Abdul Wahab
September 2026 AI Governance 6 min read

What the Directive on Automated Decision-Making actually requires of front-line officers

A front-line look at Canada's Directive on Automated Decision-Making, and what it actually asks of the officers applying it.

#AI Governance #Administrative Discretion #CRA #Automated Decision-Making

Most commentary on Canada's Directive on Automated Decision-Making is written from outside the systems it governs — by policy analysts, academics, and journalists reading the document cold. That is valuable work. It is also a fundamentally different vantage point from the one you get sitting at a desk that has to apply it.

The Directive sets out impact levels, algorithmic impact assessments (AIAs), and notice requirements. On paper, it reads like an orderly compliance checklist. In practice, the more interesting question is what happens in the gap between an automated recommendation and the officer who still has to sign off on it.

The recommendation is not the decision

Automated systems in government are almost never fully autonomous — they flag, score, or recommend, and a person is still accountable for the outcome. That accountability structure is the part the Directive gets right, but it also means the burden of judgment does not disappear. It moves.

> The hardest part of working alongside an automated system isn't distrusting it. It's knowing exactly when to.

Front-line officers develop informal heuristics for this — patterns in when a system's output tends to be reliable, and when it needs a second look. None of that shows up in the Directive's formal text, but it is arguably where the real governance happens.

Accountability and the evidentiary trail

Under administrative law principles, reasons for a decision must be transparent, justifiable, and intelligible. When an algorithmic tool assigns a risk tier to a taxpayer relief application or non-filer file, the decision maker cannot simply point to the system score as evidence. The officer remains statutory master of the file.

In formal terms, if an automated risk scoring model computes an eligibility risk score $R(\mathbf{x})$ parameterized by feature weights $\mathbf{w}$ and evidentiary vectors $\mathbf{x}$:

$$
R(\mathbf{x}) = \sigma\left(\sum_{j=1}^m w_j x_j + b\right) = \frac{1}{1 + e^{-(\mathbf{w}^T \mathbf{x} + b)}}
$$

the resulting score $R(\mathbf{x}) \in [0, 1]$ cannot substitute for statutory reasoning.[^1] If the officer cannot explain how the data inputs generated the output, the determination risks judicial review vulnerability on grounds of procedural fairness.

[^1]: Under administrative law principles established in Baker v. Canada (Minister of Citizenship and Immigration), [1999] 2 S.C.R. 817, statutory decision-makers must provide transparent and intelligible reasons reflecting their own independent assessment.

What this means for information policy research

If we only study these directives as abstract normative documents, we miss the operational layer where they are actually enforced or quietly reinterpreted. My own research at the UWM School of Information Studies tries to sit in that gap — treating front-line practice as a primary source, not just an implementation afterthought.

By Roby A. Wahab • UWM SOIS & CRA Appeals