← All services

Service 02

Advisory and Governance

Embedded advisory that makes innovation safe, defensible, and board-ready.

Leaders comparing printed operating plans across a strategy table

Overview

AI without governance is liability with a subscription fee. We serve as embedded advisors to leadership teams, installing the policies, oversight, and decision frameworks that make innovation safe, defensible, and board-ready.

In scope

  • Fractional AI advisory for executive teams.
  • AI governance frameworks and acceptable use policies.
  • Responsible AI standards, model oversight, and human-in-the-loop design.
  • Data governance aligned with Canadian privacy law, including PIPEDA and Alberta's PIPA.
  • Board and stakeholder reporting on AI risk and performance.

Our point of view

The companies moving fastest with AI are not the ones with the fewest rules. They are the ones whose rules are clear enough that nobody has to stop and ask. Governance done properly is not a brake. It is the reason your team can run experiments on Tuesday without creating a liability that surfaces in a client audit next year. We build governance as an operating capability your team uses weekly.

Who this is for

You will recognize yourself in at least one of these:

01

Your team is already using AI tools, with or without permission, and there is no policy governing any of it.

02

A client, insurer, or regulator has started asking how you use AI, and the current answer is a shrug.

03

Leadership wants to greenlight AI initiatives but cannot articulate what safe looks like.

04

You are the founder, and every AI decision in the company currently routes through your gut.

What we deliver

The AI Operating Policy

Acceptable use, data handling, and escalation rules written in language real employees can act on.

The Governance Framework

Decision rights, model oversight, human-in-the-loop gates, and incident response.

The Risk Register

Every AI touchpoint in your operation, scored and owned by a named person.

The Board Pack

Quarterly reporting format covering AI value delivered, risk position, and pipeline.

Fractional Advisory

A standing seat at your leadership table, month to month.

The first 30 days

Week 1

Inventory every AI touchpoint in the business, sanctioned or not. Shadow use included.

Week 2

Risk scoring against Canadian privacy law, client obligations, and your contracts.

Week 3

Draft policy and governance framework reviewed with leadership.

Week 4

Rollout: policy live, training delivered, escalation paths tested with a tabletop scenario.

What we measure

Every initiative carries a metric agreed before we build:

Policy adoption and attestation rate.
Shadow AI incidents surfaced and resolved.
Time to approve a new AI use case.
Audit and questionnaire pass rate.
Risk register coverage.

An illustrative system

A governed AI request, end to end

A governed AI request, end to end

Illustrative workflow
HIGHSTANDARDRE-ASSESSNew use case requestAny team, any toolData classification checkWhat data touches itRisk scoringDecision branchLeadership reviewHigh risk pathGuardrail assignmentControls + ownerApproved with conditionsDocumented scopeDeploymentIn the workflowUsage monitoringLogs + exceptionsQuarterly reviewRegister refreshed
Illustrative pattern.

Honest edges

Where this service stops:

  • We are consultants. We design the operating framework and work alongside your counsel where legal opinions are needed.
  • We will not write a policy that sits in a drawer. If leadership will not enforce it, we would rather not draft it.
  • Governance without adoption is theatre. Training and attestation are part of the engagement.

Questions we get

We are a small company. Is this overkill?

The framework scales down. A 15-person firm needs four pages and clear decision rights. What it cannot afford is zero rules and one bad incident.

Will governance slow our team down?

It does the opposite when built correctly. Clear rules remove the constant stop-and-ask. The teams that move slowest are the ones where nobody knows what is allowed.

What does the fractional advisory actually look like?

A recurring leadership session, direct access between sessions, and standing accountability for the AI risk position. Month to month, like everything we do.