A useful question is why the Canadian Compliance Framework considers four separate areas instead of a single "AI safety score." The short answer: a single number hides which part of the implementation is actually the problem.
The four areas to review:
Data Privacy — how data flows into, through, and out of the system, and whether that flow matches what's disclosed to the people it's collected from.
Ethics — whether the system's decisions are explainable, contestable, and free of the kind of bias that shows up quietly in training data rather than in code.
Regulatory Compliance — how the implementation lines up against the specific legislation that applies to the sector it's operating in, which varies a lot across provinces and industries.
Human Benefit — whether the deployment is net positive for the people affected by it, not just the organization deploying it.
A company can have strong practices in three of these and gaps in one, and that one gap is usually where the real risk sits. Averaging it into a single number would bury exactly the thing a compliance review is supposed to surface.
This framework is an advisory method, not a government approval or accredited certification. Any review needs an agreed scope, applicable requirements, documented evidence, and clear limitations.