How a data licensing inventory doubles as an AI data readiness assessment
An AI data readiness assessment checks whether a company's records can be found, exported, legally used and safely handled for AI work. Data licensing preparation covers the same ground, so the system map, inventory and rights review a client completes for SourceX also give a fractional COO a documented baseline for the client's own AI plans.
What does an AI data readiness assessment check?
An AI data readiness assessment answers four questions about a company's records: what exists, whether it can be exported, whether the company may use it, and where sensitive material sits. Data licensing preparation asks exactly the same questions, which is why the system map, inventory and rights review a client completes for SourceX double as an AI-readiness baseline.
For a fractional COO the overlap is practical. You are hired to fix how work flows, and every AI conversation the CEO starts eventually stalls at the same point: nobody knows where the operating history lives or who is allowed to use it. Doing that groundwork once, properly, serves both purposes.
| Readiness question | Licensing preparation artifact | What the client keeps |
|---|---|---|
| Where does our operating history live? | System map covering current, retired and acquired systems | One list of every tool that holds work records |
| How far back does it go? | Years of history recorded per system | A view of which processes have long, usable records |
| Can we get it out? | Export test run by the system admin | Known gaps before an AI project depends on them |
| Are we allowed to use it? | Rights review of contracts, notices and policies | Clarity on client-owned and contractor-created material |
| What is sensitive? | Redaction and de-identification requirements, agreed before any work begins | A first register of sensitive data |
| Who decides? | A named authorized sponsor | A governance owner for data decisions |
What you need before you start
Gather these before the first working session. Most come from people you already meet during a COO engagement.
- A sponsor: the owner, CEO, CFO or another authorized representative who can approve data decisions.
- The admin list: who holds administrator access to each system, whether internal IT or the company's MSP. They run exports; you do not.
- Software spend history: several years of software and subscription invoices from accounts payable, which reveal tools the current team has forgotten.
- The contracts folder: standard customer terms, major client MSAs, vendor agreements, the employee handbook and contractor agreements.
- Privacy notice and terms of service: the current versions and, where archived copies exist, earlier ones.
- Headcount history: licensing requires 50+ full-time employees at peak (contractors excluded), while a readiness assessment is useful at any size.
How to run the assessment, step by step
- List every system that has held work records. Start with email, Slack or Teams, shared drives, CRM, ERP and finance, ticketing, engineering tools, project management and call recording. Add retired tools found in the invoice history and the systems of any acquired businesses. Strong companies often reach 10-15 or more.
- Record depth and ownership for each system. Note the earliest year of records, rough scale, the business owner of the process and the technical admin. Leave the contents alone: the inventory describes systems, not records.
- Ask the admin to test two exports. Pick the oldest system and the busiest one. A pass means a complete export in a usable format with dates and metadata intact; a fail means the history is effectively locked.
- Trace the rights. Separate what the company created from what belongs to clients or partners. The Copyright Office's circular on works made for hire explains that when employees create a work as part of their jobs, the employer is its author and owner, while commissioned work counts only in listed categories and with a signed written agreement, so contractor material may not be the company's unless it was assigned in writing. Then check what the privacy notice and customer terms promised: FTC staff warned in a February 2024 post that quietly and retroactively changing terms to allow uses such as AI training may be unfair or deceptive.
- Flag sensitive categories. Mark systems heavy in consumer personal data, protected health information, payment data or call recordings, and note where recording notices were given.
- Score each system with the table in the next section, then write a one-page summary for the sponsor.
- Split the follow-up into two tracks: internal AI use cases the client wants to build, and a licensing screen if the company meets the baseline. For the gaps buyers care about, see the work that is missing from AI training data.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before relying on a rights conclusion.
How to score and use the results
| Score | What it means | Next action |
|---|---|---|
| Green | Several years of company-created records, a passing export and a known admin | Use as the foundation for AI projects and include it in a licensing screen |
| Amber | Good history but an untested export, unclear contract terms or mixed ownership | Fix the specific gap: run the export, ask counsel about the clause, separate client material |
| Red | Records deleted, locked in a cancelled tool, mostly client-owned or mostly consumer personal data | Exclude from licensing and decide whether to preserve what remains for internal use |
| Retiring | A system scheduled for shutdown or migration | Preserve a complete export before the cut-over date, whatever its other scores |
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Listing only the tools in use today | The deepest history usually sits in retired systems | Reconcile the list against several years of software invoices |
| Assuming data that exists can be exported | Some tools make bulk exports slow, partial or costly | Test exports before anyone plans around the data |
| Assuming the company owns everything in its systems | Client deliverables and contractor work may belong to others | Review client contracts and contractor agreements |
| Leaving the assessment to IT alone | IT knows where data sits, not what the business promised | Pair the admin with the sponsor and whoever owns contracts |
| Cancelling old tools to cut costs mid-assessment | History disappears with the subscription | Freeze cancellations until exports are preserved |
| Pasting sample records into the report | It spreads confidential material and adds risk | Describe systems, years and counts only |
Illustrative example: a 140-person engineering firm
Illustrative and fictional. A fractional COO joins a 140-person civil engineering firm to tighten project delivery, and the CEO also wants an AI plan. Over four working sessions the COO and the firm's MSP map 14 systems, including a project-tracking tool retired three years earlier but still billed monthly as a read-only archive.
The export test passes for email and the document system but fails for the old tracker, which exports only open projects. The rights review shows that drawings and reports delivered to clients are governed by client contracts, while internal QA checklists, RFI logs and lessons-learned notes were written by employees in their jobs.
The outcome is a two-track plan: an internal search tool over the QA and RFI history, and a licensing screen for the company-created records. The archive subscription stays active until the vendor delivers a full export.
Bringing SourceX in after the assessment
If the client meets the baseline of 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license its records and an authorized sponsor, your groundwork shortens the path. You introduce the company through your referral link or the referral form. SourceX then qualifies it, the company completes its own data inventory, price and terms are agreed with the company, and AI labs and data buyers review the opportunity only after that. Your readiness map gives the client a head start, and you never export or describe the records themselves. How it works sets out each stage, and the fractional COO partner page covers when to raise the topic in an engagement.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward becomes payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. Check your engagement letter and any conflict terms before accepting a referral reward connected to a client.
Next step
Run the six readiness questions with your next client, then test fit with the company fit checker. When a client passes, register as a partner and make the introduction. For the audit side of the work, see what a data audit is; for the questions the CEO is likely to ask next, keep the client question bank to hand.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is an AI data readiness assessment the same as a data audit?
They overlap but differ in purpose. A data audit usually checks quality, accuracy or compliance within specific systems. A readiness assessment asks a broader question: can the company find, export, legally use and safely handle its records for AI work. The licensing-style version adds a rights review and an export test, which many audits leave out.
Does a client have to license its data to benefit from the assessment?
No. The system map, export tests, rights review and sensitive-data register are useful on their own for an internal AI project, a system migration or exit preparation. Licensing is a separate decision for companies that meet the baseline and want to explore it, and nothing is binding until the company agrees price and terms and signs.
Who should own the assessment inside the client company?
Give it a business owner and a technical owner. The sponsor, an owner or executive with authority over data decisions, owns the conclusions; the system admin or MSP owns exports and access. A fractional COO coordinates the work, keeps the inventory current and makes sure contracts and privacy promises are reviewed by whoever handles legal matters.
How often should the inventory be refreshed?
Refresh it whenever a system is added, retired or migrated, and review it at least once a year during planning. The most important trigger is a planned shutdown: once a tool is cancelled without a full export, its history is usually gone. Tie the review to the software renewal calendar so retirements are caught before contracts lapse.
Does the fractional COO see the client's records if the company licenses its data?
No. As a referral partner you make the introduction and share basic fit information only. The company works directly with SourceX on its inventory, rights review and redaction rules, and records are delivered only after an executed agreement and the company's authorization. Keep your readiness report at the level of systems, years and counts.
Related pages
Free resources
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment