AI Procurement Readiness.
Selling an AI-assisted or automated system into Canadian government means answering questions about traceability, oversight, and data sovereignty before anyone evaluates your technology. We get those answers written down and defensible.
What Canadian AI procurement actually requires.
For federal institutions, the operative instrument is the Treasury Board’s Directive on Automated Decision-Making. It requires an Algorithmic Impact Assessment — 65 risk questions and 41 mitigation questions — that classifies a system into one of four impact levels, each carrying scaled requirements for peer review, transparency, human oversight, and monitoring.
Vendors are in scope by contract: system vendors and integrators are obligated to provide the documentation and monitoring data the Directive specifies, and every procurement or material modification involving an automated decision system must be integrated with Directive protocols across the project lifecycle. Documentation written for a sales conversation does not survive an assessment.
What you receive.
AIA readiness review
Your system walked through the Algorithmic Impact Assessment's risk and mitigation questions, with the likely impact level and the gaps that would surface at assessment.
Traceability & logging specification
What the system must capture — inputs, retrieved evidence with stable identifiers, model version, reviewer — so a decision can be reconstructed on request.
Data residency & sovereignty position
Where data lives, who can reach it, which jurisdiction governs that access, and what a self-hosted or model-agnostic deployment would require.
Human-oversight boundary map
The decisions that must stay with a named person, documented explicitly — the question evaluators ask and most vendors answer vaguely.
Evaluator documentation pack
The written artifacts a procurement reviewer expects: governance, privacy and PIPEDA exposure, monitoring commitments, and the reasons record.
Gap remediation roadmap
What to fix before the next bid, in priority order, scoped so your own team can execute.
Engagements are scoped against your objectives with explicit deliverables and a timeline, and formalized through a written agreement. We prepare the documentation and position; we do not certify compliance or provide legal advice.
Related analysis.
- Defending AI-assisted decisions to a regulator — what a defensible decision file contains.
- Canada’s AI for All strategy — sovereignty, trusted AI, and procurement as anchor customer.
- The compliance risk of ungrounded LLM outputs — why grounding is an architecture decision.
Common questions.
What is AI procurement readiness?
- It is the documentation, governance, and traceability posture a supplier needs before an automated or AI-assisted system can be bought by a government institution. In Canada, the operative instrument is the Treasury Board's Directive on Automated Decision-Making, which requires an Algorithmic Impact Assessment — 65 risk questions and 41 mitigation questions — classifying a system into one of four impact levels with scaled peer review, transparency, human oversight, and monitoring requirements.
Does the Directive apply to us if we are a private vendor?
- Indirectly but materially. System vendors and integrators are contractually obligated to provide the documentation and monitoring data the Directive specifies, and every procurement or material modification involving an automated decision system must be integrated with Directive protocols across the project lifecycle. If your product sits inside a federal workflow, these obligations reach your records.
What does data sovereignty mean in this context?
- Practically: where the data resides, who can access it, which jurisdiction's law governs that access, and whether the deployment can run in an environment the buyer controls. Canada's AI for All strategy places sovereign compute and trusted AI at the centre of national policy, and government buyers increasingly ask suppliers to answer these questions before technical evaluation begins.
What do we walk away with?
- An Algorithmic Impact Assessment readiness review, a traceability and logging specification for your system, a data residency and sovereignty position, a human-oversight boundary map, and an evaluator-facing documentation pack — the artifacts a procurement reviewer expects to see rather than a description of them.
Answer the evaluator’s questions before the bid.
Tell us what you sell and who you sell it to. We respond to qualified inquiries within two business days and scope a proposal from there.