See the whole path
The official checkpoints of a digital service
A worked example of the official checkpoints, the approvals, reviews, and sign-offs a Government of Canada service has to pass through, from the first problem definition all the way to retiring or replacing it, and who owns each one.
Meet Nadia, a director general
Her grants program has outgrown its spreadsheets, so she is buying a grants management system. Her project scores below her department's threshold, so it stays inside the department: no Treasury Board submission and no GC EARB. That is the ordinary case, roughly 95% of projects. Where a bigger project would branch upward is shown in the amber boxes.
Why G&Cs is the example
This journey is built around a grants and contributions system because it is a useful worked case: it touches almost every checkpoint at once - public money, procurement, a security authorization, personal information, records, and a decision made about people. The guide as a whole is not limited to G&Cs; any service can be mapped through the same path.
Left is what Nadia does.
Right is who answers, and how. The tag on each response says whether the responder is her department or a central.
Why the Create phase fills most of this table
The official checkpoints are front-loaded. Almost every formal approval, review, and sign-off happens before launch, so Create carries most of the rows. Live and Sunset look shorter here only because this table follows the checkpoints, not because there is less to do in them.
What this map covers
It is an overview of the official checkpoints only, the formal approvals, reviews, and sign-offs, laid out across the whole journey from the first problem to retiring or replacing the service. It is not the whole journey, and it does not tell Nadia how to do the work inside each step. That detail lives in the phase and sub-phase documents. This is the map of the checkpoints she has to pass through; the people she talks to give her the rest.
Funded from the department's existing operating budget. This is where the path is decided. Nadia has spotted a problem. Discovery is where she works out how serious it is, who needs to be brought in, and which path the project should take.
Notices the program is breaking.
Applications have doubled, her team cannot keep up, applicants cannot track anything, and auditors cannot verify decisions. She decides something has to change.
This is her problem to raise. The guide's point: she already owns a digital service, whether she calls it that or not.
Calls her own department's corporate services.
Asks, plainly, "where do I start?"
The enabling branches walk her through it and point her on:
- the CIO or IT office
- finance
- procurement
- security
- the privacy (ATIP) office
- records
If anything later needs a central agency, her department is the one that takes it there.
Pulls together a small team to look into it.
She cannot do this alone, and she is not meant to.
Some from her own program who know the work, and, through the CIO or IT office, a business analyst and often a project manager from the departmental project-management office. The team is small in Discovery and grows through Beta as the build and the supplier's people come on. Nadia sponsors it; she does not do the hands-on work herself.
Writes up the need and gets it onto the plan.
A short concept case describing the problem and roughly what it would take.
They add the initiative to the departmental plan and the departmental investment plan (approved by the deputy head). She feeds the initiative in; she does not update those plans herself.
Gets the project sized, risk-rated, and costed.
How big is this really, and how risky?
It helps her team complete the Project Complexity and Risk Assessment (PCRA), a detailed multi-section questionnaire (how this is organized varies by department).
- the deputy head is accountable for an accurate score
- that score is compared against the department's approved project-management capacity class (set by an Organizational Project Management Capacity Assessment)
Asks the IT office whether anything on the GC shelf already does what she needs.
Reuse comes first in GC policy. She is not the one who searches; she is the one who decides.
They check:
- the GC Reference Architectures and the enterprise solutions catalogue (on the GC network)
- the Enterprise Architecture Community of Practice
- Shared Services Canada
If a fit exists, Nadia adopts it instead of buying.
Gets the build budget committed.
A budget outline, not the full picture. This covers getting from here to launch.
Her director commits the budget to proceed - from the department's existing funds, through the department's own governance. No Treasury Board submission. This covers Discovery, Alpha, and the Beta build.
The money to run it year after year (the operational budget) is different: that is set through the Estimates process once the service is Live. She should flag the expected operating cost now, even though the formal approval comes later. If the department has not thought about ongoing funding by Discovery, it is much harder to secure it after launch.
Common gap: teams plan the build cost carefully and treat the operational budget as someone else's problem. It is not - if the funding to run the service is not committed in principle by the time Beta starts, the service risks launching with no plan for what comes next.The service goes live here. Everything above is Create (the build); everything below is Live and Sunset (running it, then retiring or replacing it).
People in this journey
The people and bodies that appear in the tables above, and what role they play.
- The users
- The people the service is for, inside or outside government. They are present at every step: research in Discovery, testing in Alpha and Beta, and the feedback and support of the live service.
- Business owner of the application
- The person accountable for the service from before it exists until after it is switched off. Owns the decisions, the money, and the assessments; reaches every other player on this list through corporate services.
- Corporate services
- The department's enabling branches: CIO/IT office, finance, procurement, security, ATIP (privacy), records. The business owner's first stop, and where the contracting authority sits.
- Departmental project-management office
- Helps the sponsor complete the PCRA, cost and score the project, and line up a project manager. How this is organized varies by department; the deputy head is accountable for the score.
- DARB
- Departmental Architecture Review Board. Inside the department, chaired by the departmental CIO. Reviews the design.
- GC EARB
- Government of Canada Enterprise Architecture Review Board. Government-wide, co-chaired by the CTO of Canada (TBS) and the CTO of Shared Services Canada. Only for large or complex projects.
- Contracting authority
- The procurement officer, in the department's contracting branch (or PSPC above the department's limit), who runs the competition and signs the contract. Not the business owner, who reaches them through corporate services.
- Authorizing official
- The senior departmental executive who signs the Authority to Operate, accepting the residual IT (cyber) security risk.
- ATIP / privacy office
- Supports the program in completing the Privacy Impact Assessment, coordinates with the Office of the Privacy Commissioner and TBS, and handles the Personal Information Bank registration. The program area owns the assessment.
- Service management function
- Whoever owns the service inventory in your department (the name varies). Records the service in the departmental and GC Service Inventory and in Application Portfolio Management, and updates it when the service retires.
- Information management office
- Holds the disposition authorities. Records cannot be destroyed without Library and Archives Canada's written consent.
Official checkpoints, by phase
Every formal approval, review, or sign-off named in the tables. Checkpoints with an official home are linked.
- Concept case
- A short write-up of the problem and rough size, used to get the initiative onto the departmental plan. Below the threshold it is an internal document with no standard template. Above it, the concept case is mandatory, approved at assistant deputy minister level or higher, and reviewed by the Chief Information Officer of Canada at the Treasury Board of Canada Secretariat. The threshold is $2.5 million where the department has no approved capacity class or class 1, $5 million at class 2, $10 million at class 3, $15 million for National Defence, and $25 million at class 4.
- Departmental investment plan
- The department's list of planned investments, approved by the deputy head. A project has to be on it before it can proceed.
- PCRA - Project Complexity and Risk Assessment
- A detailed questionnaire that rates how big and risky a project is. The score is compared against the department's approved capacity class to decide the path.
- Capacity class (OPMCA)
- The department's approved project-management capacity, set by an Organizational Project Management Capacity Assessment. If the PCRA level is above it, or the project's value exceeds the department's delegated limit, the project needs Treasury Board approval.
- Reuse / options check
- Checking the GC shelf - the GC Reference Architectures and enterprise or shared solutions catalogues - before buying or building. GC policy expects reuse where possible, and the architecture review looks for it.
- Treasury Board submission
- The small-minority path: formal approval and expenditure authority from Treasury Board, needed when a project's PCRA level exceeds the department's capacity class, or its value exceeds the department's delegated limit, or Treasury Board otherwise requires it. Can add six to twelve months or more.
- DARB - Departmental Architecture Review Board
- Architecture review inside the department, chaired by the departmental CIO. Confirms the design lines up with GC standards. For Nadia's size of project, this is where architecture review stops.
- GC EARB - Government of Canada Enterprise Architecture Review Board
- Government-wide review for large or complex projects only: above investment or capacity thresholds, using emerging technology, needing a policy exception, or running on non-public cloud. Nadia does not go here.
- Procurement / contract
- The competition and award, run by the contracting authority under the Directive on the Management of Procurement. The contracting authority signs; Nadia does not.
- Contract Security Program
- PSPC screening of the supplier's organization and personnel when the contract involves protected or classified information.
- Accessibility Conformance Report
- The supplier's statement of how accessible a specific version of the product is, tested against EN 301 549 (which includes WCAG 2.1 AA). Covers one version only - re-check on every significant update.
- Departmental accessibility statement
- Required by the amended Accessible Canada Regulations, phasing in from December 2027. The department publishes it, and one statement can cover many services. It reports where the ICT accessibility standard is not met and how to get help or an alternative; each service's testing results feed it.
- Security Assessment and Authorization → Authority to Operate
- The IT security team runs the assessment, then a senior departmental executive signs the Authority to Operate, accepting the residual security risk. Required before the system goes live.
- Privacy Impact Assessment
- The assessment of privacy risk for a service that handles personal information, completed by the program area with ATIP support, and sent to the Office of the Privacy Commissioner and TBS before launch.
- Personal Information Bank
- The registered description of the personal information the service holds, published in the department's Info Source listing. Created alongside the Privacy Impact Assessment.
- Algorithmic Impact Assessment
- Required only if a decision about a person is automated, under the Directive on Automated Decision-Making. Nadia's adjudicators decide by hand, so this checkpoint does not apply - but a later "efficiency" feature can quietly trigger it.
- Project close-out (benefits realization)
- The formal end of the funded project: confirm what was delivered, release the remaining budget, and track whether the promised benefits arrive. Required by the Directive on the Management of Projects and Programmes; the project office files it.
- GC Service Inventory + Application Portfolio Management
- The two registries a live service must be listed and rated in, approved by the deputy head and updated yearly. The CIO office does the registering; Nadia supplies the details.
- Disposition authority
- Library and Archives Canada's written consent to keep, transfer, or destroy a government record. No record may be destroyed without it. The real Sunset checkpoint.
Departmental mechanics and timelines vary; confirm against your own department before treating any step as fixed.
Nadia is invented, and so is her program. Any resemblance to real persons or programs is coincidental.