ARTICLE XVIII. ASSURANCE
Section 418. Monitoring, Evaluation, Assurance, Impact, and Renewal Purpose
418.1 Monitoring Purpose. GCRI Canada shall maintain monitoring processes to observe whether its governance, programs, research, evidence, methods, observability, ontology, public-good technical assets, data / AI / cyber controls, public-safe publications, public authority interfaces, finance-boundary controls, procurement-neutrality controls, safeguards, and Nexus-compatible activities are operating as intended. Monitoring shall be continuous or periodic as appropriate to the activity and shall identify drift, weakness, noncompliance, boundary risk, capture risk, stale evidence, technical degradation, unsafe publication, access misuse, unresolved correction, and emerging risk before harm becomes institutionalized.
418.2 Evaluation Purpose. GCRI Canada shall maintain evaluation processes to determine whether its activities remain lawful, public-benefit aligned, evidence-based, method-governed, non-executing, public-safe, technically sound, financially clean, accessible, safeguards-compliant, correctionable, and compatible with GCRI Canada’s role as an upstream research, evidence, methods, observability, ontology, public-good software, and open technical-baseline steward. Evaluation shall assess quality, relevance, integrity, usefulness, risk, limitations, and improvement needs, and shall not be reduced to volume, visibility, sponsorship value, provider uptake, public authority proximity, or capital-reader attention.
418.3 Assurance Purpose. GCRI Canada may maintain assurance processes, including internal review, management review, Board review, committee review, peer review, safeguards review, technical review, data / AI / cyber review, legal review, external review, audit, assessment, or independent verification where appropriate. Assurance shall test whether controls, records, outputs, claims, access decisions, publications, technical assets, training, programs, and interfaces comply with law, this Bylaw, approved policies, public authority boundaries, finance boundaries, procurement neutrality, provider neutrality, sponsor non-control, and public-safe publication discipline. Assurance shall not create certification, accreditation, public authority approval, finance-readiness, procurement approval, or professional opinion unless separately lawful and expressly authorized.
418.4 Impact Purpose. GCRI Canada may evaluate impact to understand whether its public-benefit work strengthens evidence literacy, methods discipline, observability literacy, technical baseline quality, public-good software stewardship, public-safe publication, public authority learning, safeguards practice, data / AI / cyber maturity, correctionability, and Nexus-compatible role separation. Impact evaluation shall be evidence-based, limitation-bearing, non-executing, and public-safe. Impact claims shall not imply that GCRI Canada caused public authority decisions, public finance approvals, procurement outcomes, investment outcomes, emergency outcomes, regulatory outcomes, provider adoption, or social results not supported by competent evidence.
418.5 Renewal Purpose. GCRI Canada shall use monitoring, evaluation, assurance, and impact learning to renew programs, policies, controls, technical assets, publications, training, records, public authority language, sponsor and provider rules, safeguards, and Nexus interface practices. Renewal may include continuation, amendment, strengthening, scaling, localization, restriction, suspension, retirement, deprecation, replacement, correction, or archival. Renewal shall be grounded in evidence, risk, mission, lawful authority, public-benefit value, technical sustainability, safeguards, and correction history.
418.6 MEAIR as Standing Governance Function. Monitoring, Evaluation, Assurance, Impact, and Renewal, referred to in this Bylaw as “MEAIR,” shall operate as a standing governance function of GCRI Canada. MEAIR shall connect corporate oversight, program review, evidence review, research integrity, technical asset stewardship, data / AI / cyber controls, public authority boundaries, finance-boundary discipline, publication review, safeguards, anti-capture, records, and correction. MEAIR shall not be a public ratings system, certification scheme, procurement tool, finance-readiness engine, recognition authority, or substitute for public authority decision-making.
418.7 MEAIR as Board Oversight Function. The Board shall oversee MEAIR at the level appropriate to GCRI Canada’s maturity, risk, size, funding, public authority interface, technical asset portfolio, publication footprint, data exposure, AI exposure, cyber exposure, safeguards responsibilities, and Nexus-compatible interfaces. Board oversight may include review of MEAIR reports, risk indicators, control failures, evaluation findings, assurance findings, impact claims, renewal decisions, unresolved corrections, deprecations, retirements, and material boundary incidents. The Board shall ensure that MEAIR is not captured by sponsor, provider, donor, funder, host, public authority, capital-reader, or reputational pressure.
418.8 MEAIR as Management Accountability Function. Management, officers, program owners, research leads, technical asset stewards, data / AI / cyber leads, publication approvers, safeguards leads, Academy leads, repository custodians, controlled-room custodians, and public authority interface owners shall use MEAIR to demonstrate performance, compliance, learning, correction, and responsible renewal within their areas. Management accountability shall include maintaining records, reporting limitations, identifying failures, correcting defects, retiring unsafe outputs, escalating unresolved risks, and resisting metrics that reward overclaim or conceal weakness.
418.9 MEAIR as Evidence-Integrity Function. MEAIR shall assess whether evidence used by GCRI Canada remains source-supported, permissioned, classified, current, relevant, complete, accurate, reproducible where feasible, limitation-bearing, and correctionable. Evidence-integrity review shall include source lineage, provenance, custody, timestamp, authority, classification, completeness, confidence, uncertainty, disputed evidence, failed evidence, spoofed evidence, missing evidence, stale evidence, superseded evidence, and correction performance. Evidence-integrity evaluation shall not convert evidence into absolute truth, public warning, public authority decision, finance-readiness, certification, or procurement approval.
418.10 MEAIR as Research-Integrity Function. MEAIR shall assess whether research activities, research agendas, methods, publications, peer review, replication, AI-use disclosure, sponsor and provider influence controls, conflicts, research ethics, protected knowledge handling, and correction practices remain aligned with research integrity. Research-integrity review shall protect independence, reproducibility where feasible, source discipline, authorship integrity, negative-result honesty, public-safe publication, and correctionability. Research performance shall not be measured by prestige, volume, funder satisfaction, sponsor satisfaction, provider uptake, or public authority attendance alone.
418.11 MEAIR as Public-Good Technical Asset Stewardship Function. MEAIR shall assess the condition, security, licensing, documentation, maintainability, public-safe status, dependency health, repository integrity, release discipline, anti-enclosure posture, correction history, deprecation status, retirement status, and sustainability of GCRI Canada’s public-good technical assets. Such assets may include software, schemas, APIs, dashboards, data dictionaries, model cards, system cards, reference architectures, profiles, test harnesses, technical baselines, ontology files, and other public-good technical materials. Technical asset review shall not become vendor certification or procurement preference.
418.12 MEAIR as Data / AI / Cyber Control Function. MEAIR shall assess whether data governance, AI governance, cybersecurity, privacy, controlled-room access, repository security, tool governance, vendor risk, incident response, access controls, AI-use restrictions, public authority data handling, protected knowledge handling, and public-safe publication controls are operating effectively. MEAIR shall identify unauthorized AI use, data over-collection, access drift, cyber weakness, unapproved storage, shadow IT, model risk, publication leakage, and unresolved incidents.
418.13 MEAIR as Public Authority Boundary Control Function. MEAIR shall assess whether public authority engagements, capacity classifications, official-capacity records, data contributions, public authority references, logos, quotes, attendance statements, dashboards, maps, public-safe summaries, and public authority-facing materials remain accurate, authorized, non-endorsing, non-delegating, and non-executing. MEAIR shall identify and correct any implication of public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, adoption, or public authority delegation.
418.14 MEAIR as Finance, Certification, Procurement, Recognition, and Public Warning Boundary Control Function. MEAIR shall assess whether GCRI Canada outputs and activities avoid finance-readiness overclaim, investment advice, insurance approval, lending approval, underwriting, rating, public finance approval, procurement approval, vendor selection, certification, accreditation, conformance approval, recognition, maturity determination, Grid status overclaim, Docket overclaim, public warning, emergency command, or official determination. Boundary monitoring shall include sponsor materials, provider materials, public authority materials, publications, dashboards, maps, benchmarks, challenges, Academy records, and Nexus-compatible claims.
418.15 MEAIR as Safeguards, Protected Knowledge, and Public-Safe Claims Control Function. MEAIR shall assess whether GCRI Canada’s safeguards for Indigenous rights, Indigenous data, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, vulnerable communities, remote communities, accessibility, consent, non-consent, withdrawal, grievance, remedy, public-safe mapping, and do-no-harm controls remain effective. MEAIR shall also review public-safe claims to prevent unsafe disclosure, stigmatization, public authority misuse, sponsor misuse, provider misuse, AI inference harm, or publication overclaim.
418.16 MEAIR as Nexus Role-Separation and Anti-Capture Function. MEAIR shall assess whether GCRI Canada remains legally separate, non-executing, public-benefit aligned, and role-separated from GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, hosts, public authorities, capital readers, insurers, lenders, universities, laboratories, and other Nexus interfaces. MEAIR shall monitor capture risk, shared-liability risk, shared-treasury implication, mandate drift, provider preference, sponsor control, public authority over-proximity, and finance-boundary drift.
418.17 MEAIR Records. GCRI Canada shall maintain MEAIR records, including monitoring purpose records, evaluation purpose records, assurance purpose records, impact purpose records, renewal purpose records, standing governance records, Board oversight records, management accountability records, evidence-integrity records, research-integrity records, public-good technical asset stewardship records, data / AI / cyber control records, public authority boundary control records, finance / certification / procurement / recognition / public warning boundary control records, safeguards / protected knowledge / public-safe claims control records, Nexus role-separation and anti-capture records, findings, recommendations, renewal decisions, corrections, deprecations, retirements, escalations, closeouts, and archives.
Section 419. Performance Governance System
419.1 Performance Governance Purpose. GCRI Canada shall maintain a performance governance system to ensure that performance is assessed according to public-benefit value, evidence quality, research integrity, technical asset stewardship, data / AI / cyber discipline, public authority boundary clarity, public-safe publication, safeguards, financial sustainability, third-party conduct, Nexus role separation, and correctionability. Performance governance shall not reward scale without integrity, speed without truth, publication without evidence, public authority presence without capacity clarity, sponsor satisfaction without independence, provider adoption without neutrality, or capital attention without finance-boundary discipline.
419.2 Board Oversight of Performance Governance. The Board shall oversee performance governance by receiving appropriate reports, reviewing material indicators, questioning limitations, monitoring corrective actions, and ensuring that performance systems support mission fidelity and public-benefit purpose. Board oversight shall include attention to whether performance metrics create perverse incentives, whether public claims are supported, whether programs remain non-executing, whether public authority boundaries are preserved, whether sponsor and provider influence is controlled, and whether weak or unsafe activities are renewed, restricted, corrected, retired, or closed.
419.3 Management Responsibility for Performance Governance. Management shall design, maintain, and use performance governance processes within approved authority. Management shall ensure that performance indicators are defined, source-supported, limitation-bearing, owned, reviewed, and corrected. Management shall escalate performance failures, boundary risks, unreliable metrics, metric manipulation, uncontrolled public claims, underperforming programs, technical asset degradation, data / AI / cyber control weakness, safeguards weakness, and unresolved corrections. Management shall not use performance reports to conceal failure or inflate institutional legitimacy.
419.4 Performance Domains. GCRI Canada’s performance domains may include public-benefit performance, evidence and methods performance, research performance, technical asset performance, data / AI / cyber performance, public authority boundary performance, public-safe publication performance, safeguards performance, financial sustainability performance, sponsor / donor / provider / host / partner conduct performance, Nexus interface performance, correction performance, training performance, and governance performance. Domains may be added, retired, or revised as GCRI Canada matures, provided that revisions remain record-supported and public-benefit aligned.
419.5 Public-Benefit Performance. Public-benefit performance shall assess whether activities advance GCRI Canada’s public-benefit purpose, improve evidence literacy, strengthen public-good technical capacity, support responsible public authority learning, improve public-safe claims discipline, support safeguards, and preserve role separation. Public-benefit performance shall not be measured primarily by revenue, media attention, sponsor visibility, provider adoption, public authority attendance, capital-reader interest, or event volume. Claims of public benefit shall be evidence-supported and limitation-bearing.
419.6 Evidence and Methods Performance. Evidence and methods performance shall assess source lineage, provenance, permission, classification, completeness, accuracy, relevance, timeliness, reproducibility, uncertainty handling, evidence pack quality, method note quality, correction speed, stale evidence handling, disputed evidence handling, and supersession discipline. Evidence and methods performance shall reward carefulness, correction, and limitation disclosure, not volume of claims or confidence without support.
419.7 Research Performance. Research performance shall assess public-benefit alignment, research ethics, human-subjects review where applicable, community and protected knowledge review, sponsor and provider influence controls, conflict management, peer review, reproducibility, replication, publication quality, AI-use disclosure, research correction, and complaint handling. Research performance shall not be distorted by prestige, publication count, funder preference, sponsor satisfaction, provider uptake, or reluctance to publish negative findings.
419.8 Technical Asset Performance. Technical asset performance shall assess maintenance, documentation, security, usability, interoperability, licensing, IP chain of title, contributor governance, release discipline, vulnerability management, dependency health, provenance, signing where appropriate, deprecation, retirement, sustainability, and public-good anti-enclosure. Technical asset performance shall not imply certification, warranty, procurement approval, provider preference, security guarantee, or public authority approval.
419.9 Data / AI / Cyber Performance. Data / AI / cyber performance shall assess lawful basis, minimization, classification, access control, retention, deletion, cross-border controls, AI-use authorization, human review, model register discipline, hallucination controls, cybersecurity baseline, incident response, repository security, vendor security, training, and correction. Performance shall reward reduced risk, reliable controls, timely remediation, and disciplined non-use where appropriate, not accumulation of data, automation volume, or unreviewed AI output.
419.10 Public Authority Boundary Performance. Public authority boundary performance shall assess capacity classification quality, official-capacity records, public authority reference accuracy, non-endorsement language, data contribution controls, dashboard and map boundary language, correction of public authority misdescription, and avoidance of public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, adoption, or delegation by implication.
419.11 Public-Safe Publication Performance. Public-safe publication performance shall assess source support, limitation language, public authority review where required, finance-boundary review, procurement-boundary review, certification-boundary review, data / AI / cyber review, safeguards review, protected knowledge review, dashboard and map limitation display, correction speed, withdrawal discipline, archive traceability, and public clarity. Publication performance shall not reward volume, virality, speed, or institutional visibility over accuracy and safety.
419.12 Safeguards Performance. Safeguards performance shall assess Indigenous rights respect, Indigenous data safeguards, local and territorial knowledge safeguards, protected knowledge handling, community protocols, consent and non-consent pathways, withdrawal pathways, correction pathways, accessibility, grievance, remedy, vulnerable community safeguards, public-safe mapping, do-no-harm controls, and non-retaliation. Safeguards performance shall not be reduced to number of consultations, community attendees, or symbolic inclusion.
419.13 Financial Sustainability Performance. Financial sustainability performance shall assess whether GCRI Canada maintains sufficient lawful, mission-aligned, diversified, well-recorded, non-capturing, tax-compliant, restricted-fund-compliant, and public-benefit-aligned resources to carry out its work. Financial sustainability shall not be pursued through sponsor control, provider preference, public authority access sale, finance-readiness implication, certification sale, procurement advantage, improper private benefit, or claims that compromise integrity.
419.14 Sponsor, Donor, Provider, Host, and Partner Conduct Performance. GCRI Canada may monitor sponsor, donor, provider, host, and partner conduct to assess compliance with approved terms, non-control, public claims discipline, public authority reference restrictions, provider neutrality, procurement neutrality, data handling, confidentiality, safeguards, and correction obligations. Performance review may identify misuse, overclaim, capture pressure, noncompliance, benefit abuse, public authority confusion, or relationship risk. Poor conduct may lead to restriction, correction, non-renewal, termination, or refusal of support.
419.15 Nexus Interface Performance. Nexus interface performance shall assess whether GCRI Canada’s interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, National Companies, Project SPVs, providers, hosts, and public authorities preserve role separation, semantic compatibility, legal separateness, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, provider neutrality, and correctionability.
419.16 Performance Review Cycle. GCRI Canada shall conduct performance review periodically and upon material events, including major program launch, major public authority engagement, major publication, technical asset release, data / AI / cyber incident, public authority correction, sponsor or provider misuse, safeguards concern, major funding change, Board request, legal change, or strategic renewal. The review cycle shall identify findings, limitations, responsible owners, corrective actions, renewal decisions, and escalation needs.
419.17 Performance Escalation. Performance concerns shall be escalated where indicators show control weakness, public-benefit underperformance, evidence weakness, research integrity risk, technical asset degradation, data / AI / cyber failure, public authority boundary risk, public-safe publication issue, safeguards weakness, sponsor or provider capture, financial sustainability risk, Nexus role-separation drift, or correction backlog. Escalation may lead to program hold, publication hold, technical asset restriction, training, policy revision, Board review, or retirement of an activity.
419.18 Performance Governance Records. GCRI Canada shall maintain performance governance records, including performance governance purpose records, Board oversight records, management responsibility records, performance domain records, public-benefit performance records, evidence and methods performance records, research performance records, technical asset performance records, data / AI / cyber performance records, public authority boundary performance records, public-safe publication performance records, safeguards performance records, financial sustainability performance records, sponsor / donor / provider / host / partner conduct performance records, Nexus interface performance records, review cycle records, escalation records, corrective actions, renewal decisions, closeouts, and archives.
Section 420. KPI Architecture and Metric Governance
420.1 KPI Architecture Purpose. GCRI Canada may maintain a KPI architecture to organize performance indicators that support public-benefit mission, governance accountability, evidence quality, research integrity, technical asset stewardship, data / AI / cyber control, public authority boundary clarity, public-safe publication, safeguards, financial sustainability, Nexus interface discipline, and correctionability. KPI architecture shall be used for learning, oversight, renewal, and risk management, not for performative legitimacy, sponsor marketing, provider preference, public authority overclaim, finance-readiness implication, certification implication, or procurement advantage.
420.2 Metric Governance Purpose. Metric governance shall ensure that metrics are defined, owned, source-supported, limitation-bearing, reviewed, corrected, retired when misleading, and protected against manipulation. Metrics shall be designed to measure what matters to GCRI Canada’s public-benefit purpose and risk posture, not merely what is easy to count. Metric governance shall prevent false precision, unsupported public claims, misleading comparisons, perverse incentives, sponsor-driven indicators, provider-driven indicators, public authority misinterpretation, and capital-reader misuse.
420.3 Metric Owner. Each material metric shall have a metric owner responsible for defining the metric, explaining its purpose, ensuring that it remains aligned with mission and risk, reviewing limitations, initiating correction, and recommending renewal, suspension, or retirement. The metric owner may be a program owner, officer, data steward, research lead, technical asset steward, publication owner, safeguards lead, public authority interface owner, finance lead, or other authorized person. Metric ownership shall not imply authority to manipulate results.
420.4 Metric Custodian. Each material metric shall have a custodian responsible for maintaining source data, calculation method, collection process, version history, quality checks, access controls, retention, and records. The custodian may differ from the owner to preserve segregation of duties where appropriate. Custodians shall protect metric data from unauthorized editing, sponsor influence, provider influence, selective reporting, AI hallucination, undocumented transformation, or deletion without authority.
420.5 Metric Definition. Each material metric shall have a clear definition identifying what is measured, why it is measured, what is included, what is excluded, the unit of measurement, calculation method, relevant time period, source, owner, custodian, limitations, and public-safe status. Ambiguous metrics shall not be used for material governance, public claims, sponsor reporting, public authority-facing materials, provider-facing materials, or public-safe summaries without clarification and limitation language.
420.6 Metric Data Source. Metric data sources shall be identified and recorded. Sources may include program records, publication records, technical asset registers, repository logs, training records, attendance records, incident records, correction records, access logs, survey data, public authority records, safeguards records, financial records, audit records, controlled-room records, AI system logs, cyber logs, and other records. Data sources shall be assessed for reliability, completeness, authority, privacy, classification, and permitted use.
420.7 Metric Collection Method. Metric collection methods shall be documented and proportionate to the metric’s purpose. Collection may be manual, automated, survey-based, system-generated, repository-based, finance-system-based, publication-review-based, or review-based. Collection methods shall avoid unnecessary personal information, protected knowledge exposure, public authority data misuse, unapproved AI processing, biased sampling, selective exclusion, duplicate counting, and unrecorded transformation. Collection methods shall be revisable where they create misleading results.
420.8 Metric Frequency. Metric frequency shall be defined according to governance need, data availability, risk, cost, and usefulness. Frequency may be real-time, monthly, quarterly, annually, event-based, release-based, program-based, incident-based, or review-based. Excessive frequency shall not be required where it creates burden without insight, and infrequent measurement shall not be used to avoid oversight. Material high-risk indicators may require more frequent review.
420.9 Metric Limitations. Every material metric shall include limitations sufficient to prevent misinterpretation. Limitations may include data quality limits, missing data, lag, bias, confidence, scope, exclusions, small sample size, non-comparability, qualitative judgment, public authority capacity limits, sponsor influence risk, provider influence risk, public-safe release limits, and lack of causal inference. Public materials shall not present metrics as more precise, comparable, causal, complete, or authoritative than they are.
420.10 Metric Confidence and Uncertainty. Metrics shall include confidence or uncertainty notes where material. Confidence may be high, moderate, low, provisional, experimental, estimated, incomplete, disputed, or not suitable for public use. Uncertainty shall be disclosed where metrics depend on incomplete sources, model outputs, survey response, qualitative judgments, changing definitions, small samples, public authority records, AI-derived analysis, or rapidly changing conditions. Metrics with uncertainty shall not be used for overconfident claims.
420.11 Metric Manipulation Risk. Metric governance shall identify manipulation risk, including gaming, selective counting, inflated attendance, inflated public authority presence, exaggerated publication performance, suppressed corrections, sponsor satisfaction inflation, provider adoption inflation, capital attention inflation, dashboard activity inflation, AI automation inflation, or underreporting of incidents. Metrics with manipulation risk shall require controls, review, contextual interpretation, and, where necessary, retirement or redesign.
420.12 Metric Public-Safe Status. Each material metric shall be classified for public-safe status. Metrics may be public, internal, controlled, restricted, experimental, provisional, not-for-public-use, public-authority-sensitive, finance-sensitive, sponsor-sensitive, provider-sensitive, privacy-sensitive, protected-knowledge-sensitive, or security-sensitive. Metrics shall not be published where doing so could mislead, expose sensitive data, reveal protected knowledge, imply public authority approval, imply finance-readiness, imply certification, imply procurement approval, or create public-safe harm.
420.13 Metric Retirement. Metrics shall be retired, suspended, re-scoped, replaced, or archived where they become misleading, stale, unreliable, manipulable, duplicative, burdensome, misaligned with mission, unsafe for public use, inconsistent with law, or likely to create perverse incentives. Retirement shall include version history, reason, effective date, affected reports, replacement metric where any, and correction of prior materials where necessary. Retired metrics shall not continue to appear in public claims without archive status.
420.14 KPI Tree. GCRI Canada may maintain a KPI tree connecting strategic public-benefit objectives to operational measures. The KPI tree may include governance performance, program performance, evidence quality, research integrity, technical asset stewardship, data / AI / cyber control, public-safe publication, safeguards, financial sustainability, training, correction, and Nexus interface performance. The KPI tree shall preserve hierarchy, avoid duplication, identify owners, and prevent single metrics from becoming proxies for institutional legitimacy.
420.15 KRI Tree. GCRI Canada may maintain a KRI tree connecting risk domains to early-warning indicators. The KRI tree may include legal risk, governance risk, public authority boundary risk, finance-boundary risk, procurement risk, certification overclaim risk, data / AI / cyber risk, safeguards risk, sponsor capture risk, provider capture risk, research integrity risk, public-safe publication risk, technical asset risk, financial sustainability risk, and Nexus role-separation risk. KRIs shall trigger review and correction, not blame avoidance.
420.16 Impact Metric Tree. GCRI Canada may maintain an impact metric tree to connect public-benefit activities to evidence of outcomes, learning, capacity, technical stewardship, public-safe publication improvement, safeguards improvement, correction improvement, and Nexus-compatible institutional discipline. Impact metrics shall distinguish outputs, outcomes, contribution, attribution, evidence strength, uncertainty, and limitations. Impact metrics shall not imply causality, public authority action, finance outcomes, procurement outcomes, or provider success unless supported by competent evidence.
420.17 Evidence Quality Metrics. Evidence quality metrics may include source lineage completeness, provenance completeness, custody completeness, timestamp currency, permission status, classification status, completeness score, accuracy review completion, relevance review completion, reproducibility status, confidence status, stale evidence ratio, disputed evidence count, evidence correction time, and evidence pack completion. Such metrics shall support evidence integrity and shall not be presented as absolute truth.
420.18 Research Integrity Metrics. Research integrity metrics may include ethics review completion, conflict disclosure completion, peer review completion, reproducibility review, replication review, method note completion, AI-use disclosure completion, publication correction rate, complaint resolution, sponsor influence review, provider influence review, protected knowledge review, and research misconduct closeout. These metrics shall support integrity and shall not punish correction or negative findings.
420.19 Data / AI / Cyber Metrics. Data / AI / cyber metrics may include lawful basis completion, data minimization review, access review completion, retention compliance, deletion completion, AI system inventory completion, model register completeness, AI human review completion, AI incident count, cybersecurity baseline status, vulnerability remediation status, repository security status, phishing training completion, incident response time, backup test status, and vendor security review completion. Metrics shall not reward unsafe automation, data accumulation, or superficial compliance.
420.20 Safeguards Metrics. Safeguards metrics may include community protocol review completion, Indigenous / local / territorial knowledge review completion, protected knowledge classification, consent pathway completion, non-consent tracking, withdrawal response, correction response, grievance closeout, accessibility support, public-safe mapping review, do-no-harm controls, and safeguards escalation resolution. Safeguards metrics shall be qualitative as well as quantitative where needed and shall not reduce community legitimacy to attendance.
420.21 Public Authority Boundary Metrics. Public authority boundary metrics may include capacity classification completion, official-capacity record completion, public authority reference approval completion, logo permission status, quote permission status, non-endorsement language use, public authority data contribution record completeness, public authority correction count, overclaim correction time, and boundary training completion. Metrics shall not reward public authority presence unless capacity clarity and boundaries are satisfied.
420.22 Finance Boundary Metrics. Finance boundary metrics may include non-reliance language completion, finance-sensitive material review completion, public finance reader classification completion, capital-reader room control status, finance overclaim count, correction time, sponsor benefit review, public finance reference review, and investment-advice boundary training. Metrics shall not reward capital attention, investor meetings, or proof-pack circulation without boundary discipline.
420.23 Publication and Claims Metrics. Publication and claims metrics may include source verification completion, public-safe review completion, AI-use review, public authority reference review, finance-boundary review, certification-boundary review, procurement-boundary review, safeguards review, correction count, correction time, retraction count, withdrawal count, archive traceability, and limitation language completeness. Publication metrics shall not reward volume, speed, or virality over accuracy.
420.24 Nexus Interface Metrics. Nexus interface metrics may include compatibility note completion, divergence log completion, semantic alignment review, interface record completeness, role-separation review, correction synchronization, cross-entity routing completion, anti-capture review, legal separateness review, no-shared-liability review, and Nexus-compatible claims review. Nexus interface metrics shall not imply shared authority, merger, recognition, maturity, finance-readiness, or procurement approval.
420.25 Metric Register and Records. GCRI Canada shall maintain metric register and records, including KPI architecture purpose records, metric governance purpose records, metric owner records, metric custodian records, metric definitions, data sources, collection methods, frequency records, limitations, confidence and uncertainty records, manipulation risk reviews, public-safe status records, metric retirement records, KPI tree records, KRI tree records, impact metric tree records, evidence quality metric records, research integrity metric records, data / AI / cyber metric records, safeguards metric records, public authority boundary metric records, finance boundary metric records, publication and claims metric records, Nexus interface metric records, corrections, revisions, retirements, closeouts, and archives.
Section 421. Non-Perverse-Incentives Rule
421.1 Non-Perverse-Incentives Purpose. GCRI Canada shall design, review, and revise metrics, targets, dashboards, KPIs, KRIs, impact indicators, program scorecards, management reports, sponsor reports, donor reports, public authority reports, public-safe summaries, and public claims to avoid perverse incentives. A perverse incentive exists where a metric rewards behaviour inconsistent with public-benefit purpose, evidence integrity, research integrity, data minimization, AI accountability, cybersecurity, privacy, safeguards, public authority boundary discipline, finance-boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, correctionability, or Nexus role separation.
421.2 No Metric That Rewards Overclaim. No metric shall reward or pressure GCRI Canada personnel or participants to overclaim evidence, public benefit, public authority involvement, finance-readiness, certification, recognition, maturity, procurement relevance, safety, resilience, security, technical readiness, public warning relevance, or Nexus-compatible status. Metrics shall recognize accurate limitation language, correction, and conservative claims as performance strengths, not weaknesses.
421.3 No Metric That Rewards Speed Over Truth. No metric shall reward speed where speed compromises source verification, evidence quality, methods review, public-safe classification, public authority reference review, data / AI / cyber review, safeguards review, legal review, correction, or Board oversight. Timeliness may be measured, but it shall be balanced against accuracy, integrity, safety, and correctionability. Where speed and truth conflict, truth shall prevail.
421.4 No Metric That Rewards Publication Volume Over Evidence Quality. No metric shall reward publication volume, article count, report count, deck count, social media output, dashboard launches, dataset releases, software releases, or media appearances without regard to source support, methods support, limitation language, public-safe review, public authority boundary review, finance-boundary review, safeguards review, and correction path. Publication quality and public-safe discipline shall outrank publication quantity.
421.5 No Metric That Rewards Sponsor Satisfaction Over Research Integrity. No metric shall reward sponsor satisfaction, donor satisfaction, funder renewal, sponsor visibility, sponsor quote use, sponsor benefit activation, or sponsor retention where such satisfaction depends on controlling research agenda, shaping findings, suppressing negative results, influencing publication, avoiding correction, obtaining public authority access, securing provider preference, implying finance-readiness, implying certification, or creating procurement advantage. Sponsor support shall remain support-without-control.
421.6 No Metric That Rewards Provider Adoption Over Provider Neutrality. No metric shall reward provider adoption, provider participation, provider contribution, provider logo use, provider market uptake, provider satisfaction, provider-controlled technical baseline use, or provider claims where such metric could undermine provider neutrality, procurement neutrality, competition discipline, public authority boundary clarity, research integrity, or public-safe claims. Technical asset use may be monitored, but not as provider endorsement, procurement advantage, or certification substitute.
421.7 No Metric That Rewards Public Authority Presence Over Capacity-Clarity. No metric shall reward the number, seniority, title, visibility, logo value, or jurisdictional significance of public authority participants without also requiring capacity classification, reference permission, non-endorsement language, public authority boundary review, and correction path. Public authority presence shall not be treated as endorsement, adoption, regulatory approval, procurement approval, funding approval, public finance approval, public warning authority, emergency command, public-private partnership, sovereign obligation, or legitimacy substitute.
421.8 No Metric That Rewards Capital Attention Over Finance Boundary Discipline. No metric shall reward capital-reader interest, investor meetings, public finance reader attendance, proof-pack circulation, finance-room access, GRA interface attention, public finance attention, or funding prospects in a manner that weakens non-reliance, finance-boundary discipline, no-investment-advice rules, no-solicitation rules, no-underwriting rules, no-rating rules, no-public-finance-approval rules, or no-finance-readiness-determination rules. Capital readability shall never override regulated-perimeter discipline.
421.9 No Metric That Rewards Dashboard Activity Over Public Safety. No metric shall reward dashboard usage, map views, alert-like activity, signal frequency, observability traffic, digital twin interactions, or data refresh volume where such activity may create public warning implication, emergency command implication, false precision, unsafe reliance, sensitive infrastructure exposure, protected knowledge exposure, public authority confusion, or public panic. Dashboard and map metrics shall include limitation, public-safe status, correction, and boundary review.
421.10 No Metric That Rewards AI Automation Over Human Accountability. No metric shall reward AI automation volume, AI-generated output count, AI-assisted publication speed, agentic workflow completion, automated review rate, or AI cost savings where such automation reduces human accountability, source verification, privacy, security, safeguards, public-safe publication, or correction. AI productivity metrics shall be balanced by hallucination, fabricated citation, human review, data leakage, bias, drift, prompt injection, and incident metrics.
421.11 No Metric That Rewards Data Accumulation Over Minimization. No metric shall reward data accumulation, dataset size, data lake growth, number of records, telemetry volume, sensor coverage, participant data volume, public authority data volume, or model training corpus size without considering lawful basis, purpose limitation, minimization, classification, retention, deletion, access controls, privacy, public authority terms, protected knowledge, and public-safe publication. Responsible non-collection and deletion may be positive performance.
421.12 No Metric That Rewards Open Release Over Security, Privacy, or Protected Knowledge. No metric shall reward open release of software, data, dashboards, maps, model artifacts, publications, technical baselines, schemas, APIs, or repositories where open release would compromise security, privacy, public authority data, protected knowledge, infrastructure sensitivity, cyber-sensitive information, export controls, sanctions controls, community safeguards, or public-safe publication. Openness shall be governed, classified, and correctionable.
421.13 No Metric That Rewards Nexus-Compatible Claims Without Record Support. No metric shall reward Nexus-compatible claims, interface claims, Grid claims, Rails claims, Docket claims, Observatory claims, Academy claims, competence-cell claims, consortium claims, national company claims, project SPV claims, provider claims, or recognition-adjacent claims without competent records, role-separation review, semantic alignment, limitation language, correction path, and authority clarity. Nexus language shall be disciplined and not used as a legitimacy multiplier without record support.
421.14 Perverse Incentive Review. GCRI Canada shall review material metrics for perverse incentives before adoption and periodically thereafter. Review shall assess whether the metric could distort conduct, encourage overclaim, suppress correction, encourage unsafe release, reward capture, incentivize data over-collection, incentivize public authority over-proximity, create finance-boundary drift, create procurement implication, encourage AI misuse, or undermine safeguards. Review shall include relevant owners, custodians, compliance, risk, data / AI / cyber, safeguards, publication, and Board oversight where appropriate.
421.15 Metric Re-Scoping, Suspension, or Retirement. Where a metric creates or materially risks perverse incentives, GCRI Canada shall re-scope, suspend, retire, replace, qualify, restrict, or correct the metric. Re-scoping may include adding limitations, changing the denominator, adding balancing indicators, moving from public to internal use, removing targets, changing ownership, adding review gates, or replacing quantitative indicators with qualitative assessment. Suspended or retired metrics shall not continue to drive incentives or public claims.
421.16 Non-Perverse-Incentives Records. GCRI Canada shall maintain non-perverse-incentives records, including purpose records, no-overclaim metric records, no-speed-over-truth records, no-publication-volume-over-evidence-quality records, no-sponsor-satisfaction-over-research-integrity records, no-provider-adoption-over-provider-neutrality records, no-public-authority-presence-over-capacity-clarity records, no-capital-attention-over-finance-boundary-discipline records, no-dashboard-activity-over-public-safety records, no-AI-automation-over-human-accountability records, no-data-accumulation-over-minimization records, no-open-release-over-security / privacy / protected knowledge records, no-Nexus-compatible-claims-without-record-support records, perverse incentive reviews, re-scoping records, suspension records, retirement records, corrections, closeouts, and archives.
Section 422. Evidence Quality Evaluation
422.1 Evidence Quality Evaluation Purpose. GCRI Canada shall evaluate evidence quality to ensure that evidence used in research, methods, observability, ontology, public-good software, technical baselines, dashboards, maps, publications, Academy materials, public authority learning, proof packs, public-safe summaries, and Nexus-compatible interfaces is source-supported, permissioned, classified, current, relevant, accurate, complete, limitation-bearing, reproducible where feasible, and correctionable. Evidence quality evaluation shall support technical truth discipline while avoiding absolute truth claims, public warning, emergency command, public authority decision, finance-readiness, certification, procurement approval, recognition, or maturity determination.
422.2 Source Lineage Review. Source lineage review shall identify where evidence came from, who provided it, how it was obtained, what record supports it, what transformations occurred, and what downstream outputs rely on it. Source lineage shall distinguish primary sources, secondary sources, public sources, public authority sources, community sources, protected knowledge, AI-generated materials, sensor data, telemetry, dashboards, maps, models, and derived outputs. Evidence lacking adequate lineage shall be restricted, qualified, rechecked, or excluded from material outputs.
422.3 Provenance Review. Provenance review shall assess origin, authenticity, chain of creation, version, author, system, repository, instrument, sensor, model, public authority source, community source, dataset, or document origin. Provenance review shall detect spoofed, fabricated, altered, stale, unauthorized, misattributed, AI-generated, or unverified evidence. Provenance uncertainty shall be recorded and reflected in confidence, limitation, and publication status.
422.4 Custody Review. Custody review shall assess whether evidence has been stored, transferred, accessed, transformed, summarized, embedded, dashboarded, mapped, or published under appropriate controls. Custody review shall identify whether evidence was handled through approved tools, secure storage, access controls, classification, confidentiality, AI-use restrictions, and transfer rules. Breaks in custody shall be recorded and may require exclusion, revalidation, correction, or incident review.
422.5 Timestamp and Currency Review. Timestamp and currency review shall assess when evidence was created, collected, received, updated, reviewed, superseded, deprecated, archived, or corrected. Evidence may become stale because conditions change, sources update, public authority terms change, data rights change, model versions change, methods improve, dashboards refresh, or publications supersede prior outputs. Currency limitations shall be disclosed where material, and stale evidence shall not support current claims without review.
422.6 Permission and Authority Review. Permission and authority review shall determine whether GCRI Canada may lawfully and ethically use, store, analyze, summarize, publish, dashboard, map, transfer, or AI-process the evidence. Review shall address ownership, license, consent, non-consent, public authority authorization, data-sharing terms, confidentiality, research ethics, protected knowledge, Indigenous governance protocols, community protocols, privacy, export controls, sanctions, and publication permissions. Evidence lacking authority shall be refused, quarantined, restricted, deleted, or corrected.
422.7 Classification Review. Classification review shall assign or confirm evidence classification, including public, internal, controlled, restricted, confidential, public authority-sensitive, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, protected-knowledge-sensitive, export-controlled, sanctions-sensitive, research-sensitive, or experimental. Classification shall travel with extracts, summaries, embeddings, dashboards, maps, model outputs, publications, controlled annexes, and archives. Misclassification shall be corrected.
422.8 Completeness Review. Completeness review shall assess whether the evidence is sufficiently complete for the intended use. Incomplete evidence may include missing fields, missing context, missing source documents, partial data, incomplete time periods, missing negative results, missing uncertainty, missing permissions, missing public authority capacity, or missing safeguards review. Incomplete evidence may be used only with appropriate limitations or excluded where completeness is essential.
422.9 Accuracy Review. Accuracy review shall assess whether evidence is factually correct, internally consistent, externally corroborated where appropriate, free from transcription error, free from AI hallucination, free from fabricated citation, free from mapping error, and free from calculation error. Accuracy review may include source checking, cross-checking, peer review, automated validation, manual validation, public authority confirmation where required, community confirmation where appropriate, or technical testing. Accuracy uncertainty shall be recorded.
422.10 Relevance Review. Relevance review shall assess whether evidence is relevant to the claim, method, publication, dashboard, map, program, training, public authority learning, technical baseline, or Nexus-compatible interface for which it is used. Evidence may be accurate but irrelevant, overgeneralized, out of scope, jurisdictionally mismatched, temporally mismatched, sectorally mismatched, or inappropriate for the audience. Irrelevant evidence shall not be used to inflate claims.
422.11 Timeliness Review. Timeliness review shall assess whether evidence is available and reviewed at a time appropriate to its use. Timeliness shall consider publication deadlines, public-safe review, data refresh cadence, dashboard update status, map update status, public authority timing, legal deadlines, incident timing, and correction timing. Timeliness pressure shall not justify use of unverified, unauthorized, unsafe, or misleading evidence.
422.12 Reproducibility Review. Reproducibility review shall assess whether evidence-derived findings can be reproduced, replicated, recalculated, re-run, rechecked, or independently reviewed where feasible. Reproducibility may require preservation of data, code, methods, model versions, parameters, prompts, retrieval settings, dependencies, environment records, test harnesses, and assumptions. Where reproducibility is not feasible because of confidentiality, protected knowledge, public authority restrictions, or data limits, limitations shall be recorded.
422.13 Calibration Review. Calibration review shall assess whether confidence scores, risk scores, model scores, dashboard indicators, map indicators, maturity-adjacent indicators, evidence weights, benchmarks, probabilities, thresholds, or classifications correspond reasonably to observed performance and available evidence. Calibration shall prevent false precision and overconfident outputs. Poorly calibrated outputs shall be corrected, restricted, re-labeled, retrained, revalidated, or retired.
422.14 Confidence and Uncertainty Review. Confidence and uncertainty review shall identify the level of support, uncertainty, assumptions, limits, disputes, missing evidence, contradictory evidence, source quality, model risk, data quality, and method reliability associated with evidence. Confidence shall be communicated honestly and proportionately. Low-confidence evidence shall not be used for high-stakes claims without limitation, escalation, or exclusion.
422.15 Disputed, Failed, Spoofed, Missing, Stale, or Superseded Evidence Review. GCRI Canada shall review disputed, failed, spoofed, missing, stale, or superseded evidence before use or continued reliance. Such evidence may require quarantine, exclusion, revalidation, public-safe clarification, correction, supersession, withdrawal, archive note, or downstream dependency review. Evidence known to be spoofed, fabricated, unauthorized, or materially false shall not be used except as an example of error or misconduct with appropriate controls.
422.16 Evidence Pack Review. Evidence packs shall be reviewed for completeness, source lineage, permission, classification, methods support, limitation language, public-safe status, public authority boundary language, finance-boundary language where relevant, certification-boundary language where relevant, procurement-boundary language where relevant, safeguards review, versioning, and correction path. Evidence packs shall not be represented as public authority approval, finance-readiness, certification, procurement approval, rating, recognition, maturity, public warning, emergency command, or professional opinion.
422.17 Evidence Correction Performance. GCRI Canada shall evaluate evidence correction performance, including time to identify errors, time to correct errors, downstream dependency review, public-safe clarification, controlled notice, archive update, recurrence, root cause, and effectiveness of corrective action. Evidence correction shall be treated as evidence integrity, not institutional embarrassment. Repeated evidence failures shall trigger methods review, training, tool review, or governance review.
422.18 Evidence Quality Evaluation Records. GCRI Canada shall maintain evidence quality evaluation records, including purpose records, source lineage review records, provenance review records, custody review records, timestamp and currency review records, permission and authority review records, classification review records, completeness review records, accuracy review records, relevance review records, timeliness review records, reproducibility review records, calibration review records, confidence and uncertainty review records, disputed / failed / spoofed / missing / stale / superseded evidence review records, evidence pack review records, evidence correction performance records, corrections, supersessions, withdrawals, closeouts, and archives.
Section 423. Research Integrity Review
423.1 Research Integrity Review Purpose. GCRI Canada shall maintain research integrity review to ensure that research agendas, methods, collaborations, evidence outputs, publications, technical baselines, public-good software, Academy materials, fellowships, labs, challenges, benchmarking, public authority learning, and Nexus-compatible outputs are public-benefit aligned, ethically reviewed where required, conflict-controlled, source-supported, reproducible where feasible, AI-use disclosed where required, sponsor- and provider-independent, safeguards-compliant, public-safe, and correctionable. Research integrity review shall protect the credibility of GCRI Canada as a public-benefit technical institution.
423.2 Research Agenda Review. Research agenda review shall assess whether proposed and ongoing research aligns with GCRI Canada’s public-benefit purpose, upstream role, non-execution posture, Nexus role separation, technical stewardship function, public authority boundaries, finance boundaries, safeguards, data / AI / cyber controls, and institutional capacity. The research agenda shall not be controlled by sponsor preference, provider interest, donor pressure, public authority proximity, capital-reader demand, media value, or institutional prestige.
423.3 Public-Benefit Alignment Review. Public-benefit alignment review shall assess whether research reasonably contributes to evidence quality, methods improvement, observability, ontology, public-good software, open technical baselines, public authority learning, public-safe publication, safeguards, technical literacy, correctionability, or Nexus-compatible role separation. Research shall not be justified by private commercial benefit alone, provider marketing, sponsor reputation, procurement advantage, finance-readiness implication, certification implication, recognition purchase, or public authority access.
423.4 Research Ethics Review. Research ethics review shall determine whether the research requires human-subjects review, institutional review, community review, Indigenous governance review, protected knowledge review, health-sensitive review, privacy review, data / AI / cyber review, or other ethics review. Research shall not proceed where required review is absent, incomplete, or materially exceeded. Ethics review conditions shall be recorded and followed.
423.5 Human-Subjects, Community, Indigenous / Local / Territorial Knowledge, Health-Sensitive, and Protected Knowledge Review. Research involving persons, communities, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, health-sensitive data, vulnerable communities, protected knowledge, or public-safe mapping shall undergo appropriate review before collection, analysis, AI use, mapping, publication, transfer, or controlled-room disclosure. Review shall assess consent, non-consent, withdrawal, attribution, confidentiality, accessibility, community protocols, FPIC where applicable, public-safe handling, and remedy.
423.6 Sponsor and Provider Influence Review. Research integrity review shall assess whether sponsors, donors, funders, providers, vendors, hosts, public authorities, capital readers, National Consortium Companies, Project SPVs, or other actors have attempted to influence research questions, evidence selection, methods, authorship, peer review, publication timing, negative-result handling, public authority language, finance-boundary language, certification language, procurement language, recognition language, or correction. Improper influence shall be refused, documented, corrected, or escalated.
423.7 Conflict Review. Research conflicts shall be disclosed, reviewed, managed, mitigated, recused, or prohibited. Conflicts may include financial interests, employment, consulting, sponsorship, provider relationships, public authority relationships, donor interests, funder interests, IP interests, publication interests, authorship interests, data access, personal relationships, institutional affiliations, National Consortium Company links, Project SPV links, or capital interests. Conflict review shall be recorded and revisited when circumstances change.
423.8 Peer Review Review. Peer review review shall assess whether peer review or expert review is appropriate, independent, competent, conflict-controlled, timely, and record-supported. Peer review may apply to research outputs, methods, technical baselines, benchmarks, models, dashboards, maps, public-safe summaries, software, or evidence packs. Peer review shall not be represented as certification, public authority approval, finance-readiness, procurement approval, recognition, maturity, or public warning authority.
423.9 Reproducibility Review. Reproducibility review shall assess whether research findings can be reproduced or reviewed using available records, data, code, methods, prompts, models, assumptions, environment, and version history. Where confidentiality, privacy, public authority terms, protected knowledge, or security prevent full reproducibility, GCRI Canada shall document limitations and provide controlled reproducibility where lawful and appropriate. Reproducibility gaps shall inform confidence and publication language.
423.10 Replication Review. Replication review shall assess whether important findings, methods, benchmarks, technical baselines, or public-safe outputs require independent replication, internal replication, external replication, controlled replication, or no replication due to feasibility limits. Replication failures shall be treated as learning and may require correction, limitation, method revision, supersession, withdrawal, or archive note. Replication shall not be ignored where results are high-impact or likely to be relied upon.
423.11 Method Notes Review. Method notes shall be reviewed for clarity, scope, assumptions, data sources, limitations, validation, reproducibility, versioning, public-safe status, AI use, uncertainty, and correction path. Method notes shall distinguish evidence methods from public authority decisions, finance-readiness determinations, certification, procurement approvals, ratings, recognition, maturity, public warnings, emergency commands, and professional opinions. Method notes shall be updated where methods materially change.
423.12 Research Publication Review. Research publications shall be reviewed for source support, methods support, authorship, attribution, conflict disclosure, AI-use disclosure where required, public authority references, finance-boundary language, certification-boundary language, procurement-boundary language, public warning language, protected knowledge, privacy, cyber sensitivity, infrastructure sensitivity, public-safe status, and correction path. Publications shall not be released where review identifies unresolved material risk.
423.13 AI-Use Disclosure Review. Research integrity review shall assess whether AI use in research design, literature review, coding, analysis, summarization, translation, transcription, drafting, visualization, citation support, peer review, or publication requires disclosure. AI-use disclosure shall be accurate and proportionate. AI assistance shall not obscure human accountability, source verification, methods responsibility, data rights, or correction obligations. Fabricated citations, hallucinated findings, or AI-generated unsupported claims shall be corrected.
423.14 Research Error, Correction, Supersession, Withdrawal, Retraction, and Archive Review. GCRI Canada shall review research errors, corrections, supersessions, withdrawals, retractions, and archive status. Review shall identify affected outputs, downstream dependencies, public authority references, data issues, AI issues, protected knowledge issues, sponsor or provider claims, public-safe implications, and required notices. Correction shall be timely, traceable, and not blocked by sponsor, provider, donor, funder, public authority, reputational, or media concerns.
423.15 Research Misconduct and Complaint Review. Research misconduct allegations and complaints shall be intaken, triaged, reviewed, investigated, corrected, and recorded according to severity. Misconduct may include fabrication, falsification, plagiarism, fabricated citations, data manipulation, method manipulation, image manipulation, AI-assisted fabrication, undisclosed conflicts, sponsor or provider influence, authorship misconduct, protected knowledge misuse, retaliation, or failure to correct. Complaints shall be handled fairly, confidentially where appropriate, and without retaliation.
423.16 Research Integrity Review Records. GCRI Canada shall maintain research integrity review records, including purpose records, research agenda review records, public-benefit alignment review records, research ethics review records, human-subjects / community / Indigenous / local / territorial knowledge / health-sensitive / protected knowledge review records, sponsor and provider influence review records, conflict review records, peer review records, reproducibility review records, replication review records, method note review records, research publication review records, AI-use disclosure review records, research error / correction / supersession / withdrawal / retraction / archive review records, misconduct and complaint review records, findings, corrective actions, closeouts, and archives.
Section 424. Technical Asset Review
424.1 Technical Asset Review Purpose. GCRI Canada shall maintain technical asset review to ensure that public-good technical assets and internal technical assets remain lawful, secure, documented, maintainable, interoperable, public-safe, properly licensed, properly versioned, contribution-controlled, dependency-aware, vulnerability-managed, anti-enclosure-aligned, and correctionable. Technical asset review shall apply to software, schemas, APIs, SDKs, dashboards, data tools, data dictionaries, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, technical baselines, repositories, release artifacts, and controlled annexes.
424.2 Public-Good Technical Asset Register Review. GCRI Canada shall review its public-good technical asset register to confirm asset identifiers, names, types, owners, stewards, maintainers, repositories, versions, statuses, licenses, classifications, public-safe status, security status, dependency status, data rights, export-control flags, known limitations, correction paths, deprecation status, and retirement status. Register inaccuracies shall be corrected. Unregistered material assets shall be added, quarantined, or decommissioned.
424.3 Software Review. Software review shall assess purpose, functionality, maintainability, security, documentation, licensing, dependencies, contribution history, test coverage, release status, public-safe status, repository controls, secrets exposure, controlled data exposure, AI-generated code review, vulnerability status, and correction path. Software shall not be released publicly where it includes restricted data, protected knowledge, public authority data, cyber-sensitive content, infrastructure-sensitive content, secrets, license conflict, or unreviewed controlled technology.
424.4 Schema and API Review. Schema and API review shall assess semantic clarity, versioning, compatibility, security, access control, data minimization, privacy, public authority terms, protected knowledge, interoperability, documentation, backward compatibility, deprecation path, and misuse risk. Schemas and APIs shall not encode misleading public authority status, finance-readiness status, certification status, procurement status, recognition status, maturity status, or Nexus-compatible status without competent record support.
424.5 Dashboard and Data Tool Review. Dashboard and data tool review shall assess data sources, update status, refresh cadence, limitations, confidence and uncertainty display, access controls, public-safe status, public warning boundary, emergency command boundary, public authority boundary, finance-boundary, certification-boundary, procurement-boundary, protected knowledge, cyber sensitivity, infrastructure sensitivity, privacy, correction path, and incident response. Dashboards shall not be treated as public warnings, public authority decisions, finance-readiness determinations, certifications, procurement approvals, recognition, maturity, or performance guarantees.
424.6 Reference Architecture Review. Reference architecture review shall assess purpose, scope, assumptions, interoperability, public-good orientation, security, privacy, data / AI / cyber controls, public authority boundary, finance-boundary, provider neutrality, procurement neutrality, export-control sensitivity, controlled technology risk, documentation, versioning, and correction path. Reference architectures shall not be represented as mandatory procurement specifications, certified architectures, public authority-approved designs, engineering sign-offs, or provider endorsements.
424.7 Technical Baseline Review. Technical baseline review shall assess evidence support, methods support, source lineage, versioning, interoperability, security, public-safe status, controlled annexes, test harnesses, gold vectors, negative tests, documentation, open-source status, licensing, contributor terms, dependency health, and correction path. Technical baselines shall be described as public-good baselines or methods artifacts, not certification, accreditation, compliance approval, procurement approval, provider preference, finance-readiness, recognition, or maturity determination.
424.8 Open-Source Governance Review. Open-source governance review shall assess repository ownership, maintainers, contribution rules, code of conduct where applicable, contributor license terms, licensing, issue handling, pull request review, release process, vulnerability disclosure, public-safe classification, community conduct, fork policy, compatibility claims, takedown procedures, and anti-enclosure. Open-source release shall not override data rights, confidentiality, public authority terms, protected knowledge safeguards, export controls, or cyber-sensitive restrictions.
424.9 Contributor Terms Review. Contributor terms review shall assess whether contributors have accepted appropriate terms, contributor license agreements, assignments, patent grants where appropriate, moral rights waivers or consents where lawful, confidentiality obligations, data rights disclosures, AI-use disclosures, conflict disclosures, employer or funder interest disclosures, open-source license disclosures, security obligations, and vulnerability disclosure obligations. Contributions lacking required terms may be rejected, quarantined, modified, withdrawn, or taken down.
424.10 IP and Licensing Review. IP and licensing review shall assess ownership, chain of title, background IP, foreground IP, derivative works, third-party rights, open-source licenses, license compatibility, patent risk, moral rights, attribution, sublicensing, public-good licensing posture, restricted licensing, controlled assets, sponsor or provider rights, university or laboratory rights, and publication rights. IP review shall preserve public-good stewardship while avoiding unauthorized release or private enclosure.
424.11 Secure Development Review. Secure development review shall assess code review, branch protection, dependency scanning, secrets scanning, test coverage, negative testing, secure configuration, authentication, authorization, logging, input validation, cryptographic handling, vulnerability handling, AI-generated code review, release approval, and secure documentation. Secure development review shall apply to public-good software, internal software, restricted software, dashboards, APIs, SDKs, scripts, and automation tools.
424.12 Repository Security Review. Repository security review shall assess access, roles, maintainers, branch protections, secrets, issue exposure, pull request exposure, release permissions, artifact storage, dependency files, license files, public/private visibility, public authority data exclusion, protected knowledge exclusion, controlled technology exclusion, export-control flags, vulnerability disclosure, and offboarding. Repository access shall be least-privilege and shall not be granted by status alone.
424.13 Dependency, SBOM, Signing, Provenance, Vulnerability, and Release Review. GCRI Canada may review dependencies, software bills of materials, signing, provenance, vulnerability status, release integrity, build processes, artifact integrity, package registry status, license status, and release notes. Review shall identify vulnerable dependencies, untrusted packages, license conflicts, unsigned releases where signing is required, provenance gaps, build reproducibility gaps, and public-safe release risks. Release shall be held or corrected where risk is material.
424.14 Fork and Compatibility Claim Review. Forks, derivative versions, compatibility claims, Nexus-compatible claims, baseline-compatible claims, API-compatible claims, schema-compatible claims, Grid claims, Rails claims, Observatory claims, or public-good asset compatibility claims shall be reviewed for accuracy, authority, version, limitations, license compliance, public-safe status, and misuse risk. Compatibility claims shall not imply certification, endorsement, procurement approval, public authority approval, finance-readiness, recognition, maturity, or provider preference.
424.15 Public-Good Anti-Enclosure Review. Technical asset review shall assess whether public-good technical assets are being enclosed, captured, privatized, sponsor-controlled, provider-controlled, license-restricted contrary to purpose, made dependent on one vendor, used for proprietary lock-in, or converted into procurement advantage. Anti-enclosure review shall preserve open technical baselines, public-good software stewardship, governed commons, neutral access, correctionability, and role separation. Restrictions may still apply for security, privacy, protected knowledge, export controls, or public-safe reasons.
424.16 Technical Asset Correction, Deprecation, Retirement, and Archive Review. Technical assets shall be corrected, deprecated, retired, withdrawn, restricted, superseded, or archived where they become insecure, unsupported, inaccurate, mislicensed, unsafe for public use, misleading, obsolete, superseded, vulnerable, noncompliant, captured, or inconsistent with public-benefit purpose. Deprecation and retirement shall include notice where appropriate, migration guidance where safe, archive status, downstream dependency review, and correction records.
424.17 Technical Asset Maintenance Sustainability Review. GCRI Canada shall assess whether technical assets have sustainable ownership, stewardship, maintainer capacity, documentation, funding, dependency management, security review, release cadence, correction path, support expectations, and retirement plan. Assets lacking sustainable maintenance shall be labeled, restricted, transferred where lawful, deprecated, archived, or retired. GCRI Canada shall not allow abandoned public-good assets to create reliance without limitation language.
424.18 Technical Asset Review Records. GCRI Canada shall maintain technical asset review records, including technical asset review purpose records, public-good technical asset register review records, software review records, schema and API review records, dashboard and data tool review records, reference architecture review records, technical baseline review records, open-source governance review records, contributor terms review records, IP and licensing review records, secure development review records, repository security review records, dependency / SBOM / signing / provenance / vulnerability / release review records, fork and compatibility claim review records, public-good anti-enclosure review records, correction / deprecation / retirement / archive review records, maintenance sustainability review records, corrective actions, closeouts, and archives.
Section 425. Data Governance Review
425.1 Data Governance Review Purpose. GCRI Canada shall maintain data governance review to ensure that data is collected, received, stored, accessed, used, analyzed, AI-processed, dashboarded, mapped, transferred, published, retained, deleted, corrected, and archived lawfully, ethically, securely, minimally, transparently where required, public-safe, and consistently with GCRI Canada’s public-benefit purpose. Data governance review shall apply to public authority data, personal information, health-sensitive data, research data, community data, Indigenous data, local and territorial knowledge data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, training data, telemetry, sensor data, dashboards, maps, embeddings, retrieval indexes, and derived outputs.
425.2 Lawful Basis Review. Lawful basis review shall determine whether GCRI Canada has authority to collect, receive, process, store, transfer, publish, or otherwise use data. Lawful basis may arise from consent, contract, public release, authorization, research agreement, data-sharing agreement, public authority authority, legal obligation, legitimate public-benefit purpose where lawful, or another recognized basis. Where lawful basis is absent, unclear, withdrawn, exceeded, or inconsistent with restrictions, data shall be refused, quarantined, deleted, returned, restricted, or re-scoped.
425.3 Purpose Limitation Review. Purpose limitation review shall identify the approved purpose for data use and ensure that data is not used beyond that purpose. Approved purposes may include research, evidence review, methods development, observability learning, public authority learning, dashboard testing, map testing, public-safe publication, technical asset development, Academy training, safeguards review, incident response, or correction. Secondary use, AI use, publication, transfer, sponsor disclosure, provider disclosure, or capital-reader disclosure requires review and authority.
425.4 Data Minimization Review. Data minimization review shall assess whether data collection, retention, access, display, publication, AI processing, and transfer are limited to what is necessary and proportionate for the approved purpose. GCRI Canada shall not accumulate data merely because storage is available, AI tools can process it, dashboards can display it, sponsors want it, providers request it, public authorities provide it, or future use is speculative. Non-collection, aggregation, redaction, masking, deletion, and restricted access may be preferred controls.
425.5 Accuracy Review. Data accuracy review shall assess whether data is accurate enough for its intended use, including source quality, completeness, currency, formatting, transformations, deduplication, geocoding, sensor reliability, public authority confirmation where required, community validation where appropriate, and correction history. Inaccurate or uncertain data shall be labeled, corrected, excluded, or used only with limitations. Data accuracy shall not be assumed because data is official, automated, model-generated, or highly granular.
425.6 Storage Limitation Review. Storage limitation review shall assess whether data is stored only as long as necessary and lawful for the approved purpose, legal obligations, research integrity, public authority terms, correctionability, audit, litigation hold, incident response, or institutional recordkeeping. Storage review shall identify retention period, deletion trigger, archive status, anonymization, aggregation, sealing, return, secure disposal, and exceptions. Indefinite retention shall require justification.
425.7 Classification Review. Data classification review shall classify data by sensitivity, source, lawful basis, confidentiality, public status, personal information, health sensitivity, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, finance sensitivity, protected knowledge, export-control risk, sanctions sensitivity, AI-use permissions, publication posture, access class, retention, and correction path. Classification shall be updated when data changes, use changes, public authority terms change, risk changes, or errors are found.
425.8 Access Control Review. Access control review shall assess whether data access is limited to authorized persons with need, role, training, confidentiality, cybersecurity readiness, AI-use authorization, public authority capacity where relevant, protected knowledge authorization where relevant, and records. Access shall be role-based, least-privilege, time-limited where appropriate, reviewed periodically, logged where appropriate, and revoked promptly upon role change or offboarding. Access shall not be granted by seniority, sponsor status, provider status, donor status, public authority title, or capital-reader interest.
425.9 Disclosure Review. Disclosure review shall assess whether data may be disclosed to internal personnel, Board members, committees, councils, reviewers, public authorities, providers, sponsors, donors, funders, hosts, partners, universities, laboratories, National Consortium Companies, Project SPVs, vendors, AI systems, cloud providers, public repositories, publications, dashboards, maps, controlled rooms, or public materials. Disclosure shall require authority, purpose, classification, confidentiality, data rights, public-safe review, and transfer controls. Unauthorized disclosure shall trigger incident response.
425.10 Retention and Deletion Review. Retention and deletion review shall determine how long data and derived outputs are retained, when they are deleted, returned, anonymized, aggregated, sealed, archived, or securely disposed, and how deletion is evidenced. Review shall include source data, extracts, transformed data, embeddings, indexes, dashboards, maps, model inputs, model outputs, backups, public-safe summaries, controlled annexes, and archives. Deletion obligations shall be reconciled with legal holds, research integrity, public authority terms, correctionability, and backups.
425.11 Cross-Border Transfer Review. Cross-border transfer review shall assess whether data may be stored, processed, accessed, transferred, backed up, AI-processed, or disclosed outside Canada or outside a relevant jurisdiction. Review shall address privacy law, public authority terms, data residency, cloud regions, AI provider terms, subprocessors, sanctions, export controls, controlled technology, protected knowledge, Indigenous data, cybersecurity, foreign access risk, and public-safe publication. Transfers may be denied, localized, restricted, anonymized, or legally reviewed.
425.12 Sovereign Data Zone Review. Where data is subject to sovereign data, public authority, Indigenous data, community data, health data, infrastructure data, or other jurisdictional restrictions, GCRI Canada shall review whether a sovereign data zone, Canadian data zone, provincial or territorial data zone, Indigenous-governed data zone, public authority-controlled environment, compute-to-data arrangement, controlled room, or restricted processing environment is required. Sovereign data zone review shall address custody, control, access, residency, deletion, audit, and correction.
425.13 Compute-to-Data Review. Compute-to-data review shall assess whether analysis should be brought to the data rather than moving data to external systems, public repositories, AI providers, cloud environments, or uncontrolled tools. Compute-to-data may be required for public authority data, health-sensitive data, protected knowledge, infrastructure-sensitive data, cyber-sensitive data, Indigenous data, community data, or controlled datasets. Review shall address approved tools, logging, output review, export controls, publication review, and deletion.
425.14 Public Authority Data Review. Public authority data review shall assess authority, lawful basis, contributor capacity, permitted use, prohibited use, AI-use restrictions, publication restrictions, transfer restrictions, retention and deletion requirements, classification, public authority review rights, confidentiality, cybersecurity, public-safe release review, and correction path. Public authority data shall not be treated as public or unrestricted unless the public authority terms and law support that classification. Public authority data shall not create public authority delegation or adoption.
425.15 Community-Protected and Indigenous / Local / Territorial Knowledge Data Review. Data involving Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, community data, protected knowledge, vulnerable communities, or remote communities shall undergo safeguards review before collection, storage, AI use, mapping, publication, transfer, or disclosure. Review shall address consent, non-consent, FPIC where applicable, community protocols, attribution, non-attribution, withdrawal, correction, public-safe mapping, protected knowledge, access limits, and remedy.
425.16 Privacy Rights Request Review. GCRI Canada shall review privacy rights requests, including access, correction, deletion, withdrawal, restriction, complaint, and appeal requests, according to applicable law, public authority terms, research ethics, data rights, confidentiality, protected knowledge obligations, legal holds, and institutional records. Requests shall be logged, assessed, responded to within applicable timelines, and closed with records. Where requests affect public-safe publications, dashboards, maps, or derived outputs, downstream correction shall be considered.
425.17 Data Incident Review. Data incidents shall be reviewed for unauthorized access, unauthorized disclosure, unauthorized use, unauthorized transfer, data leakage, privacy breach, public authority data misuse, protected knowledge exposure, AI upload, public repository exposure, cyber incident, misclassification, deletion failure, retention failure, or publication error. Data incident review shall include containment, severity, affected data, affected persons, legal obligations, public authority notice, privacy notice, safeguards review, cyber review, correction, and lessons learned.
425.18 Data Governance Review Records. GCRI Canada shall maintain data governance review records, including purpose records, lawful basis review records, purpose limitation review records, data minimization review records, accuracy review records, storage limitation review records, classification review records, access control review records, disclosure review records, retention and deletion review records, cross-border transfer review records, sovereign data zone review records, compute-to-data review records, public authority data review records, community-protected and Indigenous / local / territorial knowledge data review records, privacy rights request review records, data incident review records, corrections, restrictions, deletions, transfers, closeouts, and archives.
Section 426. AI-Use Review
426.1 AI-Use Review Purpose. GCRI Canada shall maintain AI-use review to ensure that any use of AI systems, AI assistants, generative AI, machine learning, embeddings, retrieval systems, vector stores, model evaluation tools, agentic systems, automation services, transcription tools, translation tools, coding assistants, simulation systems, digital twins, and AI-assisted publication tools is lawful, authorized, human-accountable, data-rights-compliant, privacy-compliant, cyber-secure, public-safe, limitation-bearing, and correctionable. AI-use review shall preserve GCRI Canada’s role as an upstream public-benefit steward of research, evidence, methods, observability, ontology, public-good software, open technical baselines, verifiable intelligence records, and public-safe publication, and shall prevent AI outputs from being mistaken for public authority decisions, public warnings, emergency commands, finance-readiness determinations, procurement approvals, certifications, recognition, maturity determinations, professional opinions, or institutional truth without records.
426.2 Model Register Review. GCRI Canada shall review its model register to confirm that material AI systems used by or for GCRI Canada are identified, classified, authorized, current, and controlled. Model register review shall include model name, provider, version where known, system owner, custodian, approved uses, prohibited uses, data classes permitted, data classes prohibited, risk classification, public-safe status, access class, retention settings, training or model-improvement posture, retrieval posture, human review requirement, vendor terms, security review, privacy review, export-control sensitivity, public authority data restrictions, protected knowledge restrictions, suspension status, deprecation status, retirement status, and correction path.
426.3 Model Record Review. GCRI Canada shall review model records to ensure that each material model or AI system has sufficient documentation to support governance, review, limitation disclosure, incident response, and correction. Model records may include source, provider terms, version, deployment mode, access method, approved users, intended purpose, known limitations, known risks, evaluation results, hallucination risks, bias risks, drift risks, prompt-injection risks, data leakage risks, cyber risks, public authority boundary risks, finance-boundary risks, certification-boundary risks, procurement-boundary risks, safeguards risks, and human accountability controls. Incomplete model records shall trigger restriction, further review, or non-use for higher-risk purposes.
426.4 Dataset Card, Model Card, System Card, Benchmark Card, Evaluation Harness, and Method Library Review. GCRI Canada shall review dataset cards, model cards, system cards, benchmark cards, evaluation harnesses, and method libraries used in connection with AI systems. Review shall assess purpose, data provenance, permissions, classification, lawful basis, privacy, public authority data terms, protected knowledge, Indigenous / local / territorial knowledge, data minimization, evaluation method, benchmark limits, known failure modes, bias, uncertainty, public-safe status, versioning, and correction path. These artifacts shall not be represented as certification, regulatory approval, procurement approval, finance-readiness, public authority adoption, or safety guarantee.
426.5 AI-Use Authorization Review. AI-use authorization review shall confirm that each material AI use is approved for the tool, model, user class, purpose, data class, output class, storage location, retention setting, publication posture, and human review requirement. Authorization shall distinguish low-risk drafting assistance, internal analysis, controlled analysis, public authority data processing, protected knowledge processing, publication support, coding support, agentic action, and public-facing output. Unauthorized AI use, including use of personal AI accounts for restricted work, unapproved uploads, unapproved embeddings, unapproved model training, unapproved agentic action, or direct external publication from AI output, is prohibited.
426.6 Training, Fine-Tuning, Embedding, Retrieval, and Model Improvement Restriction Review. GCRI Canada shall review whether data, documents, code, prompts, outputs, datasets, transcripts, public authority materials, protected knowledge, personal information, health-sensitive data, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled-room materials, or unpublished research may be used for AI training, fine-tuning, embedding, retrieval indexing, vector storage, model improvement, or provider-side learning. Such use shall be prohibited unless lawful basis, data rights, consent where required, public authority terms, privacy, confidentiality, cyber controls, export controls, protected knowledge safeguards, and Board- or officer-approved authorization support the use.
426.7 Retrieval and Embedding Control Review. Retrieval and embedding control review shall assess whether retrieval systems, vector stores, embeddings, indexes, knowledge bases, document stores, prompt libraries, and AI memory-like systems preserve classification, access limits, data rights, public authority terms, protected knowledge restrictions, source lineage, retention, deletion, and correction. Embeddings and retrieval indexes shall inherit the highest applicable sensitivity of the underlying material unless a documented review supports a different classification. Retrieval systems shall be tested for leakage, over-retrieval, stale content, unsupported citation, prompt injection, and unauthorized cross-context disclosure.
426.8 Inference Record Review. GCRI Canada shall review inference records where AI outputs materially support public-safe publications, evidence records, method notes, technical baselines, dashboards, maps, controlled summaries, public authority-facing materials, finance-boundary materials, safeguards reviews, or other high-risk outputs. Inference records may include prompt, system instruction, model, version, input class, output, sources retrieved, human reviewer, confidence, limitation, classification, public-safe status, and correction path. Inference records shall be protected where they contain confidential, public authority-sensitive, protected knowledge, cyber-sensitive, or privacy-sensitive material.
426.9 Human Review Performance Review. GCRI Canada shall assess whether human review of AI-assisted work is timely, competent, documented, source-verifying, limitation-aware, and independent enough for the output class. Human review shall verify citations, source support, factual accuracy, public authority references, finance-boundary language, certification-boundary language, procurement-boundary language, professional-boundary language, protected knowledge, privacy, confidentiality, cyber sensitivity, and public-safe status. Review failures shall trigger training, process correction, model restriction, publication correction, or escalation.
426.10 Agentic AI Control Review. Agentic AI control review shall assess whether AI systems capable of taking actions, calling tools, modifying files, changing repositories, sending messages, searching records, accessing external systems, making recommendations, executing scripts, publishing outputs, creating tickets, changing dashboards, or interacting with data are properly sandboxed, permission-limited, logged, monitored, approval-gated, and reversible. Agentic systems shall not make unauthorized external commitments, public authority communications, public postings, payments, procurement actions, data transfers, repository releases, access grants, or deletion actions. Unauthorized agent action shall be treated as an AI and cybersecurity incident.
426.11 AI Output Limit Review. AI output limit review shall ensure that AI-assisted outputs are not used beyond their approved status. AI outputs shall not be treated as final evidence, legal advice, investment advice, insurance advice, engineering opinion, clinical opinion, rating, public authority decision, public warning, emergency command, procurement approval, certification, finance-readiness determination, recognition, maturity determination, or official GCRI Canada position without competent human review and lawful authority. AI outputs shall be labeled, limited, verified, corrected, restricted, or excluded according to risk.
426.12 AI Incident Review. GCRI Canada shall review AI incidents to determine cause, severity, affected outputs, affected data, affected persons, affected public authority references, affected publications, affected systems, affected dashboards, affected maps, affected repositories, affected technical assets, and required correction. AI incident review shall consider whether the incident arose from tool misuse, model limitation, retrieval failure, prompt injection, human review failure, data quality issue, access control failure, vendor issue, publication process failure, or insufficient training. Corrective action shall be recorded.
426.13 Hallucination, Unsafe Output, Data Leakage, Unauthorized Agent Action, Bias, Drift, Prompt Injection, and Public Overclaim Review. GCRI Canada shall specifically review hallucinations, fabricated citations, unsupported claims, unsafe outputs, data leakage, unauthorized access, unauthorized agent actions, bias, discriminatory outputs, model drift, retrieval drift, prompt injection, jailbreaking, tool misuse, public authority misdescription, finance overclaim, procurement overclaim, certification overclaim, recognition overclaim, maturity overclaim, public warning implication, emergency command implication, and other public overclaims. Such incidents may require output withdrawal, public-safe clarification, controlled notice, model restriction, tool suspension, access revocation, vendor escalation, and training.
426.14 Model Restriction, Suspension, Deprecation, Retirement, and Archive Review. GCRI Canada shall review whether any AI model, tool, workflow, retrieval system, embedding store, agentic system, or AI-assisted process should be restricted, suspended, deprecated, retired, replaced, archived, or prohibited. Triggers may include unsafe performance, unsupported status, vendor risk, data leakage, unacceptable hallucination, bias, drift, cyber risk, privacy risk, public authority boundary risk, protected knowledge risk, contractual risk, export-control risk, or inability to maintain records. Review shall include migration needs, downstream dependencies, archive status, access revocation, and notice where appropriate.
426.15 Verifiable Intelligence Output Review. AI-assisted verifiable intelligence outputs shall be reviewed for source records, method records, model or process records, confidence records, limitation records, human review records, classification records, public-safe status, public authority boundary review, finance / certification / procurement / recognition / public warning boundary review, community and protected knowledge review, correction path, and approval status. No verifiable intelligence output shall be released externally unless it is classification-appropriate, limitation-bearing, public-safe or controlled, and supported by records sufficient to permit correction.
426.16 AI-Use Review Records. GCRI Canada shall maintain AI-use review records, including AI-use review purpose records, model register review records, model record review records, dataset card / model card / system card / benchmark card / evaluation harness / method library review records, AI-use authorization review records, training / fine-tuning / embedding / retrieval / model improvement restriction review records, retrieval and embedding control review records, inference record review records, human review performance records, agentic AI control review records, AI output limit review records, AI incident review records, hallucination / unsafe output / data leakage / unauthorized agent action / bias / drift / prompt injection / public overclaim review records, model restriction / suspension / deprecation / retirement / archive review records, verifiable intelligence output review records, corrections, restrictions, suspensions, retirements, closeouts, and archives.
Section 427. Cybersecurity Review
427.1 Cybersecurity Review Purpose. GCRI Canada shall maintain cybersecurity review to determine whether its systems, records, repositories, public-good technical assets, dashboards, maps, cloud environments, AI tools, data rooms, controlled rooms, Academy systems, communication channels, financial systems, publication systems, public authority data environments, protected knowledge environments, and vendor systems remain secure, monitored, resilient, and consistent with law, contract, public authority terms, privacy, data governance, AI governance, safeguards, and public-safe publication. Cybersecurity review shall support institutional continuity, public trust, technical asset stewardship, and correctionability.
427.2 Cybersecurity Baseline Review. GCRI Canada shall periodically review its cybersecurity baseline to confirm whether approved minimum controls remain appropriate to the organization’s size, data sensitivity, public authority interfaces, AI use, repository footprint, public-good software portfolio, controlled technology exposure, and threat environment. Baseline review may include governance, asset inventory, identity, MFA, least privilege, secure configuration, endpoint protection, network protection, cloud protection, repository protection, application security, data security, logging, monitoring, vulnerability management, incident response, backup, recovery, training, and vendor security.
427.3 Asset Inventory Review. Asset inventory review shall confirm that systems, devices, repositories, cloud services, AI tools, SaaS tools, dashboards, APIs, SDKs, domains, storage locations, data rooms, controlled rooms, communication tools, payment tools, public-good technical assets, secrets, credentials, and critical records are identified, classified, owned, and maintained. Unknown or unmanaged assets shall be investigated, classified, approved, restricted, or decommissioned. Asset inventory gaps shall be treated as cybersecurity and continuity risk.
427.4 Identity and Access Management Review. Identity and access management review shall assess whether users, roles, privileges, groups, administrators, service accounts, repository roles, dashboard roles, AI tool access, data-room access, controlled-room access, and vendor access are appropriate, approved, least-privilege, time-limited where needed, and promptly revoked upon offboarding or role change. Access shall be based on need and authority, not seniority, sponsor status, provider status, donor status, public authority title, academic prestige, or capital-reader interest.
427.5 Multi-Factor Authentication Review. GCRI Canada shall review MFA coverage for systems, repositories, cloud environments, identity providers, financial systems, email, communications, AI tools, data rooms, controlled rooms, dashboards, and administrative accounts. Exceptions shall be documented, risk-reviewed, time-limited where possible, and supported by compensating controls. Absence of MFA on high-risk systems shall be escalated.
427.6 Least-Privilege Review. Least-privilege review shall assess whether persons and systems have only the access necessary for their roles and whether privileged access is approved, monitored, limited, and reviewed. Excessive access, dormant access, inherited access, shared credentials, unmanaged service accounts, administrator sprawl, and unnecessary data exposure shall be corrected. Least privilege shall apply to staff, directors, officers, contractors, fellows, advisors, contributors, reviewers, vendors, public authority participants, sponsors, providers, and hosts.
427.7 Secure Configuration Review. Secure configuration review shall assess whether systems, devices, cloud services, repositories, storage, AI tools, dashboards, APIs, SDKs, collaboration platforms, communication tools, and publication systems are configured securely. Review shall include encryption, public access settings, sharing settings, logging, administrative controls, default settings, secrets handling, backup settings, retention settings, AI training settings, data residency settings, and public repository visibility. Misconfiguration shall be corrected promptly according to severity.
427.8 Endpoint, Network, Cloud, Repository, Application, and Data Security Review. GCRI Canada shall review endpoint, network, cloud, repository, application, and data security controls proportionate to risk. Review may include device posture, malware protection, patch status, secure network access, cloud permissions, repository branch protection, secrets scanning, dependency scanning, application testing, API security, data encryption, storage permissions, public bucket exposure, public repository exposure, and data leakage prevention. High-risk findings shall trigger remediation and incident review where appropriate.
427.9 Logging, Monitoring, Detection, and Security Telemetry Review. Logging, monitoring, detection, and security telemetry review shall assess whether GCRI Canada can detect unauthorized access, unusual activity, failed login patterns, repository changes, administrative actions, data exports, AI tool use, dashboard access, map access, cloud changes, credential misuse, and incident indicators. Logging shall be proportionate, privacy-aware, protected against tampering, and retained appropriately. Absence of logging for high-risk environments shall be escalated.
427.10 Vulnerability and Patch Management Review. GCRI Canada shall review vulnerability intake, severity classification, patch management, remediation clocks, compensating controls, exposure reduction, disclosure practices, dependency vulnerabilities, public-good software vulnerabilities, cloud vulnerabilities, repository vulnerabilities, vendor vulnerabilities, and unresolved security findings. Critical or high vulnerabilities affecting public authority data, protected knowledge, personal information, public-facing systems, repositories, or technical assets shall be escalated promptly.
427.11 Secure Development and Release Review. Secure development and release review shall assess whether software, dashboards, APIs, SDKs, scripts, automation tools, public-good technical assets, technical baselines, and repository releases follow approved development controls. Review shall include code review, branch protections, test coverage, negative tests, dependency checks, license checks, secrets checks, AI-generated code review, release approvals, provenance, signing where required, vulnerability disclosure, public-safe classification, and controlled-material exclusion.
427.12 Key, Token, Credential, Secret, and Recovery Code Review. GCRI Canada shall review handling of keys, tokens, credentials, secrets, API keys, signing keys, encryption keys, service account credentials, recovery codes, administrator credentials, database credentials, repository credentials, cloud credentials, AI provider credentials, and payment credentials. Review shall assess storage, rotation, access, logging, expiration, revocation, secrets scanning, emergency access, recovery, and incident response. Exposed or suspected-exposed secrets shall be rotated and treated as incidents.
427.13 Incident Response Review. Incident response review shall assess whether GCRI Canada can intake, triage, contain, investigate, remediate, notify, correct, and learn from cybersecurity incidents. Review shall include roles, severity levels, escalation, legal review, insurer notice, public authority notice where required, privacy notice where required, evidence preservation, forensic readiness, communications discipline, post-incident review, and corrective action. Incident response shall be tested or table-topped where appropriate.
427.14 Backup, Disaster Recovery, Business Continuity, RTO, RPO, and Testing Review. GCRI Canada shall review backup, disaster recovery, business continuity, recovery time objectives, recovery point objectives, restoration testing, dependency review, critical function identification, critical record identification, system retirement, and decommissioning. Backup review shall include encryption, access control, data classification, public authority data, protected knowledge, retention, deletion, and restoration reliability. Unrestored backups shall not be assumed valid.
427.15 Vendor Security Review. Vendor security review shall assess cloud providers, AI providers, repository providers, cybersecurity providers, data processors, Academy platforms, collaboration tools, communication tools, payment processors, publication platforms, data-room providers, controlled-room providers, and other vendors. Review shall include security controls, certifications where relevant, breach notification, subprocessors, data residency, AI-use terms, access controls, logging, incident response, audit or assurance rights where appropriate, exit readiness, and concentration risk.
427.16 Cybersecurity Training Review. Cybersecurity training review shall assess whether directors, officers, employees, contractors, fellows, advisors, developers, maintainers, reviewers, public authority participants, controlled-room participants, and other relevant persons have completed appropriate training. Training shall cover phishing, MFA, approved tools, shadow IT, AI-use restrictions, secure storage, repository security, secrets handling, incident reporting, public authority data handling, protected knowledge handling, and public-safe publication risks. Training gaps shall trigger remediation.
427.17 Cybersecurity Incident and Corrective Action Review. Cybersecurity incident and corrective action review shall assess incident trends, root causes, remediation, recurrence, access changes, vendor issues, training needs, control failures, missed detections, notification obligations, public-safe corrections, and effectiveness of corrective actions. Repeated incidents or unresolved vulnerabilities shall be escalated to management, counsel, the Board, insurers, or other competent authority as appropriate.
427.18 Cybersecurity Review Records. GCRI Canada shall maintain cybersecurity review records, including cybersecurity review purpose records, baseline review records, asset inventory review records, identity and access management review records, MFA review records, least-privilege review records, secure configuration review records, endpoint / network / cloud / repository / application / data security review records, logging / monitoring / detection / security telemetry review records, vulnerability and patch management review records, secure development and release review records, key / token / credential / secret / recovery code review records, incident response review records, backup / disaster recovery / business continuity / RTO / RPO / testing review records, vendor security review records, cybersecurity training review records, incident and corrective action review records, remediation evidence, closeouts, and archives.
Section 428. Public Authority Boundary Review
428.1 Public Authority Boundary Review Purpose. GCRI Canada shall maintain public authority boundary review to ensure that all public authority engagement, participation, data contribution, reference, publication, dashboard, map, controlled-room activity, Academy activity, public authority learning, sponsor-facing material, provider-facing material, capital-reader material, and Nexus-compatible interface accurately preserves GCRI Canada’s non-executing public-benefit role. Public authority boundary review shall prevent any implication of public authority delegation, endorsement, adoption, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, public policy adoption, infrastructure adoption, or official decision by participation.
428.2 Capacity Classification Review. GCRI Canada shall review whether each public authority participant is properly classified by capacity. Capacity classifications may include official-capacity participant, observer, regulator-listening participant, public finance reader, emergency-management participant, public infrastructure operator, technical expert, data contributor, speaker, reviewer, host, personal-capacity participant, non-attributable participant, controlled-room participant, or other recorded category. Capacity classification shall be updated when roles, titles, authority, permissions, participation status, or public references change.
428.3 Official Capacity Records Review. Official capacity records review shall confirm whether official-capacity participation is supported by appropriate authority, scope, permissions, limitations, contact records, public language, data contribution terms, quote terms, logo terms, publication review rights, confidentiality, and correction path. Official capacity shall be interpreted conservatively. Official participation by one person or office shall not be generalized into whole-of-government endorsement, public authority adoption, funding approval, procurement approval, regulatory approval, public warning authority, or sovereign obligation.
428.4 Observer Status Review. Observer status review shall confirm that observers are described accurately and are not presented as approvers, adopters, endorsers, decision-makers, regulators, funders, procurement authorities, public warning authorities, emergency commanders, or public finance authorities. Observer participation shall be learning, listening, or monitoring only unless another competent record changes the status. Observer references shall include boundary language where misunderstanding is possible.
428.5 Regulator-Listening Status Review. Regulator-listening status review shall confirm that regulator attendance, listening, technical discussion, public authority learning, or comment receipt is not described as regulatory approval, compliance clearance, safe harbor, no-action position, enforcement position, legal interpretation, licensing, permitting, inspection, certification, or official guidance. Regulator-listening records shall identify scope, limitations, confidentiality, public reference permissions, and correction path.
428.6 Public Finance Reader Status Review. Public finance reader status review shall confirm that participation by public finance bodies, development finance institutions, public lenders, public insurers, guarantee bodies, treasuries, budget offices, MDBs, DFIs, public funds, public-private partnership offices, or capital readers is described as reading, learning, evidence understanding, or non-binding engagement only. Such participation shall not be presented as public finance approval, public guarantee, lending approval, insurance approval, underwriting, rating, bankability, investability, finance-readiness, or public funding commitment.
428.7 Emergency-Management Participant Status Review. Emergency-management participant status review shall confirm that emergency-management participation, tabletop participation, simulation participation, scenario participation, dashboard review, map review, after-action review, or Observatory-related learning is not described as emergency command, public warning authority, evacuation authority, dispatch authority, incident command, responder direction, public safety command, public health order, cyber response directive, or emergency operations approval. Emergency-management references shall use non-command language.
428.8 Public Infrastructure Operator Status Review. Public infrastructure operator status review shall confirm that participation by utilities, ports, telecom operators, energy systems, water systems, public works bodies, health systems, food systems, cyber bodies, transport systems, or other public infrastructure operators is not described as operational adoption, system approval, deployment approval, procurement approval, public warning, emergency command, safety determination, resilience guarantee, or infrastructure certification. Infrastructure-related outputs shall remain evidence, methods, learning, public-safe summaries, or technical baselines unless separately and lawfully adopted by competent operators.
428.9 Public Authority Data Contribution Review. Public authority data contribution review shall assess contributor capacity, lawful basis, permitted use, prohibited use, AI-use restrictions, publication restrictions, transfer restrictions, retention and deletion requirements, classification, public authority review rights, confidentiality, cybersecurity, public-safe release review, and correction path. Data contribution shall not imply endorsement, adoption, public authority delegation, public warning, emergency command, procurement approval, funding approval, public finance approval, regulatory approval, sovereign obligation, or official determination.
428.10 Public Authority Reference Approval Review. GCRI Canada shall review public authority references before publication or controlled circulation where material. Review shall confirm that names, titles, agencies, jurisdictions, logos, quotes, photos, attendance references, data contribution references, facility references, public authority-facing language, and attribution are accurate, authorized where required, capacity-specific, public-safe, and accompanied by non-endorsement language where needed. Unauthorized or ambiguous references shall be revised, removed, restricted, or escalated.
428.11 Public Authority Logo, Quote, Attendance, Photograph, Agency, and Jurisdiction Reference Review. Public authority logos, seals, emblems, quotes, photographs, recordings, attendance lists, agency names, ministry names, municipal names, Crown names, regulator names, public institution names, public authority titles, and jurisdiction references shall be reviewed for permission, context, capacity, visual implication, public authority policy, privacy, security, attribution, and boundary language. Such references shall not imply endorsement, adoption, approval, funding, procurement, regulation, public warning, emergency command, public-private partnership, sovereign obligation, finance-readiness, certification, recognition, maturity, or provider preference.
428.12 Public Authority Non-Endorsement Language Review. GCRI Canada shall review whether non-endorsement language is required and whether it is clear, proximate, proportionate, and sufficient. Non-endorsement language shall state, as applicable, that participation, attendance, review, data contribution, hosting, quote, public authority learning, dashboard review, map review, simulation participation, or controlled-room access does not constitute endorsement, adoption, regulatory approval, procurement approval, funding approval, public finance approval, public warning, emergency command, sovereign obligation, public-private partnership, certification, recognition, finance-readiness, or provider preference.
428.13 No Public Authority Delegation Review. No public authority delegation review shall confirm that GCRI Canada has not received, implied, exercised, or represented governmental, regulatory, emergency, public warning, procurement, public finance, grant approval, public health order, public safety command, public works, infrastructure, or other public authority powers through participation or collaboration. Any proposed delegation shall require separate lawful instrument, legal review, Board review, public-safe review, and express records, and shall not be presumed from engagement.
428.14 No PPP by Participation Review. No public-private partnership by participation review shall confirm that meetings, attendance, data contributions, public authority learning, Observatory demonstrations, Nexus Universe participation, sponsor or provider presence, public materials, logos, or public authority references have not created or implied a public-private partnership, concession, joint venture, public mandate, co-delivery arrangement, shared liability, public procurement relationship, public finance relationship, or sovereign project unless a separate lawful instrument expressly establishes such relationship and GCRI Canada has approved it.
428.15 No Public Warning, Emergency Command, Procurement Approval, Funding Approval, Regulatory Approval, Public Finance Approval, Sovereign Obligation, or Adoption by Participation Review. GCRI Canada shall review whether any activity, output, participant statement, public authority statement, sponsor material, provider material, dashboard, map, report, deck, publication, data contribution, controlled-room activity, simulation, Academy session, public authority learning activity, or Nexus-compatible statement implies public warning, emergency command, procurement approval, funding approval, regulatory approval, public finance approval, sovereign obligation, public authority adoption, public infrastructure adoption, public policy adoption, safety determination, health determination, security determination, or resilience determination by participation. Any such implication shall be corrected.
428.16 Public Authority Correction Review. GCRI Canada shall review public authority corrections, withdrawals, takedowns, public clarifications, controlled notices, downstream materials reviews, and sponsor / provider / partner / media corrections involving public authority references. Public authority correction review shall assess trigger, affected materials, public-safe status, authority, revised language, public authority notice, sponsor and provider notice, archive note, recurrence, and control improvement. Corrections shall be recorded and synchronized where necessary.
428.17 Public Authority Boundary Review Records. GCRI Canada shall maintain public authority boundary review records, including purpose records, capacity classification review records, official capacity records review, observer status review, regulator-listening status review, public finance reader status review, emergency-management participant status review, public infrastructure operator status review, public authority data contribution review, public authority reference approval review, logo / quote / attendance / photograph / agency / jurisdiction reference review, non-endorsement language review, no-public-authority-delegation review, no-PPP-by-participation review, no-public-warning / emergency-command / procurement / funding / regulatory / public-finance / sovereign-obligation / adoption-by-participation review records, public authority correction review records, corrections, closeouts, and archives.
Section 429. Public-Safe Publication Review
429.1 Public-Safe Publication Review Purpose. GCRI Canada shall maintain public-safe publication review to ensure that external and controlled outputs are accurate, source-supported, method-supported, limitation-bearing, classification-appropriate, public-benefit aligned, non-executing, public authority-boundary compliant, finance-boundary compliant, procurement-neutral, certification-boundary compliant, safeguards-reviewed where required, data / AI / cyber-reviewed where required, and correctionable. Public-safe publication review shall apply to websites, articles, social media, speeches, decks, reports, whitepapers, datasets, software releases, public dashboards, public maps, public repositories, donor reports, sponsor materials, provider materials, public authority-facing materials, capital-reader materials, Academy materials, and Nexus-compatible outputs.
429.2 Publication Authority Review. Publication authority review shall confirm that the person or body approving a publication has authority to release the relevant output and that required approvals have been obtained. Review shall address author authority, program owner approval, publication approver approval, legal review where required, public authority review where required, data / AI / cyber review, safeguards review, finance-boundary review, certification-boundary review, procurement-boundary review, sponsor or provider reference review, and Board approval where risk warrants. Unauthorized publication shall trigger correction or withdrawal.
429.3 Publication Classification Review. Publication classification review shall determine whether an output is public, internal, controlled, restricted, confidential, public authority-sensitive, finance-sensitive, cyber-sensitive, infrastructure-sensitive, privacy-sensitive, protected-knowledge-sensitive, experimental, provisional, draft, superseded, withdrawn, or archived. Classification shall determine audience, access, distribution, disclaimers, retention, correction path, and archive status. Draft or controlled outputs shall not be circulated as final or public unless approved.
429.4 Claims Substantiation Review. Claims substantiation review shall confirm that every material claim is supported by evidence, method, record, authority, or source appropriate to the claim. Claims about public benefit, technical performance, risk, resilience, public authority participation, finance-readiness support, interoperability, security, safeguards, impact, adoption, participation, or Nexus compatibility shall not exceed the record. Unsupported claims shall be removed, qualified, corrected, or escalated.
429.5 Evidence and Methods Support Review. Publication review shall assess whether evidence and methods supporting an output are current, relevant, accurate, complete, permissioned, classified, reproducible where feasible, uncertainty-bearing, and correctionable. Methods shall be described sufficiently for the output class and shall not overstate confidence. Evidence and methods support shall not be treated as public authority decision, certification, finance-readiness, procurement approval, public warning, emergency command, professional opinion, recognition, or maturity determination.
429.6 Controlled Vocabulary Review. Controlled vocabulary review shall ensure that publications use GCRI Canada’s approved ontology, taxonomies, definitions, public authority capacity terms, finance-boundary terms, recognition-boundary terms, certification-boundary terms, procurement-boundary terms, safeguards terms, technical terms, and Nexus-compatible language accurately. Uncontrolled, inflated, ambiguous, or market-facing terms that could imply certification, recognition, finance-readiness, public authority approval, procurement status, public warning, emergency command, or provider preference shall be replaced or qualified.
429.7 Technical Claims Review. Technical claims review shall assess claims concerning AI, AI-RAN, O-RAN, DePIN, DLT, cyber, sovereign compute, geospatial systems, Earth observation, sensors, digital twins, robotics, drones, telecom, quantum-adjacent systems, semiconductors, advanced manufacturing, APIs, software, technical baselines, dashboards, maps, benchmarks, and public-good assets. Review shall confirm that technical claims are accurate, scoped, limitation-bearing, not false-precision, not provider-preferential, not procurement-steering, not security-guaranteeing, and not certification-like by implication.
429.8 Public Authority Reference Review. Public authority reference review shall confirm that public authority names, logos, titles, quotes, photos, attendance references, data contribution references, agency references, jurisdiction references, public finance reader references, regulator-listening references, emergency-management references, and public infrastructure operator references are accurate, authorized, capacity-classified, non-endorsing, and public-safe. Public authority references shall not imply adoption, approval, delegation, public warning, emergency command, procurement, funding, public finance approval, sovereign obligation, public-private partnership, or official determination.
429.9 Finance-Readiness Reference Review. Finance-readiness reference review shall ensure that publications do not provide investment advice, securities solicitation, insurance approval, underwriting, lending approval, rating, public finance approval, bankability, investability, finance-readiness determination, public guarantee, capital commitment, or transaction recommendation. References to technical evidence inputs, proof packs, GRA interfaces, Nexus Rails, capital-reader rooms, RNFD, NFD, or UNFSD shall include non-reliance, no-solicitation, no-underwriting, no-rating, no-public-finance-approval, and no-GCRI-Canada-finance-determination language where material.
429.10 Sponsor, Provider, Host, and Partner Reference Review. Sponsor, provider, host, and partner references shall be reviewed for accuracy, benefit schedule compliance, non-control, no provider preference, no procurement implication, no public authority endorsement, no finance-readiness implication, no certification implication, no recognition implication, no partnership or shared-liability implication, and no outcome purchase. Acknowledgments shall be factual, proportionate, and controlled. Misleading sponsor or provider references shall be corrected or removed.
429.11 Public-Safe Map Review. Public-safe map review shall assess geospatial precision, infrastructure sensitivity, critical location protection, dependency and vulnerability exposure, cyber-physical risk, protected knowledge, Indigenous / local / territorial knowledge, cultural sites, environmental knowledge, vulnerable and remote communities, public safety, health sensitivity, public authority boundary, public warning implication, emergency command implication, finance implication, procurement implication, and correction path. Maps may require aggregation, generalization, masking, obfuscation, redaction, delay, restriction, or withdrawal.
429.12 Dashboard Review. Dashboard review shall assess classification, owner, custodian, data sources, update status, refresh cadence, limitations, confidence and uncertainty display, access controls, public-safe status, incident response, correction path, public authority boundary, finance boundary, certification boundary, procurement boundary, and public warning boundary. Dashboards shall not be presented as official warnings, public authority decisions, emergency commands, finance-readiness determinations, certifications, procurement approvals, recognition, maturity guarantees, or performance warranties.
429.13 AI-Generated or AI-Assisted Content Review. AI-generated or AI-assisted content shall undergo human review, source verification, citation verification where applicable, fabrication and hallucination review, confidentiality review, data leakage review, public authority reference review, finance / certification / procurement / recognition / public warning boundary review, protected knowledge review, and public-safe classification before external release. No external publication shall be released directly from unreviewed AI output. AI use shall be disclosed where required or appropriate.
429.14 Website, Article, Social Media, Speech, Deck, Report, Whitepaper, Dataset, Software Release, and Public Dashboard Review. GCRI Canada shall review websites, articles, social media, speeches, media responses, decks, public reports, whitepapers, datasets, software releases, public dashboards, public repositories, event materials, public authority-facing materials, sponsor-facing materials, provider-facing materials, and investor-facing or capital-reader materials according to output-specific risk. Review shall address claims, sources, limitations, public authority references, sponsor / provider references, data / AI / cyber issues, safeguards, public-safe status, disclaimers, embargoes, versioning, and correction path.
429.15 Disclaimer and Boundary Language Review. Disclaimer and boundary language review shall confirm that required non-execution, non-public-warning, non-emergency-command, non-regulatory, non-certification, non-procurement, non-finance, non-investment-advice, non-insurance, non-rating, non-public-finance-approval, public authority non-endorsement, sponsor and provider non-control, AI limitation, dashboard / map limitation, Observatory / Truth Engine limitation, evidence / methods / confidence / uncertainty, and correction language is present, clear, proximate, and proportionate to risk.
429.16 Media Protocol Review. Media protocol review shall confirm that media responses, interviews, quotes, press releases, crisis communications, emergency communications discipline, public authority coordination, social media rapid response, rumor response, misinformation response, and public statements are made only by authorized spokespersons and within approved language. Media review shall prevent public warning implication, emergency command implication, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, provider preference, sponsor control implication, or release of sensitive information.
429.17 Corrections, Supersessions, Withdrawals, Retractions, Public Clarifications, and Archive Review. GCRI Canada shall review publication corrections, supersessions, withdrawals, retractions, public clarifications, controlled notices, archive status, downstream dependency notifications, replacement publications, and historical traceability. Review shall identify error severity, affected materials, affected public authority references, data / AI / cyber implications, protected knowledge implications, finance and procurement implications, sponsor and provider claims, public-safe notice needs, and archive treatment. Corrections shall be timely and traceable.
429.18 Public-Safe Publication Review Records. GCRI Canada shall maintain public-safe publication review records, including purpose records, publication authority review records, classification review records, claims substantiation review records, evidence and methods support review records, controlled vocabulary review records, technical claims review records, public authority reference review records, finance-readiness reference review records, sponsor / provider / host / partner reference review records, public-safe map review records, dashboard review records, AI-generated or AI-assisted content review records, output-specific review records, disclaimer and boundary language review records, media protocol review records, correction / supersession / withdrawal / retraction / clarification / archive review records, approvals, holds, corrections, closeouts, and archives.
Section 430. Safeguards Review
430.1 Safeguards Review Purpose. GCRI Canada shall maintain safeguards review to ensure that its research, programs, publications, datasets, dashboards, maps, AI use, public authority learning, Academy activities, fellowships, labs, challenges, benchmarking, technical assets, public-safe outputs, and Nexus-compatible interfaces protect Indigenous rights, Indigenous data, Indigenous knowledge, local and territorial knowledge, cultural sites, environmental knowledge, protected knowledge, vulnerable communities, remote communities, accessibility, consent, non-consent, withdrawal, correction, grievance, remedy, non-retaliation, and do-no-harm obligations. Safeguards review shall prevent extraction, unsafe disclosure, public authority misuse, sponsor misuse, provider misuse, AI inference harm, and publication overclaim.
430.2 Community Participation Review. Community participation review shall assess whether participation is voluntary where appropriate, non-coercive, accessible, inclusive, language-accessible, remote-community aware, vulnerable-community aware, non-extractive, adequately explained, and supported by consent, non-consent, withdrawal, correction, grievance, remedy, and feedback pathways. Review shall ensure that community participation is not used to manufacture legitimacy, public authority approval, sponsor benefit, provider benefit, finance-readiness, certification, recognition, maturity, procurement advantage, or institutional endorsement.
430.3 Indigenous Rights Review. Indigenous rights review shall assess whether activities involving Indigenous Peoples, Indigenous governments, Indigenous institutions, Indigenous territory, Indigenous data, Indigenous knowledge, treaty rights, Aboriginal rights, Indigenous governance, or rights-bearing communities respect applicable rights, protocols, laws, custodianship, consent requirements, non-consent, data sovereignty principles, cultural responsibilities, and correction pathways. Indigenous rights review shall be substantive and shall not be reduced to symbolic consultation.
430.4 Indigenous Data and Indigenous Knowledge Review. Indigenous data and Indigenous knowledge review shall assess authority, consent where applicable, custodianship, attribution, non-attribution, use limits, AI-use restrictions, mapping restrictions, publication restrictions, transfer restrictions, data residency, public authority use, sponsor and provider access, withdrawal rights, correction rights, and protected knowledge treatment. Indigenous knowledge shall not be converted into open data, AI training data, public maps, sponsor materials, provider materials, or technical baselines without authority and safeguards.
430.5 Local and Territorial Knowledge Review. Local and territorial knowledge review shall assess whether place-based knowledge, land-use knowledge, water knowledge, hazard memory, infrastructure knowledge, environmental observations, community risk knowledge, cultural knowledge, and territorial context are being handled with appropriate consent, attribution, restriction, public-safe mapping, and correction controls. Review shall prevent decontextualization, extraction, unsafe disclosure, public authority misuse, sponsor misuse, provider misuse, and AI inference harm.
430.6 Community Protocol Review. Community protocol review shall identify applicable community expectations concerning engagement, consent, meeting conduct, recording, attribution, language, accessibility, elder or youth involvement, data custody, publication, mapping, photography, translation, protected knowledge, benefit sharing, withdrawal, correction, grievance, and remedy. GCRI Canada shall not treat absence of a formal written protocol as permission for unrestricted use.
430.7 FPIC Where Applicable Review. Where free, prior, and informed consent is applicable under law, agreement, protocol, ethical standard, funder requirement, public authority term, or safeguards review, GCRI Canada shall review whether the relevant process is free, prior, informed, specific, recorded, capable of reflecting conditions, and capable of recording non-consent or withdrawal. Activities subject to FPIC shall not proceed until the applicable process is satisfied or the activity is re-scoped.
430.8 Protected Knowledge Review. Protected knowledge review shall assess whether knowledge, data, locations, practices, cultural materials, environmental observations, community vulnerabilities, infrastructure vulnerabilities, health-sensitive information, or safety-sensitive information require controlled access, non-public handling, masking, aggregation, redaction, AI-use prohibition, sponsor access prohibition, provider access prohibition, capital-reader exclusion, public authority-use restriction, or withdrawal. Protected knowledge shall be treated as a substantive safeguard category.
430.9 Public-Safe Mapping Review. Public-safe mapping review shall assess geospatial precision, re-identification risk, cultural site exposure, environmental exposure, infrastructure vulnerability, public safety risk, health risk, community stigmatization, public authority misuse, sponsor misuse, provider misuse, AI inference risk, data linkage risk, public warning implication, emergency command implication, and correction path. Maps may be generalized, masked, delayed, suppressed, restricted, or withdrawn where needed.
430.10 Vulnerable and Remote Community Review. Vulnerable and remote community review shall assess whether activities create burden, exclusion, stigma, retaliation risk, public authority pressure, sponsor pressure, provider pressure, unsafe disclosure, accessibility barriers, language barriers, digital barriers, travel burdens, health risk, public safety risk, or infrastructure exposure. Review shall determine whether additional support, alternative formats, confidentiality, non-attribution, publication restriction, or remedy pathways are required.
430.11 Cultural Site and Environmental Knowledge Review. Cultural site and environmental knowledge review shall assess whether outputs may reveal sacred sites, ceremonial sites, burial sites, archaeological locations, heritage sites, gathering sites, sensitive ecological locations, species locations, habitat information, water sources, climate indicators, resource locations, hazard-sensitive areas, or other information whose disclosure could create harm. Review may require exclusion, aggregation, masking, controlled annexes, delayed release, or non-public handling.
430.12 Accessibility Review. Accessibility review shall assess whether participation, publications, training, Academy materials, dashboards, maps, websites, events, grievance channels, consent materials, correction pathways, and public-safe summaries are accessible to persons with disabilities and to participants with language, literacy, connectivity, mobility, sensory, cognitive, or other access needs. Accessibility shall be treated as a public-benefit safeguard and not an optional add-on.
430.13 Grievance and Remedy Review. Grievance and remedy review shall assess whether affected persons and communities have accessible, non-retaliatory, confidential where appropriate, and meaningful pathways to raise concerns and obtain proportionate remedy. Remedies may include correction, withdrawal, redaction, data deletion, public-safe clarification, controlled notice, process change, apology, access restriction, safeguards redesign, or program suspension. Grievances shall not be dismissed because they are inconvenient or reputationally sensitive.
430.14 Protected Participation, Whistleblowing, Dissent Protection, Anti-Retaliation, and Confidential Reporting Review. GCRI Canada shall review whether protected participation, whistleblowing, dissent, non-consent, withdrawal, correction requests, grievance, stop-the-line use, safeguards escalation, confidential reporting, and anti-retaliation mechanisms are functioning. Review shall assess whether participants fear retaliation, whether reports are handled fairly, whether confidentiality is protected, whether dissent is captured, whether reporters are protected, and whether corrective action is implemented.
430.15 Stop-Work and Stop-the-Line Review. Stop-work and stop-the-line review shall assess whether triggers for public safety, public authority confusion, community harm, protected knowledge, safeguards breach, data / AI / cyber risk, public-safe publication risk, finance overclaim, procurement overclaim, certification overclaim, recognition overclaim, or public warning overclaim are recognized and acted upon. Review shall assess containment, escalation, restart conditions, non-retaliation, records, and lessons learned.
430.16 Do-No-Harm Review. Do-no-harm review shall assess whether GCRI Canada should proceed, pause, redesign, restrict, or terminate an activity to prevent harm to persons, communities, Indigenous rights, protected knowledge, public authority clarity, public safety, privacy, cyber security, public trust, or institutional integrity. Do-no-harm controls may include non-collection, minimization, aggregation, masking, redaction, consent requirements, AI-use prohibition, access restriction, publication hold, community review, or withdrawal.
430.17 Safeguards Correction Review. Safeguards correction review shall assess whether safeguards failures, community harms, protected knowledge exposure, consent violations, non-consent violations, withdrawal failures, public-safe mapping failures, accessibility failures, retaliation, or grievance mishandling have been corrected. Review shall include root cause, affected persons, affected communities, records, remedy, public-safe correction, controlled notice, recurrence prevention, and closeout.
430.18 Safeguards Review Records. GCRI Canada shall maintain safeguards review records, including purpose records, community participation review records, Indigenous rights review records, Indigenous data and Indigenous knowledge review records, local and territorial knowledge review records, community protocol review records, FPIC review records where applicable, protected knowledge review records, public-safe mapping review records, vulnerable and remote community review records, cultural site and environmental knowledge review records, accessibility review records, grievance and remedy review records, protected participation / whistleblowing / dissent / anti-retaliation / confidential reporting review records, stop-work and stop-the-line review records, do-no-harm review records, safeguards correction review records, corrective actions, closeouts, and archives.
Section 431. Sponsor, Donor, Funder, Provider, Host, and Partner Conduct Review
431.1 Conduct Review Purpose. GCRI Canada shall maintain conduct review for sponsors, donors, funders, providers, hosts, partners, vendors, public authority-linked supporters, universities, laboratories, National Consortium Companies, Project SPVs, and other institutional participants to ensure that support, participation, collaboration, funding, technical contribution, hosting, and public association remain lawful, public-benefit aligned, non-controlling, provider-neutral, procurement-neutral, finance-boundary compliant, public authority-boundary compliant, public-safe, and correctionable. Conduct review shall prevent control-for-cash, pay-to-play, outcome purchase, public authority access purchase, provider preference, sponsor capture, donor capture, funder capture, host pressure, partner overclaim, and misuse of GCRI Canada’s name or Nexus-compatible language.
431.2 Sponsor Non-Control Review. Sponsor non-control review shall assess whether sponsors have or are attempting to obtain control over governance, Board decisions, officers, staffing, research agenda, methods, evidence selection, publication timing, public-safe language, corrections, public authority access, technical baselines, software, dashboards, maps, benchmarks, challenge outcomes, Academy content, public claims, finance-boundary language, procurement language, certification language, or Nexus-compatible claims. Sponsor benefits shall remain limited to approved acknowledgment and benefit schedules and shall not include control.
431.3 Donor Non-Control Review. Donor non-control review shall assess whether donors attempt to control purpose, governance, research, evidence, publications, public authority relationships, staffing, grants, Academy programming, technical assets, public-good software, safeguards, or corrections through restricted gifts, renewal pressure, public acknowledgment, naming requests, access requests, or implied expectations. Donor restrictions may be accepted only where lawful, mission-aligned, public-benefit consistent, and non-controlling.
431.4 Funder Non-Control Review. Funder non-control review shall assess grantors, philanthropic funders, public funders, corporate funders, underwriters, and restricted-fund providers for conditions that may compromise research integrity, public-safe publication, public authority boundaries, finance boundaries, procurement neutrality, provider neutrality, safeguards, or correctionability. Reporting requirements shall not become control over findings, suppression of negative results, public authority overclaim, finance-readiness implication, certification implication, or procurement advantage.
431.5 Provider Non-Control Review. Provider non-control review shall assess whether providers or vendors influence technical baselines, benchmarks, challenge rules, public-good software, interoperability profiles, public authority learning, Academy content, dashboards, maps, publications, research conclusions, controlled vocabulary, or provider-facing claims for market advantage. Provider participation shall not result in preferred status, procurement advantage, certification implication, finance-readiness implication, public authority access, or exclusion of competitors.
431.6 Host Non-Control Review. Host non-control review shall assess whether host institutions, facilities, public authorities, universities, laboratories, infrastructure hosts, community hosts, or event hosts attempt to control outputs, restrict lawful correction, influence public authority language, require endorsement, obtain procurement advantage, impose unsafe data handling, limit safeguards, require public claims, or create public-private partnership implication. Hosting shall not transfer operational control to GCRI Canada or create endorsement by the host.
431.7 Partner Non-Control Review. Partner non-control review shall assess whether partners attempt to expand their role into governance authority, public authority delegation, shared treasury, shared liability, provider preference, finance-readiness influence, certification influence, procurement influence, research conclusion control, public claims control, or correction control. Partnership language shall be used only where legally accurate and shall not imply agency, joint venture, merger, public-private partnership, or shared authority unless separately recorded.
431.8 Support-Without-Control Review. Support-without-control review shall confirm that support is accepted only under terms preserving GCRI Canada’s independence, public-benefit purpose, nonprofit posture, public-good assets, non-execution, public authority boundaries, finance boundaries, procurement neutrality, provider neutrality, public-safe publication, safeguards, and correctionability. Support may include money, in-kind support, compute credits, cloud credits, software credits, facility access, data access, staff time, training support, event support, and technical support, but support shall not purchase control.
431.9 No Control-for-Cash Review. GCRI Canada shall review whether any financial contribution, grant, donation, sponsorship, subscription, fee, in-kind contribution, compute credit, cloud credit, or other support is conditioned on governance control, research outcome, public authority access, provider preference, publication suppression, benchmark result, challenge result, public claim, finance-readiness implication, certification implication, procurement advantage, recognition, maturity, or avoidance of correction. Control-for-cash arrangements are prohibited.
431.10 No Pay-to-Play Review. No pay-to-play review shall assess whether access, participation, visibility, public authority interface, Academy opportunity, controlled-room access, data-room access, benchmark inclusion, challenge participation, lab participation, technical baseline influence, publication mention, public-safe summary inclusion, or Nexus-compatible claim is tied improperly to payment or support. Fees, subscriptions, sponsorships, and grants may support lawful activities, but shall not buy status, authority, approval, recognition, or preferential treatment.
431.11 No Procurement Steering Review. Conduct review shall assess whether sponsors, providers, hosts, partners, donors, funders, public authorities, or other actors are using GCRI Canada to steer procurement, shape tender requirements, prequalify vendors, influence public buyers, exclude competitors, create preferred-provider status, or market GCRI Canada participation as procurement validation. Procurement steering shall be corrected, restricted, or terminated.
431.12 No Outcome Purchase Review. No outcome purchase review shall assess whether any actor seeks to buy research conclusions, benchmark outcomes, challenge results, Academy recognition, competence records, public authority references, public-safe claims, technical baseline language, impact claims, finance-boundary language, certification implication, procurement language, public warning implication, recognition, maturity, or public legitimacy. Purchased outcomes are prohibited and shall trigger rejection, correction, or termination.
431.13 No Veto or Suppression Right Review. GCRI Canada shall review whether any sponsor, donor, funder, provider, host, partner, public authority, capital actor, National Consortium Company, Project SPV, or other actor has or seeks veto or suppression rights over findings, methods, corrections, publications, negative results, public-safe clarifications, protected participation reports, safeguards concerns, incident reports, public authority corrections, or technical asset deprecations. Confidentiality and pre-publication review may protect legal rights and safety, but shall not become suppression of accurate, lawful, public-benefit correction.
431.14 Influence Cap and Sponsor Concentration Review. GCRI Canada shall review sponsor, donor, funder, provider, host, and partner concentration to prevent institutional dependence, capture, single-actor leverage, sector imbalance, jurisdictional overdependence, or funding pressure. Influence caps may be formal or informal and may include limits on benefits, visibility, committee participation, public authority rooms, technical input, funding concentration, renewal dependency, and public acknowledgment. Concentration risk shall be escalated to the Board where material.
431.15 Donor Aggregation and Related-Party Funding Review. Donor aggregation and related-party funding review shall assess whether multiple contributions, affiliated entities, intermediaries, donor-advised arrangements, related parties, controlled entities, or coordinated funders create hidden concentration, control, influence, sanctions risk, source-of-funds risk, private benefit, public authority access purchase, or reputation laundering. Related funding structures shall be disclosed where required and reviewed for control, conflicts, tax treatment, and public-benefit consistency.
431.16 Public Acknowledgment and Benefit Review. Public acknowledgments, sponsor benefits, donor acknowledgments, funder reports, host references, partner references, provider references, logos, quotes, event visibility, website mentions, report mentions, Academy visibility, challenge visibility, and other benefits shall be reviewed for accuracy, proportionality, authority, non-control, no endorsement, no provider preference, no procurement implication, no finance-readiness implication, no certification implication, no recognition implication, no public authority approval, and no shared-liability implication.
431.17 Provider Preference and Public Authority Access Review. GCRI Canada shall review whether any sponsor, provider, donor, funder, host, or partner obtains preferential access to public authorities, controlled rooms, public authority learning, public authority data, procurement-sensitive discussions, public finance readers, dashboards, maps, technical baselines, benchmarks, or Nexus-compatible interfaces. Provider preference and public authority access purchase are prohibited. Any access shall be public-benefit justified, role-based, documented, and boundary-controlled.
431.18 Conduct Review Records. GCRI Canada shall maintain conduct review records, including conduct review purpose records, sponsor non-control review records, donor non-control review records, funder non-control review records, provider non-control review records, host non-control review records, partner non-control review records, support-without-control review records, no-control-for-cash review records, no-pay-to-play review records, no-procurement-steering review records, no-outcome-purchase review records, no-veto-or-suppression-right review records, influence cap and sponsor concentration review records, donor aggregation and related-party funding review records, public acknowledgment and benefit review records, provider preference and public authority access review records, corrections, restrictions, refusals, terminations, closeouts, and archives.
Section 432. Impact Claims Review
432.1 Impact Claims Review Purpose. GCRI Canada shall review impact claims to ensure that claims about public benefit, technical contribution, learning, capacity formation, public authority learning, safeguards, public-good software, technical baselines, data / AI / cyber improvement, finance-readiness evidence support, Nexus-compatible interfaces, and institutional contribution are evidence-based, method-supported, limitation-bearing, non-executing, public-safe, and correctionable. Impact claims shall not be used to imply public authority adoption, finance outcomes, procurement outcomes, investment outcomes, certification, recognition, maturity, public warning, emergency command, provider success, or sponsor-driven achievement without competent evidence.
432.2 Evidence-Based Impact Claim Requirement. Every material impact claim shall be supported by evidence appropriate to the nature and scale of the claim. Evidence may include program records, training records, technical asset records, publication records, correction records, usage records, survey records, public authority learning records, safeguards records, repository records, research outputs, evaluation findings, or external records where authorized. Anecdotes, attendance, publicity, sponsor satisfaction, provider uptake, public authority presence, or capital-reader interest shall not alone support broad impact claims.
432.3 Methods-Supported Impact Claim Requirement. Impact claims shall identify or rely on a method suitable for the claim, including definition, data source, collection method, limitations, uncertainty, attribution logic, contribution logic, and correction path. Methods shall distinguish output, outcome, contribution, attribution, correlation, and causation. GCRI Canada shall not imply causal impact where only participation, exposure, access, or contribution is evidenced.
432.4 Public-Benefit Impact Review. Public-benefit impact review shall assess whether claimed impact advances GCRI Canada’s public-benefit purpose, including stronger evidence discipline, methods discipline, observability literacy, ontology alignment, public-good technical assets, public-safe publication, public authority learning, safeguards, data / AI / cyber discipline, correctionability, and Nexus role separation. Public-benefit impact shall not be claimed merely because an activity was visible, well-attended, funded, or sponsor-supported.
432.5 Technical Impact Review. Technical impact review shall assess claims concerning software, schemas, APIs, dashboards, maps, technical baselines, reference architectures, test harnesses, public-good assets, interoperability, security, AI governance, observability methods, AI-RAN, O-RAN, DePIN, DLT, cyber, sovereign compute, geospatial systems, digital twins, and related technical domains. Technical impact claims shall be scoped, versioned, limitation-bearing, and shall not imply certification, warranty, procurement approval, provider preference, or public authority approval.
432.6 Research Impact Review. Research impact review shall assess claims concerning research outputs, methods, publications, peer review, replication, evidence packs, public-safe summaries, and research agenda contributions. Review shall confirm that claims are source-supported, conflict-controlled, sponsor- and provider-independent, AI-use disclosed where required, and not overstated. Research impact shall not be measured only by publication volume, prestige, media attention, or funder satisfaction.
432.7 Learning and Capacity Impact Review. Learning and capacity impact review shall assess claims concerning Academy programs, training, fellowships, competence cells, role-based training, public-good literacy, technical literacy, evidence literacy, data / AI / cyber literacy, safeguards literacy, and public-safe publication literacy. Attendance, completion, or participation shall not be described as professional certification, regulated credential, public authority qualification, procurement preference, provider recognition, finance-readiness, or official competence unless separately lawful and authorized.
432.8 Public Authority Learning Impact Review. Public authority learning impact review shall assess whether public authority participants received learning, evidence literacy, methods literacy, dashboard literacy, map limitation understanding, public-safe publication awareness, or boundary clarity. Such claims shall not imply public authority adoption, regulatory approval, procurement approval, funding approval, public finance approval, public warning authority, emergency command, public policy adoption, infrastructure adoption, sovereign obligation, or endorsement. Capacity classification and non-endorsement language shall accompany public-facing claims where needed.
432.9 Community Safeguards Impact Review. Community safeguards impact review shall assess whether GCRI Canada improved safeguards processes, accessibility, consent pathways, non-consent respect, withdrawal pathways, correction pathways, grievance handling, remedy, public-safe mapping, protected knowledge treatment, Indigenous rights respect, local knowledge safeguards, or vulnerable community protection. Safeguards impact claims shall not imply community endorsement, Indigenous consent beyond recorded scope, public authority approval, sponsor legitimacy, provider legitimacy, or harm elimination.
432.10 Public-Good Software and Technical Baseline Impact Review. Public-good software and technical baseline impact review shall assess claims concerning public-good software releases, technical baselines, schemas, APIs, reference architectures, test harnesses, interoperability profiles, and open technical materials. Review shall assess usage evidence, maintenance status, security status, license status, contributor governance, public-safe status, correction history, and anti-enclosure. Use or adoption shall not imply certification, procurement approval, public authority approval, provider preference, warranty, or finance-readiness.
432.11 Data / AI / Cyber Impact Review. Data / AI / cyber impact review shall assess claims concerning improved data governance, AI governance, cybersecurity, privacy, incident response, model governance, repository security, public authority data handling, protected knowledge protection, and public-safe publication. Claims shall be supported by metrics, reviews, incidents, remediation, training, or records. Reduced incidents may be claimed only with caution, recognizing underreporting risk, monitoring changes, and uncertainty.
432.12 Finance-Readiness Evidence Support Impact Review Without Finance-Readiness Determination. GCRI Canada may describe its contribution to finance-readiness evidence support only as technical evidence input, method support, public-safe evidence discipline, proof pack support, or capital-readability support where separately governed. Such claims shall expressly avoid finance-readiness determination, investment recommendation, underwriting, insurance approval, lending approval, rating, public finance approval, bankability, investability, securities offering, solicitation, brokerage, finder activity, or capital commitment. Finance-related impact claims require non-reliance language.
432.13 No Overstatement. Impact claims shall not overstate scale, certainty, attribution, causality, adoption, public authority involvement, public benefit, technical maturity, security, safety, resilience, finance relevance, certification relevance, procurement relevance, community support, or Nexus compatibility. Claims shall be proportionate to evidence and shall include limitations where needed. Inflated impact claims shall be corrected.
432.14 No Attribution Without Evidence. GCRI Canada shall not attribute outcomes to its work without evidence supporting attribution or contribution. Where GCRI Canada contributed to a broader ecosystem outcome, claim language shall distinguish contribution from causation and shall identify uncertainty. Public authority decisions, procurement outcomes, funding outcomes, investment outcomes, technology deployments, community outcomes, safety outcomes, emergency outcomes, or market outcomes shall not be attributed to GCRI Canada without competent evidence and boundary review.
432.15 No Sponsor, Provider, Public Authority, Finance, Certification, Procurement, Recognition, or Maturity Overclaim. Impact claims shall not imply that sponsors controlled outcomes, providers were endorsed, public authorities adopted or approved outputs, finance-readiness was determined, procurement approval was granted, certification occurred, recognition was conferred, maturity status was assigned, Grid status was guaranteed, Docket status was validated, public warning was issued, emergency command was exercised, or Nexus-compatible status became official without competent record and lawful authority. Any such overclaim shall be corrected.
432.16 Limitation and Uncertainty Disclosure. Impact claims shall include limitation and uncertainty disclosure where material. Disclosures may address data quality, sample size, methodology, attribution limits, contribution limits, incomplete records, self-reporting, public authority capacity, sponsor or provider involvement, publication scope, time lag, confidence, external factors, and correction status. Public claims shall not hide uncertainty in a manner that misleads.
432.17 Impact Claim Correction. Where an impact claim is unsupported, overstated, misleading, stale, public authority-misdescriptive, finance-boundary violating, procurement-implying, certification-implying, recognition-implying, maturity-implying, sponsor-inflated, provider-preferential, AI-generated in error, or public-safe risky, GCRI Canada shall correct, qualify, withdraw, supersede, retract, or archive the claim. Downstream materials, sponsor reports, donor reports, public authority materials, decks, websites, social media, and partner references shall be reviewed for repetition of the error.
432.18 Impact Claims Review Records. GCRI Canada shall maintain impact claims review records, including purpose records, evidence-based impact claim requirement records, methods-supported impact claim requirement records, public-benefit impact review records, technical impact review records, research impact review records, learning and capacity impact review records, public authority learning impact review records, community safeguards impact review records, public-good software and technical baseline impact review records, data / AI / cyber impact review records, finance-readiness evidence support impact review records without finance-readiness determination, no-overstatement records, no-attribution-without-evidence records, no-sponsor / provider / public authority / finance / certification / procurement / recognition / maturity overclaim records, limitation and uncertainty disclosure records, impact claim correction records, closeouts, and archives.
Section 433. Membership, Participation, Council, Committee, Program, Academy, Fellowship, and Competence Cell Performance Review
433.1 Participation Performance Review Purpose. GCRI Canada shall maintain participation performance review to ensure that membership structures where applicable, participation categories, councils, committees, advisory bodies, working groups, programs, activation dockets, Academy activities, fellowships, competence cells, technical contributor pathways, controlled rooms, public authority interfaces, and Nexus-compatible participation surfaces remain lawful, public-benefit aligned, role-clear, boundary-controlled, non-capturing, accessible, effective, and correctionable. Participation performance review shall not inflate participation into governance authority, public authority delegation, certification, finance-readiness, procurement preference, recognition, maturity, or provider endorsement.
433.2 Membership Structure Review. GCRI Canada shall review its membership or memberless governance structure to confirm that statutory members, voting members, non-voting members, supporters, affiliates, subscribers, institutional participants, and other participation categories are accurately defined and recorded. Review shall confirm that governance rights exist only by lawful record and that donation, sponsorship, subscription, attendance, contribution, authorship, public authority participation, provider participation, technical access, Academy participation, or controlled-room access does not create membership rights unless lawfully established.
433.3 Participant Good Standing Review. Participant good standing review shall assess whether participants comply with applicable terms, confidentiality, conflicts, data / AI / cyber rules, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, safeguards, public-safe claims discipline, non-retaliation, training requirements, access limits, and correction obligations. Good standing may be affected by misconduct, overclaims, unpaid lawful fees where applicable, access misuse, confidentiality breach, data misuse, AI misuse, cyber misconduct, sponsor or provider misuse, or failure to complete required training.
433.4 Access Rights Review. Access rights review shall assess whether participants have appropriate access to records, rooms, repositories, dashboards, maps, data, AI tools, publications, Academy materials, technical assets, public authority materials, protected knowledge, finance-sensitive materials, and controlled annexes. Access shall be role-based, least-privilege, purpose-limited, time-limited where appropriate, classification-appropriate, and revoked upon role change, misconduct, closeout, or termination. Participation status alone shall not justify sensitive access.
433.5 Conflict and Recusal Review. Conflict and recusal review shall assess whether members, directors, officers, committee participants, council participants, reviewers, fellows, advisors, providers, sponsors, hosts, partners, public authority participants, technical contributors, and other participants have disclosed conflicts and recused where required. Review shall address financial interests, employment, sponsorship, provider relationships, public authority roles, donor interests, funder interests, IP interests, research interests, publication interests, procurement interests, finance interests, and Nexus entity relationships.
433.6 Committee Performance Review. Committee performance review shall assess whether committees are operating within charter, meeting with appropriate cadence, preserving quorum, managing conflicts, maintaining minutes, reviewing materials, making decisions within authority, escalating issues, preserving confidentiality, supporting Board oversight, and avoiding authority inflation. Committee performance shall not be measured merely by meeting frequency or volume of outputs. Committees shall be renewed, redesigned, suspended, or sunset where function is unclear or ineffective.
433.7 Leadership Council Performance Review. Leadership Council performance review shall assess whether any leadership council or equivalent senior advisory surface supports coordination, institutional learning, public-benefit alignment, boundary discipline, and role clarity without becoming a shadow Board, officer body, public authority, finance-readiness authority, certification authority, procurement authority, recognition authority, or execution vehicle. Review shall include representation, conflicts, dissent capture, minority reporting, advisory limits, output quality, and records.
433.8 Helix Council Performance Review. Helix Council performance review shall assess whether helix-based participation across public authorities, academia, civil society, communities, providers, sponsors, hosts, capital readers, and other actors remains balanced, capacity-classified, boundary-controlled, non-capturing, and public-benefit aligned. Review shall confirm that multi-helix participation does not create shared governance, public-private partnership, public authority delegation, provider preference, procurement steering, finance-readiness, certification, recognition, or maturity status.
433.9 Advisory Body Performance Review. Advisory body performance review shall assess whether advisory councils, scientific and technical advisory councils, public authority advisory forums, community and safeguards advisory forums, expert panels, and time-limited advisory groups provide useful, independent, conflict-controlled, confidential where needed, record-supported, non-binding advice within approved scope. Advisory body review shall ensure that advisory status is not represented as Board authority, fiduciary authority, public authority status, certification authority, finance-readiness authority, procurement authority, protocol authority, or authority to bind GCRI Canada.
433.10 Working Group and Expert Panel Performance Review. Working group and expert panel performance review shall assess scope, deliverables, timelines, membership, independence, conflicts, vendor and provider participation controls, controlled-room procedures, peer review, reproducibility, comment handling, output adoption path, correction, supersession, deprecation, sunset, and records. Working groups and expert panels shall remain methods, evidence, drafting, review, or learning surfaces unless their outputs are adopted by competent authority through recorded process.
433.11 Program Performance Review. Program performance review shall assess whether programs remain public-benefit aligned, evidence-based, method-governed, non-executing, public-safe, financially clean, technically controlled, accessible, safeguards-compliant, and correctionable. Review shall include program charter, objectives, participants, deliverables, funding, conflicts, data / AI / cyber controls, public authority boundaries, sponsor and provider conduct, publications, impact claims, records, corrective actions, renewal, redesign, sunset, or closeout.
433.12 Activation Docket Performance Review. Activation docket performance review shall assess whether activation dockets, readiness reviews, host activations, adoption windows, replication sprints, governed pilots, labs, challenge programs, and related program surfaces are properly recorded, scoped, boundary-controlled, and non-executing. Review shall confirm that docket status does not imply public authority approval, procurement approval, finance-readiness, certification, recognition, maturity, public warning, emergency command, provider preference, or operational adoption.
433.13 Academy and Training Performance Review. Academy and training performance review shall assess role-based training, attendance, learning outcomes, competence records, renewals, revocations, accessibility, evidence literacy, research integrity, data / AI / cyber literacy, public authority literacy, public-safe publication literacy, safeguards literacy, provider / sponsor / host boundary training, and credential non-inflation. Academy performance shall not be represented as professional certification, regulated credential, public authority qualification, procurement preference, finance-readiness, recognition, maturity, or provider endorsement by default.
433.14 Fellowship Performance Review. Fellowship performance review shall assess whether fellows, research fellows, visiting fellows, technical fellows, Academy fellows, public authority fellows where lawful, and community fellows where appropriate are operating within approved scope, agreement, research integrity requirements, data / AI / cyber requirements, IP terms, publication terms, safeguards terms, confidentiality, public statement limits, conflicts, and closeout requirements. Fellowship performance shall not inflate fellowship status into employment, governance authority, professional certification, public authority qualification, or authority to bind GCRI Canada.
433.15 Competence Cell Performance Review. Competence cell performance review shall assess whether competence cells support capability formation in evidence, methods, research integrity, data governance, AI governance, cybersecurity, observability methods, public-good software, technical baselines, public authority learning, safeguards, finance-boundary literacy, Academy pathways, and workforce development. Review shall confirm that competence cells are not treated as certification authorities, public authorities, provider-selection bodies, procurement bodies, finance-readiness bodies, or corporate organs unless expressly and lawfully established.
433.16 No Governance Control or Authority Inflation by Participation. Participation performance review shall confirm that participation does not create governance control, fiduciary authority, officer authority, Board authority, public authority status, public-private partnership, public warning authority, emergency command, procurement approval, funding approval, regulatory approval, public finance approval, certification authority, recognition authority, maturity authority, finance-readiness authority, provider preference, or authority to bind GCRI Canada. Authority exists only through law, Articles, this Bylaw, Board resolution, contract, or competent record.
433.17 Corrective Action, Renewal, Sunset, or Redesign. Where performance review identifies weak performance, boundary drift, role confusion, access overreach, sponsor or provider influence, public authority confusion, finance-boundary risk, procurement risk, certification implication, safeguards weakness, data / AI / cyber weakness, poor records, low public-benefit value, or unsustainable maintenance, GCRI Canada may impose corrective action, redesign, renewal, restriction, suspension, sunset, termination, closeout, or archival. Renewal decisions shall be evidence-based and record-supported.
433.18 Participation Performance Review Records. GCRI Canada shall maintain participation performance review records, including participation performance review purpose records, membership structure review records, participant good standing review records, access rights review records, conflict and recusal review records, committee performance review records, Leadership Council performance review records, Helix Council performance review records, advisory body performance review records, working group and expert panel performance review records, program performance review records, activation docket performance review records, Academy and training performance review records, fellowship performance review records, competence cell performance review records, no-governance-control-or-authority-inflation records, corrective action / renewal / sunset / redesign records, closeouts, and archives.
Section 434. Federation Performance Review
434.1 Federation Performance Review Purpose. GCRI Canada shall maintain federation performance review to assess whether its interfaces with the wider Nexus institutional federation remain lawful, public-benefit aligned, role-separated, non-executing, semantically compatible, technically useful, financially clean, provider-neutral, public authority-boundary compliant, correctionable, and supported by competent records. Federation performance review shall ensure that coordination across GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards and protocol authority functions, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, global, regional, and national consortium structures, National Consortium Companies, Project SPVs, qualified providers, sponsors, donors, hosts, public authorities, communities, universities, laboratories, and partners does not create merger, shared treasury, shared liability, public authority delegation, finance-readiness determination, certification, procurement approval, recognition, maturity determination, provider preference, sponsor control, or public-private partnership by implication.
434.2 GCRI US Interface Performance Review. GCRI Canada shall review its interface with GCRI US to ensure that evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication practices, data / AI / cyber controls, research integrity practices, and technical asset stewardship remain compatible while preserving separate legal existence, separate governance, separate records, separate treasury, separate liabilities, separate Canadian compliance obligations, and separate authority. Performance review shall identify where alignment is strong, where Canadian localization is required, where divergence is legally or operationally necessary, and where public language could mistakenly imply institutional merger, agency, parent-subsidiary control, shared fiduciary authority, or shared liability.
434.3 GRF Interface Performance Review. GCRI Canada shall review its interface with The Global Risks Forum (GRF) to ensure that technical evidence inputs, public-safe summaries, observability records, methods records, ontology support, correction records, and public-good technical materials remain distinct from GRF’s public-good registry, recognition, standing, maturity-record, claims-discipline, stakeholder-formation, public-safe reporting, and public-facing legitimacy functions. GCRI Canada shall not use federation performance language to imply that it confers recognition, standing, maturity status, registry validity, public legitimacy, certification, or claims approval. GRF-facing performance review shall confirm proper routing, limitation language, evidence lineage, correction synchronization, and no unauthorized recognition function by GCRI Canada.
434.4 GRA Interface Performance Review. GCRI Canada shall review its interface with The Global Risks Alliance (GRA) to ensure that any technical evidence, methods, observability, public-safe intelligence, proof-pack support, or finance-readiness evidence support remains upstream, non-executing, non-reliance, and outside regulated investment, securities, insurance, lending, underwriting, rating, brokerage, public finance, capital placement, or transaction execution. GRA interface performance shall be assessed for boundary language, proof-record quality, technical evidence clarity, correctionability, and prevention of any implication that GCRI Canada makes finance-readiness, insurance-readiness, bankability, investability, underwriting, public finance approval, or capital recommendation determinations.
434.5 Nexus Standards and Protocol Authority Interface Performance Review. GCRI Canada shall review its interface with Nexus Standards and any protocol authority function to ensure that research, methods, evidence, ontology, schemas, APIs, reference architectures, technical baselines, test harnesses, profiles, public-good software, and controlled vocabulary contributions are accurately routed and do not become standards adoption, protocol approval, certification, accreditation, conformance approval, compliance approval, or market authorization by GCRI Canada unless separately lawful and expressly recorded. Performance review shall assess semantic compatibility, version discipline, controlled annex handling, public-safe publication, correction synchronization, and the separation between upstream technical contribution and formal standards or protocol authority.
434.6 Nexus Network Interface Performance Review. GCRI Canada shall review its interface with Nexus Network to ensure that network participation, node relationships, institutional coordination, technical contribution, public-good software exchange, Academy support, public authority learning, and cross-border collaboration remain lawful, role-clear, public-benefit aligned, and non-controlling. Nexus Network interface performance shall be evaluated for legal separateness, no shared treasury, no shared liability, no informal membership creation, no public authority delegation, no sponsor or provider capture, and accurate public language regarding network participation. GCRI Canada shall not permit “network” language to imply governance control, agency, merger, certification, recognition, procurement approval, or finance-readiness.
434.7 Nexus Observatory Interface Performance Review. GCRI Canada shall review its interface with Nexus Observatory to ensure that observability, telemetry, sensing, dashboarding, geospatial analysis, digital twin methods, sensor methods, AI-RAN / O-RAN methods, DePIN methods, sovereign compute methods, cyber evidence methods, degraded-mode awareness, proof, traceability, verifiable intelligence, and public-safe output support remain evidence and methods functions. Review shall confirm that Observatory-related outputs are not treated as public warnings, emergency commands, public authority decisions, official dashboards, safety instructions, certification, finance-readiness, procurement approval, or provider preference. Performance review shall also assess interface records, public-safe limitations, data / AI / cyber controls, protected knowledge controls, and correction pathways.
434.8 Nexus Universe Interface Performance Review. GCRI Canada shall review its interface with Nexus Universe to ensure that universe-level architecture, doctrine, institutional narratives, public-good activation paths, visual story, observatory nodes, consortium pathways, national dense cores, regional clusters, public authority learning, and cross-sector collaboration remain compatible with Canadian legal status, nonprofit posture, public-benefit purpose, and non-execution boundaries. Nexus Universe performance review shall identify whether public materials accurately distinguish GCRI Canada from global doctrine, regional activation vehicles, public authorities, providers, National Consortium Companies, Project SPVs, sponsors, and hosts. Universe language shall not create implied control, official mandate, public-private partnership, procurement authority, finance authority, or sovereign obligation.
434.9 Nexus Risk Management Interface Performance Review. GCRI Canada shall review its interface with Nexus Risk Management to ensure that risk evidence, scenario methods, risk ontologies, uncertainty methods, digital twin methods, simulation methods, public-safe risk outputs, and decision-support materials remain governance-only and non-executing. Performance review shall confirm that GCRI Canada does not issue emergency commands, public warnings, public authority decisions, insurance underwriting, investment advice, public finance approvals, procurement approvals, ratings, certifications, recognition, or maturity determinations through risk-management work. Review shall also assess uncertainty language, method limits, public-safe classifications, and correction records.
434.10 Nexus Rails Interface Performance Review. GCRI Canada shall review its interface with Nexus Rails to ensure that technical evidence inputs, methods inputs, observability inputs, technical baseline inputs, correction inputs, and proof-support materials are accurately limited to capital-readability support where separately governed and do not become finance-readiness outputs controlled by GCRI Canada. Performance review shall confirm no routeability determination, no capital recommendation, no investor matchmaking as regulated activity, no insurance placement, no underwriting, no public finance approval, no bankability determination, and no transaction execution. Nexus Rails interface records shall include non-reliance language, finance-boundary review, correction records, and downstream dependency notes where applicable.
434.11 Nexus Grid Interface Performance Review. GCRI Canada shall review its interface with Nexus Grid to ensure that evidence inputs, technical methods inputs, observatory inputs, research inputs, baseline inputs, correction signals, and Grid-related records remain inputs only and do not become maturity determinations by GCRI Canada. Performance review shall confirm that Grid status is not represented as guarantee, certification, public authority approval, finance-readiness, insurance-readiness, procurement approval, provider preference, performance warranty, or recognition unless separately issued by a competent authority outside GCRI Canada and accurately described. Grid interface performance shall include review of correction signals, compatibility notes, public-safe language, and anti-overclaim controls.
434.12 Nexus Academy and Competence Cell Interface Performance Review. GCRI Canada shall review its interface with Nexus Academy and Nexus Competence Cells to ensure that training, role-based learning, evidence literacy, research integrity literacy, AI / data / cyber literacy, public authority boundary literacy, finance-boundary literacy, safeguards literacy, train-the-trainer materials, public-safe playbooks, controlled annexes, and competence pathways remain learning and capability-formation activities. Review shall confirm that Academy or competence cell participation is not represented as professional certification, regulated credential, public authority qualification, procurement preference, provider recognition, finance-readiness, certification, recognition, maturity, or authority to bind GCRI Canada by default.
434.13 Global, Regional, and National Consortium Interface Performance Review. GCRI Canada shall review its interfaces with global, regional, and national consortium structures to ensure that coordination supports public-good mandate formation, regional hazard evidence, national public authority learning, observatory methods, host readiness evidence, protected knowledge protocols, public-safe activation, interoperability, and localization without transferring governance control over GCRI Canada. Review shall confirm that consortium participation does not create regional supremacy over Canadian corporate governance, national public authority delegation, public-private partnership, public finance approval, procurement authority, recognition authority, certification authority, shared treasury, shared liability, or execution authority for GCRI Canada.
434.14 National Consortium Company, Project SPV, Qualified Provider, Sponsor, Donor, Host, Public Authority, Community, University, Laboratory, and Partner Interface Performance Review. GCRI Canada shall review its interfaces with National Consortium Companies, Project SPVs, qualified providers, sponsors, donors, hosts, public authorities, communities, universities, laboratories, and partners to ensure that each interface remains role-specific, lawful, documented, non-controlling, public-safe, and correctionable. Review shall confirm that National Consortium Companies and Project SPVs do not control GCRI Canada’s public-good functions; providers do not receive preference; sponsors and donors do not purchase control; hosts do not imply endorsement or operational control; public authorities do not delegate powers by participation; communities are not extracted from; universities and laboratories do not create authorship, IP, or ethics ambiguity; and partners do not create agency, merger, joint venture, or shared liability unless separately and lawfully recorded.
434.15 Compatibility Notes Review. GCRI Canada shall review compatibility notes documenting alignment between GCRI Canada and other Nexus interfaces, including legal compatibility, semantic compatibility, evidence compatibility, methods compatibility, ontology compatibility, data / AI / cyber compatibility, public authority boundary compatibility, finance-boundary compatibility, safeguards compatibility, publication compatibility, technical asset compatibility, and correction compatibility. Compatibility notes shall identify scope, assumptions, limits, version, authority, responsible owner, dependencies, and public-safe status. A compatibility note shall not create shared authority, certification, recognition, maturity, procurement approval, finance-readiness, public authority approval, or merger.
434.16 Divergence Logs Review. GCRI Canada shall review divergence logs documenting where GCRI Canada differs from global, regional, national, or affiliate practice because of Canadian law, provincial or territorial requirements, public authority terms, privacy obligations, Indigenous rights, public-sector sensitivity, tax status, nonprofit posture, technical risk, safeguards, data residency, export controls, sanctions, cyber controls, research ethics, public-safe publication, or Board decision. Divergence logs shall identify reason, legal or institutional basis, duration, review cycle, affected records, public language, correction path, and whether divergence is temporary, permanent, experimental, or under review.
434.17 Mismatch, Reconciliation, and Correction Review. GCRI Canada shall review mismatches across federation interfaces, including inconsistent terminology, conflicting records, divergent public statements, incompatible data rights, inconsistent public authority capacity descriptions, conflicting finance-boundary language, incompatible technical baselines, stale interface records, uncorrected outputs, misaligned public-safe classifications, or role-separation confusion. Reconciliation may include compatibility notes, divergence logs, record correction, public-safe clarification, controlled notice, publication update, dashboard update, map update, repository update, training update, contract clarification, or Board escalation. Where reconciliation is not appropriate, divergence shall be recorded and preserved.
434.18 Federation Performance Review Records. GCRI Canada shall maintain federation performance review records, including federation performance review purpose records, GCRI US interface performance review records, GRF interface performance review records, GRA interface performance review records, Nexus Standards and protocol authority interface performance review records, Nexus Network interface performance review records, Nexus Observatory interface performance review records, Nexus Universe interface performance review records, Nexus Risk Management interface performance review records, Nexus Rails interface performance review records, Nexus Grid interface performance review records, Nexus Academy and Competence Cell interface performance review records, global / regional / national consortium interface performance review records, National Consortium Company / Project SPV / qualified provider / sponsor / donor / host / public authority / community / university / laboratory / partner interface performance review records, compatibility note review records, divergence log review records, mismatch / reconciliation / correction review records, corrective actions, closeouts, and archives.
Section 435. Audit, Assurance Sampling, External Review, Internal Review, Peer Review, and Independent Expert Review
435.1 Audit Purpose. GCRI Canada may conduct or obtain audits to evaluate whether selected financial, governance, compliance, technical, data, AI, cyber, research, publication, safeguards, public authority, finance-boundary, procurement-neutrality, certification-boundary, and records processes are operating in accordance with law, the Articles, this Bylaw, Board-approved policies, contracts, public authority terms, funder terms, insurance requirements, and public-benefit purpose. Audit shall support institutional integrity, Board oversight, correctionability, and public trust. Audit shall not be represented as certification, accreditation, public authority approval, finance-readiness, procurement approval, provider endorsement, or professional opinion beyond its defined scope.
435.2 Assurance Sampling Purpose. GCRI Canada may use assurance sampling to test whether selected records, outputs, publications, technical assets, program files, evidence packs, AI-use records, cyber controls, public authority references, finance-boundary statements, sponsor acknowledgments, provider claims, safeguards records, training records, access records, and correction records conform to applicable standards and internal requirements. Assurance sampling may be risk-based, random, stratified, event-triggered, program-based, output-based, or targeted. Sampling findings shall be limitation-bearing and shall not imply universal assurance unless the scope supports such conclusion.
435.3 Internal Review. Internal review may be conducted by officers, management, compliance personnel, program owners, research leads, data / AI / cyber leads, safeguards leads, publication approvers, finance personnel, repository custodians, controlled-room custodians, or other authorized persons. Internal review shall assess compliance, performance, records, risks, controls, corrective actions, and renewal needs within defined scope. Internal reviewers shall disclose conflicts and shall not review matters where their own conduct, decision, or interest creates material impairment unless no alternative exists and compensating oversight is recorded.
435.4 External Review. External review may be obtained from external accountants, auditors, lawyers, cybersecurity assessors, privacy specialists, AI governance specialists, research integrity experts, safeguards experts, Indigenous governance advisors where appropriate, technical experts, insurance advisors, tax advisors, or other qualified persons. External review shall be scoped, contracted, conflict-reviewed, confidentiality-bound, data-controlled, public authority-sensitive where applicable, and record-supported. External review findings shall be considered by competent authority and converted into corrective action where appropriate.
435.5 Peer Review. Peer review may be used for research outputs, methods, evidence packs, technical baselines, dashboards, maps, software, benchmarks, model evaluations, public-safe summaries, ontology artifacts, controlled vocabularies, and Nexus-compatible technical materials. Peer review shall be competent, conflict-controlled, method-aware, limitation-bearing, and documented. Peer review shall not be marketed as certification, accreditation, compliance approval, public authority approval, procurement approval, finance-readiness, recognition, maturity, provider endorsement, or guarantee of correctness.
435.6 Independent Expert Review. Independent expert review may be used where a matter requires specialized technical, legal, ethical, cyber, AI, data, safeguards, Indigenous rights, public authority, finance-boundary, competition, export-control, or other expertise not sufficiently available internally. The independence of the expert shall be assessed relative to the issue, including conflicts, funding relationships, provider relationships, sponsor relationships, public authority relationships, academic relationships, IP interests, and prior involvement. Expert review shall be advisory unless adopted by competent authority.
435.7 Financial Audit or Review Engagement. GCRI Canada may obtain a financial audit, review engagement, compilation, agreed-upon procedures engagement, restricted-fund review, grant audit, tax review, or other financial assurance according to law, Board direction, funder requirement, member requirement where applicable, donor restriction, public authority term, or institutional need. Financial assurance shall assess records within scope and shall not imply public authority approval, charitable status where not applicable, financial guarantee, investment suitability, public finance approval, bankability, or finance-readiness. Findings shall be reviewed by the Board or appropriate committee.
435.8 Governance Audit. Governance audit may assess Board records, director records, officer authority, member records where applicable, conflicts, recusals, minutes, resolutions, delegations, committee charters, council charters, corporate filings, compliance calendar, legal separateness, role separation, public-benefit mission lock, nonprofit posture, non-distribution, and non-execution boundaries. Governance audit findings shall be used to correct records, strengthen authority matrices, update training, amend policies, and preserve validity-by-record.
435.9 Evidence and Methods Assurance Sampling. Evidence and methods assurance sampling may test source lineage, provenance, custody, timestamp, permission, classification, completeness, accuracy, relevance, reproducibility, confidence, uncertainty, method note quality, limitation language, public-safe status, and correction path. Sampling shall identify evidence weakness, stale evidence, unsupported claims, method drift, ontology drift, missing limitations, public authority overclaim risk, finance-boundary risk, certification-boundary risk, and publication correction needs. Sampling limitations shall be recorded.
435.10 Research Integrity Review. Research integrity review may assess research ethics approvals, human-subjects review, community review, Indigenous / local / territorial / protected knowledge review, sponsor and provider influence controls, conflict disclosures, peer review, authorship, attribution, data integrity, AI-use disclosure, reproducibility, publication review, misconduct complaints, correction records, and retraction records. Research integrity review shall support public trust and shall not be suppressed because findings are inconvenient to sponsors, providers, funders, public authorities, researchers, or institutional reputation.
435.11 Data / AI / Cyber Assurance Review. Data / AI / cyber assurance review may assess lawful basis, purpose limitation, minimization, classification, access controls, data retention, deletion, cross-border transfer, AI system inventory, model register, AI-use authorization, human review, hallucination controls, incident response, cybersecurity baseline, IAM, MFA, least privilege, secure configuration, vulnerability management, repository security, secrets handling, backup, disaster recovery, vendor security, and training. Review shall identify gaps, incidents, required restrictions, and corrective actions.
435.12 Public Authority Boundary Review. Public authority boundary review may test capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management participant status, public infrastructure operator status, data contribution records, logo permissions, quote permissions, attendance references, non-endorsement language, no-delegation controls, no-PPP controls, no-public-warning controls, and correction records. Findings shall be corrected promptly where public misunderstanding is possible.
435.13 Publication and Claims Review. Publication and claims review may test whether websites, reports, whitepapers, decks, social media, speeches, datasets, software releases, dashboards, maps, public repositories, donor reports, sponsor materials, provider materials, public authority-facing materials, and capital-reader materials are source-supported, method-supported, public-safe, limitation-bearing, AI-reviewed where applicable, sponsor/provider reviewed where applicable, and boundary-compliant. Unsupported or unsafe claims shall be corrected, qualified, withdrawn, or archived.
435.14 Safeguards Review. Safeguards review may assess community participation, Indigenous rights, Indigenous data, Indigenous knowledge, local and territorial knowledge, cultural sites, environmental knowledge, protected knowledge, FPIC where applicable, accessibility, vulnerable and remote communities, grievance, remedy, non-retaliation, protected participation, stop-the-line use, public-safe mapping, do-no-harm controls, safeguards incidents, and correction records. Safeguards review shall be conducted with appropriate competence and sensitivity and shall not be reduced to procedural checklists where substantive harm risk exists.
435.15 Sponsor, Provider, and Anti-Capture Review. Sponsor, provider, and anti-capture review may assess whether sponsors, donors, funders, providers, hosts, partners, vendors, public authority-linked supporters, National Consortium Companies, Project SPVs, or other actors have influenced governance, research, methods, evidence, publications, public authority access, benchmarks, challenges, Academy materials, technical baselines, software, public claims, corrections, procurement language, finance language, certification language, or recognition language. Review may test benefit schedules, acknowledgment language, concentration, related-party funding, public authority access, provider preference, and pay-to-play risks.
435.16 Technical Asset and Secure Release Review. Technical asset and secure release review may assess public-good software, internal software, restricted software, schemas, APIs, SDKs, dashboards, data tools, ontology files, model cards, system cards, benchmark cards, reference architectures, interoperability profiles, test harnesses, gold vectors, negative tests, technical baselines, repositories, dependency files, SBOMs, signatures, provenance, vulnerabilities, licenses, contribution terms, release notes, public-safe status, and deprecation or retirement status. Releases may be held or restricted where risks are material.
435.17 Reviewer Independence and Conflict Controls. All audit, assurance, review, peer review, and expert review processes shall include independence and conflict controls proportionate to scope and risk. Reviewers shall disclose financial interests, employment relationships, sponsor relationships, provider relationships, public authority relationships, donor or funder relationships, IP interests, authorship interests, prior involvement, personal relationships, and other conflicts. Conflicted reviewers may be excluded, limited, paired with independent reviewers, or permitted with recorded mitigation where appropriate. Reviewer independence shall be especially important for high-risk, public-facing, public authority-sensitive, finance-sensitive, certification-sensitive, safeguards-sensitive, or cyber-sensitive matters.
435.18 Review Scope, Findings, Recommendations, Corrective Actions, and Closeout. Each audit or review shall define scope, period, materials reviewed, standards applied, sampling method where any, limitations, reviewers, conflicts, findings, severity, recommendations, management response, corrective actions, responsible owners, deadlines, verification method, residual risk, Board reporting need, public-safe communication need, and closeout criteria. Findings shall not be closed without evidence of completion or a recorded decision to accept residual risk. Material findings shall be escalated according to severity.
435.19 Audit and Assurance Review Records. GCRI Canada shall maintain audit and assurance review records, including audit purpose records, assurance sampling purpose records, internal review records, external review records, peer review records, independent expert review records, financial audit or review engagement records, governance audit records, evidence and methods assurance sampling records, research integrity review records, data / AI / cyber assurance review records, public authority boundary review records, publication and claims review records, safeguards review records, sponsor / provider / anti-capture review records, technical asset and secure release review records, reviewer independence and conflict control records, scope records, findings, recommendations, corrective actions, management responses, Board responses, verification records, closeouts, and archives.
Section 436. Annual Assurance Report
436.1 Annual Assurance Report Purpose. GCRI Canada may prepare an annual assurance report to provide the Board with a structured, record-supported view of GCRI Canada’s public-benefit performance, governance integrity, evidence and methods quality, research integrity, technical asset stewardship, data / AI / cyber posture, public authority boundary compliance, publication and claims discipline, safeguards performance, finance / sponsorship / donation / grant / anti-capture controls, Nexus interface discipline, incidents, corrections, lessons learned, limitations, and renewal needs. The annual assurance report shall support Board oversight, institutional learning, correctionability, and renewal. It shall not be represented as certification, accreditation, public authority approval, finance-readiness, procurement approval, recognition, maturity, rating, or professional assurance beyond its defined scope.
436.2 Board Direction. The Board may direct the preparation, scope, timing, format, audience, reviewers, controlled annexes, external review, public-safe summary, and acceptance process for the annual assurance report. Board direction may identify priority risks, required domains, sampling expectations, material incidents, unresolved corrective actions, public authority-sensitive matters, finance-boundary issues, sponsor or provider concerns, safeguards concerns, technical asset issues, data / AI / cyber matters, and Nexus interface issues to be covered. The Board may delegate preparation to officers or management but shall retain oversight.
436.3 Report Scope. The annual assurance report shall define its scope, period covered, included entities or interfaces, excluded matters, methods, evidence sources, sampling approach, limitations, reviewers, conflicts, reliance on external advisors, controlled annexes, and public-safe status. Scope shall distinguish GCRI Canada’s own records from records of other Nexus entities, public authorities, sponsors, providers, hosts, National Consortium Companies, Project SPVs, universities, laboratories, or partners. Report scope shall preserve legal separateness and avoid implying consolidated assurance over entities outside GCRI Canada’s authority.
436.4 Public-Benefit Purpose Assessment. The annual assurance report may assess whether GCRI Canada’s activities during the reporting period advanced its public-benefit purpose and remained consistent with nonprofit, non-share, non-distributing, non-executing, public-good technical stewardship. Assessment may consider program activity, research activity, public-good technical assets, public-safe publications, Academy activity, fellowship activity, public authority learning, safeguards, corrections, and institutional renewal. The assessment shall identify limitations and shall not overstate impact or imply outcomes beyond evidence.
436.5 Governance Assessment. The report may assess Board performance, officer authority, committee operations, council operations, conflicts, recusals, minutes, resolutions, member structure where applicable, corporate filings, compliance calendar, legal separateness, role separation, delegation records, policy updates, training, continuity, and succession. Governance assessment shall identify governance gaps, record weaknesses, authority ambiguity, role inflation, capture risk, and corrective actions. It shall not treat informal practice as valid authority where records are required.
436.6 Evidence and Methods Assessment. The report may assess evidence quality, source lineage, provenance, custody, timestamp currency, permission, classification, completeness, accuracy, relevance, timeliness, reproducibility, confidence, uncertainty, method note quality, evidence pack quality, controlled vocabulary alignment, ontology alignment, stale evidence, disputed evidence, superseded evidence, and evidence correction performance. Evidence and methods assessment shall identify where outputs require correction, supersession, withdrawal, limitation, or further review.
436.7 Research Integrity Assessment. The report may assess research agenda alignment, research ethics review, human-subjects review where applicable, community and protected knowledge review, Indigenous rights review where applicable, sponsor and provider influence controls, conflicts, peer review, reproducibility, replication, AI-use disclosure, publication integrity, misconduct complaints, corrections, retractions, and lessons learned. Research integrity assessment shall be candid and shall not suppress negative findings or corrections for reputational reasons.
436.8 Technical Asset Assessment. The report may assess public-good software, internal software, restricted software, schemas, APIs, SDKs, dashboards, data tools, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, technical baselines, repositories, licenses, contributors, dependencies, vulnerabilities, secure release processes, documentation, maintenance sustainability, anti-enclosure posture, deprecations, retirements, and technical asset corrections. Technical asset assessment shall distinguish maintained, experimental, deprecated, retired, restricted, and public-safe assets.
436.9 Data / AI / Cyber Assessment. The report may assess data governance, privacy compliance, public authority data handling, retention, deletion, access controls, cross-border transfers, AI system inventory, model register, AI-use authorization, human review, AI incidents, hallucination controls, prompt injection controls, agentic AI controls, cybersecurity baseline, IAM, MFA, least privilege, vulnerability management, repository security, incident response, vendor security, backup, disaster recovery, business continuity, and training. The assessment shall identify material gaps, exceptions, incidents, and corrective actions.
436.10 Public Authority Boundary Assessment. The report may assess public authority capacity classifications, official capacity records, observer status, regulator-listening status, public finance reader status, emergency-management participant status, public infrastructure operator status, public authority data contributions, public authority references, non-endorsement language, no-delegation controls, no-PPP controls, no-public-warning controls, public authority corrections, and public authority-facing publications. Assessment shall identify any public authority confusion, misdescription, stale capacity records, or public language requiring correction.
436.11 Publication and Claims Assessment. The report may assess websites, articles, social media, speeches, decks, public reports, whitepapers, datasets, software releases, public dashboards, public maps, public repositories, donor reports, sponsor materials, provider materials, public authority-facing materials, capital-reader materials, disclaimers, boundary language, controlled vocabulary, technical claims, AI-assisted content, corrections, supersessions, withdrawals, retractions, public clarifications, and archive status. Publication and claims assessment shall identify unsupported claims, overclaims, stale outputs, and correction needs.
436.12 Safeguards Assessment. The report may assess community participation, Indigenous rights, Indigenous data, Indigenous knowledge, local and territorial knowledge, cultural sites, environmental knowledge, protected knowledge, FPIC where applicable, accessibility, vulnerable and remote communities, public-safe mapping, grievance, remedy, protected participation, whistleblowing, dissent protection, anti-retaliation, confidential reporting, stop-work, stop-the-line, do-no-harm controls, safeguards incidents, and safeguards corrections. Safeguards assessment shall be substantive and harm-aware.
436.13 Finance, Sponsorship, Donation, Grant, and Anti-Capture Assessment. The report may assess financial sustainability, restricted funds, grants, donations, sponsorships, subscriptions, fees, in-kind support, cost recovery, benefit schedules, donor restrictions, sponsor non-control, provider neutrality, support-without-control, no-control-for-cash, no-pay-to-play, public acknowledgments, concentration risk, related-party funding, source-of-funds concerns, tax compliance, finance-boundary language, procurement neutrality, certification boundaries, and anti-capture controls. Assessment shall identify any pressure, influence, overclaim, or dependency requiring action.
436.14 Nexus Interface and Role-Separation Assessment. The report may assess GCRI Canada’s interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, hosts, public authorities, communities, universities, laboratories, and partners. Assessment shall evaluate legal separateness, semantic compatibility, interface records, compatibility notes, divergence logs, mismatch resolution, correction synchronization, no shared treasury, no shared liability, no merger, and no authority inflation.
436.15 Incidents, Corrections, Supersessions, Withdrawals, Retractions, and Lessons Learned. The report shall identify material incidents, corrections, supersessions, withdrawals, retractions, public clarifications, controlled notices, archive changes, public authority corrections, AI incidents, cyber incidents, data incidents, safeguards incidents, publication errors, finance-boundary corrections, procurement-boundary corrections, certification-boundary corrections, sponsor or provider claim corrections, and lessons learned within the reporting period, subject to confidentiality, privilege, public-safe status, protected knowledge, and privacy. Lessons learned shall be tied to corrective actions and renewal.
436.16 Limitations of Assurance. The annual assurance report shall state its limitations, including scope limits, sampling limits, data quality limits, reliance on internal records, reliance on external reviewers, unreviewed areas, unresolved matters, confidentiality constraints, public authority restrictions, protected knowledge restrictions, legal privilege, timing limits, uncertainty, and non-certification status. Limitations shall be clear enough to prevent overreliance. The report shall not imply that absence of reported findings means absence of risk.
436.17 Controlled Annexes. The report may include controlled annexes for sensitive materials, including legal advice, privileged materials, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive evidence, protected knowledge, privacy-sensitive records, research misconduct records, whistleblowing records, personnel records, security findings, export-control reviews, sanctions reviews, detailed incident records, or other non-public materials. Controlled annexes shall be access-limited, classified, and handled under confidentiality and records rules.
436.18 Board Review and Acceptance. The Board shall review and may accept, reject, revise, remand, condition, or request further work on the annual assurance report. Board acceptance shall not eliminate underlying risks or substitute for corrective action. The Board may direct policy updates, method updates, training updates, technical asset updates, records updates, public material updates, additional assurance, external review, public-safe summary, or controlled remediation. Board review and acceptance shall be recorded.
436.19 Annual Assurance Report Records. GCRI Canada shall maintain annual assurance report records, including purpose records, Board direction records, scope records, public-benefit purpose assessment records, governance assessment records, evidence and methods assessment records, research integrity assessment records, technical asset assessment records, data / AI / cyber assessment records, public authority boundary assessment records, publication and claims assessment records, safeguards assessment records, finance / sponsorship / donation / grant / anti-capture assessment records, Nexus interface and role-separation assessment records, incident / correction / supersession / withdrawal / retraction / lessons-learned records, limitation records, controlled annex records, Board review and acceptance records, corrective actions, closeouts, and archives.
Section 437. Public-Safe Annual Report
437.1 Public-Safe Annual Report Purpose. GCRI Canada may prepare a public-safe annual report to communicate, in a lawful, accurate, limitation-bearing, accessible, non-executing, and correctionable manner, selected information concerning GCRI Canada’s public-benefit activities, research, evidence and methods work, public-good software, technical baselines, data / AI / cyber governance, public authority learning, community safeguards, Academy activities, fellowships, training, competence formation, grants, donations, sponsorships, public-good support, public-safe financial information where approved, impact claims, corrections, and non-execution boundaries. The public-safe annual report shall inform without exposing protected information, overclaiming authority, implying endorsement, or creating reliance beyond the record.
437.2 Public-Benefit Activities Summary. The public-safe annual report may summarize GCRI Canada’s public-benefit activities during the reporting period, including public-good research, evidence discipline, methods development, observability methods, ontology stewardship, public-safe publication, technical literacy, public authority learning, Academy work, competence formation, public-good software, technical baselines, safeguards, and correctionability. The summary shall be proportionate to evidence and shall not imply public authority adoption, finance-readiness, procurement approval, certification, recognition, maturity, public warning, emergency command, or provider preference.
437.3 Research Summary. The report may include a public-safe research summary describing research themes, publications, methods notes, evidence packs, collaborations, fellowships, peer review, research ethics posture, AI-use disclosure where appropriate, and corrections. The research summary shall avoid confidential data, protected knowledge, public authority-sensitive details, sponsor-controlled framing, provider preference, premature findings, unsupported claims, or overstatement of impact. Research limitations and uncertainty shall be disclosed where material.
437.4 Evidence and Methods Summary. The report may summarize evidence and methods work, including source discipline, methods development, ontology alignment, controlled vocabulary, evidence quality review, public-safe methods notes, observability evidence support, risk methods, dashboard methods, map methods, technical baselines, and correction performance. Evidence and methods summaries shall distinguish methods artifacts from public authority decisions, finance-readiness determinations, certifications, procurement approvals, ratings, recognition, maturity determinations, public warnings, and emergency commands.
437.5 Public-Good Software and Technical Baselines Summary. The report may summarize public-good software, schemas, APIs, SDKs, data dictionaries, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, technical baselines, repositories, releases, deprecations, retirements, vulnerabilities corrected, and maintenance status. The summary shall identify limitations, license posture, public-safe status, security status, and correction path where appropriate. It shall not represent technical assets as certified, warranted, procurement-approved, provider-endorsing, finance-ready, public authority-approved, or performance-guaranteed.
437.6 Data / AI / Cyber Governance Summary. The report may summarize data governance, privacy compliance, AI governance, cybersecurity baseline, model register discipline, AI-use review, human review practices, incident response, vendor security, repository security, access controls, public authority data handling, protected knowledge controls, backup and continuity, and training. Public summaries shall avoid disclosing security-sensitive details, cyber vulnerabilities, infrastructure-sensitive information, personal information, public authority-sensitive data, protected knowledge, or controlled technology. AI and cyber summaries shall be limitation-bearing.
437.7 Public Authority Learning Summary. The report may summarize public authority learning activities, capacity-building sessions, regulator-listening engagements, public finance reader learning, emergency-management learning, infrastructure-operator learning, workshops, simulations, dashboards or map literacy sessions, and public authority-facing evidence literacy. The summary shall use approved public authority language and shall not imply endorsement, adoption, delegation, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, public policy adoption, or infrastructure adoption.
437.8 Community Safeguards Summary. The report may summarize community safeguards, Indigenous rights respect, Indigenous data and knowledge safeguards, local and territorial knowledge safeguards, protected knowledge controls, public-safe mapping, vulnerable and remote community safeguards, accessibility, grievance pathways, remedy pathways, non-retaliation, protected participation, stop-work, stop-the-line, do-no-harm controls, and safeguards corrections. Public reporting shall not expose protected knowledge, culturally sensitive information, vulnerable communities, complainants, whistleblowers, confidential grievances, or sensitive locations.
437.9 Academy, Fellowship, Training, and Competence Formation Summary. The report may summarize Academy programs, role-based training, evidence literacy, research integrity training, data / AI / cyber literacy, public authority boundary training, finance-boundary literacy, safeguards training, fellowships, technical residencies, scholarships, stipends, awards, competence cells, train-the-trainer work, public-safe playbooks, controlled annexes, and localization. The summary shall include credential non-inflation language where needed and shall not represent participation as professional certification, regulated credential, public authority qualification, procurement preference, finance-readiness, recognition, maturity, or provider endorsement.
437.10 Grants, Donations, Sponsorships, and Public-Good Support Summary. The report may summarize grants, donations, sponsorships, subscriptions, in-kind support, compute credits, cloud credits, software support, facility support, public-good infrastructure support, and other support where approved for public disclosure. The summary shall distinguish support categories, avoid misleading charitable claims, preserve sponsor and donor non-control, avoid provider preference, and disclose that support does not purchase governance control, research outcomes, public authority access, finance-readiness, certification, recognition, procurement advantage, or public claims. Restricted or confidential support shall be omitted or generalized where required.
437.11 Public-Safe Financial Summary Where Approved. The report may include a public-safe financial summary where approved by the Board or delegated authority, including revenue categories, expense categories, restricted funds, program spending, reserves, public-good asset support, and financial sustainability information. Financial summaries shall be accurate, consistent with financial records, tax posture, and accounting treatment. They shall not imply charitable status where not applicable, public finance approval, investment suitability, financial guarantee, bankability, solvency guarantee, donor endorsement, sponsor control, or public authority funding commitment.
437.12 Impact Claims With Evidence and Limitations. The report may include impact claims only where supported by evidence and methods and accompanied by appropriate limitations. Impact claims shall distinguish outputs, outcomes, contribution, attribution, uncertainty, and causality. Claims concerning public benefit, technical impact, research impact, learning impact, public authority learning, safeguards impact, software use, technical baseline use, data / AI / cyber improvement, or finance-readiness evidence support shall not overstate evidence or imply certification, procurement approval, finance-readiness determination, public authority adoption, recognition, maturity, provider success, sponsor achievement, public warning, or emergency command.
437.13 Corrections, Supersessions, Withdrawals, and Retractions Summary Where Public-Safe. The report may summarize corrections, supersessions, withdrawals, retractions, public clarifications, controlled corrections, archive changes, public authority corrections, publication corrections, technical asset deprecations, AI-assisted content corrections, dashboard corrections, map corrections, and lessons learned where public-safe. The summary shall protect confidentiality, privacy, protected knowledge, legal privilege, public authority-sensitive information, cyber-sensitive information, personnel matters, and whistleblower records. Corrections shall be presented as part of institutional integrity and correctionability.
437.14 Non-Execution and Non-Endorsement Language. The public-safe annual report shall include non-execution and non-endorsement language appropriate to its content. Such language shall state, as applicable, that GCRI Canada does not issue public warnings, emergency commands, public authority decisions, regulatory approvals, procurement approvals, funding approvals, public finance approvals, investment advice, insurance approvals, underwriting, ratings, finance-readiness determinations, certifications, recognition, maturity determinations, provider preferences, public authority endorsements, sponsor-controlled outcomes, or professional opinions by default. Boundary language shall be clear and visible.
437.15 Redactions and Controlled Annexes. The report may use redactions and controlled annexes to protect confidential, privileged, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, privacy-sensitive, health-sensitive, export-controlled, sanctions-sensitive, research-sensitive, personnel-sensitive, whistleblower-sensitive, community-sensitive, Indigenous knowledge-sensitive, protected knowledge, or security-sensitive information. Redactions shall be sufficient to prevent re-identification, unsafe disclosure, public authority misuse, sponsor misuse, provider misuse, protected knowledge exposure, or cyber harm. Controlled annexes shall not be public unless separately approved.
437.16 Board Approval or Delegated Approval. The public-safe annual report shall be approved by the Board or by a delegated authority acting within approved scope. Approval shall confirm that the report has undergone appropriate publication review, public authority boundary review, finance-boundary review, sponsor / provider reference review, data / AI / cyber review, safeguards review, legal review where required, redaction review, and correction-path review. Approval shall not eliminate the obligation to correct the report if errors, overclaims, or unsafe disclosures are later identified.
437.17 Public-Safe Annual Report Records. GCRI Canada shall maintain public-safe annual report records, including purpose records, public-benefit activities summary records, research summary records, evidence and methods summary records, public-good software and technical baselines summary records, data / AI / cyber governance summary records, public authority learning summary records, community safeguards summary records, Academy / fellowship / training / competence formation summary records, grants / donations / sponsorships / public-good support summary records, public-safe financial summary records where approved, impact claim evidence and limitation records, correction / supersession / withdrawal / retraction summary records, non-execution and non-endorsement language records, redaction records, controlled annex records, approval records, publication records, corrections, closeouts, and archives.
Section 438. Corrective Action Plans, Renewal Actions, Policy Updates, Method Updates, Training Updates, Committee Updates, Records Updates, and Public Material Updates
438.1 Corrective Action Plan Purpose. GCRI Canada shall maintain corrective action plans to ensure that findings from monitoring, evaluation, assurance, audit, review, incident response, investigation, safeguards review, public authority correction, data / AI / cyber review, publication review, technical asset review, research integrity review, sponsor or provider conduct review, Board review, external review, or annual assurance reporting are translated into responsible, time-bound, evidence-supported, and verifiable action. Corrective action plans shall protect public-benefit purpose, lawful operation, non-execution, role separation, public authority boundaries, finance boundaries, provider neutrality, public-safe claims discipline, validity-by-record, and correctionability.
438.2 Corrective Action Trigger. A corrective action plan may be triggered by legal noncompliance, governance weakness, corporate filing issue, nonprofit or tax issue, privacy issue, AI incident, cyber incident, research integrity concern, evidence weakness, method weakness, public authority misdescription, finance-boundary overclaim, procurement overclaim, certification overclaim, recognition overclaim, public warning implication, emergency command implication, sponsor or provider misuse, safeguards failure, protected knowledge issue, accessibility failure, training gap, technical asset vulnerability, publication error, audit finding, assurance finding, Board directive, external review finding, complaint, grievance, or repeated minor issues indicating systemic risk.
438.3 Corrective Action Owner. Each corrective action shall have an identified owner with authority, competence, and responsibility to complete or coordinate the action. Owners may include officers, program owners, research leads, data / AI / cyber leads, privacy leads, safeguards leads, publication approvers, finance personnel, repository custodians, technical asset stewards, committee chairs, training leads, public authority interface owners, legal leads, or other authorized persons. Where ownership is shared, one accountable owner shall be identified. Conflicted persons shall not control corrective actions addressing their own misconduct without oversight.
438.4 Corrective Action Deadline. Each corrective action shall have a deadline proportionate to severity, legal requirement, public-safe risk, public authority risk, data / AI / cyber risk, protected knowledge risk, financial risk, publication status, and operational dependency. Deadlines may be immediate, urgent, short-term, medium-term, long-term, release-based, review-cycle-based, or Board-directed. Deadline extensions shall be justified, approved where required, and recorded. High-risk unresolved corrective actions shall be escalated.
438.5 Corrective Action Evidence. Corrective action completion shall be supported by evidence, which may include revised policy, revised method, revised publication, corrected record, access log, training record, deletion record, repository commit, release note, public-safe clarification, controlled notice, Board resolution, legal review, vendor confirmation, public authority confirmation, safeguards closeout, incident closeout, test result, screenshot, certificate of insurance, filing receipt, audit response, or other reliable record. Corrective actions shall not be closed merely because an intention to act was recorded.
438.6 Renewal Action Purpose. Renewal actions shall be used to improve, modernize, localize, strengthen, restrict, suspend, retire, replace, or redesign GCRI Canada programs, policies, methods, technical assets, training, committees, records, public materials, and Nexus interfaces in response to evidence, risk, law, public authority terms, technical change, AI change, cyber threat, safeguards learning, public-benefit needs, institutional capacity, correction history, or Board direction. Renewal shall be proactive as well as corrective and shall not wait for failure where material drift is foreseeable.
438.7 Policy Updates. GCRI Canada shall update policies where monitoring, evaluation, assurance, incidents, audits, legal changes, Board decisions, public authority terms, sponsor or provider conduct, data / AI / cyber risks, research integrity findings, safeguards findings, or operational experience show that existing policies are incomplete, stale, unclear, ineffective, inconsistent, or misaligned with this Bylaw. Policy updates shall identify affected policies, rationale, authority, effective date, training needs, communication needs, records affected, and superseded versions.
438.8 Method Updates. GCRI Canada shall update methods where evidence review, research review, technical review, observability review, risk review, AI review, dashboard review, map review, ontology review, controlled vocabulary review, public-safe publication review, safeguards review, or peer review identifies improvement needs. Method updates shall preserve source lineage, versioning, assumptions, limitations, reproducibility where feasible, public-safe status, and correction path. Method updates shall not be used to conceal prior error; prior versions shall be superseded or corrected where needed.
438.9 Technical Asset Updates. GCRI Canada shall update technical assets where software, schemas, APIs, SDKs, dashboards, data dictionaries, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, technical baselines, repositories, dependencies, licenses, documentation, security posture, public-safe status, or interoperability require improvement. Technical asset updates may include patches, vulnerability remediation, deprecation, retirement, access restriction, license correction, documentation update, release hold, release note, migration guidance, or archive update.
438.10 Data / AI / Cyber Control Updates. GCRI Canada shall update data, AI, and cyber controls where reviews identify access drift, unauthorized tool use, model risk, hallucination risk, prompt injection risk, agentic AI risk, data leakage, privacy weakness, public authority data risk, protected knowledge risk, repository weakness, credential exposure, vulnerability, vendor weakness, backup weakness, logging weakness, retention issue, deletion issue, or incident response gap. Updates may include tool restriction, model suspension, access revocation, MFA requirement, logging enhancement, vendor change, training, data deletion, retention change, or incident playbook revision.
438.11 Public Authority Protocol Updates. GCRI Canada shall update public authority protocols where capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, public authority data contribution, public authority references, logos, quotes, attendance language, non-endorsement language, no-delegation controls, no-PPP controls, public warning boundaries, emergency command boundaries, procurement boundaries, funding boundaries, regulatory boundaries, public finance boundaries, or correction processes require improvement. Protocol updates shall be communicated to relevant personnel and participants.
438.12 Publication and Claims Updates. GCRI Canada shall update publications and claims where output review, incident review, public authority correction, AI review, safeguards review, sponsor or provider claim review, impact claim review, technical review, or evidence review identifies unsupported claims, stale claims, overclaims, missing limitations, misleading public authority references, finance-boundary issues, certification-boundary issues, procurement implications, public warning implications, emergency command implications, protected knowledge exposure, data disclosure, cyber sensitivity, or outdated public-safe status. Updates may include correction, supersession, withdrawal, retraction, public clarification, controlled notice, redaction, archive note, or replacement publication.
438.13 Safeguards Updates. GCRI Canada shall update safeguards where community participation review, Indigenous rights review, protected knowledge review, accessibility review, grievance review, remedy review, public-safe mapping review, do-no-harm review, stop-work review, protected participation review, or incident review identifies gaps. Safeguards updates may include new consent language, non-consent tracking, withdrawal pathways, correction pathways, community protocol handling, FPIC processes where applicable, protected knowledge classification, accessibility measures, grievance channels, remedy practices, public-safe mapping controls, AI-use restrictions, or sponsor/provider access restrictions.
438.14 Committee, Council, Working Group, and Competence Cell Updates. GCRI Canada shall update committee, council, working group, expert panel, peer review board, model review panel, advisory body, and competence cell structures where performance review identifies unclear mandate, weak attendance, conflict issues, insufficient expertise, authority inflation, poor records, ineffective outputs, duplication, sponsor or provider influence, public authority confusion, boundary drift, confidentiality weakness, or unsustainable operation. Updates may include charter amendment, membership change, chair change, training, recusal rules, output limits, sunset, merger of internal functions where lawful, or redesign.
438.15 Training Updates. GCRI Canada shall update training where laws, policies, tools, AI systems, cyber threats, public authority protocols, finance-boundary rules, publication rules, research integrity standards, safeguards, protected knowledge requirements, incidents, audit findings, assurance findings, or performance reviews show that existing training is incomplete, stale, ineffective, inaccessible, or not role-specific. Training updates shall identify affected roles, required renewal, attendance records, learning outcomes, competence records, revocation where applicable, and credential non-inflation language.
438.16 Records and Register Updates. GCRI Canada shall update records and registers where corrective or renewal actions affect corporate records, Board records, officer records, member records where applicable, participant records, public authority records, data registers, model registers, technical asset registers, risk registers, issue registers, control registers, metric registers, publication registers, correction registers, training records, conflict records, access records, sponsor records, provider records, grant records, insurance records, sanctions records, export-control records, or Nexus interface records. Records shall preserve version history and traceability.
438.17 Public Material Updates. GCRI Canada shall update public materials where public websites, reports, decks, articles, social media, public dashboards, public maps, datasets, software releases, repositories, annual reports, donor reports, sponsor acknowledgments, provider references, public authority references, Academy materials, public-safe summaries, media materials, or Nexus-compatible statements become inaccurate, stale, unsupported, unsafe, overclaiming, misclassified, or superseded. Public updates shall be proportionate, visible where needed, and traceable. Public material updates shall include boundary language where appropriate.
438.18 Verification of Completion. GCRI Canada shall verify completion of corrective actions and renewal actions through evidence review, owner attestation, independent review where appropriate, system check, publication check, access review, training completion, repository review, Board review, legal review, safeguards review, public authority confirmation where required, or other suitable method. Verification shall assess whether the action actually addressed the issue, whether residual risk remains, whether downstream materials were updated, and whether further action is required.
438.19 Escalation for Non-Completion. Corrective actions and renewal actions that are overdue, incomplete, ineffective, disputed, blocked, under-resourced, ownerless, repeatedly extended, or associated with high risk shall be escalated to appropriate authority. Escalation may include officer review, committee review, Board Chair review, full Board review, counsel review, data / AI / cyber review, safeguards review, finance-boundary review, publication hold, access restriction, program suspension, technical asset deprecation, sponsor or provider restriction, public authority notice, or external review. Non-completion shall not be hidden in status reporting.
438.20 Corrective Action and Renewal Records. GCRI Canada shall maintain corrective action and renewal records, including corrective action plan purpose records, trigger records, owner records, deadline records, evidence records, renewal action purpose records, policy update records, method update records, technical asset update records, data / AI / cyber control update records, public authority protocol update records, publication and claims update records, safeguards update records, committee / council / working group / competence cell update records, training update records, records and register update records, public material update records, verification records, escalation for non-completion records, residual risk records, Board review records where applicable, closeouts, and archives.
Last updated
Was this helpful?