Skip to content

Questions

Everything people ask before starting, answered directly. If yours is not here, email hello@aireadiness.co.za and it probably will be.

Does this tell me whether we are POPIA compliant?

No, and be wary of anything that claims to. The aireadiness assessment is a self-assessment: it records what you tell us and is not verified against your systems. It can identify possible privacy and governance gaps that require verification, which is a useful starting point for a conversation with a lawyer or your Information Officer. It cannot determine compliance, and nothing in your result should be read as saying you are compliant or that you are not.

Who is behind the scoring?

The rubric is a fixed set of 25 questions with fixed point values, held in code. A language model runs the conversation and maps what you type onto one of the defined answers, but it cannot assign points or change a weighting. Two businesses giving the same answers get the same score.

What if I do not know the answer to something?

Say so. Unanswered questions reduce the confidence rating attached to your result rather than counting against you as a zero. For several questions, particularly around privacy, not knowing is itself the finding worth surfacing.

Is my data used to train a model?

No. Your answers are sent to OpenAI's API to conduct the conversation and are stored in our database so you can return to your result. They are not used to train any model, by us or by OpenAI under its commercial API terms.

How long does it take?

About ten minutes if you know your systems. Longer if you want to check something before answering, which is reasonable. You can leave and come back to the same assessment.

Do I have to pay to see my score?

No. The score, the per-area breakdown, your strengths, your blockers and the recommended next step are all free. An email address is required to display the full result. The paid report, at R10 000, is the written version with per-area detail and your own documents taken into account.

Do we need to know anything about AI to take this?

No. The questions are about your business, not about technology: where your information sits, how consistently a task gets done, who signs things off. Nothing is asked in jargon and no prior AI work is assumed. If the honest answer to a question is that nobody has ever thought about it, that is a useful finding rather than a failure.

Who is this for?

Established South African businesses that are being told they should adopt AI and want to know, honestly, whether they can. Most of the businesses this is built for have done no AI work at all: a manufacturer, a logistics operator, an accounting practice, a medical practice, a retailer with twenty years of records. Having real operations and real history is an advantage here, not a gap. It is least useful for very early-stage companies with neither.

What exactly is AI readiness?

AI readiness is whether the conditions for an AI project to succeed are actually in place: a specific problem worth solving, a process consistent enough to automate, data that can be reached and trusted, systems that can be connected to, people with capacity to run it, and a governance path for when it produces a wrong answer. It is not a measure of how advanced your technology is. A forty-year-old manufacturer can score higher than a software company.

What does the assessment measure?

Six weighted areas totalling 100 points: Business value (15), Process (15), Data (25), Technology (15), People (10), Governance (20). Data and governance together account for 45 of the 100 points, because they are the areas that most often stop a project outright.

Why are data and governance weighted so heavily?

Because they are the most common hard blockers. Data scattered across inboxes and spreadsheets, or data that cannot lawfully be used for a new purpose, sets a ceiling on what any tool can do. Model capability is rarely the constraint for a South African mid-market business; knowing where the data is and who signs off on it usually is.

Where is my data processed and stored?

The conversation is processed by OpenAI in the United States, which is cross-border processing and is disclosed rather than buried. Records are stored in a Cloudflare database in the Western Europe region. Payments are processed by PayFast in South Africa. Transactional email is sent through Cloudflare Email Sending.

What is the difference between the free check and the paid report?

The free check gives you the score, a red, amber or green rating per area, your three strongest areas, three likely blockers, one recommended next step and a confidence rating. The Readiness report, at R10 000, adds a written report prepared for your business by name, per-area detail explaining what each score is based on, the recommended pilot written up with prerequisites and effort, the ability to upload your own material to be taken into account, and a consultation to work through the findings.

What if we have already started something with AI?

Then the assessment is still useful, often more so. If a pilot is underperforming and it is not obvious why, the six areas are a reasonable checklist for where to look. In practice the cause is usually data condition or an undocumented process rather than the model itself.

What can the agent do to my data?

Read it. Nothing else. Your files are mounted read-only, so a write fails at the filesystem rather than being prevented by an instruction the agent might ignore. The sandbox its commands run in has network access switched off entirely, so there is no route by which your data leaves the workspace. Each assessment gets its own isolated workspace, and the scope is fixed by that workspace's own identity, not by a value sent with a request.

Should I give the agent a staff member's login?

No, and we will never ask for one. Where you are exporting from a system that has logins, create a separate read-only account for this and use that instead. A staff account carries that person's permissions, which are broader than a scan needs; a dedicated account can be given the minimum, switched off the moment the scan is done, and kept clearly separate in your own audit logs. We never handle passwords. You place the exports in the data room yourself.

How do I know the agent did not make its findings up?

A finding is only recorded with the exact text it came from, and that text is checked against the file before the finding is kept. If it cannot be located, the finding is discarded and the agent is told to re-read or drop it. You can also see the list of files it opened and the commands it ran, so any number it gives you can be traced back to how it was produced.

Can you fix the problems the scan finds?

Not yet, and we would rather say so than imply otherwise. The scan tells you which fields are empty, which identifiers disagree between systems, and which records cannot be joined. Doing the repair work is a separate service that is not built and not for sale. Writing to a customer's systems is a different level of trust from reading them, and we intend to build that once, properly.

What is the evidence scan?

It is where the assessment gets checked against your own material rather than your recollection, and it comes with the report. There are two ways to use it. Upload documents, a policy, a written procedure, a system list, and each is read against the questions it speaks to. Or put your exports in a data room and let the agent work through them, listing what is there, reading what is relevant, and profiling your actual tables. Every finding comes back with the exact text it came from, and nothing changes your score until you accept it.

What if we are not ready for AI?

Then the assessment says so, and tells you what to fix first. Several possible recommendations in the rubric are deliberately not AI projects at all: consolidating a dataset, writing down a process that only exists in someone's head, or establishing on what basis you hold personal information. An assessment that always concludes you are ready is a sales funnel rather than an assessment.

What industries does this work for?

Any business with real operations and real records. The rubric asks about process consistency, data condition and governance, which apply as much to a manufacturer or a medical practice as to a financial services firm. It is least useful where there is no established process to assess.

Do you work with small businesses or only enterprises?

Small and mid-sized businesses are the intended audience. The consultant-led AI readiness diagnostics available in South Africa start around R45 000, which prices out most businesses that would genuinely benefit from the exercise. This is the productised tier below that.

Can we redo the assessment later?

Yes, and it is worth doing after you have acted on the recommendation. Each run is scored independently and stored with the rubric version that produced it, so comparing two results months apart is meaningful.

What happens after the assessment?

You get your result immediately. Nothing is scheduled, nobody calls you, and you are not added to a marketing list. If you buy the report you also get a booking link for a consultation, which you use if and when you want to.

How do I get started?

Open the assessment and begin. No account is required to start, and no payment is asked for at any point in the free check.

Still deciding?

The assessment is free and takes about ten minutes. If the honest answer is that you are not ready, it will say so.

Related: trust centre, POPIA and AI and the readiness checklist.