For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE V. BOARD

118.1 Board as Governing Authority.

The Board of Directors shall be the governing authority of GCRI Canada and shall exercise the corporate powers, fiduciary oversight, strategic supervision, institutional stewardship, and reserved governance authority of the Corporation, subject to applicable law, the Articles, this Bylaw, and any member approval required by law or the Articles.

The Board shall not be merely an advisory body, ceremonial body, stakeholder forum, technical council, funder committee, public authority forum, sponsor committee, provider committee, or program steering group. It shall be the central legal authority responsible for ensuring that GCRI Canada remains a Canadian not-for-profit corporation, without share capital, non-distributing, public-benefit, non-executing, evidence-centered, methods-governed, technically rigorous, legally separate, and role-separated within the Nexus public-good stack.

118.2 Board Authority Subject to Applicable Law, Articles, This Bylaw, and Member Approval Where Required.

The Board’s authority shall be exercised only within the limits of applicable Canadian law, the Articles, this Bylaw, binding corporate filings, lawful Board resolutions, and any member approval required by law, the Articles, or this Bylaw.

No Board act shall be interpreted to override mandatory law, expand the Corporation beyond its legal capacity, authorize prohibited functions, create share-capital or profit-distribution rights, substitute GCRI Canada for a public authority, convert GCRI Canada into a regulated intermediary, or create authority for GCRI Canada to bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, National Consortium Companies, Project SPVs, providers, sponsors, hosts, funders, public authorities, or partners.

Where member approval is required, the Board may recommend, approve for submission, or conditionally authorize the matter, but the matter shall not take effect in a manner inconsistent with applicable law until the required member approval is obtained and recorded.

118.3 Board Responsibility for Corporate Governance.

The Board shall be responsible for the corporate governance of GCRI Canada, including adoption and maintenance of this Bylaw, oversight of the Articles and constituting instruments, approval of reserved matters, supervision of officers, establishment of committees where appropriate, adoption of policies, maintenance of records, approval of major strategies and budgets, and oversight of legal compliance.

Corporate governance responsibility includes ensuring that GCRI Canada maintains:

a. lawful corporate existence and registered office discipline;

b. accurate minute books, registers, resolutions, filings, and statutory records;

c. clear delegations of authority;

d. conflict, recusal, independence, and related-party controls;

e. financial controls and treasury discipline;

f. data, AI, cyber, privacy, research, publication, and safeguards controls; and

g. validity-by-record and correctionability across all material institutional acts.

118.4 Board Responsibility for Public-Benefit Purpose.

The Board shall preserve, interpret, and advance the public-benefit purpose of GCRI Canada. The Board shall ensure that the Corporation’s activities, assets, programs, funds, relationships, publications, software, data systems, technical baselines, evidence products, learning programs, and Nexus interfaces remain directed toward public-good outcomes rather than private control, private extraction, sponsor preference, provider advantage, public authority confusion, finance overclaim, or institutional self-expansion.

The Board shall treat public-benefit purpose as a binding governance standard, not a branding statement. In case of ambiguity, the Board shall prefer the interpretation that best protects public trust, public-good stewardship, evidence integrity, community safeguards, lawful compliance, role separation, and non-execution.

118.5 Board Responsibility for Mission Lock.

The Board shall be responsible for maintaining the mission lock of GCRI Canada. Mission lock means that the Corporation shall remain dedicated to upstream evidence, methods, observability, ontology, technical truth, public-good research and development, public-good software, open technical baselines, public authority learning support, and Nexus-compatible public-good stewardship.

The Board shall not permit mission drift through operational convenience, funding pressure, sponsor expectation, provider dependency, public authority proximity, capital-market attention, technology enthusiasm, event activity, institutional prestige, or emergency improvisation. Any proposed change that could alter the mission lock shall be treated as a constitutional matter requiring recorded review, legal assessment, role-separation analysis, and approval through the highest applicable governance pathway.

118.6 Board Responsibility for Nonprofit, Non-Share, Non-Distributing, and Non-Charitable Posture Unless Lawfully Changed.

The Board shall preserve the Corporation’s nonprofit, non-share, non-distributing character. No director, officer, member, participant, sponsor, donor, funder, provider, host, contributor, founder, related party, national company, Project SPV, investor, insurer, lender, contractor, or private person shall receive dividends, equity rights, ownership rights, profit participation, or distribution of surplus assets except as permitted by law for fair-value compensation, reimbursement, indemnification, lawful grants, lawful awards, or other approved public-benefit expenditures.

Unless charitable status is lawfully obtained and recorded, the Board shall ensure that GCRI Canada is not represented as a registered charity, charitable foundation, public foundation, private foundation, qualified donee, or tax-receipting charity. Any change to charitable status, tax posture, nonprofit classification, or donation-receipting authority shall require legal review, Board approval, and any required filing or member approval.

118.7 Board Responsibility for Public-Good Stewardship.

The Board shall act as fiduciary steward of GCRI Canada’s public-good role. Public-good stewardship includes active protection, maintenance, versioning, correction, public-safe release, lawful sharing, anti-enclosure protection, and continuity of public-good assets and institutional functions.

Such stewardship shall include oversight of:

a. evidence infrastructure;

b. methods libraries;

c. observability methods;

d. ontologies, schemas, data dictionaries, and controlled vocabularies;

e. technical baselines and reference architectures;

f. public-good software and open technical assets;

g. research records and publication records;

h. data, AI, cyber, and privacy safeguards;

i. community, Indigenous, local, territorial, and protected knowledge safeguards; and

j. records necessary to preserve institutional memory and correctionability.

118.8 Board Responsibility for Evidence, Methods, Observability, Ontology, Technical Truth, Public-Good R&D, Public-Good Software, and Open Technical Baselines.

The Board shall ensure that GCRI Canada’s core functions remain evidence-based, method-governed, technically credible, reviewable, reproducible where appropriate, challengeable, and correctionable.

The Board shall oversee institutional systems for evidence doctrine, method adoption, observability design, ontology governance, technical truth outputs, public-good R&D, public-good software, reference architectures, secure releases, data stewardship, AI-use controls, cybersecurity controls, publication discipline, and public-safe claims. The Board shall ensure that these outputs are not misrepresented as public authority decisions, official warnings, certifications, procurement approvals, finance-readiness determinations, investment recommendations, insurance approvals, ratings, recognition decisions, or execution instructions.

The Board shall preserve the separate legal personality of GCRI Canada. GCRI Canada shall not be treated as a branch, subsidiary, parent, division, alter ego, joint employer, common treasury, shared liability pool, or undisclosed agent of GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, national companies, Project SPVs, providers, sponsors, hosts, funders, public authorities, or partners.

The Board shall require interface agreements, public descriptions, shared projects, shared publications, shared records, shared personnel, shared systems, and shared funding arrangements to preserve legal separateness, authority boundaries, liability boundaries, treasury boundaries, employer boundaries, records boundaries, and public claims discipline.

118.10 Board Responsibility for Nexus Role Separation.

The Board shall preserve GCRI Canada’s role separation within the Nexus public-good stack. GCRI Canada shall remain within the GCRI function as an evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and open technical-baseline steward.

The Board shall ensure that GCRI Canada does not assume the role of:

a. The Global Risks Forum (GRF) as registry, recognition, maturity-records, standing, claims-discipline, stakeholder-formation, public-safe reporting, and public-facing legitimacy steward;

b. The Global Risks Alliance (GRA) as finance-readiness, capital-readability, investor-literacy, insurance-readiness, diligence-translation, and common-business-interest steward;

c. Nexus Standards or protocol authority as certification, conformance, entitlement, role-key, smart-license, or protocol-force authority unless separately and lawfully designated;

d. public authorities as regulators, emergency-command bodies, public-warning bodies, procurement bodies, public finance bodies, or sovereign decision-makers; or

e. enterprise-stack actors as project developers, asset owners, operators, lenders, insurers, brokers, dealers, underwriters, vendors, or execution vehicles.

118.11 Board Responsibility for Non-Execution Boundary.

The Board shall maintain the bright-line non-execution boundary of GCRI Canada. The Corporation shall not conduct securities dealing, investment advice, brokerage, finder activity, underwriting, lending, guarantee, insurance placement, insurance underwriting, rating, public finance approval, procurement approval, public authority decision-making, emergency command, public warning, regulated professional opinion, enterprise operation, or project execution except where separately lawful and expressly authorized within a clearly bounded and recorded non-conflicting scope.

The Board shall require any activity that approaches a regulated perimeter, public authority boundary, finance-readiness boundary, certification boundary, procurement boundary, insurance boundary, or emergency-command boundary to be paused, held, quarantined, re-scoped, externalized, terminated, or referred for legal and compliance review.

118.12 Board Responsibility for Validity-by-Record.

The Board shall ensure that material corporate acts, governance decisions, delegations, memberships, participation rights, public authority references, data access rights, AI-use permissions, public claims, publications, technical releases, software releases, controlled-room admissions, funding acceptances, sponsorship benefits, provider references, evidence outputs, methods outputs, Nexus interface outputs, and corrections obtain institutional validity only through authoritative records.

No act shall obtain governance authority, public meaning, public authority meaning, finance-readiness implication, certification implication, procurement implication, recognition implication, provider preference, sponsor benefit, or Nexus-compatible claim by memory, custom, repeated practice, email, chat, meeting attendance, circulation, technical access, reputation, sponsorship, donor status, public authority presence, or narrative alone.

118.13 Board Responsibility for Correctionability.

The Board shall ensure that GCRI Canada maintains correctionability across governance, research, evidence, methods, observability, ontology, software, technical baselines, publications, public claims, public authority references, finance-boundary references, sponsor references, provider references, data systems, AI systems, dashboards, maps, records, registers, and Nexus interfaces.

Correctionability includes the ability and duty to correct, clarify, supersede, downgrade, restrict, withdraw, retract, retire, archive, notify, and close out outputs, records, claims, access rights, or institutional acts that are inaccurate, outdated, unsupported, unsafe, overbroad, unauthorized, misclassified, misleading, superseded, improperly relied upon, or role-confusing.

118.14 Board Responsibility for Anti-Capture and Support-Without-Control.

The Board shall preserve the anti-capture posture of GCRI Canada. No sponsor, donor, funder, provider, host, investor, insurer, lender, public authority, national company, Project SPV, contractor, university, laboratory, media participant, founder, member, affiliate, or related party shall purchase, obtain, or aggregate control over GCRI Canada’s governance, research agenda, evidence conclusions, methods, technical baselines, publications, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus interfaces, software releases, public claims, or correction decisions.

Support may be accepted only under the principle of support-without-control. Funding, sponsorship, donation, subscription, in-kind support, technical contribution, hosting, public authority participation, or enterprise participation may support public-benefit activity but shall not buy outcomes, veto findings, suppress publications, secure provider preference, obtain procurement advantage, purchase recognition, influence finance-readiness, or distort institutional meaning.

118.15 Board Responsibility for Institutional Continuity.

The Board shall preserve the institutional continuity of GCRI Canada, including continuity of governance, records, evidence systems, methods systems, observability systems, ontology systems, public-good software, technical baselines, data controls, AI controls, cybersecurity controls, public authority interfaces, community safeguards, financial controls, repository systems, correction systems, and Nexus interface obligations.

The Board shall ensure that succession planning, continuity packs, backups, repository governance, records retention, officer succession, committee continuity, risk registers, legal holds, insurance, emergency governance, and wind-down planning are sufficient to protect public-benefit obligations and public-good assets during leadership change, funding disruption, cyber incident, data incident, public controversy, program suspension, emergency mode, restructuring, dissolution, or orderly transfer.

118.16 Board Authority Records.

The Board shall maintain Board authority records sufficient to demonstrate lawful governance, fiduciary oversight, reserved-matter approval, delegation, supervision, review, and correction. Such records shall include meeting notices, agendas, materials, minutes, resolutions, attendance, quorum, voting, abstentions, conflicts, recusals, materials reviewed, decisions, action items, delegated authorities, ratifications, corrections, and follow-up.

Board authority records shall be maintained in the official corporate records and, where appropriate, in official registers, repositories, Gazette or notice streams, controlled rooms, or secure archives. The absence of an adequate Board authority record may require correction, ratification, limitation, re-performance, or nullification of the affected act.


Section 119. Directors’ Duties, Public-Benefit Duty, Duty of Care, Duty of Loyalty, Prudence, Independence, and Mission Fidelity

119.1 Duty to Act in Good Faith.

Each director shall act honestly, in good faith, and with fidelity to the best interests of GCRI Canada. Good faith requires sincere attention to the Corporation’s lawful purpose, Canadian legal status, nonprofit character, public-benefit mission, public-good stewardship role, non-execution boundary, role separation, and institutional integrity.

A director shall not use Board authority for personal advantage, sponsor advantage, provider advantage, donor advantage, political advantage, public authority influence, capital-market advantage, institutional prestige, or private leverage inconsistent with the Corporation’s purpose.

119.2 Duty to Act in the Best Interests of GCRI Canada.

Each director shall act in the best interests of GCRI Canada as a distinct Canadian not-for-profit corporation and not in the separate interests of any appointing person, nominating person, member, funder, sponsor, donor, provider, host, public authority, employer, university, laboratory, community, national company, Project SPV, investor, insurer, lender, partner, affiliate, or Nexus interface.

The best interests of GCRI Canada shall be understood through its public-benefit purpose, public-good stewardship burden, legal separateness, mission lock, non-distribution rule, non-execution boundary, validity-by-record discipline, correctionability, and role-separation obligations.

119.3 Duty of Care.

Each director shall exercise the care, diligence, and skill that a reasonably prudent person would exercise in comparable circumstances. In applying this duty, a director shall give informed attention to the complexity of GCRI Canada’s role as an evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and open technical-baseline steward.

The duty of care includes preparation for meetings, review of materials, inquiry where facts are incomplete, attention to legal and compliance risks, understanding of major technical and institutional risks, oversight of delegated authority, and insistence on adequate records for material decisions.

119.4 Duty of Loyalty.

Each director shall act loyally toward GCRI Canada and shall not place personal, financial, institutional, professional, political, sponsor, donor, provider, host, public authority, employer, investor, insurer, lender, national company, Project SPV, or partner interests ahead of the Corporation’s interests.

A director shall not use confidential information, institutional opportunity, Board access, public authority proximity, technical knowledge, research information, data access, Nexus interface knowledge, or public-good asset access for improper personal or third-party benefit.

119.5 Duty of Prudence.

Each director shall act prudently in overseeing GCRI Canada’s assets, risks, funds, records, data, technical systems, publications, research, evidence outputs, partnerships, programs, public authority interfaces, and Nexus interfaces.

Prudence requires attention to foreseeable harms, legal perimeters, operational capability, financial sustainability, cyber and data risk, research integrity, public claims risk, sponsor and provider influence, public authority confusion, finance-boundary overclaim, and community safeguards. Prudence shall not permit avoidable haste to substitute for recorded review where the matter has public meaning, legal consequence, technical consequence, or institutional consequence.

119.6 Duty of Diligence.

Each director shall participate diligently in Board work, including attending meetings, reviewing materials, asking informed questions, monitoring implementation of Board resolutions, reviewing reports, supporting correction of errors, and ensuring that high-risk matters receive appropriate escalation.

Diligence includes attention to matters that may appear technical, operational, or programmatic but that carry governance significance, including data access, AI-use, cybersecurity, public authority references, finance-readiness language, certification implications, provider claims, sponsor benefits, public-safe publications, software releases, and controlled-room access.

119.7 Duty of Independence.

Each director shall exercise independent judgment. A director shall not act as a delegate, proxy, agent, spokesperson, representative, advocate, or controlled vote of any sponsor, donor, funder, provider, host, public authority, employer, investor, insurer, lender, national company, Project SPV, partner, affiliate, member group, community group, or Nexus interface unless such representative role is expressly lawful and fully disclosed, and even then subject to fiduciary duty to GCRI Canada.

Independence requires freedom from improper influence and the willingness to question management, sponsors, providers, funders, public authorities, technical experts, founders, officers, committees, councils, and external partners.

119.8 Duty of Public-Benefit Fidelity.

Each director shall preserve the public-benefit purpose of GCRI Canada in governance, strategy, budgeting, staffing, fundraising, partnerships, publications, technical releases, data access, public authority interfaces, and Nexus interfaces.

Public-benefit fidelity requires directors to resist private capture, sponsor control, provider preference, donor direction, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, and mission dilution. A director shall treat public benefit as a governance duty that constrains decision-making, not merely as an aspirational value.

119.9 Duty of Mission Fidelity.

Each director shall preserve GCRI Canada’s mission as an upstream public-good technical institution and shall ensure that the Corporation does not drift into execution, regulated intermediation, public authority substitution, certification by default, finance-readiness determination, provider selection, procurement steering, or event-marketplace identity.

Mission fidelity includes ensuring that evidence precedes recognition, methods precede claims, ontology precedes interoperability, observability precedes public meaning, technical baselines precede deployment support, and correctionability precedes institutional defensiveness.

119.10 Duty to Preserve Nonprofit and Non-Distribution Character.

Each director shall preserve GCRI Canada’s nonprofit, non-share, and non-distributing character. A director shall not authorize dividends, profit participation, equity-like rights, surplus distributions, hidden inurement, disguised commercial participation, excessive compensation, improper related-party benefit, or public-good asset transfer that violates applicable law, the Articles, this Bylaw, or public-benefit purpose.

Directors shall ensure that fair compensation, reimbursement, grants, awards, stipends, contracts, and indemnification are lawful, reasonable, recorded, conflict-managed, and not used to extract private benefit.

119.11 Duty to Preserve Non-Execution Boundary.

Each director shall preserve the non-execution boundary of GCRI Canada. A director shall not approve, encourage, tolerate, or fail to escalate conduct that would cause GCRI Canada to act as a securities dealer, investment advisor, broker, finder, underwriter, lender, guarantor, insurer, insurance intermediary, rating agency, public finance approval body, procurement authority, regulator, public warning authority, emergency command body, public authority decision-maker, or enterprise execution vehicle.

Where a director identifies possible perimeter risk, the director shall support hold, quarantine, re-scoping, legal review, role clarification, externalization, or termination as appropriate.

Each director shall preserve GCRI Canada’s legal separateness from all other Nexus, public-good, public authority, enterprise, sponsor, donor, provider, host, and partner entities.

A director serving multiple entities, holding external roles, or participating in cross-entity governance shall disclose those roles and manage conflicts. Shared personnel, shared records, shared publications, shared systems, shared funding, shared marks, or shared programs shall not be allowed to create alter ego treatment, agency, shared treasury, shared employer status, shared liability, or public confusion.

119.13 Duty to Preserve Evidence and Methods Integrity.

Each director shall preserve the integrity of evidence and methods. Directors shall ensure that evidence outputs are supported by source lineage, provenance, custody, confidence, uncertainty, limitations, classification, review, and correction pathways.

Directors shall not permit sponsor pressure, provider influence, public authority preference, funder expectation, media pressure, market demand, capital interest, institutional ambition, or political convenience to distort evidence, methods, research conclusions, observability outputs, ontology, public-good software, technical baselines, or public-safe claims.

119.14 Duty to Preserve Data, AI, Cyber, Privacy, and Safeguards Integrity.

Each director shall oversee the protection of data, AI systems, cybersecurity, privacy, controlled rooms, repositories, public authority materials, rights-bearing data, community-protected materials, Indigenous, local, territorial, cultural, environmental, and protected knowledge.

Directors shall ensure that AI use remains authorized, logged, reviewed, and non-authoritative; that cyber controls protect systems and records; that personal and sensitive information is minimized and safeguarded; and that community and protected knowledge is not extracted, published, modeled, mapped, transferred, or commercialized without appropriate authority and safeguards.

119.15 Duty to Preserve Public Authority Boundaries.

Each director shall preserve public authority boundaries. Directors shall ensure that public authority participation, data contribution, attendance, quote, logo, title, review, or presence is classified, recorded, and not misrepresented as endorsement, adoption, approval, procurement, funding, regulation, public warning, emergency command, public finance approval, sovereign obligation, or public-private partnership.

Directors shall support correction of any public authority misdescription and shall ensure that GCRI Canada does not become a substitute for governmental decision-making.

119.16 Duty to Preserve Finance-Readiness Boundaries.

Each director shall preserve finance-readiness boundaries. Directors shall ensure that GCRI Canada does not provide investment advice, securities recommendations, capital recommendations, investor solicitation, fund placement, routeability determinations, bankability determinations, insurance approvals, underwriting, ratings, lending, guarantees, or public finance approvals.

Technical evidence inputs to GRA, Nexus Rails, capital-reader rooms, proof packs, diligence gap maps, RNFD, NFD, UNFSD, or related finance-readiness materials shall be bounded, non-reliance-based, and recorded as technical evidence support only.

119.17 Duty to Avoid Improper Private Benefit.

Each director shall avoid and prevent improper private benefit. Directors shall not use GCRI Canada’s assets, reputation, public authority interfaces, public-good software, technical baselines, evidence outputs, data, publications, programs, membership structures, sponsorships, or Nexus relationships to confer improper benefit on themselves or others.

Improper private benefit includes excessive compensation, insider access, preferential provider treatment, procurement advantage, sponsor outcome purchase, donor control, hidden influence, related-party overpayment, public authority access purchase, finance-readiness influence, or appropriation of public-good assets.

119.18 Duty to Disclose and Manage Conflicts.

Each director shall disclose conflicts and potential conflicts promptly, completely, and in accordance with this Bylaw and applicable policy. Conflicts may be financial, institutional, fiduciary, professional, research-related, technical, data-related, AI-related, cyber-related, public authority-related, sponsor-related, provider-related, funder-related, host-related, national-company-related, Project-SPV-related, investor-related, insurer-related, lender-related, family-related, reputational, or personal.

A director shall comply with recusal, access restriction, information barrier, abstention, disclosure, mitigation, or resignation requirements where applicable. Failure to disclose or manage a material conflict may constitute breach of duty.

119.19 Duty to Support Correction and Supersession.

Each director shall support correctionability. Directors shall not suppress, delay, minimize, or conceal necessary correction, clarification, supersession, withdrawal, retraction, downgrade, archive, public notice, controlled notice, or stakeholder notification.

Where a director becomes aware that a record, publication, public authority reference, finance reference, certification implication, procurement implication, evidence output, method, dashboard, map, software release, technical baseline, or public claim is inaccurate, unsupported, unsafe, misleading, unauthorized, outdated, superseded, or role-confusing, the director shall support appropriate escalation and correction.

119.20 Director Duty Records.

GCRI Canada shall maintain director duty records, including director acknowledgments, conflict disclosures, annual confirmations, training records, attendance records, recusal records, materials reviewed, fiduciary duty training, public-benefit training, non-execution training, data / AI / cyber training, public authority boundary training, finance-boundary training, safeguards training, and correction records.

Such records shall demonstrate that directors understood and acted within their legal, fiduciary, public-benefit, mission-lock, non-execution, role-separation, and correctionability duties.


Section 120. Board Composition, Minimum and Maximum Number, Independence, Skills, Diversity, and Canadian Governance Competence

120.1 Number of Directors.

The Board shall consist of the number of directors fixed by the Articles, this Bylaw, or a lawful Board or member resolution within the range permitted by applicable law. The number of directors shall be sufficient to provide fiduciary oversight, Canadian governance competence, public-benefit stewardship, technical literacy, evidence oversight, financial oversight, legal compliance, data / AI / cyber oversight, public authority boundary oversight, safeguards oversight, and Nexus role-separation oversight.

The Board shall not be structured so narrowly that a single person, founder, officer, sponsor, donor, provider, host, public authority, national company, Project SPV, investor, insurer, lender, university, or affiliate can dominate governance.

120.2 Minimum Number.

The minimum number of directors shall be the minimum required by applicable law, the Articles, or a higher number approved by the Board or members where required.

Even where law permits a small Board, the Board shall consider whether the minimum number is adequate for GCRI Canada’s complexity, including its role in evidence, methods, observability, ontology, public-good software, public-good R&D, data governance, AI governance, cybersecurity, public authority interfaces, community safeguards, finance-boundary management, public-safe publication, and Nexus federation.

120.3 Maximum Number.

The maximum number of directors shall be the maximum set by the Articles, this Bylaw, or lawful resolution. The Board shall not be enlarged in a manner that creates capture, factionalism, sponsor influence, provider influence, donor influence, public authority confusion, excessive complexity, confidentiality risk, or ineffective oversight.

Expansion of the Board shall be based on governance need, competence need, independence, diversity, workload, risk profile, legal compliance, and institutional maturity, not on representational pressure, funding leverage, sponsor expectations, or provider participation.

120.4 Composition Principles.

The Board shall be composed to support prudent, independent, informed, public-benefit governance. Board composition shall balance legal, fiduciary, financial, technical, research, evidence, data, AI, cyber, privacy, public authority, community safeguards, Indigenous knowledge, accessibility, public-safe communications, and Nexus architecture competence.

The Board shall be neither a stakeholder parliament nor a sponsor council. It shall be a fiduciary body capable of making lawful, independent, recorded decisions in the best interests of GCRI Canada.

120.5 Independence Standard.

A substantial portion of the Board shall be independent in judgment, free from material conflicts, and capable of acting without improper influence from sponsors, donors, funders, providers, hosts, public authorities, national companies, Project SPVs, investors, insurers, lenders, contractors, employers, political interests, or related parties.

Independence shall be assessed functionally and not merely formally. A director may lack sufficient independence where financial dependence, professional dependence, institutional allegiance, contractual obligation, public authority role, provider relationship, sponsor relationship, donor relationship, family relationship, or reputational interest could reasonably impair independent judgment.

120.6 Canadian Governance Competence.

The Board shall include or obtain access to competence in Canadian not-for-profit governance, Canadian corporate compliance, registered office requirements, director duties, member rights where applicable, records and filings, tax and nonprofit posture, privacy, employment, contracts, public authority interfaces, and federal, provincial, territorial, municipal, Indigenous, and sectoral legal context.

Canadian governance competence is essential because GCRI Canada’s internal corporate acts shall be governed through its Canadian legal seat and shall not be displaced by Nexus instruments, foreign practices, global coordination, or external institutional expectations.

120.7 Public-Benefit Governance Competence.

The Board shall include or obtain access to public-benefit governance competence sufficient to evaluate whether activities, assets, funds, programs, publications, technical systems, partnerships, public authority interfaces, and Nexus interfaces advance the Corporation’s purpose.

Directors shall understand that public-benefit governance requires mission lock, non-distribution, anti-capture, public trust, community safeguards, public-safe communications, transparency where appropriate, controlled confidentiality where necessary, and correctionability.

120.8 Nonprofit Governance Competence.

The Board shall include or obtain access to competence in nonprofit governance, including non-distribution, private benefit limits, restricted funds, fundraising controls, sponsorship hygiene, donor restrictions, grant compliance, conflict management, board oversight, officer delegation, financial stewardship, audit readiness, and dissolution asset handling.

Nonprofit governance competence shall include understanding that nonprofit status does not permit informal governance, weak controls, donor direction, sponsor control, disguised profit distribution, or public-good asset enclosure.

The Board shall include or obtain access to legal and compliance competence sufficient to oversee corporate law, nonprofit law, tax, privacy, AI governance, cybersecurity, research ethics, employment, contracts, sanctions, export controls, competition law, procurement neutrality, public authority boundaries, finance boundaries, professional boundaries, risk management, insurance, incident response, investigations, enforcement, and dispute routing.

Legal and compliance competence may be held by directors, officers, advisors, counsel, committees, or external experts, but the Board shall retain oversight responsibility.

120.10 Evidence and Research Competence.

The Board shall include or obtain access to evidence and research competence sufficient to understand source lineage, provenance, custody, confidence, uncertainty, assumptions, limitations, reproducibility, replication, peer review, research ethics, sponsor independence, provider independence, publication integrity, correction, and public-safe translation.

The Board shall be capable of distinguishing evidence from raw data, opinion, recognition, finance-readiness, certification, procurement approval, public authority decision, public warning, and execution instruction.

120.11 Technical and Engineering Competence.

The Board shall include or obtain access to technical and engineering competence across the technology domains relevant to GCRI Canada’s work, including AI, agentic AI, AI-RAN, O-RAN, private wireless, sovereign compute, edge compute, high-performance compute, cyber-physical systems, DePIN, distributed ledgers, digital twins, sensors, robotics, drones, geospatial systems, Earth observation, climate systems, critical infrastructure, public-good software, secure release, and reference architectures.

Technical competence shall support oversight of methods and public-good technical assets without converting the Board into a technical maintainer or certification body.

120.12 Data, AI, Cybersecurity, and Privacy Competence.

The Board shall include or obtain access to competence in data governance, privacy, rights-bearing data, sovereign data, compute-to-data, cross-border transfer, AI governance, model governance, inference records, agentic AI controls, cybersecurity, repository security, secure development, vulnerability management, incident response, and business continuity.

This competence is required because GCRI Canada’s evidence, observability, public-good software, technical baselines, AI systems, dashboards, repositories, controlled rooms, and public authority interfaces depend on trustworthy data and secure systems.

120.13 Public Authority, Community, Indigenous, Safeguards, and Accessibility Competence.

The Board shall include or obtain access to competence in public authority engagement, public-sector capacity classification, public-safe communication, emergency-management boundaries, public infrastructure contexts, community safeguards, Indigenous rights and knowledge safeguards, local and territorial knowledge, protected knowledge, vulnerable and remote community protection, accessibility, grievance, remedy, non-retaliation, and public-safe mapping.

The Board shall ensure that public-good technical work does not harm communities, expose protected knowledge, misuse public authority participation, or reduce safeguards to public-relations language.

120.14 Finance-Boundary and Anti-Capture Competence.

The Board shall include or obtain access to competence in finance-boundary governance, anti-capture controls, sponsorship hygiene, donor restrictions, restricted funds, capital-reader rooms, proof packs, insurance-readiness inputs, public finance reader participation, investment-advice boundaries, securities boundaries, underwriting boundaries, rating boundaries, lending boundaries, public finance approval boundaries, procurement neutrality, and provider neutrality.

This competence shall help ensure that technical evidence support for finance-readiness work does not become capital recommendation, bankability determination, insurance approval, rating, solicitation, brokerage, or public finance approval.

120.15 Nexus Architecture and Role-Separation Competence.

The Board shall include or obtain access to competence in Nexus architecture, including the GCRI function, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, public authorities, and public-good / enterprise stack separation.

Directors shall understand that interoperability does not mean merger, shared records do not mean shared liability, public-good inputs do not mean execution, and technical centrality does not create protocol or recognition authority.

120.16 Diversity of Skills, Disciplines, Geographies, Lived Experience, and Public-Interest Perspective.

The Board shall seek diversity of skills, disciplines, geography, language, lived experience, public-interest perspective, institutional background, community perspective, technical expertise, legal perspective, governance experience, research orientation, and safeguards understanding.

Diversity shall be pursued to improve judgment, reduce blind spots, strengthen legitimacy, protect communities, improve technical review, avoid groupthink, and support public-benefit governance. Diversity shall not be used to create token participation, stakeholder capture, sponsor balancing, or provider representation without fiduciary independence.

120.17 No Composition That Creates Sponsor, Provider, Donor, Funder, Host, National Company, SPV, Investor, Insurer, Lender, or Public Authority Capture.

The Board shall not be composed in a way that creates actual, potential, or perceived capture by sponsors, providers, donors, funders, hosts, national companies, Project SPVs, investors, insurers, lenders, public authorities, contractors, founders, affiliates, related parties, or coordinated groups.

Capture risk may arise through voting concentration, employment relationships, funding dependence, sponsored seats, related-party networks, shared counsel, technical dependency, host dependency, public authority dominance, capital actor influence, provider dominance, or repeated appointment from a narrow institutional cluster. Where capture risk exists, the Board shall take corrective measures, including composition adjustment, recusal, independence review, observer-only status, role limitation, or appointment restrictions.

120.18 Board Composition Records.

GCRI Canada shall maintain Board composition records, including director number, terms, eligibility, independence assessments, skills matrix, diversity considerations, Canadian governance competence, public-benefit competence, technical competence, data / AI / cyber competence, safeguards competence, finance-boundary competence, Nexus role-separation competence, conflicts, related-party relationships, capture-risk assessments, appointment records, renewal records, and resignation or removal records.

Board composition records shall support transparency within lawful bounds, fiduciary accountability, succession planning, anti-capture discipline, and institutional continuity.


Section 121. Director Qualifications and Disqualifications

Each director shall satisfy all legal eligibility requirements under applicable law, the Articles, this Bylaw, and any Board-approved qualification policy. A person who is legally disqualified from acting as a director shall not be appointed, elected, continue, or hold themselves out as a director.

Legal eligibility shall be confirmed before appointment or election and periodically thereafter. If a director becomes legally ineligible, the director shall immediately notify the Corporation and shall cease acting to the extent required by law.

No person shall become a director unless the person consents to act in the manner required by applicable law, the Articles, this Bylaw, or Board-approved procedure.

Consent shall include acknowledgment of fiduciary duties, confidentiality duties, conflict disclosure duties, public-benefit obligations, non-execution boundaries, legal separateness, Nexus role separation, public authority boundaries, finance-boundary restrictions, data / AI / cyber obligations, safeguards obligations, records discipline, and correctionability duties.

121.3 Fit-and-Proper Standard.

Each director shall satisfy a fit-and-proper standard appropriate to a Canadian public-benefit, non-executing, public-good technical institution operating across evidence, methods, observability, ontology, public-good software, AI, cyber, data, public authority learning, public-safe publication, community safeguards, and Nexus interfaces.

Fit-and-proper review may consider integrity, competence, judgment, conflicts, independence, sanctions status, export-control concerns, financial responsibility, professional conduct, litigation or enforcement history, public claims history, data conduct, cyber conduct, safeguards conduct, and ability to act in the best interests of GCRI Canada.

121.4 Integrity Standard.

Each director shall demonstrate integrity sufficient for fiduciary stewardship of public-good assets, sensitive records, public authority interfaces, research outputs, evidence systems, data systems, AI systems, public-good software, technical baselines, controlled rooms, and protected knowledge.

Integrity includes honesty, respect for law, respect for confidentiality, respect for correction, respect for public-benefit purpose, truthfulness in disclosures, avoidance of misrepresentation, and willingness to put institutional duty ahead of personal or external interest.

121.5 Competence Standard.

Each director shall possess or be able to develop competence relevant to the Board’s responsibilities. A director need not be expert in every domain, but shall be capable of understanding Board materials, asking informed questions, identifying when expert advice is needed, and exercising judgment over legal, governance, financial, technical, research, data, AI, cyber, public authority, safeguards, and Nexus role-separation matters.

Persistent inability or unwillingness to engage with the Corporation’s complexity may constitute a qualification concern.

121.6 Independence Standard.

Each director shall be capable of independent judgment. A person may be ineligible, conditionally eligible, or subject to restrictions where relationships with sponsors, donors, funders, providers, hosts, public authorities, national companies, Project SPVs, investors, insurers, lenders, employers, contractors, related parties, or Nexus interfaces materially impair independence.

Independence review shall consider actual influence, perceived influence, financial dependence, professional dependence, fiduciary conflicts, contractual obligations, public authority roles, technical dependency, and reputational incentives.

121.7 Time-Commitment Standard.

Each director shall have sufficient time and attention to fulfill Board duties. Time commitment shall include preparation, meeting attendance, committee participation where applicable, review of materials, conflict disclosure, training, urgent governance response, correction review, and oversight of major risks.

A director who cannot regularly participate, review materials, respond to urgent matters, or satisfy training and acknowledgment obligations may be ineligible for renewal or subject to removal where permitted.

121.8 Confidentiality Capacity.

Each director shall have the capacity and willingness to protect confidential, privileged, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous, local, territorial, cultural, environmental, protected knowledge, whistleblower, controlled-room, data-room, research, sponsor, donor, provider, host, and partner materials.

A person unable to maintain confidentiality, avoid unauthorized disclosure, use secure systems, or comply with information barriers shall not serve or continue as a director where the risk is material.

121.9 Conflict-Disclosure Capacity.

Each director shall be able and willing to disclose conflicts completely, promptly, and accurately. Conflict-disclosure capacity includes understanding personal, financial, institutional, professional, fiduciary, research, data, AI, cyber, public authority, sponsor, donor, provider, host, national company, Project SPV, investor, insurer, lender, contractor, partner, family, and reputational conflicts.

A person who refuses, neglects, minimizes, conceals, or repeatedly fails to disclose material conflicts may be disqualified or removed where permitted.

121.10 Data, AI, Cyber, Privacy, and Controlled-Room Fitness Where Relevant.

Each director shall be fit to handle data, AI, cyber, privacy, and controlled-room responsibilities appropriate to the director’s role. This includes ability to use approved systems, protect credentials, avoid shadow IT, comply with AI-use restrictions, protect personal information, respect public authority data restrictions, avoid unauthorized downloads, and maintain confidentiality.

Where a director requires access to controlled rooms, restricted systems, sensitive repositories, AI tools, public authority materials, or protected knowledge, additional screening, training, acknowledgment, access limitation, or monitoring may be required.

121.11 Public Authority Boundary Understanding.

Each director shall understand that GCRI Canada is not a public authority, regulator, emergency-command body, public warning issuer, procurement authority, funding approver, public finance approver, sovereign body, or public-private partnership by participation.

A director shall be capable of identifying public authority overclaim, public authority misdescription, public authority endorsement risk, public authority data risk, public warning risk, emergency command risk, regulatory substitution risk, procurement approval risk, and sovereign obligation risk.

121.12 Finance-Readiness Boundary Understanding.

Each director shall understand that GCRI Canada does not provide investment advice, securities recommendations, broker-dealer services, finder activity, underwriting, lending, guarantees, insurance placement, insurance underwriting, ratings, public finance approvals, bankability determinations, routeability determinations, or capital recommendations.

A director shall be capable of distinguishing technical evidence inputs, observability inputs, methods support, proof-pack support, and finance-literacy support from finance-readiness determinations, investor solicitation, insurance approval, underwriting, rating, or public finance approval.

A person shall be disqualified from serving as a director if legally ineligible under applicable law, the Articles, this Bylaw, a court order, regulatory order, bankruptcy or insolvency restriction where applicable, incapacity rule, age requirement, residency requirement where applicable, sanctions restriction, or other binding legal prohibition.

Where legal ineligibility arises after appointment, the director shall cease acting to the extent required by law, and the Corporation shall update its records, filings, registers, public descriptions, and Board composition records as required.

121.14 Disqualification for Unmanaged Conflict.

A person may be disqualified, not renewed, suspended from certain matters, or removed where permitted if the person has an unmanaged conflict that materially impairs fiduciary judgment, independence, confidentiality, public-benefit fidelity, non-execution discipline, evidence integrity, public authority boundary discipline, finance-boundary discipline, or anti-capture controls.

Unmanaged conflict includes refusal to disclose, refusal to recuse, repeated conflict violations, use of Board information for external advantage, or acting as a de facto representative of an external actor.

121.15 Disqualification for Sanctions, Export-Control, Restricted-Party, Fraud, Corruption, Serious Misconduct, Harassment, Retaliation, Data Misuse, Cyber Misconduct, or Protected Knowledge Breach Where Material.

A person may be disqualified, suspended, not renewed, or removed where permitted if the person is subject to sanctions, restricted-party status, export-control restrictions, controlled technology restrictions, credible fraud findings, corruption findings, bribery, serious misconduct, harassment, retaliation, discrimination, data misuse, privacy breach, cyber misconduct, repository misconduct, AI misuse, protected knowledge breach, public authority misrepresentation, or other conduct materially inconsistent with fiduciary service.

The Board shall consider seriousness, recency, evidence, due process, remediation, legal obligations, public safety, confidentiality, reputational risk, and institutional risk before making a determination, except where immediate legal disqualification applies.

121.16 Disqualification for Misuse of GCRI Canada Name, Marks, Records, Data, Software, Public-Good Assets, or Nexus-Compatible Claims.

A person may be disqualified, suspended, not renewed, or removed where permitted if the person misuses GCRI Canada’s name, marks, logos, reports, datasets, software, technical baselines, public-good assets, publications, controlled materials, public authority references, Nexus references, or Nexus-compatible claims.

Misuse includes false claims of authority, endorsement, certification, recognition, finance-readiness, procurement advantage, public authority approval, provider preference, Docket status, Grid status, or public legitimacy. Misuse by a director is a serious breach because directors are fiduciaries and their public statements may carry heightened reliance risk.

121.17 Disqualification for Conduct Inconsistent With Public-Benefit Purpose or Non-Execution Boundary.

A person may be disqualified, suspended, not renewed, or removed where permitted if the person’s conduct is materially inconsistent with GCRI Canada’s public-benefit purpose, nonprofit character, non-distribution rule, mission lock, non-execution boundary, role separation, public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, safeguards obligations, validity-by-record, or correctionability.

Such conduct may include attempting to convert GCRI Canada into an execution vehicle, public authority substitute, capital-readiness authority, provider-selection body, certification body, sponsor-controlled platform, private-benefit structure, or public-good asset enclosure mechanism.

121.18 Qualification and Disqualification Records.

GCRI Canada shall maintain qualification and disqualification records for directors, including eligibility review, consent, fit-and-proper review, independence review, conflict review, confidentiality acknowledgment, training records, sanctions and export-control screening where applicable, public authority boundary acknowledgment, finance-boundary acknowledgment, data / AI / cyber acknowledgment, safeguards acknowledgment, disqualification analysis, Board or member decisions where applicable, resignation, removal, suspension, non-renewal, and public or controlled notice where appropriate.

Such records shall be maintained with appropriate confidentiality, privacy, access control, legal privilege where applicable, retention, sealing, and correction procedures.

Section 122. Technical, Evidence, Research, Data, AI, Cyber, Safeguards, Public Authority, Finance-Boundary, and Nexus Competence

122.1 Competence Map.

The Board shall maintain a Board competence map sufficient to identify, assess, supplement, renew, and document the skills, experience, independence, judgment, and domain literacy required for GCRI Canada to govern as a Canadian public-benefit, non-executing, public-good technical institution. The competence map shall be treated as a governance-control instrument and not as a public credential, rating, endorsement, certification, or representation that any director is authorized to provide regulated professional services on behalf of the Corporation.

The competence map shall address, at minimum, evidence, methods, research integrity, observability, ontology, public-good software, open technical baselines, data governance, AI governance, cybersecurity, privacy, rights-bearing data, Indigenous and community safeguards, protected knowledge, accessibility, public authority boundaries, finance-readiness boundaries, non-execution, regulatory perimeter discipline, Nexus role separation, public-good stack / enterprise stack separation, and institutional continuity.

The Board shall use the competence map to determine whether existing directors, officers, committees, advisors, counsel, external experts, peer reviewers, or other approved support structures are sufficient for the risks and activities before the Corporation. Where gaps are identified, the Board shall record whether the gap is accepted, mitigated, supplemented, escalated, or treated as a condition precedent to approval of a relevant program, publication, partnership, data access, technical release, public authority interface, or Nexus interface.

122.2 Evidence Competence.

The Board shall include or obtain access to evidence competence sufficient to govern the Corporation’s evidence stewardship function. Evidence competence shall include understanding of source identification, source authority, provenance, custody, timestamping, classification, evidence sufficiency, reliability, confidence, uncertainty, dispute handling, challengeability, correction, and public-safe presentation.

Evidence competence shall enable the Board to distinguish raw data, telemetry, sensor output, AI output, DePIN records, cyber logs, geospatial data, digital twin outputs, public authority inputs, operator observations, community inputs, and provider system outputs from evidence records that have been reviewed, classified, contextualized, and made subject to correction.

The Board shall ensure that evidence competence is applied before approving material evidence outputs, assurance packs, public-safe reports, dashboards, maps, Nexus Observatory inputs, Docket inputs, Grid inputs, GRF inputs, GRA inputs, standards-support inputs, or any public claim that depends on evidence.

122.3 Methods Competence.

The Board shall include or obtain access to methods competence sufficient to oversee the adoption, review, correction, retirement, and public-safe use of GCRI Canada methods. Methods competence shall include understanding of validation methods, corroboration methods, confidence-scoring methods, uncertainty methods, source-lineage methods, sensor-fusion methods, AI output review methods, AI-RAN and O-RAN signal interpretation methods, DePIN validation methods, digital twin assumption review, geospatial evidence methods, cyber evidence methods, benchmarking methods, reproducibility methods, replication methods, and correction methods.

The Board shall ensure that methods are not treated as informal practice, implied authority, sponsor preference, provider workflow, or technical convenience. Material methods shall be versioned, owned, stewarded, reviewed, limited, classified, and made subject to correction, supersession, withdrawal, or retirement.

Methods competence shall support the Board’s ability to determine whether a method is fit for purpose, whether it is experimental or adopted, whether it may be public-safe, whether controlled annexes are required, and whether use of the method could create public authority confusion, finance overclaim, certification overclaim, procurement overclaim, provider preference, or regulated-activity risk.

122.4 Research Integrity Competence.

The Board shall include or obtain access to research integrity competence sufficient to oversee public-benefit R&D, applied research, technical prototyping, public-good software development, evidence systems development, observability methods, ontology development, and publication activity.

Research integrity competence shall include understanding of research design, conflicts of interest, sponsor independence, provider independence, publication review, peer review, reproducibility, replication, research ethics, human-subjects review where required, community review where appropriate, Indigenous, local, territorial, cultural, environmental, health-sensitive, and protected knowledge review, limitation disclosure, correction, supersession, withdrawal, and retraction.

The Board shall ensure that research integrity competence is applied to material research agendas, sponsored research, public reports, whitepapers, datasets, technical releases, controlled annexes, public authority-facing materials, and any research output that may influence public meaning, institutional legitimacy, technical adoption, finance-readiness inputs, GRF inputs, GRA inputs, Nexus standards support, or public authority learning.

122.5 Observability Competence.

The Board shall include or obtain access to observability competence sufficient to oversee GCRI Canada’s support for Nexus Observatory methods, node methods, hub methods, cluster methods, hotspot methods, national dense core methods, regional cluster methods, sensor methods, AI-RAN methods, O-RAN methods, DePIN methods, digital twin methods, cyber telemetry methods, geospatial methods, Earth observation methods, dashboard methods, degraded-mode awareness, and public-safe observability outputs.

Observability competence shall include the ability to distinguish observability infrastructure from emergency command, public warning, operational control, public authority decision-making, certification, finance-readiness determination, or provider validation.

The Board shall ensure that observability outputs are governed as evidence-supporting and method-supported artifacts, subject to source lineage, confidence, uncertainty, classification, public-safe review, data / AI / cyber controls, protected knowledge safeguards, infrastructure sensitivity review, and correction pathways.

122.6 Ontology and Semantic Interoperability Competence.

The Board shall include or obtain access to ontology and semantic interoperability competence sufficient to oversee controlled vocabulary, taxonomies, schemas, data dictionaries, risk categories, maturity concepts, evidence classifications, technical profiles, AI-readable knowledge structures, standards mappings, and cross-institution vocabulary alignment.

Ontology competence shall ensure that terms with legal, governance, evidentiary, technical, public-facing, public authority, finance, certification, procurement, recognition, or Nexus consequence are not silently redefined by program teams, authors, sponsors, providers, technology vendors, public authority participants, informal working groups, or external interfaces.

The Board shall ensure that semantic interoperability supports shared meaning without shared authority. Shared terms among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Observatory, Nexus Network, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, national companies, Project SPVs, providers, sponsors, and public authorities shall not be used to collapse roles, imply control, or create unauthorized legal effect.

122.7 Public-Good Software and Open Technical Baselines Competence.

The Board shall include or obtain access to competence in public-good software, open technical baselines, reference architectures, APIs, SDKs, schemas, dashboards, data dictionaries, test harnesses, gold vectors, negative tests, model cards, system cards, dataset cards, benchmark cards, secure release, repository governance, dependency governance, SBOM, signing, provenance, vulnerability management, licensing, contributor terms, IP ownership, public-good asset stewardship, and anti-enclosure controls.

The Board shall ensure that public-good software and open technical baselines are governed as serious public-benefit infrastructure and not as informal code, unmanaged open-source material, sponsor-controlled tooling, provider marketing assets, procurement mandates, certification instruments, public authority systems, or execution platforms.

Competence in this area shall support Board oversight of secure development, release authorization, restricted asset handling, public-safe release, controlled annexes, fork governance, compatibility claims, Nexus-compatible claims, takedowns, corrections, deprecations, retirements, and successor stewardship.

122.8 AI, Agentic AI, AI-RAN, O-RAN, DePIN, Blockchain / DLT, Sovereign Compute, Edge Compute, HPC, Cyber-Physical Systems, Robotics, Drones, Sensing, Geospatial, Digital Twin, Climate, Disaster, Energy, Water, Food, Health, Industrial, Critical Infrastructure, Quantum-Adjacent, and Other Exponential Technology Competence.

The Board shall include or obtain access to competence across the exponential and mission-critical technology domains relevant to GCRI Canada’s mandate. Such competence shall include, as appropriate, AI, agentic AI, model governance, AI-RAN, O-RAN, private wireless, telecommunications, DePIN, blockchain, distributed ledger technology, Web3-relevant systems, sovereign compute, edge compute, cloud compute, high-performance compute, verifiable compute, verifiable intelligence, cyber-physical systems, robotics, drones, autonomous systems, sensors, geospatial systems, Earth observation, satellite systems, digital twins, simulations, climate systems, disaster systems, energy, water, food, health, biosecurity-relevant systems, industrial systems, ports, utilities, supply chains, advanced manufacturing, semiconductors, quantum-adjacent systems, post-quantum-relevant systems, and other emerging technologies designated by the Board.

Such competence shall be used to govern risk, evidence, methods, observability, public-good software, technical baselines, data / AI / cyber controls, public-safe publication, and Nexus interface support. It shall not be used to create GCRI Canada authority to deploy, operate, certify, procure, finance, insure, rate, regulate, command, or approve any technology, project, provider, system, or public authority function.

122.9 Data Governance Competence.

The Board shall include or obtain access to data governance competence sufficient to oversee lawful basis, purpose limitation, proportionality, minimization, accuracy, classification, retention, deletion, sealing, archival, secure disposal, access controls, disclosure controls, data-sharing, cross-border transfers, data processing agreements, sovereign data zones, compute-to-data, controlled rooms, no-download rooms, data rights requests, data incidents, and public-safe release.

Data governance competence shall enable the Board to distinguish governance need, research need, evidence need, technical development need, public authority learning need, security need, publication need, and convenience use. Sensitive data shall not be collected, processed, transferred, reused, published, modeled, embedded, indexed, or exported merely because it is technically available or operationally convenient.

The Board shall ensure that data governance competence is applied to all material data systems, evidence rooms, public authority rooms, controlled rooms, observability systems, AI systems, dashboards, maps, technical repositories, public releases, and Nexus interfaces.

122.10 AI Governance Competence.

The Board shall include or obtain access to AI governance competence sufficient to oversee model registers, model records, dataset cards, model cards, system cards, benchmark cards, evaluation harnesses, inference records, compute workload records, retrieval and embedding controls, fine-tuning restrictions, model improvement restrictions, agentic AI controls, human review, AI incident response, hallucination handling, bias review, drift review, prompt injection risk, data leakage risk, and public-safe AI outputs.

AI governance competence shall enable the Board to ensure that AI outputs are not treated as official truth, Board decisions, officer decisions, public authority decisions, public warnings, emergency commands, recognition, finance-readiness determinations, certifications, procurement approvals, ratings, provider preferences, or regulated professional opinions.

The Board shall require material AI use to be authorized, logged, classified, reviewed, limited, and correctionable. No unapproved AI processing, shadow AI use, unlogged model improvement, unrestricted embedding of sensitive material, or autonomous external action shall be permitted.

122.11 Cybersecurity Competence.

The Board shall include or obtain access to cybersecurity competence sufficient to oversee security governance, asset inventory, identity and access management, multi-factor authentication, least privilege, secure configuration, endpoint security, network security, cloud security, repository security, application security, data security, logging, monitoring, vulnerability management, incident response, backup, disaster recovery, business continuity, secure development, key management, token management, secrets management, vendor security, and controlled-room security.

Cybersecurity competence shall include understanding that GCRI Canada’s public-good technical assets, evidence systems, observability systems, repositories, AI systems, dashboards, public authority data, community-protected knowledge, and controlled rooms may create heightened risk if compromised, misconfigured, exposed, or misused.

The Board shall ensure that cybersecurity is treated as a governance and public-benefit duty, not merely as an IT function.

122.12 Privacy and Rights-Bearing Data Competence.

The Board shall include or obtain access to privacy and rights-bearing data competence sufficient to oversee personal information, sensitive personal information, health information, biometric information, geospatial information, public authority participant information, community participant information, Indigenous, local, territorial, and protected knowledge holder information, whistleblower information, youth and vulnerable person information, derived information, inferred information, scored information, and synthetic data derived from rights-bearing data.

Privacy competence shall include notice, consent where required, lawful basis, minimization, purpose limitation, access rights, correction rights, deletion rights, complaint pathways, breach notification, privacy impact review, de-identification, pseudonymization, aggregation, redaction, public-safe publication, cross-border transfer, and data processor controls.

The Board shall ensure that privacy is embedded in governance, evidence, research, observability, AI, publication, technical repositories, controlled rooms, public authority interfaces, and community safeguards.

122.13 Indigenous, Community, Protected Knowledge, Safeguards, and Accessibility Competence.

The Board shall include or obtain access to competence in Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, community protocols, protected environmental knowledge, cultural knowledge, vulnerable community safeguards, remote community safeguards, public-safe mapping, accessibility, inclusive participation, grievance, remedy, non-retaliation, protected participation, and do-no-harm controls.

Such competence shall ensure that GCRI Canada does not extract, publish, model, map, transfer, commercialize, or operationalize Indigenous, community, local, territorial, cultural, environmental, or protected knowledge for sponsor convenience, provider convenience, funder preference, public authority pressure, technical curiosity, or institutional prestige.

The Board shall ensure that safeguards competence is applied before approving relevant research, data use, AI use, observability activity, mapping, publication, public authority materials, technical releases, or Nexus interfaces.

122.14 Public Authority Interface Competence.

The Board shall include or obtain access to competence in public authority interface governance sufficient to oversee capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management participant status, public infrastructure operator status, public authority data contribution, public authority reference approval, non-endorsement language, public-safe publication, and correction of public authority misdescription.

Public authority interface competence shall enable the Board to preserve the rule that GCRI Canada is not a regulator, emergency-command body, public-warning body, procurement authority, public finance authority, public health order issuer, permitting body, sovereign decision-maker, or public-private partnership by participation.

The Board shall ensure that public authority engagement supports learning, evidence literacy, technical literacy, public-safe reporting understanding, scenario review, and capacity formation without creating delegation, adoption, endorsement, approval, obligation, or reliance.

122.15 Finance-Readiness Boundary Competence.

The Board shall include or obtain access to finance-readiness boundary competence sufficient to distinguish technical evidence support from regulated finance, securities, insurance, lending, underwriting, rating, capital placement, public finance, grant approval, budget approval, routeability, bankability, investment suitability, insurance-readiness, and finance-readiness determinations.

Such competence shall be applied to GRA interfaces, Nexus Rails interfaces, proof packs, diligence gap maps, capital-reader rooms, insurance-readiness summaries, RNFD, NFD, UNFSD, public finance reader participation, funder reporting, sponsorship materials, investor-facing materials, and any publication that could be interpreted as capital-market signaling.

The Board shall ensure that GCRI Canada’s role remains technical evidence input, observability input, methods input, correction input, and literacy support only, unless a separate lawful scope is adopted and does not violate this Bylaw.

122.16 Non-Execution and Regulatory Perimeter Competence.

The Board shall include or obtain access to competence in non-execution and regulatory perimeter analysis sufficient to identify when an activity may approach securities dealing, investment advice, brokerage, finder activity, underwriting, lending, guarantee, insurance placement, insurance underwriting, rating, payment intermediation, custody, clearing, settlement, public finance approval, procurement approval, certification, accreditation, professional opinion, public authority decision, public warning, emergency command, or regulated technical export.

Where perimeter risk exists, the Board shall require hold, quarantine, re-scoping, legal review, compliance review, externalization to licensed actors, public-safe limitation language, or termination.

Non-execution competence shall be treated as a constitutional competence of the Board because the Corporation’s public-good credibility depends on not becoming the downstream actor it is designed to inform.

122.17 Nexus Public-Good Stack and Enterprise Stack Competence.

The Board shall include or obtain access to competence in the Nexus public-good stack and enterprise stack. This competence shall include understanding of one rail / two stacks discipline, GCRI / GRF / GRA role separation, Nexus Standards and protocol authority boundaries, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, public authorities, universities, communities, media, and capital readers.

The Board shall ensure that GCRI Canada’s public-good inputs can interoperate with enterprise-stack actors without becoming enterprise execution, project development, asset ownership, vendor selection, capital placement, insurance placement, procurement steering, public authority substitution, or shared liability.

Nexus competence shall include the ability to maintain compatibility notes, divergence logs, interface records, non-merger terms, no-agency terms, role-separation terms, correction paths, and public-description discipline.

122.18 External Advisors, Committees, or Expert Panels to Supplement Board Competence.

The Board may supplement its competence through officers, committees, advisory bodies, expert panels, peer reviewers, counsel, auditors, technical reviewers, research advisors, community advisors, Indigenous knowledge advisors, public authority advisors, data / AI / cyber specialists, finance-boundary advisors, and other external experts.

Supplemental competence shall not transfer fiduciary responsibility from the Board unless permitted by law and recorded within a lawful delegation. Advisors, committees, panels, and experts shall not become directors, officers, public authorities, certification bodies, finance-readiness authorities, procurement bodies, recognition bodies, protocol authorities, or execution actors by providing advice.

The Board shall ensure that external advisors and experts are screened, conflict-managed, confidentiality-bound, scope-limited, and recorded.

122.19 Competence Review Records.

GCRI Canada shall maintain competence review records, including the Board competence map, skills matrix, independence review, competence gaps, supplemental advisor records, committee competence records, expert panel records, training records, renewal records, succession records, and mitigation plans.

Competence review records shall be reviewed periodically and whenever the Corporation undertakes a material new program, technology domain, public authority interface, data / AI / cyber activity, public-safe publication, finance-boundary interface, Nexus interface, international activity, controlled-room activity, or technical release.


Section 123. Director Election or Appointment

123.1 Election or Appointment Method.

Directors shall be elected or appointed in the manner required by applicable law, the Articles, this Bylaw, and any Board-approved nomination, election, or appointment procedure. The method of selection shall be recorded and shall identify whether the director was elected by members, appointed by the Board, appointed to fill a vacancy, appointed as an initial director, or selected through another lawful mechanism.

No person shall become a director by title, public profile, founder status, sponsor relationship, donor relationship, provider relationship, public authority participation, technical contribution, authorship, committee service, council membership, employment, advisory role, attendance, subscription, funding support, or informal recognition alone.

123.2 Appointment by Board Where Lawful.

Where permitted by applicable law, the Articles, or this Bylaw, the Board may appoint directors, including to fill vacancies, expand the Board within the authorized number, establish transitional governance, or meet competence, independence, diversity, continuity, or mission needs.

Before appointing a director, the Board shall conduct and record eligibility review, conflict review, independence review, fit-and-proper review, competence review, public-benefit alignment review, non-execution acknowledgment, role-separation acknowledgment, and any required screening. Board appointment authority shall not be used to create sponsor control, provider control, donor control, public authority control, founder entrenchment, related-party dominance, or capture by any external actor.

123.3 Election by Members Where Required by Law or Articles.

Where directors are required to be elected by members under applicable law, the Articles, or this Bylaw, the election shall be conducted in accordance with the required notice, quorum, voting, eligibility, nomination, record, and confirmation procedures.

Member election of directors shall not alter the directors’ fiduciary duties to GCRI Canada. A director elected by members shall not act as delegate, proxy, advocate, or representative of any member or membership class unless expressly permitted by law and consistent with fiduciary duty.

123.4 Nomination Process.

The Board shall establish or approve a nomination process for directors. The nomination process may be administered by the Board, a Governance and Nominating Committee, the Secretary, or another lawful body designated by the Board.

The nomination process shall be designed to identify candidates with the competence, independence, integrity, availability, judgment, public-benefit alignment, Canadian governance understanding, Nexus role-separation understanding, non-execution discipline, and safeguards awareness necessary for fiduciary service. The process shall not be used to allocate seats as sponsor benefits, donor benefits, provider benefits, public authority benefits, investor benefits, host benefits, or partner benefits.

123.5 Nomination Pack Requirements.

Each director nomination pack shall include the information reasonably required to support lawful and informed selection. The nomination pack shall include, as appropriate:

a. candidate identity and contact information;

b. biography and relevant experience;

c. competence profile;

d. public-benefit alignment statement;

e. conflict disclosure;

f. independence disclosure;

g. external roles and fiduciary duties;

h. sponsor, donor, provider, host, public authority, national company, Project SPV, investor, insurer, lender, contractor, partner, and related-party relationships;

i. sanctions, export-control, restricted-party, misconduct, data, AI, cyber, safeguards, and public claims disclosures where appropriate;

j. time-commitment confirmation;

k. confidentiality acknowledgment;

l. consent to act; and

m. required acknowledgments of this Bylaw.

The nomination pack may be classified and access-restricted where it contains personal information, sensitive information, privileged material, or confidential disclosures.

123.6 Eligibility Review Before Appointment or Election.

Before any person is appointed or elected as a director, GCRI Canada shall conduct an eligibility review. The eligibility review shall confirm that the person satisfies applicable legal requirements, Article and Bylaw requirements, consent requirements, qualification standards, and any Board-approved eligibility criteria.

Eligibility review shall also consider whether appointment or election of the person would create legal ineligibility, regulatory concern, sanctions concern, export-control concern, public authority confusion, sponsor or provider capture risk, related-party concentration, confidentiality risk, or material conflict with the Corporation’s public-benefit purpose.

123.7 Conflict Review Before Appointment or Election.

Before appointment or election, each candidate shall provide conflict disclosures sufficient to permit review of actual, potential, and perceived conflicts. The conflict review shall include financial, institutional, professional, fiduciary, research, data, AI, cyber, public authority, sponsor, donor, provider, host, national company, Project SPV, investor, insurer, lender, contractor, partner, family, and reputational conflicts.

Where conflicts are manageable, the Board may impose conditions, recusals, access restrictions, information barriers, committee restrictions, public statement limits, or other safeguards. Where conflicts are not manageable, the candidate shall not be appointed or elected unless applicable law requires otherwise and adequate lawful measures are recorded.

123.8 Independence Review Before Appointment or Election.

Before appointment or election, GCRI Canada shall assess the candidate’s independence of judgment. Independence review shall consider relationships that may materially impair or appear to impair the candidate’s ability to act in the best interests of GCRI Canada.

A candidate shall not be treated as independent merely because no formal conflict exists. The Board shall consider functional dependence, including funding dependence, employer dependence, sponsor affiliation, provider affiliation, public authority role, investor affiliation, related-party relationships, technical dependency, reputational incentives, repeated service on related boards, or external fiduciary obligations.

123.9 Fit-and-Proper Review Before Appointment or Election.

Before appointment or election, GCRI Canada shall conduct a fit-and-proper review proportionate to the role, risk profile, and access level of the candidate. The review may include integrity review, competence review, misconduct review, sanctions and export-control screening, restricted-party screening, public claims review, data / AI / cyber conduct review, safeguards conduct review, and review of any matter that may materially affect fiduciary fitness.

The Board shall record the conclusion of the fit-and-proper review and any conditions imposed.

A director shall not take office until consent to act has been received in the form required by law or Board-approved procedure. The consent shall include acknowledgment of the duties and obligations of directors under applicable law, the Articles, this Bylaw, Board policies, confidentiality obligations, conflict rules, records rules, and public-benefit governance standards.

Consent may be signed electronically where lawful and where authenticity, integrity, custody, and retention controls are satisfied.

123.11 Director Acknowledgment of Bylaw Duties.

Each director shall acknowledge this Bylaw and shall confirm that the director has reviewed or will promptly review the provisions governing Board authority, fiduciary duties, conflicts, confidentiality, reserved matters, non-execution, legal separateness, role separation, public authority boundaries, finance boundaries, data / AI / cyber obligations, safeguards, public-safe publication, validity-by-record, correctionability, amendment, dissolution, and survival.

No director may rely on lack of familiarity with this Bylaw as a basis for disregarding its requirements after reasonable onboarding has been provided.

123.12 Director Acknowledgment of Non-Execution and Role-Separation Boundaries.

Each director shall specifically acknowledge that GCRI Canada is non-executing and role-separated. The acknowledgment shall confirm that GCRI Canada does not, by default, provide recognition, finance-readiness determinations, certification, procurement approval, public authority decisions, emergency command, public warning, investment advice, insurance approval, underwriting, rating, lending, brokerage, public finance approval, or enterprise execution.

The acknowledgment shall further confirm the separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, national companies, Project SPVs, providers, sponsors, hosts, and public authorities.

123.13 Director Acknowledgment of Confidentiality, Data, AI, Cyber, Privacy, Public Authority, Finance-Readiness, Conflict, and Claims-Discipline Obligations.

Each director shall acknowledge the director’s obligations regarding confidentiality, privileged materials, personal information, rights-bearing data, public authority materials, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, commercially sensitive materials, controlled-room materials, community-protected and protected knowledge, AI-use controls, cybersecurity controls, public authority reference controls, finance-readiness boundary controls, conflict disclosure, recusal, public claims discipline, and correctionability.

The acknowledgment shall be renewed periodically or upon material update of relevant policies.

123.14 Appointment or Election Record.

GCRI Canada shall maintain a complete appointment or election record for each director. The record shall include the authority for selection, nomination materials, eligibility review, conflict review, independence review, fit-and-proper review, consent to act, Board or member resolution, term commencement, term length, voting record where applicable, conditions, recusals, access restrictions, and onboarding acknowledgments.

The appointment or election record shall be maintained in the official corporate records and director register.

123.15 Registry Entry and Public or Controlled Notice Where Appropriate.

Upon appointment or election, the Secretary or other authorized custodian shall update the director register and any required corporate filing, repository, Gazette entry, internal notice, controlled notice, or public notice.

Public notices shall use approved language and shall not imply that a director’s external affiliations constitute endorsement, public authority approval, sponsor control, provider preference, finance-readiness, certification, procurement advantage, or Nexus-wide authority.


Section 124. Initial Directors and Transitional Board Arrangements

124.1 Initial Directors.

The initial directors of GCRI Canada shall be the persons named in the Articles, organizational resolutions, incorporation records, or other lawful formation records, or otherwise appointed or elected in accordance with applicable law.

Initial directors shall have the same fiduciary duties, confidentiality duties, conflict duties, public-benefit duties, non-execution duties, role-separation duties, data / AI / cyber duties, public authority boundary duties, finance-boundary duties, and correctionability duties as all later directors. Initial status shall not create founder privilege, permanent authority, special veto, ownership interest, or exemption from this Bylaw.

124.2 Transitional Board Authority.

During the transitional period, the Board may exercise authority necessary to establish GCRI Canada’s legal, governance, financial, records, technical, data, AI, cyber, safeguards, public authority, publication, and Nexus interface controls.

Transitional authority shall include authority to adopt priority policies, establish registers, appoint officers, approve delegations, establish committees, approve initial budgets, accept lawful support, approve core systems, authorize repository structures, adopt public materials controls, and correct inconsistent legacy materials.

Transitional authority shall not permit the Board to exercise prohibited functions, weaken mission lock, bypass applicable law, ignore member approval where required, create sponsor or provider control, or convert transitional convenience into permanent undisclosed governance.

124.3 Transitional Board Duration.

The transitional Board arrangements shall continue for the period specified in the adoption resolution, Articles, formation records, Board resolution, or applicable transition plan. If no period is specified, the Board shall establish a reasonable transition period and shall review it periodically.

The transitional period shall end when the Board certifies that core governance controls, officer appointments, priority policies, registers, records systems, conflict disclosures, delegation matrix, public materials review, Nexus alignment review, and priority compliance controls have been sufficiently implemented or transitioned into ordinary governance.

124.4 Transitional Adoption of Core Policies.

The Board shall prioritize adoption of core policies necessary to operate safely and lawfully. Such policies shall include, as appropriate, conflict of interest and related-party policy, financial controls policy, signing authority and delegation matrix, records and retention policy, data governance policy, privacy policy, AI-use and model governance policy, cybersecurity policy, incident response policy, public-safe publication and claims policy, sponsorship / donation / grant / support acceptance policy, research integrity policy, public authority protocol, community safeguards and protected knowledge policy, controlled-room policy, competition policy, and sanctions / export-control policy.

The absence of a final policy shall not permit uncontrolled activity. Pending adoption, the Board shall apply the most restrictive lawful interpretation and may require holds, interim procedures, limited access, or legal review.

124.5 Transitional Adoption of Registers and Records Systems.

The Board shall establish priority registers and records systems during the transitional period. These shall include the corporate register, director and officer register, member or participant register where applicable, conflict register, related-party register, grant / donation / sponsorship / restricted fund register, public authority capacity register, evidence register, methods register, ontology register, data access register, model register, software and public-good technical asset register, publication register, incident register, correction register, risk register, and Nexus interface register.

The Board shall ensure that registers identify owners, custodians, access classes, classification rules, retention rules, correction paths, and migration rules for prior records.

124.6 Transitional Appointment of Officers.

The Board may appoint initial officers and functional leads during the transitional period. Such appointments shall be recorded, role-scoped, time-limited where appropriate, conflict-reviewed, and subject to Board supervision.

Initial officers shall not possess authority beyond their recorded role descriptions, delegation instruments, applicable law, the Articles, this Bylaw, and Board resolutions. No officer shall acquire permanent authority by transition, custom, founder status, operational necessity, title, public visibility, or technical centrality.

124.7 Transitional Establishment of Committees.

The Board may establish initial committees during the transitional period, including governance and nominating, finance / audit / risk, evidence and methods, research integrity and ethics, data / AI / cybersecurity / verifiable compute, public-good technical assets and IP, ethics / safeguards / accessibility / community / protected knowledge, public authority learning and public-safe communications, and any executive committee where necessary and lawful.

Each transitional committee shall operate under an interim charter or Board resolution identifying mandate, authority, membership, chair, records custodian, quorum or process rules, reporting duties, limits, sunset, and renewal review. No committee shall override reserved matters or exercise prohibited functions.

124.8 Transitional Approval of Delegation Matrix.

The Board shall approve an interim or final delegation matrix during the transitional period. The matrix shall address Board reserved matters, officer authority, signing authority, spending authority, contracting authority, program approval authority, publication approval authority, data access authority, AI-use authority, controlled-room admission authority, public authority reference authority, emergency authority, and escalation pathways.

The delegation matrix shall be written, versioned, recorded, revocable, and subject to periodic review. No person shall rely on implied delegation by title, role, technical access, urgency, prior practice, public visibility, sponsor relationship, or public authority contact.

124.9 Transitional Conflict Disclosures.

Each initial director, officer, committee member, advisor, senior contractor, fellow, technical maintainer, and other designated person shall submit conflict disclosures during the transitional period. The Board shall identify actual, potential, and perceived conflicts and shall impose recusals, information barriers, access limits, role limits, public statement limits, or other controls as needed.

Transitional conflicts shall be treated seriously because early institutional formation may create heightened risks of founder dominance, sponsor influence, provider dependency, public authority confusion, related-party arrangements, and informal authority.

124.10 Transitional Public Materials Review.

The Board shall cause a review of initial public materials, including websites, decks, proposals, reports, whitepapers, social media, media materials, public authority references, sponsor references, provider references, technical claims, finance-readiness references, certification references, recognition references, Docket references, Grid references, Nexus-compatible claims, AI claims, dashboard claims, observability claims, digital twin claims, DePIN claims, AI-RAN claims, proof receipt claims, and public-safe disclaimers.

Materials that overstate authority, imply public authority endorsement, imply finance-readiness, imply certification, imply procurement advantage, imply provider preference, imply GRF recognition, imply GRA determination, collapse Nexus roles, or create reliance shall be corrected, withdrawn, superseded, or clarified.

124.11 Transitional Nexus Alignment Review.

The Board shall conduct an initial Nexus alignment review to confirm GCRI Canada’s relationship with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, public authorities, universities, communities, and partners.

The review shall produce compatibility notes, divergence logs, interface records, boundary language, and correction paths where appropriate. Alignment shall not create merger, agency, shared treasury, shared liability, public authority delegation, finance authority, certification authority, recognition authority, or execution authority.

124.12 Transitional Data, AI, Cyber, Privacy, and Publication Controls.

The Board shall establish interim controls for data, AI, cyber, privacy, controlled rooms, public-safe publication, dashboards, maps, repositories, and technical releases before any high-risk activity proceeds. Such controls shall include access restrictions, approved systems, no-shadow-IT rules, no-unapproved-AI rules, model and inference record requirements where material, public-safe review, cybersecurity baselines, incident response, and correction paths.

Where controls are not yet mature, the Board shall require limitation, reduced scope, controlled access, no-download rooms, compute-to-data, legal review, safeguards review, or postponement.

124.13 Transitional Sponsor, Donor, Grant, and Funding Controls.

The Board shall establish interim controls for accepting sponsorships, donations, grants, subscriptions, fees, restricted funds, in-kind contributions, and other lawful support. These controls shall preserve support-without-control, non-distribution, no private inurement, research independence, provider neutrality, public authority boundary discipline, finance-boundary discipline, and anti-capture protections.

No transitional funding need shall justify acceptance of support that purchases outcomes, controls research, suppresses publication, grants provider preference, creates procurement advantage, influences Docket or Grid inputs, purchases recognition, influences finance-readiness, or distorts GCRI Canada’s public-good role.

124.14 Transitional Closeout.

The transitional period shall be closed only by recorded Board action. The closeout record shall confirm completion or controlled carry-forward of priority policies, registers, records systems, officer appointments, committee charters, delegation matrix, conflict disclosures, public materials review, Nexus alignment review, data / AI / cyber controls, funding controls, risk register, and initial training.

Any remaining transitional item shall be assigned an owner, deadline, risk classification, interim control, and escalation path.

124.15 Transitional Board Records.

GCRI Canada shall maintain transitional Board records, including formation records, initial director records, transitional resolutions, policy adoption records, register creation records, officer appointment records, committee establishment records, delegation matrix records, conflict disclosures, public materials review records, Nexus alignment records, data / AI / cyber control records, sponsor and funding control records, transition closeout records, and correction records.

Transitional records shall be preserved as part of the institutional memory of GCRI Canada and shall be available for lawful audit, review, correction, and continuity purposes.


125.1 Term Commencement.

A director’s term shall commence on the date specified in the appointment, election, formation record, Board resolution, member resolution, or other lawful instrument. If no date is specified, the term shall commence on the date the appointment or election becomes effective under applicable law and the Corporation’s records.

No person shall exercise director authority before the lawful commencement of the term, completion of required consent, and entry in the director register, except to the extent permitted by law for initial formation acts.

Consent to act shall be a condition of term commencement. A person selected as a director shall not be treated as an active director until consent has been obtained and recorded in the manner required by law, the Articles, this Bylaw, or Board-approved procedure.

Consent shall include acknowledgment of fiduciary duties, public-benefit purpose, mission lock, non-execution, role separation, confidentiality, conflicts, data / AI / cyber obligations, public authority boundaries, finance boundaries, safeguards, validity-by-record, and correctionability.

125.3 Registry Entry as Condition of Governance Record.

The Secretary or other authorized custodian shall enter the director in the director register promptly after appointment or election becomes effective. Registry entry shall identify the director’s name, term commencement, term expiry or review date, authority source, role, officer or committee positions where applicable, independence status, conflicts summary where appropriate, and any conditions or restrictions.

Registry entry is a governance-record condition and shall support validity-by-record. Failure to update the register shall be corrected promptly and may require ratification or clarification of acts taken during the deficiency period.

125.4 Initial Term.

The initial term of a director shall be the term specified in the Articles, this Bylaw, appointment record, election record, or Board-approved term policy. Initial terms may be staggered to support continuity, independence, institutional memory, and orderly renewal.

Initial term length shall not be used to entrench founders, sponsors, donors, providers, public authorities, related parties, or any external actor. The Board shall consider independence, competence, attendance, performance, conflicts, and mission fidelity before any renewal.

125.5 Renewal Term.

A director may be renewed or re-elected for an additional term if permitted by applicable law, the Articles, this Bylaw, and Board-approved policy. Renewal shall not be automatic.

Before renewal, GCRI Canada shall conduct independence review, conflict review, attendance review, performance review, competence review, public-benefit fidelity review, non-execution compliance review, role-separation review, confidentiality review, and any required screening.

125.6 Maximum Consecutive Terms.

The Board may establish maximum consecutive terms for directors through this Bylaw, Board policy, or Board resolution, subject to applicable law and the Articles. Term limits shall be designed to balance continuity, renewal, independence, anti-capture, institutional memory, competence, diversity, and succession planning.

Where a director reaches the maximum consecutive terms, the director may not continue except as permitted by law and any continuity exception lawfully adopted and recorded.

125.7 Staggered Terms.

The Board may implement staggered terms to ensure that the entire Board does not turn over at the same time and that institutional memory, fiduciary continuity, records continuity, technical oversight, public authority boundary oversight, data / AI / cyber oversight, and Nexus role-separation competence are preserved.

Staggering shall not be used to entrench a faction, founder group, sponsor group, provider group, public authority group, donor group, or related-party group.

125.8 Rotation Principles.

Board rotation shall support renewal, independence, competence, public-benefit stewardship, diversity, anti-capture, and resilience. Rotation shall be managed so that critical knowledge is preserved through continuity packs, records, committee succession, officer reports, onboarding, training, and mentorship without creating informal permanent authority.

A departing director shall cooperate with handover obligations, confidentiality obligations, records return, access revocation, and continuing duties.

125.9 Continuity Exception Where Lawful.

Where lawful and consistent with the Articles, the Board may approve a continuity exception permitting a director to serve beyond an ordinary term limit or expected rotation date where necessary to preserve mission-critical continuity, legal compliance, financial stability, cyber incident response, public authority boundary management, data continuity, research continuity, technical asset continuity, dissolution or restructuring oversight, or major transition completion.

A continuity exception shall be time-limited, recorded, justified, conflict-reviewed, independence-reviewed, and not used for entrenchment.

125.10 Mission-Critical Continuity Extension.

The Board may approve a mission-critical continuity extension where the departure of a director would materially impair GCRI Canada’s ability to maintain public-benefit governance, non-execution, legal separateness, evidence integrity, data / AI / cyber controls, public authority boundary discipline, finance-boundary discipline, safeguards, technical asset continuity, or Nexus interface continuity.

The extension shall identify the mission-critical need, duration, safeguards, succession plan, and closeout conditions.

125.11 Independence Review Before Renewal.

Before any renewal, the director’s independence shall be reviewed. The review shall consider changes in employment, funding relationships, sponsor relationships, provider relationships, donor relationships, public authority roles, national company relationships, Project SPV relationships, investor relationships, insurer relationships, lender relationships, contractor relationships, family relationships, and other circumstances that may impair independent judgment.

Where independence concerns exist, the Board may deny renewal, impose conditions, require recusals, limit committee service, restrict access, or require additional disclosures.

125.12 Conflict Review Before Renewal.

Before any renewal, the director shall update conflict disclosures. The Board shall review whether conflicts remain manageable and whether past compliance with conflict rules supports renewal.

Repeated late disclosures, incomplete disclosures, refusal to recuse, access misuse, public claims misuse, sponsor or provider advocacy, or role confusion shall weigh against renewal.

125.13 Performance and Attendance Review Before Renewal.

Before any renewal, the Board shall review the director’s performance and attendance. The review may consider meeting attendance, preparation, participation, judgment, committee service, training completion, confidentiality compliance, conflict compliance, public-benefit fidelity, contribution to competence needs, correction support, and respect for non-execution and role separation.

Performance review shall not be used to punish good-faith dissent, protected participation, refusal to endorse unsafe decisions, or appropriate stop-the-line action.

125.14 Term Expiry.

A director’s term shall expire at the end of the term specified in the applicable record unless renewed, extended, held over, or otherwise continued in accordance with law, the Articles, this Bylaw, or Board-approved procedure.

Upon expiry, the director shall cease exercising director authority except where holdover is permitted by law. Access to Board systems, controlled materials, confidential materials, and restricted rooms shall be reviewed and revoked or adjusted as appropriate.

125.15 Holdover Where Permitted by Law.

Where permitted by applicable law, the Articles, or this Bylaw, a director may hold over after term expiry until a successor is appointed or elected, the director is renewed, or the director ceases to hold office.

Holdover shall not create a new full term unless lawfully recorded. Holdover shall be recorded and reviewed, and shall not be used to avoid renewal review, conflict review, independence review, member approval, or Board succession planning.

125.16 Term Records.

GCRI Canada shall maintain term records for each director, including commencement date, consent, term length, renewal date, expiry date, stagger class, rotation status, term-limit status, continuity exception, mission-critical extension, independence review, conflict review, performance and attendance review, holdover status, resignation, removal, succession, access revocation, and closeout.

Term records shall be maintained in the director register and official corporate records.


Section 126. Resignation, Removal, Vacancy, Interim Appointment, and Succession

126.1 Resignation by Written Notice.

A director may resign by written notice to GCRI Canada in the manner required by applicable law, the Articles, this Bylaw, or Board-approved procedure. The notice shall be delivered to the Chair, Secretary, registered office, or other authorized recipient.

The resignation notice shall be preserved in the official corporate records. Where appropriate, the resigning director shall also provide a transition note, list of pending matters, committee assignments, conflicts, outstanding action items, controlled materials, and any concerns requiring Board attention.

126.2 Effective Date of Resignation.

A resignation shall be effective on the date specified in the resignation notice or, if no date is specified, when received by GCRI Canada, subject to applicable law. If a resignation would materially impair minimum Board continuity, the Board shall take lawful steps to address the vacancy, quorum, filings, public descriptions, and records.

A director who has resigned shall not continue to act as director after the effective date except to the extent permitted by law for transition assistance without governance authority.

126.3 Resignation Records.

The Secretary or other authorized custodian shall record the resignation in the director register, minute book, corporate records, committee records, public or controlled notices where appropriate, and any required filings.

Access rights, Board portals, email accounts, controlled-room access, repository access, data access, AI tool access, keys, tokens, credentials, and confidential materials shall be reviewed, revoked, returned, or preserved as required.

126.4 Removal Under Applicable Law.

A director may be removed only in accordance with applicable law, the Articles, this Bylaw, and any required member or Board procedure. Removal shall be recorded and shall respect due process where required or appropriate.

Removal authority shall not be used to retaliate against good-faith dissent, protected participation, whistleblowing, stop-the-line action, conflict disclosure, refusal to approve unsafe conduct, or insistence on compliance with non-execution, public authority boundaries, finance boundaries, data / AI / cyber controls, safeguards, validity-by-record, or correctionability.

126.5 Removal for Ineligibility.

A director may be removed, or shall cease to serve where required, if the director becomes legally ineligible, fails to maintain required qualifications, fails to provide required consent or acknowledgment, becomes subject to a legal disqualification, or otherwise cannot lawfully serve.

The Board shall record the basis for ineligibility, any required filings, and any actions taken to preserve validity of prior acts where necessary.

126.6 Removal for Breach of Duty.

A director may be removed where permitted by law for breach of fiduciary duty, breach of duty of care, breach of loyalty, breach of confidentiality, breach of conflict obligations, misuse of authority, failure to preserve public-benefit purpose, failure to preserve non-execution, or other material violation of this Bylaw.

Removal for breach of duty shall be supported by an adequate record, investigation or review where appropriate, opportunity to respond where required, and Board or member action as applicable.

126.7 Removal for Unmanaged Conflict.

A director may be removed, suspended from certain matters, not renewed, or otherwise restricted where permitted if an unmanaged conflict materially impairs the director’s ability to serve. Unmanaged conflict includes refusal to disclose, refusal to recuse, acting for an external interest, using Board information for third-party benefit, sponsor or provider advocacy inconsistent with fiduciary duty, or repeated conflict violations.

The Corporation may impose lesser measures where appropriate, including access limits, committee removal, recusal, information barriers, public statement restrictions, or monitored participation.

126.8 Removal for Serious Misconduct.

A director may be removed where permitted for serious misconduct, including fraud, corruption, bribery, harassment, retaliation, discrimination, data misuse, privacy breach, AI misuse, cyber misconduct, repository misconduct, protected knowledge breach, public authority misrepresentation, finance overclaim, certification overclaim, procurement overclaim, sponsor capture, provider capture, or conduct materially inconsistent with public trust.

Immediate interim restrictions may be imposed where necessary to protect the Corporation, records, people, data, systems, public authority interfaces, community safeguards, or public-good assets.

126.9 Removal for Persistent Non-Attendance.

A director may be removed, not renewed, or treated as having failed performance expectations where permitted if the director persistently fails to attend meetings, review materials, participate in required decisions, complete required training, update disclosures, or respond to governance-significant matters.

The Board shall consider legitimate reasons, accessibility needs, health issues, protected circumstances, and accommodation before removal where appropriate.

126.10 Removal for Misuse of Name, Marks, Authority, Data, Records, Software, Technical Assets, or Public Claims.

A director may be removed or restricted where permitted if the director misuses GCRI Canada’s name, marks, logo, seal, reports, datasets, software, technical baselines, repositories, records, public-good assets, public authority references, Nexus references, or public claims.

Misuse includes implying authority to bind, certification, recognition, finance-readiness, public authority endorsement, procurement advantage, provider preference, investment suitability, insurance approval, public warning, emergency command, or Nexus-wide authority without lawful authorization.

126.11 Removal for Conduct Inconsistent With Public-Benefit Purpose, Non-Execution, or Role Separation.

A director may be removed, not renewed, or restricted where permitted if the director materially acts against GCRI Canada’s public-benefit purpose, mission lock, non-execution boundary, legal separateness, role separation, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, safeguards obligations, or correctionability.

Such conduct includes attempts to use GCRI Canada as an execution vehicle, finance vehicle, certification body, procurement gatekeeper, public authority substitute, sponsor-controlled platform, provider-selection body, or private-benefit instrument.

126.12 Vacancy.

A vacancy occurs when a director resigns, is removed, dies, becomes legally ineligible, is not renewed, reaches term expiry without holdover, or otherwise ceases to hold office. The vacancy shall be recorded promptly.

The existence of a vacancy shall not invalidate prior lawful acts of the Board, provided the acts were taken with lawful authority, quorum, and records. The Board shall review whether the vacancy affects quorum, committee composition, signing authority, competence coverage, independence, or filings.

126.13 Board Authority to Fill Vacancy Where Lawful.

Where permitted by applicable law, the Articles, or this Bylaw, the Board may fill a vacancy by appointing a qualified person. The appointment shall be subject to eligibility review, conflict review, independence review, fit-and-proper review, competence review, consent, and recorded approval.

A vacancy appointment shall not be used to create capture, avoid member approval where required, bypass nomination controls, or entrench related parties.

126.14 Member Authority to Fill Vacancy Where Required.

Where applicable law, the Articles, or this Bylaw require members to fill a vacancy, the vacancy shall be submitted to members in accordance with required notice, quorum, voting, and record procedures.

The Board may recommend candidates or take interim steps only to the extent lawful and necessary to preserve governance continuity.

126.15 Remaining Directors’ Authority Where Quorum Remains.

Where a vacancy exists and the remaining directors maintain quorum, the remaining directors may continue to act within lawful authority, subject to applicable law, the Articles, this Bylaw, and any higher thresholds required for reserved matters.

The remaining directors shall consider whether any reserved matter, high-risk matter, or competence-dependent matter should be deferred until the vacancy is filled.

126.16 Minimum Board Continuity Where Quorum Does Not Remain.

Where vacancies cause the Board to fall below quorum or the minimum number required by law or the Articles, the remaining directors shall act only to the extent permitted by law to restore the Board, call a member meeting where required, protect records, preserve assets, address urgent legal obligations, maintain insurance, preserve data and cybersecurity, and prevent harm.

No expanded governance action shall be taken without lawful authority.

126.17 Interim Appointment.

Where lawful and necessary, the Board may make an interim appointment to preserve continuity. An interim director shall have only the authority permitted by law, the Articles, this Bylaw, and the appointment record.

Interim appointments shall be time-limited, purpose-limited where appropriate, conflict-reviewed, independence-reviewed, and subject to full confirmation, election, renewal, or replacement according to applicable procedure.

126.18 Acting Director Prohibition Unless Lawfully Appointed.

No person shall act as an “acting director,” “de facto director,” “shadow director,” “observer-director,” “board advisor with voting rights,” or equivalent governance authority unless lawfully appointed or elected as a director.

Board observers, advisors, officers, committee members, public authority participants, sponsors, donors, providers, founders, or external experts shall not exercise director authority by attendance, influence, authorship, funding, technical centrality, or operational control.

126.19 Succession Planning.

The Board shall maintain succession planning for directors, officers, committee chairs, records custodians, technical stewards, evidence stewards, data / AI / cyber stewards, safeguards stewards, and public authority interface stewards.

Succession planning shall protect public-benefit purpose, mission lock, legal separateness, non-execution, role separation, evidence integrity, data / AI / cyber controls, public authority boundaries, finance boundaries, technical asset continuity, and institutional memory.

126.20 Continuity Packs.

The Board shall require continuity packs for directors or roles of institutional significance. Continuity packs may include pending matters, key decisions, delegated authorities, committee assignments, conflicts, recusal obligations, major risks, key contacts, records locations, public authority interfaces, data / AI / cyber access, technical asset responsibilities, publication matters, correction matters, and Nexus interface obligations.

Continuity packs shall be classified and handled according to confidentiality, privacy, cyber, public authority, finance, and protected knowledge requirements.

126.21 Vacancy and Succession Records.

GCRI Canada shall maintain vacancy and succession records, including resignation records, removal records, vacancy notices, quorum assessments, interim appointments, successor appointments, member elections where applicable, transition notes, continuity packs, access changes, filings, public or controlled notices, and correction records.

Such records shall support continuity, legal compliance, transparency within lawful bounds, and validity-by-record.


Section 127. Board Meetings: Regular, Special, Annual, Emergency, Virtual, Hybrid, and Written

127.1 Regular Board Meetings.

The Board shall hold regular meetings at intervals sufficient to discharge its fiduciary, governance, strategic, financial, legal, risk, public-benefit, non-execution, data / AI / cyber, public authority, safeguards, and Nexus oversight responsibilities.

Regular meetings shall include, as appropriate, review of strategy, budget, financial position, risk register, conflict register, evidence and methods matters, research integrity matters, data / AI / cyber matters, public-safe publication matters, public authority boundary matters, finance-boundary matters, sponsorship and funding matters, committee reports, officer reports, corrections, incidents, and Nexus interface matters.

127.2 Special Board Meetings.

Special Board meetings may be called in accordance with applicable law, the Articles, this Bylaw, or Board-approved procedure to address matters requiring Board attention outside the regular meeting cycle.

Special meetings may address reserved matters, urgent governance issues, major contracts, funding decisions, policy adoption, officer appointments, conflicts, incidents, public authority matters, data / AI / cyber matters, publication risks, finance-boundary issues, sponsor or provider capture risks, or other material matters.

127.3 Annual Board Meeting.

The Board shall hold an annual Board meeting or annual governance session as required by law, the Articles, this Bylaw, or Board-approved procedure. The annual meeting shall review the Corporation’s governance, financial position, public-benefit performance, annual plan, budget, risk register, committee structure, director terms, officer appointments, major policies, compliance status, and public-safe annual reporting where applicable.

The annual Board meeting shall not substitute for any member meeting required by law or the Articles.

127.4 Emergency Board Meeting.

An emergency Board meeting may be called where urgent action is required to protect GCRI Canada, its public-benefit purpose, records, data, systems, public authority interfaces, community safeguards, public-good assets, legal compliance, financial controls, reputation, or Nexus interfaces.

Emergency meeting triggers may include cyber incidents, data breaches, AI incidents, public authority misdescription, public-safe publication errors, finance overclaim, certification overclaim, procurement overclaim, public warning confusion, sponsor or provider capture, legal deadlines, regulatory perimeter risks, protected knowledge harm, or other stop-the-line matters.

127.5 Virtual Board Meeting.

The Board may meet virtually where permitted by law, the Articles, and this Bylaw. Virtual meetings shall use approved secure systems appropriate to the sensitivity of the materials and shall support identity verification, participation, confidentiality, access control, voting, record creation, and minute preparation.

Virtual meeting systems shall not be used for restricted, privileged, cyber-sensitive, public authority-sensitive, infrastructure-sensitive, finance-sensitive, personal, or protected knowledge materials unless approved safeguards are in place.

127.6 Hybrid Board Meeting.

The Board may hold hybrid meetings combining in-person and electronic participation where lawful and where all participating directors can hear, be heard, deliberate, vote where applicable, access materials securely, and be recorded for attendance and quorum purposes.

Hybrid meetings shall maintain equality of participation and shall not disadvantage remote participants or create confidentiality, access, or record-integrity gaps.

127.7 In-Person Board Meeting.

The Board may hold in-person meetings at the registered office, another location in Canada, or another lawful and appropriate location. In-person meetings shall maintain confidentiality, security, accessibility, and records discipline.

Where controlled materials are reviewed, the meeting location shall be suitable for secure handling, no unauthorized recording, access restriction, and safe return or destruction of materials.

127.8 Written Resolutions Where Lawful.

The Board may act by written resolution where permitted by applicable law, the Articles, and this Bylaw. Written resolutions shall satisfy all required signature, consent, notice, unanimity, majority, circulation, record, and filing requirements.

Written resolutions shall identify the decision question, authority, text approved, effective date, conflicts, recusals, materials reviewed, and any conditions. Written resolutions shall not be used to avoid deliberation for high-risk matters where deliberation is prudent, unless urgency requires written action and ratification or follow-up review is recorded.

Electronic consent may be used where lawful and where authenticity, identity verification, integrity, record retention, and signature controls are satisfied.

Electronic consent shall not be valid if obtained through informal messaging, ambiguous assent, silence, reaction emojis, unapproved platforms, unsecured channels, or incomplete circulation unless captured and ratified in an authoritative record.

127.10 Secure Meeting Systems.

Board meetings shall use secure meeting systems appropriate to the sensitivity of the agenda and materials. Secure systems shall address identity verification, access controls, encryption where appropriate, waiting room or admission controls, recording restrictions, file-sharing controls, logging, and access revocation.

The Board shall not use unapproved personal accounts, shadow IT, informal AI tools, consumer file-sharing, or unsecured messaging for confidential Board deliberations or controlled materials.

127.11 Controlled-Room Board Sessions.

The Board may hold controlled-room sessions for matters involving highly sensitive materials, including public authority data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive evidence, trade secrets, personal information, protected knowledge, privileged materials, legal investigations, sanctions or export-control matters, AI incidents, or major security incidents.

Controlled-room sessions shall have access logs, attendance controls, no-download controls where appropriate, confidentiality reminders, restricted circulation, and closeout records.

127.12 Confidential Board Sessions.

The Board may hold confidential sessions to discuss matters requiring restricted participation, including personnel matters, officer performance, conflicts, investigations, legal advice, financial distress, sensitive partnerships, public authority matters, sponsor or provider capture risk, data incidents, cyber incidents, protected knowledge, or other sensitive issues.

Confidential session minutes may be limited but shall be sufficient to record authority, decision, attendance, recusals, and necessary actions without unnecessary disclosure.

127.13 In Camera Sessions.

The Board may meet in camera without management, officers, staff, advisors, observers, sponsors, providers, public authority participants, or other non-directors where appropriate for independent fiduciary deliberation.

In camera sessions may be used for executive performance, conflicts, investigations, legal matters, Board evaluation, succession, capture risk, or matters requiring independent Board judgment.

127.14 Executive Sessions.

The Board may hold executive sessions limited to directors and persons invited by the Board for a specific purpose. Executive sessions shall not be used to avoid required records or lawful participation rights.

Any decision made in executive session shall be recorded in a manner sufficient to establish validity, authority, conflicts, recusals, and action items.

127.15 Meeting Schedule.

The Board shall establish a meeting schedule appropriate to the Corporation’s stage, risk profile, programs, funding, public authority interfaces, data / AI / cyber activities, technical releases, publications, and Nexus interfaces.

The meeting schedule may include annual planning sessions, regular oversight meetings, committee reporting cycles, emergency preparedness sessions, risk reviews, assurance reviews, and transition reviews.

127.16 Meeting Records.

GCRI Canada shall maintain Board meeting records, including notices, waivers, agendas, materials, attendance, quorum, conflicts, recusals, abstentions, deliberation summaries, resolutions, votes, written consents, action items, responsible owners, deadlines, corrections, and follow-up records.

Meeting records shall be stored securely in the official corporate records and shall be subject to confidentiality, privilege, privacy, cyber, public authority, finance, protected knowledge, retention, and access controls.


Section 128. Notice, Waiver, Agenda, Materials, Secure Circulation, and Emergency Notice

128.1 Notice Requirement.

Notice of Board meetings shall be given in the manner required by applicable law, the Articles, this Bylaw, or Board-approved procedure. Notice shall identify the date, time, location or electronic access method, meeting type, and any special matters where required or appropriate.

Notice shall be sufficient to allow directors to prepare, identify conflicts, request materials, raise governance concerns, and participate meaningfully.

128.2 Regular Meeting Notice.

Regular meeting notice may be given through an annual calendar, Board-approved schedule, standing notice, or specific notice, to the extent permitted by law and Board procedure.

Where a regular meeting includes a reserved matter, high-risk matter, public authority-sensitive matter, finance-boundary matter, data / AI / cyber matter, protected knowledge matter, major funding matter, or material publication matter, the notice or agenda shall identify the matter with sufficient specificity for preparation and conflict review.

128.3 Special Meeting Notice.

Special meeting notice shall be given in accordance with law, the Articles, and Board procedure. The notice shall identify the purpose of the special meeting and any matter requiring specific Board action.

A special meeting shall not be used to surprise directors with material decisions without adequate materials, except where emergency conditions justify abbreviated notice and the record reflects the reason.

128.4 Emergency Meeting Notice.

Emergency meeting notice may be abbreviated where urgent action is required. Emergency notice may be given by secure electronic means, telephone, messaging system, or other approved method suitable to the urgency and sensitivity of the matter.

Emergency notice shall identify, to the extent practicable, the emergency trigger, proposed action, required participants, confidentiality level, materials access method, and any immediate conflict or recusal concerns.

128.5 Waiver of Notice.

A director may waive notice in the manner permitted by applicable law. Attendance at a meeting may constitute waiver of notice where permitted by law, unless the director attends for the express purpose of objecting to defective notice.

Waiver of notice shall be recorded. Waiver shall not cure defects that applicable law does not permit to be waived, nor shall it excuse failure to obtain member approval where required.

128.6 Agenda Circulation.

An agenda shall be circulated before each Board meeting where practicable. The agenda shall identify decision items, discussion items, consent items, reserved matters, conflicts to be declared, committee reports, officer reports, risk matters, public authority matters, finance-boundary matters, data / AI / cyber matters, safeguards matters, and correction matters.

Agenda discipline shall support informed governance, conflict review, non-execution review, role-separation review, and validity-by-record.

128.7 Board Materials Circulation.

Board materials shall be circulated sufficiently in advance to allow informed review, except where urgency, confidentiality, privilege, security, public authority sensitivity, or protected knowledge concerns require controlled circulation.

Board materials shall identify the decision question, authority, recommended action, legal basis, public-benefit rationale, evidence base, risks, conflicts, data / AI / cyber review, public authority boundary review, finance-boundary review, safeguards review, and correction path where relevant.

128.8 Secure Circulation of Confidential, Privileged, Public Authority, Cyber-Sensitive, Infrastructure-Sensitive, Finance-Sensitive, Commercially Sensitive, Personal, Community-Protected, or Protected Knowledge Materials.

Confidential, privileged, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous, local, territorial, cultural, environmental, or protected knowledge materials shall be circulated only through approved secure systems and only to persons authorized to receive them.

Such materials may require redaction, controlled-room access, no-download controls, watermarking, access logs, time-limited access, legal privilege labeling, public authority handling restrictions, data / AI / cyber restrictions, and return or deletion instructions.

No director, officer, advisor, committee member, or participant shall upload restricted Board materials into unapproved AI systems, personal drives, personal email, public repositories, unsecured chat systems, or unauthorized storage.

128.9 Late Materials.

Late materials may be accepted where necessary, but the Chair, Board, or applicable meeting authority shall consider whether directors have sufficient time to review them. For material matters, the Board may defer decision, approve subject to conditions, require supplemental review, or limit the decision to urgent interim measures.

Late materials shall be clearly identified and stored with the meeting record.

128.10 Supplemental Materials.

Supplemental materials may be circulated before or during a meeting where they clarify, correct, update, or support the matter under consideration. Supplemental materials shall be identified in the minutes or meeting record.

Where supplemental materials materially change the decision basis, the Board shall consider whether additional review, conflict disclosure, legal review, data / AI / cyber review, public authority review, finance-boundary review, or safeguards review is required.

The Board may use a consent agenda for routine, non-controversial, non-reserved, and adequately documented matters. Any director may request removal of an item from the consent agenda for separate discussion.

The consent agenda shall not be used for matters involving significant legal risk, mission lock, non-execution boundary, role separation, public authority boundary, finance boundary, certification boundary, procurement boundary, data / AI / cyber risk, protected knowledge, sponsor or provider capture, major funding, major contracts, or material public claims unless the Board has determined that consent treatment is appropriate and adequately recorded.

128.12 Agenda Control by Chair Subject to Board Authority.

The Chair may coordinate the agenda, subject to Board authority. Agenda control shall not be used to suppress dissent, avoid conflict disclosure, prevent discussion of compliance concerns, avoid correction, block protected participation, prevent stop-the-line matters, or shield officers, sponsors, providers, funders, public authorities, or partners from appropriate Board review.

Directors shall have a reasonable pathway to place governance-significant matters before the Board.

128.13 Director Right to Raise Governance-Significant Matters.

Any director may raise governance-significant matters, including legal concerns, fiduciary concerns, conflicts, non-execution concerns, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, data / AI / cyber risks, public-safe publication errors, safeguards concerns, protected knowledge concerns, sponsor or provider capture, records deficiencies, or correction needs.

Good-faith raising of such matters shall be protected and shall not be treated as disloyalty, obstruction, or misconduct.

128.14 Emergency Notice Where Cyber, Data, AI, Public Authority, Public-Safe Publication, Finance Boundary, Legal Deadline, or Stop-the-Line Matter Arises.

Emergency notice shall be given promptly where a cyber incident, data breach, AI incident, public authority confusion, public-safe publication error, finance-boundary overclaim, certification overclaim, procurement overclaim, legal deadline, regulatory perimeter issue, protected knowledge risk, community harm, sponsor or provider capture risk, or stop-the-line matter arises.

Emergency notice may be directed to the Chair, affected committee chair, Secretary, relevant officer, counsel, compliance function, data / AI / cyber function, safeguards function, or Board as appropriate. Emergency notice shall be captured in a record and followed by ratification, correction, or closeout as required.

128.15 Notice and Materials Records.

GCRI Canada shall maintain notice and materials records, including notices, waivers, agendas, circulation logs, secure access logs, late materials, supplemental materials, consent agenda materials, emergency notices, redaction records, classification records, public authority handling records, confidentiality labels, and correction records.

Notice and materials records shall support validity-by-record, informed decision-making, conflict management, legal compliance, and accountability.


Section 129. Quorum, Voting, Abstentions, Recusals, Higher Thresholds, Tie Treatment, and Written Resolutions

129.1 Quorum.

Quorum for Board meetings shall be the quorum required by applicable law, the Articles, this Bylaw, or Board-approved governance procedure. Quorum shall be determined at the time of the meeting and, where necessary, at the time of a vote.

Only duly appointed or elected directors entitled to participate in the matter shall count toward quorum, except where law provides otherwise. Observers, advisors, officers, committee members, sponsors, donors, providers, public authority participants, counsel, experts, fellows, staff, or guests shall not count toward Board quorum unless they are also directors and not recused.

129.2 Higher Quorum for Reserved Matters.

The Board may require higher quorum for reserved matters, constitutional matters, mission-lock matters, amendments, dissolution, major funding, major contracts, major public authority interfaces, major Nexus interface agreements, major data / AI / cyber matters, major public-good technical asset transfers, major public-safe publications, major finance-boundary matters, or other matters designated by law, the Articles, this Bylaw, or Board resolution.

Higher quorum requirements shall be recorded and shall not be waived informally.

129.3 Loss of Quorum by Recusal.

Where conflicts, recusals, or access restrictions reduce the number of directors eligible to deliberate or vote below quorum, the Board shall not proceed on the affected matter unless applicable law, the Articles, this Bylaw, or a lawful conflicts procedure permits action.

The Board may defer the matter, seek member approval where applicable, appoint additional independent directors where lawful, use an independent committee where lawful, obtain external review, or apply another lawful process to resolve the quorum issue.

129.4 Voting Standard.

The voting standard for Board action shall be the standard required by applicable law, the Articles, this Bylaw, or Board-approved procedure. Unless a higher threshold applies, Board action may be approved by the required majority of directors present and entitled to vote at a meeting with quorum.

Voting standards shall be identified before or at the time of decision and recorded in the minutes or written resolution.

129.5 Majority Vote.

Where a majority vote standard applies, the matter shall be approved only if it receives the required affirmative vote of directors entitled to vote. Abstentions, recusals, absences, and non-responses shall be treated according to applicable law, the Articles, this Bylaw, and Board procedure.

The minutes shall record the vote outcome and any abstentions, recusals, dissents, or minority notes where permitted.

129.6 Higher Approval Thresholds.

Higher approval thresholds may apply to matters required by law, the Articles, this Bylaw, Board resolution, member approval requirement, reserved matters schedule, conflict policy, dissolution provision, amendment provision, or other governance instrument.

Higher approval thresholds may include supermajority approval, approval of independent directors, approval of disinterested directors, unanimous written consent, member approval, special resolution, court approval, regulatory approval, or other required approval.

129.7 Unanimous Approval Where Required by Law or Articles.

Where unanimous approval is required by law, the Articles, or this Bylaw, the matter shall not be effective unless unanimous approval is obtained in the required form. Unanimous approval requirements shall be strictly observed.

A failure to obtain unanimous approval shall not be cured by informal assent, silence, attendance, repeated practice, operational implementation, sponsor expectation, public authority expectation, or officer action.

129.8 Abstentions.

A director may abstain from voting where appropriate or required. Abstentions shall be recorded. An abstention shall not be used to avoid conflict disclosure or mandatory recusal where a conflict exists.

Where abstentions affect approval thresholds, the effect shall be determined under applicable law, the Articles, this Bylaw, and Board procedure.

129.9 Mandatory Recusals.

A director shall recuse where required by applicable law, the Articles, this Bylaw, conflict policy, Board resolution, or fiduciary duty. Mandatory recusal may be required for financial conflicts, institutional conflicts, related-party transactions, sponsor or donor matters, provider matters, host matters, public authority matters, national company or Project SPV matters, investor, insurer, or lender matters, employment matters, research conflicts, data / AI / cyber conflicts, protected knowledge conflicts, or matters where the director cannot exercise independent judgment.

Mandatory recusal may require exclusion from deliberation, voting, materials, controlled rooms, executive session, or confidential records, depending on the nature of the conflict.

129.10 Voluntary Recusals.

A director may voluntarily recuse where the director reasonably believes participation could create actual, potential, or perceived conflict, impair confidence in the decision, or undermine public-benefit governance.

Voluntary recusal shall be recorded and may be accepted by the Chair or Board. Voluntary recusal shall not be treated as admission of wrongdoing.

129.11 Effect of Recusal on Deliberation and Access to Materials.

Where a director is recused, the Board shall determine whether the director must leave the meeting, abstain only from voting, be excluded from deliberation, be denied access to certain materials, be removed from controlled-room access, or be subject to an information barrier.

The effect of recusal shall be proportionate to the conflict and risk. For highly sensitive matters, including related-party transactions, sponsor influence, provider selection risk, public authority materials, finance-sensitive matters, data / AI / cyber incidents, protected knowledge, or legal investigations, access restrictions may be required.

129.12 Tie Treatment.

If a vote results in a tie, the matter shall fail unless applicable law, the Articles, this Bylaw, or Board procedure provides otherwise. The Board may reconsider, defer, request additional information, refer to committee, seek external advice, revise the proposal, or use another lawful process.

Tie treatment shall be recorded. The Chair shall not have a casting vote unless expressly permitted by applicable law, the Articles, this Bylaw, or Board procedure.

129.13 Chair Vote Where Applicable.

The Chair shall have the same voting rights as any other director unless applicable law, the Articles, this Bylaw, or Board procedure provides otherwise. The Chair shall not use procedural authority to distort voting outcomes, suppress dissent, avoid recusals, or force decisions without adequate review.

Any casting vote or special Chair voting rule shall be expressly authorized and recorded.

129.14 Written Resolution Requirements.

Written resolutions shall comply with applicable law, the Articles, this Bylaw, and Board procedure. A written resolution shall identify the exact text approved, decision authority, effective date, required approvals, conflicts, recusals, materials reviewed, and any conditions.

Written resolutions shall be stored with the corporate records and shall have the same force as a resolution adopted at a meeting only if all legal and procedural requirements are satisfied.

Electronic signature or consent may be used for written resolutions and other Board approvals where lawful and where identity, authority, intent, integrity, retention, and auditability are preserved.

Electronic signatures or consents shall not be obtained through ambiguous informal channels. The Corporation shall maintain electronic signature records, consent records, circulation records, and authenticity records sufficient to support validity-by-record.

129.16 Voting Records, Abstention Records, and Recusal Records.

GCRI Canada shall maintain voting records, abstention records, and recusal records for Board decisions. Such records shall identify the matter, authority, quorum, directors present, directors voting, directors abstaining, directors recused, effect of recusal on materials and deliberation, vote threshold, vote result, dissent or minority note where permitted, and any follow-up action.

Voting, abstention, and recusal records shall be maintained in the minute book or other official records and shall be subject to confidentiality, privilege, privacy, public authority, data / AI / cyber, protected knowledge, and retention controls.

Section 130. Electronic Participation, Secure Deliberation, and Record Integrity

130.1 Electronic Participation Permitted Where Lawful.

Directors may participate in Board meetings, committee meetings, executive sessions, in camera sessions, written resolutions, emergency sessions, controlled-room sessions, and other governance proceedings by electronic, virtual, hybrid, telephonic, secure video, secure collaboration, or other lawful communications means, provided that such participation is permitted by applicable Canadian law, the Articles, this Bylaw, and any Board-approved procedure.

Electronic participation shall be treated as participation for quorum, deliberation, voting, attendance, and records purposes only where the system used permits directors to communicate adequately, verify identity, receive and review materials as authorized, declare conflicts, participate in deliberation, vote or consent where applicable, and be recorded in the official governance record.

Electronic participation shall not reduce fiduciary duties, confidentiality obligations, conflict obligations, public-benefit obligations, non-execution duties, role-separation duties, data / AI / cyber obligations, public authority boundary obligations, finance-boundary obligations, safeguards obligations, or records obligations. A director participating electronically shall be subject to the same duties as a director physically present.

130.2 Identity Verification.

GCRI Canada shall establish identity-verification procedures for electronic participation proportionate to the sensitivity of the meeting, materials, decision, and access environment. Identity verification may include approved account credentials, multi-factor authentication, secure meeting admission, device controls, verbal confirmation, electronic signature, secure voting credentials, or other controls approved by the Board or authorized officer.

No person shall participate electronically in a Board or governance session under another person’s identity, using shared credentials, through an unauthorized proxy, through an unsecured account, or through a device or platform that materially compromises confidentiality, integrity, or access control.

Where identity cannot be verified with reasonable confidence, the Chair, Secretary, meeting administrator, or authorized security function may deny admission, restrict participation, suspend voting, move the matter to a secure channel, or require later ratification.

130.3 Secure Access.

Electronic access to Board proceedings and materials shall be granted only through approved systems, approved accounts, and approved access controls. Access shall be limited to directors and other persons authorized for the particular meeting, matter, room, record, or material class.

Secure access shall include, as appropriate, multi-factor authentication, role-based access, least-privilege permissions, time-limited links, device controls, no-download controls, watermarking, logging, encryption, waiting-room controls, removal controls, and access revocation.

No sponsor, donor, provider, public authority participant, advisor, fellow, officer, employee, contractor, observer, committee participant, council participant, technical contributor, or partner shall have access to Board deliberations or Board materials unless expressly authorized for a defined purpose and subject to confidentiality, conflict, data, cyber, public authority, finance-boundary, and records controls.

130.4 Confidentiality of Electronic Deliberations.

Electronic deliberations of the Board shall be confidential unless the Board authorizes disclosure or publication in accordance with this Bylaw. Directors and authorized participants shall ensure that electronic participation occurs in a private environment suitable for the sensitivity of the materials and deliberation.

No director or participant shall allow unauthorized persons to observe, listen to, record, view, copy, photograph, screenshot, transcribe, summarize, transmit, or otherwise access confidential Board deliberations. Directors shall take reasonable steps to prevent unauthorized visibility of screens, documents, chat windows, notes, side channels, and AI-generated summaries.

Confidentiality shall apply to audio, video, chat, screen shares, annotations, files, recordings, transcripts, metadata, voting interfaces, Board portals, drafts, comments, decision packs, executive-session materials, privileged materials, controlled-room materials, public authority materials, finance-sensitive materials, cyber-sensitive materials, infrastructure-sensitive materials, personal information, and protected knowledge.

130.5 Recording Prohibition Unless Authorized.

No Board meeting, committee meeting, executive session, in camera session, controlled-room session, emergency session, or other governance proceeding shall be recorded, transcribed, screen-captured, photographed, livestreamed, mirrored, or otherwise captured except where expressly authorized by the Board, Chair, Secretary, or other competent authority under a Board-approved procedure.

Any authorized recording or transcript shall be classified, stored, retained, restricted, corrected, sealed, deleted, or archived in accordance with the records, privacy, cyber, privilege, public authority, finance-sensitive, protected knowledge, and retention rules applicable to the session.

Unauthorized recording or capture shall constitute a governance, confidentiality, and cyber incident and may result in access restriction, investigation, removal from the meeting, suspension, termination, legal action, correction notice, or other remedy.

130.6 Protected Meeting Materials.

Board materials circulated electronically shall be protected according to their classification. Protected meeting materials include confidential, privileged, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, health-sensitive, rights-bearing, community-protected, Indigenous, local, territorial, cultural, environmental, protected knowledge, controlled-room, no-download-room, and investigation materials.

Protected materials shall not be downloaded, copied, forwarded, printed, uploaded, exported, embedded, indexed, summarized by unapproved AI tools, stored in personal drives, transmitted through personal email, placed in public repositories, or shared through unapproved messaging channels unless expressly authorized and recorded.

The Secretary, records custodian, data / AI / cyber function, legal function, or other authorized person may require enhanced controls for protected materials, including redaction, no-download access, time-limited access, secure viewer only, watermarking, access logs, screenshot prevention where available, controlled-room review, and post-meeting access revocation.

Electronic voting and electronic consent shall be conducted through mechanisms that preserve identity, authority, intent, vote integrity, confidentiality where required, auditability, and record retention. The voting or consent mechanism shall identify the matter, eligible voters, required threshold, conflicts, recusals, abstentions, vote result, effective date, and record custodian.

Electronic voting shall not be conducted through informal chat, ambiguous assent, silence, emoji reaction, unsecured messaging, unverified email, or unapproved platform unless captured and ratified through an authorized record.

Where a vote involves a reserved matter, related-party matter, conflict-sensitive matter, public authority matter, finance-boundary matter, data / AI / cyber matter, protected knowledge matter, amendment, dissolution, or material public claim, the Board may require enhanced authentication, independent verification, legal review, or formal written resolution.

130.8 Electronic Records.

Electronic Board records shall have the same authority as paper records where maintained in accordance with applicable law, the Articles, this Bylaw, and Board-approved records procedures. Electronic records shall preserve authenticity, integrity, completeness, accessibility, confidentiality, retention, audit trail, and lawful evidentiary value.

Electronic records may include notices, waivers, agendas, decision packs, materials, minutes, written resolutions, electronic consents, voting logs, attendance logs, access logs, conflict disclosures, recusal records, chat records where captured, recordings where authorized, transcripts where authorized, action items, correction records, and repository metadata.

Electronic records shall be stored in approved institutional systems. Personal storage, shadow repositories, personal email archives, unapproved collaboration tools, informal AI systems, and unlogged side-channel archives shall not constitute authoritative records unless captured, reviewed, and incorporated into the official records system.

130.9 Cybersecurity Baseline for Board Systems.

Board systems shall meet a cybersecurity baseline appropriate to the sensitivity and institutional significance of Board governance. The baseline shall include identity and access management, multi-factor authentication, least-privilege access, secure configuration, encryption where appropriate, logging, monitoring, vulnerability management, backup, retention, incident response, vendor review, access revocation, and periodic access certification.

The Board shall ensure that Board systems are treated as critical governance systems because compromise of Board records may compromise corporate authority, fiduciary decision-making, public authority interfaces, finance-boundary discipline, research integrity, data / AI / cyber controls, public-good technical assets, protected knowledge, and Nexus role separation.

Cybersecurity exceptions for Board systems shall be recorded, time-limited, risk-reviewed, and remediated. Emergency use of alternate systems shall be captured, reviewed, and migrated to approved records systems as soon as practicable.

130.10 No Use of Unapproved Personal Accounts or Shadow IT for Board Materials.

Directors, officers, staff, advisors, and authorized participants shall not use unapproved personal accounts, personal drives, consumer messaging systems, unmanaged devices, unauthorized AI tools, shadow repositories, informal collaboration spaces, or unapproved storage for Board materials, Board deliberations, written consents, votes, confidential notes, or governance records.

Use of unapproved systems may be permitted only in an emergency where no approved channel is reasonably available and where the use is necessary to prevent harm, meet a legal deadline, respond to an incident, or preserve critical governance continuity. Any emergency use shall be captured, reviewed, remediated, and migrated into the official records system.

Violation of this rule may result in incident response, access restriction, correction, cybersecurity review, disciplinary action, removal from governance roles, or other remedy.

130.11 AI Assistant Use in Board Contexts Subject to Approval.

No AI assistant, AI meeting tool, transcription tool, summarization tool, retrieval tool, drafting tool, note-taking tool, decision-support tool, or agentic AI system shall be used in Board contexts unless approved under GCRI Canada’s AI-use, data governance, privacy, cybersecurity, confidentiality, privilege, and records procedures.

AI assistant approval shall identify permitted use, prohibited use, data classes, retention settings, training or model-improvement restrictions, vendor terms, confidentiality controls, human review requirements, output limitations, and record capture requirements.

AI tools shall not be used to make Board decisions, replace director judgment, determine conflicts, issue legal advice, determine finance-readiness, certify compliance, determine public authority status, classify protected knowledge without review, or generate external public claims without authorized human review.

130.12 No Upload of Confidential Board Materials to Unapproved AI Systems.

Confidential Board materials shall not be uploaded, pasted, attached, indexed, embedded, summarized, translated, transcribed, analyzed, or otherwise processed through unapproved AI systems. This prohibition applies to privileged materials, public authority materials, finance-sensitive materials, cyber-sensitive materials, infrastructure-sensitive materials, personal information, protected knowledge, confidential contracts, investigations, Board minutes, decision packs, conflict disclosures, and controlled-room materials.

Any suspected upload of confidential Board materials to an unapproved AI system shall be treated as an AI, privacy, cybersecurity, and confidentiality incident. The incident shall be contained, assessed, corrected, recorded, and escalated as required.

130.13 Electronic Participation Incident Response.

Electronic participation incidents shall be reported, triaged, contained, reviewed, corrected, and recorded. Incidents may include unauthorized access, identity failure, meeting intrusion, recording violation, screen-share error, misdirected materials, access-control failure, data leakage, AI misuse, personal account use, cyber compromise, public authority material exposure, protected knowledge exposure, privileged-material exposure, or voting integrity concern.

The Chair, Secretary, data / AI / cyber function, legal function, compliance function, safeguards function, or other authorized person may suspend a meeting, move to executive session, restrict access, revoke credentials, freeze a vote, require re-vote, quarantine materials, initiate legal hold, issue correction notices, or refer the matter for investigation.

130.14 Secure Deliberation Records.

GCRI Canada shall maintain secure deliberation records for electronic participation, including meeting notices, attendance records, identity-verification records, access logs, materials circulation logs, voting records, consent records, system records, incident records, cybersecurity exception records, AI-use approval records, access revocation records, and correction records.

Secure deliberation records shall be maintained in the official records system and shall be subject to confidentiality, privilege, privacy, public authority, finance, cyber, infrastructure, protected knowledge, retention, sealing, deletion, archival, and successor-access controls.


Section 131. Emergency Board Decisions and Ratification

131.1 Emergency Decision Purpose.

Emergency Board decision authority exists to permit GCRI Canada to act lawfully, promptly, and proportionately when urgent circumstances require governance action before ordinary Board procedures can reasonably be completed. Emergency authority shall preserve the Corporation, its public-benefit purpose, non-execution boundary, legal separateness, records, systems, people, data, public authority interfaces, community safeguards, public-good technical assets, and Nexus role separation.

Emergency decision authority shall not convert GCRI Canada into an emergency command body, public warning authority, regulator, finance-readiness authority, procurement authority, certification body, lender, insurer, underwriter, investment advisor, public finance approval body, or execution vehicle.

131.2 Emergency Decision Triggers.

Emergency decision procedures may be triggered by circumstances requiring immediate action to prevent or mitigate legal, governance, operational, financial, data, AI, cyber, privacy, public authority, publication, research integrity, safeguards, technical asset, sponsor, provider, or Nexus interface harm.

Emergency triggers shall be interpreted narrowly and shall not be invoked for ordinary convenience, poor planning, avoidable delay, sponsor pressure, provider pressure, public relations urgency, fundraising desire, event timing, commercial opportunity, or preference to avoid normal Board review.

131.3 Cyber Incident Trigger.

A cyber incident may trigger emergency decision procedures where there is suspected or confirmed unauthorized access, credential compromise, repository compromise, ransomware, malware, vulnerability exploitation, data exfiltration, technical asset compromise, key or token exposure, supply-chain compromise, system outage, public dashboard compromise, controlled-room compromise, or other security event affecting GCRI Canada.

Emergency measures may include access revocation, credential rotation, repository freeze, release suspension, system isolation, vendor engagement, incident response activation, public-safe notice preparation, legal review, and forensic preservation.

131.4 Data Breach Trigger.

A data breach or suspected data breach may trigger emergency decision procedures where personal information, public authority data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, community-protected data, Indigenous / local / territorial knowledge, protected knowledge, confidential material, or controlled-room material may have been accessed, disclosed, altered, lost, destroyed, transferred, or processed without authority.

Emergency measures may include containment, access restriction, legal hold, privacy review, notification assessment, public authority engagement where appropriate, safeguards review, data processor escalation, publication freeze, and correction.

131.5 AI Incident Trigger.

An AI incident may trigger emergency decision procedures where an AI system, model, agentic AI tool, retrieval system, embedding system, inference system, dashboard, digital twin, automated workflow, or AI-assisted publication produces or causes hallucination, fabricated source, unsafe output, unauthorized action, data leakage, bias, discriminatory output, prompt injection, model drift, public overclaim, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, or protected knowledge exposure.

Emergency measures may include model suspension, agent shutdown, inference freeze, retrieval index quarantine, output withdrawal, human review, public-safe correction, vendor escalation, and incident investigation.

131.6 Public-Safe Publication Error Trigger.

A public-safe publication error may trigger emergency decision procedures where a report, whitepaper, dataset, dashboard, map, website, deck, media statement, social media post, technical release, public repository, or public authority-facing material contains a material error, unsafe disclosure, overclaim, missing disclaimer, wrong attribution, misleading public authority reference, finance-readiness implication, certification implication, procurement implication, provider preference, recognition implication, protected knowledge exposure, or outdated evidence.

Emergency measures may include publication freeze, takedown, correction notice, withdrawal, retraction, controlled notice, stakeholder notification, downstream dependency review, and replacement publication.

131.7 Public Authority Confusion Trigger.

Public authority confusion may trigger emergency decision procedures where GCRI Canada, its directors, officers, staff, participants, publications, dashboards, maps, public materials, events, or Nexus interfaces are being interpreted as issuing public warning, emergency command, regulatory guidance, permit approval, funding approval, public finance approval, procurement approval, sovereign endorsement, public-private partnership, official adoption, or public authority decision.

Emergency measures may include corrected language, public clarification, withdrawal of unauthorized references, contact with affected public authorities, suspension of materials, controlled notices, participant communication, and role-separation review.

131.8 Finance-Readiness Overclaim Trigger.

Finance-readiness overclaim may trigger emergency decision procedures where GCRI Canada outputs, materials, rooms, evidence packs, dashboards, public statements, sponsor materials, public authority materials, GRA interfaces, Nexus Rails interfaces, capital-reader materials, or third-party references suggest investment advice, bankability, routeability, insurance-readiness, creditworthiness, underwriting, rating, public finance approval, capital recommendation, investor solicitation, securities offering, public guarantee, grant approval, or budget allocation by GCRI Canada.

Emergency measures may include finance-boundary review, legal review, non-reliance correction, material withdrawal, stakeholder notice, sponsor or provider correction, and re-scoping.

131.9 Certification or Procurement Overclaim Trigger.

Certification or procurement overclaim may trigger emergency decision procedures where GCRI Canada outputs, technical baselines, software releases, test harnesses, dashboards, research outputs, public materials, provider references, sponsor references, public authority references, or Nexus-compatible claims are being interpreted as certification, accreditation, compliance approval, procurement approval, vendor selection, provider preference, safe harbor, maturity determination, GRF recognition, or standards compliance approval.

Emergency measures may include correction, reclassification, public clarification, provider claim takedown, procurement-neutrality notice, technical baseline disclaimer, and interface review.

131.10 Sponsor or Provider Capture Trigger.

Sponsor or provider capture may trigger emergency decision procedures where a sponsor, donor, funder, provider, vendor, host, partner, national company, Project SPV, investor, insurer, lender, contractor, or related party attempts to influence Board decisions, research findings, evidence methods, publications, data access, public authority access, Docket or Grid inputs, GRF inputs, GRA inputs, standards support, technical baselines, software releases, or public claims.

Emergency measures may include access restriction, recusal enforcement, funding review, agreement suspension, publication review, conflict investigation, benefit freeze, return or restriction of funds, and public-safe clarification.

A legal deadline may trigger emergency decision procedures where immediate Board or authorized action is needed to preserve legal existence, file statutory documents, respond to litigation, comply with regulatory obligations, preserve privilege, respond to a data breach, protect records, maintain insurance, meet tax obligations, prevent loss of rights, preserve IP, respond to sanctions or export-control matters, or comply with court, government, or contractual deadlines.

Emergency action under this trigger shall be limited to the minimum lawful action necessary to meet the deadline or preserve options pending ordinary Board review.

131.12 Safety, Safeguards, Community Harm, or Protected Knowledge Trigger.

Safety, safeguards, community harm, or protected knowledge risk may trigger emergency decision procedures where GCRI Canada activities, publications, maps, dashboards, data handling, AI processing, observability outputs, public authority interfaces, sponsor actions, provider actions, or program activities may expose vulnerable communities, remote communities, Indigenous knowledge, local or territorial knowledge, cultural sites, environmental knowledge, protected participants, whistleblowers, or sensitive locations to harm.

Emergency measures may include stop-work, publication suspension, mapping redaction, data quarantine, access restriction, safeguards review, community notice where appropriate, grievance pathway activation, non-retaliation protection, and correction.

131.13 Emergency Decision Authority.

Emergency decisions may be made by the Board, an emergency Board meeting, an executive committee where lawfully authorized, the Chair where expressly delegated, an officer within emergency delegation, or another competent authority designated by the Board, subject to applicable law, the Articles, this Bylaw, and ratification requirements.

Emergency authority shall be interpreted narrowly. No emergency actor may amend the Articles, amend this Bylaw, dissolve the Corporation, change mission lock, weaken non-execution, approve prohibited functions, bind unrelated Nexus entities, issue public warning, approve finance-readiness, certify compliance, award procurement, or exercise public authority.

131.14 Time-Bound Emergency Measures.

Emergency measures shall be time-bound, proportionate, documented, and limited to what is necessary to contain risk, preserve records, protect people, prevent legal harm, maintain continuity, or prevent public misunderstanding.

Emergency measures may include holds, freezes, quarantines, access restrictions, publication suspensions, technical isolation, credential revocation, temporary delegations, temporary spending, temporary contract authority, controlled notices, and legal preservation measures.

Emergency measures shall expire, be ratified, be replaced by ordinary authority, or be terminated according to a recorded timeline.

131.15 Ratification Requirement.

Emergency decisions taken outside ordinary Board procedure shall be presented for ratification at the next practicable Board meeting or within the timeframe established by Board policy. Ratification shall include a record of the trigger, decision authority, action taken, legal basis, public-benefit rationale, risks, conflicts, affected records, affected persons, notices issued, corrective actions, and proposed closeout.

Failure to ratify shall not automatically invalidate emergency actions if they were lawfully taken and third-party rights or legal obligations have arisen, but the Board shall determine whether correction, reversal, cure, notice, or further action is required.

131.16 Post-Emergency Review.

Following an emergency decision, the Board shall conduct or require a post-emergency review proportionate to the seriousness of the event. The review shall assess cause, authority, timeliness, adequacy, legal compliance, non-execution compliance, role-separation compliance, data / AI / cyber controls, public authority boundary controls, finance-boundary controls, safeguards, communication discipline, record sufficiency, and needed improvements.

The review may result in policy updates, technical controls, training, discipline, contract changes, access changes, public-safe correction, controlled notice, or other corrective action.

131.17 Correction and Notice Where Required.

Where an emergency decision relates to inaccurate public materials, unauthorized public authority references, finance overclaims, certification overclaims, procurement overclaims, public warning confusion, data exposure, AI error, cyber incident, protected knowledge exposure, or sponsor or provider misuse, the Board shall determine whether public correction, controlled correction, stakeholder notice, public authority notice, legal notice, regulator notice, data subject notice, participant notice, or Nexus interface notice is required.

Notice shall preserve privilege, confidentiality, public safety, cybersecurity, privacy, protected knowledge, and public-safe publication discipline.

131.18 Emergency Decision Records.

GCRI Canada shall maintain emergency decision records, including trigger records, notices, meeting records, authority records, decision records, conflict and recusal records, measures taken, access changes, technical actions, communications, legal reviews, public authority reviews, finance-boundary reviews, data / AI / cyber reviews, safeguards reviews, ratification records, post-emergency review records, correction records, and closeout records.

Emergency records shall support validity-by-record, correctionability, accountability, insurance, legal compliance, and institutional learning.


Section 132. Reserved Matters

132.1 Reserved Matters Purpose.

Reserved matters are matters of legal, constitutional, fiduciary, strategic, financial, public-benefit, institutional, risk, data, AI, cyber, public authority, finance-boundary, safeguards, or Nexus significance that require Board approval or another higher approval specified by law, the Articles, this Bylaw, Board resolution, member approval requirement, or policy.

Reserved matters shall not be approved by officers, employees, contractors, committees, councils, advisors, fellows, sponsors, donors, providers, public authority participants, working groups, technical maintainers, or informal leadership structures unless the Board has expressly delegated a matter in a manner permitted by law and this Bylaw.

Reserved-matter discipline is a constitutional protection against mission drift, authority inflation, sponsor capture, provider capture, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, records erosion, and role collapse.

132.2 Bylaw Adoption, Amendment, Repeal, or Replacement.

Adoption, amendment, repeal, restatement, replacement, suspension, or material interpretation of this Bylaw is reserved to the Board and, where required, the members or other competent authority under applicable law and the Articles.

No officer, committee, council, advisor, sponsor, provider, public authority participant, technical maintainer, program lead, or external instrument may amend this Bylaw by practice, policy, contract, technical release, public statement, funding agreement, or operational procedure.

132.3 Articles Amendment or Corporate Reorganization.

Any amendment to the Articles or constituting instruments, continuance, amalgamation, reorganization, arrangement, change of corporate form, change of legal jurisdiction, change of registered office where material, or other structural corporate change is a reserved matter.

Such matters shall require legal review, public-benefit review, nonprofit and tax review, role-separation review, non-execution review, records review, and member or regulatory approval where required.

Any change to GCRI Canada’s legal status, nonprofit status, non-share status, non-distributing status, non-charitable posture, charitable status, jurisdiction, corporate form, registered office where material, or Canadian governance seat is a reserved matter.

No fundraising strategy, donor request, grant condition, sponsor preference, public authority engagement, tax strategy, or operational convenience shall authorize such a change without Board approval and any required legal process.

132.5 Mission-Lock, Non-Execution, Public-Benefit, or Public-Good Stack Change.

Any change that could affect mission lock, public-benefit purpose, non-execution, public-good stewardship, GCRI / GRF / GRA role separation, public-good stack / enterprise stack separation, validity-by-record, correctionability, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, or sponsor non-control is a reserved matter.

The Board shall apply the most restrictive classification where doubt exists. A change shall not be treated as operational merely because it is implemented through a policy, program, technical asset, data workflow, public material, or interface agreement.

132.6 Annual Strategy and Annual Plan.

Approval of the annual strategy and annual plan is reserved to the Board. The annual strategy and annual plan shall align with GCRI Canada’s public-benefit purpose, Canadian legal status, non-execution boundary, research and evidence role, public-good technical stewardship role, data / AI / cyber duties, safeguards duties, financial capacity, and Nexus role-separation obligations.

The annual plan shall identify major programs, research priorities, public-good software priorities, technical baseline priorities, public authority learning priorities, publication priorities, funding needs, major risks, and assurance priorities.

132.7 Annual Budget and Material Budget Amendments.

Approval of the annual budget and material budget amendments is reserved to the Board. The budget shall support public-benefit operations, legal compliance, research integrity, evidence and methods stewardship, data / AI / cyber controls, public-good technical assets, public authority learning, safeguards, records systems, and institutional continuity.

Material budget amendments shall be reviewed for public-benefit purpose, non-distribution, private benefit, donor restrictions, restricted funds, sponsor influence, provider dependency, related-party conflicts, and mission drift.

132.8 Major Grants, Donations, Sponsorships, Restricted Funds, In-Kind Contributions, and Funding Arrangements.

Approval of major grants, donations, sponsorships, restricted funds, in-kind contributions, and funding arrangements is reserved to the Board or to a Board-approved threshold process. Major support shall be reviewed for legal compliance, nonprofit and tax compatibility, public-benefit alignment, non-charitable status compatibility unless lawfully changed, anti-capture, no-control-for-cash, research independence, provider neutrality, data / AI / cyber risk, IP risk, public authority boundary risk, finance-boundary risk, sanctions, export-control, and safeguards.

No major support may grant control over Board decisions, research conclusions, evidence methods, publications, technical baselines, data access, public authority access, GRF inputs, GRA inputs, Docket inputs, Grid inputs, standards support, or Nexus interface outputs.

132.9 Major Contracts and Long-Term Obligations.

Approval of major contracts and long-term obligations is reserved to the Board or to a Board-approved threshold process. Major contracts include significant service agreements, host agreements, research agreements, data-sharing agreements, software agreements, cloud agreements, AI provider agreements, public authority interface agreements, sponsorship agreements, grant agreements, controlled-room agreements, IP agreements, and cross-entity agreements.

Major contracts shall be reviewed for authority, budget, legal risk, data / AI / cyber risk, privacy, IP, confidentiality, public authority boundaries, finance boundaries, competition law, sanctions, export-control, safeguards, termination rights, records, audit rights, and correctionability.

132.10 Major Debt or Credit Facilities Where Lawful.