AI Governance

CAN/DGSI 101:2025: Canada's Homegrown AI Standard

Illustration of a maple leaf badge with a Checkmark representing a Canadian national AI standard and CAN/DGSI 101:2025 in bold white text

Canada still lacks a federal AI law, but a national AI standard written specifically for small and medium-sized businesses fills part of that gap, and most Canadian business owners have never heard of it.

That standard is CAN/DGSI 101:2025, Ethical Design and Use of Artificial Intelligence by Small and Medium Organizations. It is a genuine National Standard of Canada, accredited by the Standards Council of Canada, and it tells you exactly what responsible AI use looks like for an organization with fewer than 500 employees. If your business uses ChatGPT, AI features baked into your accounting software, or AI-assisted hiring tools, this document was written for you.

The timing matters. The federal government's attempt at an AI law, the Artificial Intelligence and Data Act, died in January 2025 when Bill C-27 fell apart with the prorogation of Parliament. Nothing replaced it. But privacy law still applies to AI, human rights law still applies to AI, and enterprise clients asking you to fill out security questionnaires still apply to AI. In that gap, a made-in-Canada standard has quietly become a usable answer.

What it is, and who wrote it

CAN/DGSI 101:2025 is the Second Edition of a national standard first published in January 2025. It replaced an older standard from 2019 that covered automated decision systems before generative AI took over the world.

The "DGSI" in the name is the Digital Governance Standards Institute, an Ottawa-based standards body that develops governance standards for digital technology. It operates under the Digital Governance Council, a national non-profit forum of technology executives. The institute pulled together a technical committee of more than 225 experts in AI, privacy law, ethics, and business to write the standard.

The "CAN" prefix is the important part. It means the document has been accredited as a National Standard of Canada by the Standards Council of Canada, a federal Crown corporation that sits within Innovation, Science and Economic Development Canada. The SCC is the same body that accredits standards development across the country, and that accreditation gives the document formal standing as a consensus standard.

The scope is refreshingly practical. It covers AI that uses machine learning to make or support decisions, explicitly including generative AI. It applies whether you built the tool yourself or bought it from a vendor, which is the situation most small businesses find themselves in. And it applies across private companies, government entities, and not-for-profits alike.

One more thing worth knowing: the requirements are principles-based. The standard expects you to take "reasonable and responsible measures" proportionate to your size, your complexity, and your risk. A five-person consultancy and a 400-person manufacturer both fit, just with different levels of effort.

What the standard asks of your business

The standard organizes its requirements into four clauses: risk management, ethics by design, deployment, and monitoring. Here is what each one means for a Canadian business owner:

You need one person accountable for AI risk. The standard requires you to appoint someone responsible for overseeing your AI risk management framework. In a small business that person might be you, your operations manager, or your IT lead.

You assess risk before anything goes live. For each AI tool, you document what could go wrong, how likely it is, and how bad it would be. The standard specifically calls for an ethical impact assessment and a privacy impact assessment. If a tool touches hiring, credit, health information, or anything affecting people's rights, that assessment gets more careful.

You need to know your data story. The ethics by design clause asks you to determine the legal authority for the data feeding your AI tools, check that data for bias, and describe the tool's limits in plain language to the people using it. For a business buying third-party tools, this mostly means understanding what your vendor does with your data and being honest about what the tool is good at and where it fails.

Your people need training. The standard requires that personnel who work with AI tools can review, explain, and oversee them. It also distinguishes between systems a human approves each time, systems a human supervises, and systems that run fully on their own, and expects training to match. A chatbot that drafts marketing copy and an automated screening tool carry very different levels of risk.

You keep watching after launch. Deployment is where the ongoing work begins. You monitor outputs for biased, unethical, or unintended results, review performance at least annually, and maintain a way for people affected by an AI-assisted decision to challenge it. There is also a requirement that surprises many owners: you must have an internal process for employees to raise concerns about an AI system before it goes live.

When someone flags a risk and you decide to live with it anyway, the accountable person documents and signs off on that decision. That paper trail is what separates a defensible governance posture from "we use AI and hope for the best."

AIReady: getting your practices independently checked

Knowing the requirements is one thing. Proving to a client, a lender, or a procurement officer that you meet them is another. That is where the Digital Governance Council's AIReady program comes in.

AIReady is an independent validation and verification program run against CAN/DGSI 101:2025. The distinction between the two matters. Validation asks whether your plans are plausible; it fits businesses that are designing an AI deployment or building their governance practices and want an outside check before launch. Verification asks whether your practices are truthful; it fits businesses with AI systems already in operation who can show real evidence that they follow the standard.

Each path comes in two depth levels. A review is a lighter-touch assessment suited to organizations starting out. An audit involves deeper evidence testing for situations where a client or partner needs more confidence in your claims.

The process itself is straightforward: you define the scope of the claim you are making, prepare your evidence (policies, risk assessments, training records, monitoring logs), the Council's assessors review it, and a separate independent reviewer signs off on the decision. If you pass, you receive a formal statement of validation or verification, plus a Digital Trustmark you can display, listed in a public registry anyone can check.

The published price range is $250 to $750 CAD, depending on the assessment type. Read that again. For less than the cost of most professional development courses, a small business can hold a nationally accredited, independently verified statement about its AI practices. Compare that to a SOC 2 audit or an ISO 42001 certification, which routinely run to five figures and months of preparation.

This is why AIReady works well as a first step on a longer compliance journey. The governance mechanics CAN/DGSI 101 asks for, an accountable owner, documented risk assessments, trained staff, monitoring, an appeals process, are the same building blocks that SOC 2 and ISO/IEC 42001 auditors expect to see. Organizations that build those mechanics now, and validate them through AIReady, arrive at a future SOC 2 or ISO engagement with most of the foundation already in place. That turns a later certification project into gap closure rather than a build from scratch.

If you bid on enterprise contracts, respond to RFPs with responsible AI questionnaires, or operate in a sector where clients are starting to ask hard questions about AI, that trustmark can earn its keep quickly.

Where to start

None of this requires a legal department or a governance committee. It requires deciding who owns AI risk in your business, taking an honest look at the AI tools you already use, and putting basic documentation around them. The national standard gives you the map, and independent validation gives you proof you can show to clients and lenders.

If you are not sure where your business stands, that is a conversation worth having. Talk to Evolutie about your AI governance needs. We help small and medium-sized businesses assess their AI use, build governance that fits their size, and prepare for validation when it makes sense, and we will tell you honestly if a formal CAN/DGSI 101 assessment is the right next step or if there is simpler groundwork to do first.

This article is general guidance, not legal advice. Consult a qualified professional for decisions specific to your business.


Sources: Digital Governance Standards Institute, CAN/DGSI 101:2025 Ethical Design and Use of Artificial Intelligence by Small and Medium Organizations, Second Edition (January 2025); Standards Council of Canada, National Standards of Canada; Digital Governance Council, AIReady Validation and Verification to CAN/DGSI 101; Digital Governance Council, Digital Trust and Verification Programmes; Innovation, Science and Economic Development Canada, The Artificial Intelligence and Data Act (AIDA); Parliament of Canada, Bill C-27, Digital Charter Implementation Act, 2022 (died on the Order Paper, January 2025); International Organization for Standardization, ISO/IEC 42001:2023, Artificial Intelligence Management System.

Want to discuss how this applies to your business?

Talk to Evolutie about your AI governance needs and whether a CAN/DGSI 101 is right for your business.

Contact Evolutie

Back to All Articles