AI-Assisted Security Assessment for IT Controls
Safety & Security
What it collects
- Security artefacts and documentation submitted as evidence against ITSG controls — such as security policies, system descriptions, test results, and control implementation statements. The register states no personal information is involved.
- Run by
- Shared Services Canada (SSC)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
Turbo SA/A is a generative AI tool that helps Government of Canada security assessors evaluate evidence against IT security controls. It uses retrieval-augmented generation to surface relevant guidance from security documentation, reducing manual effort in the assessment process. The system is currently in development and is used only by GC employees — it does not directly affect members of the public. Users are not currently informed that AI is involved in the process.
What it collects and what happens to it
Data taken in
- Security artefacts and documentation submitted as evidence against ITSG controls — such as security policies, system descriptions, test results, and control implementation statements. The register states no personal information is involved.
Processing
- The system uses large language models (LLMs) delivered via the Government of Canada's CANchat platform, combining retrieval-augmented generation with generative AI to process and reason over security documentation.
- Retrieval-augmented generation (RAG) component searches and retrieves relevant passages from a corpus of security artefacts and ITSG control documentation to ground the generative AI responses.
What it does
- The system scores and assesses security evidence against ITSG controls, surfacing relevant findings and assessments to human security assessors who make final determinations.
- Uses generative AI (via the CANchat platform) to produce assessment narratives and synthesize findings from security documentation for review by human assessors.
- Retrieval-augmented generation (RAG) retrieves and matches relevant passages from security artefacts and documentation to the specific ITSG control being assessed.
Outputs
- The system produces assessment recommendations and synthesized findings that suggest how well evidence satisfies each ITSG control, for review and decision by a human security assessor.
Run by
- Shared Services Canada is the federal department that owns and deploys the Turbo SA/A system to support security assessment processes within the Government of Canada.
Built by
- The underlying AI capability is provided through CANchat, a Government of Canada internal generative AI platform that supplies the language model and retrieval-augmented generation infrastructure used by Turbo SA/A.
Kept for
Not stated by the Helpful Places.
Shared with
- The system processes government security documentation and produces outputs accessible only to GC security assessors. No mechanism for public access to system outputs is described.
- Outputs are available to Shared Services Canada and the GC employees conducting security assessments using the system.
Stored
Not stated by the Helpful Places.
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada AI and Algorithmic Systems Register — Turbo SA/A (2526-SSC-SPC-005)Shared Services Canada, Government of Canada AI Register, entry 2526-SSC-SPC-005.
- AI registerGovernment of Canada AI Register — Turbo SA/A
- AI registerGovernment of Canada AI Register — Turbo SA/A
- Register entryPublished by the Helpful Places. Reference b38d79db. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseThe register discloses that AI use is NOT currently communicated to users of this system. GC employees using this tool may not be aware AI is involved in generating assessment outputs. This represents a transparency gap that should be addressed before broader deployment.
- Right to Algorithmic TransparencyAs this system is in development and deployed to GC employees, users have a right to understand how the AI generates its security assessment recommendations, including the role of RAG in grounding outputs in source documentation.
Risks and safeguards
- Reputational harmThe system may produce inaccurate or misleading assessments of security evidence, potentially leading to incorrect security authorization decisions for government IT systems, with reputational and operational consequences.Safeguard: Human assessors review all AI-generated outputs before decisions are finalized; the system is advisory only (human decides autonomy level).
- Societal & cultural harmLack of AI use disclosure to GC employee users (as noted in the register) undermines informed consent and institutional trust in AI-assisted decision-making.Safeguard: The system is still in development; transparency mechanisms should be implemented before wider rollout, aligned with the Government of Canada's Directive on Automated Decision-Making.