LLM integration into existing business software means connecting a large language model to the CRM or ERP you already run through three patterns: retrieval (the model reads records and documents to answer), tool calls (the model calls your system's API to look things up or draft changes) and agents (the model chains several steps, and a person approves anything written back). In Canada in fall 2026, three decisions shape the project: where prompts are processed, which model fits the data, and what the first workflow costs to build and run.
This guide covers systems such as Salesforce, HubSpot, Dynamics 365, NetSuite or SAP with a Canadian privacy lens. For the full catalogue of enterprise patterns, read our LLM integration patterns for enterprise architecture.
Get the integration scoped before anyone writes code: the two-week AI Opportunity Audit ($2,900 CAD + HST) maps your workflows and systems and ends with a 12-month roadmap and a recommended first pilot.
What are the three ways to integrate an LLM into a CRM or ERP?
The three patterns are retrieval, tool calls and agents. Most first projects combine retrieval with read-only tool calls and add write access later, behind human approval.
| Pattern | How it works | CRM or ERP example | Access it needs | Main risk |
|---|---|---|---|---|
| Retrieval (RAG) | A search index over records, notes and documents feeds the model, which answers with citations | Account summary before a renewal call; answers from contract terms | Read only, filtered by the user's permissions | Stale or over-shared records |
| Tool calls | The model calls API functions you define, such as "get order status" or "create draft task" | Order status from the ERP inside a sales chat; draft follow-up task | A short list of functions, read first | Wrong parameters or wrong record |
| Agents | The model plans several steps across tools | Triage an inbound email, match it to an account, draft the reply and the CRM update | Several functions, including write | Chained errors; needs an approval gate and logs |
The integration layer is the part that stays with you when models change. It calls the system API with the user's permissions, masks personal information the task does not need, logs every call and caps spend. For older on-premise systems without a usable API, the same layer can sit on a database view or file export; see legacy system integration.
Where does the data live? Residency, PIPEDA and Law 25
PIPEDA allows personal information to be processed outside Canada, provided the organization stays accountable, protects it by contract and is open about it. Quebec's Law 25 adds privacy impact assessments, including one before personal information leaves Québec.
What the rules say, from primary sources:
- PIPEDA. The Office of the Privacy Commissioner (OPC) states that PIPEDA "does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing". The organization must use "contractual or other means to provide a comparable level of protection" and tell customers their information may be processed in another jurisdiction.
- Law 25, section 3.3. A privacy impact assessment is required for any project to acquire, develop or overhaul an information system that handles personal information. An LLM added to a CRM that holds personal information is likely to fall under it.
- Law 25, section 17. Another assessment and a written agreement are required before personal information is communicated outside Québec, including when a vendor outside Québec processes it on your behalf.
- Law 25, section 12.1. A decision based exclusively on automated processing must be disclosed to the person, who can ask for the main factors and submit observations to a staff member. Administrative penalties reach $10 million or 2% of worldwide turnover, whichever is greater.
- Bill C-36. The federal bill tabled on June 15, 2026 would require organizations to publish a general account of any automated decision system used for predictions, recommendations or decisions with a legal or similarly significant effect on individuals, and to explain such a decision on request. LEGISinfo lists it at second reading.
Where the main vendors process prompts, as documented in September 2026:
| Option | Data at rest in Canada | Inference in Canada |
|---|---|---|
| Azure OpenAI, Standard or Regional Provisioned deployment in Canada East | Yes | Yes, for gpt-4o, gpt-4.1-mini and text-embedding models |
| Azure OpenAI, Global deployment in a Canadian region | Yes | May run in any Azure region |
| OpenAI API with Canada data residency (eligible customers approved for abuse-monitoring controls, via sales) | Yes | No |
| Anthropic API, first party | No, workspace geo is US | No, "global" or "us" only |
| Claude on Amazon Bedrock, Canada (Central) | Yes, including logs and knowledge bases | No in-Region option; the US geo profile routes to Canada (Central) or US regions, the Global profile to any region |
| Open-weight model hosted in a Canadian data centre | Yes | Yes |
For many CRM use cases, a closed API with contract terms and a privacy impact assessment is often enough. When a contract or internal policy requires in-Canada inference, the options in this table narrow to Azure Canada East deployments or a self-hosted open model. Our AI compliance service and the guide to AI privacy compliance in Canada go further.
Closed API or open model: which should a Canadian company choose?
Start with a closed API when the data allows it and speed matters. Plan for an open-weight model when residency or cost at high volume decides. Either way, keep the integration layer model-agnostic so the model can be swapped.
| Criterion | Closed API | Open-weight model hosted in Canada |
|---|---|---|
| Time to first result | Usually days | Usually weeks: hosting, security, monitoring |
| Where inference runs | Vendor's regions (see table above) | Your chosen Canadian data centre |
| Cost profile | Per token, scales with use | Per server hour, whether used or idle |
| Model updates | Vendor ships new versions | You choose and upgrade versions |
| Who operates it | Vendor | Your team or a provider |
An open-source option aimed at SMEs was announced this month. ISED's September 17, 2026 release on the ALL IN conference in Montréal reports that Mila, Mozilla and Hypertec announced plans for a Canadian-led open-source AI consortium to make advanced AI tools easier and more affordable for small and medium-sized businesses to adopt, with more choice and control over their technology and data. The release gives no timeline, model or hosting details, so design today's integration so it can switch models later. Our AI vendor selection work compares the options against your data, and the OpenAI vs Anthropic vs Google comparison covers the closed APIs.
What does LLM integration cost?
For a single workflow, model usage is often the smallest line; integration work and testing on real records cost more. Four drivers set the budget:
- Tokens. Volume × context length. Retrieval context usually dominates input tokens.
- Hosting. Search index, logs and the integration layer; GPU servers if you self-host a model.
- Integration work. API connectors, permission mapping, testing on real records, the approval screen.
- Staff time. Review of drafts during the pilot, then spot checks.
List prices in USD per million tokens, from the vendors' pricing pages in September 2026:
| Model | Input | Output |
|---|---|---|
| Gemini 3.5 Flash-Lite | $0.30 | $2.50 |
| Claude Haiku 4.5 | $1 | $5 |
| Claude Sonnet 5.5 | $2 | $10 |
Worked example. 3,000 inbound emails a month, each about 1,500 input tokens (email plus account context) and 300 output tokens, comes to 4.5 million input and 0.9 million output tokens. That is about $9 a month on Claude Haiku 4.5, $18 on Claude Sonnet 5.5 and $3.60 on Gemini 3.5 Flash-Lite. Regional processing adds to that: Anthropic charges 1.1× for US-only inference on Claude 4.6 and later models, and Anthropic's Batch API halves the price where a delay is acceptable. Prices change often; recheck them before a budget request.
On our side, prices are fixed and published: the AI Opportunity Audit is $2,900 CAD + HST for two weeks, and the six-week AI Pilot Sprint is $9,800 CAD + HST for one production AI workflow integrated with your systems. Details are on the pricing page.
How do you pilot an LLM integration in six weeks?
Pick one workflow in one system, start read-only, put a person in front of every write-back, and measure against a baseline taken before week one.
- Week 1, baseline and access. Record volumes, cycle times and staff hours. Create a service account with the narrowest API scopes. Start the privacy impact assessment if Quebec data is involved.
- Week 2, retrieval and read-only tools. Index the records the task needs and test on a set of real past cases.
- Weeks 3–4, drafts with approval. The model proposes replies or field updates; a person approves them in the screen they already use. Every approval is logged.
- Week 5, measurement. Draft acceptance rate, time per item, error types and cost per item against the baseline.
- Week 6, decision. Go, adjust or stop, with the numbers in front of the owner.
The AI Pilot Sprint follows this structure and adds team training and a written runbook. To check whether your data and processes are ready first, take the AI readiness quiz or the one-week AI readiness assessment.
What are the main risks, and how do you govern them?
Four risks cause most trouble: over-broad access, instructions hidden in customer content, confident wrong answers and undisclosed automated decisions. Each has a concrete control.
- Over-broad access. Give the integration a service account with the fewest scopes, and filter retrieval by the requesting user's permissions.
- Instructions hidden in emails or tickets. Treat every customer text as data, allow only listed tools, and require approval before any write.
- Wrong fields or answers. Show the cited source records next to each draft and validate outputs against the system's field rules.
- Automated decisions about people. Keep a person deciding credit, hiring, pricing or eligibility, and prepare the Law 25 section 12.1 notice where a decision could be fully automated.
- Training on your data. OpenAI states it does not use API or business data for training by default, and Anthropic states the same for its commercial products. Confirm it in the signed agreement.
The Canadian Centre for Cyber Security's generative AI guidance (ITSAP.00.041) adds the basics: a plan with policies on how AI may be used, multi-factor authentication and timely security patches.
Why teams work with Remolda
- Fixed, published prices from $490 CAD + HST.
- What you paid is credited toward a larger engagement.
- Work in English or French.
- Every Readiness Review notes where PIPEDA, Quebec Law 25 or sector rules shape your first use case.
- A consultant confirms scope and a start date within one business day of your request; the invoice follows that confirmation.
Get one LLM workflow live in six weeks, with human approval and measured results: book a 30-minute call or request the AI Pilot Sprint.
Sources
- OPC: Guidelines for processing personal data across borders
- LégisQuébec: Act respecting the protection of personal information in the private sector (CQLR c. P-39.1)
- Commission d'accès à l'information: Principaux changements de la Loi 25
- LEGISinfo: Bill C-36 (45th Parliament, 1st session)
- ISED: AI leadership takes centre stage at ALL IN 2026 (September 17, 2026)
- Microsoft Learn: Azure deployment types and data residency
- Microsoft Learn: model availability by Azure region
- OpenAI: Your data (API data residency)
- OpenAI: Business data privacy
- Anthropic: Data residency
- Anthropic: Is my data used for model training?
- AWS: Claude Haiku 4.5 on Amazon Bedrock, Regional availability
- AWS: Amazon Bedrock cross-Region inference in Canada
- Anthropic: Claude API pricing
- Google: Gemini API pricing
- Canadian Centre for Cyber Security: Generative artificial intelligence (ITSAP.00.041)