The 50-Point HR AI Activation Readiness Checklist
An AI rollout fails for the same reasons in every enterprise HR tenant. This 50-point checklist breaks the failure modes into the five universal pillars — data quality, role structure, process health, security, and integration trust — and lets you score your own tenant. Run a free Yoetz.ai scan to get the same 50 points scored automatically in 2 hours.

Pillar 1 — Data quality (10 points)
- 99%+ active workers with location populated
- 99%+ active workers with manager populated
- 99%+ active workers with job profile populated
- Every active position rolls up to a valid parent org
- No supervisory orgs reporting to terminated managers
- Every job profile has at least 3 skills mapped
- No worker records with missing start date
- No duplicate national identifiers (Oracle) / national IDs (SF) / Government IDs (Workday)
- All MDF objects in Active state (no draft records)
- Cost centres assigned to every legal entity
Pillar 2 — Role and skill structure (10 points)
- Skill taxonomy adopted across all job families
- Proficiency levels defined for top 100 skills
- Career framework mapped to job profiles
- Competency model linked to performance rating scale
- No orphan job profiles (no worker assigned)
- Job profiles version-controlled with effective dates
- Manager hierarchy depth ≤ 8 levels
- Position-to-job-profile mapping is 1:1
- Custom roles documented with owners
- Annual job architecture review completed
Pillar 3 — Process and routing health (10 points)
- No business processes routing to terminated workers
- Every critical BP has an exception/escalation path
- BP condition rules reference only active objects
- No BPs with > 7 day average completion time
- Approval chains documented per material transaction
- Business processes mapped to SOX controls
- BP definitions reviewed annually
- Auto-routing rules tested in Preview before promotion
- Manager-on-leave delegation configured
- Audit trail enabled on every approval step
Pillar 4 — Security and data exposure (10 points)
- No unconstrained security groups on PII domains
- Role-based groups outnumber user-based 4:1
- All ISUs have 'Do Not Allow UI Sessions' enabled
- ISU domain access right-sized in last 12 months
- MFA enforced on all admin accounts
- OAuth 2.0 used for all API integrations
- SoD matrix mapped to security groups
- Quarterly privileged access review evidence retained
- Termination → account deactivation < 24 hours
- Security policy changes peer-reviewed

Pillar 5 — Integration trust (10 points)
- Every active integration has an alert subscriber
- Alert subscriber list includes a shared mailbox
- Integration credentials rotated in last 12 months
- No personal-account ISUs
- Integration mappings reviewed pre-release
- Failed runs trigger paging within 1 hour
- Integration Audit report reviewed weekly
- OAuth token refresh monitored
- No deprecated field mappings in production
- Documented runbook per critical integration
Score yourself
Tally your checks. Below 30 means you are not ready for any AI agent in production. 30–40 means you can run a controlled POC. 40–50 means you can activate select agents. Above 45 means you are ready for broad rollout. Run a free Yoetz.ai scan to get the same 50 points scored automatically.
How to run the checklist as a real audit, not a self-assessment
A checklist scored honestly by the team responsible for the tenant tends to be optimistic — not through dishonesty, but because the people closest to a configuration decision rarely remember every edge case that has accumulated since. Treat the first pass through the 50 points as a hypothesis-generation exercise rather than a final score: for every point you mark as passing, require a specific piece of evidence (a report export, a screenshot, a query result) rather than a verbal confirmation. Points marked as passing without evidence should be treated as unknown, not as passing, until verified. This discipline alone typically moves an initial self-assessed score of 40+ down to the low 30s once evidence is actually pulled — which is the accurate starting point for planning remediation, rather than a flattering number that leads to an under-scoped rollout plan.
Common scoring mistakes across the five pillars
- Treating 'we have a skills taxonomy' as a pass when only one job family has been mapped, rather than checking coverage across all families.
- Marking security points as passing based on a policy document rather than the actual current state of security group configuration, which frequently drifts from policy.
- Counting an integration's existence as evidence of monitoring, when 'has an alert subscriber' and 'alert subscriber actually receives and acts on alerts' are different claims.
- Scoring process health based on the business process definition rather than actual completion-time data pulled from a live report.
- Assuming a point passed a year ago still passes today — every one of these 50 points can regress silently through ordinary configuration change.
Weighting the pillars for your specific AI roadmap
The checklist presents five pillars as equally weighted at 10 points each, which is a reasonable default but not universally correct. An organisation planning to activate a self-service or case-management agent first should weight Pillar 1 (data quality) and Pillar 3 (process health) more heavily, since those are the two pillars that directly determine whether the agent gives correct answers to employees. An organisation planning a talent mobility or skills-based agent first should weight Pillar 2 (role and skill structure) most heavily. Re-run the scoring exercise with a weighted model that reflects your actual first-wave agent roadmap, rather than relying solely on the unweighted total, since two tenants with the same total score of 38 can have very different actual readiness for a specific agent depending on which pillars carry their strength.
Turning checklist gaps into a remediation backlog
A completed checklist is only useful if it converts into an actionable, owned backlog. For each failed point, capture four fields: the specific finding (not just 'data quality — 6/10'), the estimated remediation effort in person-days, the accountable owner (a named individual, not a team), and a target completion date tied to your AI activation milestone. Group findings by remediation type — data cleanup, configuration change, process redesign, security policy change — since each type has a different typical cycle time and often a different owner. Security and configuration fixes can usually be completed in days to weeks; data cleanup and process redesign often take months because they require business process owner engagement, not just system administrator time.
Re-scoring cadence after initial remediation
Do not treat the 50-point checklist as a one-time gate passed before go-live. Re-score at least quarterly, and always immediately before activating each new agent, since the checklist's five pillars degrade at different rates. Security posture (Pillar 4) can regress within weeks due to a single misconfigured new integration. Data quality (Pillar 1) degrades more slowly but steadily as new hires and org changes accumulate without corresponding data hygiene discipline. Process health (Pillar 3) tends to be the most stable once fixed, but is also the most disrupted by any major business process redesign project running in parallel with your AI rollout.
Using the checklist in vendor and consultant conversations
The 50-point structure is also useful as a common language when engaging a systems integrator or AI vendor about readiness. Rather than accepting a vendor's generic 'is your data clean' question, hand them your actual scored checklist with evidence attached. This does two things: it demonstrates you have already done the discovery work they would otherwise bill for, and it lets you have a much more specific negotiation about which of the 50 points their solution actually depends on versus which are irrelevant to their specific use case — narrowing the remediation scope and the associated cost before a statement of work is signed.
Building an evidence repository that survives staff turnover
A checklist scored once by a departing HRIS analyst has limited long-term value if the evidence behind each score lives only in that person's inbox or personal file structure. Build a shared, structured evidence repository — a single folder structure or a lightweight internal wiki page per checklist point — where every scan cycle's evidence is filed consistently, with a date and the name of the person who verified it. This matters more than it initially sounds, because the second and third scoring cycles are where the real value of the checklist emerges: being able to compare this quarter's evidence against last quarter's for the same point is what reveals whether a fix actually held or quietly regressed. Without a consistent repository, every scoring cycle effectively starts from zero, and organisations lose the ability to demonstrate remediation trend to an executive sponsor or auditor.
Translating the checklist into department-specific scorecards
A single tenant-wide checklist score is useful for an executive summary, but it obscures meaningful variation across business units, especially in large or federated organisations where regional HR teams manage their own configuration nuances within a shared platform. Break the 50 points into department- or region-specific scorecards where the underlying data supports it — job profile completeness, for example, can vary drastically between a corporate headquarters function that has invested in skills taxonomy work and a recently acquired business unit that has not yet been fully integrated into shared people processes. Presenting department-level scorecards alongside the aggregate lets you sequence AI rollout by readiness rather than by convenience or political priority, activating agents first in the business units genuinely prepared for them.
Using the checklist to set realistic AI rollout timelines with executives
One of the most valuable uses of a completed, evidence-backed checklist is as a timeline-setting tool in conversations with executives who have been sold an aggressive AI rollout timeline by a vendor or a peer organisation's success story. A checklist score of 28/50 concentrated in specific, identifiable gaps gives you a credible, specific basis to negotiate a realistic go-live date — 'we can activate the case management agent in six weeks once these four data quality items are closed' is a far stronger position than a vague statement that 'the data needs more work.' Executives are generally receptive to a specific, bounded remediation plan tied to evidence; they are understandably less receptive to open-ended caution that cannot point to what, specifically, needs to change.
Common blockers organisations hit when trying to close Pillar 2 gaps
- Skills taxonomies are frequently built once by a vendor-led project and never maintained, so the 'skills mapped' checkbox reflects a taxonomy that is already a year or more out of date relative to the organisation's actual job families.
- Job profile ownership is often unclear — no single function is accountable for keeping job profiles current as roles evolve, so gaps reappear even after an initial cleanup project closes them.
- Competency frameworks imported from an off-the-shelf library rarely map cleanly onto an organisation's actual internal job architecture, creating a false sense of completeness that only becomes visible when an agent starts producing mismatched recommendations.
- Multi-country organisations often have region-specific job architecture variations that a global skills taxonomy project overlooks entirely, leaving certain regions structurally unable to reach a high Pillar 2 score without dedicated regional work.
When to bring in outside help for specific checklist pillars
Not every pillar requires the same type of remediation expertise, and organisations sometimes make the mistake of engaging a single external partner to address all five pillars when the underlying work is genuinely disparate. Security and integration pillar gaps (Pillars 4 and 5) are typically best resolved by internal IT/HRIS teams with platform administration expertise, since they involve direct configuration changes that internal staff are best positioned to own long-term. Role and skill structure gaps (Pillar 2) often benefit from specialist job architecture or organisational design consultants, since the work is fundamentally about business content decisions rather than system configuration. Matching the right type of expertise to each pillar's specific gap, rather than defaulting to a single generalist engagement, typically produces faster and more durable remediation.
Frequently asked questions
Is a score of 40/50 good enough to activate any AI agent?
It depends which 10 points are failing. A 40/50 score concentrated in one pillar (for example, all 10 gaps in Pillar 2, role and skill structure) means you are well positioned for a self-service or case agent but not ready for a talent mobility agent. Always look at pillar-level detail, not just the total.
Can the checklist be adapted for platforms other than Workday, SAP, and Oracle?
Yes — the five pillars (data quality, role structure, process health, security, integration trust) are universal failure modes for any AI layer built on top of an HR system of record. The specific navigation paths and terminology change per platform, but the underlying checks transfer directly.
How long does a full manual pass through all 50 points typically take?
For a mid-sized tenant with one dedicated administrator, expect 2–4 weeks to gather evidence-backed answers manually across all 50 points. An automated scan like Yoetz.ai's compresses this to roughly 2 hours by querying the tenant directly rather than relying on manual report pulls.
Should every business unit in a multi-country tenant score separately?
Yes, if configuration or data quality varies meaningfully by country or business unit — which it usually does. A global average score can mask a specific region that is significantly behind and would fail a targeted agent rollout in that region even though the global number looks acceptable.
How should we store checklist evidence so it remains useful across multiple scoring cycles?
Use a shared, structured repository — a consistent folder structure or internal wiki — dated and attributed per checklist point, rather than relying on individual staff members' personal files. This is what makes it possible to compare cycle over cycle and demonstrate genuine remediation trend rather than starting from zero each time.
Is it better to hire one consultant for all five pillars or specialists per pillar?
Specialists per pillar generally produce faster, more durable results, since security and integration gaps require platform administration expertise while role and skill structure gaps require job architecture or organisational design expertise — these are genuinely different skill sets.
Continue reading
Find out what's broken in your tenant
Free first scan. Read-only access. Results in under 2 hours.
Start Your Free Scan