AI Governance for a GTA Accounting Firm: Building a Model Risk Register and OSFI B-13-Aligned Framework
A GTA accounting and advisory firm serving regulated financial institutions needed to demonstrate AI governance controls to an enterprise client and prepare for OSFI B-13-adjacent requirements.
AI Governance for a GTA Accounting Firm: Building a Model Risk Register and OSFI B-13-Aligned Framework
*This is a composite case study. The scenario, challenge, and outcome are based on patterns Group 4 Networks observes across Toronto financial services clients. No individual organization is identified.*
A GTA-based accounting and advisory firm with 40 professionals served a mix of private companies and several federally regulated financial institutions. Its work for the FI clients included tax advisory, audit support, and financial modelling - work that involved sensitive client financial data and, increasingly, AI-assisted analysis.
The first was an enterprise client questionnaire from one of the firm's FI clients. The questionnaire - aligned to the client's own OSFI B-13 vendor management requirements - included detailed questions about the firm's use of AI tools in engagements, model documentation practices, and data governance controls. The managing partner had no answers ready.
The second pressure came from within the firm. Three of the firm's advisory staff had been using AI tools to assist with financial modelling and tax projection work. Two of the tools involved client financial data being processed outside the firm's controlled environment, with no data processing agreements and no documentation of how the AI outputs were validated before being incorporated into client deliverables.
The firm did not fall directly under OSFI B-13 - that guidance applies to federally regulated financial institutions, not their professional services providers. But the firm's FI clients were applying B-13-aligned standards to their vendor relationships, and the firm needed to demonstrate equivalent rigor in how it governed AI tool use in client engagements.
Group 4 Networks conducted a Shadow AI Audit across the firm's Microsoft 365 environment, network, and endpoint fleet within five business days.
5 AI tools in active use across the firm's advisory and tax teams 3 of the 5 tools were processing client financial data - including projection inputs, tax return data, and financial statement excerpts - on servers outside Canada No data processing agreements existed for any of the 5 tools No documentation existed for how AI-generated outputs were reviewed or validated before use in client deliverables The firm's existing engagement letters did not disclose AI tool use to clients