Modernising ERP, cloud infrastructure or CRM can create useful foundations for AI, but it does not by itself establish AI readiness. The two overlap, but they assess different organisational conditions.

Two different lenses

For the purposes of this framework, I use digital-transformation maturity and AI readiness as two different lenses.

Digital transformation maturity is the extent to which an organisation's processes, customer channels, and internal workflows have been digitised, integrated, and optimised. It asks: how efficiently do data and communication flow through the current operating model?

AI readiness is a different question: the mix of clean data, use-case clarity, governance, analytical skill, and adaptable decision processes that let algorithmic systems be safely and profitably embedded. It asks: is the organisation structurally and culturally prepared to let algorithms augment or automate its decisions?

An organisation can be highly digitally mature and still AI-unready. The reverse is also true: an early-adopter SME running on basic software can be more AI-ready than a digitally sophisticated one, if its data is clean, its ownership is clear, and its leadership is genuinely willing to change how decisions get made.

This distinction is not just an operating observation. Academic research on organisational AI adoption treats AI readiness as involving AI-specific organisational conditions that go beyond simply owning digital technology. Jöhnk, Weißert and Wyrtki's 2021 interview study with 25 AI experts, published in Business & Information Systems Engineering, identifies organisational AI readiness as spanning five categories (strategic alignment, resources, knowledge, culture, and data), distinct from general technology adoption. Separately, Vial's 2019 review of digital transformation research in the Journal of Strategic Information Systems frames digital transformation itself as a multidimensional process, not a single infrastructure milestone. Neither study validates the specific four-dimension comparison or five-level ladder below, those are my own synthesis for practical use, but both support the underlying claim that "digitised" and "AI-ready" are measuring different things.

Dimension Digital Transformation Maturity AI Readiness
Technology & Infrastructure Stable cloud networks, integrated software Environments where models can be tested safely without breaking production
Data Architecture Digitised records and dashboards Consistent, well-understood data with clear ownership and known limitations
People & Culture Basic digital literacy, standard change management Willingness and ability to question and check algorithmic outputs rather than accept them by default
Governance & Risk Standard cybersecurity and IT policy Use-case review, human accountability for automated decisions, and (where relevant) the legal obligations that already apply: see the policy note below

Locating yourself: a five-level ladder

The two-lens distinction explains why the gap exists. This ladder (an author framework, not a validated instrument) is a practical way to locate where an organisation currently sits on the readiness axis specifically.

Level 0
Unaware & Unstructured
No formal AI use, fragmented data.
Level 1
Ad-Hoc Experiments
Staff use consumer tools individually, often without leadership's knowledge, with no governance.
Level 2
Structured Use Cases
A specific, lower-risk problem is named and a tool deployed against it under basic rules.
Level 3
Integrated Workflows
AI is embedded into core processes and depends on genuinely clean internal data.
Level 4
Managed Capability
AI is governed, measured, and steered as a strategic capability, not a collection of tools.

The five-level AI readiness ladder, Level 0 (Unaware & Unstructured) through Level 4 (Managed Capability).

The lower levels capture a recognisable organisational pattern: AI experimentation can begin informally before approved tools, ownership and governance are established. A quick self-check: are staff using AI tools without your explicit knowledge? If yes, you're at Level 1. Do you have a documented list of approved tools and the specific problems they solve? If no, you haven't reached Level 2. Is your core operational data clean enough for an algorithm to read without a human translating it first? If no, Level 3 isn't achievable yet regardless of what tools you buy.

Move one level at a time. Jumping from Level 0 to Level 4 in one step is not a realistic plan; it's a way to spend a year's budget on a single failed rollout.

Hype vs. readiness

Before approving any AI project, it's worth separating genuine readiness from confident-sounding hype. Hype tends to sound broad and tool-led: "every department needs AI immediately," "this tool will solve your productivity problem," "you don't need to change your workflows," "governance can come later." None of these claims explain the operational change actually required.

A genuinely AI-ready organisation can answer, specifically: which business problem AI will address, where the relevant data lives, who owns the workflow, what outputs need human review, what risks must be controlled, and how value will be measured. If those questions can't be answered clearly, the project isn't ready, no matter how compelling the pitch was.

Hypothetical illustration, not a specific client. Picture a hotel group with a mature digital booking engine: real-time availability, integrated payments, a clean customer-facing interface. That's genuine digital maturity. If this group plugs an AI dynamic-pricing tool directly into that system without first building governance to monitor its recommendations, or without examining historical booking data for gaps, inconsistencies or patterns that require attention before use, the result may be a tool that produces erratic prices or quietly carries old mistakes forward at scale, damaging both revenue and guest trust. The booking engine was never the readiness gap. The missing governance and the unexamined data were.

Closing the gap: a process-readiness checklist

AI automation makes sense when the workflow is documented, the data is available and consistent, the task is repetitive or decision-supportive rather than purely judgment-based, human review remains possible, business value is measurable, and risk can actually be controlled. Where any of these is missing, the right move is to fix the process first, not automate around it.

  • Document the workflow as it actually runs today, not as the org chart says it runs
  • Remove duplicate or redundant steps before automating any of them
  • Standardise data entry so the same field means the same thing everywhere
  • Assign clear process ownership: one name, not a department
  • Define quality checks before automation, not after something goes wrong
  • Decide explicitly where human judgement stays central, rather than letting that boundary drift

A policy note

It's tempting to treat "AI readiness" and "compliance with Mauritius's emerging AI policy" as the same project. They're related but distinct. The FAIR Guidelines that accompany the National AI Strategy are explicitly scoped to the public sector; readiness work described here is good practice regardless of that scope, not a response to a private-sector obligation that doesn't yet exist. Separately, the Data Protection Act 2017 already applies to specific automated decisions about people: Section 38 addresses decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect the individual. What the National AI Strategy actually says for SME owners covers this distinction, and Section 38 specifically, in full.

What to do next

Do not approve funding for a new AI project until you've run an honest self-assessment against the ladder above and can answer the readiness questions specifically. If you're a policymaker or ecosystem builder, the same distinction matters at scale: general digitalisation support (subsidised software, basic connectivity) is not the same thing as dedicated AI-readiness support (data governance clinics, structured literacy training), and conflating the two in programme design will fund a lot of digitisation that never becomes AI capability.