AI governance for a smaller manufacturer or distributor
AI governance is how your company decides which AI tools people may use and what data each tool may see. It also sets who checks AI work before it leaves the building, and what you keep on record. A company of 30 people can run it with one named owner and a one-page register. This page shows that setup, explains the main frameworks in plain words, and sets out the Canadian rules as of September 2026.

What AI governance means for a company your size
Your AI policy is the document staff read and follow, and governance is how the decisions behind that policy get made. AI security covers where your data goes once a tool has it, and what the model keeps. Governance does not cover attacks that use AI against you, such as fake invoices and cloned voices. Those are covered in AI cybersecurity for manufacturers.
Statistics Canada asked businesses whether they had used AI to produce goods or deliver services over the previous 12 months. In the second quarter of 2026, 13.1 percent of manufacturers and 7.9 percent of wholesalers said yes, against 19.2 percent across all industries, according to the agency’s table by industry.
In the same Statistics Canada survey, 13.4 percent of businesses named cybersecurity or privacy concerns as a barrier to using AI, the most common answer. Cost came second, at 10.6 percent.
What AI governance decides
AI governance at a smaller company settles four questions. Each answer goes into the register described in the next section.
Which AI tools are allowed
Keep two lists: the AI tools staff may use for work, and the tools they may not use. Count AI features inside software you already pay for, such as an assistant built into your email or your ERP. The Canadian Centre for Cyber Security (the Cyber Centre) recommends the same approach in its top 10 AI security actions: “Apply allow and deny lists for AI solutions.”
Some business plans let an administrator enforce part of the list. Microsoft’s Copilot privacy page says admins “have full control to select which agents are allowed in their organization.” To find the tools people already use on personal accounts, see shadow AI at a smaller company. To choose a tool you can approve, see ChatGPT alternatives for business in Canada.
What data each tool may see
Sort the data your company holds into a few classes, then decide which classes each tool may read. At a plant or a distributor, the usual classes are drawings, prices and costs, customer lists, and employee files.
PIPEDA, the federal private-sector privacy law, keeps you responsible for personal information that you transfer to a third party for processing. Principle 4.1.3 asks you to use “contractual or other means” to give that information a comparable level of protection (PIPEDA, Schedule 1). The privacy commissioners’ principles for generative AI give organizations that use it this advice: where personal information, especially sensitive or confidential personal information, must go into a prompt, “only do so where authorised.”
What happens to the data after a tool receives it, including what the model keeps, is covered in AI security for a smaller company.
Who approves the output
Name the person who checks each kind of AI output before it takes effect. The estimator approves quotes that AI drafts, the buyer approves purchase orders, and whoever sends a customer email approves its text. The Cyber Centre’s action 9 asks for the same control: “Ensure that human-in-the-loop oversight and execution controls are in place.” Human-in-the-loop means a person reviews the output before anyone acts on it.
What you keep on record
Keep an inventory of the AI tools in use and the decisions made about each one. The NIST framework, described below, asks for mechanisms to inventory AI systems (Govern 1.6).
Innovation, Science and Economic Development Canada (ISED) publishes an implementation guide for managers of AI systems, written to help organizations apply the voluntary code of conduct described below. It covers AI run “for internal business purposes” and suggests a central repository of AI documentation, such as risk assessments and incident reports, kept “with an appropriate retention period.” At a company your size, that repository is the register below, plus a folder of vendor terms and approvals.
A governance setup a 30-person company can run
This setup needs one named owner and a one-page register, and it fits a company with no compliance team.
Name one owner
Pick one person to own AI governance, usually the owner, the president or the operations lead. PIPEDA already asks each organization it covers to designate an individual accountable for its compliance with the privacy principles (principle 4.1). In Quebec, the private sector act gives the role of person in charge of protecting personal information to the person with the highest authority in the enterprise. That person may delegate the role in writing (section 3.1).
NIST’s Govern 2.3 places responsibility for decisions about AI risks with executive leadership. Give the AI role to the person who already holds the privacy role, so decisions about data and decisions about AI sit with one owner.
Keep a one-page AI register
The register is one table, with a row for each AI tool and for each AI feature inside software you already own. Keep it in a shared spreadsheet that only the owner edits. The rows below are generic examples, with the review dates left in square brackets.
| Tool and plan | Owner | Data it may see | Data it must not see | Who approves output | Vendor terms checked | Next review |
|---|---|---|---|---|---|---|
| General chat assistant, business plan | Operations lead | Procedures, public product data, draft emails | Customer lists, costs and margins, employee files | The person who sends the text | Training, retention, storage location | [Date] |
| Quote drafting tool on company data | President | Drawings, past quotes, material prices | Employee files | Estimator | Same, plus where the model runs | [Date] |
| AI screening feature in hiring software | Office manager | Applications for the posted job | Files on current employees | Hiring manager, for every decision | Same, plus the Ontario posting disclosure where it applies | [Date] |
Fill in the row before a tool goes into use. A tool with no row is not approved.
Add an approval step for new tools
- A staff member asks the owner for the tool and names the job it is for.
- The owner reads the vendor’s terms: whether it trains models on your data, how long it keeps prompts, and where it stores them. The Cyber Centre recommends vendor contracts with clauses “prohibiting unauthorized use of organizational data for model training.” The full checklist for this review is in secure AI at work.
- If the tool will handle personal information and Quebec’s private sector act applies to you, the owner completes a privacy impact assessment first. That is a written review of which personal information a system uses and how it is protected. The Quebec section says when the Act requires one.
- The owner records the decision in the register, with the data classes allowed and the person who approves output.
Review on a schedule and retire tools
Give each row a review date, and review it sooner when a vendor changes its terms or its plans. NIST’s Govern 1.7 covers decommissioning AI systems. When you retire a tool, close its accounts and handle the data it holds under your retention rules. Keep the row, marked retired, as part of the record.
Train the people who use AI
Among businesses that use AI, 32.0 percent reported AI-related training for existing employees, and 21.6 percent for existing executives, according to Statistics Canada. PIPEDA already counts training staff on your privacy policies and practices as part of accountability (principle 4.1.4).
ISED’s guide asks for acceptable use policies that set out appropriate use, prohibited activities and user responsibilities. Those written rules belong in your AI policy for employees, which has a template you can adapt. For sessions where your team learns AI on its own work, see AI training for your team.
Start with the tools your team already uses
Tell Derik which AI tools your staff use today and which records they touch. He will tell you where a private setup on your own data would fit.
Start a conversationAI governance frameworks explained plainly
An AI governance framework is a published set of practices for deciding how an organization uses AI and recording those decisions. Three of them apply to a company that uses AI. The fourth, the federal voluntary code of conduct, is written mainly for AI vendors. A table at the end of this section compares all four.
NIST AI Risk Management Framework
The US National Institute of Standards and Technology (NIST) released the AI Risk Management Framework 1.0 on January 26, 2023. NIST says it is “intended for voluntary use,” and that version 1.0 is being revised as part of the White House AI Action Plan.
The framework core has four functions:
- Govern. Decide who is responsible, which rules apply and what gets documented.
- Map. Establish where AI is used and what could go wrong in that setting.
- Measure. Test and track the risks you identified.
- Manage. Rank those risks and act on them.
NIST calls Govern “a cross-cutting function” that enables the other three. It is the part a small company can use first, because most of it is about ownership and records. Govern 1.1 asks that legal and regulatory requirements involving AI are understood, managed and documented. Govern 6.1 covers risks from third-party AI, including infringement of intellectual property.
ISO/IEC 42001
ISO/IEC 42001:2023 is the international standard for an AI management system. A management system is the written set of rules and responsibilities a company follows for one area of its work, the kind ISO 9001 sets up for quality. ISO published it in December 2023 and says it is for organizations “of any size involved in developing, providing, or using AI-based products or services.” On September 26, 2026, the ISO store listed it at CHF 225.
A company gets certified through an audit by a certification body, and an accreditation body checks the certification bodies. The Standards Council of Canada describes itself as “the only accreditation body in Canada offering Artificial Intelligence Management Systems accreditation, based on ISO/IEC 42001.” It adds that 42001 can be integrated with ISO 9001 “due to its common structure.” If your plant is certified to ISO 9001, your team already knows that structure.
CAN/DGSI 101, the Canadian standard for smaller organizations
CAN/DGSI 101:2025, Ethical Design and Use of Artificial Intelligence by Small and Medium Organizations, sets minimum requirements for organizations “which typically have fewer than 500 employees.” It is limited to AI that uses machine learning for automated decisions, and it includes generative AI and “third-party tools deployed for internal use by the organization.” A chat assistant your staff use for work fits that description.
According to its listing, the standard aligns with the OECD AI Principles, the federal Directive on Automated Decision-Making and the NIST framework. The Digital Governance Council lists it free of charge. On September 26, 2026, the council also listed a paid AIReady validation and verification service to the standard.
Canada’s voluntary code of conduct
The federal Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems dates from September 2023, and its page lists 46 signatories. It is written for organizations “developing or managing the operations of a generative AI system with general-purpose capabilities.” That describes AI vendors more than the companies that buy from them. ISED’s 2026 discussion paper on AI transparency calls it “voluntary and not enforceable.”
ISED’s implementation guide, cited above, fits a company your size better, because it covers AI systems run for internal business purposes.
| Framework | Published by | Binding or voluntary | Cost to read | Certification or verification |
|---|---|---|---|---|
| NIST AI RMF 1.0 | NIST, United States | “Intended for voluntary use,” according to NIST | Free download from NIST | None described on NIST’s page |
| ISO/IEC 42001:2023 | ISO and IEC | No Canadian law requires it | CHF 225 on the ISO store (September 26, 2026) | Audit by a certification body, accredited in Canada by the Standards Council of Canada |
| CAN/DGSI 101:2025 | Digital Governance Council | No Canadian law requires it | Free | AIReady validation and verification, a paid service (September 26, 2026) |
| Voluntary code of conduct | Government of Canada (ISED) | “Voluntary and not enforceable,” according to ISED | Free | Organizations sign it, and 46 are listed |
Where to start
Start with the owner and the register, and use NIST’s Govern function as your checklist. Read CAN/DGSI 101 next, because it is free and written for organizations your size. Look at ISO/IEC 42001 certification when a customer or a contract asks for it.
The Canadian legal picture as of September 2026
This page is general information and is not legal advice. Ask your counsel which rules apply to your company and your data.
No AI-specific federal law applies to your company today
The Artificial Intelligence and Data Act (AIDA) was part of Bill C-27. The bill passed second reading and went to committee on April 24, 2023. It did not pass before the parliamentary session ended on January 6, 2025.
The Prime Minister launched AI for All, Canada’s national AI strategy, on June 4, 2026. The strategy commits to modernizing consumer privacy legislation. It also announces a Canada Trusted AI Certification program “to help Canadians identify trustworthy AI products in the marketplace.”
Bill C-36, introduced on June 15, 2026, would enact the Protecting Privacy and Consumer Data Act. It includes proposed rules on automated decision systems, meaning technology that “assists or replaces the judgment of human decision-makers.” Under the first-reading text, an organization would give a general account of its use of such systems. The account covers decisions about people that could have “a legal or similarly significant effect” on them. On request, the organization would explain such a decision to the person concerned. In September 2026 the bill was at second reading in the House of Commons, so these rules are proposals.
ISED ran a consultation on AI transparency from July 23 to September 23, 2026, and a What We Heard report is to follow. Its discussion paper asks how any measures should account for small and medium-sized enterprises. The federal Directive on Automated Decision-Making applies to institutions subject to the Policy on Service and Digital, which are federal institutions.
Privacy law already covers AI that uses personal information
PIPEDA applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. Organizations under the Alberta, British Columbia or Quebec laws are generally exempt from PIPEDA for that activity inside the province.
The federal, provincial and territorial privacy commissioners published their principles for generative AI in December 2023. They write that generative AI tools “do not occupy a space outside of current legislative frameworks.” They add that many of their considerations will be required to comply with privacy law. For organizations that use generative AI, they recommend privacy impact assessments and tools that respect privacy laws.
Quebec
If you carry on an enterprise in Quebec, the Act respecting the protection of personal information in the private sector applies to you. Law 25 amended it, and these sections bear directly on AI governance. All of them are in force.
- Section 3.1. The person with the highest authority in the enterprise is in charge of protecting personal information, and may delegate the role in writing.
- Section 3.2. The enterprise sets governance policies and practices for personal information, proportionate to its activities and approved by the person in charge. It publishes detailed information about them on its website in simple and clear language.
- Section 3.3. Any project to acquire, develop or overhaul an information system involving personal information requires a privacy impact assessment.
- Section 12.1. The enterprise tells a person when a decision about them rests only on automated processing of their personal information. On request, it tells the person which information was used and the reasons and principal factors behind the decision. The person may also submit observations to a staff member who can review the decision.
- Section 17. Before personal information is communicated outside Quebec, or entrusted to someone outside Quebec, a privacy impact assessment is required.
The Commission d’accès à l’information, Quebec’s privacy regulator, lists the notice on automated decisions among the main changes brought by Law 25.
Ontario
An Ontario employer that uses AI to screen, assess or select applicants for a publicly advertised job must disclose it in the posting. The rule generally applies to postings made on or after January 1, 2026. It does not apply to an employer with fewer than 25 employees on the day of posting (Employment Standards Act guide). Covered employers keep a copy of each posting and any associated application form for 3 years after the posting comes down.
Bill 194, the Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024, received Royal Assent. Its AI rules are for public sector entities.
If you sell into the EU
The EU AI Act became applicable on August 2, 2026, with some exceptions. The AI Omnibus, a package of amendments that entered into force on July 27, 2026, moved the rules for high-risk uses listed in Annex III to December 2, 2027. Article 2(1)(c) reaches providers and deployers outside the EU “where the output produced by the AI system is used in the Union.” If output from your AI tools is used in the EU, ask counsel whether the Act applies to you.
How ThriveAI helps
A tool ThriveAI builds fits the register on this page. Nothing is sent or saved in your systems until the person responsible approves it, and every correction is kept in your company’s own record, which you can export for your AI register.
ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data, and works hands on with your team. The platform it builds on is designed to keep each client’s data on its own server in Canada.
You choose the model that reads your data. One option is an open-weight model, whose files are published so it can run on that server. The other is a hosted model under a written zero data retention agreement, meaning the provider does not store your prompts or its answers after it responds, apart from exceptions the provider lists, such as legal holds. Some hosted models cannot run under zero data retention. As of September 2026, Anthropic requires 30-day retention for four of its models, so the agreement names the model and its service tier. A hosted model may also process requests outside Canada.
Working sessions run on site with your team, in French or English, and include hands-on training. Derik Lawlis, the founder, leads every project and stays close to the build, as About ThriveAI explains.