Algorithmic Impact Assessment: The Federal Tool Private Companies Should Steal
An algorithmic impact assessment asks what a system does to people, not what it does for you. That is a different question from a privacy assessment, and most companies never ask it.
An algorithmic impact assessment measures the consequences an automated decision system has on the people subject to it, and sets the level of oversight required in proportion. The federal government built one for its own institutions under the Treasury Board Directive on Automated Decision-Making. It does not apply to private companies. Use it anyway.
The reason is simple. There is no comparable free, tested, structured instrument in Canada for private-sector use, and the alternative most companies default to is a privacy impact assessment, which answers a different question.
How is this different from a privacy impact assessment?
A PIA asks whether personal information is handled lawfully. An AIA asks whether the decision is fair, explainable, reversible, and proportionate to the stakes.
You can pass one and fail the other, easily. A hiring screener that collects nothing beyond what candidates already submitted, stores it in Canada, and deletes it on schedule will sail through a PIA. It can still be the wrong tool entirely, if it filters people on a proxy nobody examined and there is no practical route to appeal.
| Privacy impact assessment | Algorithmic impact assessment | |
|---|---|---|
| Central question | Is the information handled lawfully? | What does this decision do to the person? |
| Looks at | Collection, use, disclosure, retention, safeguards | Stakes, reversibility, explainability, fairness, oversight |
| Triggered by | Personal information processing | Automated decisions affecting people |
| Output | Mitigations for privacy risk | Required oversight level and controls |
| Legal status in Canada | Required in defined cases under Law 25 | Required for federal institutions, voluntary for business |
Both are worth doing on the same system, and they share inputs. Our PIA wizard covers the first; the second is what this post is about.
What does the assessment actually measure?
Four dimensions, and the scoring matters less than the discussion each one forces.
Stakes. What happens to someone if the system is wrong? A misfiled support ticket is recoverable. A denied application, a flagged claim, or a rejected candidate may not be, because the person often never learns why.
Reversibility. Is there a real route to challenge and reverse the outcome, and does the person know it exists? A theoretical appeal process buried in a footer is not reversibility.
Explainability. Can you tell the person, in plain language, what factors drove the outcome? If the honest answer is that a model produced a score and nobody can say why, that constrains where the system can be used.
Reach. How many people, how often, and can they avoid it? A system applied to every applicant with no alternative path carries more weight than one applied to a subset who opted in.
Score these consistently and a useful thing happens: systems sort themselves into tiers, and the oversight you owe each tier becomes an argument you can actually win internally.
What do you do with the result?
Attach specific controls to specific tiers, and write them down before deployment, not after the first complaint.
For low-impact systems, registration in the inventory and periodic review is enough. For medium, add a named human reviewer with authority to override, a documented accuracy expectation, and disclosure to the affected person that automation was involved. For high impact, add pre-deployment testing on representative data, monitoring after launch, a defined appeal path with a human decision-maker, and periodic re-assessment.
The disclosure line deserves attention because it is the one Canadian law is moving toward fastest. Quebec's Law 25 already requires informing a person when a decision is based exclusively on automated processing, and giving them the opportunity to submit observations. Bill C-27's proposed successor to PIPEDA contemplates explanations for automated decisions. Building the disclosure now costs a sentence; retrofitting it later costs a project.
Is this overkill for a small business?
For most systems, yes, and I would rather you skip it than do it badly on everything.
The threshold I use: run an AIA on any system that produces an outcome about an identified person that the person would object to if they understood it. That is a short list in most companies. It usually catches hiring tools, credit or risk scoring, fraud flags, claims triage, and anything applied to patients or students. It usually excludes drafting assistants, summarisers, meeting notes, and code helpers, which is most of what a small company runs.
Do the short list properly. Ignore the rest until it changes category, and remember that a drafting assistant becomes an assessed system the day someone starts pasting its output into a decision letter unedited.
For the fairness testing that a high-tier result usually demands, testing an AI system for bias covers what reasonable measures look like in practice.
This is general information, not legal advice.
Valdra runs the impact assessment alongside the privacy assessment against the same system record, so the tier you assign drives the controls and the review schedule automatically. The AI governance view holds both.
Frequently asked questions
What is an algorithmic impact assessment?+
A structured assessment of what an automated decision system does to the people subject to it, measuring stakes, reversibility, explainability, and reach, then setting oversight requirements in proportion. Canada's federal version exists under the Treasury Board Directive on Automated Decision-Making.
Does the federal Directive apply to private companies?+
No. It governs federal institutions. Private companies are free to adopt the method voluntarily, and many do, because there is no comparable free and tested instrument built for private-sector use in Canada.
How does an AIA differ from a privacy impact assessment?+
A PIA asks whether personal information is handled lawfully. An AIA asks whether the decision itself is fair, explainable, reversible, and proportionate. A system can pass a PIA cleanly and still be the wrong tool for the decision it is making.
Which systems actually need one?+
Any system producing an outcome about an identified person that the person would object to if they understood it. In practice that means hiring tools, credit and risk scoring, fraud flags, claims triage, and systems applied to patients or students, not drafting assistants or meeting notes.
Do I have to tell people a decision was automated?+
Quebec's Law 25 requires informing a person when a decision is based exclusively on automated processing and allowing them to submit observations. The proposed federal successor to PIPEDA contemplates explanations for automated decisions, so building the disclosure now is cheaper than retrofitting it.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Try Valdra