CXO Ready
    CXO Ready guides

    Step-by-step videos for succeeding with CXO Ready

    These take you through the steps you need to succeed with CXO Ready.

    Guide 1

    Defining your business objectives

    Why are you doing the AI? Set the commercial and strategic context before you start.

    Guide 2

    Manage your AI Systems & Roadmap

    Turn AI ideas into a structured roadmap of initiatives, priorities, and delivery plans and then track the controls and governance.

    Guide 3

    Create & track AI-related policies

    Document governance policies and keep ownership, review dates, and policy status visible.

    Guide 4

    Assess the readiness of your team

    Measure organisational readiness, culture, skills, and change capability for AI adoption.

    Guide 5

    AI literacy training & communications

    Put training courses and communication campaigns in place for your organisation.

    Guide 6

    Assess EU AI Act and GDPR alignment

    Review your regulatory position and understand alignment with the EU AI Act and GDPR.

    Guide 7

    Follow governance and regulatory recommendations

    Use recommendations to improve AI governance and strengthen regulatory compliance.

    Before you start

    Questions about getting started

    What should our first AI governance policy cover?

    Less than most drafts attempt. What is permitted and what is not, what has to be recorded before an AI system goes live, who approves it, what data must never go into a third-party tool, and who to tell when something goes wrong. A policy people can hold in their head beats a comprehensive one nobody reads.

    How do we run a shadow AI discovery survey?

    Short, anonymous where possible, and framed as amnesty rather than audit. Ask what tools people use, what they use them for and what data goes in. The framing decides the result: people do not declare tools they expect to lose, so a survey that reads as a policy check finds far less than one that reads as an offer to sanction what works.

    What should we report to the board about AI?

    Four things, on one page: how many AI systems you run, how many carry material governance gaps, what is being done about the worst of them and by when, and what changed since last time. Boards do not need the register — they need to know somebody has one and is acting on it.

    How often should we review AI systems?

    Quarterly for anything high-risk or customer-facing, annually for the rest, and immediately when something material changes — a new data source, a vendor model update, or an incident. Point-in-time assessment fails for AI because the risk position moves without anyone shipping code.

    Where should we start with AI governance?

    With an inventory. Almost every organisation that feels behind on AI governance is actually behind on knowing what it runs, and every later step — classification, risk assessment, evidence — depends on that register existing. The guides follow that order deliberately.

    How long does an initial AI inventory take?

    Days rather than months for the systems you already know about, and longer for the ones you do not. The unknown portion is usually surfaced through team surveys, and how long that takes depends on how many parts of the business you need to reach.

    Who should lead this internally?

    Someone with the standing to ask every department what they are using — usually the CIO, CTO or a risk lead. The work itself distributes across system owners, but the initial sweep needs authority behind it, which is the most common reason a first attempt stalls.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy