Dealer AI Guy Diagnostic
The Dealer AI Readiness Checklist
A 114-check diagnostic across 17 sections of dealership operations. Score each item red, yellow, or green to see whether the store is AI-ready, pilot-ready, or still needs foundation work.
The honest rule: if you are not sure, score it red. The point is to find the holes before a vendor demo makes everything look easy.
No login, no upload, no hidden form. Your score is stored in this browser only.
Why this checklist exists
Most dealer AI projects do not underperform because the AI is weak. They underperform because the dealership foundation is weak: messy data, slow websites, unclear ownership, loose governance, and workflows nobody can inspect on Monday morning.
This checklist is the diagnostic to run before buying another AI tool. It covers the boring foundation and the operational reality: data, website, AI visibility, compliance, BDC, sales, F&I, fixed ops, marketing, inventory, accounting, HR, governance, workflows, training, measurement, risk, and roadmap.
How to score
Green = 2 points. True today. Verified. Documented. Someone owns it.
Yellow = 1 point. Partly true. Working but inconsistent, undocumented, or dependent on one person.
Red = 0 points. Not true, unknown, or assumed with no proof.
Readiness bands
80% to 100%: AI-ready. Move on offense.
60% to 79%: Pilot-ready. Pick one workflow and baseline it.
40% to 59%: Foundation first. Fix the weak spots before buying.
Below 40%: Rebuild the base. Triage the foundation.
0 of 114 checks scored
Running result
Start scoring below
Your readiness band and weakest sections will update as you score the checklist.
Part 1
Foundation
Section 1
Data foundation
Before AI can help, the store has to know what data it has, where that data lives, and which of it is trustworthy.
Inventoried systems
The store has a written list of every system that holds customer, lead, vehicle, financial, or operational data. DMS, CRM, website platform, inventory feed, chat tool, call tracking, texting platform, F&I menu, service scheduler, payroll, accounting, parts catalog. If a manager cannot name the systems on a notecard, this is red.
Data ownership
Each system has a named human owner inside the dealership. Not the vendor. Not "whoever set it up." A named person who can grant access, kill access, and answer questions about the data inside.
Data quality baseline
Someone has run a duplicate check, a stale-record check, and a missing-field check on the CRM and DMS in the last ninety days. The store knows what percentage of records are usable.
Integration map
The store knows which systems talk to which other systems, in which direction, and whether the integration is API-based, file-based, or manual copy-paste. If two managers give different answers to "how does our chat tool send leads to the CRM," this is red.
DMS data access rights
The store has reviewed its DMS contract and knows what it costs and how long it takes to give a third-party AI vendor read or write access to its own data. This matters because some legacy DMS contracts treat dealer data as something the dealer has to pay to access. The CDK-Reynolds antitrust litigation made this a public issue. The lesson is the same regardless of vendor: know the cost of moving your own data before you need to move it.
Customer data segmentation
The store can identify, in the CRM and DMS, which records contain financial information protected under the FTC Safeguards Rule and which do not. AI vendors that touch protected data are governed differently from AI vendors that do not.
Section 2
Website technical foundation
This is the closest thing to an antenna in your dish. If the signal cannot leave the building, nothing else matters.
Crawlability and indexability
Inventory, SRP, VDP, service, finance, and location pages return a 200 status code, are not blocked by robots, and appear in Google Search Console as indexed. Run a coverage report. If half the VDPs are excluded, this is red.
Page speed for humans and machines
Core Web Vitals pass on mobile for the home page, an SRP, a VDP, and the service page. Slow pages do not just lose customers. They get crawled less often, which means AI search engines see a stale version of your store.
Structured data is correct, complete, and stable
AutoDealer schema on the home page. Vehicle schema with VIN, price, availability, and mileage on every VDP. LocalBusiness schema with the same NAP everywhere. Service schema on the service page. FAQPage schema on pages with real Q&A. If schema breaks every time the inventory feed updates, this is red.
NAP consistency
Name, address, and phone are identical on the website, Google Business Profile, OEM locator, Facebook, Apple Maps, and the top ten directories. AI engines treat inconsistency as evidence that the entity is not real.
Differentiation content
Every primary page explains why this dealership, not just what is on the lot. The "why us" answer is on the home page, the about page, and the service page. If the home page only lists inventory and a phone number, the AI has nothing to cite.
Internal search hygiene
Internal site search works, returns results, and does not generate hundreds of crawlable thin pages that dilute authority. Faceted navigation is controlled.
Site speed monitoring
Someone watches Core Web Vitals weekly. Regression triggers an action. If the site got slower after the last platform update and nobody noticed, this is red.
Section 3
AI visibility and answer engine readiness
This is the section most stores fail without knowing it. Customers are asking ChatGPT, Perplexity, Gemini, and Copilot which dealer they should buy from. The store that does not appear in the answer does not exist for that buyer.
The store appears in answer engines for its core queries
Test ten queries by hand. "Best GMC dealer near [city]." "Where to get a Sierra serviced in [zip]." "What dealer in [metro] has the most Yukons." If the dealership is missing or misrepresented, this is red.
Brand-name accuracy in AI responses
Ask AI engines about the store by name. Confirm hours, address, brand portfolio, and key staff are correct. AI engines inherit bad data from old directories and OEM tools, so this needs to be checked, not assumed.
llms.txt is published and curated
The site has an llms.txt file at the root that gives AI engines a curated map of the most important content. Not every engine reads it yet. The ones that do lean on it heavily.
AI crawlers are not blocked from public content
Robots.txt does not blanket-block GPTBot, ClaudeBot, PerplexityBot, or Google-Extended unless that block is deliberate and approved by a manager. Many sites block AI crawlers by accident through a platform default.
Entity reinforcement across the web
Google Business Profile, Yelp, BBB, OEM locator, Apple Maps, Bing Places, and the top ten relevant directories carry the same facts the website carries. AI engines triangulate. They trust facts that appear in many trustworthy places.
Review velocity and breadth
The store has fresh reviews on Google, Yelp, DealerRater, and Cars.com that arrive on a regular cadence, not in suspicious bursts. AI engines weight recent reviews more than old ones.
Wikipedia-class third-party citations
The dealer principal, the rooftop, or the store is mentioned on at least one high-authority third-party source. Local newspaper, OEM press release, industry trade publication, chamber of commerce. ChatGPT pulls roughly half its top citations from encyclopedic and editorially-published sources, so this matters more than people think.
Conversational content on key pages
The buying-help and service-help pages answer real customer questions in plain language. "Do you take trade-ins with negative equity." "How long does a tire rotation take." "Can I bring my own financing." AI engines extract sentences. If the page only contains marketing copy, there is nothing to extract.
Section 4
Security, privacy, and compliance
AI without governance is a lawsuit waiting for a trigger. This section is where you stop the bleeding before it starts.
Written information security program
The store has a current, written information security program under the FTC Safeguards Rule. Not a template printed three years ago. Current. Reviewed in the last twelve months. Signed by the qualified individual.
Multi-factor authentication everywhere
MFA is enforced on every system that touches customer information, including DMS, CRM, email, and any AI tool that handles customer data. Username and password alone is a Safeguards Rule violation on day one.
Vendor risk reviews
Every AI vendor has been through a vendor risk review that documents what data they access, where they store it, who their subprocessors are, and what happens to the data if the dealership cancels. If the answer is "I think they use AWS," this is red.
Penetration testing and vulnerability scanning
Annual third-party pen test for stores with more than 5,000 consumer records. Vulnerability scanning at least every six months. Findings get remediated, not filed.
Breach notification readiness
The store knows it must notify the FTC within thirty days of discovering an unauthorized acquisition of unencrypted information affecting five hundred or more consumers. There is a written playbook for who calls whom.
OFAC sanctions screening
Every deal runs OFAC screening, and records are retained for ten years, not five. The retention requirement extended in March 2025 under the 21st Century Peace through Strength Act.
State AI law exposure mapped
The store knows which state AI laws apply to its operations and out-of-state customers. The Colorado AI Act is the headline example. It applies to anyone doing business with Colorado residents who uses automated decision-making technology that materially influences financial or lending decisions. It takes effect January 1, 2027.
Adverse action and human-review playbook
Where AI influences a financial decision, the store can produce a notice to the consumer, an explanation of the AI's role, and a process for meaningful human review on request. This is becoming table stakes for any AI that touches credit, leasing, or insurance.
Customer-facing AI disclosure
When a customer is talking to an AI agent, they know it. The disclosure is in the script, in the chat header, or in the SMS opt-in. Pretending the AI is a human is a fast path to a consumer protection complaint.
Free-tool data leakage policy
Employees know not to paste customer information, deal sheets, or proprietary pricing into free public AI tools. There is a written policy and a sanctioned tool for the work people would otherwise do in ChatGPT.
Part 2
Operational readiness
Section 5
BDC and customer contact center
The BDC is the highest-leverage AI deployment in most stores, because it touches volume the human team is already missing.
Missed-call baseline measured
The store knows how many calls it misses per week and what percentage of callers hang up during business hours versus after hours. Most stores miss three hundred to five hundred calls a week and do not know it.
First-response time baseline measured
The store knows the average response time on inbound web leads, chat leads, and SMS leads, broken out by hour of day and day of week. If the answer is "fast," this is red.
Appointment set rate baseline measured
The store knows its current appointment set rate on inbound calls and inbound web leads, by source. A typical human BDC sets thirty to forty percent of qualified inbound calls. AI voice agents are reporting set rates substantially higher than that in real deployments, but the only way to know if it will work in your store is to measure where you are.
Hand-off rules are written
The team knows exactly when AI hands the call to a human, when a human takes over a chat, and when a deal must touch a manager. Hand-off rules live in writing, not in someone's head.
Voicemail and after-hours coverage
Every after-hours inbound call gets either an AI conversation or, at minimum, a tracked voicemail that triggers a callback. If after-hours calls vanish, this is red.
Call tracking and conversation intelligence
Every inbound and outbound call is recorded, tracked, and tagged. CallRail or equivalent is properly configured. Calls flow back into the CRM with the right attribution. AI cannot improve a function that is not measured.
Outbound calling discipline
Outbound calls are made on a schedule with a defined cadence. AI is used to support the cadence, not replace it. The team knows the difference between "I called once and they did not answer" and "I made five attempts across three channels."
SMS compliance
The store has explicit opt-in for every number it texts, the carrier registration is current, and the texting platform produces audit-ready logs. AI that texts a customer without proper opt-in is a TCPA exposure.
Section 6
Variable operations: sales and F&I
Variable ops is where AI can lift gross. It is also where AI can incinerate a deal if the governance is weak.
Inbound lead routing is deterministic
The store knows which leads go to which salesperson, in which order, with which fallback. Routing is in the CRM, not in a spreadsheet on someone's desktop.
Quote and price discipline
Salespeople and any AI agent quoting price follow the same pricing rules. The store has a single source of truth for price, payment, and incentives. The AI is not free-handing numbers based on the inventory feed and an old rebate.
Trade evaluation workflow
Trade appraisals follow a documented workflow with photos, condition notes, and ACV ranges. If AI is used to pre-appraise online, the result is clearly framed as an estimate, not a binding offer.
Deal jacket discipline
The deal jacket is digital, structured, and gated. OFAC, red flags, stip collection, and licensee verification are required fields. The jacket cannot move to the lender until the gates are green. AI is used to validate, not to skip the gates.
F&I menu consistency
Every customer is presented the menu the same way. The store can produce documentation of menu presentation. AI is used to personalize the offer, not to vary the menu in ways that create disparate-impact exposure.
Adverse action notices
Adverse action notices are produced automatically, on time, with the correct reasons. If a credit decision was AI-assisted, the notice and the audit trail reflect that.
Stipulation collection automation
Stips are collected through a digital workflow with automated reminders. The store knows its current stip kick rate. The industry average runs around fifteen percent. If the store does not know its kick rate, this is red.
Equity mining is real and current
The store runs equity mining on a defined cadence, against fresh DMS and credit-bureau data, with multi-channel outreach. SMS plus email plus voicemail outperforms email alone by roughly two to one on contact-to-trade rate. If equity mining is an annual project, this is yellow at best.
Sales-to-service handoff
New sold customers are introduced to service through a defined workflow, with a first-service appointment ideally scheduled before they leave the lot. AI handles the reminders. Humans handle the introduction.
Section 7
Fixed operations: service and parts
Service and parts contribute roughly half of total dealer gross profit. AI here pays for itself faster than almost any other deployment, but only if the workflow underneath is clean.
Appointment booking is digital, accurate, and consistent
The customer can book online, by phone, by text, and in person. Every channel returns the same available slots. Conflicting channels are the single most common reason service AI underperforms.
Loaner and shuttle logistics integrated
The booking workflow knows whether a loaner is available, whether a shuttle is needed, and what the customer prefers. AI cannot rescue a booking process that hides this from the customer until check-in.
Multi-point inspection completion is measured
The store knows its current MPI completion rate. Many stores baseline around sixty-five to seventy-two percent. A photo-required MPI workflow can lift that into the mid-nineties within sixty days. Every missing MPI is upsell that did not happen.
Declined service is captured in writing
Declined work is logged in the RO, by line item, with the dollar value and the reason. If declined work is only a verbal note from the advisor, this is red. AI cannot recover what it cannot see.
Declined service recovery sequences are running
Thirty, sixty, ninety, and one hundred twenty day follow-ups are automated. Industry data suggests properly run sequences recover north of twenty percent of declined revenue. If recovery is a quarterly "let's send an email blast," this is red.
Recall and service campaign outreach is automated
OEM recall data flows into a workflow that texts and emails affected owners on a cadence, with clear booking links. The customer is told what the recall is in plain language. AI handles the volume. Humans handle the exceptions.
Status updates to the customer
While the vehicle is in the shop, the customer receives proactive status updates by text. The customer does not have to call the advisor to find out what is happening. AI is a strong fit for this, and customer satisfaction lifts measurably when it is in place.
Service-to-sales conversion workflow
Service customers who are in an equity position or whose vehicle is approaching a major repair are flagged for a service-to-sales conversation. The conversation is structured, scripted, and consented to. AI does the identification. A trained service-to-sales rep does the conversation.
Parts inventory accuracy
Parts on-hand counts in the DMS match physical reality. AI-driven parts forecasting cannot help a store whose perpetual inventory is wrong by twelve percent.
Section 8
Marketing and demand generation
Marketing AI is where most dealers buy first and govern last. This is the inverse of what should happen.
Conversion tracking is correct end-to-end
Google Ads, Facebook, and any other paid channel report conversions that match what the CRM and DMS see, within a defined tolerance. Enhanced conversions are configured. Offline conversion import is live where the channel supports it. If the marketing dashboard says one thing and the CRM says another, every AI optimization is downstream of a lie.
Call tracking is fully wired
Every paid channel feeds a unique tracking number. Calls flow back into the CRM with source attribution. Call outcomes flow back to the ad platform. CallRail or equivalent is correctly configured. AI bidding without offline conversions is paying full price for half the picture.
Audience strategy lives off owned data
The store has built and refreshes customer audiences from DMS and CRM data for use in retargeting, suppression, and lookalike modeling. Buying audiences off cold third-party data while your owned list rots is the single most common waste in dealer marketing.
Creative production has guardrails
Generative creative for ads, social, and email follows brand standards, OEM compliance rules, and a human review before publishing. The store has a policy on AI-generated images of vehicles, especially around trim representation.
Email and SMS lists are clean
Bounce rates, opt-out rates, and complaint rates are inside healthy ranges. Suppression lists are honored. AI cannot rescue a list that is being throttled by carriers and mailbox providers.
Landing pages match ad promises
Every paid campaign points to a landing page that delivers what the ad promised, with the right offer and the right form. AI ad spend optimizing toward a broken landing page is expensive arithmetic.
Performance reviewed weekly with a written decision rule
Someone reviews the numbers every week and the store has a written rule for when a campaign expands, gets fixed, or gets killed. AI accelerates whichever pattern you already have.
Section 9
Inventory and merchandising
The VDP is where the buying decision is made. AI gives merchandising leverage that did not exist three years ago.
Acquisition-to-online lag is under twenty-four hours
From the moment a unit hits the back lot to the moment it is live online with photos, description, and price is under one business day for the front-line vehicles. AI photo enhancement and AI description writing make this possible. If the lag is a week, this is red.
Photo standards are consistent
Every front-line vehicle has the same photo set: exterior angles, interior, dashboard, odometer, key features, and damage photos where applicable. AI background normalization is acceptable. Faking trim details is not.
VDP descriptions are unique and conversational
Every VDP has a description that reads like a human salesperson explaining the vehicle to a specific buyer, not a feature dump. AI generates the draft. A human edits for accuracy. Cookie-cutter descriptions are invisible to AI search.
Pricing strategy is documented and consistent
Pricing methodology, market positioning, and discount strategy are documented. AI tools that adjust price are governed by the methodology, not the other way around.
Aging policy is enforced
The store has a written aging policy and someone owns it. Units past the threshold get a defined action, not a shrug.
Trade reconditioning workflow
Reconditioning has a defined time standard, a defined cost standard, and a defined approval path. AI cannot fix a recon process that takes fourteen days because nobody is watching it.
Section 10
Accounting and back office
This is the least glamorous section and the one with the highest ROI per dollar of effort.
AP invoice intake is digital
Vendor invoices arrive at one address, get captured with OCR, get matched against POs, and get routed for approval. AI exception handling is in place. If invoices arrive by fax to a single person's inbox, this is red.
Fraud detection on AP
Duplicate-payment detection, unusual-pattern detection, and vendor-master-change alerts are active. AI is now table stakes for this. Manual review alone is not.
Reconciliations are timely
Bank reconciliations, schedules, and balance sheet reconciliations are current. The store does not close the month with stale recs and an aspirational adjustment.
Floor plan and OEM rebate tracking is automated
Floor plan curtailments and OEM money are tracked in real time, not at month-end. AI can surface anomalies if the data is clean.
Audit trail is intact
Every system change, every approval, every override is logged with user and timestamp. If an auditor asks who approved a journal entry in June, the system has the answer.
Section 11
HR, workforce, and culture
AI changes the job. The store has to change the management around it.
Job descriptions reflect the AI-augmented reality
Roles that now work alongside AI have job descriptions that say so, with the skills and expectations updated.
Compensation plans are not at war with AI
If the BDC pay plan rewards human-set appointments and penalizes AI-set appointments, the team will sabotage the AI. Fix the plan first.
Training cadence is real
New tools come with onboarding, role-specific training, and a refresher cadence. Not just a vendor demo on launch day.
Internal communication is open about AI
Leadership has explained to the team what AI is doing, what it is not doing, and how it changes the work. The team is not finding out about new AI tools from the customer.
Hiring profile updated
New hires are screened for comfort with AI-assisted workflows. Technical literacy is part of the rubric.
Part 3
Organizational readiness
Section 12
Governance and vendor management
Every AI vendor either makes the store safer or makes the store more exposed. There is no neutral option.
AI vendor inventory
The store has a written list of every AI tool in use, who owns it, what data it touches, what it costs, and when the contract renews.
Data processing agreements signed
Every vendor that touches customer information has a current data processing agreement. Subprocessors are disclosed. AI training rights are addressed in writing.
Permissions follow least-privilege
Each AI tool has access to the minimum data it needs to do its job. Not more.
Cancellation terms are known
The store knows what happens to its data if it cancels each AI vendor and how long it takes to get the data back in a usable form.
Reporting and proof of use
Each AI tool produces evidence of what it did, on what customer, with what result. If the only proof is the vendor's own dashboard, that is yellow. Independent verification is green.
Brand-voice and compliance review
Customer-facing AI output is reviewed against brand voice, accuracy, and compliance standards on a defined cadence. Spot checks are documented.
Kill switch
The store has a documented, tested process to disable any AI tool within one business day if it misbehaves.
Section 13
Workflow design and process architecture
AI without a workflow is a toy. AI inside a workflow is an asset.
First use case attached to a real operational problem
The first deployment solves a measurable pain. Missed calls. Slow response. Declined service. Not "let's try AI."
Named workflow owner
A specific human owns the workflow. Not "the marketing team" or "the BDC." A person, with a job title.
SOP is short enough to train
The standard operating procedure fits on one page and a new hire can run it in week one. Long SOPs do not get followed.
Human takeover point is defined
The team knows exactly where the human takes over from the AI. The transition is invisible to the customer.
Exception path is defined
When the AI does not know, where does it go. The exception path is faster than the default path. Otherwise the team routes around it.
Decision log
Changes to the workflow are logged with date, change, owner, and reason. The store can answer "why did we change the script in March" three months later.
Section 14
Staff training and change management
The store that trains wins. The store that buys does not.
Managers can coach the workflow
Department managers understand the AI workflow well enough to coach a struggling team member on it. Not just escalate to a vendor.
Employees know what AI cannot do
The team knows the AI's limits, not just its capabilities. They know when to escalate.
Customer-facing talk tracks exist
Salespeople, advisors, and BDC reps have language for "yes, that was our AI, here is how I can help further." Customers are not confused.
Privacy and accuracy expectations are taught
Training covers what data the AI sees, what it should never see, and how to handle a customer who is uncomfortable.
Refresher cadence is on the calendar
Training is not a one-time event. It is on the calendar quarterly at minimum.
Section 15
KPI architecture and measurement
Most AI projects fail in the measurement, not the technology.
Baseline measured before launch
The store has a measured baseline for every metric the AI is supposed to move. Without a baseline, every result is a story.
Three to five KPIs per workflow
Not twenty. Response time, set rate, show rate, sold rate, RO count, declined recovery, visibility lift. Few and weighty.
Weekly review during pilot
The numbers get reviewed weekly during the pilot window, not at the end. Pilots that hide their metrics never end.
Written decision rule
Before launch, the team writes down what success looks like, what failure looks like, and what triggers expansion, fix, or kill.
Attribution is clean
The store can isolate the AI's contribution from background changes in the market. If sales went up but ad spend also went up, the AI is not the reason.
Section 16
AI risk management and incident response
The store that has not thought about what could go wrong is the store that finds out in public.
Risk register
The store has a written list of the top AI risks it faces. Wrong price quoted. Customer info leaked. Discrimination in lending. Hallucinated promise. The list is short and prioritized.
Prompt-injection awareness
The team knows that public AI tools can be manipulated by adversarial customers. The Chevy Tahoe-for-a-dollar incident in 2023 happened to a real dealership chatbot. The lesson is in writing.
Output review on high-stakes interactions
Any AI that produces a binding-looking statement has a human review before it goes to the customer.
Customer-facing AI is sandboxed
Customer-facing AI cannot quote final price, finalize a deal, or commit the store legally. Limits are enforced at the system level, not the policy level.
Incident playbook
There is a written playbook for what to do when an AI gets something wrong. Who calls the customer. Who notifies the GM. Who pauses the tool. Who documents the incident.
Post-incident review
After any incident, the store runs a short review and updates the workflow or the controls. The lesson does not get forgotten.
Part 4
Strategy
Section 17
AI roadmap and sequencing
The store with a roadmap moves three times as fast as the store buying tools one at a time.
Sequenced roadmap exists
The store has a written, dated roadmap of the next three to five AI deployments, in order, with owners and expected outcomes.
Foundation precedes deployment
Foundation gaps in Sections 1 through 4 are scheduled before, not after, the next AI deployment. Otherwise the AI inherits the gap.
Budget is allocated
AI has a line in the budget. Not just a vendor invoice that hits unexpectedly each month.
Executive sponsor named
The dealer principal or GM owns the AI program. Not the marketing manager. Not the IT vendor.
Quarterly review
The roadmap gets reviewed and updated quarterly. The market moves too fast for an annual plan.
What to do tomorrow
Pick the lowest-scoring section. Assign an owner. Give them thirty days. Re-score. If the lowest score is in data, website, AI visibility, or compliance, fix that before buying another AI tool.
Start with the free dealer AI tools or ask about an AI readiness audit.
Published by Dealer AI Guy. Ariel Coro is the founder of Dealer Growth Hackers and the publisher of Dealer AI Guy.