A redacted version of the National Security and Intelligence Review Agency’s (NSIRA) Review of the Canadian Security Intelligence Service’s (CSIS) Use of the Justification Framework (JF) was recently released under the Access to Information Act.
The JF, established under section 20.1 of the Canadian Security Intelligence Service Act (CSIS Act), allows designated CSIS employees, in limited circumstances, to commit or direct acts or omissions that would otherwise constitute offences under Canadian law while carrying out CSIS’s intelligence mandate.
NSIRA found that CSIS complied with the statutory limitations on use of the JF in all operations reviewed. However, it also identified several instances where CSIS may not have complied with other requirements of the CSIS Act, including requirements relating to designation, authorization, reporting and notification to NSIRA.
The JF gives CSIS exceptional authority to undertake activities that would otherwise be illegal. The JF therefore includes safeguards intended to ensure that this authority is exercised within the prescribed limits and remains subject to review and accountability.
NSIRA’s findings highlight the importance of ensuring that these safeguards are consistently followed, documented and reported.
Key observations
- Limits on prohibited conduct: CSIS complied with the limits on use of the framework JF in all operations reviewed.
- Designation: Some employees may have committed otherwise illegal acts without the required designation.
- Authorization: Some acts may have been directed without the authorization required by law.
- Documentation: Reasonableness and proportionality were not consistently documented as required by CSIS policy.
- Reporting: Some required internal reporting and notifications to NSIRA were not made.
- Public reporting: Annual reports for 2019–2022 were not published or made available when required.
Recommendation and Next steps
NSIRA recommended that CSIS strengthen its internal guidance, oversight and quality assurance to ensure that use of the Justification Framework complies with the CSIS Act and internal policy requirements.
The findings are based on a limited sample of operations and should not be interpreted as an assessment of every use of the Justification Framework by CSIS.