An AI audit for your business: what it covers, how long it takes, what you get

An "AI audit" means three different things. This is the one an implementation starts with: what we check, how long it takes, and what document you get.

“AI audit” is now the name of three different services, and anyone selling you one of them without saying which is mainly selling you the ambiguity. The first is a readiness audit or process audit: which process to automate first, and whether to automate at all. The second is a compliance audit against the EU AI Act: what the law requires of you and how to show it. The third is an AI visibility audit: whether ChatGPT or Gemini mention your brand — work that sits on the edge of SEO. Search results add articles about AI in financial auditing on top of that, and this is a fourth, entirely different thing.

This piece is about the first of them — the audit as the opening phase of any AI implementation in a company — seen from the buyer’s side: what gets checked, what it asks of your team, how long it takes, what document you receive, what drives the cost, and when it is money wasted. Where we compare ourselves with the market, we go on what Polish consultancies publish about their own audits (checked on 6 September 2026).

What an AI audit is — and what it is not

The AI audit meant here — also called a process audit for AI, or an artificial intelligence audit — is a short review with a scope fixed in advance: how work is done today in one department or one group of processes. It ends with a ranked list of candidate processes, one picked to start with and the reasoning for it, and measurable success criteria agreed before anything is built. It contains no choice of tool — that is the last decision in a project, and the audit exists to make the first ones.

It is not AI Act compliance work

AI Act work answers a different question: which AI systems you already run, which duties your lawyer assigns to your role, and what has to be implemented so compliance can be demonstrated. We describe that separately, on the page about the AI Act technical compliance sprint. One can reveal the need for the other, but they are not the same deliverable, and neither is a legal opinion: classifying systems and interpreting the regulation belong to your lawyer, we do the engineering part.

It is not an AI visibility audit

An AI visibility audit checks whether ChatGPT or Gemini mention your brand. That is SEO work, which we do not do, and the word “AI” in its name refers to where your brand appears, not to how your company works.

It is not an AI strategy

A strategy written before the first implementation rests on assumptions nobody has tested yet. An audit that runs for two months and ends in a presentation about directions is usually a strategy under another name. Our phase one is deliberately short, because it should produce a decision, not a vision: a pilot of a specific process, or a reasoned “not now”.

What an AI audit covers: three things we check

An AI readiness audit — another name for the same thing — looks at three layers: processes, data and systems. Each of them can stop a project on its own.

Processes

The basis is interviews with the people who do the work, not only with management. A manager knows how the process is supposed to look; the person doing it knows how it actually looks and where they patch it with a spreadsheet. The interviews follow a fixed structure, so you know in advance what your team will be asked:

  1. Which tasks take the most time in a week, and how many times a month do they repeat?
  2. Where does the input come from — email, PDF, a system, a phone call — and where does the output have to go?
  3. Who decides the borderline cases, and by what rule?
  4. What does an error in this process look like, who notices it, and how long after?
  5. Can you export the last hundred cases of this process today, as a single table?
  6. Is there personal data in it, and if so — whose, and who is the controller?
  7. Is there an off-the-shelf tool that already does this, and why are you not using it?
  8. What AI tools is the team using today off its own bat?

The last question is often the most instructive: tools a team brought in by itself show where people have already diagnosed the problem.

Data

There is one test, and it comes from the piece on how to implement AI in a company: export the last hundred cases of the process as a single table. Not a description of how it could be done — an attempt to do it. Someone from your company makes the attempt, and we assess the result: the format, whether the fields are complete, and whether the rule behind past decisions can be read out of the history. If a hundred cases have a hundred layouts, you have just seen the first stage of any project that follows. If the sample contains personal data, it is minimised before it goes anywhere outside your company — we set out how we handle that on the page about data security and GDPR.

Systems

The third layer is an inventory of the systems the input comes from and the systems the output has to reach. One property of each interests us — whether it has an API or a file import. If it does, integration is a question of scope, not of possibility; if it does not, the scope grows by a workaround somebody will have to maintain. So when we cost the future work, we count integrations, not features.

How we score processes: the scorecard

The implementation page promises a list of candidates “ranked by impact against cost”. This is what the phase-one scorecard looks like. Every process from the interviews gets five criteria on a 0–2 scale — frequency, stability of the rules, availability of data, how detectable and reversible errors are, and ownership — plus an estimate of the impact: hours per month, that is the number of runs times the minutes each one takes.

Several rules can be read straight off the card without adding anything up. A zero on data means “data first, not AI”. A zero on rules or on ownership means an organisational task: as long as two people do the same thing differently and both are right, the technology will entrench the disagreement. An impact below a few hours a month means the fixed cost of the model, the integration and the monitoring has nothing to pay itself back from; we put it as “if a process takes two hours a month, it is almost certainly not worth it”, and we have collected every condition under which we advise against a project on the page what we don’t do.

Illustrative example, not a description of a client. The figures show the structure, not the market. A fictional B2B distributor, forty people, interviews in three departments:

Process Impact (hrs/month) Systems Frequency Data Rules Error Owner Score Recommendation
Keying orders from email into the ERP by hand 600 × 6 min = 60 email → ERP (API) 2 2 1 2 2 9/10 pilot this one first
Preparing quotes for enquiries 80 × 25 min = 33 email, spreadsheet, CRM 2 1 0 1 2 6/10 write down the pricing rules first
Predicting delivery delays no history 0 ruled out we don’t sell prediction without historical data
Monthly report for the board 1 × 120 min = 2 ERP, spreadsheet 0 2 2 2 2 8/10 too infrequent; the fixed cost won’t pay back

Process one wins not because it scores highest, but because sixty hours a month has something to cover the fixed running cost from, and an error comes to light the same day in the warehouse. Process four has an almost equally good card and is still ruled out: two hours once a month will never pay back an integration. Process two comes back once the sales team writes down its pricing rules. Process three is out for a different reason: prediction without history is a data-collection project sold as prediction, and we don’t run those.

For the process chosen, before the pilot starts, a success criterion is written in one sentence — in the example: “Today an order from an email reaches the ERP after four hours on average; after implementation, after 30 minutes, with an error rate no higher than today’s 2%.” Plus one stipulation that is not scored: “every implementation starts in a mode where the system prepares and a person approves.” In the example: the system creates the order in the ERP as a draft and someone in order handling approves it — from day one; loosening that oversight is a decision made on data from the pilot.

What you get after an AI audit

The three outputs of phase one are published in our implementation methodology and read exactly like this: “A list of candidate processes with time and cost estimates, one process picked to start with and the reasoning for it, and measurable success criteria agreed before anything is built.” The audit ends in a document and a decision, not a presentation.

The document has a fixed structure — a template below, not any client’s report:

  • Page one: the decision and the criteria. One of two sentences — “pilot process X” or “not worth it now, because…” — and the success criteria the pilot will be judged against.
  • Scorecards for every process reviewed, including the rejected ones, with the reason.
  • The chosen process with the reasoning and an outline scope for the pilot: what is in, what stays out, and which question it has to settle.
  • A list of things to prepare before the pilot: access, the data export, the person who will approve the output.
  • Regulatory signals to pass to your lawyer — wherever the process involves personal data, or a tool whose use may fall under the AI Act. This points at what to check; it is not a legal assessment, and we do not give legal advice.
  • A list of what we advised against, and why.

A negative recommendation is an expected outcome of the audit, not its failure — the project can end after phase one, and it is designed that way. And if it turns out an off-the-shelf tool does the same job on a subscription, we will write that too, even when it means no engagement for us.

How long an AI audit takes — and why longer is not better

One to two weeks for a single department or group of processes — that is the figure from the methodology. Illustratively: the first week is interviews and the attempt at the data export, the second is the scorecards, the document, and a meeting where we go through the decision.

For comparison, Polish consultancies publish audit durations from “2–5 working days” through “2–4 weeks” to “a few weeks to several months” for a whole organisation, and one of them gives “1–2 weeks” in the introduction and “2–4 weeks” in the Q&A on the same page (checked on 6 September 2026). It is hard to read out of statements like that what a week actually buys.

An audit that runs for two months is a strategy, and a strategy written before the first pilot is guesswork on paper. The whole first project — audit, pilot (two to four weeks) and production rollout (four to twelve) — usually takes two to four months; an eight-week audit would eat the time in which the pilot could already have produced hard numbers. And what stretches the schedule is not engineering work but access to data and decisions on the client side.

How many hours it costs your people

We found this line item in none of the offers we read, and it is the one that decides whether an audit establishes anything at all. The methodology lists what we need from you: one person who knows the process and can decide about changes to it; access to real data, not a demo sample; a contact on the IT side for access questions; and agreement that the answer may be negative.

Illustratively, for the distributor above: six interviews of about an hour with people from three departments, two hours for the data export, an hour of IT time for access and questions about systems, an hour of the decision-maker’s time to discuss the outcome and as much again to read the document. A dozen or so hours in total across two weeks, spread over four to six people. Those hours have to exist.

An audit usually fails not on method but on the calendar: nobody had those hours, so the interviews happened with the manager instead of the person doing the work, and a description of how the export could be done replaced the export. What comes out is a document about processes nobody described — and a decision based on guesswork.

How much an AI audit costs

We will not give a range here, because the cost depends on four things we do not know before talking to you: how many departments and processes there are to review, how many systems data has to be pulled from, whether working on a sample of data is in scope or only interviews, and whether personal data in that sample needs extra handling. We quote after a free consultation. This is the cheapest and most tightly scoped stage of the whole project precisely because it has an ending built into it: it can end with the conclusion that the work is not worth doing.

For the record, as at 6 September 2026: most Polish firms publish an “individual quotation” against an audit. The only public figure we found is one price list published on 18 February 2026 with a line reading “4,000–6,000 zloty excluding VAT” for a process audit — with no description of what is produced for it, so there is nothing to compare it against.

Before you commission an audit, do the free version of it: the five self-assessment steps from the piece on how much an AI implementation costs. If you arrive with a named process, a measured number and a successful export of a hundred cases, the audit gets shorter and cheaper, because what is left is the part you cannot do yourself: comparing several processes and making the decision.

When an AI audit is not worth it

Eight situations in which an audit is money wasted:

  • You already have the process, the number and the exported data. The audit would shrink to confirming the criteria — go straight to the pilot scope.
  • You want a document for the board, not a decision. That is a strategy — we advise writing it after the first pilot, on real numbers.
  • You need a legal classification. Lawyer first; technical preparation for AI Act requirements is the second audit from the top of this piece.
  • It is about brand visibility in ChatGPT. Different service, different suppliers.
  • Nobody has a dozen or so hours for us. The audit will document guesswork.
  • The process runs a few times a month. The fixed cost of any integration has nothing to pay itself back from.
  • An off-the-shelf tool exists. The audit can end with the sentence “buy the subscription” — we will say it even when it costs us the engagement — but if you already know that, you do not need us.
  • The company is small enough that the process fits in one head. The five free self-assessment steps are enough; an audit is for setting several processes from several departments side by side.

How to prepare for an AI audit

Six things you can do before the first interview; each one shortens the audit and improves the decision at the end:

  1. Name one decision-maker for each process you want reviewed — someone who can say how the process should look, not only how it looks.
  2. Write down the systems the data comes from and the systems the output has to reach, together with who administers them.
  3. Try exporting the last hundred cases of one process yourself, as a single table. Whatever stops you is more valuable information than the file.
  4. Measure one number for two weeks — the one that has to change: handling time, rework rate, delay.
  5. List the AI tools your team already uses off its own bat — no judgement, just the list.
  6. Agree internally that “not worth it” is an acceptable result. Without that, the audit becomes a formality in front of a decision already made.

What next

The audit is the first of four phases of an AI implementation in a company — the pilot, the production rollout and the handover follow, and you can stop after any of them. Describe one process to us: what repeats in it, where the data comes from, and who is responsible for it. We will tell you whether an audit makes sense for you — including when the answer is “not worth it yet”.

Frequently asked questions

What does an AI audit in a company cover?

The AI audit described here is a review of how work is done today in one department or one group of processes: interviews with the people who do that work, a check on whether the data behind those processes can actually be exported and processed, and an inventory of the systems the information comes from and the systems the output has to reach. It ends with a list of candidate processes with time and cost estimates, one process picked to start with and the reasoning for it, and measurable success criteria agreed before anything is built. It is not an EU AI Act compliance audit, and it is not an audit of how visible your brand is inside AI tools — those are three different services sold under one name.

How long does an AI audit take?

With us, one to two weeks for a single department or group of processes: the first week is interviews and the data export, the second is scoring the processes, writing the document and talking the results through. Polish consultancies publish durations from a few working days to several months (checked on 6 September 2026), though an audit that runs for two months is usually a strategy document under another name. The short timeframe is deliberate: an audit should produce a decision about a pilot, not a vision. What actually stretches the schedule is access to data and decisions on the client side, not engineering work.

How much does an AI audit cost?

We do not publish a price list for the audit, because its cost depends on how many departments and processes there are to review, how many systems data has to be pulled from, and whether a sample of real data is in scope or only interviews. We quote after a free consultation. It is the cheapest and most tightly scoped stage of the whole project, because it has an ending built into it: it can end with the conclusion that the work is not worth doing. For the record: most Polish firms publish an "individual quotation", and the only public figure we found (checked on 6 September 2026) is one agency range of a few thousand zloty excluding VAT, with no description of what is produced for it.

How is an AI audit different from an AI Act audit?

The AI audit described here answers which process is worth automating first, and whether any of them is — it looks at time, data, systems and who owns the process. An AI Act technical compliance sprint answers which AI systems the company already uses, which duties your lawyer has assigned to your role, and what has to be implemented so that compliance can be demonstrated. The first ends in a decision about a pilot; the second in a register of systems and implemented, documented controls. One can reveal the need for the other, but they are not the same document, and neither replaces a lawyer.

When is an AI audit not worth it?

When you already have the process picked, the number you want to move measured, and a successful export of the last hundred cases — then the audit shrinks to confirming the criteria and you are better off going straight to the pilot scope. When you want a strategy document for the board, a legal classification of a system, or brand visibility in ChatGPT — those are different services. And when nobody in the company has a dozen or so hours to give over two weeks: an audit without time from the people who do the work describes guesswork, not processes.