Back to the blog
AI Consulting

AI audit steps: the methodology from assessment to roadmap

3. August 202610 min

Illustration: AI-generated

Building with AI is getting easier and cheaper every month. Tools like Claude, Cursor or Copilot and countless no-code platforms make it easier than ever to build a first agent or workflow yourself. You might think nobody needs consulting anymore.

The opposite is true. The easier building becomes, the bigger the question of what is even worth building. The bottleneck shifts from technology to clarity. And clarity does not come from yet another tool, it comes from a clean assessment of where you stand. That is exactly what an AI audit delivers.

This article does not describe an abstract ideal process. It describes the one we actually run: 90 minutes, seven timed blocks, a document at the end. Including the questions that get asked and what ends up in that document.

Why most AI projects do not fail on the technology

Most AI initiatives do not fail because the model was too weak. They fail on a lack of direction: where to start, what actually moves a number, what is feasible and in which order it pays off.

The most quoted evidence for this is the report "The GenAI Divide: State of AI in Business 2025" by MIT Project NANDA, published in July 2025. Its finding: the vast majority of the generative AI efforts studied deliver no measurable contribution to the bottom line, despite investment in the tens of billions.

Read that number with care, and we say so deliberately. The report is not peer reviewed, it rests on just over 300 publicly documented initiatives, 52 interviews and 153 surveyed executives, and it has been criticised on methodological grounds. For the argument in this article the percentage does not actually matter.

What matters more is the reason the report itself gives: pilots stall because the tools in use cannot retain feedback, cannot adapt to context and do not improve over time. Translated, the project was started at a point where it could never grow into everyday work. That is not a technology problem, it is a selection problem. And that is exactly where a structured audit comes in.

What an AI audit is, and what it is not

An AI audit is not an extended discovery call and not a tool demo. It is a timed working session with a fixed agenda that ends in a result document you are promised during the meeting itself.

The core working principle: nothing gets estimated. Everything that ends up in the document comes from what you said in the session. Notes are taken live and visibly while we talk. That way you watch your own answers turn into a prioritisation during the meeting, instead of receiving a deck three weeks later that you can no longer trace back.

The 90 minute AI audit agenda, step by step

BlockMinuteWhat exists at the end of this block
Setup and framing0–10Target outcome, trigger, frame for the session
Discovery10–35A list of concrete time sinks per area
Stack and data30–40System landscape, data maturity, mandatory integrations
Opportunities40–55Candidate list of possible AI solutions
Prioritisation55–75A scored impact versus effort matrix
Roadmap and next steps75–88Sequence and compliance points
Close88–90Summary and result document

The transitions are fluid, discovery and stack overlap in practice. The timing is still not an end in itself: it stops the session from getting stuck in the first interesting topic and leaving the prioritisation to be rushed at the end. That is exactly where the mistake happens that the whole project later hangs on.

Setup and framing: sharpening the target

The first ten minutes establish the one outcome you want to leave with and why the topic is on the table right now. This is not small talk. Knowing the trigger, whether that is lost tenders, a growing team without growing processes or pressure from the board, changes how every later opportunity gets rated.

Discovery: where the time actually goes

The longest block. We walk through your areas one by one and look for one or two concrete pain points in each. Three questions carry most of it:

  • "Walk me through a typical week. Where does your team lose the most time?"
  • "Which tasks are repetitive, manual or copy and paste heavy?"
  • "Where do errors or delays cost you the most?"

The questions are deliberately plain. The value is not in the question, it is in not stopping at the first answer. "We do a lot manually" is not a pain point. "Two people move quote data from the inbox into the ERP every Monday and it takes them half a day" is one, because it can be quantified and automated.

Stack and data: what is already there

Before talking about solutions, it has to be clear what they would connect to:

  • "Which tools do you use today, meaning CRM, ERP, spreadsheets?"
  • "How clean and how well connected is your data?"
  • "Does anything have to be integrated no matter what?"

This block decides the later effort rating. The same idea is a quick win when the data sits in a clean CRM with an open API, and a big bet when it is spread across four systems and a grown spreadsheet landscape. Skip this step and you are rating effort blind.

Opportunities: one idea per bottleneck

Only now do solutions enter, one or two per pain point, each with a single line explaining why this one. That line goes into the document unchanged and matters more than it looks: it forces the benefit to be stated in one sentence. Anything that cannot be justified in one sentence rarely survives prioritisation.

Nothing is scored yet. Collecting and scoring are kept apart on purpose, because otherwise the awkward ideas get filtered out early, before anyone has judged their impact.

Prioritisation: impact times effort

Every collected opportunity gets two ratings, impact and effort, each low, medium or high. The placement into four fields follows automatically:

FieldImpactEffortWhat happens with it
Quick winHighLowGoes first, often within the first 90 days
Big betHighHighWorth it, but needs a real plan
Nice to haveLowLowOnly if there is capacity left
SkipLowHighDeliberately not built

From the scored opportunities we mark the top three to five together. The most interesting field is not quick win, it is skip. Almost every company arrives with two or three ideas that are internally settled and still mean high effort for little impact. Retiring them visibly during the session often saves more money than the first quick win earns.

An audit that only tells you what to build is a sales call. One that also tells you what to leave out is consulting.

Roadmap and compliance

The marked opportunities turn into a sequence, quick wins first, big bets in a second phase. The reason is organisational more than technical: a visible early win buys internal patience for the larger effort.

Before the sequence is fixed, we go through four compliance points:

  • EU AI Act: is this a high risk application under Annex III at all? For most operational automation it is not, in which case the transparency duties under Article 50 are what apply. It changes as soon as AI reaches into selection or personnel decisions.
  • GDPR: is personal data involved, and on what legal basis is it processed?
  • UAE PDPL: for work with a regional connection, the questions of data residency and consent.
  • Human in the loop: which decisions require a person to confirm before anything happens?

None of this replaces legal advice. It does prevent a project from failing during delivery over a question that could have been settled in ten minutes at the start. In companies with a works council a fifth point regularly joins the list, because systems capable of recording performance or behaviour are subject to codetermination. In practice that is often a bigger hurdle than the AI Act.

Close: what you walk away with

The final minutes summarise and secure the transition. The result document contains:

  • Starting position and target picture, captured in your own words
  • The bottlenecks identified per business area
  • The opportunities, each with its one line of reasoning
  • The matrix placing every opportunity into quick win, big bet, nice to have or skip
  • The recommended sequence, quick wins first
  • The relevant compliance points
  • The recommendation for the next step

Not a deck full of generic statements, but a prioritised map of your biggest levers. And here is the real test: every statement in it can be traced back to something that was said in the session.

When 90 minutes are not enough: the Strategy Sprint

The audit condenses the assessment to the essentials. It works with whatever can be drawn out of a conversation in an hour and a half, and that is deliberately a snapshot from one perspective. If that is enough, you have clarity about your biggest lever and can start.

If you need a plan your management can sign off, the two week Strategy Sprint follows. It runs in three phases:

PhaseWhat happensResult
Discovery and mappingConversations with leaders and key people, capturing the most important processes as they are todayAn evidenced inventory of bottlenecks rather than a snapshot
Opportunity designA documented collection of use cases, a technical feasibility check for eachA scored use case list and a target architecture
Validation and roadmapJoint prioritisation, impact and effort calculation, alignment with managementA 90 day and 12 month roadmap plus a business case

The difference is not length, it is how much weight the result can carry. The audit shows where the levers are. The sprint shows what they return, what they cost and in which order they pay off, plus an automation architecture describing how it fits together technically. The AI Audit is fully credited toward the sprint.

How to recognise a good AI audit

The difference is not the number of slides, it is four things.

  • It works with your numbers, not industry averages. Every statement in the result has to trace back to something said in the session.
  • It separates collecting from scoring. Score ideas immediately and you lose the awkward ones before anyone has judged their impact.
  • It states effort honestly. People who have never built underestimate integrations reliably. Effort estimates without delivery experience are wishful thinking.
  • It produces a document you can explain yourself. If you cannot retell the result to your leadership in five minutes, it was the wrong result.

Conclusion: clarity is the new bottleneck

Building AI keeps getting easier. The bottleneck therefore moves to the question of what is really worth it, in which order and with what expected effect. These are exactly the questions a good AI audit answers.

If you notice that AI initiatives stall at your company or never really start, the most sensible next step is not more tool research, it is a clear assessment of where you stand. An hour and a half goes further than most people expect.

Key Takeaways

  • 1The bottleneck is not the technology, it is clarity about what is worth doing and in which order.
  • 2The AI Audit runs 90 minutes across seven timed blocks: setup, discovery, stack and data, opportunities, prioritisation, roadmap, close.
  • 3Prioritisation follows impact times effort across four fields. The most valuable one is skip, meaning what deliberately does not get built.
  • 4The two week Strategy Sprint is the deeper engagement in three phases with architecture and a business case. The audit is fully credited toward it.

Sources: the statement about ineffective AI pilots comes from the report "The GenAI Divide: State of AI in Business 2025" by MIT Project NANDA (July 2025). The report is not peer reviewed and rests on just over 300 publicly documented initiatives, 52 structured interviews and 153 surveyed executives; its methodology has been publicly criticised. We cite it for its explanation of why pilots fail, not for the percentage. The notes on the EU AI Act, GDPR, UAE PDPL and codetermination are general orientation and do not replace legal advice.