Run your own AI diagnostic.
This is the engagement I charge $20,000 for, written out in full. Follow it and you'll finish with the same four artifacts my clients get: a complete AI inventory, an honest read on your data, a ranked list of what to automate, and a plan you can put in front of a board. Two people, about three weeks.

The method isn't the expensive part.
People ask why I publish the thing I sell. Because the walkthrough was never what you were paying for. What costs money is the judgment applied to your specific mess: knowing which of forty findings actually matters, which vendor claim won't survive a security review, and which use case looks brilliant until you check whether the data behind it exists.
Plenty of companies can run this themselves, and should. If you have a capable operator, three weeks and the willingness to hear uncomfortable answers, everything you need is on this page. If you finish it and the picture is worse than you hoped, you'll at least know exactly what you're hiring for, which makes you a much better client than someone starting from a blank page.
One warning before you start. A diagnostic only pays off if you're willing to write down what you find, including the parts that make somebody look bad. A sanitized inventory is worse than no inventory, because it produces confident decisions built on a fiction.
What this takes.
Set it up properly and it runs in three weeks. Set it up badly and it becomes a survey nobody answers.
One owner, not a committee
Someone senior enough to ask finance for expense data and get it. A diagnostic run by a committee produces a document that offends nobody and decides nothing.
An amnesty, stated up front
Announce that nobody gets in trouble for admitting which AI tools they use. Without that sentence your shadow-AI audit finds a fraction of the truth, and you'd rather know now than during an audit.
Access to four systems
Expense and card data, your SSO or identity provider logs, the browser or network telemetry your IT team already has, and the vendor contracts folder.
About three weeks
Roughly a week per phase, at maybe a day a week of effort from the owner plus an hour each from a dozen colleagues. Longer than that and momentum leaks away.
Five steps, in this order.
The order matters more than the speed. Every step consumes what the one before it produced, and skipping the inventory is why most AI strategies describe a company that doesn't exist.
Inventory everything, including the parts nobody told you about
- List every AI tool with a paid subscription, from expense reports and card statements rather than from memory
- Pull SSO and identity logs for every app anyone signed into with a work account, then filter for AI vendors
- Ask IT for outbound traffic to the top fifty AI domains. This is where the shadow AI actually surfaces
- Check the software you already own: your CRM, helpdesk, analytics and office suite all shipped AI features you never bought deliberately
- For each entry record the owner, what data it touches, whether it retains that data, and whether anybody reviewed it
- Send one anonymous three-question survey to staff: what AI do you use, for what, and what would you stop doing if it vanished
Read the data honestly
- For each function, write down where its operational data actually lives and who owns it
- Rate each source on three things: is it complete, is it current, and can a system reach it through an API rather than a person exporting a spreadsheet
- Flag every source that only one human knows how to interpret, because that is a dependency disguised as a dataset
- Write the sentence most diagnostics skip: which of our ideas are blocked until the data is fixed, and how long would fixing it take
- Note what is legally constrained: customer PII, health data, anything under contract restrictions with a client or supplier
Find the opportunities, function by function
- Walk each function separately: purchasing, customer service, marketing, sales, production, logistics, finance, HR, and engineering if you have engineers
- In each, ask one question: what work here is mostly reading, deciding by a rule, and producing a document or a message?
- Interview the person who does that work, not their manager. Managers describe the process as designed; the doer knows the exceptions, and the exceptions are where automation breaks
- Write each opportunity as a sentence with a number in it: hours a week, error rate, cost per transaction, days of delay
- Deliberately look for the boring ones. Invoice matching and ticket triage return more, faster, than the impressive customer-facing idea
Rank, and be willing to kill things
- Score each opportunity on four axes: annual value, feasibility with today's tools, data readiness from step 2, and risk if it gets something wrong
- Multiply rather than average. An idea that scores brilliantly on value and near zero on data readiness is not a middling project, it's blocked
- Sort into three buckets: do now, do once the data is fixed, and don't do. The third bucket is the one that proves the exercise was honest
- Pick exactly one to start. A portfolio that begins with six parallel pilots is how companies arrive at pilot purgatory
- For the one you pick, write what success looks like as a number, and what you'll do if it isn't reached by a stated date
Close the governance gap and write the plan
- Classify each inventory entry by risk: does it touch customer data, can it act without a human, could a wrong output reach a customer or a regulator
- Check the prohibited and high-risk categories in the EU AI Act if you touch the EU market at all, and note where SOC 2, ISO 27001, HIPAA or GDPR obligations already apply
- Write a one-page acceptable-use policy in plain language: approved tools, what may never be pasted into them, and how to request something new
- Name who reviews an AI system before it ships, and what they're allowed to block. A review body without a veto is decoration
- Assemble the plan: the one project, the data fixes it depends on, the policy, the owner of each item, and the dates
What you should be holding at the end.
If you finish without these four artifacts, the exercise turned into a discussion. These are the same four my clients receive.
The AI inventory
A single sheet with every AI system in the company: tool, owner, data touched, retention, review status and risk classification. Nothing else you produce is trustworthy until this exists, which is why it's step one.
The data readiness read
Per function: where the data lives, whether a system can reach it, and which opportunities are blocked until that changes. Usually the least popular document and the most useful one.
The ranked portfolio
Every opportunity scored on value, feasibility, data readiness and risk, sorted into do-now, blocked, and won't-do. Including the won't-do list, which is what makes the other two credible.
The plan and the policy
One project with a number attached and a date, the data fixes it depends on, a one-page acceptable-use policy, and a named reviewer who can stop a launch. Short enough that a board reads all of it.
Where doing it yourself falls down.
This walkthrough is the real method, not a teaser. It still has limits, and you should know them before you start rather than discover them in week three.
The parts that need scar tissue
- , Knowing which of forty findings actually matters this quarter
- , Judging a vendor's claims without having watched similar tools fail
- , Estimating effort for something nobody in the room has built before
- , Saying the uncomfortable thing about a project a senior person sponsors
- , Turning the plan into working systems, which is a different job entirely
The parts that only you can do
- →The inventory, because your people will tell you the truth faster than they'll tell me
- →Knowing where the real operational pain sits, function by function
- →Judging which internal politics will actually block a project
- →Building the muscle, so the second diagnostic takes a week instead of three
- →Deciding, with evidence, whether you need to hire anyone at all
Want the worksheet
to fill in?
The five steps as a structured worksheet: the inventory table, the data readiness grid, the scoring sheet and the plan template. Fill it in on screen, then save or print your completed copy.
About running it yourself.
What is an AI diagnostic?
A structured assessment of what AI a company already runs, what its data can support, where AI would actually pay, and what governance is missing. It produces four artifacts: an auditable AI inventory including shadow AI, a data readiness read per function, a ranked portfolio of opportunities scored on value, feasibility, data and risk, and a sequenced plan with a policy and a named reviewer.
How long does it take to run internally?
About three weeks for a mid-sized company, at roughly a day a week from the person running it plus an hour each from a dozen colleagues. The inventory takes the longest because shadow AI has to be found rather than asked for.
Why would you publish the thing you charge for?
Because the method was never the expensive part. What clients pay for is judgment applied to their specific situation: which findings matter, which vendor claims won't survive a security review, and which use case is quietly blocked by data that doesn't exist. Companies that run this themselves and then call me are better clients, because they already know what they're hiring for.
What is the single biggest mistake people make?
Starting with the opportunity list instead of the inventory. It feels productive and it produces a strategy for a company that doesn't exist. The second biggest is skipping the won't-do list, because a portfolio with nothing declined is a wish list rather than a decision.
Do we need technical people to run it?
For the inventory and the opportunity work, no. A capable operator with access to expense data and IT logs can do it. Step 2 needs someone who understands where your data physically lives, and step 5 benefits from someone who has read a compliance framework before. Neither requires an engineer.
What if we find something alarming?
Most companies do, usually customer data pasted into an unreviewed tool. Contain it, document what happened, and treat the acceptable-use policy in step 5 as urgent rather than administrative. Finding it during your own diagnostic is enormously better than finding it during a customer's security review.
Related reading & paths.
Fractional Chief AI Officer
What happens after the diagnostic: the seat that owns the plan and builds it.
AI Governance & Risk
Step 5 in depth: the inventory, the control set and the review gates that hold.
What a Chief AI Officer costs
If the diagnostic says you need an owner, this is what one costs.
Ran it and don't like
what you found?
Send me the inventory and the ranked list. I'll tell you straight which findings I'd act on first, and whether you need someone in the seat at all.