Organisation Deep Dive Assessment
Challenge the capability position before you rely on it.
Before you start, this page covers who should participate and why the scope matters. Reviewing that guidance will help you complete the assessment with a more accurate, defensible result.
Challenge each position, and record the basis for it.
Answer against the scope as it operates today. Each question takes a response and the basis for it. An unknown is a finding: it scores zero and stays visible as a gap. Confirm existence, ownership and approval status only, and do not enter budgets, personal data or credentials. Your result appears as soon as you finish, and a private link to it is emailed to you.
Loading the assessment.
How useful was this assessment?
Your feedback is critical to improving this assessment, and every comment is read by the team. Rate it, add a comment if you can, and we will email your result link straight after.
Use it where the position needs to be challenged.
A Deep Dive is appropriate where consequences are material, views conflict, confidence is limited, operating options are disputed, or a decision needs independent facilitation. It is built for a working session with the people who own each domain, and it can also be completed online as a first pass.
The assessment does not assume progression towards greater automation or Agentic AI. The Agentic AI module applies only where Agentic AI is an active portfolio concern or a foreseeable governed capability. One isolated productivity tool does not make it relevant.
If you want a lighter first view of the same scope, start with the Organisation Readiness Assessment.
Readiness is distributed across the organisation.
Executives understand purpose, appetite and investment. Process owners and front-line teams understand how work actually happens. Technology, data and security leaders understand access and dependency. Legal, compliance, risk and audit understand obligations and assurance. HR and change leaders understand whether people can exercise meaningful oversight.
The assessment is designed to expose the differences between these perspectives. An approved position, an individual view and a disagreement between functions are not equivalent answers, so each carries a different weight. Each one reveals a different action.
The same foundations decide value. KPMG's 2026 Global AI Pulse found the strongest outcomes were associated not with deploying more AI, but with capabilities such as accountability, governance and cost visibility. McKinsey found that organisations with explicit ownership for responsible AI reached materially higher maturity than those without a clearly accountable function.
KPMG, Global AI Pulse Q2 2026. McKinsey, State of AI Trust in 2026.
Treat a one-person result as provisional until the functions that own each domain have confirmed it.
Combine authority, expertise and operational reality.
Include both decision-makers and people close to the work. Senior leaders can define the intended operating model. Operational participants reveal the exceptions, workarounds, tacit knowledge and dependencies that a sound operating change depends on.
| Perspective | Typical participants | Contribution |
|---|---|---|
| Executive direction | Sponsor, COO, CIO, CTO or business-unit leader | Outcomes, funding, acceptable authority and decisions |
| Process and operations | Process owners, operational leaders, process excellence | Actual work, exceptions, dependencies and performance |
| Technology, data and AI | Architecture, IT, integration, data and AI leaders | Feasibility, information, platforms and observability |
| Security and identity | Security, IAM and resilience leaders | Access, permissions, traceability and continuity |
| Governance and assurance | Risk, legal, privacy, compliance and internal audit | Obligations, challenge, controls and evidence |
| People and organisation | HR, workforce, learning and change | Roles, capacity, consultation, skills and oversight |
| Commercial ecosystem | Finance, procurement and supplier management | Economics, contracts, concentration and exit |
| Front-line knowledge | Managers, subject-matter experts and users | Workarounds, tacit knowledge and real consequences |
Run it as a working session with the full team.
The online result is an indicative baseline. To turn it into decisions, work through the same domains with the people who own them and capture the following alongside each answer.
-
Set the scope
Agree whether the assessment covers the whole organisation, a division, a department or a team. The report title names the scope, and a scoped result must not be presented as representing the whole organisation.
-
Assign domain leads
Give each domain an accountable lead who can gather evidence and involve the right specialists. Accountability should not default to IT because AI is involved.
-
Gather evidence before concluding
Use current strategies, policies, process documentation, architecture, data records, risk assessments, audit findings, incident data, workforce plans and performance measures. Record "unknown" where evidence does not exist.
-
Review answers together
Use the questions to surface disagreement as well as gaps. Different answers from operations, IT, risk and executives are themselves a readiness finding.
-
Convert findings into decisions
Identify missing confirmations, capability gaps, accountable owners and the processes worth assessing next. Prioritise by value, exposure and dependency, not by how easy a gap is to close.
-
Reassess as authority expands
Confidence changes as processes, regulation, technology and the operating model change. Repeat the assessment at agreed milestones and after a material change.
Capture with every answer
- A response: demonstrated, established, partially established, recognised or planned, not established, unknown or not applicable.
- The basis for it: approved, owner confirmed, team consensus, individual view or disputed.
- The accountable owner.
- The internal source that confirms the position. Do not record confidential detail.
- The required action, its priority, its dependency and a target date.
An honest "not established" or "unknown" is more valuable than an unsupported "established". The objective is not to appear ready. It is to understand how far the position can be relied on.
Twelve domains, and a conditional Agentic AI module.
The overall score is the average confidence across the core questions. Each domain is scored on its own. The conditional Agentic AI questions are reported separately and never blended into the overall figure. Eleven gates sit in the Agentic AI module and apply when it is relevant. A gate that needs a condition cannot be averaged away.
- 1
Strategy, Purpose and Value
5 questions
- 2
Governance Operating Model and Accountability
4 questions
- 3
Use-Case Portfolio and Risk Classification
6 questions
- 4
Process and Operating-Model Readiness
6 questions
- 5
Data, Knowledge, Context and Memory
6 questions
- 6
Technology Architecture and Integration
4 questions
- 7
Security, Agent Identity and Access
3 questions
- 9
Testing, Evaluation and Independent Assurance
5 questions
- 10
Operational Control, Monitoring, Incident Response and Resilience
6 questions
- 11
Legal, Regulatory, Ethical and Affected-Person Rights
6 questions
- 12
Workforce, Organisation and Change
5 questions
- 13
Third Parties, Economics and Lifecycle Roadmap
7 questions
A foundation for decisions, not a document that sits on a shelf.
A process can look technically suitable while organisational ownership or governance remains insufficient. Strong enterprise governance does not make every process ready. This is the context that makes a process assessment meaningful.
- A shared organisational context supported by evidence.
- A disagreement and unknowns register.
- A register of the initiatives, decisions and accountabilities in scope.
- Clear decision rights and accountable owners.
- Gates that need a condition before anything proceeds.
- Cross-cutting organisational actions.
- Candidate processes for the Process Readiness Assessment.
- A baseline that can be refreshed after material change.
Designed with reference to recognised frameworks.
The assessment reflects organisational and lifecycle concepts from the NIST AI Risk Management Framework and ISO/IEC 42001, risk, transparency and human-oversight concepts relevant to the EU AI Act, and agent-specific control areas identified by OWASP. These sources give credible foundations, but no framework can answer the questions for your organisation. That takes evidence from the people who own, operate, govern and experience the work.
IGX360 independently developed this assessment. It is not certification, assurance, legal advice or endorsement by the referenced organisations.
Move from organisational capability to a defined process.
Once the team can name a process and the outcome it must deliver, use the Process Readiness Assessment. It shows how much confidence can be placed in your understanding of that process and which operating modes are worth investigating.
The Organisation Deep Dive Assessment provides an indicative confidence baseline for internal discussion. It does not constitute legal, regulatory, security or technical advice, certification, assurance, or approval to deploy any technology. IGX does not independently validate the information unless expressly stated. Obtain appropriate specialist advice and assurance for the use case, sector and jurisdictions involved.