The deliverable

What the report actually looks like

Most assessments are sold on a promise. This is the document an AI readiness engagement produces, in the shape it arrives in: findings ranked by risk, a roadmap with hours against each fix, and a plain note about which items you should not pay us for.

The practice below is invented and the answers behind it are made up. The structure, the wording of the findings, and the remediation items are the real ones, taken from the framework our technicians work through.

Simulated demo

AI readiness and governance

Simulated demo

AI Readiness Assessment

A 14-person dental practice (invented for this example)

Establishes where regulated data lives, which AI tools can reach it, which vendors will sign an agreement, and what the written policy needs to say.

HIPAA Security Rule (where PHI is in scope)FTC Safeguards Rule (where GLBA applies)State breach notification lawCyber insurance underwriting questions

Executive summary

The practice runs on a well-maintained system of record, and the day-to-day security posture around it is better than average for its size. The exposure is entirely on the AI side, and it is recent. Two staff have been using a consumer AI tool on personal accounts to draft patient correspondence, on a plan tier that cannot carry a business associate agreement at any price. That is the finding to act on first, and it is not fixable by asking the vendor.

The rest of the roadmap is ordinary hygiene that the AI exposure has made urgent: there is no written data inventory, mailboxes are being used as a document store, and multi-factor authentication is enforced on email but not on the practice management system. None of it is unusual. All of it would be asked about by an insurer.

Findings
9
Critical
2
High
4
Est. hours
79

What we found

Ordered by risk, most urgent first.

  1. 01Staff are using AI tools on personal accounts

    critical

    Shadow AI discovery

    Work is being done in accounts the organization does not control. There is no admin visibility, no retention setting, no agreement, and no way to revoke access when the person leaves.

    What fixes it

    • Move AI use onto organization accounts: Provision the approved tools under the tenant, then block the personal-account path so the data stops leaving through it.
    • Draft an acceptable use policy for this organization: Name the systems, name the data, and say plainly what may and may not go into an AI tool. Written to be handed to staff, not filed.
  2. 02AI tools are on a tier that cannot carry an agreement

    critical

    Vendor agreements

    The tools in use are on free or personal plans. No agreement is available at that tier at any price, so this cannot be resolved by asking the vendor.

    What fixes it

    • Replace tools that cannot be brought under an agreement: Some vendors will not sign at any tier. Select a replacement that will, migrate the workflow, and retire the original.
    • Move AI use onto organization accounts: Provision the approved tools under the tenant, then block the personal-account path so the data stops leaving through it.
  3. 03There is no written inventory of where sensitive data lives

    high

    Data inventory

    Nobody can currently describe, on paper, where patient records are held. Every other control in this report depends on that list, and an insurer or auditor asks for it first.

    What fixes it

    • Build a written data inventory: Produce one document listing every system and location holding sensitive records, who owns each, and what regime applies to it.
  4. 04Sensitive records are accumulating in mailboxes

    high

    Data inventory

    Mailboxes are holding patient records as attachments. A mailbox has no retention control, no access review, and is the most commonly compromised store in an organization this size.

    What fixes it

    • Give clients a way to send documents that is not email: Stand up secure file exchange in the tenant you already pay for, and retire the mailbox as a document store.
    • Define a retention and deletion schedule: Decide what is kept, for how long, and what deletes it. Then configure the systems to do it rather than relying on someone remembering.
  5. 05Working copies exist outside the system of record

    high

    Data inventory

    Staff keep local copies of patient records to get their work done. These copies are outside every control applied to the primary system, and they are the copies that reach an AI tool.

    What fixes it

    • Control sensitive data on endpoints: Encrypt the devices, restrict removable media, and remove the local copies that the current workflow keeps producing.
  6. 06Multi-factor authentication has gaps

    high

    Identity and access

    Some systems in scope are still reachable with a password alone. Partial enforcement is generally reported as full enforcement on a questionnaire, which is the actual risk.

    What fixes it

    • Enforce multi-factor authentication everywhere in scope: Make it a tenant requirement rather than a user option, and include the AI tools in the scope, not only email.
  7. 07Subprocessors behind the AI vendors have not been reviewed

    medium

    Vendor agreements

    A covered vendor can still route data to a model provider that is not covered. The chain has not been followed past the first link.

    What fixes it

    • Review the agreement position for every tool: Establish, per tool, whether an agreement exists, whether the tier supports one, and who the subprocessors are underneath it.
  8. 08The training setting is believed correct but was never verified

    medium

    Tenant configuration

    The setting is assumed to be off because someone remembers changing it. Nothing records what it was set to, or on which plan.

    What fixes it

    • Verify the privacy settings rather than assume them: Open the console on the plan actually being paid for, confirm the setting, and keep the screenshot.
  9. 09Data residency requirements have not been checked

    low

    Vendor agreements

    No one has confirmed where the vendor processes the data against any residency obligation the organization carries.

    What fixes it

    • Review the agreement position for every tool: Establish, per tool, whether an agreement exists, whether the tier supports one, and who the subprocessors are underneath it.

The roadmap

Every fix above, de-duplicated and ordered by risk then by effort. Work it top to bottom. 1 of 10 can be done in-house without us.

  1. 01Enforce multi-factor authentication everywhere in scope

    critical

    Make it a tenant requirement rather than a user option, and include the AI tools in the scope, not only email.

    Standard6 hoursWe can do this for you

  2. 02Move AI use onto organization accounts

    critical

    Provision the approved tools under the tenant, then block the personal-account path so the data stops leaving through it.

    Standard8 hoursWe can do this for you

  3. 03Replace tools that cannot be brought under an agreement

    critical

    Some vendors will not sign at any tier. Select a replacement that will, migrate the workflow, and retire the original.

    Project20 hoursWe can do this for you

  4. 04Review the agreement position for every tool

    high

    Establish, per tool, whether an agreement exists, whether the tier supports one, and who the subprocessors are underneath it.

    Quick win3 hoursWe can do this for you

  5. 05Draft an acceptable use policy for this organization

    high

    Name the systems, name the data, and say plainly what may and may not go into an AI tool. Written to be handed to staff, not filed.

    Standard6 hoursWe can do this for you

  6. 06Give clients a way to send documents that is not email

    high

    Stand up secure file exchange in the tenant you already pay for, and retire the mailbox as a document store.

    Standard6 hoursWe can do this for you

  7. 07Build a written data inventory

    high

    Produce one document listing every system and location holding sensitive records, who owns each, and what regime applies to it.

    Standard8 hoursWe can do this for you

  8. 08Control sensitive data on endpoints

    high

    Encrypt the devices, restrict removable media, and remove the local copies that the current workflow keeps producing.

    Project16 hoursWe can do this for you

  9. 09Verify the privacy settings rather than assume them

    medium

    Open the console on the plan actually being paid for, confirm the setting, and keep the screenshot.

    Quick win2 hoursYour team can do this

  10. 10Define a retention and deletion schedule

    medium

    Decide what is kept, for how long, and what deletes it. Then configure the systems to do it rather than relying on someone remembering.

    Standard4 hoursWe can do this for you

How we can help

The engagements that cover the roadmap above, priced in credits. In the real report these are buttons: anyone on the account can start one without leaving the document.

  • Identity & Access Hardening

    MFA enforcement, single sign-on where it fits, offboarding, and a repeatable access review.

    12 credits
  • AI Tools Deployment

    Approved tools provisioned under your tenant, configured deliberately, with the personal-account path closed.

    20 credits
  • Written Security Program

    The policy set, the rollout to staff, and the evidence trail an auditor or insurer asks for.

    15 credits
  • Microsoft 365 Migration

    Secure file exchange and mail moved onto the tenant you already pay for.

    15 credits
  • Security & Compliance Audit

    The full control review behind the data inventory, one regime at a time.

    12 credits
  • Full Infrastructure Audit

    Endpoints, network and servers inspected end to end, with the findings written down.

    20 credits

A delivered report closes on this note: it describes what was observed and reported during the review, on the date of the review. It is a point-in-time assessment against the framework named at the top, not a certification and not a legal opinion.

Two ways in

Find out roughly where you stand, or scope the real thing

The scorecard is eight questions and takes about two minutes. It gives you an indication, not an assessment. The engagement is the document above.

Assessments are one-time and fixed in scope. Remediation is quoted separately, after you have the findings.