2 organizations · 2 AI policies · 30+ systems audited · 10+ SOPs delivered · Executive approval secured

The business problem

Most organizations know they need an AI policy. Few know where to start, and even fewer end up with one their teams actually follow.

The real gap is execution. Policies written in isolation, without understanding how people actually work, without mapping the tools already in use, and without a framework for enforcement, end up as PDF documents nobody reads.

The real challenge is building governance that’s rigorous enough to protect the organization and practical enough that people actually adopt it.

The work

Williams Engineering Canada (Dec 2025 – Jun 2026)

AI tools were already part of daily work at Williams Engineering. The organization needed a policy framework to guide that use responsibly.

I authored and implemented the corporate AI Policy from scratch: scoping, drafting, stakeholder alignment, and executive approval. I established governance standards for responsible AI adoption across the organization, and mapped current and future-state workflows (As-Is/To-Be) to ground the policy in how the organization actually operated.

The outcome: a board-approved AI policy, implemented and adopted — the kind people actually open.

Alberta Chambers of Commerce (Apr 2026 – Present)

ACC needed more than a policy. They needed a full governance foundation, one built to scale across a national organization with diverse stakeholders, multiple systems, and AI tool evaluation that never really stops.

I authored ACC’s organization-wide AI Use Policy, informed by ISO/IEC 42001’s core governance principles: approved tools, prohibited use cases, data protection requirements, human oversight protocols, transparency obligations, and enforcement procedures. I performed a full AI Readiness Audit across 30+ tools and systems, delivering an executive report and roadmap that informed tool evaluation and reduced technology risk. I led a technology, workflow, and data gap analysis across the organization’s systems to identify and prioritize AI use cases by value, impact, and feasibility, then built the business case behind each recommendation: weighed against risk analysis and a technology consolidation plan, so every tool decision traced directly back to the policy.

The outcome: a governance framework that ACC can keep building on for years, well past this engagement — Process Library, 10+ SOPs, and knowledge hub included.

What good AI governance actually requires

Most organizations underestimate the scope. A policy document is the visible output. The real work happens underneath it.

System mapping comes first. You can’t govern what you haven’t inventoried. Every tool, every workflow, every data touchpoint needs to be understood before a policy can be written responsibly.

Stakeholder alignment comes next. Governance that leadership doesn’t understand won’t get approved. Governance that staff don’t understand won’t get followed.

Then plain language. International frameworks like ISO/IEC 42001 matter as a foundation, but so does writing in language a non-technical team member can actually act on.

And the audit always comes before the policy. Skip it, and you’re writing rules for a workplace you haven’t actually looked at yet — guesswork with a letterhead.

The business takeaway

AI governance is a competitive asset: the difference between an organization that can confidently expand its AI use and one that’s one incident away from a reputational or compliance problem.

Done well, it also accelerates adoption. When people know exactly what they can use, what they can’t, and why, they stop hesitating and start moving.

That’s the outcome both of these engagements were designed to deliver.

Need AI governance built properly for your organization? I can walk you through what that looks like.