Back to Home

Solutions · Financial services

AI your compliance officer can sign off on

Advisors summarize portfolios with it. Analysts model with it. The question isn't whether your firm uses AI — it's what leaves in the prompt on a busy day, and what your next audit shows you did about it.

The duty you carry

A client's holdings, a pending transaction, an account number in a reconciliation note: financial data is identifying, material, and regulated all at once. Privacy law treats financial records as sensitive; regulators expect documented control over where client data flows, including to technology providers staff adopt on their own; and material non-public information carries its own rules the moment it reaches an outside service. "The tool seemed helpful" is not a control framework — a logged, prompt-level safeguard is.

The moment it breaks

Synthetic example. The real version happens on your busiest day.

TypedDraft a portfolio review for Marcus Chen — his RRSP #5521-88410 is overweight after the $1.8M vested-stock deposit last month.
SentDraft a portfolio review for [NAME] — his [ACCOUNT] is overweight after the [HOLDINGS] last month.

The review gets drafted. The client, the account, and the position never leave the firm — and the event is logged for your next compliance review.

Caught, in your vocabulary

Client identities and contacts

Names, emails, and household details that connect a prompt to a client file.

Account and payment numbers

Account, card, and transit numbers riding along in notes, statements, and reconciliations.

Holdings, transactions, and deal terms

Positions, pending trades, and the material non-public information markets care about.

The rules you answer to

01

PIPEDA and provincial privacy law

Financial records are personal information with heightened sensitivity. Safeguards must be demonstrable, not assumed.

02

Regulator guidance on technology risk

Supervisors expect documented oversight of where client data flows — including the AI tools employees reach for without asking.

03

Market conduct and MNPI

Material non-public information in a public AI tool is disclosure you can't take back. Catching it at the prompt is the control.

Also relevant: SOC 2 · NIST AI RMF

Answers for your situation

All guides

What the rules say

Credit unions, wealth managers, and MGAs: do OSFI B-10 and B-13 apply to employee AI use?

OSFI Guidelines B-10 and B-13 bind federally regulated financial institutions, so most provincially regulated credit unions, wealth managers, and MGAs are not directly subject to them. They still tend to reach you through the federally regulated insurers, banks, and trust companies you work with, and through provincial guidance built on the same expectations. Either way, the practical test is the same: can you show that client and member data does not leave in an employee's AI prompt?

Read the guide

Specific work and data

M&A boutiques: can the deal team put data room documents and diligence summaries into AI?

Only into a tool the firm has vetted, and only if the NDA, the client and the law allow it. Evaluation material is usually shared under an NDA that limits who may receive it and what it may be used for, personal information in the data room is often shared under a privacy law exception tied to the transaction, and a public company deal may involve undisclosed material facts. Pasting that material into a personal AI account can fall outside all three.

Read the guide
Fractional CFOs: is it safe to keep several clients' financials in one AI account?

Not without deliberate separation. Features such as memory, chat history, projects and custom GPTs are built to carry context forward, so one client's figures can shape the answers you get for another. If you are a CPA in Ontario, Rule 208 of the CPA Code prohibits using one client's confidential information for the advantage of a third party and requires measures that limit access to it, and CPA Ontario's 2026 AI guidance says confidential data should go only into environments verified as secure.

Read the guide
Can contact centre agents use AI to draft replies that contain customer personal information?

Agents can use AI to improve tone and structure, but customer identifiers, account numbers, card data and health or claim details should not go into a public AI tool. The organization remains accountable for customer information it hands to any third party, and a personal AI account comes with no contract that protects it. The practical answer is to keep AI in the workflow while removing personal information before a prompt is submitted.

Read the guide

From our research