AI governance and regulatory readiness

Somebody has asked how your organization governs its use of AI, and the honest answer is a slide. What is wanted is the thing behind the slide: a list of the AI in use, a statement of which of it matters and why, a set of controls somebody owns, and evidence that any of it is real.

The artifact that is actually accepted

A board wants to know which uses could hurt the organization and who is accountable for each. A customer wants to know whether their data trains a model and who approved the system that touches it. A regulator, where one has reach, wants to see that a process existed before the decision rather than after the question. All three are satisfied by the same artifact, and none of them is satisfied by a policy document alone.

So the work builds the artifact: inventory, classification, controls, decision rights and evidence — assembled in that order, because each one is what makes the next one possible.

AI inventory and use-case register

The register records, per use case: what it does and for whom; which models and vendors sit behind it; what data it touches and whether that is personal, health, financial or otherwise regulated; whether it makes or materially influences a decision about a person; whether a human reviews that decision and with what authority to overturn it; who owns it; and when it was approved and by whom.

Classification then sorts the register into tiers by consequence: uses that affect a person’s rights, access, employment, credit or care sit at the top; uses that touch regulated data sit next; uses that touch neither sit at the bottom and should be governed lightly so the attention goes where it belongs. Where the inventory does not exist yet, shadow AI discovery and AI vendor risk is the engagement that produces it.

Choosing the framework you are measured against

The choice is driven by who is asking, not by which framework is best. Each is named below with its number and a link to its own source, and the comparison is set out in detail in ISO 42001 vs NIST AI RMF.

FrameworkWhat it is for
ISO/IEC 42001:2023A management-system standard for artificial intelligence. An organization can be assessed against it and receive a certificate, which is issued by an accredited certification body.
ISO/IEC 23894:2023Guidance on AI risk management, used where the goal is a coherent risk process rather than a certificate.
NIST AI RMF 1.0A voluntary risk management framework released 26 January 2023, organized around the GOVERN, MAP, MEASURE and MANAGE functions, with a Generative AI Profile (NIST AI 600-1) released 26 July 2024. NIST states that AI RMF 1.0 is being revised.
EU AI ActRegulation (EU) 2024/1689 of 13 June 2024, laying down harmonised rules on artificial intelligence. Whether it applies to your organization is a question for your counsel.

Pick ISO/IEC 42001 when a customer or a market expects a recognized certificate; pick NIST AI RMF 1.0 when you want a risk framework to organize around without a certificate at the end of it. The controls you build overlap heavily either way. Organizations with an EU nexus frequently need both: a framework to organize around and a separate legal assessment of the Regulation’s reach, discussed in the EU AI Act for Canadian suppliers.

Gap review against your chosen framework

The review reads your framework clause by clause or function by function against what your organization actually does, and records one of four states for each: in place with evidence; in place without evidence, which is the most common and the easiest to fix; partially in place; or absent. The distinction between the first two is the whole point, because a control nobody can evidence will not survive an assessor, a customer’s due diligence or an incident.

The output is a gap register with an owner, an effort estimate and a dependency for each line, which is what turns a framework into a plan.

Control set, policy suite and decision rights

  • The control set, stated as controls rather than intentions: each with an owner, an enforcement point and the evidence it produces.
  • The policy suite: acceptable use, development and procurement standards for AI, data handling for prompts and training, human oversight requirements by tier, and an incident policy that names AI scenarios.
  • Decision rights for AI approval. Who may approve a new use case at each tier, what they must see before deciding, how long it takes, and the route for the answer to be no. A process with no realistic path to approval is a process that gets bypassed.

Canada: what is actually in force

Canada has no federal AI statute in force. The bill that would have created one reached committee consideration in the House of Commons and went no further before that parliamentary session ended, so the law that governs your AI today is the law that already governed your data. The bill was C-27 in the 44th Parliament, 1st session, which would have enacted the Artificial Intelligence and Data Act alongside two privacy statutes; LEGISinfo records its status as at consideration in committee in the House of Commons, with its latest activity the second reading and referral to committee on 24 April 2023. It never received Royal Assent. The background is set out in AIDA did not pass.

What does apply is the law that already governed the data:

  • PIPEDA for personal information handled in the course of commercial activity, including its accountability principle, under which an organization remains responsible for personal information transferred to a third party for processing.
  • In British Columbia, the Personal Information Protection Act for private-sector organizations and the Freedom of Information and Protection of Privacy Act for public bodies. There is no British Columbia AI statute.
  • Sector regulators and contractual obligations, which in practice move faster than legislatures and are what most organizations are actually answering to.

Canada’s Centre for Cyber Security publishes applicable guidance in ITSAP.00.041. How any of this applies to your organization is a question for your counsel; what we do is make sure the facts and controls they need are in place and evidenced. The wider statutory picture is mapped in compliance and privacy.

Who issues a certificate, and why it is never SecHB

A certificate against ISO/IEC 42001 is issued by an accredited certification body after its own assessment. SecHB prepares an organization for that assessment and is never the issuer of the result. That separation is structural, not modest: the body that assesses you cannot also have built what it assesses, which is exactly why readiness work and the assessment itself come from different places.

What this engagement produces is readiness — the inventory, the controls, the gap register closed, and the evidence assembled — so that when an assessor, a customer or a regulator looks, they find something rather than a promise.

Roadmap and evidence pack

The roadmap sequences the gap register by dependency and by what unblocks the most: the controls a customer asks about first, the ones an assessor will look for, and the ones that are cheap now and expensive later. Each item carries an owner and a target.

The evidence pack is what you put in front of a customer: the register, the control set with the evidence each produces, the policy suite, the decision record for approved use cases, and the roadmap for what is not done yet. Its shape is set out in the evidence pack, and the same discipline applied to the AI systems themselves is AI security assessment.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Who issues an ISO/IEC 42001 certificate?

A certificate against ISO/IEC 42001 is issued by an accredited certification body after its own assessment. SecHB prepares an organization for that assessment and is never the issuer of the result.

Does Canada have an AI law?

Canada has no federal AI statute in force. The bill that would have created one reached committee consideration in the House of Commons and went no further before that parliamentary session ended, so the law that governs your AI today is the law that already governed your data.

Does the EU AI Act apply to a Canadian company?

A Canadian company can fall within the EU AI Act’s reach through its customers, its products or its operations in the Union, and the assessment of whether it does is a legal question for your counsel rather than one we answer.

ISO/IEC 42001 or NIST AI RMF — which should we pick?

Pick ISO/IEC 42001 when a customer or a market expects a recognized certificate; pick NIST AI RMF 1.0 when you want a risk framework to organize around without a certificate at the end of it. The controls you build overlap heavily either way.

Start with the register

Describe who is asking, what AI is in use and which framework you are being measured against. The reply says what the gap review would cover and what the evidence pack would contain.

Discuss a scope