GaganAI

Sample deliverable · AI Safe Start · $1,500–2,500

What a written AI policy looks like

Not a downloaded template with your name pasted in. This is written around the tools your practice actually uses and the way your team actually works — short enough that people read it, specific enough that they can follow it.

This is a sample, written for a fictional practice. Meridian Financial Planning and everyone named here are invented. Yours would be written for your practice, your tools, and your team.

Meridian Financial Planning — AI Use Policy
Version 1.0 · Effective 14 March 2026 · Owner: Sandra Okafor, Principal · Next review: March 2027
Applies to everyone: the principal, all staff, contractors, and students — on any device, including personal ones.

The one rule that matters most

Never put client-identifying information into an AI tool that has not been approved in section 4.

If you remember nothing else from this policy, remember that sentence. Policies that open with definitions and scope statements do not get read; this one opens with the rule.

How we classify information

ClassWhat it coversInto an approved tool?
PublicMarketing copy, published articles, general education materialYes
InternalDraft processes, meeting agendas, non-client templatesYes
Client-confidentialAnything naming or identifying a client, their household, their holdings, their circumstancesOnly with identifiers removed
Regulated / sensitiveSIN, date of birth, account numbers, banking details, government ID, health informationNever. No exceptions.

When in doubt, treat it as client-confidential and ask Sandra.

Removing identifiers, in practice

Abstract rules do not change behaviour. Worked examples do — so the policy carries the actual before and after, and so does the training session.

Not acceptable

“Here's Priya Raman's statement, SIN 123-456-789 — summarise it and draft her a note about the RRSP room.”

Fine

“Draft a plain-language explanation of how unused RRSP contribution room carries forward, for a client in their late fifties.”

A human reviews everything

AI output is a draft, never a finished product. Nothing produced with AI assistance goes to a client, a regulator, or the public until a person here has read it in full and taken responsibility for it. We do not use AI to generate personalised financial recommendations — advice is a human judgment made by a qualified person.

If something goes wrong

Mistakes happen. Reporting one quickly is treated as doing the right thing, not as a disciplinary matter — because a team that fears blame hides mistakes, and a hidden mistake is the expensive kind.

  1. Stop. Don't send anything further or try to delete your way out of it.
  2. Write down what happened — which tool, what information, roughly when.
  3. Tell Sandra the same day.
  4. Sandra decides on next steps, including whether the client must be told, taking advice where needed.

The vendor due-diligence file

A written policy on its own answers “what may we do?” It does not answer “who else holds our client data, and on what terms?” — which is the question a compliance review, a professional liability insurer, or a nervous client will actually ask. So every approved tool gets a one-page file.

Example entry

Tool and plan
ChatGPT Business
Approved for
Internal + de-identified client-confidential
Trained on our data?
No — verified in workspace settings 14 Mar 2026
Who has access
4 named staff, practice email only, MFA on
Data location
Recorded from vendor documentation, dated
Next review
March 2027, or on any terms change

Every claim carries the date it was checked. That date is what makes the file credible in a year's time, when the vendor's settings have moved and nobody remembers what was true at signing.

Also included in AI Safe Start: an inventory of every AI use case across the practice, the approved-tools checklist with each setting verified and dated, the 90-minute team training session, a one-page statement you can show clients, and a signed acknowledgement from every member of staff.

What this is not: a security audit, a penetration test, or a certification that your practice complies with PIPEDA, CIRO rules, or any other regulation. It is a written policy, configured tools, and a trained team.

Want this for your practice?

Half an hour on a call is enough to tell whether it's worth doing — and I'll say so if it isn't.