AI Governance in Practice: The Five Foundations Mid-Market Canadian Organizations Are Building in 2026
Most Canadian organizations now have AI deployed in production. Most do not have a governance program to match.
PwC Canada's 2026 Trust in AI Report, drawn from 220 senior decision-makers at Canadian organizations, found that 72 per cent name responsible AI a top priority. Only 36 per cent have a dedicated governance function. The gap between the stated priority and the operating reality is where most mid-market organizations currently live.
IBM Canada's May 2026 research puts a cost on that gap. AI irregularities — errors, bias, duplication, and uncoordinated deployments — cost large Canadian enterprises an estimated $144 million per year. Half of those losses trace to governance failures, not to flaws in the AI itself. Only 18 per cent of Canadian organizations have coordinated governance systems spanning the full AI lifecycle. And 63 per cent of Canadian executives say governance gaps already make it harder to scale AI deployments across their operations.
The compliance dimension is accelerating this. Bill C-36 (the Protecting Privacy and Consumer Data Act), tabled in June 2026 and before Parliament, introduces explicit automated decision disclosure obligations — organizations will be required to make public a general account of their use of automated decision systems and, on request, explain any prediction, recommendation, or decision with a legal or significant effect on an individual. The penalty framework for serious violations reaches $25 million or five per cent of global revenue, whichever is greater.
Statistics Canada's Q2 2026 survey shows the adoption side of this equation: 19.2 per cent of Canadian businesses now use AI to produce goods or deliver services — a figure that tripled from 6.1 per cent in Q2 2024. The businesses deploying AI fastest are exactly the organizations most exposed to the governance gap.
This post describes the five foundations of an operating AI governance program — not the standard (ISO 42001) that organizes them, but the practical work that makes a governance claim credible.
Foundation 1: The AI Inventory Register
You cannot govern what you cannot see. An AI inventory register is the most basic governance control and the most consistently missing one. The register catalogs every AI system in use across the organization: the tool name and vendor, the use case, the data it accesses, the business unit that owns it, the vendor's data processing and residency commitments, and the date the vendor risk assessment was last completed.
For mid-market organizations, the register typically reveals a more complex picture than the IT team knew existed. Departmental subscriptions, embedded AI features in SaaS tools, and recent Microsoft 365 Copilot rollouts each add entries. The register does not need to be a formal system — a maintained spreadsheet is the right starting point — but it needs an owner and a review cadence.
The OPC's September 2026 guidance on assessing third-party service providers requires organizations to maintain documented evidence of third-party AI vendor assessments covering data storage locations, subprocessor chains, breach notification timelines, and contractual data deletion obligations. The inventory register is the scaffold for that evidence.
Foundation 2: Acceptable Use and Data Classification Policy
An AI acceptable use policy does two things. It tells employees which tools are approved, for which purposes, and what data may be used as input. And it creates the documented control that demonstrates the organization took reasonable steps to manage personal information handling under PIPEDA — and, once in force, under the PPCDA.
The policy needs to cover three classification decisions:
Data that must not be input to external AI systems. At minimum: personal information of customers, employees, or third parties; confidential business information; and client data governed by contracts with confidentiality obligations. For most mid-market organizations, this is not a theoretical risk — employees regularly draft client-facing documents using AI tools and, without a policy, make the input decision themselves.
Tools that are approved and why. Employees are more likely to comply with a policy that explains the rationale than one that simply lists prohibitions. An approved tool with documented data processing commitments, Canadian data residency, and a signed DPA is categorically different from an unapproved tool with opaque handling. Explaining that difference matters for the policy to land.
The process for requesting approval of a new tool. An approved list with no pathway for additions produces shadow AI. The policy should be a front door, not a fence.
PwC's report found that 65 per cent of leaders cite unclear ownership and difficulty inventorying existing AI systems as their primary governance barriers. An acceptable use policy addresses the ownership problem directly — every approved tool has a named owner who is responsible for keeping the vendor assessment current and monitoring how the tool is used.
Foundation 3: Automated Decision Disclosure Readiness
The Bill C-36 disclosure obligation is a governance control in practice, not only a compliance checklist item. Any automated decision system that generates predictions, recommendations, or decisions with significant effects on individuals — hiring decisions, credit assessments, pricing, claims adjudication — needs to be documented to a standard that can support an explanation on request.
The documentation the obligation requires already exists in well-governed organizations: the system's purpose, the data inputs, the logic the model applies, the business rules it implements, and the human review step (if any) that sits between model output and final decision. Organizations that have documented their workflows and data flows for PIPEDA compliance are largely ready for the disclosure standard. Those that have not are not.
The practical question for mid-market organizations is not whether they use automated decision systems — most do, often embedded in CRM scoring, HR screening tools, or financial reporting software — but whether they know they do and whether they have the documentation to explain what those systems are doing.
The gap is real. IBM's research found that most organizations lack the visibility into their AI systems to govern them effectively. A disclosure obligation on those systems is only possible if the visibility exists.
Foundation 4: Risk Classification and Assessment Workflow
Not every AI use case carries the same risk. A governance program that treats an internal document drafting tool the same as a system making credit decisions about customers is inefficient and, eventually, unsustainable. Risk classification gives the organization a way to apply proportionate controls.
A workable classification framework for mid-market organizations uses three tiers:
Standard use. Tools that process only non-personal, internal information for knowledge work purposes — document drafting, meeting summaries, code assistance. These require acceptable use policy coverage and vendor registration but not individual assessments for each use case.
Elevated use. Tools that access internal business data, customer records, or financial information. These require a vendor risk assessment and a documented data processing agreement at go-live, with annual renewal.
High-impact use. Automated decision systems affecting customers, employees, or third parties in ways that could have legal or significant effects. These require the disclosure readiness documentation above, a Privacy Impact Assessment under Quebec Law 25 for organizations with Quebec operations, and management sign-off on the risk assessment before deployment.
ISO 42001, the international standard for AI management systems — for which PwC Canada launched the first North American certification program in February 2026 and KPMG Canada earned certification in September 2026 — organizes governance controls around exactly this risk-based logic. Certification is not required, but the standard's structure maps to the same problem: proportionate controls applied to proportionate risk.
Foundation 5: Ongoing Monitoring and Review Cadence
Governance is not a project with an end date. The tools change, the vendor landscape shifts, the regulatory environment moves, and new use cases appear faster than compliance teams can review them. A governance program needs a repeating operating rhythm to stay current.
The minimum review cycle for mid-market organizations covers three cadences:
Continuous. New AI tool requests are routed through the acceptable use approval process before deployment. Shadow IT monitoring flags unapproved tools.
Quarterly. The AI inventory register is reviewed and updated. Any tool that has changed its data processing commitments, had a reported breach, or been subject to regulatory action is flagged for reassessment.
Annual. All elevated and high-impact use cases are reassessed. Vendor DPAs are renewed. The acceptable use policy is updated to reflect regulatory changes — including any PPCDA developments as the bill moves through Parliament — and redistributed with employee acknowledgment.
The cadence is not expensive. For most mid-market organizations, the quarterly and annual reviews are a half-day exercise once the inventory register is established. The cost of the operating rhythm is low. The cost of operating without one — in governance failures, regulatory exposure, and the inability to scale AI safely — compounds quickly.
Where Most Mid-Market Organizations Should Start
The IBM and PwC data converge on the same finding: Canadian organizations are deploying AI faster than they are building the oversight infrastructure to manage it. The governance gap is not primarily a technology problem. It is an organizational one.
The entry point for most mid-market organizations is the inventory register and the acceptable use policy — the two controls that close the immediate visibility and ownership gaps and create the foundation the other three foundations build on. Both are low-cost to produce and high-value on day one: the inventory immediately surfaces vendor risk exposures the organization did not know existed, and the policy stops the accumulation of new ungoverned deployments while the rest of the program is built.
Organizations that have already deployed AI broadly without these foundations are not starting from scratch — they are backfilling documentation that the systems in use already implicitly require. The review typically takes two to four weeks of structured assessment and results in a program that is defensible to the OPC, ready for Bill C-36's disclosure obligations, and positioned to scale AI deployment with controls that match the risk.
Sources
- IBM Canada. *New IBM Study: AI is Moving Faster Than Oversight in Canada.* canada.newsroom.ibm.com (May 2026)
- PwC Canada. *Canadian Organizations Facing Critical Readiness Gap in Trusted AI Adoption.* pwc.com (2026)
- Osler. *The Protecting Privacy and Consumer Data Act (Bill C-36): Key Obligations and Enforcement Overview.* osler.com (June 2026)
- Statistics Canada. *Analysis on Artificial Intelligence Use by Businesses in Canada, Second Quarter of 2026.* statcan.gc.ca (June 2026)
- Office of the Privacy Commissioner of Canada. *Guidance on Assessing Third-Party Service Providers.* priv.gc.ca (September 2026)
- PwC Canada. *PwC Canada Launches Groundbreaking AI Governance Certification (ISO 42001).* pwc.com (February 2026)
- KPMG Canada. *KPMG Canada Achieves ISO 42001 Certification.* kpmg.com (September 2026)
- Intelligent CIO. *IBM Study Warns Canada's AI Governance Is Failing to Keep Pace with Adoption.* intelligentcio.com (May 2026)
Cloud Forces' AI Advisory service includes AI governance and security reviews for mid-market Canadian organizations — covering the inventory register, acceptable use policy, vendor risk assessment process, automated decision disclosure readiness, and the review cadence needed to maintain the program. As an AWS Consulting Partner since 2019 and a team certifying on Claude, we design governance frameworks that are defensible under PIPEDA, ready for the PPCDA, and proportionate to the AI footprint you actually have. Book a consultation to assess where your program stands.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make AI and cloud practical for Canadian SMEs. He leads Cloud Forces’ AI advisory and Claude deployment work and oversees the secure cloud platforms the firm runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation