Digital maturity and artificial intelligence
Is your organization ready to adopt artificial intelligence?
An assessment that answers that question with evidence, before you invest in tools, vendors or pilots.
The problem
The causes can be seen before you start
AI projects that do not succeed usually fail for reasons that can be seen before they start. A RAND study of failed projects found that the main causes include poorly defined problems, a lack of suitable data and infrastructure that is not ready.1 And in a Gartner survey, 63% of organizations said they did not have, or did not know if they had, the right data management practices for AI.2
In daily operations, it looks like this: incomplete data, systems that do not connect, processes that live in side spreadsheets, or a leadership team that makes decisions about an operation that is not the real one.
Free self-assessments are not enough: one person answers them, they measure perception and they end in a score that does not say what to do.
1. RAND Corporation, “The Root Causes of Failure for Artificial Intelligence Projects and How They Can Succeed” (2024). Qualitative study based on interviews with experts.
2. Gartner, “Lack of AI-Ready Data Puts AI Projects at Risk”, press release of February 26, 2025. Survey of data management leaders, 2024.
Why measure before you invest
Less risk in the investment
Avoid paying for pilots that cannot scale
If the data or the integration is not there, the assessment shows it before you hire tools or vendors.
Put the technology budget in order
It shows which investment enables the others and which one does not make sense yet, so you do not pay twice for the same thing.
Gives you a solid case for the board
Each recommendation comes with the evidence behind it and the assumptions it depends on.
How it works
Four steps, with evidence
Three profiles answer, separately
Management (including finance), IT and operations answer an online questionnaire, with questions designed for each role. It takes about 15 minutes per person.
We ask for evidence, not opinion
Key questions ask for a fact that can be checked: a number, a system field, a document. The evidence is reviewed with the people in charge before the report is closed. Without evidence, no dimension can go above level 3.
The gap between profiles is a finding
When management and operations see the organization differently, the report shows it, because that is where the risks of any implementation usually are.
Report presented to management
A document made to take to the board, and a session to present it.
What we measure
Six dimensions
| Dimension | Question it answers | Main reference |
|---|---|---|
| Strategy and governance | Is there a clear direction, with an owner, a budget and goals? | NIST AI RMF (govern) · ISO/IEC 42001 |
| Data | Does the data exist, is it accessible, is its quality measured and does it have an owner? | DAMA-DMBOK · ISO/IEC 42001 |
| Technology and infrastructure | Can the technology base take on something new, or is every change major surgery? | NIST AI RMF (map) |
| Processes and automation | How digital is the real operation, and where is data lost? | Process maturity models |
| People and culture | Does the team know how, have the means and want to adopt change? | ISO/IEC 42001 (competence and awareness) |
| Risk, ethics and compliance | Does the organization know which AI it uses, who is responsible for it, what happens if it fails and which rules apply? | NIST AI RMF (measure, manage) · ISO/IEC 42001 |
Each dimension is placed on a five-level scale: Non-existent, Basic, Developing, Formalized and Embedded.
No averages. The result shows which dimension holds back the others. An organization with good technology and data without an owner is not halfway there: it is held back by its data.
What it is based on
Recognized frameworks, stated precisely
To be precise. NIST AI RMF and ISO/IEC 42001 are not maturity models. The assessment measures the practices these frameworks call for, on our own scale, and the full rubric is delivered with the report. The result is shown as a current profile and a target profile, the way NIST suggests for gap analysis.
Scope of the assessment. The Miralles Consultores assessment is an external evaluation, based on the information and evidence the organization provides. It uses the NIST AI Risk Management Framework 1.0, the ISO/IEC 42001:2023 standard and the DAMA-DMBOK body of knowledge as references, and measures the practices these frameworks describe on its own scale. It is not a certification, it is not a conformity audit against any standard, and it is not endorsed by NIST, ISO, IEC or DAMA International. Miralles Consultores is not a certification body. The assessment is not legal advice.
Why this assessment
Three commitments
We say what we find
If the assessment shows that an organization is not ready to adopt artificial intelligence, the report says so and explains what needs to be fixed first. We do not invent use cases to justify a sale.
A documented method, not a black box
Each level has a rubric. The summary is published in “How we measure”, and the full version is delivered with the report. The result can be traced back, and it is not averaged: it shows which dimension holds back the rest.
We do not resell software
We do not resell software or take commissions from vendors. The assessment does not commit you to hire any later stage.
What the organization receives
A report to make decisions
Across the six dimensions, on the assessment scale, traceable to the frameworks.
Which one holds back the others, and why.
Between management, IT and operations.
Which personal data and artificial intelligence laws the organization should review with its legal advisor, based on the countries where it operates.
By impact and feasibility, each one with the requirements to meet first.
What to do first, what comes next and what should wait.
To measure again later.
Industries
A common core and a module for each industry
The assessment has a core that is common to all industries and a module for each industry, with questions and examples designed for how work is done, and where data is lost, in each one. The industry modules are built as we work with organizations in each industry.
Construction
Job sites that create data every day in systems that do not talk to each other: progress, costs, subcontracts, equipment.
Real estate development
From land to after-sales service, with information spread across sales, projects and finance.
Engineering
Hours, deliverables and scope changes that must match what is billed.
Mining
Highly instrumented operations, where the challenge is usually to connect plant, maintenance and management data.
Oil & gas
Critical assets, contractors and safety and environmental requirements that make data and AI governance a must.
Public sector
Government agencies and state-owned companies, where the first concerns are the traceability of decisions, interoperability between agencies and the use of automated systems in decisions that affect people. The three profiles are adapted: leadership, IT and the business area.
For mid-sized and large organizations in Latin America, with a clear IT lead and an operation that creates data every day.
Frequently asked questions
What people usually ask
What if the result is that we are not ready?
The report says so, with evidence, and explains what needs to be fixed first. It is one of the most valuable results of the assessment: it keeps you from investing in an initiative that cannot work yet.
Are the answers confidential?
The organization does not receive individual answers. Results are shown grouped by profile. If only one person answers for a profile (for example, a single IT lead), that person is told before starting, because the result for that profile reflects their own answers. By area, results are shown only when there are three answers or more.
While the questionnaire is open, only the consultant can see individual answers. After that, names and email addresses are deleted, and answers remain linked only to a profile, an area and a random code. When a profile or an area has very few people, someone who knows the organization could guess who answered: that is why the limits above apply, and those answers are protected as personal data.
How long does it take?
About 15 minutes per person for the questionnaire, plus a session to present the report.
Do you compare us with other organizations in our industry?
Not yet. The comparison is against the assessment scale, and we say so. The industry comparison is built as more assessments are completed.
Do you certify ISO/IEC 42001?
No. The assessment shows how far the organization is from the practices the standard calls for. Certification is granted by an accredited certification body which, to stay impartial, cannot be the same party that advises. The assessment is not legal advice either.
What comes after the assessment?
If the organization wants to move forward, the report becomes a work plan: data clean-up, systems integration, AI governance or pilots.
Want to know where your organization stands?
Request a conversationReferences available during the conversation.