 Sunco Communication and Installation Ltd. AI Readiness Assessment Prepared for Northgate Millwork Ltd. |
Hello Dana Whitfield, Thank you for completing the Sunco AI Readiness Assessment. Your personalized results are below. Assessment completed: August 20, 2026 |
Your Score 55% aligned · grade B | | AI Readiness Signal AI Explore Good foundation with targeted gaps to close |
|
HOW THIS SCORE WAS CALCULATED Your AI Readiness Score is the percentage of assessed practices your organization has in place, measured against the nine control objectives of ISO/IEC 42001:2023 (Annex A), the Canadian Centre for Cyber Security’s Top 10 AI Security Actions (ITSAP.10.049), and your obligations under Alberta’s Personal Information Protection Act. Each of the 34 questions scores 0 to 3, where 0 means the practice is fully in place. Band thresholds at 50% and 85% are taken from the achievement scale published in ISO/IEC 33020:2019; the letter-grade divisions within those bands are Sunco’s own. This assessment surfaces readiness gaps — it does not certify compliance with any standard. |
Section Breakdown | Section | Aligned | Risk Level | | Strategy, Leadership and Capacity | 33% | HIGH RISK | | Data Readiness and Quality | 58% | Moderate Risk | | Security and Privacy Controls | 52% | Moderate Risk | | Infrastructure and Integration Readiness | 78% | Moderate Risk | | Workforce Readiness and Change Management | 67% | Moderate Risk | | Governance, Ethics, and Compliance | 53% | Moderate Risk |
|
AT A GLANCE 3 in place | 29 need work | 2 high risk |
Every answer you gave, sorted into three groups. Pillars appear worst-first within each. |
IN PLACE · 3 What you’re doing well These practices are already in place. They are the foundation everything else gets built on — and they are the reason the gaps below are worth fixing rather than starting over. |
| Strategy, Leadership and Capacity | 1 of 8 · 33% aligned |
Have you identified where repetitive, manual work is costing your team the most time? Yes — we know the top two or three processes and roughly what they cost us in hours |
| Infrastructure and Integration Readiness | 2 of 6 · 78% aligned |
Is your internet connectivity reliable enough to support cloud-based AI tools across all locations? Yes, reliable business-grade connectivity with redundancy at all locations |
Is your network segmented and secure enough to isolate AI tool traffic from sensitive systems? Yes, network segmentation is in place and regularly reviewed |
|
NEEDS WORK · 29 What needs work Partly in place, informal, or not yet documented. None of these are emergencies — but each one is something an auditor, an insurer, or an AI project would eventually stumble over. |
| Strategy, Leadership and Capacity | 5 of 8 · 33% aligned |
| Does your organization have a documented AI strategy or policy? | Partly in place |
Your answer: No strategy exists. We are reacting to what others are doing A documented AI strategy is the single strongest predictor of successful adoption. Without it, teams adopt tools inconsistently, security controls are bypassed, and investment is wasted. How Sunco closes this Start with a half-day session to define what AI is for in your business. Sunco facilitates this and produces the policy document as the output, so you leave with the artifact rather than an action item. |
ISO/IEC 42001:2023 · Annex A.2 — Policies related to AI A.2 is the first control objective an ISO/IEC 42001 auditor tests. An organization with no documented AI policy cannot demonstrate conformity with the standard’s opening requirement. |
|
| Has leadership defined specific business problems AI should solve? | Partly in place |
Your answer: AI adoption is being driven by general interest, not a defined business need The most common reason AI projects get cancelled is that nobody can answer what problem this solves and how we will know it is working. One specific, measurable use case changes everything. How Sunco closes this Run a use-case workshop that scores candidate ideas on business value, data availability and risk. Sunco brings the scoring model so the shortlist is defensible to your board. |
NIST AI RMF 1.0 · MAP 1 — Context is established and understood MAP is the function that establishes context before risk can be assessed. Without a defined problem statement there is nothing to map, and every downstream risk judgement becomes guesswork. |
|
| Are AI adoption decisions made with input from operations, HR, legal, and finance? | Partly in place |
Your answer: Decisions are made by individual departments independently AI tools affect payroll, privacy, contracts, and operations simultaneously. A tool approved by IT but not reviewed by HR or legal has created compliance problems for Canadian SMBs — particularly where personal information is involved. How Sunco closes this Introduce a single approval path for AI tools. Departmental autonomy is how one team’s convenient tool becomes the whole organization’s disclosure problem. |
Alberta PIPA · Consent and reasonable purposes The reasonable-purposes test is applied to the business, not to the IT department. A tool adopted without HR or legal review can put personal information to a use the business cannot defend. |
|
| If you approved an AI or automation project this quarter, who would run it day to day? | Partly in place |
Your answer: It would land on whoever had capacity that week Readiness is not only about controls — it is about whether anyone has the hours. Projects with a named owner and allocated time land; projects owned by whoever has capacity that week do not. Microsoft’s 2026 Work Trend Index found only 26% of people say leadership is clearly aligned on AI, and unclear ownership is where that shows up first. How Sunco closes this Assign a single owner before the project starts. Rotating ownership is why pilots produce activity without producing a decision. Sunco can carry the delivery load while your owner stays accountable for the outcome. |
ISO/IEC 42001:2023 · Annex A.4 — Resources for AI systems A.4 treats people and their available time as a resource the organization must actually provide, not assume. An unresourced owner is the most common reason a governance framework exists on paper and nowhere else. |
|
| Thinking about your last two or three technology projects — how did they land? | Partly in place |
Your answer: One or more stalled partway and was quietly dropped Track record predicts more than intent. An organization that has delivered technology change recently can usually absorb another; one whose last two projects stalled will stall again on the same constraint, whatever that constraint was. Naming it is more useful than ignoring it. How Sunco closes this Worth understanding why before starting another. In our experience it is almost always ownership or integration, both of which are addressable — but not by trying harder the same way. |
|
| Strategy, Leadership and Capacity: Sunco runs a half-day AI strategy session that produces three things you do not have today: a named governance owner, two defined use cases with success criteria, and an inventory of the AI tools already running in your business. |
| Security and Privacy Controls | 7 of 7 · 52% aligned |
| Do you know whether your AI vendors store, train on, or share your business data? | Mostly in place |
Your answer: We have checked some vendors but not all Many popular AI tools use customer inputs to improve their models by default. Confidential client communications, internal strategy documents, and employee data entered into these tools may be used to train AI systems. How Sunco closes this Complete the review for every tool that receives client or employee data. Free and low-cost tiers are the ones most likely to train on your inputs by default. |
ISO/IEC 42001:2023 · Annex A.10 — Third-party and customer relationships A.10 exists because AI supply chains obscure who is accountable for data. Under Alberta’s PIPA, the obligation stays with your organization regardless of what the vendor’s terms say. |
|
| Have you assessed whether your current cybersecurity controls are sufficient for an AI-augmented environment? | Mostly in place |
Your answer: A partial assessment was done but did not specifically address AI AI tools introduce threat vectors that standard IT assessments do not cover: prompt injection, data poisoning, unauthorized model access, and new API endpoints. Controls adequate before AI may have significant gaps after. How Sunco closes this Extend the assessment to AI-specific vectors. A conventional review will not test prompt injection, model access or the new API surface your AI tools introduce. |
CCCS ITSAP.10.049 · Actions 1, 4 and 5 — prompt injection mitigation, AI testing and red teaming, data poisoning safeguards These are three of the ten AI security actions Canada’s national cyber security authority publishes for organizations. None of them is covered by a conventional IT security assessment. |
|
| Are employees trained on what data is safe to input into AI tools? | Partly in place |
Your answer: Employees use AI tools without specific guidance on data inputs The 2026 Verizon Data Breach Investigations Report found a human element present in 62% of breaches. An employee who pastes a client contract into a public AI tool has transmitted confidential information to a third party — likely without consent and potentially in breach of client agreements. How Sunco closes this Deliver a one-hour AI data-safety session. This is the lowest-cost control available against your most likely AI incident. |
CCCS ITSAP.10.049 · Action 8 — Data privacy, vendor and contractual controls Most client agreements contain confidentiality terms that predate generative AI. Staff cannot honour a contractual restriction they have never been told about. |
|
| Do you have a process to detect and manage shadow AI (unsanctioned AI tool use)? | Mostly in place |
Your answer: We have policies but limited visibility into actual usage Employee use of unapproved AI tools rose from 15% to 45% of employees in a single year (Verizon DBIR 2026), and IBM found shadow AI incidents more than doubled to 43% of AI-related security incidents. An acceptable use policy plus a quarterly tool audit is the minimum control. How Sunco closes this Add visibility to the policy — network or SaaS discovery plus a quarterly survey. A policy with no detection mechanism documents intent rather than control. |
ISO/IEC 42001:2023 · Annex A.9 — Use of AI systems A.9 governs authorized use. An organization that cannot say which AI systems are in use cannot demonstrate that any of them are used responsibly. |
|
| Does your organization have endpoint protection and access management controls in place? | Mostly in place |
Your answer: Basic antivirus and some MFA is in place Vulnerability exploitation has overtaken credential abuse as the leading way attackers get in — 31% of breaches against 13% (Verizon DBIR 2026) — and IBM found 92% of organizations suffering an AI-related breach lacked proper AI access controls. AI tools reach your business systems through the same endpoints, the same credentials, and the same unpatched software your employees use every day. How Sunco closes this Extend MFA to every account that can reach business data, and move from antivirus to managed detection. Partial MFA leaves the unprotected accounts as the obvious target. |
CCCS ITSAP.10.049 · Action 6 — Data usage controls and model theft prevention AI systems inherit the access posture of the accounts connected to them. Where MFA and least privilege are absent, an AI integration widens an existing weakness rather than creating a new one. |
|
| How quickly are security patches applied across your servers, workstations and network equipment? | Partly in place |
Your answer: When someone gets to it The 2026 Verizon Data Breach Investigations Report found vulnerability exploitation displaced credential abuse as the leading way attackers get in for the first time in 19 years — 31% of breaches against 13%. Patching is now the single highest-value security control in that report, and it applies to every system an AI tool connects to. How Sunco closes this Move to a defined cadence with reporting. Unpatched systems are now the leading initial access vector, and "when someone gets to it" is not a position you can describe to an insurer. |
|
| When an AI tool or automation connects to one of your business systems, how does it authenticate? | Partly in place |
Your answer: It uses an individual employee’s login IBM found 92% of organizations that suffered an AI-related breach lacked proper AI access controls. An automation running on an employee’s login inherits everything that person can reach — and keeps working after they leave, change role, or have their credentials stolen. How Sunco closes this Move each integration to its own service account. Personal credentials tie your automations to one person’s employment and expose everything they can see. Sunco can re-platform these without downtime. |
CCCS ITSAP.10.049 · Action 6 — Data usage controls and model theft prevention Canada’s cyber security authority treats AI access control as a distinct action, not a by-product of normal identity management. An AI integration is a non-human identity and needs to be governed as one. |
|
| Security and Privacy Controls: Sunco assesses your security posture for the AI environment specifically — vendor data handling, endpoint and access controls, shadow AI visibility — and closes the gaps AI adoption creates before they become claims. |
| Governance, Ethics, and Compliance | 5 of 5 · 53% aligned |
| Does your organization audit AI outputs for accuracy, bias, or errors before acting on them? | Mostly in place |
Your answer: Informal review happens but is inconsistent AI errors often look identical to correct outputs. Without a review process, AI-generated mistakes in communications, analysis, or recommendations reach clients and decision-makers with no check. How Sunco closes this Define which output types must be reviewed before use — anything client-facing, financial or personnel-related — so review is triggered by category rather than by individual judgement. |
ISO/IEC 42001:2023 · Annex A.5 — Assessing impacts of AI systems A.5 is the control objective covering impact assessment. Reviewing outputs before acting on them is the operational form of that requirement. |
|
| Are there controls to prevent AI from making autonomous decisions in regulated areas? | Mostly in place |
Your answer: Partial controls exist but are not consistently applied Decisions affecting employment, credit, or essential services carry accountability obligations regardless of whether AI was involved. The Privacy Commissioner’s position is that accountability rests with the organization, not with any automated system — and if you serve customers in Quebec, Law 25 already requires you to disclose decisions made exclusively by automated processing. How Sunco closes this Map which decision types AI touches and apply the human-approval requirement consistently across all of them. Inconsistent application is difficult to defend after the fact. |
Quebec Law 25 · Act respecting the protection of personal information in the private sector, s. 12.1 This is the only binding automated-decision transparency law in Canada today. It applies based on where the individual is, not where your business is — so it reaches an Alberta company serving Quebec customers. |
|
| Does your organization have a process for evaluating new AI tools before adoption? | Mostly in place |
Your answer: Informal evaluation happens but no consistent criteria or process A one-page evaluation checklist covering data practices, security certifications, Canadian data residency, and integration fit takes 30 minutes per tool and prevents months of remediation. How Sunco closes this Standardize the criteria into a short checklist so evaluations are comparable and repeatable regardless of who performs them. |
ISO/IEC 42001:2023 · Annex A.10 — Third-party and customer relationships A.10 requires supplier risk to be assessed, not assumed. A pre-adoption checklist is the lightest mechanism that satisfies it and the easiest to apply consistently. |
|
| Before adopting an AI tool that affects customers or employees, do you assess what could go wrong for the people involved? | Partly in place |
Your answer: We assess technical and security risk, but not impact on people This is the control that distinguishes governance from paperwork. It is also the direction Canadian law is moving: Bill C-36, tabled in June 2026, would add automated-decision transparency duties, and Quebec’s Law 25 already requires it where a decision is made exclusively by automated processing. How Sunco closes this Extend your existing review to cover the people affected — employees and customers. It is the same meeting with two more questions in it, and it is the gap most SMBs have. |
ISO/IEC 42001:2023 · Annex A.5 — Assessing impacts of AI systems A.5 is the control objective an ISO/IEC 42001 auditor uses to separate organizations that govern AI from organizations that have written a policy about it. It asks for an assessment before deployment, not a review afterwards. |
|
| If AI helped produce work you delivered to a customer, would you tell them? | Partly in place |
Your answer: We have not considered whether to disclose Disclosure is becoming a commercial question as much as a compliance one. Some clients now ask directly, and some contracts already restrict it. Being able to answer clearly — either way — is worth more than having a policy nobody can summarise. How Sunco closes this Decide before a client asks you. Check your top client contracts for confidentiality or AI clauses at the same time — several will already have them. |
ISO/IEC 42001:2023 · Annex A.8 — Information for interested parties Customers are interested parties under A.8. The standard does not dictate what you disclose, but it does expect the organization to have decided — and to be consistent about it. |
|
| Governance, Ethics, and Compliance: Sunco builds you a practical AI governance framework — impact review, approval path, oversight controls and vendor evaluation — sized for a business your size rather than borrowed from an enterprise. |
| Data Readiness and Quality | 4 of 4 · 58% aligned |
| Do you know where all your business-critical data lives? | Mostly in place |
Your answer: We know the main systems but not all edge cases You cannot govern what you cannot see. Starting with your top five systems — where customer, financial, and operational records live — gives you enough visibility to make safe AI decisions. How Sunco closes this Close the edge cases — they are where unmanaged personal information usually sits. Departmental spreadsheets and legacy shares are the two most common blind spots. |
ISO/IEC 42001:2023 · Annex A.7 — Data for AI systems A.7 is the control objective most SMBs fail first. Data provenance cannot be documented for systems whose location is unknown, so a gap here cascades into every other data control. |
|
| Is your data organized, labelled, and accessible, or siloed across disconnected systems? | Partly in place |
Your answer: Largely siloed. Teams cannot easily access each other’s data AI tools drawing on siloed or inconsistently formatted data produce unreliable results. A common cause of stalled AI pilots in smaller organizations is data spread across several systems that were never connected. How Sunco closes this Silos cap AI value at whatever one system can see. Sunco assesses which integrations unlock the most value first so the sequence is driven by outcome, not by convenience. |
|
| Do you have a data retention and classification policy? | Mostly in place |
Your answer: Informal practices exist but nothing is formally documented When you feed business data into an AI tool, you need to know what you are feeding it. A simple three-tier classification (public, internal, confidential) is the foundation of safe AI data use. How Sunco closes this Document the practice you already follow. A three-tier scheme on one page is enough to make "what can go into an AI tool" a question with an answer. |
CCCS ITSAP.10.049 · Action 6 — Data usage controls and model theft prevention Canada’s national cyber security authority lists data usage controls among its ten AI security actions. Classification is the mechanism that makes such a control enforceable rather than aspirational. |
|
| Do you have consent and governance controls for personal data used in AI workflows? | Mostly in place |
Your answer: General privacy controls exist but AI-specific rules have not been defined Alberta’s PIPA and federal privacy law apply to personal information processed through a third-party AI tool exactly as they apply to any other processing — including data typed into ChatGPT or Microsoft Copilot. In May 2026 the Privacy Commissioner found a major AI provider had no valid consent for personal information it had collected. How Sunco closes this Extend the existing controls to name AI tools explicitly. Staff will not infer that a privacy policy written before AI covers the tool they opened this morning. |
Alberta PIPA · Consent for collection, use and disclosure Entering a client record into a third-party AI tool is a disclosure. PIPA does not exempt it because the recipient is software, and the organization — not the vendor — carries the obligation. |
|
| Data Readiness and Quality: Sunco maps your data landscape across your top systems, identifies the integration and governance gaps that block AI value, and sequences the cleanup so the highest-value use case becomes possible first. |
| Workforce Readiness and Change Management | 4 of 4 · 67% aligned |
| Have employees been informed about how AI will and will not change their roles? | Mostly in place |
Your answer: Some communication has happened but not consistently across all teams Employees who do not understand why AI is being introduced either resist it or use it in unsanctioned ways. A simple all-hands message covering what you are adopting, why, and what it will not replace costs nothing and dramatically increases adoption and compliance. How Sunco closes this Close the gaps — uneven communication produces uneven adoption and leaves the least-informed teams improvising with unsanctioned tools. |
ISO/IEC 42001:2023 · Annex A.8 — Information for interested parties Employees are interested parties under A.8. Communication is a control objective in the standard, not simply good change management. |
|
| Does your organization have AI literacy training in place or planned? | Mostly in place |
Your answer: Informal guidance has been shared but no structured training AI literacy means employees understand what AI tools can and cannot do, know what data is safe to input, and can recognize when an AI output needs human review. A two-hour introduction changes behaviour immediately. How Sunco closes this Formalize it into a short session with a record of attendance. Structure is what makes the expectation enforceable and survivable through turnover. |
|
| Are managers equipped to review AI-assisted work for accuracy and quality? | Mostly in place |
Your answer: Some managers have self-educated but no formal guidance exists Human oversight of AI is not a nice-to-have. Managers who cannot recognize a plausible-but-wrong AI output are the last line of defence, and right now many of them are not equipped to play that role. How Sunco closes this Give managers a short review standard — what to check, what to escalate. Self-education produces inconsistent thresholds across teams. |
CCCS ITSAP.10.049 · Action 9 — Human-in-the-loop oversight and execution controls Human-in-the-loop oversight is one of the ten actions Canada’s cyber security authority publishes. The Privacy Commissioner is consistent with it: accountability rests with the organization, never with the automated system. |
|
| Does your organization have an AI acceptable use policy? | Mostly in place |
Your answer: A general IT acceptable use policy exists but does not address AI specifically An AI acceptable use policy needs to answer three questions: which tools are approved, what data cannot be entered, and what the consequences of violations are. A one-page document answering these is the minimum governance floor. How Sunco closes this Add one AI paragraph to the existing policy covering approved tools and prohibited data inputs. This is a thirty-minute change that closes the most common compliance gap. |
ISO/IEC 42001:2023 · Annex A.9 — Use of AI systems A.9 is where an acceptable use policy is evidenced. IBM found 68% of breached organizations lacked the governance to manage AI or detect shadow AI — this control is the most common thing missing. |
|
| Workforce Readiness and Change Management: Sunco helps you build AI literacy, acceptable use frameworks and review habits so your people become the control layer around AI rather than the source of its risk. |
| Infrastructure and Integration Readiness | 4 of 6 · 78% aligned |
| Do your core business systems have API or integration capabilities? | Mostly in place |
Your answer: Some systems have integration capabilities but others do not The most powerful AI use cases connect multiple systems. AI that can pull from your CRM, generate a communication, and log the outcome back is transformative. AI in isolation is just another tool. How Sunco closes this Map which of your priority use cases depend on the closed systems, and plan replacement or middleware for those specifically rather than across the whole estate. |
ISO/IEC 42001:2023 · Annex A.6 — AI system life cycle Integration is a life-cycle concern, not a one-off project. Systems that cannot exchange data cannot support the monitoring and change management A.6 expects once a tool is live. |
|
| Are your communication platforms current enough to support AI-assisted features? | Mostly in place |
Your answer: On a relatively current platform but AI features have not been enabled AI-assisted call transcription, meeting summaries, smart routing, and communication analytics are available in modern unified communications platforms. Legacy phone systems cannot access these capabilities. How Sunco closes this Enable and configure the AI features you are already licensed for. This is the fastest AI value available to most organizations, and it is usually already paid for. |
|
| Do you have a plan for managing AI tool licensing, access, and cost as usage scales? | Mostly in place |
Your answer: We manage this informally but have not formalized a plan AI tool costs grow faster than the value they deliver when licensing and usage are not managed. A simple governance document covering approved tools, per-seat costs, and an annual review keeps investment aligned with outcomes. How Sunco closes this Document current per-seat spend and set an annual review date. Informal management is how duplicate subscriptions accumulate across departments. |
|
| If an AI or automation project needed two of your systems to exchange data, who would build that? | Mostly in place |
Your answer: We would need help, and we know who we would call Integration is where most SMB automation either happens or dies. Statistics Canada found Alberta businesses cite data limitations as a barrier to AI at 6.5% against 3.8% nationally — the widest gap between Alberta and the national picture on any barrier measured. How Sunco closes this Good position. Make sure whoever you call understands both systems — integration failures are usually about the business process between them, not the connection itself. |
ISO/IEC 42001:2023 · Annex A.6 — AI system life cycle A.6 covers the whole life of a system, not its purchase. Integrations that nobody can build, monitor or change are the point at which a life-cycle process stops existing in practice. |
|
| Infrastructure and Integration Readiness: As your systems integrator, Sunco connects the communications, networking and cloud infrastructure your AI tools depend on — so they work consistently across every location and every employee. |
|
HIGH RISK · 2 Your biggest risks These carry real exposure today — regulatory, security, or financial. We would address these before adding any further AI tooling. |
| Strategy, Leadership and Capacity | 2 of 8 · 33% aligned |
| Is there a designated person or team responsible for AI governance? |
Your answer: We have not considered governance yet AI governance does not need a dedicated department. It needs one accountable owner who can answer: what tools are approved, who can use them, and what data is allowed in. How Sunco closes this Name an owner before your next AI tool purchase. Without one, no policy survives contact with the business and no incident has a clear path to resolution. |
ISO/IEC 42001:2023 · Annex A.3 — Internal organisation A.3 exists because accountability cannot be distributed. The Privacy Commissioner’s guidance is blunter still: accountability for AI decisions rests with the organization, not with any automated system. |
|
| Does your organization track which AI tools employees are currently using? |
Your answer: We have not looked into this Employee use of unapproved AI tools rose from 15% to 45% of employees in a single year, according to the 2026 Verizon Data Breach Investigations Report. Shadow AI is the norm, not the exception. A free internal survey takes under two hours. How Sunco closes this Start here — this is the cheapest and highest-yield action in the entire assessment. You cannot govern, secure or budget for tools you cannot see. |
|
| Strategy, Leadership and Capacity: Sunco runs a half-day AI strategy session that produces three things you do not have today: a named governance owner, two defined use cases with success criteria, and an inventory of the AI tools already running in your business. |
|
⚡ Quick Wins — Act On These Now | | Run a 30-minute internal audit of which AI tools employees are already using. Start with IT, sales, and operations. Employee use of unapproved AI tools rose from 15% to 45% in a single year — you need to see it before you can manage it. |
| | Write down one specific business problem AI should solve and define what success looks like in measurable terms. Specificity is what separates AI projects that deliver from ones that stall. |
| | Review the data processing terms of your top three AI vendors. Confirm whether they train on your data by default. Many free and low-cost AI tools use your inputs for model training unless you opt out. |
|
Assessment Framework & Standards Alignment Your results have been evaluated against the following internationally recognized frameworks and Canadian regulatory obligations. ISO/IEC 42001 AI Management System The international standard for governing AI within an organization. Its Annex A sets out nine control objectives covering AI policy, roles, resources, impact assessment, system lifecycle, data, transparency, use, and third-party relationships. This assessment is structured around those nine objectives. | NIST AI RMF 1.0 AI Risk Management Framework A voluntary framework organized around four functions — Govern, Map, Measure, and Manage — used to identify and manage risk across an AI system’s life. Referenced here for risk-management structure; it is currently under revision by NIST. | ALBERTA PIPA Personal Information Protection Act Alberta’s private-sector privacy law, and the law that most directly governs an Alberta business feeding personal information into an AI tool. It requires consent for reasonable purposes, reasonable safeguards, and breach reporting to the Commissioner where there is a real risk of significant harm. | PIPEDA Federal privacy law Applies to federally regulated businesses and to personal information crossing provincial or national borders — which captures most Canadian organizations using AI services hosted outside Canada. In May 2026 the Privacy Commissioner applied it to a major AI provider, finding consent and transparency failures. | CCCS ITSAP.10.049 Top 10 AI Security Actions Canada’s national cyber security authority sets out ten concrete AI security actions, from prompt-injection and deepfake defences to data-usage controls, vendor and contractual controls, and human-in-the-loop oversight. The security and workforce sections of this assessment map to these actions. |
Canada has no AI-specific statute. The Artificial Intelligence and Data Act (Bill C-27) died on the Order Paper when Parliament was prorogued in January 2025 and was not reintroduced; Bill C-36, tabled in June 2026, is before Parliament but is not law. This assessment surfaces readiness gaps against the frameworks above — it does not certify compliance with any of them. Consult qualified counsel regarding your specific obligations. |
|
AI Readiness Benchmark WHY THIS MODEL MATTERS Statistics Canada surveyed Canadian businesses in April and May 2026 on whether they use AI to produce goods or deliver services. Nationally 19.2% did. Among Alberta businesses with 20 to 99 employees the figure was 21.1%, against 25.8% for the same size band nationally. Alberta firms were also more likely than average to name cyber security and privacy as the barrier holding them back — 16.1% against 13.4% nationally. That is the environment your readiness score sits in. |
Your Readiness, In Context | Your AI Readiness Score | 55% | | | | Among businesses of 20 to 99 employees, this many use AI to produce goods or deliver services: | | Alberta | 21.1% | | Canada, same size band | 25.8% |
|
| In Alberta, 37.6% of businesses your size told Statistics Canada AI simply is not relevant to them. A defined use case is what moves an organization out of that group. |
These are contextual benchmarks drawn from Statistics Canada’s Canadian Survey on Business Conditions, second quarter 2026. They show how many comparable businesses are using AI in production — they are not readiness scores, and they are not a measure of how those businesses would score on this assessment. Use them to anchor a conversation about where your organization sits, not as a performance comparison. |
Sunco’s Recommendation AI Explore: Good foundation with targeted gaps to close. |
|
Book Your AI Readiness Review A Sunco advisor will walk through your results and identify the highest-impact next steps for your organization. 30 minutes • Free • No obligation |
Research Sources and Methodology Every figure and framework reference in this report is listed below with a link to the original source, so you can verify any of it yourself. Gartner — Lack of AI-Ready Data Puts AI Projects at Risk Through 2026, organizations will abandon 60% of AI projects unsupported by AI-ready data. Tier 2 source · Global · verified 2026-08-19 |
Statistics Canada — Table 33-10-1167-01, Canadian Survey on Business Conditions, Q2 2026 21.1% of Alberta businesses with 20 to 99 employees used AI to produce goods or deliver services in the 12 months to Q2 2026; 25.8% nationally for the same size band. Tier 1 source · Canada / Alberta · verified 2026-08-19 |
Statistics Canada — Table 33-10-1169-01, barriers limiting the use of AI, Q2 2026 37.6% of Alberta businesses with 20 to 99 employees reported AI is not relevant to their business. Tier 1 source · Alberta · verified 2026-08-19 |
Statistics Canada — Table 33-10-1169-01, barriers limiting the use of AI, Q2 2026 16.1% of Alberta businesses cite cyber security and privacy as a barrier to AI use, against 13.4% nationally; data limitations 6.5% against 3.8%. Tier 1 source · Canada / Alberta · verified 2026-08-19 |
Salesforce — State of Data and Analytics Report 84% of data and analytics leaders say their data strategies need a complete overhaul before their AI ambitions can succeed. Tier 2 source · Global (18 countries) · verified 2026-08-19 |
IBM / Ponemon Institute — Cost of a Data Breach Report 2026 (Canada release) The average cost of a data breach in Canada reached CA$7.11 million, taking an average of 205 days to detect and contain. Tier 2 source · Canada · figures in CAD · verified 2026-08-19 |
IBM / Ponemon Institute — Cost of a Data Breach Report 2026 Security incidents involving shadow AI more than doubled to 43%, up from 20% the previous year. Tier 2 source · Global · verified 2026-08-19 |
IBM / Ponemon Institute — Cost of a Data Breach Report 2026 68% of breached organizations lacked the governance to manage AI or detect shadow AI. Tier 2 source · Global · verified 2026-08-19 |
IBM / Ponemon Institute — Cost of a Data Breach Report 2026 92% of organizations that experienced an AI-related breach lacked proper AI access controls. Tier 2 source · Global · verified 2026-08-19 |
Verizon — 2026 Data Breach Investigations Report — Executive Summary A human element was present in 62% of breaches. Tier 2 source · Global · verified 2026-08-19 |
Verizon — 2026 Data Breach Investigations Report — Executive Summary Vulnerability exploitation displaced credential abuse as the leading initial access vector for the first time in 19 years, at 31% of breaches against 13% for credential abuse. Tier 2 source · Global · verified 2026-08-19 |
Verizon — 2026 Data Breach Investigations Report Employee use of unapproved (shadow) AI tools rose from 15% to 45% of employees in a single year. Tier 2 source · Global · verified 2026-08-19 |
McKinsey / QuantumBlack — The state of AI in 2025: Agents, innovation, and transformation AI high performers are nearly three times as likely as others to say their organizations have fundamentally redesigned individual workflows. "High performers" are the ~6% of respondents attributing at least 5% of EBIT to AI. Tier 2 source · Global · verified 2026-08-19 |
Microsoft — 2026 Work Trend Index Annual Report Only 26% of people say leadership is clearly aligned on AI; organizational factors account for more than twice the AI impact of individual factors. Tier 2 source · Global (10 countries) · verified 2026-08-19 |
ISO/IEC — ISO/IEC 42001:2023 — Information technology, Artificial intelligence, Management system Nine control objectives and 38 controls for an AI management system (Annex A); scoring backbone for this assessment. Tier 1 source · International · verified 2026-08-19 |
ISO/IEC — ISO/IEC 33020:2019 — Process measurement framework for assessment of process capability Achievement scale: Not achieved ≤15%, Partially achieved >15–50%, Largely achieved >50–85%, Fully achieved >85%. Source of this assessment’s band thresholds. Tier 1 source · International · verified 2026-08-19 |
Canadian Centre for Cyber Security — Top 10 artificial intelligence security actions: A primer (ITSAP.10.049) Ten AI security actions for organizations, including prompt injection mitigation, AI testing and red teaming, data poisoning safeguards, data usage controls, vendor and contractual controls, and human-in-the-loop oversight. Tier 1 source · Canada · verified 2026-08-19 |
Office of the Privacy Commissioner of Canada — PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC The Privacy Commissioner of Canada, with provincial counterparts, found an AI provider did not have valid consent for personal information collected, and identified transparency and accountability failures. Tier 1 source · Canada · verified 2026-08-19 |
Government of Alberta — Personal Information Protection Act (Alberta) Alberta’s private-sector privacy law: consent for reasonable purposes, reasonable safeguards, and breach reporting to the Commissioner where there is a real risk of significant harm. Substantially similar to PIPEDA, which is generally displaced within Alberta. Tier 1 source · Alberta · verified 2026-08-19 |
Government of Quebec — Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, s. 12.1 Where a decision is based exclusively on automated processing of personal information, the organization must inform the individual no later than when the decision is communicated, and allow them to submit observations to a person able to review it. In force since 22 September 2023. Tier 1 source · Quebec · verified 2026-08-19 |
Parliament of Canada — LEGISinfo — Bill C-27 (44-1) Bill C-27, containing the Artificial Intelligence and Data Act, died on the Order Paper when Parliament was prorogued on 6 January 2025 and was not reintroduced. LEGISinfo shows its last activity as 26 September 2024, at committee. No AI-specific bill is before the current Parliament. Tier 1 source · Canada · verified 2026-08-19 |
Parliament of Canada — LEGISinfo — Bill C-36 (45-1) Bill C-36, the Protecting Privacy and Consumer Data Act, received first reading on 15 June 2026 and is at second reading. It is not law. Tier 1 source · Canada · verified 2026-08-19 |
NIST — NIST AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0) Four functions — Govern, Map, Measure, Manage — across 19 categories. NIST states on this page that AI RMF 1.0 is being revised under the White House AI Action Plan, so specific subcategories may change. Tier 1 source · International · verified 2026-08-19 |
Office of the Privacy Commissioner of Canada — Principles for responsible, trustworthy and privacy-protective generative AI technologies Organizations should make generative AI outputs traceable and explainable, and accountability for decisions rests with the organization, not with any automated system, with an effective challenge mechanism for significant decisions. Tier 1 source · Canada · verified 2026-08-19 |
Statistics are reproduced as published by the sources above and were verified on the dates shown. Regulatory positions reflect the law in force at the time of verification and may change. This assessment surfaces readiness gaps and does not certify compliance with any standard; consult qualified counsel regarding your specific obligations. |
 Sunco Communication and Installation Ltd. 18961 111 Ave NW, Edmonton, AB T5S X4 1-866-310-7007 | marketingteam@sunco.ca | sunco.ca |
© 2026 Sunco Communication & Installation Ltd. All rights reserved. |
|
|