AI Readiness Assessment for Small Business

A 60-person specialty manufacturer in Robinson Township called us after their ops director spent a weekend watching a competitor demo an AI quoting tool at a trade show. Monday morning, the CEO wanted to know two things: could they do the same thing, and were they about to leak proprietary CAD data into a public chatbot if they tried? Half the staff was already pasting customer specs into free ChatGPT accounts. Nobody had told them to stop, because nobody had a policy.
That conversation is the exact reason we built our AI readiness assessment for small business. It is not a sales pitch dressed up as a workshop, and it is not a 90-page report that dies in a SharePoint folder. It is a two-week engagement that answers the questions a Pittsburgh-area owner actually asks: where is AI already in my company, what is safe to turn on, what will it cost, and what breaks first if I get it wrong.
The challenge
The manufacturer had four real problems stacked on top of each other. First, shadow AI: employees using personal accounts to summarize RFPs, draft emails, and, in one case, transcribe customer calls. Second, a Microsoft 365 Business Premium tenant with permissions that had drifted for six years, meaning any Copilot rollout would surface HR files to the shop floor on day one. Third, a subset of contracts flowed through a prime that mentioned DFARS clauses, so CUI handling was in scope even though the client had never heard the term. Fourth, the CEO had a board meeting in eight weeks and needed a defensible answer to "what's our AI plan."
Turning on Copilot before you fix file permissions is the fastest way to email your salary spreadsheet to the entire company.
An off-the-shelf checklist was not going to cut it. Neither was a generic strategy deck. They needed a grounded look at their tenant, their data, and their contractual obligations, delivered by people who could then actually implement the fix.

How it was solved
We ran our standard AI readiness assessment for small business in three phases across roughly two weeks.
Phase one was discovery. Two of our engineers pulled a data-map of the Microsoft 365 tenant, ran Microsoft Purview against the top ten SharePoint sites, inventoried every SaaS app touching customer data, and interviewed nine employees across sales, engineering, and finance about what they were already doing with AI. We paired that with a review of their prime contracts to flag CMMC Level 2 exposure and DFARS 7012 language.
Phase two was scoring. We ranked twenty-three candidate use cases on a simple grid: business value, data sensitivity, implementation lift, and risk if it hallucinates. A customer-facing quoting bot scored poorly (high risk, CUI-adjacent). An internal RFP-summarization tool running on Azure OpenAI inside their tenant scored highly. A finance reconciliation workflow was flagged for our AI workflow automation team as a phase-two build.
Phase three was the roadmap. Not a wish list, a sequenced plan with dollar figures, an acceptable-use policy draft, a permissions-remediation project scoped against their existing managed IT agreement, and a go/no-go recommendation on Microsoft 365 Copilot licensing for Q2.
Outcomes
TL;DR: The deliverable is a prioritized, budgeted, risk-scored plan the owner can hand to a board, not a philosophy lecture on generative AI.
The board meeting went fine. More importantly, the client made three decisions in the next thirty days that they would not have made otherwise. They paused a planned Copilot purchase for the sales team until Purview labels were deployed, saving roughly $11,000 in licenses that would have been shelfware. They greenlit a small custom AI application for internal RFP triage, which our team built on their existing Azure tenant. And they published an acceptable-use policy that ended the shadow-AI problem in a week, because employees finally knew what was sanctioned.
The CMMC finding was the sleeper. Because we caught the DFARS language early, they entered their prime's flow-down conversation with a real remediation timeline instead of a panicked one. That is a very different position to negotiate from.

Takeaway
If you run a 20-to-300 person business anywhere from Cranberry to Monroeville to Washington, the pattern above is probably yours too. Employees are already using AI. Your file permissions were not designed for a tool that reads everything the user can read. Somewhere in your contract stack is a compliance clause (HIPAA, SOC 2, CMMC, PCI) that constrains what models you can use and where the data can live. And the pressure to "have an AI plan" is coming from a board, a customer, or a competitor, not from a considered internal strategy.
An AI readiness assessment for small business is how you get out in front of all four at once, in weeks rather than quarters, without committing to a platform you will regret. Our engagements are fixed-fee, tenant-specific, and delivered by the same vCIO and engineering team who will implement whatever you decide to move forward with. No handoff to a stranger.
Talk to us
If you are inside 75 miles of Pittsburgh and want a scoped AI readiness assessment for small business, call 724.888.7007 or reach us through the contact form. We will tell you on the first call whether an assessment is the right next step or whether you should fix something else first.
Related reading

AI Document Automation for Financial Services
Pittsburgh-based guidance on AI document automation for financial services: what to evaluate, where most providers fall short, and how to deploy it safely.

AI Automation for Law Firms in Pittsburgh
AI automation for law firms in Pittsburgh: intake, drafting, and document review workflows built with privilege, confidentiality, and PA Bar ethics in mind.

Customer Facing AI Chatbot for Accounting Firms
Pittsburgh-built customer facing AI chatbot for accounting firms: secure client intake, tax-season triage, and portal support with clear guardrails and audit trails.