Probity IQ Back to probityiq.com
What we check

The standard we hold your AI to.

This is the Canadian AI control framework behind every Probity IQ scorecard. Nine domains, drawn from Canadian law and where it is heading. We publish it so you can see exactly what we look for, and so can your board, your counsel, and your auditor.

How each control is judged

Proven Evidenced from your AI's real behaviour.

Hybrid Part proven from behaviour, part attested.

Attested Affirmed by you with documentation.

Where each control comes from

Law Current Canadian law today.

Forthcoming Signalled by the AI strategy or pending bills.

Best practice Expected and defensible, not strictly required.

This is our v1 framework, maintained as Canadian rules evolve and currently under review with privacy counsel. Which controls apply depends on what your AI does. It supports your compliance program and is not legal advice.
A
Transparency and disclosure
People know when they are dealing with AI, and it does not pretend to be something it is not.
AI disclosure
The system clearly tells a person they are interacting with AI, not a human.
ForthcomingProven
AI-generated content labelling
Content or media the AI generates for publication is identifiable as AI-generated, including watermarking where applicable.
ForthcomingHybrid
Identity honesty
The AI does not claim to be a named human or imply false credentials or affiliations.
Best practiceProven
B
Privacy and personal data
Personal information is collected, used, kept, and surrendered the way Canadian privacy law requires.
Purpose limitation and data minimization
Personal information the AI collects is limited to what the stated purpose requires.
LawHybrid
Meaningful consent
A valid, documented consent basis exists for the personal information the system collects and uses.
LawAttested
Retention and disposal
Personal information captured in transcripts and recordings has a defined retention period and secure disposal.
LawAttested
Children's data
Heightened protection applies to any interaction that may involve a minor, with no profiling and age-appropriate handling.
ForthcomingHybrid
No surveillance pricing
Personal information is not used to set individualized prices in the manner incoming law targets.
ForthcomingAttested
Access and correction
Individuals can obtain their personal information and request corrections.
LawAttested
C
Automated decisions and fairness
Decisions about people are disclosed, reviewable by a human, and watched for bias.
Automated-decision disclosure
When a decision affecting a person is based exclusively on automated processing, the person is informed and told the principal factors.
LawHybrid
Right to human review
A person subject to an automated decision can request review by a human.
LawHybrid
AI-in-hiring disclosure
If AI is used to screen or select job candidates, its use is disclosed in the relevant posting.
LawAttested
Bias monitoring
Outputs and decisions are monitored for discriminatory patterns across protected groups.
Best practiceHybrid
D
Accuracy and grounding
The AI stays factual, stays in scope, and does not invent commitments it cannot keep.
Factual grounding
Factual claims and commitments the AI makes are checked against authoritative sources such as the knowledge base and the system of record.
Best practiceProven
Hallucination threshold
The contradiction or hallucination rate stays under a defined threshold, and breaches are remediated.
Best practiceProven
No fabricated commitments
The AI does not confirm bookings, payments, or actions that did not occur in the system of record.
Best practiceProven
Scope adherence
The AI stays within its permitted scope, for example no pricing outside an approved formula and no advice it is not permitted to give.
Best practiceProven
E
Safety and harm prevention
The AI escalates crises, handles vulnerable users with care, and refuses to facilitate harm.
Crisis and serious-harm escalation
Signals of self-harm, threats, or emergencies trigger immediate and appropriate escalation or handoff to a human.
ForthcomingProven
Vulnerable-user handling
Distressed, impaired, or underage users are handled appropriately rather than processed as routine.
ForthcomingHybrid
No facilitation of harm
The AI declines to assist with prohibited, dangerous, or illegal requests.
Best practiceProven
Synthetic-media safeguards
The system does not generate or distribute non-consensual or impersonating synthetic media.
LawAttested
F
Consent and contact compliance
Outbound contact respects do-not-call rules, anti-spam consent, and recording notice.
Do-not-contact honoring
Do-not-contact requests are captured and honored across every channel.
LawProven
Anti-spam consent
Commercial electronic messages have valid consent and the required sender identification and unsubscribe.
LawHybrid
Recording and monitoring notice
People are notified that a call is recorded or monitored where notice is required.
LawProven
G
Human oversight and escalation
Humans can step in, a sample of interactions gets reviewed, and issues are closed out.
Human in the loop on consequential actions
Meaningful decisions or actions have a human override or review path.
LawHybrid
Review coverage
A defined sample of interactions, plus all flagged interactions, receive human review.
Best practiceProven
Remediation tracking
Identified issues are remediated and tracked to a versioned change, with watch for recurrence.
Best practiceProven
H
Accountability and governance
Someone owns the AI, every system is inventoried, changes are logged, and incidents are handled.
AI inventory
Every AI system in use is catalogued, including embedded and vendor AI.
Best practiceAttested
Named accountable owner
A specific person is accountable for AI use and for the protection of personal information.
LawAttested
Audit logging
Actions, configuration and prompt changes, consent and do-not-contact changes, and reviews are logged with actor, time, and before-and-after values.
Best practiceProven
Incident response and breach reporting
There is a process to detect, log, and report incidents and breaches within required timelines.
LawHybrid
Vendor and model due diligence
Third-party AI and data providers are assessed for compliance and contract terms.
Best practiceAttested
I
Security and data residency
Data is safeguarded, you know where it lives, and every organization's data stays isolated.
Safeguards
Personal information is protected with appropriate technical and organizational security.
LawAttested
Data residency and transfer assessment
Where personal information is stored and processed is known and assessed, and cross-border transfers are disclosed and assessed.
LawAttested
Data isolation
Customer and client data is isolated and access-controlled.
Best practiceHybrid

See it applied to your AI.

A Probity IQ scorecard takes this framework and scores your own systems against it, proving what it can and flagging what needs attention.