Example artifact generated by Azrivo — a Plan-mode deliverable from a generic business scenario. AI-generated draft; verify before use. See the run →
AI Readiness Gate
Every candidate where the proposed solution involves AI/LLM tooling must clear this gate before entering design. Six dimensions. Pass / Conditional / Fail. No exceptions.
When to use this gate: Apply after the process has passed the intake triage and scored well enough on the Evaluation Criteria (Step 2) to be a viable candidate — and the solution approach proposed involves generative AI, LLMs, or any model whose output is probabilistic rather than deterministic. RPA-only, deterministic rule engines, and classic workflow automation skip this gate.
Gate Status:INCOMPLETE
Green: 0 Yellow: 0 Red: 0
Answer all questions across all six dimensions to receive a gate determination.
Dimension 1 of 6—
Data Sensitivity & Exposure
What data does the AI touch, and where does it go? The core concern is whether sensitive data leaves your control boundary or enters a model provider's environment without adequate contractual, technical, or regulatory safeguards.
Q1. What is the highest classification of data the AI will process?
Q2. Where will the data be processed — i.e., where does the model run?
Q3. Can the data be masked, anonymized, or pseudonymized before the AI sees it?
Dimension 2 of 6—
Hallucination Tolerance & Blast Radius
LLM output is probabilistic, not deterministic. The question is: when the model hallucinates, who catches it, and what breaks? This dimension measures the cost of being wrong and whether a human stands between the AI and the real world.
Q4. Is a human reviewing the AI's output before it takes any consequential action?
Q5. What is the blast radius of a single hallucinated output?
Q6. Is the output verifiable — i.e., can correctness be cheaply and reliably checked?
Dimension 3 of 6—
Bias & Fairness Exposure
Does the AI's output affect people in consequential ways? If the model encodes a bias — from training data or prompt design — who gets hurt and how badly? This dimension separates "the AI summarizes meeting notes" from "the AI screens job applicants."
Q7. Does the AI's output directly or indirectly affect decisions about people?
Q8. Could the AI's output disadvantage a group with protected characteristics — even unintentionally?
Q9. Is there a bias monitoring and mitigation plan for this use case?
Dimension 4 of 6—
Explainability & Auditability
Can a regulator, auditor, or non-technical stakeholder understand why the system produced a given output? Where explainability is legally required, a black-box LLM answer is not sufficient — you need an explainability layer, a deterministic fallback, or a different approach.
Q10. Is there a legal or regulatory requirement to explain the AI's output?
Q11. Can the proposed AI approach produce an auditable decision trail?
Q12. Is there a non-AI fallback that can produce the same outcome — for audit or when the AI is unavailable?
Dimension 5 of 6—
Model Sourcing & Vendor Constraints
Where does the model come from, who controls it, and what constraints bind it? This covers data residency, jurisdiction, IP terms, vendor lock-in, and the build-vs-buy decision for the model itself.
Q13. What is the proposed model deployment model?
Q14. Do data residency or jurisdictional requirements constrain where the model can run?
Q15. Has vendor due diligence been completed — security review, IP terms, SLA, exit plan?
Dimension 6 of 6—
AI Governance & Policy Compliance
Does the organization have an AI acceptable-use policy, and does this use case comply with it? This dimension catches the "nobody asked legal" scenario — the automation team builds something useful that quietly violates a policy nobody knew existed.
Q16. Does the organization have a formal AI acceptable-use policy or governance framework?
Q17. Has legal / compliance / infosec reviewed this specific use case for AI deployment?
Q18. Is there an AI governance body (council, board, steering committee) that must approve AI deployments — and has it been engaged?
If no governance body exists, select the green option (the CoE is the de facto approver). If one exists and mandates approval, engaging it is a prerequisite.
Integration with the broader framework: This gate feeds into Step 2's Risk Safety dimension. A process that scores 1–2 on Risk Safety (Step 2) and also FAILs this gate is a strong signal for deterministic-only automation or deferral. Processes that PASS this gate proceed to the AI solution design track in Step 4. CONDITIONAL processes proceed to design but carry a list of guardrail conditions that must be satisfied before go-live — see the routing table below. This gate should be re-run at design completion (did the design actually satisfy the conditions?) and again post-deployment (did reality match the assessment?).
Fictional example artifact generated by Azrivo (azrivo.com) from a generic business scenario, to show what a Plan-mode run produces. Not a real company deliverable; AI-generated — treat as a reviewable first draft.