How do we choose a firm to run an AI readiness assessment for a government contracting business?

Hire the firm that will tell you which of your AI ambitions your data cannot support yet. Require a written current-state finding rather than a maturity score, a prioritized use case list with the rejected ones named and explained, a control mapping to the frameworks your contracts already name, and a roadmap with a point at which you are allowed to stop. Then ask what the firm will not do.

An AI readiness assessment is the cheapest place in the whole program to find out that the answer is no. That only works if the firm running it is willing to say so, and a government contracting business has more ways to reach no than most: controlled unclassified information sitting in the same repositories as everything else, flow-down clauses that constrain where processing may happen, and a data estate that grew around contract boundaries rather than around analytics. The criteria below are written so you can check them from public sources or a first scoping conversation, without taking a vendor’s word for anything.

What the assessment actually has to determine

Four determinations, and a readiness assessment that skips any of them has not finished. First, data readiness measured against your real repositories rather than a questionnaire: where the content lives, how it is labeled, what the permissions actually are once inheritance is accounted for, and how much of it is duplicated. Second, the boundary question, which for a government contractor is a compliance question before it is a technology question: which data classes are in scope, which contract clauses govern them, and whether the processing may happen in a commercial environment at all. Third, platform fit, which is a narrower question than it sounds once the first two are answered. Fourth, use case prioritization, including the use cases the assessment rejects.

That fourth one is the tell. An assessment that returns a tidy list of approved opportunities and no rejected ones has been run as a pre-sales exercise. Prioritization is a ranking, and a ranking with nothing at the bottom is not a ranking.

The evaluation criteria, published before the shortlist

  • A written current-state finding, not a maturity score. A number on a five-point scale tells you nothing you can act on and cannot be argued with, which is precisely why it is popular. Ask for the finding: what is true about the estate today, stated in sentences, with the evidence beside it.
  • Data readiness assessed against your actual repositories. The firm should tell you how it will get access, what it will scan, and what it will do about the content it cannot see. A readiness assessment conducted entirely through interviews measures what your staff believe about the estate.
  • Shadow AI exposure named, with the method that found it. Staff are already using something. The useful deliverable is which tools, in which departments, touching which data, and how that was determined rather than assumed.
  • Rejected use cases, with reasons. Ask to see this section of a prior deliverable, redacted as needed. It is the single fastest way to tell an assessment practice from a proposal practice.
  • Control mapping to the frameworks your contracts already name. For most government contractors that means NIST SP 800-171 and DFARS 252.204-7012, with CMMC where the contract calls for it. The mapping should produce artifacts an assessor can review, not a slide asserting alignment.
  • The environment determination stated separately from platform preference. Where the data may be processed is a contractual finding. Which product you buy is a recommendation. A deliverable that fuses the two has hidden the reasoning you most need to audit.
  • A roadmap with sequencing, dependencies and a stop point. You should be able to complete phase one, read the result, and decline phase two without stranding the work.
  • Stated independence from the build. Ask directly whether the assessment fee is credited against implementation, who on the team is compensated on the follow-on, and what the firm has recommended against in the last year. There is no wrong answer here, only an undisclosed one.

Five questions that separate an assessment from a sales exercise

  1. What would make you tell us we are not ready, and when did you last tell a client that?
  2. How will you determine data readiness, and what happens to the repositories you cannot get access to during the engagement?
  3. Show us the rejected use cases from a comparable deliverable, redacted. What made you reject them?
  4. Which of our contract clauses would change your recommendation, and how do you plan to read them?
  5. What is explicitly out of scope, and what does the assessment deliberately not answer?

Compare the specificity of the answers rather than the confidence. The firm that can describe a program it talked a client out of is describing an assessment practice. The firm that cannot is describing a funnel.

What i3solutions offers here, and what it has not delivered

The offer is defined and published. i3solutions publishes an LLM Readiness and Strategy Assessment as a two to three week engagement whose deliverables are a current-state assessment of shadow AI exposure and data readiness, a use case analysis, a platform evaluation, a roadmap with recommendations, and an executive summary. The full scope, along with the governance framework and deployment engagements that can follow it, is set out on the LLM adoption consulting page. That is the offer this page is describing, and the methodology above is the one it runs.

Now the part most vendor pages leave out. i3solutions has no published case study of a delivered AI readiness assessment, and this page is not going to imply one. What exists in the published record is adjacent work, and it is worth being exact about what each piece measures.

On applied machine learning, i3solutions built an analytical platform for a US Department of Defense analytic center, described in the case study without naming the organization. Employing state-of-the-art data collection, feature extraction, and visualization solutions, i3solutions developed and trained over 20 machine learning models. Those models organize information drawn from very large volumes of open and private source material. That is model delivery inside a defense environment. It is not a readiness assessment, and the two require different evidence. The account is in the data analytics and data fusion case study.

On governance at federal scale, i3solutions runs a governed Power Platform for a federal defense agency supporting roughly 10,000 personnel across about 180 locations, which works because it is governed, not despite it. That is the discipline a readiness assessment is testing your organization for, applied to a platform rather than to AI. Again, labeled rather than blurred.

The firm-level facts are simpler. i3solutions is a Microsoft Solutions Partner. i3solutions has completed more than 600 Microsoft platform implementations. The delivery teams are senior and US-based. Those are platform facts, and they are the reason the data readiness half of an assessment tends to go quickly here: the repositories in question are usually SharePoint, Microsoft 365 and Dataverse, and the permission archaeology that makes data readiness hard is the same work as a migration assessment.

A firm-selection page that blurred what its own evidence measures would fail its own first criterion, which is why the labels are on it.

Where i3solutions is not the right fit

Honest disqualification is cheaper than a bad engagement. i3solutions is not the right vehicle when what you want is a scored maturity index for a board deck, when the assessment is expected to conclude that you should build, when your platform direction is away from Microsoft, when the requirement is lowest-price-technically-acceptable staffing, or when you want a committed implementation number quoted on an estate nobody has inventoried. We also do not certify AI compliance and cannot guarantee an assessment outcome, because no accredited scheme issues that determination and any firm implying otherwise is selling something that does not exist.

The fit is a government contractor that needs the boundary and data questions answered properly, in writing, before committing to a build, and that wants the answer to be usable whether it turns out to be yes or no.

How to run the selection

Shortlist two or three firms and ask each for the same four artifacts: a redacted assessment deliverable from a comparable engagement, the rejected use case section from inside it, a control mapping artifact, and the scope language showing what the assessment does not answer. Then weight the answers by who asked the most uncomfortable questions about your data before quoting. Scope and price the assessment before you commit to any implementation, and keep the two decisions separate on paper, because the assessment loses most of its value the moment its conclusion is already spoken for.

If you are earlier than that, the background reading is already written down. The comparison of do-it-yourself AI integration against architect-led governance covers the failure mode most readiness assessments end up documenting, secure Copilot enablement versus turning it on covers the same question for Microsoft 365, and IT systems analysis services describes the assessment discipline applied to the wider estate. When you are ready to test fit, i3solutions routes a senior U.S.-based engineer to a client call usually within one to two weeks, and you can reach the team by phone at 703.652.8966.

Frequently asked questions

What should an AI readiness assessment for a government contractor actually produce?

A written current-state finding rather than a maturity score, covering data readiness measured against your real repositories, shadow AI exposure with the method that found it, the contractual boundary determining where processing may happen, a prioritized use case list that names the rejected candidates and why, a control mapping to the frameworks your contracts already cite, and a roadmap with sequencing and a defined stop point. If the deliverable cannot be handed to a compliance lead and an engineering lead and be useful to both, it was scoped as a sales artifact.

Has i3solutions delivered an AI readiness assessment we can read about?

No. i3solutions has no published case study of a delivered AI readiness assessment and does not claim one. The readiness assessment is a defined and published offer with named deliverables, and the adjacent published record is model delivery for a US Department of Defense analytic center, where i3solutions developed and trained over 20 machine learning models, and platform governance for a federal defense agency supporting roughly 10,000 personnel across about 180 locations. Those are different engagements measuring different things, and this page labels them rather than presenting them as assessment proof.

How long does an AI readiness assessment take?

i3solutions publishes its LLM Readiness and Strategy Assessment as a two to three week engagement, producing a current-state assessment of shadow AI exposure and data readiness, a use case analysis, a platform evaluation, a roadmap with recommendations, and an executive summary. Where an engagement lands inside that window is driven by how many repositories are in scope and how quickly access is granted, which is the practical reason access arrangements belong in the kickoff rather than in week two.

Will an assessment tell us whether we can use AI with controlled unclassified information?

It should tell you what your contracts require and what your current environment permits, which is the part most organizations are missing. It cannot tell you that you are compliant, because compliance determinations for controlled unclassified information rest on your system boundary, your contract clauses and, where CMMC applies, an accredited assessor reviewing your environment and evidence. A readiness assessment produces the finding and the artifacts. It does not produce the determination.

How is an AI readiness assessment different from a Copilot readiness engagement?

A Copilot readiness engagement is scoped to one product and asks whether your Microsoft 365 estate is safe to switch it on, which is largely a permissions, labeling and oversharing question. An AI readiness assessment is product-agnostic and asks a wider question first: which data may be used at all, which use cases are worth doing, and what has to be true before any platform decision is made. Contractors frequently need the narrower one, and an assessment worth its fee will say so instead of selling the larger engagement.