evidoria

← Back to browse

Good practice Imported

Canada's Algorithmic Impact Assessment Registry — Mandatory Pre-Deployment Disclosure for Federal AI

Canada · Ottawa · See the Canada profile

Since April 2019, Canada's Directive on Automated Decision-Making has made federal departments score AI risk and publish Algorithmic Impact Assessments before go-live; by Aug 2024, 22 were public on the Open Government Portal.

22
Algorithmic Impact Assessments published (by August 2024)
1 April 2019
Directive in force since
Canada's Algorithmic Impact Assessment Registry — Mandatory Pre-Deployment Disclosure for Federal AI

Details

Maturity
Established
Promoter
Treasury Board of Canada Secretariat
Period
2019–present
Keywords
digital government, AI governance, administrative law, public sector accountability

Context

Canada's Directive on Automated Decision-Making, issued 4 March 2019 and in force from 1 April 2019, requires federal departments to assess, mitigate and disclose the impacts of automated decision systems used in administrative decisions about the public, centred on the Algorithmic Impact Assessment (AIA) - a questionnaire scoring risk on a four-level scale.

Objectives

Ensure departments assess and publicly disclose the risks of automated decision systems before they go into production, for systems scored Level II and above.

Activities

Departments completed AIAs covering systems including automated triage tools for immigration applications, the ArriveCAN proof-of-vaccination recognition system, and disability-benefit decision support. A 2023 update added requirements to assess impacts by gender and age. Since November 2025 the public register has held individual records for every federal automated decision system.

Results

As of August 2024, Canadian federal agencies had published 22 AIAs. A February 2025 review by the World Privacy Forum found the framework had been revised multiple times but flagged expertise shortages inside departments, difficulty designing risk-scoring questions, and publication requirements 'often met only in a partial manner.'

Conclusions

Six years in, the directive stands as one of the most mature statutory frameworks for disclosing government AI use before deployment, while its own external reviewers document that coverage and rigour remain uneven across departments; the review's own conclusion was candid that whether the AIA approach 'works as intended' remains an open question.

Implementation

Indicative cost
Medium (€50k–€500k)
Time to results
Long (> 3 years)
Staffing & skills
Departmental staff completing AIAs, Treasury Board of Canada Secretariat oversight, Independent peer reviewers

Conditions for success

  • A statutory directive with a defined, publicly documented risk-scoring methodology
  • Mandatory pre-deployment publication for higher-risk (Level II+) systems
  • Periodic revision of the framework (e.g. the 2023 update adding gender/age impact questions)

Common failure modes

  • Expertise shortages inside departments for completing assessments
  • Difficulty designing the risk-scoring questions themselves
  • Publication requirements 'often met only in a partial manner' per the Feb 2025 external review

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful