46 / 63AI Governance

AI governance for Canadian firms, built on rules that actually apply

Canadian AI governance scoped to what binds you, with the controls running inside your systems.

  • CCIE and CCDE-led team
  • Building since 2021
  • Canadian data residency available
THE WORK

AI governance, three pillars, one operator.

One Canadian team works out what binds you, then builds the AI governance framework and the controls that back it.

  1. 1

    Obligation mapping

    We establish which rules reach you: sector, province, and whether you touch the EU at all. Naming what doesn't apply is half the value, because scoping an AI compliance programme to the strictest regime you've heard of is how firms buy work they'll never need.

  2. 2

    Policy and model inventory

    Every model catalogued with an owner, an approval record, and a review date. Your AI policy stays short and points at that register, because the register is the artifact people actually keep current.

  3. 3

    Technical controls

    Logging, access boundaries, and human review gates wired into the systems, not written in a binder. AI oversight only counts when someone can pull the log for a decision a model made last Tuesday.

THE PROOF

Built to last. Evidence over promises.

Canada has no AI statute in force. Federally regulated financial institutions still face OSFI Guideline E-23 from 2027-05-01, which pulls AI risk management inside the model risk rules they already answer to.

IN PRODUCTION

Governance Canadian regulators can follow.

Two vendors quoted us EU AI Act readiness programmes. We have no European customers. SMEnode spent the first fortnight working out what actually binds us, came back with OSFI E-23 and PIPEDA, and said the EU work was unnecessary for now. Then they built the model inventory and the logging. The framework is nine pages and our auditor accepted it.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

An AI governance framework for Canadian firms, made real.

Most AI governance work starts with the wrong rulebook. Here's how to find yours first.

Start with your rulebook, not the strictest one.

An AI governance framework worth having names your obligations, your models, and who answers for each. The pillars are the same everywhere: accountability, transparency, fairness, privacy. That part is settled and you can read it free on any vendor site. The work is deciding which rules bind you, because scoping to the strictest regime you've heard of is how firms buy a compliance programme they don't need. We start by asking whether you have EU users at all. Many Canadian firms don't, and the answer changes the budget by a lot.

Controls, not documents.

Then we build controls, not documents. Risk sits in three places. The model somebody deployed without telling anyone, which no policy catches. Approval that exists as an email thread rather than a record. And a framework whose review dates passed a year ago. We do model inventory, ownership, logging, and human review gates, and we use NIST AI RMF to organise the work because its four functions (Govern, Map, Measure, Manage) are practical and it's the most widely adopted reference. A framework is a filing system for decisions. It doesn't make them.

What actually binds a Canadian firm today.

Canadian obligations, as they stand on 2026-08-20. There's no federal AI statute in force: AIDA died at prorogation in early 2025 and the government has said it won't return as drafted, with narrower bills moving instead, including Bill C-36 on privacy and consumer data and Bill C-34 on digital-safety duties covering certain AI chatbot services (source: Torys LLP, 2026). What does bind you: PIPEDA, Quebec's Law 25, and for federally regulated financial institutions OSFI Guideline E-23, published 2025-09-11 and effective 2027-05-01, which covers AI and machine learning models directly (source: OSFI). The EU AI Act reaches you only if you touch EU users, and its penalties run to 35M euros or 7% of global turnover (source: Government of Canada Trade Commissioner Service).

Inference graph
THE METHOD

How our AI oversight work runs.

Four steps, and the first one often saves the most money. Scoping means telling clients which regimes don't apply to them, and that conversation shortens a lot of proposals including our own. We'd rather build a framework that covers your real obligations well than a bigger one covering hypotheticals badly. After scoping, the work is unglamorous: catalogue the models, name owners, wire the logging, set review dates that someone is accountable for keeping.

  1. Step 01

    Scope the obligations

    Sector, province, EU exposure, contractual commitments. We name what doesn't apply and why, in writing, so nobody reopens the question in month four.

  2. Step 02

    Inventory the models

    Every model in use, including the ones nobody registered. Owner, purpose, data, and approval status for each. Shadow deployments turn up in this step, and they always do.

  3. Step 03

    Build the controls

    Logging, access boundaries, human review gates, and an approval record. In the systems, not in a document, so the evidence is a query rather than a promise.

  4. Step 04

    Set the review cadence

    Dates, owners, and what triggers an out-of-cycle review. Regulation moves, and this is the step that keeps the framework current after we've gone.

QUESTIONS

AI governance questions, answered straight.

Answers first, including which rules probably don't apply to you. An architect takes the call.

Not a general one. AIDA died at prorogation in early 2025 and the government has said it won't return as drafted, so there's no federal AI statute in force as of 2026-08-20. What binds you is PIPEDA, provincial privacy law like Quebec's Law 25, and sector regulation. Narrower bills are moving through Parliament, including Bill C-36 and Bill C-34, so this answer has a shelf life and we date it deliberately.

Only if your AI touches people in the EU, and that catches more Canadian firms than expected: EU subsidiaries, European customers, or selling AI-enabled software into the EU. If none of that applies, you don't need an EU AI Act programme and we'll say so. If it does, penalties reach 35M euros or 7% of global turnover, so the scoping question is worth answering properly.

If you're a federally regulated financial institution, this is your near-term deadline. OSFI's updated Guideline E-23 on model risk management was published 2025-09-11 and takes effect 2027-05-01, and it covers AI and machine learning models, not just actuarial ones. It's the most concrete AI-adjacent obligation in Canada right now, and it's the one we plan most engagements against.

NIST AI RMF for structure, because its four functions are practical and it's the most widely adopted reference. ISO 42001 is a certifiable standard, which is a different objective: you'd pursue it when a customer or a tender demands the certificate. We can prepare you for it, and certification itself needs an accredited body, not us.

Both, and that's the point of buying it here. Plenty of firms will write you an AI policy. Fewer can then wire the logging, set the access boundaries, and build the model inventory into your actual systems. A governance framework nobody instrumented is a document that describes intentions. Ours comes with the controls running.

A model register with an owner and an approval record against each entry, the scoping memo naming which regimes apply and which don't, evidence that the logging and the human review gates run inside your systems, and a review calendar with dates and named owners. All of it is yours. If you take the practice back in house, the runbooks go with it.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.