For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE VI. MANAGEMENT

Section 141. Officers and Executive Leadership Structure

141.1 Officer Structure.

GCRI Canada shall maintain an officer and executive leadership structure sufficient to support lawful corporate governance, fiduciary implementation, public-benefit administration, non-executing operations, public-good technical stewardship, evidence and methods integrity, data / AI / cyber controls, finance-boundary discipline, public authority boundary discipline, safeguards, records integrity, and Nexus role separation.

The officer structure shall be established, modified, consolidated, or discontinued by the Board in accordance with applicable law, the Articles, this Bylaw, Board-approved delegation instruments, and the Corporation’s public-benefit purpose. No title, function, job description, public profile, funding role, technical access, authorship role, operational necessity, or external expectation shall create officer authority unless the role is lawfully appointed, delegated, or recorded.

141.2 Required Officers Where Mandated by Law or Articles.

GCRI Canada shall appoint and maintain any officers required by applicable law, the Articles, or a valid Board resolution. Required officers shall perform the statutory, corporate, fiduciary, records, notice, financial, and compliance functions assigned to them by law, the Articles, this Bylaw, and Board-approved instruments.

Where applicable law or the Articles require an officer function but do not prescribe a specific title, the Board may designate the appropriate officer title, provided that the designation is recorded and does not create ambiguity regarding authority, responsibility, accountability, or public representation.

141.3 Optional Officers.

The Board may create optional officer roles or executive leadership roles where necessary or useful to administer GCRI Canada’s public-benefit mission. Optional officers may include, without limitation, executive, operating, evidence, research, technology, data, AI, cybersecurity, safeguards, legal, compliance, financial, development, program, communications, academy, repository, or public authority interface roles.

Optional officer roles shall be mission-bound, authority-limited, records-based, revocable, and subject to Board oversight. No optional officer role shall be interpreted to expand GCRI Canada’s legal capacity into execution, public authority action, certification, procurement, finance-readiness determination, investment activity, insurance activity, public warning, emergency command, provider selection, or Nexus-wide institutional control.

141.4 Chair.

The Chair shall be an officer of Board governance, unless otherwise determined by the Board or required by law. The Chair’s primary role shall be to support the Board’s fiduciary effectiveness, agenda discipline, meeting integrity, director engagement, mission fidelity, non-execution oversight, public-benefit stewardship, role-separation discipline, and continuity of governance.

The Chair shall not possess sole executive authority, unilateral power to bind GCRI Canada, authority to override Board reserved matters, or authority to represent the Corporation beyond authorized scope unless such authority is separately delegated and recorded.

141.5 Vice-Chair.

The Vice-Chair may be appointed to support the Chair and to provide governance continuity where the Chair is unavailable, conflicted, recused, suspended, incapacitated, or vacant. The Vice-Chair shall perform duties assigned by the Board, by the Chair within lawful authority, or by this Bylaw.

The Vice-Chair shall not independently expand the powers of the Chair, Board, or any officer. Acting in place of the Chair shall not confer authority beyond the Chair’s lawful authority or any specific recorded delegation.

141.6 President.

The Board may appoint a President to serve as an executive officer responsible for leadership, management, external coordination, program implementation, institutional development, or other duties determined by the Board. The President’s authority shall be defined by written role description, delegation matrix, Board resolution, employment or engagement terms, and applicable policy.

The President shall operate within Board-approved strategy, budget, mission lock, public-benefit purpose, non-execution boundary, data / AI / cyber controls, public authority boundary, finance boundary, provider neutrality, sponsor non-control, and records discipline.

141.7 Chief Executive Officer.

The Board may appoint a Chief Executive Officer to serve as the principal executive officer of GCRI Canada, subject to Board oversight and the limitations of this Bylaw. The Chief Executive Officer may be responsible for implementation of Board decisions, supervision of operations, management of personnel, execution of approved contracts within delegation, financial administration within approved authority, and coordination of programs, partnerships, public-good infrastructure, and Nexus interfaces.

The Chief Executive Officer shall not exercise Board reserved powers, amend the Articles or this Bylaw, alter mission lock, weaken non-execution, authorize prohibited functions, bind legally separate Nexus entities, or convert executive convenience into institutional authority.

141.8 Executive Director.

The Board may appoint an Executive Director as the principal operating or executive officer of the Corporation, either instead of or in addition to a President or Chief Executive Officer. The Executive Director shall manage operations within delegated authority and shall support implementation of Board-approved strategy, programs, policies, and institutional controls.

Where more than one executive title exists, the Board shall define the reporting relationship, authority boundaries, reserved matters, signature authority, spending authority, public representation authority, and escalation duties of each role to avoid ambiguity, overlap, apparent authority, or governance drift.

141.9 Secretary.

The Secretary shall serve as the principal corporate records, notice, governance instrument, and authenticity officer unless another arrangement is lawfully approved by the Board. The Secretary shall maintain, or cause to be maintained, the minute book, Board and member records where applicable, resolutions, officer and director registers, committee and council records, adoption records, version records, repository records, Gazette or notice-stream records, and other corporate governance records.

The Secretary’s records function shall be central to validity-by-record and correctionability. No governance act requiring an official record shall be treated as complete merely because it was discussed, circulated, announced, or operationalized without proper record capture.

141.10 Treasurer.

The Treasurer shall support financial stewardship, budget discipline, accounting integrity, restricted-fund tracking, bank account oversight, financial reporting, grant and sponsorship accounting, non-distribution compliance, private-benefit review, audit or review engagement support, tax compliance support, and financial controls.

The Treasurer shall not approve payments, contracts, reimbursements, investments, grants, sponsorships, restricted funds, or financial commitments beyond authority granted by law, this Bylaw, Board resolution, or the signing and spending authority matrix.

141.11 Chief Evidence Officer.

The Board may appoint a Chief Evidence Officer or designate an evidence function to steward evidence doctrine, evidence quality, evidence classification, source lineage, provenance, confidence, uncertainty, dispute handling, assurance packs, public-safe evidence outputs, evidence correction, and evidence inputs to authorized Nexus interfaces.

The Chief Evidence Officer shall not issue recognition, standing, maturity determinations, finance-readiness determinations, certification, procurement approval, public authority decisions, public warnings, or execution instructions.

141.12 Chief Research Officer.

The Board may appoint a Chief Research Officer or designate a research function to oversee research agenda coordination, public-benefit R&D, research integrity, peer review, reproducibility, replication, research ethics pathways, sponsor independence, conflict-managed research, fellowship coordination, research publication review, and research correction.

The Chief Research Officer shall preserve independence of research conclusions and shall ensure that research is not controlled by sponsors, providers, donors, funders, public authorities, national companies, Project SPVs, or market actors.

141.13 Chief Technology Officer.

The Board may appoint a Chief Technology Officer or designate a technical function to steward public-good software, open technical baselines, reference architectures, repositories, secure development, release pipelines, SBOM and dependency governance, APIs, SDKs, schemas, dashboards, data tools, test harnesses, technical contributor coordination, secure releases, signing, provenance, rollback, and technical asset registers.

The Chief Technology Officer shall not convert technical architecture, repository control, system access, maintainer status, software release, reference implementation, or interoperability support into institutional authority, certification authority, procurement mandate, public authority decision, or provider preference.

141.14 Chief Data / AI / Cyber Officer.

The Board may appoint a Chief Data / AI / Cyber Officer or designate a combined or separated data, AI, privacy, security, and cybersecurity function. This role or function may oversee data governance, privacy controls, rights-bearing data, sovereign data zones, cross-border transfers, compute-to-data, AI governance, model registers, inference records, agentic AI controls, cybersecurity baseline, identity and access management, logging, monitoring, incident response, vendor security, and approved technology environments.

The Chief Data / AI / Cyber Officer shall maintain escalation duties for data, privacy, AI, cyber, controlled-room, public authority data, protected knowledge, and infrastructure-sensitive matters.

141.15 Chief Safeguards, Ethics, or Protected Participation Officer.

The Board may appoint a Chief Safeguards, Ethics, or Protected Participation Officer or designate a safeguards function responsible for community safeguards, Indigenous knowledge safeguards, protected knowledge controls, accessibility, grievance and remedy pathways, protected participation, whistleblowing, non-retaliation, do-no-harm review, public-safe mapping, and safeguards stop-the-line escalation.

This role shall not act as a public authority adjudicator, tribunal, regulator, emergency body, or community representative by default. Its authority shall be limited to the safeguards functions lawfully assigned by the Board.

The Board may appoint or retain a General Counsel, Legal Officer, Compliance Officer, or legal and compliance function to support corporate compliance, nonprofit compliance, tax compliance, contract review, regulatory perimeter review, public authority boundary review, finance-boundary review, sanctions and export-control review, competition-law discipline, privacy, AI, cyber, research ethics, employment, IP, incident response, enforcement, disputes, and claims discipline.

The legal or compliance function shall not substitute for Board reserved matters, fiduciary judgment, or competent external legal advice where required. Legal review shall support lawful decision-making but shall not itself create Board approval unless expressly authorized.

141.17 Chief Operating Officer, Program Officer, Development Officer, Communications Officer, or Other Officers Where Approved.

The Board may appoint a Chief Operating Officer, Program Officer, Development Officer, Communications Officer, Academy Officer, Public Authority Interface Officer, Repository Officer, or other officer where useful for lawful administration. Each such role shall be defined by written role description, reporting line, delegation scope, authority matrix, conflict rules, public communications limits, records duties, and escalation requirements.

No operational, development, communications, or program role shall create authority to alter GCRI Canada’s mission, approve prohibited functions, control public authority meaning, imply finance-readiness, issue certification, select providers, bind separate Nexus entities, or override records discipline.

141.18 Distinction Between Statutory Officers and Functional Leads.

The Board shall distinguish between statutory officers, corporate officers, executive officers, functional leads, program leads, technical leads, committee chairs, council officers, fellows, advisors, contractors, and staff roles. Functional responsibility shall not automatically create corporate officer status, fiduciary authority, signature authority, spending authority, public representation authority, or authority to bind GCRI Canada.

Where a functional lead uses a title that could imply officer authority, the Board shall ensure that the role description, public profile, delegation record, and internal records clearly define the limits of authority.

141.19 No Officer Authority Without Appointment, Delegation, or Recorded Role.

No person shall possess officer authority, executive authority, signature authority, spending authority, contracting authority, publication authority, data-access authority, AI-use authority, controlled-room authority, public authority reference authority, finance-boundary authority, or authority to speak for or bind GCRI Canada unless such authority is established by law, the Articles, this Bylaw, Board resolution, written delegation, written role description, or other authorized record.

Authority shall not arise from seniority, expertise, authorship, title ambiguity, funder relationship, sponsor relationship, provider relationship, public authority contact, technical access, repository permission, meeting attendance, external perception, social prominence, or proximity to leadership.

141.20 Officer Structure Records.

GCRI Canada shall maintain officer structure records, including officer titles, statutory status, appointment records, role descriptions, reporting lines, delegations, authority matrices, signature authority, spending authority, public representation authority, data / AI / cyber authority, controlled-room authority, public authority interface authority, conflict disclosures, training records, performance review records, suspension or removal records, succession records, and amendments to the officer structure.

Officer structure records shall be maintained in the official corporate records system and shall support validity-by-record, fiduciary oversight, public-benefit accountability, legal compliance, and institutional continuity.


Section 142. Appointment, Term, Authority, Review, Suspension, Removal, and Succession of Officers

142.1 Appointment Authority.

The Board shall have authority to appoint officers of GCRI Canada except where applicable law, the Articles, this Bylaw, or a Board-approved delegation permits another appointment pathway. Officer appointment shall be a recorded governance act and shall identify the title, role, authority, reporting line, term, effective date, conditions, limitations, and responsible oversight body.

No person shall assume officer status by informal designation, public announcement, organizational chart, website listing, email signature, funder representation, event role, technical role, or operational necessity without an appointment record.

142.2 Board Appointment of Officers.

The Board shall appoint the Chair, Vice-Chair, Secretary, Treasurer, President, Chief Executive Officer, Executive Director, and any other officer designated by the Board as requiring Board appointment. Board appointment shall be made by resolution, written consent, or other lawful decision process.

The appointment record shall identify whether the role is statutory, corporate, executive, functional, interim, acting, unpaid, paid, employee-based, contractor-based, volunteer-based, or otherwise structured. The record shall also identify whether the officer may bind GCRI Canada and, if so, within what limits.

142.3 Appointment of Functional Leads by Delegated Authority Where Permitted.

The Board may authorize an officer to appoint functional leads, program leads, technical leads, repository leads, data stewards, AI stewards, cybersecurity leads, publication leads, safeguards leads, research leads, or other non-statutory roles within an approved delegation.

Such appointments shall not create corporate officer status unless expressly stated in a Board-approved record. Functional leads shall operate within written scope, access controls, public claims limits, and escalation duties.

142.4 Eligibility and Fit-and-Proper Review.

Before appointing an officer, GCRI Canada shall conduct an eligibility and fit-and-proper review proportionate to the role. The review may consider legal eligibility, integrity, competence, experience, fiduciary understanding, public-benefit alignment, non-execution understanding, role-separation understanding, confidentiality capacity, conflict profile, sanctions exposure, export-control exposure, data / AI / cyber fitness, public authority boundary understanding, finance-boundary understanding, and safeguards sensitivity.

A person who cannot reasonably satisfy the eligibility and fit-and-proper standard shall not be appointed or shall be appointed only with recorded restrictions, supervision, or conditions.

142.5 Conflict Review Before Appointment.

Before officer appointment, GCRI Canada shall review actual, potential, and perceived conflicts of interest. Conflict review shall include financial interests, employment relationships, consulting arrangements, sponsor relationships, donor relationships, provider relationships, host relationships, public authority roles, national company roles, Project SPV roles, investor, insurer, lender, contractor, university, laboratory, media, family, or related-party interests.

The Board may require disclosure, recusal, access restriction, resignation from conflicting roles, role limitation, independent supervision, or denial of appointment.

142.6 Independence Review Where Required.

Where an officer role requires independence or materially affects research integrity, evidence integrity, finance-boundary discipline, public authority references, data / AI / cyber controls, safeguards, compliance, financial stewardship, or anti-capture controls, GCRI Canada shall conduct an independence review before appointment.

Independence review shall determine whether the person can exercise judgment for GCRI Canada’s public-benefit purpose without improper influence from sponsors, donors, funders, providers, public authorities, national companies, Project SPVs, investors, insurers, lenders, employers, partners, or personal interests.

No person shall serve as an officer unless the person consents to serve. Consent may be recorded in writing, electronically, by signed appointment letter, employment agreement, contractor agreement, Board record, or other approved form.

The consent record shall include acknowledgment of this Bylaw, role limits, fiduciary or management duties where applicable, confidentiality, conflict disclosure, data / AI / cyber controls, public authority boundaries, finance boundaries, sponsor non-control, provider neutrality, records obligations, and correction duties.

142.8 Written Role Description.

Each officer shall have a written role description or equivalent appointment record. The role description shall identify duties, authority, reporting line, reserved matters, signature authority, spending authority, contracting authority, program authority, publication authority, data / AI / cyber authority, public communications authority, public authority interface authority, escalation duties, records duties, confidentiality obligations, and limitations.

No officer role description shall be interpreted to authorize prohibited functions or override this Bylaw.

142.9 Authority Scope.

Each officer’s authority shall be limited to the scope recorded in the appointment record, role description, delegation matrix, Board resolution, employment or engagement terms, and applicable policy. Authority may be limited by amount, subject matter, geography, time, program, publication class, data class, access class, public authority capacity, finance-boundary class, risk class, or other control.

Where authority is ambiguous, the narrower lawful interpretation shall apply until clarified by the Board or competent delegated authority.

142.10 Term of Office.

The Board may establish a fixed, renewable, indefinite, interim, acting, project-based, program-based, employment-based, or contract-based term for officer service. Term length shall be recorded. A term shall not create entitlement to continued service beyond applicable law, contract, Board resolution, or this Bylaw.

Expiration of a term shall not invalidate lawful acts taken during the term, but acts after expiration shall require renewal, holdover authority, or other lawful record.

142.11 Renewal or Reappointment.

Officer renewal or reappointment shall require review of performance, eligibility, conflicts, independence where required, compliance history, role fit, institutional needs, and any incidents, corrections, or boundary issues. Renewal shall be recorded and may include revised authority, revised compensation, revised reporting line, revised conditions, or non-renewal.

No officer shall have an automatic right to renewal unless required by lawful contract or applicable law.

142.12 Performance Review.

Officers shall be subject to performance review at intervals determined by the Board or applicable policy. Performance review shall evaluate role execution, public-benefit alignment, mission fidelity, operational effectiveness, legal compliance, records discipline, data / AI / cyber compliance, public authority boundary compliance, finance-boundary compliance, sponsor and provider independence, safeguards compliance, personnel leadership, and escalation behavior.

Performance review shall not reward overclaim, speed over truth, sponsor satisfaction over research integrity, provider adoption over neutrality, public authority presence over capacity clarity, capital attention over finance-boundary discipline, or publication volume over evidence quality.

142.13 Suspension.

The Board, or a designated authority where lawfully delegated, may suspend an officer where necessary to protect GCRI Canada, investigate concerns, address conflicts, preserve records, contain risk, respond to misconduct, protect confidentiality, address data / AI / cyber incidents, prevent public authority confusion, prevent finance or certification overclaim, prevent sponsor or provider capture, or comply with law.

Suspension may include removal of authority, access restriction, public representation restriction, spending freeze, signature freeze, data access freeze, controlled-room restriction, repository restriction, and communication restrictions.

142.14 Removal.

The Board may remove an officer to the extent permitted by law, the Articles, contract, and this Bylaw. Grounds may include loss of eligibility, breach of duty, failure of performance, misconduct, unmanaged conflict, confidentiality breach, data misuse, AI misuse, cyber misconduct, public authority overclaim, finance overclaim, certification or procurement overclaim, sponsor or provider capture, retaliation, harassment, legal ineligibility, or conduct inconsistent with public-benefit purpose.

Removal shall be recorded and shall address transition, access revocation, records return, confidentiality survival, public claims correction, and authority termination.

142.15 Resignation.

An officer may resign by written notice or other approved written record. The resignation shall be effective on the date stated in the notice or, if no date is stated, on receipt or as otherwise determined under applicable law and the relevant appointment terms.

Resignation shall not relieve the officer of continuing obligations relating to confidentiality, records, data protection, IP, non-retaliation, conflict disclosure, cooperation, legal holds, correction, and return of property.

142.16 Vacancy.

A vacancy in an officer role may arise by resignation, removal, death, incapacity, expiration of term, disqualification, suspension where treated as vacancy, failure to appoint, or creation of a new role. The Board shall determine whether to fill, consolidate, leave vacant, restructure, or discontinue the role, subject to legal requirements.

Where the vacancy affects a required officer role, critical records function, financial controls, data / AI / cyber controls, public authority protocols, safeguards, or legal compliance, the Board shall ensure continuity measures.

142.17 Interim or Acting Officer Appointment.

The Board may appoint an interim or acting officer where necessary for continuity, emergency response, transition, vacancy coverage, conflict coverage, leave coverage, or program need. Interim or acting authority shall be expressly recorded, time-limited where appropriate, and subject to clear authority limits.

An acting title shall not confer permanent appointment, expanded authority, or authority over reserved matters unless expressly approved by the Board.

142.18 Succession Planning.

The Board shall require succession planning for key officer roles, including Secretary, Treasurer, principal executive officer, evidence function, research function, technical function, data / AI / cyber function, safeguards function, and legal or compliance function where applicable.

Succession planning shall address institutional memory, records access, authority transfer, knowledge transfer, emergency coverage, access controls, signature authority, bank authority, repository access, controlled-room access, data stewardship, and public communications.

142.19 Officer Transition and Handover.

Outgoing officers shall complete transition and handover steps required by the Board, role description, contract, or policy. Handover may include records transfer, access revocation, continuity notes, pending matters, unresolved risks, conflicts, open corrections, contract status, financial status, public authority matters, data / AI / cyber matters, repository matters, controlled-room matters, and pending publications.

Failure to complete handover may be treated as a governance or contractual matter and may affect indemnification, references, access, or future eligibility where lawful.

142.20 Appointment, Review, Suspension, Removal, Resignation, Vacancy, and Succession Records.

GCRI Canada shall maintain officer records, including appointment records, consent records, role descriptions, eligibility reviews, conflict reviews, independence reviews, training acknowledgments, authority matrices, performance reviews, compensation records, suspension records, removal records, resignation notices, vacancy records, interim appointment records, succession plans, transition records, access revocation records, and closeout records.

Such records shall be maintained securely and shall support legal compliance, fiduciary oversight, continuity, auditability, correctionability, and institutional trust.


Section 143. Chair

143.1 Chair Role.

The Chair shall serve as the principal governance leader of the Board and shall support the Board in fulfilling its fiduciary, public-benefit, records, oversight, and role-separation duties. The Chair shall help ensure that the Board acts collectively, lawfully, deliberately, and consistently with the Articles, this Bylaw, applicable law, and GCRI Canada’s non-executing public-good role.

The Chair’s role is governance leadership, not personal command. The Chair shall not be treated as the Corporation’s sole authority, executive substitute, public authority representative, finance authority, certification authority, or Nexus-wide controlling actor.

143.2 Board Governance Leadership.

The Chair shall support effective Board governance by promoting disciplined meetings, informed deliberation, timely escalation, director participation, conflict management, records quality, committee alignment, and oversight of management. The Chair shall assist the Board in maintaining focus on public-benefit purpose, fiduciary accountability, mission lock, non-execution, and institutional continuity.

The Chair shall encourage Board culture that prioritizes truth over speed, record over narrative, correction over concealment, role clarity over prestige, and public-good stewardship over capture.

143.3 Meeting Leadership.

The Chair shall preside at Board meetings unless unavailable, conflicted, recused, suspended, or otherwise unable to act. Meeting leadership shall include calling the meeting to order, confirming quorum, guiding the agenda, managing deliberation, ensuring directors have appropriate opportunity to participate, supporting orderly decision-making, and ensuring that conflicts, recusals, abstentions, and decisions are properly captured.

The Chair shall not suppress material dissent, prevent lawful escalation, conceal conflicts, rush reserved matters, or allow informal decisioning to substitute for recorded Board action.

143.4 Agenda Coordination Subject to Board Authority.

The Chair may coordinate meeting agendas with the Secretary, principal executive officer, committee chairs, legal or compliance function, and other authorized persons. Agenda coordination shall be subject to Board authority and shall not be used to exclude governance-significant matters, suppress risk, avoid conflict disclosure, bypass reserved matters, delay corrections, or prevent directors from raising appropriate concerns.

Agendas shall identify decision items, discussion items, consent items, confidential items, privileged items, controlled-room items, public authority-sensitive items, finance-boundary items, data / AI / cyber items, safeguards items, and matters requiring higher review where appropriate.

143.5 Fiduciary Discipline.

The Chair shall support fiduciary discipline by encouraging directors to act in good faith, with care, loyalty, prudence, diligence, independence, confidentiality, and public-benefit fidelity. The Chair shall help ensure that directors receive sufficient information, time, and context to evaluate material decisions.

The Chair shall not permit fiduciary responsibility to be displaced by management preference, sponsor expectation, provider pressure, public authority attendance, technical urgency, reputational concern, donor influence, or Nexus coordination pressure.

143.6 Public-Benefit Purpose Stewardship.

The Chair shall help the Board preserve GCRI Canada’s public-benefit purpose and nonprofit, non-share, non-distributing posture. The Chair shall ensure that Board deliberations consider whether material decisions advance evidence integrity, methods integrity, public-good technical stewardship, public authority learning, public-safe communication, community safeguards, and Nexus-compatible public-good coordination.

The Chair shall support rejection, re-scoping, or correction of matters that would convert GCRI Canada into a private-benefit, market-executing, sponsor-controlled, provider-controlled, finance-facing, certification-facing, procurement-facing, or public authority-substituting body.

143.7 Mission-Lock Stewardship.

The Chair shall support mission-lock discipline by ensuring that Board decisions do not silently dilute GCRI Canada’s role as an upstream evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and open technical-baseline institution.

The Chair shall ensure that mission-significant changes are treated as reserved matters or constitutional matters where required and are subject to recorded review, impact assessment, lawful approval, and correction of inconsistent materials.

143.8 Non-Execution Boundary Stewardship.

The Chair shall support Board oversight of the non-execution boundary. The Chair shall ensure that activities suggesting execution, market intermediation, public authority action, procurement selection, finance-readiness determination, investment advice, insurance placement, certification, public warning, emergency command, or regulated professional output are escalated before approval or external release.

The Chair shall have authority, within Board-approved procedure, to require a hold, deferral, legal review, committee review, or re-scoping of a matter where non-execution risk is material.

143.9 Role-Separation Stewardship.

The Chair shall help preserve role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, public authorities, and enterprise actors.

The Chair shall ensure that Board materials and public descriptions do not imply merger, agency, shared treasury, shared liability, parent-subsidiary status, recognition authority, finance-readiness authority, standards authority, procurement authority, public authority delegation, or enterprise execution by GCRI Canada.

143.10 Board Evaluation and Continuity Support.

The Chair shall support Board evaluation, director development, committee review, succession planning, continuity packs, emergency succession, and Board renewal. The Chair shall work with the Governance and Nominating Committee or equivalent body where established.

The Chair shall ensure that Board continuity does not depend on any single founder, donor, sponsor, provider, public authority relationship, technical architect, or external Nexus actor.

143.11 Director Engagement and Participation Support.

The Chair shall support active and informed director engagement. The Chair shall encourage directors to prepare, ask questions, disclose conflicts, understand materials, participate in deliberation, and request additional information where needed.

The Chair shall support respectful dissent, minority views, expert caution, safeguards concerns, legal concerns, data / AI / cyber concerns, public authority boundary concerns, and finance-boundary concerns.

143.12 Escalation of Governance-Significant Matters.

The Chair shall ensure that governance-significant matters are escalated to the Board, appropriate committee, legal or compliance function, data / AI / cyber function, safeguards function, or other competent authority. Such matters may include reserved matters, boundary incidents, conflicts, research integrity issues, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, data breach, AI incident, cyber incident, protected knowledge concern, sponsor capture, provider capture, or public-safe publication risk.

The Chair shall not allow governance-significant matters to remain informal where record-based action is required.

143.13 No Sole Executive Authority Unless Separately Delegated.

The Chair shall not possess sole executive authority merely by virtue of office. The Chair may perform executive, signing, spending, contracting, communications, or program duties only where separately delegated by the Board or authorized under applicable law, the Articles, this Bylaw, or recorded policy.

Any such delegation shall be limited, revocable, recorded, and subject to reserved matters, conflicts, records requirements, and non-execution boundaries.

143.14 No Authority to Override Board Reserved Matters.

The Chair shall not override Board reserved matters, committee review requirements, member approval requirements, legal review requirements, conflict rules, public authority protocols, finance-boundary controls, certification-boundary controls, publication controls, data / AI / cyber controls, safeguards controls, or correctionability duties.

Chair action taken in emergency circumstances shall be time-limited, recorded, subject to ratification where required, and incapable of authorizing prohibited functions.

143.15 No Public Representation Beyond Authorized Scope.

The Chair may represent GCRI Canada publicly only within authorized scope. Public representation by the Chair shall be accurate, public-safe, non-executing, non-certifying, non-finance-determining, non-procurement, non-public-warning, non-public-authority-substituting, and consistent with approved language.

The Chair shall not imply that GCRI Canada speaks for GCRI US, GRF, GRA, Nexus Network, Nexus Standards, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, or partners unless expressly authorized by the relevant lawful instrument.

143.16 Chair Conflict and Recusal Duties.

The Chair shall disclose conflicts and shall recuse where required. Where the Chair is conflicted, the Vice-Chair, another director, committee chair, or other person designated by the Board shall lead the relevant matter.

The Chair shall not control agenda, materials, deliberation, access, minutes, or communications for a matter in which the Chair is recused, except as expressly permitted under recorded conflict controls.

143.17 Chair Records.

GCRI Canada shall maintain Chair records, including appointment records, role description, delegation records, conflict disclosures, recusals, public representation approvals, meeting leadership records, agenda records, escalation records, emergency actions, ratifications, training records, evaluation records, and closeout records.

Chair records shall support fiduciary accountability, continuity, role clarity, and institutional trust.


Section 144. Vice-Chair

144.1 Vice-Chair Role.

The Vice-Chair shall support the Chair and the Board in maintaining governance continuity, meeting discipline, fiduciary oversight, mission fidelity, non-execution discipline, role separation, and public-benefit stewardship. The Vice-Chair shall perform duties assigned by the Board, by this Bylaw, or by lawful delegation.

The Vice-Chair’s role shall be supplementary and continuity-focused unless the Board assigns additional authority.

144.2 Support to Chair.

The Vice-Chair may assist the Chair with agenda coordination, director engagement, committee coordination, Board evaluation, succession planning, escalation of governance-significant matters, and maintenance of Board process. Such support shall remain subject to Board authority, confidentiality, conflict rules, and records discipline.

Support to the Chair shall not create independent power to direct management, bind the Corporation, approve reserved matters, or speak publicly beyond authorized scope.

144.3 Acting Role Where Chair Is Unavailable, Conflicted, Recused, Suspended, or Vacant.

The Vice-Chair may act in place of the Chair where the Chair is unavailable, conflicted, recused, suspended, incapacitated, or the office is vacant. Acting authority shall be limited to the authority the Chair could lawfully exercise, subject to any restrictions imposed by the Board.

Where the Vice-Chair also has a conflict, the Board may designate another director to preside or act for the relevant matter.

144.4 Delegated Duties.

The Board may delegate specific duties to the Vice-Chair, including committee oversight, director onboarding, policy review, interface review, emergency governance support, Board evaluation support, or special projects. Delegated duties shall be recorded and shall identify scope, duration, authority, reporting duties, and limitations.

No delegated duty shall include prohibited functions or override Board reserved matters unless expressly and lawfully authorized.

144.5 Board Continuity Support.

The Vice-Chair shall support Board continuity by assisting with succession planning, emergency coverage, committee continuity, director engagement, continuity packs, and governance transitions. The Vice-Chair may support the Chair and Secretary in ensuring that essential Board processes continue during vacancy, illness, emergency, cyber incident, data incident, public authority boundary incident, or other disruption.

Continuity support shall preserve lawful authority, quorum, records, confidentiality, and non-execution boundaries.

144.6 Governance Integrity Support.

The Vice-Chair shall support governance integrity by helping identify process defects, conflicts, incomplete records, agenda omissions, unresolved action items, boundary concerns, and matters requiring escalation. The Vice-Chair may recommend that the Chair or Board defer, hold, re-scope, or review a matter where governance integrity is at risk.

The Vice-Chair shall not use this role to create factional authority, informal veto, or personal control over Board process.

144.7 Escalation Support.

The Vice-Chair shall assist in escalating governance-significant matters where the Chair is unavailable, conflicted, or unable to act. Escalation may include bringing matters to the Board, committee, Secretary, Treasurer, legal or compliance function, data / AI / cyber function, safeguards function, or other competent authority.

Escalation support shall be records-based and shall not bypass required process unless emergency procedure applies.

144.8 No Independent Expansion of Chair Authority.

The Vice-Chair shall not independently expand the authority of the Chair, the Board, any officer, any committee, or the Vice-Chair role itself. Acting for the Chair shall not authorize action that the Chair could not take.

Any ambiguity shall be resolved in favour of narrower lawful authority, Board oversight, and recorded clarification.

144.9 No Executive Authority Unless Separately Delegated.

The Vice-Chair shall not possess executive authority merely by virtue of office. Executive, management, signing, spending, contracting, publication, public communications, data access, AI-use, controlled-room, public authority interface, or Nexus interface authority shall require separate recorded delegation.

The Vice-Chair shall not direct staff, contractors, officers, fellows, advisors, providers, sponsors, or public authority participants except within a lawful and recorded authority path.

144.10 Vice-Chair Conflict and Recusal Duties.

The Vice-Chair shall disclose conflicts, update conflict disclosures, and recuse where required. Where acting for the Chair, the Vice-Chair shall be subject to the same conflict and recusal duties as the Chair.

A conflicted Vice-Chair shall not preside over, influence, access restricted materials for, or communicate outside process regarding the conflicted matter unless expressly permitted by recorded conflict controls.

144.11 Vice-Chair Records.

GCRI Canada shall maintain Vice-Chair records, including appointment records, role description, delegation records, acting authority records, conflict disclosures, recusal records, escalation records, continuity support records, public representation approvals, training records, and closeout records.

Such records shall support governance continuity, accountability, validity-by-record, and role clarity.


Section 145. President, Chief Executive Officer, or Executive Director

145.1 Executive Leadership Role.

The President, Chief Executive Officer, or Executive Director, as applicable, shall serve as the principal executive leader or operating leader of GCRI Canada within the authority granted by the Board. The executive leadership role shall implement Board-approved strategy, policies, programs, budgets, partnerships, records systems, controls, and public-benefit activities.

The executive leader shall not replace the Board, exercise reserved powers, create governance authority by practice, or convert operational management into constitutional control.

145.2 Management of Operations Within Board-Approved Strategy.

The executive leader shall manage operations within Board-approved strategy, annual plan, budget, policies, delegations, and lawful authority. Operations may include research administration, evidence and methods workflows, public-good technical asset support, publications, training, fellowship programs, public authority learning, controlled rooms, partnerships, fundraising support, personnel supervision, and Nexus interface coordination.

Management authority shall be bounded by public-benefit purpose, mission lock, non-execution, role separation, data / AI / cyber controls, safeguards, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, and records discipline.

145.3 Implementation of Board Resolutions.

The executive leader shall implement Board resolutions faithfully, timely, and within the conditions approved by the Board. Implementation shall include coordination of responsible owners, action items, records, filings, notices, contracts, policies, corrections, and follow-up reporting.

The executive leader shall not expand, narrow, reinterpret, delay, or materially alter a Board resolution without appropriate authority or escalation.

145.4 Implementation of Annual Plan.

The executive leader shall implement the annual plan approved by the Board and shall report on progress, risks, deviations, resource needs, boundary issues, and corrective actions. The annual plan shall be implemented as a governance instrument, not as authority to bypass reserved matters or approve activities outside scope.

Material deviation from the annual plan shall be escalated to the Board or competent committee.

145.5 Implementation of Budget.

The executive leader shall administer the Board-approved budget within spending authority, financial controls, restricted-fund rules, grant conditions, sponsorship conditions, donor restrictions, accounting policies, and non-distribution obligations.

The executive leader shall not approve material budget amendments, restricted fund reallocations, major expenditures, major contracts, debt obligations, or extraordinary commitments except within approved authority.

145.6 Supervision of Staff, Contractors, Consultants, Fellows, Volunteers, and Operational Teams.

The executive leader may supervise staff, contractors, consultants, fellows, volunteers, seconded personnel, operational teams, and program teams within Board-approved authority and applicable law. Supervision shall include onboarding, role clarity, training, confidentiality, conflicts, performance, conduct, records, access controls, and offboarding.

Supervision shall not imply that personnel may bind GCRI Canada, speak publicly, access controlled materials, use AI systems, process data, communicate with public authorities, or approve publications beyond recorded authority.

145.7 Program Management.

The executive leader may manage approved programs, including research programs, evidence programs, methods programs, observability programs, ontology programs, public-good software programs, Academy programs, fellowship programs, public authority learning programs, controlled-room programs, and Nexus interface programs.

Program management shall require intake, case IDs where material, scope control, risk classification, data / AI / cyber review, safeguards review, public authority review, finance-boundary review, publication posture, milestone tracking, correction paths, and closeout records.

145.8 Partnership Management.

The executive leader may manage partnerships, MoUs, interface agreements, collaboration instruments, host relationships, university relationships, public authority interfaces, provider relationships, sponsor relationships, donor relationships, and Nexus interfaces within authority approved by the Board.

Partnership management shall preserve no-merger, no-agency, no-partnership, no-shared-liability, no-shared-treasury, non-execution, public authority boundary, finance-boundary, provider neutrality, sponsor non-control, data / AI / cyber, IP, confidentiality, safeguards, and correction clauses.

145.9 Fundraising and Development Management Within Board Policy.

The executive leader may manage fundraising and development activities within Board-approved policy, fundraising strategy, budget, and acceptance tests. This may include grant applications, donor engagement, sponsorship discussions, institutional subscriptions, in-kind support, public-good infrastructure support, and development communications.

Fundraising shall not imply securities offering, investment solicitation, finance-readiness outcome, public finance approval, procurement preference, certification, recognition, public authority access, outcome purchase, sponsor control, donor control, or provider preference.

145.10 Research Operations Management Subject to Research Integrity Controls.

The executive leader may support research operations, including staffing, budgets, timelines, collaboration agreements, ethics processes, peer review workflows, publication workflows, and research infrastructure. Research operations shall remain subject to research integrity, independence, ethics, evidence, methods, data, AI, cyber, privacy, safeguards, publication, and conflict controls.

The executive leader shall not direct research conclusions to satisfy sponsors, donors, providers, funders, public authorities, partners, market actors, or institutional convenience.

145.11 Evidence and Technical Operations Management Subject to Evidence and Methods Controls.

The executive leader may manage evidence and technical operations, including evidence packs, methods workstreams, observability methods, ontology work, public-good software workflows, repository administration, technical baselines, dashboards, data tools, model records, and secure release processes.

Evidence and technical operations shall remain subject to evidence quality, source lineage, confidence, uncertainty, methods review, public-safe classification, secure development, technical asset governance, and correctionability.

145.12 Data, AI, Cyber, Privacy, Public Authority, Publication, Sponsorship, Safeguards, and Controlled-Room Compliance Duties.

The executive leader shall ensure operational compliance with data governance, AI governance, cybersecurity, privacy, sovereign data, public authority protocols, public-safe publication, sponsorship acceptance, provider neutrality, safeguards, protected knowledge, controlled-room rules, clean-room rules, records discipline, and incident response requirements.

The executive leader shall ensure that staff and participants understand that operational urgency does not excuse unauthorized data processing, AI use, publication, public authority reference, sponsor benefit, provider claim, or controlled-room disclosure.

145.13 Authority to Execute Contracts Within Delegation.

The executive leader may execute contracts only within recorded delegation, Board-approved signing authority, budget authority, contract policy, conflict controls, legal review requirements, public authority boundary review, data / AI / cyber review, IP review, export-control review, sanctions review, finance-boundary review, and safeguards review where applicable.

Contracts outside delegation, contracts involving reserved matters, major contracts, restricted funds, public authority commitments, data-sharing, AI processing, controlled technology, public-good technical assets, Nexus interface obligations, or high-risk activities shall be escalated.

145.14 Authority to Approve Expenditures Within Delegation.

The executive leader may approve expenditures within the approved budget and spending authority matrix. Expenditures shall comply with financial controls, dual approval thresholds, restricted-fund rules, grant conditions, sponsorship terms, procurement policy, conflict rules, payment controls, and accounting requirements.

The executive leader shall not self-approve personal compensation, reimbursement, related-party payments, conflict-tainted payments, major expenditures, or payments outside authority.

145.15 Duty to Escalate Reserved Matters.

The executive leader shall identify and escalate reserved matters to the Board. Reserved matters include amendments to the Articles or this Bylaw, mission-lock changes, non-execution changes, major policies, major contracts, major budgets, restricted funds, major partnerships, public authority protocols, Nexus interface agreements, dissolution, major asset transfers, major technical asset licensing, material data / AI / cyber decisions, high-risk publications, and any other matter reserved by law, Articles, this Bylaw, or Board resolution.

Failure to escalate a reserved matter may constitute an invalid act, governance incident, or breach of duty.

145.16 Duty to Escalate Boundary, Perimeter, Integrity, Public Authority, Finance, AI, Data, Cyber, or Safeguards Risks.

The executive leader shall promptly escalate material risks involving non-execution, regulated perimeter, public authority confusion, finance-readiness overclaim, investment or insurance boundary, procurement overclaim, certification overclaim, recognition overclaim, provider preference, sponsor control, research integrity, evidence integrity, data breach, privacy incident, AI incident, cyber incident, protected knowledge exposure, community harm, public-safe publication error, or retaliation.

Escalation may require hold, stop, quarantine, access restriction, publication freeze, legal review, committee review, Board review, public-safe correction, or controlled notice.

145.17 No Authority to Amend Bylaw, Articles, Mission Lock, Public-Good Role, or Non-Execution Boundary.

The executive leader shall have no authority to amend the Articles, this Bylaw, mission lock, public-benefit purpose, public-good role, non-execution boundary, GCRI / GRF / GRA role separation, public authority boundary, finance-boundary protections, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, validity-by-record, correctionability, or dissolution provisions except through lawful Board and member processes where required.

Operational drift, repeated practice, funding agreement, public statement, technology integration, or program operation shall not amend constitutional meaning.

145.18 No Authority to Bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Consortiums, National Consortium Companies, Project SPVs, Providers, Sponsors, Hosts, Public Authorities, or Partners.

The executive leader shall not bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, communities, partners, or any other legally separate person unless expressly authorized by a lawful instrument from that person.

Coordination, shared mission, shared records, shared methods, common branding, public event participation, shared personnel, or Nexus alignment shall not create authority to bind another entity.

145.19 Executive Performance and Reporting Duties.

The executive leader shall report to the Board at intervals determined by the Board. Reports shall address operations, finances, programs, personnel, research, evidence, technical assets, data / AI / cyber controls, public authority interfaces, publications, sponsorships, partnerships, risks, incidents, corrections, compliance matters, and Nexus interfaces.

Reports shall be accurate, evidence-based, limitation-aware, and records-supported. The executive leader shall not conceal material risks, conflicts, incidents, overclaims, or failures.

145.20 Executive Records.

GCRI Canada shall maintain executive records, including appointment records, role description, delegation records, performance reports, Board reports, operational plans, budget implementation records, contract records, expenditure records, personnel records, program records, partnership records, fundraising records, escalation records, incident records, correction records, and executive closeout records.

Executive records shall support Board oversight, fiduciary accountability, legal compliance, auditability, continuity, and correctionability.


Section 146. Secretary

146.1 Secretary Role.

The Secretary shall serve as the principal officer responsible for corporate records, Board and member notices where applicable, minute books, governance instruments, repository discipline, version control, authenticity, adoption records, registers, Gazette or notice-stream coordination, and governance-record integrity.

The Secretary’s role is central to the validity-by-record doctrine. The Secretary shall support the principle that no material governance act obtains institutional authority unless properly recorded, classified, stored, and retrievable.

146.2 Corporate Records Custodian.

The Secretary shall act as custodian of corporate governance records unless another custodian is designated by the Board. Corporate records include Articles, this Bylaw, amendments, Board resolutions, member resolutions where applicable, officer appointments, committee charters, council charters, policies, registers, filings, notices, certifications, and official records of governance-significant acts.

The Secretary may delegate administrative records tasks but shall remain responsible for ensuring that custody is clear, secure, versioned, and auditable.

146.3 Minute Book Custody.

The Secretary shall maintain the minute book of GCRI Canada, including Board minutes, member minutes where applicable, written resolutions, committee records where required, consent records, attendance records, quorum records, voting records, conflict records, recusal records, and action records.

The minute book may be maintained electronically where lawful, provided that authenticity, integrity, access control, retention, backup, and tamper-evidence are preserved.

146.4 Board and Member Notice Administration.

The Secretary shall administer notices for Board meetings and member meetings where applicable. Notice administration shall include preparation, circulation, proof of delivery, waiver records, emergency notice records, agenda attachments, materials circulation, and compliance with applicable law, the Articles, this Bylaw, and Board procedure.

Notice defects shall be escalated for correction, waiver, ratification, adjournment, or re-notice as appropriate.

146.5 Board and Member Meeting Records.

The Secretary shall maintain meeting records for Board and member proceedings, including agendas, materials, minutes, resolutions, attendance, quorum, voting, abstentions, recusals, conflicts, dissent notes where permitted, action items, and follow-up requirements.

Meeting records shall distinguish discussion from decision and shall identify where a decision is subject to conditions, member approval, legal review, filing, notice, or implementation requirements.

146.6 Resolutions Custody.

The Secretary shall maintain custody of Board resolutions, member resolutions where applicable, written resolutions, officer delegations, committee recommendations, ratifications, corrections, supersessions, withdrawals, appointments, removals, and reserved matter decisions.

Resolutions shall be indexed, dated, versioned where appropriate, and linked to relevant decision packs, authority records, registers, and notices.

146.7 Articles, Bylaw, Policies, Charters, Terms of Reference, and Governance Instrument Custody.

The Secretary shall maintain the authoritative versions of the Articles, this Bylaw, schedules, policies, committee charters, council charters, terms of reference, protocols, forms, templates, delegation matrices, reserved matters schedules, and other governance instruments.

The Secretary shall ensure that outdated, draft, superseded, withdrawn, translated, summarized, or unofficial versions are clearly marked and do not create operative authority.

146.8 Director, Officer, Member, Committee, Council, Delegate, and Authority Registers.

The Secretary shall maintain or coordinate registers for directors, officers, members where applicable, non-voting members, supporters, subscribers, participants, delegates, committee members, council members, fellows, advisors, contributors, maintainers, contractors, volunteers, public authority participants, delegations, authority surfaces, and other governance roles.

Registers shall identify status, appointment, term, rights, authority, limitations, conflicts, training, good standing, suspension, termination, and access controls where applicable.

146.9 Adoption Record Custody.

The Secretary shall maintain adoption records for this Bylaw, amendments, policies, schedules, charters, delegations, technical baselines, publication policies, public authority protocols, data / AI / cyber policies, safeguards policies, and other governance-significant instruments.

Adoption records shall include text considered, resolution, approval threshold, effective date, version identifier, member approval where required, repository deposit, notice record, supersession record, and certification where appropriate.

146.10 Gazette or Notice Stream Coordination.

The Secretary shall coordinate the Gazette or Gazette-equivalent notice stream for adoption, amendment, repeal, correction, supersession, withdrawal, retraction, appointment, delegation, suspension, termination, publication status change, public authority correction, and other governance-significant notices.

Notices shall be classified as public, public-safe, controlled, or internal according to policy and shall include sufficient metadata to support traceability without disclosing protected material.

146.11 Repository Discipline Coordination.

The Secretary shall coordinate repository discipline for authoritative governance records. Repository discipline includes custody designation, access control, folder or register structure, version control, metadata, change logs, archive copies, publication status, official-location records, and migration procedures.

No unofficial copy, slide deck, AI-generated summary, public webpage, email attachment, or derivative communication shall override the authoritative repository record.

146.12 Versioning and Supersession Records.

The Secretary shall maintain versioning and supersession records for governance instruments, policies, schedules, charters, public materials, forms, templates, registers, controlled vocabularies, technical profiles, and other controlled documents.

Version records shall identify current status, prior versions, superseded versions, withdrawn versions, archived versions, effective dates, change classifications, adoption authorities, and correction paths.

146.13 Seal, Certification, and Authenticity Controls Where Applicable.

Where GCRI Canada uses a corporate seal, certification statement, electronic signature, hash, tamper-evident reference, or authenticity control, the Secretary shall maintain custody, usage rules, signature records, certification logs, and access controls.

No person shall certify a record, affix a seal, issue an official copy, or authenticate a governance instrument without authority.

The Secretary may coordinate corporate filings, annual returns, registered office updates, director and officer updates, member records where applicable, statutory notices, and other filings assigned by the Board or required by law.

The Secretary may coordinate with counsel, accountants, registered agents, officers, or service providers, but remains responsible for ensuring that filing records are captured in the corporate records system where assigned.

146.15 Record Access and Confidentiality Administration.

The Secretary shall administer access to governance records in accordance with law, the Articles, this Bylaw, privacy rules, confidentiality rules, privilege rules, public authority restrictions, data / AI / cyber controls, safeguards, and access classifications.

Access may be public, public-safe, internal, controlled, restricted, privileged, sealed, or subject to legal hold. The Secretary shall not disclose restricted records without authority.

146.16 Correction and Clarification Record Coordination.

The Secretary shall coordinate correction and clarification records for governance instruments, minutes, resolutions, registers, notices, public authority references, public claims, and other official records. Corrections shall preserve historical traceability and shall not silently overwrite the official record.

The Secretary shall ensure that corrected, superseded, withdrawn, or clarified records are linked to the original record and to any downstream notices.

146.17 Secretary Conflict and Independence Duties.

The Secretary shall disclose conflicts and shall not control records, access, minutes, certifications, notices, or correction processes for matters in which the Secretary has an unmanaged conflict. Where required, the Board shall designate another officer, director, counsel, or records custodian to handle the matter.

The Secretary shall maintain independence in recordkeeping and shall not alter records to serve management preference, sponsor pressure, provider pressure, public authority pressure, donor pressure, or reputational convenience.

146.18 Secretary Records.

GCRI Canada shall maintain Secretary records, including appointment records, role description, delegation records, certifications, filings, repository logs, version logs, notice logs, register maintenance records, access records, correction records, conflict disclosures, recusal records, and transition records.

Secretary records shall support legal compliance, authenticity, validity-by-record, correctionability, and institutional continuity.


Section 147. Treasurer

147.1 Treasurer Role.

The Treasurer shall support the Board’s financial stewardship of GCRI Canada and shall assist in maintaining nonprofit treasury discipline, budget integrity, accounting controls, financial reporting, restricted-fund accountability, grant and sponsorship tracking, bank account oversight, tax compliance support, and financial risk escalation.

The Treasurer shall act in service of the Corporation’s public-benefit purpose, non-distribution rule, no-private-inurement rule, sponsor non-control, donor non-control, provider neutrality, anti-capture discipline, and records integrity.

147.2 Financial Stewardship Support.

The Treasurer shall support prudent stewardship of corporate resources and shall assist the Board in ensuring that funds are used for lawful public-benefit purposes. Financial stewardship shall include oversight support for operating funds, restricted funds, grants, donations, sponsorships, institutional subscriptions, fees, in-kind contributions, reserves, program budgets, and public-good technical asset funding.

The Treasurer shall help ensure that financial resources do not become a pathway for control, private benefit, provider preference, research influence, publication influence, recognition influence, finance-readiness influence, certification influence, or public authority access purchase.

147.3 Budget Preparation Support.

The Treasurer shall support preparation of the annual budget and any material budget amendments. Budget preparation shall align with Board-approved strategy, public-benefit purpose, research priorities, evidence and methods needs, public-good software needs, data / AI / cyber controls, safeguards, legal compliance, insurance, continuity, and Nexus interface obligations.

The Treasurer shall ensure that restricted funds, grant conditions, sponsorship conditions, donor restrictions, in-kind dependencies, and major commitments are clearly identified.

147.4 Financial Reporting Support.

The Treasurer shall support preparation and presentation of financial reports to the Board, Finance, Audit, and Risk Committee, management, auditors or reviewers, funders, grantors, donors, sponsors, and public-safe audiences where authorized.

Financial reporting shall be accurate, timely, understandable, limitation-aware, and consistent with accounting standards, Board policy, restricted-fund rules, confidentiality, and public-safe transparency.

147.5 Accounting Records Oversight.

The Treasurer shall support oversight of books of account, chart of accounts, transaction records, receipts, invoices, expense records, reimbursement records, revenue records, restricted-fund records, in-kind valuation records, bank records, reconciliations, payroll records where applicable, tax records, and financial close processes.

Accounting records shall be maintained in approved systems and shall support auditability, tax compliance, donor reporting, grant reporting, financial controls, and institutional continuity.

147.6 Bank Account Oversight.

The Treasurer shall support oversight of bank accounts, investment accounts where lawful and appropriate, payment platforms, credit cards, electronic payment systems, restricted accounts, reserve accounts, and account access controls.

Bank account opening, closing, signer changes, electronic payment permissions, wire permissions, foreign exchange arrangements, and emergency payment authority shall require recorded authority under the financial controls policy.

147.7 Restricted Funds Oversight.

The Treasurer shall support oversight of restricted funds, including donor restrictions, grant restrictions, sponsorship restrictions, program restrictions, legal restrictions, Board-designated funds, and restricted in-kind support. Restricted funds shall be tracked separately where appropriate and used only for authorized purposes.

The Treasurer shall escalate any proposed use inconsistent with restriction, public-benefit purpose, non-execution, data / AI / cyber controls, safeguards, finance-boundary discipline, or anti-capture rules.

147.8 Grants, Donations, Sponsorships, In-Kind Contributions, Subscriptions, Fees, and Cost-Recovery Revenue Tracking.

The Treasurer shall support tracking of grants, donations, sponsorships, in-kind contributions, institutional subscriptions, individual subscriptions, training fees, Academy fees, fellowship fees, cost-recovery fees, controlled-room fees where lawful, technical access fees where lawful, and other revenue.

Each revenue stream shall be classified for accounting, tax, restriction, conflict, anti-capture, public acknowledgment, non-charitable payment treatment, and records purposes.

147.9 Treasury Controls.

The Treasurer shall support treasury controls, including segregation of duties, dual approvals, expenditure thresholds, payment controls, reimbursement controls, expense policies, bank reconciliations, fraud controls, restricted-fund controls, reserves, investment controls where applicable, and financial access controls.

Treasury controls shall prevent self-approval, unauthorized payments, related-party abuse, hidden private benefit, funder control, sponsor control, provider preference, and improper use of public-good resources.

147.10 Signing Authority Coordination.

The Treasurer shall support coordination of signing authority for bank accounts, contracts, payments, grants, sponsorships, donations, restricted funds, in-kind contributions, tax filings, and financial certifications. The Treasurer shall maintain or coordinate signing authority records with the Secretary.

Signing authority shall be role-based, amount-limited, subject-matter-limited, revocable, and consistent with the Board-approved authority matrix.

147.11 Expenditure Control.

The Treasurer shall support expenditure controls to ensure that expenditures are authorized, budgeted, documented, properly coded, purpose-aligned, conflict-reviewed where required, supported by receipts or invoices, and approved under applicable authority.

The Treasurer shall escalate unusual, high-risk, related-party, restricted-fund, foreign, emergency, sponsor-sensitive, provider-sensitive, public authority-sensitive, or finance-sensitive expenditures.

147.12 Audit or Review Engagement Support.

The Treasurer shall support audits, review engagements, compilations, financial reviews, internal reviews, funder reviews, grant reviews, and Board financial reviews where required or approved. Support may include preparation of records, management representations, responses to inquiries, corrective actions, and implementation of recommendations.

The Treasurer shall ensure that audit or review processes preserve confidentiality, privilege where applicable, data protection, and public-safe disclosure limits.

147.13 Tax and Nonprofit Compliance Support.

The Treasurer shall support tax and nonprofit compliance, including filings, GST/HST or sales tax treatment where applicable, payroll tax where applicable, donation receipt controls where applicable, non-charitable payment treatment unless charitable status is lawfully obtained, cross-border tax considerations, restricted-fund tax treatment, and private-benefit review.

The Treasurer shall escalate any financial arrangement that could jeopardize nonprofit status, tax compliance, public-benefit purpose, non-distribution, or no-private-inurement requirements.

147.14 Fraud Control and Financial Incident Escalation.

The Treasurer shall support fraud prevention, fraud detection, financial incident response, anti-corruption controls, bribery prevention, kickback prevention, gifts and hospitality controls, expense controls, payment fraud controls, and financial misconduct escalation.

Financial incidents shall be recorded, triaged, investigated, contained, corrected, and reported to the Board or appropriate committee as required.

147.15 Private Benefit and Inurement Review Support.

The Treasurer shall support review of private benefit, private inurement, related-party transactions, unreasonable compensation, excessive reimbursement, disguised commercial participation, sponsor capture, provider capture, donor control, and improper personal benefit.

The Treasurer shall escalate any transaction or arrangement that may create improper benefit to directors, officers, members, sponsors, donors, funders, providers, hosts, partners, founders, related parties, or private persons.

147.16 Financial Dashboard and Board Reporting.

The Treasurer may support financial dashboards and Board reporting tools, provided that such dashboards are classified, access-controlled, accurate, current, and limitation-aware. Financial dashboards shall not replace official financial statements, accounting records, Board approvals, audit reports, or official records.

Where dashboards are used, their data sources, refresh cadence, limitations, and correction paths shall be recorded.

147.17 Treasurer Conflict and Recusal Duties.

The Treasurer shall disclose conflicts and recuse from financial matters where required. Conflicts may include personal financial interests, related-party transactions, funder relationships, sponsor relationships, donor relationships, provider relationships, contract relationships, employment relationships, investment relationships, or other interests affecting judgment.

A conflicted Treasurer shall not approve, process, recommend, conceal, or control access to records for the conflicted matter except as expressly permitted under recorded controls.

147.18 Treasurer Records.

GCRI Canada shall maintain Treasurer records, including appointment records, role description, delegation records, bank account records, signing authority records, budget records, financial reports, restricted-fund records, revenue records, expenditure records, reconciliation records, audit or review records, tax records, private-benefit reviews, fraud incident records, conflict disclosures, recusal records, and transition records.

Treasurer records shall support fiscal stewardship, legal compliance, auditability, anti-capture, and institutional continuity.


Section 148. Chief Evidence Officer or Evidence Function

148.1 Evidence Function Purpose.

The evidence function shall preserve GCRI Canada’s upstream truth role by stewarding evidence doctrine, evidence quality, evidence classification, source lineage, provenance, confidence, uncertainty, limitation discipline, evidence challenge, evidence correction, assurance packs, and public-safe evidence outputs.

The evidence function shall ensure that evidence is treated as recorded, contextual, reviewable, challengeable, correctionable, and bounded by purpose. Evidence shall not be treated as recognition, finance-readiness, certification, procurement approval, public authority decision, public warning, emergency command, rating, or execution instruction.

148.2 Evidence Doctrine Stewardship.

The Chief Evidence Officer or evidence function shall steward evidence doctrine for GCRI Canada, including the rules that distinguish raw data from evidence, evidence from opinion, evidence from recognition, evidence from finance-readiness, evidence from certification, and evidence from public authority action.

Evidence doctrine shall address source lineage, method support, classification, confidence, uncertainty, provenance, custody, limitations, correction, public-safe publication, and downstream interface use.

148.3 Evidence Quality Oversight.

The evidence function shall oversee evidence quality, including completeness, accuracy, relevance, timeliness, reliability, reproducibility, calibration, source integrity, method integrity, data integrity, model integrity, and fitness for purpose.

Evidence quality oversight may include review, rejection, quarantine, downgrade, confidence adjustment, limitation statement, reclassification, correction, or supersession.

148.4 Evidence Classification Oversight.

The evidence function shall oversee classification of evidence according to publication class, access class, data sensitivity, security sensitivity, public authority sensitivity, finance sensitivity, infrastructure sensitivity, cyber sensitivity, community-protected status, Indigenous / local / territorial knowledge sensitivity, and public-safe release status.

Classification shall occur before use, sharing, publication, dashboard display, Nexus interface routing, GRF input, GRA input, Grid input, Docket input, or public authority-facing use.

148.5 Evidence Lineage and Provenance Oversight.

The evidence function shall ensure that evidence records include lineage, provenance, custody, timestamps, jurisdictional context, permission basis, consent or contribution basis where applicable, source reliability, source limitations, transformation steps, reviewer identity where appropriate, and correction path.

Evidence lacking adequate lineage or provenance shall not be used for material public claims, public-safe reports, finance-boundary inputs, public authority-facing materials, or Nexus interface outputs without appropriate limitation or quarantine.

148.6 Assurance and Evidence Pack Oversight.

The evidence function may oversee assurance packs and evidence packs, including pack scope, owner, custodian, authority surface, evidence inventory, method notes, lineage, confidence, uncertainty, limitations, public authority review, finance-boundary review, safeguards review, publication class, controlled annexes, expiry, review cycle, and correction path.

An assurance or evidence pack shall not be represented as certification, recognition, finance-readiness determination, procurement approval, public authority decision, rating, or guarantee.

148.7 Source Integrity Oversight.

The evidence function shall oversee source integrity, including source identity, authority, permission, timeliness, completeness, bias, context, reliability, custody, tamper indicators, spoof indicators, failed inputs, stale data, superseded data, conflicting sources, and missing data.

Where source integrity is disputed or degraded, the evidence function shall require limitation, confidence adjustment, challenge review, quarantine, or correction.

148.8 Confidence, Uncertainty, Dispute, and Limitation Discipline.

The evidence function shall maintain confidence and uncertainty discipline for material evidence outputs. Confidence shall be supported by rationale, source quality, corroboration, calibration, method suitability, and review status. Uncertainty shall be disclosed where material to interpretation, public-safe use, public authority understanding, finance-boundary use, or downstream routing.

Disputed evidence, contradictory evidence, failed signals, spoof indicators, missing data, stale data, and superseded data shall be handled through recorded methods and correction pathways.

148.9 Evidence Challenge and Correction Oversight.

The evidence function shall oversee evidence challenge and correction pathways. Challenges may relate to source accuracy, method suitability, classification, confidence, public authority context, protected knowledge, sponsor influence, provider influence, data integrity, model output, or public claim use.

The evidence function may recommend correction, reclassification, confidence adjustment, supersession, withdrawal, archive, notice, or downstream dependency review.

148.10 Evidence Inputs to GRF, GRA, Nexus Standards, Nexus Observatory, Nexus Grid, Nexus Docket, and Other Nexus Interfaces Where Authorized.

The evidence function may prepare or support evidence inputs to The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Observatory, Nexus Grid, Nexus Docket, Nexus Rails, Nexus Network, Nexus Universe, and other authorized Nexus interfaces.

Such inputs shall remain within GCRI Canada’s evidence role and shall not constitute GRF recognition, GRA finance-readiness, standards certification, Grid maturity determination, Docket approval, public authority decision, procurement approval, provider selection, public warning, or enterprise execution.

148.11 Evidence Public-Safe Review Support.

The evidence function shall support public-safe review of evidence outputs, including reports, dashboards, maps, datasets, software documentation, whitepapers, technical notes, public authority-facing materials, sponsor-facing materials, provider-facing materials, and media materials.

Public-safe review shall address source limitations, confidence, uncertainty, redaction, aggregation, de-identification, infrastructure sensitivity, cyber sensitivity, protected knowledge, public authority boundaries, finance boundaries, certification boundaries, and correction paths.

148.12 No Recognition, Standing, Finance-Readiness, Certification, Procurement, or Public Authority Decision Authority.

The evidence function shall not determine recognition, standing, maturity, public legitimacy, finance-readiness, insurance-readiness, investment suitability, bankability, routeability, certification, accreditation, compliance approval, procurement approval, public authority decision, public warning, emergency command, rating, provider preference, or execution status.

Any evidence output that could be misunderstood as such shall include limitation language, classification, review, and correction path.

148.13 Evidence Function Reporting.

The Chief Evidence Officer or evidence function shall report to the executive leader, Board, or designated committee as determined by the Board. Reports may include evidence quality status, evidence pack status, methods issues, disputes, corrections, public-safe review issues, Nexus interface inputs, confidence trends, source integrity concerns, and boundary risks.

Material evidence integrity issues shall be escalated promptly.

148.14 Evidence Function Records.

GCRI Canada shall maintain evidence function records, including evidence doctrine records, evidence registers, source lineage records, provenance records, classification records, confidence records, uncertainty records, quality reviews, evidence packs, challenge records, correction records, public-safe review records, GRF and GRA input records, Nexus interface records, and evidence function reports.

Such records shall support technical truth, public trust, correctionability, interoperability, and institutional continuity.


Section 149. Chief Research Officer or Research Function

149.1 Research Function Purpose.

The research function shall steward GCRI Canada’s public-benefit R&D, research integrity, research ethics pathways, reproducibility, peer review, research agenda coordination, publication integrity, sponsor independence, provider independence, fellowship coordination, and research correction.

Research shall be conducted to advance evidence, methods, observability, ontology, technical truth, public-good software, open technical baselines, public authority learning, safeguards, and Nexus-compatible public-good infrastructure. Research shall not be used as a vehicle for private capture, public authority substitution, finance execution, certification, procurement, or market endorsement.

149.2 Research Agenda Coordination.

The Chief Research Officer or research function may coordinate the research agenda of GCRI Canada within Board-approved strategy, public-benefit purpose, available resources, research integrity controls, data / AI / cyber controls, safeguards, and Nexus role separation.

Research agenda coordination shall identify priorities, public-benefit rationale, methods needs, evidence needs, ethical considerations, sponsor or provider influence risks, publication posture, resource requirements, and correction pathways.

149.3 Public-Benefit R&D Oversight.

The research function shall oversee public-benefit R&D activities, including applied research, methods development, observability research, ontology research, public-good software prototyping, open baseline development, technical testing, evidence systems development, and institutional learning.

Public-benefit R&D shall be directed toward reusable, auditable, correctionable, interoperable, public-good outcomes and shall not be reduced to sponsor deliverables, provider validation, commercial consulting, marketing support, or transactional services.

149.4 Research Integrity Oversight.

The research function shall oversee research integrity, including honesty, accuracy, transparency, independence, conflict management, methodological rigor, reproducibility, limitation disclosure, peer review, data integrity, authorship integrity, publication integrity, and correction.

Research integrity shall apply to internal research, sponsored research, collaborative research, public authority-facing research, technical research, data science, AI-assisted research, field research, community research, and Nexus interface research.

149.5 Research Ethics Review Coordination Where Required.

The research function shall coordinate research ethics review where required by law, institutional policy, funder requirements, host requirements, university requirements, public authority requirements, or Board-approved policy. Ethics review may include human-subjects review, community review, Indigenous knowledge review, health-sensitive review, protected knowledge review, data protection review, and do-no-harm review.

No research requiring ethics review shall proceed without required approval, exemption, or recorded determination.

149.6 Human-Subjects, Community, Indigenous / Local / Territorial Knowledge, Health-Sensitive, and Protected Knowledge Review Coordination.

The research function shall coordinate review of research involving human participants, community participants, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, health-sensitive data, protected knowledge, vulnerable populations, remote communities, or public-safe mapping risks.

Such review shall address consent, non-consent, attribution, withdrawal, correction, privacy, safeguards, public-safe publication, data sovereignty, knowledge protection, and non-extraction.

149.7 Peer Review and Reproducibility Oversight.

The research function shall oversee peer review, technical review, replication, reproducibility, method notes, code review where applicable, dataset review, model review, benchmark review, and limitation statements.

Where full reproducibility cannot be achieved due to sensitive data, protected knowledge, security, public authority restrictions, or proprietary constraints, the research function shall require controlled transparency, method disclosure, limitation language, or independent review where appropriate.

149.8 Research Sponsorship Independence Oversight.

The research function shall oversee independence of sponsored, grant-funded, donor-supported, provider-supported, host-supported, or partner-supported research. Funding support shall not control findings, methods, conclusions, publication timing beyond approved review windows, evidence classification, public authority access, technical baselines, or Nexus interface outputs.

Sponsor or provider influence risks shall be disclosed, reviewed, mitigated, recorded, and corrected where necessary.

149.9 Research Conflict Management.

The research function shall identify and manage research conflicts, including financial, institutional, intellectual, sponsor, provider, funder, host, public authority, employment, consulting, authorship, data-access, model-access, and publication conflicts.

Conflict management may include disclosure, recusal, independent review, limitation language, alternative reviewer assignment, access restriction, publication disclosure, or rejection of conflicted work.

149.10 Research Publication Review.

The research function shall support review of research publications for evidence support, methods support, limitation disclosure, AI-use disclosure, sponsor disclosure, provider disclosure, conflict disclosure, public authority boundary language, finance-boundary language, certification-boundary language, data / AI / cyber review, safeguards review, and public-safe release.

Research publication shall not overstate certainty, imply endorsement, imply public authority adoption, imply finance-readiness, imply certification, imply procurement approval, or conceal material limitations.

149.11 Research Correction, Supersession, Withdrawal, and Retraction Oversight.

The research function shall oversee correction, supersession, withdrawal, retraction, clarification, archive, and downstream dependency review for research outputs. Triggers may include error, unsupported claim, outdated evidence, method flaw, data issue, model issue, sponsor influence, provider influence, conflict omission, public authority misdescription, protected knowledge issue, AI hallucination, or public-safe risk.

Research correction shall preserve historical traceability and shall not be treated as concealment.

149.12 Fellowship and Research Network Coordination.

The research function may coordinate research fellows, visiting fellows, technical fellows, students, supervisors, academic partners, laboratories, research networks, and collaborative research groups. Fellowship and research network activities shall be governed by written terms addressing scope, confidentiality, IP, data, AI use, cyber, publication, ethics, conflicts, safeguards, attribution, and closeout.

Participation in a research network shall not create certification, recognition, public authority approval, provider endorsement, finance-readiness determination, or authority to bind GCRI Canada.

149.13 No Sponsor Control of Research Findings.

No sponsor, donor, funder, provider, host, partner, public authority participant, national company, Project SPV, investor, insurer, lender, or external actor shall control research findings, methods, limitations, evidence interpretation, publication conclusions, correction decisions, or research integrity determinations.

Agreements may include lawful review periods for confidentiality, IP, data protection, public authority restrictions, or protected knowledge, but shall not grant veto, suppression, outcome purchase, or conclusion control.

149.14 No Public Authority or Finance Execution by Research Output.

Research outputs shall not constitute public authority decisions, public warnings, emergency commands, procurement approvals, funding approvals, public finance approvals, sovereign obligations, investment advice, insurance approvals, ratings, lending decisions, underwriting decisions, or finance-readiness determinations.

Where research may be used by public authorities, capital readers, insurers, lenders, GRF, GRA, or Nexus interfaces, the output shall include appropriate classification, limitation language, non-reliance language, and correction path.

149.15 Research Function Reporting.

The Chief Research Officer or research function shall report to the executive leader, Board, or designated committee as determined by the Board. Reports may address research agenda status, ethics reviews, publications, peer review, reproducibility, sponsor independence, conflicts, corrections, fellowships, partnerships, and research risks.

Material research integrity concerns shall be escalated promptly.

149.16 Research Function Records.

GCRI Canada shall maintain research function records, including research agenda records, research approvals, ethics records, human-subjects records, community review records, Indigenous / local / territorial knowledge records, health-sensitive records, peer review records, reproducibility records, sponsor disclosure records, provider disclosure records, conflict records, publication records, correction records, fellowship records, and research reports.

Such records shall support research integrity, public-benefit accountability, correctionability, and institutional continuity.


Section 150. Chief Technology Officer or Technical Function

150.1 Technical Function Purpose.

The technical function shall steward GCRI Canada’s public-good technical assets, including public-good software, open technical baselines, reference architectures, schemas, APIs, SDKs, dashboards, data tools, test harnesses, gold vectors, negative tests, repositories, release pipelines, secure development controls, dependency governance, technical asset registers, and secure release practices.

The technical function shall serve GCRI Canada’s public-benefit, non-executing, evidence-supporting, methods-supporting, observability-supporting, ontology-supporting, and Nexus-compatible role. It shall not become a provider, operator, systems integrator, procurement authority, certification body, protocol authority, public authority, finance-readiness authority, or enterprise execution actor by technical centrality.

150.2 Public-Good Software Stewardship.

The Chief Technology Officer or technical function shall steward public-good software developed, maintained, released, or governed by GCRI Canada. Stewardship shall include scope definition, repository governance, licensing, contributor terms, secure development, versioning, documentation, public-safe release, limitation language, vulnerability response, deprecation, and correction.

Public-good software shall be developed to support interoperability, evidence integrity, methods repeatability, observability, public-safe communication, technical literacy, and open baselines, not to create provider preference, procurement mandate, certification, finance-readiness determination, or public authority decision.

150.3 Open Technical Baselines Stewardship.

The technical function shall steward open technical baselines, including reference specifications, implementation patterns, interoperability profiles, test harnesses, schemas, data dictionaries, model cards, system cards, benchmark cards, observability profiles, AI governance profiles, cybersecurity profiles, and public-safe dashboard profiles.

Open technical baselines shall be versioned, reviewable, limitation-aware, correctionable, and protected against enclosure, sponsor control, provider capture, hidden encumbrance, or misleading certification claims.

150.4 Reference Architecture Stewardship.

The technical function shall steward reference architectures supporting evidence systems, observability systems, Nexus Observatory methods, Nexus Truth Engine methods, verifiable compute, verifiable intelligence, secure data rooms, controlled rooms, public-safe dashboards, AI governance, cyber resilience, and public-good infrastructure.

Reference architectures shall be treated as guidance, baseline, or interoperability support, not as mandatory procurement specifications, performance warranties, compliance approvals, or certification artifacts.

150.5 Repository Governance.

The technical function shall oversee repositories used for software, schemas, documentation, technical baselines, public-good assets, controlled technical materials, and technical records. Repository governance shall include ownership, maintainership, access controls, branch protection, code ownership, review rules, secret scanning, license scanning, vulnerability monitoring, issue tracking, release tagging, archive status, and offboarding.

No repository permission shall create governance authority, corporate authority, public representation authority, certification authority, procurement authority, or public authority meaning.

150.6 Secure Development Lifecycle Oversight.

The technical function shall oversee secure development lifecycle practices, including secure design review, threat modeling, code review, dependency review, static analysis where appropriate, dynamic testing where appropriate, secrets control, access control, vulnerability management, secure build pipelines, and secure release review.

Secure development shall apply proportionately to public repositories, controlled repositories, internal systems, dashboards, APIs, SDKs, schemas, data tools, AI tools, model evaluation harnesses, and observability tooling.

150.7 Release Pipeline Oversight.

The technical function shall oversee release pipelines for public-good software, schemas, technical baselines, dashboards, documentation, APIs, SDKs, and other technical artifacts. Release pipelines shall include approval gates, versioning, release notes, provenance, signing where appropriate, SBOM where appropriate, public-safe review, rollback procedures, deprecation procedures, and correction paths.

No release shall be made where it would expose personal information, protected knowledge, public authority sensitive data, cyber-sensitive data, infrastructure-sensitive data, controlled technology, export-controlled material, or unsafe claims without required review and approval.

150.8 SBOM, Dependency, License, and Vulnerability Management Oversight.

The technical function shall oversee software bills of materials where appropriate, dependency tracking, license compatibility, open-source compliance, vulnerability intake, vulnerability classification, remediation clocks, disclosure practices, and dependency risk management.

Dependency and vulnerability management shall account for public-good software sustainability, supply-chain security, repository security, contributor risk, AI provider risk, cloud provider risk, and critical supplier concentration.

150.9 API, SDK, Schema, Dashboard, Data Tool, and Test Harness Oversight.

The technical function shall oversee APIs, SDKs, schemas, dashboards, data tools, test harnesses, gold vectors, negative tests, benchmark tools, observability tools, and technical libraries. Such assets shall be registered, versioned, classified, documented, access-controlled where necessary, and subject to correction.

Dashboards, APIs, test harnesses, and data tools shall not be represented as public warnings, certification, procurement approval, finance-readiness determination, public authority decision, provider ranking, or performance guarantee.

150.10 Technical Contributor and Maintainer Coordination.

The technical function may coordinate developers, maintainers, technical contributors, open-source participants, repository administrators, reviewers, and external technical partners. Coordination shall require contributor terms, IP terms, licensing review, confidentiality rules, security rules, AI-use disclosure, data-rights review, conflict disclosure, sponsor or provider disclosure, and access controls.

Maintainer status shall not confer authority to alter institutional meaning, publish official claims, approve compatibility claims, certify systems, bind GCRI Canada, or speak publicly for the Corporation.

150.11 Technical Asset Register Coordination.

The technical function shall coordinate the technical asset register, including asset identifiers, owners, stewards, maintainers, repositories, versions, status, license, classification, security status, dependency status, data-rights status, export-control or controlled-technology flags, known limitations, correction paths, and retirement status.

No material public-good technical asset shall be externally released, transferred, retired, deprecated, restricted, or materially altered without appropriate record and authority.

150.12 Technical Interoperability Support.

The technical function may support interoperability across GCRI Canada, GCRI US, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, hosts, public authorities, universities, communities, and partners.

Interoperability support shall preserve legal separateness, semantic clarity, role separation, access controls, correctionability, and no-merger discipline. Shared technical semantics shall not create shared treasury, shared liability, agency, protocol authority, certification, public authority delegation, or finance-readiness authority.

150.13 Secure Release, Signing, Provenance, Rollback, and Deprecation Oversight.

The technical function shall oversee secure release practices, including release authorization, release candidate review, provenance records, artifact signing where appropriate, package signing where appropriate, reproducible build review where appropriate, vulnerability review, rollback planning, deprecation notices, migration notes, public-safe release notes, controlled release notes, and archive records.

Where a release is compromised, unsafe, unsupported, outdated, superseded, misleading, or overclaimed, the technical function shall support restriction, suspension, rollback, patch, correction, withdrawal, deprecation, retirement, or public-safe notice.

150.14 No Technical Permission as Institutional Authority.

Technical permission, including repository access, administrator access, maintainer rights, commit rights, deployment rights, dashboard access, API keys, cloud permissions, data tool access, model access, controlled-room system access, or signing-key access, shall not constitute institutional authority unless supported by a lawful governance record.

Technical access shall be least-privilege, purpose-limited, logged, revocable, and subordinate to the Board, officers, delegations, records policies, data / AI / cyber controls, public authority protocols, safeguards, and this Bylaw.

150.15 No Reference Implementation as Certification or Procurement Mandate.

No reference implementation, public-good software release, schema, API, SDK, dashboard, data tool, test harness, technical baseline, benchmark, profile, or interoperability mapping created or supported by GCRI Canada shall constitute certification, accreditation, compliance approval, procurement mandate, vendor qualification, public authority approval, finance-readiness determination, provider preference, or guarantee by default.

Any external use of such assets shall be subject to licensing terms, limitation language, public-safe claims rules, compatibility claim rules, and correctionability.

150.16 Technical Function Reporting.

The Chief Technology Officer or technical function shall report to the executive leader, Board, or designated committee as determined by the Board. Reports may include technical asset status, repository status, release status, security status, vulnerabilities, dependencies, licensing, contributor activity, public-good software sustainability, technical baseline updates, interoperability issues, correction actions, and technical risks.

Material security, release, IP, license, public-safe, data / AI / cyber, export-control, or technical claim risks shall be escalated promptly.

150.17 Technical Function Records.

GCRI Canada shall maintain technical function records, including technical asset registers, repository records, contributor records, IP records, license records, secure development records, code review records, SBOM records, dependency records, vulnerability records, release records, signing records, provenance records, rollback records, deprecation records, interoperability records, compatibility claim records, correction records, and technical function reports.

Technical function records shall support public-good stewardship, security, auditability, correctionability, anti-enclosure, provider neutrality, and institutional continuity.

Section 151. Chief Data / AI / Cyber Officer or Data / AI / Cyber Function

151.1 Data / AI / Cyber Function Purpose.

151.1.1 Where established by the Board, the Chief Data Officer, Chief AI Officer, Chief Cybersecurity Officer, combined Data / AI / Cyber Officer, office, committee-supported function, or equivalent function shall support the Corporation’s governance of data, privacy, cybersecurity, AI systems, model use, controlled environments, secure infrastructure, data processors, cloud tools, and technology-risk controls.

151.1.2 The function shall preserve the Corporation’s public-benefit, non-executing, rights-respecting, privacy-protective, security-conscious, correctionable, and role-bounded posture.

151.2 Data Governance Oversight.

151.2.1 The data / AI / cyber function shall support data governance, including classification, lawful basis, purpose limitation, minimization, access controls, retention, deletion, provenance, quality, metadata, lineage, sharing controls, publication review, and correction.

151.2.2 No dataset, data stream, derived dataset, metadata layer, dashboard, model input, inference output, or analytic product shall be treated as unrestricted merely because it is technically accessible, internally generated, aggregated, public-facing, or useful.

151.3 Privacy Governance Support.

151.3.1 The function shall support privacy governance by advising on personal information, rights-bearing data, sensitive information, re-identification risk, contextual integrity, lawful processing, consent where applicable, retention limits, access restrictions, and privacy-by-design controls.

151.3.2 Privacy shall be treated as an institutional safeguards obligation and not merely as an administrative compliance formality.

151.4 Rights-Bearing Data Controls.

151.4.1 Rights-bearing data shall include personal information, community-sensitive data, Indigenous or protected knowledge, health-sensitive data, public authority data, vulnerable participant data, geospatially sensitive data, critical infrastructure data, cyber-sensitive data, commercially confidential data, and any data whose misuse may affect rights, dignity, safety, sovereignty, livelihood, culture, environment, or public trust.

151.4.2 The function shall support controls for collection, receipt, storage, transformation, AI processing, publication, transfer, deletion, and correction of rights-bearing data.

151.5 Sovereign Data Zone and Localization Controls.

151.5.1 Where work involves sovereign, national, regional, Indigenous, public authority, community, health, critical infrastructure, or other localization-sensitive data, the function shall support sovereign data zone and localization controls.

151.5.2 Such controls may include jurisdictional storage rules, access residency, cloud-region limitations, compute-to-data methods, encryption, local custodian arrangements, cross-border review, contractual restrictions, and publication limitations.

151.6 Cross-Border Data Transfer Review.

151.6.1 The function shall support review of cross-border transfers of data, including transfers to foreign affiliates, collaborators, cloud providers, AI providers, contractors, research partners, public authorities, sponsors, vendors, or repositories.

151.6.2 Review shall consider lawful basis, contractual protections, data class, receiving jurisdiction, onward transfer, processor obligations, government-access risk, privacy obligations, Indigenous and community safeguards, public authority constraints, and publication risk.

151.7 Compute-to-Data Controls.

151.7.1 Where data should not move freely, the function shall support compute-to-data controls that permit analysis, model evaluation, validation, or research while minimizing data exposure.

151.7.2 Compute-to-data environments shall include appropriate access controls, query limits, output review, logging, export restrictions, model-use restrictions, retention limits, and closeout requirements.

151.8 AI Governance Oversight.

151.8.1 The function shall support AI governance for all material AI use by or for the Corporation, including AI-assisted drafting, classification, retrieval, analytics, summarization, coding, inference, model evaluation, agentic workflows, decision support, and publication support.

151.8.2 AI systems shall not be used in a manner that creates unreviewed institutional decisions, unsupported claims, hidden data processing, public authority confusion, rights-bearing harm, research unreliability, false precision, or uncontrolled reliance.

151.9 Model Register Oversight.

151.9.1 The function shall support a model register for material AI models, foundation models, specialized models, classifiers, embedding models, retrieval systems, fine-tuned models, agentic tools, evaluation tools, and externally provided AI systems used by the Corporation.

151.9.2 The register shall record model name, provider, version, purpose, data inputs, approved use, prohibited use, access class, privacy posture, security posture, evaluation status, limitations, owner, retention implications, and review date.

151.10 Inference Record Oversight.

151.10.1 The function shall support inference record controls where AI outputs may influence publications, evidence products, research workflows, dashboards, public-safe summaries, controlled-room materials, classification decisions, or other material institutional outputs.

151.10.2 Inference records may include prompt class, input class, model used, date, reviewer, output use, confidence limits, human verification, correction, and publication status, subject to privacy, security, privilege, and proportionality limits.

151.11 Retrieval, Embedding, Fine-Tuning, Training, and Agentic AI Controls.

151.11.1 The function shall support controls for retrieval-augmented generation, embeddings, vector stores, fine-tuning, training, synthetic data, model evaluation, automated agents, tool-using systems, and workflow automation.

151.11.2 No rights-bearing, confidential, privileged, public authority, Indigenous, protected knowledge, sponsor-sensitive, cyber-sensitive, or controlled-room material shall be embedded, trained on, fine-tuned, externally processed, or made available to agentic tools except under recorded approval and controls.

151.12 Cybersecurity Baseline Oversight.

151.12.1 The function shall support cybersecurity baselines for systems, repositories, cloud environments, devices, accounts, data rooms, controlled rooms, dashboards, APIs, technical assets, collaboration tools, and public-facing infrastructure.

151.12.2 Cybersecurity baselines shall include, as appropriate, asset inventory, access control, multifactor authentication, encryption, patching, vulnerability management, endpoint security, network segmentation, backup, incident response, logging, monitoring, and staff training.

151.13 Identity, Access, Logging, Monitoring, Incident Response, and Business Continuity Oversight.

151.13.1 The function shall support identity and access management, privileged-access controls, role-based access, joiner-mover-leaver processes, logging, monitoring, incident response, disaster recovery, business continuity, and continuity of critical records.

151.13.2 Access shall be granted according to need, role, data class, environment class, duration, training, conflict posture, and supervision requirement, and shall be revoked when no longer justified.

151.14 Controlled-Room and Clean-Room Technology Controls.

151.14.1 The function shall support technology controls for controlled rooms, restricted rooms, clean rooms, secure data rooms, public authority rooms, finance-readiness rooms, research rooms, and protected participation environments.

151.14.2 Such controls may include device limits, recording prohibitions, export controls, screen controls, supervised access, logging, no-AI-use conditions, no-download rules, identity verification, watermarking, and closeout.

151.15 Vendor, Tool, Cloud, AI Provider, and Data Processor Security Review.

151.15.1 The function shall support security and data review of vendors, tools, cloud services, AI providers, software platforms, data processors, subprocessors, and managed-service providers.

151.15.2 Review shall consider security posture, data processing terms, retention, training-use restrictions, cross-border transfer, confidentiality, incident notice, audit rights, termination, portability, deletion, lock-in, and compatibility with public-good obligations.

151.16 No Unapproved AI Processing or Shadow IT.

151.16.1 No director, officer, employee, contractor, volunteer, fellow, advisor, contributor, committee participant, or partner may use unapproved AI tools, cloud tools, repositories, personal accounts, messaging systems, storage platforms, automation tools, or data-processing systems for Corporation work where such use may expose controlled, confidential, rights-bearing, privileged, public authority, or security-sensitive material.

151.16.2 Shadow IT shall be subject to containment, review, access withdrawal, correction, deletion, incident treatment, and discipline where appropriate.

151.17 Data / AI / Cyber Incident Escalation.

151.17.1 Data breaches, privacy incidents, cyber incidents, unauthorized AI processing, model misuse, public authority data exposure, controlled-room breaches, protected knowledge exposure, critical vulnerability, account compromise, ransomware, data loss, or unsafe publication shall be escalated promptly under the Corporation’s incident procedures.

151.17.2 Escalation shall include containment, preservation of evidence, legal review, privacy review, safeguards review, notification assessment, remediation, correction, and post-incident review.

151.18 Data / AI / Cyber Function Reporting.

151.18.1 The function shall report to the Executive Director, Board, committee, or designated oversight authority regarding data governance, privacy, AI use, cybersecurity, incidents, vendor risks, access controls, sovereign data constraints, and material technology-risk posture.

151.19 Data / AI / Cyber Function Records.

151.19.1 The function shall maintain or support records of data inventories, classifications, approvals, AI tools, model registers, inference records, access rights, incidents, vendors, processors, security reviews, remediation actions, transfers, retention decisions, and closeouts.

Section 152. Chief Safeguards, Ethics, or Protected Participation Function

152.1 Safeguards Function Purpose.

152.1.1 Where established by the Board, the Chief Safeguards Officer, ethics officer, protected participation officer, safeguards office, committee-supported function, or equivalent function shall support safeguards, ethics, protected participation, do-no-harm review, community protection, accessibility, grievance pathways, non-retaliation, and rights-sensitive institutional conduct.

152.1.2 The safeguards function shall preserve the Corporation’s public-benefit character by ensuring that research, evidence, technical systems, publications, data practices, public authority interfaces, and stakeholder engagement do not cause avoidable harm.

152.2 Ethics and Safeguards Oversight.

152.2.1 The safeguards function shall support ethical review, safeguards review, protected participation review, rights-sensitive participation review, and public-benefit proportionality review for activities involving affected persons, communities, vulnerable groups, public-facing risk information, protected knowledge, or high-impact technologies.

152.3 Community Safeguards.

152.3.1 The function shall support community safeguards where Corporation work involves local communities, remote communities, under-resourced communities, high-risk communities, disaster-affected communities, climate-exposed communities, health-affected communities, infrastructure-dependent communities, or communities whose data, images, knowledge, conditions, or risks may be represented.

152.3.2 Community engagement shall not be extractive, tokenistic, coercive, misleading, or used to create unsupported legitimacy.

152.4 Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Safeguards.

152.4.1 The function shall support safeguards for Indigenous, local, territorial, cultural, ecological, environmental, traditional, community-held, sacred, sensitive, or protected knowledge.

152.4.2 Such knowledge shall not be collected, digitized, mapped, published, modelled, transferred, commercialized, or used in AI systems without appropriate authority, consent where required, restrictions, context, attribution, protection, and withdrawal or correction pathways.

152.5 Vulnerable and High-Risk Participant Safeguards.

152.5.1 The function shall support safeguards for minors, students, fellows, whistleblowers, affected communities, displaced persons, disaster survivors, persons exposed to retaliation, persons in precarious employment, vulnerable researchers, public authority staff acting under constraint, and others whose participation may involve elevated risk.

152.6 Public-Safe Mapping Review Support.

152.6.1 The function shall support review of maps, dashboards, geospatial outputs, vulnerability visualizations, infrastructure depictions, community-risk displays, public-safe summaries, and situational products before publication or controlled release.

152.6.2 Public-safe mapping shall avoid exposing sensitive locations, protected knowledge, vulnerable populations, critical infrastructure weaknesses, security vulnerabilities, or misleading risk signals.

152.7 Accessibility and Inclusion Support.

152.7.1 The function shall support accessibility, inclusion, language access, disability accommodation, inclusive participation, safe participation, and meaningful access to Corporation programs, materials, meetings, controlled processes, and public-safe outputs.

152.8 Grievance and Remedy Pathway Coordination.

152.8.1 The safeguards function shall coordinate or support grievance, concern, complaint, remedy, correction, withdrawal, access restriction, participation protection, and escalation pathways.

152.8.2 Grievance pathways shall be understandable, accessible, non-retaliatory, timely, documented, and proportionate to the seriousness of the matter.

152.9 Protected Participation and Whistleblowing Support.

152.9.1 The function shall support protected participation and whistleblowing pathways for persons who report misconduct, safeguards concerns, data misuse, public overclaim, retaliation, conflicts, harassment, unsafe publication, community harm, or role-boundary violations.

152.10 Non-Retaliation Oversight.

152.10.1 The Corporation shall prohibit retaliation against any person who in good faith raises a concern, seeks safeguards review, refuses unsafe conduct, reports misconduct, participates in an investigation, or supports a protected person.

152.10.2 The safeguards function shall support monitoring, escalation, and remedy of retaliation concerns.

152.11 Do-No-Harm Review.

152.11.1 The function shall support do-no-harm review for activities that may affect communities, public trust, vulnerable persons, rights-bearing data, public-safe outputs, AI systems, public authority interfaces, critical infrastructure, environmental interests, or protected knowledge.

152.11.2 Do-no-harm review may require narrowing, delay, redesign, restricted release, anonymization, aggregation, safeguards conditions, or non-publication.

152.12 Safeguards Stop-the-Line Escalation.

152.12.1 The safeguards function may escalate a stop-the-line concern where an activity presents material risk of community harm, protected knowledge exposure, vulnerable participant harm, retaliation, unsafe publication, rights-bearing data misuse, public authority confusion, AI harm, or institutional overclaim.

152.12.2 Stop-the-line escalation shall trigger prompt review by the Executive Director, Chair, Board, committee, legal function, data / AI / cyber function, or other competent authority.

152.13 Safeguards Incident Review.

152.13.1 Safeguards incidents shall be reviewed for cause, harm, mitigation, remedy, correction, record impact, publication impact, access impact, discipline, and recurrence prevention.

152.14 No Safeguards Process as Public Authority Adjudication Unless Lawfully Authorized.

152.14.1 Safeguards processes of the Corporation shall not be represented as public authority adjudication, legal determination, regulatory finding, human rights tribunal process, emergency determination, public warning, or official remedy unless lawfully authorized by a competent public authority.

152.15 Safeguards Function Reporting.

152.15.1 The safeguards function shall report material safeguards risks, grievances, incidents, protected participation concerns, stop-the-line escalations, accessibility issues, community concerns, and corrective actions to the appropriate oversight authority.

152.16 Safeguards Function Records.

152.16.1 The safeguards function shall maintain records of safeguards reviews, grievances, protected reports, incidents, remedies, stop-the-line actions, accessibility accommodations, community safeguards, protected knowledge controls, and corrective actions, subject to confidentiality and privacy controls.

153.1 Legal and Compliance Function Purpose.

153.1.1 Where established or retained, the General Counsel, legal function, compliance function, external counsel, or equivalent advisory function shall support lawful operation, corporate compliance, regulatory perimeter discipline, contract integrity, public authority boundary control, claims discipline, legal risk management, privilege, legal holds, investigations, and dispute management.

153.1.2 The legal and compliance function shall advise and support; it shall not substitute for Board reserved matters, officer accountability, management responsibility, or lawful decision-making by competent corporate organs.

153.2 Corporate Compliance Support.

153.2.1 The function shall support compliance with applicable corporate law, bylaws, articles, filings, registers, board processes, officer authority, records obligations, governance instruments, and internal approval procedures.

153.3 Nonprofit and Tax Compliance Support.

153.3.1 The function shall support the Corporation’s nonprofit, non-share, non-distributing, public-benefit, and tax-related compliance posture, including private benefit, inurement, restricted funds, grants, donations, sponsorships, related-party matters, and mission-lock concerns.

153.4 Contract Review.

153.4.1 The function shall support review of material contracts, grants, memoranda, sponsorship agreements, data agreements, technology agreements, research agreements, host agreements, vendor agreements, publication agreements, contributor terms, and shared-service arrangements.

153.4.2 Contract review shall verify authority, purpose, legal risk, financial exposure, data obligations, IP terms, confidentiality, termination, liability, insurance, dispute terms, sanctions, export controls, public claims, and consistency with non-execution.

153.5 Regulatory Perimeter Review.

153.5.1 The function shall support review of activities that may approach regulated domains, including finance, insurance, securities, lending, underwriting, ratings, procurement, certification, public authority activity, data protection, AI, cyber, controlled technology, employment, research ethics, export controls, sanctions, competition, and professional services.

153.6 Public Authority Boundary Review.

153.6.1 The function shall support review of public authority participation, public authority references, public-sector data, public authority rooms, government-facing communications, regulatory engagement, and public authority capacity labels.

153.6.2 Public authority participation shall not be described as endorsement, procurement, official exercise, public warning, regulatory action, public finance approval, emergency authority, or government adoption unless expressly authorized and recorded.

153.7 Finance, Insurance, Securities, Lending, Underwriting, Rating, Public Finance, Procurement, and Certification Boundary Review.

153.7.1 The function shall support review to ensure that the Corporation does not provide investment advice, securities offering, solicitation, brokerage, underwriting, lending, insurance placement, rating, guarantee, public finance approval, procurement approval, certification, accreditation, conformity assessment with legal force, or regulated recommendation.

153.7.2 Finance-readable, insurance-readable, procurement-relevant, or certification-adjacent materials shall include bounded-reliance language and shall not overstate maturity, authority, or consequence.

153.8 Sanctions and Export-Control Review.

153.8.1 The function shall support sanctions, export-control, controlled-technology, restricted-party, end-use, end-user, cross-border transfer, and technology-access review where relevant to participants, data, software, AI models, technical systems, sponsors, vendors, public authorities, jurisdictions, or controlled rooms.

153.9 Competition and Antitrust Review.

153.9.1 The function shall support competition and antitrust review for convenings, member activity, sponsor participation, vendor coordination, benchmarking, information sharing, pricing discussions, procurement-adjacent work, standards-adjacent work, and market-facing communications.

153.9.2 The Corporation shall not facilitate collusion, market allocation, bid-rigging, exclusionary conduct, improper information exchange, or anti-competitive coordination.

153.10 Privacy, AI, Cyber, Research Ethics, Employment, IP, and Controlled Technology Legal Support.

153.10.1 The function shall support legal review relating to privacy, AI governance, cybersecurity, research ethics, employment, contractor classification, volunteer engagement, intellectual property, licensing, copyright, moral rights, trade secrets, confidential information, controlled technology, and repository governance.

153.11 Claims Discipline and Public-Safe Communications Legal Support.

153.11.1 The function shall support legal review of claims, publications, reports, dashboards, website materials, sponsor acknowledgments, public authority references, technical descriptions, media statements, social media, presentations, and public-safe releases.

153.11.2 Communications shall be truthful, bounded, status-accurate, limitation-aware, and consistent with recorded authority.

153.12 Dispute, Investigation, Enforcement, and Incident Support.

153.12.1 The function shall support disputes, investigations, enforcement, complaints, incidents, breaches, grievances, public correction, takedowns, employment matters, contract disputes, IP disputes, data incidents, cyber incidents, and safeguards incidents.

153.13 Privilege Management.

153.13.1 The function shall manage or support privilege, including legal advice privilege, litigation privilege, privileged investigations, privileged communications, document marking, circulation limits, waiver prevention, and privileged record handling.

153.14 Legal Hold Management.

153.14.1 The function shall support legal holds where litigation, investigation, regulatory inquiry, dispute, audit, incident, complaint, or reasonably anticipated proceeding requires preservation of records.

153.14.2 Legal holds shall override ordinary deletion or retention schedules to the extent required.

153.15 No Legal Function as Substitute for Board Reserved Matters.

153.15.1 Legal review shall not convert an unauthorized act into an authorized act, approve a reserved matter, waive Board approval, excuse conflict procedures, or substitute for fiduciary judgment.

153.15.2 Counsel may advise; the competent corporate authority must decide.

153.16 Legal and Compliance Function Reporting.

153.16.1 The function shall report material legal risk, compliance gaps, disputes, regulatory concerns, boundary risks, privileged matters requiring action, legal holds, and reserved matters to the Executive Director, Chair, Board, committee, or other competent authority.

153.17 Legal and Compliance Function Records.

153.17.1 The function shall maintain or support records of legal reviews, contracts, legal holds, disputes, investigations, regulatory reviews, compliance advice, boundary reviews, privileged records, claims reviews, and incident legal support, subject to privilege and confidentiality.

Section 154. Secretariat and Central Bureau

154.1 Secretariat Purpose.

154.1.1 The Secretariat shall support the orderly administration of governance, records, meetings, notices, registers, intake, workflow, committee support, participation administration, publication support, and institutional continuity.

154.1.2 The Secretariat shall be an administrative and coordination function, not a substitute for the Board, officers, committees, councils, legal function, technical function, data / AI / cyber function, safeguards function, or any other competent authority.

154.2 Central Bureau Purpose.

154.2.1 Where established, the Central Bureau shall provide coordinated administrative, records, workflow, routing, intake, registry-support, notice, repository, and shared-service support for the Corporation and, where lawfully authorized, for specified Nexus-related administrative interfaces.

154.2.2 The Central Bureau shall not become an unrecorded governance organ, recognition authority, finance-readiness authority, protocol authority, public authority, or enterprise execution office by virtue of administrative centrality.

154.3 Governance Administration.

154.3.1 The Secretariat shall support governance administration, including calendars, agendas, notices, minutes, resolutions, consent records, committee mandates, officer records, registers, policies, action logs, and governance closeout.

154.4 Board Support.

154.4.1 The Secretariat shall support Board meetings, Board materials, decision records, director notices, conflict records, attendance records, voting records, resolution execution, document circulation, and Board follow-up.

154.5 Committee Support.

154.5.1 The Secretariat shall support committees by maintaining mandates, membership records, agendas, minutes, decisions, recommendations, referrals, escalation records, and closeout records.

154.6 Council Support.

154.6.1 Where the Corporation hosts or supports councils, advisory bodies, working groups, panels, or Nexus-related coordination bodies, the Secretariat shall administer participation, papers, notices, records, terms of reference, and boundary language.

154.6.2 Council support shall not create governance authority unless expressly conferred by lawful instrument.

154.7 Meeting Administration.

154.7.1 The Secretariat shall administer meetings, including scheduling, notices, quorum support, attendance, materials, minutes, action items, recusal records, confidentiality markings, virtual participation controls, and meeting archives.

154.8 Forms-First Intake Administration.

154.8.1 The Secretariat shall support forms-first intake for requests, proposals, complaints, incidents, access requests, publication requests, public authority references, technical asset requests, controlled-room requests, and other institutional workflows.

154.8.2 No matter shall be treated as approved merely because it has been received, discussed, assigned, or informally advanced.

154.9 Case ID Administration.

154.9.1 The Secretariat shall support case ID administration for matters requiring traceability, including incidents, requests, proposals, reviews, approvals, publications, corrections, grievances, public authority records, data requests, technical assets, and legal reviews.

154.10 Register and Repository Administration.

154.10.1 The Secretariat shall support institutional registers and repositories, including governance records, policy repositories, technical asset registers, decision registers, publication records, conflict records, delegation records, participation records, and closeout records.

154.11 Gazette or Notice Stream Administration.

154.11.1 Where the Corporation maintains a gazette, notice stream, publication log, internal bulletin, controlled announcement channel, or repository notice mechanism, the Secretariat shall administer issuance, status, versioning, corrections, and archival records.

154.12 Publication Workflow Support.

154.12.1 The Secretariat shall support publication workflows, including intake, routing, review assignment, claims review, legal review, data review, safeguards review, approval status, release records, corrections, withdrawals, and supersession.

154.13 Controlled-Room Administration Support.

154.13.1 The Secretariat shall support controlled-room administration, including participant lists, capacity labels, access terms, confidentiality terms, room classification, attendance logs, document controls, recording restrictions, and closeout.

154.14 Public Authority Capacity Record Administration.

154.14.1 The Secretariat shall support public authority capacity records by documenting the role, capacity, attribution status, participation limits, public reference permissions, data constraints, and communications restrictions applicable to public authority participants.

154.15 Membership and Participation Administration.

154.15.1 The Secretariat shall support membership, participant, advisor, fellow, volunteer, contractor, sponsor, host, and partner administration, including applications, records, terms, access, notices, status changes, suspensions, resignations, terminations, and offboarding.

154.16 Program Administration.

154.16.1 The Secretariat shall support program administration, including program calendars, approved scopes, participant records, deliverables, budgets where assigned, reporting timelines, risk logs, review gates, closeout, and archival records.

154.17 Records and Closeout Administration.

154.17.1 The Secretariat shall support records and closeout by ensuring that matters are completed, archived, corrected, withdrawn, escalated, or carried forward under recorded status.

154.18 Secretariat Without Independent Governance Authority.

154.18.1 The Secretariat shall not approve reserved matters, alter records substantively without authority, bind the Corporation, waive review, issue recognition, approve publication, classify public authorities, authorize finance-readiness claims, or determine technical status except as expressly delegated.

154.19 Central Bureau Without Board Substitution.

154.19.1 The Central Bureau shall not substitute for the Board, committees, officers, legal function, technical function, data / AI / cyber function, safeguards function, or any Nexus entity’s competent governance organ.

154.20 Secretariat and Central Bureau Records.

154.20.1 The Secretariat and Central Bureau shall maintain records of administrative actions, meetings, notices, registers, workflows, case IDs, publication routing, controlled rooms, public authority records, memberships, program administration, and closeout actions.

Section 155. Nexus Council Bureau Hosting, Shared Services, Data Processor Status, and No-Governance-Organ Rule

155.1 Nexus Council Bureau Hosting.

155.1.1 The Corporation may host, administer, or support a Nexus Council Bureau or similar coordination bureau only under recorded authority, defined scope, approved terms, and role-separation controls.

155.1.2 Hosting shall mean administrative support unless the governing instrument expressly provides otherwise.

155.2 Shared-Service Character.

155.2.1 Any shared-service arrangement shall be treated as operational, administrative, technical, records, convening, or support infrastructure and shall not be interpreted as merger, agency, fiduciary control, parent-subsidiary relationship, alter ego status, or unified governance.

155.3 Administrative Support Only Unless Otherwise Authorized.

155.3.1 The Bureau may provide scheduling, records, notice, intake, routing, repository, communication, meeting, technical, data-processing, and coordination support within approved scope.

155.3.2 It shall not determine institutional policy, public meaning, recognition, finance-readiness, protocol effect, execution authority, or corporate obligations unless expressly authorized.

155.4 Data Processor or Service-Provider Status Where Applicable.

155.4.1 Where the Corporation processes data for another Nexus entity, council, consortium, host, program, or lawful partner, the Corporation shall document whether it acts as data controller, joint controller, processor, service provider, custodian, host, repository administrator, or other legally relevant role.

155.4.2 Data-processing terms shall identify purpose, instructions, data classes, subprocessors, security, retention, deletion, access, incident notice, cross-border transfer, and audit or assurance rights.

155.5 No Statutory Governance Organ by Hosting Alone.

155.5.1 Hosting a Bureau shall not make the Bureau a statutory organ of the Corporation or of any other Nexus entity unless a lawful constitutional instrument expressly creates that status.

155.6 No Authority to Bind GCRI Canada by Service Role Alone.

155.6.1 No person acting through a Bureau, shared-service desk, secretariat interface, technical support role, or administrative support role may bind GCRI Canada merely by providing services.

155.7 No Authority to Bind Nexus Entities by Service Role Alone.

155.7.1 No Bureau-hosting or shared-service role shall authorize the Corporation, its personnel, or any hosted function to bind GRF, GRA, GCRI US, Nexus Standards, Nexus Network, any regional or national consortium, any national company, any SPV, any host, or any other entity.

155.8 No Authority to Determine Recognition, Finance-Readiness, Protocol Entitlements, Public Authority Meaning, or Enterprise Execution.

155.8.1 The Bureau shall not determine recognition, registry standing, maturity status, finance-readiness, protocol entitlements, public authority meaning, procurement meaning, certification meaning, sponsor rights, vendor status, Docket movement, Grid maturity, or enterprise execution status.

155.9 Service-Level Terms.

155.9.1 Shared services shall be governed by service-level terms identifying scope, service standards, availability, escalation, responsibilities, limits, costs, confidentiality, data handling, security, exit, continuity, and dispute handling.

155.10 Data, Confidentiality, Cybersecurity, Privacy, Access, and Records Controls.

155.10.1 Bureau-hosted services shall comply with data, confidentiality, cybersecurity, privacy, access, records, retention, deletion, legal hold, and incident controls at a level proportionate to the sensitivity of the supported activity.

155.11 Conflict and Role-Separation Controls.

155.11.1 The Corporation shall maintain conflict and role-separation controls where Bureau-hosting places the Corporation near recognition, finance-readiness, protocol, public authority, sponsor, vendor, or execution-adjacent functions.

155.12 Shared-Service Cost Allocation Where Applicable.

155.12.1 Shared-service costs may be allocated among participating entities or functions only under recorded, fair, transparent, mission-consistent, and legally supportable terms.

155.12.2 Cost allocation shall not create hidden control, improper subsidy, private benefit, or undocumented related-party advantage.

155.13 Exit, Transition, and Continuity Controls.

155.13.1 Bureau-hosting and shared services shall include exit, transition, portability, continuity, records transfer, access termination, data return, data deletion, credential revocation, and successor-support controls.

155.14 Nexus Council Bureau Hosting Records.

155.14.1 The Corporation shall maintain records of Bureau-hosting authority, service terms, data roles, access rights, service levels, costs, conflicts, incidents, exits, and role-separation controls.

Section 156. Staff, Contractors, Consultants, Volunteers, Fellows, Advisors, and Seconded Personnel

156.1 Personnel Categories.

156.1.1 The Corporation may engage employees, contractors, consultants, volunteers, fellows, advisors, seconded personnel, interns, researchers, contributors, and other personnel categories as lawful and appropriate to its mandate.

156.1.2 Each person shall be classified according to legal status, role, authority, compensation, supervision, access, IP obligations, confidentiality, data rights, conflict obligations, and termination conditions.

156.2 Employees.

156.2.1 Employees shall serve under written employment terms, applicable law, approved policies, supervision, compensation controls, confidentiality obligations, IP provisions, conflict rules, data and security obligations, and performance management.

156.3 Contractors.

156.3.1 Contractors shall serve under written contract and shall not be treated as employees, officers, agents, or representatives except to the extent expressly provided by law and contract.

156.4 Consultants.

156.4.1 Consultants may provide expert, strategic, technical, legal, research, data, communications, safeguards, governance, or operational advice within written scope and shall not bind the Corporation unless expressly authorized.

156.5 Volunteers.

156.5.1 Volunteers may support the Corporation only under written or recorded terms appropriate to role, access, supervision, confidentiality, safety, data, IP, conflict, and conduct requirements.

156.6 Fellows.

156.6.1 Fellows may participate in research, technical, policy, educational, observability, evidence, safeguards, or public-good work under fellowship terms that define status, stipend if any, supervision, deliverables, authorship, IP, access, and public claims.

156.7 Advisors.

156.7.1 Advisors may provide non-binding advice unless appointed to a formal office or committee with recorded authority.

156.7.2 Advisor title shall not create governance authority, fiduciary authority, employment, representation authority, or right to bind the Corporation.

156.8 Seconded Personnel.

156.8.1 Seconded personnel may serve under written secondment terms identifying home institution, supervision, confidentiality, IP, conflicts, data access, authority limits, costs, insurance, conduct, termination, and role separation.

156.8.2 Secondment shall not create sponsor control, public authority control, donor control, vendor control, or institutional capture.

156.9 Written Engagement Terms.

156.9.1 Every personnel engagement shall be governed by written or formally recorded terms proportionate to role and risk.

156.9.2 Terms shall address role, duration, compensation, expenses, reporting line, deliverables, authority limits, confidentiality, IP, data, security, AI use, conflicts, public communications, termination, and access revocation.

156.10 Role Scope and Authority Limits.

156.10.1 Personnel may act only within assigned scope and delegated authority.

156.10.2 No person may bind the Corporation, approve expenditures, sign contracts, access controlled data, speak publicly, admit participants, approve publications, or make institutional claims unless authorized.

156.11 Confidentiality Obligations.

156.11.1 Personnel shall protect confidential, privileged, personal, rights-bearing, technical, security-sensitive, sponsor-sensitive, public authority, research, community, and protected knowledge information.

156.12 IP and Work Product Obligations.

156.12.1 Personnel shall comply with IP, authorship, moral rights, assignment, license, open-source, repository, publication, and work-product terms applicable to their engagement.

156.12.2 Work product created for the Corporation shall be governed by written terms sufficient to preserve public-good stewardship and lawful reuse.

156.13 Data, AI, Cyber, Privacy, Controlled-Room, and Security Obligations.

156.13.1 Personnel shall comply with data, AI, cyber, privacy, controlled-room, clean-room, repository, device, account, credential, and security obligations.

156.13.2 Unauthorized processing, copying, AI input, external storage, personal-account use, public disclosure, or retention of controlled materials is prohibited.

156.14 Conflict Disclosure.

156.14.1 Personnel shall disclose financial, institutional, research, sponsor, vendor, public authority, employment, contractual, family, investment, IP, data, procurement, certification, finance, or reputational conflicts relevant to their role.

156.15 Public Claims and Communications Limits.

156.15.1 Personnel shall not speak for the Corporation, use its name, describe status, refer to public authorities, cite sponsors, claim endorsement, announce results, publish controlled materials, or imply authority except within approved communications authority.

156.16 No Apparent Authority by Access, Title, Expertise, Authorship, or Proximity.

156.16.1 Access, title, expertise, authorship, repository contribution, meeting attendance, committee participation, public visibility, email domain, badge, affiliation, or proximity to leadership shall not create apparent authority to bind the Corporation.

156.17 Onboarding, Training, Supervision, Performance, Offboarding, and Access Revocation.

156.17.1 Personnel shall receive onboarding, training, supervision, performance review where applicable, policy access, role clarification, conflict review, security orientation, and offboarding.

156.17.2 Offboarding shall include return of property, access revocation, credential termination, data return or deletion, confidentiality reminders, work-product transfer, and records closeout.

156.18 Personnel Records.