AI Adoption ReadinessFractional CISO
PricingAbout
Senior led AI governance and compliance. Canada wide.

Senior practitioners. Not a platform.

Auxlo is a senior led AI governance and compliance practice for regulated Canadian organizations. Every engagement is delivered by a credentialed practitioner, with no junior hand offs, no offshore drafting, and no template dump. We map how AI moves your data, govern it against the frameworks that bind you, and leave you with evidence an auditor accepts.

We work with law firms, clinics, financial services, and technology companies that cannot afford to get this wrong.

Flat fee, known up front. A senior practitioner replies in under 12 hours, a real person, not a bot.

Coverage

What we cover, and what we will tell you we do not.

One practice for the binding Canadian statutes and the international frameworks your clients ask for. If a request falls outside what we can deliver at a senior standard, we say so on the first call and point you to someone who can.

Canadian law, binding
  • PIPEDA
  • Law 25, Quebec
  • PHIPA and provincial health acts
  • Alberta PIPA
  • BC PIPA
International frameworks, requested
  • SOC 2, Type I and Type II readiness
  • ISO 27001
  • ISO 42001, AI management
  • GDPR readiness
  • NIST AI RMF alignment
AI governance, applied
  • AI tool inventory and risk register
  • Human oversight checkpoints
  • Vendor and model due diligence
  • AI use policy and staff literacy
  • Board and client reporting

We prepare you to pass. The independent auditor or certification body issues the report or certificate.

The path

From your first AI tool to your auditor's sign-off, one clear path.

Step 1
Assess
AI Adoption Readiness Assessment

A fixed fee diagnostic. We inventory every AI tool you use, assess the risk against Canadian privacy law and the international AI and security frameworks, tell you which tools are safe for your data, and give you a prioritized roadmap of fixes to make before you scale.

See the AI Adoption Readiness Assessment
Step 2
Build
Governed AI and compliance programs

We build the program that satisfies the rules: AI use policies, human oversight controls, confidentiality controls, vendor due diligence, staff AI literacy training, and the compliance evidence your auditor or your clients ask for. This is where MapleGuard, our Canadian compliance work, and Auxlo Global, our international framework work, both live.

See how we build
Step 3
Stay
Ongoing partner retainer

We keep your AI inventory and risk register current, vet new AI tools before you adopt them, deliver quarterly reviews, and keep you ahead of the rules as they change.

Learn about the retainer
Confidentiality and human oversight

Your sensitive data stays yours.

For law firms and clinics, the risk is not only compliance on paper, it is confidentiality in practice. We build AI adoption so your privileged and personal data never trains a public model. Every automation carries a mandatory human checkpoint. Legal research and drafting are verified against the source, not taken on trust. We work from encrypted, secured devices, carry cyber liability coverage, and can sign a mutual confidentiality agreement before any engagement begins.

  • Privileged and personal data never trains a public model
  • A mandatory human checkpoint on every automation
  • Research and drafting verified against the source
  • Encrypted, secured devices and cyber liability coverage
  • Mutual confidentiality agreement signed before we begin
Before you scale

Seven questions we will ask you, and your board will ask you next.

If you can answer all seven with evidence, you do not need us yet. Most organizations can answer two or three.

Work through these with a senior practitioner
  1. 01Which AI tools are in use across the organization right now, including the ones nobody approved?
  2. 02For each one, what data goes in, and where does that data physically live?
  3. 03Which of those tools train on your inputs, and can you prove they do not?
  4. 04Where is the human checkpoint before an AI output reaches a client, a patient, or a regulator?
  5. 05Which statute or framework governs each use case, and who signed off on that mapping?
  6. 06If a client or a regulator asked for your AI governance evidence today, what would you send?
  7. 07Who is accountable when an AI output is wrong, and is that written down?
Canadian law we cover (MapleGuard)
International frameworks (Auxlo Global)
Why this matters now

The numbers Canadian boards are working with.

$25M
Maximum administrative penalty under Law 25, or 4 percent of worldwide turnover
$6.3M
Average cost of a data breach for a Canadian organization
1 in 4
Canadian businesses now use AI in producing goods or delivering services
12h
Senior practitioner reply, a real person, not a bot

Sources: Office of the Privacy Commissioner of Canada and Commission d'accès à l'information du Québec published guidance, IBM Cost of a Data Breach Report, and Statistics Canada surveys on business AI adoption. Figures are indicative of the published ranges, not a guarantee of your outcome.

Stacking frameworks

Do them together and you pay once for the same evidence.

Most of the controls behind Law 25, SOC 2, ISO 27001, and ISO 42001 are the same controls described in different language. Run them as separate projects and you pay for the same access reviews, the same risk register, and the same vendor due diligence three times over. We scope them as one program and map each piece of evidence to every framework it satisfies.

Law 25 plus PIPEDA
Roughly 70 percent shared evidence

One privacy program, two statutes satisfied

SOC 2 plus ISO 27001
Roughly 80 percent shared controls

One control set, two attestations

ISO 27001 plus ISO 42001
Shared management system

AI governance built on the security system you already need

Build your estimate

Our estimator already reflects a multi framework discount when you stack.

MapleGuard, our method

AI drafts. Experts approve.

MapleGuard is how we work, not a product you log into. AI accelerates the first draft of your policies, risk registers, and vendor responses. A credentialed reviewer then checks and signs off on every artifact before you rely on it, with a documented human checkpoint on everything. You get the speed of AI and the accountability of a named expert. We keep a documented record of every review and approval as part of the engagement.

Step 1
Discover
  • Scope definition workshop
  • Risk register kickoff
  • Asset inventory
Step 2
Build
  • Policy library (10 to 15 docs)
  • Control mapping
  • Evidence folder setup
Step 3
Test
  • Vendor risk assessments
  • IRP tabletop exercise
  • Training records
Step 4
Deliver
  • Internal audit simulation
  • Evidence package finalized
  • Audit-day support
MapleGuard: Canadian regulatory compliance

Every Canadian privacy law, covered.

MapleGuard covers the Canadian privacy and health-information statutes that legally apply to your business. These are binding laws, not voluntary attestations.

Federal
PIPEDA

The Personal Information Protection and Electronic Documents Act, Canada's governing federal private-sector privacy law.

Federal privacy reform (tracked)

Bill C-27 (which contained the proposed CPPA, a data tribunal, and AIDA) died on the Order Paper in 2025. Canada continues to operate under PIPEDA, with no federal AI statute in force. A new private-sector privacy bill is expected, and federal AI regulation is now proceeding as a separate standalone bill. MapleGuard tracks both so you're ready when they land.

Quebec
Law 25 (Loi 25)

Fully in force. The strictest privacy regime in Canada. Applies to any business handling Quebec residents' personal data, including automated decision-making. Referred to as Law 25 throughout the rest of this site.

Provincial private-sector
Alberta PIPA

Alberta's Personal Information Protection Act governs private-sector handling of personal information in Alberta.

British Columbia PIPA

BC's Personal Information Protection Act governs private-sector handling of personal information in British Columbia. (Public-body data residency in BC is a FIPPA matter, not PIPA; a FIPPA reference can be added here pending legal review.)

Health information: provincial & territorial
Ontario PHIPA

Personal Health Information Protection Act.

Alberta HIA

Health Information Act.

Saskatchewan HIPA

Health Information Protection Act.

Manitoba PHIA

Personal Health Information Act.

Nova Scotia PHIA

Personal Health Information Act.

New Brunswick PHIPAA

Personal Health Information Privacy and Access Act.

Newfoundland & Labrador PHIA

Personal Health Information Act.

PEI Health Information Act

Prince Edward Island's health information statute.

Yukon HIPMA

Health Information Privacy and Management Act.

Northwest Territories HIA

Health Information Act.

In Manitoba, Saskatchewan, and PEI, a health custodian may face both the provincial health act and PIPEDA at once.

Public sector
Federal Privacy Act

Governs federal government institutions. Provincial and territorial public-sector statutes available on request.

AI governance, grounded in Canadian rules

Canada has no federal AI statute in force today. Bill C-27 (which included AIDA) lapsed in 2025, and a new standalone federal AI bill is expected. Law 25 already regulates automated decision-making in Quebec. MapleGuard helps you govern AI against the Canadian rules that apply today, and prepares you for what's coming. ISO 42001 and EU AI Act readiness (international AI requirements) live on Auxlo Global.

See Auxlo Global →
Where we fit alongside your lawyer

A lawyer interprets Law 25 and tells you your legal risk. We build the program that satisfies it: the data map, the assessments, the incident runbook, the evidence. When the CAI, Quebec's privacy regulator, or a partner asks you to prove it, the lawyer argues the law and we hand over the proof. Confirm legal interpretation with qualified counsel; the operational program is ours.

Pricing

Pricing that fits the actual job.

Senior led engagements at a flat fee, known up front, with no junior hand offs and no hourly meter. Stack frameworks and you pay once for the evidence they share. Build your estimate below, then we confirm it on a free scoping call.

Engagement estimator
Step 1 of 8: Frameworks
Choose your frameworks

Multi-select. We blend pricing when you stack frameworks, with a 30 percent multi-framework discount already reflected below.

Canadian compliance (binding law)
International and client-requested frameworks
Prefer to talk first? Book a free scoping call.
Free compliance assessment

Find your gaps in five minutes.

Our AI-powered assessment generates a custom gap analysis and a prioritized remediation roadmap, instantly, for free, no account. Canadian-operated practice; Canadian data residency available on paid engagements.

  • Pick your frameworks
  • Answer 8 quick yes/partial/no questions
  • Receive a scored gap report and prioritized remediation roadmap
Free compliance assessment
Step 1 of 3
Which frameworks apply to you?

Canadian privacy laws are binding statutes. International frameworks are voluntary attestations clients ask for.

Canadian regulations (binding law): MapleGuard
International & client-requested frameworks: Auxlo Global
Who leads the work
You will not be handed to a junior. The person who scopes your engagement is the person who does the work and signs off on it.

Auxlo is a senior led AI governance and compliance practice serving regulated Canadian organizations from Ottawa, remotely across the country. Engagements are led by David Kamgue, a credentialed audit, risk, and security practitioner with over fifteen years of experience across regulated environments. Every artifact is reviewed and signed off by a credentialed professional before you rely on it. We prepare you to pass. The independent auditor or certification body issues the report or certificate.

CISA · CRISC · CISM
Credentialed across audit, risk, and information security
15+ years in regulated environments
Audit, risk, and security across finance, health, and technology
Ottawa based, Canada wide
Canadian operated, Canadian data residency available on paid engagements
Bilingual delivery
Engagements delivered in English or French

What we believe

  • Compliance work is judgement work. Software can accelerate a draft, it cannot own the decision.
  • Say no to scope we cannot deliver at a senior standard, and say it on the first call.
  • A flat fee known up front is a discipline, not a discount. It forces us to scope honestly.
  • Evidence beats documentation. A policy nobody follows is a liability, not a control.
  • Your data stays yours. Privileged and personal information never trains a public model.
The Auxlo guarantee

If your auditor finds a gap within our agreed scope that we should have caught, we fix it at no additional charge.

Honest scope, honest delivery. If something inside the work we agreed slipped through, it's on us to make it right, no arguments, no extra invoice.

Book your engagement

The enterprise deal is waiting on you.

Every day you wait is a day a competitor with a SOC 2 report closes the deal you should have closed.

  • A senior practitioner replies in under 12 hours, a real person, not a bot
  • Engagements delivered in English or French
  • Flat fee, full cost known up front
  • Canadian data residency available on paid engagements
Service area:
Remote across Canada
Free 20-minute scoping call
Tell us enough to scope it properly

No obligation. No sales pitch. A senior practitioner, you, and a clear path forward.

Get a senior practitioner on the problem.

Twenty minutes, no sales pitch. You describe the situation, we tell you what it takes, and whether we are the right practice for it.

  • Flat fee, total cost known up front
  • A senior practitioner replies in under 12 hours
  • Canadian data residency available on paid engagements
  • Engagements delivered in English or French