Back to Frameworks

Canada Artificial Intelligence and Data Act (AIDA)

Canada
v2022 (proposed - not yet enacted)
10 domains
20 controls

The Artificial Intelligence and Data Act (AIDA), proposed as Part 3 of Bill C‑27 (Digital Charter Implementation Act), is a pending Canadian federal law that would establish a risk‑based regulatory framework for high‑impact artificial intelligence systems. The Act would impose obligations on providers and operators of high‑impact AI systems, including conducting risk assessments, implementing monitoring and mitigation measures, maintaining detailed documentation, and providing transparency notices to affected individuals. It defines “high‑impact” AI based on criteria such as the system’s scope, level of autonomy, and potential for significant harm. The Act also includes provisions for exemptions, enforcement powers for the Minister of Innovation, Science and Industry, and alignment with existing privacy legislation. As of now, AIDA remains a proposed statute and has not yet been enacted.

Unverified

Canada Artificial Intelligence and Data Act (AIDA) is a compliance framework from Canada with 10 domains and 20 controls that map to 23 other frameworks. The largest domains are Design and Development Requirements (4 controls), Governance (4 controls), Operations (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Accountability and Governance

2 controls
Controls in the Accountability and Governance domain of Canada Artificial Intelligence and Data Act (AIDA)2 controls
CodeTitle
AIDA-11Incident Reporting
AIDA-13Risk Mitigation Measures

Assurance

1 controls
Controls in the Assurance domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-19Audit and Assurance

Deployment and Operations

1 controls
Controls in the Deployment and Operations domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-9Robustness and Validation

Design and Development Requirements

4 controls
Controls in the Design and Development Requirements domain of Canada Artificial Intelligence and Data Act (AIDA)4 controls
CodeTitle
AIDA-4Bias and Discrimination Mitigation
AIDA-5Data Governance
AIDA-6Transparency to Users
AIDA-7Public Reporting

Fairness

1 controls
Controls in the Fairness domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-17User Redress

Governance

4 controls
Controls in the Governance domain of Canada Artificial Intelligence and Data Act (AIDA)4 controls
CodeTitle
AIDA-1Scope and High-Impact Systems
AIDA-12Record Keeping
AIDA-18Training and Competence
AIDA-2Accountability Framework

High-Impact AI System Classification

1 controls
Controls in the High-Impact AI System Classification domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-3Harm Assessment

Operations

4 controls
Controls in the Operations domain of Canada Artificial Intelligence and Data Act (AIDA)4 controls
CodeTitle
AIDA-10Monitoring and Drift Detection
AIDA-16Generative AI Specific Measures
AIDA-20Cessation of High-Risk Use
AIDA-8Human Oversight

Security

1 controls
Controls in the Security domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-15Security of AI Systems

Third-Party

1 controls
Controls in the Third-Party domain of Canada Artificial Intelligence and Data Act (AIDA)1 controls
CodeTitle
AIDA-14Third-Party AI Components

Your Compliance Coverage

If you comply with Canada Artificial Intelligence and Data Act (AIDA), you already cover:

Maps to 23 other frameworks

20 total controls
OECD AI Principles
11 source controls mapped|8 target controls covered
55%
NIST AI Risk Management Framework (AI RMF 1.0)
7 source controls mapped|6 target controls covered
35%
OECD Recommendation on Artificial Intelligence (2024 Update)
5 source controls mapped|5 target controls covered
25%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
4 source controls mapped|5 target controls covered
20%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 source controls mapped|5 target controls covered
20%
ISO/IEC 29134:2023
3 source controls mapped|1 target controls covered
15%
ISO/IEC 23894:2023
2 source controls mapped|3 target controls covered
10%
ISO/IEC 27400:2022
2 source controls mapped|3 target controls covered
10%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|2 target controls covered
10%
SQF Code Edition 9 - Safe Quality Food
2 source controls mapped|2 target controls covered
10%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|1 target controls covered
10%
ISO/IEC 29147:2018
2 source controls mapped|1 target controls covered
10%
ISO/IEC 27031:2011
2 source controls mapped|1 target controls covered
10%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
5%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|3 target controls covered
5%
ISO 37301:2021
1 source controls mapped|1 target controls covered
5%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
5%
ISO/IEC 38500:2024
1 source controls mapped|2 target controls covered
5%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
5%
ISO/IEC TR 24028:2020
1 source controls mapped|1 target controls covered
5%
NIST SP 800-171
1 source controls mapped|1 target controls covered
5%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
5%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
5%

What is Canada Artificial Intelligence and Data Act (AIDA) and who does it apply to?

Canada Artificial Intelligence and Data Act (AIDA) is a compliance framework from Canada with 10 domains and 20 controls. The Artificial Intelligence and Data Act (AIDA), proposed as Part 3 of Bill C‑27 (Digital Charter Implementation Act), is a pending Canadian federal law that would establish a risk‑based regulatory framework for high‑impact artificial intelligence systems. The Act would impose obligations on providers and operators of high‑impact AI systems, including conducting risk assessments, implementing monitoring and mitigation measures, maintaining detailed documentation, and providing transparency notices to affected individuals. It defines “high‑impact” AI based on criteria such as the system’s scope, level of autonomy, and potential for significant harm. The Act also includes provisions for exemptions, enforcement powers for the Minister of Innovation, Science and Industry, and alignment with existing privacy legislation. As of now, AIDA remains a proposed statute and has not yet been enacted. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Canada Artificial Intelligence and Data Act (AIDA) actually require?

Canada Artificial Intelligence and Data Act (AIDA) has 20 controls organised across 10 domains. The largest domains are Design and Development Requirements (4 controls), Governance (4 controls), Operations (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Canada Artificial Intelligence and Data Act (AIDA) do I already cover?

Canada Artificial Intelligence and Data Act (AIDA) maps to 23 other compliance frameworks. The top mapping partners are OECD AI Principles (55% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (35% coverage), OECD Recommendation on Artificial Intelligence (2024 Update) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Canada Artificial Intelligence and Data Act (AIDA)?

Start your Canada Artificial Intelligence and Data Act (AIDA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Canada Artificial Intelligence and Data Act (AIDA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required