Canada - Algorithmic Impact Assessment (2019)
Algorithmic Impact Assessment (AIA) tool (Treasury Board of Canada Secretariat)
Canada
RAI-CA-NA-AIAATXX-2019The Algorithmic Impact Assessment (AIA) tool requires Canadian federal departments to evaluate automated decision system risks, issued by the Treasury Board of Canada Secretariat in 2019. Currently In Force (Amended) effective 2019-05-01, it determines procedural duties and is monitored by the TBS Office of the Chief Information Officer.
Summary
The Algorithmic Impact Assessment (AIA) tool is an open, government-provided risk assessment questionnaire maintained by the Treasury Board of Canada Secretariat (TBS). First launched in May 2019 to operationalize the Directive on Automated Decision-Making, the AIA helps federal departments and agencies identify, score and manage risks arising from automated decision systems (ADS), including those that rely on artificial intelligence (AI). The AIA asks structured questions across project, system, algorithm, decision, impact and data domains (65 risk questions) and mitigation/consultation domains (41 mitigation questions). Responses produce a quantitative score that maps to one of four impact levels (Level I — little/no impact; Level II — moderate impact; Level III — high impact; Level IV — very high impact). Impact levels determine the scope of mitigation measures and procedural obligations under the Directive, such as peer review, testing, monitoring, human oversight levels, and publication requirements.
The AIA is explicitly tied to the Directive on Automated Decision-Making and is mandatory for federal institutions where an automated decision system makes or supports an administrative decision affecting rights, interests or privileges of clients. The Directive came into force in 2019 and applies to systems developed or procured after April 1, 2020; departments are required to complete and publish the AIA as part of the approval and deployment lifecycle. The AIA was developed through open, multi-stakeholder engagement and is published under an open source licence; its implementation includes a publicly-accessible web questionnaire, downloadable/archivable results (PDF/JSON), and a public repository of published AIAs on the Open Government Portal that provides transparency and examples of government use-cases.
Practically, the AIA is intended to be completed early in a project (design phase) and again prior to production to validate the impact rating. The tool’s scoring differentiates raw impact and mitigation strength; if mitigation scores exceed a threshold the final score is adjusted to reflect effective risk management. The TBS Office of the Chief Information Officer (OCIO) maintains the tool, supports departments on interpretation and publication, and monitors compliance with the Directive. Amendments to the Directive in 2023 clarified scope, added requirements (including extending coverage to automation affecting federal employees) and set transition timelines for compliance with new provisions. Departments that fail to comply may face administrative remediation requirements, mandatory corrective actions, halted deployments and internal accountability measures; the Directive is a mandatory policy instrument for federal institutions but typically relies on internal governance, auditing and Treasury Board oversight rather than criminal sanctions. The AIA and its published assessments interact with other Canadian instruments (Privacy Act, Access to Information Act, Treasury Board policies, and evolving federal AI strategy and legislative proposals), and the AIA’s open design and scoring methodology have been referenced internationally as a model for public-sector AI risk assessment.
Full article
Read full text ↗Overview
The Algorithmic Impact Assessment (AIA) is a standardized, nation-wide tool maintained by the Treasury Board of Canada Secretariat (TBS) to operationalize the Directive on Automated Decision-Making and ensure federal institutions assess, mitigate and publish risks from automated decision systems (ADS). Introduced in 2019 and distributed openly (including via a public GitHub repository), the AIA consists of risk and mitigation questionnaires that yield an impact score and corresponding level (I–IV). The tool is used by departments to guide governance, testing and transparency measures before a system reaches production and to support ongoing monitoring and public disclosure obligations.
Definitions
Key terms used by the AIA include "automated decision system" (any technology used to make or support administrative decisions, including rule-based systems, machine learning, natural language processing and generative AI), "impact level" (a four-tier scale from Level I to Level IV that reflects potential harm to rights, health, economic interest and ecosystems), "raw impact score" and "mitigation score" (numerical outputs from the questionnaire used to determine final impact), and "client" (an individual or entity affected by the decision). The Directive’s and AIA’s scope, guidance and examples of "administrative decision" are set out on the TBS site and supporting guidance documents.
Governance and Institutional Framework
The AIA is embedded in the Government of Canada’s governance architecture for responsible AI. The Treasury Board of Canada Secretariat, through its Office of the Chief Information Officer (OCIO), maintains the tool, issues interpretation guidance and oversees departmental compliance. Departments listed under the Financial Administration Act (Schedules I, I.1 and II) are subject to the Directive; some entities (for example the Canada Revenue Agency) may be subject to separate arrangements. The AIA requires departmental senior officials and designated approval authorities to review, sign-off and publish completed assessments to the Open Government Portal. Departments must also consult legal services, privacy officers (where personal information is used) and other specialists as part of the assessment and mitigation planning.
Key Focus Areas
The AIA questionnaire and supporting guidance concentrate on multiple risk domains: project governance (roles, approval authorities, program objectives), system architecture and security (design, data flows and cybersecurity classification), algorithmic design (model type, explainability and training data provenance), decision context (what decisions are made and to whom they apply), impact analysis (risks to rights, health, dignity, economic interests and intersectional groups), data governance (personal information, retention, provenance and accuracy), consultation (stakeholder and community engagement, including GBA+ analysis), and mitigation measures (human oversight, testing regimes, peer review and monitoring). For high-impact systems (Levels III–IV), the Directive and AIA require additional steps such as external peer review, strengthened human intervention, and more rigorous testing and documentation.
Implementation Framework
Departments are expected to complete an AIA at the start of the design phase and again before production. The online AIA tool runs as a questionnaire (the official web instance and an open-source implementation are available) that produces a results package exportable as JSON or PDF for departmental records and publication. Appendix C of the Directive maps mitigation requirements according to impact level; departments must integrate AIA results into project governance artifacts (project charters, risk registers, procurement materials and security assessments). The AIA scoring logic (raw impact vs mitigation score and the 80% mitigation adjustment rule) drives whether additional controls are required before deployment.
Monitoring and Evaluation
Once deployed, automated decision systems must be monitored in production: the Directive and AIA require regular reviews and re-assessments whenever system functionality or scope changes, and on a scheduled basis aligned with monitoring plans. Departments must track outcomes, fairness and accuracy metrics, complaint and recourse data, and maintain records sufficient to support audits and investigations. The OCIO provides central support and may request updates, while departmental internal audit and TBS oversight processes assess compliance with the directive and AIA publication requirements.
Penalties, Liability, and Appeals
The Directive (and the AIA which operationalizes it) is a mandatory policy instrument for federal institutions; non-compliance can trigger administrative enforcement by TBS including corrective action demands, requirement to halt or remediate deployments, internal accountability measures and escalation to deputy heads or the Treasury Board. The AIA itself does not create criminal penalties; affected individuals retain rights under the Privacy Act, Access to Information Act and other applicable statutes to seek remedies. Departments are also required to provide recourse and review mechanisms for individuals affected by decisions as part of mitigation measures tied to higher impact levels.
Relationship to Other Instruments
The AIA is closely linked to the Directive on Automated Decision-Making and complements other federal instruments including the Privacy Act, Policy on Service and Digital, guidance on generative AI, and the Open Government publication requirements. The AIA’s open-source code is maintained in the TBS GitHub repository, enabling public reuse and international adaptation. Completed AIAs are published on the Open Government Portal alongside departmental transparency materials.
International Alignment
The Canadian AIA has been referenced internationally as a practical public-sector model for algorithmic impact assessment. Its open approach aligns with OECD and international best practice on AI governance and is used as an exemplar by international observatories such as the OECD Observatory of Public Sector Innovation. The AIA’s risk-tiering, open-source implementation and publication requirements facilitate cross-jurisdictional comparisons and inform transnational policy dialogue on responsible public-sector AI.
Implementation Timeline
| Event | Date |
|---|---|
| Directive announced | 2019-03-04 |
| Directive in force | 2019-04-01 |
| AIA tool launched (first public release) | 2019-05-01 |
| Directive amendments published | 2023-04-25 |
| Transition deadlines for new/legacy systems (amendments) | 2023-10-25 and 2024-04-25 |
Sources and References
| Source | Type |
|---|---|
| Algorithmic Impact Assessment tool — Treasury Board of Canada Secretariat | Primary Source |
| Guide on the Scope of the Directive on Automated Decision-Making — Treasury Board of Canada Secretariat | Primary Source |
| GitHub: canada-ca/aia-eia-js (AIA open-source repo) | Primary Source |
| Open Government Portal — Algorithmic Impact Assessment published results | Primary Source |
Requirements for a company
What an organisation has to do under Canada - Algorithmic Impact Assessment (2019), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
7- Complete an Algorithmic Impact Assessment at the design phase and prior to system production deployment.Canadian federal departments deploying automated decision systems
- Obtain formal review and sign-off on completed impact assessments from designated departmental senior officials.Canadian federal departments deploying automated decision systems
- Publish completed Algorithmic Impact Assessment results to the Open Government Portal.Canadian federal departments deploying automated decision systems
- Consult legal services, privacy officers, and domain experts during the assessment and mitigation process.Canadian federal departments deploying automated decision systems
- Subject high-impact automated decision systems to external peer review prior to operational deployment.Federal departments deploying Level III or IV automated decision systems
- Monitor deployed systems and re-assess them whenever functionality or scope changes, following scheduled monitoring plans.Canadian federal departments operating automated decision systems
- +1 more in the table below
Should not do
1- Do not deploy automated decision systems without incorporating AIA mitigation results into project governance artifacts.Canadian federal departments deploying automated decision systems
Who must do what
The obligations under Canada - Algorithmic Impact Assessment (2019), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Canadian federal departments deploying automated decision systems | Complete an Algorithmic Impact Assessment at the design phase and prior to system production deployment. “Departments are expected to complete an AIA at the start of the design phase and again before production.” | Before production | — | Recommended |
| 2 | Canadian federal departments deploying automated decision systems | Obtain formal review and sign-off on completed impact assessments from designated departmental senior officials. “requires departmental senior officials and designated approval authorities to review, sign-off and publish completed assessments” | Before production | — | Recommended |
| 3 | Canadian federal departments deploying automated decision systems | Publish completed Algorithmic Impact Assessment results to the Open Government Portal. “publish completed assessments to the Open Government Portal.” | — | — | Recommended |
| 4 | Canadian federal departments deploying automated decision systems | Consult legal services, privacy officers, and domain experts during the assessment and mitigation process. “Departments must also consult legal services, privacy officers (where personal information is used) and other specialists” | — | — | Recommended |
| 5 | Federal departments deploying Level III or IV automated decision systems | Subject high-impact automated decision systems to external peer review prior to operational deployment. “For high-impact systems (Levels III–IV), the Directive and AIA require additional steps such as external peer review” | Before deployment | Appendix C | Recommended |
| 6 | Canadian federal departments operating automated decision systems | Monitor deployed systems and re-assess them whenever functionality or scope changes, following scheduled monitoring plans. “require regular reviews and re-assessments whenever system functionality or scope changes, and on a scheduled basis aligned with monitoring plans.” | Ongoing post-deployment | — | Recommended |
| 7 | Canadian federal departments deploying automated decision systems | Establish recourse and review mechanisms for individuals affected by automated administrative decisions. “Departments are also required to provide recourse and review mechanisms for individuals affected by decisions” | — | — | Recommended |
| 8 | Canadian federal departments deploying automated decision systems | Do not deploy automated decision systems without incorporating AIA mitigation results into project governance artifacts. “departments must integrate AIA results into project governance artifacts (project charters, risk registers, procurement materials and security assessments).” | Before deployment | Appendix C | Recommended |
Related Regulations
Directive on Automated Decision-Making (Treasury Board of Canada Secretariat)
Canada97% similar
Implementation Guide for Managers of Artificial Intelligence Systems (Innovation, Science and Economic Development Canada)
Canada91% similar
Guide on the use of generative AI (Treasury Board of Canada Secretariat)
Canada91% similar
NSW Artificial Intelligence Assessment Framework (AIAF)
Australia91% similar
Algorithm Charter for Aotearoa New Zealand
New Zealand91% similar
© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash