AI governance consulting for rules people actually follow
AI governance fails in one of two ways. Either nothing is written down, or twelve pages are written down and nobody's read them.
What works is a page. What's supported, what needs a look first, what never happens, what data can go in, and who to ask. Signed, owned, and dated.
The gap, in numbers
36% of Canadian organizations have no AI governance function at all. 65% of leaders name unclear ownership as a top barrier (PwC Canada, 2026).
Meanwhile 93% are using AI and 2% see a return (KPMG Canada, 2025).
Those aren't three separate findings. Ungoverned AI use doesn't compound, because nothing gets standardized, nothing gets reused, and every team solves the same problem again.
Governance is one of six owners
In our model, governance is where the Data question gets answered: what can AI touch, and what can it never touch?
It touches three of the other five. Tools, because approval has to mean something. People, because a rule nobody's trained on isn't a rule. Results, because you can't measure what you haven't defined.
See the full model on the system page.
What you get
The Governance One-Pager. Part of Foundation, and the description is the specification: the governance one-pager your staff will actually read. It comes with the other six Findings documents, including the AI Inventory and the 12-Month Plan.
The signed policy. In Adoption, governance moves from a document to something in force. The policy gets signed, the owners get named on the Owner Map, six parts and six names, and role-based training makes the rules something people have actually been walked through.
The Agent Register. In Partnership, every system, its owner, its guardrails, and when it was last checked.
Four steps for the situations rules don't cover
Rules handle what you saw coming. For everything else, we teach the same four steps. Assess, Approve, Adopt, Document.
| Step | The question you're answering |
|---|---|
| Assess | What happened, what was shared, and what's exposed? |
| Approve | What use would you actually accept here? |
| Adopt | What's the safe way to do the same job? |
| Document | What's the one rule, who owns it, and when does it get looked at again? |
Document is the step people skip, and it's the one that stops you solving the same problem twice.
The longer version, written for you to use on your own: the practical AI governance guide for Canadian companies.
What governance here doesn't mean
It doesn't mean blocking AI. A policy that makes the work harder loses to whatever's easiest, every time.
It also isn't legal, regulatory, privacy, or compliance advice. We build the operating rules for how your company uses AI. Where you need a lawyer, you need a lawyer, and we'll say so.
Where it connects
- AI readiness assessment to see where you stand first.
- AI strategy consulting for direction and the 12-month plan.
- AI training for employees so the rules reach the people using AI.
- All four stages.
Who this is for
Canadian companies of 30 people and up, any industry, where staff are using AI and no one has written down what's allowed.
Questions
01 What is AI governance consulting?
Work that decides what AI can be used for at your company, who owns those decisions, what data is off limits, and how uncertain cases get escalated. We deliver it as the Governance One-Pager in Foundation and the signed policy in Adoption.
02 Isn't governance just a policy document?
The document is about a fifth of it. The rest is a named owner, an escalation route people use, training so the rules are known, and a review date so it doesn't go stale.
03 Will this slow our team down?
The opposite, usually. Most of the delay in ungoverned companies is people stopping to guess whether something's allowed, or avoiding AI because nobody told them it was fine.
04 Do you cover privacy law and compliance?
No. We build your operating rules for AI use. Legal, privacy, and regulatory advice comes from your counsel, and we'll tell you when you've hit that line.
05 How long until governance is in place?
The Governance One-Pager comes out of Foundation, two to four weeks. The signed policy and named owners land in Adoption, another three to six.
06 What if we already have an AI policy?
Bring it. Most of the ones we see are too long to read and too vague to use. We wrote up how to fix that.