AI governance for a smaller manufacturer or distributor

AI governance is how your company decides which AI tools people may use and what data each tool may see. It also sets who checks AI work before it leaves the building, and what you keep on record. A company of 30 people can run it with one named owner and a one-page register. This page shows that setup, explains the main frameworks in plain words, and sets out the Canadian rules as of September 2026.

Overhead view of a bright production hall with stainless process skids laid out in rows and two technicians at work

What AI governance means for a company your size

Your AI policy is the document staff read and follow, and governance is how the decisions behind that policy get made. AI security covers where your data goes once a tool has it, and what the model keeps. Governance does not cover attacks that use AI against you, such as fake invoices and cloned voices. Those are covered in AI cybersecurity for manufacturers.

Statistics Canada asked businesses whether they had used AI to produce goods or deliver services over the previous 12 months. In the second quarter of 2026, 13.1 percent of manufacturers and 7.9 percent of wholesalers said yes, against 19.2 percent across all industries, according to the agency’s table by industry.

In the same Statistics Canada survey, 13.4 percent of businesses named cybersecurity or privacy concerns as a barrier to using AI, the most common answer. Cost came second, at 10.6 percent.

What AI governance decides

AI governance at a smaller company settles four questions. Each answer goes into the register described in the next section.

Which AI tools are allowed

Keep two lists: the AI tools staff may use for work, and the tools they may not use. Count AI features inside software you already pay for, such as an assistant built into your email or your ERP. The Canadian Centre for Cyber Security (the Cyber Centre) recommends the same approach in its top 10 AI security actions: “Apply allow and deny lists for AI solutions.”

Some business plans let an administrator enforce part of the list. Microsoft’s Copilot privacy page says admins “have full control to select which agents are allowed in their organization.” To find the tools people already use on personal accounts, see shadow AI at a smaller company. To choose a tool you can approve, see ChatGPT alternatives for business in Canada.

What data each tool may see

Sort the data your company holds into a few classes, then decide which classes each tool may read. At a plant or a distributor, the usual classes are drawings, prices and costs, customer lists, and employee files.

PIPEDA, the federal private-sector privacy law, keeps you responsible for personal information that you transfer to a third party for processing. Principle 4.1.3 asks you to use “contractual or other means” to give that information a comparable level of protection (PIPEDA, Schedule 1). The privacy commissioners’ principles for generative AI give organizations that use it this advice: where personal information, especially sensitive or confidential personal information, must go into a prompt, “only do so where authorised.”

What happens to the data after a tool receives it, including what the model keeps, is covered in AI security for a smaller company.

Who approves the output

Name the person who checks each kind of AI output before it takes effect. The estimator approves quotes that AI drafts, the buyer approves purchase orders, and whoever sends a customer email approves its text. The Cyber Centre’s action 9 asks for the same control: “Ensure that human-in-the-loop oversight and execution controls are in place.” Human-in-the-loop means a person reviews the output before anyone acts on it.

What you keep on record

Keep an inventory of the AI tools in use and the decisions made about each one. The NIST framework, described below, asks for mechanisms to inventory AI systems (Govern 1.6).

Innovation, Science and Economic Development Canada (ISED) publishes an implementation guide for managers of AI systems, written to help organizations apply the voluntary code of conduct described below. It covers AI run “for internal business purposes” and suggests a central repository of AI documentation, such as risk assessments and incident reports, kept “with an appropriate retention period.” At a company your size, that repository is the register below, plus a folder of vendor terms and approvals.

A governance setup a 30-person company can run

This setup needs one named owner and a one-page register, and it fits a company with no compliance team.

Name one owner

Pick one person to own AI governance, usually the owner, the president or the operations lead. PIPEDA already asks each organization it covers to designate an individual accountable for its compliance with the privacy principles (principle 4.1). In Quebec, the private sector act gives the role of person in charge of protecting personal information to the person with the highest authority in the enterprise. That person may delegate the role in writing (section 3.1).

NIST’s Govern 2.3 places responsibility for decisions about AI risks with executive leadership. Give the AI role to the person who already holds the privacy role, so decisions about data and decisions about AI sit with one owner.

Keep a one-page AI register

The register is one table, with a row for each AI tool and for each AI feature inside software you already own. Keep it in a shared spreadsheet that only the owner edits. The rows below are generic examples, with the review dates left in square brackets.

Tool and planOwnerData it may seeData it must not seeWho approves outputVendor terms checkedNext review
General chat assistant, business planOperations leadProcedures, public product data, draft emailsCustomer lists, costs and margins, employee filesThe person who sends the textTraining, retention, storage location[Date]
Quote drafting tool on company dataPresidentDrawings, past quotes, material pricesEmployee filesEstimatorSame, plus where the model runs[Date]
AI screening feature in hiring softwareOffice managerApplications for the posted jobFiles on current employeesHiring manager, for every decisionSame, plus the Ontario posting disclosure where it applies[Date]

Fill in the row before a tool goes into use. A tool with no row is not approved.

Add an approval step for new tools

  1. A staff member asks the owner for the tool and names the job it is for.
  2. The owner reads the vendor’s terms: whether it trains models on your data, how long it keeps prompts, and where it stores them. The Cyber Centre recommends vendor contracts with clauses “prohibiting unauthorized use of organizational data for model training.” The full checklist for this review is in secure AI at work.
  3. If the tool will handle personal information and Quebec’s private sector act applies to you, the owner completes a privacy impact assessment first. That is a written review of which personal information a system uses and how it is protected. The Quebec section says when the Act requires one.
  4. The owner records the decision in the register, with the data classes allowed and the person who approves output.

Review on a schedule and retire tools

Give each row a review date, and review it sooner when a vendor changes its terms or its plans. NIST’s Govern 1.7 covers decommissioning AI systems. When you retire a tool, close its accounts and handle the data it holds under your retention rules. Keep the row, marked retired, as part of the record.

Train the people who use AI

Among businesses that use AI, 32.0 percent reported AI-related training for existing employees, and 21.6 percent for existing executives, according to Statistics Canada. PIPEDA already counts training staff on your privacy policies and practices as part of accountability (principle 4.1.4).

ISED’s guide asks for acceptable use policies that set out appropriate use, prohibited activities and user responsibilities. Those written rules belong in your AI policy for employees, which has a template you can adapt. For sessions where your team learns AI on its own work, see AI training for your team.

Start with the tools your team already uses

Tell Derik which AI tools your staff use today and which records they touch. He will tell you where a private setup on your own data would fit.

Start a conversation

AI governance frameworks explained plainly

An AI governance framework is a published set of practices for deciding how an organization uses AI and recording those decisions. Three of them apply to a company that uses AI. The fourth, the federal voluntary code of conduct, is written mainly for AI vendors. A table at the end of this section compares all four.

NIST AI Risk Management Framework

The US National Institute of Standards and Technology (NIST) released the AI Risk Management Framework 1.0 on January 26, 2023. NIST says it is “intended for voluntary use,” and that version 1.0 is being revised as part of the White House AI Action Plan.

The framework core has four functions:

NIST calls Govern “a cross-cutting function” that enables the other three. It is the part a small company can use first, because most of it is about ownership and records. Govern 1.1 asks that legal and regulatory requirements involving AI are understood, managed and documented. Govern 6.1 covers risks from third-party AI, including infringement of intellectual property.

ISO/IEC 42001

ISO/IEC 42001:2023 is the international standard for an AI management system. A management system is the written set of rules and responsibilities a company follows for one area of its work, the kind ISO 9001 sets up for quality. ISO published it in December 2023 and says it is for organizations “of any size involved in developing, providing, or using AI-based products or services.” On September 26, 2026, the ISO store listed it at CHF 225.

A company gets certified through an audit by a certification body, and an accreditation body checks the certification bodies. The Standards Council of Canada describes itself as “the only accreditation body in Canada offering Artificial Intelligence Management Systems accreditation, based on ISO/IEC 42001.” It adds that 42001 can be integrated with ISO 9001 “due to its common structure.” If your plant is certified to ISO 9001, your team already knows that structure.

CAN/DGSI 101, the Canadian standard for smaller organizations

CAN/DGSI 101:2025, Ethical Design and Use of Artificial Intelligence by Small and Medium Organizations, sets minimum requirements for organizations “which typically have fewer than 500 employees.” It is limited to AI that uses machine learning for automated decisions, and it includes generative AI and “third-party tools deployed for internal use by the organization.” A chat assistant your staff use for work fits that description.

According to its listing, the standard aligns with the OECD AI Principles, the federal Directive on Automated Decision-Making and the NIST framework. The Digital Governance Council lists it free of charge. On September 26, 2026, the council also listed a paid AIReady validation and verification service to the standard.

Canada’s voluntary code of conduct

The federal Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems dates from September 2023, and its page lists 46 signatories. It is written for organizations “developing or managing the operations of a generative AI system with general-purpose capabilities.” That describes AI vendors more than the companies that buy from them. ISED’s 2026 discussion paper on AI transparency calls it “voluntary and not enforceable.”

ISED’s implementation guide, cited above, fits a company your size better, because it covers AI systems run for internal business purposes.

FrameworkPublished byBinding or voluntaryCost to readCertification or verification
NIST AI RMF 1.0NIST, United States“Intended for voluntary use,” according to NISTFree download from NISTNone described on NIST’s page
ISO/IEC 42001:2023ISO and IECNo Canadian law requires itCHF 225 on the ISO store (September 26, 2026)Audit by a certification body, accredited in Canada by the Standards Council of Canada
CAN/DGSI 101:2025Digital Governance CouncilNo Canadian law requires itFreeAIReady validation and verification, a paid service (September 26, 2026)
Voluntary code of conductGovernment of Canada (ISED)“Voluntary and not enforceable,” according to ISEDFreeOrganizations sign it, and 46 are listed

Where to start

Start with the owner and the register, and use NIST’s Govern function as your checklist. Read CAN/DGSI 101 next, because it is free and written for organizations your size. Look at ISO/IEC 42001 certification when a customer or a contract asks for it.

The Canadian legal picture as of September 2026

Not legal advice

This page is general information and is not legal advice. Ask your counsel which rules apply to your company and your data.

No AI-specific federal law applies to your company today

The Artificial Intelligence and Data Act (AIDA) was part of Bill C-27. The bill passed second reading and went to committee on April 24, 2023. It did not pass before the parliamentary session ended on January 6, 2025.

The Prime Minister launched AI for All, Canada’s national AI strategy, on June 4, 2026. The strategy commits to modernizing consumer privacy legislation. It also announces a Canada Trusted AI Certification program “to help Canadians identify trustworthy AI products in the marketplace.”

Bill C-36, introduced on June 15, 2026, would enact the Protecting Privacy and Consumer Data Act. It includes proposed rules on automated decision systems, meaning technology that “assists or replaces the judgment of human decision-makers.” Under the first-reading text, an organization would give a general account of its use of such systems. The account covers decisions about people that could have “a legal or similarly significant effect” on them. On request, the organization would explain such a decision to the person concerned. In September 2026 the bill was at second reading in the House of Commons, so these rules are proposals.

ISED ran a consultation on AI transparency from July 23 to September 23, 2026, and a What We Heard report is to follow. Its discussion paper asks how any measures should account for small and medium-sized enterprises. The federal Directive on Automated Decision-Making applies to institutions subject to the Policy on Service and Digital, which are federal institutions.

Privacy law already covers AI that uses personal information

PIPEDA applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. Organizations under the Alberta, British Columbia or Quebec laws are generally exempt from PIPEDA for that activity inside the province.

The federal, provincial and territorial privacy commissioners published their principles for generative AI in December 2023. They write that generative AI tools “do not occupy a space outside of current legislative frameworks.” They add that many of their considerations will be required to comply with privacy law. For organizations that use generative AI, they recommend privacy impact assessments and tools that respect privacy laws.

Quebec

If you carry on an enterprise in Quebec, the Act respecting the protection of personal information in the private sector applies to you. Law 25 amended it, and these sections bear directly on AI governance. All of them are in force.

The Commission d’accès à l’information, Quebec’s privacy regulator, lists the notice on automated decisions among the main changes brought by Law 25.

Ontario

An Ontario employer that uses AI to screen, assess or select applicants for a publicly advertised job must disclose it in the posting. The rule generally applies to postings made on or after January 1, 2026. It does not apply to an employer with fewer than 25 employees on the day of posting (Employment Standards Act guide). Covered employers keep a copy of each posting and any associated application form for 3 years after the posting comes down.

Bill 194, the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, received Royal Assent. Its AI rules are for public sector entities.

If you sell into the EU

The EU AI Act became applicable on August 2, 2026, with some exceptions. The AI Omnibus, a package of amendments that entered into force on July 27, 2026, moved the rules for high-risk uses listed in Annex III to December 2, 2027. Article 2(1)(c) reaches providers and deployers outside the EU “where the output produced by the AI system is used in the Union.” If output from your AI tools is used in the EU, ask counsel whether the Act applies to you.

How ThriveAI helps

A tool ThriveAI builds fits the register on this page. Nothing is sent or saved in your systems until the person responsible approves it, and every correction is kept in your company’s own record, which you can export for your AI register.

ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data, and works hands on with your team. The platform it builds on is designed to keep each client’s data on its own server in Canada.

You choose the model that reads your data. One option is an open-weight model, whose files are published so it can run on that server. The other is a hosted model under a written zero data retention agreement, meaning the provider does not store your prompts or its answers after it responds, apart from exceptions the provider lists, such as legal holds. Some hosted models cannot run under zero data retention. As of September 2026, Anthropic requires 30-day retention for four of its models, so the agreement names the model and its service tier. A hosted model may also process requests outside Canada.

Working sessions run on site with your team, in French or English, and include hands-on training. Derik Lawlis, the founder, leads every project and stays close to the build, as About ThriveAI explains.

Questions people ask

Is AI governance required by law in Canada?
No federal law written only for AI applies to private companies as of September 2026. Privacy law already covers AI that uses personal information, and Quebec's private sector act requires notice when a decision about a person rests only on automated processing. In Ontario, employers with 25 or more employees must disclose AI screening in public job postings. This is general information and is not legal advice.
What happened to the Artificial Intelligence and Data Act?
It was part of Bill C-27, which was still in committee when the parliamentary session ended on January 6, 2025, so it did not pass. In June 2026 the government introduced Bill C-36, a privacy bill with proposed rules on automated decision systems. It would require a general account of how an organization uses them for decisions that could significantly affect people, and an explanation of such a decision on request. The bill was at second reading in September 2026.
What is an AI governance framework?
It is a published set of practices for deciding how an organization uses AI and recording those decisions. The best known are the NIST AI Risk Management Framework, which is voluntary, and ISO/IEC 42001, which a company can be certified against. CAN/DGSI 101:2025 is the Canadian standard for organizations that typically have fewer than 500 employees.
Who should own AI governance in a small company?
One named person, usually the owner, the president or the operations lead. PIPEDA already asks you to designate someone accountable for personal information. In Quebec, the person with the highest authority holds that role unless it is delegated in writing.
What is the difference between AI governance and an AI policy?
Governance is how decisions about AI get made and recorded: who approves a tool, what data it may see and who checks its output. The AI policy is the document staff read and follow.
Do we need ISO/IEC 42001 certification?
No Canadian law requires it. On September 26, 2026, the ISO store listed the standard at CHF 225. Certification needs an audit by a certification body, and in Canada the Standards Council of Canada accredits those bodies. Start with an owner and a register, and look at certification when a customer or a contract asks for it.
Does AI governance apply if staff only use ChatGPT?
Yes. A chat assistant is an AI tool that staff put company data into. The Canadian Centre for Cyber Security recommends lists of approved AI tools and controls on shadow AI, meaning AI tools staff use without the company's approval. CAN/DGSI 101 also counts third-party tools deployed for internal use as AI.

Contact

Put a one-page AI register in place

Tell Derik which AI tools your team uses today and who checks what they draft. He will tell you what your register should list and who should own it.

Prefer to talk? Book a meeting.

Your message goes to Derik Lawlis, the founder.