Does CIRO Allow AI Meeting Notes?

CIRO has no formal AI policy, but the 2026 Compliance Report signals exactly what examiners will ask about AI in your practice.

Sandy
10 min read
Does CIRO Allow AI Meeting Notes?

TL;DR

CIRO has no formal AI policy, but the February 2026 Compliance Report signals exactly what examiners will ask: whether your firm can explain how its AI tools work, what controls are in place, and how you verify accuracy. CSA Staff Notice 11-348 places AI meeting documentation in the lower-risk portion of the regulatory spectrum. The framework for responsible use already exists. The question was never really about permission.

The Question You're Actually Asking

If you've looked for guidance from the Canadian Investment Regulatory Organization (CIRO) on whether your practice can use AI meeting documentation tools, you already know the answer: there isn't one. No policy. No guidance note. No bulletin. Search ciro.ca for "artificial intelligence" and you'll find examination priorities and a regulatory sandbox, but nothing that tells you whether the tool recording your client conversation is going to be a problem at your next review.

That silence is uncomfortable, because the ground is shifting. Global Relay, the compliance archiving platform used by firms across Canada, recently reported a 3,000% increase in firms capturing ChatGPT data. Advisors are using AI tools, evaluating them, or aware they'll need to decide soon.

CIRO hasn't said yes, and they haven't said no. What they did, in their February 2026 Compliance Report, is signal exactly what examiners will be looking for when they ask about AI in your operations. And what they described tells you more than a simple yes or no ever could.

The Real Question: Can You Show Your Work?

The February 2026 Compliance Report is the closest CIRO has come to addressing AI in your practice. It doesn't create new rules. It describes what Financial and Operations Compliance examiners will be looking at when they visit your firm.

The specific language: CIRO will be "inquiring about the use of AI in dealers' operations and reviewing the operational controls implemented to ensure AI is working as designed."

Two things matter in that sentence. First, AI examination sits under Financial and Operations Compliance, not Business Conduct. CIRO is treating AI as an operational risk management question. Controls, testing, validation. Not "is the advisor behaving properly" but "do the systems work and can you demonstrate that."

Second, "working as designed" is a testable standard. It implies your firm can explain what the tool does, how it produces its output, and how you verify accuracy. If you can't answer those questions about your AI meeting documentation tool, you're not ready for that examination.

This is principles-based regulation doing what it's designed to do. CIRO doesn't regulate the technology. It regulates documentation quality, client protection, and supervisory oversight. The question was never really about permission.

Two Layers of Guidance

Canadian securities regulation doesn't have a single AI rulebook. What it has are two layers of guidance from two different bodies, and being precise about which said what matters.

The first layer is CIRO itself. The 2026 Compliance Report makes clear that firms whose compliance policies simply restate principles-based rules without documenting specific procedures are falling short. CIRO has seen this pattern across Client Focused Reforms implementation and is now extending the same scrutiny to AI. If your firm's AI policy amounts to "we use AI responsibly," that is precisely the kind of vague language CIRO has already called inadequate.

The second layer is CSA Staff Notice 11-348, published in December 2024 by the Canadian Securities Administrators, the umbrella body of provincial securities commissions. This is the closest thing to formal AI guidance in Canadian capital markets. It sets out principles for AI use across the securities industry, from data governance to explainability to third-party vendor oversight. The comment period closed in March 2025. Over a year later, no follow-up guidance has been issued. Firms are operating within a principles-based framework and waiting for specifics that haven't arrived.

These two layers work together. CSA 11-348 establishes the principles. CIRO's examination process tests whether your firm has translated those principles into documented, demonstrable controls. The gap between the two is where most firms are right now: aware they need to do something, unclear on exactly what "enough" looks like.

BLG, one of Canada's largest law firms, published an analysis of the 2026 Compliance Report in April 2026. Their reading aligns with what the report signals: firms should be documenting their AI use across all aspects of business and operations, and compliance teams should be thinking carefully about how they respond to AI-related examination questions.

In practical terms: if your firm is using or evaluating an AI meeting documentation tool, the compliance conversation isn't about whether the technology is permitted. It's about whether you can explain how it works, what controls are in place, and how those controls map to obligations your firm already has. The framework for that conversation already exists. The question is whether you've done the work to apply it.

Where AI Meeting Notes Sit in the Regulatory Spectrum

CSA Staff Notice 11-348 doesn't treat all AI use cases the same way. It establishes a spectrum of risk, from operational efficiency tools at one end to discretionary investment decision-making at the other.

At the lower end: tools that improve trade execution efficiency or streamline back-office processing. In the middle: tools that assist with information gathering, client communication, and operational workflows. At the higher end: tools that generate investment recommendations, assess suitability, or make portfolio decisions on behalf of clients.

AI meeting documentation sits squarely in the lower-risk portion of this spectrum. A tool that transcribes a client conversation and produces a draft summary is gathering and organizing information the advisor already heard. It isn't assessing suitability. It isn't recommending products. It isn't making decisions. The advisor reviews the output, edits it, approves it, and takes responsibility for the final record.

That distinction matters because the compliance obligations scale with the risk. A tool generating investment recommendations triggers explainability requirements, suitability validation, and detailed supervisory oversight. A documentation tool triggers a different, more manageable set of expectations: data handling, accuracy verification, vendor due diligence, and record retention.

None of this means meeting documentation tools get a pass. The CSA is clear that any AI application handling client information carries obligations around privacy, third-party oversight, and output verification. But the nature of those obligations is proportionate. An advisor evaluating an AI meeting notes tool is not facing the same compliance burden as a firm deploying algorithmic portfolio management.

What the Enforcement Record Shows

Regulatory frameworks matter, but enforcement cases show you what regulators actually prioritize. Two recent cases illustrate why documentation quality is already under scrutiny, with or without AI in the picture.

In March 2026, National Bank Financial (NBF) agreed to a $1 million fine after admitting it failed to adequately supervise a Registered Representative with respect to note-taking and suitability. The firm had detected note-taking deficiencies but did not adequately pursue the red flags those deficiencies raised. The fine signals where CIRO's enforcement attention is focused: not just on what advisors recommend, but on whether the systems around them ensure those recommendations are properly documented and supervised.

Earlier, in Re White, 2024 CIRO 67, a CIRO hearing panel weighed an advisor's account of client conversations against the complainant's recollection. The panel found the advisor's contemporaneous notes credible and persuasive. The notes were taken at the time of the meetings, they were consistent, and they were corroborated by other records. Three qualities that determined whose version of events the panel believed.

Behind both cases sits a broader pattern. When the CSA reviewed 105 firms for Client Focused Reforms compliance in late 2025, they found widespread documentation deficiencies across KYC, KYP, suitability assessments, and policies and procedures. The industry was already struggling with documentation before AI entered the conversation. It's one reason compliance officers face specific confidence gaps when evaluating AI tools.

That context reframes the AI question. The risk isn't that AI meeting documentation tools will create compliance problems. The risk is that the documentation problems already exist, and adding AI tools without proper controls makes an existing gap harder to defend.

The Requirements Most Advisors Don't Know About

Beyond the examination itself, there are two practical requirements that most advisors evaluating AI meeting tools haven't considered.

The first is the material business change notification. Under CIRO Guidance Note GN-2200-21-001, introducing new technology-enabled systems that require vendors not previously reviewed by CIRO may constitute a material business change requiring advance written notification. BLG's April 2026 analysis of the Compliance Report noted that the scope of what CIRO considers a "change of business" has expanded in recent years, resulting in extended review periods. An advisor who starts using an AI meeting tool without raising this with their compliance department may be creating exactly the kind of undocumented risk that examiners are now looking for.

The second is the sampling requirement. CSA Staff Notice 11-348 states that firms using outsourced AI for client-facing processes should be sampling the output and verifying accuracy on an ongoing basis. For AI meeting documentation, that means someone at your firm should be spot-checking a sample of AI-generated summaries against what was actually said in the meeting. Not every summary. A sample, reviewed regularly, with the process documented.

In practical terms: before your firm approves an AI meeting documentation tool, someone needs to check whether the adoption triggers a material business change notification. And once the tool is in use, your firm needs a process for periodically reviewing a sample of AI-generated summaries against the original conversations. Both are conversations to have with your compliance department before you start, not after.

What Responsible Implementation Looks Like

CSA Staff Notice 11-348 is clear on one point above all others: AI cannot substitute for an advising representative as the decision-maker on suitability determinations. The advisor remains responsible. The tool assists. The human decides.

For AI meeting documentation, that principle translates into a specific workflow. The tool generates a draft summary. The advisor reviews it against their own recollection of the conversation. They edit where the tool got something wrong, add context the tool couldn't capture, and approve the final version. The record that goes into the client file is the advisor's record, not the machine's.

When I started building Meeting Notes Pro, this review-and-approve workflow wasn't a response to a regulatory requirement. I designed it because it felt imperative. Financial advisors carry responsibility for their clients' financial wellbeing. They need to know what's in their documentation, stand behind it, and be confident it reflects what actually happened. The fact that this approach aligns with what the regulatory framework requires isn't a coincidence. The common sense and the compliance obligation point in the same direction.

Beyond the review workflow, responsible implementation means knowing where client data goes. Whether personal information leaves the advisor's device. How long it's retained, and by whom. At Northern Catalyst, these questions shaped every architectural decision in Meeting Notes Pro's security model. Whether the vendor can explain their data handling in language a compliance officer can evaluate. These aren't technical questions. They're the same due diligence questions your firm would ask about any vendor handling client information.

The regulatory framework doesn't demand perfection. It demands that you can show your work.

This is what Meeting Notes Pro was built for.

One process. Fifteen minutes to set up. Your meeting information captured, your practice protected, your compliance documented.

Learn more about Meeting Notes Pro

What's Coming Next

The regulatory landscape is not standing still. When the CSA published Staff Notice 11-348, they included consultation questions asking whether formal risk management standards, data governance rules, and third-party vendor requirements should be turned into specific rules. The comment period closed over a year ago. Whatever comes next will build on the principles already in place, not replace them.

CIRO's own InnovateSafe sandbox, launched in December 2025, offers a structured pathway for firms testing new technologies within a regulatory framework. No AI-related projects have been approved through it yet, but its existence signals something important: the regulator is building infrastructure for innovation, not barriers against it.

For advisors, this means that waiting for perfect regulatory clarity before evaluating AI meeting documentation tools is itself a choice, and not necessarily a safer one. The firms that will be best positioned when specific guidance arrives are the ones already operating within the principles that guidance will formalize. Document your controls. Verify your outputs. Know where client data goes. That work doesn't become obsolete when the rules get more specific. It becomes the foundation.

Compliance & AI Dispatch

Once a month: what is changing across CIRO, PIPEDA, and Quebec Law 25, and what it means for advisors using AI tools. A five-minute read.

Northern Catalyst does not share email addresses.

Sandy

Sandy

Founder, Northern Catalyst

Building tools for Canadian financial advisors

Related Posts