Language selection

Government of Canada / Gouvernement du Canada

Search


Survey of Canadian Security Intelligence Service Technical Capabilities: Report

Survey of Canadian Security Intelligence Service Technical Capabilities


Report

Table of Contents

Date of Publishing:

HTML Version Coming Soon

Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!

Share this page
Date Modified:

Survey of Canadian Security Intelligence Service Technical Capabilities: Backgrounder

Survey of Canadian Security Intelligence Service Technical Capabilities


Backgrounder

Backgrounder

A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Survey of the Canadian Security Intelligence Service (CSIS)’s Technical Capabilities was recently released under the Access to Information Act.

CSIS uses technical capabilities to support its investigations into threats to Canada’s security. As national security threats become increasingly technically enabled, CSIS must ensure its technical capabilities, governance structures, and legal frameworks continue to evolve while protecting Canadians’ rights and privacy.

The survey provided NSIRA with a foundational understanding of CSIS’s technical capabilities, how they are governed, and the risks associated with their use. Its observation also helped inform NSIRA’s first technology-focused review, CSIS Lifecycle of Warranted Information.

Why NSIRA conducted this review

NSIRA reviews CSIS’s activities for compliance with the law and whether they are reasonable and necessary. To do this effectively, NSIRA must understand the technologies CSIS uses and how they affect intelligence collection.

This review helped NSIRA identify areas where additional review may be needed, particularly for higher-risk technologies involving advanced collection methods, large amounts of data, or where collection incidentally occurs from people who are not the subject of an investigation.

Why this matters to Canadians

Technical capabilities can support important national security work, but their use may also affect privacy and other rights. CSIS activities are governed by legislation and Federal Court warrants, which set limits on how information can be collected.

Because technology changes quickly, independent review helps ensure that CSIS’s use of these capabilities remains lawful, reasonable, and necessary.

Key observations

NSIRA found several areas where CSIS could strengthen the management of technical capabilities:

  • Policies and guidance needed updating. Outdated policies and reliance on interim direction increased compliance risks.
  • Compliance responsibilities required stronger coordination. A decentralized approach created challenges in maintaining a complete view of compliance risks.
  • External technologies created additional risks. The use of partner or third-party technologies can make it more difficult to assess privacy, security, and compliance considerations.
  • Performance measurement needed improvement. CSIS lacked a consistent way to assess the effectiveness and value of its technical capabilities.
  • Tracking of warrant details within operations should be strengthened. NSIRA found that CSIS should strengthen its documentation of activities conducted under Federal Court warrants to better demonstrate compliance with the limits and conditions set by the Court.

Recommendation and Next steps

NSIRA recommended that CSIS share the full, unredacted version of the report with designated judges of the Federal Court. CSIS agreed to this recommendation.

The knowledge gained through this survey continues to help guide NSIRA’s reviews of CSIS’s use of technical capabilities, including higher-risk technologies and activities requiring further review. It remains a valuable resource for identifying areas of greater risk and helping NSIRA prioritize future review work.  

Share this page
Date Modified:

Review of Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act for 2023: Report

Review of Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act for 2023


Report

Table of Contents

Date of Publishing:

HTML Version Coming Soon

Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!

Share this page
Date Modified:

Review of Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act for 2023: Backgrounder

Review of Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act for 2023


Backgrounder

Backgrounder

A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) annual review, Departmental Implementation of the Avoiding Complicity in Mistreatment by Foreign Entities Act (ACA) for 2023: Mitigation and Armed Conflict, was recently released under the Access to Information Act.

The NSIRA Act requires NSIRA to annually review the implementation of all directions issued under the ACA.

NSIRA’s 2023 review examined how departments assessed the risk of mistreatment when sharing information with foreign entities. The review examined several instances of information sharing, including situations involving complex security environments and armed conflicts. 

NSIRA identified areas where departments can improve their risk assessments, record-keeping, and use of safeguards before sharing information. The review also identified examples where departments determined that information should not be shared because the risks could not be addressed.

Protecting against mistreatment

Under the ACA, departments cannot share information with, or use information from, a foreign entity when doing so would create a substantial risk that an individual could be mistreated.

Before sharing information, departments must assess potential risks and take steps to address them. If the risk cannot be mitigated, the information cannot be shared.

Departments must also maintain records showing how these requirements were considered when making information-sharing decisions.

Key findings

NSIRA identified several areas where departments can strengthen their implementation of the ACA, including:

  • improving risk assessments before information sharing;
  • documenting decisions and safeguards;
  • monitoring mitigation measures; and
  • maintaining records that demonstrate compliance.

NSIRA also noted that operational needs or relationships with foreign entities do not replace the requirement to address the risk of mistreatment.

Examples

NSIRA reviewed information-sharing activities involving several federal departments and agencies.

The review identified concerns related to the assessment and documentation of risks by the Canadian Security Intelligence Service (CSIS), the Royal Canadian Mounted Police (RCMP), Immigration, Refugees and Citizenship Canada (IRCC), and Global Affairs Canada (GAC).

NSIRA also identified an example where the Department of National Defence (DND) and the Canadian Armed Forces (CAF) determined that information should not be shared because the risks could not be addressed.

Recommendations and next steps

NSIRA made two recommendations to strengthen compliance with the ACA, including improvements to risk assessments, documentation, and information-sharing practices.

Using its authority under section 31 of the NSIRA Act, NSIRA also required CSIS, DND/CAF, GAC, IRCC, and the RCMP to conduct a study of information sharing with foreign entities from countries engaged in armed conflict.

The study examined challenges in applying the Ministerial Directions and identified potential gaps in the ACA framework. The departments provided a report on the study to the appropriate Minister and submitted a copy to NSIRA in 2026, as required under the Act.

Share this page
Date Modified:

Annual Review of Select Canadian Security Intelligence Service Activities, 2024: Backgrounder

Annual Review of Select Canadian Security Intelligence Service Activities, 2024


Backgrounder

Backgrounder

A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Annual Review of Select Canadian Security Intelligence Service (CSIS) Activities (ARSCA), 2024, was previously released under the Access to Information Act.

Under the CSIS Act, CSIS is required to provide NSIRA with information related to seven categories of CSIS activities. NSIRA reviews this information as part of its mandate to assess whether CSIS activities are carried out in accordance with Canadian law, Ministerial Direction, and internal policies.

In addition to reviewing the information CSIS is required by statute to provide, NSIRA examined a range of CSIS activities and identified trends and issues related to governance, accountability, information management, and operational processes.

As part of the review, NSIRA also followed up on issues and recommendations identified in previous reviews. This included a technical inspection involving datasets, where NSIRA confirmed that CSIS had deleted certain datasets in line with an earlier NSIRA recommendation.

Key observations

The review identified several areas where additional work or improvements may be needed, including:

  • how CSIS reports potentially unlawful conduct;
  • financial intelligence collection procedures and engagement with financial institutions;
  • how updated Ministerial Directions are reflected in CSIS policies.

As part of the review, NSIRA issued a compliance report under section 35 of the NSIRA Act concerning reporting obligations under section 20(2) of the CSIS Act. NSIRA found that CSIS may not have acted in compliance with the law when it failed to submit reports regarding potentially unlawful conduct by CSIS employees, including possible Charter-related violations, to the Minister. However, the review also noted that, in 2025, the CSIS Director approved a memorandum endorsing a broader interpretation of the reporting requirements of the CSIS Act and that NSIRA expects to see implementation of the required reporting.

Moreover, the review examined CSIS’s first use of a court-authorized Threat Reduction Measure in 2024 and recommended that CSIS establish a formal approval process for these measures.

Next steps

NSIRA made six recommendations aimed at strengthening accountability, improving reporting practices, updating policies, and supporting privacy protections.

NSIRA stated that it will continue monitoring these issues and may undertake additional targeted reviews in the future.

Share this page
Date Modified:

Annual Review of Select Canadian Security Intelligence Service Activities, 2024: Report

Annual Review of Select Canadian Security Intelligence Service Activities, 2024


Report

Table of Contents

Date of Publishing:

HTML Version Coming Soon

Our team is working on an HTML version of this content to enhance usability and compatibility across devices. We aim to make it available in the near future. Thank you for your patience!

Share this page
Date Modified:

Submissions

Submissions

Share this page
Date Modified:

NSIRA Complaint Forms

NSIRA Complaint Forms

Complaint against CSIS

Form 16

Complaint against CSE

Form 17

Complaint – Security Clearances

Form 18

Affidavit

Form 1302

Notice of Informal Resolution

Form 1009

Notice of Motion

Form 1301

Statement of Events

Form

Summary of Anticipated Evidence

Form 1200

Summons

Form 800

Share this page
Date Modified:

Make a Complaint

Make A Complaint


Complaints Process

If NSIRA determines that the subject of the complaint falls within its mandate to investigate, NSIRA will proceed with its investigation by reviewing documentary evidence, conducting investigative interviews of the complainant and witnesses identified by the parties and/or conducting an oral or written hearing on some or all of the issues of the complaint.

Once NSIRA’s investigation is completed, it will prepare a report with its findings and/or recommendations. A declassified copy of the final report will be sent to the complainant. A declassified and depersonalized version of the final report will be published on NSIRA’s website.

Informal Resolution

A complaint made to NSIRA, including a referral from the CRCC, can be informally resolved if the complainant and responding department consent.

The purpose of an informal resolution is to resolve some or all of the issues in a complaint. An informal resolution may take the form of any number of remedial actions and has several benefits. The goal is to provide an opportunity for the parties to gain a better understanding of the situation that gave rise to the complaint and to provide them with an opportunity to deal with the complaint expeditiously and to the satisfaction of all parties.

If the complaint is resolved informally, the terms of the informal resolution must be set out in writing and signed by all parties. A party or the NSIRA Member assigned to the investigation of the complaint may, at any time, request a resolution meeting between the parties. In the event that a complaint cannot be resolved informally, the merits of the complaint will be investigated by a different NSIRA Member.

Share this page
Date Modified: