A guide for Canadian public bodies using AI

Algorithmic impact assessments for Canadian public bodies: what each regime requires, and what a defensible AIA contains

The federal directive and its four impact levels, Ontario's regulated-AI provisions and the IPC and OHRC principles, Alberta's automated-system notice, Quebec's automated-decision rights, and the European and British rules that reach a Canadian institution through its vendors — then the assessment itself, section by section, and where each element lives in AccessPoint. For privacy officers who inherited AI governance, CIOs who inherited the privacy office, and the program leads whose new tool makes recommendations about people.

In Canada the algorithmic impact assessment is a federal obligation with a published tool and four impact levels, a provincial expectation that Ontario, Alberta and Quebec express through disclosure duties, principles and regulation-making powers rather than a named form, and an international standard that arrives with vendors: the EU AI Act's fundamental rights impact assessment for public-sector deployers and the UK's mandatory algorithmic transparency records. The content of a defensible AIA is the same in every case, and the federal tool is the most complete template for it.

Most public bodies discover their AI estate the same way: a program area switches on a feature inside software it already licenses, and the privacy office learns about it from a helpdesk ticket. The governance question that follows is not whether to assess but against what, because the rules differ by order of government and by the vendor's home jurisdiction. This guide sets out the current obligations for Canadian public bodies, regime by regime, then describes the assessment that satisfies all of them, and how AccessPoint runs it.

Federal: the directive and the tool

The Treasury Board's Directive on Automated Decision-Making applies to any automated decision system in production that is used to make an administrative decision or a related assessment about a client, across every institution subject to the Policy on Service and Digital. It took effect on April 1, 2019 and applies to systems developed or procured after April 1, 2020; systems developed or procured before June 24, 2025 have until June 24, 2026 to comply with the updated requirements, as do agents of Parliament.

Section 6.1 is the AIA requirement: complete, approve and publish the final results of an algorithmic impact assessment before production; apply the requirements of Appendix C as determined by the assessment; and review, approve and update the published assessment on a scheduled basis and whenever the system's functionality or scope changes. The rest of section 6 scales with the impact level: notice before decisions through every service channel, meaningful explanations after them, access to and the right to test proprietary components, documented decisions, testing and monitoring of outcomes, data quality and governance, peer review by qualified experts with a published summary, Gender-based Analysis Plus, employee training, security and legal review, human involvement, recourse, and reporting.

The Algorithmic Impact Assessment tool is a mandatory questionnaire. It scores raw impact across 65 questions to a maximum of 169 points and mitigation across 41 questions to a maximum of 77; where the mitigation score reaches 80 percent of its maximum, 15 percent is deducted from the raw impact score. The current score places the system in one of four levels, from Level I (little impact) to Level IV (very high impact), and the level determines which Appendix C requirements apply. Two consequences follow for anyone building an AIA elsewhere: the questions are public, and the mitigation half of the score is the reason to write the controls into the assessment rather than around it.

Ontario: a framework waiting for its regulations, and principles that are not

Schedule 1 of Bill 194, the Enhancing Digital Security and Trust Act, 2024, gives Ontario the power to regulate public-sector AI. Section 5 applies to prescribed public sector entities that use an AI system in prescribed circumstances and requires them to provide information to the public about the use, to develop and implement an accountability framework, to take prescribed steps to manage risk, to use the system in accordance with prescribed requirements and not to use it where prohibited; section 6 adds disclosure and oversight duties when a system is used in prescribed circumstances; sections 7 and 8 hold the regulation-making and technical-standards powers. As of September 2026 the AI regulations have not been made: the regulations that took effect on July 1, 2026 cover cyber security for hospitals, colleges and universities (O. Reg. 51/26) and school boards' handling of children's information (O. Reg. 52/26). Ministries and provincial agencies are meanwhile bound by the Responsible Use of AI Directive.

What is in force is the regulators' expectation. In January 2026 the Information and Privacy Commissioner and the Ontario Human Rights Commission published joint principles for the responsible use of AI by public-sector institutions: valid and reliable, safe, privacy protective, human rights affirming, transparent, and accountable. They are recommendations, applying across the AI lifecycle from design to retirement, and the two commissions have said the principles will ground their assessment of institutions' AI adoption. Their practical steps are an AIA in all but name: identify the AI you already use, conduct impact assessments, assign accountable individuals with the authority to intervene, and create a process for questions and concerns. And since July 1, 2025, section 38(3) of FIPPA requires a written privacy impact assessment before personal information is collected, which for an AI system means the PIA and the AIA describe one collection. The Ontario PIA guide covers that duty in full.

Alberta and Quebec: disclosure duties with teeth

Alberta. Under the Protection of Privacy Act, in force since June 11, 2025, a collection notice must state the public body's intention, if any, to input the personal information into an automated system to generate content or make decisions, recommendations or predictions. The government's guide defines an automated system as any system, software or process that uses computation to determine outcomes, make or aid decisions, inform policy implementation, collect data or observations, or otherwise interact with individuals and communities. The mandatory PIA under section 26 and the Ministerial Regulation, with its innovative-technology submission factor, is where that automation is described; the Alberta POPA guide sets out the trigger.

Quebec. Section 65.2 of the Act respecting Access to documents held by public bodies and the Protection of personal information requires a public body that renders a decision based exclusively on automated processing of personal information to inform the person concerned no later than when it informs them of the decision, and on request to tell them the personal information used, the reasons and the principal factors and parameters that led to the decision, and their right to have the information corrected. Section 63.5 separately requires a privacy impact assessment for any project to acquire, develop or overhaul an information system involving personal information, proportionate to the sensitivity, purposes, quantity and distribution of the information, with the body's access-and-privacy committee consulted from the outset.

Rules that arrive with the vendor

Two foreign regimes reach Canadian institutions through the systems they buy. Under Article 27 of the EU AI Act, deployers that are bodies governed by public law must perform a fundamental rights impact assessment before deploying a high-risk AI system, covering the deployer's processes in which the system will be used, the period and frequency of use, the categories of people likely to be affected, the specific risks of harm, the human oversight measures and the measures to be taken if the risks materialize; where a data protection impact assessment already covers an element, it need not be repeated. In the United Kingdom, the Algorithmic Transparency Recording Standard is mandatory for all government departments and for arm's-length bodies that deliver public or frontline services, and its published records are a useful model for the public summary of an AIA. A vendor that has completed either will have most of what a Canadian AIA needs; a vendor that has completed neither is telling you something.

What a defensible AIA contains

Every regime above converges on the same content. The federal tool is the fullest public expression of it, and an assessment built to the following sections will satisfy a Treasury Board reviewer, an Ontario commissioner applying the joint principles, and an EU Article 27 obligation at once.

SectionWhat it establishesWhere it lives in AccessPoint
System and decisionWhat the system decides or recommends, for whom, with what authority, whether it makes or assists the decision, and the human-involvement levelThe AI/ADM register on the subject: intended purpose, model or service, acquisition mode, deployment status, human-involvement level
DataEvery data source, whether it holds personal information, its provenance and quality controlsThe subject's data-source inventory with contains-personal-information flags, bound to the record of processing
People affected and impactWho is affected, how reversible the decision is, the scale, and the impact level or risk classificationRisk classification from the pack's taxonomy, including statutory classes, and the scored questionnaire
Risks of error, bias and harmEach risk with likelihood, impact and the harm to individualsThe risk register, scored on likelihood and impact with the harm-to-individuals lens
Mitigations and controlsTesting, monitoring, peer review, training, security, legal review, and the evidence for eachControls linked from the controls library with a designation; mitigation tasks and commitments with owners and dates
Transparency and recourseNotice before decisions, explanation after, how to challenge, and the published summaryThe notice and human-involvement requirements in the compliance profile; the publication summary from the closure tab
Approval and review cadenceWho approved, when, and when the assessment is reviewed or the system re-assessedReview sign-off; the derived approval date; Re-assess with the reassessment date pulled forward on change

Building the program

  1. Find the estate. The definitions are broad enough to include spam filters, chatbots and any tool that predicts or recommends. An all-staff question and a review of software licences produce the first inventory; the register keeps it.
  2. Classify before you assess. Impact level, risk class, or the EU's high-risk categories decide how much assessment each system needs. Screen everything; assess in proportion.
  3. Assess the system, not the vendor's brochure. Ask for the vendor's own assessment, model documentation and testing evidence, and record what they could not provide as a risk.
  4. Put people in the loop on paper. Name the human-involvement level, the accountable owner with the authority to intervene, and the recourse route, because every regime asks for all three.
  5. Pair the AIA with the PIA wherever personal information is processed, and keep the two consistent on data sources, oversight and controls.
  6. Re-assess on change. Models retrain, vendors ship features, a second program adopts the system. The assessment on record has to describe the system that exists.
  7. Govern your own tools the same way. If the software your office uses to process requests or assessments has AI in it, it belongs in the register too.

How AccessPoint runs it

AIAs on the assessment engine

Algorithmic impact assessments are an assessment type beside PIAs and security assessments, with scoring and tiering, a preliminary screener, typed questionnaires, section delegation to the people who built or operate the system, a review workflow and sign-off, all on an auditable trail. Templates configure to the directive or policy that binds you, and to your own framework where none does yet.

An AI systems register

A subject typed as an automated decision-making system carries its AI/ADM register: technical and privacy owners, intended purpose, AI model or service, deployment status, acquisition mode, human-involvement level, a risk classification drawn from a pack-seeded taxonomy with statutory classes, and a data-source inventory with personal-information flags. The approval date is derived from the latest assessment in effect, never typed in. The AI Systems Register report lists the estate with deployment status, risk classification, human involvement, mandatory-control gaps and the derived approval position.

A compliance profile that evaluates itself

The universal baseline rules require an assessment before production for an automated-decision system, an ADM notice and documented human involvement; the federal pack adds the Directive on Automated Decision-Making's requirements; a required assessment reads as met exactly while one is In Effect, and before-production items stay visible until the system is deployed.

Algorithmic risk in the same register as privacy risk

Risks from an AIA land in the ISO 31000 register with inherent and residual scoring, treatments, key risk indicators and governed acceptance that expires, beside the privacy risks they belong with, so leadership sees one exposure picture.

Re-assessment built in

Approved assessments are read-only; change goes forward through Re-assess on the same subject, and the reassessment date is pulled forward when the subject's recorded purpose changes.

Its own AI governed by construction

AccessPoint's optional AI Assist runs on Azure OpenAI in your own tenant; every output is a suggestion a person decides on, prompts and responses are never stored, each feature switches individually, a monthly token budget you set caps spend, you choose where inference is processed, and each case's audit export carries a disclosure of exactly which AI features touched it and what people decided. The AI governance report shows, per feature, whether people accepted, edited or dismissed each output.

Everything runs inside your own Microsoft 365 and Azure tenant, beside the access requests, PIAs, breaches and complaints the same office already handles.

Sources

Related reading on this site: AI governance and AIA software, how AI Assist is built, the companion guides on federal PIAs under the 2024 standard, Ontario's mandatory PIAs and Alberta's POPA PIAs, the public roadmap, or book a demo.

Algorithmic Impact Assessment Questions

What is an algorithmic impact assessment?

A structured assessment of a system that makes or assists decisions about people, covering what it decides, the data it uses, the people it affects, the risks of error, bias and harm, the human oversight in place, and the mitigations owed. In the federal government it is a mandatory questionnaire under the Directive on Automated Decision-Making that assigns an impact level from I to IV and, with it, the obligations that apply.

Which Canadian public bodies must complete an AIA?

Federal institutions subject to the Policy on Service and Digital, for any automated decision system in production used to make an administrative decision or a related assessment about a client; existing systems have until June 24, 2026 to comply with the updated directive. Provincial and municipal bodies do not yet face a statute that names an AIA, but Ontario's Enhancing Digital Security and Trust Act provides for regulated AI use, the IPC and OHRC published six principles in January 2026 that call for impact assessments across the AI lifecycle, Alberta requires collection notices to disclose automated-system use, and Quebec requires disclosure and explanation of decisions based exclusively on automated processing.

How is a federal AIA scored?

The Treasury Board's tool asks 65 impact questions scoring up to 169 points and 41 mitigation questions scoring up to 77. If the mitigation score reaches 80 percent of its maximum, 15 percent is deducted from the raw impact score. The current score places the system in one of four impact levels, and the level sets the notice, explanation, peer-review, human-involvement and other requirements in the directive's Appendix C.

Is an AIA the same as a privacy impact assessment?

No. A PIA assesses the collection, use and disclosure of personal information against privacy law; an AIA assesses the decision-making system itself, including its effects on rights, fairness and recourse. A system that processes personal information to make decisions needs both, and the two should describe the same data sources, oversight and controls.

What does AccessPoint do for AI governance?

It runs AIAs on the same assessment engine as PIAs, with screening, typed questionnaires, section delegation, a risk register, review and sign-off; it keeps an AI systems register of every automated-decision subject with its owners, purpose, model, deployment status, human-involvement level and risk classification; its compliance profile evaluates the applicable rules automatically; and it governs its own optional AI Assist the same way, with person-decided outputs, no prompt storage and a per-case AI disclosure.

See AccessPoint in action. 30 minutes, on your jurisdiction's rules, with the person who built it.

© 2026 Realizer Services Inc. About Privacy Terms