Skip to content
This is NOT an official site of the Government of Canada. Click here for the official AI registry.

AI-Assisted Security Assessment for IT Controls

Safety & Security

What it collects

Operational data
Anonymized data
  • Security artefacts and documentation submitted as evidence against ITSG controls — such as security policies, system descriptions, test results, and control implementation statements. The register states no personal information is involved.
Run by
Shared Services Canada (SSC)
Where
No fixed location
Kept
Not stated by the Helpful Places.
Shared with
Accountable organization
Your copy
You cannot see the data it holds about you. What you can do

What it is for

Turbo SA/A is a generative AI tool that helps Government of Canada security assessors evaluate evidence against IT security controls. It uses retrieval-augmented generation to surface relevant guidance from security documentation, reducing manual effort in the assessment process. The system is currently in development and is used only by GC employees — it does not directly affect members of the public. Users are not currently informed that AI is involved in the process.

What it collects and what happens to it

Data taken in

Operational data
Anonymized data
  • Security artefacts and documentation submitted as evidence against ITSG controls — such as security policies, system descriptions, test results, and control implementation statements. The register states no personal information is involved.

Processing

Language Models
  • The system uses large language models (LLMs) delivered via the Government of Canada's CANchat platform, combining retrieval-augmented generation with generative AI to process and reason over security documentation.
Search & Retrieval
  • Retrieval-augmented generation (RAG) component searches and retrieves relevant passages from a corpus of security artefacts and ITSG control documentation to ground the generative AI responses.

What it does

Deciding (Analytical AI)
Human decides
  • The system scores and assesses security evidence against ITSG controls, surfacing relevant findings and assessments to human security assessors who make final determinations.
Creating (Generative AI)
Human decides
  • Uses generative AI (via the CANchat platform) to produce assessment narratives and synthesize findings from security documentation for review by human assessors.
Understanding (Semantic AI)
Human decides
  • Retrieval-augmented generation (RAG) retrieves and matches relevant passages from security artefacts and documentation to the specific ITSG control being assessed.

Outputs

A recommendation or prediction
Anonymized data
  • The system produces assessment recommendations and synthesized findings that suggest how well evidence satisfies each ITSG control, for review and decision by a human security assessor.

Run by

Shared Services Canada (SSC)
  • Shared Services Canada is the federal department that owns and deploys the Turbo SA/A system to support security assessment processes within the Government of Canada.

Government of Canada AI Register — Turbo SA/A

Built by

Government of Canada
  • The underlying AI capability is provided through CANchat, a Government of Canada internal generative AI platform that supplies the language model and retrieval-augmented generation infrastructure used by Turbo SA/A.

Government of Canada AI Register — Turbo SA/A

Kept for

Not stated by the Helpful Places.

Shared with

Not available to me
  • The system processes government security documentation and produces outputs accessible only to GC security assessors. No mechanism for public access to system outputs is described.
Available to the accountable organization
  • Outputs are available to Shared Services Canada and the GC employees conducting security assessments using the system.

Stored

Not stated by the Helpful Places.

How to read the colours

Can it identify you?

Anonymized data
Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
Pseudonymous data
Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
Identifiable data
The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.

Who completes the loop?

Human decides
This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
Human executes
This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
Autonomous
This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.

Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.

What you can do

Ask about this system

Questions go to the Helpful Places, not the vendor.

Your rights

  • Right to Be Informed of AI UseThe register discloses that AI use is NOT currently communicated to users of this system. GC employees using this tool may not be aware AI is involved in generating assessment outputs. This represents a transparency gap that should be addressed before broader deployment.
  • Right to Algorithmic TransparencyAs this system is in development and deployed to GC employees, users have a right to understand how the AI generates its security assessment recommendations, including the role of RAG in grounding outputs in source documentation.

Risks and safeguards

  • Reputational harmThe system may produce inaccurate or misleading assessments of security evidence, potentially leading to incorrect security authorization decisions for government IT systems, with reputational and operational consequences.Safeguard: Human assessors review all AI-generated outputs before decisions are finalized; the system is advisory only (human decides autonomy level).
  • Societal & cultural harmLack of AI use disclosure to GC employee users (as noted in the register) undermines informed consent and institutional trust in AI-assisted decision-making.Safeguard: The system is still in development; transparency mechanisms should be implemented before wider rollout, aligned with the Government of Canada's Directive on Automated Decision-Making.