AI & Research
Who Is Accountable for the AI? Governance in Sustainable Finance
Oct 6, 2026 · 5 min read

In this article
Sustainable AI needs an owner. A footprint measured once and a source cited once prove little unless someone is accountable for keeping both true as models, vendors and data change.
That accountability is AI governance. In sustainable finance it has moved from good practice to an expectation of regulators, clients and shareholders. This piece covers what it means inside an investment firm, which rules now apply, and where to start.
What AI governance means in an investment firm
AI governance is the set of answers to four plain questions. A firm that can answer all four has governance. A firm that cannot is relying on its vendors’ goodwill.
| Element | The question it answers |
|---|---|
| Inventory | Where is AI used in our research, screening, reporting and client work? |
| Ownership | Who signs off on each use, and who answers when it is wrong? |
| Validation and monitoring | How do we know it works today, and how will we notice when it stops? |
| Vendor oversight | What do we know about the models we buy, and what can we ask of their providers? |
The last row matters most in our field. Few investment firms train their own models. Most of their AI arrives inside tools they buy, so governing AI largely means governing suppliers.
Language models also change in ways older models did not. A provider can update a model without notice, and the same prompt can return a different answer next month. Monitoring has to be continuous, because a one-time approval goes stale.
The rules are arriving unevenly
No single AI law covers a Canadian investment firm today. The obligations come from a patchwork of financial regulation, privacy law, European rules and voluntary standards.
| Instrument | What it asks | Status, October 2026 |
|---|---|---|
| OSFI Guideline E-23 | Model risk management for AI and machine-learning models, vendor models included | Final September 2025; effective 1 May 2027 [1][2] |
| Quebec Law 25 | Privacy duties, including transparency about automated decisions | Fully in force since September 2024 |
| EU AI Act | Documentation duties for general-purpose model providers, energy use included | Applied to those providers from 2 August 2025; high-risk duties delayed in July 2026 [3][4] |
| Canada’s AIDA | A proposed federal AI law | Lapsed in January 2025; the 2023 voluntary code on generative AI remains |
| ISO/IEC 42001 | A certifiable AI management system | Published December 2023; appearing in procurement |
| NIST AI Risk Management Framework | A voluntary risk framework with a generative AI profile | Active |
| ISO/IEC TR 20226 | Metrics for the environmental side of AI systems | Published July 2025 [5] |
Two things stand out. In Canada the binding pressure comes through the financial regulator, with no AI statute behind it. And the standards now reach the environmental footprint, so governance and sustainability are converging on the same evidence.
Investors sit on both sides of the question
Investors ask portfolio companies about AI governance, and are now being asked about their own.
On the asking side, AI oversight has reached the proxy ballot. At Alphabet’s 2026 meeting, shareholder proposals on AI board oversight, AI water use and climate disclosure went to a vote. None was approved, and they are likely to return.[6]
On the receiving side, E-23 is the clearest signal. It applies to federally regulated banks and insurers, and it names risks specific to AI, such as models that re-tune themselves and models that drift. Because vendor models are in scope, the duty passes down the supply chain to every tool those institutions buy.[1]
Firms outside OSFI’s reach still feel it. An asset manager serving a bank or a pension plan will meet these questions in due diligence, whatever its own regulator requires.
A firm that votes for AI oversight at a technology company, and has no inventory of its own AI, has a stewardship position it cannot defend.
Where to start
Governance does not need a large programme to begin. Five steps cover most of the ground, and the first three need no new tools.
- List every AI use. Include the AI inside purchased tools, since that is where most of it sits.
- Rank each use by consequence. A drafting aid and a model that feeds investment decisions need different levels of control.
- Name an owner for each material use. One person, with authority to pause it.
- Write vendor requirements into contracts. Source traceability, notice of model changes, accuracy evidence and footprint data per assessment.
- Adopt a framework and report against it. ISO/IEC 42001 or the NIST framework gives the structure. E-23 sets the bar for anyone serving Canadian banks and insurers.
The fourth step links governance to sustainability. Footprint and traceability become durable when they are contract terms that someone checks.
Governance is how the promise holds
AI for sustainability is a claim about purpose. Sustainable AI is evidence about footprint and trust. Governance is what keeps that evidence true after the launch, the audit or the sales meeting.
We think the firms that earn trust with AI will be the ones that can say who is accountable for it. The size of the model will matter less. Read how we handle this on our Trust page.
- [1]OSFI, Guideline E-23: Model Risk Management, effective 1 May 2027
- [2]McCarthy Tétrault, OSFI E-23 Guideline and its impact on financial institutions
- [3]European Commission, Navigating the AI Act
- [4]EU Artificial Intelligence Act, Digital Omnibus on AI, 2026
- [5]ISO, ISO/IEC TR 20226:2025, Environmental sustainability aspects of AI systems
- [6]Alphabet Inc., Form 8-K, 2026 annual meeting results
- [7]ISO/IEC 42001:2023, NIST AI Risk Management Framework 1.0, Quebec Law 25 and Canada’s Voluntary Code of Conduct on generative AI are cited by name.