Meridian Financial Planning — AI Use Policy
Version 1.0 · Effective 14 March 2026 · Owner: Sandra Okafor, Principal · Next review: March 2027
Applies to everyone: the principal, all staff, contractors, and students — on any device, including personal ones.
The one rule that matters most
Never put client-identifying information into an AI tool that has not been approved in section 4.
If you remember nothing else from this policy, remember that sentence. Policies that open with definitions and scope statements do not get read; this one opens with the rule.
How we classify information
| Class | What it covers | Into an approved tool? |
|---|---|---|
| Public | Marketing copy, published articles, general education material | Yes |
| Internal | Draft processes, meeting agendas, non-client templates | Yes |
| Client-confidential | Anything naming or identifying a client, their household, their holdings, their circumstances | Only with identifiers removed |
| Regulated / sensitive | SIN, date of birth, account numbers, banking details, government ID, health information | Never. No exceptions. |
When in doubt, treat it as client-confidential and ask Sandra.
Removing identifiers, in practice
Abstract rules do not change behaviour. Worked examples do — so the policy carries the actual before and after, and so does the training session.
Not acceptable
“Here's Priya Raman's statement, SIN 123-456-789 — summarise it and draft her a note about the RRSP room.”
Fine
“Draft a plain-language explanation of how unused RRSP contribution room carries forward, for a client in their late fifties.”
A human reviews everything
AI output is a draft, never a finished product. Nothing produced with AI assistance goes to a client, a regulator, or the public until a person here has read it in full and taken responsibility for it. We do not use AI to generate personalised financial recommendations — advice is a human judgment made by a qualified person.
If something goes wrong
Mistakes happen. Reporting one quickly is treated as doing the right thing, not as a disciplinary matter — because a team that fears blame hides mistakes, and a hidden mistake is the expensive kind.
- Stop. Don't send anything further or try to delete your way out of it.
- Write down what happened — which tool, what information, roughly when.
- Tell Sandra the same day.
- Sandra decides on next steps, including whether the client must be told, taking advice where needed.
The vendor due-diligence file
A written policy on its own answers “what may we do?” It does not answer “who else holds our client data, and on what terms?” — which is the question a compliance review, a professional liability insurer, or a nervous client will actually ask. So every approved tool gets a one-page file.
Example entry
- Tool and plan
- ChatGPT Business
- Approved for
- Internal + de-identified client-confidential
- Trained on our data?
- No — verified in workspace settings 14 Mar 2026
- Who has access
- 4 named staff, practice email only, MFA on
- Data location
- Recorded from vendor documentation, dated
- Next review
- March 2027, or on any terms change
Every claim carries the date it was checked. That date is what makes the file credible in a year's time, when the vendor's settings have moved and nobody remembers what was true at signing.
Also included in AI Safe Start: an inventory of every AI use case across the practice, the approved-tools checklist with each setting verified and dated, the 90-minute team training session, a one-page statement you can show clients, and a signed acknowledgement from every member of staff.
What this is not: a security audit, a penetration test, or a certification that your practice complies with PIPEDA, CIRO rules, or any other regulation. It is a written policy, configured tools, and a trained team.