AI-Assisted Fraud Detection for Government Payments
Enforcement · Financial Services
What it collects that can identify you
- Historical Receiver General payment transaction records, hashed or pseudonymized where applicable, used to train and run the anomaly detection models.
Also collects operational data, which is anonymized data.
- Run by
- Public Services and Procurement Canada (PSPC)
- Where
- No fixed location
- Kept
- Retained Not specified in public register
- Shared with
- Accountable organization
- Your copy
- You cannot see the data it holds about you. What you can do
What it is for
This system automatically scores and ranks government payment transactions to detect anomalous or potentially fraudulent activity across federal payment streams managed by the Receiver General. It surfaces high-risk patterns for review by human analysts, who make final determinations. The system processes payment metadata including some pseudonymized personal information, and its outputs inform but do not replace human judgment.
What it collects and what happens to it
Data taken in
- Historical Receiver General payment transaction records, hashed or pseudonymized where applicable, used to train and run the anomaly detection models.
- Receiver General payment metadata, reference datasets, and business rules that define normal payment patterns and thresholds used by the fraud scoring models.
Processing
- Flags unusual payment events departing from a learned baseline of normal Receiver General transaction behavior; outputs thresholded risk scores rather than direct decisions.
- Scores and ranks individual transactions by fraud risk, classifying them into risk tiers to prioritize analyst workbench review and alerting.
What it does
- Scores and ranks payment transactions by risk level; human analysts review surfaced patterns and make final determinations on potentially fraudulent activity.
- Ingests and structures raw Receiver General payment metadata and historical transaction records as input to the scoring and anomaly detection pipeline.
Outputs
- Risk scores and rankings surfaced to the analyst workbench and alerting system; high-risk patterns are flagged for human review but no automated enforcement action is taken.
Run by
- Federal department responsible for deploying and operating this fraud detection system across Receiver General payment streams.
Built by
- The system was developed internally by the Government of Canada rather than procured from a commercial vendor.
Kept for
- Payment transaction records and model outputs are retained in accordance with Government of Canada records management requirements; specific retention periods are not disclosed in the public register entry.
- Duration: Not specified in public register
Shared with
- Output risk scores and flagged transaction patterns are available to GC employees (analysts) within Public Services and Procurement Canada for review and action.
- Individuals whose payment transactions are scored by the system do not have direct access to the risk scores or flags assigned to their transactions.
Stored
- As a federal government system handling sensitive payment data, storage is expected to be within Canadian jurisdiction consistent with Government of Canada data residency policies; specific storage details are not disclosed publicly.
- Duration: Not specified in public register
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerReceiver General – Fraud Detection (Payments) — Government of Canada Algorithmic Impact Assessment RegisterPublic Services and Procurement Canada, AI Register ID 2526-PSPC-SPAC-008.
- AI registerReceiver General – Fraud Detection (Payments)
- AI registerReceiver General – Fraud Detection (Payments)
- Register entryPublished by the Helpful Places. Reference e7515b15. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseIndividuals whose payment transactions are processed by this system have the right to be informed that AI is used in fraud detection for Receiver General payments. The Government of Canada publishes information about this system in the public AI Register.
- Right to Algorithmic TransparencyInformation about how this fraud detection system works is publicly available through the Government of Canada's AI Register. The system includes explainability features where feasible to support analyst understanding of its outputs.
- Right to a Human ReviewThe system's risk scores and flags are reviewed by human analysts before any action is taken. No automated enforcement decisions are made directly by the AI system; human judgment is required at every consequential step.
Risks and safeguards
- Financial & business harmRisk of false-positive fraud flags leading to wrongful suspension or delay of legitimate government payments to individuals or organizations. Mitigated by: human analyst review of all high-risk flags before any action is taken; explainability features where feasible to support analyst judgment; the system scores/ranks rather than makes binding decisions.
- Reputational harmRisk that individuals or organizations are incorrectly flagged as fraudulent, causing reputational damage through misclassification. Mitigated by: requiring human analyst review before any enforcement or communication; explainability features to support accurate decisions; pattern discovery outputs reviewed in context of business rules and reference datasets.