AI-Assisted Change Risk Correlation for IT Governance
Safety & Security · Planning & Decision-making
What it collects
- Previous change requests and incident documentation stored in a approximately 300,000-row Excel spreadsheet. This constitutes the primary historical training and query corpus for the system. No personal information is included.
- Run by
- Canada Revenue Agency (CRA)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
What it is for
This AI chatbot helps Canada Revenue Agency's Change Advisory Board analyze proposed IT change requests by correlating them against hundreds of thousands of past incidents and change records to flag potential risks before changes are approved. It operates at a speed and scale beyond human capacity, surfacing patterns a reviewer might otherwise miss. The system is currently in development and does not process personal information. Its outputs advise human board members, who retain final decision-making authority.
What it collects and what happens to it
Data taken in
- Previous change requests and incident documentation stored in a approximately 300,000-row Excel spreadsheet. This constitutes the primary historical training and query corpus for the system. No personal information is included.
Processing
- The system correlates data points from incoming change requests against historical incident records to identify patterns and predict potential issues. It processes tens of thousands of data points to surface risk signals at a scale not achievable by human reviewers alone.
- Retrieval from the 300,000-row historical change and incident corpus allows the chatbot to surface relevant past cases and support correlation analysis on demand.
What it does
- The system predicts, classifies, and scores change requests against historical incident patterns. Outputs are advisory — the Change Advisory Board members make the final approval or rejection decisions.
- The chatbot interface allows Change Advisory Board members to query and retrieve relevant information from past change and incident records, grounding its correlations in historical documentation.
Outputs
- The system produces risk correlations and potential causality assessments for proposed change requests — advisory outputs that help the Change Advisory Board identify issues that might otherwise go undetected at human processing speeds.
Run by
- The Canada Revenue Agency (CRA) is the federal department deploying and developing this AI chatbot to support its Change Advisory Board's IT governance processes.
Built by
Not stated by the Helpful Places.
Kept for
Not stated by the Helpful Places.
Shared with
- Outputs and query results are available to CRA employees serving on or supporting the Change Advisory Board. The register indicates primary users are Government of Canada employees.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — CRA CAB AI Chatbot (2526-CRA-ARC-016)Canada Revenue Agency, Government of Canada Open Data Portal, AI Register ID 2526-CRA-ARC-016.
- AI registerGovernment of Canada AI Register — CRA CAB AI Chatbot
- Register entryPublished by the Helpful Places. Reference 9cca7fd8. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Algorithmic TransparencyGC employees who interact with this system as Change Advisory Board members are informed of its AI-assisted nature through the register and internal governance processes. The system is disclosed publicly on the Government of Canada's open AI register.
- Right to a Human ReviewThe Change Advisory Board retains human decision-making authority over all change request approvals. AI outputs are advisory only; no change request is approved or denied solely on the basis of the AI system's output.
Risks and safeguards
- Reputational harmThe system may surface false correlations, incorrectly flagging a change request as risky and potentially delaying legitimate IT changes or implying fault for past incidents.Safeguard: Outputs are explicitly advisory; the Change Advisory Board exercises independent human judgment on all approvals. The system is in development, allowing for validation before production use.
- Financial & business harmIncorrect risk predictions could lead to unnecessary delays in IT change implementation, causing operational disruption and associated costs to CRA operations.Safeguard: Human reviewers on the Change Advisory Board validate all AI-generated risk assessments before changes are blocked or approved, and the open-source development model allows for transparency and iterative improvement.