AI GOVERNANCE & RISK MANAGEMENT
Protect your business and its relationships while putting AI to work.
Protecting your reputation starts with knowing how AI is being used, what information it handles, and who is accountable for its results.
Use AI with confidence, accountability, and control.
AI can help your team work faster and make better use of information. Without clear safeguards, it can also expose confidential data, introduce errors, and damage the trust of clients, customers, and vendors.
DOS helps small and mid-sized businesses, offices, and nonprofit organizations understand their AI use, assess risks and gaps, and put practical governance into everyday work.
Do you know where AI is being used in your organization?
- Which AI tools are staff using, including informal or unapproved tools?
- What customer, employee, or business information is being entered?
- Who checks AI-generated work before it reaches customers?
- Which decisions or actions require human approval?
- What happens if AI produces an error or exposes information?
Assessment first. Practical recommendations next.
We begin by understanding your organization and talking with the people doing the work. Recommendations follow the assessment, so your governance reflects actual uses, risks, and resources.
1. Discover and inventory AI use
We work with leadership and staff to identify AI tools, their purposes, the information they handle, and the workflows they support. This includes informal use that may not be visible to management.
You receive: An AI inventory and a clear picture of current use.
2. Assess risks and identify gaps
We assess risks to information, people, business relationships, and reputation. We review policies, responsibilities, approvals, oversight, existing controls, and staff awareness to identify what is missing or needs improvement.
You receive: A risk and gap assessment with priorities for action.
3. Develop a practical governance roadmap
We discuss the findings with your team and recommend proportionate safeguards that fit your operations. Together, we establish priorities, responsibilities, and practical next steps.
You receive: A prioritized roadmap with clear ownership.
4. Implement safeguards and build staff awareness
We help put agreed policies, human oversight, approval rules, and information-handling controls into practice. Staff training explains the risks, why governance matters, and how to use AI responsibly in their actual work.
You receive: Practical guidance, accountable processes, and a better-informed team.
5. Review and improve
AI tools and business needs change. We help establish a review process to monitor use, respond to issues, and update controls as your organization evolves.
You receive: An approach to ongoing review and continual improvement.
Governance that supports your business
The goal is to protect your reputation, your information, and the trust of clients, customers, and vendors while helping your team use AI productively. Clear rules and responsibilities reduce avoidable mistakes and give staff greater confidence about what they can do and when to ask for help.
Grounded in internationally recognized approaches
Our assessments and recommendations draw on established AI governance principles, risk-management frameworks, and management-system standards, adapted to your organization’s size, activities, and risks.
OECD AI Principles and classification framework
We consider responsible-use principles alongside five assessment dimensions: People & Planet, Economic Context, Data & Input, AI Model, and Task & Output. This helps us understand how an AI system works, where it is used, and whom it may affect.
NIST AI Risk Management Framework
We use the four functions—Govern, Map, Measure, and Manage—to structure responsibilities, understand AI use, assess risks, and prioritize appropriate safeguards.
ISO/IEC 42001 — AI Management Systems
We draw on its management-system approach to support clear policies, accountability, documented processes, monitoring, and continual improvement. Ron Dehmel holds ISO/IEC 42001 Foundations certification.
Legal and regulatory context
Our assessments consider applicable Canadian federal and provincial requirements and relevant international developments, including the EU AI Act where applicable.
These foundations help turn governance into practical controls, staff guidance, and a review process that supports your business.
Start with an AI governance assessment
Tell us how your organization is using—or considering using—AI. We’ll discuss your concerns and identify the appropriate first step.