Category: blog
AI adoption should begin with an assessment
Not a software purchase
Not a company-wide rollout
Not unrestricted access to public tools
AI readiness depends on the condition of your data, infrastructure, security controls, policies, and support model
Use this checklist before adopting AI tools or adding AI features to existing business systems
1. Define the business use case
AI should address a defined workflow
Examples:
- Customer service response drafts
- Document search
- Meeting summaries
- Invoice processing
- Sales forecasting
- Internal knowledge retrieval
- Help desk triage
- Marketing content production
- Scheduling and administrative tasks
Document the following:
- Current workflow
- Business owner
- Employees involved
- Systems used
- Time required
- Error rate
- Expected AI contribution
- Success metric
A first pilot should have limited scope
Possible metrics:
- Hours saved per week
- Reduction in manual entry
- Response time
- Processing volume
- Error reduction
- Employee adoption rate
Avoid adopting AI because it is available
Select one operational problem
Measure the result
2. Assign ownership
AI projects require an accountable owner
Assign responsibility for:
- Use-case selection
- Vendor review
- Data approval
- Access control
- User training
- Output review
- Incident escalation
- Performance measurement
Include representatives from:
- Leadership
- Operations
- IT
- Security
- Finance
- Legal or compliance when required
The owner does not need to be an AI specialist
The owner must have authority to approve or stop the use case
3. Complete a data inventory
AI tools use business data
Your organization must know where that data is stored
Inventory:
- File servers
- Microsoft 365
- Google Workspace
- CRM platforms
- Accounting systems
- Help desk systems
- Cloud storage
- Email systems
- Network shares
- Local workstations
- Backup repositories
- Third-party SaaS platforms
For each data source, document:
- System name
- Data owner
- Users with access
- Data type
- Sensitivity
- Retention requirement
- Data location
- Export options
- Vendor access
- Backup status
Data that cannot be located cannot be governed
X-Tek provides business IT support, cloud services, infrastructure, and network maintenance
These controls support the inventory and access review required before AI adoption
4. Check data hygiene
AI output depends on input quality
Review the datasets planned for AI use
Check for:
- Duplicate records
- Missing fields
- Outdated contacts
- Conflicting customer identifiers
- Inconsistent naming
- Unstructured documents
- Old policy versions
- Unapproved spreadsheets
- Incorrect permissions
- Orphaned files
- Duplicate cloud repositories
Create a cleanup process
Set rules for:
- Record ownership
- Required fields
- Naming conventions
- Version control
- Retention
- Deletion
- Approval
- Change tracking
Do not connect an AI tool to every available file share
Start with a defined data set
Remove unnecessary content
Validate the remaining information

5. Classify sensitive information
Create data categories that employees can use
A basic model:
Public
Information approved for public distribution
Examples:
- Published service descriptions
- Public contact information
- Marketing material
Internal
Business information intended for employees
Examples:
- Internal procedures
- Nonpublic project information
- General operational documents
Restricted
Information requiring controlled access
Examples:
- Customer records
- Financial information
- Payroll data
- Credentials
- Contracts
- Legal documents
- Personal information
- Health information
- Payment card data
- Security configurations
Define which categories may be submitted to each AI service
Public AI tools should not receive restricted business data unless the service, contract, configuration, and security controls have been reviewed
Employees should not make individual decisions about sensitive data handling
Document the rules
Apply them through policy, permissions, training, and monitoring
6. Review identity and access controls
AI systems can search, summarize, classify, and act on connected information
Excessive permissions increase exposure
Review:
- User accounts
- Administrator accounts
- Shared accounts
- Service accounts
- API keys
- Third-party integrations
- Group memberships
- Former employee access
- Vendor access
- Mobile device access
Required controls:
- Multi-factor authentication
- Role-based access
- Least-privilege permissions
- Separate administrative accounts
- Credential rotation
- Secure secrets storage
- Periodic access reviews
- Prompt and output access controls
AI access should follow existing business permissions
An employee should not gain access to restricted information through an AI search interface
7. Assess the security posture
AI adoption does not replace standard cybersecurity controls
Review the current environment:
- Endpoint protection
- Firewall configuration
- Patch management
- Email security
- MFA coverage
- Backup monitoring
- Network segmentation
- Vulnerability scanning
- Account monitoring
- Incident response
- Security awareness training
AI tools add additional attack surfaces
Potential risks include:
- Prompt injection
- Data leakage
- Malicious files
- Compromised integrations
- Excessive API permissions
- Exposed credentials
- Unauthorized automated actions
- Inaccurate or manipulated output
- Unmonitored third-party connectors
Review proactive network security controls for small businesses before connecting AI to operational systems
Security gaps should be addressed before the pilot expands

8. Confirm backup and recovery controls
AI-generated content becomes business data when it is stored or used operationally
Back up:
- Prompts when required
- Outputs used in business processes
- Configuration files
- Automation workflows
- Knowledge bases
- Vector stores
- Integration settings
- API configuration
- Source documents
Confirm:
- Backup frequency
- Retention periods
- Encryption
- Off-site storage
- Recovery point objectives
- Recovery time objectives
- Restoration procedures
- Backup monitoring
- Recovery testing
Do not assume a SaaS platform will restore all AI-related information
Review the provider's backup and export capabilities
Test recovery before critical workflows depend on the system
Cloud migration planning should include data audits, security controls, backup strategy, and recovery objectives
9. Create an AI acceptable-use policy
Employees may already be using AI tools
The first policy step is visibility
List:
- Approved AI tools
- Prohibited tools
- Approved use cases
- Restricted data types
- Required human review
- Account requirements
- Retention expectations
- Output verification
- Incident reporting steps
- Personal account restrictions
Policy requirements should include:
- No confidential data in unapproved tools
- No credentials in prompts
- No automated customer commitments without review
- No employment decisions based only on AI output
- No use of unlicensed content
- No assumption that AI output is accurate
- No bypassing IT or security controls
Review the policy quarterly
Update it when tools, vendors, regulations, or workflows change
10. Review vendors and managed AI services
A managed AI service can reduce implementation and operational requirements
It does not remove responsibility
Review each provider's:
- Data retention practices
- Data residency
- Model training terms
- Subprocessors
- Breach notification process
- Access controls
- Encryption
- Audit logging
- Availability commitments
- Export capability
- Service termination process
- Support model
- Contractual restrictions
Document the shared responsibility model
Define who:
- Configures the AI service
- Approves data connections
- Manages user access
- Reviews logs
- Monitors alerts
- Tests backups
- Handles incidents
- Validates output
- Updates integrations
- Reviews vendor changes
Managed AI should be connected to managed IT operations
This includes:
- Endpoint management
- Identity administration
- Cloud configuration
- Security monitoring
- Backup monitoring
- Network maintenance
- User support
X-Tek can assess the existing environment and identify where managed IT support, cloud services, infrastructure changes, and AI consulting should be applied

11. Establish human review
AI output requires verification
Set review requirements based on risk
Human approval should be required for output involving:
- Customer commitments
- Financial decisions
- Legal statements
- Employment actions
- Security response
- Compliance records
- Contract changes
- Medical or personal information
- Automated system changes
Document:
- Who reviews the output
- What is checked
- When approval is required
- Where approval is recorded
- What happens when output is incorrect
Low-risk drafting may require a quick review
High-risk decisions require documented approval
12. Train employees
Training should address the tools employees will actually use
Cover:
- Approved tools
- Prohibited data
- Prompt construction
- Output validation
- Phishing and malicious content
- Account security
- Reporting procedures
- Human review
- Copyright and confidentiality
Training should be role-specific
Executives need policy and risk visibility
Managers need workflow controls
Employees need operating procedures
IT staff need configuration, logging, access, and incident procedures
13. Score the organization
Use a simple readiness score
For each item, assign:
- 0 : Not started
- 1 : Partially implemented
- 2 : Documented and tested
Score these areas:
- Business use case
- Ownership
- Data inventory
- Data hygiene
- Data classification
- Identity controls
- Security posture
- Backup and recovery
- AI policy
- Vendor review
- Human oversight
- Employee training
Interpretation:
0–8
Begin with foundational IT and data controls
9–16
A limited low-risk pilot may be appropriate
17–24
The organization has a baseline for controlled expansion
The score is a planning tool
It is not a security certification
14. Use a phased implementation model
A practical sequence:
Phase 1 : Assess
- Inventory systems
- Identify data
- Review access
- Document risks
- Select one workflow
Phase 2 : Prepare
- Clean data
- Enable MFA
- Reduce permissions
- Confirm backups
- Approve the vendor
- Publish policy
Phase 3 : Pilot
- Limit users
- Limit data
- Track results
- Review outputs
- Record incidents
- Measure the defined KPI
Phase 4 : Secure
- Tune permissions
- Enable logging
- Test recovery
- Review integrations
- Update documentation
Phase 5 : Scale
- Add workflows
- Expand users
- Review performance
- Repeat vendor and access assessments
- Maintain quarterly governance reviews
X-Tek consulting and managed AI support
SMBs often have the business need but not the internal capacity for data preparation, vendor assessment, identity management, security monitoring, and ongoing administration
X-Tek can help assess:
- Current IT infrastructure
- Cloud platforms
- Network configuration
- Backup and recovery
- Endpoint protection
- User permissions
- Data locations
- AI use cases
- Vendor requirements
- Managed support needs
The assessment should produce:
- Readiness score
- Risk register
- Data inventory
- Recommended controls
- Pilot scope
- Implementation plan
- Support responsibilities
- Review schedule
AI readiness is an IT readiness issue
Data must be governed
Access must be controlled
Systems must be monitored
Backups must be tested
Outputs must be reviewed
Start with one use case and a defined control model
Submit a Business Solutions Information Request to X-Tek
Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075

