The executive checklist: 30 questions before scaling AI
A verification routine across five dimensions — data, risk, integration, people and cost — to separate enthusiasm from readiness.
*Closing article in our series on enterprise AI, legacy integration and information governance.*
Executive summary
Scaling AI too early produces recurring cost without assets and exposure without a trail. This checklist gathers, across five dimensions, the questions the whole series supports. The rule is simple: if you cannot answer a question with evidence — a document, a number or a demo — it becomes a plan item before it becomes scale.
1. Data and knowledge
- 1.Do we know where the most valuable data lives in each priority process?
- 2.Is there an identifiable current version of the documents AI will consult?
- 3.Does someone own the archive, with authority to retire obsolete material?
- 4.Are source permissions inherited by the index and enforced per user?
- 5.Are prompts, context and responses recorded in our own infrastructure?
- 6.Can we locate every place a given data subject's data appears?
2. Risk and compliance
- 1.Does each use case have a declared purpose and legal basis?
- 2.Is the risk matrix published and predictable for those proposing cases?
- 3.Do high-risk cases go through an impact assessment before production?
- 4.Is human review mandatory where decisions affect people?
- 5.Do contracts expressly forbid using our content for training?
- 6.Do we know the subprocessors and the effective inference region?
- 7.Do we know, in writing, what happens to our data at contract end?
- 8.Can we produce the trail behind a decision in under one business day?
3. Integration and architecture
- 1.Does the first use case cross a real legacy system?
- 2.Is there a translation layer isolating legacy from AI applications?
- 3.Is user identity propagated end to end?
- 4.Do we know how much extra load source systems can absorb?
- 5.Do the archive, versioned prompts and trail live outside the vendor's platform?
- 6.Can we describe, in half a page, a migration to another vendor?
4. People and process
- 1.Do the five governance roles have named people and a meeting cadence?
- 2.Does the acceptable use policy fit on one page and is it published?
- 3.Is the official path more convenient than the unapproved alternative?
- 4.Is there a channel to report errors without penalty for good faith?
- 5.Is archive curation owned by the domain expert rather than IT?
- 6.Were the freed hours reallocated into capacity or cost reduction?
5. Cost and return
- 1.Is there a baseline measured before the intervention?
- 2.Does each case have one primary and one quality metric?
- 3.Does total cost include integration, curation, governance and change management?
- 4.Does each pilot have a written exit criterion and a decision date?
How to use it
Answer as a group, with evidence, and mark each item in one of three states: met, planned, or not met. The scaling rule: no medium- or high-risk use case reaches production with a "not met" item in dimensions 1 and 2.
| Range | Interpretation | Action |
|---|---|---|
| 24 to 30 met | Ready to scale with control | Federate low-risk cases |
| 15 to 23 | Ready for specific cases | Scale one domain at a time |
| Below 15 | Risk of cost without assets | Return to wave 1 of the roadmap |
Conclusion
This series began with a simple thesis: using ChatGPT, Claude or Gemini is only part of the equation. The other part — preserving, auditing, sharing and reinvesting the knowledge produced across the whole company — is what separates expense from equity. The checklist above is the verification instrument; the 12-month roadmap is the path.
Further reading
Engineering track:
- Technical readiness checklist for AI in production — the technical deep dive on this topic.
