Home About Us Services ↳ Canada PR Visa (Permanent Residency) ↳ Work Permit Canada ↳ LMIA — Labour Market Impact Assessment ↳ Spouse & Family Sponsorship Visa ↳ Student Visa Canada ↳ Visitor Visa ↳ Business Visa Provinces ↳ 🏙️ Ontario ↳ 🏔️ British Columbia ↳ 🌾 Alberta ↳ 🌻 Saskatchewan ↳ 🌊 Manitoba ↳ ⚓ Nova Scotia ↳ 🍁 New Brunswick ↳ 🦞 Prince Edward Island ↳ 🐟 Newfoundland & Labrador ↳ 🌊 Atlantic Immigration Program Healthcare Blog FAQ Careers Canadian Latest policies Contact

Income Tax Audit Manual

Compliance Programs Branch (CPB)

Chapter 4.0 Auditor's standard of conduct, authorities, and responsibilities

4.1.0 Introduction

As employees of the CRA, auditors are stewards of the public trust. Canada’s tax system relies on the voluntary compliance of taxpayers, who must have confidence in the CRA. Auditors play a critical role in maintaining that confidence and in enhancing and promoting compliance with Canada's tax laws through communication, quality service, and responsible enforcement.

Audit activities form an integral part of the CRA's mission to administer tax, benefits, and related programs, and to ensure compliance on behalf of governments across Canada, thereby contributing to the ongoing economic and social welfare of Canadians.

Auditors are expected to reflect the People First philosophy of the CRA in their work and to act in accordance with the Agency's values of integrity, respect, professionalism, and collaboration, at all times. They are expected to fulfil their duties in an efficient and effective manner. 

4.2.0 Auditor's standard of conduct

Auditors are governed by the Code of Integrity and Professional Conduct (Code), which describes the standard of conduct expected from them. The Code provides a one-source reference for various documents that set out the CRA policy and procedures to provide employees with guidance on dealing with difficult situations or ethical issues.

Auditors are required to read and adhere to the Code and to the Directive on Conflict of Interest, as part of their terms and conditions of employment. Employee misconduct not only raises serious concerns among Canadians, but also erodes public trust and damages the reputation of the public service as a whole. Breaches of the Code or the Directive can result in disciplinary action, up to and including termination of employment which serve as a strong reminder of the critical importance of integrity in public service.

Safeguarding of taxpayer information

As part of their duties, auditors have access to a significant amount of taxpayer information. The CRA handles one of the largest repositories of personal and financial information in the country and this information must be safeguarded at all times.

Auditors must adhere to strict confidentiality standards and only access taxpayer information on a need-to-know basis. Access to taxpayer information is monitored in real time and unauthorized access to protected information may lead to serious consequences, up to and including termination of employment.

For more information on the auditor’s responsibilities regarding the protection of information and assets, go to 4.4.0, Security of information and assets

4.3.0 Avoiding conflict of interest

A conflict of interest arises whenever an employee's private interests, outside activities, receipt of a gift, hospitality or other benefit, or plans for post-employment, will impair, or could be perceived to impair, their ability to make decisions with integrity, impartiality, honesty, and in the best interests of the CRA and the Government of Canada.

Auditors are responsible for ensuring that they do not place themselves in real, potential, or perceived conflicts of interest, as outlined in the Code of Integrity and Professional Conduct.

All CRA employees are required to disclose certain private interests, assets, liabilities, and relationships, in accordance with the Directive on Conflict of Interest. If an auditor is offered or receives a gift, hospitality, or other benefit, based on their CRA duties, they must respectfully decline and then disclose the offer in a confidential disclosure form available on the Conflict of Interest page.

All employees are expected to provide the same impartial service to all taxpayers and benefit recipients. They must immediately inform their team leader of any requests for preferential treatment or privileged access.

4.3.1 Assigning, reassigning, and treating audit files to avoid a conflict of interest

Auditors must never provide services to, or deal with files of, friends, family members, acquaintances, business associates, current or former colleagues, or current or former supervisors, unless prior approval has been obtained. Furthermore, auditors must never deal or interfere with any file related to their private interests or outside activities or employment. For more information, go to the employees obligations described in the Directive on Conflict of Interest under 7. Roles and responsibilities.

If an auditor’s assigned workload includes the file of an individual or entity for which they identify a real, apparent, potential, or perceived conflict of interest, they must not access the file, and must immediately inform their team leader.

There may be other situations where a real conflict of interest does not exist, but the auditor requests that the file be reassigned because it might be difficult to remain objective and impartial due to present or past relationship with the taxpayer or their representative. The file will normally be reassigned to an auditor who does not have an existing relationship with the taxpayer and/or entity identified in the file. If it is not possible to avoid a real, apparent, potential, or perceived conflict of interest by reassigning the file to another auditor within the Tax Services Office (TSO), the file should be transferred to another TSO.

Providing that a CRA employee whose business is being audited has complied with the Directive on Conflict of Interest, treatment of the file should be identical to any other audit case.

4.4.0 Security of information and assets

4.4.1 Security of information and other assets

All CRA employees have statutory requirements to maintain the confidentiality of taxpayer information in accordance with specific provisions of section 241 of the ITA and, as such, must safeguard, identify, categorize, and mark the information at the appropriate level. Auditors must ensure that unauthorized persons who may attempt to obtain protected or classified information are not given the opportunity to do so.

Information and assets fall in one of the three following categories: classified, protected, or unclassified. 

Classified information and assets

Auditors are generally not exposed to classified information and assets as part of their duties.

This category includes sensitive information and assets that are important to the national interest (security of the nation) including Confidential, Secret, and Top Secret. Top Secret assets include encryption codes and certain encryption devices. This category applies to information and assets that, if compromised, could reasonably be expected to cause injury to the national interest, defence, and maintenance of the social, political, and economic stability of Canada.

For examples, go to Appendix B: Examples of Classified information and their Level.

Protected information and assets

Most of the information handled by auditors falls into this category and therefore requires protection.

The protected category (Protected A, Protected B, or Protected C) applies to information and assets that, if compromised, could reasonably be expected to cause injury to a non-national interest, that is, an individual interest such as a person or an organization. Taxpayer information and personal data is protected.

For examples, go to Appendix A: Examples of Protected information and their level.

Unclassified information and assets

If the information or asset does not fall into either the protected or classified categories, it is considered unclassified. This category includes assets of value include computers, printers, fax machines, and furniture. It also includes information that is publicly available.

Identification and marking of information

All documents must be identified and marked appropriately throughout their lifecycle according to the Identification and Marking of Protected and Classified Information and Assets Directive and the related Identification and Marking of Protected and Classified Information and Assets Procedures. The table in section 5.3.1.6 of these procedures assists auditors in determining whether an information or asset is protected, classified, or unclassified. To further assist auditors in identifying and marking information, the CRA has also developed the Protected Information Categorization Tool and the Classified Information Categorization Tool.

The auditor must categorize and mark every Outlook email, Word, Excel, and PowerPoint document with a categorization level before it is sent, saved, or printed. For more information, refer to Purview Sensitivity Labels.

Security of taxpayer data and audit working papers

All audit working papers are considered to be "information holdings" and are subject to the federal government’s Service and digital corporate policy instruments developed by the Treasury Board of Canada Secretariat.

For guidance on accessing and safeguarding information, systems, computers and related devices, go to Information and Systems Security Directive and Computer Systems and Electronic Networks Usage Directive.

For more information on audit working papers, go to 9.8.0, Working papers.

Auditor guidelines for information and asset security

Auditors must only access protected and classified information and assets as part of their assigned duties on a need-to-know basis. All users must exercise due diligence and complete appropriate Corporate Mandatory Training to protect CRA information, systems, computers, and related devices from unauthorized use, access, disclosure, alteration, or destruction.

Communiqué AD-17-01, Accessing taxpayer information during compliance activities, provides guidance to auditors on authorized access to taxpayer information as well as information on how to document access to information on ancillary or third-party taxpayers.

Prior to accessing any taxpayer information where the taxpayer is not subject to compliance activities, the auditor must obtain approval from their supervisor. Also, all access must be documented and reported to the auditor’s supervisor, and documentation must be kept by the auditor for at least five years and kept in a manner consistent with guidelines on How to save electronic information.

When processing, storing, or transmitting protected information on the CRA computer systems located either on CRA premises or outside of the workplace, auditors must apply security safeguards as outlined at 6.3 Internet access in the Information and Systems Security Directive. Only information up to the Protected B level can be processed, stored, or transmitted on the RCNet (Revenue Canada Network).

Also consider the Directive on Workplace Arrangements as well as the Telework InfoZone page.

For guidance on transmitting, storing, transporting, and destroying protected or classified information and assets, go to section 4.4.4, Transmittal of sensitive information, and the three subsequent sections. For related information, also go to chapter 3.0, Taxpayer rights and taxpayer relief.

4.4.2 Security Corporate policy instruments

Information and property assets must be protected from improper use, theft, and deliberate damage. All reasonable precautions must be taken to prevent accidental damage. Auditors must take extra measures to protect sensitive information and assets.

The Security Branch’s Corporate policy instrument are intended to maintain a level of security sufficient to protect the CRA’s people, information, and assets, and to ensure that information about taxpayers is kept strictly confidential and handled at the appropriate level. They are also intended to provide awareness and a clear understanding of the responsibilities and accountabilities of all CRA employees, as well as various other stakeholders related to the CRA Security Program. Observance of these instruments safeguards the well-being of employees, the information entrusted to the CRA, assets and revenues, and the Security Program’s contribution to the success of CRA programs and services.

4.4.3 CRA operations manuals

Auditors have access to CRA operations manuals as part of their work-related duties. Certain sections of these manuals contain protected or classified information that is protected under the Access to Information Act. Care must be exercised before releasing to the public any part of the CRA's operations manuals, as such release must be subject to a rigorous prior assessment.

4.4.4 Transmittal of sensitive information

The CRA’s policies are intended to ensure the confidentiality, integrity, and availability of all CRA information that is transmitted and transported, including taxpayer and corporate information. For information on the communication methods to consider when communicating with taxpayers or their representatives, go to Secure Communications Options – CPB.

Email

Internal email with information up to and including Protected A can be sent without encryption. Protected B information must be encrypted using CRA-approved encryption. Transmission of Protected C and classified information by email is not permitted.

Emails must be marked to comply with the Identification and Marking of Protected and Classified Information and Assets Directive. For more information on marking documents and files, go to 4.4.1, Security of information and other assets, under Identification and marking of information.

When protected taxpayer information is included in an email or memorandum, the subject line must include the designation “CONTAINS TAXPAYER INFORMATION,” as mentioned on the InfoZone page Security responsibilities: Communication and transmittal of information. The requirements for this designation apply to CRA internal communications exclusively.

Section 5.10 of the Transmittal and Transport of Protected and Classified Information and Assets Standards addresses email communications with the public. The CRA does not directly request or accept taxpayer information by email. Auditors must not email protected and classified information to taxpayers, even if they specifically request and authorize it. Unclassified information may be emailed to a taxpayer with the following conditions:

  • The message must be in text format only
  • The message may include attachments (for example, PDF files)
  • The message must not contain any hyperlinks, including QR codes, unless they are requested by the taxpayer or a member of the public and the hyperlink is from Canada.ca

Information networks that are not adequately protected and all electronic communications that are not adequately protected are subject to unauthorized access (pirating), interception, and rerouting. The consequences of such actions include service interruptions, financial losses resulting from the theft of telecommunication services, and the unauthorized disclosure of information.

For more information on sending emails, refer to sections 5.8 to 5.11 of the Transmittal and Transport of Protected and Classified Information and Assets Standards.

If an email received appears suspicious, malicious, or inappropriate, follow the steps at Suspicious emails and phishing to report it.

Cell phones

Communications using cell phones, wireless headsets, or other equipment (personal cellular communication services or PCCS) that use unprotected radio frequency technology are subject to risk of being intercepted. The users of these communication systems must assume that a third party may be listening to the conversation and take these precautions:

  • Up to and including Protected B information can be communicated externally with the public through voice and audio.
  • Only unclassified information can be communicated within the Government of Canada unless CRA-approved end-to-end encryption is used.
  • Protected C and classified information must never be communicated over wireless technology.
  • Cell phones and PCCS Mobile devices are attractive items that must be kept in a safe place. When left in a vehicle, the mobile devices should be placed in the trunk or out of view and the doors must be locked. Anti-theft devices should be used when available.

Protected information must not be recorded on any voice messaging system. Auditors’ voicemail greeting messages must clearly instruct callers not to provide protected information in voice messages.

Devices must not be connected to any computer equipment (CRA or personal). Employees must use CRA-issued or authentic manufacturer adapters that plug into an electrical outlet to charge their cell phones.

For more information, go to section 5.2 of the Transmittal and Transport of Protected and Classified Information and Assets Standards, Guidance on the secure use of government-issued mobile devices (cell phones, smart devices, mobile modems), and Security responsibilities: Communication and transmittal of information.

Fax machines

The CRA uses the standard fax public network and the secure fax classified network. The public network is used to receive information from taxpayers. It can also be used to send unclassified documents to a taxpayer. The standard fax public network must not be used to transmit protected information, either internally or externally.

Protected C or classified information must only be transmitted using the secure fax classified network. For more information, go to Accountable COMSEC Material Procedures.

If there is a need to send Protected A or Protected B documents internally, go to Secure fax protected network for detailed instructions on using the scan feature that is available on the CRA-approved multi-function printers and then send them by email.

Transmittal of sensitive information by regular mail or by an electronic communications tool

The auditor must ensure that the right information is delivered to the correct taxpayer, whether through regular mail or by an electronic communications tool.

When sending correspondence to an individual taxpayer, the auditor must respect the CRA policy to limit the display of social insurance numbers (SIN) by replacing the first six digits of the SIN with X’s on letters sent to the taxpayer. When the auditor expects a taxpayer to return a letter to the CRA, they must ensure the mark “PROTECTED B when completed” appears on the top-right hand corner of each page of the letter. For more information, go to 10.2.3, Obligation to keep adequate books and records, under Informing the taxpayer.

Protected and classified information and assets must be adequately safeguarded when sent by mail. The mailing standards inside and outside of Canada are detailed at Appendix A of the Secure Mailing of Information and Assets Procedures, which also provides auditors with the steps that must be followed to ensure that all protected and classified information or assets mailed within and outside the CRA are properly and securely packaged and transmitted.

All protected and classified information and assets should be sent through a CRA mailroom that has established and approved procedures for transmittal of mail both within and outside the CRA. The sender is responsible to ensure information and assets are properly packaged before sending them to the mailroom or mailing them directly. The detailed Secure Mailing of Information and Assets Procedures described between 5.1 and 5.4 should be followed at all times.

Auditors sending documents to taxpayers or representatives using an electronic communications tool must ensure they are attaching the correct information before sending electronic correspondence.

If there is a need to send Protected A or Protected B documents internally, a CRA-approved multi-functional printer (MFP) must be used. For more information, go to the section above, Fax machines.

For more information, go to Storage, Disposal, Transmittal and Transport of Protected and Classified Information and Assets Directive and to Transmittal and Transport of Protected and Classified Information and Assets Standards.

Electronic communications in Integras

The auditor can communicate digitally with taxpayers and third parties who are registered to CRA’s online services (My Account, My Business Account, and Represent a Client). The Integras case number serves as a reference number. When the taxpayer or the representative has access to the CRA’s online services, this should be considered the preferred method of communication.

To learn more about this option, go to Initiate Taxpayer Enquiry and Respond to Enquiry.

Secure Drop Zone

The Secure Drop Zone (SDZ) is a standalone application that allows the auditor and the taxpayer or their representative to send and receive documents digitally through a web browser. For more information, go to Secure Drop Zone (SDZ).

Misdirected correspondence

Misdirected correspondence incidents are considered a security incident involving a breach of information and must be reported immediately by submitting a Security Incident Report (SIR) on the Emergency and Incident Management Electronic Tool (EIMET). If an auditor has sent an electronic communication via Integras to the wrong taxpayer, in addition to submitting a SIR, they must create an Action Request and send an email to the National Integras Support Section / Section nationale du soutien d'Integras (CRA/ARC). For more information, go to Security Incident Reporting and Management Procedures – Misdirected Correspondence. For details on the roles and responsibilities of employees in misdirected correspondence, go to Roles and Responsibilities.

4.4.5 Storing protected and classified information and assets

Protected A or B information and assets must be stored in a locked desk or other commercial furniture equipped with a locking mechanism; the key must be removed and not left visible.

Protected and classified information and assets, and containers in which they are stored, must be located in areas where access is controlled in accordance with the highest level of sensitivity of the material. Protected and classified information and assets must be securely stored when not in use or when left unattended. Proper security measures must also be taken when storing protected and classified information electronically. Refer to the following corporate policy instruments for guidance:

  • Storage, Disposal, Transmittal and Transport of Protected and Classified Information and Assets Directive
  • Information and Systems Protection Standards, more specifically under:
    • 5.2 Personal electronic devices
    • 5.3 Portable data storage devices (this refers to devises such as CDs, DVDs, USB memory sticks, and hard drives)
    • 5.4 Use of equipment outside CRA premises

Secure USB keys and external hard drives (S-USB), used for the secure storage and transport of sensitive information in electronic format, enhance controls to prevent misuse of information. They also protect the confidentiality of corporate and taxpayer information. For more information, go to Portable Data Storage Devices.

Before connecting a portable data storage device to a network-connected CRA computer, auditors must always manually scan it on a CRA computer that is not connected to the network. For more information on protected and classified information and assets, go to 4.4.1, Security of information and other assets, and 4.8.6, Security of software.

4.4.6 Transportation of information and assets outside the office

Auditors must ensure that protected and classified information and assets are transported according to the security standards described in section 6 of the Transmittal and Transport of Protected and Classified Information and Assets Standards.

Auditors must exercise good judgment and provide reasonable assurance that every effort has been made to safeguard protected and classified information and assets at all times. When in doubt, auditors must consult their team leader.

Assets and paper documents must be kept under the auditor’s control during transportation. Protected A and B paper documents must be safeguarded, at a minimum, in a locked briefcase when transported. The briefcase must be labeled with a forwarding or return address and phone number of the CRA office. The locked briefcase must be placed in a locked trunk or out of sight in a locked vehicle.

4.4.7 Destroying information and assets

Information and documents that are no longer required and that have met their retention period must be disposed of in accordance with requirements and procedures approved by the Security Services Directorate of the Security Branch. Although protected documents and property do not concern national security, the information is nevertheless sensitive and may involve taxpayer and/or personal information. Waste that is designated as protected is sent for destruction, in keeping with established security standards.

For more information on disposing of protected and classified information and assets, go to Storage, Disposal, Transmittal and Transport of Protected and Classified Information and Assets Directive and Disposal of Protected and Classified Information and Assets Standards.

4.4.8 Security and use of property

CRA offices are frequently located in publicly accessible complexes. Auditors must politely question all strangers (including CRA employees they do not know and are not displaying a CRA identification card) and visitors in their immediate work area to ensure they have a valid reason for being there. If necessary, the local security office must be advised immediately.

Auditors are responsible for the proper care, handling, and safeguarding of furniture, equipment, and other property in their possession. They must return the assets when changing work locations or when employment is terminated.

Periodic checks are made to ensure that assets assigned to the auditor are still in their possession. In addition, standards such as the following should be used as a guide:

  • Expensive and attractive items such as computers, cell phones, calculators, tape recorders, and cameras must be securely stored when not in use.
  • Private property, such as purses, wallets, cash, and items of sentimental value should be kept in a safe place at all times. Purses and wallets should never be left unattended.
  • All losses and thefts should be reported to the local security office to facilitate possible identification of the person responsible and the return of recovered items.

Taking an interest in security is most important for the protection of public and personal property as well as for the safety of all CRA employees.

For more information, go to the Code of Integrity and Professional Conduct, under We protect our assets, and for taxpayer property and information held by the CRA, see We protect information.

Use of Crown property

Unless proper authorization is received, employees may not use equipment, material (including CRA identification cards), vehicles, or facilities owned or leased by the Crown for any purposes other than official purposes.

For more information, go to the Code of Integrity and Professional Conduct, under We protect our assets.

Intellectual property

Under section 72 of the Canada Revenue Agency Act, section 12 of the Copyright Act, and section 3 of the Public Servants Inventions Act, anything employees have created, designed, developed, or produced while doing their job becomes the property of the CRA. This includes software, computer devices, work methods, forms, and evaluation systems. To market or sell these items is breaking the law and the employee could face legal action.

When leaving the CRA, employees cannot take any documents or communicate unpublished information that was obtained while an employee of the CRA.

4.4.9 CRA computer information systems

The CRA operates one of the nation's largest private telecommunications networks. The network is used to conduct business with taxpayers using systems such as NETFILE, to communicate with each other using email systems, to communicate with other departments, and increasingly, to connect with other Internet-based contacts.

The CRA computer systems and electronic networks are valuable tools for obtaining, storing, and distributing information. The primary systems, databases, and networks, such as mainframe applications, are corporate resources provided for CRA business purposes only to authorized individuals to perform their duties, as outlined in the Information and Systems Security Directive.

All employees must have had a valid security status, clearance reliability check, or security clearance in order to access to the CRA's electronic networks.

Access to CRA information, systems, computers, and related devices is provided through a user account with a single, unique, and traceable user ID. All CRA employees accessing CRA systems and electronic networks are held accountable for any actions taken under their user ID.

The computer systems are protected by security systems; access is controlled by authorized personnel and monitored in real time. A control list is maintained and revised as needed by the CRA.

Passwords are particularly important, must be remembered and protected, and should never be shared with anyone. Employees must ensure any system or administrator passwords are kept in a safe place, in a protected format, and are only shared on a need-to-know basis. For more information, go to Passwords and User Account and Password Management Standards.

To prevent unauthorized access to CRA information and systems, all device screens (such as, workstations, desktops and laptops, and smart devices) must be locked at all times (CTRL + ALT + DEL followed by Enter, or Windows Key + L) when left unattended. Employees must log off at the end of each day, unless otherwise instructed by the Information Technology Branch.

Users are granted access to the departmental intranet and Internet systems to perform work‑related activities. The CRA promotes the use of the intranet and the Internet in a responsible and informed manner for work-related purposes. Unacceptable or unlawful activity is not permitted.

For more information, go to Service and digital.

Limited personal use

Users are authorized limited personal use of CRA secondary systems and electronic networks, such as email, Microsoft Office, and Internet under the following conditions:

  • All related legislation and CPIs are followed
  • Use does not interfere with employee performance or productivity
  • Use does not interfere with the conduct of CRA business
  • Use is not for financial gain
  • Use does not impose a performance or storage burden on CRA electronic networks, and use falls within meal and authorized break periods

Personal use must comply with the Code of Integrity and Professional Conduct and the Directive on Conflict of Interest.

For examples of acceptable and unacceptable use of CRA systems and electronic networks, go to Computer Systems and Electronic Networks Usage Directive.

4.5.0 Rights and obligations of auditors

4.5.1 Right to privacy

The Privacy Act protects the privacy of all Canadians with respect to personal information about themselves held by a government institution. That right is extended to the place of work. The Privacy Act provides the employee protection by limiting the extent that any organization, including the CRA, can go to when investigating employees or prospective employees.

4.5.2 Official languages

The Canadian Constitution states that English and French are the official languages of Canada and have equal status, rights, and privileges.

The main objectives of the Official Languages Act and its policies are to ensure that:

  • The public can obtain services from and communicate with the Government of Canada in both official languages (this is stated in the Taxpayer Bill of Rights)
  • Public servants can generally work in the official language of their choice
  • There is full participation for both French-speaking and English-speaking Canadians in the Government of Canada institutions

When auditors are occupying a bilingual position, their language obligations take precedence over their rights. They must always respect their clients’ language preference.

For more information, go to Official languages.

4.5.3 Employment equity and diversity

The CRA is committed to achieving equitable practices in the workplace by removing employment barriers for members of equity-deserving groups: women, persons with disabilities, Indigenous peoples, and visible minorities. The CRA strives to:

  • Have a workforce that reflects Canada's diverse population
  • Offer equal opportunities for advancement based on candidates' and employees' competencies and knowledge

The CRA goes beyond what is mandated by the Employment Equity Act and also takes into consideration additional equity-deserving groups such as 2SLGBTQI+ communities.

Employees are given the opportunity to voluntarily self-identify through the workforce profile questionnaire. The Workforce profile questionnaire is the only method that allows the CRA to determine the internal representation of designated group members. The information provided is kept confidential under the provisions of the Privacy Act and section 24 of the Pay Equity Act.

For more information, go to Employment equity.

4.5.4 Health and safety

The CRA developed a number of policies, standards, regulations, and guidelines concerning employee health and safety to ensure protection from exposure to occupational hazards and environmental conditions and factors. For more information, go to Occupational Health and Safety.

The CRA is committed to providing a healthy, physically and psychologically safe, violence-free, harassment-free, and inclusive workplace, which respects the requirements outlined in the Canada Labour Code (CLC), Part II and in the Work Place Harassment and Violence Prevention Regulations.

The Guide to preventing workplace violence provides information on risk factors that may contribute to incidents of workplace violence, warning signs for types of workplace violence, and suggestions for how to prevent these types of incidents from occurring.

The Workplace Harassment and Violence Prevention and Resolution Procedures outline the activities that the CRA must follow in order to identify risk factors and prevent workplace harassment and violence, as well as how to resolve occurrences of workplace harassment and violence when they arise. The goal of these different activities is to collaboratively identify the changes or preventive actions required to decrease the likelihood of harassment and violence occurring in the workplace. These procedures also provide details on how the responsibilities set out in the Directive on Occupational Health and Safety apply to prevent workplace harassment and violence.

The Standard Operating Procedures for Field Employees provide employees who are required to perform off-site visits and duties with measures that should be employed in order to minimize the risks to health and safety in executing their duties. Go to the KnowHow page Security in the field for information on interactions and best practices.

4.5.5 Suicide threat calls

For information on handling a suicide threat call, go to Suicide threat calls.

When a suicide threat call is received by an employee, the team leader or manager must be informed. As indicated on the page linked in the paragraph above, the team leader or manager must file a Security Incident Report (SIR) using the Emergency and Incident Management Electronic Tool (EIMET).

4.5.6 Administrative responsibilities

For internal forms used for administrative purposes, go to Registered internal forms and publications listing.

Time reports

Audit Divisions use weekly activity reports to track the units of production, time per unit, and time spent on other activities.

For more information, go to Time and Activity Recording (TAR) Instructions.

Travel reports

Field auditors may be required to travel on government business. The specific duties of the position determine the extent, nature, and frequency of travel.

The Directive on Travel, and the related Procedures on Travel, should also be consulted by the auditor when planning a trip.

For more information, go to the KnowHow page Travel.

International travel

For additional information on travelling outside of Canada for business purposes, go to Travelling outside of Canada on CRA business.

Supplementary Business Insurance

Auditors who use their personal vehicle for government business may need to increase insurance coverage to include business use (Supplementary Business Insurance or SBI). The need for additional coverage should be discussed with an insurance agent. If an additional cost is incurred, the auditor is entitled to reimbursement.

For more information, go to section 5.7.7.6 of the Procedures on Travel and to the KnowHow page TF9 Supplemental Business Insurance (SBI). 

4.6.0 Legal authority to conduct audits

Subsection 231.1(1) of the ITA and subsection 62(1) of the Underused Housing Tax Act (UHTA) provide the legal authority for authorized employees to conduct audits.

Pursuant to subsection 231.1(1) of the ITA, auditors may:

  • inspect, audit, or examine records
  • examine property and processes
  • enter any premises or place where any business is carried on, any property is kept, or any books or records are or should be kept
  • compel the taxpayer or any other person to answer questions, both orally and in writing, and to provide all reasonable assistance
  • require a taxpayer or any other person to provide all reasonable assistance

Paragraph 231.1(1)(a) enables an auditor to request household information when it is relevant in determining if the taxpayer has complied with their obligations under the ITA.

If the place referred to in paragraph 231.1(1)(c) is a personal dwelling, entry is expressly forbidden without the occupant's consent unless a judge has issued a warrant that authorizes entering the dwelling.

Paragraph 231.1(1)(d) enables auditors to compel the taxpayer or any other person to provide assistance at a place designated by the authorized person, by video-conference, or by another form of electronic communication. This paragraph specifies that auditors can require a taxpayer or any other person to respond to answer questions, both orally and in writing.

Subsection 231.5(1) of the ITA and section 66 of the UHTA allow authorized employees to make copies of documents. 

4.6.1 RC121A authorization card

Field auditors must identify themselves with their RC121A authorization card. Taxpayers must properly identify themselves at interviews and the presence of any third party must be authorized by the taxpayer.

Field auditors are provided an RC121A authorization card that outlines that the person named on the card is authorized to carry out their functions under the relevant provisions of the ITA, and the UHTA. According to RC121A, the bearer is authorized to administer and enforce various tax and benefit-related statutes listed on the CRA’s website. This authorization includes the legislative authority outlined in section 4.6.0, Legal authority to conduct audits.

The name on the RC121A authorization card must be the legal name, as shown on the authorized person's birth certificate or other official document (certificate of name change, marriage certificate, certificate of Canadian citizenship). A new card must be issued when a person legally changes their name.

The RC121A authorization card must not be used as a personal identification card or for any purposes for which it is not intended. It must be kept separate from the auditor's CRA identification card, and should never leave the auditor’s possession during field work. Any request to photocopy or photograph the RC121A authorization card must be denied for security reasons, but taxpayers may copy the wording by hand.

A lost or stolen RC121A authorization card is a security incident and must be reported immediately by completing a Security Incident Report (SIR) on the Emergency and Incident Management Electronic Tool (EIMET). For more information, go to the Security Incident Reporting and Management Directive.

Entering business premises when access is refused

The RC121A authorization card enables auditors to enter any business under audit and to request information, documents, and records, without prior notice. However, auditors conduct civil audits, not criminal investigations; therefore, entry cannot be forcibly imposed against taxpayer opposition.

If the taxpayer refuses and asks the auditor to leave the premises, the auditor should respect that and follow the guidelines in section 4.7.5, Specific guidelines for responding to unusual or threatening situations, to calmly leave the premises in order to avoid further conflict. 

4.7.0 Auditing under unusual circumstances

4.7.1 History

The information that follows is based on communiqué AD-01-02, Conducting Enforcement Actions under Unusual Circumstances. The communiqué provides guidelines that apply when conducting enforcement actions under unusual or threatening circumstances, including those situations that may arise as a result of various de-tax activities.

4.7.2 Tax protesters

Tax protesters are individuals or advocacy groups who protest Canada’s tax policy by various means which are often built around obscure constitutional and legal arguments. Some of these individuals and groups operate as business organizations which offer seminars, tax evasion material, and counseling for a fee.

Tax protesters encourage others to join in anti-tax movements through seminars and information sessions. Some de-tax organizers act as representatives for taxpayers in dealing with the CRA.

Common de-tax strategies used by taxpayers that are being encountered by auditors are:

  • Video or audio taping audits/interviews off CRA premises or within the taxpayers' places of business/premises
  • Requiring auditors to fill out questionnaires before allowing access to their books and records and/or premises
  • Refusing to file returns when required or filing returns filled with N/A (not applicable)
  • Using various technicalities to delay or postpone enforcement actions, for example, question constitutionality of federal taxes, making excessive requests for disclosure of information, and other harassment tactics
  • Putting liens on personal properties of auditors
  • Distributing derogatory, defamatory, and threatening statements against auditors through Internet and flyers

For more information on tax protester activities, go to the Tax protester information guide – Tax programs.

4.7.3 Responsibilities of team leaders regarding auditor security

If an assignment involves unusual or potentially volatile circumstances, the first priority for a team leader is to take any required action to protect the auditor and to prevent injury. The team leader must also ensure that enforcement actions are not postponed or delayed indefinitely. To do this, the team leader should:

  • Ensure that appropriate precautionary measures and procedures are in place, such as requiring auditors to provide precise itineraries and implementing a "buddy" system
  • Re-schedule any off-site meeting to be held instead on CRA premises or at another neutral location and/or attend the meeting with the auditor or assign a "buddy" to be present at the meeting
  • If appropriate, issue a requirement for documents or information, which would require that the records be made available at the CRA office
  • Discuss volatile situations with Department of Justice officials and the local security official to determine what alternative measures may be taken
  • Request police involvement or protection when volatile situations are expected
  • Notify the director and the local security official as soon as possible after an auditor reports an incident

4.7.4 Helpful safety reminders

General

Employee safety is the highest priority in any threatening or dangerous situation. Auditors must immediately remove themselves from such situations while ensuring their own safety, the safety of their families, and that of their colleagues and the taxpayer at all times. To assist in effectively implementing these guidelines, auditors should:

  • Adhere to established CRA work procedures, preventative measures, guidelines (such as the ones contained in the Corporate policy instruments (CPIs) - SB, and reporting requirements
  • Request guidance and assistance from their team leader, if required to call on and confront difficult individuals
  • Use best judgement to identify threats or prevent threats from happening when conducting audits and related tasks

Reporting known or suspected advocates of harassment and violence, intimidation, or abuse of government employees

In accordance with CRA security policies, the reporting of situations of threat, assault, or abuse, is required, no matter how the situation is perceived by the auditor or team leader. The auditor must also inform their team leader and their local security when a personal matter could jeopardize their safety and the safety of other CRA employees or their ability to conduct their duties.

Auditors who encounter or come across publicly available information on known or suspected advocates of violence, intimidation, or abuse of government employees, and non-compliance with tax legislation, in the course of performing their authorized duties, must report their findings to their team leader. The report should include relevant details on the persons or groups and the activities being advocated or promoted. In all cases, the management team will share the findings with other operational areas in the TSO. If the case has possible regional or national implications, the management team will notify other offices in the region and Headquarters accordingly.

Auditors are not to investigate persons or groups involved in these activities and they are not authorized to access confidential taxpayer information solely for this purpose. Unauthorized access to taxpayer information is an offence, and employees who attempt such access are subject to disciplinary measures, including dismissal.

Abusive telephone conversations

While speaking with taxpayers on the telephone, auditors may be subjected to name-calling, swearing, or ridicule, directed either at them or at the organization.

Auditors should attempt to focus the conversation on the taxpayer's specific tax related issues that created the situation and to limit the conversation to that subject. This can be achieved by asking questions to clarify any ambiguities or by obtaining facts, by remaining objective and polite, and by avoiding objectionable behaviour.

Should the abuse continue, the auditor must warn the caller that such behaviour will not be tolerated and that the telephone call will be terminated. If the offensive behaviour continues, the auditor must calmly end the conversation.

Abusive calls must be reported as security incidents to the team leader and local security official. Keeping complete records of all abusive conversations is important to ensure that the CRA can better assess the pattern of abuse, identify any escalating behaviors, and understand the potential threat a taxpayer may pose to CRA employees over time.

If a taxpayer makes statements which involve the threat of damage to government property, or the threat of harm or injury to a CRA employee or third party, this is considered a verbal threat. When this happens, a Security Incident Report (SIR) must be filed on the Emergency and Incident Management Electronic Tool (EIMET).

For more information, go to Aggressive, abusive, and threatening calls. 

Assignment with potential for an incident involving threat or violence

Auditors should be aware that an interview or meeting, on-site or off-premises, can become threatening, even though there is no indication of potential violence at the outset.

In preparation for a field visit, field auditors should always verify if a threat indicator is on the taxpayer's file. If a threat indicator is displayed, they must follow the instructions that appear on the screen. Auditors must never tell a taxpayer that a threat indicator is on their account.

Before entering any situation where there is a suspected risk of threats or violence, auditors should seek guidance and assistance from their team leader.

Auditors should adhere to the following precautionary measures if it is suspected that an assignment may be potentially volatile. These measures could minimize the auditors’ exposure to possible harm or injury:

  • A precise itinerary should be left to the team leader via email or Microsoft Teams indicating the name of the contact, telephone number, exact address of the taxpayer, and the times when the auditor is supposed to be at the taxpayer's premises.
  • The auditor should request the presence of the team leader or a "buddy" during the meeting with a taxpayer who is known or suspected to be hostile towards the CRA.
  • The auditor should schedule meetings with other CRA employees, on the same field trip, at specified times and places.
  • During the field visit, the auditor should contact the office at specified times. Failure to make a scheduled contact would alert the team leader of imminent trouble and enable them to take appropriate action.
  • As soon as a problem becomes imminent, the auditor must vacate the taxpayer's premises and/or contact the team leader.

When required to visit taxpayer premises, the auditor must be aware that taxpayers may own firearms or other weapons (including guard dogs).

If there is a perceived risk or if they are threatened with a weapon, the auditor must leave the premises immediately. The auditor must call the police immediately if the threat is imminent, and report the situation to their team leader or the security official as soon as possible.

Auditors should refer to the Standard Operating Procedures for Field Employees for information on measures that should be employed in order to minimize the risks to health and safety in executing their duties.

4.7.5 Specific guidelines for responding to unusual or threatening situations

Video or audio recording

When a meeting with a taxpayer takes place on CRA premises, the auditor must not consent to being video taped or recorded. This is to ensure the privacy of other taxpayers and to protect sensitive information. If the taxpayer insists on recording while on CRA premises, the meeting must be terminated immediately, and the taxpayer informed that management will be in contact to discuss the issue and make other arrangements.

When a meeting occurs at a taxpayer’s premises, the CRA has no legal authority to prevent a taxpayer from audio- or video‑recording an interview, audit, or examination. A taxpayer who records on their own property is not violating any law. However, auditors are not permitted to make audio or video recordings of interviews.

If an auditor becomes aware that they are being recorded, they should stop the interview, explain the reason for discontinuing the interaction, advise that alternative arrangements will be made, and inform the taxpayer that management will follow up regarding the matter. Auditors should be comfortable in discontinuing all interactions upon discovering that they are being recorded. Doing so does not infringe any taxpayer rights.

The auditor must document the incident in Form T2020, Memo for File, including details of the reporting to management for further analysis.

Demands for personal and other irrelevant information

For reasons of personal security, auditors must never provide any of their personal information to taxpayers, such as a home phone number or address, or produce personal documents such as a driver's license.

If the taxpayer demands other irrelevant information from the auditor and hinders them from performing their duties, the meeting should be terminated. The incident must be reported to the team leader.

Questionnaires, forms, and non-disclosure agreements

Auditors must never sign or complete a questionnaire or any other form produced by the taxpayer or their representative. Auditors must inform their team leader that the taxpayer or their representative made such a request.

If a taxpayer refuses to allow an auditor to conduct an audit because the auditor has refused to sign a form, the usual enforcement measures (such as issuing a request for documents or information) should be followed.

Some taxpayers are concerned that sensitive information may be divulged inappropriately and have requested that the auditor sign a non-disclosure agreement before allowing access to the records and premises. Auditors must never sign a non-disclosure agreement. Instead, the auditor should inform the taxpayer that the Access to Information Act and the Privacy Act strictly control how the government collects, uses, stores, discloses, and disposes of any personal information. Auditors should also inform the taxpayer that the ITA includes strict confidentiality provisions.

For more information, go to 10.2.2, Legislative authorization to inspect, audit, or examine books and records.

Reviewing records at a taxpayer's residence

Reviewing books and records at a taxpayer's residence could leave the auditor vulnerable to accusations of wrongdoings by the taxpayer. This is because the auditor may be left alone with the books and records most of the time, and also has access to the taxpayer's household belongings or properties.

To minimize being placed in a compromising situation, the auditor should consider:

  • Borrowing the books and records and doing the review in the office or a hotel room, with the taxpayer's consent. Some taxpayers may consider borrowing books and records as a form of seizure by the CRA, which is why this is only an option.
  • Avoiding after-hour appointments for conducting the review, if possible.
  • Requesting the presence of a "buddy" and/or the taxpayer or representative at all times, if the review has to be conducted at the taxpayer's place of residence.

Offensive or threatening interviews

If, during a meeting, the taxpayer or their authorized representative start using offensive or intimidating language or behaviour, or cause the auditor to feel threatened, the auditor should:

  • Calmly suspend or terminate the interview as soon as possible
  • Consult the team leader to decide on appropriate measures that should be taken
  • Prepare a written report of the incident, detailing all relevant facts

When the meeting is being held on CRA premises, the auditor should immediately advise the team leader and local security, and call the police.

When the meeting is being held off-premises, the auditor must immediately remove themselves from the situation and call the police. The incident should also be reported to the team leader and local security as soon as possible.

If the auditor experiences any kind of difficulty terminating the meeting or removing themselves from the situation, they should try to attract the attention of other persons in the vicinity.

Threatening correspondence

When receiving threatening correspondence (by any means), either at the office or at home, auditors must avoid unnecessary handling of the correspondence, and turn it over to the local security official as soon as possible.

Lien on personal property

If a tax protestor has registered a lien on an auditor’s personal property, the incident should be reported to the team leader immediately. The management team will request local Department of Justice officials to take the necessary action to facilitate removal or de-registration of the improper lien. The incident should be reported to Headquarters, including the Security Services Directorate of the Security Branch.

Assaults

The safety of auditors is paramount and must prevail above and beyond any action, and takes precedence over any duty. When the potential for assault exists and the auditor’s safety appears to be at risk, the auditor must:

  • Not restrain or agitate the taxpayer or representative
  • Vacate the premises immediately
  • Use best judgement on how to secure personal safety and protection if unable to leave, such as calling for help using a cellular telephone or attracting attention of other people nearby
  • Call the police as soon as possible, if assaulted, follow their instructions, obtain a medical examination from a qualified physician, and alert the team leader as soon as possible
  • Prepare a written report of the incident, detailing all relevant facts

In situations where an assault has taken place on or off CRA premises, the auditor must withdraw from the danger area to a location from where they could attract the attention of other CRA employees or of the general public.

The auditor must connect with the Security Branch’s Security Incident Reporting and Management, and report the incident by filing a Security Incident Report (SIR) on the Emergency and Incident Management Electronic Tool (EIMET).

In situations where an auditor is being prevented from leaving the danger area, they should attempt to seek help from nearby persons, by shouting or by making noise.

Note that there is an obligation on the auditor's part to retreat as far as is feasible and to de-escalate any potential violent situations.

Post-incident help, employee compensation, and benefits

The CRA is committed to protecting, supporting, and assisting its employees and their families where there has been any act of threat, assault, or abuse directed against them or their property in the performance of their duties, or as a direct result of the performance of their duties. This support is available in many forms, including counselling through the Employee Assistance Program (EAP). The team leader should contact their Local Human Resources advisors for details on the support available and for procedures to be followed in order to obtain it.

Team leaders are encouraged to recommend the Employee Assistance Program (EAP) to their employees whenever an incident has affected their physical, mental, and/or emotional well‑being.

For more information, go to the Security Incident Reporting and Management Directive and to the Security Incident Reporting and Management Procedures. 

4.8.0 Laptop use, care, and security

4.8.1 Background

Equipment is provided to the auditor for official purposes at the office, at the taxpayer’s place of business, while in travel status, or any other location where CRA business is conducted, including telework locations.

Laptops are a very important tool for use in the audit process. Proper use and care of the equipment is necessary to prevent damage and to safeguard the assets of the CRA as well as the security and confidentiality of taxpayer information.

The portability of laptops increases the risk of loss and potential damage both in transit and at the work site. Software and sensitive information stored on the laptop requires safekeeping.

4.8.2 Responsibility of users

Users are responsible for:

  • Performing regular backups of information (saving documents in a corporate shared repository, such as a shared drive or GCdocs, rather than on a laptop’s hard drive (C: drive) or on a personal (H:) drive, ensures files are automatically backed up on the CRA network, and that they remains accessible by others with a need-to-know).
  • Ensuring equipment and electronic media is securely stored according to the Storage of Protected and Classified Information and Assets Standards.
  • Providing a clean area for laptop use and cleaning the laptop when necessary (for more information, go to 4.8.4, Laptop preventative care and maintenance).
  • Reporting any problems encountered with equipment or software.
  • Observing software licensing agreements.
  • Observing suggested security guidelines for the use and care of equipment.
  • Ensuring sensitive information stored on Portable data storage devices (PDSDs) is encrypted using CRA-approved encryption software as per the Storage of Protected and Classified Information and Assets Standards and the Electronic Devices Standards.
  • Scanning all PDSDs for viruses on a CRA computer that is not connected to the network before using the CRA equipment (for more information, go to 4.8.6, Security of software).
  • Handling and storing PDSDs as recommended by the manufacturer.
  • Locking PDSDs and other information in a secure place when not in use (including when working outside of a CRA worksite, such as when teleworking).
  • Protecting passwords at all times.
  • Employees must use a security key to create a personal identification number (PIN) for signing into Windows and accessing cloud resources such as Microsoft Teams, SharePoint, or OneDrive. The security key is a device, similar in form to a USB key, that authenticates users when accessing cloud services, and is the default method for signing into Windows. Using the key reduces the risk of unauthorized access to CRA devices, helps eliminate cyber security threats that arise from using only a username and password, and decreases the possibility of user credentials being compromised through phishing attacks. By using this universally accepted technology, the CRA follows the policies and guidance on multi-factor authentication issued by the Treasury Board Secretariat and the Canadian Centre for Cyber Security. For more information, go to Internal Multi-Factor Authentication (IMFA).
  • Immediately reporting any actual or suspected loss, as well as unauthorized disclosure of sensitive information or access to CRA computer systems, according to prescribed procedures.

4.8.3 Laptop general use and care

  • The following suggestions are provided to limit problems that may be encountered if laptops are not cared for appropriately:
  • Do not move the laptop when the disk is in operation. The laptop should be turned off prior to moving it to ensure that the disk head is parked.
  • If the laptop has been exposed to extreme cold, allow it to warm to room temperature prior to use. This will take approximately 60 minutes.
  • The power should be left on when the laptop is not in use for short periods of time. Turning the power on and off several times during the course of the day may cause damage to the power supply.
  • The power should not be turned off during an application. Improper exits from an application may cause loss of data files. Files are not encrypted when the application is not exited properly.
  • The "Shut down" procedure closes files and removes temporary files from the directory. If this procedure is not completed, the system prompts the user to scan the disk at start-up to ensure that the integrity of system has not been compromised.
  • Power should be switched off prior to unplugging the laptop or attaching any peripheral equipment such as a printer.
  • Flipping the screen to the closed position will shut off the display, allow the screen to cool down after long periods of use, and protect the screen from damage.
  • Ensure that the screen saver feature is password protected and used when away from the laptop for short periods of time.
  • Using the legs at the rear of the laptop (if available) increases air circulation around the equipment and keeps it from overheating. The legs also provide a more comfortable angle for working at the keyboard.
  • Extreme caution should be exercised with food and drink around the laptop to prevent costly repairs and down time.
  • Carrying carts should be used only if absolutely necessary to transport the laptop.

4.8.4 Laptop preventative care and maintenance

The auditor should follow these suggestions to keep the laptop available for use:

  • Check the carrying case and strap for wear.
  • Clean the screen using the materials provided. Individually packaged wipes are available in most offices. If spray cleaners are used, always spray the cleaner on a clean cloth, never on the screen.
  • Dust and small particles can be removed from the keyboard using a can of condensed air. The nozzle should be positioned properly towards the keyboard. Short bursts of the condensed air are aimed at the keyboard to remove small objects and dust that collect between keys over time. A soft damp cloth can be used to wipe the surface of the keyboard when not in use. Keeping the cover closed when the laptop is not in use will not only prevent damage to the screen but also help prevent the collection of dirt in and on the keyboard.
  • Avoid attaching sticky labels to the laptop.

4.8.5 Security guidelines for laptops

Physical security

The portable nature of laptops makes them particularly susceptible to theft. Auditors are expected to exercise reasonable care to prevent loss and damage.

  • Laptops must never be left in a vehicle overnight. Likewise, they must never be left where visible to passers-by while the vehicle is parked and unattended.
  • When the laptop must be left in a vehicle, it should not be visible. If possible, the laptop should always be locked in the trunk when in transit.
  • When travelling by air within Canada, the laptop must be kept under the control and possession of the auditor at all times, and should not be checked as baggage.
  • If travelling outside of Canada by air on Commissioner-approved CRA business, send an email to the Security-International CRA Travel / Voyage d’ARC Internationaux-Sécurité (CRA-ARC) mailbox for best practices.
  • All laptops should be marked with CRA identification numbers. A label with a forwarding or return address and phone number of the CRA office must be attached to the carrying case. Additional identification (such as a business card) should be placed inside the carrying case.
  • Laptops should be locked in a secure place at night. When working outside of a CRA worksite, such as when teleworking, laptops that contain up to and including Protected B information, must be stored out of sight, when not in use.
  • Loss or theft of equipment or information must be reported immediately to the team leader and by filing a Security Incident Report (SIR) on the Emergency and Incident Management Electronic Tool (EIMET). The CRA is responsible for replacing the equipment if there is no evidence of negligence on the part of the employee.

4.8.6 Security of software

Software installed on laptops must not be copied. Software agreements and copyright restrictions should be followed at all times. Copies of programs developed by the CRA, such as penalty and interest programs, are not to be made available to the public.

All software from sources outside the CRA should be scanned and tested for viruses to minimize the risk of infecting the PC environment. Portable data storage devices (PDSDs) used on external PCs should be scanned on a computer that is not connected to the network prior to using on CRA hardware since they can contain viruses and malware.

If a virus is found on software or on a PDSD, it should be reported as soon as possible to prevent possible spreading.

For more information on security considerations related to the use of software, go to the Software page.

4.8.7 Personal use of laptops

Limited personal use of CRA-issued laptop computers is permitted, provided that the personal use complies with CRA policies and legislation, and if the productivity and performance of the auditor and their colleagues are maintained. For more information, go to 4.4.9, CRA computer information systems, under Limited personal use.

4.8.8 Support

The following procedures should be followed when the laptop requires servicing:

  • Document what occurred prior to the failure or problem; record any error messages or numbers that are displayed
  • Contact the National IT Service Desk by using the Fusion – Service Portal
  • For urgent issues, call the National IT Service Desk
  • If the laptop failure significantly affects the completion of any audits in progress, the team leader should be advised

Page details

2026-07-01

Quick Enquiry

We usually reply within a few hours
By submitting you agree to be contacted about your enquiry.
Call us Chat on WhatsApp
M

Migova AI Assistant

Online now
Hi 👋 I'm the Migova AI assistant, powered by OpenAI. Ask me about PR, study visas, work permits, LMIA, family sponsorship, provinces, or healthcare immigration to Canada.
Canada PR
Study Visa
LMIA / Work Permit