Skip to content

Private equity and portfolios

AI readiness assessment for portfolio companies: what to score

By SourceX Editorial · Updated

Short answer

An AI readiness assessment for portfolio companies should score the records and permissions behind any AI plan, not the tools in use. Rate ten criteria from 0 to 3, covering connected systems, accessible history, rights clarity, export capability and more. Any zero on rights clarity or privacy maturity blocks outside licensing, whatever the total.

Key takeaways

  • Score ten criteria from 0 to 3 so every company gets a total out of 30 on the same basis.
  • Score unknowns as zero until someone produces evidence.
  • A zero on rights clarity or privacy maturity blocks external licensing regardless of the total.
  • The same scorecard serves internal AI projects and data licensing, but different criteria decide each.

What should an AI readiness assessment score?#

An AI readiness assessment should score whether a portfolio company's records and permissions can support AI work, because tools are easy to buy and usable records are not. Ten criteria cover the ground: four about the records, three about rights and privacy, and three about the company's capacity to act.

Each criterion uses a 0 to 3 scale. Zero means absent or unknown, one means partial, two means adequate with known gaps, and three means strong and evidenced. Keep the scale coarse on purpose: finer scales invite debate without changing any decision, and a value creation lead needs comparable answers across companies, not precision within one.

The ten-criterion scorecard#

The ten-criterion scorecard describes the two ends of each scale so assessors can place a company between them. Scores of one and two fall in between: some evidence, with gaps that are named in the notes column of your working sheet.

The ten-criterion scorecard
CriterionScores 0 whenScores 3 when
Connected systemsRecords sit in separate tools with no shared IDsCore systems share customer, job, order or ticket IDs
Accessible historyLittle history survived past migrationsSeveral years of records can still be exported
Record linkageRequests, decisions and outcomes are stored apartA request can be followed to its decision and result
English shareRecords are mostly in other languages, or unknownRecords are predominantly in English
Rights clarityCustomer contracts and terms were never reviewed for data useContracts are reviewed and permitted uses are written down
Privacy maturityNo map of where personal data sitsPersonal data is mapped by system, with retention rules
Vendor and export termsPlatform terms and export rights are unknownExport rights are confirmed for each key platform
Export capabilityNo one has pulled full history from core systemsFull exports with free text and attachments have been tested
Owner and approverNo one owns data decisionsAn executive owns the work and the signer is known
Use or buyer fitNo identified internal use or outside interestA specific internal use or buyer interest is documented

How to score consistently across companies#

Consistent scoring matters more than precise scoring, because the point is to compare companies and track change over the hold. The rules below keep scores honest when several people assess several companies, and they make the scorecard defensible when a portfolio CEO disagrees with a number.

  • Score from evidence such as a system list, a contract review or a test export; opinions score as unknown.
  • Score unknowns as zero until evidence arrives.
  • Use the same assessor, or hold a short calibration session, across companies.
  • Record the evidence and the date beside each score.
  • Rescore after any system migration, acquisition or material contract change.

Where readiness scores usually go wrong#

Readiness scores usually go wrong in the same few ways, and nearly all of them inflate the total. Check for each one before a scorecard reaches an investment committee or a board pack, because an inflated score sends a company into a fit check or pilot it cannot finish.

  • Counting company age as accessible history when a past migration dropped most of the records.
  • Scoring connected systems from an integration diagram rather than from a shared ID that actually appears in the records.
  • Treating a website privacy policy as evidence of privacy maturity.
  • Scoring rights clarity from current terms while older versions still govern most of the archive.
  • Letting company leadership score itself without attaching evidence.

Score bands and the next action for each#

Score bands turn a total into a next action, which is what makes the assessment useful in a portfolio review. Treat 20 out of 30 as a working pass threshold and adjust it once several companies have been scored.

Two gates override the total. A zero on rights clarity or on privacy maturity means no external licensing work starts until that criterion reaches at least two, even if the company scores well everywhere else. Internal pilots can still proceed under the company's own controls.

Score bands and the next action for each
Total out of 30What it meansNext action
0 to 10Records or permissions are not yet in placeName an owner, list systems and stop history loss in planned migrations
11 to 19Some strong records, with material gapsClose the two weakest criteria, usually rights review and export testing
20 to 24Ready for a scoped internal pilot or a licensing fit checkRun a metadata-only fit check on the strongest record family
25 to 30Strong across records, rights and capacityPrioritize for both internal AI work and licensing review

Internal AI readiness vs licensing readiness#

Internal AI readiness and licensing readiness draw on the same ten criteria but lean on different ones. An internal project such as quote support or ticket triage depends most on connected systems, export capability and a named owner. Licensing records to AI developers depends most on accessible history, record linkage, rights clarity and privacy maturity.

That difference explains why a company can be ready for one and not the other. A business with modern connected systems but little surviving history may suit internal pilots and not licensing, while a company with a deep archive in a retired system may be the reverse. Report both readings rather than a single verdict.

Illustrative: scoring two portfolio companies#

Illustrative: a value creation lead scores two fictional companies. The first, an electrical contractor on ServiceTitan, scores well on connected systems, linkage and export, because estimates, jobs, invoices and callbacks share job numbers. It scores zero on privacy maturity: no one has mapped where homeowner details sit across job notes, photos and call recordings.

The second, a B2B billing software vendor, scores high on history and linkage across Jira, GitHub and Zendesk, and its customer contracts were reviewed during a recent refinancing. Its weak point is export capability, since no one has pulled full Zendesk history with attachments.

The contractor clears the working threshold, but the privacy gate holds licensing back, so its next action is a data map. The software vendor moves to a metadata-only fit check while IT tests a full export.

How SourceX looks at the same questions#

The SourceX Enterprise Data Value Framework covers the licensing side of this scorecard. It is a qualitative SourceX methodology whose drivers include rights, recency, scale, data cleanliness and AI utility, with preparation cost and privacy burden reducing net value, so low scores on rights clarity or privacy maturity show up there too. A company that scores well can start with a fit check that collects metadata only, so nothing leaves the company.

If the company proceeds, the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, turns the scorecard's gaps into specific tasks, and the SourceX Evidence Packet records how each one was resolved.

Frequently asked questions

Why does the scorecard include English share?

Licensing fit often depends on records being predominantly in English, so language affects the external reading of the score. It matters much less for internal projects. A company with large archives in other languages is not ruled out, but those records may need separate confirmation of buyer interest before scoping.

Should the scorecard include AI tools staff already use?

Track them separately. Which AI tools staff use, and under what data terms, is a governance and risk question. It does not show whether records can support new work, so mixing it into the readiness score blurs both answers.

How often should a portfolio company be rescored?

Rescore at each annual value creation review and after any event that changes the inputs: a system migration, an add-on acquisition, a new customer contract template or a change in data ownership. Keep earlier scores so the board can see movement over the hold.

Who should fill in the scorecard at the company?

One executive owner, usually the COO, CFO or CTO, with input from IT on systems and exports and from counsel on rights. The value creation lead reviews the evidence and keeps scoring consistent across the portfolio.

Can a company with a low total still license data?

Sometimes, if one record family is strong. Totals describe the whole company, while licensing works package by package. A low total with a rights-clear, well-linked support archive can still justify a fit check on that archive alone.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify