AI Governance & Responsible Adoption
Let your people use AI without losing control of data, decisions or accountability.
Your staff already use ChatGPT, Copilot or Claude, someone has asked whether that's allowed, and nobody has written the answer down. Northvian puts practical rules around tools, company data, human oversight and accountability, sized to your organization rather than to a template.
01
Is this you?
-
“Someone on the team pasted a client's file into ChatGPT to summarize it, and we only found out because they mentioned it.”
ChatGPT
-
“A partner asked whether we were allowed to use these tools, and the honest answer was that nobody had decided.”
-
“A vendor we already use is switching on an AI feature by default, and we don't know what it does with our data.”
-
“Our hiring team is trialling an AI screener, and someone asked whether we have to tell candidates.”
-
“We have Copilot in Microsoft 365 and Gemini in Google Workspace, different teams use different things, and there is no shared rule.”
CopilotGemini
-
“We'd like people to use these tools more, not less. We just want to be able to say what's fine and what isn't.”
02
What this work is
AI governance, at twenty people or two hundred, is not a committee. It is a short set of written answers to four questions: which tools may we use, what company and customer information may go into them, which decisions must stay with a person, and who is accountable when something goes wrong. Everything else, the registers, the training, the review cycle, exists to keep those four answers true as the tools and the use change.
Good governance enables adoption. When staff know which tools are approved and what they may paste in, they use them more, in the open, and stop using personal accounts. When managers know which decisions AI may draft but not make, they can say yes to the drafting. The alternative to written rules is not safety; it is the same use, hidden.
The work is proportional. A twelve-person agency needs a one-page rule, an approved-tools list with three entries and one named owner. A two-hundred-person firm handling client files needs the same things plus a data classification, a decision register, a vendor questionnaire and a review cadence. We size it to what you handle and how many people touch it, and we say when something is more than you need.
For Canadian organizations the legal picture is specific, and it moves. Customer and client personal information that staff put into AI tools sits under federal privacy law for commercial activity; employee information is treated differently, and differently again by province. Ontario has job-posting disclosure and electronic-monitoring rules that reach AI at certain employer sizes. A new federal privacy bill was tabled in 2026 and is not law. Law societies and regulators have published expectations for their licensees. We keep a dated summary of what applies, the same one that sits in our free AI Ground Rules kit with its sources, and we are clear about what this is: engineering and operational advice, not legal advice, and no guarantee of compliance. Your lawyer signs off on the policy. We make it something people will follow.
03
What we might tell you not to do
-
Don't ban the tools
A ban moves the use to personal phones and personal accounts, where you have no visibility and no terms. Approve a short list for specific uses and say what may not go in.
-
Don't write a twelve-page policy
Nobody reads it, so nobody follows it. One page of rules people can remember, with examples, and the registers behind it for the people who need them.
-
Don't copy a template that cites laws that don't apply to you
Some free Canadian templates cite bills that died or rules written for the public sector. If your policy quotes them, it is wrong on its first page, and the people who notice will be the ones you least want to.
-
Don't let AI make the decisions that need a person
Hiring, credit, client advice, pricing, discipline and termination: AI may draft or suggest for these, a person decides, and the rule is written down. That is the line regulators keep drawing, and it is also where the reputational risk lives.
-
Don't treat a vendor's new AI feature as covered by the old contract
Ask the six questions (training on your data, retention, region, admin controls, audit logs, breach notice) before it is switched on, not after.
-
Don't govern by email
A rule that lives in a message from last spring is not a rule. Give it a page, an owner, and a date it gets reviewed.
04
What we actually do
- 01
Inventory the use
Who uses what, for what, on which accounts. A short survey and a few conversations, with no blame attached. You get the real picture, which is usually broader than anyone assumed.
- 02
Classify the data
Green, amber and red for AI purposes, with your own examples: client files, personal information, pricing, contracts under NDA, public marketing copy. You get a one-page classification staff can apply in the moment.
- 03
Approve the tools
Consumer, business and enterprise tiers explained; the vendor questions asked of every tool in use; a short approved list with what each is approved for. You get the approved-tools register.
- 04
Draw the decision line
Which decisions AI may draft, which it may suggest on, and which it stays out of, with hiring, credit, client advice, pricing and termination as the worked rows. You get the decision register.
- 05
Write the policy
Scope, tools, permitted and prohibited uses, data handling by tier, human review, disclosure, incidents, review cycle. One page of rules, the detail behind it. You get the policy, ready for your lawyer.
- 06
Roll it out
A short session for staff, the procedure for "I pasted something I shouldn't have", and the owner named. You get adoption, not a document.
- 07
Set the review
A date, an owner, and what triggers an earlier look: a new vendor feature, a new law, an incident. You get a rhythm that survives us leaving.
05
What you receive
-
Current-use inventory
Who uses which tools for what, on which accounts, today.
-
AI data classification
Green, amber and red with your own examples, and the rule for each tier per tool class.
-
Approved-tools register
Each approved tool, its tier, what it is approved for, and the answers to the vendor questions.
-
Decision register
Which decisions AI may draft, suggest on, or must stay out of, and who decides.
-
AI use policy
One page of rules people can remember, with the detail behind it, ready for legal review.
-
Staff guidance and session
A short session, the examples that make the rules stick, and a one-page handout.
-
Incident procedure
What to do, and who to tell, when information goes where it should not have.
-
Review cadence and owner
A named owner, a date, and the triggers for an earlier look.
06
Illustrative scenario
An accounting firm where everyone was using AI and nobody had said so
Situation
I'm the managing partner of a thirty-person accounting firm. I assumed a couple of people were using ChatGPT. The inventory found that most of the firm was, on personal accounts, for everything from client emails to summarizing financial statements. One partner had asked whether we were allowed to. I didn't have an answer, and I hadn't checked whether our professional body had published any guidance.
What the work looked like
The classification put client financial information in red for consumer tools and amber for the business-tier tool we then approved, with its terms checked for training use and retention. The decision register said AI may draft client correspondence and summaries, a person reviews anything that leaves the firm, and AI stays out of advice on a client's position. The policy was one page. Our lawyer reviewed it in an afternoon. The staff session was forty minutes, mostly questions.
What changed
Use went up, in the open. The personal accounts stopped. The whole firm drafts on the approved tool, with the review step visible. The registers get a look each quarter, and the next vendor to switch on an AI feature got the six questions before anyone clicked accept.
07
How an engagement runs
- 01 1 to 2 weeks
Inventory and classify
The survey and conversations, the current-use picture, the data classification with your examples.
- 02 1 to 2 weeks
Tools, decisions and policy
The vendor questions answered, the two registers, the one-page policy drafted for your lawyer.
- 03 About 1 week
Roll out and set the review
The staff session, the incident procedure, the owner named, the review date set.
Formats
- A fixed-scope governance engagement, typically two to four weeks for an organization of up to a few hundred people.
- A policy and register review, for organizations that already have something written.
- A short governance check by the quarter, once the rules exist.
Bands assume one jurisdiction and one main workplace suite. Regulated sectors, or client contracts with their own AI clauses, add time, and we say so at the inventory stage.
08
Technical and risk notes
What we look at
- Tool tiers in use: consumer, business and enterprise, and the admin controls each actually gives you.
- Tenant settings on Copilot, Gemini and similar: what is enabled, data-sharing defaults, retention, where processing happens.
- Vendor terms: training on your data, retention, region, audit logs, breach notification, sub-processors.
- Identity: single sign-on to approved tools, personal-account use, and what happens at offboarding.
- The data classification, and how it maps to tool tiers and to labels you already use.
- The decisions AI touches, and whether human review is enforced in the workflow or assumed.
- Logging and audit: what the tools record, who can see it, and for how long.
- Disclosure obligations: hiring, monitoring and client-facing use, in your jurisdiction.
- The incident path: what happens when information goes where it should not have.
What can go wrong
- The free tier a team uses may train on what they paste; the business tier does not, and nobody switched.
- A workplace suite switched on an AI feature by default with access to every mailbox and file.
- Client-confidential material sits in personal accounts that stay when the person leaves.
- The AI screener in hiring has no disclosure, no human review, and no record of what it was told.
- The policy cites a law that never passed.
- A vendor changes its terms and nobody is watching.
- The review date passes, and the register is a year stale.
- The rule exists, and nobody can find it.
09
Questions people ask
What does AI governance mean for an organization our size?
Four written answers: which tools, what data may go in, which decisions stay human, who is accountable. At twenty people that is a page, a short list and a name. At two hundred it adds a data classification, two registers, a vendor questionnaire and a review cadence. It does not mean a committee, a framework binder or a compliance program.
What law actually applies to us today?
It depends on what information your staff handle and where you are. Customer and client personal information used in a business is under federal privacy law; employee information is a provincial and contractual matter for most employers; Ontario adds hiring-disclosure and electronic-monitoring rules at certain sizes; a new federal privacy bill is tabled and not yet law. We keep a dated summary with sources and point you to it, and your lawyer confirms it for your situation.
What do we get, and how long does it take?
The current-use inventory, the data classification, the approved-tools and decision registers, a one-page policy, a staff session, an incident procedure and a review cadence with a named owner. Typically two to four weeks for an organization of up to a few hundred people.
How is it priced?
As a fixed scope, quoted after a first conversation about your size, sector and the tools already in use. The quarterly governance check, once the rules exist, is a small standing arrangement. Neither includes legal review; that stays with your lawyer.
How does this connect to the free AI Ground Rules kit?
The kit is the same method as a document: the classification, the registers, the policy template, the decision table, a thirty-day rollout and a self-score. An organization can run it on its own. The engagement is us doing it with you, on your tools and your data, with your examples, and it starts from wherever the kit got you.
Won't rules slow adoption down?
The opposite, as a rule. Staff who know what is approved use it openly, and managers who know which decisions stay human can say yes to the rest. The rules take a page. What slows adoption is the uncertainty that exists before the page is written.
What do you do for law firms and regulated sectors?
The same method, with the sector guidance built in: law society expectations for licensees, any guidance your professional body has published, and the disclosure and oversight rules that reach your clients and candidates. Client-confidential material gets its own row in the classification, and the decision register is written around advice, not just administration.
Can our staff use ChatGPT at work?
Probably yes, for the right things, on the right tier. The consumer tier and the business tier handle your data differently, so the answer is which account, for which work, with which information. Write that down and most of the question goes away.
Write the answer down.
Tell us what your people use today. We'll size the rules to your organization, not to a template.