This is the exact grading criteria we use in our $2,500 Readiness Scan. Check every box that’s true for your organization. Be honest — we will be.
28 checkpoints across 6 domains. Each one matters. No partial credit.
Before an AI system can align with your values, those values need to exist in writing — clear enough that a machine can parse them and a new employee can understand them on day one.
Not a motivational poster. A specific, actionable statement that describes what your organization does, for whom, and why. One paragraph max.
Each value has a name AND a 2-3 sentence definition of what it means in practice. Not just “Integrity” — but what integrity looks like in your daily operations.
A machine needs to know who it’s serving. “Everyone” is not an answer. Define your primary audience clearly enough that an AI can adjust its tone and priorities.
If your AI speaks to customers, it needs a voice guide. Formal or casual? Technical or plain? What words do you never use? What topics are off-limits?
Not a committee. A name. Someone who can say “yes, the AI should do this” or “no, it shouldn’t.” This person will be your Oethos admin.
Your SOPs are the playbook. An AI governance system enforces your playbook — but only if the playbook exists, is current, and is specific enough to be unambiguous.
Customer onboarding, support escalation, content approval, hiring, procurement — the top 10 things your business does repeatedly. Written down. Step by step.
Not just “do steps 1-5.” Each procedure explains what success looks like and why this process exists. The machine needs intent, not just instructions.
What happens when the normal path breaks? Who gets called? What’s the fallback? If your SOPs only cover the happy path, the AI will freeze on edge cases.
Stale SOPs are worse than no SOPs — they teach the AI outdated behavior. If your last update was 2023, you’re training your AI on ancient history.
Not in someone’s email. Not on a random Google Drive. One place where every team member — and eventually, your AI — can find the current version.
AI makes decisions constantly — what to say, what to recommend, when to stop. Your organization needs documented decision boundaries so the AI knows where its authority ends and a human begins.
Dollar thresholds, access levels, decision tiers. Who can approve a $500 expense vs. a $50,000 contract? These same tiers apply to AI autonomy.
When something goes wrong — or the AI encounters something it shouldn’t handle — who does it notify? What’s the chain? How fast?
Firing someone. Issuing a refund over $X. Responding to legal threats. Contacting media. Define the bright lines the AI must never cross alone.
The AI needs to know who reports to whom. Not the aspirational org chart — the real one. If your VP of Sales actually reports to the CEO’s spouse, document it.
When two departments disagree, what happens? When a customer disputes an AI decision, who reviews it? Conflict resolution is governance.
What can your AI see? What must it never touch? Which data leaves your network and which stays? If you can’t answer these questions today, your AI can’t follow rules that don’t exist.
Not all data is equal. Your AI needs to know what it can reference, what it can share, and what it must never include in a response. Four tiers. Documented.
If you’re using cloud AI, your prompts leave your network. Do your prompts contain customer PII? Employee data? Trade secrets? Know the boundaries.
Does your privacy policy mention AI? Does it explain that customer interactions may be processed by AI systems? If not, you have a legal gap.
AI audit trails generate data. Conversation logs, decision records, compliance documentation. How long do you keep them? Who can access them? When are they deleted?
ChatGPT, Copilot, Grammarly, Jasper, custom bots — do you know every AI tool your employees use? Shadow AI is the #1 governance risk. You can’t govern what you can’t see.
Where does AI enhance your humans? Where do humans stay in the loop? This isn’t about replacing people — it’s about knowing which tasks are better with AI and which aren’t.
List the specific tasks: “AI drafts first responses, human reviews.” “AI summarizes calls, human makes decisions.” Specific. Not “use AI everywhere.”
Performance reviews? Hiring decisions? Legal advice? Medical recommendations? Some tasks should never be delegated to AI. Document the exclusions.
Not just “here’s a login.” Actual training: what the AI can do, what it can’t, how to verify its output, when to escalate. Untrained users create ungovernable AI.
If someone notices the AI said something wrong and they’re afraid to report it, you have a governance failure. Psychological safety is an AI governance requirement.
What laws apply to your AI usage? Which industry regulations govern your sector? If you don’t know, you’re already non-compliant.
EU AI Act? GDPR? HIPAA? Industry-specific rules? List them. If you’re not sure, that’s an answer too — and it means you need the Readiness Scan.
Not just “don’t use ChatGPT for client data.” A real policy: what’s allowed, what’s not, consequences for violations, signed acknowledgment. On file.
What happens when the AI says something wrong to a customer? Who’s notified? What’s the response time? How do you communicate it? Plan this before it happens.
If a regulator, customer, or court asks “why did your AI do X?” — can you answer? Can you show the logs, the rules that were active, and the decision path? That’s what Oethos provides. But you need the foundation first.
This kit tests your documentation. The scan tests your reality. Here’s what we do that a checklist can’t:
We map every AI system you’re running — the models, the harnesses, the brains, the skill sets. Not what you think is deployed. What actually is.
We compare your AI’s actual capabilities against your stated goals. Where are the blind spots? Where is AI doing things nobody authorized? Where is it missing entirely?
How is your AI wired? Is it a single model with a prompt, or a multi-agent system with tools and memory? We assess the harness, the orchestration, and the decision flow.
Your policy says “don’t share customer data.” But does your AI actually follow that? We test what your AI does, not what your documents say it does.
Why this matters: Most organizations discover during the scan that their AI is doing things they didn’t know about. Shadow deployments. Unmonitored integrations. Models with access to data they shouldn’t have. The checklist above tests if you’re prepared. The scan tests if you’re safe.
We believe you should know exactly where your money goes. Here's the real timeline and what happens at each stage.
We collect your SOPs, policies, org charts, AI tool inventory, and governance docs. We expect to help you extract and compile this. Most organizations don't have it organized. That's normal. That's why we're here.
We audit your AI deployments, analyze your harness and skill architecture, and map gaps. For each gap, we determine: is this one we fill, or one you fill? If we fill it, we work on it. If you fill it, we guide you and hold you accountable.
We pressure-test your gap remediation. We check your work. We push you when you stall. The average engagement takes a full month because people delay, get busy, and need help 'getting to it.' That's expected. That's part of the process.
You receive a full readiness report. If you're ready for Oethos, we talk next steps. If you're not, you're still closer than when you started — the assessment itself is a consulting engagement that has value regardless of outcome.
$2,500 for a minimum of two weeks of dedicated work by a real person. That's roughly half a month's salary. The average engagement stretches to a month because organizations need help, stall on deliverables, and discover more gaps than expected.
This is almost a 50/50 chance of a net loss for us. We know that going in.
Our gamble: that we find an organization with their foundation solid enough that we can build something real together. And even when we don't — the assessment still got you closer to ready. That's the value. That's why it's worth it either way.
Be honest with yourself. Each checkbox represents a real requirement for responsible AI governance.