AI for SMEs

Assessing AI Readiness: A Self-Check for Swiss SMEs

What is AI readiness – and why a self-check?

AI readiness describes the maturity with which a company can introduce and operate artificial intelligence in a value-adding way. It does not answer the question 'Which tool should we buy?' but 'Are our data, processes, people and rules ready enough for AI to deliver any benefit at all?'. Skip this foundation and you pay for it later with failed pilot projects.

A self-check makes the assessment structured and repeatable. Instead of gut feeling, it gives an honest snapshot along clearly defined dimensions – a basis for prioritisation, budget and a realistic roadmap. This is especially valuable for Swiss SMEs, where resources are tight and every misinvestment is keenly felt.

The four dimensions of AI readiness

AI readiness breaks down into four dimensions. Each is necessary, none alone is sufficient. If one dimension is weak, it slows the others: poor data makes even the best model worthless, and missing skills leave good tools unused.

  • Data: availability, quality, structure and legally sound usability of your data – the raw material of every AI application.
  • Processes: how clear, documented and standardised your workflows are. AI supports and automates processes – chaotic workflows don't get better, they just get chaotic faster.
  • Skills: the knowledge, experience and openness of your people, plus access to technical know-how, internally or via partners.
  • Governance: responsibilities, data protection, security and rules for responsible use – from the revDSG to an internal AI policy.

The SME self-check: a checklist in four blocks

Answer each question with yes, partly or no. If 'no' answers cluster in one block, that's where your bottleneck is. Use the list as a team conversation guide, not a box-ticking exam.

  • Data: do we know which data we hold, where it sits and who owns it?
  • Data: are key data digital, up to date and of sufficient quality (few duplicates, gaps or errors)?
  • Data: are we legally allowed to use this data for the intended purpose (revDSG, contracts, consents)?
  • Processes: are the processes we want to improve with AI documented and reasonably standardised?
  • Processes: do we have a concrete, measurable use case with clear value rather than 'something with AI'?
  • Skills: is there a responsible person and a time budget for the topic?
  • Skills: are employees broadly open, and do we have access to the necessary know-how (internally or via partners)?
  • Governance: is there a simple AI policy (what is allowed, which tools, which data may be used)?
  • Governance: are data protection and information security clarified, including the use of cloud services and providers outside Switzerland/the EU?
  • Governance: is it defined who reviews AI outputs before they reach customers or authorities?

From score to decision: interpreting maturity levels

Roughly total up your 'yes' answers and place yourself on a maturity level. What matters is not the exact score but the honest pattern – and where your biggest lever lies.

  • Starting out: many 'no' answers, data and processes unclear. Recommendation: build the basics – clean up data, define a simple use case, rather than automating straight away.
  • Building: the basics are in place, first experiments are running. Recommendation: run a focused pilot with a clear KPI and learn from it.
  • Advanced: data, processes and governance mesh together. Recommendation: scale, standardise and integrate AI into existing workflows.
  • Repeat the self-check every six months: AI readiness is not a one-off status but shifts with your data, team and regulation.

Common mistakes in the assessment

  • Starting with the technology instead of the problem: buying tools before the value is clear.
  • Overestimating data quality: 'we have lots of data' is not the same as usable, clean, permitted data.
  • Forgetting people: without acceptance, training and clear ownership, any solution stalls.
  • Misreading governance as a brake rather than an enabler – clear rules speed up decisions.
  • Assessing once and never again: readiness ages as soon as data, team or regulation change.
  • Starting too big: an over-ambitious first project ties up budget and kills motivation when setbacks hit.

Swiss perspective: revDSG, FDPIC and cost structure

For Swiss SMEs, data protection is part of readiness, not an afterthought. What applies is the revised Data Protection Act (revDSG/nFADP), overseen by the FDPIC – not EU regulation, though that can apply additionally for EU customers. Anyone feeding personal data into AI systems should check the processing purpose, legal basis and, for high risk, a data protection impact assessment.

Think about cost in terms of structure rather than a single figure: one-off efforts (data preparation, rollout, training) and ongoing costs (licences, operation, maintenance, internal time). ROI rarely comes from the tool alone but from effort saved or better decisions – calculate it per use case in CHF and with realistic, not euphoric, assumptions.

  • Do we know the processing purpose and legal basis for every use of personal data?
  • Do we know where our AI providers store and process data (Switzerland, EU, US)?
  • Is a data protection impact assessment planned for high-risk processing?
  • Can we honour data subject rights such as access and deletion even in AI-supported processes?

From assessment to roadmap

An assessment is only worth what follows from it. Translate your results into a few prioritised steps rather than a long wish list.

  • Close the biggest bottleneck first – usually data or a clearly defined use case.
  • Choose a small, measurable pilot (around 8–12 weeks) with a defined success criterion.
  • Assign a responsible person and a realistic time budget.
  • Write a one-page AI policy before tools are rolled out widely.
  • Document results, repeat the self-check every six months and adjust the roadmap.

Frequently asked questions

What is the difference between AI readiness and digital maturity?

Digital maturity broadly describes how well a company uses digital tools and processes. AI readiness is narrower and more demanding: it also checks whether data is of usable quality, processes suit automation and governance for AI use exists. Digital maturity is usually the prerequisite; AI readiness is the next step built on it.

How long does an AI readiness assessment take?

A first self-check with the checklist is doable in a few hours, ideally in a team workshop. A thorough assessment including a data review and prioritisation takes a few days to a couple of weeks depending on size and complexity. What matters is not the duration but that the right people from operations, IT and management contribute honestly.

Do we need perfect data before starting with AI?

No. Perfect data barely exists, and waiting for it prevents any progress. For the specific use case you need data that is good enough, current and legally usable – not for the whole company at once. A sensible approach is to deliberately choose your first use case where the data situation is already solid.

Who should be involved in the assessment at an SME?

Ideally a small, mixed team: someone from management (priorities, budget), someone from the affected department (process knowledge), IT or an IT partner (data, security) and the person responsible for data protection. In small firms these may be the same two or three people. What matters is the mix of business, technical and decision-making perspectives.

How should we roughly think about the cost and ROI of AI?

Separate one-off efforts (data preparation, rollout, training) from ongoing costs (licences, operation, maintenance, internal time). Estimate the benefit per use case concretely in CHF – such as hours saved or errors avoided – and use cautious assumptions. Sound figures depend heavily on the individual case; be sceptical of blanket return promises.

How does the assessment account for the revDSG?

Data protection is one of the four dimensions. For every planned AI use involving personal data, check the processing purpose and legal basis under the revDSG, clarify where providers store data, and plan a data protection impact assessment for high risk. Also ensure data subject rights such as access and deletion remain achievable in AI-supported processes. When unsure, the FDPIC offers guidance.

← Back to overview

Practical AI for your business

From idea to implementation – we show you what is concretely possible in your case.

Request a demo