The Dade Companies

Free resource

Copilot & AI Readiness Checklist

Use this checklist to resolve the licensing, security, governance, and adoption questions that determine whether Microsoft Copilot creates measurable value. Print it, or work through it with your team.

Review it with us

1. Licensing readiness

  • Current Microsoft 365 plans documented, including which users are eligible for Copilot
  • Add-on licensing requirements and prerequisites confirmed for the intended user groups
  • License ownership and renewal dates known, with a named internal owner
  • Pilot user count agreed before any broad license commitment

2. Identity and access

  • Multi-factor authentication enforced for all users in scope
  • Privileged and administrative accounts inventoried and separated from daily-use accounts
  • Group membership reviewed so access reflects current roles, not historical ones
  • Guest and external access reviewed for the sites and teams in pilot scope

3. Data governance

  • Locations of sensitive data identified across mail, files, sites, and chats
  • Oversharing reviewed — organization-wide links, open sites, and legacy shared folders
  • Retention and deletion expectations documented for the content Copilot can reach
  • Data owners named for each major repository in scope

4. Information protection

  • Sensitivity labeling approach defined for confidential and regulated content
  • Protection expectations agreed for content that must never surface in AI responses
  • Monitoring and audit expectations defined for AI usage
  • Applicable regulatory or contractual obligations documented

5. Pilot scope

  • A specific business use case selected rather than a general rollout
  • Pilot group, duration, and success measures agreed in writing
  • Acceptable and unacceptable uses documented for pilot participants
  • Escalation path defined for questionable or incorrect AI output

6. Training and enablement

  • Role-based training planned for the pilot group, not a single generic session
  • Prompting practices and verification habits included in the training
  • Internal guidance published in plain language and easy to find
  • A named internal champion supports users during the pilot

7. Adoption measurement

  • Baseline captured before the pilot so change can be measured
  • Measures tied to work outcomes, not license activation counts
  • A review checkpoint scheduled to decide expand, adjust, or stop
  • Findings documented so the next phase inherits the decision record

8. Governance and decision assurance

  • Accountability for AI decisions assigned to named roles
  • A documented review path for new AI use cases
  • Transparency expectations set for how AI-assisted work is disclosed internally
  • Periodic reassessment scheduled as licensing, features, and regulation change

How to use your answers

Any item you cannot confidently check is a readiness gap, not a blocker. Prioritize identity, oversharing, and information protection first — those determine what Copilot can surface. Governance and training determine whether the results are trusted and sustained.

© 2026 The Dade Companies LLC. Provided for planning purposes; specific requirements depend on your environment and licensing.