and understood.
Your governance framework specifies who approves new AI use cases, who determines data access permissions, and who is accountable when outputs lead to poor decisions. Good looks like: A named individual or committee can answer "Who decides?" for any proposed AI application within 24 hours.
2. AI use cases fit within existing governance structures.
You've extended your information governance committee's charter to include AI initiatives rather than creating a parallel approval process. Good looks like: AI projects follow the same risk assessment, data classification, and compliance review as any other system that accesses enterprise information.
3. Records management obligations apply to AI-generated content.
Your organization recognizes that AI does not suspend retention requirements. Prompts, outputs, training datasets, and model artifacts are evaluated against your Records Control Schedule. Good looks like: You can describe the retention period and disposition authority for AI-generated content in at least one business function.
Information Quality
4. You know where authoritative content lives.
For each business function, you can identify the system of record and distinguish it from collaboration spaces, personal drives, and archived repositories. Good looks like: When asked "Where's the current version?", employees point to a specific location, not three different SharePoint sites.
5. Duplicate and outdated content has been identified.
You've measured duplication rates across major repositories and can quantify how much ROT (redundant, obsolete, trivial) content exists. Good looks like: You have a baseline percentage and a remediation target, even if cleanup hasn't started yet.
6. Draft documents are separated from approved records.
Your classification scheme distinguishes working files from records, and metadata or Business Classification Scheme makes that distinction clear to both users and systems. Good looks like: An AI tool retrieving a policy document can determine whether it's a draft or the approved version.
Metadata and Context
7. Core metadata fields are consistently applied.
Document type, security classification, retention code, and approval status are captured reliably across repositories. Good looks like: At least 80% of records in your major systems have complete metadata in required fields.
8. Security labels control AI access appropriately.
Sensitivity classifications (confidential, internal, public) are enforced through permissions, not just advisory labels. Good looks like: An AI tool respecting permission boundaries cannot surface restricted HR records to unauthorized users.
9. Business context is embedded in your classification scheme.
Your taxonomy reflects how work gets done, not just how departments are organized. Functional classification helps AI understand what information means, not just where it's stored. Good looks like: Your file plan groups "customer contracts" by contract type and lifecycle stage, not by which sales rep owns the account.
Retention and Disposition
10. Your Records Control Schedule covers active repositories.
Retention rules apply to the systems where people actually work, not just formal archives. SharePoint, shared drives, and collaboration platforms have retention codes assigned. Good looks like: You can demonstrate that at least 70% of your organization's active content is covered by a retention rule.
11. Disposition happens on schedule.
Content eligible for destruction is actually being destroyed. Legal holds are managed through a documented process. Good looks like: You can produce disposition reports showing content destroyed in the last 12 months under approved authorities.
12. Over-retention is treated as a risk.
Leadership understands that keeping everything creates legal exposure and degrades AI performance. Good looks like: Your governance committee has approved a multi-year ROT reduction target with executive sponsorship.
Technology and Access Controls
13. Repository permissions are current and appropriate.
Security groups are reviewed regularly. Former employees don't retain access. Over-shared folders have been identified. Good looks like: You've completed a permissions audit in the last 12 months and remediated critical findings.
14. AI tool access is logged and auditable.
You can answer: What did the AI retrieve? Who asked the question? What was returned? Good looks like: Your AI platform integrates with your security information and event management (SIEM) system or produces queryable logs.
15. Search scope is intentionally limited.
AI tools don't automatically access every repository. You've defined which content types and locations are appropriate for each use case. Good looks like: Your legal AI assistant can search contracts and case files but not employee performance reviews.
Common Mistakes
Starting with the technology. Organizations evaluate AI vendors before assessing whether their information environment can support any tool effectively. The best platform can't fix poor governance.
Treating AI as an IT project. AI readiness is a records management challenge. IT owns the infrastructure, but information governance professionals must define what content the tool can access, how long outputs are retained, and what controls apply.
Assuming metadata will be added later. If your current content lacks consistent classification, security labels, or retention codes, AI won't magically improve it. You're teaching the tool to work with what you have today.
Ignoring shadow AI. When approved tools are too restrictive or difficult to use, employees turn to consumer AI platforms. That's a governance failure, not a policy violation. The compliant path must also be the easiest path.
Waiting for perfection. No organization has flawless governance. The goal is to identify critical gaps and remediate them before they become AI-amplified risks.
Next Steps
Score your current state honestly. Each checklist item you can't verify represents a risk that AI will make visible and urgent.
Prioritize governance and quality improvements over technology selection. If you can't answer "Who decides?" or "Where's the authoritative version?", no AI platform will solve that problem.
Start small. Pick one business function, one repository, or one use case. Prove you can manage information quality, metadata, and retention in a limited scope before expanding.
Your AI readiness isn't measured by which tools you've purchased. It's measured by whether your information environment can support them safely.



