Systems are not within scope when they:
automate calculations
implement straightforward criteria as defined in laws or regulations
follow legislatively defined rules in a manner that does not replace judgment
An example of a system that does not fall in scope is one that limits eligibility of a program to those 18 years of age or above when this is a clear requirement under the regulation.
The directive applies only to systems that will be deployed or are in production.
Research and experimentation are out of scope of the directive so that the requirements of the directive do not unduly burden researchers or discourage exploration of technological capabilities in the federal government.
Deployment of systems in scope of the directive
Systems are considered in production when they are in use and have impacts on real clients, such as when they are:
fully deployed in a production environment to support departmental operations
deployed in a production environment at a smaller scale, such as in a pilot (including beta testing and client experience testing) where outputs contribute to decisions that impact some clients
Deployment of systems outside the scope of the directive
Systems are not in scope when they are used solely for research and experimentation purposes and are not intended to be used to automate operations, such as when they are:
run on sample data as part of the development, testing or proof of concept phases
being explored in a test environment, sandbox or research lab where results are not used in decisions that impact real clients
Although systems used solely for research and experimentation purposes do not fall within the scope of this directive, there are other requirements that must still be followed, such as those relating to privacy, security, information management, and values and ethics.
Ensuring compliance
When departments develop and test systems that will fall within the scope of the directive, they must plan for compliance with the directive. They should become aware of the requirements of the directive and take steps to meet them.
For example, departments should test not only the functionality, efficacy, security and validity of the system, but also the mitigation measures that address risks identified from early AIAs, privacy impact assessments, security assessments, GBA Plus and so on.
Examples of system activities that are in or out of scope of the directive
Triaging client applications based on their complexity as determined through machine-defined criteria
Examining a financial transaction to estimate the probability of fraud
Generating an assessment, score or classification about the client
Generating a summary of relevant client information for officers to determine eligibility to a program
Presenting information from multiple sources to an officer (such as by data matching and fuzzy matching)
Using facial recognition or other biometric technology to target subjects for additional scrutiny