AI-Powered Fraud Detection in CRA Secure Portals
Safety & Security · Enforcement
What it collects that can identify you
- Access logs capturing the interactions of all users with the CRA's secure portals — billions of historical records of portal activity such as login events, transaction requests, and navigation patterns.
- Digital fingerprint data — technical device and session attributes (e.g. browser type, IP characteristics, device identifiers) used as signals in anomaly detection. The register states this data does not constitute personal information.
- Run by
- Canada Revenue Agency (CRA)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Not stated by the Helpful Places.
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
This system uses artificial intelligence and machine learning to scan billions of access-log records from the Canada Revenue Agency's secure online portals and flag suspicious or potentially fraudulent transactions. It is used internally by Government of Canada employees and does not directly affect the general public's portal access. The system is currently in development. The CRA states that the data processed does not constitute personal information.
What it collects and what happens to it
Data taken in
- Access logs capturing the interactions of all users with the CRA's secure portals — billions of historical records of portal activity such as login events, transaction requests, and navigation patterns.
- Digital fingerprint data — technical device and session attributes (e.g. browser type, IP characteristics, device identifiers) used as signals in anomaly detection. The register states this data does not constitute personal information.
Processing
- Machine learning–based anomaly detection applied to portal access logs to identify patterns that deviate from a baseline of normal user behaviour and may indicate fraudulent transactions.
What it does
- The system scans access-log records and scores or flags transactions as suspicious. The primary users are GC employees who review and act on these outputs, indicating human decision authority downstream.
- Automatically ingests and processes billions of historical access-log records and digital fingerprint data, converting raw portal interaction signals into structured anomaly detections without per-record human review.
Outputs
- Flags or anomaly scores identifying suspicious and potentially fraudulent transactions, surfaced to GC employees for review. These are advisory outputs — the register indicates that GC employees are the primary users, implying human follow-up action.
Run by
- The Canada Revenue Agency (CRA) is the federal department accountable for deploying and operating this AI-based anomaly detection system within its secure portals.
Built by
- The system was developed by the Government of Canada, indicating in-house development rather than a commercial vendor.
Kept for
Not stated by the Helpful Places.
Shared with
- The anomaly detection outputs and access-log data are used internally by GC employees. There is no mechanism described for individuals to access the data or outputs produced by this system.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Registry — Anomaly Detection: Detecting fraudulent transactions within CRA's secure portals (2526-CRA-ARC-012)
- AI registerGovernment of Canada AI Register — 2526-CRA-ARC-012
- AI registerGovernment of Canada AI Register — 2526-CRA-ARC-012
- Register entryPublished by the Helpful Places. Reference aea2a093. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Algorithmic TransparencyThe CRA has published a description of this system in the Government of Canada's AI Register, which provides basic information about its purpose and data sources. Detailed information about the model logic or specific detection thresholds is not publicly disclosed. Contact the CRA for further information about this system.
Risks and safeguards
- Civil liberties harmSystematic surveillance of portal access behaviour could have a chilling effect on legitimate users or lead to erroneous flags that restrict access to government services. The register states no personal information is involved, and primary users are GC employees who review outputs, providing a human-in-the-loop safeguard. The system is currently in development, suggesting mitigations are still being designed. No additional technical or policy mitigations are described in the source material.