Policy on security, privacy and artificial intelligence

Updated – August 2026

How FC Morissette Consulting safeguards client information

As a Government of Canada ProServices supplier, FC Morissette Consulting meets its obligations for managing sensitive information and data. This includes:

  • Maintaining appropriate organizational security screening and clearance through Public Services and Procurement Canada’s (PSPC) Contract Security Program (CSP).
  • Ensuring that any personnel who access sensitive or protected information have valid security status.
  • Applying appropriate IT security controls when processing, storing, transmitting or accessing protected or classified information.
  • Not electronically processing or storing protected or classified information unless authorized in writing by the appropriate Government of Canada authorities.
  • Obtaining prior written permission before subcontracting work that involves Government of Canada security requirements.
  • Following physical and electronic document-safeguarding requirements specified in applicable contracts.
  • Maintaining appropriate oversight, review and audit readiness of security and privacy controls throughout contract performance.

Managing client information for security and privacy

I maintain a Secret-level Government of Canada security clearance, currently valid until February 2035.

I manage client information according to its sensitivity and classification:

  • Sensitive client deliverables and data are stored only on client-approved platforms. These can include Government of Canada platforms such as GC SharePoint and GC Teams that are designed to handle Protected B or higher information. Clients provide access through client-issued hardware, Government of Canada VPN and/or network access.
  • Information held on my own systems is limited to Protected A or non-classified information. It is stored in my Microsoft 365 and OneDrive accounts, which are in line with Government of Canada security standards. These platforms are approved for Protected A, and in some circumstances Protected B, information; however, in my own practice I limit storage to Protected A only.
  • Data on my systems is access-controlled and safeguarded in a manner consistent with PSPC Contract Security Program requirements.
  • I do not store or manage Protected B or higher, or security-classified client information, on my own systems.
  • If a client inadvertently sends me Protected B or higher, or security-classified information, I advise the client and follow their direction to resolve the situation to their satisfaction.
  • When there is uncertainty, I clarify the sensitivity and classification of the information with the client before proceeding.

Using Artificial Intelligence to support consulting projects

I use generative artificial intelligence (AI) tools to accelerate my work, improve the development of client products and reduce costs to clients.

I charge clients only for work actually performed, in accordance with contract terms. If a client instructs me not to use AI tools to support their project, I respect that direction and charge for the full amount of time and effort required to deliver the work without AI assistance.

As the Government of Canada continues to evolve its approach to AI, I apply three core principles:

  • Transparency: I disclose how AI tools are used to support and accelerate contract deliverables.
  • Human review: I review, validate and approve AI-assisted outputs for accuracy, fairness and appropriateness.
  • Accountability: I remain fully responsible for all final deliverables, regardless of whether AI assisted in their development.

How I use AI

I may use paid AI services such as ChatGPT, Gemini or Perplexity to support suitable, unclassified and anonymized work, including:

  • research and analysis;
  • drafting documents and templates;
  • analyzing publicly available frameworks and information; and
  • developing training and learning materials.

AI-assisted outputs generally serve as a rough first draft, analytical aid or starting point for my further work. All final products are developed, edited, finalized, validated and approved by me before they are provided to clients.

I do not enter Protected B or higher, security-classified, personal or other sensitive client information into publicly available or non-Government-of-Canada-managed AI tools.

Where source material contains Protected A or otherwise sensitive information, I first minimize and anonymize the material so that protected, identifying and unnecessary sensitive information is removed before any suitable remaining content is processed by an AI service.

I do not enter identifiable organizational or client information into AI tools unless the tool and use have been specifically authorized for that purpose. This includes, for example:

  • names of individuals;
  • team or organizational names;
  • email addresses;
  • identifiable documents;
  • financial information; and
  • other information that could reasonably identify a client, organization or individual.

Where practical, information is anonymized using generic references such as “Organization X,” “Team XYZ,” or “Employee A/B” rather than actual names or titles.

When I have uncertainty, I clarify the proposed use of AI with the client, including any relevant security, privacy and cost implications.


AI data-protection and privacy settings

Technical safeguards supplement, rather than replace, the privacy and information-management practices described elsewhere in this policy.

When using paid AI services:

  • I configure available privacy settings to limit the use and sharing of information submitted to the service. In particular, I disable available settings that permit conversations or work to be used to improve or train AI models.
  • For particularly sensitive work that is otherwise appropriate for AI processing, I use available temporary-chat features where appropriate. These conversations should not appear in chat history, create memories or be used to train AI models, although service providers may retain them for up to 30 days for safety purposes.
  • AI services are provided by third-party technology providers. Information processed through these services may be temporarily retained or accessible to the provider in accordance with its applicable privacy, security and service terms. I use paid accounts and available privacy controls to minimize retention, access and secondary use of client-related information.
  • I consider the applicable privacy, security and data-handling practices of the AI services I use and apply my own safeguards, including data minimization and anonymization, before providing information to them.

Using AI to support executive coaching and leadership development

My use of AI in coaching is guided by the International Coaching Federation (ICF) Code of Ethics, including its requirements concerning confidentiality, privacy, informed agreement, professional accountability and the responsible use of technology, including artificial intelligence.

I also take into account the ICF Artificial Intelligence (AI) Coaching Framework and Standards, which provide additional guidance on ethical, transparent and privacy-conscious uses of AI in coaching.

Client consent and purpose

With the client’s prior informed consent, I may use transcription technology to create a written transcript of an executive coaching or leadership-development session and may subsequently use an AI tool to process an anonymized version of that transcript for the limited purpose of preparing a coaching summary.

The transcript and AI-assisted processing are used to support:

  • accurate documentation of the discussion;
  • identification and organization of themes discussed during the session; and
  • preparation of a useful follow-up coaching summary for the client.

Protecting coaching information

Before any transcript is provided to an AI tool, I manually review and anonymize it.

This includes removing, as appropriate:

  • the client’s name and other personal identifiers;
  • names of colleagues and other identifiable individuals;
  • identifiable organizations;
  • information that could reasonably identify particular parties; and
  • classified, protected or other sensitive information that should not be processed by the AI service.

Only the resulting anonymized and appropriately minimized version is used for AI-assisted analysis and summarization.

Human review and professional accountability

I may use a secure, paid AI account to help prepare a structured summary of the coaching conversation using my established coaching-summary template.

AI is used as a synthesis and drafting tool to help identify and organize matters discussed during the session, including:

  • key realizations;
  • observations;
  • areas for further reflection; and
  • practical next steps.

AI does not replace my professional judgement as an executive coach.

Because AI-generated outputs may contain errors, omissions or biases, I independently review and validate all AI-assisted coaching summaries before they are provided to clients. I remain responsible for determining the appropriateness of the resulting summary and for further anonymizing or revising it where required.

Client review

The resulting summary is provided to the client as a coaching and leadership-development aid.

Clients are encouraged to:

  • review the summary;
  • correct or clarify anything that does not accurately reflect their understanding of the discussion; and
  • use the agreed observations and next steps to support their ongoing development and follow-up between coaching sessions.

Keeping this policy current

I periodically review and update these security, privacy and artificial-intelligence practices to remain aligned with evolving Treasury Board of Canada Secretariat, Public Services and Procurement Canada, client and professional guidance and requirements.