
Free AI Readiness Assessment | EPC Group
EPC Group AI Readiness Assessment — 4-week fixed-fee engagement covering identity, data surface, license, governance, use case, and compliance readiness for Microsoft Copilot rollout. Output: ADR + 12-month roadmap.
EPC Group AI Readiness Assessment — 4-week fixed-fee engagement covering identity, data surface, license, governance, use case, and compliance readiness for Microsoft Copilot rollout. Output: ADR + 12-month roadmap.

The AI Readiness Assessment is EPC Group's fixed-fee 4-week engagement that determines whether your organization is ready to deploy Microsoft 365 Copilot, Power BI Copilot, Microsoft Copilot Studio agents, and Azure OpenAI Service custom applications — and produces the roadmap to close gaps where it isn't.
This is the working enterprise AI Readiness Assessment overview EPC Group delivers for Fortune 500 organizations preparing for Microsoft AI rollout.
EPC Group's AI practice is led by Errin O'Connor (CEO, 4-time Microsoft Press author, original Microsoft Power BI beta team member, Project Crescent 2010-2013). Senior architects bring 15+ years of Microsoft AI architecture experience.
| Week | Output |
|---|---|
| Week 1 | Discovery — tenant inventory, identity, data, license, governance baseline |
| Week 2 | Use case prioritization, value modeling, persona analysis |
| Week 3 | Risk assessment, governance gap analysis, compliance mapping |
| Week 4 | Roadmap delivery, phased plan, ADR document |
Output: Architecture Decision Record (ADR), 12-month roadmap, business case, governance framework.
Mid-market: $40K-$60K. Fortune 500: $80K-$150K.
| Check | Why It Matters |
|---|---|
| Microsoft Entra ID coverage | Copilot requires Microsoft Entra-anchored identity |
| MFA at 100% coverage | Required for Copilot Conditional Access |
| Hardware token / FIDO2 / PIV/CAC for privileged | Required for regulated tenants |
| Conditional Access policies | Required to enforce Copilot access posture |
| Microsoft Entra PIM | Required for admin elevation |
| Inactive account cleanup | Inactive accounts shouldn't burn Copilot licenses |
| Service account hygiene | Service accounts should not have Copilot |
| Hybrid identity health | Microsoft Entra Connect / Cloud Sync stable |
Typical findings: 5-15% of accounts inactive but still licensed; MFA coverage gaps in service accounts and contractor accounts; Conditional Access policies underdeveloped.
| Check | Why It Matters |
|---|---|
| Microsoft 365 Group / SharePoint sprawl | Drives Copilot grounding overhead |
| "Everyone except external users" sites | Creates oversharing risk in Copilot |
| Sensitivity-label coverage | 80%+ on regulated content required |
| Auto-labeling rules | Required for ongoing label coverage |
| Microsoft Restricted Search readiness | Day-1 Copilot deployment mitigation |
| External sharing posture | Sensitivity-label-aware sharing required |
| Microsoft 365 Group lifecycle policies | Inactive groups create stale grounding |
| Stale OneDrive content | Departed-employee content drives grounding noise |
Typical findings: 30-50% of sites with broad permissions; sensitivity-label coverage at 5-15% pre-assessment; weak external sharing controls.
| Check | Why It Matters |
|---|---|
| Microsoft 365 E3 / E5 backbone | Required prerequisite for Copilot |
| Microsoft 365 E5 features (Defender, Purview Premium) | Required for Copilot governance |
| Microsoft Fabric F-SKU sizing | F64+ required for Power BI Copilot |
| Microsoft Power Platform licensing | Required for Copilot Studio agents |
| Microsoft Defender for Cloud Apps | Required for BYOAI / Shadow AI governance |
| Microsoft Entra ID P2 | Required for risk-based access |
| Microsoft Purview Premium | Required for AI Hub and Audit retention |
Typical findings: E3 backbone with E5 add-on licensing complexity; Microsoft Fabric capacity not yet provisioned; Microsoft Defender for Cloud Apps not licensed.
| Check | Why It Matters |
|---|---|
| Microsoft Purview AI Hub configured | Required for Copilot risk monitoring |
| Microsoft Purview Audit (Premium) retention | Required for compliance attestation |
| Microsoft Sentinel for SOC monitoring | Required for AI-related security events |
| AI ethics committee charter | Required for responsible AI |
| AI risk register | Required for ongoing governance |
| AI vendor risk management process | Required for BYOAI control |
| Workforce AI literacy training plan | Required for adoption and compliance |
| Acceptable Use Policy (AUP) AI provisions | Required for policy enforcement |
Typical findings: AI Hub not configured; AI ethics committee not established; AUP doesn't cover AI tools; workforce AI training plan absent.
| Check | Why It Matters |
|---|---|
| Department-by-department use case inventory | Drives prioritization |
| Persona-by-persona value modeling | Drives ROI projection |
| Common workflow patterns | Drives Copilot Studio agent prioritization |
| High-frequency knowledge lookup scenarios | Drives custom agent value |
| Power BI semantic model coverage | Drives Power BI Copilot value |
| Microsoft Dynamics 365 / CRM coverage | Drives Copilot for Sales / Service value |
| Source code repository coverage | Drives GitHub Copilot value |
Typical findings: 30-50% of use cases unidentified; ROI not modeled; persona prioritization absent.
| Check | Why It Matters |
|---|---|
| HIPAA BAA executed | Required for healthcare Copilot |
| FINRA Rule 3110 supervision program | Required for financial services Copilot |
| FedRAMP Moderate / High tenant | Required for federal Copilot |
| CMMC Level 2 readiness | Required for DoD Copilot |
| EU AI Act conformity assessment | Required for high-risk AI in EU |
| NIST AI RMF mapping | Required for federal alignment |
| ISO 42001 alignment | Voluntary but valuable for international |
| GDPR / CCPA / EU Data Boundary | Required for European tenants |
Typical findings: BAA execution status unverified; supervision program absent; NIST AI RMF mapping not started.
20-50 page document covering:
4 weeks fixed-fee, with optional 1-2 week extension for complex multinational or regulated-industry scenarios.
EPC Group fixed-fee:
EPC Group team:
Customer team:
For existing Copilot deployments, EPC Group offers a Copilot Health Audit instead — focused on adoption, governance, oversharing, and Microsoft Purview AI Hub posture. Same fixed-fee pricing.
Microsoft 365-anchored AI assessment (the default) covers Microsoft Cloud. For multi-cloud AI strategy (Microsoft + AWS Bedrock + Google Vertex), assessment scope expands. Mid-market multi-cloud: $80K-$120K. Fortune 500: $200K-$400K.
Yes. Healthcare (HIPAA), financial services (FINRA, SEC), government (FedRAMP, CMMC), pharma (GxP), and EU AI Act-regulated organizations are EPC Group's primary AI assessment customers.
Most clients proceed to a 90-day Microsoft Copilot Pilot Implementation ($150K-$350K fixed-fee) covering 50-200 users with measurable success criteria. Larger enterprises move to Enterprise Implementation ($400K-$1.5M) for full production rollout.
EPC Group senior architects with combined Microsoft 365, Microsoft Fabric, Microsoft Purview, Microsoft Defender, and AI governance experience. Errin O'Connor leads the practice.
Schedule a 30-minute AI Readiness Assessment scoping call at /schedule or call (888) 381-9725. Errin O'Connor or a senior architect takes scoping calls personally.
Related reading: Copilot for Microsoft 365 Complete Deployment Guide, Microsoft Copilot Governance Framework for Regulated Industries, vCAIO Services, AI Governance Framework Enterprise, and Enterprise AI Center of Excellence Microsoft Setup Guide.
CEO & Chief AI Architect
Microsoft Press bestselling author with 29 years of enterprise consulting experience.
View Full ProfileEPC Group's Governed AI on Microsoft framework unifies Microsoft Purview + Fabric + Power BI + M365 + Entra + Copilot + Agent 365 into a single integrated governance control plane. Six layers, four industry overlays, 29 years of regulated-industry Microsoft consulting.
AI GovernanceMicrosoft launched Sovereign Cloud with governance + productivity + AI capabilities even when disconnected. EPC Group implementation guide for US federal + state + local + DIB contractors. With FedRAMP + CMMC + ITAR + CJIS alignment.
AI GovernanceBehind-the-scenes methodology tour of how EPC Group built the 47-control M365 Copilot HIPAA governance framework. From 200+ deployments. Decision tree, control selection rationale, real-world tuning.
Our team of experts can help you implement enterprise-grade ai governance solutions tailored to your organization's needs.