Why a Copilot readiness assessment comes before the purchase order

copilot readiness assessment checklist b archive cabinet three drawers

Copilot readiness assessment work is the step most organisations skip, and it is the single clearest predictor of whether a Microsoft 365 Copilot rollout delivers value or quietly becomes shelfware. The software itself installs in an afternoon. The conditions that make it genuinely useful — a tidy data estate, correct permissions, a governed tenant and people who know what to ask — take considerably longer to put in place.

Microsoft sells Copilot as an add-on licence, which makes it feel like a purchasing decision. It is not. It is a data governance decision wearing a productivity badge. Copilot reads what your staff can already read, which means it inherits every permission mistake your tenant has accumulated since the day it was created.

What actually goes wrong without an assessment

The failure mode is rarely dramatic. Nobody’s tenant explodes. Instead, an employee asks Copilot a reasonable question about salary bands or redundancy plans, and Copilot answers accurately from a document that was technically accessible but practically invisible. A Microsoft 365 security audit usually finds that document long before Copilot does — but only if somebody runs one first.

The cost of getting the sequence wrong

At roughly £25 per user per month on an annual commitment, a hundred-seat deployment is a £30,000 yearly decision. Committing to that before a Copilot readiness assessment tells you whether the underlying data can support it is an expensive way to discover that your SharePoint estate needs six months of remediation.

Who should own the assessment

The work spans IT, security, compliance, HR and the business units who will actually use the tool. In practice, someone has to hold the pen. A Copilot readiness assessment run purely by IT tends to produce a technical prerequisites checklist and miss the governance questions entirely.

What a Copilot readiness assessment actually measures

copilot readiness assessment checklist c shield with keyhole

A useful Copilot readiness assessment is not a licence compatibility check. It measures six independent dimensions, and a serious weakness in any one of them will undermine the other five. Treating it as a single yes/no gate is the most common structural mistake.

The six dimensions in brief

Your data estate, your permissions model, your compliance posture, your commercial case, your technical prerequisites, and your people. Each carries its own evidence, its own owner and its own remediation timeline. The Copilot readiness assessment checklist that follows works through them in that order, because each one depends on the ones before it.

Why the order matters

Fixing permissions before you know where your data lives wastes effort on sites nobody uses. Buying licences before you have named use cases produces adoption figures that embarrass everyone involved. The sequence is not arbitrary — it front-loads the work that takes longest to complete.

Evidence, not opinion

Every item below should resolve to a piece of evidence: a report, an export, a screenshot, a named owner. “We think permissions are fine” is not an assessment finding. A Copilot readiness assessment that cannot be handed to an auditor is a conversation, not a control.

Checklist part 1: your data estate and information architecture

copilot readiness assessment checklist d balance scale empty pans

Copilot grounds its answers in your Microsoft Graph — mail, files, chats, meetings and the semantic index built across them. The quality of that index is the quality of your answers. This is where a Copilot readiness assessment either finds a solid foundation or a decade of accumulated sprawl.

Map where your content actually lives

Inventory every SharePoint site, Teams team, OneDrive account and mailbox in scope. Record the owner, the last activity date and the approximate item count for each. Sites with no owner and no activity in two years are not archives; they are liabilities that Copilot will happily read from.

Identify and quarantine stale content

Superseded policies, old pricing sheets and abandoned project folders are the most reliable source of confidently wrong Copilot answers. The tool has no way to know that the 2019 expenses policy was replaced. If it is indexed, it is a candidate answer.

Check for duplicate and near-duplicate documents

Where five versions of the same handbook exist across four sites, Copilot may cite any of them. Consolidating to a single authoritative copy per document type does more for answer quality than almost any other remediation in this Copilot readiness assessment.

Assess your file server position

Content still sitting on a traditional file server is invisible to Copilot entirely. If a meaningful share of your working documents lives there, your assessment should feed straight into a file server to SharePoint migration plan before any licences are bought.

Verify metadata and naming discipline

Consistent site names, document libraries and content types help the semantic index disambiguate. This matters most in organisations with several business units using the same vocabulary for different things — “the contract” means something different in sales and in legal.

Checklist part 2: permissions, identity and the oversharing problem

copilot readiness assessment checklist e four rising blank columns

This section is where most Copilot readiness assessment exercises find their genuinely serious issues. Copilot enforces existing permissions faithfully. That is precisely the problem: it also surfaces content that was technically permitted but practically undiscoverable through normal search behaviour.

Run a data access governance review

Microsoft’s data access governance reports in the SharePoint admin centre show sites shared with “Everyone except external users”, sites with anonymous links, and sites with unusually broad access. Every organisation running this for the first time finds something uncomfortable. That is the report doing its job.

Audit the “Everyone” and company-wide groups

The single most common finding is a site shared with everyone in the organisation because it was easier than managing a group. Before Copilot, that site was buried. After Copilot, it is one natural-language question away from anybody with a licence.

Review external and guest access

Guest accounts that were never removed after a project ended represent both a security exposure and a Copilot readiness assessment blocker. Map every guest, the sites they can reach, and whether the sponsoring relationship still exists.

Check sharing link defaults

Tenant-wide defaults that create “anyone with the link” URLs will keep generating exposure faster than you can remediate it. Tightening the default to “people in your organisation” or “specific people” stops the problem growing while you fix the backlog.

Consider Restricted SharePoint Search as a stopgap

Where the permissions backlog is too large to clear before launch, Restricted SharePoint Search limits Copilot and enterprise search to a curated allow-list of sites. It buys time. It is not a fix, and any Copilot readiness assessment that treats it as one is storing up trouble.

Confirm identity hygiene

Every user needs a properly licensed Microsoft Entra ID account and an active OneDrive. Shared or generic accounts, dormant accounts with live permissions and unmanaged service accounts all distort what Copilot can reach. Pair this with your wider security review rather than treating it as a Copilot-only task.

Checklist part 3: compliance, retention and governance

copilot readiness assessment checklist f signpost three blank arrows

Copilot creates new content, new prompts and new interaction records. All of it is discoverable, all of it is subject to your retention obligations, and most organisations have not thought about any of it before the first licence is assigned.

Classify your sensitive data first

Sensitivity labels are the mechanism Copilot uses to respect confidentiality, and labelled content carries its protection into Copilot-generated outputs. An unlabelled estate gives Copilot no signal at all about what is confidential. Microsoft’s Purview retention documentation is the practical starting point for the wider policy set.

Decide how prompts and responses are retained

Copilot interactions are stored and are subject to retention policy, eDiscovery and audit. Your Copilot readiness assessment should record an explicit decision on retention duration rather than inheriting a default nobody chose. This links directly to the difference between retention and backup, which trips up a surprising number of organisations.

Check your DLP policies still make sense

Data loss prevention rules written for email and file sharing may behave unexpectedly when content is being summarised and regenerated rather than sent. Review whether your existing rules cover the new pathways Copilot opens.

Establish an acceptable use position

Staff need to know what they may put into a prompt, what they may do with the output, and where human review is mandatory. This is a short document, but its absence is conspicuous during any audit and it is the cheapest item on the entire checklist.

Record your lawful basis and DPIA position

For UK organisations processing personal data through Copilot, a data protection impact assessment is frequently appropriate. Deciding this before deployment, with a documented rationale either way, is considerably easier than reconstructing it afterwards.

Checklist part 4: licensing, cost and commercial modelling

The commercial section of a Copilot readiness assessment is where optimism meets the renewal calendar. Copilot is a per-user, annually committed cost layered on top of your existing subscriptions, which makes seat allocation a decision with a twelve-month tail.

Confirm prerequisite licensing

Copilot requires an underlying Microsoft 365 or Office 365 subscription of the right tier. Verify what every user in scope actually holds today rather than what the procurement record says they hold. Microsoft’s Copilot requirements documentation is the authoritative reference and changes periodically.

Clean up existing licence waste first

Almost every tenant carries unused and over-specified licences. Running a Microsoft 365 licence audit before adding Copilot frequently funds a meaningful share of the new spend from savings you already had.

Model seats by role, not by headcount

Copilot delivers uneven value across job families. Roles with heavy document, meeting and mailbox loads see the strongest returns. Field staff, shift workers and single-application users often see very little. A blanket rollout is the most expensive way to learn this.

Define what success is worth

Agree in advance what measurable outcome justifies the cost — hours returned per user per week, faster document turnaround, reduced backlog in a named process. A Copilot readiness assessment without a success definition cannot produce a renewal recommendation twelve months later.

Plan for the free tier

Copilot Chat is available to Microsoft 365 users without the paid add-on and handles general web-grounded queries. Using it as a proving ground for a subset of users is a low-risk way to test appetite before committing to per-seat spend.

Checklist part 5: technical and device prerequisites

The technical layer is the most straightforward part of any Copilot readiness assessment, which is precisely why it should not be allowed to consume the majority of the effort. Most of these items are verifiable in a morning.

Verify application versions and update channels

Copilot functionality is tied to current builds of the Microsoft 365 apps. Devices sitting on a deferred update channel or an old Office version will silently lack features, generating support tickets that look like Copilot faults. Microsoft’s Copilot setup guidance lists the current baseline.

Check Outlook, Teams and browser readiness

Several Copilot experiences depend on specific clients — the new Outlook, current Teams, and a supported browser. Mixed estates where half the users are on legacy clients produce inconsistent experiences that undermine confidence quickly.

Confirm device management coverage

Every device that will run Copilot should be enrolled, compliant and patched. If your device management coverage has gaps, those gaps become the route by which Copilot output leaves your control.

Test network and regional data handling

Confirm where your tenant’s data resides, whether that satisfies your commitments, and that no network path is blocking the required endpoints. This is usually uneventful, but it is far cheaper to check than to diagnose mid-pilot.

Validate accessibility and language coverage

Confirm that the languages your organisation works in are supported at the level your staff expect, and that Copilot’s outputs meet your accessibility standards. Both are easy to overlook and awkward to retrofit.

Checklist part 6: people, use cases and adoption

Technology readiness without human readiness produces the most familiar failure in this space: a fully compliant, correctly licensed deployment that nobody uses after week three. This part of the Copilot readiness assessment carries more weight than its position at the end suggests.

Name your first use cases precisely

“Improve productivity” is not a use case. “Reduce the time to produce the monthly board pack from two days to four hours” is. Three or four precise use cases with named owners give a pilot something to prove and a business case something to measure.

Identify and equip your champions

Every successful rollout runs on a small group who use the tool constantly and teach everyone else informally. Identify them before launch, give them early access, and give them a channel to report what works. This costs nothing and changes outcomes materially.

Assess prompting skill honestly

Most staff have never written a structured prompt. The gap between a vague question and a well-framed one is the entire difference between a useful answer and a disappointing one. Budget for genuine training, not a recorded webinar nobody watches.

Establish a verification habit

Staff must know that Copilot output requires checking, particularly for figures, dates and citations. Building that expectation into the first training session is far more effective than correcting it after a bad document reaches a client.

Plan how you will measure usage

Microsoft provides adoption reporting through the Copilot dashboard. Decide before launch which metrics you will review monthly and who reviews them. Data that nobody looks at will not survive contact with a renewal conversation.

How to score your Copilot readiness assessment

Scoring converts a long checklist into a decision. The approach that works in practice is deliberately simple: rate each of the six dimensions red, amber or green against defined criteria, and let the pattern of colours drive the recommendation.

Define the thresholds before you score

Green means no blocking issues and a named owner for ongoing maintenance. Amber means known issues with an agreed remediation plan and date. Red means an issue that would cause harm if Copilot were enabled tomorrow. Writing these definitions before scoring prevents the optimism that creeps in afterwards.

Weight permissions and data above everything else

A red in permissions or data governance blocks deployment outright, regardless of how green the other four dimensions look. A red in adoption planning delays value but harms nobody. Your Copilot readiness assessment should make that asymmetry explicit.

Produce three outputs, not one

A completed assessment should yield a go/no-go recommendation, a prioritised remediation backlog with owners and dates, and a phased rollout plan tied to remediation milestones. A document that produces only the first of these leaves the hard work undone.

Re-run it, don’t file it

Tenants drift. Sites get created, permissions get widened, people leave. Re-running the Copilot readiness assessment annually — or after any significant reorganisation — keeps the picture honest. An assessment filed and forgotten describes a tenant that no longer exists.

Copilot readiness assessment mistakes that cost the most

The failure patterns are remarkably consistent across organisations of very different sizes. Recognising them in advance is cheaper than discovering them during a pilot.

Treating it as a purely technical exercise

The technical prerequisites are the easiest fifth of the work and the most comfortable for IT teams to focus on. An assessment that produces a thorough version-compatibility matrix and says nothing about oversharing has inverted its own priorities.

Assuming existing permissions are correct

Permissions are correct in the sense that they do what they were configured to do. Whether they reflect what the organisation intends today is a completely different question, and it is the one that matters here.

Rolling out to everyone at once

Broad simultaneous deployment removes your ability to learn cheaply. A phased rollout tied to your Copilot readiness assessment findings lets each wave benefit from what the previous one uncovered.

Skipping the baseline measurement

Without a before figure, the after figure proves nothing. Capture how long the target tasks take today, before anybody has a licence. This takes an afternoon and it is the only thing that makes the twelve-month renewal conversation straightforward.

Ignoring the data foundation

Copilot is a retrieval system before it is a generation system. Organisations that have already done the work described in an AI-ready data checklist start from a materially stronger position, because the same disciplines apply.

Leaving governance until after launch

Retention decisions, acceptable use and DPIA positions are all easier to establish before the first prompt is typed. Retrofitting governance onto an active deployment means changing behaviour people have already learned.

Turning your Copilot readiness assessment into a 90-day plan

An assessment that does not become a schedule tends to become a memory. The following structure maps the findings onto a realistic timeline for a mid-sized organisation.

Days 1 to 30: remediate and decide

Clear the red findings. Run the data access governance reports, fix the broadest sharing exposures, tighten default sharing links, and label your most sensitive content. Confirm prerequisite licensing and agree the pilot cohort. This is the heaviest month and it deserves the most attention.

Days 31 to 60: pilot with intent

Enable a small, deliberately mixed cohort covering your named use cases. Measure against the baseline you captured. Collect the prompts that worked and the ones that did not, and feed both into training material. Keep the group small enough that you can actually talk to everybody in it.

Days 61 to 90: expand or stop

Review the pilot against the success definition agreed during the Copilot readiness assessment. Expand to the next wave, adjust the seat model, or stop and remediate further. All three are legitimate outcomes, and the discipline to choose the third when the evidence supports it is what separates a controlled programme from an expensive habit.

Beyond 90 days: operate it properly

Assign ongoing ownership for permissions hygiene, licence allocation and adoption reporting. These are operational responsibilities now, not project tasks. Organisations without internal capacity for this frequently fold it into their existing managed IT services arrangement, which is usually cheaper than building the capability from scratch.

Copilot readiness assessment: frequently asked questions

How long does a Copilot readiness assessment take?

The assessment itself takes two to four weeks for a mid-sized organisation. Remediation is the variable: a well-governed tenant may need a fortnight, while a tenant with a decade of unmanaged sharing can need six months. The assessment’s main value is telling you which of those you are.

Can we run one ourselves or do we need help?

Internal teams can run a Copilot readiness assessment perfectly well if they have Microsoft 365 admin depth, security input and the authority to ask uncomfortable questions about permissions. The last of those three is usually the constraint rather than the technical knowledge.

Does Copilot really expose data it should not?

Copilot does not bypass permissions. It surfaces content users were already permitted to see but would rarely have found. The distinction matters legally and matters not at all to the person who reads a document they should not have.

What if the assessment says we are not ready?

That is the assessment working correctly, and it is a considerably better outcome than discovering the same facts after committing to twelve months of licences. Use the remediation backlog, fix the reds, and reassess. The work is valuable independently of whether Copilot is ever deployed.

How does this fit our wider AI plans?

A Copilot readiness assessment is effectively a data readiness assessment with a Microsoft label on it. The permissions hygiene, classification and governance work it demands is the same foundation any future AI strategy will require, whichever tools you eventually choose.

What should we do first, today?

Run the data access governance reports in your SharePoint admin centre and look at how many sites are shared organisation-wide. That single report takes minutes and tells you more about your real readiness than any vendor questionnaire, because it deals in data management facts rather than intentions.