Canada - Automated Decision-Making Directive
Directive on Automated Decision-Making (Treasury Board of Canada Secretariat)
Canada
RAI-CA-NA-ADTBCXX-2019The Treasury Board of Canada Secretariat’s Directive on Automated Decision-Making (launched 4 March 2019, in force 1 April 2019) requires federal departments to assess, mitigate and publish the impacts of automated decision systems (ADS) used in administrative decision-making. It mandates completion of an Algorithmic Impact Assessment (AIA), scaled mitigation measures by impact level (I–IV), peer review, monitoring, human oversight and provision of recourse.
Summary
The Directive on Automated Decision-Making (the "Directive"), issued by the Treasury Board of Canada Secretariat (TBS) and launched publicly on 4 March 2019, sets mandatory policy requirements for federal departments that develop, procure or deploy automated decision systems (ADS) which make or assist administrative decisions affecting rights, interests or privileges of clients (including members of the public, businesses and federal employees). The Directive establishes a risk- and impact-based framework: departments must complete the Treasury Board’s Algorithmic Impact Assessment (AIA) tool to determine an ADS’s impact level (Level I — little impact to Level IV — very high impact). Based on the resulting impact level, the Directive prescribes progressively stronger mitigation measures including additional testing, peer review, transparency, monitoring, data governance, bias and fairness assessment, documentation, privacy and legal review, human oversight and recourse.
The Directive covers a broad range of automated systems (from deterministic rules-based systems to sophisticated machine learning) when they replace or augment human judgment in administrative decision-making. It applies to systems developed or procured after 1 April 2020 (with earlier publish/transition rules introduced through subsequent amendments), while research and purely experimental systems are generally out of scope. Departments must publish completed AIAs on the Open Government Portal in an accessible format and, for higher-impact systems, publish peer review findings or summaries prior to production. The Directive emphasizes accountability (senior official responsibility and Chief Information Officer oversight), ongoing testing and monitoring of outcomes, documentation and records retention, and consultative steps with legal services and privacy officers.
Although a policy instrument (not primary statute), the Directive has enforcement effect within the federal administration through internal compliance mechanisms and oversight by TBS (Office of the Chief Information Officer). It has been amended and reviewed since 2019 (significant amendments effective 25 April 2023 and further updates reflected in TBS guidance as recently as June 2025) to strengthen transparency, senior-level accountability, testing and monitoring. The Directive is complemented by guidance documents, a public AIA tool, peer review guidance and a scope guide, and intersects with statutory privacy and access-to-information obligations. Departments that fail to meet Directive requirements face administrative escalations, remediation requirements, procurement restrictions and reputational risk; criminal penalties are not imposed by the Directive itself. The Directive positions Canada’s federal public service to manage the risks of automated decision-making while promoting responsible AI aligned with administrative law principles of transparency, legality and procedural fairness.
Full article
Read full text ↗Overview
The Treasury Board of Canada Secretariat (TBS) Directive on Automated Decision-Making (launched 4 March 2019 and put into force 1 April 2019) establishes mandatory requirements for federal departments that use automated decision systems (ADS) to make or assist administrative decisions. It sets a proportional, impact-based approach organized around the Algorithmic Impact Assessment (AIA) that determines four impact levels (Level I to Level IV) and maps those to mitigation steps. The Directive’s objective is to ensure transparency, fairness, accountability and quality of government automated decisions while preserving citizen rights and public trust. For the primary policy text and official publication see the Government of Canada publications entry and the TBS policy page: Directive on automated decision-making (Publications GC) and the TBS portal for responsible use of AI: Responsible use of AI (Canada.ca).
Definitions
The Directive defines key terms used across the instrument. "Automated decision system (ADS)" refers to any system (including AI and machine learning, rule-based systems, or other technologies) used to make, assist, or inform an administrative decision. "Administrative decision" means decisions that affect the rights, interests or privileges of clients. "Impact level" is the result of the AIA, expressed as Level I (little/no impact) to Level IV (very high impact). "Full automation" occurs when the system makes the final decision; "partial automation" applies when the system contributes to or augments human judgment. The Directive distinguishes production systems from research/experimental systems (the latter are generally out of scope).
Governance and Institutional Framework
The Directive is owned by the Treasury Board of Canada Secretariat and operationalized by the Office of the Chief Information Officer (OCIO) within TBS. Departmental governance must assign senior accountability: deputy-head-level awareness, an Assistant Deputy Minister or equivalent sponsor, and designated project leads responsible for completing the AIA, implementing mitigations, and publishing results. The OCIO provides the AIA tool, guidance and oversight. Departments must consult their legal services and privacy officers early in the project lifecycle. See TBS guidance for roles and responsibilities: Algorithmic Impact Assessment (AIA) tool page and peer review guidance: Guide to Peer Review.
Key Focus Areas
The Directive concentrates on a set of interrelated obligations: (1) Risk assessment and impact scoring through the AIA, (2) Proportionate mitigation mapping (Appendix C) tied to impact level, including testing, bias and fairness evaluation, and peer review, (3) Transparency obligations — publishing the AIA and peer review results (or summary) before launch for systems at impact Level II and above, (4) Human oversight — ensuring appropriate human roles and ability to override or review automated outputs, (5) Data governance and privacy — conducting privacy impact assessments and ensuring secure handling of training and operational data, (6) Monitoring and measurement — post-deployment monitoring of accuracy, fairness and adverse outcomes, (7) Documentation, reproducibility and recordkeeping to support audits and accountability, and (8) Remediation and recourse — providing appeal or challenge mechanisms for affected individuals. The Directive also requires departmental legal and privacy consultations during concept and design stages to ensure compatibility with statutory obligations and administrative law principles.
Implementation Framework
Implementation is operationalized through the AIA which is mandatory and publicly available; it contains risk and mitigation questions that produce an impact-level score. For each impact level, the Directive prescribes baseline and additional measures (peer review, increased testing, monitoring frequency, human-in-the-loop rules). Departments must publish the final AIA on the Open Government Portal in accessible formats and in both official languages. The 2023 amendments tightened timing and publication requirements: AIAs should be published prior to launch, peer review findings (full or summary) should be published pre-production for higher impact systems, and internal compliance timelines were introduced to allow transition for existing systems. The OCIO offers departmental support and maintains the AIA tool. For scope and applicability guidance see TBS’s scope guide: Guide on the Scope of the Directive.
Monitoring and Evaluation
Monitoring requirements include routine operational performance checks, bias and fairness testing, outcome monitoring for adverse events, and scheduled AIA reviews (frequency determined by impact level and system change). Departments must validate mitigation effectiveness and update the AIA following changes to system functionality or scope. Reporting obligations to TBS and public reporting via the Open Government Portal enable centralized monitoring of uptake and outcomes across government. The OCIO may request information and conduct compliance assessments; departments should align monitoring schedules with reporting and review cycles identified in the Directive.
Penalties, Liability, and Appeals
As a Treasury Board policy instrument, the Directive does not create criminal penalties; enforcement is administrative and internal. Non-compliance can trigger escalation to deputy heads, mandated remediation plans, suspension or blocking of procurement or deployment, and reputational and political consequences. Departments remain subject to statutory obligations (Privacy Act, Access to Information Act) and potential review by the Office of the Privacy Commissioner. The Directive requires departments to provide procedural recourse or appeals mechanisms for affected individuals when automated decisions materially affect rights or interests.
Relationship to Other Instruments
The Directive complements existing federal instruments including the Policy on Service and Digital, Directive on Service and Digital, Privacy Act and related privacy and information management policies, and the government’s digital standards. It aligns departmental technology procurement processes with modernized procurement practices and qualified supplier lists. Guidance materials (AIA tool, peer review guidance, scope guide) and publications by TBS provide interpretive support. See the policy collection and associated documents on the Government of Canada AI pages: Responsible use of AI collection.
International Alignment
The Directive reflects international trends toward impact-based regulation of AI in the public sector and aligns with principles from OECD and other jurisdictions’ public-sector AI guidance (transparency, fairness, accountability). Canada’s approach emphasizes administrative law compatibility and public accountability and has informed, and been informed by, peer governments and international standards bodies. The Directive’s impact-tier model and the mandatory public risk assessment align with global best practices for public-sector AI governance and facilitate international interoperability on responsible AI approaches.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| Public launch of Directive | 2019-03-04 | Announcement by TBS (news release). |
| Directive in force | 2019-04-01 | Initial implementation and departmental adoption begins. |
| AIA tool launch | 2019-05-01 | Online AIA made available to departments (tool maintained by OCIO). |
| Applicability threshold (systems developed/procured after) | 2020-04-01 | Directive applies to systems developed or procured after this date. |
| Amendments (major) | 2023-04-25 | Amendments effective; transition timelines provided for new and existing systems. |
| Fourth review / updates | 2025-06-24 | Further updates to increase transparency, accountability, and monitoring. |
Sources and References
| Source | Type |
|---|---|
| Directive on automated decision-making (Publications.gc.ca BT48-31/2021E-PDF) | Primary Source |
| Algorithmic Impact Assessment tool (Canada.ca) | Primary Source |
| Guide on the Scope of the Directive (Canada.ca) | Primary Source |
| Guide to Peer Review of Automated Decision Systems (Canada.ca) | Primary Source |
Requirements for a company
What an organisation has to do under Canada - Automated Decision-Making Directive, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
12- Assign senior accountability for automated decision system projects.Federal departments using automated decision systems.
- Consult legal services and privacy officers early in the project lifecycle.Federal departments using automated decision systems.
- Complete an Algorithmic Impact Assessment (AIA) at the concept stage.Federal departments using automated decision systems.
- Implement proportionate mitigation measures based on the AIA impact level.Federal departments using automated decision systems.
- Conduct peer review for systems at impact Level II and above.Federal departments using automated decision systems with Level II+ impact.
- Publish the final AIA and peer review results on the Open Government Portal.Federal departments using automated decision systems at impact Level II and above.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Canada - Automated Decision-Making Directive, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Federal departments using automated decision systems. | Assign senior accountability for automated decision system projects. “Departmental governance must assign senior accountability: deputy-head-level awareness, an Assistant Deputy Minister or equivalent sponsor, and designated project leads.” | Before project initiation | — | Critical |
| 2 | Federal departments using automated decision systems. | Consult legal services and privacy officers early in the project lifecycle. “Departments must consult their legal services and privacy officers early in the project lifecycle.” | At concept and design stages | — | Critical |
| 3 | Federal departments using automated decision systems. | Complete an Algorithmic Impact Assessment (AIA) at the concept stage. “Complete AIA at concept stage” | At concept stage | — | Critical |
| 4 | Federal departments using automated decision systems. | Implement proportionate mitigation measures based on the AIA impact level. “Proportionate mitigation mapping (Appendix C) tied to impact level, including testing, bias and fairness evaluation, and peer review.” | Before system deployment | — | Critical |
| 5 | Federal departments using automated decision systems with Level II+ impact. | Conduct peer review for systems at impact Level II and above. “peer review findings (full or summary) should be published pre-production for higher impact systems” | Before system launch/production | — | Critical |
| 6 | Federal departments using automated decision systems at impact Level II and above. | Publish the final AIA and peer review results on the Open Government Portal. “Departments must publish the final AIA on the Open Government Portal in accessible formats and in both official languages.” | Before system launch | — | Critical |
| 7 | Federal departments using automated decision systems. | Ensure appropriate human oversight, including the ability to override or review automated outputs. “Human oversight — ensuring appropriate human roles and ability to override or review automated outputs.” | Before system deployment | — | Critical |
| 8 | Federal departments using automated decision systems. | Conduct Privacy Impact Assessments and ensure secure handling of training and operational data. “Data governance and privacy — conducting privacy impact assessments and ensuring secure handling of training and operational data.” | Before system deployment | — | Critical |
| 9 | Federal departments using automated decision systems. | Establish a post-deployment monitoring plan for accuracy, fairness, and adverse outcomes. “Monitoring and measurement — post-deployment monitoring of accuracy, fairness and adverse outcomes.” | Post-deployment, ongoing | — | Critical |
| 10 | Federal departments using automated decision systems. | Provide appeal or challenge mechanisms for individuals affected by automated decisions. “Remediation and recourse — providing appeal or challenge mechanisms for affected individuals.” | Before system deployment | — | Critical |
| 11 | Federal departments using automated decision systems. | Document system functionality, reproducibility, and recordkeeping to support audits. “Documentation, reproducibility and recordkeeping to support audits and accountability.” | Ongoing, throughout system lifecycle | — | Important |
| 12 | Federal departments using automated decision systems. | Validate mitigation effectiveness and update the AIA following system changes. “Departments must validate mitigation effectiveness and update the AIA following changes to system functionality or scope.” | Following system changes or scheduled reviews | — | Important |
Related Regulations
Canada - Algorithmic Impact Assessment (2019)
Canada97% similar
Canada - Generative AI Guidance
Canada92% similar
Canada - AI Systems Management Guide
Canada92% similar
Canada - British Columbia - AI Responsible Use Principles
Canada91% similar
Canada - Quebec - Responsible AI Use Guidelines
Canada91% similar
© Regulations.AI · updated on 13-Jun-2026