Our customer contact data lives primarily in spreadsheets, email threads, business cards, or individual employees’ memories — not a centralized, searchable, permission-controlled CRM.
We have no formally documented lead intake process. Responses to inbound inquiries depend on who sees the message first, not on a defined, measurable workflow.
If a key salesperson, account manager, or business owner were to leave tomorrow, significant customer history, pricing context, and relationship intelligence would leave with them — unrecoverable.
We cannot produce, in under 60 seconds, a filtered, exportable list of customers who have not transacted in the past 90 days, segmented by revenue tier.
We send no planned, segmented email communication to our customer base — or we distribute irregular newsletters that are not tied to a content calendar, campaign objective, or measurable outcome.
Our email subscriber list has never been audited for duplicate records, hard bounces, consent compliance under CASL or GDPR, or inactive subscribers exceeding 6 months without engagement.
We have no automated follow-up sequences triggered by prospect behaviour — a lead who completes a form, visits a pricing page, abandons a quote, or goes silent after a proposal receives zero automated outreach.
We cannot state our current cost-per-lead, lead-to-close conversion rate, or email open-to-click ratio as a tracked, real-time figure — only as a rough estimate or historical anecdote.
No formal assessment has been conducted to identify which of our manual, repetitive workflows — quoting, scheduling, customer follow-up, reporting — could be partially or fully automated using current AI, RPA, or integration tools.
No member of our team is consistently using AI-powered tools in their daily work — not for drafting proposals, summarizing meetings, generating reports, or managing customer communication.
Our technology stack is siloed: our website, CRM, accounting software, scheduling platform, and communication tools operate independently and do not share data or trigger cross-system actions.
We have no written, shared technology roadmap for the next 12 months — new tools are adopted reactively when pain becomes critical, not selected proactively against a strategic framework.
We have no written, tested Incident Response Plan (IRP). If we discovered a ransomware attack or confirmed data breach at 8:00am Monday, we could not name the first three steps our team would take — and who is authorized to take them.
System access is not role-restricted. Former employees, contractors, or vendors may still hold active credentials to our CRM, file storage, email platform, or banking portals — and we cannot confirm otherwise.
We are not confident our data collection, email marketing, and storage practices comply with CASL, GDPR, or FIPPA as applied to our specific customer and employee data — and we have not obtained legal confirmation.
We have no verified, off-site or cloud backup of our critical business data taken within the last 30 days — and we have never conducted a restore test to confirm the backup is actually recoverable.
Our leadership team has not reviewed digital performance data — website traffic, lead volume, campaign results, customer acquisition cost, churn rate — in a structured, documented meeting within the past 90 days.
We have no written, shared business plan or growth strategy document. Direction exists in the owner’s or leadership’s heads — not in a form that can be delegated, measured, held accountable, or handed to a successor.
We cannot identify, by name and approximate revenue contribution, our top three customer segments — meaning we do not know which customer relationships to protect, which to grow, and which type to systematically replicate.