CTO Toolkit
AI Engineering Readiness Checklist
Assess whether an organisation has the context, guardrails and verification needed for AI-assisted delivery.
How to use this
Score readiness before scaling AI tooling org-wide. If context and verification are weak, fix those first — otherwise AI amplifies thrash.
Context & standards
- Architecture principles and coding standards are discoverable
- Requirements / DoR quality is strong enough for humans and AI
- Domain glossaries and critical workflows are documented where they matter
- Someone has painted a picture of what good looks like for the systems teams touch
Guardrails & permissions
- Clear policy on what AI may access (code, tickets, customer data)
- Secret handling and prompt/data leakage risks are addressed
- Agent permissions are least-privilege by default
- Bypass paths exist but are controlled and auditable
Verification & learning
- TDD / automated verification can constrain AI-assisted changes
- Code review still owns judgement; AI does not replace accountability
- Security and quality checks run in the normal delivery path
- Outcomes feed back into rules, skills and playbooks
Operating model fit
- AI is framed inside CONTEXT → AIM → EXECUTE → VERIFY → LEARN
- Leaders measure value beyond “lines generated”
- Training covers judgement and workflow, not only tool tips
- A named owner exists for AI engineering enablement
This is an original, generic framework for reuse. It is not proprietary employer material.