A GTA accounting and advisory firm serving regulated financial institutions needed to demonstrate AI governance controls to an enterprise client and prepare for OSFI B-13-adjacent requirements. This composite case study covers shadow AI detection, a model risk register, and how the firm established a quarterly review cadence that satisfied client requirements.
AI Governance for a GTA Accounting Firm: Building a Model Risk Register and OSFI B-13-Aligned Framework
This is a composite case study. The scenario, challenge, and outcome are based on patterns Group 4 Networks observes across Toronto financial services clients. No individual organization is identified.
The Problem
A GTA-based accounting and advisory firm with 40 professionals served a mix of private companies and several federally regulated financial institutions. Its work for the FI clients included tax advisory, audit support, and financial modelling - work that involved sensitive client financial data and, increasingly, AI-assisted analysis.
Two pressures arrived within the same quarter.
The first was an enterprise client questionnaire from one of the firm's FI clients. The questionnaire - aligned to the client's own OSFI B-13 vendor management requirements - included detailed questions about the firm's use of AI tools in engagements, model documentation practices, and data governance controls. The managing partner had no answers ready.
The second pressure came from within the firm. Three of the firm's advisory staff had been using AI tools to assist with financial modelling and tax projection work. Two of the tools involved client financial data being processed outside the firm's controlled environment, with no data processing agreements and no documentation of how the AI outputs were validated before being incorporated into client deliverables.
The firm did not fall directly under OSFI B-13 - that guidance applies to federally regulated financial institutions, not their professional services providers. But the firm's FI clients were applying B-13-aligned standards to their vendor relationships, and the firm needed to demonstrate equivalent rigor in how it governed AI tool use in client engagements.
What the Audit Found
Group 4 Networks conducted a Shadow AI Audit across the firm's Microsoft 365 environment, network, and endpoint fleet within five business days.
Findings:
- 5 AI tools in active use across the firm's advisory and tax teams
- 3 of the 5 tools were processing client financial data - including projection inputs, tax return data, and financial statement excerpts - on servers outside Canada
- No data processing agreements existed for any of the 5 tools
- No documentation existed for how AI-generated outputs were reviewed or validated before use in client deliverables
- The firm's existing engagement letters did not disclose AI tool use to clients
From a professional standards perspective, the use of AI tools in client engagements without disclosure and without a validation framework was a material gap. From a client relationship perspective, the enterprise FI client's B-13-aligned questionnaire could not be answered without a governance framework in place.
The Approach
Group 4 Networks built a governance framework in three phases, designed to address both the immediate client questionnaire and the firm's longer-term governance needs.
Phase 1 - Shadow AI control and data classification (weeks 1 to 4)
The 5 unapproved tools were assessed against the firm's data classification model. Two tools that had accessed client financial data were immediately restricted from firm-managed devices pending replacement with approved alternatives. Three tools used only for internal administrative work were assessed as lower risk and allowed to continue pending data processing agreement review.
A four-tier data classification model was applied to the firm's work:
- Tier 1: General business content, published research - any approved tool
- Tier 2: Internal firm data - tools with Canadian data residency only
- Tier 3: Client financial and tax data - controlled tools with signed data processing agreements and Canadian data processing
- Tier 4: Regulated FI client data - no external AI processing without explicit written client authorization
Phase 2 - Model risk register (weeks 3 to 6)
A model risk register was built to document each AI tool in active use within the firm. Each registry entry included:
- Tool name and vendor
- Model type and intended use
- Data accessed (by classification tier)
- Validation method for AI outputs before use in client work
- Data processing agreement status
- Review schedule
The initial registry included 4 entries - the 3 administrative tools and Microsoft 365 Copilot, which was deployed as the approved drafting and analysis tool for Tier 2 work. The 2 tools that had accessed Tier 3 client data were retired from the registry following restriction.
Phase 3 - Quarterly review cadence and client disclosure (weeks 5 to 8)
A quarterly model review cadence was established - a 90-minute working session each quarter to review the model registry, assess any new AI tools in use, update data processing agreements, and review any validation issues that had arisen in the preceding quarter.
Engagement letter language was updated to disclose AI tool use in client work, consistent with emerging professional standards guidance from CPA Canada. The disclosure specified which categories of client data could be processed by AI tools and confirmed that AI outputs are reviewed by a qualified professional before inclusion in any client deliverable.
Outcome
At the 90-day mark:
- B-13-aligned governance framework in place: model risk register, data classification policy, quarterly review cadence, and output validation procedures documented
- Enterprise client questionnaire answered: the FI client's vendor questionnaire was completed with reference to the documented governance framework within the 90-day window
- Model registry live with 4 entries, each with documented data tier, validation method, and review schedule
- 4 tools assessed, 2 retired from client-data use following the audit; 0 unapproved AI tools accessing Tier 3 client financial data at 90-day check
- Quarterly review cadence established: first quarterly review completed at day 90 with the managing partner and two senior advisors
- Engagement letter disclosure updated across all active engagements
The managing partner's view at the 90-day review: the governance framework was not just a compliance response - it gave the firm a structured way to evaluate and adopt new AI tools as they emerged, rather than reacting to client questions after the fact.
What This Means for Toronto Financial Services Firms
OSFI Guideline B-13 applies directly to federally regulated financial institutions. But B-13-aligned standards are increasingly being applied through vendor management programs to the professional services firms, technology providers, and advisors that FIs work with. An accounting firm, law firm, or advisory practice that cannot demonstrate AI governance controls may face vendor questionnaire failures, contract conditions, or exclusion from RFP processes.
Beyond client requirements, professional standards for accounting and advisory work increasingly expect that AI tool use in client engagements is disclosed, that outputs are validated, and that the firm can document its AI governance practices.
Group 4 Networks' AI Governance service includes model risk register development, shadow AI detection, and the quarterly review cadence that professional services firms need to manage AI tool use in regulated client engagements. Our financial services IT support covers the full technology stack for GTA accounting, advisory, and financial services firms.
Contact us at (416) 623-9677 or book a free AI Governance assessment.
Frequently Asked Questions
Does OSFI B-13 apply to accounting firms and professional services providers?
OSFI Guideline B-13 applies directly to federally regulated financial institutions (FRFIs). It does not directly regulate professional services firms. However, FRFIs are required under B-13 to apply their technology risk management standards to their third-party relationships and vendor arrangements, which means B-13-aligned requirements are increasingly flowing through to FI clients' vendor management programs. An accounting firm serving regulated FIs may face B-13-aligned questions in vendor questionnaires even though B-13 does not apply to the firm directly.
What is a model risk register and why do financial services firms need one?
A model risk register is a documented inventory of every AI tool or quantitative model in use at an organization, including the tool's purpose, the data it accesses, how outputs are validated before use, and when the tool was last reviewed. In financial services, model risk management is a formal discipline - OSFI's B-15 (climate risk) and internal guidance for FIs cover model validation requirements. For professional services firms serving FI clients, a model risk register demonstrates the same rigor in a form that vendor questionnaires and enterprise clients can assess.
How should an accounting firm disclose AI tool use to clients?
CPA Canada has issued emerging guidance on AI use in professional engagements. The current consensus is that engagement letters should disclose when AI tools may be used in client work, specify what categories of client data may be processed, and confirm that AI outputs are reviewed by a qualified professional before inclusion in any client deliverable. Group 4 Networks includes engagement letter disclosure language as part of the AI Governance implementation for professional services clients.
Can Microsoft 365 Copilot be used with confidential client financial data?
Microsoft 365 Copilot operates within the Microsoft 365 trust boundary, with data processed in Canadian data centres for Canadian tenants. Copilot does not use customer data to train the underlying models. For financial data classified at Tier 3 (client financial and tax data), the key questions are what data Copilot can access within the tenant and whether appropriate sensitivity labels restrict Copilot from processing the most sensitive client content. Group 4 Networks assesses this configuration as part of the AI Governance engagement for financial services clients.
How long does it take to build a model risk register for a professional services firm?
For a firm of 30 to 60 professionals, the initial model risk register can be built within three to four weeks of the Shadow AI Audit. The audit identifies every tool in active use; the register documents each one against the required fields. The register is a living document, updated at each quarterly review cycle as tools are added, retired, or modified. Group 4 Networks provides the register template and manages the quarterly update process as part of the ongoing AI Governance service.