Overall Readiness
Established
Confidence 50 to 56
Prepared for
Braeside & Carrick LLP
Professional Services
This is a real report from a previous engagement, anonymised for privacy. Your report will be tailored to your organisation’s specific data and context.
AI Readiness Report
Edition 1v2.11.1
Overall Readiness
Established
Confidence 50 to 56
Prepared for
Braeside & Carrick LLP
Professional Services
Dimensions
6 scored
Contents
8 sections
Click any section to jump
Professional Services
22 August 2026
Maturity Level: Established
Confidence range: 50 — 56
Confidential
Braeside & Carrick LLP scores 53 out of 100 on this assessment, which places the firm in the "Established" band. In plain terms, the foundations are in place but they are not yet joined up. The firm uses a good range of digital tools and has a clear sense of where it wants to go, yet the data sits in separate systems and a lot of work that could be automated is still done by hand. A score in the low fifties is a solid starting point. It says the firm is ready to build, not starting from scratch.
The strongest areas are use cases and strategy. The firm has a clear, well articulated view of the problems it wants to solve and the opportunities it wants to chase, which is rarer than it sounds. There is strong awareness of where data quality breaks down, good adoption of digital tools across the practice, and a reliable backup process is already in place. These are real assets. The firm knows its own pain points in detail and has already identified practical fixes, such as extending an existing tool that captures client records cleanly to more clients.
The gaps that need attention sit in data quality, people and skills, and governance, all of which score in the lower forties. The same client data is entered into several systems by hand, so no one can see a single complete picture of a client without checking four places. Confidence in the current tools is low, some essential tool categories are weak, and there is no dedicated owner for data. On governance, there is no policy covering staff use of AI and no related training, even though staff are already using AI tools informally for client work. This is the most pressing risk to address before it causes a problem.
The firm's most important goal is clear and time bound: getting through the April 2027 Making Tax Digital wave, when the threshold drops and the bulk of the firm's sole trader and landlord clients move to quarterly submissions, without hiring more admin staff. That deadline is in the future and it is fixed in law, which makes it a genuine forcing function. Almost everything in this report connects back to it, because the manual chasing and tracking that already strains the practice will not scale to four times the workload. To help the firm act at a pace and cost that suits its appetite, the recommendations are organised into three cumulative tiers, Essentials, Enhanced, and Accelerated, set across a 90-day and a 12-month horizon. The firm can start with the Essentials and step up as confidence and the business case grow.
Factors that boosted your score
Data backup process is in place
Data Quality
Strong awareness of data quality challenges
Data Quality
Good adoption of digital tools across the business
Technology
Factors that reduced your score
Low confidence in existing tools
Technology
Gaps in essential tool categories
Technology
Low overall technology confidence across the team
People & Skills
Your score is built from real data, not guesswork. Here’s how we turn your questionnaire responses and consultation insights into a clear, comparable measure of AI readiness.
Your questionnaire responses and consultation call provide the raw data we assess.
We score six dimensions of AI readiness, each weighted by importance.
Dimension scores are combined into a single 0–100 score using a balanced formula.
If any area falls below a safe threshold, your overall score is capped until it’s addressed.
Three different scales appear in this report depending on what is being measured:
Not all dimensions contribute equally to AI readiness. The weights below reflect what we consistently see drives readiness across organisations at different stages.
A simple average can hide a critical weakness. An organisation with excellent technology but poor governance would look healthier than it really is.
The weighted geometric mean penalises imbalance, so any single weak dimension pulls the overall score down honestly. It’s the same approach used in the UN Human Development Index.
In practical terms, the fastest way to lift your overall score is to address your weakest dimension rather than further improving an area where you already score well.
Your overall score includes a ±3 point margin to reflect natural variation in assessment responses. This is shown as a shaded range on your score circle. Any assessment is a snapshot. Small differences in how questions are interpreted could shift the result by a few points in either direction.
Braeside & Carrick LLP is an accountancy practice operating across four offices in central Scotland: Stirling, Perth, Falkirk, and Dunfermline. The firm dates back to the late 1980s and employs just under 80 staff. It is led by three equity partners and serves around 800 active clients. The client base is mostly sole traders (around 600), with roughly 200 landlords and 150 limited companies. The sole trader and landlord segments are the firm's main focus of concern ahead of the Making Tax Digital changes.
The firm runs a broad mix of digital tools, with good adoption across the business. Accounting and bookkeeping sit in Xero, Sage 50 for older clients, Dext for capturing records, and BrightPay for payroll. Practice management, including engagement letters and tax filings, runs through IRIS, which is hosted on a server in Stirling that is around six years old and maintained by a local IT provider on a retainer. The Microsoft 365 suite is in use, including Outlook, SharePoint, Teams, and Excel. A manually maintained Excel tracker acts as the master list for client records and status. Client relationship and marketing functions use HubSpot CRM and Mailchimp, the website runs on WordPress, and DocuSign handles signatures. Client data is spread across several of these systems, which the firm identifies as a core problem: no single system holds a complete view of a client. There is also informal, unmanaged use of AI tools, including ChatGPT on personal accounts and Microsoft Copilot paid for by one partner.
In terms of roles, the firm is led by three equity partners with split responsibilities across business services, tax, and audit and corporate clients. Day to day ownership of the client tracking spreadsheet rests with a senior manager in Stirling, though this is by default rather than a defined data role. No one in the firm formally owns data or systems as a responsibility, and there are no in-house developers or IT staff; technical support is outsourced to the external IT provider. The questionnaire and consultation indicate a need for clearer ownership of data and AI as the firm prepares for change.
A scan of all six dimensions. Click each tab for the score, top finding, and recommended next step. Click any signal to see the rubric and evidence.
Consolidate to one master client tracker
Consolidate to one master client tracker
Provision Microsoft Copilot on firm accounts
Deliver AI training to all staff
Issue interim AI use guidance to all staff
List remaining clients suitable for Dext
Productise a monthly advisory reporting pack
Braeside & Carrick LLP runs on a wide spread of capable software, but the firm's client data is scattered across at least six systems with very little joining them up. By the managing partner's own honest estimate, the data divides roughly as follows: Xero holds about 30% (live books for around 250 clients), IRIS about 20% (the practice management record), Sage 50 about 15% (legacy clients), SharePoint about 15% (client files), the Excel tracker about 10%, and Outlook inboxes about 10%. The last figure is the most telling: a tenth of the firm's working knowledge exists only in email.
The systems of record are IRIS, Xero and Sage 50, supported by an Excel tracker that has quietly become the operational heartbeat of the practice. The tracker carries one row per client and records who has sent records, what is missing and what has been filed. It is maintained largely by one senior manager and is the single most important, and most fragile, asset in the data landscape. Dext and BrightPay are bright spots: both are rated as working well and both feed the accounting systems automatically.
The firm also has two AI tools in informal use. ChatGPT is used by staff on personal accounts to draft client emails and explain tax rules, with no policy and a real risk that client details are being pasted in. Microsoft Copilot is used by a single partner on a personal licence. Neither is governed, and the organisation rightly views the AI its staff already use as a more pressing concern than any AI it might buy.
The firm has a small number of strong automated links and a large number of manual ones. Where automation exists, it works well. Dext feeds receipts and invoices straight into Xero with no typing, and BrightPay posts payroll journals into Xero through the Xero API. Teams and SharePoint are joined as standard. These connections show the firm can run clean, automated flows when the tools are wired together.
The problem is everything around the client record. A new client is typed into IRIS first, then again into Xero or Sage, then onto the Excel tracker, and sometimes a fourth time into HubSpot. None of these systems talk to each other, so the same client data is entered three or four times and small differences creep in. A spring mailing found that about one address in six was wrong in at least one system.
The most damaging manual flow is the chasing process. The knowledge of who has done their bookkeeping already exists inside Xero and Dext, yet a human reads it client by client and types the status into the spreadsheet. The Xero API could feed this automatically but is not connected. Client correspondence sits trapped in individual Outlook inboxes with no link to the central record. HubSpot and Mailchimp both hold contact data but are not synced, and website enquiries are not wired into the CRM.
The biggest single point of failure is the Excel tracker. It is understood in full by one person, it has no version control, and staff work from saved copies. In January, two staff chased from different copies and about forty clients were chased twice for records they had already sent, with at least one client quoting both reminder emails back to the firm. This is a clear data integrity and reputational risk that will only grow under Making Tax Digital, when annual returns become quarterly submissions.
Fragmentation is the second major risk. With no single client view, answering a simple status question can take half a day of cross-checking IRIS, Xero and the inboxes. The repeated manual retyping of client data guarantees that the three systems drift apart over time.
The informal AI use carries two distinct risks. The first is confidentiality: client financial details going into a free consumer tool on a personal phone, which the firm cannot reconcile with its professional duties or with ICAS guidance on AI and client confidentiality. Under the UK GDPR and the Data Protection Act 2018, enforced by the ICO, the firm is responsible for personal data even when staff use unapproved tools. The second is accuracy: a junior nearly sent a client an AI-written tax explanation that was confidently wrong, which would have put the firm's reputation and professional indemnity cover at risk had it not been caught at review. There is no AI policy and no training.
Finally, the firm keeps everything and has never deleted a client record, which sits uncomfortably with data minimisation and retention duties under the UK GDPR. The data processing agreements with software suppliers have never been reviewed as a set, and the firm is not sure whether it has an incident plan. The questionnaire flags that the organisation has requested GDPR guidance, which should be picked up during the consultation.
The clearest opportunity is to replace the manual chasing process. Xero has a full Accounting API that is available across all plans, so client record status can be pulled automatically rather than read and retyped by a person. This directly addresses the firm's top two goals: getting through the April 2027 Making Tax Digital wave without new admin staff, and automating the chasing and tracking of records. A staged approach can start with practice tools or Microsoft Power Automate connecting systems the firm already owns, building towards a single client status dashboard across the whole book.
Extending Dext is likely the cheapest single win. It already works well for around 200 clients and feeds Xero cleanly. Around 150 more clients, including many of the least digital landlords now in scope for April 2027, could be moved onto it, and every one becomes a client the firm stops chasing by hand.
Several other APIs sit available but unused. HubSpot and Mailchimp can be synced to stop duplicate contact lists drifting apart, and the firm should review whether it needs both for email marketing. Website enquiries can flow into HubSpot automatically. DocuSign can connect to SharePoint so signed engagement letters file themselves. On the AI side, the priority is governance before expansion: a written policy, an approved tool on firm accounts with understood data terms, and staff training, which the organisation has already said it would view as money well spent.
Two platform changes deserve attention. Sage 50 has no modern cloud API; consolidating its legacy clients onto Xero, which the firm rates highly and which has a full API, would remove a manual island. BrightPay's desktop product is being retired at the end of the 2025/26 tax year, so a move to the cloud version should be planned now rather than left to chance.
Braeside & Carrick LLP has a clear, well argued case for change and a genuine forcing function in the April 2027 Making Tax Digital wave, which pulls roughly 600 sole traders and 200 landlords into quarterly reporting. The firm knows what it wants and why, which is rare. The foundations that hold it back are practical: client data is scattered across IRIS, Xero, Sage 50, an Excel tracker and Outlook with no single view, skills and ownership of data are thin, and staff are already using consumer AI tools with no policy or training. In short, the ambition and direction are strong, while the day to day plumbing and controls need work before AI can be deployed safely. The per dimension breakdown below shows exactly where the strengths and gaps sit.
The firm has identified concrete, high value uses tied to real numbers. Automating the chasing process could reclaim roughly two full time staff and around fifty thousand pounds a year, the Xero data already held for 250 clients could power advisory work worth eight to fifteen thousand per client against an average compliance fee of eight hundred, and moving another 150 clients onto Dext is a cheap, immediate win. These are specific, costed opportunities rather than vague aspirations.
Strategy is anchored by a hard legal deadline rather than a wish list, with a sensible sequence of pilot this autumn, run properly by January 2027, and battle ready for the April 2027 wave. The goals are clearly ranked, MTD and chasing automation first, AI control next, advisory growth and partner time after, and the firm prefers fixing the biggest pain points first to prove value. The main open questions are an agreed budget and a clear decision making process at partner level, neither of which has been settled.
Digital adoption is broad, with Xero, Dext, BrightPay and DocuSign all rated as working well, and Dext already pulling clean records from 200 clients with no retyping. The weak points are an Excel tracker carrying 800 client rows as the practice heartbeat, an IRIS install on a six year old Stirling server that runs slowly over the VPN for remote offices, and tools like Sage 50, IRIS and HubSpot CRM flagged as a struggle. There is no written IT roadmap; support is reactive break-fix only.
The same client is entered by hand into IRIS, then Xero or Sage, then the Excel tracker, and small differences creep in between them. A spring mailing found around one in six addresses wrong in at least one system, and the firm has never deleted records, so files for clients who left ten years ago still sit on the server. Awareness of the problem is high, but there is no forcing function keeping records clean day to day.
Core hygiene is partly in place, with Cyber Essentials renewed for three years and MFA on Microsoft and Xero, but there is no password manager, no AI policy, and uncertainty over whether an incident plan exists or has ever been rehearsed. Data processing agreements with suppliers have never been reviewed as a set, retention is effectively keep everything forever, and the firm acknowledges it cannot currently meet recent ICAS guidance on AI and client confidentiality. Staff are pasting client details into consumer ChatGPT on personal accounts with no oversight.
Skills are patchy and concentrated. The senior manager who maintains the tracker is self taught and highly capable, and the younger intake pick up digital tools quickly, but a middle band of experienced accountants treat new systems as a threat and some quietly fear for their jobs. There is no training budget for data or systems; CPD spend goes on tax updates, and nobody has been on so much as an Excel course.
Braeside & Carrick LLP has a reasonable foundation of basic security controls but significant governance gaps that need attention before the firm scales up its use of data and AI. On the positive side, the firm holds Cyber Essentials certification (renewed annually for three years), has multi-factor authentication on Microsoft and Xero, and runs a cloud backup managed by its IT provider. These are solid building blocks. However, several core governance controls are either incomplete or absent. There is no AI usage policy and no AI training, despite clear evidence that staff routinely paste client details into free consumer AI tools on personal accounts. There is no password manager, no data retention policy (the firm has never deleted a client record), no reviewed set of data processing agreements with software suppliers, and uncertainty over whether an incident response plan exists or has ever been tested.
The overall level of risk is medium to high, driven mainly by uncontrolled AI use against a backdrop of highly sensitive client financial data. As an accountancy practice regulated by professional bodies, the firm carries confidentiality and professional indemnity exposure that the current informal AI practices directly threaten. A junior recently nearly sent a client an AI-written tax explanation that was confidently wrong. The firm itself has identified getting control of staff AI use as a priority and would view paid training as money well spent. The good news is that most gaps are common for an SME and are fixable with modest, practical steps. The firm also flagged that it needs GDPR guidance, which this report can help direct.
The transcript confirms the firm keeps everything and has never deleted a client record, including files for clients who left ten years ago. This conflicts with UK GDPR storage limitation expectations.
Neither the questionnaire nor the transcript references a published privacy notice. This should be confirmed during follow-up; under UK GDPR a notice explaining how client data is used is expected.
A data protection policy may exist, but its coverage is unconfirmed and the firm has asked for guidance in this area. The UK GDPR and Data Protection Act 2018 apply, enforced by the ICO.
Agreements were likely signed when each supplier (Xero, IRIS, Dext, the IT provider) was taken on, but nobody has reviewed them as a set. The managing partner was unsure.
There is no password manager. Staff manage their own passwords, with passwords kept on post-it notes and reused across systems.
MFA is enabled across all Microsoft services and Xero, confirmed in the consultation.
The transcript confirms Cyber Essentials held for three years, renewed annually with support from the local IT provider.
No staff have received AI safety training. Juniors taught themselves, which the firm recognises as the core problem.
No acceptable use policy is evidenced. The absence of any rules on personal-account AI use and shadow tool adoption indicates this control is not in place.
Neither source covers a documented offboarding or access removal process. With four offices and just under eighty staff this should be explored during the consultation.
There is no AI usage policy. Staff use free personal ChatGPT accounts for client work, with client details suspected of being pasted in.
Staff use consumer AI tools on personal phones with no approved firm accounts or data terms understood. The managing partner is fairly sure client names and numbers have already been entered.
It is unclear whether a formal incident response plan exists. The IT provider may hold something, but the firm has never rehearsed it and could not say what it would do in a ransomware event.
A cloud backup is in place, managed by the firm's IT provider. This is a clear strength, though the backups have not been tested with a restore exercise.
Most UK organisations processing personal data must register with the ICO and pay the annual data protection fee under the Data Protection (Charges and Information) Regulations 2018. Registration status is not evidenced and should be confirmed.
Client status is tracked in a manually maintained Excel spreadsheet with multiple saved copies, which caused duplicate chasing of about forty clients in January. There is no reliable single audit trail across IRIS, Xero, Sage and email.
The questionnaire references identity checks for money laundering rules as part of client onboarding, indicating sector compliance checks are performed, though tracked manually via email and memory.
Staff routinely use free personal ChatGPT accounts for client work and client details are suspected of being entered. With no policy, no approved tool, and no training, the firm cannot meet professional confidentiality guidance. This risks breach of client confidentiality, UK GDPR exposure and professional indemnity issues.
A junior nearly sent a client a confidently wrong AI-written explanation of a tax rule, caught only at review. If such output went out under the firm's letterhead it would threaten professional reputation and possibly PI insurance.
The firm is unsure whether an incident plan exists and has never rehearsed one. A ransomware event during peak season could leave the firm unable to respond, with no clear recovery steps and untested backups.
The firm has never deleted client records, holding data for clients who left ten years ago. This conflicts with UK GDPR storage limitation principles and increases the volume of sensitive data exposed in any breach.
Staff manage their own passwords, with reuse and passwords written on post-its. MFA reduces but does not remove the risk. A password manager is a low-cost fix.
Agreements with key suppliers have never been reviewed as a set. Gaps could leave the firm without a clear legal basis for sharing client data with processors, a UK GDPR requirement.
Client status sits across four systems and a manually maintained spreadsheet with multiple copies, which already caused duplicate client chasing. This weakens audit reliability and will not scale to the April 2027 Making Tax Digital wave.
The firm has requested GDPR guidance and key documents such as a privacy notice are not evidenced. Without clear documentation the firm cannot demonstrate accountability to the ICO.
The master tracking spreadsheet is understood fully by only one senior manager. Absence creates operational and continuity risk, illustrated by the January duplicate-chasing incident.
The IRIS server is about six years old, maintained reactively by the IT provider with nothing written down. This is a monitoring item rather than an immediate governance failure.
Braeside & Carrick LLP knows what it wants and why. The firm scores well on strategy (66) and use cases (80), which means the goals are clear and the business problems are real. The gap is in the foundations that support those goals: data quality (44), people and skills (42), and governance (43) all sit in amber. The route to each goal runs through those weaker foundations, so the order of work matters.
This is your prioritised action plan, grounded in your consultation and questionnaire responses. Every item is specific to your business: real systems, real processes, costed against typical SME pricing. The plan is sequenced into three phases that build on each other.
Quick Wins · Weeks 1–2
Low-effort, low-cost moves you can start this week. No procurement, no committee, no new headcount.
90-Day Plan · Weeks 3–12
Foundational improvements that deliver measurable gains within a quarter, with modest budget and a small project team.
12-Month Plan · Months 4–12
Strategic investments, system integrations, training programmes, and longer transformations that need time to land.
How to use it. Tick each action as you commit to it. The dashboard updates live to show your projected readiness score, which dimensions move most, and how the gains compound across phases. Tools, indicative costs, and timelines sit on every action. Your selections save automatically and follow you across devices, so you can return to this plan as you make progress.
Dimension radar
Per-dimension projection
Overall
baseline 53
Projected lift
vs today
Actions ticked
0% complete
Quick Wins · Weeks 1–2
Immediate, low-cost steps to contain AI risk, test backups, and stop the duplicate-chasing problem within two weeks.
90-Day Plan · Weeks 3–12
Foundational governance, security, and data work to reduce risk and prepare for the MTD automation build.
12-Month Plan · Months 4–12
Strategic build of the automated client-chasing dashboard, staff training, and infrastructure work to meet the April 2027 MTD deadline.
Quick Wins · Weeks 1–2
Immediate, low-cost steps to contain AI risk, test backups, and stop the duplicate-chasing problem within two weeks.
Costs shown are indicative ranges based on typical SME pricing at time of assessment. They do not constitute a quotation. Actual costs will vary based on the firm's specific requirements, chosen suppliers, and implementation approach.
A scannable view of the schemes most likely to apply to your business. Money and eligibility confidence are front and centre. Tap any row to see why it is relevant and how to act.
Funding index. High and medium relevance only. Indicative figures.
HM Revenue & Customs
Consultant summary
Braeside & Carrick LLP is a Stirling-based accountancy practice with four offices and just under eighty staff, serving around eight hundred clients across central Scotland. As a Scotland-based small to medium enterprise, the firm can access a strong layer of devolved funding aimed at digital adoption, AI readiness and innovation, alongside UK-wide tax reliefs that reward investment in technology. The most useful schemes for the firm are the discretionary capital and AI readiness grants delivered by Scottish enterprise agencies, which are well suited to the kind of staged, practical project the firm is planning ahead of the April 2027 Making Tax Digital wave.
The firm's location matters for eligibility. Stirling, Perth, Falkirk and Dunfermline sit in central Scotland, which is the Scottish Enterprise area rather than the Highlands and Islands or the South of Scotland. This affects which regional agency the firm can approach directly. Several of the listed tax reliefs apply automatically to UK companies and partnerships and are worth claiming where qualifying spend or innovation exists, although note that a limited liability partnership has a different tax position from a limited company for some reliefs. The schemes are ranked below by how well they fit the firm's plans and structure.
Important: not financial advice
This section is provided for information only and does not constitute financial, tax, legal, or investment advice. The schemes above were publicly advertised at the time this report was generated. Eligibility criteria, deadlines, and award amounts may change without notice, and headline figures are indicative only.
Do not commit any company resource (time, money, or staff) on the basis of this report alone. Before pursuing any scheme, the company must carry out its own due diligence: confirm current eligibility directly with the scheme administrator, and take advice from a qualified accountant, tax adviser, or solicitor as appropriate.
Apex Insights cannot be held responsible for any loss, cost, or decision arising from reliance on the information in this section.
Reference material for this report. Use the deep-dive page for the full scoring methodology.
No external benchmarks or third-party audits are used. Every claim in this report is grounded in the data above.
For a full explanation of how scores are calculated, including the 64 signals, weights, geometric mean formula, and gate system, see the dedicated deep-dive page.
Read how the model worksYour report will be built from your organisation’s actual data and context, not this sample.
You stay anonymous on this site.
We count visits only to help us improve it. No tracking or advertising cookies, and we never identify you or follow you to other sites. Cookie Policy