Sidekick Orchestration
// Advisor AI use map · Canada

Where AI fits your advisory practice,and where it doesn’t.

The AI rules for Canadian advisors in one place: what’s off limits, what your compliance team decides, and where you can start this week. Every rule is sourced.

See my map

By Chase Bernier, Sidekick OrchestrationChecked against 28 official sourcesVersion 1.0 · September 28, 2026Not legal advice

// Your map · investment advisor, British Columbia

Here’s where AI fitsfor you.

Rules from CIRO and NI 31-103, and BC’s Personal Information Protection Act. No Canadian law is written for how advisors use AI, so the limits come from rules you already follow. You stay responsible for everything AI produces.

  1. Never7hard lines from law, regulator rules and plain risk
  2. Your firm decides9areas to settle with your dealer or firm first
  3. Your call3levels of client information to choose from
  4. Go7everyday tasks, each with a prompt to try
// Start this week
  • Research and learning in a business AI plan
  • Meeting notes with your firm’s notetaker
  • Drafting client emails that you read and send
Or start with our free Starter Kit →
// Never

The hard lines.No firm policy makes these okay.

Each line names its authority, so you can see what is binding and what is advice.

Regulator rule + guidance

Let AI make the suitability determination

AI can research, compare and draft. The decision stays with you. Securities regulators say a suitability determination can’t be outsourced, and that at AI’s current stage it can’t stand in for an advising representative making investment decisions.

Law + best practice

Put client information into a personal or free AI account

You stay accountable for client information you give to any outside service, and that needs contract protection. A personal account has no data agreement with your firm, and your firm can’t see, supervise or keep what happens in it.

Regulator rule + best practice

Let AI send anything to a client that no person has read

Client communications must be supervised and must not mislead. Your firm’s rules set whether that is approval before sending or review after. Either way, AI can write a polished email with a wrong number in it. A person reads it and sends it.

Regulator rule

Talk to clients through AI tools your firm can’t capture and keep

Your records must show what you told clients, and you must keep them for 7 years (NI 31-103 s.11.6). An AI app that messages clients outside your firm’s email or CRM leaves a gap in those records. CIRO lists messages through unapproved channels as a common problem.

// Your firm decides

Settle these with compliancebefore you start.

Your dealer or firm must approve and supervise these, and may be stricter than the law. Where it is, the firm’s rule wins.

Which AI tools you may useRegulator rule

At a dealer, the dealer picks the tools. It must vet outside services and supervise how they’re used. Take this page to your branch manager or compliance team and ask which tool is approved. Expect a business plan with training off and a data agreement.

Whether client names and details may go into promptsFirm policy

Privacy law permits it for the purposes the client gave you the information, with safeguards and a contract with the provider. Many firms are stricter, for example names only, with no account numbers or balances. Follow your firm’s version.

AI notetakers on client callsLaw + firm policy

Recording a call you are part of is legal. Privacy law still means telling clients you’re recording and why, at the start. The transcript and summary become client records, so your firm decides the tool, the words you use to tell the client, and where the records are kept.

How AI-drafted emails and marketing get reviewedRegulator rule

Your firm’s communications policy says what needs approval before it goes out and what gets reviewed after. AI drafts follow the same policy.

Telling clients you use AIRegulator guidance

Securities regulators expect firms to disclose AI use that directly affects the service a client gets, usually in the relationship disclosure. Your firm sets the wording.

Your errors and omissions insuranceBest practice

Ask your insurer, or whoever arranges your E&O cover, whether errors in AI-assisted work are covered, and whether they expect anything from you, such as a written policy.

Conflicts and bias in AI toolsRegulator rule + guidance

An AI tool can lean toward in-house or higher-fee products without anyone noticing. Conflict rules still apply, and regulators flag this risk for AI. Your firm decides how tools are tested and watched.

Whether your AI use must be reported to a regulatorRegulator guidance

CIRO says it will ask about AI use in dealer exams. A significant change in how you serve clients may mean updating the firm’s registration filings. Compliance decides.

Canadian data storageFirm policy

No general Canadian privacy law requires client data to stay in Canada. Your firm, a client contract or a carrier may require it. If so, check where the AI tool stores data before you connect it. Clients should be told their data may be processed outside Canada.

// Data map

What information can gointo an AI tool.

“Firm-approved tool” means a business AI plan your firm has approved, with training off and a data agreement in place. Never a personal or free account.

InformationAnswerWhy
Public informationMarket commentary, product documents, rules, your own templatesYesNothing about a client. Use it freely.
Client names and contact detailsName, email, phone, employerFirm-approved toolAllowed with an approved tool. Much of it is already public. Your firm may limit it.
Meeting notes and goalsLife events, family, plans, preferencesFirm-approved toolThis is where AI saves the most time. Read every summary before it goes into the file.
Know-your-client profileIncome, net worth, risk tolerance, time horizonWritten sign-offSensitive financial information. Needs your firm’s written approval and the security basics.
Holdings, statements and policiesAccount values, positions, plan documents, policy detailsWritten sign-offWorth the most for analysis. Check every figure before you rely on it.
Health informationHealth notes from planning conversationsAsk complianceSensitive, and needs express consent. Keep it out of general AI tools unless your firm approves a specific use.
SINs and government ID numbersSIN, driver’s licence, passport numbersNeverThe law limits how a SIN can be used. AI never needs them.
Bank and card numbersAccount, transit and card numbersNeverExactly what fraud needs. AI never needs them.
Passwords and sign-in codesAny login, key or one-time codeNeverAnyone who sees one can act as you.
// By task

What AI can doin your day.

Pick a task. Each one has a prompt you can try today in a firm-approved tool.

Yes, in a firm-approved tool

AI drafts. You send from your firm’s email, so the message is captured.

Good uses

  • Drafting follow-ups, reminders and answers to routine questions
  • Turning your rough notes into a clear email
  • Summarizing a long thread before you reply

Where the line is

  • AI sending on its own
  • A personal account or app writing to clients
  • Anything with a SIN or account number in it

Ask compliance

  • Which drafts need approval before sending
  • How AI-drafted messages are supervised
// Your call

How much should AI knowabout your clients?

Once the hard lines and your firm’s rules are met, this is a choice. No law picks it for you. More information makes AI more useful, and means reading its work more closely. Pick a level. The policy below follows it.

Want a partner to set up your chosen level with your compliance team and IT provider?

// Before client information goes near AI

Lock down the accountsAI connects to.

The biggest risk usually isn’t the AI. It’s a reused password on the email account the AI is connected to.

These protect you whether you use AI or not. For settings, connections and working with your IT provider, read AI and sensitive information.

  • Two-step sign-in on every accountEmail, CRM, cloud storage and the AI tool itself. A stolen password is then not enough on its own.
  • A password manager, with one password per accountNo reused passwords, and none built from family names or birthdays.
  • A business AI plan, not a personal oneTraining off, a data agreement with the provider, and access you can remove the day someone leaves.
  • Locked, updated devicesScreen lock, automatic updates and disk encryption on your laptop and phone.
  • Approved connections, drafts before sendsYour IT provider approves which apps connect to email and files. Start with read-only access and drafts.
  • A plan for when something goes wrongBackups, and knowing who to call and what you must report.
// In practice

Advisors and finance leadersalready working this way.

Kevin ChaputInsurance advisor, Bloom Benefits
“I built an interactive dashboard with my company’s branding in two minutes. Commission structures, stages, all of it. Then I built an accounting folder that basically works like a bookkeeper.”

Training sessions and client calls feed into Solo, which updates Salesforce, compares carrier PDFs to the client’s situation, and drafts follow-up emails in his voice.

Calls and trainingUpdates and draftsKevin reviews
Nathan ParkhouseFounder, Nathan Parkhouse Advisory
“It remembers. Twenty-five years of relationships, and it holds the ledger: who introduced whom, what I promised, what they said in their own words.”

Pre-call briefs are built from his files, calendar and recent emails. By Nathan’s estimate, preparing properly for a call went from about 45 minutes to about five minutes of reading.

About 45 minutesabout 5to prepare properly for a call

Files, calendar and emailPre-call briefNathan reads
Aman GrewalManaging partner
“It feels like you suddenly have an admin, an analyst, and a small team working behind the scenes.”

An AI workspace helps plan the day, prepare meetings, and draft presentations, investment memos, and financial models.

Research and contextAnalysis and draft workAman decides

Client-reported results, not independently measured. Solo is our 30-day setup for one person: see Sidekick Solo · More client work

// For anything not listed

Five questionsfor any new use of AI.

Answer in order. This is how to decide the next case this page doesn’t cover.

  1. Is the AI making a decision about a client?A recommendation, an approval, a risk rating or a claim.
  2. Does it touch anything on the never list?SINs, ID numbers, bank or card numbers, passwords.
  3. Is the tool approved by your firm?A business plan your compliance team or principal has signed off.
  4. Is the result saved where your records must be kept?Emails in firm email, notes in the CRM, analysis in the client file.
  5. Will a person read it before it reaches a client or the file?Emails, summaries, notes, analysis.
// Result

Start with question 1.

Answer in order. You’ll see the result as you go.

// Your policy

A firm AI use policy,ready for compliance to adapt.

Fill in your details. The text follows your role, province and level. Copy it into your own document, or print it, and have compliance approve it.

// Draft for compliance review

AI use policy: Your firm

Policy owner: ________ · Approved AI tool: ________ · Client information level: Names, no numbers · Effective: ________ · Next review: ________

Scope

  1. This policy applies to everyone at the firm who uses AI for work involving clients, including staff and contractors.
  2. The policy owner named above keeps the list of approved tools and uses, and reviews this policy at least once a year.

Tools

  1. Only the approved AI tool, approved by the firm, is used for client work. Personal or free AI accounts are never used for client work.
  2. Before a new AI tool is approved, the firm reviews the provider’s terms, security, data location and training settings, and records the review.
  3. Access is removed the day someone leaves.

Client information

  1. Client names, contact details, goals and meeting notes may go into the approved AI tool. Account numbers, balances and holdings do not.
  2. Social Insurance Numbers, government ID numbers, bank or card numbers, passwords and sign-in codes never go into any AI tool.
  3. Health information stays out of AI tools unless compliance approves a specific use.
  4. Clients are told that their information may be processed outside Canada by service providers.

Decisions and review

  1. AI can research, compare and draft. The advisor makes and records every suitability determination.
  2. AI drafts. A person reads everything before it reaches a client or the client file, and sends it from firm systems.
  3. AI tools are watched for bias toward particular products, and any concern goes to compliance.

Records and disclosure

  1. Client communications, and AI output that becomes part of a client record, are kept in firm systems for 7 years (NI 31-103 s.11.6).
  2. Clients are told at the start of a meeting when an AI notetaker is running. Only the approved notetaker is used.
  3. Clients are told how AI is used in the service they receive, in wording compliance approves.
  4. AI-drafted marketing goes through the normal approval process, follows anti-spam law, and never overstates what AI does.

Security and incidents

  1. Every account the AI connects to has two-step sign-in and a unique password. Devices are locked, updated and encrypted.
  2. Anyone who thinks client information may have leaked through an AI tool tells the policy owner the same day, so the firm can assess it and report it where required.
  3. Everyone who uses AI for client work completes training on this policy before they start, and when it changes.
  4. Breaking this policy is handled under the firm’s normal disciplinary process.

I have read this policy and will follow it.

Name ____________Signature ____________Date ________

General information, not legal advice. Adapted from the Sidekick Orchestration Advisor AI use map, Version 1.0, September 28, 2026.

Want this policy fitted to your firm’s tools and client work, ready for your compliance lead to review and approve?

// What is changing

Coming next,and what to watch.

// SourcesAll 28 official sources behind this map

Prepared by Chase Bernier, Founder of Sidekick Orchestration. Each rule was checked against its primary source on September 28, 2026. General information, not legal or compliance advice. Your dealer’s, firm’s or carrier’s compliance team has the final say.

  1. PIPEDA, Schedule 1: accountability (4.1.3) and safeguards (4.7)
  2. PIPEDA ss.10.1 and 10.3: breach reports and breach records
  3. BC Personal Information Protection Act
  4. Alberta Privacy Commissioner: breach notification under PIPA s.34.1
  5. Quebec private-sector privacy act (Law 25): ss.3.1, 3.3, 3.5, 3.8, 12, 12.1, 17, 18.3
  6. Quebec Act respecting the distribution of financial products and services, ss.27 and 28
  7. Privacy commissioners of Canada: principles for generative AI (December 2023)
  8. Privacy Commissioner of Canada: processing personal data across borders
  9. Privacy Commissioner of Canada: recording customer telephone calls
  10. Privacy Commissioner of Canada: Social Insurance Numbers
  11. Income Tax Act s.237(2)(b): use of Social Insurance Numbers
  12. CSA Staff Notice and Consultation 11-348: AI systems in capital markets (December 2024)
  13. NI 31-103 (consolidated January 1, 2026): ss.11.1, 11.5, 11.6, 13.2, 13.3, 13.4, 13.18
  14. CIRO Investment Dealer and Partially Consolidated Rules: 3402, 3601 to 3602, 3703, 3803 to 3804
  15. CIRO Mutual Fund Dealer Rules: 2.2.6 (suitability), 2.7 (sales communications)
  16. CIRO: cybersecurity incident reporting
  17. CIRO Compliance Report 2026 (February 17, 2026)
  18. CIRO: outsourcing arrangements
  19. CIRO: Quebec mutual fund dealers (oversight from July 4, 2026)
  20. CCIR and CISRO: Guidance on Conduct of Insurance Business and Fair Treatment of Customers
  21. FSRA (Ontario): Fair Treatment of Customers, GR0008APP
  22. OSFI Guideline E-23: model risk management (effective May 1, 2027)
  23. AMF Guideline for the Use of Artificial Intelligence (effective May 1, 2027)
  24. FINTRAC: record keeping for securities dealers
  25. FINTRAC: record keeping for life insurance
  26. CRTC: Canada’s anti-spam legislation
  27. Criminal Code s.184: one-party consent to recording
  28. Bill C-36, Protecting Privacy and Consumer Data Act: status
// Next step

Want this set up for your firm?Know where AI fits your firm, and what to do first.

We coach your leaders on AI, then help you roll it out. Your compliance team approves the policy, your IT provider approves the connections, and then we train your advisors.

Have a question first? Text Chase at 778-999-0985 or email chase@sidekickorchestration.ai.

30 minutes with Chase. You leave knowing where AI fits your firm and what to do next, whether that’s with us or not. See how we work with advisory and insurance firms, or try the free AI assessment.