Canada - Algorithmic Impact Assessment (2019)

Algorithmic Impact Assessment (AIA) tool (Treasury Board of Canada Secretariat)

Canada

RAI-CA-NA-AIAATXX-2019
Effective: May 1, 2019
In Force (Amended)(In Force (Amended))
PolicyGovernance and OversightRisk Management
Export PDF

The Algorithmic Impact Assessment (AIA) tool requires Canadian federal departments to evaluate automated decision system risks, issued by the Treasury Board of Canada Secretariat in 2019. Currently In Force (Amended) effective 2019-05-01, it determines procedural duties and is monitored by the TBS Office of the Chief Information Officer.

Summary

The Algorithmic Impact Assessment (AIA) tool is an open, government-provided risk assessment questionnaire maintained by the Treasury Board of Canada Secretariat (TBS). First launched in May 2019 to operationalize the Directive on Automated Decision-Making, the AIA helps federal departments and agencies identify, score and manage risks arising from automated decision systems (ADS), including those that rely on artificial intelligence (AI). The AIA asks structured questions across project, system, algorithm, decision, impact and data domains (65 risk questions) and mitigation/consultation domains (41 mitigation questions). Responses produce a quantitative score that maps to one of four impact levels (Level I — little/no impact; Level II — moderate impact; Level III — high impact; Level IV — very high impact). Impact levels determine the scope of mitigation measures and procedural obligations under the Directive, such as peer review, testing, monitoring, human oversight levels, and publication requirements.

The AIA is explicitly tied to the Directive on Automated Decision-Making and is mandatory for federal institutions where an automated decision system makes or supports an administrative decision affecting rights, interests or privileges of clients. The Directive came into force in 2019 and applies to systems developed or procured after April 1, 2020; departments are required to complete and publish the AIA as part of the approval and deployment lifecycle. The AIA was developed through open, multi-stakeholder engagement and is published under an open source licence; its implementation includes a publicly-accessible web questionnaire, downloadable/archivable results (PDF/JSON), and a public repository of published AIAs on the Open Government Portal that provides transparency and examples of government use-cases.

Practically, the AIA is intended to be completed early in a project (design phase) and again prior to production to validate the impact rating. The tool’s scoring differentiates raw impact and mitigation strength; if mitigation scores exceed a threshold the final score is adjusted to reflect effective risk management. The TBS Office of the Chief Information Officer (OCIO) maintains the tool, supports departments on interpretation and publication, and monitors compliance with the Directive. Amendments to the Directive in 2023 clarified scope, added requirements (including extending coverage to automation affecting federal employees) and set transition timelines for compliance with new provisions. Departments that fail to comply may face administrative remediation requirements, mandatory corrective actions, halted deployments and internal accountability measures; the Directive is a mandatory policy instrument for federal institutions but typically relies on internal governance, auditing and Treasury Board oversight rather than criminal sanctions. The AIA and its published assessments interact with other Canadian instruments (Privacy Act, Access to Information Act, Treasury Board policies, and evolving federal AI strategy and legislative proposals), and the AIA’s open design and scoring methodology have been referenced internationally as a model for public-sector AI risk assessment.

Full article

Read full text ↗

Overview

The Algorithmic Impact Assessment (AIA) is a standardized, nation-wide tool maintained by the Treasury Board of Canada Secretariat (TBS) to operationalize the Directive on Automated Decision-Making and ensure federal institutions assess, mitigate and publish risks from automated decision systems (ADS). Introduced in 2019 and distributed openly (including via a public GitHub repository), the AIA consists of risk and mitigation questionnaires that yield an impact score and corresponding level (I–IV). The tool is used by departments to guide governance, testing and transparency measures before a system reaches production and to support ongoing monitoring and public disclosure obligations.

Definitions

Key terms used by the AIA include "automated decision system" (any technology used to make or support administrative decisions, including rule-based systems, machine learning, natural language processing and generative AI), "impact level" (a four-tier scale from Level I to Level IV that reflects potential harm to rights, health, economic interest and ecosystems), "raw impact score" and "mitigation score" (numerical outputs from the questionnaire used to determine final impact), and "client" (an individual or entity affected by the decision). The Directive’s and AIA’s scope, guidance and examples of "administrative decision" are set out on the TBS site and supporting guidance documents.

Governance and Institutional Framework

The AIA is embedded in the Government of Canada’s governance architecture for responsible AI. The Treasury Board of Canada Secretariat, through its Office of the Chief Information Officer (OCIO), maintains the tool, issues interpretation guidance and oversees departmental compliance. Departments listed under the Financial Administration Act (Schedules I, I.1 and II) are subject to the Directive; some entities (for example the Canada Revenue Agency) may be subject to separate arrangements. The AIA requires departmental senior officials and designated approval authorities to review, sign-off and publish completed assessments to the Open Government Portal. Departments must also consult legal services, privacy officers (where personal information is used) and other specialists as part of the assessment and mitigation planning.

Key Focus Areas

The AIA questionnaire and supporting guidance concentrate on multiple risk domains: project governance (roles, approval authorities, program objectives), system architecture and security (design, data flows and cybersecurity classification), algorithmic design (model type, explainability and training data provenance), decision context (what decisions are made and to whom they apply), impact analysis (risks to rights, health, dignity, economic interests and intersectional groups), data governance (personal information, retention, provenance and accuracy), consultation (stakeholder and community engagement, including GBA+ analysis), and mitigation measures (human oversight, testing regimes, peer review and monitoring). For high-impact systems (Levels III–IV), the Directive and AIA require additional steps such as external peer review, strengthened human intervention, and more rigorous testing and documentation.

Implementation Framework

Departments are expected to complete an AIA at the start of the design phase and again before production. The online AIA tool runs as a questionnaire (the official web instance and an open-source implementation are available) that produces a results package exportable as JSON or PDF for departmental records and publication. Appendix C of the Directive maps mitigation requirements according to impact level; departments must integrate AIA results into project governance artifacts (project charters, risk registers, procurement materials and security assessments). The AIA scoring logic (raw impact vs mitigation score and the 80% mitigation adjustment rule) drives whether additional controls are required before deployment.

Monitoring and Evaluation

Once deployed, automated decision systems must be monitored in production: the Directive and AIA require regular reviews and re-assessments whenever system functionality or scope changes, and on a scheduled basis aligned with monitoring plans. Departments must track outcomes, fairness and accuracy metrics, complaint and recourse data, and maintain records sufficient to support audits and investigations. The OCIO provides central support and may request updates, while departmental internal audit and TBS oversight processes assess compliance with the directive and AIA publication requirements.

Penalties, Liability, and Appeals

The Directive (and the AIA which operationalizes it) is a mandatory policy instrument for federal institutions; non-compliance can trigger administrative enforcement by TBS including corrective action demands, requirement to halt or remediate deployments, internal accountability measures and escalation to deputy heads or the Treasury Board. The AIA itself does not create criminal penalties; affected individuals retain rights under the Privacy Act, Access to Information Act and other applicable statutes to seek remedies. Departments are also required to provide recourse and review mechanisms for individuals affected by decisions as part of mitigation measures tied to higher impact levels.

Relationship to Other Instruments

The AIA is closely linked to the Directive on Automated Decision-Making and complements other federal instruments including the Privacy Act, Policy on Service and Digital, guidance on generative AI, and the Open Government publication requirements. The AIA’s open-source code is maintained in the TBS GitHub repository, enabling public reuse and international adaptation. Completed AIAs are published on the Open Government Portal alongside departmental transparency materials.

International Alignment

The Canadian AIA has been referenced internationally as a practical public-sector model for algorithmic impact assessment. Its open approach aligns with OECD and international best practice on AI governance and is used as an exemplar by international observatories such as the OECD Observatory of Public Sector Innovation. The AIA’s risk-tiering, open-source implementation and publication requirements facilitate cross-jurisdictional comparisons and inform transnational policy dialogue on responsible public-sector AI.

Implementation Timeline

EventDate
Directive announced2019-03-04
Directive in force2019-04-01
AIA tool launched (first public release)2019-05-01
Directive amendments published2023-04-25
Transition deadlines for new/legacy systems (amendments)2023-10-25 and 2024-04-25

Sources and References

SourceType
Algorithmic Impact Assessment tool — Treasury Board of Canada SecretariatPrimary Source
Guide on the Scope of the Directive on Automated Decision-Making — Treasury Board of Canada SecretariatPrimary Source
GitHub: canada-ca/aia-eia-js (AIA open-source repo)Primary Source
Open Government Portal — Algorithmic Impact Assessment published resultsPrimary Source

Requirements for a company

What an organisation has to do under Canada - Algorithmic Impact Assessment (2019), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Complete an Algorithmic Impact Assessment at the design phase and prior to system production deployment.Canadian federal departments deploying automated decision systems
  • Obtain formal review and sign-off on completed impact assessments from designated departmental senior officials.Canadian federal departments deploying automated decision systems
  • Publish completed Algorithmic Impact Assessment results to the Open Government Portal.Canadian federal departments deploying automated decision systems
  • Consult legal services, privacy officers, and domain experts during the assessment and mitigation process.Canadian federal departments deploying automated decision systems
  • Subject high-impact automated decision systems to external peer review prior to operational deployment.Federal departments deploying Level III or IV automated decision systems
  • Monitor deployed systems and re-assess them whenever functionality or scope changes, following scheduled monitoring plans.Canadian federal departments operating automated decision systems
  • +1 more in the table below

Should not do

1
  • Do not deploy automated decision systems without incorporating AIA mitigation results into project governance artifacts.Canadian federal departments deploying automated decision systems

Who must do what

The obligations under Canada - Algorithmic Impact Assessment (2019), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Canadian federal departments deploying automated decision systemsComplete an Algorithmic Impact Assessment at the design phase and prior to system production deployment.
Departments are expected to complete an AIA at the start of the design phase and again before production.
Before productionRecommended
2Canadian federal departments deploying automated decision systemsObtain formal review and sign-off on completed impact assessments from designated departmental senior officials.
requires departmental senior officials and designated approval authorities to review, sign-off and publish completed assessments
Before productionRecommended
3Canadian federal departments deploying automated decision systemsPublish completed Algorithmic Impact Assessment results to the Open Government Portal.
publish completed assessments to the Open Government Portal.
Recommended
4Canadian federal departments deploying automated decision systemsConsult legal services, privacy officers, and domain experts during the assessment and mitigation process.
Departments must also consult legal services, privacy officers (where personal information is used) and other specialists
Recommended
5Federal departments deploying Level III or IV automated decision systemsSubject high-impact automated decision systems to external peer review prior to operational deployment.
For high-impact systems (Levels III–IV), the Directive and AIA require additional steps such as external peer review
Before deploymentAppendix CRecommended
6Canadian federal departments operating automated decision systemsMonitor deployed systems and re-assess them whenever functionality or scope changes, following scheduled monitoring plans.
require regular reviews and re-assessments whenever system functionality or scope changes, and on a scheduled basis aligned with monitoring plans.
Ongoing post-deploymentRecommended
7Canadian federal departments deploying automated decision systemsEstablish recourse and review mechanisms for individuals affected by automated administrative decisions.
Departments are also required to provide recourse and review mechanisms for individuals affected by decisions
Recommended
8Canadian federal departments deploying automated decision systemsDo not deploy automated decision systems without incorporating AIA mitigation results into project governance artifacts.
departments must integrate AIA results into project governance artifacts (project charters, risk registers, procurement materials and security assessments).
Before deploymentAppendix CRecommended

© Regulations.AI · updated on 13-Jun-2026 · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash