Private equity and portfolios
AI readiness assessment for portfolio companies: what to score
By SourceX Editorial · Updated
Short answer
An AI readiness assessment for portfolio companies should score the records and permissions behind any AI plan, not the tools in use. Rate ten criteria from 0 to 3, covering connected systems, accessible history, rights clarity, export capability and more. Any zero on rights clarity or privacy maturity blocks outside licensing, whatever the total.
Key takeaways
- Score ten criteria from 0 to 3 so every company gets a total out of 30 on the same basis.
- Score unknowns as zero until someone produces evidence.
- A zero on rights clarity or privacy maturity blocks external licensing regardless of the total.
- The same scorecard serves internal AI projects and data licensing, but different criteria decide each.
What should an AI readiness assessment score?#
An AI readiness assessment should score whether a portfolio company's records and permissions can support AI work, because tools are easy to buy and usable records are not. Ten criteria cover the ground: four about the records, three about rights and privacy, and three about the company's capacity to act.
Each criterion uses a 0 to 3 scale. Zero means absent or unknown, one means partial, two means adequate with known gaps, and three means strong and evidenced. Keep the scale coarse on purpose: finer scales invite debate without changing any decision, and a value creation lead needs comparable answers across companies, not precision within one.
The ten-criterion scorecard#
The ten-criterion scorecard describes the two ends of each scale so assessors can place a company between them. Scores of one and two fall in between: some evidence, with gaps that are named in the notes column of your working sheet.
| Criterion | Scores 0 when | Scores 3 when |
|---|---|---|
| Connected systems | Records sit in separate tools with no shared IDs | Core systems share customer, job, order or ticket IDs |
| Accessible history | Little history survived past migrations | Several years of records can still be exported |
| Record linkage | Requests, decisions and outcomes are stored apart | A request can be followed to its decision and result |
| English share | Records are mostly in other languages, or unknown | Records are predominantly in English |
| Rights clarity | Customer contracts and terms were never reviewed for data use | Contracts are reviewed and permitted uses are written down |
| Privacy maturity | No map of where personal data sits | Personal data is mapped by system, with retention rules |
| Vendor and export terms | Platform terms and export rights are unknown | Export rights are confirmed for each key platform |
| Export capability | No one has pulled full history from core systems | Full exports with free text and attachments have been tested |
| Owner and approver | No one owns data decisions | An executive owns the work and the signer is known |
| Use or buyer fit | No identified internal use or outside interest | A specific internal use or buyer interest is documented |
How to score consistently across companies#
Consistent scoring matters more than precise scoring, because the point is to compare companies and track change over the hold. The rules below keep scores honest when several people assess several companies, and they make the scorecard defensible when a portfolio CEO disagrees with a number.
- Score from evidence such as a system list, a contract review or a test export; opinions score as unknown.
- Score unknowns as zero until evidence arrives.
- Use the same assessor, or hold a short calibration session, across companies.
- Record the evidence and the date beside each score.
- Rescore after any system migration, acquisition or material contract change.
Where readiness scores usually go wrong#
Readiness scores usually go wrong in the same few ways, and nearly all of them inflate the total. Check for each one before a scorecard reaches an investment committee or a board pack, because an inflated score sends a company into a fit check or pilot it cannot finish.
- Counting company age as accessible history when a past migration dropped most of the records.
- Scoring connected systems from an integration diagram rather than from a shared ID that actually appears in the records.
- Treating a website privacy policy as evidence of privacy maturity.
- Scoring rights clarity from current terms while older versions still govern most of the archive.
- Letting company leadership score itself without attaching evidence.
Score bands and the next action for each#
Score bands turn a total into a next action, which is what makes the assessment useful in a portfolio review. Treat 20 out of 30 as a working pass threshold and adjust it once several companies have been scored.
Two gates override the total. A zero on rights clarity or on privacy maturity means no external licensing work starts until that criterion reaches at least two, even if the company scores well everywhere else. Internal pilots can still proceed under the company's own controls.
| Total out of 30 | What it means | Next action |
|---|---|---|
| 0 to 10 | Records or permissions are not yet in place | Name an owner, list systems and stop history loss in planned migrations |
| 11 to 19 | Some strong records, with material gaps | Close the two weakest criteria, usually rights review and export testing |
| 20 to 24 | Ready for a scoped internal pilot or a licensing fit check | Run a metadata-only fit check on the strongest record family |
| 25 to 30 | Strong across records, rights and capacity | Prioritize for both internal AI work and licensing review |
Internal AI readiness vs licensing readiness#
Internal AI readiness and licensing readiness draw on the same ten criteria but lean on different ones. An internal project such as quote support or ticket triage depends most on connected systems, export capability and a named owner. Licensing records to AI developers depends most on accessible history, record linkage, rights clarity and privacy maturity.
That difference explains why a company can be ready for one and not the other. A business with modern connected systems but little surviving history may suit internal pilots and not licensing, while a company with a deep archive in a retired system may be the reverse. Report both readings rather than a single verdict.
Illustrative: scoring two portfolio companies#
Illustrative: a value creation lead scores two fictional companies. The first, an electrical contractor on ServiceTitan, scores well on connected systems, linkage and export, because estimates, jobs, invoices and callbacks share job numbers. It scores zero on privacy maturity: no one has mapped where homeowner details sit across job notes, photos and call recordings.
The second, a B2B billing software vendor, scores high on history and linkage across Jira, GitHub and Zendesk, and its customer contracts were reviewed during a recent refinancing. Its weak point is export capability, since no one has pulled full Zendesk history with attachments.
The contractor clears the working threshold, but the privacy gate holds licensing back, so its next action is a data map. The software vendor moves to a metadata-only fit check while IT tests a full export.
How SourceX looks at the same questions#
The SourceX Enterprise Data Value Framework covers the licensing side of this scorecard. It is a qualitative SourceX methodology whose drivers include rights, recency, scale, data cleanliness and AI utility, with preparation cost and privacy burden reducing net value, so low scores on rights clarity or privacy maturity show up there too. A company that scores well can start with a fit check that collects metadata only, so nothing leaves the company.
If the company proceeds, the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, turns the scorecard's gaps into specific tasks, and the SourceX Evidence Packet records how each one was resolved.
Frequently asked questions
Why does the scorecard include English share?
Licensing fit often depends on records being predominantly in English, so language affects the external reading of the score. It matters much less for internal projects. A company with large archives in other languages is not ruled out, but those records may need separate confirmation of buyer interest before scoping.
Should the scorecard include AI tools staff already use?
Track them separately. Which AI tools staff use, and under what data terms, is a governance and risk question. It does not show whether records can support new work, so mixing it into the readiness score blurs both answers.
How often should a portfolio company be rescored?
Rescore at each annual value creation review and after any event that changes the inputs: a system migration, an add-on acquisition, a new customer contract template or a change in data ownership. Keep earlier scores so the board can see movement over the hold.
Who should fill in the scorecard at the company?
One executive owner, usually the COO, CFO or CTO, with input from IT on systems and exports and from counsel on rights. The value creation lead reviews the evidence and keeps scoring consistent across the portfolio.
Can a company with a low total still license data?
Sometimes, if one record family is strong. Totals describe the whole company, while licensing works package by package. A low total with a rights-clear, well-linked support archive can still justify a fit check on that archive alone.
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo I need customer consent to license support tickets?
- InsightDo former employees have to consent before a closed company licenses their messages?
- InsightCan HVAC and plumbing companies license technician helmet-camera footage?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.