Practice 03 · AI Governance & Technology Risk

AI adoption is national policy. Governance is the working part.

Canada's AI strategy is pushing adoption across the economy, with legislation signaled behind it. Every organization that adopts acquires a governance problem on the way: policies, risk assessment, accountability, and eventually conformity. ISO/IEC 42001 is the instrument. We make it operational.

AI for All, Canada's national AI strategy, launched June 4, 2026
AI transparency consultation closed July 2026; legislation signaled
Why now

The strategy is economic. The machinery is regulatory.

AI for All launched June 4, 2026 under Canada's first Minister of Artificial Intelligence. Its ambitions are growth and adoption; its machinery is sovereign compute, modernized privacy and online safety law, a public consultation on AI transparency, and a stated commitment to follow with legislation. Organizations that build governance now meet whatever lands already standing.

$200B
targeted GDP gains from AI adoption in the national strategy
5x
targeted increase in business AI adoption
2023
ISO/IEC 42001 published: the certifiable AI management system standard
The instrument

What an AI management system actually gives you

ISO/IEC 42001 is a management system standard, structured like ISO 27001, built for AI. It turns principles into operations.

Govern

Policy, roles, accountability

A management approved AI policy, named accountability for AI outcomes, and an approval path for new AI use, so adoption does not outrun oversight.

Assess

Risk and impact assessment

Every use case classified by consequence, data sensitivity, and autonomy, with impact assessments where outcomes touch people.

Control

Lifecycle controls and human oversight

Controls across the AI lifecycle from data and development through deployment, monitoring, and retirement, including procured AI, with humans in the loop where it matters.

Prove

Records, audit, certification

Evidence that the controls operate, internal audit to test them, and the option of certification by an accredited body when a certificate is worth having.

What we do

Five services, one practice

ISO/IEC 42001 is the frame. The practice is technology risk your leadership can actually govern.

ISO/IEC 42001 readiness

Gap assessment against the standard, a build plan, and evidence that stands up to a certification audit if you choose to pursue one.

AI governance frameworks and policy

Policy, roles, decision rights, and an intake process for new AI use, sized to your organization rather than copied from a template.

AI risk and impact assessment

A use case inventory, risk classification, and impact assessments for the systems that affect people, credit, safety, or rights.

Responsible AI controls and evidence

Operational controls for data, models, vendors, monitoring, and incidents, each producing records as a side effect of running.

Technology governance for boards

The oversight layer: what the board should see, how often, and with what evidence behind it.

How the engagement runs

Eight steps, inventory to operation

Time and materials, with checkpoints. Your team implements; we design, support, and verify. Every stage produces an artifact you keep.

  1. AI inventory

    Every system, model, and vendor feature in use or planned, including the ones nobody declared.

  2. Risk and impact assessment

    Each use case classified by consequence, data sensitivity, and autonomy.

  3. Governance framework

    Policy, roles, accountability, and an approval path for new AI use.

  4. Gap assessment

    Against ISO/IEC 42001, producing a register and a sequenced plan.

  5. Management system build

    Lifecycle controls, monitoring, human oversight, and records.

  6. Evidence and internal audit

    Prove the controls operate, not just exist.

  7. Certification readiness

    If you want the certificate: a readiness review before a certification body ever arrives.

  8. Operate and adapt

    Performance monitoring, incident handling, and tracking the legislation the strategy has signaled.

What you walk away with

Artifacts, not advice

  • An AI inventory including procured and embedded AI
  • A risk classification and impact assessments for the uses that matter
  • A governance framework with named accountability
  • A gap register and build plan against ISO/IEC 42001
  • Operating controls that produce their own evidence
  • A board oversight pack for AI and technology risk
Questions

Asked often

Is ISO/IEC 42001 certifiable?

Yes. It is a certifiable management system standard, published in 2023, audited by accredited certification bodies. Certification is optional; the management system is valuable either way, and we build it so the certificate is a decision rather than a rebuild.

We only use vendor AI like Copilot. Does governance still apply?

Yes, and this is the most common gap we see. Procured and embedded AI still needs an inventory entry, a use policy, risk classification, and oversight. The vendor runs the model; you own the outcomes.

Is there Canadian AI legislation in force now?

Not for general AI use. The national strategy signals legislation, and the government ran a public consultation on AI transparency in July 2026. Governance built now is the preparation that makes whatever lands routine instead of disruptive.

How does 42001 relate to our ISO 27001 system?

They share the same harmonized management system structure, so an integrated system is practical: one governance layer, shared audits and reviews, with AI specific risk, lifecycle, and oversight controls added. Existing 27001 work carries over.

Adopting AI faster than you can answer for it?

Start with the inventory and a 42001 gap assessment. Two artifacts, and your governance conversation changes from abstract to concrete.