Skip to content

Evidence request lists

Canada Artificial Intelligence and Data Act (AIDA)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Accountability and Governance

AIDA-11
Incident Reporting

Report material harms or risks of harm from AI systems to the AI and Data Commissioner.

Artefacts an auditor will ask for
  • IR plan
  • Notification templates
  • Regulator log
Where this commonly fails
  • No reporting threshold
  • Untested process
AIDA-13
Risk Mitigation Measures

Establish, implement and maintain measures to mitigate identified risks of harm and biased output.

Artefacts an auditor will ask for
  • Mitigation register
  • Control mapping
  • Effectiveness reviews
Where this commonly fails
  • Untracked controls
  • No effectiveness review

Assurance

AIDA-19
Audit and Assurance

Subject high-impact systems to independent audit or assurance reviews proportionate to risk.

Artefacts an auditor will ask for
  • Audit reports
  • Remediation plans
  • Auditor scope
Where this commonly fails
  • No independent review
  • Internal only

Deployment and Operations

AIDA-9
Robustness and Validation

Validate AI system performance, robustness, and reliability against intended use cases.

Artefacts an auditor will ask for
  • Validation reports
  • Performance metrics
  • Stress test results
Where this commonly fails
  • No validation
  • Single environment testing

Design and Development Requirements

AIDA-4
Bias and Discrimination Mitigation

Implement measures to detect, mitigate and monitor biased outputs across protected characteristics.

Artefacts an auditor will ask for
  • Bias test reports
  • Disparity metrics
  • Mitigation log
Where this commonly fails
  • No fairness testing
  • No protected group analysis
AIDA-5
Data Governance

Ensure training and operational data is appropriate, lawfully obtained and quality-assured.

Artefacts an auditor will ask for
  • Dataset cards
  • Provenance logs
  • Quality reports
Where this commonly fails
  • Unknown provenance
  • No quality checks
AIDA-6
Transparency to Users

Disclose to users when they interact with a high-impact AI system and provide intended use information.

Artefacts an auditor will ask for
  • User notices
  • Disclosure screenshots
  • System cards
Where this commonly fails
  • No user notice
  • Buried disclosure
AIDA-7
Public Reporting

Publish plain-language descriptions of high-impact AI systems, including capabilities and limitations.

Artefacts an auditor will ask for
  • Public system card
  • Website page
  • Limitations statement
Where this commonly fails
  • Internal only documentation
  • No limitations disclosed

Fairness

AIDA-17
User Redress

Provide affected individuals a means to challenge or seek correction of AI decisions impacting them.

Artefacts an auditor will ask for
  • Appeal process
  • Redress log
  • Outcome reviews
Where this commonly fails
  • No appeal path
  • No human reviewer

Governance

AIDA-1
Scope and High-Impact Systems

Identify AI systems that may be high-impact based on intended use, risk of harm and reliance on automated decisions.

Artefacts an auditor will ask for
  • AI system inventory
  • High-impact classification log
  • Use case register
Where this commonly fails
  • No AI inventory
  • Classification not documented
AIDA-12
Record Keeping

Maintain records of measures taken to comply with AIDA obligations, available on Commissioner request.

Artefacts an auditor will ask for
  • Evidence vault
  • Document index
  • Retention policy
Where this commonly fails
  • No central evidence
  • Lost artefacts
AIDA-18
Training and Competence

Train staff developing, deploying or operating AI systems on AIDA obligations and risks.

Artefacts an auditor will ask for
  • Training records
  • Curriculum
  • Attestations
Where this commonly fails
  • No AI-specific training
  • Engineers untrained on ethics
AIDA-2
Accountability Framework

Establish an accountability framework with roles for AI risk owners, sign-off authorities and an AI ethics function.

Artefacts an auditor will ask for
  • RACI
  • AI governance charter
  • Board minutes
Where this commonly fails
  • No named owner
  • Ad hoc reviews

High-Impact AI System Classification

AIDA-3
Harm Assessment

Assess potential harms including physical, psychological, economic and biased output before deploying AI.

Artefacts an auditor will ask for
  • AIA template
  • Harm register
  • Mitigation plan
Where this commonly fails
  • No structured assessment
  • Bias risk ignored

Operations

AIDA-10
Monitoring and Drift Detection

Continuously monitor deployed systems for performance drift and emerging harms.

Artefacts an auditor will ask for
  • Drift reports
  • Alert thresholds
  • Retraining log
Where this commonly fails
  • No drift monitoring
  • No retraining policy
AIDA-16
Generative AI Specific Measures

Apply additional measures for general-purpose and generative AI including content provenance.

Artefacts an auditor will ask for
  • Watermarking spec
  • Provenance metadata
  • Misuse policy
Where this commonly fails
  • No content labelling
  • No misuse monitoring
AIDA-20
Cessation of High-Risk Use

Have authority and procedure to suspend or cease operation of an AI system causing serious harm.

Artefacts an auditor will ask for
  • Cessation procedure
  • Test results
  • Decision logs
Where this commonly fails
  • No formal cessation plan
  • Untested rollback
AIDA-8
Human Oversight

Maintain human oversight proportional to risk, including ability to intervene and override automated decisions.

Artefacts an auditor will ask for
  • Oversight procedure
  • Override logs
  • Reviewer training
Where this commonly fails
  • Rubber-stamp review
  • No override capability

Security

AIDA-15
Security of AI Systems

Protect AI systems against adversarial attacks, model theft and data poisoning.

Artefacts an auditor will ask for
  • Threat model
  • Red team reports
  • Access controls
Where this commonly fails
  • No threat modelling
  • No adversarial testing

Third-Party

AIDA-14
Third-Party AI Components

Assess and manage risks from third-party models, APIs and datasets used in high-impact systems.

Artefacts an auditor will ask for
  • Vendor AI register
  • Model cards
  • Contractual clauses
Where this commonly fails
  • Unknown upstream models
  • No vendor diligence
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Canada Artificial Intelligence and Data Act (AIDA) framework page.