Client Focused Reforms Documentation: A 2026 Advisor Guide

What Canadian advisors need to capture under Client Focused Reforms: the four documentation pillars, what regulators keep finding, and what AI tools must do.

Sandra Lyne
10 min read
Client Focused Reforms Documentation: A 2026 Advisor Guide

TL;DR

A December 2025 sweep of 105 Canadian firms found widespread documentation gaps across KYC, KYP, suitability, and policies and procedures, four years after Client Focused Reforms took effect. Most advisors do the underlying work in client meetings; the failure point is capturing it in a form that survives compliance review years later. Two recent CIRO cases set the stakes: a $1M National Bank Financial settlement, and Re White (2024 CIRO 67) where contemporaneous notes saved an advisor. AI documentation tools have to cover the four pillars, meet CSA Staff Notice 11-348's explainability bar, and handle PII locally to satisfy PIPEDA and Quebec Law 25.

A December 2025 sweep by Canadian regulators reviewed 105 firms and reported widespread documentation deficiencies across KYC, KYP, suitability, and policies and procedures. The notice never says how many of the 105 firms had problems. It does say the problems are recurring, four years after Client Focused Reforms took effect.

The notice describes a documentation gap. Advisors talk about costs, weigh alternatives, and make suitability judgments in client meetings every week. The gap is what happens between the conversation and the record. The discussion about cost impact becomes "discussed costs." The alternatives actually considered become "alternatives were appropriate." Months later, in a compliance review, the file shows the action but not the reasoning.

I've taken the time to read the staff notices, talking to advisors about how documentation actually happens in their week, and building software to handle the part of the job no one likes. The pattern is clearer than the regulatory text makes it look.

The documentation gaps regulators keep finding

The same deficiencies keep coming up across Canadian regulatory reviews. Phase 1 in 2023 named them. The 2025 CIRO Compliance Report named them again. Phase 2 confirmed them at the end of 2025. KYC information in ranges too wide to be meaningful. KYP records that file the issuer's documentation without showing the firm's own analysis. Suitability notes that record the recommendation but not the consideration of cost, concentration, or alternatives. Policies and procedures that restate the rules without describing how the firm intends to comply with them.

The rule-by-rule architecture is in What CIRO Requires in Meeting Documentation. This article picks up where that one ends, with the observation that runs through every staff notice: the underlying work is mostly happening. What's missing is the record.

A suitability determination involves at least five judgments under IDPC Rule 3402 and MFD Rule 2.2.6. Most advisors make all five during a client meeting and few capture all five afterwards in the file. The 2025 Compliance Report names a specific failure pattern with rare bluntness:

"Instances where KYC information should have been queried for reasonability, but it was not."

The judgments were being made, the compliance supervisor was looking for them in the file, and they weren't there.

What two enforcement cases show

In March 2026, National Bank Financial Inc. (NBF) settled with CIRO. The firm paid a $1 million fine plus $50,000 in costs for failing to adequately supervise a registered representative with respect to note-taking and suitability. The supervisory gap was specific: the firm did not have controls in place to ensure that meeting documentation was being captured at the standard CIRO expects.

Two years earlier, in Re White (2024 CIRO 67), the panel heard an unsuitability complaint against an investment advisor. The advisor's defence rested on contemporaneous handwritten notes he had taken in each client meeting. The notes were archived through his dealer's systems, which made them tamper-proof and inaccessible to the advisor after the fact. That archival pattern was what the panel relied on: the notes could not have been edited after the complaint was raised. The hearing panel found his account of the meetings more credible than the complainants' testimony, and the contemporaneous notes were a significant reason the panel sided with him.

The two cases sit on either side of the same observation. Across regulatory reviews, complaint hearings, and supervisory examinations, documentation is the artifact that survives. When it is captured in real time, in a form that is preserved without depending on the advisor's later recollection, it can decide which version of events the decision-maker treats as credible. The rules are specific about what has to be in those records.

When supervision failed
CIRO SETTLEMENT · MARCH 2026

National Bank Financial Inc. paid a $1 million fine plus $50,000 in costs for failing to adequately supervise a registered representative's note-taking and suitability documentation. The firm lacked controls to ensure meeting documentation met the standard CIRO expects.

When notes saved an advisor
HEARING PANEL DECISION · 2024

Re White, 2024 CIRO 67. Contemporaneous handwritten notes, archived through the dealer's tamper-proof systems, became the credible record. The panel preferred the advisor's account over the complainants' testimony.

What a Client Focused Reforms meeting record has to show

Client Focused Reforms documentation rests on four pillars: KYC information, KYP assessment, suitability determination, and alternatives considered. Each has rule citations and a body of guidance behind it; What CIRO Requires walks the architecture rule-by-rule.

PillarWhat it capturesWhere it's specified
KYC informationThe client's financial circumstances, investment knowledge, risk profile, and (since 2021) the distinction between risk tolerance and risk capacityIDPC Rule 3202, NI 31-103 s.13.2, MFD Rule 2.2.1
KYP assessmentThe registrant's own analysis of the product, not the issuer's documentation filed without reviewIDPC Rule 3300, NI 31-103 s.13.2.1
Suitability determinationThe five factors: KYC, KYP, account impact, cost impact, and a reasonable range of alternativesIDPC Rule 3402(1)(i), MFD Rule 2.2.6(1), NI 31-103 s.13.3(1)(a)
Alternatives consideredThe specific alternatives weighed and why the recommendation was chosen over themSame as suitability; flagged in Staff Notice 31-368 as commonly missing

For compliance officers

The four pillars line up with what BCC examiners verify. A meeting record that does not show all four is a record that has the action without the reasoning, which is the recurring deficiency Phase 2 identified.

Newsletter

When CIRO, PIPEDA, or Law 25 changes, the Dispatch explains what it means.

Once a month: what is changing across CIRO, PIPEDA, and Quebec Law 25, and what it means for advisors using AI tools. A five-minute read.

Subscribe, free

What AI meeting documentation has to do

A tool that helps with Client Focused Reforms documentation has to do specific work in each of the four pillar areas. KYC updates from the conversation need to land in language a supervisor can read months later. KYP rationale belongs on the page. The suitability discussion has to show cost, concentration, and alternatives. The alternatives considered, and why they were not chosen, have to be in the file.

CSA Staff Notice 11-348 sets the standard for AI in advisor workflows. It requires "an appropriate degree of explainability" in KYC processes with human monitoring, and "a high degree of explainability" in suitability determinations. The advisor remains the registered representative responsible for the recommendation. The AI output is an input to the file. The advisor reviews it, accepts or revises it, and signs off. AI produces a draft. The advisor's judgement decides what the record says.

A high degree of explainability.

CSA Staff Notice 11-348 (December 2024). The standard set for AI in suitability determinations. KYC faces the lower bar of 'an appropriate degree.'

PIPEDA and Quebec Law 25 add a second layer. The privacy obligation requires safeguards before personal information is transmitted to any third-party service, including AI tools. The architecture that addresses this is local PII removal: client names, account numbers, and identifying details are detected and tokenized on the advisor's device before any transcript is sent to the AI for processing. The AI sees structure without identity. The PII rejoins the record locally.

The way Meeting Notes Pro was built happens to map cleanly to all four pillars. That's because KYC updates, KYP rationale, suitability discussion, and alternatives considered are the conversations advisors are already having. The tool captures them.

Local PII removal protects client data on the advisor's device before anything is sent. The reviewer-confirms workflow is there because advisors want final control over what goes in the file. Both serve the advisor first. The regulators get what they ask for as a result.

Meeting Notes Pro

Built around the four documentation pillars.

KYC updates, KYP rationale, suitability discussion, and alternatives considered. The conversations advisors already have, captured in a form supervisors can verify months later. PII removed locally on the advisor's device before any transcript is sent.

For firm counsel, the compliance brief walks through how the architecture maps to CSA Staff Notice 11-348, PIPEDA, and Quebec Law 25.

What your compliance department will want to verify

A compliance review of AI meeting documentation walks six checkpoints: material business change notification, outsourcing obligations, vendor sampling and verification, KYC explainability, suitability explainability, and PIPEDA and Quebec Law 25 obligations. Each carries a separate guidance instrument or staff notice.

For firm counsel. Six checkpoints, in the order a compliance review walks through them.

  1. Material business change notification. AI meeting documentation is the kind of operational change that may trigger material business change notification under GN-2200-21-001. CIRO's 2026 Compliance Report states that firms adopting AI should expect questions about their AI use and reviews of their "operational controls implemented to ensure AI is working as designed." The same report names a related deficiency: policies that restate the rule without describing how the firm intends to comply.

  2. Outsourcing obligations. Third-party AI tools fall under outsourcing obligations under GN-2300-21-003. The firm retains responsibility for the work; the vendor performs a function of the registered firm. Vendor diligence and the ongoing oversight responsibilities sit at the firm level.

  3. Vendor sampling and verification. CSA Staff Notice 11-348 requires registrants to sample and verify AI outputs on an ongoing basis, particularly for processes that touch suitability. The obligation continues for as long as the firm uses the tool.

  4. KYC explainability. CSA 11-348 requires "an appropriate degree of explainability" in KYC processes, with human monitoring. The advisor needs to be able to articulate what the AI captured and why.

  5. Suitability explainability. CSA 11-348 sets a higher bar for suitability determinations: "a high degree of explainability." The reasoning has to be visible alongside the recommendation.

  6. PIPEDA and Quebec Law 25. If client data is transmitted to a third-party AI service, the firm is responsible for ensuring appropriate safeguards. Quebec Law 25 adds explicit requirements for consent, breach notification, and disclosure of cross-border data flows. Personal information routed to AI infrastructure outside Canada falls within the cross-border disclosure rules.

Key Takeaways

    • What Phase 2 found. Canadian regulators reviewed 105 firms in December 2025 and reported widespread documentation deficiencies across KYC, KYP, suitability, and P&P. The same patterns showed up in Phase 1 and the 2025 Compliance Report.
    • The four pillars. Client Focused Reforms require records of KYC information, the registrant's KYP assessment, suitability across five factors, and the alternatives considered. Each carries rule citations under IDPC, MFD, and NI 31-103.
    • Where the gap is. Most advisors do the work in the meeting. The failure point is capturing what happened in a form that survives a compliance review years later.
    • What enforcement shows. Recent CIRO cases confirm the stakes on both sides. Meeting documentation has cost firms when supervision failed, and it has saved advisors when notes were the credible record years later.
    • What AI meeting documentation does. Captures the four-pillar conversation in real time, with the advisor reviewing and confirming the draft, and PII removed locally before transmission. The architecture serves the advisor first; compliance follows.

Compliance & AI Dispatch

Once a month: what is changing across CIRO, PIPEDA, and Quebec Law 25, and what it means for advisors using AI tools. A five-minute read.

Northern Catalyst does not share email addresses.

Sandra Lyne

Sandra Lyne

Founder, Northern Catalyst | Developer, Meeting Notes Pro

Building tools for Canadian financial advisors

Related Posts