The six foundations we assess before anyone picks a tool
By Ashish Malik, Co-Founder and CEO, 108 ideaspace inc. | 01-10-2026
In short
AI readiness is an organization’s ability to adopt AI responsibly, at scale, and in a way that survives the person who set it up. At 108 ideaspace, we assess it across six foundations: strategy, data, process, governance, people and risk. For associations, nonprofits and regulators, most of that work has little to do with AI tools, and any weakness in those foundations becomes more visible once AI arrives.
Give a model three overlapping definitions of “active member,” and it will choose one, sound completely certain, and put that number in a board report. That is the AI readiness problem in one sentence, and it has nothing to do with which tool you buy.
Yet the questions arriving at association and nonprofit leadership tables tend to sound the same: which tools should we adopt, where can we automate, what are staff allowed to use, and what are our peer organizations doing?
These are fair questions. But none of them is the first question.
What is AI readiness?
The first question, and the real test of AI readiness, is whether the organization could absorb AI if you handed it over tomorrow, responsibly, at scale, and in a way that survives the person who set it up moving into another role. Getting AI into an association is easy now. It arrives whether you plan for it or not, and it is already embedded in Microsoft 365, in Salesforce, and probably in your AMS. Getting sustained value from it is different work, and most of that work has very little to do with AI. In our AI readiness work at 108 ideaspace, we assess what we call the Six Foundations of AI Readiness, all of which sit below the technology: strategy, data, process, governance, people and risk. Weaknesses in any of those areas do not disappear when AI is introduced. They become more visible and more consequential.
Why AI magnifies weaknesses you already have
Give a model clean, well-governed data, and it will help your team find information faster than ever. Give it messy data, and it will deliver the mess faster, and with more confidence.
Process behaves the same way. Apply AI to a well-designed workflow, and you create real capacity. Apply it to a workflow that exists only because of a system limitation from 2011, and you have simply made unnecessary work cheaper. That is worse than it sounds, because automation tends to make poor processes permanent. Nobody prioritizes removing a step that has stopped hurting.
The same holds true for governance, decision-making and organizational accountability. AI readiness has to begin below the technology.
The Six Foundations of AI Readiness
1. Strategy: What are we trying to achieve?
We do not see AI as a strategy. AI is an enabler, just like your CRM. Better member service is the objective. Greater capacity in a team of nine. Faster access to knowledge the organization already owns, improved decision-making, more relevant member experiences, reduced administrative burden.
So, the question is not where we can use AI. It is what we are trying to improve, and whether AI is the right way to improve it. Organizations that skip that step tend to accumulate a collection of interesting demonstrations that never become organizational capabilities: high effort, low return. Buying AI without that clarity is like buying gym equipment and expecting the fitness to come automatically.
2. Data: Can AI trust what the organization knows?
Mission-driven organizations hold enormous amounts of information: member records, engagement history, research, publications, learning activity, transactions, event participation, policy material and decades of committee knowledge sitting in shared drives. But holding information does not make it AI-ready.
You need to know where it lives, who owns it, whether it is accurate, how each field is defined in practice rather than in the data dictionary, who should be allowed to access it, and whether the use you have in mind is one your members would recognize as reasonable. Member information collected to administer a membership may not be usable for analysis or personalization without clear disclosure, and in some cases consent, even though the organization already holds it. And if two departments cannot agree on the member count today, AI will not resolve the argument. It will give each of them a more articulate version of their own answer.
Your AI strategy will eventually collide with your data strategy. Organizations that address that relationship early will have a considerable advantage.
3. Process: Are we automating the right work?
Automation is the most attractive promise on this list and the easiest one to misuse. Our rule has not changed since long before AI: do not buy software to fix a process problem. Before automating a process, ask whether it should exist in its current form. A useful sequence is to eliminate, then simplify, then standardize, and only then automate.
For example, consider a team that spends two days a month reconciling event registrations against member records. AI could perform that reconciliation faster. But that is not necessarily the right project, because the better question is why two systems need reconciling at all. Often the answer is a sync that has been failing quietly on a subset of records since somebody applied an update. AI readiness requires understanding how work actually gets done, not simply finding technology that does the same work faster.
4. Governance: What is AI allowed to do?
Many organizations now have an AI policy. That is a useful start. But a policy is not governance.
Governance is a set of decisions about acceptable use, privacy, intellectual property, information access, accountability, transparency, human review and vendor risk. And as these tools evolve from generating information to taking action, one question becomes more important than the rest: what is AI allowed to do? Can it draft a member communication, or send it? Recommend a record change, or make it? Trigger a workflow? Approve something? Flag a certification application, or decide on one?
The greater the consequence, the clearer the governance needs to be.
5. People: Are we preparing people or just giving them tools?
Providing access to an AI tool does not create AI capability. I often say you must train your AI employee just like your human employees. The humans working alongside it deserve the same investment. Staff need enough literacy to understand what these tools do well, where they can fail, how to evaluate outputs and when human judgment remains essential. They also need to understand how their roles and processes may change, which makes this a change management challenge as much as a technology one.
Some people will embrace AI immediately. Others will question its reliability, occasionally for very good reasons. And others will reasonably wonder what greater “efficiency” means for their role. That last group is not resisting technology. They are asking a fair question, and it deserves a direct answer from leadership, not an enthusiastic all-staff message.
6. Risk: What happens when AI gets it wrong?
Summarizing internal meeting notes and assessing whether someone meets a professional credentialing requirement are not the same activity, even when the same model performs both.
A practical question to put in front of every proposed use case is this: if AI gets this wrong, what happens? If the answer is that someone notices and corrects a sentence, lightweight oversight is appropriate. If the consequence touches a member’s finances, professional standing, privacy, eligibility, safety or regulatory status, then the requirements for human review, transparency, auditability and named accountability should increase accordingly.
AI readiness is not about eliminating risk. It is about understanding where risk exists and governing it deliberately.
Where to start: readiness, not a shopping list
None of this requires a transformation program before anyone can experiment. But it does require some discipline, in roughly this order.
Start by finding out what is already happening across the organization, and ask without consequences attached. You will almost certainly discover more experimentation than leadership realizes, some of it in tools nobody approved. Microsoft and LinkedIn’s 2024 Work Trend Index found that 78 percent of AI users were bringing their own AI tools to work. Then assess readiness across the six foundations and identify the gaps that would prevent AI from scaling safely. Then look for organizational problems worth solving (the real ones that surface in staff frustration and member feedback) and prioritize them by value, readiness, and risk rather than novelty.
A high-value opportunity with reliable data, a well-understood process and manageable risk is an excellent place to begin. An exciting use case built on questionable data, unclear accountability and a poorly understood process probably is not. Start deliberately. Establish the guardrails first, including which tools are approved. Measure what changes. Then expand from what worked.
The goal is not to become an AI organization
The pressure to do something with AI is understandable, but adoption is not the outcome. The organizations that ultimately gain the most from AI will not be the ones that adopted the most tools or launched the most pilots. They will be the ones that understand where AI creates value and have built the organizational capacity to use it responsibly. That means trusted data, better processes, clear governance, prepared people, appropriate controls, and a strategy that determines where technology belongs.
Which is largely a description of a well-run organization.
AI readiness: frequently asked questions
What is AI readiness?
AI readiness is an organization’s ability to adopt AI responsibly, at scale, and in a way that survives staff changes. It depends less on the tools than on six foundations underneath them: strategy, data, process, governance, people and risk.
What are the six foundations of AI readiness?
The Six Foundations of AI Readiness, as 108 ideaspace uses them, are strategy (what you are trying to improve), data (whether AI can trust what you know), process (whether you are automating the right work), governance (what AI is allowed to do), people (whether staff are prepared, not just equipped) and risk (what happens when AI gets it wrong).
Is an AI policy the same as AI governance?
No. A policy tells staff which tools they may use. Governance decides what AI may draft, send, change or approve, who reviews it, and who is accountable when it gets something wrong. The greater the consequence, the clearer the governance needs to be.
How much human oversight does an AI use case need?
Match oversight to consequence. A meeting summary needs light review. Anything that touches a member’s finances, professional standing, privacy, eligibility or regulatory status needs human review, auditability and a named owner.
Where should an association start with AI?
Start by finding out what staff are already using. Then assess the six foundations, choose a real problem with reliable data, a well-understood process and manageable risk, set guardrails, measure what changes, and expand from what worked.
How AI-ready is your organization?
In a 30-minute conversation, we will walk through the six foundations with you, show you where you stand, and identify the AI opportunities worth pursuing first.
CTA: Book a 30-minute AI readiness conversation →
Related: Your AI Strategy Should Start with Problems, Not Tools
About the author
Ashish Malik is Co-Founder and CEO of 108 ideaspace inc., a Toronto-based technology consultancy for associations, nonprofits, regulators and mission-driven organizations. He has worked with organizations in the sector for more than 15 years.









