// Draft for compliance reviewAI use policy: Your firm
Policy owner: ________ · Approved AI tool: ________ · Client information level: Names, no numbers · Effective: ________ · Next review: ________
Scope
- This policy applies to everyone at the firm who uses AI for work involving clients, including staff and contractors.
- The policy owner named above keeps the list of approved tools and uses, and reviews this policy at least once a year.
Tools
- Only the approved AI tool, approved by the firm, is used for client work. Personal or free AI accounts are never used for client work.
- Before a new AI tool is approved, the firm reviews the provider’s terms, security, data location and training settings, and records the review.
- Access is removed the day someone leaves.
Client information
- Client names, contact details, goals and meeting notes may go into the approved AI tool. Account numbers, balances and holdings do not.
- Social Insurance Numbers, government ID numbers, bank or card numbers, passwords and sign-in codes never go into any AI tool.
- Health information stays out of AI tools unless compliance approves a specific use.
- Clients are told that their information may be processed outside Canada by service providers.
Decisions and review
- AI can research, compare and draft. The advisor makes and records every suitability determination.
- AI drafts. A person reads everything before it reaches a client or the client file, and sends it from firm systems.
- AI tools are watched for bias toward particular products, and any concern goes to compliance.
Records and disclosure
- Client communications, and AI output that becomes part of a client record, are kept in firm systems for 7 years (NI 31-103 s.11.6).
- Clients are told at the start of a meeting when an AI notetaker is running. Only the approved notetaker is used.
- Clients are told how AI is used in the service they receive, in wording compliance approves.
- AI-drafted marketing goes through the normal approval process, follows anti-spam law, and never overstates what AI does.
Security and incidents
- Every account the AI connects to has two-step sign-in and a unique password. Devices are locked, updated and encrypted.
- Anyone who thinks client information may have leaked through an AI tool tells the policy owner the same day, so the firm can assess it and report it where required.
- Everyone who uses AI for client work completes training on this policy before they start, and when it changes.
- Breaking this policy is handled under the firm’s normal disciplinary process.
I have read this policy and will follow it.
Name ____________Signature ____________Date ________
General information, not legal advice. Adapted from the Sidekick Orchestration Advisor AI use map, Version 1.0, September 28, 2026.