Canada Artificial Intelligence and Data Act (AIDA)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Accountability and Governance
Report material harms or risks of harm from AI systems to the AI and Data Commissioner.
- IR plan
- Notification templates
- Regulator log
- No reporting threshold
- Untested process
Establish, implement and maintain measures to mitigate identified risks of harm and biased output.
- Mitigation register
- Control mapping
- Effectiveness reviews
- Untracked controls
- No effectiveness review
Assurance
Subject high-impact systems to independent audit or assurance reviews proportionate to risk.
- Audit reports
- Remediation plans
- Auditor scope
- No independent review
- Internal only
Deployment and Operations
Validate AI system performance, robustness, and reliability against intended use cases.
- Validation reports
- Performance metrics
- Stress test results
- No validation
- Single environment testing
Design and Development Requirements
Implement measures to detect, mitigate and monitor biased outputs across protected characteristics.
- Bias test reports
- Disparity metrics
- Mitigation log
- No fairness testing
- No protected group analysis
Ensure training and operational data is appropriate, lawfully obtained and quality-assured.
- Dataset cards
- Provenance logs
- Quality reports
- Unknown provenance
- No quality checks
Disclose to users when they interact with a high-impact AI system and provide intended use information.
- User notices
- Disclosure screenshots
- System cards
- No user notice
- Buried disclosure
Publish plain-language descriptions of high-impact AI systems, including capabilities and limitations.
- Public system card
- Website page
- Limitations statement
- Internal only documentation
- No limitations disclosed
Fairness
Provide affected individuals a means to challenge or seek correction of AI decisions impacting them.
- Appeal process
- Redress log
- Outcome reviews
- No appeal path
- No human reviewer
Governance
Identify AI systems that may be high-impact based on intended use, risk of harm and reliance on automated decisions.
- AI system inventory
- High-impact classification log
- Use case register
- No AI inventory
- Classification not documented
Maintain records of measures taken to comply with AIDA obligations, available on Commissioner request.
- Evidence vault
- Document index
- Retention policy
- No central evidence
- Lost artefacts
Train staff developing, deploying or operating AI systems on AIDA obligations and risks.
- Training records
- Curriculum
- Attestations
- No AI-specific training
- Engineers untrained on ethics
Establish an accountability framework with roles for AI risk owners, sign-off authorities and an AI ethics function.
- RACI
- AI governance charter
- Board minutes
- No named owner
- Ad hoc reviews
High-Impact AI System Classification
Assess potential harms including physical, psychological, economic and biased output before deploying AI.
- AIA template
- Harm register
- Mitigation plan
- No structured assessment
- Bias risk ignored
Operations
Continuously monitor deployed systems for performance drift and emerging harms.
- Drift reports
- Alert thresholds
- Retraining log
- No drift monitoring
- No retraining policy
Apply additional measures for general-purpose and generative AI including content provenance.
- Watermarking spec
- Provenance metadata
- Misuse policy
- No content labelling
- No misuse monitoring
Have authority and procedure to suspend or cease operation of an AI system causing serious harm.
- Cessation procedure
- Test results
- Decision logs
- No formal cessation plan
- Untested rollback
Maintain human oversight proportional to risk, including ability to intervene and override automated decisions.
- Oversight procedure
- Override logs
- Reviewer training
- Rubber-stamp review
- No override capability
Security
Protect AI systems against adversarial attacks, model theft and data poisoning.
- Threat model
- Red team reports
- Access controls
- No threat modelling
- No adversarial testing
Third-Party
Assess and manage risks from third-party models, APIs and datasets used in high-impact systems.
- Vendor AI register
- Model cards
- Contractual clauses
- Unknown upstream models
- No vendor diligence
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canada Artificial Intelligence and Data Act (AIDA) framework page.