The Firm

What is Nord Paradigm?

Nord Paradigm is an AI governance consulting firm based in Chicoutimi, Quebec, serving organizations across Canada in both English and French. The firm helps companies adopt artificial intelligence responsibly by benchmarking governance posture against Quebec’s Loi 25, ISO/IEC 42001, and emerging Canadian AI regulation, then translating findings into concrete implementation roadmaps. Nord Paradigm operates as an implementation advisor, not a certification body, and combines hands-on AI practice with audit methodology drawn from aeronautical quality management.

Who founded Nord Paradigm?

Nord Paradigm was founded by Dominic-André Leclerc, a 21-year veteran of the Royal Canadian Air Force who retired at the rank of Warrant Officer. He served as an avionics systems technician and AF9000+ Lead Auditor, responsible for quality management compliance across complex military aviation systems. He is pursuing ISO/IEC 42001 Lead Auditor and IAPP AI Governance Professional (AIGP) certifications to formalize his AI governance practice alongside his existing audit credentials.

Where is Nord Paradigm located?

Nord Paradigm Inc. is headquartered at 393, rue Racine Est, 4e étage, Chicoutimi, Quebec, G7H 1T2, Canada. The firm is registered in Quebec and serves clients across Canada either remotely or on-site. Being based in the Saguenay region positions Nord Paradigm to serve regional Quebec SMBs that are often underserved by Montreal and Toronto consultancies, while still working with national clients.

Do you work with clients outside Quebec?

Yes. Nord Paradigm can work with organizations outside Quebec when the mandate fits. The current primary market is French-speaking Quebec, with most engagements delivered remotely and on-site work available when scope justifies travel. English-language delivery is available for Canadian and international teams that need it.

Do you offer services in French?

Yes. French is the primary working language for the current Quebec market, and English delivery is available when the organization or partner context requires it. Reports, audits, policies, workshops, and client communications can be produced in either language, with professional Quebec French standards for organizations operating under Loi 25.

Why work with a specialized firm instead of a Big Four consultancy?

Nord Paradigm offers audit-grade rigor without Big Four overhead. Big Four engagements typically allocate senior partners to scoping calls, then hand delivery to junior staff, and bill accordingly. With Nord Paradigm, the founder runs the engagement directly. The methodology is rooted in AF9000+ aeronautical auditing, where evidence chains and structured remediation are non-negotiable. Smaller firms also move faster: a gap analysis closes in weeks, not quarters.

How Engagement Works

What services does Nord Paradigm offer?

Nord Paradigm offers a four-step service path. Step one is Breach, the free automated public-signal diagnostic. Step two is Breach Pro, the human-validated AI visibility audit with buyer-prompt, competitor, and source evidence plus a prioritized 90-day plan. Step three is the AI Implementation Partnership, which turns one priority process at a time into a working AI workflow. Step four is practical AI governance and ISO/IEC 42001 support. Prism remains in development as a deeper internal governance audit platform.

Where should I start with Nord Paradigm?

Most organizations start with the free Breach AI disruption report at breach.nordparadigm.com, which delivers a personalized analysis in under two minutes. Organizations that already know they need governance work can book a free 20-minute discovery call. The free Breach is designed to qualify the conversation, not gate it.

The Free AI Visibility Baseline

What is Breach?

Breach is a free automated public-signal diagnostic for small and mid-size businesses. It checks whether the public website clearly describes the business, supports important claims with visible proof, and remains technically readable. It produces a fast baseline of what is clear, what is missing, and what to fix first.

Why does AI visibility matter for small and local businesses?

Buyers increasingly ask tools like ChatGPT, Perplexity, Gemini, Copilot, and Google AI for recommendations before they visit websites. A buyer might ask who to hire, which local provider is reliable, or which company solves a specific problem. If the assistant names competitors, directories, or outdated information, the lost opportunity may never show up cleanly in your analytics.

Can buyers ask ChatGPT for a business like mine and never see us?

Yes. AI assistants can omit a business, recommend competitors, or answer from incomplete sources. Free Breach reviews the controllable public signals that influence how systems interpret a business. Breach Pro adds documented buyer-prompt probes, named competitor observations, visible sources when available, and a prioritized plan.

What does Breach test?

Free Breach reviews the public website for business identity, service clarity, visible proof, trust signals, structured and technical readability, and source gaps such as business profiles, reviews, third-party profiles, testimonials, case studies, and outdated claims. Breach Pro adds documented buyer-prompt testing and named competitor and source evidence.

What do we receive?

Free Breach provides a practical public-signal report showing what the website communicates clearly, which proof or trust signals are missing, where technical readability needs attention, and which fixes should come first. Breach Pro adds documented prompts, observed AI answers, named competitors, visible sources when available, human validation, and a prioritized 90-day plan.

Do you use a black-box AI visibility score?

No. Free Breach provides a transparent public-signal baseline rather than claiming a stable AI ranking. Its score reflects controllable website clarity, public proof, trust signals, and technical readability. Breach Pro adds documented prompt observations, competitor and source evidence, and human validation.

Who is Breach designed for?

Breach is designed for owners, executives, marketers, and SEO partners at small and mid-sized businesses who want a concrete view of how AI-assisted discovery sees the business. It is especially useful for service businesses, professional firms, local companies, and Quebec SMBs that need bilingual visibility checks.

The paid AI visibility audit

What is Breach Pro?

Breach Pro is a 10-to-14-page AI visibility audit that builds on the free Breach baseline. It documents buyer-prompt tests, up to three observed competitors, visible sources, and web gaps, adds human validation, and turns the evidence into a 90-day plan. It does not promise an AI ranking, recommendation, citation, or lead.

What is the difference between Breach and Breach Pro?

Breach is the free, fast public-signal diagnostic. Breach Pro is the 10-to-14-page paid AI visibility audit: documented buyer prompts, up to three observed competitors, visible sources, human validation, evidence-backed priorities, and a 90-day plan.

Can you guarantee that ChatGPT will recommend my business?

No. Nobody serious should guarantee placement in ChatGPT, Gemini, Perplexity, Copilot, or Google AI results. AI systems do not behave like stable ranked search pages. They select and synthesize answers from changing sources. Breach Pro provides a repeatable measurement baseline and a prioritized fix plan, not a guaranteed placement claim.

Can Breach Pro prove ROI?

Breach Pro can show visibility, accuracy, competitor presence, source gaps, and changes over time. It can also help you look for AI-related signals in Search Console, Bing Webmaster Tools, analytics, CRM notes, intake forms, and customer conversations. But AI attribution is still imperfect: a mention in an AI answer is not automatically a lead.

How is Breach Pro delivered?

Breach Pro is delivered as a 10-to-14-page executive-ready AI visibility audit within three business days. It documents buyer-prompt evidence, observed answers, up to three competitors, visible sources, source gaps, human validation, and prioritized actions your team or agency can execute over 90 days.

How can I request Breach Pro?

Breach Pro is available for a limited number of founding-beta engagements at $499 CAD. Submit a request to join the beta; the request creates no commitment.

The AI Governance Audit

What is Prism?

Prism is a deeper internal AI governance audit platform currently in development. Its intended scope includes AI systems, risk posture, policies, controls, evidence, and organizational readiness aligned with ISO/IEC 42001. Current governance and ISO readiness needs are handled separately through ISO 42001 advisory engagements.

When will Prism launch?

Prism is currently in development as Nord Paradigm’s dedicated governance audit. Interested organizations can join the waitlist at nordparadigm.com. In the meantime, organizations can access gap analysis, policy design, internal audits, and certification handoff through Nord Paradigm’s ISO 42001 advisory engagements.

What is the difference between Breach Pro and Prism?

Breach Pro is a 10-to-14-page AI visibility audit delivered within three business days, with documented buyer prompts, up to three observed competitors, visible sources, human validation, web priorities, and a 90-day plan. Prism is a deeper internal governance audit platform still in development. Responsibilities, policies, controls, evidence, internal audits, and certification handoff belong to scoped ISO 42001 advisory engagements.

Implementation Advisory

What is ISO/IEC 42001?

ISO/IEC 42001 is the first international standard for AI management systems, published in December 2023 by ISO and IEC. It specifies the requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organization. The standard covers governance, risk management, AI impact assessments, data governance, and lifecycle controls. It is rapidly becoming the global baseline for demonstrating responsible AI practices, similar to how ISO 27001 became standard for information security.

How do you prepare for an ISO/IEC 42001 audit?

Preparing for an ISO/IEC 42001 audit starts with a gap analysis between your current practices and the standard’s requirements and reference controls. Next comes designing the governance documentation: AI policy, risk management framework, roles and decision rights, AI system impact assessments, and lifecycle controls. The system then has to operate long enough to produce verifiable evidence, followed by an internal audit and readiness review before the external certification audit. An organization already mature on ISO 9001 or ISO 27001 usually moves faster. Nord Paradigm prepares the organization; an independent accredited body performs the certification.

Is ISO 42001 mandatory in Canada?

No. ISO/IEC 42001 is voluntary in Canada. However, it is becoming a de facto requirement in EU procurement and a pragmatic baseline in the absence of federal Canadian AI legislation, since AIDA died on the order paper. Canadian organizations selling to or partnering with European entities, or operating under Quebec’s Loi 25 and Ontario’s AI hiring disclosure rules, increasingly find ISO 42001 referenced in due diligence questionnaires.

How long does ISO 42001 implementation take?

End-to-end ISO 42001 implementation typically runs 6 to 12 months for mid-sized Canadian organizations, depending on existing governance maturity and the complexity of the AI systems in scope. A standalone gap analysis can be completed in 2 to 4 weeks. Full readiness for an external certification audit usually takes 3 to 6 months once gap remediation begins. Organizations with mature ISO 9001 or ISO 27001 systems move faster.

What is the difference between ISO 42001 implementation and certification?

Implementation means building the AI management system: writing policies, designing controls, running risk assessments, training staff, and operating the system long enough to generate evidence. Certification is the formal attestation by an accredited external auditor that the system meets ISO/IEC 42001 requirements. An implementation advisor like Nord Paradigm prepares the organization. An accredited certification body conducts the certification audit and issues the certificate.

Can Nord Paradigm certify our organization against ISO 42001?

No. Certification bodies must be accredited by a national authority, in Canada the Standards Council of Canada, and are kept structurally independent from implementation advisors to avoid conflicts of interest. Nord Paradigm prepares organizations for the external audit. Accredited certification bodies in Canada include MHM, DEKRA Canada, and CSA Group. Nord Paradigm coordinates the handoff to the chosen certification body.

What does Nord Paradigm’s ISO 42001 implementation engagement cover?

A full ISO 42001 implementation engagement runs in five phases: gap analysis against ISO 42001 clauses and Annex B controls; policy and governance design covering AI policy, risk framework, roles, decision rights, and escalation paths; control implementation operationalizing risk management, AI impact assessments, data governance, and lifecycle controls; an internal audit and readiness review based on AF9000+ audit methodology; and certification handoff with documentation support for the external audit. Each phase is independently scopable.

How much does ISO 42001 implementation cost?

ISO 42001 implementation costs vary with organization size, the number of AI systems in scope, existing governance maturity, and the level of advisory involvement. Gap analyses are typically scoped as fixed-fee engagements. Full implementations are usually hybrid engagements combining advisory retainer and project-based work. Nord Paradigm provides scoped proposals after an initial discovery conversation rather than publishing per-day rates.

Why is AF9000+ audit experience relevant to ISO 42001?

AF9000+ is the Royal Canadian Air Force’s quality management standard for aviation maintenance organizations, derived from ISO 9001 with additional aeronautical safety requirements. The underlying audit discipline transfers cleanly to AI management systems. Both demand documented processes, traceable decisions, risk-based thinking, and continuous improvement. ISO/IEC 42001 sits in the same management-system family as ISO 9001, so a senior AF9000+ auditor reading ISO 42001 sees familiar architecture and applies the same evidence standards.

How Engagements Are Scoped

What does AI governance consulting cover at Nord Paradigm?

AI governance consulting at Nord Paradigm covers policy development, risk assessment methodology, accountability structures, AI impact assessments, lifecycle controls, and alignment with Loi 25, ISO/IEC 42001, the EU AI Act, and Canadian privacy law. Engagements typically include gap analysis against an applicable standard, design of governance documentation, implementation support, and an internal pre-certification audit. The end goal is an AI management system the organization can maintain on its own.

What is “selective advisory work” at Nord Paradigm?

Selective advisory refers to custom consulting engagements that fall outside the productized service ladder, typically discussed after a Breach or Breach Pro analysis. These engagements address specific governance challenges that don’t fit a standard ISO 42001 readiness path: AI policy reviews, vendor due diligence support, board-level governance briefings, incident response planning, or ad-hoc decision support during an AI deployment. Nord Paradigm takes on selective advisory engagements where the fit is clear and the scope is well defined.

What size organizations does Nord Paradigm work with?

Nord Paradigm focuses on small and mid-sized Canadian organizations, particularly Quebec SMBs, professional service firms, and regional businesses adopting AI tools faster than their governance can support. Engagements range from a fixed-fee gap analysis for a 25-person firm up to multi-phase ISO 42001 readiness programs for organizations with hundreds of staff. The firm does not chase enterprise procurement cycles where Big Four economics dominate.

What makes the Nord Paradigm methodology different?

The methodology is rooted in AF9000+ aeronautical audit discipline. In military aviation, audit findings are evidence-based, traceable, and tied to corrective actions with clear ownership. That same structure applied to AI management systems produces governance documentation that survives external scrutiny, whether from a certification body, a privacy regulator, or an EU procurement officer. The result is governance that holds up under audit, not governance theater.

Education and Capability Building

Does Nord Paradigm offer AI governance workshops?

Yes. Nord Paradigm runs interactive workshops and training sessions for leadership teams and practitioners covering responsible AI adoption, governance fundamentals, risk literacy, Loi 25 compliance for AI systems, ISO/IEC 42001 awareness, and strategic planning for AI integration. Workshops range from a single half-day executive briefing to multi-session programs aligned to a specific governance initiative.

Who should attend Nord Paradigm workshops?

Workshops are designed for two audiences. Leadership-track sessions target executives, board members, and senior managers who need to understand AI governance enough to make decisions and oversee implementation. Practitioner-track sessions target the people doing the work: privacy officers, IT leaders, compliance staff, HR leaders deploying AI in hiring, and operations leaders deploying AI in service delivery. Custom mixed-audience formats are available.

Are workshops available in French?

Yes. Workshops can be delivered in French or English, including custom curricula. For Quebec organizations operating under Loi 25, the default is professional Quebec French with regulatory terminology and case examples relevant to their context.

Can Nord Paradigm build a custom training curriculum for our team?

Yes. Custom curricula are available for organizations that want training built around their specific tools, sector, and risk profile. A custom engagement typically begins with a short scoping conversation to identify the audience, the AI systems in use, the regulatory exposure, and the desired learning outcomes. Nord Paradigm then designs the curriculum, delivers the sessions live or remotely, and provides reference materials the organization can reuse internally.

What topics do Nord Paradigm workshops cover?

Workshop topics include AI governance fundamentals, ISO/IEC 42001 awareness and management system design, Loi 25 obligations for AI systems, AI risk literacy for non-technical leaders, responsible AI adoption frameworks, AI impact assessment methodology, vendor and tool evaluation, and strategic AI planning. Custom workshops can also address sector-specific concerns: AI in healthcare, AI in financial services, AI in HR and hiring, or AI in public sector procurement.

The Regulatory Landscape

What is Loi 25 and how does it affect AI in Quebec?

Loi 25, formally An Act to modernize legislative provisions as regards the protection of personal information, is Quebec’s privacy law. It applies to any business handling personal information of Quebec residents and includes specific obligations relevant to AI: transparency about automated decision-making, the right to human review of algorithmic decisions, and privacy impact assessments for new technologies. AI systems that touch personal data of Quebec residents must comply, regardless of where the business is headquartered.

What are a Quebec SMB’s obligations under Loi 25?

Loi 25 applies to any business that handles the personal information of Quebec residents, including SMBs. The main obligations include: appointing a person responsible for the protection of personal information; obtaining clear consent and limiting collection to what is necessary; informing individuals of the purpose of collection and keeping that information current; reporting confidentiality incidents that present a risk of serious harm; governing the disclosure of information to vendors, including outside Quebec; and conducting a privacy impact assessment for sensitive technology projects. For AI systems, Loi 25 adds transparency about automated decisions and the right to human review. An SMB tends to reduce its risk by first mapping where personal information lives and how AI uses it.

Is AIDA still happening in Canada?

No. The Artificial Intelligence and Data Act (AIDA), the federal AI bill bundled into Bill C-27, died on the order paper when Parliament was prorogued. There is currently no replacement federal AI bill on the horizon. Canadian AI regulation is therefore fragmented across provincial laws like Loi 25, Ontario’s AI hiring disclosure rules, federal privacy law (PIPEDA), and the extraterritorial reach of the EU AI Act. ISO 42001 increasingly serves as the pragmatic anchor.

Does the EU AI Act apply to Canadian companies?

Yes, in many cases. The EU AI Act has extraterritorial reach. It applies to any organization placing AI systems on the EU market, providing AI services used in the EU, or whose AI system outputs are used in the EU. Canadian companies selling to European customers, supplying European partners, or processing data on EU residents may fall within scope. ISO 42001 conformance is increasingly cited in EU procurement due diligence as evidence of responsible AI management.

What is Bill C-27?

Bill C-27 was the federal Digital Charter Implementation Act, which bundled three pieces of legislation: the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). The bill died on the order paper. Its components, including AIDA, are not currently law and have no scheduled return. Canadian organizations should plan against existing provincial law and international standards rather than waiting for federal action.

What Canadian AI regulations should my business prepare for now?

Canadian businesses should prepare for Loi 25 if they handle personal information of Quebec residents, Ontario’s Working for Workers Four Act provisions on AI in hiring if they recruit in Ontario, federal PIPEDA for personal information generally, and the EU AI Act if they have any European exposure. ISO/IEC 42001 provides a structured framework that covers the underlying obligations across all of these regimes and serves as a defensible baseline if and when federal AI legislation returns.

Search, Answers, and AI Assistants

What is AI visibility?

AI visibility is how your business appears when someone asks tools like ChatGPT, Perplexity, Gemini, Copilot, or Google AI questions about your category, service, or local market. It is not just whether your website ranks on Google. It is whether AI assistants can understand what you do, trust the available information, and include you when answering buyer questions.

Is this just SEO with a new name?

Partly, but not completely. Good SEO still matters: crawlable pages, clear service descriptions, reviews, local profiles, useful content, accurate business information, and technical health. AI visibility adds a different layer: testing how assistants answer buyer-style prompts, which competitors are selected, what sources are used, and what gaps weaken trust.

How do you measure something that changes?

AI answers vary by prompt wording, tool, location, personalization, source availability, and time. That is why Breach Pro uses controlled prompt sets and dated observations to create a documented baseline. The output is visibility evidence and directionally useful measurement, not an absolute ranking.

How can I make my business more visible to AI assistants?

Start with fundamentals: crawlable pages, clear service and location pages, accurate business profiles, consistent contact details, strong reviews, credible third-party profiles, proof assets, case studies, and content that answers real customer questions. AI assistants need extractable trust signals, not tricks.

Do we need an llms.txt file or special AI markup?

Not as a magic fix. Google says special AI files or markup are not required to appear in its generative AI search features. Structured data can still help as part of normal SEO, but the priority is clear pages, accurate business data, consistent profiles, useful proof, and customer-focused content.

Should we publish lots of AI-written content to get cited?

No. More generic AI content can make a site less useful and less credible. Better content usually means specific, current, experience-based pages that answer real buyer questions with examples, proof, and clear service information.

Does this apply to Quebec and French-language businesses?

Yes. Free Breach can review the English and French public signals a bilingual market depends on. Breach Pro adds documented English and French buyer prompts, local phrasing, service-area language, and observations of how assistants describe the business in both languages.

Working Together

How much does an AI roadmap cost (and what makes the price vary)?

Nord Paradigm does not publish a fixed price for an AI roadmap, because the cost depends on the real scope of the engagement. The main factors that make the price vary are: the number of AI systems and use cases to examine; the governance maturity already in place; the number of websites, brands, or languages to cover for AI visibility; the depth of competitive analysis requested; the level of implementation support afterward; and the applicable regulatory obligations, such as Loi 25 or a European procurement requirement. A scoped gap analysis is generally offered as a fixed fee, while a full roadmap combines a fixed fee with support. Pricing is shared after a short discovery conversation, once the scope is clear.

How does Nord Paradigm price its work?

Nord Paradigm’s service ladder starts with the free Breach diagnostic. The BREACH Pro founding-beta audit is a $499 CAD beta price, with a $999 CAD regular launch price. AI Implementation is $999 CAD per month, designed as a 90-day program with a first-month exit for the first five companies, and is limited to five active clients. Governance, ISO 42001 support, workshops, and other custom advisory work are scoped per engagement.

What is included in the AI Implementation Partnership?

The AI Implementation Partnership includes two 60-minute working sessions each month and unlimited messaging support for quick questions and progress updates, with a response within 12 business hours. It costs $999 CAD per month, is designed as a 90-day program with a first-month exit for the first five companies, and is limited to five active clients. Messaging does not include IT administration or open-ended troubleshooting. See the full offer.

How do I get started with Nord Paradigm?

The lowest-friction starting point is running the free Breach AI disruption report at breach.nordparadigm.com, which takes under two minutes and produces a personalized PDF. Organizations that want a deeper conversation can book a free 20-minute discovery call.

What is the typical engagement timeline?

A free Breach report runs in under two minutes. Breach Pro is delivered within three business days and includes a 45-minute screen-share debrief. The AI Implementation Partnership is designed as a 90-day program and includes two 60-minute working sessions per month plus unlimited messaging support, with replies within 12 business hours. A scoped ISO 42001 or Loi 25 gap analysis typically takes 2 to 4 weeks; full ISO 42001 readiness commonly runs 3 to 6 months, and end-to-end implementation including external certification handoff can run 6 to 12 months.

How quickly does Nord Paradigm respond to inquiries?

Nord Paradigm typically responds within 24 to 48 hours on business days. Urgent matters should be flagged in the message subject. The firm operates on Eastern Time from Chicoutimi, Quebec, and is reachable in both English and French.

Still have questions?

Start with a free Breach AI diagnostic in under two minutes, or book a free 20-minute discovery call.

Run your free Breach Book a 20-minute discovery call