Abbotsford AI Procurement Rules - City Bylaw Guide
This guide explains how Abbotsford, British Columbia staff must approach procurement of artificial intelligence (AI) tools for municipal use. It summarizes the city procurement framework, required reviews for data and privacy, approval routes, and practical steps staff should follow before acquiring or deploying AI-based software or services. Where the city’s official procurement or privacy pages are referenced, links point to those sources for details and contacts. Procurement Services[1]
Scope & When These Rules Apply
These rules apply when staff seek to purchase, license, commission, or subscribe to AI tools or services that will be used in providing municipal programs, storing or processing city data, or affecting decisions about the public. Common examples include predictive analytics for service demand, automated licence-plate recognition, natural language processing for public inquiries, and decision-support models used by city departments.
Key Compliance Steps Before Procurement
- Conduct a needs assessment and document the intended use and expected outcomes.
- Complete a privacy impact assessment or data protection review when the tool accesses personal or sensitive information. FOI & Privacy[3]
- Identify technical, security, and integration requirements and confirm compatibility with city infrastructure.
- Engage Procurement Services early for procurement method, competitive requirements, and contracting templates. Procurement Services[1]
- Obtain necessary departmental and legal approvals before committing to licensing or cloud-hosting arrangements.
Procurement Methods and Thresholds
Abbotsford’s purchasing procedures determine whether a competitive process, request for proposals, or sole-source approval is required. Staff must follow the thresholds and processes set by the city’s procurement policy and use approved contract templates for software, cloud services, and data processing agreements. City bylaws and policies[2]
Penalties & Enforcement
Enforcement for procurement non-compliance is handled through the city’s Procurement Services and the Corporate Services/legal team; bylaws and internal policies provide the controlling instruments. Specific monetary fines, scales, or administrative penalties for internal procurement breaches are not typically published as bylaw fines on the public procurement pages and therefore are not specified on the cited page.[1]
- Monetary fines: not specified on the cited page.
- Escalation: first, repeat, or continuing internal infractions and their disciplinary steps are not specified on the cited page.
- Non-monetary sanctions: contract termination, suspension of procurement privileges, requirement to remediate security/privacy gaps, and referral to legal action are used as administrative remedies where authorized by contract or policy.
- Enforcer and complaints: Procurement Services coordinates compliance and investigations; By-law Enforcement handles bylaw breaches where applicable. Use official Procurement contact pages to report suspected procurement irregularities. Procurement Services[1]
- Appeals and reviews: specific appeal routes and time limits for procurement protests or internal disciplinary appeals are not specified on the cited page.
Applications & Forms
The city publishes procurement guidance and contact points; specific vendor registration, purchase requisition, or AI-specific application forms are not clearly listed on the public procurement pages and are therefore not specified on the cited page. Departments should contact Procurement Services for required templates, requisition forms, or bidding documents.[1]
How-To
- Identify the business need and list data, privacy, and technical requirements.
- Consult Procurement Services and Corporate Services to select an appropriate procurement route.
- Complete privacy/data impact review and obtain approvals before issuing any solicitation.
- Run the competitive process or obtain documented sole-source approval; finalize contract terms including data use, security, and termination rights.
- Monitor deployed AI tools for performance, fairness, and compliance; report incidents per corporate procedures.
FAQ
- Do staff need a privacy review before buying an AI tool?
- Yes. If the tool accesses or processes personal or sensitive data, a privacy impact assessment or equivalent review is required; consult the city’s FOI and privacy guidance. FOI & Privacy[3]
- Can a department award a sole-source contract for an AI system?
- Only with documented business justification and Procurement Services approval; follow the city’s procurement policy and approval matrix. Procurement Services[1]
- Who enforces procurement compliance?
- Procurement Services and Corporate Services coordinate enforcement and remedial actions, with By-law Enforcement involved where public bylaw issues arise.
Key Takeaways
- Engage Procurement Services early and document approvals.
- Perform privacy and data-impact reviews for tools handling personal information.
- Use approved contracts that specify security, data use, and exit rights.
Help and Support / Resources
- Procurement Services - City of Abbotsford
- By-law Enforcement - City of Abbotsford
- Freedom of Information & Privacy - City of Abbotsford