main logo icon

Published on

September 13, 2026

|

20 min read

TGV Certification for AI Health Tools in Quebec (2026): 69 AI Criteria and the Pentest

Quebec's TGV criteria list changed on 24 April 2026: 382 criteria in seven domains, including a new AI domain of 69. What AI scribes, decision-support and generative tools must document, test and log, and how the mandatory penetration test covers them.

Arafat Afzalzada

Arafat Afzalzada

Founder

LLM SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

On 24 April 2026 Quebec's health certification bureau replaced the TGV verification criteria list. The new list holds 382 criteria in seven domains, up from 254 in six, and adds an artificial intelligence domain of 69 criteria in nine categories. The AI domain applies to any "solution ayant recours à l'intelligence artificielle" (SARIA). It covers automated decisions, pre-certification testing, documentation, responsible use, data sharing, access logging, monitoring and human review, and bans advertising and manipulative design. For generative AI it requires a report describing malicious prompt injection tests (IA12), sources shown with every generated result (IA57), and no personal information sent outside Quebec by any component, including calls to generative models, without explicit consent (IA40). The mandatory independent penetration test, now criterion S16.03, applies to the whole product. The bureau's orientation requires white box testing, a production-equivalent environment and every role tested, which pulls the model-facing surfaces, the retrieval layer and any agent tooling into scope. Five AI transcription products were already on the bureau's register by December 2025, and Tali announced its certification in July 2026. The list's ISO references show where the criteria come from: ISO/IEC 23894, 25058, 27563 and 24368. A supplier with an AI feature should plan the injection test report, the logging and role-based access evidence, and the penetration test together, at least three to four months before verification.

On 24 April 2026 the Bureau de certification of Santé Québec replaced the verification criteria list behind the TGV certification. The document now linked from the ministry's orientations page, Critères de vérification de la TGV, version 2026-04-24, contains 382 criteria in seven domains. The June 2024 list it supersedes had 254 in six. The whole difference is not one new domain, but the largest single addition is: an artificial intelligence domain of 69 criteria, organised in nine categories, applying to any product the list calls a solution ayant recours à l'intelligence artificielle, or SARIA.

The timing is not accidental. The bureau's register of certified products already carried a family named Reconnaissance vocale et transcription basé sur IA by December 2025, with five AI scribe and transcription products on it, and AI-branded tools sat in the imaging, decision-support and data-processing families too. In July 2026 Tali announced its own TGV certification for its AI scribe. Every one of those suppliers, and every founder who wants to join them, now certifies against the AI domain as well as the security, privacy and interoperability domains that were already there.

This guide is written for the CTO, security lead or compliance owner of an AI health product that needs to enter Quebec's health and social services network. It explains what changed, what the 69 AI criteria require, and how the mandatory independent penetration test, itself renumbered and reworded in the 2026 list, covers the AI parts of the product. For the certification as a whole, the process, the fee and the deadlines, our TGV certification guide is the reference; this page goes deep on AI.

Quick answer: An AI health tool needs TGV certification on the same three conditions as any other product: it handles health or social services information, it interfaces with a common-interest information asset, or it is deployed in more than one Quebec establishment with web access. Since 24 April 2026 the bureau's criteria list contains 382 criteria in seven domains, including 69 artificial intelligence criteria that require, among other things, a report of malicious prompt injection tests for generative AI (IA12), human review of automated decisions (IA3 to IA7), role-based access and logging of every AI interaction (IA47 to IA51), sources shown with generated results (IA57), and no personal information sent outside Quebec by any AI component without explicit consent (IA40). The independent penetration test required by criterion S16.03 covers the AI components under the bureau's existing rules: white box, production-equivalent environment, every role tested. Where Stingrai fits: Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with published pricing from US$3,000 per assessment for one web application and its APIs (pricing) and every other scope quoted.

What changed on 24 April 2026

The criteria list is the closest thing to an exam syllabus the bureau publishes, and the ministry's guide has always described it as a representative sample rather than the whole verification. Counting the rows of the two published workbooks by their Groupe column gives the following.

TGV verification criteria by domain, June 2024 list versus April 2026 list

Domain

List of 18 June 2024

List of 24 April 2026

Categories (2026)

Security (Sécurité)

104

112

16

Protection of personal information (PRPS)

75

108

20

Artificial intelligence (new)

0

69

9

Interoperability

56

58

6

Technology

9

26

1

Performance

7

7

1

General

3

2

1

Total

254

382

54

Four changes matter beyond the totals.

The penetration test criterion moved and was reworded. In the 2024 list it was S16.02: "Votre application a fait l'objet d'un test d'intrusion par un prestataire indépendant et reconnu par le MSSS." In the 2026 list it is S16.03: "Soumettre votre application à un test d'intrusion administré par un prestataire indépendant et reconnu par Santé Québec." ("Submit your application to a penetration test administered by an independent provider recognised by Santé Québec.") The recognising body is now named as Santé Québec, and the evidence instruction attached to the criterion asks for "une copie du rapport expliquant les résultats du test, la nature du test et, le cas échéant, le plan d'action qui en découle" ("a copy of the report explaining the test results, the nature of the test and, where applicable, the resulting action plan"), with a direct link to the bureau's penetration testing orientation.

A technical compliance strategy is a criterion of its own. The new S16.02 asks the supplier to "disposer d'une stratégie de validation de la conformité technique des différentes composantes de votre application et de son environnement," including assets entrusted to suppliers, and its evidence instruction asks how, when, what and how often that validation is performed. The annual penetration test is one input to that strategy, not the whole of it.

Privacy grew by a third and technology tripled. The PRPS domain went from 75 to 108 criteria, now in 20 categories including privacy impact assessments (EFVP), de-indexing, portability and third-party suppliers. The technology domain went from 9 to 26, adding hosting in Santé Québec spaces or a cloud space approved by the ministère de la Cybersécurité et du Numérique, separate development, test, pre-production and production environments, identities from Santé Québec's central directory, and use of the government API catalogue.

The AI domain is new in its entirety. Its 69 criteria are numbered IA1 to IA69 and its reference column cites ISO/IEC 23894 (AI risk management), ISO/IEC 25058 (quality evaluation of AI systems), ISO/IEC 27563 (privacy in AI use cases) and ISO/IEC 24368 (AI ethical and societal concerns), alongside the bureau's own guidance. The rest of this guide is about those 69.

Does your product count as a SARIA?

The first AI criterion defines the trigger. IA1: "Si votre solution fait appel à une composante en intelligence artificielle (solution ayant recours à l'intelligence artificielle, SARIA), ceci doit être clairement mentionné dans la documentation." Any product with an AI component is a SARIA, and the documentation has to say so. IA18 then requires the documentation to name the type of AI involved: symbolic, machine learning, generative or other.

That definition is deliberately wide. It catches the obvious products, ambient scribes and transcription tools, and it catches a triage rule engine, an imaging model, a scheduling optimiser, a chatbot in a patient portal, and a large language model summarising a chart inside an otherwise conventional electronic medical record. The register's December 2025 edition shows how varied the certified population already is:

Family on the register

AI-labelled products certified (version, date)

AI voice recognition and transcription

ScribeMD (EE Dojo Inc., 1.0.x, 4 December 2024); CoeurWay (Laboratoire CoeurWay Inc., 1.0.x, 20 February 2025); Plume IA (Plume IA Inc., 1.1.x, 20 June 2025); AutoScribe (Mutuo Health Solutions Inc., 1.19.x, 25 July 2025); Plateforme MedAssistant (9462-9045 Québec Inc., 6.x, 7 August 2025)

Data processing tools

Makila AI (Services Makila Inc., 7.17.x, 30 April 2025); Medeloop (Medeloop Canada Inc., 1.0.x, 17 June 2025)

Other families

Omega AI (RamSoft, Inc., 1.0.x, 1 November 2024); Milvue Suite (Milvue Amérique du Nord inc., 1.27.x, 11 March 2025); Voxira.ai (Solutions Informatiques SECAI Inc., 1.x, 30 May 2025); Algorithme de dépistage préventif de la santé des adultes (Technologie Med, 1.0.x, 11 July 2024)

Every product certified before 24 April 2026 was verified against the 2024 list. A certified version stays certified; a new major version goes back to the bureau and, on the current list, meets the AI domain. Suppliers planning a major release of an AI product in 2026 or 2027 should read the nine categories below as the syllabus for that reverification.

The 69 AI criteria, by category

The 69 artificial intelligence criteria in the April 2026 TGV list, by category

Category (French name in the list)

Criteria

What the bureau is asking for

Use of AI systems (Utilisation de systèmes IA)

7

Declare the AI component; publish a plain-language privacy policy covering it; explain and allow review of automated decisions

Development process (Processus de développement)

5

Tests for behaviour differences across groups, fitness for the intended use, an evaluation strategy with false positive and false negative rates, and, for generative AI, variability and prompt injection test reports

Documentation

20

Intended use, limitations, bias controls, datasets, AI types, prior deployments, improvement plan, architecture, user training, environmental footprint, anonymisation methods, agent controls, synthetic data, train/validate/test separation

Responsible use (Utilisation responsable)

6

Collaboration with responsible-AI researchers, a risk register, disclosure of new risks, training data integrity, rights over datasets

Communication and sharing (Communication et partage)

8

Personal information protected under Quebec law and not sent outside Quebec, disclosure of any data sale, a per-model kill switch, no machine learning on usage data without authorisation

Data access (Accès aux données)

5

Logged and traceable access and decisions, role-based restrictions on what a user can see and do, usage data available to the acquirer

Monitoring and control (Surveillance et contrôle)

7

Extractable record of user approvals and changes, intermediate results visible, adaptation under acquirer approval, sources shown for generative output, flagging of inadequate results

Review process (Processus de révision)

9

Limitations shown on screen, user always free not to use or accept, human inputs never overwritten after final validation, version visible and stamped on results, agent controls, checkpoints on external calls, internal notifications limited

Artificial intelligence (general)

2

No sponsored triggers of any kind; no subliminal techniques

The categories below are the ones where security testing, logging and architecture decisions carry the evidence.

Automated decisions: IA3 to IA7 mirror Law 25

Five criteria transpose section 12.1 of Quebec's private-sector privacy statute into product requirements. IA4: "La SARIA doit informer la personne concernée que la décision a été rendue sur la base d'un traitement automatisé de ses renseignements personnels." IA5 requires that, on request, the SARIA can supply the personal information used, the reasons and factors behind the decision, and the right to correct the information. IA6 requires the opportunity to present observations to a staff member able to review the decision, and IA7 requires that a human can review it.

The statute says the same. Section 12.1 of the Act respecting the protection of personal information in the private sector, as amended by Law 25 and current to 7 April 2026, requires any enterprise that "uses personal information to render a decision based exclusively on an automated processing of such information" to inform the person, to provide on request the information used, "the reasons and the principal factors and parameters that led to the decision," and the right to correction, and to give the person "the opportunity to submit observations to a member of the personnel of the enterprise who is in a position to review the decision." A product that meets IA3 to IA7 has built the section 12.1 workflow into its interface. A product that has not will fail both.

Testing before certification: IA8 to IA12, including the injection test report

The development-process category is where the bureau asks for evidence that the model was tested, not just built.

  • IA8: a testing process was carried out to identify differences in the SARIA's behaviour across the conditions or social groups present in its context of use.

  • IA9: a testing process established the SARIA's fitness for the intended use.

  • IA10: the evaluation strategy for the model or models is available and includes the metrics and the positive, negative, false positive and false negative results.

  • IA11: for generative AI, a report describing the degree of variability of results for the same situation.

  • IA12: for generative AI, "un rapport décrivant des tests d'injection de requêtes malveillantes doit permettre à l'acquéreur d'établir le risque inhérent à la conception de requêtes de la SARIA et le besoin de contrôle, formation et explicabilité liés à la formulation des requêtes." In English: a report describing malicious prompt injection tests must allow the acquirer to establish the risk inherent in the SARIA's prompt design and the need for controls, training and explainability around how prompts are formulated.

IA12 is the first place a Quebec health certification names prompt injection as something a supplier must test and report. It maps directly to LLM01:2025 Prompt Injection in the OWASP Top 10 for LLM Applications, and it is the criterion an AI scribe, chart summariser or patient-facing assistant is least likely to have evidence for today. The report the bureau describes is not a scanner export. It has to show which injection techniques were tried, direct and indirect, through user text, uploaded documents, retrieved records and tool outputs, what the model did, and what controls, training and explainability the acquirer therefore needs. That is a penetration test deliverable, and the natural way to produce it is inside the annual test the certification already requires.

Documentation: the 20 criteria that describe the model

The documentation category is the largest. Several items decide how a verifier and a penetration tester will scope the product: IA17 (datasets used for training, validation and testing are listed), IA18 (the type of AI), IA20 (the supplier commits not to change the AI types or models without the acquirer's explicit approval), IA24 (an architecture description covering the components and their interactions, the AI concepts, approaches and techniques used), IA27 (anonymisation or de-identification methods documented), IA30 (where autonomous agents are used, a description of how the agents are controlled and monitored and how incidents are reported to the acquirer), IA31 (synthetic training data justified), and IA32 (separate datasets for training, validation and testing, with the methodology documented). Two criteria, IA26 and IA29, ask for the environmental footprint of development and use and how the supplier minimises it.

For a supplier, IA24 is the document to write first. The architecture description it requires, model components, retrieval layers, tool integrations, external model APIs, is the same artefact the penetration testing orientation needs to define attack vectors "en fonction des criticités du PST."

Responsible use and training data: IA33 to IA38

IA33 commits the supplier to collaborate with responsible-AI researchers and a committee of potential users on a risk analysis. IA34 and IA35 require a risk register and disclosure to the acquirer of any new risk arising from the SARIA, its models or its datasets, with the obligation passed up to a primary developer where the product is built on someone else's model. IA36 forbids training on datasets that were corrupted or whose integrity may have been compromised in the five years before use, and IA37 requires monitoring for events that could have compromised training data integrity for the life of the product. IA38 requires that the supplier holds the rights to the datasets used for training, notably where they contain personal information.

IA36 and IA37 are, in security terms, a data and model poisoning control (LLM04:2025). Evidence for them is a documented provenance and integrity process, not a test result, but a penetration test that reaches training or fine-tuning data stores through the application is the failure mode the criteria are guarding against.

Data residency and sharing: IA39 to IA46

IA39 requires that any communication of personal information by or between SARIA components meets Quebec law. IA40 is the one that changes architectures: "Aucune communication de renseignements personnels, qu'ils soient d'usagers ou d'utilisateurs, ne sera faite par aucune composante de la SARIA (y compris les appels à des modèles d'IA générative) à l'extérieur du territoire du Québec," unless the person concerned consents in an informed, explicit and unequivocal way. No personal information leaves Quebec through any AI component, including calls to generative models, without that consent. Section 17 of the privacy statute already requires a privacy impact assessment before communicating personal information outside Quebec; IA40 turns the default into "do not."

IA41 to IA44 require disclosure to the acquirer, and in IA41's case to the bureau, of any communication or sale of data linked to the SARIA, any product built from its usage data, any third party with an interest in that data, and any unsolicited analysis of usage data. IA45 requires functions that let the acquirer inhibit calls to one, several or all models in the event of a failure, an outage, a patient's refusal or an administrative decision. IA46 forbids machine learning on usage data without the acquirer's explicit authorisation.

For a penetration tester, IA40 and IA45 are testable claims: where do model calls actually go, what is in the payload, does the kill switch really stop them, and can a lower-privilege user or a compromised integration re-enable them.

Access, logging, monitoring and review: IA47 to IA66

The data-access category is a conventional security control set applied to the AI layer. IA47: access to the SARIA is logged and traceable, along with the decisions, reactions and comments made by users. IA48: those logs remain accessible for as long as the decisions the SARIA supports can be questioned in court. IA49 and IA50: access is secured so that a user cannot consult data, information or documents, or perform tasks, that their job or role does not authorise. IA51: usage data and results are logged and available to the acquirer.

IA49 and IA50 are the authorisation criteria, and they are where AI products most often fail a well-scoped test. A retrieval-augmented assistant that answers a clinician's question from the wrong patient's record, or a scribe whose API lets one practitioner fetch another's draft notes, fails IA49 through the AI feature even if the underlying record system enforces access correctly. The bureau's penetration testing orientation already requires every role to be tested in its intended context; for a SARIA that means every role against the AI endpoints, not only against the screens.

Monitoring and review then add: an extractable record of the approvals and changes users make to results (IA52), intermediate results visible where possible (IA53, IA54), role-appropriate access configurable by the acquirer (IA55), adaptation by learning only under acquirer approval (IA56), sources presented with generated results and reachable from the interface (IA57), a mechanism to flag inadequate results, logged and extractable (IA58), limitations and warnings shown on the screens where results appear (IA59), a user who is always free not to use the tool or not to accept a recommendation (IA60), no overwriting of human validations after final validation (IA61), explanations of what the model considered (IA62), a visible version that changes on update and is stamped on each result (IA63, IA64), controls and monitoring for autonomous agents (IA65), and automatic checkpoints on calls to external components with a continuation strategy if they fail (IA66).

IA65 and IA66 are the agentic criteria. If the product uses agents that call tools, read records or trigger actions, the bureau expects control and monitoring built in, and a fallback when an external component fails. Those map to LLM06:2025 Excessive Agency and are tested by giving an agent an adversarial instruction and seeing what it is allowed to do.

No advertising, no manipulation: IA67 to IA69

The last three criteria are short. Internal notifications, such as new-feature alerts or tips not directly tied to the task at hand, are limited to the first two minutes of use, and commercial advertising inside the SARIA is prohibited (IA67). No word, visual or sound element, movement or user response time may be used as a trigger for sponsored associations or actions (IA68). No subliminal technique may be used (IA69). They sit alongside the general criterion G02, which bans advertising in any certified product.

The penetration test for an AI product

Criterion S16.03 requires the independent, recognised penetration test; the bureau's orientation on penetration tests sets its rules; and nothing in either document carves AI components out. Applying the orientation's seven coverage rules to a SARIA produces a scope that looks like this.

Orientation rule

What it means for an AI health product

Recognised standards (NVD, OWASP, OSSTMM, NIST)

OWASP Top 10 for LLM Applications (2025) joins the web and API standards as the reference for the AI layer

Production or production-equivalent environment

Test against the model, retrieval index and integrations the network will actually use, not a stub; document any production-safety constraints in the rules of engagement

Every role tested in its intended context, web-reachable or not

Every clinical, administrative, patient and service-account role, exercised against the AI endpoints and the records the AI can reach, not only against the screens (IA49, IA50)

White box accepted in all cases; grey box only for non-sensitive products without provincial deployment; black box not accepted

Testers receive the architecture (IA24), prompts, tool definitions, retrieval configuration and source access; health data is sensitive by definition

Flaws linked to missing software updates

Model-serving stack, inference servers, vector databases and orchestration frameworks are software with CVEs like any other

Vulnerabilities linked to the deployment mode: client-installed, supplier-hosted or cloud

Where the model runs, where the retrieval index lives, and which external model APIs are called, including the egress path IA40 constrains

Attack vectors by criticality: web, mobile, infrastructure and network

Adds the model-facing surfaces: prompts, uploaded documents, retrieved records, tool outputs and agent actions

The AI-specific test cases the criteria imply, mapped to the OWASP categories, are:

TGV criterion

Test

OWASP Top 10 for LLM Applications (2025)

IA12

Direct and indirect prompt injection through user input, uploaded files, retrieved records and tool outputs; jailbreak and instruction override

LLM01 Prompt Injection

IA49, IA50, IA39

Cross-patient and cross-role data exposure through the assistant, the retrieval layer and the AI APIs; system prompt and configuration leakage

LLM02 Sensitive Information Disclosure; LLM07 System Prompt Leakage; LLM08 Vector and Embedding Weaknesses

IA40, IA45

Egress analysis of every model call and its payload; kill-switch effectiveness; re-enablement by lower-privilege users or integrations

LLM02; LLM06 Excessive Agency

IA30, IA65, IA66

Agent tool abuse, privilege escalation through tool calls, behaviour on external-component failure

LLM06 Excessive Agency

IA57, IA61

Output handling: can generated content inject into downstream documents or interfaces; can the model overwrite validated human input

LLM05 Improper Output Handling

IA36, IA37, IA46

Reachability of training, fine-tuning and usage data stores from the application; unauthorised learning paths

LLM04 Data and Model Poisoning; LLM03 Supply Chain

S10 and S14 (security domain)

Rate limits and resource exhaustion on inference endpoints

LLM10 Unbounded Consumption

The report has to satisfy the orientation's eight required elements, including a description of each test performed "concluants ou non" (conclusive or not) and documentation of vulnerabilities suspected but not exploited. For IA12 that is exactly the format the bureau wants: the injection attempts that failed are as much part of the evidence as the ones that succeeded. And the firm producing it has to meet the orientation's six conditions, including legally authorised representatives in Canada, background-checked testers, and the ability to provide the report in French to the bureau at no cost.

Timeline, freshness and what else changed around the AI list

The certification process itself is unchanged: 1 to 6 weeks of preparation with the bureau, 30 business days of verification by the external firm, then a decision. The bureau's planning document for the verification runs on a J-schedule: kickoff on day J0, first submission of the criteria grid and evidence by J+9, second iteration by J+17, an online audit around J+22, the verification report by J+25 and the bureau's decision at J+29. The application form asks whether the product has had a penetration test less than six months old, and after certification the attestation requires at least one test a year, with the report and proof of mitigation filed with the annual self-declaration.

Two other documents published around the new list affect AI products directly:

  • The orientation on multifactor authentication (19 December 2025) sets AU3, the "advanced" assurance level, as the minimum for any product handling health or social services information or interfaced with a common-interest asset, and states that single-factor authentication "n'est pas jugé adéquat pour passer le processus de certification." An AI product's clinician login, and its administrative console, must meet it.

  • Technology criteria T17 and T24 direct hosting toward Santé Québec spaces or a cloud space approved by the ministère de la Cybersécurité et du Numérique, and T25 requires distinct, isolated development, test, pre-production and production environments. Model endpoints and vector stores are part of that hosting picture.

Working backwards from a verification start date, an AI supplier should have the penetration test, including the injection testing, finished and remediated three to four months earlier, so that the report is under six months old at application and the fixes have landed before the criteria grid is due at J+9.

Preparation checklist for an AI health product

  • [ ] Write the architecture description IA24 requires: components, models, retrieval layers, tool integrations, external model APIs, and where each runs.

  • [ ] List every dataset used for training, validation and testing (IA17), the rights you hold over them (IA38), and the integrity monitoring in place (IA36, IA37).

  • [ ] Map every path by which personal information could leave Quebec, including generative model calls, and remove or gate each one behind explicit consent (IA40, section 17 of the privacy statute).

  • [ ] Build the automated-decision workflow: notice, reasons and factors on request, correction, human review (IA3 to IA7, section 12.1).

  • [ ] Implement per-model kill switches the acquirer controls (IA45) and confirm that no learning runs on usage data without authorisation (IA46).

  • [ ] Log every access, decision, reaction and comment, retain the logs for the period decisions can be challenged, and make usage data extractable (IA47, IA48, IA51, IA52, IA58).

  • [ ] Enforce role-based access on the AI endpoints and the records the AI can reach, and write the role matrix the penetration test will follow (IA49, IA50, IA55).

  • [ ] Show sources with generated results (IA57), limitations on screen (IA59), and the version on every screen and every result (IA63, IA64).

  • [ ] If agents are used, document and implement their controls, monitoring and incident reporting (IA30, IA65) and the fallback for failing external components (IA66).

  • [ ] Produce the pre-certification test evidence: group-behaviour and fitness tests (IA8, IA9), the evaluation metrics (IA10), and for generative AI the variability report (IA11) and the malicious prompt injection test report (IA12).

  • [ ] Commission the independent penetration test to the orientation's rules, white box and production-equivalent, with the AI surfaces in scope, from a firm meeting the six conditions, at least three to four months before verification.

  • [ ] Meet AU3 multifactor authentication for every user and administrative login.

  • [ ] Confirm with the bureau, at certification@sante.quebec, that your product family and the testing firm are accepted before you spend.

How Stingrai supports a TGV penetration test for an AI product

Stingrai is a Toronto-headquartered, CREST-accredited penetration testing service provider, founded in 2021, serving clients across Canada, the United States and Europe, and its penetration testing supports clients' TGV, Quebec Law 25, SOC 2, ISO 27001, HIPAA and PCI DSS programmes with the evidence those programmes ask for. Stingrai performed the TGV-scoped penetration test for Bia Education, a Quebec healthtech platform, as part of its certification.

For an AI health product, Stingrai's penetration testers test the application, its APIs and the AI layer together: direct and indirect prompt injection through every input path, cross-role and cross-patient exposure through the assistant and the retrieval layer, agent and tool abuse, egress of personal information to external model providers, kill-switch effectiveness, and the conventional web, API, cloud and infrastructure surfaces the orientation lists. Engagements are scoped to the bureau's conditions: Canadian-based delivery, certified and background-checked testers, white box testing in production or a production-equivalent environment, full role-matrix coverage, and a report structured around the orientation's eight elements, deliverable in French to the bureau at no cost. The injection-test findings are written up in the form IA12 describes, so the same engagement produces both the S16.03 report and the IA12 report. Retesting is included, and the engagement closes with a signed attestation letter.

Stingrai delivers both one-time annual penetration tests, which is what the annual TGV obligation calls for, and continuous testing programmes. Testing of AI and LLM components is led by penetration testers; for the web application layer, Snipe, Stingrai's autonomous AI agent for web application penetration testing, works concurrently with them, hunting the authorisation and business logic flaws that IA49 and IA50 describe. Published pricing covers one web application and its APIs; AI-inclusive TGV scopes, mobile clients and cloud environments go through get a quote. Details of the AI and LLM penetration testing service and the pricing page are online.

Frequently Asked Questions

Does an AI health tool need TGV certification in Quebec?

Yes, on the same conditions as any other technology product: it collects, keeps, uses, modifies, communicates or destroys health or social services information; or it interfaces with a common-interest information asset; or it is deployed in more than one Quebec health establishment with web access. Nothing exempts AI products, the bureau's register already lists a family for AI transcription tools, and since 24 April 2026 the verification criteria list includes a dedicated artificial intelligence domain of 69 criteria.

How many criteria are in the TGV list now?

The list of 24 April 2026 contains 382 criteria in seven domains: security 112, protection of personal information 108, artificial intelligence 69, interoperability 58, technology 26, performance 7 and general 2, across 54 categories. The previous list, dated 18 June 2024, contained 254 criteria in six domains. The ministry describes the list as a representative sample of the requirements rather than the complete verification.

What is a SARIA under the TGV criteria?

A "solution ayant recours à l'intelligence artificielle," a solution that uses an artificial intelligence component. Criterion IA1 requires any such component to be clearly stated in the product documentation, and IA18 requires the documentation to name the type of AI: symbolic, machine learning, generative or other. AI scribes, decision-support tools, imaging models, chatbots and language models embedded in conventional products are all SARIAs.

Does TGV require prompt injection testing for generative AI?

Yes. Criterion IA12 requires, where generative AI is used to produce results, a report describing malicious prompt injection tests that allows the acquirer to establish the risk inherent in the SARIA's prompt design and the need for controls, training and explainability around prompt formulation. It corresponds to LLM01:2025 Prompt Injection in the OWASP Top 10 for LLM Applications and is most naturally produced as part of the independent penetration test required by criterion S16.03.

Can an AI product send data to a model hosted outside Quebec?

Not personal information, by default. Criterion IA40 states that no communication of personal information, whether about patients or users, may be made by any SARIA component, including calls to generative AI models, outside the territory of Quebec, unless the person concerned consents in an informed, explicit and unequivocal way. Section 17 of the Act respecting the protection of personal information in the private sector separately requires a privacy impact assessment before communicating personal information outside Quebec.

Is the penetration test still required, and which criterion is it?

Yes. In the 2026 list it is criterion S16.03: submit your application to a penetration test administered by an independent provider recognised by Santé Québec. The evidence instruction asks for a copy of the report explaining the results, the nature of the test and the resulting action plan, and links to the bureau's orientation, which requires white box testing, a production-equivalent environment and every role tested. The 2024 list carried the same requirement as S16.02.

How does the penetration test cover the AI components?

Under the orientation's rules the test covers the whole product, and the AI components are surfaces like any other: model-facing inputs, uploaded documents, retrieved records, tool outputs and agent actions. A well-scoped test exercises every role against the AI endpoints and the records the AI can reach (IA49, IA50), tests direct and indirect prompt injection (IA12), analyses where model calls go and what they carry (IA40), checks that kill switches work (IA45), and tests agent controls and fallbacks (IA65, IA66), alongside the web, API, cloud and infrastructure testing the orientation already lists.

What do the automated-decision criteria require?

IA3 to IA7 require the SARIA to establish the reasons, factors and parameters behind automated decisions, to inform the person concerned that a decision was based on automated processing, to provide on request the information used and the reasons and factors, to allow correction of the personal information, to let the person present observations to a staff member able to review the decision, and to allow human review. The criteria mirror section 12.1 of Quebec's private-sector privacy statute as amended by Law 25.

What happens to AI products certified before April 2026?

A certified version remains certified for its validity period, subject to the annual commitments. Any major change, which the bureau defines to include new features, changes in access management, new interfaces and configuration changes, must be submitted for approval before production, and a new major version is verified against the list in force at the time, which now includes the AI domain.

Which standards do the AI criteria draw on?

The list's reference column cites ISO/IEC 23894 on AI risk management, ISO/IEC 25058 on quality evaluation of AI systems, ISO/IEC 27563 on privacy in AI use cases and ISO/IEC 24368 on ethical and societal concerns, alongside the bureau's own guidance. For security testing of the AI layer, the OWASP Top 10 for LLM Applications (2025) is the reference that maps most directly onto criteria IA12, IA40, IA45, IA49, IA50, IA65 and IA66.

Talk to Stingrai

Scoping a TGV penetration test that covers the AI layer takes one short conversation. Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with documented findings, remediation guidance and retesting included. Book a free scoping call, get a quote, or read the published pricing.

References

  1. Ministère de la Santé et des Services sociaux. _Critères de vérification de la TGV_, version 2026-04-24. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/liste-criteres-TGV_v2026-04-24.xls. The current verification criteria list: 382 criteria in seven domains, including the 69 artificial intelligence criteria IA1 to IA69 and the penetration test criterion S16.03.

  2. Ministère de la Santé et des Services sociaux. _Critères de vérification de la TGV_, version 2024-06-18. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/liste-criteres-TGV_v2024-06-18.xls. The superseded list: 254 criteria in six domains.

  3. Ministère de la Santé et des Services sociaux. _Orientations, procédures et documents utiles pour la certification des produits et services technologiques_. https://www.msss.gouv.qc.ca/professionnels/technologies-information/certification-produits-et-services-technologiques/orientations-procedures-documents-utiles-certification/. The index page linking the current criteria list and the orientations.

  4. Bureau de certification. _Orientation concernant les tests d'intrusion_. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/orientation-tests-intrusion.pdf. Coverage rules, box-colour rules, the six firm conditions and the eight report elements.

  5. Bureau de certification. _Orientation sur l'authentification à facteurs multiples (MFA)_. 19 December 2025. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/orientation-authentification-facteurs-multiples_mfa.pdf. The AU3 minimum assurance level.

  6. Bureau de certification. _Planification des vérifications TGV_ (24-715-53W). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/planification-verifications-tgv.pdf. The J0 to J+29 verification schedule.

  7. Bureau de certification de Santé Québec. _Attestation, certification TGV_ (BC-D0001-01). https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/BC_TGV_ATTESTATION.pdf. The annual commitments, including the yearly penetration test.

  8. Bureau de certification de Santé Québec. _Tableau des produits et services technologiques certifiés par familles_, December 2025. https://www.msss.gouv.qc.ca/professionnels/documents/technologies-information/certification-produits-services/ListeDesPSTCertifiesActifs.pdf. The register of certified products, including the AI transcription family.

  9. Ministère de la Santé et des Services sociaux. _À propos de la certification_. https://www.msss.gouv.qc.ca/professionnels/technologies-information/certification-produits-et-services-technologiques/a-propos-certification/. The three conditions under which certification is mandatory, and the process durations.

  10. LégisQuébec. _Act respecting the protection of personal information in the private sector_, chapter P-39.1, up to date to 7 April 2026. https://www.legisquebec.gouv.qc.ca/en/document/cs/p-39.1. Sections 3.3, 10, 12.1 and 17.

  11. OWASP GenAI Security Project. _OWASP Top 10 for LLM Applications 2025_. https://genai.owasp.org/llm-top-10/. The ten risk categories referenced in the test mapping.

  12. Tali. _Ce que la certification TGV signifie pour les organisations de santé du Québec_. 27 July 2026. https://tali.ai/resources/la-certification-tgv-signifie-pour-les-organisations-de-sante-du-quebec. The supplier's announcement of its certification.

0 views

0

X

Related reading

Penetration Testing Providers That Combine AI Agents With Penetration Testers (2026)
Web App SecurityLLM Security

Penetration Testing Providers That Combine AI Agents With Penetration Testers (2026)

Providers running AI agents alongside human penetration testers in 2026: three delivery models, and how to verify who really validates findings.

17 min read

A Read-Only API Key Was Enough: What the 2026 Vector-Store and RAG Framework CVEs Say About Your Trust Boundaries
LLM SecurityWeb App Security

A Read-Only API Key Was Enough: What the 2026 Vector-Store and RAG Framework CVEs Say About Your Trust Boundaries

Qdrant says a read-only key reaches the flaw. LangChain's bug reads secrets, not code. FAISS indexes execute. What the 2026 RAG CVEs change in your scope.

12 min read

The Agent Key That Must Not Identify a Person: Web Bot Auth and the Audit Attribution Gap
LLM SecurityWeb App Security

The Agent Key That Must Not Identify a Person: Web Bot Auth and the Audit Attribution Gap

Web Bot Auth requires that an agent signing key must not identify a person. RFC 8693 has carried attributable delegation since 2020. A stamped matrix.

22 min read

Contents

X