AI Readiness Starts with Information Readiness: A Practical Framework for Jamaican Organisations
- 14 hours ago
- 4 min read
Artificial intelligence can analyse, classify and generate information at remarkable speed. It cannot correct an organisation’s information environment by assumption.
If source information is incomplete, duplicated, outdated, poorly classified or accessible to the wrong people, an AI initiative may reproduce those weaknesses at greater speed and scale. The technology may be capable, while the information it depends on remains unsuitable for the intended use.
For Jamaican organisations, AI readiness should therefore include a disciplined review of information readiness.
Information readiness is not a certification and it does not guarantee a successful AI outcome. It is a management condition: the organisation knows what information it has, what it means, who is responsible for it, whether it is fit for the intended purpose and which controls apply.
Five dimensions of information readiness
1. Information is known and owned
An organisation cannot govern information it has not identified.
Important content may be spread across paper files, shared drives, email, cloud applications, employee devices and legacy systems. Before connecting an AI tool to these sources, the organisation should know which repositories are authoritative, which contain duplicates and who makes decisions about each information set.
Useful questions include:
Which information supports critical decisions or services?
Who owns its accuracy, access and lifecycle?
Which repository contains the complete and current version?
What information should not be used for the proposed AI purpose?
2. Information has sufficient quality and context
AI systems need more than accessible files. They need information that can be interpreted in context.
A document title such as Final_v3_new.pdf provides little useful meaning. Metadata can explain the document type, subject, date, owner, status, business process and retention category. Classification and metadata help people and systems distinguish between a draft, an approved record and an obsolete copy.
Quality requirements should be defined for the use case. Information used to summarise internal knowledge may need different validation from information used to make a high-impact operational decision.
3. Access is controlled
Information should be available to authorised users and protected from inappropriate access.
Connecting an AI service to a repository without reviewing permissions can expose sensitive information or make it available beyond its intended purpose. Access design should consider business roles, confidentiality, personal data, contractual restrictions and the minimum information required.
This is also where privacy obligations matter. Jamaica’s Office of the Information Commissioner describes data-protection standards that include fairness and lawfulness, purpose limitation, data minimisation, accuracy, retention and security. Organisations should obtain appropriate legal or privacy advice for their circumstances.
4. Lifecycle rules are operating
Keeping everything indefinitely is not information readiness.
Organisations need rules for retention, legal or operational holds, archival and authorised disposal. These rules should work in practice, not remain only in a policy document.
An AI system should not be trained, prompted or connected to records that the organisation should no longer hold or use. Conversely, important records should not disappear because ownership and retention decisions were unclear.
5. Use, risk and accountability are defined
AI readiness is not simply an IT decision.
The organisation should define the intended use, expected benefit, affected users, risk owner, human review, acceptable error and stop condition. NIST’s voluntary AI Risk Management Framework provides a useful structure for managing risks associated with the design, development, deployment and use of AI systems.
The important question is not only whether the AI tool works. It is whether the organisation can explain and govern how information is selected, used, reviewed and protected.
A practical 30-day starting point
An organisation does not need to resolve every historical information problem before testing AI. It should, however, create a controlled boundary.
Week 1: define the use case
State the decision, task or service the AI initiative is intended to support. Name the business owner, users, expected output and unacceptable outcomes.
Week 2: identify the source information
Inventory the repositories and information types required for the use case. Identify authoritative sources, duplicates, gaps and restricted content.
Week 3: test quality and controls
Sample the information for completeness, accuracy, metadata, permissions, retention and privacy issues. Define acceptance criteria for the pilot.
Week 4: run a controlled assessment
Test the use case with a limited information set, human review and documented findings. Record what worked, what failed and what must change before expansion.
The management decision
AI can create value when it is introduced with a clear purpose and a governed information foundation. Without that foundation, the organisation may spend time correcting avoidable errors, investigating permissions and rebuilding trust in the output.
The starting point is not a new tool. It is a clear view of the information the organisation expects that tool to use.
Start an information-readiness conversation
ScanBox can facilitate a 30-minute Information Readiness Conversation to help identify the first questions your organisation should answer. This is a diagnostic conversation, not a certification, legal opinion or guarantee of AI outcomes.
