Date of Publishing:
HTML Version Coming Soon
Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!
Date of Publishing:
Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!
A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Survey of the Canadian Security Intelligence Service (CSIS)’s Technical Capabilities was recently released under the Access to Information Act.
CSIS uses technical capabilities to support its investigations into threats to Canada’s security. As national security threats become increasingly technically enabled, CSIS must ensure its technical capabilities, governance structures, and legal frameworks continue to evolve while protecting Canadians’ rights and privacy.
The survey provided NSIRA with a foundational understanding of CSIS’s technical capabilities, how they are governed, and the risks associated with their use. Its observation also helped inform NSIRA’s first technology-focused review, CSIS Lifecycle of Warranted Information.
NSIRA reviews CSIS’s activities for compliance with the law and whether they are reasonable and necessary. To do this effectively, NSIRA must understand the technologies CSIS uses and how they affect intelligence collection.
This review helped NSIRA identify areas where additional review may be needed, particularly for higher-risk technologies involving advanced collection methods, large amounts of data, or where collection incidentally occurs from people who are not the subject of an investigation.
Technical capabilities can support important national security work, but their use may also affect privacy and other rights. CSIS activities are governed by legislation and Federal Court warrants, which set limits on how information can be collected.
Because technology changes quickly, independent review helps ensure that CSIS’s use of these capabilities remains lawful, reasonable, and necessary.
NSIRA found several areas where CSIS could strengthen the management of technical capabilities:
NSIRA recommended that CSIS share the full, unredacted version of the report with designated judges of the Federal Court. CSIS agreed to this recommendation.
The knowledge gained through this survey continues to help guide NSIRA’s reviews of CSIS’s use of technical capabilities, including higher-risk technologies and activities requiring further review. It remains a valuable resource for identifying areas of greater risk and helping NSIRA prioritize future review work.
Date of Publishing:
Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!
A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) annual review, Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act (ACA) for 2023: Mitigation and Armed Conflict, was recently released under the Access to Information Act.
The NSIRA Act requires NSIRA to annually review the implementation of all directions issued under the ACA.
NSIRA’s 2023 review examined how departments assessed the risk of mistreatment when sharing information with foreign entities. The review examined several instances of information sharing, including situations involving complex security environments and armed conflicts.
NSIRA identified areas where departments can improve their risk assessments, record-keeping, and use of safeguards before sharing information. The review also identified examples where departments determined that information should not be shared because the risks could not be addressed.
Under the ACA, departments cannot share information with, or use information from, a foreign entity when doing so would create a substantial risk that an individual could be mistreated.
Before sharing information, departments must assess potential risks and take steps to address them. If the risk cannot be mitigated, the information cannot be shared.
Departments must also maintain records showing how these requirements were considered when making information-sharing decisions.
NSIRA identified several areas where departments can strengthen their implementation of the ACA, including:
NSIRA also noted that operational needs or relationships with foreign entities do not replace the requirement to address the risk of mistreatment.
NSIRA reviewed information-sharing activities involving several federal departments and agencies.
The review identified concerns related to the assessment and documentation of risks by the Canadian Security Intelligence Service (CSIS), the Royal Canadian Mounted Police (RCMP), Immigration, Refugees and Citizenship Canada (IRCC), and Global Affairs Canada (GAC).
NSIRA also identified an example where the Department of National Defence (DND) and the Canadian Armed Forces (CAF) determined that information should not be shared because the risks could not be addressed.
NSIRA made two recommendations to strengthen compliance with the ACA, including improvements to risk assessments, documentation, and information-sharing practices.
Using its authority under section 31 of the NSIRA Act, NSIRA also required CSIS, DND/CAF, GAC, IRCC, and the RCMP to conduct a study of information sharing with foreign entities from countries engaged in armed conflict.
The study examined challenges in applying the Ministerial Directions and identified potential gaps in the ACA framework. The departments provided a report on the study to the appropriate Minister and submitted a copy to NSIRA in 2026, as required under the Act.
A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Annual Review of Select Canadian Security Intelligence Service (CSIS) Activities (ARSCA), 2024, was previously released under the Access to Information Act.
Under the CSIS Act, CSIS is required to provide NSIRA with information related to seven categories of CSIS activities. NSIRA reviews this information as part of its mandate to assess whether CSIS activities are carried out in accordance with Canadian law, Ministerial Direction, and internal policies.
In addition to reviewing the information CSIS is required by statute to provide, NSIRA examined a range of CSIS activities and identified trends and issues related to governance, accountability, information management, and operational processes.
As part of the review, NSIRA also followed up on issues and recommendations identified in previous reviews. This included a technical inspection involving datasets, where NSIRA confirmed that CSIS had deleted certain datasets in line with an earlier NSIRA recommendation.
Key observations
The review identified several areas where additional work or improvements may be needed, including:
As part of the review, NSIRA issued a compliance report under section 35 of the NSIRA Act concerning reporting obligations under section 20(2) of the CSIS Act. NSIRA found that CSIS may not have acted in compliance with the law when it failed to submit reports regarding potentially unlawful conduct by CSIS employees, including possible Charter-related violations, to the Minister. However, the review also noted that, in 2025, the CSIS Director approved a memorandum endorsing a broader interpretation of the reporting requirements of the CSIS Act and that NSIRA expects to see implementation of the required reporting.
Moreover, the review examined CSIS’s first use of a court-authorized Threat Reduction Measure in 2024 and recommended that CSIS establish a formal approval process for these measures.
Next steps
NSIRA made six recommendations aimed at strengthening accountability, improving reporting practices, updating policies, and supporting privacy protections.
NSIRA stated that it will continue monitoring these issues and may undertake additional targeted reviews in the future.
Date of Publishing:
Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!
Form 16
Form 17
Form 18
Form 1302
Form 1009
Form 1301
Form
Form 1200
Form 800
If NSIRA determines that the subject of the complaint falls within its mandate to investigate, NSIRA will proceed with its investigation by reviewing documentary evidence, conducting investigative interviews of the complainant and witnesses identified by the parties and/or conducting an oral or written hearing on some or all of the issues of the complaint.
Once NSIRA’s investigation is completed, it will prepare a report with its findings and/or recommendations. A declassified copy of the final report will be sent to the complainant. A declassified and depersonalized version of the final report will be published on NSIRA’s website.
A complaint made to NSIRA, including a referral from the CRCC, can be informally resolved if the complainant and responding department consent.
The purpose of an informal resolution is to resolve some or all of the issues in a complaint. An informal resolution may take the form of any number of remedial actions and has several benefits. The goal is to provide an opportunity for the parties to gain a better understanding of the situation that gave rise to the complaint and to provide them with an opportunity to deal with the complaint expeditiously and to the satisfaction of all parties.
If the complaint is resolved informally, the terms of the informal resolution must be set out in writing and signed by all parties. A party or the NSIRA Member assigned to the investigation of the complaint may, at any time, request a resolution meeting between the parties. In the event that a complaint cannot be resolved informally, the merits of the complaint will be investigated by a different NSIRA Member.