Summary

  • Emergency delivery did not suspend the duty to preserve a decision trail. ArriveCAN supported a real public-service requirement during a fast-changing health-border response. That context explains urgency, but it did not eliminate the need to record requirements, procurement choices, task approvals, security, testing, acceptance and payment. The Auditor General's performance audit found pervasive management and contracting weaknesses that prevented a precise calculation of cost.

  • Approximately C$59.5 million was an estimate, not an exact final bill. The audit reconstructed expenditure from the records available and expressly said exact cost could not be determined. The amount must remain approximate. It cannot be casually combined with contract ceilings, unrelated departmental contracts, future spending, tax, or every expenditure associated with border-health policy.

  • Supplier layers made evidence more important, not automatically illegitimate. Prime contractors, subcontractors, named bid resources, task-authorisation positions, work items and unique people are different populations. Intermediation may provide capacity, but value has to be proved through the actual person, clearance, rate, time, deliverable and acceptance. A missing link does not prove that every hour was fictitious; it does mean the Crown cannot rely on assumption as assurance.

  • The Procurement Ombud reviewed practices rather than deciding criminal guilt. Its ArriveCAN review examined competition, restrictive criteria, task authorisations, service orders, resource substitution and documentation and made 13 recommendations. Those are administrative procurement findings. They are not a conviction, and they do not establish that every proposed resource failed to work.

  • Audit, testimony, investigation and supplier-integrity action must remain separate. Auditor findings are assurance conclusions under a defined scope. Parliamentary transcripts contain attributed witness evidence and allegations. An agency investigation or referral to police is a procedural fact, not proof of charge or guilt. Suspension and ineligibility protect procurement integrity administratively; they are not criminal sentences.

  • The broader CBSA internal audit is relevant but cannot be relabelled an ArriveCAN audit. CBSA's contracting and procurement audit expressly excluded ArriveCAN contracts. Its findings and management plan can inform control design across the agency, but cannot corroborate a disputed fact about a particular ArriveCAN task authorisation or invoice.

  • Supplier action must retain its legal character. Public Services and Procurement Canada determined GC Strategies to be ineligible for seven years on 6 June 2025. That is a material administrative integrity action. It should not be inflated into a criminal conviction, nor diluted into a routine vendor-management event.

  • Durable reform is measured in transactions, not announcements. Action plans, new oversight functions and reported contractor reductions are control designs and management representations. Proof requires sampled procurement files showing that requirements precede solicitation, challenge is independent, substitutions are approved, clearances precede access, invoices reconcile to accepted work and emergency exceptions expire.

A border-health application was also a continuity service

ArriveCAN has to be evaluated in its operating context. In 2020, border and public-health requirements were changing quickly, travellers needed a usable channel for submitting information, and public servants needed a way to support decisions at scale. Delaying a service can create harm; so can releasing an unreliable one. Public-sector continuity therefore depends on controlled speed rather than a false choice between perfect paperwork and urgent delivery.

The product boundary extended beyond a phone application. It included web access, accessibility, call and border support, interfaces, privacy and security controls, changing policy rules, testing, release management and maintenance. A requirement might originate in health policy, border operations or technology. A supplier might provide specialized people rather than an entire product. A contracting authority might establish a vehicle while CBSA directed the work. Accountability had to follow this whole chain.

An emergency product still needs a minimal evidence spine. Every change should connect the public requirement to an authorised owner, an implementable specification, a release record, test evidence, acceptance and any incident response. The spine can be lightweight during the first weeks, but it cannot be optional. If a decision is made orally, a contemporaneous note should identify what changed, why delay was unacceptable, who accepted the risk and when the normal record will be completed.

Continuity also demands that releases can be reversed. Border rules affect real people and can change travel instructions, quarantine messaging and frontline workload. A product team needs staged deployment, monitored outcomes, a rollback path and a named decision maker. Testing is not only a technical exercise: policy, operational and accessibility owners must verify that the software implements the current rule and communicates it accurately.

The accountability issue is therefore not whether urgency existed. It is whether urgency became an indefinite operating model after the first emergency release. Repeated releases and later maintenance provide opportunities to formalize requirements, establish competition, reconcile resources and build records. A temporary exception should carry an expiry date and a plan for transition. Without those controls, emergency rationale can become a permanent substitute for challenge.

The audit could estimate cost but not certify a precise total

The Auditor General reported an estimated ArriveCAN cost of approximately C$59.5 million and said the exact cost could not be calculated because agency financial records were not sufficiently complete or reliable for that purpose. The official audit summary preserves both elements: the approximate amount and the underlying record failure. Reporting only the number removes the most important qualification.

An estimate is not defective merely because it is estimated. Auditors often reconstruct expenditure using contracts, invoices, cost centres, interviews and allocation methods. The accountability question is whether the scope, method, uncertainty and exclusions are clear. In this case, the inability to produce a precise total was itself evidence of weak financial management: management should have been able to identify the application, component, supplier, fiscal period and purpose attached to spending.

Several amounts that appear in public discussion answer different questions. A contract ceiling is the maximum authorised amount, not necessarily expenditure. An invoice records a supplier claim, not by itself accepted value. A payment records cash disbursed, not the product to which every dollar belongs. An estimated application cost allocates shared work under a method. A contract held by another department may involve the same supplier but not ArriveCAN. Those amounts cannot be stacked as though they were compatible line items.

Cost attribution should start at work authorization. Each service order or task authorization should carry a product code, requirement, cost ceiling, named roles and responsible manager. Timesheets and deliverables should inherit the code. Invoices should reconcile to accepted time and outputs. Shared infrastructure or management cost should use a documented allocation rule. Finance should reconcile totals to the general ledger and explain differences between commitment, expenditure and payment.

Value for money also cannot be reduced to the estimated total divided by the number of downloads or releases. A digital public service may require security, support and surge capacity that are invisible in the interface. Conversely, a functioning application does not prove every procurement layer or rate was reasonable. The correct test compares the approved need, alternatives, competition, rate, actual resource, accepted output, service outcome and risk at the time of decision.

Requirements needed an independent challenge function

Requirements determine who can bid and what government later accepts. If they are vague, suppliers price uncertainty and managers struggle to judge completion. If they are tailored too narrowly, competition can be nominal. The procurement record should show how each mandatory criterion relates to an operational need, who drafted it, what market information supported it and whether an independent reviewer challenged its effect.

The Procurement Ombud's official practice-review index establishes the provenance of the ArriveCAN review and related procurement oversight. The review described situations in which criteria were overly restrictive and examined supplier involvement in shaping requirements. Those findings warrant control repair, but the inference must stay bounded. Supplier input can be legitimate market engagement; restrictive criteria can arise without collusion. The problem is the absence of documented independence and proportionality.

Emergency non-competitive contracting has its own test. The file should identify the authority used, the urgent event, why competition would cause unacceptable delay, the market alternatives considered, the price basis, the approval and the duration. A bridge contract should be limited to the bridge. Once the immediate need stabilizes, the buyer should either compete the work or document why the exceptional basis still applies.

Competitive contracting is not automatically adequate. A solicitation can be formally open while criteria narrow the field to one practical bidder, evaluation records are thin, or incumbent knowledge creates an unexamined advantage. Reviewers need the requirement history, questions from bidders, scoring evidence, conflict declarations and changes between solicitation and task authorization. They should be able to reproduce why the selected bid won.

A useful challenge function is organizationally separate from the delivery team and contracting officer who need the purchase to proceed. It tests whether the requirement is outcome-based, qualifications are necessary, durations are reasonable, resource categories match the work and a simpler procurement vehicle exists. Under urgency, challenge can be rapid. Independence matters more than length.

Post-award changes must receive the same scrutiny. If the need, rate, resource mix or deliverable changes materially, the buyer should ask whether the original competition still supports the work. Serial amendments can turn a bounded award into a different procurement. A cumulative-change threshold should trigger senior review and, where appropriate, a new competition.

Task authorisations were the bridge between contracts and work

A professional-services contract creates terms and a ceiling; it does not prove that a particular person was authorised to perform a particular activity. Task authorisations and service orders are the bridge. Each should state the requirement, period, category, rate, maximum amount, resource, security level, deliverable, reporting route and acceptance authority before work begins.

This distinction matters because procurement populations are easy to confuse. A bid may list several candidate resources to demonstrate capacity. A task authorization may contain positions rather than final individuals. A supplier may substitute a person. A subcontractor may employ the person who actually works. One individual may perform several work items. Counting names across those records without deduplication or status labels produces false certainty.

The OPO review examined proposed-resource substitution and work performed by resources other than those in the bid record. Substitution is not inherently improper. People leave, availability changes and urgent needs evolve. The control question is whether the replacement was approved before work, met mandatory qualifications, had the appropriate rate and clearance, and was traceable through time and deliverables. Retroactive paperwork cannot provide the same protection.

Supplier layers also require transparency. The Crown should know the prime contractor, every material subcontractor, the actual worker, the rate paid by government, the rate paid down the chain where policy allows collection, and the service each layer provides. A prime may recruit, coordinate, assume risk or provide quality assurance. If it adds value, the record should show that function. If it only passes invoices, competition and pricing decisions should account for the margin.

No single missing document proves that a named person did no work. Evidence can sometimes be corroborated through version histories, access logs, meeting records, issue trackers and accepted outputs. But reconstruction after controversy is expensive and weaker than contemporaneous control. The manager certifying payment should not have to infer months later who participated.

A resource ledger can prevent the ambiguity. It assigns a stable identifier to each unique person and links employer, subcontractor, bid status, task status, clearance, dates, category, rate, timesheets, deliverables and substitutions. Public reporting can aggregate the ledger without exposing personal information. Auditors retain access to the controlled record and can distinguish people from proposed positions or billed line items.

Security, time, deliverables and invoices formed one evidence chain

Professional-services assurance is strongest when four types of evidence reconcile. Security evidence shows that the person was permitted to access the information and environment. Time evidence shows when authorised work occurred. Deliverable evidence shows what was produced. Invoice evidence shows what was claimed and certified. A valid payment file should connect all four to the task authorization.

Security status is not a generic badge. The required level depends on the work, systems and information. The file should identify the requirement and confirm that eligibility existed before access. If a person changes employer or assignment, the responsible security office should determine whether status remains valid. Procurement, identity management and project access records should reconcile automatically so expired or unmatched resources cannot enter the environment.

Timesheets are necessary for time-based work but not sufficient evidence of value. They should identify the task, date, hours and approver and be compared with availability limits and project activity. Generic descriptions repeated across weeks are a warning. However, an issue ticket or repository entry alone also does not prove the billed time; complex analysis, meetings and testing may not produce code. Assurance requires proportional corroboration.

Deliverables should be defined at a level that a manager can accept. For agile work, this can include completed stories, tested releases, resolved defects, security assessments, decision records and operational outcomes rather than a large document. Acceptance should record the criteria, evidence reviewed, defects or holdbacks and the person authorised to sign. A deliverable cannot be made auditable by naming it after it is complete.

Invoice certification is an accountability act, not an administrative click. The certifier should confirm that the correct resource worked within the authorised period and rate, the claimed quantity is supported, the work was accepted and tax and subcontracting information comply with terms. Segregation of duties should prevent one person from defining the task, directing the work, approving substitution and certifying every invoice without review.

Automation can strengthen this chain. A system can block invoices exceeding a task ceiling, flag a timesheet before clearance, identify overlapping billing, require acceptance evidence and retain a versioned audit trail. Automation should not convert weak data into a green status. Exceptions must be visible, time-limited and approved by a named authority.

Testing and release evidence connected procurement to public impact

Procurement records answer what government ordered and paid for. Product records answer whether the service worked. ArriveCAN needed traceability from policy requirement through design, implementation, test, approval, release and monitored outcome. Without it, managers cannot tell whether a supplier deliverable satisfied the need or whether a release incident came from policy interpretation, code, data, integration or operations.

Testing had to cover more than a happy path on one device. It included accessibility, English and French presentation, web and mobile behaviour, identity and document handling, privacy and security, rule changes, time zones, connectivity constraints, border workflows and support procedures. Emergency delivery can prioritize tests by risk, but any deferred test should have an owner, interim safeguard and completion date.

The Auditor General described weak documentation around testing and noted a release that sent erroneous quarantine directions to some travellers. The lesson is not that every release failed. It is that government must be able to show what was tested, what was not, who accepted residual risk, how monitoring detected an incident and when affected people were corrected. An event log should preserve impact without overstating it.

Release management should use a controlled package: approved requirement, code or configuration version, test results, known defects, privacy and security sign-offs, operational readiness, rollback procedure and release authority. Urgent changes can use an expedited package, but the same fields remain. After release, telemetry and frontline reports should be reviewed against expected behaviour.

Service continuity includes human fallback. Travellers need alternatives if they lack a compatible device, connectivity or ability to use the application. Border officers and support personnel need current instructions when rules or software change. A digital channel cannot quietly redefine legal eligibility or transfer the burden of correcting government error to the traveller.

Product outcome and commercial acceptance should meet in one record. The manager accepting a sprint or service period should see release results, open defects and operational incidents. A supplier may have completed the contracted work even if a policy decision later changes; equally, activity and releases do not prove that every billed category added value. Explicit acceptance criteria protect both government and suppliers from retrospective storytelling.

Auditor General and Procurement Ombud findings had different mandates

The Auditor General conducted a performance audit and reported to Parliament on whether organizations managed the application with due regard to value for money and followed relevant practices within the audit scope. In an opening statement to Parliament, the Auditor General summarized the breakdown in basic management and contracting disciplines. The statement is useful framing, but the detailed report controls scope, methods and exact conclusions.

The Procurement Ombud examined procurement practices and made recommendations within its mandate. Its review explored solicitation design, task authorisations, service orders, resource evidence and record keeping. A practice review can identify systemic weakness without deciding a private-law damages claim or criminal offence. Its findings should be cited as findings of the Ombud, not merged with every OAG conclusion.

The two records overlap because they review parts of the same procurement environment, but overlap is not duplication. One may sample different files, use a different period, test a different policy requirement or count resources differently. A combined accountability matrix should preserve source, mandate, population, period and result for each proposition. Agreement can reinforce a control diagnosis; disagreement should prompt reconciliation.

Administrative findings can be serious without criminal language. Weak competition, missing approvals, poor documentation and unsupported certification expose public money and institutional legitimacy even when there is no adjudicated criminal offence. Overstatement is not necessary to make the case for reform. Indeed, converting every failure into an accusation can make precise responsibility harder to establish.

Recommendations likewise need owners and evidence. A response that says “agreed” is a commitment, not completion. A policy issued is an output, not operating effectiveness. Closure should require implementation artifacts and sampled transactions showing that the targeted condition changed. Independent assurance should test the same failure modes under both normal and emergency procurement.

Parliamentary evidence required attribution and corroboration

Parliamentary committees made the procurement record visible by requesting documents and hearing from officials, suppliers and other witnesses. The House Government Operations and Estimates Committee's meeting 100 evidence is a primary transcript of what entities said. It is not a judgment that every statement was accurate, complete or corroborated.

That distinction matters where witnesses disagree about who recruited a resource, who performed work, how requirements were drafted or what a supplier knew. The accurate form is “the witness testified” or “the member alleged,” followed where possible by the contract, email, task authorization, invoice, audit finding or later decision that confirms or conflicts with it. Repetition in a hearing does not transform allegation into established fact.

The Public Accounts Committee's study activity record establishes chronology, meetings and evidence associated with parliamentary examination of the audit. The page does not itself prove a disputed procurement proposition. Study administration, testimony, committee findings and government response are distinct evidence types.

Committees can expose gaps that audits did not adjudicate and ask accountability questions that contracting records avoid. They can also operate in a political setting, use compressed questions and receive answers without immediate document verification. A responsible article preserves the public value of the proceedings while refusing to turn every exchange into a finding of misconduct.

An evidence register can help. For each material claim it records the speaker, date, exact proposition, status as testimony or allegation, corroborating record, contradiction, investigative status and final disposition if any. This prevents a dramatic statement from becoming detached from attribution as it moves through reports and public discussion.

Procedural fairness also protects institutional learning. Officials and suppliers should be held to records and clear standards, but responsibility should attach to the actual decision, authority and evidence. A committee transcript may justify further audit or investigation; it does not replace either. Where a matter remains unresolved, the record should say so plainly.

Internal review and investigation were not adjudication

Before the February 2024 external reports, CBSA provided parliamentary briefings on its internal work. A January 2024 agency status page described internal investigation and audit activity as of that date. It is a dated agency account, not a substitute for the later OAG and OPO findings and not proof of an investigative outcome.

Investigation has a different purpose from audit. An audit evaluates controls, records and performance against criteria. An administrative investigation can examine employee conduct or policy compliance. A referral to the Royal Canadian Mounted Police asks an independent law-enforcement body to assess information. Referral does not establish that charges followed, that an offence occurred or that any person is guilty.

This separation should be maintained even when the same document or transaction appears in several processes. An auditor may find limited public evidence documentation without concluding that a record was deliberately falsified. An employer may take precautionary action under its policies. Police and prosecutors apply their own legal thresholds. Courts decide charged matters under criminal standards. None of those stages should be anticipated in reporting.

Agency briefings can still provide useful operational context: the review bodies involved, records being collected, interim restrictions and intended management response. Their limitations should travel with them. They describe what the agency said on a date and may change as evidence develops.

Control repair need not wait for a criminal conclusion. If records cannot establish who approved a task or whether a clearance preceded work, management can strengthen systems immediately. At the same time, reform should not overwrite evidence. Legal holds, access controls and chain-of-custody procedures must preserve records for investigators, employees, suppliers, auditors and Parliament.

The clean accountability sequence is: identify a control failure; preserve and test records; refer suspected conduct under the applicable threshold; allow the competent body to decide; record the outcome; and adjust controls. Public dashboards should distinguish open, referred, concluded administratively, charged and adjudicated matters without identifying people beyond lawful disclosure.

Agency and central procurement responses were management evidence

CBSA's May 2024 response overview described changes to testing, governance and contractor use after the external reports. Such a response matters because accountability includes remediation. But reported action is management evidence: a reduction in contractors or a new committee does not by itself show that requirements, invoices and releases now reconcile.

A December 2024 CBSA fact sheet recorded publication of internal audits and management action plans. Publication increases transparency, yet status labels need acceptance criteria. “Implemented” should mean the control exists, relevant people use it and testing found it effective—not merely that a document or training module was issued.

Treasury Board's March 2024 committee briefing described central control and policy responses. This is a departmental briefing, not an adjudication of supplier conduct. Its value lies in defining the policy owner's interpretation, intended oversight and commitments that later assurance can test.

Public Services and Procurement Canada's November 2024 Public Accounts briefing set out procurement response, supplier information and reform from the contracting authority's perspective. Agency accounts should be compared with OAG and OPO recommendations rather than used to mark them complete automatically.

A credible action tracker maps each recommendation to the exact underlying condition, owner, deadline, artifact and outcome test. If a recommendation concerns proposed resources, the test samples whether actual resources match approved substitutions and clearances. If it concerns competition, the test reviews requirements, market evidence and bidder participation. If it concerns invoices, the test traces payment back to task, time and accepted work.

The tracker should expose exceptions. Emergency files, sole-source amendments and high subcontracting margins deserve targeted sampling. Repeated failure should trigger escalation independent of the delivery chain. Results should be reported with denominator, period and severity so a high completion percentage cannot hide a small number of material uncontrolled contracts.

Supplier suspension and ineligibility were administrative integrity measures

In March 2024 PSPC announced suspensions concerning GC Strategies, including security-status and procurement consequences described in the release. Suspension protects the government while facts or eligibility are assessed. It is precautionary and administrative; it is not proof of a criminal offence.

The later seven-year ineligibility decision was a distinct stage under the supplier-integrity regime. It affected eligibility for federal contracting under the applicable policy and stated period. Its significance should not be understated: excluding a supplier is a substantial public-procurement action. But its authority, criteria and appeal or reconsideration structure differ from a criminal court.

The Ineligibility and Suspension Policy provides the administrative framework. Policy-based discretion, procedural steps and contracting effects should be reported in their own terms. Words such as conviction, sentence, fraud or guilt require an appropriate adjudicative basis and cannot be inferred from ineligibility alone.

Supplier integrity also has actor and contract boundaries. A decision about GC Strategies does not establish misconduct by every subcontractor, worker, public servant or customer. It does not convert all federal contracts involving the supplier into ArriveCAN costs. Transport Canada's cross-department briefing is relevant to broader contract and suspension context, but those departmental contracts cannot be added to the application estimate simply because a supplier name overlaps.

Administrative action should feed practical controls. Procurement systems need to prevent new awards to an ineligible supplier, identify affected active contracts, assess continuity and determine whether subcontracting creates indirect exposure. Security systems should reconcile organizational status with individual access. Contracting officers need documented guidance for exceptions and transitions.

Fairness and continuity must coexist. Government should preserve competition and protect services while applying integrity policy consistently. Existing work may need orderly transfer; subcontractors may hold necessary knowledge; public services cannot be abandoned. Transition decisions should document the risk, interim authority, data return, intellectual property, access removal and acceptance of remaining deliverables.

Reform design required proof under emergency conditions

PSPC's March 2024 procurement improvement action plan described measures involving oversight, supplier integrity, professional services and fraud-risk response. Plans establish direction and ownership. They do not demonstrate that the same safeguards would withstand a ministerial deadline, operational surge or rapidly changing requirement.

Operating assurance should use real files. A reviewer selects normal and emergency procurements, then traces requirement authorship, challenge, authority, competition, evaluation, conflict declarations, task authorization, resource identity, clearance, time, deliverable, acceptance, invoice and payment. Exceptions should have contemporaneous reasons and expiry. The test should include amendments and subcontractor changes, where weak controls often migrate.

Emergency exercises can test the system before the next crisis. A simulated urgent digital service should require a team to buy specialized capacity within days while preserving the minimal evidence spine. Assurance observes whether systems permit rapid approval, whether challenge is available outside business hours, whether market options are recorded and whether temporary instruments automatically trigger later review.

Metrics need denominators. Report the share of sampled tasks approved before work, substitutions approved before billing, resources cleared before access, invoices linked to acceptance and exceptions closed by due date. Also report severity and value. Ninety-nine compliant low-value files do not cancel one large unreviewed amendment.

Control independence matters. Delivery leaders can explain urgency but should not alone waive competition, approve the supplier they consulted, accept the work and certify payment. Procurement, security, finance and product owners each hold distinct evidence. A senior emergency authority may accept residual risk, but the acceptance should be visible and time-limited.

Technology should create auditability by default. Procurement and product systems can share stable identifiers so a release traces to tasks and accepted work without exposing commercially sensitive or personal data publicly. Versioned records, role-based access and immutable logs reduce retrospective reconstruction. Human reviewers still decide whether evidence demonstrates value.

A durable control map for digital public procurement

The first domain is public need. A policy or service owner defines the outcome, affected population, urgency, legal authority and continuity requirement. Product managers translate it into prioritized work and acceptance criteria. Changes retain versions and approvals. The goal is not to freeze an emergency response but to make adaptation observable.

The second domain is sourcing. Procurement specialists record market analysis, method, competition, evaluation, conflicts, price reasonableness and exceptions. A challenge authority tests restrictive criteria and supplier influence. Amendments are assessed cumulatively. Every emergency instrument has an expiry and transition decision.

The third is resource identity. A ledger separates proposed positions, named people, approved resources, substitutions, subcontractors and work items. Security status, system access, time and rate align to the actual individual. Privacy controls limit access while auditors can still trace the chain.

The fourth is delivery. Tasks identify outputs, and product systems record implementation, tests, release and incidents. Acceptance connects contracted work to evidence without pretending every useful service produces code. Defects, deferred tests and residual risks have owners and dates.

The fifth is financial control. Commitments, invoices, payments and allocated product costs reconcile. Managers certify only after reviewing supported time and deliverables. Finance distinguishes exact ledger expenditure from estimates and contract ceilings. Cost reports state scope, period, exclusions and uncertainty.

The sixth is integrity and escalation. Employees and suppliers have protected channels to report conflicts, false records or pressure. Triage distinguishes contract-management errors, administrative misconduct and suspected crime. Referrals preserve their procedural character, and outcomes feed proportionate action without assuming guilt.

The seventh is independent assurance. Internal audit, the Procurement Ombud, the Auditor General and parliamentary committees have different mandates. Their records remain distinct in an evidence matrix. Recommendation closure requires operating tests, and the broader CBSA audit remains labelled as excluding ArriveCAN rather than being borrowed as direct proof.

The eighth is public reporting. Citizens should see what the service was for, an appropriately qualified cost, major procurement methods, material findings, management responses and supplier actions. Reports should distinguish audit findings, testimony, allegations, investigation status, administrative decisions and court outcomes. That vocabulary is part of control.

Value-for-money proof should survive a cold-file review

The final accountability test is whether a qualified reviewer who did not participate in the project can understand a file without relying on institutional memory. The reviewer should be able to identify the public need, compare the chosen procurement route with alternatives, reproduce evaluation and price reasoning, determine which unique people actually worked, confirm access authority, connect time to accepted output and reconcile payment to the product cost. A file that can be explained only by the manager who created it is not a durable public record.

A cold-file review should begin with a sample designed around risk rather than convenience. It should include an emergency award, a competitively awarded professional-services contract, a large amendment, a substituted resource, a subcontracting chain, an invoice certified near a deadline and a release associated with an operational incident. Reviewers should test complete evidence chains, not merely whether each file contains a document with the expected title.

Exceptions need qualitative assessment. A missing signature corrected one day later before work began is different from an authorization reconstructed after payment. A task with a clear deliverable but an incomplete meeting record differs from months of generic time entries with no acceptance evidence. Reporting should distinguish severity, exposure, recurrence and whether compensating evidence exists. That approach avoids both false reassurance from document counts and unfair conclusions from minor clerical gaps.

Value also has a time dimension. Emergency capacity can be worth more during an immediate operational surge than under normal conditions. The file should record that rationale and then show when surge pricing, non-competitive authority or added supplier layers ended. Continuing a premium arrangement after the constraint disappears requires a new decision. Otherwise, a defensible emergency choice becomes an indefensible standing practice through inertia.

Outcome evidence completes the record. For ArriveCAN-like services, this includes availability, accessibility, defect and incident trends, support demand, policy accuracy, release stability and the effort needed to maintain the product. Commercial performance and public outcome are related but not identical. A supplier can meet a narrowly drafted task while the overall service underperforms; a service can function while particular procurement charges remain unsupported. Assurance should report both.

Cold-file review results should feed learning before controversy. Procurement leaders can identify requirements that repeatedly attract one bidder, product teams whose urgent exceptions never expire, resource categories with frequent substitutions and managers certifying invoices without adequate acceptance records. Targeted intervention is more useful than another generic reminder. It changes the conditions that produce weak evidence.

Finally, public bodies should retain the review package for the life of the service and the required records period. Messages, approvals and product artifacts should be captured in authorized repositories, with privacy and security restrictions applied without destroying auditability. Departing staff and suppliers should transfer records and knowledge. When the file remains intelligible after people move on, accountability becomes an institutional property rather than a personal recollection.

Conclusion

ArriveCAN became an accountability test because an urgent digital service outgrew the evidence system around it. Requirements changed, multiple authorities and supplier layers participated, and records did not consistently connect tasks, people, clearances, work, invoices, releases and cost. The result was not merely untidy administration. It prevented the government and its auditors from demonstrating a precise total and complete value-for-money trail.

The approximately C$59.5 million figure must remain an audit estimate. Contract ceilings, payments, other departmental contracts and unrelated border-health expenditure are different measures. Precision begins by naming the unit and scope, not by choosing the largest available number.

Responsibility also requires mandate discipline. OAG and OPO findings are serious administrative accountability records, not criminal convictions. Parliamentary evidence is attributed testimony unless corroborated. Investigation and referral do not establish charge or guilt. Suspension and seven-year ineligibility are consequential supplier-integrity actions, but they remain administrative.

Reform is credible when a reviewer can select a current emergency task and reconstruct it end to end: the need, procurement method, challenge, supplier, actual resource, subcontractor, clearance, time, deliverable, acceptance, invoice, payment, product release and outcome. An action plan or committee cannot substitute for that trace.

The durable standard is controlled speed. Government should be able to respond quickly without making accountability a future archaeology project. When emergency exceptions expire, supplier layers are transparent, costs reconcile and independent assurance can reproduce decisions, digital procurement becomes both faster to defend and harder to misuse.