An assessment question can become a procurement problem surprisingly quickly. If the buyer needs to explain how a system was tested for unfair impacts, but the supplier will provide only a marketing summary, the missing evidence cannot be repaired by writing a more confident answer in the form.
Canada’s Directive on Automated Decision-Making makes the Algorithmic Impact Assessment part of the governance of covered federal systems. The procurement implication is practical: identify the information and review rights the buyer will need while there is still an opportunity to secure them.
First establish whether the directive applies
The directive concerns production systems used to make an administrative decision or a related assessment about a client. Systems used only for research, experimentation, or testing are excluded. Its applicability also depends on institutional and timing provisions. Provincial and municipal buyers must examine their own instruments; federal requirements should not be presented as a universal Canadian AI procurement rule.
For a covered system, the final AIA must be completed, approved, and published before production. The directive also calls for review and updates, including when functionality or scope changes. The responsible institution needs a way to obtain the supplier information that those duties require.
| Need to establish | Supplier contribution | Buyer responsibility |
|---|---|---|
| What role automation plays | Workflow and component documentation | Confirm how the actual service uses the output |
| How performance was tested | Methods, results and known limitations | Assess relevance to the intended population and use |
| How decisions can be examined | Version information and accessible records | Verify a sample decision can be reconstructed |
| What changed after acceptance | Change notices and updated documentation | Review the assessment and affected controls |
Acceptance should include a traceable decision
Select a representative case and follow it from input to outcome. Identify the software and model versions, the information used, the rules applied, and any human intervention. Examine whether the records support the explanation the institution needs to give. A dashboard showing a success rate cannot answer all of those questions.
The directive includes testing for accuracy, unintended bias, and unfair impacts, together with ongoing outcome monitoring. Procurement teams should work with service, policy, privacy, security, and legal owners to determine the test access and documentation needed for their system. The supplier’s own benchmark may inform that work without being sufficient for the institution’s decision.
Write for the second version
The first accepted release will change. A supplier may replace a model, revise a decision rule, or introduce a new data source. Access to released component versions and appropriate review, testing, monitoring, and audit rights help the institution understand those changes. Confidentiality safeguards can be part of the arrangement without making the evidence inaccessible.
Keep unresolved supplier dependencies visible before contract award. Where evidence cannot be obtained, the institution needs to decide how that affects the proposed use, procurement terms, or acceptance. The AIA is easier to maintain when the contract has already made its questions answerable.
Selected primary sources
Open the primary-source pages used to verify the claims summarized here.