How to Assess AI Readiness During Diligence: The 5-Domain Scored Checklist

How to Assess AI Readiness During Diligence: The 5-Domain Scored Checklist

How to assess AI readiness during diligence: score data, process, vendors, workforce exposure, and regulation 0 to 4. See which quadrant your target lands in.

Published

Last Modified

Topic

AI Diligence

Author

Amanda Miller, Content Writer

TLDR: The method for how to assess AI readiness during diligence is a five-domain checklist scored 0 to 4 per domain from data room evidence and management interviews: data, process maturity, vendor dependency, workforce exposure, and regulatory surface. Readiness and exposure are scored separately and never netted, because a target can be highly exposed and completely unready at the same time. The output is two numbers the investment committee can underwrite, not a paragraph about the target's cloud setup.

Best For: AI Operating Partners and value creation directors at mid-market PE funds whose portfolio companies are enterprise-scale (1,000 to 15,000 employees), with a target in exclusivity and an IC memo that needs an AI section.

An AI readiness assessment during diligence is a scored evaluation that tells a deal team whether a target can capture AI value within the hold period and how much of its current earnings sit in work that AI is likely to change. The assessment is different from the AI paragraph in a technology diligence report, which describes systems, and from a management presentation, which describes ambition. Both readiness and exposure need a number, they need to come from evidence the deal team can point to, and they need to be produced inside the two to three weeks that exclusivity usually allows. This post gives the five domains, the evidence that scores each one, the scale, and the rule for turning the scores into an IC position.

Why Does the Investment Committee Need to Know How to Assess AI Readiness During Diligence?

The investment committee needs a method for how to assess AI readiness during diligence because AI is now inside the underwrite, and unscored AI claims are the ones that fail during the hold. In EY's Q2 2026 Private Equity Pulse, 76% of firms said they had increased their focus on AI, automation, and data infrastructure, and 36% named unmet underwriting expectations as a barrier to exit. Those two numbers describe the same problem from both ends of the hold.

The management narrative is ahead of the evidence

Most CIMs now carry an AI slide, and the results behind it are thin. Bain's 2026 CEO survey found 82% of CEOs report their AI transformation is delivering below-target results, with 23% below 40% of ambition. McKinsey's 2026 State of AI survey found only 37% of companies attribute any EBIT impact to AI, roughly unchanged from the prior year, and only about 6% reach the high-performer bar of 5% or more. If a target's management says AI is already contributing to margin, that claim belongs in the 37%, and the diligence question is what evidence puts it there.

Funds are scoring inconsistently, when they score at all

FTI Consulting's 2026 Private Equity AI Radar, a survey of 200 fund and operating leaders, found 36% of funds using AI across multiple use cases and just 7% at enterprise scale, with 35% citing talent as the main constraint. L.E.K.'s PE Pulse 2026 found only 21% of PE professionals rate their own AI expertise as advanced, and 68% of firms rely on external advisors for value creation work. A checklist with named inputs is how a deal team that is not expert produces a defensible score anyway.

AI Readiness vs. AI Exposure: Why the Two Scores Never Net

AI readiness is the target's ability to deploy AI and capture value from it within the hold period; AI exposure is the share of the target's revenue, margin, or labor cost that sits in work AI is likely to change, whether or not the target does the changing. Readiness is about the target. Exposure is about the market. Scoring them as one number hides the most dangerous case, a target with high exposure and low readiness, behind an average.

The four quadrants the IC actually cares about


Low exposure

High exposure

High readiness

Modest upside; AI is a hold-period efficiency lever, not a thesis

Strongest case; the value creation plan can lead with AI and the target can execute it

Low readiness

Neutral; price on fundamentals and fund a data foundation in year one

Highest risk; competitors or customers move first; underwrite a readiness build before any AI upside

The quadrant is the decision, and the domains below are how a target lands in one. PwC's mid-year 2026 private capital outlook describes modern diligence as evaluating how exposed a target is to AI disruption and whether it has the data and technology foundations to adopt AI, which is the same split, and notes sponsors have grown more cautious on software targets for exactly that reason.

How the thinking got here

Two years ago AI diligence was a subsection of technology diligence and mostly listed tools. The 4-lens definition of AI due diligence separates it from technology and cyber diligence by what it looks for: exposure, readiness, dependency, and data. The scored checklist in this post is what that definition looks like when a deal team has to run it on a real target with a real deadline.

How to Assess AI Readiness During Diligence: The 5-Domain Scored Checklist

The method for how to assess AI readiness during diligence scores five domains from 0 to 4 using named evidence from the data room and three management interviews: data, process maturity, vendor dependency, workforce exposure, and regulatory surface. The first three produce the readiness score. The last two produce the exposure score. Assembly calls this the 5-Domain Readiness and Exposure Scorecard, and the inputs for each domain are listed below so a deal team can run it without an AI specialist in the room.

Domain 1: Data (readiness)

Evidence to request: the system of record list with owners, the last twelve months of reporting packs, and any data dictionary or master data policy. Score 0 if core operating data lives in spreadsheets and email with no owner; 2 if a system of record exists per major process but reconciliations are manual; 4 if there are validated master tables with owners and a documented refresh cadence. RSM's October 2025 guidance lists data quality as the first prerequisite for AI readiness and the top concern in its middle-market survey; in practice this domain decides whether anything else in the scorecard can be acted on in year one.

Domain 2: Process maturity (readiness)

Evidence to request: process documentation for the three highest-volume back-office workflows (typically order intake, accounts payable, and customer support), cycle time or backlog metrics if they exist, and the exception handling procedure. Score 0 if nobody can describe the process end to end; 2 if the process is documented but exceptions are handled ad hoc; 4 if intake is standardized, exception rates are measured, and one workflow already has a baseline. The reason process comes before technology is that AI applied to an undocumented process automates the exceptions along with the work, which is the same lesson the map of where AI creates EBITDA in portfolio companies points to from the value creation side.

Domain 3: Vendor dependency (readiness)

Evidence to request: the AI and automation vendor list with contract terms, the share of any live AI workflow that runs on a single vendor, and whether the target owns the prompts, rules, and training data or the vendor does. Score 0 if a live workflow depends on one vendor with no exit terms and vendor-owned logic; 2 if contracts allow exit but switching would rebuild the workflow; 4 if the target owns the logic and data and can swap the model. Gartner's June 2025 forecast estimated only about 130 of the thousands of agentic AI vendors are real and predicted more than 40% of agentic AI projects will be cancelled by the end of 2027. A target whose AI story rests on one of the other vendors has a readiness problem that looks like a strength on the management slide. The technology stack assessment for PE due diligence covers the architecture side of this domain.

Domain 4: Workforce exposure (exposure)

Evidence to request: headcount by role family with fully loaded cost, and the task mix for the ten largest role families. Score exposure 0 if under 10% of labor cost sits in roles that are mostly document handling, data entry, or routine correspondence; 2 if 10% to 30%; 4 if over 30%. Use public occupation-level exposure measures to classify roles, not management's opinion. The Federal Reserve Bank of Dallas found in September 2026 that job postings in AI-exposed occupations fell about 8% relative to less-exposed roles by early 2025, and that more-exposed firms had already cut automatable tasks in their postings by nearly half relative to the mean. Exposure is not a negative on its own: it is the size of the prize if readiness is there, and the size of the risk if it is not.

Domain 5: Regulatory surface (exposure)

Evidence to request: the list of decisions the target makes about individuals (credit, employment, eligibility, pricing), the jurisdictions it sells into, and any AI policy or incident log. Score exposure 0 if the target makes no individual-level automated decisions and sells only into lightly regulated markets; 2 if it makes such decisions in one regulated domain; 4 if it makes them in several, or sells into the EU where, per Travers Smith's May 2026 note, high-risk AI obligations now land on 2 December 2027, inside most hold periods. EY's September 2026 governance survey found 26% of large companies using agents cannot detect unauthorized agents operating internally and 36% suffered a materially negative AI incident in the past year; a target with a high regulatory surface and no incident log has not looked.

For a carve-out, or a target in a regulated sector where the exclusivity window is two weeks and the data room is thin, a generic approach is not enough; the answer is a dedicated diligence program that first scores the five domains from the evidence that exists and lists the evidence that does not as explicit gaps, second runs a baseline on one high-volume workflow using the target's own transaction data so at least one readiness score is measured rather than interviewed, and third converts the gaps into a priced 100-day workplan the IC can treat as a condition rather than a hope. That program produces a score with a confidence level attached, which is the only kind an IC should accept on a compressed timeline.

How Do You Turn the Scores Into an Underwriting Position?

The scores become an underwriting position by adding readiness across domains 1 to 3 (0 to 12), adding exposure across domains 4 and 5 (0 to 8), placing the target in the quadrant, and attaching one value hypothesis per point of exposure that readiness can support. The rule is that no AI upside enters the model for a target scoring under 6 on readiness, whatever the exposure, until a funded readiness build is in the 100-day plan.

The three-line IC summary

Every IC memo section should reduce to three lines: the readiness score with its weakest domain named, the exposure score with the largest role family named, and the quadrant with its consequence for price and plan. Grant Thornton's 2026 AI Impact Survey found 78% of senior leaders lack confidence they could pass an independent AI governance audit within 90 days; the three-line summary is what an operating partner will be held to when the same question is asked of the portfolio company two years later. The 3-column register for governing AI spend across a portfolio is where the readiness build gets tracked once the deal closes.

What a red flag looks like in the scorecard

A red flag is a readiness domain scoring 0 alongside an exposure domain scoring 4. A target with 35% of labor cost in document-handling roles and no system of record for the work those roles do is the clearest example: the exposure is real, competitors with better data will act on it, and the target cannot. Accenture's December 2025 analysis reported AI-related PE deal value more than tripled between 2023 and 2024 to 8% of total deal value; a rising share of that value is being paid for exposure that readiness cannot yet convert.

What Skeptics on the Deal Team Get Wrong About Scored AI Readiness

The objections come from the deal partner, the tech DD provider, and the operating partner's own doubts, and each one has a specific answer.

"I could ask an AI tool to build this matrix in two seconds." You could, and it would give you the domains. What it cannot give you is the evidence requests tied to the target's data room, the scoring anchors calibrated to what a 2,000-person distributor's accounts payable process actually looks like, or a baseline measured from the target's own transactions. The matrix is not the work. The evidence and the anchors are.

"The tech DD already covers this." Technology diligence describes systems and their condition. It rarely scores process maturity, never scores workforce exposure, and treats vendor dependency as a licensing question rather than a readiness question. The 4-phase AI diligence framework shows where the two overlap; the scorecard in this post is the part that does not.

"Two weeks is not enough to score five domains." Two weeks is enough to score five domains from evidence and state which scores are interviewed rather than measured. What two weeks is not enough for is a full AI strategy, and the scorecard is deliberately not one. Gartner's finance research predicted 90% of finance functions would deploy at least one AI tool by 2026. Most targets already have a tool. The diligence question is whether the five domains let it matter.

When Should the Operating Partner Run the Scorecard, and Who Owns It?

The operating partner should run the scorecard in the first week of confirmatory diligence, own the scoring anchors across deals so scores are comparable, and hand the evidence requests to the deal team so the associates gather the inputs while the operating partner scores them. The scorecard belongs to the fund, not to the deal, because its value compounds when every target in the pipeline is scored the same way.

Once three or four targets have been scored, the fund has a distribution, and the distribution is what makes the score defensible: a readiness score of 5 means something when the IC knows the last four targets scored 3, 4, 7, and 9. That is also when the operating partner stops answering "what are you really doing" and starts answering "which quadrant." EY's Q2 2026 pulse found 62% of firms emphasizing margin improvement and cost transformation in their value creation plans; a scored readiness position is what decides whether AI is in that plan or waiting behind a data foundation.

This analysis was developed using methodologies and operating experience from Assembly.

Frequently Asked Questions

How do you assess AI readiness during diligence?

AI readiness is assessed during diligence by scoring five domains from 0 to 4 using data room evidence and management interviews: data, process maturity, vendor dependency, workforce exposure, and regulatory surface. The first three give a readiness score out of 12; the last two give an exposure score out of 8. The two scores are reported separately.

What is the difference between AI readiness and AI exposure in diligence?

AI readiness is the target's ability to deploy AI and capture value in the hold period; AI exposure is the share of its revenue, margin, or labor cost in work AI is likely to change. Readiness is about the target, exposure is about the market, and netting them into one number hides the high-exposure, low-readiness case.

What does an AI readiness assessment in due diligence cover?

An AI readiness assessment in due diligence covers data, process maturity, and vendor dependency for readiness, plus workforce exposure and regulatory surface for exposure. Each domain has named evidence requests, a 0 to 4 scale with anchors, and a stated confidence level showing whether the score was measured from data or taken from interviews.

What is the 5-Domain Readiness and Exposure Scorecard?

The 5-Domain Readiness and Exposure Scorecard is a diligence method that scores data, process maturity, vendor dependency, workforce exposure, and regulatory surface on a 0 to 4 scale, sums the first three as readiness and the last two as exposure, and places the target in one of four quadrants that map to price and value creation plan.

What data room evidence shows AI readiness?

The strongest data room evidence of AI readiness is a system of record list with named owners, validated master tables, and reporting packs that reconcile without manual work. Process documentation for the three highest-volume workflows and a measured exception rate on at least one of them are the next strongest signals a deal team can find.

How do you assess vendor dependency in AI diligence?

Vendor dependency is assessed by checking whether the target owns the prompts, rules, and training data behind any live AI workflow, and whether contracts allow exit without rebuilding it. Gartner estimated in 2025 that only about 130 of thousands of agentic AI vendors are real, which makes single-vendor dependence a readiness risk.

How do you measure workforce exposure to AI for a target company?

Workforce exposure is measured as the share of fully loaded labor cost in role families whose task mix is mostly document handling, data entry, or routine correspondence, classified with public occupation-level exposure measures rather than management opinion. Under 10% scores 0, 10% to 30% scores 2, and over 30% scores 4 on the exposure scale.

Why do readiness and exposure scores never net in AI diligence?

Readiness and exposure never net because a target can be highly exposed and completely unready at once, and an average hides that case. A distributor with 35% of labor cost in document-handling roles and no system of record for that work is the highest-risk quadrant, not a middling score, and the IC needs to see it as such.

What regulatory surface matters in AI diligence?

The regulatory surface that matters is the set of automated decisions the target makes about individuals, such as credit, employment, eligibility, or pricing, and the jurisdictions it sells into. EU AI Act high-risk obligations now apply from 2 December 2027, which falls inside most hold periods for deals closing in 2026.

How long does an AI readiness assessment take during diligence?

An AI readiness assessment takes two to three weeks inside confirmatory diligence, with evidence requests issued in week one, three management interviews in week two, and scoring with confidence levels by the end. A compressed two-week window still produces scores, provided each one states whether it was measured from data or taken from interviews.

What is a red flag in an AI readiness assessment?

A red flag is any readiness domain scoring 0 next to any exposure domain scoring 4. The most common form is a large share of labor cost in exposed roles with no system of record for their work. Competitors with better data can act on that exposure while the target cannot, which turns apparent upside into hold-period risk.

How does the AI readiness score feed the value creation plan?

The readiness score sets the gate: no AI upside enters the model for a target scoring under 6 out of 12 until a funded readiness build is in the 100-day plan. Above that gate, each exposure point that readiness can support becomes one value hypothesis, with the weakest readiness domain named as the first workstream.

Why are AI claims in a CIM unreliable without scoring?

AI claims in a CIM are unreliable because most AI programs deliver below their stated ambition. Bain's 2026 CEO survey found 82% of CEOs report below-target AI results, and McKinsey's 2026 survey found only 37% of companies attribute any EBIT impact to AI. A claimed contribution needs evidence that puts it in that minority.

Who should own the AI readiness scorecard at a PE fund?

The operating partner should own the scorecard and its scoring anchors across every deal, while deal team associates gather the evidence. Fund-level ownership keeps scores comparable between targets, and after three or four scored deals the fund has a distribution that makes any single score defensible in front of the investment committee.

How is AI readiness assessment different from technology due diligence?

AI readiness assessment scores what technology diligence describes. Technology diligence reports system condition and licensing; the readiness scorecard scores process maturity, workforce exposure, and whether the target owns the logic behind its AI workflows. FTI's 2026 survey found only 7% of funds at enterprise-scale AI deployment, which is why the scored layer is usually missing.

When does an external partner add value to an AI readiness assessment?

An external partner adds value when the exclusivity window is short, the data room is thin, or the fund has no scoring anchors yet. L.E.K.'s 2026 PE Pulse found 68% of firms rely on external advisors for value creation work; the useful version measures one workflow baseline from the target's own transactions instead of interviewing for every score.

Your AI Transformation Partner.

Your AI Transformation Partner.

© 2026 Assembly, Inc.