RIBO Responsible AI Use: A 4-Pillar Policy Template for Ontario Insurance Brokerages (2026)

Tags:

RIBO Responsible AI Use: A 4-Pillar Policy Template for Ontario Insurance Brokerages (2026)

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

RIBO published its Responsible AI Use Among RIBO Licensees guidance on May 29, 2025. The document does not amend the Code of Conduct. It restates that existing obligations (competence, integrity, client best interest, confidentiality, and Fair Treatment of Customers) already govern AI use. It recommends governance controls around competency, licensed oversight, transparency, bias monitoring, and data protection.

This template turns those recommendations into a practical written policy: a clause-by-clause artifact a 12-broker brokerage can adopt before its next RIBO renewal. It reads alongside our MBRCC + RIBO + FSRA brokerage cybersecurity playbook.

Key Takeaways

  • RIBO’s May 29, 2025 guidance restates that the Code of Conduct and the Fair Treatment of Customers expectations apply to AI use without amendment. A written policy is how a brokerage shows, in a complaint, that it operationalized those duties.
  • The four pillars are accountability and oversight, transparency and explainability (the human-in-the-loop disclosure), fairness and bias (audited outputs), and data governance (vetted vendors, no open AI for client data).
  • RIBO’s sharpest single sentence: firms should ensure that anything “generated or altered by an AI tool” is “overseen by a licensed member” before being presented to a client. The policy names the licensed reviewer and the oversight artifact.
  • The third-party vendor clause matters most. RIBO holds the licensee responsible for Code of Conduct compliance even when the AI sits inside a carrier portal, a broker management system (BMS), or a quoting engine the brokerage did not build.
  • RIBO plus the federal Personal Information Protection and Electronic Documents Act (PIPEDA) form the core compliance stack, with Quebec’s Law 25 layered on where it applies to a brokerage’s Quebec business. The policy reads against the full stack, not just the RIBO pillar.

The May 2025 RIBO guidance: legal anchor

According to RIBO’s Responsible AI Use Among RIBO Licensees guidance (May 29, 2025), the regulator’s position is that the existing Code of Conduct already governs AI use. The guidance does not introduce a new rule.

It groups its recommendations into four areas, frames them against the Fair Treatment of Customers document, and leaves the licensee and the brokerage to show in writing that AI use stays inside the existing rules.

The compliance gap is not the absence of rules. It is the absence of a firm-level policy that translates those rules into desk-level practice. A brokerage that produces an oral “we tell brokers not to use ChatGPT for client work” in a complaint investigation is functionally indistinguishable from a brokerage with no governance.

RIBO regulates Ontario general-insurance brokers and brokerages. The Financial Services Regulatory Authority (FSRA) regulates insurers and other financial-services entities, and it also conducts RIBO’s annual examination on behalf of Ontario’s Minister of Finance.

If a brokerage group includes an entity or individual directly regulated by FSRA, assess FSRA’s IT Risk Management Guidance for that regulated entity; do not treat it as a universal second-regulator rule for every RIBO brokerage. Our MBRCC + RIBO + FSRA brokerage cybersecurity playbook covers the security mapping; this document covers the four AI pillars.

Pillar 1: Accountability and oversight

The first pillar is competency and accountability for customer outcomes. RIBO frames it as a training and governance expectation: brokers should “be trained to understand and be able to identify when AI is being used” and the risks of using it, and firms should run “governance structures that monitor risks and provide ongoing due diligence and education” around the AI tools in use.

Fusion’s implementation pattern is to name one accountable owner. The template designates an AI Lead (often the Principal Broker in a small brokerage) who owns the approved-tools matrix and the quarterly audit, with the Privacy Officer accountable for client personal information. A brokerage that cannot point to one person who owns the AI policy and the approved-tools matrix will struggle to demonstrate “governance structures.”

The AI Lead role is fixed in the policy and announced internally so every broker knows whose desk an AI question lands on.

RIBO is explicit on the vendor-pass-through point. “It is a RIBO licensee’s professional responsibility to comply with the Code of Conduct” even when the AI is delivered by a third-party vendor.

The carrier’s quoting AI, the BMS-embedded summarizer, the spreadsheet plug-in that auto-classifies a claim: none of those shifts liability away from the broker handling the file. The accountability clause has to bind the brokerage to vendor diligence, not just user behaviour.

Pillar 2: Transparency and explainability

The second pillar is the human-in-the-loop disclosure. RIBO writes that “a customer should know when they are engaging with AI instead of a human” and says brokerages should closely monitor generative AI use through one or more licensed brokers.

The disclosure clause has to do two things. It has to define the trigger conditions for telling the client AI was used, and it has to specify how the disclosure is delivered.

Disclosure is not needed for every internal use. The cases that matter are where the client is engaging with AI as if it were a broker (automated chat, AI-generated quote explanation, AI-summarized policy review presented to the insured) and where the AI materially shapes the advice the client receives.

Recommended wording. “The brokerage discloses AI use to the client in three circumstances: (a) the client is interacting with an automated system that simulates broker-customer dialogue, (b) the work product presented to the client is materially shaped by an AI tool, or (c) the client’s engagement letter or service-level agreement requires it.”

“The disclosure is in writing, is filed with the matter, and identifies the category of AI tool used and the licensed broker who reviewed the output.”

“Firms should ensure that anything generated or altered by an AI tool is overseen by a licensed member before being presented to a client.”

RIBO, Responsible AI Use Among RIBO Licensees (May 29, 2025)

Pillar 3: Fairness and bias in claims and underwriting AI

The third pillar is fairness. RIBO gives underwriting as its example: firms using AI for underwriting should be “auditing and monitoring generated outputs to ensure that the model is performing as intended and is not subject to systemic biases.”

This is the pillar most underbuilt in current Ontario brokerage policies because most brokerages treat AI as a productivity layer on top of carrier underwriting, not as a decision system the brokerage operates.

That framing is incomplete. The brokerage operates a decision system the moment it lets an AI tool suggest a market, summarize a risk for a carrier submission, or pre-classify a claim by category before a licensed broker reviews.

Each of those is an AI-shaped decision that touches a Code of Conduct duty (best interest, integrity, fair treatment). RIBO does not prescribe a cadence, sample size, proxy set, or threshold for the auditing it describes; testing for adverse impact on proxies such as postal code, age band, and occupation is Fusion’s recommended methodology.

This template uses a quarterly sample audit as Fusion’s recommended operating method. A bare “the brokerage will monitor AI outputs for fairness” clause is hard to evidence; a clause that specifies a quarterly written audit of a sample of AI-assisted submissions, names the licensed reviewer, and documents the methodology (which proxies were tested, what threshold triggered a flag, how flags were resolved) produces a record you can show.

Pillar 4: Data governance, privacy, and the RIBO + PIPEDA + Law 25 stack

The fourth pillar is data. RIBO expects firms to vet vendors so that “customer data does not leave control of the firm” and that “individual licensees should avoid processing any client information through an open AI system.”

This is the clause most closely aligned with the federal privacy statute and, where a brokerage’s Quebec business engages it, Quebec’s private-sector privacy law.

According to the Office of the Privacy Commissioner of Canada’s principles for responsible AI, PIPEDA already covers AI processing of personal information under the existing accountability, consent, and safeguards principles. The brokerage’s data-governance clause has to read against PIPEDA at the same time it reads against RIBO.

Where Quebec’s law applies, the oversight body is the Commission d’accès à l’information (CAI).

Under the regime the CAI administers, transfers of personal information outside Quebec require a privacy impact assessment and adequate protection under a written agreement. If a decision is based exclusively on automated processing of personal information, the person must be informed and, on request, given the prescribed information and an opportunity to submit observations to a staff member able to review the decision. A brokerage in that position reads its disclosure clause (Pillar 2) against those obligations, not just RIBO.

The 4-pillar policy template: clause-by-clause comparison

This is the spine readers will print. Each row maps one template clause to the RIBO pillar it serves, what your adapted clause should specify, and the failure mode most brokerages hit when they shortcut the clause.

RIBO AI policy clauses, mapped to the four pillars and common failure modes
Template clause RIBO pillar What your adapted clause should specify Common pitfall
Scope Accountability “Governs all personnel, including licensed brokers, CSRs, account managers, contract producers, and authorized vendors with system access.” Scope limited to licensed brokers; leaves CSR-driven AI use uncovered.
Named officer Accountability An AI Lead (often the Principal Broker in a small brokerage) who owns the policy, the approved-tools matrix, and the quarterly audit, with the Privacy Officer accountable for client personal information (template Clauses 3.1 and 3.2). No named officer; nobody owns the artifact when RIBO asks.
Approved tools Accountability + Data “Candidate tier 1 (not approved until the brokerage completes its own review): Microsoft 365 Copilot inside brokerage tenant, vendor AI inside BMS, named carrier-portal AI features.” Categories instead of named products; unenforceable.
Prohibited tools Data Free and consumer tiers of chat assistants by name (consumer ChatGPT, Claude.ai, Gemini, Perplexity), plus any tool not approved in the tools matrix (template Clause 4.2). Allowing “internal-only” consumer AI; one paste is a breach.
Licensed-member oversight Accountability “Any AI-generated or AI-altered output is reviewed by a licensed broker before client delivery; review logged.” AI output goes to client without licensed review; RIBO pillar 1 + 2 fail.
Client disclosure Transparency “Disclose AI use where client engages automated dialogue, output materially shapes advice, or SLA requires.” No disclosure protocol; client surprise becomes a complaint.
Bias audit Fairness “Quarterly written sample audit of AI-assisted submissions; named reviewer; methodology documented.” “Will monitor for fairness” with no methodology; fails Pillar 3.
Vendor diligence Data + Accountability Vendor contracts that bar training on brokerage or client data and record storage and processing locations (template Clause 8.2); Canadian residency as a preference is Fusion’s baseline, not a PIPEDA rule. Vendor onboarded by another department without policy review; data leaves firm control.
Privacy and Law 25 Data PIPEDA safeguards for every AI workflow; where Quebec’s Law 25 applies, its transfer-assessment and automated-decision transparency obligations layer on (template Clauses 6 and 11.3). Single-statute drafting; misses Law 25 trigger on Quebec files.
Training Accountability AI-use training at onboarding and annually, completion recorded with a signed acknowledgement (template Clause 9.1); a fixed hour count is a Fusion rollout suggestion, not template wording. “Training as needed” language; no completion records when RIBO asks.
Incident response All four An immediate trigger: contain, assess, document; escalation to the Principal Broker; Escalate internally and assess any RIBO reporting obligation against the specific by-law, guideline, request, complaint process, or other legal duty engaged by the facts (template Clause 10). No defined trigger; incidents go unreported; notification duties missed.
Annual review Accountability Annual full review by the AI Lead, Privacy Officer, and Principal Broker; quarterly interim on the oversight log; re-acknowledged in writing (template Clause 12). One-time policy; stale within twelve months.

The deployment hierarchy underneath this template, including the carrier-portal AI mapping and the BMS-embedded AI inventory, lives in our AI for Ontario insurance brokerages roadmap. The policy itself only carries the clauses.

The 6-step adoption rollout

The policy is the artifact. The rollout is what makes it stick. The steps below sequence the work in the order Ontario brokerages have executed it in real deployments.

Steps 1-3: Draft, review, and sign

  1. Draft. Adapt the template clauses to brokerage specifics. Name the approved tools the brokerage actually uses. Designate the AI Lead (often the Principal Broker in a small brokerage) and name the Privacy Officer accountable for client personal information. Inventory carrier-portal AI features and BMS-embedded AI in the same pass.
  2. Review. Send the draft to the brokerage’s E&O carrier, typically through the IBAO program. Where the brokerage uses outside counsel for professional-conduct matters, include them. Send it to the IT advisor responsible for the brokerage’s security controls. If the group includes an FSRA-regulated entity or individual, include the applicable FSRA IT Risk controls for that regulated scope. The review gates the bias audit methodology and the vendor diligence clause.
  3. Sign. The Principal Broker, Privacy Officer, and AI Lead sign the policy. Every bound person signs an acknowledgement filed with personnel records. The signed master copy is retained internally with the brokerage’s governance records, next to the E&O certificates; RIBO’s 2026-27 renewal survey asks whether the firm has a workplace generative-AI policy and which AI tools it uses.

Steps 4-6: Train, publish, and annual review

  1. Train. Run AI-use training for every bound person before the policy takes effect; the template requires training at onboarding and annually, and the four-hour first-cycle format is Fusion’s rollout suggestion. Required topics: approved-tools list, prohibited-tools list, the four pillars, oversight artifact procedure, vendor diligence, incident triggers. Sign-off filed.
  2. Publish. Policy posted to brokerage intranet. Disclosure paragraph added to client engagement letters and to the brokerage website privacy notice. Vendor list shared with the principal’s office.
  3. Annual review. Full review at twelve months by the AI Lead, Privacy Officer, and Principal Broker with the IT advisor. Update approved tools, document incidents recorded, refresh the bias audit methodology, re-sign, re-acknowledge. Quarterly interim review tracks the licensed-oversight log.

FIELD NOTE FROM MIKE

In a 12-broker Mississauga brokerage I worked with in Q1 2026, the pillar everyone underbuilt was Pillar 3 fairness. The brokerage already had a sensible approved-tools list and a Principal-Broker oversight cadence, but its draft fairness clause read “we monitor AI outputs for fairness as part of normal supervision.”

That clause cannot demonstrate the auditing RIBO describes. We rewrote it to specify a quarterly written sample audit of fifteen randomly selected AI-assisted submissions, identifying the named reviewer (a senior licensed broker who is not the Principal Broker, for independence).

The rewrite also named the proxies tested (postal-code, age band, named-driver gender split), the threshold that triggers a flag, and the remediation path for any flag raised. The audit lives in a one-page register attached to the policy.

This is the most common Pillar 3 gap we see in brokerage reviews. In each case the fix was the same: name the cadence (quarterly), name the artifact (one-page audit per quarter), name the reviewer, and name the methodology. RIBO’s wording expects the model to be “performing as intended” and not “subject to systemic biases.” A clause without methodology cannot demonstrate either.

Field-note details are a composite drawn from multiple brokerage engagements, with identifying details changed.

The downloadable template below already addresses the Pillar 3 fairness gap and the carrier-portal AI inventory.

Common policy mistakes Ontario brokerages make

Mistake 1: Treating carrier-portal AI as out of scope

The most common drafting error is a policy that covers tools the brokerage installed but exempts AI features inside carrier portals, the BMS, or the quoting engine. RIBO’s vendor-pass-through wording makes this gap material.

The brokerage is responsible for Code of Conduct compliance even when the AI was delivered by a third-party vendor. The scope clause and the vendor-diligence clause both have to bind those features explicitly.

Mistake 2: Skipping the licensed-member oversight log

RIBO is unusually direct on this pillar: anything AI-generated or AI-altered needs licensed oversight before client delivery. Brokerages without a documented oversight artifact fall back to “the licensed broker reviews everything anyway.”

In a complaint investigation that argument fails. The log is what makes the oversight visible. A one-line entry per matter, naming the licensed reviewer and the AI tool, is enough.

Mistake 3: One-statute drafting

Brokerages whose Quebec business brings them under Law 25, but who draft the data clause against RIBO and PIPEDA alone, miss the transfer-assessment and automated-decision obligations. The fix is a single sentence in the privacy clause: “where Quebec’s private-sector privacy law applies, its privacy-impact-assessment and automated-decision transparency obligations apply alongside PIPEDA.”

Mistake 4: Letting the policy go stale

AI tools change quarterly. Vendors change DPAs. New BMS features ship. A policy written in mid-2025 that has not been reviewed by mid-2026 is stale on its face. The annual-review clause is what keeps the document current and what gives the brokerage a defensible posture if a complaint reaches RIBO.

RIBO’s 2026-27 renewal survey asks whether a brokerage has a workplace generative-AI policy and which AI tools it uses. Separately, RIBO recommends vetting current and future AI vendors so customer data remains under the firm’s control and is not used for vendor training.

The IT controls underneath the policy

Policy is necessary but not sufficient. The technical controls that enforce the policy are what stop the prohibited-tools clause from being theatre. Microsoft Purview sensitivity labels gate Copilot access by client matter.

Conditional access policies block personal-account sign-ins to consumer AI on brokerage devices. Data loss prevention rules block policy numbers, SINs, and named-driver identifiers from being pasted into unapproved tools. Audit logging retains the activity record under the brokerage’s documented legal, regulatory, contractual, and security retention requirements.

Our cybersecurity services for Canadian businesses deploy these controls for insurance brokerages as part of the AI rollout, not after. The policy and the controls go in together or the policy is unenforced.

Where FSRA’s IT Risk Guidance applies to an entity in the brokerage group, a material IT risk incident is notified to FSRA as soon as is reasonable, normally within 72 hours or sooner after materiality is determined; the working steps are in our FSRA IT Risk Incident Notification SOP for brokerages.

Download the RIBO AI Policy Template

Fill in the three fields below. We’ll email the editable Word document (twelve clauses plus the tools matrix, disclosure kit, vendor due-diligence questionnaire, and incident runbook) and the one-page implementation checklist after you submit, and the download links appear on screen immediately.

FREE DOWNLOAD

The RIBO-Aligned AI Use Policy Template for Ontario Brokerages (2026)

Twelve clauses, the tools matrix, the client disclosure kit, and the implementation checklist. Editable Word document plus a one-page PDF.


Written by Mike Pearlstein, CISSP. No sales call required.

Form not loading? Email us directly and we’ll send the template.

Frequently Asked Questions

Does RIBO require Ontario insurance brokerages to have a written AI policy?

RIBO has not amended the Code of Conduct to mandate a written AI policy as such. The May 29, 2025 Responsible AI Use Among RIBO Licensees guidance makes clear that the existing Code of Conduct, the Fair Treatment of Customers expectations, and the confidentiality and competence duties already apply to AI use.

A written policy is the standard way a brokerage demonstrates it has operationalized those duties. In an investigation involving AI, a brokerage without one has to reconstruct its governance from memory instead of pointing to a document.

What are the four RIBO Responsible AI Use pillars?

The four pillars are: (1) accountability and oversight, including the expectation that licensees be trained to identify when AI is in use and that the brokerage establish governance structures; (2) transparency, including the expectation that a client know when they are engaging with AI instead of a broker.

The remaining pillars are: (3) fairness and bias, expecting AI outputs to be audited for systemic bias and models to perform as intended; and (4) data governance, expecting vendor vetting and telling licensees to avoid open AI systems for client information.

Can an Ontario broker use ChatGPT for client work?

Not the consumer version. RIBO says individual licensees should avoid processing client information through an open AI system; the guidance does not name specific products. As a stricter Fusion control, this template treats consumer ChatGPT as unapproved for client information.

ChatGPT Enterprise with a signed DPA and controlled data residency can be considered for non-client research and internal work product. A signed DPA makes a tool eligible for review, not approved: client personal information requires the vendor to pass the brokerage’s full privacy and security review, and we start ChatGPT Enterprise at non-client work. Tier 1 approval inside a brokerage typically goes to Microsoft 365 Copilot inside the brokerage tenant, vendor AI delivered inside a BMS under a written DPA, and named carrier-portal AI features.

Does the brokerage have to disclose AI use to clients every time?

Not for every use. RIBO’s expectation is that a customer know when they are engaging with AI instead of a human. The template’s disclosure clause triggers where the client is engaging with an automated system that simulates broker-customer dialogue, where AI materially shapes the work product presented to the client, and where the service-level agreement or engagement letter requires it. Routine internal use such as summarizing a renewal email or pre-classifying a claim category for licensed review does not require client-by-client disclosure but is covered by the brokerage’s general technology notice.

Is the brokerage responsible when the AI is inside a carrier portal it did not build?

Yes. RIBO is explicit that it is the licensee’s professional responsibility to comply with the Code of Conduct even when using third-party vendors. The brokerage cannot pass the duty back to the carrier or the BMS provider. The policy must bind vendor AI features the same way it binds brokerage-installed tools, and the vendor-diligence clause is what makes the binding traceable in a regulatory review.

How does RIBO interact with FSRA on AI matters?

RIBO regulates Ontario general-insurance brokers and brokerages under the Registered Insurance Brokers Act. FSRA regulates insurers and other financial-services entities, and it also conducts RIBO’s annual examination on behalf of the Minister of Finance. FSRA’s IT Risk Management Guidance applies to the entities and individuals FSRA regulates; if a brokerage group includes one, assess that guidance for the regulated entity rather than treating it as a second rule book for every RIBO brokerage. Where it applies, a material IT risk incident is notified to FSRA as soon as is reasonable, normally within 72 hours or sooner after materiality is determined.

What about Quebec-resident insureds and Law 25?

Where Quebec’s private-sector privacy law (Law 25) applies to a brokerage’s business, two obligations matter most for AI work. Transfers of personal information outside Quebec require a privacy impact assessment and adequate protection under a written agreement. And when a decision is based exclusively on automated processing of personal information, the person must be informed and, on request, given the prescribed information and an opportunity to submit observations to a staff member able to review the decision. A multi-province brokerage adopts the strictest applicable standard and confirms the territorial analysis with counsel.

What is the bias audit requirement under Pillar 3?

RIBO expects firms to audit and monitor AI outputs to ensure models perform as intended and are not subject to systemic biases. It does not prescribe a cadence, sample size, or methodology.

The template operationalizes this as a quarterly sample audit: its placeholders suggest ten AI-assisted client documents and five chatbot conversations per quarter, checked for factual errors, coverage misstatements, and indicators of systemic bias or performance drift, with results tabled at the management meeting. Naming the reviewer, the proxies tested, the flag threshold, and the remediation path is Fusion’s recommended write-up.

What should the brokerage do after an AI incident?

The policy should name the internal incident triggers explicitly. Typical internal triggers include: confidential or privileged client information may have been disclosed to an unapproved AI tool, an AI-generated material misstatement reached a client, an unauthorized AI tool is detected on a brokerage device, or a client raises an AI-related concern.

The template’s incident clause triggers immediately: contain, assess, document, and escalate material client-facing errors to the Principal Broker right away; a fixed 24-hour internal window is a Fusion rollout suggestion, not template wording. Any RIBO reporting obligation is assessed against the specific by-law, guideline, request, complaint process, or other legal duty engaged by the facts, per the template’s Clause 10.4 (notify vendor, carrier, and counsel as applicable; cooperate with any RIBO inquiry), and the Privacy Officer assesses whether PIPEDA breach reporting applies. FSRA notification enters only where FSRA directly regulates an entity in the brokerage group.

Does the policy need to address Microsoft 365 Copilot specifically?

Yes if the brokerage runs on Microsoft 365, which most Canadian brokerages do. The data-governance clause should require Microsoft Purview sensitivity labels on every client matter folder before Copilot is enabled.

The licensed-oversight clause should specify that Copilot output is treated as draft work product subject to the same review standard as any other AI-generated output before client delivery. Our Microsoft 365 Copilot guidance for Canadian businesses covers the deployment specifics, and the Copilot oversharing prevention guide covers the Purview labelling sequence.

How often should the AI policy be reviewed?

Annually for a full review, with a quarterly interim review focused on the licensed-oversight log and the bias audit. The annual review produces a written record covering tools added or removed, incidents recorded, training completion rates, and updates to RIBO, FSRA, or OPC guidance.

The reviewed policy is re-circulated to all bound personnel and re-acknowledged in writing within thirty days. The cycle can align with the brokerage’s RIBO renewal, since the 2026-27 renewal survey asks whether the firm has a workplace generative-AI policy and which tools it uses; the policy itself is retained internally, not filed with RIBO.

Does this template apply to mortgage brokerages too?

Not directly. Mortgage brokerages are regulated by FSRA through the Mortgage Brokerages, Lenders and Administrators Act and supervised against the Mortgage Broker Regulators’ Council of Canada (MBRCC) cybersecurity and conduct principles. The data-governance and vendor-diligence pillars transfer, but the conduct-rule citations are different. Mortgage brokerages should adapt this template against the MBRCC framework. Our annotation of MBRCC’s 4 cybersecurity principles for mortgage brokerages covers the mortgage equivalent.

How will my data be used?

Your name, brokerage name, and email go into Fusion Computing’s contact system, and we use those details to deliver the template files. We may send occasional updates relevant to Ontario brokerage IT and AI compliance, no more than once a month.

We do not sell your contact information. We use service providers, including our CRM and email systems, to process the form and deliver the files. Any ongoing marketing email includes an unsubscribe link. See our Privacy Policy for details.

Bottom line

A RIBO-aligned AI policy is short. It designates an AI Lead (often the Principal Broker in a small brokerage) who owns the approved-tools matrix and the quarterly audit, keeps the Privacy Officer accountable for client personal information, lists approved and prohibited tools by product, documents licensed-member oversight per matter, requires vendor contracts that bar training on client data, reads against PIPEDA (and Quebec’s Law 25 where it applies) alongside the RIBO Code, and gets annual sign-off from the AI Lead, Privacy Officer, and Principal Broker. Brokerages with that policy in force answer a RIBO inquiry from the document instead of from memory.

The carrier-portal AI inventory and the BMS-embedded AI mapping that sit underneath the policy live in the full AI for Ontario insurance brokerages roadmap, and the cross-cluster context is in our MBRCC + RIBO + FSRA brokerage cybersecurity playbook.

Book a 30-minute RIBO AI policy working session

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611