A McKim & Co. diagnostic
Before you spend a dollar on AI, find out whether your operation is actually ready for it.
Most AI projects that fail don't fail because someone picked the wrong tool. They fail because the operation underneath wasn't ready — scattered data, undocumented processes, policies that don't exist yet, coverage that hasn't caught up. The technology takes the blame. The foundation was the problem.
This free AI operational readiness assessment is built for that gap. It doesn't ask which chatbot to buy. It asks whether your business — as it actually runs today — can put AI to work without creating exposure you'll pay for later. Thirty questions, 8–12 minutes, every one answerable from what you already know about your own company. No AI expertise, no framework vocabulary, no prep. A real diagnostic, not a lead-gen tool — you'll leave with something true about your operation whether or not you take another step with us.
How the analysis works
This isn't a scored quiz that hands back a number and a tip sheet. Your answers run through a library of operational failure patterns — built from three decades of running regulated, multi-site operations — that turns responses into named, specific findings about your business. The way an experienced operator would sit across the table, listen, and tell you what they're actually seeing.
The result reads as analysis, not a checklist. It tells you which patterns are showing up in your operation, what each one means in plain language, and what exposure or opportunity it represents. Most people find it gives them words for things they've felt but couldn't name.
Exactly what we ask for — and why
Your name, work email, a password, company name, industry, and phone.
That's the bare minimum to send your results back and know who you are. No birth date, no address, no payment information — the assessment is free.
Who this is built for
Small and mid-sized businesses in regulated or compliance-sensitive fields — professional services, healthcare, financial services, and the practices around them — typically 5 to 200 people, where the work itself is excellent but the operational and compliance layer underneath was built in motion and never fully developed.
If you're a large enterprise with a compliance department and a GRC platform, you have staff for this. This is for the operator carrying it largely alone.
Questions, answered straight
How long does the assessment take?
About 8–12 minutes — thirty questions. Every one is answerable from what you already know about your business. There's nothing to look up and nothing to prepare.
Do I need to know anything about AI?
No. The questions are written in plain operator's language. If you can describe how your business actually runs, you can answer all of them.
Is it really free?
Yes. The assessment and your personalized report cost nothing, and they're built to be useful on their own — whether or not you ever work with us.
What do you do with my answers?
They're used to generate your report — that's it. We ask for the minimum needed to send your results back and know who we're talking to, and we don't sell or share your information.
Is this just a lead-generation form?
No — and you'll be able to tell. A lead-gen form gives you a number and a sales call. This gives you named, specific findings that stand on their own. If a next step makes sense, the report says so plainly. If it doesn't, you still leave with something true and potentially valuable to the business.
What's actually in the report?
Three things: where you stand across the four axes — AI footprint, compliance and insurance, infrastructure, and pressure — the specific findings your answers surfaced, and a proportionate next step matched to your readiness.
Who's behind the assessment?
McKim & Co. — an operations advisory built on three decades of running regulated, multi-site businesses. The assessment reflects how an experienced operator reads a company, not how a software vendor sells one.
What does "AI operational readiness" actually mean?
AI operational readiness is whether your business — its processes, data, policies, people, and insurance coverage — can put AI to work without creating new risk. It's a property of the operation, not the technology: the same tool that pays off in a well-run business creates exposure in a disorganized one. Readiness is measurable, and it's what this assessment reads.
How do I know if my business is ready for AI?
Look at four things: what AI is already in use (including unapproved tools), whether your policies and insurance match that use, whether your processes and data are solid enough to build on, and how much real pressure you're under to move. If you can't answer those four confidently, that's what a readiness assessment is for.
Why do most AI projects fail in small and mid-sized businesses?
Most fail for operational reasons, not technical ones. The tool works; the operation it lands in doesn't — undocumented processes, scattered data, no ownership, no policy. AI accelerates whatever it touches, so it scales the mess as readily as the strengths. Fixing the foundation first is what makes the difference.
What is shadow AI, and should I worry about it?
Shadow AI is AI your staff use without approval or oversight — personal chatbot accounts, browser extensions, AI features quietly switched on inside software you already own. It matters because it's invisible: client data can leave your business through tools nobody vetted, and no policy covers what nobody knows is happening. Most businesses have more of it than they think.
Does cyber insurance cover AI use?
Not automatically — carriers are updating what they ask and what they exclude as AI use spreads. If your application described a business that wasn't using AI and your operation now is, that gap can surface at renewal, audit, or claim time. Reviewing your actual AI use against your current policy language is worth doing before your next renewal.
What should a small business do before buying AI tools?
Before buying anything, get a clear read on the operation the tool will land in: what's documented, where the data lives, who owns the process, what policies exist, and what AI is already in use. That read is the whole point of an operational readiness assessment — it tells you whether to build, or to fix the foundation first.