What We Do

AI Readiness Diagnostic

Turning AI readiness from assumption into evidence

An independent, fixed-scope assessment of operating model and management system maturity.

Two project assurance engineers in helmets and vests observe glowing futuristic industrial machinery at sunset with wind turbines, depicting AI transformation readiness for the energy minerals and resources industry.
Trusted to audit and assure operations at:

Why do AI deployments stall?

AI is entering operational decision-making faster than management systems are being extended to govern it and vendors, integrators and internal teams all have reasons to tell you it is fine.

Regulation has not rescued anyone's timeline. The EU AI Act's high-risk obligations were deferred because the surrounding standards infrastructure was not ready, but its transparency obligations and enforcement powers took effect on 2nd August 2026 regardless. The deadline moved, the operating model gap did not. The deferral is time to build governance properly, not a reprieve.

BCG's 2025 research, drawing on 1,250 senior executives, found that 60% of organisations report minimal gains from AI despite substantial investment, and only 5% qualify as genuinely built for it.

The failure point is rarely the algorithm. It is the operating model: unclear decision rights, escalation routes that never anticipated automated decisions, competence requirements written for roles that have since changed, and documentation the new systems cannot read.

What the PDAS diagnostic assesses

The diagnostic is a fixed-scope, fixed-fee independent assessment, delivered in four to six weeks depending on the size of the organisation. It answers one question: can your operating model and management system absorb AI into operational decision-making, and if not, what needs to change first?

We assess maturity, not conformance. This is an independent assessment, not a certification audit.

Operating Model

How the enterprise is configured to deliver

How your organisation is wired: value chain and phases, structure across corporate, business and asset levels, decision rights, accountabilities and the interfaces between functions, areas and projects. We assess that configuration against good-practice design, then test whether it can carry AI in the decision loop.

Management System

How that configuration is governed

The documented practices, processes, procedures and controls you already run, either aligned with or certified to ISO 9001, 14001, 45001 and 27001 under the Harmonised Structure, alongside the IOGP 510 and 511 operating management system framework. That is the foundation AI has to sit on.

We also assess forward alignment - including the direction of the ISO 9001 revision now in development, which is being shaped around digitalisation and AI.

Data and Knowledge Readiness

 Whether the foundation can feed it

AI consumes what your organisation has written down and measured. We assess whether that foundation is fit to be consumed, the quality, availability, ownership and traceability of operational data (assessed with reference to the ISO/IEC 5259 data-quality series), whether documented knowledge is current, structured and machine-readable (ISO 30401), and whether a single, governed version of the truth exists for the decisions AI will touch. If the data cannot be trusted, the AI industrialises the distrust.

AI-Specific Readiness

Whether governance extends to AI

Whether your management system actually governs AI in the decision loop, assessed against ISO/IEC 42001 and the obligations now in force under the EU AI Act, drawing on the standards built around it: ISO/IEC 23894 for AI risk management, ISO/IEC 42005 for impact assessment, and ISO/IEC 38507 for what AI oversight means at Board level.

We look at the controls that matter in practice: AI policy and named accountabilities; risk management and impact assessment; lifecycle controls from procurement and vendor due diligence through deployment, monitoring, drift and decommissioning; human oversight that is real rather than nominal; logging and records that would survive independent review; incident response when a model gets it wrong; and Board-level visibility of where AI sits in the decision chain. Including the commercial and financial decisions that sit outside conventional OMS scope - where AI is often adopted first and governed last.

Culture

Whether people will work with it

The strongest governance on paper fails in a culture that cannot carry it. We assess culture the way the EMR sector already understands from safety: structured interviews across corporate, site and project levels; observed practice against espoused process; how bad news actually travels and how decisions are actually challenged.

Specifically for AI: whether people will use, question or quietly bypass automated outputs, and whether your assurance activity would detect any of the three. We draw on ISO 10010's framework for evaluating organisational quality culture and on safety-culture maturity practice familiar to every operator in the sector, so the findings land in language your leadership already speaks. What we report is the gap between the culture the documents describe and the culture the interviews reveal.

Who performs the assessment

Our principal assessors hold the Artificial Intelligence Governance Professional (AIGP) certification from the International Association of Privacy Professionals (IAPP), the global body for privacy, AI and data governance credentialing. AIGP covers AI risk management, the regulatory frameworks including the EU AI Act, and the controls required to deploy AI responsibly.

They hold it alongside credentials from PMI, AXELOS, CQI, IIBA and NEBOSH - project delivery, quality, business analysis and safety — and more than 150 years of collective EMR experience. That combination is the point: assessors who understand AI governance and have run the management systems it has to sit inside.

What you receive

  • A maturity view of each dimension in scope - scored and benchmarked against good practice and the relevant standards. Where more than one is assessed, an integrated view of how they interact.
  • A clear read on where what we assess is sound and where it is not - reported process versus observed practice.
  • A prioritised intervention sequence: what to fix first, and why
  • A Board-ready briefing, delivered and walked through
  • Where wanted, a fixed-scope proposal for the next step

The diagnostic stands alone. Any next step is a separate decision the findings have to earn - advisory or assurance work, never building or selling AI, and never dependent on your vendors, integrators or delivery teams.

That is how the independence holds.

Book  A Consultation

Who this is for

Energy, Minerals and Resources owner-operators and contractors, typically at the scale where a Big Four transformation programme is disproportionate, but the AI governance problem is identical.

The diagnostic is likely for you if any of these apply:

ISO/IEC 42001 has appeared in a tender, a client questionnaire or an insurance conversation

Your Board or Audit and Risk Committee has asked who is accountable when AI informs an operational decision

Your operating management system is due its periodic review, and AI was not in scope last time

AI pilots or vendor deployments are underway, and nobody has mapped which operational decisions they touch

AI is informing cost, schedule or commercial decisions that sit outside your certified management system

Your operating model has grown by accretion, and no one has independently checked whether it still holds

This is not for you if you want someone to select, build or implement AI. We do not do that work, and that is deliberate - it is what makes the assessment independent.

How it works

Scoping call

We agree boundaries, sites, respondents and which dimensions are in scope - one or all four. Document request issued. Scope and fee fixed before work starts.

Evidence and interviews

Structured interviews across a stratified sample, with document and system review, on site or remote. We test what the system says against what the records show.

Assessment

Each dimension in scope is scored for maturity and benchmarked against good-practice design and the relevant standards. Maturity, not conformance - an independent assessment, not a certification audit.

Findings

A Board-ready briefing: your maturity position across the dimensions assessed, and a prioritised roadmap. Delivered and walked through.A Board-ready briefing: your maturity position across the dimensions assessed, and a prioritised roadmap. Delivered and walked through.

One management system, not two

ISO/IEC 42001 is built on the Harmonised Structure, the same clause architecture as ISO 9001, 14001, 45001 and 27001. It is designed to extend the management system you already run, not to sit beside it with its own manual, audits and interfaces. One management system, extended, including into the commercial and financial decisions your current scope was never written to cover.

A parallel system is not just wasted effort. It creates interface risk in exactly the place AI needs clarity: who decides, who signs, who stops.

Nor does extending to ISO/IEC 42001 tie you to one regime. It is jurisdiction-neutral, maps across to frameworks such as the NIST AI RMF, and builds much of the governance infrastructure the EU AI Act assumes. And because we assess readiness rather than certify, working with us commits you to no certification body and no certification path. You keep every option open.

FAQ

What is an OMS and AI-readiness diagnostic?

A structured, evidence-based assessment of how ready your operating model and management system are to govern AI. Each area is scored against a weighted set of criteria drawn from good practice and the relevant standards, giving you a measure of maturity rather than an opinion. During scoping you tell us what matters most to your operation, and we weight the assessment accordingly, so the result reflects your priorities rather than a generic template.

Do we need ISO/IEC 42001 certification first?

No - and most clients haven't certified. That is often why they are here: the diagnostic tells you where you stand before you decide whether certification is worth pursuing at all.We are not a certification body and we do not issue certificates. That is part of our independence, by design. Our assessors are qualified lead auditors, so the work is conducted to audit-grade rigour against the standard's requirements, overseen by an AIGP-certified practitioner. You get the depth of a formal audit without committing to a certification path, and whether or not you ever certify, the findings stand on their own.

We already run ISO 9001, 45001 and 14001. Why is that not enough for AI?

Those standards govern quality, safety, environment and information security for decisions made by people in defined roles. AI changes who - or what - makes the decision, and where accountability sits.

Your existing system usually has the right bones. But its decision rights, competence requirements, management of change and assurance were written before automated decisions entered the loop. And the commercial and financial decisions AI is now touching - estimating, forecasting, schedule risk, claims - sit outside the scope those frameworks were written to cover.

The diagnostic tests whether they still hold and where they need extending, inside the system you already run, not alongside it.

What does the EU AI Act deferral mean for operators outside the EU?

Two things. If you place products or operate in the EU, the high-risk obligations still apply , deferred to 2 December 2027 for stand-alone systems and 2 August 2028 for AI built into regulated products. Those dates are now fixed and the direction is settled.

But not everything moved. The transparency obligations were not deferred and apply from 2 August 2026, and the AI literacy duty has applied since February 2025. And even outside the EU, the Act is already shaping client questionnaires, insurance and Board expectations globally.

The deferral is time to build governance properly, not a reprieve.

What do we actually receive at the end?

A Board-ready briefing: an integrated maturity view of each dimension in scope, a clear read on where your operating model and management system are sound and where they are not, and a prioritised intervention sequence. Delivered and walked through. Where wanted, a fixed-scope proposal for the next step.

How is this different from a Big Four engagement or a vendor's AI readiness assessment?

A Big Four programme is broader, longer and deliberately built to expand. A vendor's assessment isn't independent, its outcome supports a sale.The PDAS assessment is deliberately confined to an agreed scope and fee, and structurally independent. We build no AI models, select no platforms, integrate no AI systems and take no vendor commissions. Nothing in our revenue depends on the answer we give you. And it is led by practitioners who have run these operations.

How is our information handled during the diagnostic?

Under NDA, with a defined document request agreed at scoping. Evidence is handled confidentially, access is limited to the assessment team, and materials are returned or destroyed on request at the close of the engagement. Your material is not used to train AI models, and is not shared with vendors, platforms or third parties.

What does the AI readiness assessment cost?

A fixed fee, agreed in writing before any work begins. No day-rate creep, no land-and-expand. It is priced as a defined diagnostic and scales with scope - a single dimension costs less than the full four - and by design it sits well below a Big Four programme. We confirm the figure after the scoping call, once boundaries and sample size are set.

Why PDAS

PDAS was founded by Energy, Minerals and Resources practitioners, not career consultants. More than 150 years of combined capital-project and operations experience - spent designing, implementing and assuring operating management systems inside the sector, not advising on them from outside. Our founding proposition is independent verification: reported process tested against what the records show. We now apply it to AI entering operational decision-making.

Our independence is structural. We build no AI, select no platforms, run no implementations and take no vendor commissions. Our only stake is getting the answer right.

Four project assurance colleagues smiling and posing together in an office lounge area with a wall sign that reads PDAS Project Delivery Assurance Services.

How ready is your organisation for AI?

Answer ten questions to generate your AI Readiness Snapshot.

Before committing to a multi-month transformation or procuring another tool, get an honest baseline of where your operating model stands by answering eight questions.

How ready is your organisation for AI?

Before we start
Two optional details, so the read is set in your context. Neither is scored.
Your snapshot
Ten answers in. Change any of them with Back before you generate.

Your snapshot appears on screen. You can ask for a copy once you have it.

Thank you! Your submission has been received!
Something went wrong while submitting the form.
Please try again.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.