Guide · Discover phase

How to run an AI readiness assessment for an SMB client

Before you write a single rule about AI, find out what your client's staff are already doing. A structured discovery engagement gives you a real deliverable, a defensible starting point, and a natural path into follow-on work.

Why discovery comes first

You cannot govern what you have not found

It is tempting to open a client engagement with a policy template — fill in the company name, adjust a few clauses, send it out. This almost never works: a policy written in ignorance of what people actually use gets ignored.

If the accounting team has been pasting client data into a free AI tool to draft emails, a policy that never mentions it will not stop them. If nobody realizes the CRM vendor turned on an AI summarization feature by default, banning "AI tools" in the abstract does nothing about it. Rules written for a company that does not exist do not get followed by the company that does.

Discovery flips the order. Find out what is already happening, sort it into what is fine, what needs conditions, and what needs to stop — then write anything down. The resulting policy reads like it was written by someone who has met the client, because it was.

This is also the honest reason discovery is worth charging for. It produces information the client did not have, organized so they can act on it. That is a deliverable, not a preamble to the real work.

Shadow AI discovery

Finding what is already in use

"Shadow AI" is shadow IT with a current name: tools employees adopted on their own because they solved a problem faster than asking IT. None of these methods require covert monitoring — tell staff you're running an assessment and why. Combine several; each catches things the others miss.

Anonymous staff survey

The highest-yield method. Short, anonymous, framed as fact-finding rather than enforcement. See the design notes below — how you ask determines whether people tell the truth.

Expense and subscription review

Pull recent expense reports and card statements for AI-adjacent vendor names, and check the company's software subscription list. Personal-card subscriptions expensed back to the business are a strong signal of unmanaged tool sprawl.

Browser extensions and OAuth grants

Most identity providers (Google Workspace, Microsoft 365 admin center) show which third-party apps employees have granted access to their account. Review this list for AI writing assistants, meeting bots, and extensions with access to email, files, or calendar.

Department lead conversations

Ask managers directly what their team does day to day, and where they've looked for a faster way to do it. Frontline managers often know about tool use their own leadership does not.

Survey design

Designing a staff survey people will actually answer honestly

A badly designed survey produces a clean-looking report that is wrong. Four design choices matter more than the question list itself:

  • Anonymous, and visibly so. Use a tool that doesn't log names or IP addresses by default, and say so in the intro — if people suspect answers are traceable, they under-report.
  • Explicit amnesty framing. State plainly that the goal is understanding current practice, not identifying or disciplining anyone for tools already in use.
  • Short. Five to eight questions, answerable in under five minutes. A long survey gets rushed or abandoned, and rushed answers are worse than none.
  • Ask about tasks before tool names. "What tasks do you do that involve writing, summarizing, or researching?" surfaces use that "Do you use ChatGPT?" misses — people often don't think of a built-in feature as "AI" until you describe what it does.

Illustrative starting point — adapt the wording and length to the client, not a standard to reuse unchanged:

Sample survey outline (adapt before use)

  1. What tasks take up the most repetitive time in your role (writing, summarizing, scheduling, research, data entry, etc.)?
  2. Have you used any tool — free, paid, or built into other software — to do those tasks faster than manually? Name any you recall.
  3. For each tool named: personal-pay, company-pay, or free account?
  4. What kind of information have you put into it (general text, customer names, financial data, code, health information, none)?
  5. Has a manager or client asked you to use, or avoid, a specific AI tool?
  6. Is there a task you wish an AI tool could help with, but haven't tried yet?

Interviews

Stakeholder interviews: who to talk to, what to ask

Owner / executive sponsor

What is driving interest in doing this now? What would make this a wasted engagement? Any tools they've explicitly heard about and want addressed or blocked?

IT / operations lead

What is already managed centrally (SSO, device management, approved software list)? What visibility exists into third-party app access? Any past incidents involving a tool leaking data?

Department managers

What does their team spend time on? Where have they encouraged — or quietly tolerated — a faster way of working? What would they want a policy to make easier, not just safer?

Keep interviews to 20–30 minutes each, aimed at specific, concrete answers about current behavior — not opinions about AI in general.

The inventory

What to record for every tool you find

A tool register is only useful if it captures enough detail to decide on later. For each tool found via survey, interview, or technical review, log:

  • Tool name and vendor
  • Who uses it — one person, a team, or company-wide
  • What data goes in — general text, customer data, financial data, code, personal or health information
  • Account type — company-managed, individually paid, or free/personal
  • Business task it serves — the specific job, not just "AI writing tool"

That last field matters most. "Drafts follow-up emails to prospects" is something you can make a bounded decision about. "AI tool for productivity" is not.

The deliverable

Turning findings into something the client will pay for

Raw survey notes and interview transcripts aren't a deliverable — they're working material. What the client pays for is a package with four parts:

1. Findings summary

Plain-language account of what discovery turned up: which tools, how many people, what kind of data, and any surprises (especially the "already switched on" category).

2. Initial tool register with Conditional-first verdicts

Every tool gets an initial verdict. Default to Conditionally approved rather than a standing Approved — even for Low-risk tools. Low does not mean auto-Approve, and Approved does not mean unrestricted; a first-pass register bounds risk while you learn more, not settles it permanently.

3. A shortlist of decisions the client must make

Not fifty open questions — the handful of calls only the client can make, such as whether a tool handling customer data continues, or a department exception is warranted.

4. A proposed 30-day rollout

What happens next, in order: interim guidance, a formal policy, tool-specific reviews, and an ongoing review cadence.

A findings summary with no recommended decisions is homework you're handing back to the client.The verdicts and shortlist are what make it a deliverable.

The follow-on

How discovery sets up the next engagement

Done well, the assessment produces its own next step. The 30-day rollout proposal is the pitch for a second, larger engagement: the acceptable-use policy, tool-by-tool reviews, employee guidance, and a living tool register.

After rollout, the ongoing relationship is a light quarterly review: revisit the register, check for new tools, confirm nothing Conditionally approved has quietly become unrestricted, and promote anything stable to standing Approved. That cadence turns a one-off fee into a recurring line item, without becoming a heavy compliance program the client resents paying for.

Common mistakes

What derails an otherwise good assessment

  • Turning it into an audit that feels like an inquisition. If staff sense they're being investigated rather than surveyed, they stop answering honestly, and you lose the amnesty framing's value.
  • Boiling the ocean. Cataloging every conceivable AI-adjacent feature across every system in week one stalls the engagement. Scope discovery to a defined window and known-likely sources.
  • Delivering findings with no recommended decisions. A list of tools with no verdicts leaves the client where they started, just better informed.
  • A slide deck nobody can act on. If the deliverable can't be handed to an operations lead as a working document — register, verdicts, next steps — it gets filed away instead of used.

FAQ

Questions we actually get asked

How long should a discovery engagement take?

It depends on client size and how many systems you're reviewing. Scope it as a fixed, bounded engagement with a clear survey window and defined interview list, rather than leaving it open-ended.

Do I need special tools to check browser extensions and OAuth grants?

No — this is usually available directly in the client's existing identity provider admin console (for example, connected apps or third-party access settings in Google Workspace or Microsoft 365). Check the vendor's current documentation for the exact path, since layouts change.

Is it legal to review employees' subscription expenses or app access?

Reviewing company-paid expenses and admin-console records the client already controls is generally straightforward, but monitoring practices carry legal and HR obligations that vary by jurisdiction. Recommend transparency with staff about what's being reviewed and why, and have clients confirm specifics with their own legal or HR advisor first.

What if the survey turns up almost nothing?

That's a legitimate finding, not a failed assessment — it means the client has more headroom to design proactive guidance before habits form, rather than reacting to entrenched shadow use. Say so plainly in the findings summary instead of padding the report.

Where this fits

Delivering this as a packaged client engagement

Everything above is the Discover phase of the Discover → Decide → Operate method behind the AI Guardrails Kit. Running it well from scratch takes real preparation: a survey you trust, an interview list, a register template, and a way to turn findings into verdicts instead of just notes.

The MSP / Consultant Pack ($299) ships a client-ready discovery agenda, a client pitch one-pager, scope language for bounding the engagement, and a practitioner license to reuse the materials across every client. It also includes the Decide and Operate materials this discovery work feeds into: the acceptable-use policy, tool playbooks, and the quarterly review structure described above.

The full kit is available now on the AI Guardrails Kit page — Business Pack $79, MSP / Consultant Pack $299, one-time. Read more on the For MSPs page, or try the free AI tool checklist to see the style first. Questions: hello@railstead.com.

Operational templates only — not legal, compliance, privacy, security, HR, or professional advice. Seller: CurioHausCo LLC.