PTENES
TRACK 3

🛡️ Audit: readiness, data, and risk

Before promising AI, audit. Measuring the organization’s actual readiness — data, technology, people, processes, and governance — is what separates a consultant who delivers from one who sells smoke. Sometimes the honest recommendation is: “fix the data first.”

Data Technology People Processes Governance 3 4 5 Current profile Target (5/5) AI Readiness Assessment 5 dimensions · 0–5
4
Modules
24
Topics
~3h
Duration
Audit
Level

Learning path map

Detailed content

3.1~45 min

📋 AI Readiness Assessment: Dimensions of Readiness

Measure the organization's actual readiness across 5 dimensions before recommending any implementation. The radar reveals where the gaps are—and which one to address first.

What it is:

A structured assessment of an organization’s capacity to adopt and operate AI effectively. It’s not an enthusiasm test—it’s a diagnosis of infrastructure, data, people, processes, and governance.

Why learn:

Without it, you prescribe AI for soil that isn’t ready. The project fails, and the technology gets the blame—when the problem was readiness.

Key concepts:

Readiness ≠ enthusiasm; 5 measurable dimensions; radar chart as a conversation tool.

What it is:

The most critical dimension. It assesses whether the data exists, whether it is high quality (complete, consistent, up to date, unbiased), whether it is accessible, and whether it complies with privacy requirements and LGPD.

Why learn:

AI models are only as good as the input data. Bad data, bad AI — no matter which model you choose.

Key concepts:

GIGO (garbage in, garbage out); completeness, consistency, currency; LGPD as a requirement.

What it is:

Assesses whether the infrastructure supports AI: available APIs, processing capacity, integration between systems, and whether the current stack can connect data to models.

Why learn:

A good AI idea can be blocked by legacy systems without an API or by siloed databases that no one can connect.

Key concepts:

Current stack; APIs and integrations; legacy systems as a risk; cloud vs. on-premise.

What it is:

Assesses the team’s AI literacy, cultural openness to change, and whether there are internal leaders able to sustain adoption after the consultant leaves.

Why learn:

The best technical solution fails if the team doesn’t adopt it. A culture resistant to AI is as real a constraint as a lack of data.

Key concepts:

AI literacy; internal champions; resistance to change; change management.

What it is:

Processes: are workflows documented and ready to integrate AI? Governance: are there AI use policies, designated owners, and the ability to monitor risks?

Why learn:

Without a documented process, AI enters chaos and amplifies it. Without governance, the organization operates in the hope that nothing goes wrong.

Key concepts:

Process as a prerequisite; responsible AI use policy; person responsible for AI (CAIO).

What it is:

Each dimension gets a score from 0 to 5. The visual radar makes the gaps obvious to the client—and shows where to focus before any implementation.

Why learn:

The radar shifts the conversation from “let’s implement AI” to “see where you are today — and what we need to address first.”

Key concepts:

Score by dimension; radar chart as an alignment artifact; priority gap = highest return.

View Full
3.2~40 min

📶 AI maturity models

Stages from ad hoc to transformational—used as a mirror to calibrate expectations, not as a trophy to win. Knowing where the organization stands is a prerequisite for any honest roadmap.

What it is:

Frameworks that describe progressive stages of organizational AI capability—from no structure (ad hoc) to AI integrated as a competitive advantage (transformational).

Why learn:

They let you position the organization without judgment and communicate the next step concretely, instead of using abstractions about "digital maturity".

Key concepts:

Current stage ≠ failure; next level = achievable goal; model as shared vocabulary.

What it is:

Ad hoc: isolated experiments, no vision, no structured data. Aware: leadership recognizes the importance of AI, but there’s still no dedicated strategy or budget.

Why learn:

Most Brazilian SMBs are here. Recognizing this stage helps avoid prescribing level 4 roadmaps to level 1 organizations—a sure recipe for failure.

Key concepts:

Isolated pilots; no historical data; curious leadership without commitment.

What it is:

The organization has AI projects running, structured data, a dedicated or contracted technical team, and measurable results from its first use cases.

Why learn:

It’s where the consultant can make the biggest immediate impact—expanding what already works to other processes and building governance before it scales.

Key concepts:

First wins documented; expansion by priority; foundation for scaling with control.

What it is:

Operational: AI integrated into multiple processes, with MLOps, continuous monitoring, and KPIs. Transformational: AI as a central competitive advantage, enabling new business models.

Why learn:

These are the stages that require a specialized internal team and formal governance—the external consultant contributes but can’t be the sole support.

Key concepts:

MLOps; AI KPIs; new business model; self-sustainability after the consultant.

What it is:

The temptation to jump from level 1 to level 4 out of enthusiasm — or under pressure from leadership that wants “transformational AI” without building the foundation. Projects that skip stages almost always get stuck.

Why learn:

A consultant who enables the leap shares responsibility for the failure. The honest recommendation is to sequence, not rush.

Key concepts:

Stages aren’t optional; a weak foundation collapses; sustainable speed > maximum speed.

What it is:

The maturity model feeds directly into the roadmap: the next step is to advance one level, not three. Each recommendation is anchored in the organization’s current stage.

Why learn:

Connects the diagnosis to the prescription — gives the client a clear and realistic path instead of a vision of "where we'd like to be".

Key concepts:

Next level as a goal; sequenced roadmap; measurable advancement criteria.

View Full
3.3~45 min

🗄️ Data and infrastructure audit

Inventory, qualify, and assess the organization's data before any implementation. "Bad data, bad AI"—and a consultant who doesn't audit the data before making recommendations is selling an illusion.

What it is:

Map all of the organization's data repositories: databases, spreadsheets, ERP systems, CRM, unstructured files, emails, and documents. Without an inventory, you don't know what you're working with.

Why learn:

Companies often underestimate their data—and discover during the inventory that they have more (or less) than they thought. The inventory defines the project’s actual scope.

Key concepts:

Structured vs. unstructured data; data catalog; data silos; shadow IT.

What it is:

Completeness (filled-in fields), consistency (same format and standard), currency (data is not outdated), and bias (underrepresentation of groups that skews results). The 4 dimensions that determine whether data is "trainable".

Why learn:

A model trained on biased data reproduces and amplifies that bias. Out-of-date data produces useless predictions. A quality audit protects against these risks.

Key concepts:

Data quality score; completeness %; freshness; bias detection; representative sampling.

What it is:

Assess whether the data can be accessed by the systems that will feed the AI: APIs, connectors, access permissions, and whether legacy systems allow reliable export.

Why learn:

Even the highest-quality data in a system without an API is inaccessible to AI. Integration is what turns data into fuel.

Key concepts:

API-first; ETL/ELT; data pipeline; permissions and roles; integration vs. manual export.

What it is:

Verify that the personal data collected has a legal basis, that consent is obtained where necessary, and that its use in AI models doesn't violate data subject rights — especially in RAG with internal documents.

Why learn:

Using customer data in AI models without a legal basis exposes the company to the ANPD. A consultant who ignores the LGPD is delivering a risk, not a solution.

Key concepts:

Legal basis; data minimization; RAG and personal data; DPO; compliance before the project.

What it is:

RAG requires organized, chunked, indexable documents. Fine-tuning requires many consistent, high-quality examples (input/output). The audit determines which approach is feasible.

Why learn:

Proposing fine-tuning for a company with no labeled data wastes budget. The available data determines the technique, not the other way around.

Key concepts:

RAG vs. fine-tuning vs. few-shot; chunking; embeddings; labeled data as an asset.

What it is:

The audit’s final deliverable: a report with a score for each data quality dimension, a list of critical issues, remediation recommendations, and a readiness statement for each use case.

Why learn:

It’s the artifact that objectively justifies “fix the data first”—and protects the consultant from being held accountable for AI results based on poor data.

Key concepts:

Data health score; critical vs. manageable issues; readiness by use case; remediation plan.

View Full
3.4~50 min

🏛️ Governance and risk: NIST AI RMF, ISO 42001, EU AI Act

Governance isn’t bureaucracy—it’s what makes it possible to scale AI with control. Knowing the frameworks (NIST, ISO, EU AI Act) enables the consultant to recommend structures proportional to the risk of each use.

What it is:

NIST’s AI Risk Management Framework organizes risk management into 4 functions: GOVERN (policies and culture), MAP (identify risks by context), MEASURE (assess impacts), MANAGE (address and monitor).

Why learn:

The RMF is the framework most widely adopted by organizations that need vocabulary and structure for AI governance — and it serves as the basis for any internal policy.

Key concepts:

GOVERN → MAP → MEASURE → MANAGE; contextual risks; continuous management cycle.

What it is:

ISO/IEC 42001 is the first international AI management system (AIMS) standard. Based on the PDCA cycle (Plan-Do-Check-Act), it sets requirements for organizations to develop, deploy, and use AI responsibly.

Why learn:

Clients with certification requirements or vendor audits will ask for compliance with 42001. A consultant familiar with the standard can guide them through the compliance journey.

Key concepts:

AIMS; PDCA applied to AI; certification; compliance audit; documented AI policy.

What it is:

The EU AI Act classifies AI uses into 4 categories: unacceptable (prohibited — e.g., social scoring), high risk (healthcare, credit, employment — requires strict compliance), limited (chatbots — requires transparency), and minimal (spam filters — no special requirements).

Why learn:

Even Brazilian companies that operate with data from European citizens are subject to the AI Act. And the classification framework is useful even for internal governance without a legal obligation.

Key concepts:

4 risk classes; prohibited vs. obligations vs. transparency; extraterritorial scope; classify before deployment.

What it is:

The 5 fundamental risks: bias (discrimination from biased data), hallucination (incorrect outputs presented with confidence), security (data leakage via prompt injection), privacy (personal data in prompts), and reputation (public harm caused by an AI failure).

Why learn:

Without mapping these risks before the project, the consultant delivers a ticking time bomb. Identifying and mitigating risks is part of the minimum professional scope.

Key concepts:

Risk map by use case; proportional mitigation; residual risk accepted by leadership.

What it is:

An internal FAQ chatbot requires less governance than credit AI. The recommended structure should be proportional to the level of risk and the size of the organization—neither excessive bureaucracy nor naivety.

Why learn:

An SMB with a customer service chatbot doesn’t need an ethics committee like a bank’s. Proportionality is what makes governance practical and widely adopted.

Key concepts:

Risk × control; light governance for low risk; controls scale with impact.

What it is:

Well-designed governance accelerates adoption: clear policies reduce decision time, risk mapping builds confidence to expand, and continuous monitoring catches problems early—before they become crises.

Why learn:

A consultant who presents governance as "protection that enables" sells much better than one who presents it as "mandatory compliance."

Key concepts:

Operational trust; early detection; policy as an accelerator; governance as an advantage.

View Full
← Back to start Next track: Plans →