ARTICLE VIII. RECORDS
Section 195. Forms-First Governance System
195.1 Forms-First Principle. GCRI Canada shall operate a forms-first governance system under which every material governance, evidence, research, data, AI, cyber, privacy, publication, sponsorship, public authority, Nexus interface, technical asset, safeguards, conflict, integrity, or correction act is initiated, classified, reviewed, approved, recorded, and closed through a structured intake instrument or approved equivalent record. The forms-first principle is a constitutional control for validity-by-record, correctionability, auditability, public-safe publication, public authority discipline, finance-boundary discipline, non-execution, anti-capture, and Nexus role separation.
195.2 Governance by Structured Intake. Governance acts shall proceed through structured intake before action unless an emergency fast-lane procedure applies. Governance intake shall identify the proposed act, authority basis, decision-maker, affected instruments, reserved-matter status, required approvals, conflicts, legal review needs, member approval requirements where applicable, public-benefit rationale, mission-lock implications, non-execution implications, Nexus role-separation implications, and record owner.
195.3 Evidence by Structured Intake. Evidence acts shall proceed through structured intake identifying the evidence source, lineage, provenance, custody, timestamp, permission basis, classification, reliability, confidence, uncertainty, limitations, public-safe status, correction path, and intended use. No raw data, telemetry, sensor signal, AI-RAN signal, DePIN record, cyber log, dashboard output, digital twin output, public authority contribution, provider system output, or community input shall become GCRI Canada evidence merely by receipt, circulation, presentation, or technical integration.
195.4 Research by Structured Intake. Research activities shall be initiated through structured intake identifying research purpose, public-benefit rationale, research question, methods, sponsors or funders, conflicts, data requirements, human-subjects implications, community or Indigenous knowledge implications, protected knowledge implications, publication posture, ethics review needs, peer review expectations, and correction path. Research intake shall preserve research independence and shall prevent sponsor, provider, donor, funder, host, public authority, or enterprise actor control over research conclusions.
195.5 Data, AI, Cyber, Privacy, and Controlled-Room Intake. Any material data access, data processing, data transfer, AI use, model use, inference generation, embedding, retrieval, fine-tuning, training, cyber access, repository access, controlled-room access, clean-room access, data-room access, evidence-room access, public authority room access, or no-download-room activity shall require structured intake. Such intake shall identify lawful basis, purpose, data class, security class, access class, AI-use status, model identity where applicable, cyber controls, privacy review, cross-border transfer risk, sovereign data requirements, retention, deletion, and access-revocation conditions.
195.6 Publication and Public-Safe Claims Intake. Publications, public-safe summaries, technical notes, methods notes, reports, whitepapers, datasets, dashboards, maps, websites, decks, media materials, software release notes, public authority references, sponsor acknowledgments, provider references, Nexus-compatible claims, finance-reference language, certification-boundary language, and public claims shall proceed through publication and claims intake. Such intake shall identify evidence support, methods support, controlled vocabulary, limitation language, disclaimer requirements, public authority review, finance-boundary review, certification and procurement review, data / AI / cyber review, safeguards review, and correction path.
195.7 Sponsorship, Donation, Grant, Subscription, In-Kind, and Support Intake. All sponsorships, donations, grants, subscriptions, in-kind contributions, restricted funds, unrestricted support, underwriting, challenge funds, prizes, compute credits, cloud credits, software licenses, data contributions, facility access, public-good support, and cost-recovery arrangements shall proceed through support intake. Support intake shall identify legal compliance, tax treatment, restrictions, benefit schedules, valuation, conflicts, related-party status, sanctions and export-control review, data / AI / cyber implications, sponsor or donor influence risk, provider neutrality risk, and anti-capture controls.
195.8 Public Authority Participation and Reference Intake. Any public authority participation, public authority capacity classification, public authority data contribution, public authority quote, logo, name, title, agency reference, photograph, attendance reference, controlled-room participation, regulator-listening status, public finance reader status, emergency-management participation, public infrastructure operator participation, or public authority learning activity shall proceed through public authority intake. Such intake shall preserve no-delegation, non-endorsement, no-public-warning, no-emergency-command, no-procurement, no-regulatory-approval, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation rules.
195.9 Nexus Interface and Cross-Entity Coordination Intake. Any interface with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, protocol authority, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, providers, hosts, sponsors, public authorities, universities, laboratories, communities, or partners shall proceed through Nexus interface intake where material. Interface intake shall identify role boundaries, no-merger terms, no-agency terms, shared-record status, compatibility notes, divergence logs, correction path, and authority limits.
195.10 Technical Asset, Software, Baseline, Repository, and Release Intake. Technical assets, public-good software, open technical baselines, schemas, APIs, SDKs, dashboards, data dictionaries, model cards, system cards, benchmark cards, test harnesses, reference architectures, interoperability profiles, repositories, releases, secure builds, SBOMs, signing keys, packages, and technical documentation shall proceed through technical asset intake. Intake shall identify asset owner, steward, maintainer, license, classification, IP status, contributor terms, security review, dependency review, vulnerability status, public-safe status, export-control status, no-certification language, and correction or rollback path.
195.11 Safeguards, Community, Indigenous, Protected Knowledge, and Grievance Intake. Any matter involving community participation, Indigenous knowledge, Indigenous data, local knowledge, territorial knowledge, cultural knowledge, protected environmental knowledge, vulnerable communities, remote communities, public-safe mapping, accessibility, grievance, remedy, protected participation, whistleblowing, non-retaliation, or do-no-harm review shall proceed through safeguards intake. Safeguards intake shall be capable of triggering stop-the-line review, access restrictions, publication hold, re-scoping, community consultation, consent or non-consent review where applicable, correction, withdrawal, or controlled notice.
195.12 Conflict, Recusal, Related-Party, and Integrity Intake. Conflicts, recusals, related-party matters, gifts, hospitality, independence issues, sponsor influence concerns, provider influence concerns, donor or funder influence concerns, public authority role confusion, research integrity issues, data misuse, AI misuse, cyber misconduct, protected knowledge misuse, retaliation, harassment, public claims overreach, and other integrity matters shall proceed through structured integrity intake. Such intake shall identify covered persons, affected matters, required recusals, access restrictions, investigation path, interim measures, and correction requirements.
195.13 No Material Institutional Act Without Intake Unless Emergency Procedure Applies. No material institutional act shall be treated as valid, adopted, approved, published, released, delegated, recognized, relied upon, or externally meaningful unless it has passed through required intake or a recorded emergency procedure. Emergency action shall be captured, classified, reviewed, ratified where required, corrected where necessary, and entered into the applicable register.
195.14 Forms-First Intake Records. GCRI Canada shall maintain forms-first intake records, including forms, case IDs, submitters, dates, authority bases, classifications, reviews, approvals, refusals, holds, quarantines, corrections, supersessions, withdrawals, closeouts, and retention status. Intake records shall be maintained in a manner that supports auditability, validity-by-record, correctionability, public-safe publication, role separation, legal compliance, and institutional memory.
Section 196. No-Email-Governance Rule and Prohibition on Informal Decisioning
196.1 No-Email-Governance Rule. GCRI Canada shall not govern by email, chat, informal message, meeting memory, presentation, spreadsheet, task board, repository comment, oral instruction, side agreement, or unrecorded operational practice. Email and informal communication may support deliberation, drafting, coordination, scheduling, evidence gathering, comment handling, or transmission, but shall not by themselves constitute authoritative governance action unless captured into the approved record system.
196.2 Email as Communication, Not Authoritative Governance Record Unless Captured. Email shall be treated as a communication channel and not as an authoritative governance record unless the relevant content is captured, classified, assigned a case ID where required, entered into the appropriate register, approved by competent authority, and linked to the applicable decision, delegation, publication, evidence, methods, data, AI, cyber, public authority, finance-boundary, safeguards, or correction record.
196.3 Chat, Message, Call, Meeting Note, Presentation, Spreadsheet, Task Board, Ticket, Repository Comment, or Informal Note as Non-Authoritative Unless Captured. Chat messages, direct messages, calls, informal meeting notes, presentations, spreadsheets, task-board entries, tickets, repository comments, draft documents, AI-generated summaries, voice notes, whiteboards, slide decks, annotated screenshots, or informal notes shall not create authority, approval, adoption, delegation, public meaning, technical release, public authority reference, finance-readiness implication, certification implication, procurement implication, or Nexus-compatible claim unless captured into an official record.
196.4 No Informal Approval. No person shall rely on informal approval for any material act requiring governance review, legal review, publication approval, data access, AI-use approval, cyber access, public authority reference, finance-boundary review, technical release, sponsorship acceptance, provider participation, controlled-room admission, safeguards review, or Board approval. Statements such as “approved,” “fine,” “go ahead,” “looks good,” or equivalent informal language shall not constitute approval unless issued through an authorized decision record.
196.5 No Decision by Silence. Silence, non-response, failure to object, attendance, continued participation, repeated circulation, document access, file viewing, comment inactivity, or operational continuation shall not constitute approval, adoption, consent, waiver, ratification, public authority endorsement, sponsor acceptance, provider approval, finance-readiness determination, certification, procurement approval, or release authorization unless a non-objection procedure has been expressly authorized, properly noticed, time-bounded, and recorded.
196.6 No Decision by Repeated Practice Alone. Repeated practice, custom, convenience, historical habit, prior staff action, prior draft treatment, legacy process, verbal understanding, or informal precedent shall not amend this Bylaw, create authority, validate a defective act, establish membership rights, establish advisory rights, create public authority meaning, create finance-boundary meaning, or override records discipline. Repeated practice may be documented for correction, ratification, policy update, or transition review only.
196.7 No Decision by Operational Convenience. Operational convenience, urgency, workload, event timing, sponsor expectations, public authority availability, provider deployment timelines, publication deadlines, technical release cycles, media opportunities, grant deadlines, or Nexus Universe scheduling shall not bypass required intake, authority mapping, conflict review, data / AI / cyber review, public authority review, finance-boundary review, safeguards review, or Board reserved-matter approval.
196.8 No Decision by Sponsor, Provider, Donor, Host, Public Authority, or Partner Expectation. No expectation, request, pressure, funding condition, implementation desire, branding preference, timetable, public statement, access demand, publication request, technical preference, or relationship need of a sponsor, provider, donor, host, public authority, university, laboratory, partner, funder, investor, insurer, lender, national company, Project SPV, consortium, or other external actor shall be treated as GCRI Canada authorization.
196.9 No Decision by Technical Permission Alone. Technical permission, repository access, dashboard access, API keys, cloud access, model access, data-room access, controlled-room access, credentials, administrative privileges, merge permission, ticket assignment, branch permission, deployment capability, or system ownership shall not constitute governance authority, publication authority, evidence authority, method-adoption authority, data authorization, AI-use authorization, public authority reference authority, finance-boundary authority, certification authority, or procurement authority.
196.10 Emergency Fast-Lane Exception Subject to Capture and Ratification. Emergency fast-lane action may be taken only where necessary to address a legal deadline, data breach, cyber incident, AI incident, public authority confusion, public-safe publication error, protected knowledge risk, community harm risk, sponsor or provider capture risk, finance overclaim, certification overclaim, procurement overclaim, public warning overclaim, repository compromise, credential compromise, or other urgent matter. Emergency action shall be time-limited, recorded as soon as practicable, reviewed by competent authority, ratified where required, corrected where necessary, and closed through the applicable register.
196.11 Conversion of Informal Communications Into Official Records. Informal communications may be converted into official records only through capture, classification, completeness review, authority mapping, conflict review, approval by competent authority where required, and entry into the applicable register. Conversion shall not retroactively validate an act that is unlawful, constitutionally impermissible, outside authority, contrary to this Bylaw, or inconsistent with non-execution, role separation, public authority boundaries, finance boundaries, safeguards, or data / AI / cyber controls.
196.12 Incomplete, Defective, or Uncaptured Decision Treatment. An incomplete, defective, or uncaptured decision shall be treated as pending, non-operative, voidable, restricted, quarantined, returned, or invalid according to severity and applicable law. GCRI Canada may require re-intake, additional evidence, legal review, conflict disclosure, corrected authority mapping, public-safe review, Board ratification, member approval where required, correction notice, withdrawal, or nullification.
196.13 Informal Decision Correction, Ratification, or Nullification. Where an informal decision appears to have been acted upon, GCRI Canada shall review whether it may be lawfully corrected, ratified, re-scoped, narrowed, superseded, withdrawn, or nullified. No ratification shall approve prohibited functions, unauthorized public authority delegation, finance execution, certification overclaim, procurement overclaim, public warning overclaim, sponsor capture, provider capture, unlawful data handling, unlawful AI processing, or protected knowledge misuse.
196.14 No-Email-Governance Records. GCRI Canada shall maintain records of informal-decision incidents, conversions of informal communications into official records, ratifications, nullifications, corrections, emergency fast-lane uses, no-email-governance exceptions, training, enforcement actions, and process improvements. Such records shall support institutional discipline, auditability, legal compliance, correctionability, and prevention of governance drift.
Section 197. Mandatory Case ID for Every Material Governance, Evidence, Research, Data, AI, Cyber, Publication, Sponsorship, Public Authority, and Nexus Coordination Act
197.1 Case ID Requirement. Every material governance, evidence, research, data, AI, cyber, privacy, publication, sponsorship, public authority, safeguards, conflict, integrity, technical asset, software release, Nexus interface, or cross-entity coordination act shall be assigned a unique case ID before review, approval, adoption, publication, release, implementation, or closeout, unless an emergency procedure requires immediate action and delayed case creation. A delayed case ID shall be created as soon as practicable.
197.2 Material Governance Acts. Material governance acts requiring a case ID include Board decisions, member approvals where applicable, Bylaw amendments, policy adoption, committee creation, council creation, officer appointments, delegations, reserved matters, registered office changes, corporate filings, major contracts, major grants, major sponsorships, major public statements, risk escalations, and any act affecting mission lock, public-benefit purpose, legal separateness, non-execution, role separation, or corporate authority.
197.3 Board and Committee Acts. Board and committee acts requiring a case ID include meeting decisions, written resolutions, emergency decisions, reserved-matter approvals, committee recommendations, committee decisions where delegated, recusals, conflicts, action items, policy approvals, strategy approvals, budget approvals, litigation decisions, public authority protocols, data / AI / cyber policies, research integrity policies, safeguards policies, and correction approvals.
197.4 Officer Delegations. Officer appointments, acting appointments, authority delegations, signature authority, spending authority, contracting authority, publication authority, program approval authority, data access authority, AI-use authority, controlled-room authority, public authority interface authority, emergency authority, and revocations of authority shall require case IDs and delegation records.
197.5 Membership and Participation Acts. Statutory member admissions, non-voting member admissions, supporter admissions, subscriptions, participant admissions, fellow appointments, advisor appointments, observer admissions, delegate designations, public authority participant classifications, provider participation, sponsor participation, host participation, contributor access, good standing determinations, suspensions, terminations, reinstatements, appeals, and offboarding shall require case IDs where material.
197.6 Evidence and Methods Acts. Evidence intake, evidence classification, evidence pack creation, method adoption, method versioning, source-lineage review, confidence scoring, evidence challenge, evidence correction, observability method review, ontology update, controlled vocabulary update, technical truth output, assurance pack creation, public-safe evidence release, and evidence withdrawal shall require case IDs.
197.7 Research and Publication Acts. Research agenda approvals, research project intake, ethics review, human-subjects review, community review, Indigenous or protected knowledge review, sponsored research review, research publication, peer review, reproducibility review, publication approval, public-safe summary, controlled annex release, correction, supersession, withdrawal, retraction, and archival shall require case IDs.
197.8 Technical Asset and Software Release Acts. Technical asset creation, repository creation, public-good software release, open technical baseline release, schema release, API release, SDK release, dashboard release, data dictionary release, model card release, dataset card release, system card release, benchmark card release, test harness release, secure build, SBOM issuance, signing-key use, package release, vulnerability disclosure, emergency patch, rollback, deprecation, retirement, and takedown shall require case IDs.
197.9 Data Access, Data Processing, Data Transfer, AI-Use, Model, Inference, Cyber, and Controlled-Room Acts. Material data access, processing, sharing, transfer, deletion, sealing, retention exception, AI-use approval, model approval, inference record, compute workload record, embedding, retrieval indexing, fine-tuning, training, model improvement, agentic AI use, cyber access, credential issuance, repository access, controlled-room admission, data-room access, evidence-room access, clean-room access, public authority room access, and no-download-room access shall require case IDs.
197.10 Sponsorship, Donation, Grant, Restricted Fund, In-Kind Contribution, Subscription, and Fee Acts. Support acceptance, refusal, restriction, return, termination, restricted fund approval, sponsorship benefit schedule, donor condition review, grant application, grant acceptance, in-kind valuation, subscription approval, fee schedule approval, cost-recovery arrangement, public acknowledgment, sponsor reference, provider reference, and anti-capture review shall require case IDs where material.
197.11 Public Authority Capacity, Participation, Data Contribution, Reference, and Room Acts. Public authority capacity classification, official capacity verification, observer status, regulator-listening status, public finance reader status, emergency-management participant status, public infrastructure operator status, public authority data contribution, public authority reference approval, quote approval, logo approval, attendance reference, photograph use, room participation, non-endorsement language, correction, and clarification shall require case IDs.
197.12 Nexus Interface, GRF Interface, GRA Interface, GCRI US Interface, Nexus Standards Interface, Consortium Interface, National Company Interface, Project SPV Interface, and Provider Interface Acts. Material cross-entity interfaces shall require case IDs, including interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, protocol authority, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Regional Consortiums, National Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified providers, hosts, sponsors, donors, universities, laboratories, communities, public authorities, and partners.
197.13 Safeguards, Community, Indigenous, Protected Knowledge, Grievance, Complaint, and Remedy Acts. Community participation, Indigenous knowledge review, Indigenous data review, local knowledge review, territorial knowledge review, protected knowledge handling, vulnerable community review, remote community review, public-safe mapping review, consent pathway, non-consent record, attribution, withdrawal, correction, grievance, remedy, whistleblowing, protected participation, non-retaliation, stop-the-line, and do-no-harm review shall require case IDs.
197.14 Public Claims, Public-Safe Publication, Media, Dashboard, Map, Dataset, Whitepaper, Report, Deck, and Website Acts. Public claims, public-safe publications, media responses, public reports, whitepapers, dashboards, maps, datasets, software release communications, public decks, websites, social media, articles, speeches, sponsor acknowledgments, provider references, public authority references, Nexus-compatible claims, finance-reference language, and disclaimer approvals shall require case IDs where material.
197.15 Conflict, Recusal, Related-Party, Integrity, Enforcement, Investigation, and Dispute Acts. Conflicts, recusals, related-party transactions, gifts, hospitality, independence determinations, misconduct allegations, investigations, incidents, enforcement actions, sanctions, appeals, reinstatements, disputes, cross-entity disputes, forum-shopping controls, corrective actions, and settlement or closeout decisions shall require case IDs.
197.16 No Record / No Case ID / No Public Meaning Rule. No material act lacking a required record and case ID shall be treated as adopted, approved, authorized, public, official, effective, certified, recognized, finance-ready, procurement-approved, public authority-approved, Nexus-compatible, released, or institutionally meaningful. A missing case ID shall trigger correction, restricted reliance, re-intake, ratification review, nullification, public-safe clarification, or other remediation.
197.17 Case ID Records. GCRI Canada shall maintain case ID records identifying case number, title, date, submitter, owner, custodian, steward, authority surface, classification, lifecycle status, approvals, linked records, outputs, corrections, supersessions, withdrawals, closeout, archival status, and retention requirements.
Section 198. Case ID Schema, Uniqueness, Metadata, Classification, Ownership, Stewardship, RACI, and Lifecycle States
198.1 Case ID Schema. GCRI Canada shall maintain a standardized case ID schema capable of distinguishing entity, year, function, case type, sequence number, classification, authority surface, and lifecycle status. The schema may be implemented through forms, registers, repositories, ledgers, ticketing systems, document management systems, or other approved systems, provided that uniqueness, traceability, integrity, access control, and correctionability are preserved.
198.2 Unique Identifier. Each case ID shall be unique, non-duplicative, persistent, searchable, and traceable across related records. Duplicate case IDs shall be reconciled through a recorded merge, cross-reference, supersession, or correction process. No case ID shall be reused for a different matter.
198.3 Date and Time Metadata. Each case shall include date and time metadata sufficient to establish intake date, submission time where relevant, review dates, approval dates, effective dates, publication dates, correction dates, supersession dates, withdrawal dates, closure dates, and archival dates. Time-sensitive matters shall include time zone and emergency status where relevant.
198.4 Entity and Function Metadata. Each case shall identify GCRI Canada as the responsible entity unless another entity is involved, and shall identify affected functions, including governance, Board, officer, committee, Council, evidence, methods, research, observability, ontology, software, data, AI, cyber, privacy, public authority, safeguards, publication, finance boundary, sponsorship, provider interface, Nexus interface, or correction function.
198.5 Case Type. Each case shall be assigned a case type reflecting the nature of the act, including governance, decision, delegation, evidence, method, research, publication, technical asset, software release, data access, AI use, cyber access, controlled room, public authority, sponsorship, grant, donation, conflict, incident, correction, interface, dispute, enforcement, or dissolution-related case type.
198.6 Authority Surface. Each case shall identify the authority surface responsible for review or decision, including Board, member body where applicable, committee, officer, Secretariat, legal function, evidence function, research function, technical function, data / AI / cyber function, safeguards function, publication authority, public authority protocol authority within GCRI Canada’s non-executing role, or other delegated authority.
198.7 Owner. Each case shall have an owner responsible for advancing the matter, ensuring completeness, coordinating review, obtaining approvals, maintaining timelines, and closing the case. Ownership shall not itself create decision authority unless separately delegated.
198.8 Custodian. Each case shall have a custodian responsible for maintaining the authoritative record, ensuring repository discipline, controlling access, preserving integrity, and coordinating retention, sealing, deletion, or archival as applicable.
198.9 Steward. Each case may have a steward responsible for substantive quality, mission alignment, method integrity, evidence integrity, public-good technical integrity, public authority boundary discipline, finance-boundary discipline, safeguards integrity, or Nexus interface compatibility, depending on case type.
198.10 Responsible, Accountable, Consulted, and Informed Roles. Each material case shall identify responsible, accountable, consulted, and informed roles where appropriate. RACI mapping shall not expand authority beyond this Bylaw, the Articles, applicable law, Board resolutions, officer delegations, or approved charters.
198.11 Classification Metadata. Each case shall include classification metadata sufficient to determine publication class, access class, data sensitivity, security sensitivity, competition sensitivity, public authority sensitivity, finance sensitivity, infrastructure sensitivity, cyber sensitivity, community or protected knowledge sensitivity, AI-use status, export-control status, sanctions status, and retention category.
198.12 Publication Class. Each case shall identify whether outputs are public, public-safe summary, controlled, restricted, internal, embargoed, archived, withdrawn, or non-public. Publication class shall determine review, redaction, disclaimer, approval, access, and correction requirements.
198.13 Access Class. Each case shall identify who may access the case record and under what conditions, including Board access, officer access, committee access, Council access, staff access, controlled-room access, public authority access, external reviewer access, community reviewer access, provider access, sponsor access, or public access.
198.14 Data Sensitivity Class. Each case involving data shall identify data sensitivity, including personal information, sensitive personal information, health-sensitive data, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, proprietary data, community-protected data, Indigenous / local / territorial knowledge, protected knowledge, anonymized data, aggregated data, synthetic data, or public data.
198.15 Security Class. Each case shall identify security class where relevant, including ordinary, confidential, restricted, controlled-room, no-download, cyber-sensitive, infrastructure-sensitive, credential-sensitive, export-controlled, sanctions-sensitive, incident-sensitive, privileged, or legal-hold status.
198.16 Competition Sensitivity Class. Cases involving providers, vendors, sponsors, operators, markets, benchmarking, comparative outputs, pricing, costs, margins, bids, customers, procurement, or commercial strategy shall include competition sensitivity classification and may require clean-team, clean-room, aggregation, de-identification, legal review, or meeting restrictions.
198.17 Public Authority Capacity Flag. Cases involving public authorities shall include a public authority capacity flag identifying whether the public authority role is official, observer, regulator-listening, public finance reader, emergency-management participant, public infrastructure operator, data contributor, reviewer, speaker, controlled-room participant, personal-capacity participant, or another approved status.
198.18 Finance Boundary Flag. Cases involving finance-readiness references, capital-reader rooms, proof packs, GRA inputs, investor literacy, insurance-readiness evidence, public finance readers, grants, public finance, lenders, insurers, underwriters, ratings, routeability, bankability, or capital-readability shall include a finance-boundary flag and non-reliance review.
198.19 Certification Boundary Flag. Cases involving standards support, conformance-supporting tools, interoperability profiles, technical baselines, training records, competence records, provider claims, technology claims, maturity references, Docket references, Grid references, or Nexus-compatible claims shall include a certification-boundary flag.
198.20 Procurement Boundary Flag. Cases involving vendors, providers, hosts, public authorities, procurement-sensitive discussions, bid materials, provider participation, technical comparisons, public authority references, or market baseline materials shall include a procurement-boundary flag and provider-neutrality review.
198.21 Regulatory Perimeter Flag. Cases with potential securities, insurance, lending, underwriting, brokerage, rating, legal, engineering, clinical, accounting, public finance, public authority, public warning, emergency command, privacy, AI, cyber, export-control, sanctions, competition, or other regulated-activity implications shall include a regulatory perimeter flag and escalation record.
198.22 Safeguards Flag. Cases involving communities, Indigenous knowledge, local knowledge, territorial knowledge, protected knowledge, vulnerable communities, public-safe mapping, health-sensitive data, remote communities, grievance, remedy, protected participation, whistleblowing, non-retaliation, or do-no-harm concerns shall include a safeguards flag.
198.23 Indigenous / Community / Protected Knowledge Flag. Cases involving Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, protected environmental knowledge, community protocols, protected knowledge, or public-safe mapping shall include a specific protected knowledge flag and shall be routed to safeguards review before publication, transfer, AI use, or public-safe release.
198.24 AI-Use Flag. Cases involving AI systems, AI assistants, model use, inference records, embeddings, retrieval, fine-tuning, training, model improvement, agentic AI, automated classification, AI-generated content, AI-assisted publication, or verifiable intelligence shall include an AI-use flag.
198.25 Cross-Border Transfer Flag. Cases involving data transfer, remote access, cloud storage, AI provider processing, controlled-room access, public authority data, community-protected data, export of software, model sharing, repository access, or cross-border participation shall include a cross-border transfer flag where applicable.
198.26 Sanctions / Export-Control Flag. Cases involving restricted persons, restricted jurisdictions, controlled technology, AI-RAN, O-RAN, cyber tools, cryptography, geospatial data, Earth observation, drones, robotics, autonomous systems, sovereign compute, quantum-adjacent systems, semiconductors, advanced manufacturing, public release of controlled software, foreign person access, or cross-border technology transfer shall include sanctions and export-control flags where applicable.
198.27 Lifecycle States: Intake, Incomplete, Triage, Under Review, Hold, Quarantine, Approved, Rejected, Returned, Adopted, Published, Controlled, Corrected, Superseded, Withdrawn, Retired, Archived, Closed, Reopened. Each case shall maintain a lifecycle state. Lifecycle states shall be used consistently and shall determine permitted actions, required approvals, access rights, publication posture, correction duties, and closeout obligations. No case shall be treated as adopted, published, released, or closed unless the corresponding lifecycle state is entered by authorized record.
198.28 Case ID Metadata Records. GCRI Canada shall maintain case ID metadata records sufficient to support search, audit, reporting, correction, downstream dependency management, interoperability, legal compliance, and institutional continuity. Metadata changes shall be logged, versioned, and correctionable.
Section 199. Completeness Gate, Intake, Admissibility, Triage, and Return of Incomplete Submissions
199.1 Completeness Gate Purpose. The completeness gate shall ensure that GCRI Canada does not review, approve, publish, release, act on, or externally communicate material matters without sufficient information to determine authority, legality, public-benefit alignment, non-execution compliance, role separation, risk, safeguards, classification, evidence support, method support, and correction path.
199.2 Completeness Checklist Library. GCRI Canada shall maintain a checklist library for recurring case types, including Board decisions, officer delegations, committee actions, evidence intake, method adoption, research review, publication approval, software release, data access, AI use, cyber access, public authority participation, sponsorship acceptance, grant acceptance, provider participation, controlled-room admission, safeguards review, public-safe mapping, incidents, corrections, and Nexus interface matters.
199.3 Required Intake Fields. Each intake shall include required fields appropriate to case type, including submitter, owner, requested action, purpose, authority basis, affected parties, affected instruments, evidence or rationale, classification, public-benefit basis, non-execution analysis, role-separation analysis, conflicts, risks, approvals required, deadline, intended output, publication posture, correction path, and closeout requirements.
199.4 Required Authority Identification. Every submission shall identify the proposed decision authority or review authority. Where authority is uncertain, the case shall be routed for authority mapping before action. No submission shall proceed merely because a person is senior, technically central, a funder, a sponsor, a provider, a public authority participant, an author, a committee chair, a Council participant, a host, or a Nexus interface actor.
199.5 Required Evidence or Rationale. Every submission shall include sufficient evidence, rationale, or supporting documentation to permit review. Evidence shall be linked to source lineage where relevant. Unsupported assertions, reputational claims, promotional statements, sponsor narratives, provider materials, public authority expectations, AI-generated conclusions, dashboard outputs, or informal summaries shall not satisfy the evidence requirement without review.
199.6 Required Classification. Every submission shall include proposed classification, including publication class, access class, data sensitivity, security class, public authority status, finance-boundary status, certification-boundary status, procurement-boundary status, regulatory perimeter status, safeguards status, AI-use status, and cross-border or export-control status where applicable.
199.7 Required Conflict Disclosure. Submitters and participants shall disclose conflicts relevant to the matter, including financial, institutional, research, sponsor, donor, funder, provider, host, national company, Project SPV, investor, insurer, lender, contractor, public authority, IP, data, AI, cyber, community, protected knowledge, publication, or reputational conflicts. Missing conflict disclosures may result in return, hold, quarantine, or later correction.
199.8 Required Data / AI / Cyber Disclosure Where Applicable. Submissions involving data, AI, models, inference, embeddings, retrieval, compute, repositories, credentials, cyber access, controlled rooms, dashboards, maps, software, technical assets, or digital systems shall disclose data classes, AI tools, model identities, cyber controls, security risks, privacy risks, storage locations, transfer risks, vendor or processor involvement, retention, deletion, and incident history where relevant.
199.9 Required Public Authority Disclosure Where Applicable. Submissions involving public authorities shall disclose public authority identity, capacity, authority basis, official status, observer status, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, data contribution terms, reference permissions, non-endorsement language, and any risk of public authority confusion.
199.10 Required Finance, Certification, Procurement, or Regulatory Perimeter Disclosure Where Applicable. Submissions involving capital, insurance, lending, underwriting, ratings, public finance, proof packs, GRA interfaces, procurement, provider claims, certification, standards support, technical baselines, conformance tools, public authority procurement, or regulated activity shall disclose finance-boundary, certification-boundary, procurement-boundary, and regulatory perimeter issues and shall be routed for review.
199.11 Required Safeguards and Protected Knowledge Disclosure Where Applicable. Submissions involving communities, Indigenous knowledge, local knowledge, territorial knowledge, protected knowledge, public-safe mapping, vulnerable communities, remote communities, health-sensitive data, protected participation, grievances, remedies, or do-no-harm issues shall disclose safeguards implications and shall be routed for safeguards review before action.
199.12 Admissibility Review. The Secretariat, authorized officer, records function, legal function, or other designated intake reviewer shall determine whether a submission is admissible, incomplete, out-of-scope, duplicative, abusive, unsafe, misdirected, prohibited, or requiring emergency routing. Admissibility review shall not determine the merits unless delegated authority permits such determination.
199.13 Triage Lanes. GCRI Canada may assign cases to triage lanes, including governance, evidence and methods, research, technical asset, data / AI / cyber, public authority, sponsorship / grant / finance boundary, safeguards, publication, legal / compliance, incident, correction, or emergency lanes. A case may be assigned to multiple lanes where cross-cutting review is required.
199.14 Governance Triage. Governance triage shall determine whether a matter requires Board action, member approval, committee review, officer approval, policy review, delegation review, reserved-matter treatment, legal review, records correction, or constitutional protection analysis.
199.15 Evidence and Methods Triage. Evidence and methods triage shall determine evidence sufficiency, source lineage, method status, confidence, uncertainty, limitation language, challengeability, correction path, public-safe status, and whether the matter implicates GRF, GRA, Nexus Observatory, Nexus Standards, Nexus Grid, Nexus Docket, or other Nexus interfaces.
199.16 Research Triage. Research triage shall determine research integrity, ethics review, human-subjects review, community review, Indigenous or protected knowledge review, sponsor independence, provider influence, data requirements, publication posture, peer review needs, and correction path.
199.17 Technical Asset Triage. Technical asset triage shall determine asset type, ownership, license, IP status, contributor terms, repository status, security status, dependency status, SBOM requirements, vulnerability status, public-safe status, export-control status, release path, rollback path, and no-certification boundary language.
199.18 Data / AI / Cyber Triage. Data / AI / cyber triage shall determine lawful basis, purpose limitation, privacy risk, data sensitivity, AI-use risk, model risk, cyber risk, cross-border transfer risk, vendor risk, controlled-room requirements, incident history, retention, deletion, and access controls.
199.19 Public Authority Triage. Public authority triage shall determine capacity classification, authority basis, data contribution terms, public-reference permissions, non-endorsement language, no-delegation discipline, public warning boundary, emergency-command boundary, procurement boundary, funding boundary, regulatory boundary, and public finance boundary.
199.20 Sponsorship / Grant / Finance Boundary Triage. Sponsorship, grant, and finance-boundary triage shall determine support type, restrictions, benefit schedule, valuation, tax treatment, sponsor or donor influence, provider neutrality, anti-capture risk, finance-readiness overclaim risk, GRA interface implications, public authority access risk, and public claims constraints.
199.21 Safeguards Triage. Safeguards triage shall determine community impact, Indigenous rights implications, protected knowledge status, public-safe mapping risk, vulnerability risk, consent or non-consent pathways where applicable, accessibility, grievance pathways, retaliation risk, do-no-harm concerns, and stop-the-line triggers.
199.22 Emergency Triage. Emergency triage shall be used for time-sensitive matters involving legal deadlines, data breaches, cyber incidents, AI incidents, public authority misdescription, publication errors, protected knowledge exposure, community harm, finance overclaim, certification overclaim, procurement overclaim, public warning overclaim, sponsor or provider capture, repository compromise, credential compromise, or continuity risk. Emergency triage shall not suspend non-execution, role separation, legal compliance, safeguards, or correctionability.
199.23 Return of Incomplete Submissions. Incomplete submissions may be returned with identified deficiencies, required fields, review conditions, deadline, classification concerns, authority gaps, evidence gaps, conflict gaps, data / AI / cyber gaps, public authority gaps, finance-boundary gaps, safeguards gaps, or correction needs. Returned submissions shall not proceed until resubmitted or waived by competent authority where lawful.
199.24 Rejection of Abusive, Duplicative, Spam, Misleading, Unsafe, or Out-of-Scope Submissions. GCRI Canada may reject submissions that are abusive, duplicative, spam, misleading, unsafe, malicious, unlawful, outside scope, contrary to public-benefit purpose, inconsistent with non-execution, designed to obtain improper provider advantage, designed to purchase influence, designed to create public authority confusion, or designed to create finance, certification, procurement, recognition, or public warning overclaim.
199.25 Triage Records. GCRI Canada shall maintain triage records, including completeness review, deficiencies, admissibility determinations, assigned lanes, returned submissions, rejected submissions, emergency routing, holds, quarantines, reviewer notes, escalation records, and closeout status.
Section 200. Decision Packs and Decision-Grade Artifact Requirements
200.1 Decision Pack Requirement. Material decisions shall be supported by a decision pack sufficient for the competent authority to understand the question, authority, options, evidence, risks, legal basis, public-benefit rationale, non-execution implications, Nexus role-separation implications, data / AI / cyber implications, public authority implications, finance-boundary implications, safeguards implications, implementation requirements, communication posture, correction path, and closeout obligations. A decision pack is a governance-control instrument, not a substitute for approval.
200.2 Decision Question. Each decision pack shall state the decision question clearly, narrowly, and operationally. The question shall identify what is being approved, rejected, deferred, adopted, published, released, delegated, funded, accepted, corrected, withdrawn, superseded, terminated, or escalated.
200.3 Decision Authority. Each decision pack shall identify the competent decision authority, including Board, member body where required, committee, officer, Secretariat function, legal function, evidence function, research function, technical function, data / AI / cyber function, safeguards function, publication authority, or other delegated authority. If authority is uncertain, the decision shall be held for authority mapping.
200.4 Options Architecture. Each decision pack shall present reasonable options where appropriate, including approve, approve with conditions, defer, return for further work, reject, re-scope, quarantine, publish as public-safe summary, restrict to controlled annex, externalize to another entity, refer to GRF, refer to GRA, refer to Nexus Standards, refer to public authority, terminate, withdraw, or correct.
200.5 Recommended Decision. Where a recommendation is provided, it shall be identified as a recommendation only and shall include rationale, conditions, required approvals, implementation steps, limitations, unresolved issues, dissent, and correction path. A recommendation shall not bind the decision authority.
200.6 Legal Basis. Each decision pack shall identify the legal basis for the proposed action, including applicable law, Articles, this Bylaw, Board resolution, officer delegation, committee charter, policy, contract, grant condition, public authority requirement, data protection requirement, IP right, or other authority. Legal basis shall be reviewed where the matter is material, novel, cross-border, regulated, public authority-sensitive, finance-sensitive, data-sensitive, AI-sensitive, cyber-sensitive, safeguards-sensitive, or constitutionally significant.
200.7 Public-Benefit Rationale. Each decision pack shall state how the proposed decision serves GCRI Canada’s public-benefit purpose and public-good technical stewardship role. The rationale shall distinguish public-benefit value from institutional convenience, sponsor preference, provider preference, reputational advantage, event timing, market opportunity, fundraising pressure, public authority attention, or enterprise-stack demand.
200.8 Mission-Lock Analysis. Each decision pack shall address whether the proposed act preserves mission lock, nonprofit character, non-distribution, public-good stewardship, legal separateness, role separation, evidence integrity, methods integrity, public-good technical asset integrity, data / AI / cyber integrity, community safeguards, and public-safe claims discipline.
200.9 Non-Execution Analysis. Each decision pack shall analyze whether the proposed act risks converting GCRI Canada into an execution actor, market actor, broker, finder, lender, insurer, underwriter, rating body, public finance approver, procurement body, certification authority, public authority, emergency command body, public warning authority, provider selector, project operator, national company controller, Project SPV controller, or enterprise-stack actor.
200.10 Nexus Role-Separation Analysis. Each decision pack shall analyze implications for GCRI Canada’s relationship to GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, protocol authority, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, hosts, sponsors, public authorities, universities, communities, and partners.
200.11 Evidence Base. Each decision pack shall identify the evidence base supporting the decision, including source records, evidence records, methods records, research records, technical records, public authority records, safeguards records, financial records, risk records, or incident records. Unsupported claims shall be identified as assumptions or excluded from decision-grade reliance.
200.12 Method Notes. Where the decision relies on methods, models, calculations, classifications, observability outputs, benchmarks, dashboards, AI outputs, digital twins, DePIN records, AI-RAN signals, cyber telemetry, geospatial data, or technical baselines, the decision pack shall include method notes sufficient to understand applicability, limitations, confidence, uncertainty, review status, and correction path.
200.13 Source Lineage. Decision packs shall identify source lineage where evidence is material. Source lineage shall include origin, custody, permission, timestamp, transformation, classification, reliability, limitation, and any known dispute, failure, staleness, supersession, or correction history.
200.14 Assumptions and Limitations. Each decision pack shall disclose assumptions and limitations. Assumptions shall be material, explicit, reviewable, and capable of update. Limitations shall address evidence limits, method limits, data limits, AI limits, legal limits, public authority limits, finance-boundary limits, certification-boundary limits, procurement limits, safeguards limits, implementation limits, and public-safe communication limits.
200.15 Risk Analysis. Each decision pack shall include risk analysis proportionate to the matter, including legal risk, governance risk, financial risk, operational risk, research integrity risk, evidence risk, methods risk, data risk, AI risk, cyber risk, privacy risk, public authority boundary risk, finance-boundary risk, certification and procurement risk, sponsor or provider capture risk, safeguards risk, reputational risk, and continuity risk.
200.16 Data / AI / Cyber / Privacy Review. Where applicable, each decision pack shall include data / AI / cyber / privacy review addressing lawful basis, purpose limitation, data minimization, access controls, AI-use authority, model identity, inference records, cyber controls, repository security, cross-border transfer, vendor risk, retention, deletion, incident history, and public-safe release status.
200.17 Public Authority Review. Where applicable, each decision pack shall include public authority review addressing capacity classification, authority basis, public authority data contribution, public authority reference language, non-endorsement, no-delegation, no-public-warning, no-emergency-command, no-procurement, no-funding, no-regulatory-approval, no-public-finance, and public-private partnership boundary controls.
200.18 Finance Boundary Review. Where applicable, each decision pack shall include finance-boundary review addressing whether the matter could be interpreted as investment advice, solicitation, securities offering, brokerage, finder activity, lending, underwriting, insurance placement, rating, credit opinion, public finance approval, grant approval, budget allocation, routeability, bankability, finance-readiness, insurance-readiness, capital-readability, or GRA output.
200.19 Certification and Procurement Boundary Review. Where applicable, each decision pack shall include certification and procurement boundary review addressing standards-support claims, conformance-supporting tools, technical baselines, training records, competence records, provider claims, public authority procurement contexts, vendor references, procurement advantage, provider preference, certification implication, accreditation implication, maturity implication, Grid implication, Docket implication, or Nexus-compatible claim.
200.20 Competition / Market Sensitivity Review. Where applicable, each decision pack shall include competition and market sensitivity review addressing providers, vendors, operators, sponsors, market data, benchmarking, comparative outputs, pricing, costs, margins, bids, customers, market allocation, procurement, commercially sensitive information, clean-team needs, clean-room needs, aggregation, de-identification, and meeting discipline.
200.21 Sanctions / Export-Control Review. Where applicable, each decision pack shall include sanctions, export-control, national security, controlled technology, sensitive AI, AI-RAN, O-RAN, DePIN, cyber tool, cryptography, geospatial, Earth observation, drone, robotics, autonomous system, telecom, critical infrastructure, quantum-adjacent, semiconductor, advanced manufacturing, dual-use, public release, repository access, foreign person access, or cross-border transfer review.
200.22 Community Safeguards and Protected Knowledge Review. Where applicable, each decision pack shall include community safeguards and protected knowledge review addressing Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, vulnerable communities, remote communities, public-safe mapping, accessibility, consent or non-consent pathways, grievance, remedy, protected participation, non-retaliation, and do-no-harm controls.
200.23 Impact Analysis. Each decision pack shall include impact analysis proportionate to the matter, including public-benefit impact, institutional impact, technical impact, research impact, evidence impact, publication impact, community impact, public authority impact, finance-boundary impact, provider-neutrality impact, sponsor-control impact, data / AI / cyber impact, operational impact, and downstream dependency impact.
200.24 Implementation Readiness. Each decision pack shall address implementation readiness, including responsible owner, resources, timeline, dependencies, policies, forms, registers, repositories, access controls, training, communications, technical readiness, legal readiness, safeguards readiness, data / AI / cyber readiness, public authority readiness, correction readiness, and closeout requirements.
200.25 Communications and Publication Posture. Each decision pack shall identify whether the matter will remain internal, controlled, public-safe, public, embargoed, restricted, archived, or unpublished. Communications posture shall include required disclaimers, non-reliance language, public authority non-endorsement language, finance-boundary language, certification-boundary language, provider-neutrality language, sponsor non-control language, AI limitation language, dashboard or map limitation language, and correction notice requirements.
200.26 Correction Path. Each decision pack shall identify the correction path if the decision, evidence, method, publication, technical asset, data handling, AI output, public authority reference, finance reference, certification-related claim, procurement-related claim, safeguards treatment, or implementation becomes inaccurate, unsupported, unsafe, unauthorized, outdated, superseded, misleading, overbroad, or role-confusing.
200.27 Closeout Requirements. Each decision pack shall identify closeout requirements, including final approval entry, register update, repository deposit, notice, publication, access revocation, contract closeout, controlled-room closeout, data deletion or retention, correction log, supersession record, public-safe summary, stakeholder notification, Board report, or archival.
200.28 Decision Pack Records. GCRI Canada shall maintain decision pack records, including submitted materials, authority mapping, options, recommendation, evidence base, method notes, source lineage, assumptions, limitations, reviews, approvals, conflicts, recusals, dissent, conditions, implementation steps, communications posture, correction path, closeout, and archival status. Decision pack records shall be maintained as authoritative governance artifacts supporting validity-by-record, correctionability, auditability, and institutional continuity.
Section 201. Decision Question, Options, Impact Analysis, Evidence Lineage, Uncertainty, Operational Feasibility, Regulatory Perimeter Assessment, Competition Memo, Rights / Harm Assessment, Security / Privacy Review, Financial Exposure Note, and Decision Authority Mapping
201.1 Decision Question Discipline. Every material decision presented within GCRI Canada shall be framed by a disciplined decision question that is sufficiently precise to identify the requested act, the competent authority, the affected records, the proposed output, the intended legal or institutional effect, and the consequences of approval, rejection, deferral, restriction, correction, withdrawal, or escalation. The decision question shall not be framed in promotional, rhetorical, ambiguous, outcome-forcing, sponsor-driven, provider-driven, public authority-confusing, finance-implying, certification-implying, or execution-facing terms. It shall distinguish between approval to study, approval to convene, approval to publish, approval to release a technical asset, approval to enter a contract, approval to accept support, approval to classify evidence, approval to refer an input to another Nexus institution, and approval to take any other institutional act.
201.2 Options Architecture Discipline. Each material decision pack shall present a structured options architecture proportionate to the matter. The options shall identify the practical, legal, public-benefit, technical, financial, safeguards, public authority, data / AI / cyber, and Nexus role-separation consequences of each available path. Options may include approval, approval with conditions, approval for internal use only, approval for controlled release only, public-safe release, deferral, return for further evidence, quarantine, re-scoping, referral to legal counsel, referral to the Board, referral to a committee, referral to GCRI US, referral to The Global Risks Forum (GRF), referral to The Global Risks Alliance (GRA), referral to Nexus Standards or protocol authority, referral to a public authority where lawful, rejection, withdrawal, supersession, termination, or archival.
201.3 Do-Nothing or Defer Option. Where a decision could create risk, ambiguity, public meaning, finance implication, certification implication, public authority implication, data / AI / cyber exposure, community harm, protected knowledge risk, or Nexus role confusion, the decision pack shall expressly include a do-nothing, defer, hold, or no-action option unless the matter is legally mandatory or emergency action is required. The do-nothing or defer option shall not be treated as institutional failure; it may be the preferred public-good posture where evidence is insufficient, authority is unclear, public safety requires restraint, or the proposed act would invite overclaim, capture, or perimeter breach.
201.4 Impact Analysis. Each decision pack shall include impact analysis proportionate to the proposed act. Impact analysis shall identify the expected and reasonably foreseeable effects on GCRI Canada’s public-benefit purpose, legal status, nonprofit and non-distribution character, non-execution boundary, evidence integrity, methods integrity, public-good technical assets, data / AI / cyber posture, public authority boundaries, finance-readiness boundaries, certification and procurement boundaries, community safeguards, protected knowledge, sponsor and provider neutrality, institutional reputation, resource capacity, continuity, and Nexus interoperability.
201.5 Public-Benefit Impact. The public-benefit impact analysis shall identify how the proposed decision advances public-good evidence infrastructure, methods stewardship, observability, ontology, technical truth, public-good R&D, public-good software, open technical baselines, research integrity, public authority learning, community safeguards, public-safe publication, or Nexus-compatible institutional trust. It shall also identify any risk that the decision would substitute private benefit, sponsor visibility, provider advantage, event optics, fundraising convenience, public authority access, or enterprise-stack demand for genuine public-benefit justification.
201.6 Legal Impact. The legal impact analysis shall identify applicable Canadian corporate, nonprofit, tax, privacy, AI governance, cybersecurity, research ethics, employment, sanctions, export-control, competition, contract, IP, public authority, professional-boundary, and other relevant legal considerations. Where the decision involves cross-border activity, foreign law, public authority data, controlled technology, sensitive AI, securities, insurance, lending, underwriting, rating, public finance, procurement, emergency management, health, public safety, or regulated professional domains, the legal impact analysis shall identify whether counsel review, external advice, public authority routing, re-scoping, or abstention is required.
201.7 Governance Impact. The governance impact analysis shall identify the effect of the decision on the Board, officers, committees, councils, working groups, competence cells, members, participants, delegates, fellows, advisors, staff, contractors, volunteers, contributors, and controlled-room participants. It shall identify whether the decision affects reserved matters, member approval rights where applicable, officer delegations, committee charters, council mandates, authority matrices, records obligations, conflict controls, or future precedent. No governance impact analysis shall imply that operational convenience, repeated practice, public expectation, or technical capability can amend this Bylaw.
201.8 Nexus Interface Impact. The Nexus interface impact analysis shall identify whether the decision affects GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, protocol authority, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified providers, hosts, sponsors, public authorities, universities, communities, or other Nexus interfaces. It shall specify any required compatibility note, divergence log, interface record, no-merger clause, no-agency clause, non-execution clause, correction notice, or cross-entity routing.
201.9 Evidence Lineage Analysis. Where a decision relies on evidence, the decision pack shall identify source lineage, provenance, custody, timestamp, jurisdictional origin, contribution authority, permission basis, evidence transformation, classification, reliability, confidence, uncertainty, limitations, disputes, missing inputs, failed signals, stale data, superseded materials, AI-assisted processing, public authority contribution status, protected knowledge status, and correction path. Evidence lineage analysis shall distinguish raw data from evidence, inference from verified record, model output from reviewed artifact, dashboard display from governance record, and public authority participation from public authority decision.
201.10 Uncertainty Disclosure. Every material decision pack shall disclose material uncertainty. Uncertainty may include evidence uncertainty, method uncertainty, legal uncertainty, regulatory perimeter uncertainty, data quality uncertainty, model uncertainty, operational uncertainty, financial exposure uncertainty, public authority boundary uncertainty, community harm uncertainty, protected knowledge uncertainty, sponsor or provider influence uncertainty, publication risk uncertainty, or Nexus interface uncertainty. Where uncertainty is material and unresolved, the decision authority shall adopt the most restrictive lawful interpretation, defer, re-scope, impose conditions, require additional review, or decline the act.
201.11 Assumptions Register. Each decision pack shall include an assumptions register where material assumptions underlie the proposed decision. Assumptions shall be stated expressly, assigned an owner where appropriate, classified by risk, linked to evidence where available, reviewed for reasonableness, and updated or retired when superseded. No assumption shall be disguised as a fact, no sponsor or provider assertion shall be treated as neutral evidence without review, and no AI-generated output shall be treated as an assumption-free basis for institutional action.
201.12 Operational Feasibility. The operational feasibility analysis shall identify whether GCRI Canada has the lawful authority, human capacity, technical capacity, financial capacity, governance capacity, data / AI / cyber controls, records systems, publication controls, safeguards capacity, legal support, continuity capability, and implementation discipline necessary to carry out the proposed act. A decision shall not be approved merely because it is desirable, urgent, funded, reputationally attractive, technically possible, or requested by an external actor if GCRI Canada lacks feasible capacity to perform it safely and lawfully.
201.13 Resource Implications. Each decision pack shall identify required staff time, contractor time, officer oversight, Board or committee time, legal review, technical resources, compute, storage, security tooling, insurance implications, financial cost, opportunity cost, translation, accessibility, public-safe publication, community participation, protected knowledge safeguards, training, records administration, and ongoing maintenance. Resource implications shall include full lifecycle costs, not merely launch costs.
201.14 Regulatory Perimeter Assessment. A regulatory perimeter assessment shall be included where a decision could implicate securities, investment advice, capital raising, brokerage, finder activity, lending, insurance, underwriting, ratings, public finance, public procurement, certification, accreditation, professional advice, legal advice, engineering opinion, clinical opinion, public health, emergency management, public warning, public authority approval, data protection, AI regulation, cyber regulation, sanctions, export controls, competition law, or controlled technology. Where perimeter risk exists, the matter shall be escalated, held, re-scoped, externalized to licensed or competent actors, or rejected.
201.15 Competition and Market Sensitivity Memo. Where a decision involves providers, vendors, sponsors, operators, industry participants, market data, benchmarking, comparative outputs, prices, costs, margins, capacity, bids, customers, suppliers, procurement, product roadmaps, future commercial strategy, market access, vendor qualification, or provider claims, the decision pack shall include a competition and market sensitivity memo. The memo shall identify prohibited topics, clean-team needs, clean-room needs, aggregation requirements, de-identification requirements, independent administration requirements, meeting discipline, minutes controls, and stop-meeting authority.
201.16 Rights, Harm, Safeguards, and Protected Knowledge Assessment. Where a decision may affect persons, communities, Indigenous peoples, local knowledge holders, territorial knowledge holders, vulnerable communities, remote communities, protected participants, whistleblowers, complainants, cultural sites, environmental knowledge, public-safe mapping, health-sensitive information, or rights-bearing data, the decision pack shall include a rights, harm, safeguards, and protected knowledge assessment. The assessment shall identify consent or non-consent pathways where applicable, withdrawal and correction pathways, do-no-harm controls, accessibility, language needs, non-retaliation, grievance and remedy pathways, and publication restrictions.
201.17 Security and Privacy Review Checklist. Where a decision involves data, systems, repositories, dashboards, maps, AI tools, controlled rooms, public authority materials, protected knowledge, software release, cloud systems, vendors, data processors, credentials, keys, tokens, cross-border transfer, public release, or technical integration, the decision pack shall include a security and privacy review checklist. The checklist shall address lawful basis, purpose limitation, minimization, classification, access control, encryption, logging, retention, deletion, incident response, vendor risk, cyber risk, privacy rights, public-safe release, and breach notification.
201.18 AI-Use and Model Governance Review Checklist. Where a decision involves AI systems, AI assistants, model outputs, inference records, embeddings, retrieval, fine-tuning, training, model improvement, agentic AI, evaluation harnesses, model cards, dataset cards, system cards, benchmark cards, digital twins, automated classification, public-safe intelligence, or AI-generated content, the decision pack shall include an AI-use and model governance review checklist. The checklist shall identify model identity, permitted uses, prohibited uses, data inputs, training restrictions, human review, hallucination risk, bias risk, drift risk, prompt injection risk, data leakage risk, output limits, correction path, and non-authority language.
201.19 Financial Exposure Note. Each decision pack involving expenditure, funding, grant acceptance, sponsorship, donation, restricted funds, in-kind contribution, subscription, fee, cost recovery, procurement, contract, long-term obligation, liability, asset transfer, technical asset maintenance, or program launch shall include a financial exposure note. The note shall identify budget source, restricted or unrestricted status, cash impact, runway impact, tax treatment, reporting obligations, reimbursement conditions, return obligations, contingent liabilities, related-party issues, and anti-capture risks.
201.20 Insurance and Liability Note. Where a decision may create legal exposure, public-facing reliance, research risk, data risk, cyber risk, professional-boundary risk, public authority confusion, event risk, controlled-room risk, software release risk, volunteer or participant risk, community harm risk, contract risk, or cross-border risk, the decision pack shall include an insurance and liability note. The note shall identify relevant insurance, exclusions, indemnification issues, limitation language, contractual protections, residual risk, and any need for additional coverage or external review.
201.21 Public Authority Boundary Note. Where a decision involves a public authority, public institution, Crown entity, municipality, regulator, agency, ministry, utility, public infrastructure operator, public finance body, emergency management body, public health body, public safety body, or public-sector participant, the decision pack shall include a public authority boundary note. The note shall confirm capacity classification, approved reference language, non-endorsement, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, and correction path.
201.22 Claims and Publication Note. Where a decision may result in public communication, external-facing output, website language, report, whitepaper, dataset, dashboard, map, media response, social media, deck, software release note, public-safe summary, sponsor acknowledgment, provider reference, public authority reference, finance-readiness reference, standards-support reference, Nexus-compatible claim, or impact claim, the decision pack shall include a claims and publication note. The note shall identify evidence support, methods support, reviewer approvals, classification, disclaimers, redactions, controlled annexes, public-safe restrictions, and correction path.
201.23 Decision Authority Mapping. Each decision pack shall map the proposed act to the competent decision authority under applicable law, the Articles, this Bylaw, Board resolutions, officer delegations, committee charters, council mandates, policies, contracts, and schedules. Decision authority mapping shall identify whether Board approval, member approval, committee recommendation, officer approval, legal review, public authority permission, safeguards review, data / AI / cyber approval, or cross-entity interface approval is required.
201.24 Required Approvals, Consultations, Recusals, and Ratifications. Each decision pack shall identify required approvals, consultations, recusals, abstentions, conflict controls, public authority permissions, sponsor or donor disclosures, provider disclosures, legal reviews, technical reviews, safeguards reviews, data / AI / cyber reviews, publication approvals, Board ratifications, member confirmations where applicable, and emergency ratifications. A missing approval shall prevent operative effect unless lawfully cured.
201.25 Decision Artifact Records. GCRI Canada shall maintain decision artifact records, including the decision question, options, do-nothing or defer option, impact analysis, evidence lineage, uncertainty disclosure, assumptions register, feasibility assessment, regulatory perimeter assessment, competition memo, rights and safeguards assessment, security and privacy checklist, AI-use checklist, financial exposure note, insurance and liability note, public authority boundary note, claims and publication note, authority mapping, approvals, recusals, ratifications, final decision, conditions, implementation record, correction path, and closeout record.
Section 202. Official Registers
202.1 Official Register Architecture. GCRI Canada shall maintain an official register architecture consisting of approved registers for corporate governance, Board acts, member acts where applicable, directors, officers, members, participants, delegates, councils, committees, fellows, advisors, contributors, conflicts, recusals, related parties, evidence, methods, ontology, models, datasets, software, public-good technical assets, publications, corrections, incidents, sponsorships, grants, donations, restricted funds, public authority capacity, references, data contributions, rooms, providers, vendors, hosts, partners, third-party risk, Gazette notices, and other matters designated by the Board. Registers are authoritative record instruments, not informal tracking tools.
202.2 Register Authority. Each official register shall be established by this Bylaw, Board resolution, approved policy, delegated authority, or lawful corporate requirement. No register shall create substantive authority beyond its approved scope. Entry in a register may evidence status, authority, classification, access, approval, correction, or lifecycle state only where the underlying decision authority and record requirements have been satisfied.
202.3 Register Custodian. Each official register shall have a named custodian responsible for integrity, access control, completeness, versioning, correction, retention, audit trail, export control, and repository discipline. The Secretary shall be the default custodian of corporate governance registers unless the Board designates another custodian. Technical, evidence, data, AI, cyber, safeguards, publication, or finance registers may have specialized custodians subject to Board-approved records architecture.
202.4 Register Owner. Each official register shall have a register owner responsible for substantive accuracy, review cadence, field design, register use, reporting, escalation, and compliance with this Bylaw. Ownership may sit with the Board, an officer, a committee, the Secretariat, evidence function, research function, technical function, data / AI / cyber function, safeguards function, finance function, legal function, or other designated function.
202.5 Register Access Class. Each register shall be assigned an access class. Access may be public, public-safe, controlled, restricted, Board-only, officer-only, committee-only, counsel-only, controlled-room, no-download, public authority-limited, safeguards-limited, cyber-limited, or otherwise restricted. Access classification shall reflect legal, privacy, cyber, public authority, finance, competition, community, protected knowledge, research integrity, and public-safe publication requirements.
202.6 Register Classification. Each register shall be classified according to record type, sensitivity, publication status, data class, security class, public authority sensitivity, finance sensitivity, competition sensitivity, infrastructure sensitivity, cyber sensitivity, protected knowledge status, AI-use status, export-control status, sanctions status, and retention category where applicable.
202.7 Register Fields. Each official register shall contain fields sufficient to support validity-by-record, correctionability, auditability, legal compliance, and operational use. Fields may include case ID, record ID, title, date, owner, custodian, authority basis, status, classification, approvals, restrictions, conflicts, access rights, linked records, effective date, expiry date, review date, correction path, supersession status, withdrawal status, archival status, and retention period.
202.8 Register Update Rules. Register updates shall be made only by authorized persons, through approved workflows, with sufficient support record, date, author identity, change reason, and audit trail. Material updates shall not be made silently. Updates that alter authority, status, public meaning, access rights, publication posture, correction status, or legal effect shall require the approval or review specified by this Bylaw, policy, or delegation.
202.9 Register Correction Rules. Register errors shall be corrected by transparent correction process. Corrections shall preserve historical traceability, identify corrected fields, correction date, correction authority, reason, affected downstream records, and notice requirements. Register correction shall not erase material history except where lawful deletion, sealing, privacy protection, protected knowledge protection, or legal privilege requires restricted treatment.
202.10 Register Reconciliation. Registers shall be periodically reconciled against related records, repositories, case IDs, Board minutes, committee minutes, policies, publication records, technical repositories, data rooms, controlled rooms, financial records, public authority records, sponsorship records, and Nexus interface records. Reconciliation shall identify mismatches, stale entries, duplicate entries, missing records, unauthorized entries, inconsistent classifications, and unresolved correction needs.
202.11 Register Audit Trail. Each official register shall maintain an audit trail sufficient to show creation, modification, approval, correction, supersession, withdrawal, deletion, sealing, archival, export, access, and closeout events. Audit trails shall be protected from unauthorized alteration and shall be retained according to the applicable retention schedule.
202.12 Register Retention. Registers shall be retained according to retention schedules approved by the Board or competent authority. Retention shall account for corporate law, tax law, privacy law, research integrity, public authority obligations, grant conditions, sponsor conditions, legal holds, litigation risk, public-good technical asset continuity, evidence continuity, correctionability, and institutional memory.
202.13 Register Publication or Controlled-Access Status. The Board or authorized officer shall determine whether a register or register extract is public, public-safe, controlled, restricted, internal, or confidential. Public versions may be redacted, summarized, aggregated, or delayed. Controlled access shall be used where full publication would expose personal information, public authority data, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, finance-sensitive evidence, commercially sensitive information, privileged material, or safety-sensitive material.
202.14 Register Interoperability. Official registers may interoperate with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, national companies, Project SPVs, providers, public authorities, or other approved systems only through lawful, recorded, role-separated, access-controlled, and correctionable interfaces. Interoperability shall not create shared liability, shared authority, merger, agency, certification, recognition, finance-readiness, public authority action, or execution authority.
202.15 Register Export and Transfer Controls. Register exports, transfers, mirrors, synchronizations, extracts, public summaries, API access, data-room access, controlled-room access, or cross-border access shall require authorization, classification review, data / AI / cyber review, privacy review, public authority review, finance-boundary review, safeguards review, sanctions and export-control review, and legal review where applicable. No register export shall include personal information, protected knowledge, public authority sensitive data, cyber-sensitive material, or controlled technology without lawful authority and safeguards.
202.16 Official Register Records. GCRI Canada shall maintain records of register creation, authority, custodianship, ownership, field structure, access class, classification, updates, corrections, reconciliations, audit trails, retention, publication status, controlled access, interoperability, exports, transfers, failures, recoveries, migrations, and retirements.
Section 203. Corporate Register
203.1 Corporate Register Purpose. GCRI Canada shall maintain a Corporate Register as the authoritative record of its corporate existence, constituting instruments, Bylaw, Board and member acts, registered office, corporate filings, statutory returns, officer and director records, corporate status, tax and nonprofit status, insurance, indemnification, and other foundational legal records. The Corporate Register shall preserve legal continuity, Canadian governance seat discipline, validity-by-record, correctionability, and institutional memory.
203.2 Articles and Constituting Instruments. The Corporate Register shall contain the Articles, letters patent, certificate of incorporation, continuance documents, amendments, restatements, supplementary letters patent, certificates, notices, filings, and any other constituting instruments of GCRI Canada. It shall identify the operative version, effective date, filing date, issuing authority, amendments, superseded instruments, and any member approval or governmental approval where required.
203.3 Bylaw Register. The Corporate Register shall include a Bylaw Register identifying this Bylaw, prior bylaws, amendments, restatements, version identifiers, adoption resolutions, member confirmations where required, effective dates, supersession records, Gazette or notice-stream entries, official repository location, certification pages, and archival copies. No unofficial copy, draft, summary, translation, slide deck, public explanation, or AI-generated summary shall override the Bylaw Register.
203.4 Board Resolution Register. The Corporate Register shall include a Board Resolution Register containing Board resolutions, written resolutions, emergency resolutions, reserved-matter approvals, delegation approvals, committee creations, officer appointments, policy approvals, strategy approvals, budget approvals, major contracts, major grants, major sponsorships, major public authority protocols, major data / AI / cyber approvals, and other Board acts. Each entry shall include date, quorum, voting record, conflicts, recusals, materials reviewed, authority basis, effective date, conditions, and linked case ID.
203.5 Member Resolution Register Where Applicable. Where GCRI Canada has statutory members or where member approval is required by law, Articles, or this Bylaw, the Corporate Register shall include a Member Resolution Register containing member notices, meeting records, written resolutions, special resolutions, quorum records, voting records, class or category approvals, member conflict records where applicable, approval thresholds, effective dates, filings, and linked Board records.
203.6 Registered Office Records. The Corporate Register shall maintain records of GCRI Canada’s registered office, changes of registered office, Board approvals, filings, notices, effective dates, statutory compliance records, and authoritative contact information. Registered office records shall distinguish registered office, governance seat, operational address, program address, host location, controlled room, data location, and public-facing contact point.
203.7 Corporate Filings. The Corporate Register shall contain corporate filings made to federal, provincial, territorial, municipal, tax, charity, nonprofit, employment, privacy, or other competent authorities where applicable. Filings shall be recorded with filing date, responsible officer, confirmation, receipt, status, deadlines, amendments, deficiencies, corrections, and retention class.
203.8 Statutory Returns. The Corporate Register shall include annual returns, information returns, tax returns, nonprofit returns, corporate updates, director updates, officer updates, registered office updates, and other statutory or regulatory returns. The register shall identify due dates, submission dates, confirmation numbers, deficiencies, corrections, responsible owner, and compliance status.
203.9 Seal and Certification Records Where Applicable. Where GCRI Canada uses a corporate seal, certified copy process, officer certificate, Secretary certificate, digital signature, hash, or authenticity control, the Corporate Register shall maintain records of custody, authorized use, signature authority, certification text, certified documents, date of certification, recipient where appropriate, and any revoked or corrected certification.
203.10 Corporate Status Records. The Corporate Register shall include records evidencing active status, good standing, continuance, amalgamation, dissolution status, revival, name status, filing status, registered office status, director status, officer status, and any notices of default, deficiency, compliance issue, suspension, restoration, or correction.
203.11 Tax and Nonprofit Status Records. The Corporate Register shall include tax registration records, nonprofit status records, charitable status records if ever lawfully obtained, non-charitable posture records, GST/HST or sales tax records where applicable, payroll registration records where applicable, donation receipt authority where applicable, restricted fund tax treatment records, and tax compliance correspondence. The register shall preserve the distinction between nonprofit public-benefit status and charitable status unless charitable status is lawfully obtained.
203.12 Insurance Records. The Corporate Register shall include insurance policies, binders, certificates, renewals, endorsements, exclusions, claims, incident notices, coverage reviews, Board approvals, broker records, and related correspondence. Insurance records shall include directors’ and officers’ insurance, cyber insurance, professional liability or errors and omissions insurance, general liability, employment practices, property, event, fiduciary, crime, fraud, fidelity, and other coverage where applicable.
203.13 Indemnification Records. The Corporate Register shall include indemnification approvals, advancement approvals, undertakings, eligible person records, Board determinations, conflict reviews, exclusions, repayment obligations, insurance coordination, claims, settlements, legal opinions, and closeout records. Indemnification records shall not be interpreted as permission to breach fiduciary duties, non-execution boundaries, public authority boundaries, finance boundaries, safeguards obligations, or legal compliance.
203.14 Corporate Register Access and Retention. Access to the Corporate Register shall be controlled according to law, Articles, this Bylaw, Board policy, member rights where applicable, privacy obligations, confidentiality, privilege, cyber controls, and public-safe disclosure requirements. Corporate Register records shall be retained for the period required by law and for any longer period necessary to preserve legal continuity, auditability, validity-by-record, correctionability, institutional memory, and public-good asset stewardship.
Section 204. Director, Officer, Member, Participant, Delegate, Council, Committee, Fellow, Advisor, and Contributor Registers
204.1 Director Register. GCRI Canada shall maintain a Director Register identifying each director, appointment or election authority, consent to act, term commencement, term expiry, renewals, resignation, removal, vacancy, independence status, qualifications, conflicts, recusals, training, attendance, committee service, contact information, statutory information required by law, and offboarding status. The Director Register shall be maintained with strict accuracy because Board authority, fiduciary governance, quorum, reserved matters, indemnification, and corporate filings depend on it.
204.2 Officer Register. GCRI Canada shall maintain an Officer Register identifying each officer, title, appointment authority, role description, delegation scope, term, reporting line, authority limits, signing authority, spending authority, contracting authority, publication authority, data / AI / cyber authority, public authority interface authority, conflicts, recusals, compensation approval where applicable, performance review, suspension, removal, resignation, acting status, and offboarding status.
204.3 Member Register Where Applicable. Where GCRI Canada has statutory members, it shall maintain a Member Register in accordance with applicable law, the Articles, and this Bylaw. The Member Register shall identify member category, admission date, good standing, voting rights where applicable, notice rights, meeting rights, approval rights, suspension, termination, resignation, reinstatement, conflicts where relevant, and member records required by law. No person shall be treated as a statutory member unless entered into the Member Register or otherwise recognized by lawful record.
204.4 Non-Voting Member and Supporter Register. GCRI Canada may maintain a Non-Voting Member and Supporter Register identifying non-voting members, supporters, affiliates, institutional participants, subscribers, public-good supporters, and other non-statutory participation categories. The register shall clearly state that such status does not create governance control, fiduciary authority, authority to bind GCRI Canada, certification, recognition, finance-readiness status, procurement advantage, provider preference, or public authority endorsement.
204.5 Participant Register. GCRI Canada shall maintain a Participant Register for persons and institutions participating in programs, research, labs, councils, working groups, controlled rooms, Academy activities, technical projects, public authority learning, safeguards processes, Nexus interface activities, or other participation surfaces. The register shall identify participation category, capacity, rights, restrictions, access class, confidentiality duties, data / AI / cyber duties, public claims limits, good standing, suspension, termination, and closeout.
204.6 Delegate and Representative Register. GCRI Canada shall maintain a Delegate and Representative Register where institutions, public authorities, communities, sponsors, providers, universities, laboratories, partners, or other bodies designate representatives. The register shall identify the represented entity, delegate identity, capacity, authority evidence, term, substitute rules, voting or advisory status where applicable, public statement limits, conflicts, and revocation. No delegate shall have authority beyond the written record.
204.7 Council Register. GCRI Canada shall maintain a Council Register identifying the Leadership Council, Helix Councils, advisory councils, public authority councils, industry and operator councils, academic and research councils, civil society and media councils, community and Indigenous councils, and any other approved council. The register shall identify council charter, mandate, membership, chair, vice-chair, secretary, rapporteur, term, authority limits, advisory status, output classes, quorum, consensus rules, conflicts, and records custodian.
204.8 Committee Register. GCRI Canada shall maintain a Committee Register identifying standing committees, special committees, technical committees, advisory committees, executive committee if established, governance and nominating committee, finance / audit / risk committee, evidence and methods committee, research integrity and ethics committee, observatory methods committee, data / AI / cybersecurity / verifiable compute committee, public-good technical assets committee, safeguards committee, public authority learning and public-safe communications committee, and any other Board-approved committee. The register shall identify authority, charter, members, chair, reporting line, delegated powers, limits, quorum, review cycle, sunset, and records.
204.9 Leadership Council Register. The Leadership Council Register shall identify Leadership Council members, appointment authority, expertise, term, renewal, good standing, conflict disclosures, confidentiality acknowledgments, governance subscription or no-fee status where applicable, sponsored seat controls where applicable, public reference permissions, removal, suspension, resignation, and closeout. The register shall state that Leadership Council status does not create Board status, officer status, fiduciary authority, agency, public authority status, finance-readiness authority, certification authority, procurement authority, protocol authority, or execution authority.
204.10 Helix Council Register. The Helix Council Register shall identify membership and representation across the Public Authority Council, Industry and Operator Council, Academic and Research Council, Civil Society and Media Council, and Community and Indigenous Council. It shall record capacity classifications, representation limits, advisory voting semantics, consensus indications, dissent records, public statement limits, competition controls, safeguards controls, and cross-council coordination records.
204.11 Fellow Register. GCRI Canada shall maintain a Fellow Register identifying research fellows, visiting fellows, technical fellows, Academy fellows, public authority fellows where lawful, community fellows where appropriate, term, scope, stipend or support where applicable, research agreement, IP terms, publication terms, data / AI / cyber permissions, safeguards duties, conflicts, public statement limits, completion, suspension, termination, and closeout.
204.12 Advisor Register. GCRI Canada shall maintain an Advisor Register identifying advisors, advisory scope, appointment authority, term, conflicts, confidentiality obligations, IP and work product terms, data access, AI-use permissions, public statement limits, public authority capacity where applicable, sponsor or provider affiliations, independence status, offboarding, and records return.
204.13 Observer Register. GCRI Canada shall maintain an Observer Register identifying observers, including public authority observers, institutional observers, community observers, funder observers, provider observers, sponsor observers, academic observers, and controlled-room observers where authorized. The register shall identify access limits, confidentiality obligations, no-vote status, no-governance-control status, non-endorsement language, and public statement restrictions.
204.14 Contributor and Maintainer Register. GCRI Canada shall maintain a Contributor and Maintainer Register identifying developers, maintainers, technical contributors, open-source contributors, schema contributors, dataset contributors, model contributors, documentation contributors, dashboard contributors, and security contributors. The register shall identify contributor terms, license or assignment instrument, moral rights treatment where applicable, repository access, code review status, secure development obligations, vulnerability disclosure obligations, AI-use disclosures, export-control status, conflicts, access revocation, and offboarding.
204.15 Contractor, Consultant, Volunteer, and Seconded Personnel Register. GCRI Canada shall maintain registers for contractors, consultants, volunteers, and seconded personnel identifying engagement terms, role scope, authority limits, confidentiality obligations, IP terms, data / AI / cyber access, controlled-room permissions, public statement limits, conflict disclosures, workplace compliance, security training, performance status, offboarding, access revocation, and records return.
204.16 Register Access, Screening, Good Standing, Suspension, Termination, and Offboarding Fields. Each person or institution register shall include fields for screening, eligibility, sanctions review, export-control review where applicable, conflict review, independence review, good standing, restrictions, suspension, termination, resignation, reinstatement, appeal, offboarding, access revocation, credential revocation, confidentiality survival, IP survival, records return, and closeout. No person or institution shall retain access or public status after termination except as expressly recorded and lawful.
Section 205. Conflict, Recusal, Related-Party, Gifts, Hospitality, and Independence Registers
205.1 Conflict Register. GCRI Canada shall maintain a Conflict Register recording actual, potential, and perceived conflicts involving directors, officers, members, participants, delegates, council members, committee members, fellows, advisors, staff, contractors, volunteers, contributors, maintainers, sponsors, donors, funders, providers, hosts, public authorities, national companies, Project SPVs, investors, insurers, lenders, contractors, and partners. The register shall support fiduciary integrity, research integrity, evidence integrity, provider neutrality, sponsor non-control, public authority boundary discipline, finance-boundary discipline, and anti-capture controls.
205.2 Annual Conflict Declarations. Covered persons designated by the Board or policy shall submit annual conflict declarations. Annual declarations shall disclose financial interests, employment, consulting, advisory roles, board roles, investments, grant relationships, sponsorship relationships, provider relationships, public authority roles, university or laboratory affiliations, IP interests, data interests, AI or cyber interests, family or close personal interests, and other relationships that could affect judgment, access, outputs, claims, or institutional trust.
205.3 Event-Based Conflict Declarations. Covered persons shall submit event-based conflict declarations when a conflict arises or becomes known in relation to a specific decision, publication, evidence artifact, research project, technical release, public authority interface, finance-readiness input, sponsorship, grant, provider participation, controlled room, Council matter, committee matter, dispute, enforcement action, or Nexus interface. Event-based disclosure shall occur before participation in deliberation or decision wherever practicable.
205.4 Financial Conflict Records. Financial conflict records shall identify compensation, equity, options, carried interests, success fees, grants, donations, sponsorships, consulting fees, employment, investment interests, lender interests, insurer interests, revenue-sharing, procurement interests, vendor interests, IP royalties, and other financial relationships that may affect or appear to affect GCRI Canada’s decisions or outputs.
205.5 Institutional Conflict Records. Institutional conflict records shall identify roles, affiliations, loyalties, contractual relationships, public authority positions, board memberships, consortium roles, university or laboratory roles, provider relationships, sponsor relationships, donor relationships, host relationships, national company relationships, Project SPV relationships, investor relationships, insurer relationships, lender relationships, and partner relationships that may affect institutional judgment or role separation.
205.6 Research Conflict Records. Research conflict records shall identify sponsor influence, provider influence, funder influence, publication restrictions, data access dependencies, methodology control, authorship disputes, peer review conflicts, academic conflicts, student or supervisor conflicts, grant conflicts, IP conflicts, and any relationship that could affect research agenda, methods, conclusions, limitations, correction, or publication integrity.
205.7 Data / AI / Cyber Conflict Records. Data / AI / cyber conflict records shall identify relationships with data providers, AI providers, cloud providers, cybersecurity vendors, repository providers, model developers, tool vendors, processors, subprocessors, technical contributors, maintainers, security researchers, and others whose interests may affect access, security review, AI-use approval, incident response, public-safe release, or technical asset governance.
205.8 Public Authority Conflict Records. Public authority conflict records shall identify official roles, advisory roles, procurement roles, regulatory roles, public finance roles, emergency management roles, public infrastructure roles, public health roles, public safety roles, political roles, personal-capacity participation, and any relationship that could create public authority confusion, improper influence, procurement implication, regulatory implication, funding implication, or sovereign-obligation implication.
205.9 Sponsor, Donor, Provider, Host, National Company, SPV, Investor, Insurer, Lender, and Contractor Conflict Records. The Conflict Register shall record conflicts involving sponsors, donors, funders, providers, hosts, National Consortium Companies, Project SPVs, investors, insurers, lenders, contractors, and other enterprise-stack actors. Such records shall identify the affected decision, requested benefit, relationship intensity, aggregation risk, control risk, procurement risk, finance-readiness risk, certification risk, publication risk, and required mitigation.
205.10 Recusal Register. GCRI Canada shall maintain a Recusal Register recording required and voluntary recusals from deliberation, access, decision, drafting, review, publication, technical release, public authority interaction, finance-boundary matter, certification-boundary matter, procurement-sensitive matter, evidence review, research review, incident review, dispute, enforcement action, or appeal. Recusal records shall identify the matter, person, basis, scope, start date, end date, access restrictions, and participation limits.
205.11 Access Restriction Records. Where conflict, recusal, confidentiality, public authority sensitivity, finance sensitivity, cyber sensitivity, data sensitivity, protected knowledge, competition sensitivity, or investigation integrity requires access restriction, GCRI Canada shall record the restriction, scope, affected systems, affected records, duration, reviewer, approval, exception, and revocation. Access restrictions shall be enforceable through technical and procedural controls.
205.12 Related-Party Register. GCRI Canada shall maintain a Related-Party Register identifying transactions, arrangements, contracts, grants, donations, sponsorships, payments, reimbursements, employment, consulting, fellowships, procurement, IP transfers, licenses, data access, or benefits involving directors, officers, members, key personnel, related persons, affiliated entities, sponsors, donors, funders, providers, hosts, national companies, Project SPVs, or other related parties. Related-party matters shall be reviewed for fairness, reasonableness, legal compliance, conflicts, private benefit, inurement, and public-benefit alignment.
205.13 Gifts and Hospitality Register. GCRI Canada shall maintain a Gifts and Hospitality Register recording gifts, meals, travel, lodging, entertainment, event invitations, honoraria, speaking fees, discounts, benefits, tickets, access, or other hospitality offered to or by covered persons. The register shall identify value, source, recipient, purpose, approval, refusal, return, donation, or other disposition. Gifts and hospitality shall not be used to obtain access, influence, public authority reference, provider preference, finance-readiness implication, certification implication, procurement advantage, or research outcome.
205.14 Independence Register. GCRI Canada shall maintain an Independence Register recording independence determinations for directors, officers, committee members, council participants, reviewers, fellows, advisors, technical reviewers, peer reviewers, model reviewers, publication reviewers, and other roles requiring independence. The register shall identify criteria, disclosures reviewed, determination, restrictions, review date, and renewal requirement.
205.15 Cooling-Off and Revolving-Door Records. Where policy or decision requires cooling-off periods or revolving-door controls, GCRI Canada shall maintain records identifying prior roles, future roles, restricted matters, restriction period, access restrictions, public authority restrictions, provider or sponsor restrictions, procurement restrictions, finance-boundary restrictions, publication restrictions, and review dates.
205.16 Conflict Correction and Enforcement Records. GCRI Canada shall maintain records of conflict corrections, late disclosures, nondisclosures, breach determinations, access revocations, decision re-openings, publication corrections, public-safe clarifications, recusals imposed after the fact, sanctions, removals, terminations, appeals, reinstatements, and training or control improvements arising from conflict matters.
Section 206. Evidence, Methods, Ontology, Model, Dataset, Software, Public-Good Technical Asset, Publication, Correction, and Incident Registers
206.1 Evidence Register. GCRI Canada shall maintain an Evidence Register recording evidence artifacts accepted, rejected, quarantined, corrected, superseded, withdrawn, retired, or archived. The register shall identify source lineage, provenance, custody, timestamp, jurisdiction, permission, contributor, classification, confidence, uncertainty, limitations, public-safe status, affected Nexus interface, use restrictions, challenge status, correction path, and linked case ID.
206.2 Assurance and Evidence Pack Register. GCRI Canada shall maintain an Assurance and Evidence Pack Register recording evidence packs, assurance packs, proof-supporting packs, technical diligence packs, public-safe evidence summaries, controlled annexes, and related evidence bundles. Each entry shall identify pack owner, custodian, authority surface, evidence inventory, methods notes, confidence notes, limitation notes, public authority review, finance-boundary review, safeguards review, classification, expiry, review cycle, correction path, and downstream dependencies.
206.3 Method Register. GCRI Canada shall maintain a Method Register recording adopted, draft, experimental, restricted, public-safe, superseded, withdrawn, retired, and archived methods. The register shall identify method owner, custodian, steward, purpose, applicability, limitations, exclusions, dependencies, version, effective date, review cycle, public-safe status, controlled annexes, validation status, peer review status, correction history, and linked evidence or publication outputs.
206.4 Ontology and Controlled Vocabulary Register. GCRI Canada shall maintain an Ontology and Controlled Vocabulary Register recording controlled terms, definitions, taxonomies, semantic mappings, risk categories, evidence classifications, maturity concepts, public authority capacity terms, finance-boundary terms, certification-boundary terms, Nexus interface terms, localization variants, no-silent-meaning-shift controls, version history, correction history, and divergence logs.
206.5 Schema and Data Dictionary Register. GCRI Canada shall maintain a Schema and Data Dictionary Register recording schemas, data dictionaries, metadata profiles, APIs, controlled fields, validation rules, data classes, evidence classes, model records, inference records, observability records, public-safe dashboard fields, technical profiles, version history, compatibility status, and correction path.
206.6 Dataset Register. GCRI Canada shall maintain a Dataset Register recording datasets, derived datasets, synthetic datasets, public datasets, controlled datasets, restricted datasets, public authority datasets, community-protected datasets, Indigenous / local / territorial knowledge datasets, health-sensitive datasets, cyber-sensitive datasets, infrastructure-sensitive datasets, training datasets, evaluation datasets, benchmark datasets, retention status, deletion status, and access restrictions.
206.7 Model Register. GCRI Canada shall maintain a Model Register recording AI, machine learning, statistical, digital twin, simulation, generative, agentic, inference, embedded, third-party, open-source, fine-tuned, retrieval-augmented, and tool-chain models. The register shall identify model identity, provider, owner, version, permitted uses, prohibited uses, data class, risk class, evaluation status, known limitations, incident history, human review requirements, deployment status, suspension status, retirement status, and correction path.
206.8 Inference Record Register. GCRI Canada shall maintain an Inference Record Register for material AI outputs. Entries shall identify input classification, prompt or query record where lawful and appropriate, context sources, model identity, tool identity, execution environment, output classification, confidence notes, limitation notes, human reviewer, use decision, public-safe status, correction path, retention, redaction, and linked publication or decision record.
206.9 Compute Workload Register. GCRI Canada shall maintain a Compute Workload Register recording material compute workloads, including workload identifier, purpose, authority, data inputs, data classification, compute environment, jurisdiction, model or code identity, tool identity, execution time, output, output classification, limitations, reviewer, retention, deletion, correction path, and secure environment status.
206.10 Benchmark and Evaluation Register. GCRI Canada shall maintain a Benchmark and Evaluation Register recording benchmarks, evaluation harnesses, benchmark cards, evaluation results, test sets, gold vectors, negative tests, reproducibility results, model tournament results where applicable, limitation notes, confidence notes, sponsor or provider influence review, public-safe status, and correction history.
206.11 Software Register. GCRI Canada shall maintain a Software Register recording public-good software, internal software, restricted software, open-source projects, reference implementations, tools, scripts, dashboards, packages, services, repositories, dependencies, license status, version, release status, security review, SBOM status, vulnerability status, signing status, maintainer, access class, public-safe status, and deprecation status.
206.12 Public-Good Technical Asset Register. GCRI Canada shall maintain a Public-Good Technical Asset Register recording public-good technical assets, including software, schemas, APIs, SDKs, dashboards, data dictionaries, model cards, dataset cards, system cards, benchmark cards, reference architectures, technical baselines, interoperability profiles, test harnesses, gold vectors, negative tests, observability tools, verifiable compute artifacts, and public-safe intelligence methods. Each entry shall identify owner, steward, maintainer, license, classification, public-safe status, security status, IP status, data rights, export-control flag, limitations, correction path, and retirement status.
206.13 API, SDK, Dashboard, Test Harness, Gold Vector, Negative Test, and Reference Implementation Register. GCRI Canada shall maintain registers or register fields for APIs, SDKs, dashboards, test harnesses, gold vectors, negative tests, and reference implementations. Entries shall identify version, purpose, classification, method dependency, evidence dependency, security review, public-safe status, conformance-supporting status, no-certification boundary, release notes, known issues, rollback path, and correction path.
206.14 Publication Register. GCRI Canada shall maintain a Publication Register recording reports, whitepapers, public-safe summaries, technical notes, methods notes, evidence notes, dashboards, maps, datasets, software releases, websites, decks, media materials, social media outputs, public authority references, sponsor acknowledgments, provider references, finance-readiness references, disclaimers, publication dates, versions, approvals, redactions, controlled annexes, corrections, withdrawals, retractions, supersessions, and archive status.
206.15 Public-Safe Map and Dashboard Register. GCRI Canada shall maintain a Public-Safe Map and Dashboard Register identifying map or dashboard owner, data sources, update cadence, classification, public-safe review, infrastructure sensitivity, cyber sensitivity, protected knowledge review, public authority boundary review, finance-boundary review, limitation language, access controls, incident history, correction path, and withdrawal status.
206.16 Correction Register. GCRI Canada shall maintain a Correction Register recording corrections, clarifications, errata, public-safe correction notices, controlled correction notices, register corrections, evidence corrections, method corrections, research corrections, publication corrections, public authority corrections, finance-boundary corrections, certification-boundary corrections, procurement-boundary corrections, data / AI / cyber corrections, safeguards corrections, and downstream dependency remediation.
206.17 Supersession, Withdrawal, Retraction, Deprecation, Retirement, and Archive Register. GCRI Canada shall maintain a register for superseded, withdrawn, retracted, deprecated, retired, and archived records, outputs, methods, publications, technical assets, software releases, datasets, models, dashboards, maps, public claims, public authority references, and controlled annexes. The register shall identify reason, authority, date, replacement record, archive location, public-safe notice, controlled notice, access restrictions, and downstream dependency review.
206.18 Incident Register. GCRI Canada shall maintain an Incident Register recording legal, governance, research integrity, evidence, methods, data, privacy, AI, cyber, public authority, finance-boundary, certification-boundary, procurement-boundary, sponsor, provider, safeguards, protected knowledge, publication, workplace, retaliation, and continuity incidents. Entries shall identify severity, case ID, owner, containment, investigation, findings, corrective action, notification, correction, closeout, and lessons learned.
206.19 Register Classification, Custody, and Access Rules. All registers described in this Section shall be classified, assigned custodians, access-controlled, versioned, auditable, correctionable, retained, and protected according to this Bylaw and applicable policy. No register entry shall be used to imply certification, recognition, finance-readiness, procurement approval, public authority approval, public warning, emergency command, provider preference, or execution authority unless separately and lawfully authorized, and no such authority is created by default.
Section 207. Sponsorship, Grant, Donation, Restricted Funds, In-Kind Contribution, and Donor Registers
207.1 Sponsorship Register. GCRI Canada shall maintain a Sponsorship Register recording all sponsorship proposals, accepted sponsorships, refused sponsorships, restricted sponsorships, terminated sponsorships, sponsor identities, sponsor benefits, sponsor acknowledgments, sponsor restrictions, sponsor-related conflicts, sponsor concentration, public claims, publication review, and anti-capture controls. The Sponsorship Register shall state that sponsorship does not create control, recognition, certification, finance-readiness influence, provider preference, procurement advantage, public authority access, research finding rights, publication veto rights, or Nexus interface authority.
207.2 Grant Register. GCRI Canada shall maintain a Grant Register recording grant applications, grant agreements, grantor identity, purpose, budget, restrictions, deliverables, reporting obligations, data rights, IP terms, publication rights, public authority conditions, community safeguards, cross-border conditions, sanctions and export-control review, financial tracking, amendments, closeout, and return or reallocation obligations.
207.3 Donation Register. GCRI Canada shall maintain a Donation Register recording donors, donation amounts, dates, restrictions, conditions, acknowledgment terms, tax treatment, receipt status where lawful, refusal or return decisions, conflict review, related-party status, anti-capture analysis, and public-benefit use. Donation records shall preserve non-charitable payment treatment unless charitable status is lawfully obtained and donation receipting is lawfully authorized.
207.4 Donor Register. GCRI Canada shall maintain a Donor Register identifying donors, donor categories, related persons, affiliated entities, aggregation status, cumulative support, restrictions, conflicts, screening status, acknowledgment permissions, privacy preferences, communication permissions, refusal history, return history, and influence cap status.
207.5 Funder Register. GCRI Canada shall maintain a Funder Register identifying funders, grantors, public funders, philanthropic funders, institutional funders, program funders, restricted funders, underwriting funders, and public-good support funders. The register shall identify conditions, reporting obligations, independence protections, public claims restrictions, data / AI / cyber implications, public authority implications, and role-separation constraints.
207.6 Restricted Funds Register. GCRI Canada shall maintain a Restricted Funds Register recording all restricted funds, restrictions, permitted uses, prohibited uses, fund balance, expenditure records, budget allocation, reporting obligations, donor or grantor conditions, Board approvals, amendments, closeout, return, reallocation, or cy-près-style handling where lawful and appropriate. Restricted funds shall not be used in a manner inconsistent with public-benefit purpose, non-execution, legal compliance, data / AI / cyber controls, safeguards, or sponsor non-control.
207.7 Unrestricted Support Register. GCRI Canada shall maintain an Unrestricted Support Register recording unrestricted donations, unrestricted grants, unrestricted sponsorships, operating support, subscriptions, fees, cost-recovery support, and general contributions. Unrestricted support shall remain subject to public-benefit use, nonprofit purpose, non-distribution, no private inurement, anti-capture, conflict review, and public-safe acknowledgment controls.
207.8 In-Kind Contribution Register. GCRI Canada shall maintain an In-Kind Contribution Register recording equipment, compute credits, cloud credits, software licenses, data room tools, facilities, staff time, sensors, AI-RAN equipment, O-RAN equipment, connectivity, cybersecurity tools, hardware, datasets, technical infrastructure, laboratory access, or other non-cash contributions. Entries shall identify valuation, ownership, custody, use rights, maintenance, support, data review, cyber review, IP review, export-control review, sanctions review, public claims review, and closeout.
207.9 Valuation Records. GCRI Canada shall maintain valuation records for in-kind contributions, restricted support, non-cash benefits, discounted services, donated licenses, compute credits, facility access, equipment, technical infrastructure, and other support where valuation is required for accounting, tax, public reporting, restricted fund tracking, anti-capture review, or sponsor benefit analysis. Valuations shall be reasonable, documented, and not inflated to create undue influence or public claim advantage.
207.10 Support Acceptance Records. Support acceptance records shall identify the support type, source, lawful basis, public-benefit rationale, nonprofit and tax treatment, restrictions, conditions, conflicts, related-party status, sanctions screening, export-control screening, data / AI / cyber implications, public authority implications, sponsor or donor influence analysis, provider neutrality analysis, Board approval where required, and acceptance conditions.
207.11 Support Conditions Records. Conditions attached to sponsorships, grants, donations, restricted funds, in-kind contributions, subscriptions, or other support shall be recorded. Conditions shall be rejected, revised, or restricted where they would create sponsor control, donor control, provider preference, public authority access purchase, research finding purchase, publication veto, suppression right, standards outcome purchase, finance-readiness purchase, certification purchase, procurement advantage, recognition purchase, private inurement, or mission drift.
207.12 Sponsor Benefit Records. Sponsor benefits shall be recorded in a benefit schedule identifying visibility, acknowledgment, logo placement, speaking opportunity, training seats, controlled-room access, preview windows, advisory participation, reporting rights, or other benefits. Sponsor benefit records shall include non-endorsement language, no-control language, no-outcome-purchase language, public authority boundary language, provider neutrality language, and correction path.
207.13 Acknowledgment Records. Acknowledgment records shall identify approved public language, logo use, naming references, donor recognition, sponsor recognition, funder recognition, grantor recognition, in-kind acknowledgment, publication acknowledgment, website acknowledgment, event acknowledgment, and non-endorsement language. No acknowledgment shall imply certification, recognition, public authority approval, finance-readiness, procurement advantage, provider preference, or sponsor control.
207.14 Influence Cap and Aggregation Records. GCRI Canada shall maintain influence cap and aggregation records identifying concentration of support by sponsors, donors, funders, providers, related parties, affiliates, controlled entities, sponsored seats, in-kind dependencies, cloud dependencies, compute dependencies, AI provider dependencies, cybersecurity dependencies, repository dependencies, and host dependencies. Aggregation records shall support capture review, diversification, recusal, access restriction, Board review, refusal, return, or termination.
207.15 Conflict and Related-Party Funding Records. Funding records shall identify conflicts and related-party funding arrangements, including support from directors, officers, members, advisors, sponsors, providers, hosts, national companies, Project SPVs, investors, insurers, lenders, contractors, public authorities, universities, laboratories, or affiliated entities. Such records shall support fairness review, reasonableness review, private benefit review, recusal, public-safe disclosure, and Board oversight.
207.16 Refusal, Return, Restriction, Termination, and Closeout Records. GCRI Canada shall maintain records of refused support, returned support, restricted support, terminated support, closeout of grants, closeout of sponsorships, closeout of donations, closeout of in-kind contributions, unresolved conditions, disputed funds, public corrections, and donor or sponsor communications. Closeout records shall preserve public-benefit use, legal compliance, anti-capture discipline, and correctionability.
Section 208. Public Authority Capacity, Reference Approval, Data Contribution, Room Participation, and Non-Endorsement Registers
208.1 Public Authority Capacity Register. GCRI Canada shall maintain a Public Authority Capacity Register identifying public authorities and public-sector participants, their capacity classification, authority basis, participation scope, access rights, public reference permissions, data contribution status, controlled-room participation, and non-endorsement requirements. The register shall prevent public authority confusion, implied delegation, public warning implication, procurement implication, funding implication, regulatory implication, public finance implication, and sovereign-obligation implication.
208.2 Official-Capacity Records. Official-capacity records shall identify the public authority, ministry, agency, department, municipality, Crown entity, utility, public institution, regulator, public infrastructure operator, public health body, public safety body, emergency management body, or other public body represented; the individual participant; authority evidence; scope of authority; limits; term; attribution permissions; and approved public language.
208.3 Observer Records. Observer records shall identify public authority observers and other observers admitted for learning, observation, or technical understanding only. Observer records shall include access limits, confidentiality obligations, non-attribution terms where applicable, no-vote status, no-governance-control status, no-endorsement language, no-adoption language, no-procurement language, no-funding language, no-regulatory-approval language, no-public-warning language, and no-sovereign-obligation language.
208.4 Regulator-Listening Records. Regulator-listening records shall identify participants attending in a listening or learning capacity without issuing regulatory guidance, safe harbor, permit, compliance determination, enforcement position, official legal interpretation, or endorsement. Records shall include confidentiality terms, non-attribution terms where applicable, competition controls, public reference limits, and correction path.
208.5 Public Finance Reader Records. Public finance reader records shall identify public finance bodies, MDB / DFI participants, budget actors, grant actors, public guarantee actors, sovereign finance actors, or other public finance readers participating for diligence literacy or evidence understanding only. Records shall state that participation does not create grant approval, budget allocation, appropriation approval, MDB approval, DFI approval, public guarantee, public credit approval, sovereign obligation, public finance commitment, investment recommendation, or finance-readiness determination by GCRI Canada.
208.6 Emergency-Management Participant Records. Emergency-management participant records shall identify emergency management bodies and participants involved in scenario, simulation, tabletop, exercise, observability, after-action, learning, or evidence review activities. Records shall state that participation does not create incident command, dispatch authority, evacuation authority, public warning authority, operational resource direction, responder command, or substitution for emergency management organizations.
208.7 Public Infrastructure Operator Records. Public infrastructure operator records shall identify utilities, ports, telecom operators, energy systems, water systems, food systems, health systems, public works, transportation systems, cyber systems, and other infrastructure operators participating in public authority or public-interest contexts. Records shall identify infrastructure-sensitive data controls, public-safe handling, operational boundary, no procurement implication, no adoption implication, no performance warranty, no resilience guarantee, and correction path.
208.8 Public Health, Public Safety, Public Works, Utility, Port, Telecom, Energy, Water, Food, Health, Cyber, and Infrastructure Participant Records. GCRI Canada shall maintain sector-specific participant records for public health, public safety, public works, utility, port, telecom, energy, water, food, health, cyber, and infrastructure participants. Such records shall identify sector-specific sensitivity, data restrictions, publication restrictions, emergency-command boundaries, procurement boundaries, regulatory boundaries, public-safe mapping requirements, and public authority reference controls.
208.9 Public Authority Reference Approval Register. GCRI Canada shall maintain a Public Authority Reference Approval Register for public authority names, logos, titles, agencies, departments, ministries, municipalities, jurisdictions, quotes, photographs, recordings, attendance references, data contribution references, room participation references, and public materials. No public authority reference shall be used externally unless approved or otherwise permitted by a lawful and recorded basis.
208.10 Public Authority Logo, Name, Title, Quote, Photograph, Attendance, and Agency Reference Records. Public authority reference records shall identify the specific reference, proposed use, medium, duration, approval basis, approving person where applicable, attribution requirements, non-endorsement statement, required disclaimers, publication class, withdrawal rights, correction path, and downstream materials affected by the reference.
208.11 Public Authority Data Contribution Register. GCRI Canada shall maintain a Public Authority Data Contribution Register recording public authority data sources, contributor identity, capacity, lawful basis, permitted use, prohibited use, AI-use restrictions, publication restrictions, transfer restrictions, retention, deletion, classification, confidentiality, cybersecurity requirements, review rights, correction rights, withdrawal rights, and public-safe release conditions.
208.12 Public Authority Room Participation Register. GCRI Canada shall maintain a Public Authority Room Participation Register recording public authority participation in controlled rooms, data rooms, evidence rooms, public authority rooms, clean rooms, capital-reader rooms, no-download rooms, simulations, exercises, and learning rooms. Entries shall identify access rights, room rules, confidentiality, data restrictions, competition rules, public authority boundary language, finance-boundary language, and closeout.
208.13 Public Authority Non-Endorsement Register. GCRI Canada shall maintain a Public Authority Non-Endorsement Register recording required non-endorsement language, approved disclaimers, affected public materials, public authority objections, corrections, clarifications, withdrawals, and updates. The register shall make clear that public authority participation, attendance, data contribution, quote, photograph, logo use, or reference does not imply endorsement, adoption, funding, procurement, regulation, public warning, command, public finance approval, or sovereign obligation.
208.14 Public Authority Correction, Withdrawal, and Clarification Records. GCRI Canada shall maintain records of public authority corrections, withdrawals, clarifications, takedowns, changed capacity classifications, withdrawn permissions, outdated references, public authority objections, public-safe notices, controlled notices, downstream materials review, sponsor or provider correction, and media correction where required.
Section 209. Provider, Vendor, Contractor, Host, Partner, and Third-Party Risk Registers
209.1 Provider Register. GCRI Canada shall maintain a Provider Register identifying qualified enterprise providers, technology providers, AI providers, AI-RAN providers, O-RAN providers, DePIN providers, telecom providers, sensor providers, cybersecurity providers, cloud providers, software providers, data providers, dashboard providers, integration providers, and other providers participating in GCRI Canada activities. The register shall identify participation purpose, contract basis, contribution terms, conflicts, independence status, public claims limits, provider neutrality, no preferred provider status, no procurement advantage, and correction path.
209.2 Vendor Register. GCRI Canada shall maintain a Vendor Register identifying vendors supplying goods, services, software, cloud services, professional services, facilities, equipment, connectivity, data tools, security tools, collaboration systems, event services, translation, accessibility, legal, accounting, consulting, or other services. Vendor entries shall identify procurement basis, contract status, due diligence, security review, privacy review, sanctions screening, export-control review, conflict review, insurance requirements, access rights, and offboarding.
209.3 Contractor Register. GCRI Canada shall maintain a Contractor Register identifying contractors and consultants, role scope, engagement terms, authority limits, compensation, tax and worker classification status, confidentiality, IP obligations, data / AI / cyber access, controlled-room access, public claims limits, conflicts, performance, termination, and offboarding.
209.4 Host Register. GCRI Canada shall maintain a Host Register identifying host institutions, host sites, host facilities, host systems, host communities, host public authority contexts, host safety obligations, host data contributions, host cybersecurity posture, host access rules, host public reference permissions, host activation agreements, and host closeout records. Host status shall not create public authority delegation, procurement preference, provider preference, asset transfer, operational control, or GCRI Canada execution authority.
209.5 Partner Register. GCRI Canada shall maintain a Partner Register identifying partners, collaboration type, interface agreement, MoU, research agreement, data-sharing agreement, public-good technical asset agreement, public authority interface agreement, sponsorship agreement, provider agreement, university agreement, community agreement, or Nexus interface agreement. Partner entries shall identify no-merger, no-agency, no-shared-liability, non-execution, data / AI / cyber, IP, confidentiality, safeguards, public claims, and correction clauses.
209.6 Cloud Provider Register. GCRI Canada shall maintain a Cloud Provider Register identifying cloud providers, service regions, data localization, security controls, encryption, key management, logging, access controls, subcontractors, data processor status, AI-use restrictions, public authority data handling, community-protected data restrictions, incident notification terms, exit readiness, and concentration risk.
209.7 AI Provider Register. GCRI Canada shall maintain an AI Provider Register identifying AI providers, models, services, training restrictions, data-use terms, retention terms, privacy terms, security controls, cross-border processing, model improvement settings, human review requirements, hallucination controls, incident response, public-safe restrictions, and prohibited uses.
209.8 Data Processor Register. GCRI Canada shall maintain a Data Processor Register identifying processors and subprocessors, processing purpose, data categories, lawful basis, contract terms, privacy addendum, security addendum, transfer mechanism, audit rights, incident notification, deletion or return obligations, retention, and exit readiness.
209.9 Critical Supplier Register. GCRI Canada shall maintain a Critical Supplier Register identifying suppliers whose failure could materially affect governance continuity, evidence systems, data / AI / cyber controls, repositories, public-good technical assets, controlled rooms, public authority interfaces, publications, financial operations, or Nexus interfaces. The register shall identify dependency risk, concentration risk, backup arrangements, exit plans, continuity plans, and review cycle.
209.10 Third-Party Risk Register. GCRI Canada shall maintain a Third-Party Risk Register consolidating legal, financial, operational, security, privacy, AI, cyber, sanctions, export-control, public authority, finance-boundary, certification-boundary, procurement, safeguards, IP, reputational, continuity, and capture risks associated with providers, vendors, contractors, hosts, partners, cloud providers, AI providers, data processors, public authorities, sponsors, donors, funders, and other third parties.
209.11 Due Diligence Records. Due diligence records shall include identity verification, corporate status, beneficial ownership or control where applicable, sanctions screening, export-control review, financial standing where relevant, security posture, privacy posture, references, qualifications, conflicts, related-party status, insurance, litigation or misconduct history where appropriate, human rights considerations, cybersecurity history, and public claims history.
209.12 Security Review Records. Security review records shall identify system access, data access, infrastructure sensitivity, cyber controls, identity and access management, encryption, logging, vulnerability posture, secure development, incident history, penetration testing where applicable, SOC or equivalent reports where available, repository access, credentials, key management, and exit controls.
209.13 Privacy Review Records. Privacy review records shall identify data categories, personal information, sensitive personal information, health data, public authority data, community-protected data, Indigenous / local / territorial knowledge, lawful basis, purpose limitation, minimization, transfer, retention, deletion, rights handling, breach notification, processor terms, and privacy impact review where required.
209.14 Sanctions and Export-Control Screening Records. GCRI Canada shall maintain sanctions and export-control screening records for providers, vendors, contractors, hosts, partners, public authorities where appropriate, sponsors, donors, funders, participants, contributors, controlled-room participants, and technical access recipients. Screening records shall identify jurisdiction, restricted-party status, controlled technology, sensitive AI, AI-RAN, O-RAN, cyber tools, cryptography, geospatial data, Earth observation, dual-use items, public release risk, and access restrictions.
209.15 Conflict and Independence Records. Third-party registers shall include conflict and independence records identifying provider conflicts, sponsor conflicts, host conflicts, donor conflicts, public authority conflicts, related-party status, market conflicts, research conflicts, data conflicts, AI conflicts, cyber conflicts, IP conflicts, and measures taken to preserve independence, neutrality, and public-benefit purpose.
209.16 Access, Credential, Offboarding, Incident, and Closeout Records. GCRI Canada shall maintain records of third-party access, credentials, keys, tokens, permissions, controlled-room admission, repository access, cloud access, AI tool access, data access, access reviews, revocations, offboarding, incident response, contract closeout, data return or deletion, records return, confidentiality survival, IP survival, and final closeout.
Section 210. Gazette and Authoritative Notice Stream
210.1 Gazette Purpose. GCRI Canada shall maintain a Gazette or Gazette-equivalent authoritative notice stream to provide controlled, traceable, versioned, and authoritative notice of governance-significant acts. The Gazette shall support validity-by-record, correctionability, institutional memory, public-safe transparency, legal compliance, stakeholder notice, repository discipline, and prevention of silent governance drift.
210.2 Gazette or Gazette-Equivalent Notice Stream. The Gazette may be implemented as a formal Gazette, official notice stream, repository notice page, corporate register extract, controlled notice system, public-safe publication log, internal governance notice stream, or other Board-approved mechanism. The system shall be authoritative only to the extent approved by the Board and shall identify which notices are public, public-safe, controlled, restricted, internal, archived, superseded, or withdrawn.
210.3 Public Gazette. The Public Gazette may include public-safe notices of Bylaw adoption, major amendments, public-facing policies, public-safe annual reports, public-good software releases, public technical baselines, public-safe corrections, public-safe withdrawals, public-safe supersessions, public-safe public authority clarifications, public notices of major institutional changes, and other public-safe governance-significant acts approved for public release.
210.4 Controlled Gazette. The Controlled Gazette may include notices that are not appropriate for public release because they involve confidential governance matters, public authority data, cyber-sensitive matters, infrastructure-sensitive information, finance-sensitive evidence, sponsor or provider confidential information, protected knowledge, personal information, privileged material, investigations, incidents, controlled rooms, or restricted technical assets. Controlled Gazette access shall be limited according to classification.
210.5 Internal Notice Stream. The Internal Notice Stream may include notices for directors, officers, staff, contractors, committees, councils, fellows, advisors, contributors, controlled-room participants, and other internal or role-based audiences. Internal notice shall not create public meaning unless expressly approved for public release.
210.6 Notices of Adoption. The Gazette shall record notices of adoption for bylaws, policies, schedules, annexes, committee charters, council charters, methods, technical baselines, public-good software releases, controlled vocabularies, major registers, major public authority protocols, major data / AI / cyber policies, safeguards policies, and other adopted instruments where notice is required or appropriate.
210.7 Notices of Amendment. The Gazette shall record notices of amendments to the Bylaw, Articles where appropriate, policies, schedules, annexes, charters, methods, technical baselines, controlled vocabularies, public materials, public-safe summaries, technical assets, and other instruments. Amendment notices shall identify version, effective date, superseded version, authority, repository location, and transition provisions where applicable.
210.8 Notices of Repeal. The Gazette shall record notices of repeal where a bylaw provision, policy, schedule, annex, charter, method, publication, technical asset, register field, protocol, or other instrument is repealed by competent authority. Repeal notices shall identify continuing obligations, survival provisions, transition rules, and archival location.
210.9 Notices of Correction. The Gazette shall record notices of correction where a public or controlled record, publication, method, evidence artifact, register entry, public authority reference, finance-boundary reference, certification-related claim, procurement-related claim, dashboard, map, software release, technical baseline, or public-safe summary is corrected. Correction notices shall preserve historical traceability and shall not conceal material error.
210.10 Notices of Supersession. The Gazette shall record notices of supersession where a new version replaces a prior version of a Bylaw, policy, method, publication, technical baseline, software release, controlled vocabulary, dataset, model record, dashboard, map, public-safe summary, or other output. Supersession notices shall identify the superseding record, superseded record, effective date, continued reliance rules, and downstream dependencies.
210.11 Notices of Withdrawal. The Gazette shall record notices of withdrawal where an output, record, publication, method, dataset, dashboard, map, technical asset, public authority reference, sponsor acknowledgment, provider reference, or claim is withdrawn. Withdrawal notices shall identify whether the withdrawal is due to error, risk, supersession, authority defect, public authority issue, finance overclaim, certification overclaim, procurement overclaim, data / AI / cyber issue, safeguards issue, or other cause.
210.12 Notices of Retraction. The Gazette shall record notices of retraction where a publication, report, research output, technical claim, public-safe summary, dashboard, map, dataset, or other public or controlled output is materially unreliable, unsupported, unsafe, unauthorized, misleading, or otherwise inappropriate for continued reliance. Retraction notices shall identify the reason, affected outputs, downstream dependencies, replacement record where any, and non-reliance language.
210.13 Notices of Appointment. The Gazette or applicable notice stream shall record notices of appointment where appropriate for directors, officers, committee chairs, committee members, council chairs, council members, fellows, advisors, custodians, register owners, designated reviewers, authorized spokespersons, and other roles. Appointment notices shall identify authority, effective date, term, scope, and limits.
210.14 Notices of Delegation. The Gazette or controlled notice stream shall record material delegations of authority, including signing authority, spending authority, contracting authority, publication authority, data access authority, AI-use authority, controlled-room authority, public authority interface authority, emergency authority, and technical release authority. Delegation notices shall identify delegator, delegate, scope, limits, term, conditions, revocation rights, and authority basis.
210.15 Notices of Suspension. The Gazette or controlled notice stream shall record suspensions where required or appropriate, including suspension of members, participants, fellows, advisors, contributors, providers, sponsors, controlled-room access, data access, AI-use permissions, technical assets, software releases, methods, publications, dashboards, maps, public claims, public authority references, committees, councils, programs, or Nexus interfaces. Suspension notices shall identify scope, reason, duration, review path, and correction path.
210.16 Notices of Termination. The Gazette or controlled notice stream shall record terminations where required or appropriate, including termination of participation, membership, fellowships, advisory roles, contributor access, provider participation, sponsorship, grants, contracts, controlled-room access, programs, committees, councils, publications, technical assets, or interfaces. Termination notices shall identify effective date, surviving obligations, records return, data disposition, confidentiality, IP, access revocation, and closeout.
210.17 Notices of Public Authority Correction. The Gazette shall record public authority correction notices where public authority participation, capacity, name, logo, quote, title, agency, attendance, photograph, data contribution, endorsement status, procurement implication, funding implication, regulatory implication, public warning implication, or public finance implication has been misstated, misunderstood, withdrawn, changed, or corrected.
210.18 Notices of Publication Status Change. The Gazette shall record publication status changes, including public release, controlled release, embargo, classification change, reclassification, downgrade, upgrade, redaction, public-safe summary release, controlled annex creation, withdrawal, retraction, supersession, archival, or retirement. Publication status notices shall identify affected outputs, effective date, access status, and reliance limitations.
210.19 Notice Classification, Redaction, and Access Rules. Each Gazette notice shall be classified before issuance. Public notices shall be public-safe and shall not disclose personal information, protected knowledge, public authority sensitive data, cyber-sensitive information, infrastructure-sensitive information, privileged information, finance-sensitive evidence, commercially sensitive information, or unsafe operational details unless lawful, necessary, approved, and safeguarded. Controlled notices shall identify access class, redaction rules, recipients, confidentiality obligations, and redistribution limits.
210.20 Gazette Records. GCRI Canada shall maintain Gazette records, including notice text, case ID, authority basis, issuing person, approval record, publication class, access class, date, effective date, affected records, repository link, supersession link, correction link, redaction record, recipient list where controlled, proof of publication or delivery, withdrawal status, archival status, and retention period. Gazette records shall be maintained as authoritative evidence of notice and shall support institutional continuity, auditability, correctionability, and public-safe transparency.
Section 211. Publication Classes, Access Classes, Handling Classes, Competition Sensitivity Classes, Data Sensitivity Classes, and Security Classes
211.1 Classification Architecture. GCRI Canada shall maintain a classification architecture for all records, registers, publications, datasets, models, software, dashboards, maps, evidence packs, methods, controlled vocabularies, public authority materials, sponsorship materials, provider materials, finance-boundary materials, council materials, Board materials, committee materials, controlled-room materials, and Nexus interface materials. The classification architecture shall be designed to preserve public-benefit transparency where safe, restrict sensitive materials where necessary, prevent unlawful or unsafe disclosure, maintain evidence and methods integrity, protect personal information, safeguard community and protected knowledge, preserve public authority boundaries, protect cyber and infrastructure-sensitive information, prevent competition-law exposure, and ensure that no publication, access, or handling class is used to imply recognition, certification, finance-readiness, procurement approval, public authority approval, emergency command, public warning, provider preference, or execution authority.
211.2 Publication Class P0: Public. Publication Class P0 shall mean materials approved for unrestricted public release. P0 materials may include public-facing bylaws, public-safe policies, approved public reports, public-safe technical notes, public-good software releases, public technical baselines, approved public announcements, public Gazette notices, and other materials determined by competent authority to be safe for public release. P0 classification shall require confirmation that the material does not disclose restricted personal information, privileged information, cyber-sensitive details, infrastructure-sensitive details, protected knowledge, public authority-sensitive information, finance-sensitive information, confidential sponsor or provider information, or unsafe operational details.
211.3 Publication Class P1: Public-Safe Summary. Publication Class P1 shall mean a public-safe summary, abstract, map, dashboard, notice, deck, report, or explanation derived from controlled or restricted material but prepared for public understanding without exposing sensitive inputs, unsafe details, protected knowledge, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, personal information, confidential material, or regulated-activity implications. P1 materials shall preserve meaning without overclaiming, shall disclose limitations where appropriate, and shall include non-endorsement, no-certification, no-finance-readiness, no-procurement, no-public-warning, no-emergency-command, and no-public-authority-approval language where required.
211.4 Publication Class P2: Controlled. Publication Class P2 shall mean materials available only to approved audiences under access controls, confidentiality obligations, use restrictions, room rules, repository controls, data / AI / cyber controls, or public authority terms. P2 materials may include controlled evidence packs, controlled methods notes, controlled annexes, working drafts, public authority materials, finance-boundary review materials, sponsor or provider materials, security-reviewed technical materials, controlled data summaries, and consultation drafts. P2 classification shall not authorize redistribution, public quotation, external posting, AI ingestion, model training, derivative publication, or use for public claims unless separately approved.
211.5 Publication Class P3: Restricted / Confidential / Controlled Room. Publication Class P3 shall mean restricted, confidential, privileged, protected, controlled-room, counsel-only, Board-only, security-sensitive, infrastructure-sensitive, public authority-sensitive, protected-knowledge, data-room, clean-room, no-download, or otherwise highly restricted materials. P3 materials may include legal advice, incident files, unresolved disputes, raw sensitive evidence, personal information, protected community knowledge, Indigenous / local / territorial knowledge, cyber-sensitive materials, vulnerability information, infrastructure-sensitive maps, public authority non-public data, finance-sensitive diligence materials, competition-sensitive information, and restricted technical artifacts. P3 materials shall be handled only by authorized persons and shall not be copied, exported, summarized, quoted, uploaded to unapproved AI systems, or disclosed except under lawful authority and recorded controls.
211.6 Access Classes. GCRI Canada shall maintain access classes that define who may view, use, edit, approve, export, publish, archive, or delete a record. Access classes may include public, public-safe, internal, controlled, restricted, Board-only, officer-only, committee-only, council-only, staff-only, counsel-only, auditor-only, reviewer-only, public authority-limited, sponsor-limited, provider-limited, data-room, controlled-room, clean-room, no-download, safeguards-limited, cyber-limited, finance-boundary-limited, and protected-knowledge-limited. Access shall be granted by role, purpose, authority record, need-to-know, confidentiality status, conflict status, and security clearance where applicable.
211.7 Handling Classes. GCRI Canada shall maintain handling classes for storage, copying, transmission, citation, AI use, repository placement, download, printing, screenshotting, forwarding, retention, deletion, redaction, public-safe transformation, and cross-border transfer. Handling classes shall specify whether materials may be emailed, stored in cloud systems, placed in repositories, displayed in meetings, included in Board packs, used in AI-assisted workflows, shared with public authorities, shared with sponsors, shared with providers, shared with Nexus institutions, or released publicly.
211.8 Competition Sensitivity Classes. Competition sensitivity classes shall be used for materials involving market actors, vendors, providers, operators, suppliers, sponsors, investors, insurers, lenders, price information, cost information, capacity information, procurement information, bid information, customer information, supplier information, roadmaps, commercially sensitive benchmarks, provider comparisons, or market allocation risks. Competition-sensitive materials shall be subject to clean-room procedures, aggregation, de-identification, agenda controls, stop-meeting authority, restricted minutes, antitrust counsel review where required, and exclusion of improper market coordination.
211.9 Data Sensitivity Classes. Data sensitivity classes shall identify whether data is public, public-safe, internal, controlled, restricted, personal, sensitive personal, health-sensitive, public authority-sensitive, community-protected, Indigenous / local / territorial knowledge, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, export-controlled, sanctions-sensitive, privileged, confidential, or otherwise restricted. Data sensitivity classification shall control access, processing, AI use, retention, deletion, transfer, publication, and breach response.
211.10 Security Classes. Security classes shall identify the security posture required for records, systems, repositories, rooms, models, datasets, software, dashboards, maps, credentials, keys, tokens, APIs, logs, and technical artifacts. Security classes may require encryption, multifactor authentication, restricted repositories, key management, immutable logging, tamper-evident audit trails, no-download controls, vulnerability review, security review, incident monitoring, penetration testing where appropriate, and secure deletion.
211.11 Public Authority Sensitivity Classes. Public authority sensitivity classes shall be applied to materials involving ministries, agencies, departments, municipalities, regulators, Crown entities, public finance bodies, emergency management bodies, public health bodies, public safety bodies, public infrastructure operators, utilities, ports, telecom systems, energy systems, water systems, food systems, cyber systems, or other public bodies. Such classification shall preserve capacity classification, non-endorsement, no-delegation, no-public-warning, no-emergency-command, no-procurement-approval, no-regulatory-approval, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation boundaries.
211.12 Finance Sensitivity Classes. Finance sensitivity classes shall be applied to materials involving finance-readiness inputs, capital-readability, public finance readers, investors, insurers, lenders, underwriters, ratings, grants, public finance, guarantees, securities, investment discussions, revenue projections, risk allocations, insurance implications, financial exposure, project SPVs, National Consortium Companies, or capital routing. Finance-sensitive materials shall not be treated as investment advice, securities advice, insurance underwriting, lending advice, rating, public finance approval, capital placement, investor matchmaking, or finance-readiness determination by GCRI Canada.
211.13 Infrastructure Sensitivity Classes. Infrastructure sensitivity classes shall be applied to materials involving critical infrastructure, ports, telecom, AI-RAN, O-RAN, private wireless, energy, water, food, health, public works, transport, cyber systems, compute facilities, sensors, geospatial data, Earth observation, public-safe maps, digital twins, system vulnerabilities, operational dependencies, degraded-mode analysis, or resilience posture. Infrastructure-sensitive materials shall be handled to avoid enabling harm, misuse, targeting, manipulation, or public panic.
211.14 Cyber Sensitivity Classes. Cyber sensitivity classes shall be applied to vulnerabilities, exploits, incident records, system diagrams, access credentials, tokens, keys, logs, repository information, security architecture, penetration test results, cloud configurations, AI toolchain security, supply-chain security, SBOMs, dependency risks, and other materials that could affect confidentiality, integrity, availability, authenticity, or resilience. Cyber-sensitive materials shall be subject to restricted access, need-to-know review, coordinated disclosure where applicable, incident response controls, and secure retention.
211.15 Community-Protected and Protected Knowledge Classes. Community-protected and protected knowledge classes shall be applied to materials involving Indigenous knowledge, local knowledge, territorial knowledge, community-sensitive data, cultural information, sacred sites, community vulnerability, livelihood information, environmental knowledge, health-sensitive community information, protected participation, or other knowledge requiring consent, custodial respect, contextual limitation, non-extraction, or restricted publication. Such materials shall not be publicized, abstracted, modeled, mapped, commercialized, or transferred without lawful authority and safeguards.
211.16 Classification Assignment. Classification shall be assigned at creation, intake, contribution, receipt, drafting, registration, publication, repository entry, room admission, or interface transfer. The assigning person shall use the most restrictive reasonable classification where uncertainty exists. Classification shall be recorded with date, owner, custodian, basis, applicable restrictions, review cycle, and any required approvals.
211.17 Classification Review. Classifications shall be reviewed when materials are revised, corrected, superseded, prepared for publication, moved between repositories, transferred across borders, shared with public authorities, shared with sponsors or providers, used in AI systems, included in evidence packs, placed into controlled rooms, or relied upon for public claims. Review shall consider legal, privacy, cyber, public authority, finance, competition, infrastructure, community safeguards, and protected knowledge risk.
211.18 Reclassification, Downgrade, Upgrade, and Public-Safe Release. Materials may be reclassified, downgraded, upgraded, or transformed into public-safe summaries only by authorized process. Downgrade shall require confirmation that sensitivity has expired, been removed, been redacted, been aggregated, been consented to, or otherwise been lawfully reduced. Upgrade shall occur immediately where new risk, error, sensitivity, protected knowledge, legal issue, public authority concern, cyber issue, finance-boundary concern, or unsafe disclosure risk is identified.
211.19 Classification Records. GCRI Canada shall maintain classification records identifying class assignment, assigning person, owner, custodian, access class, handling class, sensitivity class, review date, reclassification history, downgrade or upgrade reason, public-safe release basis, restrictions, redactions, approvals, incidents, corrections, and archival status.
Section 212. Controlled Rooms, Clean Rooms, Data Rooms, Evidence Rooms, Public Authority Rooms, Capital-Reader Rooms, and No-Download Rooms
212.1 Controlled-Room Purpose. Controlled rooms shall be used to permit limited, supervised, recorded access to sensitive materials where ordinary sharing would create legal, privacy, cyber, public authority, finance, competition, infrastructure, protected knowledge, safeguards, or institutional integrity risks. A controlled room is a governance and information-control mechanism, not an execution vehicle, certification body, finance-readiness authority, procurement process, public authority forum, or emergency command center.
212.2 Clean-Room Purpose. Clean rooms may be established to manage competition-sensitive, provider-sensitive, sponsor-sensitive, market-sensitive, or multi-party materials under strict controls. Clean rooms shall prevent improper information exchange, market coordination, bid signaling, price disclosure, customer allocation, supplier allocation, roadmap exchange, procurement distortion, provider preference, or sponsor influence. Clean rooms may use aggregation, redaction, neutral facilitation, counsel oversight, restricted notes, and stop-meeting protocols.
212.3 Data-Room Purpose. Data rooms may be established for controlled access to datasets, evidence packs, diligence materials, technical materials, grants, sponsorship records, public authority materials, public-good software materials, or Nexus interface materials. Data rooms shall define permitted viewers, permitted uses, download restrictions, copying restrictions, AI-use restrictions, retention, watermarking, logging, export controls, and closeout.
212.4 Evidence-Room Purpose. Evidence rooms may be established for review of evidence artifacts, assurance packs, observability records, model records, inference records, technical baselines, public-safe maps, dashboards, incident records, correction records, and methods records. Evidence rooms shall preserve provenance, chain of custody, methodological integrity, reviewer independence, uncertainty disclosure, correctionability, and limitation discipline.
212.5 Public Authority Room Purpose. Public authority rooms may be established for public authority learning, capacity building, evidence review, scenario review, observability method review, public-safe publication review, or boundary-controlled engagement. Public authority rooms shall classify each public authority participant’s capacity and shall not create public authority delegation, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, endorsement, adoption, sovereign obligation, or operational control.
212.6 Capital-Reader Room Boundary Where GCRI Canada Provides Technical Inputs Only. Capital-reader rooms may be used only where GCRI Canada provides technical evidence inputs, methods notes, observability inputs, public-good technical baselines, or correction records for capital-readability support under role-separated conditions. GCRI Canada shall not operate capital placement, investor matchmaking, securities advice, investment advice, lending advice, insurance placement, underwriting, rating, public finance approval, finance-readiness determination, or routeability determination through a capital-reader room.
212.7 No-Download Room Purpose. No-download rooms may be established where materials may be viewed but not downloaded, printed, copied, screenshotted, exported, scraped, ingested into AI tools, or redistributed. No-download controls may apply to protected knowledge, public authority data, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, privileged materials, confidential sponsor or provider materials, personal information, or sensitive evidence.
212.8 Room Authorization. Each controlled room, clean room, data room, evidence room, public authority room, capital-reader room, or no-download room shall be authorized by a recorded authority basis. The authorization shall identify purpose, owner, custodian, access class, room rules, participant categories, prohibited uses, permitted outputs, logging requirements, closeout conditions, and correction path.
212.9 Room Admission Standards. Admission to a room shall require eligibility review, identity confirmation, capacity classification, conflict disclosure, confidentiality commitment, data / AI / cyber acknowledgment, public statement limits, sanctions and export-control review where applicable, competition-law controls where applicable, protected knowledge restrictions where applicable, and approval by the designated room authority. Admission shall be revocable at any time for breach, conflict, risk, changed status, or closeout.
212.10 Room Access Controls. Room access controls may include named-user access, multifactor authentication, watermarking, restricted IP access, no-forwarding controls, no-download controls, session logging, time-limited access, role-limited access, document-level permissions, screen-share restrictions, redaction, physical room controls, visitor logs, device restrictions, and supervised review.
212.11 Room Confidentiality Controls. Room participants shall maintain confidentiality of room materials, discussion, participant identity where restricted, public authority materials, protected knowledge, personal information, sensitive evidence, sponsor or provider materials, finance-sensitive materials, cyber-sensitive materials, and infrastructure-sensitive materials. Confidentiality obligations shall survive room closeout unless lawfully released.
212.12 Room Data / AI / Cyber Controls. Room rules shall specify whether data may be copied, queried, processed, modeled, embedded, summarized, translated, analyzed by AI systems, used for model training, transferred, exported, or retained. Unless expressly authorized, room materials shall not be uploaded to external AI systems, used for model training, embedded into vector stores, copied into unapproved tools, or transferred to unapproved repositories.
212.13 Room Competition Controls. Where a room includes competitors, providers, vendors, operators, sponsors, investors, insurers, lenders, or market actors, competition controls shall prohibit improper exchange of prices, costs, margins, bids, capacity, customers, suppliers, market strategy, future plans, procurement information, or competitively sensitive non-public information. Agendas, minutes, participation, and outputs shall be structured to prevent competition-law exposure.
212.14 Room Public Authority Controls. Where a room includes public authority participants, room records shall identify capacity, public reference permissions, non-endorsement language, no-delegation language, no-public-warning language, no-emergency-command language, no-regulatory-approval language, no-procurement-approval language, no-funding-approval language, no-public-finance-approval language, and no-sovereign-obligation language.
212.15 Room Finance Boundary Controls. Where a room involves finance-sensitive materials, public finance readers, investors, insurers, lenders, project SPVs, National Consortium Companies, capital-readability, finance-readiness inputs, or Nexus Rails interface materials, room controls shall prohibit investment advice, securities advice, underwriting, rating, lending advice, insurance placement, investor matchmaking, capital placement, routeability determination, public finance approval, and finance-readiness determination by GCRI Canada.
212.16 Room Protected Knowledge Controls. Where a room includes community-protected, Indigenous, local, territorial, cultural, environmental, health-sensitive, or protected participation materials, room controls shall include access limitations, contextual integrity rules, consent or authorization records where applicable, non-extraction rules, publication restrictions, AI-use restrictions, withdrawal rights, correction rights, and community safeguards.
212.17 Room Exhibit Handling and Chain of Custody. Room exhibits shall be identified, numbered, classified, logged, and stored with chain-of-custody controls proportionate to sensitivity. Exhibit handling shall record source, receipt date, contributor authority, access restrictions, transformations, annotations, reviewer actions, downloads where permitted, redactions, corrections, withdrawal, and archival disposition.
212.18 Room Logs. Rooms shall maintain logs of participants, access events, materials viewed, downloads where permitted, questions, exhibits, decisions, outputs, restrictions, incidents, corrections, and closeout actions. Logs shall be classified and retained according to room type and sensitivity.
212.19 Room Closeout. Room closeout shall include access revocation, credential termination, download review, records return or deletion, confidentiality reminder, unresolved issue log, correction review, output classification, dependency review, and archival disposition. Room closeout shall not waive surviving confidentiality, data, AI, cyber, IP, public authority, finance-boundary, competition, or protected knowledge obligations.
212.20 Room Records. GCRI Canada shall maintain room records identifying authorization, purpose, room rules, owner, custodian, participants, capacity classifications, conflicts, access permissions, materials, logs, incidents, outputs, corrections, closeout, access revocations, and retention.
Section 213. Record Authenticity, Integrity Controls, Signature Controls, Hashes, Audit Trails, Custody, and Tamper-Evidence
213.1 Authenticity Requirement. GCRI Canada shall maintain controls sufficient to determine whether a record is authentic, who created it, who approved it, who modified it, which version is operative, and whether it has been superseded, corrected, withdrawn, retracted, deprecated, retired, sealed, or archived. Authenticity is a condition of governance reliance, evidence reliance, publication reliance, technical asset release, public authority reference, and Nexus interface validity.
213.2 Record Integrity Requirement. Records shall be protected from unauthorized alteration, deletion, substitution, backdating, misclassification, false attribution, unrecorded editing, unapproved publication, unapproved AI alteration, and unauthorized repository movement. Record integrity controls shall apply to corporate records, Board records, committee records, council records, member records where applicable, evidence records, methods records, datasets, models, software, publications, corrections, incidents, registers, and Gazette notices.
213.3 Signature Controls. GCRI Canada shall maintain signature controls for documents requiring execution, certification, approval, attestation, Board authorization, officer authorization, contract approval, public authority protocol approval, controlled-room admission, data access, contributor terms, sponsorship agreements, grant agreements, restricted fund agreements, or other formal assent. Signature authority shall be recorded and limited by law, Articles, this Bylaw, Board resolutions, delegations, policies, and contracts.
213.4 Electronic Signature Controls Where Lawful. Electronic signatures may be used where lawful and approved. Electronic signature controls shall identify signer identity, authentication method, document version, timestamp, signature certificate or audit trail, signature authority, consent to electronic execution where required, and storage location. Electronic signatures shall not cure absence of authority, unresolved conflict, missing approval, unlawful purpose, or breach of this Bylaw.
213.5 Certification Controls. Certified copies, officer certificates, Secretary certificates, seal use, authenticity confirmations, register extracts, and official transcripts shall be issued only by authorized persons. Certification shall identify the certified record, version, date, basis, certifying person, scope, limitations, and reliance language. Certification shall not create substantive approval, recognition, public authority endorsement, finance-readiness, procurement approval, or technical validity beyond the certified record.
213.6 Hash or Integrity Reference Where Used. GCRI Canada may use cryptographic hashes, checksums, timestamps, digital signatures, repository commits, immutable logs, content-addressed storage, or other integrity references to support tamper-evidence. Where used, the integrity reference shall be linked to the record version, repository, custodian, creation time, approval status, and supersession or correction status. A hash or ledger reference shall not substitute for governance authority.
213.7 Tamper-Evident Logging. Tamper-evident logging shall be used where proportionate for registers, repositories, controlled rooms, data rooms, AI-use records, model records, evidence packs, public authority materials, finance-sensitive records, cyber-sensitive records, software releases, and correction records. Logs shall record access, modification, approval, export, deletion, correction, and administrative activity.
213.8 Audit Trail Requirement. Material records shall maintain an audit trail showing creation, review, approval, access, edits, classification, reclassification, publication, correction, supersession, withdrawal, retraction, archival, deletion, sealing, and transfer. Audit trails shall be retained and access-controlled in accordance with sensitivity and legal requirements.
213.9 Custody Record. Records shall identify a custodian responsible for storage, access control, versioning, correction, retention, and archival. Custody may be assigned to the Secretary, officer, committee, register owner, repository maintainer, data steward, evidence steward, technical asset steward, counsel, safeguards lead, or other authorized person.
213.10 Chain-of-Custody for Sensitive Evidence. Sensitive evidence shall be subject to chain-of-custody records identifying source, contributor, authority basis, receipt, classification, storage location, transformations, access, review, use, export, correction, withdrawal, and archival. Chain-of-custody discipline shall apply to public authority evidence, protected knowledge, personal information, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, incident evidence, and contested evidence.
213.11 Repository Custody. Repositories containing bylaws, policies, methods, datasets, models, software, public-good technical assets, schemas, technical baselines, publications, or correction records shall have assigned custodians, maintainers, access rules, branch or version controls where applicable, release controls, review gates, archive controls, and incident response procedures.
213.12 Access Logs. Access logs shall be maintained for sensitive records, controlled rooms, data rooms, evidence rooms, repositories, registers, public authority materials, AI systems, datasets, models, software repositories, and finance-sensitive materials. Logs shall identify user, role, time, record accessed, action taken, export or download where permitted, and unusual activity where detectable.
213.13 Change Logs. Change logs shall be maintained for material records, methods, policies, technical assets, software, datasets, models, controlled vocabularies, schemas, publications, dashboards, maps, and Gazette notices. Change logs shall identify what changed, why it changed, who changed it, who approved it, effective date, affected dependencies, and correction or supersession relationship.
213.14 Unauthorized Change Detection. GCRI Canada shall maintain procedures to detect unauthorized changes, including repository monitoring, access review, integrity checks, audit log review, anomaly detection where appropriate, human review, and incident reporting. Unauthorized changes shall be treated as record integrity incidents.
213.15 Record Integrity Incident Response. Where record integrity is compromised or suspected, GCRI Canada shall contain the issue, preserve evidence, restrict access, identify affected records, determine whether public or controlled correction is required, notify appropriate persons, restore trusted versions, review downstream dependencies, and record corrective action. Record integrity incidents may require legal, data / AI / cyber, public authority, finance-boundary, safeguards, or Board review.
213.16 Authenticity and Integrity Records. GCRI Canada shall maintain records of authenticity controls, signature controls, electronic signature events, certification events, hash references, tamper-evident logs, audit trails, custody assignments, chain-of-custody records, access logs, change logs, integrity incidents, restoration actions, and corrective measures.
Section 214. No Silent Edit, Versioning, Change Logs, Supersession Chains, Errata, and Repository Discipline
214.1 No Silent Edit Rule. No material record, bylaw, policy, method, evidence artifact, dataset, model record, software release, public-good technical asset, publication, dashboard, map, Gazette notice, public authority reference, finance-boundary material, sponsor acknowledgment, provider reference, controlled vocabulary, or Nexus interface artifact shall be materially edited without a recorded change. Silent edits are prohibited where they alter meaning, authority, reliance, classification, evidence, methods, public claims, public authority status, finance implications, certification implications, procurement implications, access rights, correction status, or legal effect.
214.2 Versioning Requirement. Material records shall be versioned. Versioning shall identify draft, consultation draft, approved version, public-safe version, controlled version, restricted version, superseded version, withdrawn version, retracted version, archived version, or retired version. Versioning shall preserve historical traceability and shall allow users to determine which version was operative at a given time.
214.3 Version Identifier. Each material version shall have a version identifier, effective date, approval date, approval authority, repository location, classification, and supersession status. Version identifiers may use numbering, dates, release tags, repository commits, hashes, docket IDs, Gazette references, or other approved methods.
214.4 Change Log. Each material version shall have a change log proportionate to the record. The change log shall identify substantive changes, editorial changes, corrections, redactions, downgraded or upgraded classification, public-safe transformations, legal changes, technical changes, evidence updates, methods updates, dependency changes, and affected downstream materials.
214.5 Editorial Correction. An editorial correction is a correction that does not change substantive meaning, authority, rights, duties, classification, evidence, methods, reliance, or public claims. Editorial corrections may include typographical corrections, formatting corrections, numbering corrections, cross-reference corrections, and non-substantive style corrections. Editorial corrections shall still be recorded where made to an official record.
214.6 Material Correction. A material correction is a correction that changes or clarifies substantive meaning, evidence, methods, authority, rights, duties, limitations, public claims, classification, reliance, technical output, public authority status, finance implication, certification implication, procurement implication, or Nexus interface meaning. Material corrections shall require appropriate review, approval, notice, and downstream dependency analysis.
214.7 Constitutional Correction. A constitutional correction is a correction affecting the Articles, this Bylaw, member rights where applicable, Board authority, director duties, corporate purpose, nonprofit character, non-distribution character, mission lock, non-execution boundary, public authority boundary, finance-readiness boundary, legal separateness, or core institutional architecture. Constitutional corrections shall require the approvals required by law, Articles, and this Bylaw.
214.8 Errata. Errata may be issued to identify and correct errors in publications, technical notes, methods, datasets, dashboards, maps, software documentation, public-safe summaries, or controlled materials. Errata shall identify the affected text, artifact, date, nature of error, correction, reliance effect, and whether further correction, supersession, withdrawal, or retraction is required.
214.9 Supersession Chain. Where a record is replaced by a later record, GCRI Canada shall maintain a supersession chain identifying the superseded record, superseding record, effective date, reason, continuing reliance rules, affected dependencies, public or controlled notice, and archive location.
214.10 Withdrawal Chain. Where a record is withdrawn, GCRI Canada shall maintain a withdrawal chain identifying the withdrawn record, reason, authority, date, reliance limitations, affected dependencies, public or controlled notice, and archive or sealing status.
214.11 Retraction Chain. Where a record is retracted, GCRI Canada shall maintain a retraction chain identifying the retracted record, reason, authority, date, severity, affected dependencies, non-reliance language, corrective action, public or controlled notice, and archive or sealing status.
214.12 Deprecation Chain. Where a technical asset, method, dataset, model, software release, dashboard, API, SDK, schema, controlled vocabulary, or reference implementation is deprecated, GCRI Canada shall maintain a deprecation chain identifying the deprecated artifact, replacement or alternative where any, effective date, support status, security status, reliance limitations, sunset date, and archive location.
214.13 Archive Copy. An archive copy shall be preserved for material official records unless deletion, sealing, privacy law, protected knowledge requirements, legal order, security concern, or other lawful reason requires restricted handling. Archive copies shall identify version, status, effective period, classification, reliance limitations, and access restrictions.
214.14 Repository Discipline. Official repositories shall be structured to distinguish drafts, working files, consultation materials, approved records, public-safe materials, controlled materials, restricted materials, superseded materials, withdrawn materials, retracted materials, deprecated materials, retired materials, and archive copies. Repository discipline shall prevent unauthorized publication, obsolete reliance, conflicting versions, uncontrolled duplication, and silent meaning drift.
214.15 Unofficial Copy Controls. Unofficial copies, summaries, translations, excerpts, decks, screenshots, exported PDFs, AI-generated summaries, and working copies shall be marked or handled so they do not override official records. Where unofficial copies are used externally, they shall include appropriate limitations and shall not create public meaning beyond the official record.
214.16 Redline and Draft Controls. Drafts and redlines shall be classified, access-controlled, labeled as non-operative, and protected from confusion with adopted instruments. Redlines may not be circulated externally unless approved and shall not be cited as authority unless the approval record permits such use.
214.17 Public-Safe Summary Update Controls. Public-safe summaries shall be updated when underlying controlled materials are materially corrected, superseded, withdrawn, retracted, or reclassified, unless the competent authority determines that the public-safe summary remains accurate. Public-safe updates shall preserve clarity, avoid overclaim, and disclose correction where necessary.
214.18 Versioning and Repository Records. GCRI Canada shall maintain versioning and repository records identifying official repositories, custodians, version identifiers, change logs, redlines, drafts, unofficial copies, public-safe summaries, supersession chains, withdrawal chains, retraction chains, deprecation chains, archive copies, access controls, and correction history.
Section 215. Validity-by-Record Doctrine in Corporate Governance
215.1 Validity-by-Record Principle. GCRI Canada shall operate under the doctrine of validity-by-record. Institutional acts, statuses, authorities, approvals, classifications, releases, memberships, delegations, public claims, public authority references, data permissions, AI-use permissions, controlled-room access, sponsorship benefits, Nexus interface claims, and technical releases are valid only to the extent supported by a competent record made under applicable law, the Articles, this Bylaw, Board resolutions, policies, delegations, contracts, and approved registers.
215.2 Governance Validity by Record. Governance action shall be valid only where recorded by minutes, resolutions, written consents, registers, notices, delegations, policies, or other competent governance records. Informal discussion, repeated practice, meeting attendance, email circulation, public expectation, donor pressure, sponsor preference, provider request, or narrative consensus shall not substitute for governance record.
215.3 Board Validity by Record. Board decisions shall require proper record of notice, quorum, materials reviewed, conflicts, recusals, voting, resolution text, authority basis, conditions, effective date, and follow-up. A Board decision lacking required record may be corrected, ratified, limited, suspended, or treated as non-operative according to law and this Bylaw.
215.4 Officer Delegation Validity by Record. Officer authority shall exist only to the extent recorded in law, Articles, this Bylaw, Board resolution, employment agreement, delegation matrix, policy, contract, or written authorization. Officer practice shall not expand authority beyond the record.
215.5 Committee and Council Validity by Record. Committees and councils shall act only within recorded charters, mandates, delegations, agendas, minutes, recommendations, and output classes. Advisory bodies shall not become decision authorities by participation, expertise, seniority, funding, public authority attendance, or public narrative.
215.6 Membership and Participation Validity by Record. Membership, non-voting participation, supporter status, subscription status, fellowship, advisory status, council status, committee status, contributor status, maintainer status, host status, sponsor status, provider status, public authority participation, and controlled-room access shall exist only as recorded in the applicable register or agreement. Participation shall not create statutory membership, governance rights, fiduciary authority, public authority status, provider preference, or authority to bind GCRI Canada.
215.7 Evidence and Methods Validity by Record. Evidence and methods shall be institutionally valid only where recorded with provenance, source, classification, method, limitations, uncertainty, review status, authority, and correction path. Unrecorded evidence, unsupported inference, stale data, AI-generated output, sponsor assertion, provider assertion, public authority comment, or informal expert view shall not become institutional evidence without record.
215.8 Research Output Validity by Record. Research outputs shall be valid only where supported by research records, methods records, evidence lineage, authorship records, conflict records, review records, publication approval, classification, limitations, and correction path. Drafts, presentations, preliminary findings, workshops, or public remarks shall not be treated as final research outputs unless recorded as such.
215.9 Technical Asset and Software Release Validity by Record. Technical assets and software releases shall be valid only where recorded in the applicable register with version, maintainer, license, security review, dependency review, release approval, documentation, limitations, classification, known issues, and correction path. Repository access, commit rights, maintainer status, or technical capability shall not create institutional release authority.
215.10 Data Access and AI-Use Validity by Record. Data access and AI-use permissions shall be valid only where recorded with user, purpose, data class, system, permitted use, prohibited use, retention, transfer, model-training restrictions, security controls, approval, expiration, and revocation path. No person may infer data or AI-use permission from job role, project involvement, convenience, prior access, or technical ability.
215.11 Public Authority Reference Validity by Record. Public authority references shall be valid only where recorded with capacity classification, approved language, scope, non-endorsement, no-delegation, no-public-warning, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, and correction path. Attendance, participation, data contribution, or informal comment by a public authority shall not create public authority endorsement.
215.12 Sponsorship, Grant, Donation, and Support Validity by Record. Sponsorship, grant, donation, restricted fund, unrestricted support, in-kind contribution, subscription, or other support shall be valid only where recorded with source, amount or value, restrictions, conditions, conflicts, acceptance authority, tax treatment, acknowledgment language, benefit schedule, influence caps, and closeout. Support shall not create governance control or outcome rights.
215.13 Public Claim Validity by Record. Public claims shall be valid only where supported by approved evidence, approved language, publication authority, limitation language, classification review, public authority reference approval where applicable, sponsor or provider acknowledgment approval where applicable, and correction path. Claims shall not be created by marketing convenience, event language, proposal language, social media, or slide summaries unless authorized.
215.14 Nexus Interface Validity by Record. Interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, National Consortium Companies, Project SPVs, providers, hosts, sponsors, public authorities, communities, universities, and other Nexus actors shall be valid only where recorded by interface record, compatibility note, divergence log, agreement, protocol, register entry, or other competent record.
215.15 No Authority by Memory, Practice, Circulation, Status, Reputation, Sponsorship, Attendance, Technical Access, or Narrative Alone. No person, body, record, claim, tool, output, dashboard, map, model, dataset, software release, meeting, council, committee, controlled room, sponsor benefit, public authority participation, or Nexus interface shall acquire authority by memory, practice, circulation, status, reputation, seniority, sponsorship, donation, attendance, contribution, authorship, technical access, informal approval, or narrative alone.
215.16 Validity-by-Record Records. GCRI Canada shall maintain records sufficient to evidence validity-by-record, including authority records, approvals, registers, minutes, resolutions, delegations, access records, classification records, interface records, correction records, and Gazette notices.
Section 216. No Record / No Public Meaning Rule
216.1 No Record / No Public Meaning. No statement, status, claim, participation, output, meeting, dashboard, map, dataset, model, software artifact, public authority appearance, sponsor acknowledgment, provider participation, evidence pack, methods note, Nexus interface, or technical release shall have public meaning on behalf of GCRI Canada unless supported by an authorized record. Where no record exists, no public meaning shall be inferred.
216.2 No Public Claim Without Record. GCRI Canada shall not make, permit, or rely on a public claim unless the claim is supported by approved evidence, approved language, publication authority, classification review, limitation language, and correction path. Unauthorized claims shall be corrected or withdrawn.
216.3 No Recognition Implication Without Record. No person, entity, project, provider, host, sponsor, public authority, National Consortium Company, Project SPV, technical asset, method, dataset, model, or publication shall be described as recognized by GCRI Canada unless a competent recognition record exists and GCRI Canada is lawfully authorized to make such recognition. By default, GCRI Canada does not serve as a recognition authority.
216.4 No Maturity Implication Without Record. No maturity level, readiness status, capability status, grid status, observatory status, risk status, host readiness, provider readiness, project readiness, or institutional maturity shall be implied without a competent record and lawful authority. GCRI Canada shall not be treated as a maturity-determining body unless expressly authorized within its non-executing technical mandate.
216.5 No Public Authority Reference Without Record. No public authority name, logo, agency, title, quote, photograph, attendance reference, data contribution, or participation reference shall be used without a public authority reference record or other lawful authority. Public authority reference shall never imply endorsement, delegation, approval, funding, procurement, regulation, public warning, emergency command, public finance approval, or sovereign obligation unless expressly and lawfully recorded by the public authority.
216.6 No Finance-Readiness Implication Without Record. No finance-readiness, capital-readability, routeability, investment suitability, bankability, insurability, creditworthiness, public finance eligibility, or financial approval implication shall be made without a competent record and lawful authority. GCRI Canada shall not make finance-readiness determinations by default.
216.7 No Insurance-Readiness Implication Without Record. No insurance-readiness, underwriting suitability, risk-transfer suitability, premium expectation, coverage availability, or insurer approval shall be implied without a competent record and lawful authority. GCRI Canada shall not act as an insurer, broker, underwriter, rating agency, or insurance advisor.
216.8 No Procurement Implication Without Record. No procurement approval, vendor qualification, preferred provider status, public-sector eligibility, contract award implication, purchasing recommendation, or tender advantage shall be implied without a competent record and lawful authority. GCRI Canada shall maintain procurement neutrality.
216.9 No Certification Implication Without Record. No certification, accreditation, credential, conformity assessment, professional qualification, compliance approval, safety approval, performance warranty, technical guarantee, public authority approval, or seal of assurance shall be implied without a competent record and lawful authority. GCRI Canada is not a certification authority by default.
216.10 No Nexus-Compatible Claim Without Record. No claim that an entity, project, protocol, method, dataset, model, software, dashboard, map, public authority process, finance process, or technical asset is Nexus-compatible, Nexus-aligned, Nexus-approved, Nexus-recognized, Nexus-ready, or Nexus-certified shall be made without a competent Nexus interface record and lawful authority.
216.11 No Provider Preference Without Record and Lawful Authority. No provider shall be described as preferred, endorsed, approved, recommended, ranked, selected, certified, procurement-ready, finance-ready, public authority-ready, or Nexus-selected by GCRI Canada without lawful authority and a competent record. Provider participation in GCRI Canada activities shall not create preference.
216.12 No Sponsor Benefit Without Record. No sponsor, donor, funder, grantor, supporter, or subscriber shall receive acknowledgment, access, visibility, speaking opportunity, room participation, publication reference, logo placement, advisory participation, or other benefit unless recorded in an approved benefit schedule or support record. Sponsor benefit records shall include non-control and non-endorsement language.
216.13 No Data Access Without Record. No person shall access datasets, public authority data, personal information, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, model records, inference records, or controlled evidence without a recorded access authorization.
216.14 No AI-Use Permission Without Record. No person shall use GCRI Canada data, records, evidence, protected knowledge, public authority materials, controlled-room materials, software, or publications in AI systems without recorded permission specifying permitted use, prohibited use, model-training restrictions, retention, output review, security controls, and correction path.
216.15 No Controlled-Room Access Without Record. No person shall enter, view, receive, or use controlled-room, clean-room, data-room, evidence-room, public authority room, capital-reader room, or no-download room materials without recorded admission, capacity classification, confidentiality obligation, access restrictions, and closeout path.
216.16 No Technical Release Without Record. No software, dataset, model, schema, API, SDK, dashboard, map, test harness, benchmark, gold vector, negative test, public-good technical asset, method, or technical baseline shall be released without a release record, version identifier, classification review, security review where applicable, license review, documentation, limitations, and correction path.
216.17 Record Deficiency Response. Where a record is missing, incomplete, inconsistent, unauthorized, stale, unsupported, or misleading, GCRI Canada shall pause reliance, restrict access, correct the record, create a deficiency record, obtain ratification where lawful, issue public or controlled clarification where necessary, and conduct downstream dependency review.
216.18 No Record / No Public Meaning Records. GCRI Canada shall maintain records of record deficiencies, unauthorized claims, unauthorized references, missing approvals, corrective actions, ratifications, withdrawals, clarifications, public-safe notices, controlled notices, and dependency reviews.
Section 217. Correctionability Doctrine in Corporate Governance
217.1 Correctionability Principle. GCRI Canada shall operate under the doctrine of correctionability. Every material record, claim, method, evidence artifact, dataset, model, software release, publication, dashboard, map, public authority reference, sponsorship record, provider reference, finance-boundary statement, Nexus interface artifact, and governance act shall remain capable of correction, clarification, supersession, withdrawal, retraction, downgrade, upgrade, archival, or other appropriate lifecycle action.
217.2 Duty to Correct Inaccurate Records. GCRI Canada shall correct records that are inaccurate in fact, authority, date, status, classification, ownership, provenance, evidence, method, approval, public meaning, public authority capacity, finance boundary, certification boundary, procurement boundary, data rights, AI-use permission, or access status.
217.3 Duty to Correct Outdated Records. GCRI Canada shall correct or supersede records that have become outdated because of new evidence, changed law, changed policy, changed public authority status, changed technical conditions, changed data rights, changed AI-use rules, changed security posture, changed sponsor or provider status, changed Nexus interface status, or changed institutional authority.
217.4 Duty to Correct Unsupported Records. GCRI Canada shall correct records, claims, conclusions, dashboards, maps, publications, evidence summaries, methods notes, or public-safe outputs that lack adequate support, evidence lineage, review, authority, limitation disclosure, or correction path. Unsupported material shall not continue to be used merely because it has circulated.
217.5 Duty to Correct Unsafe Records. GCRI Canada shall correct, restrict, downgrade, withdraw, or reclassify records that create public safety risk, cyber risk, infrastructure risk, privacy risk, protected knowledge risk, public authority confusion, finance overclaim, certification overclaim, procurement implication, provider preference, sponsor control implication, community harm, retaliation risk, or operational misuse.
217.6 Duty to Correct Overbroad Records. GCRI Canada shall correct records that state conclusions, permissions, approvals, classifications, claims, public authority references, Nexus compatibility statements, technical capabilities, finance implications, or public-benefit impacts more broadly than the evidence or authority supports. Overbroad records shall be narrowed.
217.7 Duty to Correct Unauthorized Records. GCRI Canada shall correct or withdraw records created, edited, published, released, cited, exported, accessed, or relied upon without authority. Unauthorized records may be quarantined, marked non-operative, withdrawn, retracted, or referred for investigation.
217.8 Duty to Correct Superseded Records. GCRI Canada shall mark superseded records as superseded and shall identify the superseding record, effective date, reliance rules, and archive location. Superseded records shall not remain presented as operative.
217.9 Duty to Correct Misleading Public Materials. GCRI Canada shall correct public materials that could mislead stakeholders about GCRI Canada’s purpose, authority, nonprofit status, non-execution boundary, public authority relationships, finance-readiness role, certification role, procurement role, provider neutrality, sponsor role, research conclusions, technical capabilities, public-good assets, Nexus interfaces, or legal status.
217.10 Duty to Correct Public Authority Misdescription. GCRI Canada shall correct any misdescription of public authority participation, capacity, approval, endorsement, funding, procurement, regulatory status, public warning, emergency command, public finance role, or sovereign obligation. Corrections shall be made promptly and with appropriate notice to the affected public authority where required.
217.11 Duty to Correct Finance, Insurance, Investment, Procurement, Certification, Recognition, or Maturity Overclaim. GCRI Canada shall correct any statement or record that implies finance-readiness, insurance-readiness, investment suitability, lending suitability, underwriting approval, rating, procurement approval, certification, recognition, maturity status, or provider preference beyond lawful authority and competent record. Such corrections may require public-safe notice, controlled notice, sponsor or provider notice, public authority notice, or Nexus interface notice.
217.12 Duty to Correct Data, AI, Cyber, Privacy, Community, Indigenous, Protected Knowledge, or Public-Safety Errors. GCRI Canada shall correct records involving data misuse, AI misuse, model error, inference error, cyber exposure, privacy error, personal information error, protected knowledge exposure, Indigenous / local / territorial knowledge misuse, community harm, public-safe mapping issue, dashboard error, or public safety concern. Corrections may require access restriction, notification, deletion, sealing, withdrawal, retraction, incident response, or safeguards review.
217.13 Correction Without Concealment. Corrections shall not be used to conceal material error, misconduct, conflict, unauthorized action, public authority misdescription, finance overclaim, certification overclaim, procurement implication, protected knowledge breach, data incident, AI incident, cyber incident, or research integrity issue. Historical traceability shall be preserved subject to lawful confidentiality, privacy, privilege, sealing, or protected knowledge requirements.
217.14 Correction With Historical Traceability. Corrections shall preserve the corrected record, correction date, correction authority, reason, affected fields, affected downstream records, reliance implications, notice status, and archival status. Where a public correction is required, the correction shall be clear enough to prevent continued reliance on the incorrect record.
217.15 Correctionability Records. GCRI Canada shall maintain correctionability records, including correction requests, review records, correction decisions, amended records, supersession records, withdrawal records, retraction records, public-safe notices, controlled notices, dependency reviews, stakeholder notifications, and closeout records.
Section 218. Correction, Clarification, Errata, Supersession, Suspension, Downgrade, Withdrawal, Retraction, Reinstatement, Retirement, and Archival
218.1 Correction. Correction means an authorized change to a record, publication, evidence artifact, method, dataset, model, software release, dashboard, map, register, Gazette notice, public authority reference, sponsor acknowledgment, provider reference, finance-boundary statement, or Nexus interface artifact to remedy error, inaccuracy, overbreadth, omission, unauthorized meaning, unsafe disclosure, or changed circumstance.
218.2 Clarification. Clarification means an authorized statement that explains, narrows, contextualizes, or corrects potential misunderstanding without necessarily altering the underlying record. Clarification may be used where a public claim, public authority reference, finance-boundary statement, technical output, dashboard, map, or Nexus interface artifact could be misunderstood.
218.3 Errata. Errata means a listed correction of errors in a publication, technical note, dataset, software documentation, methods note, evidence note, public-safe summary, dashboard, map, or other output. Errata may be editorial or material and shall identify the affected artifact and correction.
218.4 Supersession. Supersession means replacement of a prior record, method, publication, dataset, model, software release, technical asset, policy, controlled vocabulary, dashboard, map, or notice by a later authorized version. Supersession shall identify the prior version, new version, effective date, authority, reliance rules, and archive location.
218.5 Suspension. Suspension means temporary restriction of use, access, publication, reliance, participation, release, or operation pending review. Suspension may apply to records, publications, datasets, models, software, dashboards, maps, room access, participant status, contributor access, provider participation, sponsor benefits, public authority references, or Nexus interfaces.
218.6 Downgrade. Downgrade means reduction of sensitivity, access restriction, handling restriction, or publication restriction where lawful and safe. Downgrade may occur after redaction, aggregation, consent, expiry of sensitivity, security review, public authority approval, safeguards review, or public-safe transformation.
218.7 Withdrawal. Withdrawal means removal of an output, record, publication, reference, dataset, model, software release, dashboard, map, public claim, public authority reference, sponsor acknowledgment, provider reference, or Nexus interface artifact from active use or public availability because it is no longer approved, safe, current, authorized, or appropriate.
218.8 Retraction. Retraction means formal removal from reliance of a materially unreliable, unauthorized, unsupported, unsafe, misleading, or improper record or publication. Retraction shall be used where correction or clarification is insufficient to prevent harm or continued reliance.
218.9 Reinstatement. Reinstatement means restoration of a suspended, withdrawn, restricted, or retired record, access, participation status, technical asset, publication, dataset, model, software release, dashboard, map, or interface after review confirms that reinstatement is lawful, safe, corrected, and authorized.
218.10 Retirement. Retirement means planned cessation of active maintenance, use, publication, or reliance for a method, dataset, model, software release, technical asset, dashboard, map, register field, program, or output. Retirement shall include transition, replacement where appropriate, reliance limitation, security posture, and archive disposition.
218.11 Archival. Archival means preservation of a record for historical, legal, evidentiary, governance, research integrity, technical continuity, correctionability, audit, or institutional memory purposes. Archival does not imply current approval, current authority, current reliability, or current public meaning.
218.12 Trigger Conditions. Lifecycle actions may be triggered by error, new evidence, changed law, changed policy, public authority concern, data incident, AI incident, cyber incident, protected knowledge concern, public safety concern, conflict, sponsor influence, provider influence, competition concern, finance-boundary concern, certification-boundary concern, procurement concern, technical vulnerability, model drift, research integrity issue, public claim issue, or Nexus interface mismatch.
218.13 Authority to Initiate. A lifecycle action may be initiated by the Board, an officer, committee, council, register owner, custodian, evidence steward, methods steward, data / AI / cyber lead, safeguards lead, publication lead, legal counsel, public authority contact, affected community representative, reviewer, contributor, or other authorized person under policy. Initiation does not itself determine outcome.
218.14 Authority to Approve. Approval authority for correction, clarification, errata, supersession, suspension, downgrade, withdrawal, retraction, reinstatement, retirement, or archival shall depend on the record class, risk, authority basis, public meaning, legal effect, public authority involvement, finance implication, technical risk, data / AI / cyber sensitivity, protected knowledge status, and Board-reserved matters.
218.15 Urgent Correction. Urgent correction may be made or initiated where delay could cause public harm, public authority confusion, cyber exposure, infrastructure risk, privacy breach, protected knowledge harm, finance overclaim, certification overclaim, procurement implication, safety risk, legal exposure, or institutional integrity harm. Urgent correction shall be documented and ratified or reviewed promptly by the competent authority.
218.16 Controlled Correction. Controlled correction shall be used where the affected record is controlled, restricted, confidential, privileged, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, protected-knowledge, or otherwise unsuitable for public notice. Controlled correction shall notify authorized recipients as necessary without unsafe disclosure.
218.17 Public Correction. Public correction shall be used where a public record, public claim, public authority reference, public-safe output, dashboard, map, software release, technical baseline, publication, sponsor acknowledgment, provider reference, or Gazette notice requires public clarification to prevent continued misunderstanding or reliance.
218.18 Downstream Dependency Review. Each material lifecycle action shall include downstream dependency review identifying affected records, publications, datasets, models, software, dashboards, maps, methods, evidence packs, Board materials, committee materials, council materials, public authority materials, sponsor materials, provider materials, public-safe summaries, controlled rooms, and Nexus interfaces.
218.19 Correction Closeout. Correction closeout shall include confirmation that the lifecycle action was approved, recorded, implemented, noticed where required, reflected in registers, reflected in repositories, reflected in public-safe materials, communicated to affected stakeholders where required, and linked to affected downstream dependencies.
218.20 Correction Lifecycle Records. GCRI Canada shall maintain correction lifecycle records identifying trigger, requester, owner, review, authority, decision, action type, affected records, notices, dependency review, implementation, closeout, and archival status.
Section 219. Public-Safe Correction Notices, Controlled Correction Notices, Stakeholder Notification, and Downstream Dependency Management
219.1 Public-Safe Correction Notice. A public-safe correction notice shall be issued where public materials require correction, clarification, withdrawal, retraction, supersession, downgrade, or reliance limitation and public notice is necessary to prevent continued misunderstanding, unsafe reliance, overclaim, public authority confusion, finance implication, certification implication, procurement implication, or Nexus interface confusion. Public-safe correction notices shall be clear, accurate, proportionate, non-defamatory, non-inflammatory, and protective of sensitive information.
219.2 Controlled Correction Notice. A controlled correction notice shall be issued where correction must be communicated to a limited audience because the underlying material is confidential, privileged, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, competition-sensitive, protected-knowledge, personal-information-bearing, or otherwise restricted. Controlled correction notices shall identify recipients, access restrictions, redistribution limits, and confidentiality obligations.
219.3 Internal Correction Notice. An internal correction notice may be issued to directors, officers, staff, committees, councils, fellows, advisors, contractors, volunteers, contributors, maintainers, room participants, or other internal actors where internal reliance must be corrected. Internal notices shall specify immediate action required, affected records, reliance restrictions, and reporting obligations.
219.4 Stakeholder Notification. Stakeholder notification shall be provided where a correction materially affects stakeholders who relied on or received the affected material. Stakeholders may include public authorities, communities, Indigenous or local knowledge holders, sponsors, donors, funders, providers, hosts, partners, universities, laboratories, council participants, committee members, members, subscribers, contributors, Nexus institutions, National Consortium Companies, Project SPVs, or public users.
219.5 Public Authority Notification. Public authority notification shall be made where a correction affects public authority capacity, public authority name, logo, title, quote, photograph, data contribution, room participation, public reference, endorsement status, public warning implication, emergency command implication, regulatory implication, procurement implication, funding implication, public finance implication, or sovereign-obligation implication.
219.6 Sponsor, Donor, Provider, Host, Partner, or Funder Notification. Sponsors, donors, providers, hosts, partners, or funders shall be notified where a correction affects approved acknowledgment, benefit schedules, public claims, references, room participation, data access, provider neutrality, sponsor non-control, conflict status, restricted fund use, closeout, or public materials. Such notification shall not grant veto or control over correction.
219.7 GRF, GRA, GCRI US, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Grid, Nexus Rails, Consortium, National Company, or SPV Notification Where Relevant. Where a correction affects Nexus interface meaning, interoperability, technical baselines, public-good software, observability methods, risk management, Nexus Rails inputs, Nexus Grid inputs, Nexus Academy materials, consortium coordination, National Consortium Companies, Project SPVs, GRF recognition or claims-discipline surfaces, GRA convening surfaces, GCRI US technical records, or Nexus Standards protocol records, GCRI Canada shall notify the relevant Nexus institution or interface actor through recorded channels.
219.8 Sensitive Data Protection in Correction Notices. Correction notices shall not disclose personal information, protected knowledge, cyber-sensitive information, infrastructure-sensitive information, privileged material, confidential public authority material, finance-sensitive material, commercially sensitive information, or unsafe operational details except where lawful, necessary, approved, and safeguarded.
219.9 Privilege and Confidentiality Preservation. Correction notices shall preserve legal privilege, settlement privilege, investigation confidentiality, Board confidentiality, public authority confidentiality, sponsor or provider confidentiality, research confidentiality, protected participation confidentiality, and controlled-room confidentiality. Where public notice is required, public-safe language shall be used.
219.10 Cybersecurity and Infrastructure Sensitivity Preservation. Correction notices involving cybersecurity or infrastructure-sensitive issues shall avoid exposing vulnerabilities, system diagrams, attack paths, credentials, operational dependencies, unpatched systems, sensitive geospatial detail, critical infrastructure weaknesses, or public safety risks. Coordinated disclosure or restricted notice may be used where appropriate.
219.11 Community and Protected Knowledge Preservation. Correction notices involving community-protected knowledge, Indigenous / local / territorial knowledge, cultural knowledge, environmental knowledge, protected participation, or community-sensitive information shall be prepared with safeguards review and, where appropriate, community input or custodial review. Public notice shall not compound harm.
219.12 Downstream Dependency Identification. GCRI Canada shall identify downstream dependencies affected by a correction, including records, registers, publications, public-safe summaries, datasets, models, software, dashboards, maps, methods, technical baselines, public authority references, sponsor acknowledgments, provider references, council outputs, Board materials, committee materials, Gazette notices, and Nexus interface artifacts.
219.13 Dependency Impact Analysis. Dependency impact analysis shall identify whether downstream materials must be corrected, superseded, withdrawn, retracted, downgraded, upgraded, restricted, re-reviewed, reclassified, or archived. It shall also identify whether reliance was public, controlled, internal, public authority-facing, finance-facing, sponsor-facing, provider-facing, or Nexus-facing.
219.14 Dependency Remediation. Dependency remediation shall include updating affected records, issuing notices, correcting public materials, restricting access, updating repositories, updating registers, replacing datasets, updating model cards, updating method notes, updating dashboards or maps, correcting public authority references, correcting sponsor or provider references, and documenting closeout.
219.15 Notification and Dependency Records. GCRI Canada shall maintain notification and dependency records identifying notice type, recipients, classification, affected records, affected dependencies, analysis, remediation actions, dates, owners, approvals, confirmations, exceptions, and closeout.
Section 220. Retention, Litigation Holds, Archiving, Secure Disposal, Deletion, Sealing, Portability, and Successor Access
220.1 Retention Schedule. GCRI Canada shall maintain a retention schedule for corporate records, governance records, financial records, tax records, employment records, research records, evidence records, methods records, datasets, models, software, publications, public authority records, sponsorship records, grants, donations, restricted funds, contracts, controlled rooms, incidents, corrections, and Nexus interface records. Retention periods shall comply with law and shall preserve validity-by-record, correctionability, auditability, research integrity, technical continuity, public-good asset stewardship, and institutional memory.
220.2 Corporate Record Retention. Corporate records, including Articles, bylaws, Board minutes, Board resolutions, member records where applicable, director and officer registers, corporate filings, statutory returns, registered office records, seal records, certificates, policies, and corporate status records, shall be retained for the period required by law and, where appropriate, permanently.
220.3 Financial Record Retention. Financial records, including budgets, audited or reviewed financial statements, accounting records, tax filings, grant records, sponsorship records, donation records, restricted fund records, expense records, payroll records, insurance records, indemnification records, procurement records, contracts, invoices, receipts, and support acceptance records, shall be retained according to law, funder requirements, tax requirements, audit needs, and Board policy.
220.4 Research Record Retention. Research records, including research protocols, ethics approvals, methods, evidence lineage, peer review records, authorship records, conflict records, publication review records, data management plans, consent records where applicable, community safeguards records, protected knowledge records, and correction records, shall be retained to support research integrity, reproducibility where appropriate, public-safe publication, and correctionability.
220.5 Evidence Record Retention. Evidence records, including evidence artifacts, assurance packs, observability records, public authority data, chain-of-custody records, confidence notes, uncertainty notes, limitation notes, review records, and correction records, shall be retained according to sensitivity, legal obligations, public authority terms, data rights, protected knowledge obligations, and institutional reliance needs.
220.6 Data / AI / Cyber Record Retention. Data / AI / cyber records, including data access records, AI-use permissions, model records, inference records, prompt records where retained, compute workload records, repository logs, access logs, security review records, privacy review records, incident records, vulnerability records, deletion records, and cyber control records, shall be retained according to legal, privacy, security, public authority, protected knowledge, and audit requirements.
220.7 Publication Record Retention. Publication records, including reports, public-safe summaries, technical notes, methods notes, evidence notes, datasets, dashboards, maps, software releases, websites, decks, media materials, public claims, approval records, correction records, withdrawal records, retraction records, and archive copies, shall be retained to preserve public meaning, reliance history, and correctionability.
220.8 Public Authority Record Retention. Public authority records, including capacity classifications, reference approvals, data contribution records, room participation records, non-endorsement records, public authority corrections, public authority protocols, public finance reader records, emergency management participation records, and public infrastructure operator records, shall be retained according to law, public authority terms, confidentiality, and institutional boundary needs.
220.9 Sponsorship, Grant, Donation, and Support Record Retention. Sponsorship, grant, donation, restricted fund, unrestricted support, in-kind contribution, subscription, donor, funder, acknowledgment, benefit, influence cap, conflict, refusal, return, restriction, termination, and closeout records shall be retained according to law, tax requirements, audit requirements, funder conditions, restricted fund obligations, anti-capture review, and public-benefit accountability.
220.10 Legal Hold. A legal hold shall suspend ordinary deletion, disposal, destruction, alteration, or archival actions for records that may be relevant to litigation, threatened litigation, investigation, regulatory inquiry, public authority inquiry, audit, dispute, claim, incident, employment matter, contract dispute, data breach, cyber incident, protected knowledge matter, or other legal process. Legal holds shall be issued, tracked, communicated, and lifted only by authorized process.
220.11 Investigation Hold. An investigation hold may be imposed where records are relevant to internal investigation, research integrity review, conflict review, misconduct review, data incident, AI incident, cyber incident, public authority issue, finance-boundary issue, certification-boundary issue, procurement-boundary issue, protected knowledge issue, or safeguards concern. Investigation holds shall preserve evidence and prevent spoliation or premature correction.
220.12 Preservation Hold. A preservation hold may be imposed to preserve records of institutional significance, public-good technical assets, evidence lineage, major decisions, major corrections, public authority interfaces, Nexus interfaces, public-safe publications, software releases, technical baselines, or historical records needed for continuity and institutional memory.
220.13 Archiving. Archiving shall preserve records in a stable, retrievable, classified, access-controlled, and versioned form. Archives shall distinguish operative records from superseded, withdrawn, retracted, deprecated, retired, sealed, or historical records. Archive access shall be controlled by classification and lawful authority.
220.14 Sealing. Sealing may be used for records that must be preserved but restricted from ordinary access due to privilege, legal order, investigation integrity, personal information, protected knowledge, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, settlement confidentiality, or other lawful reason. Sealed records shall remain traceable without exposing restricted contents.
220.15 Secure Disposal. Secure disposal shall be used for physical and electronic records that are eligible for destruction under the retention schedule and not subject to legal hold, investigation hold, preservation hold, protected knowledge obligations, or continuing reliance. Disposal shall be documented and shall use methods appropriate to sensitivity.
220.16 Secure Deletion. Secure deletion shall be used for electronic records, datasets, logs, files, backups where practicable, credentials, keys, tokens, AI tool outputs, temporary files, controlled-room exports, and repositories where deletion is lawful and required. Secure deletion shall consider backups, mirrors, caches, exports, third-party processors, AI systems, vector stores, and downstream copies.
220.17 Data Portability. Data portability may be provided where required by law, contract, public authority terms, contributor terms, participant rights, or policy. Portability shall be subject to identity verification, classification, third-party rights, protected knowledge obligations, public authority restrictions, security review, and lawful basis.
220.18 Successor Access Where Lawful. Where GCRI Canada undergoes lawful restructuring, dissolution, transfer of records, archive transition, repository transition, or successor stewardship arrangement, successor access shall be governed by law, Articles, this Bylaw, Board approval, member approval where required, donor or grant restrictions, public authority terms, data / AI / cyber obligations, protected knowledge obligations, confidentiality, IP rights, and public-benefit continuity.
220.19 Retention Exception Review. Exceptions to retention, deletion, sealing, disposal, portability, or successor access shall be reviewed by competent authority and recorded. Exceptions may be required by law, public authority terms, protected knowledge obligations, privacy rights, cyber risk, research integrity, legal hold, investigation hold, public-benefit continuity, or correctionability.
220.20 Retention, Hold, Archive, Disposal, Deletion, and Access Records. GCRI Canada shall maintain records of retention schedules, holds, archives, sealed records, disposal, deletion, portability, successor access, exceptions, approvals, owners, custodians, dates, affected records, and closeout.
Section 221. Register / Ledger / Repository Interoperability, Dual Logging, Mismatch Detection, Reconciliation, and Divergence Logs
221.1 Interoperability Purpose. GCRI Canada may maintain interoperability among registers, ledgers, repositories, rooms, Gazette streams, evidence systems, software repositories, data catalogues, AI-use logs, public authority records, Nexus interface records, and related systems to preserve continuity, traceability, correctionability, and public-good coordination. Interoperability shall not dilute legal authority, create informal authority, merge institutions, create shared liability, or convert technical logging into governance approval.
221.2 Register Interoperability. Official registers may interoperate where authorized to reduce duplication, identify inconsistencies, support auditability, improve correctionability, maintain access discipline, and preserve institutional memory. Register interoperability shall maintain field-level meaning, classification, authority basis, source register, update rules, correction rules, and access restrictions.
221.3 Ledger Interface Where Lawful and Approved. GCRI Canada may use ledger interfaces, append-only logs, cryptographic attestations, timestamping, content-addressed references, or distributed record systems where lawful and approved. Ledger interfaces may support evidence of existence, integrity, sequencing, or notice, but shall not substitute for Board approval, officer delegation, member approval where applicable, legal compliance, public authority approval, or substantive governance authority.
221.4 Repository Interoperability. Repositories for bylaws, policies, methods, evidence, datasets, models, software, technical assets, controlled vocabularies, publications, public-safe summaries, and correction records may interoperate with registers and notices. Repository interoperability shall preserve versioning, classification, access control, change logs, release records, dependency records, and archival status.
221.5 Dual Logging. Dual logging may be used where an act should be recorded in more than one system, including a corporate register and Gazette, a method register and repository, a software register and code repository, an evidence register and evidence room, a public authority register and room log, a sponsorship register and financial system, or a Nexus interface record and internal register. Dual logging shall identify the authoritative record and mirror record.
221.6 Mirrored Governance Semantics. Where records are mirrored, the governance meaning shall remain consistent. A mirror shall not expand, narrow, or alter authority, classification, status, access, public meaning, reliance, or correction state unless the authoritative record is updated by competent authority. Mirrors shall identify their relationship to the authoritative record.
221.7 Cross-Entity Record Interfaces. Cross-entity record interfaces may be established with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, National Consortium Companies, Project SPVs, hosts, providers, public authorities, universities, communities, or other approved actors. Each interface shall preserve legal separateness, role separation, no-agency, no-merger, no-shared-liability, non-execution, and correctionability.
221.8 Interfaces With GRF Registers. Interfaces with The Global Risks Forum (GRF) registers may support public-good recognition discipline, public-facing legitimacy records, maturity-record references, claims discipline, stakeholder formation records, public-safe reporting, and correction notices where lawful and approved. GCRI Canada shall not treat GRF records as GCRI Canada governance acts unless adopted or referenced by competent GCRI Canada record.
221.9 Interfaces With GRA Artifacts. Interfaces with The Global Risks Alliance (GRA) artifacts may support convening records, public authority learning materials, stakeholder engagement outputs, public-good coordination, and public-safe communications where lawful and approved. GRA convening artifacts shall not create GCRI Canada corporate authority, finance-readiness authority, public authority delegation, or technical release authority.
221.10 Interfaces With Nexus Standards or Protocol Records. Interfaces with Nexus Standards or protocol records may support technical baseline alignment, interoperability, controlled vocabulary alignment, protocol compatibility, method references, and correction notices. GCRI Canada shall not act as protocol authority unless expressly authorized and recorded, and protocol records shall not override GCRI Canada’s corporate governance records.
221.11 Interfaces With GCRI US Records. Interfaces with GCRI US records may support public-good R&D coordination, evidence methods, ontology, observability, software stewardship, technical baselines, research integrity, and correctionability. Such interfaces shall preserve Canadian corporate separateness, separate Board authority, separate records, separate treasury, separate liabilities, separate public claims, and no automatic adoption of GCRI US records by GCRI Canada.
221.12 Interfaces With Nexus Network, Nexus Observatory, Nexus Grid, Nexus Rails, Nexus Academy, Consortiums, National Companies, Project SPVs, and Providers Where Lawful. GCRI Canada may interface with Nexus Network, Nexus Observatory, Nexus Grid, Nexus Rails, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, providers, hosts, sponsors, public authorities, universities, and communities where lawful, approved, role-separated, and recorded. Such interfaces shall not create execution authority, provider preference, procurement approval, finance-readiness determination, public authority approval, certification, emergency command, public warning, or shared liability.
221.13 Mismatch Detection. GCRI Canada shall maintain procedures to detect mismatches among registers, ledgers, repositories, rooms, Gazette notices, public materials, controlled materials, public authority records, sponsorship records, provider records, technical repositories, and Nexus interface records. Mismatches may include inconsistent status, version, classification, access rights, public meaning, authority basis, correction status, publication status, or dependency mapping.
221.14 Mismatch Classification. Mismatches shall be classified by severity, including editorial mismatch, metadata mismatch, access mismatch, classification mismatch, authority mismatch, public claim mismatch, public authority mismatch, finance-boundary mismatch, certification-boundary mismatch, procurement-boundary mismatch, data / AI / cyber mismatch, protected knowledge mismatch, technical dependency mismatch, or legal-risk mismatch.
221.15 Reconciliation. Reconciliation shall identify the authoritative record, correct mirror records, update registers, update repositories, issue notices where required, restrict access where necessary, correct public materials, and document the reconciliation path. Reconciliation shall preserve historical traceability and shall not silently erase conflicting records.
221.16 Divergence Logs. Divergence logs shall record intentional or unresolved differences among GCRI Canada records and related Nexus records, including differences with GCRI US, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Grid, Nexus Rails, Nexus Academy, consortiums, National Consortium Companies, Project SPVs, providers, hosts, or public authorities. Divergence logs shall identify reason, owner, status, risk, compatibility effect, correction path, and review date.
221.17 Compatibility Notes. Compatibility notes may be used to explain how a GCRI Canada record relates to another Nexus record, public authority record, technical baseline, method, dataset, software release, consortium document, project record, or external record. Compatibility notes shall not create adoption, merger, agency, shared authority, public authority approval, finance-readiness, procurement approval, certification, or execution authority.
221.18 No Ledger Entry as Substitute for Governance Authority. No ledger entry, timestamp, hash, repository commit, audit log, ticket, issue, pull request, dashboard event, AI log, data-room log, room log, or technical record shall substitute for governance authority. Technical evidence of existence or integrity does not create approval, validity, authority, publication status, public meaning, or legal effect unless linked to a competent governance record.
221.19 No On-Chain PII or Protected Data. GCRI Canada shall not place personal information, sensitive personal information, public authority-sensitive data, protected knowledge, Indigenous / local / territorial knowledge, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, confidential records, or privileged material on-chain or in immutable public systems unless lawful, approved, safe, necessary, and subject to appropriate controls. By default, immutable public systems shall use references, hashes, attestations, or non-sensitive metadata rather than sensitive contents.
221.20 Interoperability, Dual-Logging, Mismatch, Reconciliation, and Divergence Records. GCRI Canada shall maintain records of interoperability approvals, register interfaces, ledger interfaces, repository interfaces, dual logging, authoritative record mappings, mirror records, mismatches, mismatch classification, reconciliation actions, divergence logs, compatibility notes, cross-entity notices, correction notices, access controls, and closeout.
Last updated
Was this helpful?