Treadstone Associates
Definition

What is an algorithmic impact assessment?

An algorithmic impact assessment, or AIA, is a structured review completed before an automated decision system goes into production, that scores how much the system could affect the people it touches and sets which safeguards apply as a result.

Treadstone Associates · Updated 2026

How it’s used in Canada

This is not a proposal or a voluntary code — it is a live, binding requirement under the Treasury Board’s Directive on Automated Decision-Making, which states plainly: “Completing, approving and publishing the final results of an algorithmic impact assessment in an accessible format on the Open Government Portal prior to the production of any automated decision system”.

The directive grades the result on four bands, described on its own page as “Impact Assessment Levels” keyed to reversibility and duration of impact on rights, equality, dignity, privacy, autonomy, health and economic interests, running from Level I (low risk) to Level IV, with the required safeguards scaling up at each level.

The scope is federal-government-only — it applies to systems used by federal departments to make an administrative decision about a client, and does not reach a private Canadian business at all. Québec runs a different, genuinely private-sector instrument for one specific use: its privacy regulator, the Commission d’accès à l’information, states that “avant d’avoir recours à un système d’IA, l’employeur doit réaliser une démarche d’évaluation des facteurs relatifs à la vie privée (EFVP)”, roughly: before using an AI system, the employer must complete a privacy impact assessment before an employer uses an AI system in hiring — a hard pre-deployment duty, and a separate requirement from anything in the federal PIPEDA, which has no equivalent pre-deployment assessment duty.

Worked example

A federal department building a tool to flag benefit applications for manual review must complete and publish its AIA before the tool ever touches a real file — the assessment itself decides which of the directive’s Appendix C safeguards apply, from basic notice to a full human-review guarantee, based on how reversible and how serious the potential impact is.

A Québec employer that wants an AI tool to pre-screen résumés faces a comparable but legally distinct duty: not the federal AIA, which does not apply to it at all, but its own province’s pre-deployment privacy assessment — two different named instruments, from two different regulators, that happen to share the same underlying idea of assessing impact before the system is used rather than after.

Related terms

See also: high-impact AI system, AI governance, which Canadian regulators touch AI.

Where this leads

Working out how deep a review an AI system actually warrants, and what evidence that review needs to produce, is a due-diligence question — ai-due-diligence covers how that assessment gets structured.