Every discussion of CRA audit risk eventually reaches a question business owners genuinely want answered: what makes them pick you? The honest answer has changed materially in the last several years, and it is now partly a question about statistical modelling rather than entirely a question about which boxes you ticked on a return.

Key Takeaway

The CRA's own 2025–26 Departmental Plan commits to improving its use of data, technology and business intelligence to more accurately and efficiently identify high-risk taxpayers, and states that data analytics and advanced risk assessment let it better identify and address high-risk aggressive tax planning. That is a primary-source, published commitment, not an inference. Separately, the CRA maintains that AI does not make final decisions about individual Canadians, with a spokesperson stating that all tax filings are reviewed and processed with human oversight and that AI does not determine audits, assessments, or benefit eligibility. Both are accurate, because they describe different stages: algorithmic risk scoring increasingly influences which files receive attention, while a human officer makes the resulting decisions. The practical consequence for a business owner is that being statistically unusual now carries more weight than it did, independent of whether anything is actually wrong.

What The CRA Has Actually Committed To In Writing

Rather than relying on practitioner inference, it is worth starting with the CRA's own published language. The Canada Revenue Agency's 2025–26 Departmental Plan states that the CRA focuses its compliance activities on groups at the highest risk of non-compliance, that it will continue to improve the use of data, technology and business intelligence to more accurately and efficiently identify high-risk taxpayers, and that using data analytics and advanced risk assessment, the CRA can better identify and address high-risk aggressive tax planning[1]. The same plan identifies the targets of these efforts as including tax avoidance in the wealthy population and promoters and advisors facilitating unacceptable arrangements[1].

This is a modest-sounding paragraph in a routine planning document, and it is the most authoritative available statement on the subject. It establishes three things without ambiguity: risk-based targeting is official policy, data analytics is the stated mechanism, and improving that capability is a forward commitment rather than a description of a completed project.

The CRA's Official Position On Human Oversight

The counterweight deserves equal prominence, because coverage of this topic frequently omits it. The CRA has been careful to maintain that AI does not make final decisions about individual Canadians, with a CRA spokesperson stating that all tax filings are reviewed and processed with human oversight, and that AI does not determine audits, assessments, or eligibility for benefits[2].

This is a meaningful commitment and should not be dismissed as public relations. It draws a line between algorithmic input and human decision that matters both administratively and legally, and it is consistent with how tax administration in Canada has traditionally been structured, with assessments and audits being exercises of statutory authority by officials rather than automated outputs.

Reconciling Selection With Decision

The apparent contradiction between "we use analytics to identify high-risk taxpayers" and "AI does not determine audits" resolves cleanly once you separate two stages that ordinary language collapses together.

Selection is the question of which files receive human attention at all. With millions of returns and finite audit capacity, some triage mechanism has always existed; what has changed is its sophistication. Practitioner commentary describes the CRA's capabilities as able to process millions of tax returns in seconds, analyzing large amounts of financial information to identify patterns difficult to detect manually, allowing resources to focus where the likelihood of error or non-compliance is considered higher[3].

Decision is what happens after a human officer opens the file: whether to audit, what to assess, whether penalties apply. This is where the CRA's human-oversight commitment operates.

Practitioner commentary characterizes the significance of the first stage bluntly, describing AI as playing a decisive, if opaque, role in the selection of taxpayers for audit, and noting that every Canadian who files is in some measure already being assessed by an automated system before a human officer ever opens the file[2]. That framing and the CRA's position are compatible. A model that never decides anything can still substantially determine who ends up in front of someone who does.

What Is Actually Being Analyzed

Practitioner reporting identifies specific focus areas where AI-driven cross-referencing is described as active: unreported income from cryptocurrency transactions, offshore structures, platform-economy earnings, and digital payments[2]. Related commentary describes heightened scrutiny of digital transactions specifically, with e-transfers, cryptocurrency holdings, and online payments routinely analyzed, alongside machine learning techniques detecting complex arrangements including offshore structures[4], and predictive risk assessment using data mining and predictive modelling to prioritize audits and enforcement based on risk levels[4].

The common thread across these categories is worth naming: they are all areas where third-party data exists that can be matched against what a taxpayer reported. Cross-referencing is only powerful where there is something to cross-reference against, which is why platform economy income, digital payment flows, and reportable offshore arrangements feature prominently while, say, a cash-intensive local service business remains harder to model from data the agency already holds.

The Myth Worth Killing First

Before going further, a widespread and incorrect belief deserves direct correction, because it distorts how business owners think about this entire subject. Commentary addressing this notes that Canadians have become increasingly curious about CRA's use of AI, and that social media rumours, sometimes inspired by foreign examples, have led many to believe the CRA has unrestricted, real-time access to every bank account[5]. The reality is described as more nuanced, combining advanced technology with strict privacy regulations, and the operative summary is that the CRA uses AI for tax compliance risk assessment rather than constant account monitoring[5].

This distinction matters practically. The CRA's information-gathering powers are statutory, bounded, and in many cases require specific processes to exercise. Sophisticated analytics applied to information the agency lawfully holds or receives is a different thing from continuous surveillance of private accounts, and conflating them produces both unnecessary anxiety and, occasionally, poor decisions made on the assumption that everything is already visible anyway.

The Transparency Gap

The genuine concern practitioners raise is not that risk scoring exists but that it is not visible to the taxpayer it affects. Commentary describes the position directly: a taxpayer whose return is flagged by an algorithm as anomalous may have no direct awareness that an automated system was involved in triggering their audit, and no straightforward legal avenue to discover it[2]. The same analysis notes a taxpayer algorithmically flagged as an outlier faces a materially elevated risk of audit, reassessment, and penalties, often without knowing an automated system drove the process[6].

There is a defensible administrative rationale for this opacity, and it deserves acknowledgment rather than dismissal: a risk model whose selection criteria were public would be trivially gameable, and a tax authority that published its audit triggers would have effectively published a compliance-avoidance manual. The tension between explicability and enforcement effectiveness is genuine and does not have an obviously correct resolution. It is worth contrasting this, though, with the direction of travel elsewhere in Canadian regulation: as covered elsewhere in this publication, OSFI's Guideline E-23 requires federally regulated financial institutions to build explainability into models throughout the lifecycle and to document alternative controls where a model is a black box. Financial institutions are being held to an explainability standard that tax administration, for defensible but debatable reasons, does not currently apply to itself.

Can Selection Itself Be Challenged?

This question is live enough that Canadian tax practitioners have written specifically on it: a June 2026 Law360 Canada piece by tax lawyer David Rotfleisch is titled directly, "Can taxpayers challenge CRA's AI audit selection?", following an earlier instalment examining the CRA's growing use of advanced analytics, risk-scoring systems and other technologies to identify files for potential audit and compliance review[7].

This article does not have access to the full analysis in that piece and will not speculate about its conclusions. What can be said from the general structure of Canadian tax administration is that the traditional avenues available to a taxpayer, objection and appeal, are directed at the correctness of an assessment rather than at the process by which a file came to be examined. A reassessment that is substantively correct does not obviously become incorrect because an algorithm surfaced the file. Whether procedural fairness or administrative law arguments have purchase against selection methodology specifically is a genuinely open question that a taxpayer facing it should put to a Canadian tax lawyer rather than resolve from a general article.

Why "Outlier" Is The Operative Concept

The most practically useful shift in thinking this development requires is understanding that risk models identify statistical deviation, and statistical deviation is not the same as wrongdoing. A model flags returns that look unlike comparable returns. Most business owners intuitively assume audit risk correlates with having done something wrong; under a modelling approach it correlates with looking unusual relative to a peer comparison the taxpayer cannot see and did not choose.

This has an uncomfortable implication that deserves stating plainly. A business with entirely legitimate but atypical characteristics, an unusual expense ratio driven by a genuine one-time event, a margin profile that diverges from its industry code because the industry code is a poor fit, a large legitimate deduction in a year that otherwise looks ordinary, is more likely to be flagged than an identical business without the anomaly, regardless of correctness. The correct response is not to avoid the legitimate item; it is to document it well enough that a human reviewer resolves the question quickly, which is what the practical guidance below is oriented around.

Why Practitioners Call This A Generational Change

Tax practitioner commentary characterizes the CRA's accelerating use of AI in audit selection and compliance enforcement as one of the most significant structural changes to Canadian tax administration in a generation, describing algorithmic risk modelling, machine learning cross-referencing, and AI-powered data analytics as now active and consequential features of how the CRA identifies which taxpayers to scrutinize[6].

That is strong language from an interested source, and it is worth testing rather than accepting. The case for it rests on a genuine structural shift: for most of the history of Canadian tax administration, the binding constraint on enforcement was the agency's capacity to look at things, which meant the practical probability of any given return receiving scrutiny was low and roughly indiscriminate outside specific programs. Analytics does not increase audit capacity, but it substantially improves the allocation of it, which changes the distribution of risk even if the total volume of audits is unchanged. A taxpayer who looks ordinary is arguably safer than before; one who looks unusual is arguably less safe. That redistribution, rather than any increase in enforcement volume, is the actual change, and describing it as structural seems fair even discounting for the source's commercial interest.

A Worked Case: The Legitimate Anomaly

A Canadian professional services corporation recorded an unusually large professional fees expense in one fiscal year, roughly four times its historical run rate, arising from a genuine and fully deductible litigation matter that concluded that year. Every dollar was legitimate, supported by invoices, and correctly characterized.

Relative to the corporation's own history and to comparable filers, the figure was a clear statistical outlier, and the corporation received a query. The resolution was straightforward but instructive in its timing: because the underlying documentation had been organized contemporaneously, with invoices, the engagement letter, and a short internal memo explaining the matter's nature and the deductibility analysis retained together, the response was assembled in days rather than weeks and the matter closed without escalation.

The transferable lesson is not that documentation prevents flagging, it does not, since the model cannot see the documentation at the selection stage. It is that documentation determines what happens after flagging. In a system where being unusual is increasingly likely to attract a look, the value of contemporaneous substantiation shifts from insurance against being wrong toward efficiency in demonstrating you were right.

What Actually Reduces Your Exposure

Practitioner guidance on this subject converges on straightforward points, and it is worth noting that none of them involve trying to look unremarkable. Commentary emphasizes the need for complete and accurate reporting to avoid triggering penalties[8] and recommends honest reporting, proper documentation, and prompt responses to CRA inquiries to minimise audit risk[5].

Translating that into specifics for a business owner operating in a risk-scored environment: report platform, digital payment, and crypto income completely, since these are precisely the categories where third-party data most readily enables cross-referencing and where a mismatch is most mechanically detectable. Document legitimate anomalies contemporaneously, at the time they occur rather than when asked, since the worked case above turns entirely on that timing. Ensure your industry classification actually fits, because peer comparison against an ill-fitting comparison group manufactures outlier status from nothing. Respond promptly and completely to initial queries, since the least expensive outcome is one resolved at first contact. And, where a matter is significant, practitioner commentary consistently advises engaging a Canadian tax lawyer before responding to the CRA[6], advice this publication passes along while noting the commercial interest of its source, discussed below.

A Note On Where This Reporting Comes From

Intellectual honesty requires flagging something about this article's sources that readers should weigh. The CRA does not publish detailed descriptions of its risk-scoring methodology, so most available commentary on the subject comes from Canadian tax law firms, several of the sources cited here originate from the same practice, and those firms have an evident commercial interest in readers concluding that audit risk is elevated and that professional representation is advisable.

This does not make the reporting wrong. The underlying claims are consistent with the CRA's own published Departmental Plan language, and tax practitioners see selection patterns in aggregate that outside observers cannot. But readers should distinguish the well-evidenced core, that the CRA has publicly committed to expanding data analytics and risk-based targeting, from the more atmospheric characterizations of that development's significance, which come from interested parties. This article has attributed both, and has anchored the load-bearing claims to the CRA's own primary-source language wherever possible.

The Other Side: Advisors Are Being Modelled Too

One element of the CRA's stated approach is easy to overlook and matters for how businesses choose professional help. The Departmental Plan identifies its compliance focus as including not only tax avoidance in the wealthy population but also promoters and advisors that facilitate unacceptable arrangements seeking to avoid taxes otherwise payable[1]. In an analytics-driven environment, this is a meaningful design choice: patterns are detectable not only across a taxpayer's own filings but across the portfolio of filings associated with a particular preparer, promoter, or arrangement type.

The practical implication for a business owner is that the choice of advisor now carries a dimension of risk it previously did not, or at least did so less visibly. A preparer whose client base collectively exhibits an unusual pattern may attract attention that propagates to individual clients who did nothing unusual themselves. This is not an argument for avoiding aggressive planning by avoiding advisors who do it, which would be both impractical and often unwarranted, but it is a reason to understand what positions are being taken on your behalf and why, rather than treating filing as something delegated and not examined.

The Limits Of This Analysis

Several caveats matter. The CRA does not disclose its risk models, so no article, including this one, can tell a taxpayer what specifically triggers selection; anyone claiming otherwise is speculating. The distinction this article draws between selection and decision is an analytical reconciliation of the CRA's stated position with practitioner observation, not something the CRA has itself articulated in those terms. The question of whether AI-driven selection can be challenged is genuinely unresolved and this article deliberately declines to answer it. Finally, this article is not tax advice, and the general observations here cannot substitute for advice from a Canadian tax professional who knows your specific circumstances; a business facing an actual CRA query should seek that advice rather than act on a general framework.

Frequently Asked Questions

Does the CRA use AI to decide who gets audited?
The CRA maintains that AI does not make final decisions, with a spokesperson stating all filings are reviewed with human oversight and that AI does not determine audits, assessments, or benefit eligibility. Its own Departmental Plan does commit to using data analytics and advanced risk assessment to identify high-risk taxpayers. The reconciliation is that analytics increasingly influences which files get attention, while humans make the resulting decisions.
Can the CRA see all my bank accounts in real time?
No. This is a widespread belief, sometimes fuelled by social media and foreign examples, that commentary specifically identifies as incorrect. The CRA uses AI for compliance risk assessment rather than constant account monitoring, and its information-gathering powers are statutory and bounded rather than unrestricted.
What kinds of income are most likely to be cross-referenced?
Practitioner reporting identifies cryptocurrency transactions, offshore structures, platform-economy earnings, and digital payments as active focus areas. The common feature is that third-party data exists to match against what was reported, which is what makes cross-referencing effective in those categories.
Will I be told if an algorithm flagged my return?
Practitioner commentary indicates a taxpayer may have no direct awareness that an automated system was involved and no straightforward avenue to discover it. There is a defensible administrative reason for this, since published selection criteria would be gameable, but it is a genuine transparency gap.
Does having an unusual but legitimate expense increase audit risk?
Plausibly yes, because risk models identify statistical deviation rather than wrongdoing. A legitimate anomaly can look identical to a problematic one at the selection stage. The practical response is not to avoid the legitimate item but to document it contemporaneously so that a human review resolves quickly.
Can I challenge the fact that an algorithm selected me?
This is genuinely unsettled, and Canadian tax practitioners have written specifically on the question. Traditional objection and appeal routes address the correctness of an assessment rather than the selection process. Anyone facing this should put the question to a Canadian tax lawyer rather than rely on general commentary.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article anchors its load-bearing claims to the CRA's own published Departmental Plan and is explicit about the commercial interests of its secondary sources; see References below.

References

  1. Canada Revenue Agency. (2025). Canada Revenue Agency's 2025–26 Departmental Plan. Government of Canada. canada.ca/.../2025-26-cra-departmental-plan.html
  2. Canadian Accountant. (2026, June 15). How The CRA Uses Artificial Intelligence In Canadian Tax Audits: What Taxpayers Must Know Now. canadian-accountant.com/content/taxation/cra-artificial-intelligence
  3. CA-SIR. (2026, June 24). CRA Audits Explained: What Triggers A Tax Investigation In Canada? ca-sir.com/resources/article/cra-audit-triggers-tax-investigation-canada-2026
  4. Rotfleisch & Samulovitch P.C. (2025, October 28). CRA's Increasing Use Of Digital Tools And AI Analytics To Enforce Penalties, via Mondaq. mondaq.com/.../cras-increasing-use-of-digital-tools-and-ai-analytics
  5. CKS Aksens. (2025, August 17). AI And The CRA: How Canada Actually Monitors Financial Transactions. cksaksens.com/global/en-ca/ai-and-the-cra-how-canada-actually-monitors-financial-transactions
  6. Tax Law Canada. (2026, June 5). How The CRA Uses Artificial Intelligence In Canadian Tax Audits. taxlawcanada.com/how-the-cra-uses-artificial-intelligence-in-canadian-tax-audits
  7. Rotfleisch, D. J. (2026, June 11). Can Taxpayers Challenge CRA's AI Audit Selection? Law360 Canada. law360.ca/ca/business/articles/2488274
  8. TaxPage. (2025, September 25). CRA's Increasing Use Of Digital Tools And AI Analytics To Enforce Penalties. taxpage.com/articles-and-tips/cras-increasing-use-of-digital-tools-and-ai-analytics

This article discusses published government planning documents and tax practitioner commentary and is provided for general informational purposes. It is not tax or legal advice. The CRA does not publish its risk-scoring methodology and no article can tell you what specifically triggers selection. If you are facing a CRA query or audit, consult a Canadian tax professional about your specific circumstances.