Strategy & Leadership
2 questions
AI vision tied to business outcomes; exec sponsorship; budget; AI ownership; clear business alignment
Our agency has a written AI strategy tied to named mission outcomes for residents (wait times, error rates, response times) rather than to the number of pilots launched.
AI initiatives have an accountable executive sponsor (agency head, deputy, CIO, or Chief AI Officer) with funding that survives the appropriations cycle.
Use-Case Portfolio
2 questions
Inventory + prioritization; opportunity matrix; ROI cases; AI-type fit
We maintain an inventory of candidate AI use cases classified by consequence to the resident (administrative / resident-facing / consequential determination), not merely by department.
We have selected at least one end-to-end resident journey (a benefits application, a licensing process, an inspection workflow) to redesign whole, rather than a portfolio of isolated departmental use cases.
Data Foundations
2 questions
Quality, accessibility, lineage, governance, integration, labeling
The data an AI workflow would need is reachable across agency boundaries through documented sharing agreements, an integration layer, or a warehouse — not blocked by statutory silos nobody has tested.
We have named data stewards, a catalog, and quality metrics for the specific records that would feed AI decisions, and we know which of those records are subject to retention schedules.
Technology & Infrastructure
2 questions
Cloud, APIs, integrations, security architecture, MLOps/LLMOps, model hosting
We have an approved approach for AI workloads — hosting, model access, identity, and integration with systems of record — that has cleared our security review or state cloud-authorization process.
We can forecast, allocate, and cap inference spend per workflow, so AI run costs cannot quietly become the line item that ends the program mid-year.
Security & Privacy
2 questions
Information security, data protection, vendor/3rd-party risk, ePHI / FERPA / PII controls
AI systems touching regulated data (criminal justice information, federal tax information, health, or benefits records) are covered by the applicable authorization and vendor agreements before use, not after.
We have documented data classification and route AI use cases through privacy and security review, including an assessment of what becomes a public record when a model generates it.
Talent & Culture
2 questions
AI literacy, skills, training, change management, adoption appetite, resistance risk
Frontline staff have practical AI guidance and training, and understand that the goal is handling more volume with better judgment rather than reducing headcount.
Where role redesign is required, we have engaged the relevant unions, civil service rules, and job classifications early rather than discovering the constraint after design.
Process Maturity
2 questions
Workflows documented; repetitive / high-friction / measurable tasks identifiable
The workflows targeted for AI are mapped end to end with baseline cycle times, backlog volumes, rework rates, and appeal or send-back rates.
We can distinguish process steps that exist because of legislative or regulatory requirement from those that exist only because of legacy constraint.
Governance, Risk & Responsibility
2 questions
Policies, AI inventory, risk tiering, human oversight, bias testing, explainability, audit trails
We have drawn an explicit line for human sign-off based on consequence to the resident — not a blanket "a human reviews everything" default that nobody can actually staff.
A resident affected by an AI-assisted decision can be told that AI was involved, receive an explanation, and have a human review and override it.
Vendor & Procurement Readiness
2 questions
Build/buy/partner decisioning; vendor DD; contract templates; BAAs/DPAs; tool sprawl control
Our AI contracts pay for measurable outcomes at production volume rather than for inputs (licenses, seats, hours), and share delivery risk with the vendor.
Vendor due diligence covers model transparency, accessibility (Section 508 / WCAG), data ownership, exit and data-return terms, and the right to audit — not just security and price.
Implementation Capacity & Operations
2 questions
Can the org actually pilot, buy, build, deploy, train, monitor? Post-deploy monitoring; shadow-AI discovery
We have moved at least one AI pilot into sustained operational use with explicit go-live criteria, or we understand precisely what stopped us.
Production AI is monitored for accuracy drift, disparate impact across the populations we serve, and shadow AI (staff using personal accounts on resident records).