ARTICLE XX. CONTINUITY
Section 452. Amendment Authority
452.1 Amendment Authority. The authority to amend this Bylaw shall exist only as provided by applicable Canadian law, the Articles, this Bylaw, any required member approval where applicable, and competent corporate records of GCRI Canada. Amendment authority shall be exercised as a formal act of governance and shall not be implied from practice, urgency, funding need, program convenience, public authority participation, sponsor support, provider participation, technical release, federation instrument, external doctrine, Nexus-compatible terminology, or operational precedent. Every amendment shall preserve the legal identity of GCRI Canada as a Canadian public-benefit, nonprofit, non-share, non-distributing, non-executing, upstream technical institution unless a lawful and express amendment validly provides otherwise.
452.2 Board Authority to Amend Where Permitted by Law. The Board may amend, repeal, replace, restate, suspend, or adopt provisions of this Bylaw to the extent permitted by applicable law, the Articles, and this Bylaw. Board amendment authority includes authority to approve amendments required for corporate governance, legal compliance, public-benefit mission fidelity, records discipline, Nexus role separation, non-execution, data / AI / cyber controls, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, safeguards, correctionability, and institutional continuity, subject to any member approval, special resolution, filing, confirmation, or other requirement imposed by law or the Articles. The Board shall not use amendment authority to evade required approvals, impair statutory rights, validate prohibited conduct retroactively where law does not permit, or conceal material governance change.
452.3 Member Approval Where Required by Law, Articles, or This Bylaw. Where applicable law, the Articles, or this Bylaw requires approval by members, voting members, a class or category of members, or another statutory approval body, no amendment requiring such approval shall become effective until the required approval has been properly obtained and recorded. Member approval requirements shall be identified before adoption or implementation of any affected amendment. The Board may approve an amendment subject to required member approval where law permits, but such conditional approval shall not be represented as final effectiveness unless and until the required member approval has occurred.
452.4 Special Resolution Where Required. Where applicable law, the Articles, this Bylaw, or a lawful governance instrument requires a special resolution for an amendment, the amendment shall be approved only by the threshold, notice, quorum, class approval, written resolution procedure, meeting procedure, filing, or confirmation process required for such special resolution. No ordinary resolution, officer approval, committee approval, advisory recommendation, consent indication, public authority concurrence, sponsor support, donor approval, provider endorsement, or operational necessity shall substitute for a required special resolution. The special resolution record shall include the text approved, voting threshold, approval date, effective date, and any conditions.
452.5 No Amendment by Officer Alone. No officer of GCRI Canada, acting alone or jointly with another officer, shall amend this Bylaw unless expressly authorized by applicable law, the Articles, this Bylaw, and a competent Board or member approval record for a strictly limited ministerial act, such as filing, certification, formatting, compilation, or publication of an amendment already lawfully adopted. Officer authority may support drafting, intake, legal review, records management, notice, filing, and implementation, but shall not create substantive amendment authority. Any officer act purporting to amend this Bylaw without required authority shall be void or ineffective to the fullest extent permitted by law and shall be corrected.
452.6 No Amendment by Committee Alone. No Board committee, standing committee, special committee, governance committee, legal committee, audit committee, risk committee, technical committee, advisory committee, council, review panel, working party, competence cell, emergency team, controlled-room group, or other committee-like body shall amend this Bylaw by its own act unless applicable law and the Board have expressly delegated a narrow authority that is legally capable of delegation and does not require Board or member approval. Committees may review, recommend, draft, classify, assess, consult, and monitor amendments, but committee action shall not equal adoption unless the required adoption authority is separately recorded.
452.7 No Amendment by Leadership Council, Helix Council, Advisory Body, Working Group, Fellow, Advisor, Sponsor, Donor, Provider, Host, Public Authority Participant, Partner, National Company, Project SPV, or Nexus Interface Alone. No Leadership Council, Helix Council, advisory body, working group, expert panel, peer review board, model review panel, fellow, advisor, researcher, staff member, contractor, volunteer, technical contributor, developer, maintainer, sponsor, donor, funder, provider, host, public authority participant, university, laboratory, community participant, partner, National Consortium Company, Project SPV, consortium, GCRI US interface, GRF interface, GRA interface, Nexus Standards interface, Nexus Network interface, Nexus Observatory interface, Nexus Universe interface, Nexus Rails interface, Nexus Grid interface, Nexus Academy interface, Nexus Competence Cell, or other Nexus interface shall amend this Bylaw by participation, recommendation, approval, funding, technical contribution, public authority presence, public statement, implementation practice, or interface record. External input may inform an amendment, but adoption shall remain with the lawful authority of GCRI Canada.
452.8 No Implied Amendment by Practice, Custom, Funding Agreement, Program Operation, Public Statement, Technical Release, or External Instrument. No practice, custom, repeated conduct, informal understanding, funding agreement, grant condition, donor restriction, sponsorship arrangement, provider agreement, host agreement, partner agreement, program operation, Academy practice, fellowship practice, competence cell practice, public authority engagement, public statement, website language, deck, report, dashboard, map, dataset, software release, repository commit, technical baseline, public-good asset, compatibility note, divergence log, federation instrument, MOU, interface agreement, authorization pack, external doctrine, or Nexus-compatible instrument shall amend this Bylaw by implication. If an external instrument conflicts with this Bylaw, the conflict shall be handled through amendment, waiver where lawful, correction, renegotiation, limitation, or rejection, and not through silent override.
452.9 Amendment Consistent With Applicable Canadian Law. Every amendment shall be interpreted and adopted consistently with applicable Canadian law, including corporate law, nonprofit law, tax law, privacy law, employment and contractor law, human rights and accessibility obligations, sanctions and export-control requirements, competition and procurement-neutrality constraints, research ethics obligations where applicable, public-sector data restrictions where applicable, Indigenous rights and protected knowledge safeguards where applicable, and other legal obligations relevant to GCRI Canada. An amendment that would cause GCRI Canada to act unlawfully, abandon required corporate formality, misstate its legal status, create improper private benefit, breach data or public authority obligations, or enter regulated activity without lawful authority shall not be adopted.
452.10 Amendment Consistent With Articles and Constituting Instruments. Every amendment shall be consistent with the Articles, letters patent, certificate, bylaws, special resolutions, member approvals where applicable, Board resolutions, registered office records, corporate filings, and other constituting instruments of GCRI Canada. No amendment shall contradict, supersede, or impair a higher-ranking constituting instrument unless the higher-ranking instrument is itself lawfully amended through the required process. Where inconsistency is identified, the amendment shall be revised, deferred, conditioned, or accompanied by the required higher-order corporate action.
452.11 Amendment Record Requirement. No amendment shall be validly implemented unless supported by an amendment record sufficient to evidence authority, text, classification, process, approvals, thresholds, effective date, transition rules, and records update. The amendment record shall include, as applicable, proposed text, prior text, redline, rationale, change class, legal review, impact assessment, consultation record, Board materials, Board resolution, member approval record where required, special resolution where required, filing record where required, effective date, version number, publication record, notice record, transition plan, supersession record, archival record, and correction path. Amendment records shall preserve validity-by-record and shall be retained as permanent corporate records unless law permits otherwise and the Board approves a different retention period.
452.12 Amendment Authority Records. GCRI Canada shall maintain amendment authority records, including amendment authority records, Board authority records, member approval requirement records, special resolution records, officer non-amendment records, committee non-amendment records, external participant and Nexus interface non-amendment records, no-implied-amendment records, Canadian-law consistency records, Articles and constituting instrument consistency records, amendment records, version records, filings, notices, transition records, supersession records, correction records, closeouts, and archives.
Section 453. Change Control Principles
453.1 Change Control Purpose. GCRI Canada shall maintain change control principles to ensure that amendments, restatements, schedules, annexes, policies, protocols, controlled vocabularies, technical baselines, federation instruments, authorization packs, public-safe language, program charters, and related governance materials are changed only through disciplined, recorded, reviewable, lawful, public-benefit aligned, and correctionable processes. Change control shall protect mission lock, non-execution, Nexus role separation, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, provider neutrality, sponsor non-control, data / AI / cyber integrity, safeguards, and validity-by-record.
453.2 Record-Based Change. Every material change shall be based on records. A record-based change shall identify the text or instrument being changed, the authority for change, the person or body initiating the change, the rationale, the proposed language, the review path, the approval threshold, the effective date, affected instruments, affected records, affected public materials, transition needs, and correction needs. GCRI Canada shall not rely on oral understandings, informal drafts, unapproved markups, meeting recollections, side letters, public statements, or technical practices as substitutes for recorded change.
453.3 No Silent Change. No amendment, restatement, interpretation, schedule update, annex update, policy update, protocol update, public authority language update, finance-boundary language update, technical baseline update, ontology update, controlled vocabulary update, federation instrument update, or authorization pack update shall be made silently where the change affects authority, rights, duties, classifications, boundaries, records, public-safe status, public claims, public authority references, sponsor or provider benefits, data / AI / cyber controls, safeguards, or correction paths. Silent change undermines validity-by-record and is prohibited for material matters.
453.4 No Hidden Parallel Governance Text. GCRI Canada shall not maintain hidden parallel governance text, shadow bylaws, unofficial constitutions, undisclosed operating charters, informal authority matrices, sponsor-side governance terms, provider-side governance terms, public authority-side understandings, unapproved Nexus interface rules, or private control documents that modify, contradict, or override this Bylaw without lawful adoption. Drafting materials, controlled annexes, legal advice, and confidential implementation notes may exist, but they shall not function as undisclosed amendments or parallel governance unless properly authorized and harmonized.
453.5 No Informal Override. No officer instruction, staff practice, committee habit, council recommendation, emergency convenience, program precedent, public authority preference, sponsor pressure, donor restriction, funder timeline, provider request, host requirement, partner expectation, technical deployment, repository release, dashboard launch, map launch, Academy practice, fellowship practice, or controlled-room convention shall override this Bylaw or a lawful policy adopted under it. Where operational practice diverges from governing text, the practice shall be corrected, documented as divergence where lawful, or brought forward for formal amendment.
453.6 No Sponsor-Driven Change Without Board Review. No sponsor-driven change to this Bylaw, mission language, public authority language, finance-boundary language, certification-boundary language, procurement-neutrality language, research agenda, evidence methods, public-safe publication rules, technical baselines, sponsor benefit schedules, public claims, or federation interface terms shall be adopted without Board review or other competent authority review proportionate to risk. Sponsor support shall remain support-without-control. Any proposed change connected to sponsorship shall be reviewed for private benefit, capture, public authority access purchase, finance-readiness influence, procurement advantage, certification influence, recognition influence, and correction resistance.
453.7 No Provider-Driven Change Without Board Review. No provider-driven change to technical baselines, interoperability profiles, public-good software, open-source rules, benchmarks, challenge rules, Academy materials, public authority learning materials, public-safe publications, procurement-neutrality terms, certification-boundary language, provider participation rules, or public claims shall be adopted without Board review, committee review, technical review, conflict review, and provider-neutrality review proportionate to risk. Provider participation shall not control GCRI Canada’s evidence, methods, technical baselines, publication language, public authority access, or correction decisions.
453.8 No Funding-Driven Change That Weakens Public-Benefit Purpose. GCRI Canada shall not adopt any funding-driven amendment, policy change, program change, public language change, technical release, donor restriction, grant condition, sponsorship benefit, subscription term, or cost-recovery arrangement that weakens public-benefit purpose, nonprofit posture, non-distribution, mission lock, research integrity, evidence integrity, safeguards, public-safe publication, role separation, non-execution, provider neutrality, or correctionability. Funding needs shall not justify private control, pay-to-play, outcome purchase, public authority overclaim, finance-boundary drift, procurement steering, certification overclaim, or recognition overclaim.
453.9 No Operational Convenience Change That Weakens Records Discipline. Operational convenience shall not justify changes that weaken notice, minutes, resolutions, approvals, version control, access records, public authority capacity records, data classification, AI-use records, cyber records, research records, publication records, correction records, conflict records, recusal records, training records, technical asset registers, interface records, or archival discipline. GCRI Canada may simplify processes where lawful and risk-appropriate, but simplification shall remain record-supported, reviewable, and correctionable.
453.10 No Emergency Change That Becomes Permanent Without Review. Emergency changes, temporary holds, interim delegations, emergency communications language, access restrictions, repository freezes, dashboard suspensions, public authority clarifications, public-safe publication holds, data quarantines, AI tool suspensions, controlled-room defaults, or emergency governance measures shall not become permanent without review, ratification, classification, amendment where required, transition planning, and records. Emergency measures shall sunset, be converted into ordinary governance through competent authority, or be terminated. Emergency practice shall not become hidden permanent law.
453.11 No Localization Change That Fragments Core Meaning. Localization shall not fragment the core meaning of GCRI Canada’s public-benefit purpose, non-execution boundary, role separation, public authority capacity terms, finance-boundary terms, certification terms, procurement-neutrality terms, recognition terms, safeguards terms, public-safe publication terms, evidence terms, methods terms, observability terms, ontology terms, Grid terms, Rails terms, Academy terms, competence terms, node terms, chapter terms, host terms, provider terms, sponsor terms, or correction terms. Localization may adapt form, language, examples, and legal references, but material divergence shall be recorded in compatibility notes and divergence logs.
453.12 No Technical Change That Alters Legal Authority Without Governance Approval. No technical change, including software release, repository change, API change, schema change, ontology change, dashboard change, map change, model change, AI agent change, automation change, technical baseline update, access control change, identity object change, role object change, signature process change, hash process change, or evidence artifact change, shall alter legal authority, governance rights, public authority capacity, finance-readiness status, certification status, procurement status, recognition status, maturity status, public-safe classification, data rights, IP rights, or access rights without appropriate governance approval and records.
453.13 No Terminology Change That Creates Semantic Drift. No terminology change shall create semantic drift, ambiguity, inflated authority, market implication, public authority implication, finance implication, certification implication, procurement implication, recognition implication, maturity implication, provider preference, sponsor control implication, or public warning implication. Changes to defined terms, controlled vocabulary, ontology, schemas, public language, public authority capacity terms, finance-boundary terms, or Nexus-compatible terms shall be reviewed for semantic integrity and downstream effects before adoption.
453.14 Public-Good Continuity. Change control shall preserve public-good continuity. Amendments and updates shall not undermine GCRI Canada’s stewardship of research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, public authority learning, Academy support, safeguards, technical literacy, and correctionability. Where a change retires or restricts a public-good asset, method, program, or publication, the reason, public-safe status, transition, replacement, archive, and correction path shall be recorded.
453.15 Mission Lock Continuity. Change control shall preserve mission lock. Any proposed change affecting GCRI Canada’s purpose, nonprofit posture, non-share status, non-distribution, public-benefit orientation, public-good technical institution character, governance authority, role separation, non-execution, anti-capture, or public-safe claims discipline shall receive heightened review and shall not be adopted without the required legal, Board, and member approvals where applicable. Mission lock shall not be diluted by language modernization, funding convenience, or federation alignment.
453.16 Non-Execution Continuity. Change control shall preserve non-execution continuity. No amendment or update shall quietly convert GCRI Canada into an operator, implementer, public infrastructure manager, emergency command body, public warning authority, procurement agent, finance arranger, insurer, lender, underwriter, broker, provider selector, National Consortium Company, Project SPV, public authority, certification body, recognition body, or regulated professional services provider. Any lawful expansion of function shall require explicit text, legal review, Board approval, required member approval where applicable, boundary controls, and transition records.
453.17 Role-Separation Continuity. Change control shall preserve role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, donors, hosts, public authorities, universities, laboratories, communities, and partners. Changes shall not collapse roles, transfer reserved functions, create shared liability, imply merger, or allow one actor to substitute for another.
453.18 Correctionability Continuity. Change control shall preserve correctionability. Amendments and updates shall include correction paths, supersession rules, archive status, affected records review, public material updates, downstream dependency review, and mechanisms to correct errors discovered after adoption. No change shall prevent correction, suppress correction records, erase superseded text without archive, or prohibit public-safe clarification where required. Correctionability shall remain a permanent governance principle.
453.19 Change Control Records. GCRI Canada shall maintain change control records, including change control purpose records, record-based change records, no-silent-change records, no-hidden-parallel-governance-text records, no-informal-override records, sponsor-driven change review records, provider-driven change review records, funding-driven change review records, operational convenience review records, emergency change review records, localization change records, technical change governance approval records, terminology and semantic drift review records, public-good continuity records, mission lock continuity records, non-execution continuity records, role-separation continuity records, correctionability continuity records, corrective actions, closeouts, and archives.
Section 454. Change Classes: Editorial, Material, Constitutional, Emergency, Localization, Technical, and Policy
454.1 Change Classification Requirement. Every proposed amendment, restatement, schedule update, annex update, policy integration, technical-conformance update, localization update, emergency update, public language update, federation instrument update, authorization pack update, controlled vocabulary update, ontology update, or related governance change shall be classified before adoption. Classification shall identify whether the change is editorial, clerical, formatting, numbering, material, constitutional, mission-lock, public-benefit purpose, non-execution boundary, role-separation, governance-authority, emergency, localization, technical-conformance, policy-integration, schedule, annex, or another appropriate class. Classification shall determine review intensity, approval threshold, consultation need, legal review, effective date, transition plan, and records.
454.2 Editorial Change. An editorial change is a change that improves clarity, grammar, syntax, readability, cross-reference style, defined-term consistency, capitalization, punctuation, or non-substantive drafting quality without altering legal meaning, authority, rights, duties, boundaries, approvals, classifications, records, public-safe status, public authority capacity, finance-boundary posture, certification boundary, procurement neutrality, recognition boundary, safeguards, data / AI / cyber controls, or correction paths. Editorial changes may be approved through a simplified process if permitted by policy and law, but shall remain recorded and versioned.
454.3 Clerical Change. A clerical change corrects typographical errors, obvious transcription errors, broken cross-references, duplicated words, missing punctuation, formatting artifacts, document-control errors, or similar non-substantive mistakes. A clerical change shall not be used to alter substance. Where a purported clerical change could affect meaning, obligation, authority, threshold, date, role, classification, or boundary, it shall be classified as more restrictive than clerical and reviewed accordingly.
454.4 Formatting Change. A formatting change adjusts layout, heading style, bolding, indentation, spacing, tables, numbering display, pagination, document-control presentation, annex organization, or publication formatting without changing text meaning. Formatting changes shall preserve section numbers, cross-references, version history, public-safe status, and archive integrity. Formatting shall not be used to hide deletions, demote limitations, obscure disclaimers, weaken boundary language, or make substantive terms less visible.
454.5 Numbering Change. A numbering change renumbers sections, subsections, schedules, annexes, tables, cross-references, definitions, or internal references without changing substantive meaning. Numbering changes shall include cross-reference review and a mapping table where material. Renumbering shall not be used to remove provisions, alter hierarchy, change precedence, or conceal amendment history. Where renumbering affects interpretation or legal references, it shall receive legal or governance review.
454.6 Material Change. A material change is any change that affects legal meaning, rights, duties, governance authority, approval thresholds, membership rights where applicable, Board powers, officer powers, committee powers, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, non-execution, data / AI / cyber controls, safeguards, public-safe publication rules, technical asset governance, federation interfaces, records requirements, correction paths, or institutional risk. Material changes shall receive legal, governance, and impact review proportionate to risk and shall be adopted only by the required authority.
454.7 Constitutional Change. A constitutional change is a change affecting the fundamental structure, legal character, objects, purposes, Articles, membership structure, Board authority, director duties, nonprofit posture, non-share status, non-distribution, public-benefit identity, dissolution provisions, amendment authority, mission lock, or other constituting features of GCRI Canada. Constitutional changes shall receive heightened legal review, Board review, member approval where required, special resolution where required, and filing where required. Constitutional changes shall not be adopted by implication, urgency, practice, funding agreement, or external instrument.
454.8 Mission-Lock Change. A mission-lock change is any change that could alter, weaken, expand, narrow, reframe, qualify, suspend, or reinterpret GCRI Canada’s public-benefit purpose, public-good technical stewardship, upstream role, anti-capture posture, non-distribution, evidence integrity, methods integrity, observability role, ontology role, public-good software role, technical baseline role, public-safe publication discipline, safeguards, correctionability, or Nexus role separation. Mission-lock changes shall be reviewed conservatively and shall require Board approval and any additional approval required by law, Articles, or this Bylaw.
454.9 Public-Benefit Purpose Change. A public-benefit purpose change is any change to GCRI Canada’s purposes, objects, public-benefit language, eligible activities, prohibited activities, public-good role, mission, scope, beneficiaries, or institutional posture. Such changes shall be assessed for Canadian law, nonprofit posture, tax implications, private benefit risk, donor and grant implications, public authority implications, public claims implications, safeguards, and Nexus compatibility. A public-benefit purpose change shall not be used to convert GCRI Canada into a private-benefit, commercial execution, finance, procurement, certification, recognition, or public authority body.
454.10 Non-Execution Boundary Change. A non-execution boundary change is any change that could alter GCRI Canada’s prohibition or limitation on project execution, infrastructure operation, emergency command, public warning, procurement execution, finance execution, provider selection, regulated professional services, certification, recognition, maturity determination, public authority decision-making, National Consortium Company functions, Project SPV functions, or enterprise-stack control. Such changes require the most restrictive review available under this Bylaw, including legal review, Board review, risk review, public authority boundary review, finance-boundary review, and member approval where required.
454.11 Role-Separation Change. A role-separation change is any change affecting the relationship among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, donors, hosts, public authorities, universities, laboratories, communities, and partners. Such changes shall be reviewed for merger implication, shared liability, shared treasury, public authority delegation, finance-boundary drift, certification overclaim, procurement steering, recognition overclaim, provider preference, sponsor control, and public-safe language.
454.12 Governance-Authority Change. A governance-authority change is any change affecting who may decide, approve, amend, delegate, bind, represent, sign, appoint, remove, admit, suspend, terminate, certify, recognize, publish, access records, control repositories, control data, control AI tools, control technical assets, control public authority interfaces, or control finance-sensitive materials. Governance-authority changes shall be reviewed for lawfulness, conflicts, fiduciary duties, records, access controls, cybersecurity, public authority boundaries, finance boundaries, safeguards, anti-capture, and correctionability.
454.13 Emergency Change. An emergency change is a temporary change adopted to address urgent risk under Emergency Governance Mode or comparable authority. Emergency changes shall be narrowly tailored, time-limited, recorded, ratified where required, and sunset or converted into ordinary governance through proper process. Emergency changes shall not alter mission lock, non-execution, role separation, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, member rights where applicable, or constitutional structure permanently unless adopted through the required non-emergency process.
454.14 Localization Change. A localization change adapts text, methods, protocols, public authority language, safeguards, data controls, Academy materials, technical baselines, federation instruments, or public-safe publication practices to Canadian, provincial, territorial, Indigenous, community, regional, national, sectoral, legal, linguistic, cultural, public authority, or operational context. Localization changes shall preserve core meaning and shall not fragment definitions, weaken mission, weaken non-execution, weaken role separation, reduce safeguards, create public authority overclaim, create finance-readiness implication, or create local shadow governance. Material localization shall be documented through compatibility notes and divergence logs.
454.15 Technical-Conformance Change. A technical-conformance change updates schemas, APIs, software, repository rules, metadata, ontology files, controlled vocabularies, identity objects, role objects, dashboards, maps, technical baselines, model cards, system cards, benchmark cards, test harnesses, signatures, hashes, provenance methods, or auditability mechanisms to conform to approved technical requirements. Technical-conformance changes shall be reviewed for legal authority, data rights, IP, cybersecurity, privacy, export controls, public authority terms, protected knowledge, public-safe status, and whether the change alters substantive governance meaning.
454.16 Policy-Integration Change. A policy-integration change integrates Board-approved policies, procedures, protocols, operating rules, codes, schedules, annexes, public authority protocols, data / AI / cyber controls, research integrity procedures, safeguards procedures, publication procedures, sponsor rules, provider rules, or federation instruments into this Bylaw or its implementation architecture. Policy integration shall identify precedence, scope, conflicts, effective date, superseded instruments, affected training, affected records, and whether the integrated policy changes legal meaning or merely operationalizes existing authority.
454.17 Schedule or Annex Change. A schedule or annex change modifies schedules, annexes, controlled annexes, public annexes, technical annexes, policy annexes, definitions annexes, authorization pack templates, public language packs, brand packs, data-sharing templates, model-sharing templates, evidence-sharing templates, or other appendices. Schedule or annex changes shall be classified according to substance. A schedule or annex change that affects rights, duties, authority, boundaries, data controls, public authority language, finance language, certification language, procurement language, safeguards, or correction shall not be treated as merely administrative.
454.18 More Restrictive Classification Where Doubt Exists. Where reasonable doubt exists regarding change classification, GCRI Canada shall apply the more restrictive classification and corresponding review and approval process. Doubt shall be resolved in favor of legal compliance, Board oversight, member approval where required, public-benefit purpose, mission lock, non-execution, role separation, public authority boundary discipline, finance-boundary discipline, provider neutrality, safeguards, data / AI / cyber integrity, and correctionability. Classification uncertainty shall be recorded rather than hidden.
454.19 Change Classification Records. GCRI Canada shall maintain change classification records, including classification requirement records, editorial change records, clerical change records, formatting change records, numbering change records, material change records, constitutional change records, mission-lock change records, public-benefit purpose change records, non-execution boundary change records, role-separation change records, governance-authority change records, emergency change records, localization change records, technical-conformance change records, policy-integration change records, schedule or annex change records, more-restrictive-classification records, reviewer records, approval records, corrections, closeouts, and archives.
Section 455. Amendment Initiation, Intake, Impact Assessment, Consultation, Drafting Discipline, Version Control, Adoption Thresholds, Effective Dates, and Transition Plans
455.1 Amendment Initiation. An amendment may be initiated only through an authorized amendment initiation process. Initiation shall identify the need for amendment, the affected provisions, the proposed change class, the proponent, the rationale, the risks addressed, the risks created, the intended effect, the affected records, the affected public materials, the required review path, and any urgency. Initiation shall not itself constitute adoption or authorization to implement the proposed change.
455.2 Authorized Proponents. Authorized proponents may include the Board, Board Chair, Board committee, officer, governance lead, legal lead, compliance lead, data / AI / cyber lead, safeguards lead, research integrity lead, publication lead, technical asset steward, public authority interface owner, or another person or body authorized by the Board or this Bylaw to propose amendments. External actors, including sponsors, donors, providers, hosts, public authorities, partners, consortiums, National Consortium Companies, Project SPVs, GCRI US, GRF, GRA, or other Nexus interfaces, may suggest or request consideration of amendments, but shall not become adoption authorities by proposing text.
455.3 Amendment Intake. Amendment intake shall capture the proposed amendment, affected sections, proponent, date, urgency, change class, rationale, legal issues, governance issues, public-benefit issues, role-separation issues, non-execution issues, public authority issues, finance / certification / procurement / recognition / public warning boundary issues, data / AI / cyber / privacy issues, research integrity issues, safeguards issues, sponsor or provider issues, transition needs, and records affected. Intake may reject, defer, consolidate, return for revision, or route a proposal based on authority, completeness, risk, duplication, or incompatibility.
455.4 Case ID Requirement. Each material amendment proposal shall receive a case identifier sufficient to track intake, review, drafts, redlines, consultations, legal advice, impact assessments, Board materials, member materials where applicable, approvals, filings, effective dates, transition actions, records updates, public material updates, and closeout. Case IDs shall preserve traceability across versions and shall be used in amendment records, change logs, and archives. Minor clerical or formatting changes may be grouped under a batch case ID where permitted.
455.5 Proposed Text Requirement. A material amendment proposal shall include proposed text or a clear instruction for preparing proposed text. The text shall be drafted in final-form bylaw language or accompanied by sufficient instructions for final-form drafting. Proposed text shall identify insertions, deletions, replacements, renumbering, definitions affected, cross-references affected, schedules or annexes affected, and transition provisions. Concepts, comments, emails, meeting notes, funding terms, or technical tickets shall not substitute for proposed bylaw text where formal amendment is required.
455.6 Rationale Requirement. A material amendment proposal shall include a rationale explaining the problem, opportunity, legal requirement, governance need, risk, correction, localization need, technical-conformance need, emergency need, policy-integration need, public authority need, safeguards need, or public-benefit basis for the amendment. The rationale shall identify why existing text is insufficient, what the amendment is intended to accomplish, what risks it mitigates, what risks it creates, and whether non-amendment alternatives were considered. Rationale shall not rely solely on sponsor preference, provider convenience, funding pressure, reputational pressure, or operational speed.
455.7 Impact Assessment. A material amendment shall undergo impact assessment proportionate to change class and risk. Impact assessment shall consider legal effect, governance effect, public-benefit effect, mission-lock effect, non-execution effect, role-separation effect, public authority effect, finance-boundary effect, certification-boundary effect, procurement effect, recognition effect, public warning effect, data / AI / cyber effect, privacy effect, research integrity effect, safeguards effect, sponsor / donor / provider / host / partner effect, technical asset effect, records effect, public material effect, training effect, and transition effect.
455.8 Legal Impact Assessment. Legal impact assessment shall assess consistency with applicable Canadian law, corporate law, nonprofit law, tax law, privacy law, employment and contractor law, sanctions and export-control law, competition and procurement neutrality, research ethics, IP, contract law, public authority terms, public-sector obligations, Indigenous rights and protected knowledge where relevant, accessibility and human rights obligations, and any filing or approval requirements. Legal impact assessment shall identify whether member approval, special resolution, external filing, notice, or legal opinion is required.
455.9 Corporate and Tax Impact Assessment. Corporate and tax impact assessment shall assess whether the amendment affects GCRI Canada’s corporate status, nonprofit status, non-share status, non-distribution, member rights where applicable, Board authority, director duties, officer authority, assets, restricted funds, grants, donations, sponsorships, subscriptions, cost recovery, private benefit, related-party transactions, compensation, tax filings, public claims about tax status, or eligibility for funding. Any amendment that risks improper private benefit or tax misdescription shall be revised or rejected unless lawfully resolved.
455.10 Public-Benefit Impact Assessment. Public-benefit impact assessment shall assess whether the amendment advances or weakens GCRI Canada’s public-benefit purpose, public-good technical stewardship, research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, technical literacy, Academy support, public authority learning, safeguards, accessibility, correctionability, and anti-capture. Amendments that convert public-benefit functions into private benefit, provider advantage, sponsor control, or public authority access sale shall not be adopted.
455.11 Nexus Role-Separation Impact Assessment. Nexus role-separation impact assessment shall assess whether the amendment affects GCRI Canada’s relationship with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, donors, hosts, public authorities, universities, laboratories, communities, and partners. The assessment shall identify risks of merger implication, shared liability, shared treasury, substituted authority, recognition overclaim, finance-boundary drift, procurement steering, provider preference, sponsor control, or public authority confusion.
455.12 Non-Execution Impact Assessment. Non-execution impact assessment shall assess whether the amendment could cause or imply project execution, infrastructure operation, emergency command, public warning, public authority decision-making, procurement execution, finance execution, investment advice, insurance placement, underwriting, lending, rating, certification, recognition, maturity determination, provider selection, National Consortium Company function, Project SPV function, or regulated professional service. Any amendment that expands execution must be explicit, lawful, Board-approved, subject to required member approval where applicable, and accompanied by boundary controls.
455.13 Public Authority Boundary Impact Assessment. Public authority boundary impact assessment shall assess whether the amendment affects public authority participation, capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management participation, public infrastructure operator participation, public authority data contribution, public authority references, logos, quotes, attendance, public authority learning, public warning boundaries, emergency command boundaries, no-delegation rules, no-PPP rules, procurement boundaries, funding boundaries, regulatory boundaries, public finance boundaries, sovereign obligation language, or public authority adoption language.
455.14 Finance, Certification, Procurement, Recognition, and Public Warning Boundary Impact Assessment. This boundary impact assessment shall evaluate whether the amendment affects finance-readiness, insurance-readiness, investment advice, securities solicitation, capital placement, underwriting, lending, rating, public finance approval, bankability, investability, procurement approval, vendor selection, certification, accreditation, compliance approval, conformance approval, recognition, standing, maturity, Grid status, Docket status, public warning, emergency command, or official determination. Amendments shall include non-reliance, boundary language, and authority controls where needed.
455.15 Data / AI / Cyber / Privacy Impact Assessment. Data / AI / cyber / privacy impact assessment shall assess whether the amendment affects lawful basis, purpose limitation, minimization, classification, access controls, retention, deletion, cross-border transfers, data localization, public authority data, protected knowledge, Indigenous / local / territorial knowledge, AI-use authorization, model training, embeddings, retrieval, agentic AI, human review, cybersecurity baseline, repository security, incident response, vendor risk, privacy rights, public-safe publication, and records. Amendments shall not weaken data / AI / cyber discipline for convenience.
455.16 Research Integrity Impact Assessment. Research integrity impact assessment shall assess whether the amendment affects research independence, agenda setting, research ethics, human-subjects review, public authority data, community research, Indigenous rights, protected knowledge, sponsor and provider influence, conflicts, peer review, reproducibility, replication, AI-use disclosure, publication review, correction, withdrawal, retraction, authorship, attribution, or misconduct processes. Amendments shall preserve research integrity and shall not grant sponsors, providers, donors, funders, or public authority participants control over conclusions.
455.17 Community Safeguards and Protected Knowledge Impact Assessment. Community safeguards and protected knowledge impact assessment shall assess whether the amendment affects Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, consent, non-consent, FPIC where applicable, withdrawal, attribution, non-attribution, public-safe mapping, accessibility, grievance, remedy, vulnerable communities, remote communities, protected participation, whistleblowing, dissent, anti-retaliation, and do-no-harm. Amendments shall not weaken safeguards or convert protected knowledge into uncontrolled data.
455.18 Sponsor, Donor, Provider, Host, Partner, National Company, and Project SPV Capture Impact Assessment. Capture impact assessment shall assess whether the amendment creates or increases sponsor control, donor control, funder control, provider preference, host pressure, partner authority inflation, National Consortium Company influence, Project SPV influence, public authority access purchase, pay-to-play, outcome purchase, finance-boundary drift, procurement advantage, certification influence, recognition influence, research influence, publication suppression, or correction resistance. Amendments creating capture risk shall be rejected, revised, conditioned, or escalated to the Board.
455.19 Consultation Where Appropriate. Consultation may be conducted where appropriate with directors, officers, members where applicable, committees, councils, advisors, staff, contractors, fellows, technical contributors, legal counsel, data / AI / cyber leads, safeguards leads, public authority interface owners, affected public authorities, communities, Indigenous or local knowledge holders where appropriate, sponsors, providers, hosts, partners, GCRI US, GRF, GRA, Nexus Standards, or other relevant interfaces. Consultation shall inform but not displace lawful amendment authority. Consultation records shall distinguish comments received from decisions adopted.
455.20 Drafting Discipline. Amendment drafting shall use precise, final-form bylaw prose, consistent defined terms, controlled vocabulary, correct cross-references, clear hierarchy, boundary language, public-safe terminology, and records discipline. Drafting shall avoid ambiguity, marketable overclaim, public authority implication, finance implication, certification implication, procurement implication, recognition implication, maturity implication, public warning implication, emergency command implication, provider preference, sponsor control implication, and semantic drift. Drafting shall preserve the adopted formatting discipline of this Bylaw unless the Board approves a formatting update.
455.21 Redline Requirement. Material amendments shall include a redline or comparable comparison showing additions, deletions, replacements, renumbering, and affected cross-references unless the Board determines that a clean restatement is more practical and a change memorandum provides equivalent traceability. The redline shall be retained with amendment records. Where controlled annexes or sensitive materials are involved, redlines may be access-controlled, but traceability shall be preserved.
455.22 Version Control. Every amendment shall be subject to version control. Version control shall identify draft number, date, author or drafter, reviewer, change class, approval status, superseded draft, adopted version, effective date, publication status, archive status, and affected instruments. Drafts shall be marked as drafts and shall not be treated as adopted text. Superseded versions shall be archived unless deletion or restriction is required by law, privilege, confidentiality, protected knowledge, security, or public authority terms.
455.23 Adoption Threshold Identification. Before adoption, GCRI Canada shall identify the adoption threshold required for the amendment, including Board approval, committee recommendation, member approval where required, special resolution where required, class approval where required, filing where required, notice where required, public authority approval where required by contract or law, or other condition. Threshold identification shall be recorded and reviewed where uncertainty exists. The most restrictive plausible threshold shall be used where doubt remains and legal review is unavailable.
455.24 Effective Date. Each amendment shall specify an effective date or method for determining effectiveness. An amendment may be effective immediately upon required approval, on a future date, upon filing, upon member approval, upon satisfaction of a condition, upon publication, upon notice, or upon another lawful trigger. The effective date shall distinguish adoption from implementation and shall identify whether transitional rules apply. No amendment requiring approval or filing shall be treated as effective before the required condition is satisfied.
455.25 Transition Plan. A material amendment shall include a transition plan where necessary. The transition plan may address affected policies, programs, committees, councils, membership rights where applicable, contracts, public authority records, data / AI / cyber controls, technical assets, public materials, Academy materials, training, sponsor benefits, provider terms, host arrangements, federation instruments, authorization packs, compatibility notes, divergence logs, records, registers, effective dates, legacy materials, and correction needs. Transition plans shall prevent stale or superseded language from continuing to operate.
455.26 Amendment Closeout. Amendment closeout shall confirm that the adopted text has been integrated into the official Bylaw, version records have been updated, superseded versions have been archived, required filings have been completed, notices have been issued where required, affected policies have been updated, public materials have been updated where needed, training has been revised where needed, records and registers have been updated, compatibility notes and divergence logs have been revised where needed, and unresolved transition actions have owners and deadlines. Closeout shall be recorded.
455.27 Amendment Initiation and Adoption Records. GCRI Canada shall maintain amendment initiation and adoption records, including initiation records, authorized proponent records, intake records, case ID records, proposed text records, rationale records, impact assessment records, legal impact assessment records, corporate and tax impact assessment records, public-benefit impact assessment records, Nexus role-separation impact assessment records, non-execution impact assessment records, public authority boundary impact assessment records, finance / certification / procurement / recognition / public warning boundary impact assessment records, data / AI / cyber / privacy impact assessment records, research integrity impact assessment records, community safeguards and protected knowledge impact assessment records, capture impact assessment records, consultation records, drafting discipline records, redlines, version control records, adoption threshold records, effective date records, transition plans, closeout records, and archives.
Section 456. Member Approval Where Required by Law
456.1 Member Approval Purpose. Where GCRI Canada has statutory members, voting members, classes of members, or any other member approval structure recognized by applicable law, the Articles, or this Bylaw, member approval shall be obtained for amendments requiring such approval. Member approval protects statutory rights, corporate validity, transparency, mission lock, constitutional integrity, and lawful governance. It shall not be treated as optional, ceremonial, or replaceable by Board preference, officer action, committee recommendation, sponsor support, public authority presence, provider input, operational urgency, federation alignment, or public statement.
456.2 Identification of Member Approval Requirement. Before adopting or implementing any amendment, GCRI Canada shall identify whether member approval is required by applicable law, the Articles, this Bylaw, a prior member resolution, a special resolution requirement, a class approval rule, or another lawful instrument. Identification shall consider whether the amendment affects purposes, objects, Articles, membership rights, voting rights, director election or removal rights, dissolution provisions, distribution or non-distribution provisions, bylaw amendment authority, member classes, special rights, or other matters reserved to members. Uncertainty shall be resolved through legal review or more restrictive approval.
456.3 Notice to Members Where Applicable. Where member approval is required or sought, GCRI Canada shall provide notice to members in the manner and time required by applicable law, the Articles, this Bylaw, and Board-approved procedures. Notice shall identify the meeting or written resolution process, proposed amendment, affected provisions, approval threshold, special resolution requirement where any, class approval requirement where any, effective date, explanatory materials, voting method, quorum requirement, and member rights. Notice shall be accurate and shall not omit material risks or required approvals.
456.4 Text Circulation. The text of the proposed amendment shall be circulated to members where required or appropriate. Text circulation shall include the proposed final text and, where useful or required, a redline, summary of changes, affected cross-references, transition provisions, and effective date. Members shall not be asked to approve vague concepts, undisclosed text, oral descriptions, or materially incomplete drafting where formal approval of bylaw text is required. If the text changes materially after circulation, further notice or recirculation shall be provided where required.
456.5 Explanatory Materials. Explanatory materials may be provided to members to support informed approval. Such materials may include rationale, change classification, legal impact, public-benefit impact, mission-lock impact, non-execution impact, role-separation impact, public authority boundary impact, finance / certification / procurement / recognition / public warning boundary impact, data / AI / cyber / privacy impact, safeguards impact, capture impact, Board recommendation, dissent or minority note where permitted, transition plan, and effective date. Explanatory materials shall be accurate, balanced, limitation-bearing, and not misleading.
456.6 Member Meeting or Written Resolution Where Permitted. Member approval may be sought at a member meeting or by written resolution where permitted by applicable law, the Articles, and this Bylaw. The chosen process shall comply with notice, quorum, voting, signature, electronic participation, written resolution, record, and filing requirements. Written resolutions shall identify the exact text approved and shall satisfy any unanimity, threshold, or procedural requirement imposed by law. Member meetings shall preserve minutes, attendance, quorum, voting, conflicts where applicable, and decision records.
456.7 Quorum. Where member approval is sought at a meeting, quorum shall be determined according to applicable law, the Articles, this Bylaw, and any applicable member class rules. No amendment requiring member approval shall be approved at a meeting lacking quorum. Quorum records shall identify members present, represented, or otherwise participating, voting members entitled to vote, class or category quorum where applicable, abstentions where relevant, and any challenges to quorum. Defective quorum shall trigger correction, adjournment, reconvening, or legal review.
456.8 Voting Threshold. The voting threshold required for member approval shall be identified before the vote and applied precisely. Thresholds may include ordinary resolution, special resolution, two-thirds approval, majority of votes cast, majority of members, class approval, unanimous written resolution, or another legally required threshold. Votes shall be counted according to law, the Articles, this Bylaw, and member rights. An amendment shall not be treated as approved unless the required threshold is satisfied and recorded.
456.9 Special Resolution Where Required. Where a special resolution is required, GCRI Canada shall comply with the procedural and voting requirements for special resolutions, including text circulation, notice, threshold, written resolution requirements, filing where required, and class approval where applicable. A special resolution shall identify the exact amendment or authorization approved. No Board resolution, ordinary member resolution, advisory vote, consensus indication, sponsor or donor approval, public authority concurrence, or operational practice shall substitute for a required special resolution.
456.10 Class or Category Approval Where Required. Where a class or category of members has separate approval rights, veto rights, voting rights, consent rights, or statutory protection, the required class or category approval shall be obtained before the amendment becomes effective. Class or category approval shall be conducted with appropriate notice, text circulation, quorum, threshold, conflict controls where applicable, and records. No amendment shall impair class or category rights through general approval where separate approval is required.
456.11 Member Conflict Disclosure Where Applicable. Where applicable law, the Articles, this Bylaw, Board policy, or the nature of the amendment requires member conflict disclosure, members shall disclose material conflicts relevant to the amendment. Conflicts may include sponsor interests, provider interests, donor interests, funder interests, host interests, public authority roles, employment, contracts, related-party interests, IP interests, National Consortium Company interests, Project SPV interests, finance interests, procurement interests, certification interests, recognition interests, or personal benefit. Conflict disclosure shall be recorded, and voting or participation restrictions shall be applied where required.
456.12 Member Approval Record. Member approval records shall include notice, text circulated, explanatory materials, meeting or written resolution process, quorum, voting threshold, votes cast, abstentions, class approvals where applicable, conflicts disclosed where applicable, special resolution text where applicable, effective date, filing requirements, conditions, and certification by the appropriate officer or records custodian. Member approval records shall be retained as corporate records and linked to the amendment case ID, official Bylaw version, and transition plan.
456.13 Failure to Obtain Required Approval. If required member approval is not obtained, the amendment shall fail, remain pending, be revised, be withdrawn, be re-noticed, or be returned to the Board for further action, as appropriate. Failure to obtain approval shall be recorded. No officer, committee, program, public statement, funding condition, sponsor request, provider request, public authority request, or Nexus interface shall implement the failed amendment as if approved. If any action was taken in anticipation of approval, GCRI Canada shall review whether reversal, correction, notice, ratification where lawful, or transition action is required.
456.14 No Effect Until Required Approval Is Obtained. An amendment requiring member approval shall have no effect until the required approval, special resolution, class approval, filing, or other condition is obtained, unless applicable law expressly permits conditional or interim effect. Draft text, Board approval subject to member confirmation, committee recommendation, officer circulation, public statement, website posting, external instrument, funding agreement, or operational change shall not make the amendment effective. Any public or internal material suggesting effectiveness before approval shall be corrected.
456.15 Member Approval Records. GCRI Canada shall maintain member approval records, including member approval purpose records, approval requirement identification records, notice records, text circulation records, explanatory materials, member meeting records, written resolution records, quorum records, voting threshold records, special resolution records, class or category approval records, member conflict disclosure records, member approval records, failure-to-obtain-approval records, no-effect-until-required-approval records, filings, certifications, transition records, corrections, closeouts, and archives.
Section 457. Amendment Review for Canadian Law, Public-Benefit Purpose, Nexus Alignment, Non-Execution, Public Authority Boundaries, Finance-Readiness Boundaries, Data / AI / Cyber, Safeguards, Tax Status, and Conflicts
457.1 Mandatory Amendment Review. Every material amendment to this Bylaw, the Articles where related to this Bylaw, any schedule, annex, policy, protocol, federation instrument, authorization pack, public-safe language pack, controlled vocabulary, technical baseline governance instrument, public authority protocol, finance-boundary instrument, safeguards instrument, or other lower-order governance instrument materially affecting this Bylaw shall undergo mandatory amendment review before adoption, implementation, publication, reliance, filing, or circulation as operative text. Mandatory amendment review shall be proportionate to the change class and shall determine whether the proposed amendment is lawful, valid, public-benefit aligned, mission-preserving, non-executing, role-separated, financially clean, public authority-boundary compliant, data / AI / cyber compliant, safeguards-compliant, semantically coherent, correctionable, and compatible with GCRI Canada’s role as a Canadian upstream public-benefit technical institution. No amendment shall be advanced to adoption where a required review identifies unresolved illegality, mission drift, public authority overclaim, finance-boundary breach, certification overclaim, procurement implication, sponsor or provider capture, data misuse, AI misuse, cyber exposure, protected knowledge harm, or unrecorded authority unless the defect is corrected, mitigated, escalated, or expressly rejected by competent authority with reasons.
457.2 Canadian Law Review. Canadian law review shall assess whether the proposed amendment complies with applicable federal, provincial, territorial, municipal, public-sector, corporate, nonprofit, tax, privacy, employment, contractor, human rights, accessibility, sanctions, export-control, competition, procurement-neutrality, IP, research ethics, public authority, Indigenous rights, data governance, cybersecurity, AI governance, and records obligations relevant to GCRI Canada. The review shall identify whether the amendment requires legal advice, statutory filing, member approval, special resolution, class approval, public authority consent, contractual amendment, tax analysis, privacy assessment, research ethics review, public-sector data review, or other legal condition. A proposed amendment shall not be adopted if it would require GCRI Canada to misstate legal status, exercise public authority powers without lawful delegation, undertake regulated activity without lawful authority, compromise statutory duties, weaken mandatory records, or create legal inconsistency with Canadian law.
457.3 Articles and Corporate Status Review. Articles and corporate status review shall determine whether the proposed amendment is consistent with GCRI Canada’s Articles, letters patent, certificate, corporate objects, legal form, registered office records, director and officer structure, member structure where applicable, nonprofit and non-share status, non-distribution provisions, corporate filings, prior special resolutions, and other constituting instruments. Where a proposed amendment affects corporate objects, governance authority, director powers, member rights, dissolution, distribution, corporate status, registered records, or fundamental legal posture, the review shall identify whether amendment to the Articles or another higher-order corporate instrument is required. No bylaw amendment shall be used to accomplish indirectly what requires amendment of the Articles, statutory filing, member approval, special resolution, or another higher-order approval.
457.4 Nonprofit and Tax Status Review. Nonprofit and tax status review shall assess whether the amendment preserves GCRI Canada’s nonprofit, non-share, non-distributing, public-benefit posture and avoids improper private benefit, earnings distribution, disguised compensation, control-for-cash, pay-to-play, provider preference, sponsor control, donor control, related-party benefit, tax misdescription, restricted-fund misuse, or incompatible commercial activity. The review shall consider grants, donations, sponsorships, subscriptions, cost recovery, service fees, in-kind support, compute credits, cloud credits, restricted funds, partner contributions, and any revenue-adjacent activity affected by the amendment. A funding-oriented amendment shall be rejected or revised if it compromises mission lock, public-benefit purpose, nonprofit character, independent governance, research integrity, evidence integrity, public-safe publication, safeguards, correctionability, or the prohibition on private control of GCRI Canada’s public-good functions.
457.5 Charitable Status Review if Applicable. If GCRI Canada is, becomes, applies to become, represents itself as, or is treated in any instrument as a charity or charitable organization, charitable status review shall assess whether the amendment is consistent with charitable purposes, charitable activities, receipting obligations, disbursement rules, fundraising rules, political activity limits where applicable, private benefit restrictions, related business restrictions, grantmaking requirements, direction and control requirements where applicable, and public reporting obligations. If GCRI Canada is not a registered charity, the amendment shall not imply charitable status, charitable receipting, charitable regulatory approval, donor tax credit eligibility, or charitable public authority status. Where charitable status is uncertain, public language shall be conservative and legally reviewed before adoption or publication.
457.6 Public-Benefit Purpose Review. Public-benefit purpose review shall assess whether the amendment advances, preserves, or weakens GCRI Canada’s public-benefit role as an upstream steward of research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, technical literacy, public authority learning support, safeguards, Canadian localization, and correctionability. The review shall reject or revise amendments that convert public-benefit activities into private benefit, vendor advantage, sponsor-driven legitimacy, public authority access sale, finance-readiness implication, procurement advantage, certification influence, recognition purchase, or enterprise execution. Public-benefit purpose shall be evaluated substantively, not merely by labels, preambles, marketing terms, or stated intent.
457.7 Mission Lock Review. Mission lock review shall assess whether the amendment preserves GCRI Canada’s core mission, legal character, nonprofit posture, non-distribution, non-execution boundary, role separation, public-good technical stewardship, anti-capture discipline, public-safe claims discipline, validity-by-record, and correctionability. Amendments affecting mission language, permitted activities, prohibited activities, governance authority, public authority relationships, finance-boundary posture, sponsor benefits, provider participation, recognition-adjacent claims, certification-adjacent claims, technical asset governance, or public-safe publication shall receive heightened mission-lock review. No amendment shall weaken mission lock through ambiguity, euphemism, lower-order instrument, funding condition, federation language, or operational convenience.
457.8 Nexus Constitutional Alignment Review. Nexus constitutional alignment review shall assess whether the amendment remains compatible with Nexus constitutional doctrines, instruments, role taxonomy, federation architecture, one-rail / two-stack discipline, public-good stack architecture, enterprise stack boundary, non-execution discipline, validity-by-record, correctionability, public authority capacity classification, finance-readiness boundaries, public-safe publication, and safeguards, to the extent consistent with Canadian law and GCRI Canada’s Articles. Nexus alignment shall be used for mission coherence and interoperability, not to override Canadian law, GCRI Canada corporate governance, statutory requirements, Board authority, member approval where required, or Canadian localization. Where alignment and Canadian legal requirements diverge, the divergence shall be recorded through compatibility notes or divergence logs.
457.9 GCRI / GRF / GRA Role-Separation Review. GCRI / GRF / GRA role-separation review shall confirm that the amendment preserves the distinct roles of GCRI Canada, GCRI US, The Global Risks Forum (GRF), and The Global Risks Alliance (GRA). The review shall ensure that GCRI Canada does not assume GRF’s public-good registry, recognition, standing, maturity-record, claims-discipline, stakeholder-formation, public-safe reporting, or public-facing legitimacy functions, and does not assume GRA’s finance-readiness, capital-readability, risk-finance, insurance, underwriting, lending, rating, public finance, or transaction-interface functions. GCRI Canada may provide technical evidence, methods, observability, ontology, public-good software, technical baseline, public-safe publication, and correction inputs, but shall not convert inputs into recognition, finance-readiness, certification, procurement approval, or execution authority.
457.10 Public-Good Stack and Enterprise Stack Separation Review. Public-good stack and enterprise stack separation review shall assess whether the amendment preserves GCRI Canada’s public-good stack role and avoids migration into enterprise-stack execution. The review shall identify whether the amendment affects National Consortium Companies, Project SPVs, qualified providers, vendors, hosts, sponsors, funders, capital readers, insurers, lenders, underwriters, public-private partnership vehicles, procurement actors, implementation vehicles, or transaction-oriented structures. Any amendment permitting interface with enterprise-stack actors shall include non-reliance, provider-neutrality, procurement-neutrality, sponsor non-control, no-shared-liability, no-execution, finance-boundary, public authority-boundary, data / AI / cyber, safeguards, and correction controls.
457.11 Non-Execution Review. Non-execution review shall determine whether the amendment could cause, imply, enable, or normalize GCRI Canada acting as an operator, implementer, emergency commander, public warning body, public infrastructure operator, telecom operator, AI-RAN or O-RAN operator, DePIN operator, utility operator, clinical operator, procurement agent, finance arranger, broker, finder, insurer, lender, underwriter, rating body, certifier, recognizer, maturity authority, provider selector, National Consortium Company, Project SPV, regulated professional services provider, or public authority substitute. Any amendment that touches implementation, pilots, labs, dashboards, maps, technical baselines, public authority learning, public finance readers, capital readers, providers, hosts, or program activation shall be reviewed for non-execution language, authority limits, public-safe limitations, and correction path.
457.12 Public Authority Boundary Review. Public authority boundary review shall assess whether the amendment affects public authority participation, capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, public authority data contribution, logos, titles, quotes, attendance references, public authority-facing materials, public authority learning, public-safe dashboards, maps, Observatory outputs, public warnings, emergency command, regulatory approvals, procurement approvals, funding approvals, public finance approvals, sovereign obligations, public-private partnership language, or public authority adoption language. Amendments shall include boundary language where needed and shall not permit public authority delegation by implication, attendance, data contribution, controlled-room participation, public statement, or federation interface.
457.13 Finance-Readiness, Insurance, Investment, Lending, Underwriting, Rating, Public Finance, and Capital-Reader Boundary Review. Finance-boundary review shall assess whether the amendment affects finance-readiness, insurance-readiness, investment suitability, securities solicitation, capital placement, brokerage, finder activity, investor matchmaking, lending, underwriting, guarantee, rating, public finance approval, bankability, investability, public guarantee, public finance reader rooms, proof packs, GRA interfaces, Nexus Rails, RNFD, NFD, UNFSD, capital-reader materials, or finance-sensitive evidence. The review shall require non-reliance language where appropriate and shall confirm that GCRI Canada does not make finance-readiness determinations, investment recommendations, underwriting decisions, insurance placements, lending approvals, ratings, public finance approvals, or transaction decisions.
457.14 Certification, Accreditation, Compliance Approval, Procurement, Recognition, Maturity, Docket, Grid, and Nexus-Compatible Claim Boundary Review. Certification and recognition boundary review shall assess whether the amendment could imply certification, accreditation, compliance approval, conformance approval, procurement approval, vendor selection, preferred provider status, recognition, standing, maturity, Docket validity, Grid status, Nexus-compatible official status, public legitimacy, safety approval, security approval, technical approval, or public authority adoption. The review shall distinguish technical evidence inputs, methods artifacts, technical baselines, Academy records, competence records, public-safe summaries, and interface records from certification, recognition, maturity, procurement, or approval functions. Any language capable of overclaim shall be revised, limited, or accompanied by precise boundary language.
457.15 Data / AI / Cyber / Privacy Review. Data / AI / cyber / privacy review shall assess whether the amendment affects lawful basis, purpose limitation, data minimization, classification, access controls, confidentiality, retention, deletion, cross-border transfer, data localization, sovereign data zones, public authority data, personal information, health-sensitive data, Indigenous data, protected knowledge, AI-use authorization, model registers, model training, fine-tuning, embeddings, retrieval, agentic AI, AI-generated content, human review, cybersecurity baseline, repository controls, vendor security, incident response, breach notification, public-safe release, and records. Amendments shall not allow unapproved AI processing, unapproved storage, shadow IT, uncontrolled public release, weakened cyber controls, or unclear privacy duties.
457.16 Research Integrity Review. Research integrity review shall assess whether the amendment affects research agenda independence, evidence integrity, methods integrity, authorship, attribution, peer review, reproducibility, replication, research ethics, human-subjects review, AI-use disclosure, publication review, data rights, sponsor influence, provider influence, public authority influence, conflict controls, negative result treatment, misconduct processes, correction, supersession, withdrawal, retraction, or archive status. Amendments shall not permit sponsors, providers, funders, donors, public authorities, hosts, National Consortium Companies, Project SPVs, or partners to control research conclusions, suppress findings, manipulate methods, purchase outcomes, or prevent corrections.
457.17 Community Safeguards, Indigenous / Local / Territorial Knowledge, Protected Knowledge, Accessibility, and Non-Retaliation Review. Safeguards review shall assess whether the amendment affects Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, community protocols, consent, non-consent, FPIC where applicable, withdrawal, attribution, non-attribution, public-safe mapping, vulnerable communities, remote communities, accessibility, grievance, remedy, protected participation, whistleblowing, dissent protection, anti-retaliation, and do-no-harm. Amendments shall not weaken safeguards, convert protected knowledge into open data, permit sponsor or provider access to protected knowledge without authority, or create community legitimacy overclaim.
457.18 Sanctions, Export-Control, Controlled Technology, Competition, Professional Boundary, and Public-Safe Claims Review. This review shall assess whether the amendment affects sanctions screening, restricted-party controls, export controls, controlled technology, sensitive AI, AI-RAN, O-RAN, DePIN, DLT, cyber tools, cryptography, geospatial systems, Earth observation, drones, robotics, autonomous systems, sensors, telecom, critical infrastructure, quantum-adjacent systems, semiconductors, advanced manufacturing, competition and antitrust discipline, market-sensitive information, benchmarking, procurement neutrality, professional boundaries, legal opinions, engineering opinions, clinical opinions, investment opinions, insurance opinions, accounting or tax opinions, public health orders, emergency management orders, and public-safe claims. Amendments shall include safeguards against regulated or professional overclaim where necessary.
457.19 Conflict and Related-Party Review. Conflict and related-party review shall assess whether any proponent, drafter, reviewer, director, officer, member where applicable, committee member, council participant, sponsor, donor, funder, provider, host, partner, public authority participant, university, laboratory, National Consortium Company, Project SPV, or other actor has a material interest in the amendment. Conflicts may include financial interest, governance interest, public authority interest, procurement interest, provider advantage, finance interest, certification interest, recognition interest, IP interest, research interest, publication interest, related-party benefit, employment relationship, family relationship, or reputational interest. Conflicts shall be disclosed, recorded, managed, recused, or escalated before adoption.
457.20 Amendment Review Records. GCRI Canada shall maintain amendment review records, including mandatory amendment review records, Canadian law review records, Articles and corporate status review records, nonprofit and tax status review records, charitable status review records where applicable, public-benefit purpose review records, mission lock review records, Nexus constitutional alignment review records, GCRI / GRF / GRA role-separation review records, public-good stack and enterprise stack separation review records, non-execution review records, public authority boundary review records, finance-readiness / insurance / investment / lending / underwriting / rating / public finance / capital-reader boundary review records, certification / accreditation / compliance approval / procurement / recognition / maturity / Docket / Grid / Nexus-compatible claim boundary review records, data / AI / cyber / privacy review records, research integrity review records, safeguards review records, sanctions / export-control / controlled technology / competition / professional boundary / public-safe claims review records, conflict and related-party review records, findings, conditions, revisions, approvals, escalations, closeouts, and archives.
Section 458. Gazette Notices, Repository Updates, Synchronization, Supersession, and Public-Safe Notice
458.1 Notice of Amendment. GCRI Canada shall give notice of adopted amendments in the manner required by applicable law, the Articles, this Bylaw, Board resolution, member approval where applicable, public authority terms, contract, policy, or public-safe publication discipline. Notice of amendment shall identify the amendment, version, effective date, authority, affected provisions, superseded text, transition rules where applicable, and location of authoritative text. Notice shall be accurate, limitation-bearing where needed, and shall not imply public authority approval, finance-readiness, certification, recognition, procurement approval, or Nexus-wide adoption unless such status is separately lawful and recorded.
458.2 Gazette or Notice-Stream Entry. GCRI Canada may maintain a Gazette, notice stream, amendment register, repository release log, official update page, internal notice board, or comparable notice mechanism for amendments and material governance updates. A Gazette or notice-stream entry shall identify the amendment case ID, title, change class, adoption authority, approval date, effective date, version number, affected instruments, supersession status, public-safe status, controlled annex status, and correction contact. Gazette or notice-stream entries shall support transparency, validity-by-record, public-safe communication, and archival traceability.
458.3 Repository Update. Where GCRI Canada maintains an official repository for this Bylaw, related policies, schedules, annexes, templates, public-safe summaries, controlled vocabularies, technical profiles, or public-good governance materials, the repository shall be updated after adoption of an amendment. Repository updates shall include the authoritative adopted text, version metadata, release notes where appropriate, redline or comparison where appropriate, superseded version link or archive reference, effective date, and correction path. Repository updates shall not publish controlled, privileged, public authority-sensitive, protected knowledge, privacy-sensitive, cyber-sensitive, or export-controlled materials unless approved for the relevant access class.
458.4 Authoritative Text Deposit. The authoritative text of this Bylaw and any amendment shall be deposited in an approved corporate record location, official repository, minute book, document management system, records system, or other authoritative location designated by the Board or officers acting within authority. The authoritative text deposit shall include clean adopted text, approval record, version number, effective date, supersession record, and archival reference. Copies, excerpts, public summaries, working drafts, AI-generated summaries, training slides, public decks, or website pages shall not displace the authoritative text.
458.5 Supersession of Prior Version. Upon effectiveness of an amendment, the prior version of the affected text shall be superseded to the extent stated in the amendment record. Supersession shall identify the prior version, new version, effective date, affected provisions, transitional effect, continuing obligations, legacy records, and any provisions that remain applicable to prior acts or prior periods. Supersession shall not erase historic obligations, prior valid acts, correction obligations, legal holds, public authority restrictions, data rights, protected knowledge restrictions, or archival requirements unless lawfully authorized.
458.6 Archive of Prior Version. GCRI Canada shall archive prior versions of this Bylaw and material lower-order instruments to preserve institutional memory, legal traceability, amendment history, correctionability, and auditability. Archives shall include version number, effective period, supersession date, authority, redline or comparison where available, public-safe status, controlled annex status, and access classification. Archived versions shall be marked as superseded, withdrawn, deprecated, or historical, as applicable, and shall not be presented as operative text except for historic reference, legal review, audit, dispute, or transition purposes.
458.7 Public-Safe Notice Where Appropriate. GCRI Canada may issue public-safe notice of amendments where the amendment affects public-facing purpose, public authority language, public-safe publication, sponsor or provider references, public-good technical assets, Academy materials, public participation, public reports, public dashboards, public maps, public repositories, public claims, or other matters likely to be read by external stakeholders. Public-safe notice shall describe the amendment accurately and with appropriate limitations, non-execution language, non-endorsement language, and correction path. Public-safe notice shall not disclose controlled annexes, confidential materials, privileged materials, public authority-sensitive information, protected knowledge, cyber-sensitive details, or personal information.
458.8 Controlled Notice Where Appropriate. Controlled notice may be provided to directors, officers, members where applicable, staff, contractors, fellows, advisors, committees, councils, public authority participants, sponsors, providers, hosts, donors, funders, partners, universities, laboratories, communities, Nexus interfaces, or other authorized persons where the amendment affects controlled materials, data rights, public authority records, protected knowledge, technical assets, AI systems, cyber controls, finance-boundary materials, research integrity, safeguards, or internal procedures. Controlled notice shall be access-limited, classification-appropriate, confidential where required, and accompanied by implementation instructions where needed.
458.9 Internal Notice. Internal notice shall be provided where an amendment affects directors, officers, employees, contractors, fellows, advisors, volunteers, committee members, council participants, technical contributors, developers, maintainers, publication approvers, public authority interface owners, data / AI / cyber leads, safeguards leads, finance personnel, program owners, or records custodians. Internal notice may require training updates, policy updates, access changes, public material updates, repository changes, records updates, and acknowledgment where appropriate. Internal notice shall distinguish adopted text from drafts and shall identify the effective date and transition rules.
458.10 Stakeholder Notice Where Required. Stakeholder notice shall be provided where required by law, contract, public authority terms, funding agreement, grant terms, donor restriction, sponsorship agreement, provider agreement, host agreement, data-sharing agreement, model-sharing agreement, evidence-sharing agreement, research agreement, ethics approval, community protocol, Indigenous governance protocol, Academy terms, subscription terms, or other obligation. Stakeholder notice shall be tailored to the stakeholder’s role and shall not broaden rights, authority, reliance, public authority implication, finance implication, certification implication, procurement implication, or recognition implication beyond the adopted amendment.
458.11 Public Authority Notice Where Required. Public authority notice shall be provided where an amendment affects public authority data, public authority participation, capacity classification, official-capacity records, public authority references, public authority review rights, public authority-facing materials, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, public-safe dashboards, public maps, public authority learning materials, or any notice required by law, contract, data-sharing instrument, or public authority terms. Public authority notice shall preserve non-endorsement, no-delegation, no-public-warning, no-emergency-command, no-procurement, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation language.
458.12 GCRI US, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Consortium, National Company, Project SPV, Provider, Sponsor, Donor, Host, Partner, or Funder Notice Where Relevant. Where an amendment materially affects an interface with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, a consortium, National Consortium Company, Project SPV, qualified provider, sponsor, donor, host, partner, funder, university, laboratory, community, or other interface actor, GCRI Canada may provide relevant notice consistent with confidentiality, legal separateness, role separation, data rights, public authority terms, protected knowledge, and public-safe status. Such notice shall not request or imply external approval unless required by a lawful instrument, nor shall it create shared authority, shared liability, or amendment power in the recipient.
458.13 Synchronization of Policies, Schedules, Templates, Registers, Public Materials, and Technical Systems. After an amendment, GCRI Canada shall synchronize affected policies, schedules, annexes, protocols, operating procedures, forms, templates, registers, controlled vocabularies, technical profiles, public-safe summaries, public materials, websites, decks, reports, dashboards, maps, repositories, APIs, schemas, data rooms, controlled rooms, training materials, Academy materials, sponsor materials, provider materials, public authority materials, federation instruments, authorization packs, compatibility notes, divergence logs, and technical systems. Synchronization shall identify owners, deadlines, affected materials, transition status, residual risk, and verification of completion.
458.14 No Outdated Version as Operative Text. No outdated, superseded, withdrawn, draft, archived, unapproved, AI-generated, unofficial, reformatted, excerpted, or externally modified version of this Bylaw shall be treated as operative text after the effective date of a lawful amendment. Persons using, citing, circulating, or relying on outdated versions shall be directed to the authoritative text. If an outdated version has been published, circulated, embedded in a policy, used in a contract, posted on a website, included in training, or relied on in a decision, GCRI Canada shall correct, withdraw, replace, or qualify the outdated version as appropriate.
458.15 Notice and Synchronization Records. GCRI Canada shall maintain notice and synchronization records, including notice of amendment records, Gazette or notice-stream entry records, repository update records, authoritative text deposit records, supersession records, archive records, public-safe notice records, controlled notice records, internal notice records, stakeholder notice records, public authority notice records, Nexus interface notice records, synchronization records for policies / schedules / templates / registers / public materials / technical systems, no-outdated-version records, correction records, closeouts, and archives.
Section 459. Annex Modularity, Policy Updates, Schedule Updates, and Operating Procedure Updates
459.1 Annex Modularity Purpose. GCRI Canada may use annex modularity to permit schedules, annexes, controlled annexes, policies, protocols, operating procedures, forms, templates, registers, controlled vocabularies, technical profiles, public-safe summaries, public language packs, authorization packs, and other lower-order instruments to be updated without restating the entire Bylaw, provided that such updates remain lawful, authorized, subordinate to this Bylaw, public-benefit aligned, non-executing, role-separated, public authority-boundary compliant, finance-boundary compliant, data / AI / cyber compliant, safeguards-compliant, and correctionable. Annex modularity shall support maintainability and precision, not hidden amendment of core governance.
459.2 Schedules. Schedules may set out detailed lists, tables, matrices, calendars, registers, templates, thresholds, delegations, committee charters, policies, technical profiles, public language packs, or implementation details that support this Bylaw. Schedules shall be authorized by the Board or other competent authority and shall identify their version, effective date, authority, owner, scope, precedence, review cycle, and correction path. A schedule shall not override this Bylaw, the Articles, applicable law, member rights where applicable, public authority terms, or mandatory safeguards.
459.3 Annexes. Annexes may contain supplementary legal, technical, procedural, operational, public-safe, or controlled materials supporting this Bylaw. Annexes may be public, internal, controlled, restricted, confidential, privileged, public authority-sensitive, cyber-sensitive, finance-sensitive, protected-knowledge-sensitive, export-controlled, or otherwise classified. Annexes shall be governed by access, version, retention, correction, supersession, and archival rules. Annexes shall not be used to create secret amendment authority, hidden execution authority, finance authority, certification authority, recognition authority, public warning authority, or public authority delegation.
459.4 Policies. Policies may operationalize this Bylaw by establishing rules for conflicts, financial controls, signing authority, records retention, data governance, privacy, sovereign data, AI use, cybersecurity, incident response, public-safe publication, sponsorship, donation, grant acceptance, research integrity, public authority protocol, community safeguards, controlled rooms, competition, sanctions, export controls, and other governance domains. Policies shall be approved by the Board or delegated authority as required, shall remain consistent with this Bylaw, and shall not weaken mission lock, non-execution, role separation, public authority boundaries, finance boundaries, safeguards, or correctionability.
459.5 Protocols. Protocols may define specific processes for public authority engagement, controlled rooms, clean rooms, public-safe publication, safeguards, protected knowledge, data sharing, model sharing, evidence sharing, Observatory interfaces, Rails interfaces, Grid interfaces, Academy interfaces, technical asset releases, repository management, incident response, emergency governance, and federation routing. Protocols shall include scope, authority, roles, inputs, outputs, decision limits, records, classification, public-safe status, review cycle, and correction path. Protocols shall not convert process participation into public authority decision-making, certification, finance-readiness, procurement approval, recognition, or execution authority.
459.6 Operating Procedures. Operating procedures may set out step-by-step implementation for approved policies and protocols. Operating procedures shall be subordinate to this Bylaw and shall not create substantive rights, duties, powers, authorities, public claims, public authority relationships, finance roles, certification roles, procurement roles, or recognition roles beyond authorized instruments. Procedures may be updated more frequently than the Bylaw where authorized, but material procedural changes affecting rights, authority, boundaries, safeguards, data / AI / cyber controls, or public-safe status shall receive appropriate review.
459.7 Forms. Forms may be used for intake, consent, disclosure, conflict reporting, public authority capacity classification, data contribution, AI-use authorization, publication review, sponsor acknowledgment, provider reference, host participation, research ethics, safeguards review, incident reporting, corrective action, training attendance, member matters where applicable, committee reporting, and other record needs. Forms shall collect only necessary information, include required limitations and confidentiality language, and preserve privacy, data minimization, accessibility, public authority boundaries, protected knowledge, and correction paths. A form shall not create authority inconsistent with this Bylaw.
459.8 Templates. Templates may be used for agreements, MOUs, interface agreements, authorization packs, data-sharing instruments, model-sharing instruments, evidence-sharing instruments, publication approvals, board resolutions, committee charters, public-safe disclaimers, controlled notices, public authority notices, sponsor acknowledgments, provider references, host records, program charters, and technical asset records. Templates shall include required boundary clauses and shall be reviewed periodically. A template shall not be used mechanically where the transaction or interface requires tailored legal, data / AI / cyber, public authority, finance, safeguards, or technical review.
459.9 Registers. Registers may record corporate status, directors, officers, members where applicable, participants, supporters, contributors, conflicts, recusals, related parties, gifts, grants, donations, sponsorships, restricted funds, research, evidence, methods, ontology, controlled vocabularies, data processing, access, models, software, public-good technical assets, publications, public authority capacity, references, risks, issues, controls, incidents, corrections, enforcement, policies, technical assets, federation interfaces, and other material records. Registers shall have custodians, classification, update rules, access controls, versioning, review cycles, and correction paths.
459.10 Controlled Vocabularies. Controlled vocabularies may define approved terms for governance, evidence, methods, observability, ontology, public-safe publication, public authority capacity, finance-boundary terms, recognition-boundary terms, certification-boundary terms, procurement-boundary terms, safeguards, data / AI / cyber, technical assets, programs, federation interfaces, and Nexus-compatible language. Controlled vocabularies shall prevent semantic drift, authority inflation, overclaim, public authority confusion, finance implication, certification implication, procurement implication, recognition implication, maturity implication, provider preference, sponsor control implication, and public warning implication. Changes to core terms shall be reviewed as material where meaning is affected.
459.11 Technical Profiles. Technical profiles may define schemas, APIs, reference architectures, interoperability profiles, evidence profiles, Observatory profiles, AI governance profiles, cybersecurity profiles, data profiles, model cards, system cards, benchmark cards, test harnesses, gold vectors, negative tests, technical baseline profiles, repository profiles, and public-good software profiles. Technical profiles shall be versioned, classified, public-safe reviewed, security-reviewed where appropriate, and corrected where necessary. Technical profiles shall not be represented as certification, compliance approval, public authority approval, procurement approval, finance-readiness, provider preference, or warranty.
459.12 Public-Safe Summaries. Public-safe summaries may translate controlled, technical, legal, governance, evidence, methods, research, safeguards, or assurance materials into public-facing language. Public-safe summaries shall be accurate, limitation-bearing, non-executing, non-endorsing, non-finance, non-certifying, non-procurement, public authority-boundary compliant, and correctionable. Public-safe summaries shall not disclose controlled annexes, protected knowledge, personal information, public authority-sensitive information, cyber-sensitive information, export-controlled materials, or unsupported impact claims.
459.13 Lower-Order Instrument Update Authority. Lower-order instruments may be updated by the Board, a Board committee, an officer, or another authorized person only to the extent authority is expressly granted by law, the Articles, this Bylaw, Board resolution, policy, or the instrument itself. Update authority shall specify scope, limits, review requirements, effective date, publication or notice requirements, and records. Lower-order update authority shall not include power to amend this Bylaw, alter mission lock, weaken non-execution, alter member rights where applicable, or assume public authority, finance, certification, procurement, recognition, or execution functions.
459.14 No Lower-Order Instrument May Override the Bylaw. No schedule, annex, controlled annex, policy, protocol, operating procedure, form, template, register, controlled vocabulary, technical profile, public-safe summary, authorization pack, interface agreement, MOU, public statement, repository release, dashboard, map, dataset, software release, public report, or external instrument shall override this Bylaw, the Articles, or applicable law. If a lower-order instrument conflicts with this Bylaw, this Bylaw shall prevail unless the Bylaw is lawfully amended. The conflicting instrument shall be corrected, suspended, withdrawn, revised, or marked subordinate.
459.15 Material Lower-Order Changes Requiring Board Review. Lower-order changes shall require Board review, or review by a Board-authorized committee, where they materially affect legal authority, governance rights, member rights where applicable, public-benefit purpose, mission lock, non-execution, role separation, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, data / AI / cyber controls, privacy, research integrity, safeguards, protected knowledge, sponsor benefits, provider participation, public claims, technical asset releases, federation interfaces, or correctionability. The Board may establish thresholds for materiality, but doubtful changes shall be escalated.
459.16 Emergency Lower-Order Changes. Emergency lower-order changes may be made to protect legal compliance, data security, privacy, AI safety, cybersecurity, public authority clarity, protected knowledge, public-safe publication, finance-boundary discipline, procurement neutrality, certification boundaries, technical asset integrity, or continuity where delay would create material risk. Emergency changes shall be narrow, temporary, recorded, reviewed, ratified where required, and sunset or converted into ordinary governance. Emergency lower-order changes shall not permanently amend this Bylaw or core mission terms without required process.
459.17 Change Log and Versioning. Every material lower-order instrument shall maintain change log and versioning sufficient to identify prior version, new version, change date, effective date, change class, approving authority, drafter, reviewer, reason, affected sections, redline where appropriate, public-safe status, controlled annex status, superseded materials, transition actions, and correction path. Change logs shall be retained and shall support audit, assurance, public-safe publication, and correctionability. Unversioned material lower-order instruments shall be treated as deficient and corrected.
459.18 Annex, Policy, Schedule, and Procedure Records. GCRI Canada shall maintain annex, policy, schedule, and procedure records, including annex modularity purpose records, schedule records, annex records, policy records, protocol records, operating procedure records, form records, template records, register records, controlled vocabulary records, technical profile records, public-safe summary records, lower-order update authority records, no-override records, material lower-order change review records, emergency lower-order change records, change logs, version records, corrections, closeouts, and archives.
Section 460. Interpretation, Severability, Conflict With Law, Conflict With Articles, Conflict With Nexus Documents, and Localization
460.1 Interpretation Purpose. This Bylaw shall be interpreted to preserve lawful corporate governance, public-benefit purpose, nonprofit and non-share posture, non-distribution, mission lock, non-execution, role separation, validity-by-record, correctionability, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, data / AI / cyber integrity, research integrity, safeguards, public-safe publication, and Canadian legal compliance. Interpretation shall favor a reading that makes provisions lawful, coherent, enforceable, public-safe, semantically consistent, and consistent with GCRI Canada’s upstream public-benefit technical role.
460.2 Public-Benefit Interpretation. All provisions shall be interpreted in favor of GCRI Canada’s public-benefit purposes and against private-benefit capture, sponsor control, provider preference, donor control, funder control, public authority access sale, finance-readiness implication, procurement steering, certification overclaim, recognition overclaim, public warning overclaim, emergency command implication, or enterprise execution. Where language is ambiguous, the interpretation that best preserves public-good stewardship, evidence integrity, methods integrity, public-safe publication, safeguards, and correctionability shall prevail.
460.3 Canadian Law-Compliant Interpretation. This Bylaw shall be interpreted consistently with applicable Canadian law. Where a provision is reasonably capable of more than one interpretation, the interpretation most consistent with Canadian federal, provincial, territorial, corporate, nonprofit, tax, privacy, employment, human rights, accessibility, sanctions, export-control, competition, public-sector, research ethics, Indigenous rights, data governance, AI governance, cybersecurity, and other applicable legal requirements shall govern. No interpretation shall create unlawful authority, regulated activity, public authority delegation, improper private benefit, or breach of mandatory law.
460.4 Mission-Preserving Interpretation. This Bylaw shall be interpreted to preserve mission lock and institutional continuity. No provision shall be construed to dilute GCRI Canada’s public-benefit purpose, upstream evidence and methods role, observability role, ontology role, public-good software role, open technical baseline role, public-safe publication role, Academy and competence support role, safeguards role, Canadian localization role, or correctionability. General language shall not override specific mission-preserving limitations.
460.5 Non-Execution-Preserving Interpretation. This Bylaw shall be interpreted to preserve non-execution. No provision shall be construed to authorize GCRI Canada to operate public infrastructure, command emergencies, issue public warnings, make public authority decisions, execute procurement, arrange capital, solicit investment, place insurance, underwrite, lend, rate, certify, accredit, recognize, determine maturity, select providers, manage National Consortium Companies, control Project SPVs, provide regulated professional opinions, or perform enterprise-stack execution unless such authority is expressly, lawfully, and specifically adopted with required controls. Ambiguous operational language shall be read as evidence, methods, learning, observability, public-good technical, public-safe publication, or support activity only.
460.6 Role-Separation-Preserving Interpretation. This Bylaw shall be interpreted to preserve role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, donors, funders, hosts, public authorities, universities, laboratories, communities, and partners. No provision shall be read to create merger, agency, shared treasury, shared liability, substituted authority, public authority delegation, GRF recognition by GCRI Canada, GRA finance-readiness by GCRI Canada, protocol authority by GCRI Canada, or enterprise execution by GCRI Canada unless separately lawful and express.
460.7 Validity-by-Record and Correctionability Interpretation. This Bylaw shall be interpreted through validity-by-record and correctionability. Authority, status, approval, participation, capacity, access, recognition, public authority relationship, finance-boundary status, certification-boundary status, procurement-boundary status, data rights, AI-use authorization, technical asset status, public-safe publication status, and amendment effectiveness shall exist only by competent records where records are required. Errors, omissions, overclaims, stale materials, unsupported claims, conflicting records, and unsafe outputs shall be corrected, superseded, withdrawn, clarified, restricted, or archived according to this Bylaw.
460.8 Severability. If any provision of this Bylaw is determined by a court, competent authority, Board legal review, or other lawful process to be invalid, unlawful, void, voidable, unenforceable, or inapplicable, that determination shall not affect the validity or enforceability of the remaining provisions to the fullest extent permitted by law. The invalid or unenforceable provision shall be severed, narrowed, reformed, suspended, or amended as necessary to preserve public-benefit purpose, mission lock, non-execution, role separation, records discipline, safeguards, and lawful operation. Severability shall not be used to preserve an amendment whose central purpose is unlawful or contrary to GCRI Canada’s constituting instruments.
460.9 Conflict With Mandatory Law. If this Bylaw conflicts with mandatory applicable law, mandatory law shall prevail to the extent of the conflict. The conflicting provision shall be interpreted narrowly, suspended, amended, or severed as required. GCRI Canada shall record the conflict, obtain legal review where appropriate, implement corrective action, update affected materials, and notify relevant persons where required. No internal practice, Board resolution, member approval, lower-order instrument, Nexus document, sponsor agreement, provider agreement, public authority request, or funding condition shall override mandatory law.
460.10 Conflict With Articles or Constituting Instruments. If this Bylaw conflicts with the Articles, letters patent, certificate, special resolution, statutory filing, or other higher-order constituting instrument of GCRI Canada, the higher-order constituting instrument shall prevail to the extent required by law. The Bylaw provision shall be interpreted consistently where possible or amended where necessary. GCRI Canada shall not use bylaw interpretation to amend the Articles indirectly or to avoid required member approval, special resolution, filing, or statutory process.
460.11 Conflict With This Bylaw and Lower-Order Instruments. If any policy, protocol, procedure, schedule, annex, controlled annex, form, template, register, controlled vocabulary, technical profile, public-safe summary, authorization pack, federation instrument, MOU, interface agreement, public statement, publication, dashboard, map, repository, software release, or other lower-order instrument conflicts with this Bylaw, this Bylaw shall prevail unless the Bylaw is lawfully amended. The lower-order instrument shall be corrected, suspended, withdrawn, revised, qualified, or marked subordinate. Reliance on a lower-order conflicting instrument shall not validate an act prohibited by this Bylaw.
460.12 Conflict With Nexus Constitutional Documents. If a Nexus constitutional document, doctrine, charter, protocol, global instrument, federation instrument, consortium instrument, public-good stack instrument, enterprise-stack instrument, or Nexus-compatible document conflicts with Canadian law, the Articles, or this Bylaw as applied to GCRI Canada, Canadian law, the Articles, and this Bylaw shall prevail for GCRI Canada internal corporate governance and Canadian legal acts. The conflict shall be documented through compatibility notes, divergence logs, amendment review, or interface correction. Nexus documents shall inform alignment where consistent, but shall not override GCRI Canada’s lawful governance.
460.13 GCRI Canada Internal Corporate Governance Primacy. GCRI Canada’s internal corporate governance shall be governed by applicable Canadian law, the Articles, this Bylaw, Board resolutions, member approvals where applicable, officer delegations, and competent GCRI Canada records. No external entity, federation interface, public authority participant, sponsor, donor, provider, host, partner, National Consortium Company, Project SPV, GCRI US interface, GRF interface, GRA interface, Nexus interface, consortium, university, laboratory, or community body shall control GCRI Canada internal corporate governance unless a separate lawful instrument validly and expressly provides a limited role consistent with law and this Bylaw.
460.14 Nexus Documents as Mission-Alignment and Interoperability Instruments Where Consistent With Law. Nexus documents may be used as mission-alignment, interoperability, semantic, technical, public-safe publication, evidence, methods, observability, ontology, Academy, competence, safeguards, correction, and interface instruments where consistent with Canadian law, the Articles, and this Bylaw. Such documents may guide terminology, architecture, interface discipline, role separation, and public-good coordination. They shall not be treated as automatically binding corporate law for GCRI Canada, as amendments to this Bylaw, as public authority instruments, as finance-readiness determinations, as certifications, as procurement approvals, as recognition, or as execution mandates unless lawfully adopted within their permitted scope.
460.15 Localization to Canadian Federal, Provincial, Territorial, Indigenous, Community, Public Authority, Tax, Privacy, AI, Cyber, Research, and Sector Contexts. This Bylaw shall be localized as necessary to Canadian federal, provincial, territorial, Indigenous, community, public authority, tax, privacy, AI, cyber, research, public-sector, sectoral, and local contexts. Localization may include adjusted language, notices, consent processes, public authority capacity terms, data controls, safeguards, public-safe publication controls, technical profiles, and training materials. Localization shall preserve core meaning, public-benefit purpose, mission lock, non-execution, role separation, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, data / AI / cyber integrity, safeguards, and correctionability.
460.16 Localization Without Fracture. Localization shall not fracture the Bylaw into inconsistent local meanings, shadow governance, uncontrolled chapters, conflicting public authority language, fragmented data rules, weakened safeguards, inconsistent finance-boundary language, local certification claims, provider-preference practices, sponsor-control practices, or unrecorded execution authority. Where a local requirement or context requires divergence from a general Nexus-compatible approach, the divergence shall be recorded, justified, reviewed, and tied to compatibility notes, divergence logs, public-safe language, and correction path. Localization shall enable lawful adaptation without semantic drift.
460.17 Interpretation and Localization Records. GCRI Canada shall maintain interpretation and localization records, including interpretation purpose records, public-benefit interpretation records, Canadian-law-compliant interpretation records, mission-preserving interpretation records, non-execution-preserving interpretation records, role-separation-preserving interpretation records, validity-by-record and correctionability interpretation records, severability records, conflict-with-law records, conflict-with-Articles records, conflict-with-Bylaw-and-lower-order-instruments records, conflict-with-Nexus-documents records, GCRI Canada internal corporate governance primacy records, Nexus mission-alignment and interoperability records, localization records, no-fracture records, compatibility notes, divergence logs, corrections, closeouts, and archives.
Section 461. Transitional Period and Initial Implementation
461.1 Transitional Period Purpose. A transitional period may be used to move GCRI Canada from prior instruments, drafts, practices, templates, public statements, program materials, records, policies, charters, technical assets, public authority language, sponsor materials, provider materials, Nexus interface materials, and internal processes into compliance with this Bylaw. The transitional period shall support orderly adoption, records completion, policy buildout, committee formation, register creation, public material correction, public authority language correction, data / AI / cyber control implementation, safeguards implementation, training, and compatibility alignment. Transition shall not be used to delay urgent correction or continue prohibited functions.
461.2 Transitional Period Commencement. The transitional period shall commence on the effective date of this Bylaw or on another date approved by the Board in connection with adoption, restatement, or implementation. The commencement record shall identify the effective date, transition scope, responsible officers, priority actions, initial policies, initial committees, initial registers, public material updates, high-risk legacy materials, required notices, and Board reporting schedule. If different provisions have different effective dates, the transitional commencement record shall identify each operative date.
461.3 Transitional Period Duration. The transitional period shall last for the period approved by the Board or required for orderly implementation, subject to legal deadlines, public authority obligations, data / AI / cyber risk, safeguards risk, public-safe publication risk, and mission-critical corrections. The Board may extend, shorten, or phase the transitional period by recorded decision. No extension shall justify continuation of unlawful acts, public authority overclaims, finance-boundary breaches, certification overclaims, procurement implications, provider preference, sponsor control, unsafe publications, data misuse, AI misuse, cyber weakness, or protected knowledge exposure.
461.4 Transitional Board Authority. During the transitional period, the Board may adopt implementation resolutions, priority policies, committee charters, officer delegations, signing matrices, records rules, public-safe language packs, public authority protocols, data / AI / cyber controls, safeguards procedures, finance controls, sponsor controls, provider controls, technical asset registers, and corrective action plans needed to implement this Bylaw. Transitional Board authority shall remain subject to applicable law, the Articles, member approval where required, fiduciary duties, public-benefit purpose, mission lock, non-execution, role separation, and records requirements.
461.5 Transitional Officer Authority. Officers may take transitional implementation actions within delegated authority, including creating records, updating registers, circulating notices, organizing Board materials, implementing policy templates, coordinating legal review, correcting public materials, restricting access, updating repositories, collecting conflicts, classifying public authority participants, updating public-safe language, coordinating training, and preparing closeout reports. Officers shall not use transitional authority to amend this Bylaw, create new prohibited functions, bind GCRI Canada beyond authority, waive mission lock, confer recognition, determine finance-readiness, certify, approve procurement, or accept sponsor or provider control.
461.6 Transitional Committee Authority. Committees may support transition by reviewing policies, registers, conflicts, finance controls, evidence and methods practices, research integrity procedures, data / AI / cyber controls, safeguards, public authority language, public-safe publication, technical asset governance, and Nexus interface alignment. Transitional committees may recommend actions, draft materials, conduct reviews, and monitor implementation, but shall not replace Board authority, member approval where required, officer authority, or legal requirements. Committee charters and interim mandates shall be recorded.
461.7 Transitional Secretariat Authority. The secretariat or records function may compile official texts, maintain version records, organize minute books, establish repositories, create registers, mark drafts and superseded materials, circulate notices, maintain implementation calendars, support Board and committee meetings, track corrective actions, collect acknowledgments, update templates, and prepare archival records. Secretariat authority shall be administrative and records-based. The secretariat shall not alter adopted text, approve amendments, issue public authority language, certify status, recognize entities, determine finance-readiness, or override governance decisions.
461.8 Transitional Use of Prior Instruments. Prior bylaws, charters, policies, templates, public statements, program materials, technical materials, public authority materials, sponsorship materials, provider materials, Nexus interface materials, and internal practices may be used during the transitional period only to the extent they are lawful, not inconsistent with this Bylaw, not misleading, and not unsafe. Prior instruments shall be classified as superseded, transitional, under review, or operative where appropriate. Any prior instrument inconsistent with mission lock, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, safeguards, data / AI / cyber controls, or correctionability shall be corrected, suspended, or withdrawn.
461.9 Supersession of Prior Bylaws, Charters, Policies, Templates, Public Statements, and Internal Practices Where Inconsistent. This Bylaw shall supersede prior bylaws, charters, policies, templates, public statements, internal practices, external-facing descriptions, role descriptions, program materials, authorization practices, public authority language, finance-boundary language, certification language, procurement language, recognition language, sponsor language, provider language, and Nexus interface language to the extent inconsistent with this Bylaw. Supersession shall be recorded and implemented through updates, notices, archive markings, withdrawal, public-safe correction, controlled notice, training, and records synchronization.
461.10 Transitional Validity of Prior Acts Where Lawful and Not Inconsistent With Mission Lock or Non-Execution. Prior acts taken before adoption of this Bylaw may remain valid to the extent they were lawful when taken, within authority, not inconsistent with mandatory law, not inconsistent with the Articles, not materially inconsistent with public-benefit purpose, not prohibited by non-execution, not public authority overclaims, not finance-boundary breaches, not certification or procurement overclaims, not sponsor or provider capture, not data / AI / cyber violations, and not safeguards violations. Prior acts requiring ratification, correction, limitation, withdrawal, or archival shall be reviewed. Transitional validity shall not excuse misconduct or unsafe reliance.
461.11 Transitional Correction of Inconsistent Materials. GCRI Canada shall identify and correct inconsistent materials during transition, including websites, decks, reports, social media, public authority references, sponsor acknowledgments, provider references, Academy materials, training materials, program charters, controlled room rules, public dashboards, maps, datasets, software releases, technical baselines, templates, forms, agreements, compatibility notes, divergence logs, and public-safe summaries. Correction may include revised language, boundary disclaimers, withdrawal, replacement, archive note, controlled notice, public-safe clarification, or stakeholder notice. High-risk materials shall be prioritized.
461.12 Transitional Risk-Based Prioritization. Transitional implementation shall be prioritized by legal risk, public authority risk, finance-boundary risk, data / AI / cyber risk, public-safe publication risk, protected knowledge risk, safeguards risk, sponsor or provider capture risk, technical asset risk, governance validity risk, and public reliance risk. High-risk corrections shall be addressed before low-risk formatting or editorial updates. The Board or officers may use a transition risk register to track priority, owner, deadline, status, and residual risk.
461.13 Transitional Reporting to Board. Officers, committees, or implementation leads shall report to the Board during the transitional period at intervals determined by the Board or as risk requires. Reports may include status of policy adoption, committee formation, register creation, public material correction, data / AI / cyber controls, safeguards, public authority protocol, sponsor and provider controls, technical asset registers, training, incident corrections, unresolved inconsistencies, high-risk gaps, and closeout readiness. Board reporting shall be candid, record-supported, and not limited to success narratives.
461.14 Transition Closeout Conditions. The transitional period may be closed out when priority policies are adopted or scheduled, priority committees are established or intentionally deferred, priority registers are created or assigned, high-risk public materials are corrected, public authority language is reviewed, data / AI / cyber controls are operational at minimum baseline, safeguards procedures are in place, core records are organized, training has commenced, amendment and notice records are complete, and unresolved residual risks have owners and deadlines. Closeout shall be approved by the Board or delegated authority and recorded.
461.15 Transitional Period Records. GCRI Canada shall maintain transitional period records, including transitional purpose records, commencement records, duration records, Board authority records, officer authority records, committee authority records, secretariat authority records, prior instrument use records, supersession records, prior act validity review records, inconsistent material correction records, risk-based prioritization records, Board reporting records, closeout condition records, implementation calendars, action logs, correction records, closeouts, and archives.
Section 462. Priority Policies
462.1 Priority Policy Adoption Purpose. GCRI Canada shall adopt or maintain priority policies necessary to operationalize this Bylaw, preserve lawful governance, protect public-benefit purpose, support nonprofit and tax compliance, maintain financial controls, preserve records, govern data / AI / cyber practices, manage incidents, control public-safe claims, protect research integrity, govern public authority participation, protect community safeguards and protected knowledge, manage controlled rooms, preserve competition discipline, implement sanctions and export-control screening, and support correctionability. Priority policies may be adopted in phases, but high-risk policies shall be prioritized according to legal, operational, public authority, data / AI / cyber, safeguards, finance, and publication risk.
462.2 Conflict of Interest and Related-Party Policy. GCRI Canada shall adopt or maintain a conflict of interest and related-party policy governing directors, officers, members where applicable, employees, contractors, fellows, advisors, committee members, council participants, reviewers, public authority participants, sponsors, donors, providers, hosts, partners, technical contributors, National Consortium Company interfaces, Project SPV interfaces, and other affected persons. The policy shall address disclosure, annual updates, transactional conflicts, research conflicts, public authority conflicts, finance conflicts, procurement conflicts, provider conflicts, sponsor conflicts, IP conflicts, related-party transactions, gifts, hospitality, recusals, abstentions, Board review, records, enforcement, and correction.
462.3 Financial Controls Policy. GCRI Canada shall adopt or maintain a financial controls policy governing budgeting, accounting, bank accounts, payments, reimbursements, grants, donations, sponsorships, subscriptions, cost recovery, restricted funds, in-kind support, expense approvals, segregation of duties, signing authority, fraud prevention, payroll or contractor payments where applicable, reserves, financial reporting, tax records, audit or review engagement, public-safe financial summaries, and records. The policy shall preserve nonprofit and non-distribution character, prevent improper private benefit, and prohibit finance-readiness, investment advice, underwriting, lending, rating, insurance placement, public finance approval, or capital execution by GCRI Canada.
462.4 Signing Authority and Delegation Matrix. GCRI Canada shall adopt or maintain a signing authority and delegation matrix identifying who may bind GCRI Canada, approve contracts, approve expenditures, approve policies, approve public materials, approve data access, approve AI use, approve technical releases, approve public authority references, approve sponsor acknowledgments, approve provider references, approve controlled-room access, approve grants, approve hiring or contracting, approve emergency measures, and approve filings. The matrix shall include thresholds, dual approvals, Board approvals, prohibited commitments, conflict controls, emergency limits, records, and revocation. No delegation shall authorize prohibited functions.
462.5 Document Retention and Records Policy. GCRI Canada shall adopt or maintain a document retention and records policy governing corporate records, Board records, member records where applicable, committee records, contracts, grants, donations, sponsorships, financial records, tax records, research records, evidence records, methods records, data records, AI records, cyber records, public authority records, safeguards records, publication records, technical asset records, incident records, enforcement records, amendment records, federation records, and archives. The policy shall address classification, retention periods, legal holds, access controls, sealing, redaction, secure disposal, versioning, correction, and archival.
462.6 Data Governance Policy. GCRI Canada shall adopt or maintain a data governance policy governing lawful basis, purpose limitation, minimization, accuracy, storage limitation, classification, access, disclosure, retention, deletion, public authority data, personal information, health-sensitive data, research data, public-safe outputs, dashboards, maps, data sharing, AI-use restrictions, data registers, cross-border transfers, protected knowledge, and correction. The policy shall ensure data is handled according to public-benefit purpose, privacy, cybersecurity, safeguards, public authority terms, and records discipline.
462.7 Privacy Policy. GCRI Canada shall adopt or maintain a privacy policy governing collection, use, disclosure, transfer, storage, retention, deletion, access, correction, complaints, privacy rights, breach response, processors, subprocessors, public authority data, research participants, employees, contractors, fellows, advisors, subscribers, participants, donors, sponsors, providers, hosts, website users, Academy participants, and other personal information contexts. The policy shall identify privacy roles, notices, consent where required, lawful basis, safeguards, security, cross-border issues, privacy requests, incident response, and records.
462.8 Sovereign Data and Cross-Border Transfer Policy. GCRI Canada shall adopt or maintain a sovereign data and cross-border transfer policy governing data localization, Canadian data zones, provincial or territorial data restrictions, Indigenous data governance, community data governance, public authority data terms, health data, protected knowledge, cloud regions, subprocessors, foreign access, AI processing, backups, compute-to-data, data rooms, controlled rooms, transfer approvals, transfer denials, transfer records, deletion, return, and correction. The policy shall preserve lawful custody, public-safe handling, and safeguards.
462.9 AI-Use and Model Governance Policy. GCRI Canada shall adopt or maintain an AI-use and model governance policy governing approved AI tools, prohibited AI uses, model register, model records, AI-use authorization, model training restrictions, fine-tuning, embeddings, retrieval, vector stores, agentic AI, AI-assisted publication, human review, source verification, hallucination controls, fabricated citation controls, bias, drift, prompt injection, data leakage, AI incident response, AI vendor terms, AI records, and model restriction, suspension, retirement, deprecation, and archival. The policy shall prohibit unreviewed AI external publication and unauthorized processing of restricted materials.
462.10 Cybersecurity Policy. GCRI Canada shall adopt or maintain a cybersecurity policy governing security governance, asset inventory, identity and access management, MFA, least privilege, secure configuration, endpoint security, network security, cloud security, repository security, application security, data security, logging, monitoring, vulnerability management, patching, incident response, backup, disaster recovery, business continuity, third-party security, secure development, secrets management, security training, and records. The policy shall be proportionate to GCRI Canada’s risk profile, public authority interfaces, technical assets, data sensitivity, and AI use.
462.11 Incident Response Policy. GCRI Canada shall adopt or maintain an incident response policy governing legal, governance, research integrity, evidence, methods, data, privacy, AI, cybersecurity, public authority boundary, finance-boundary, certification-boundary, procurement-boundary, recognition-boundary, public warning, sponsor capture, provider capture, safeguards, protected knowledge, publication, workplace, retaliation, and continuity incidents. The policy shall address intake, severity, case IDs, triage, interim measures, stop / hold / quarantine / freeze / access restrictions, investigations, decision authorities, notifications, corrective actions, post-incident review, and records.
462.12 Public-Safe Publication and Claims Policy. GCRI Canada shall adopt or maintain a public-safe publication and claims policy governing websites, articles, social media, speeches, decks, reports, whitepapers, datasets, software releases, public dashboards, maps, public repositories, donor reports, sponsor materials, provider materials, public authority-facing materials, capital-reader materials, disclaimers, public authority references, finance-boundary language, certification language, procurement language, recognition language, public warning language, AI-assisted content, corrections, withdrawals, retractions, archive status, and records.
462.13 Sponsorship, Donation, Grant, and Support Acceptance Policy. GCRI Canada shall adopt or maintain a sponsorship, donation, grant, and support acceptance policy governing eligibility, due diligence, source-of-funds review, sanctions screening, related-party review, restricted funds, gift conditions, sponsorship benefits, donor acknowledgments, in-kind support, compute credits, cloud credits, provider support, host support, public authority-linked support, sponsor non-control, donor non-control, provider neutrality, no pay-to-play, no control-for-cash, no outcome purchase, no public authority access sale, public language, refusal, return, termination, and records.
462.14 Research Integrity Policy. GCRI Canada shall adopt or maintain a research integrity policy governing research agenda review, public-benefit alignment, research ethics, human-subjects review where applicable, community review, Indigenous rights review, protected knowledge review, sponsor and provider influence controls, conflicts, peer review, reproducibility, replication, method notes, publication review, AI-use disclosure, authorship, attribution, misconduct, complaints, corrections, supersessions, withdrawals, retractions, and records.
462.15 Public Authority Protocol. GCRI Canada shall adopt or maintain a public authority protocol governing capacity classification, official-capacity participation, observer status, regulator-listening status, public finance reader status, emergency-management participation, public infrastructure operator participation, public authority data contribution, public authority references, logos, quotes, attendance, public authority learning, public authority-facing materials, non-endorsement language, no-delegation, no-PPP, no-public-warning, no-emergency-command, no-procurement, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, notice, correction, and records.
462.16 Community Safeguards, Indigenous Knowledge, Protected Knowledge, Accessibility, Grievance, and Non-Retaliation Policy. GCRI Canada shall adopt or maintain a community safeguards, Indigenous knowledge, protected knowledge, accessibility, grievance, and non-retaliation policy governing Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, community protocols, consent, non-consent, FPIC where applicable, withdrawal, attribution, non-attribution, public-safe mapping, vulnerable communities, remote communities, accessibility, grievance, remedy, protected participation, whistleblowing, dissent, anti-retaliation, stop-work, stop-the-line, do-no-harm, and records.
462.17 Controlled-Room and Clean-Room Policy. GCRI Canada shall adopt or maintain a controlled-room and clean-room policy governing controlled rooms, data rooms, evidence rooms, clean teams, clean rooms, public authority rooms, finance-sensitive rooms, protected knowledge rooms, cyber-sensitive rooms, public-safe publication rooms, AI-use restrictions, no-download rules, access controls, confidentiality, logging, output review, competition controls, market-sensitive information, public authority boundaries, finance boundaries, safeguards, closeout, and records. Controlled rooms shall not create public authority decisions, procurement steering, finance execution, certification, recognition, or provider preference.
462.18 Competition and Antitrust Policy. GCRI Canada shall adopt or maintain a competition and antitrust policy governing meetings, benchmarking, market baseline libraries, provider participation, sponsor participation, public authority participation, working groups, technical baselines, challenge programs, Academy activities, data sharing, price information, bid information, market-sensitive information, clean-team procedures, clean-room procedures, no price coordination, no bid coordination, no market allocation, no provider exclusion, no procurement steering, stop-meeting protocols, legal review, training, incidents, and records.
462.19 Sanctions and Export-Control Policy. GCRI Canada shall adopt or maintain a sanctions and export-control policy governing restricted-party screening, jurisdiction screening, beneficial ownership review where appropriate, payments, donations, sponsorships, grants, subscriptions, awards, reimbursements, vendors, providers, hosts, partners, public authority-linked entities, contributors, controlled-room access, repository access, software releases, data sharing, model sharing, AI-RAN, O-RAN, DePIN, DLT, cyber tools, cryptography, geospatial, Earth observation, drones, robotics, autonomous systems, sensors, telecom, critical infrastructure, quantum-adjacent systems, semiconductors, advanced manufacturing, controlled technology, public release, denials, restrictions, licensing, escalation, training, and records.
462.20 Priority Policy Records. GCRI Canada shall maintain priority policy records, including priority policy adoption purpose records, conflict of interest and related-party policy records, financial controls policy records, signing authority and delegation matrix records, document retention and records policy records, data governance policy records, privacy policy records, sovereign data and cross-border transfer policy records, AI-use and model governance policy records, cybersecurity policy records, incident response policy records, public-safe publication and claims policy records, sponsorship / donation / grant / support acceptance policy records, research integrity policy records, public authority protocol records, community safeguards / Indigenous knowledge / protected knowledge / accessibility / grievance / non-retaliation policy records, controlled-room and clean-room policy records, competition and antitrust policy records, sanctions and export-control policy records, approvals, versions, training, corrections, closeouts, and archives.
Section 463. Priority Committees
463.1 Priority Committee Establishment Purpose. GCRI Canada may establish priority committees to support Board oversight, public-benefit governance, financial stewardship, evidence and methods integrity, research integrity, data / AI / cyber governance, safeguards, public-good technical asset stewardship, public authority learning, public-safe communications, executive coordination where needed, and implementation of this Bylaw. Priority committees shall operate under Board authority, recorded charters, conflict rules, confidentiality obligations, records requirements, and defined reporting lines. Committees shall not become shadow Boards, public authorities, finance-readiness authorities, certification authorities, procurement authorities, recognition authorities, provider-selection bodies, or execution vehicles.
463.2 Governance and Nominating Committee. The Governance and Nominating Committee may support Board composition, director qualifications, independence review, conflicts, committee charters, governance policies, succession, Board evaluation, Bylaw amendments, member matters where applicable, legal separateness, mission lock, role separation, and corporate records. The Committee may recommend directors, officers, committee members, governance improvements, and amendment processes, but shall not itself amend this Bylaw, appoint directors where law or the Articles require another process, waive fiduciary duties, or override member rights where applicable.
463.3 Finance, Audit, and Risk Committee. The Finance, Audit, and Risk Committee may support financial controls, budgets, financial reporting, audit or review engagements, grants, donations, sponsorships, restricted funds, in-kind support, insurance, reserves, risk registers, incident oversight, anti-capture, related-party review, and risk escalation. The Committee shall preserve nonprofit and non-distribution character, sponsor non-control, donor non-control, provider neutrality, finance-boundary discipline, and no regulated finance activity by GCRI Canada. It shall not make investment recommendations, underwrite risk, approve public finance, rate projects, arrange capital, or determine finance-readiness.
463.4 Evidence and Methods Committee. The Evidence and Methods Committee may support evidence quality, source lineage, provenance, custody, timestamp discipline, permission, classification, methods notes, reproducibility, observability methods, risk methods, dashboard methods, map methods, ontology alignment, technical truth discipline, public-safe evidence outputs, correction, supersession, withdrawal, and archive status. The Committee shall preserve evidence and methods integrity without conferring public authority decisions, public warnings, emergency commands, finance-readiness, certification, procurement approval, recognition, maturity, or provider preference.
463.5 Research Integrity and Ethics Committee. The Research Integrity and Ethics Committee may support research agenda review, public-benefit alignment, research ethics, human-subjects review where applicable, community review, Indigenous rights review, protected knowledge review, sponsor and provider influence controls, conflicts, peer review, reproducibility, replication, authorship, attribution, AI-use disclosure, research misconduct review, publication integrity, corrections, withdrawals, retractions, and research records. The Committee shall not suppress negative findings, allow sponsor or provider control, or substitute for external ethics review where required.
463.6 Data, AI, Cybersecurity, and Verifiable Compute Committee. The Data, AI, Cybersecurity, and Verifiable Compute Committee may support data governance, privacy, AI-use controls, model register, AI incident review, cybersecurity baseline, repository security, secure development, vendor security, controlled rooms, data localization, cross-border transfer, public authority data handling, protected knowledge controls, verifiable compute methods, verifiable intelligence records, technical auditability, tamper evidence, and incident response. The Committee shall not authorize unreviewed AI outputs, uncontrolled data processing, unsafe public release, or technical authority that changes legal authority without governance approval.
463.7 Ethics, Safeguards, Accessibility, Community, Indigenous, and Protected Knowledge Committee. The Ethics, Safeguards, Accessibility, Community, Indigenous, and Protected Knowledge Committee may support Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, community protocols, consent, non-consent, FPIC where applicable, withdrawal, accessibility, grievance, remedy, protected participation, whistleblowing, dissent, anti-retaliation, public-safe mapping, vulnerable and remote community safeguards, stop-work, stop-the-line, and do-no-harm. The Committee shall have authority to recommend holds, restrictions, corrections, or escalation where safeguards risk is material.
463.8 Public-Good Technical Assets, Software, Open Baselines, and IP Committee. The Public-Good Technical Assets, Software, Open Baselines, and IP Committee may support public-good software, internal software, restricted software, schemas, APIs, SDKs, dashboards, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, technical baselines, repository governance, contributor terms, open-source governance, IP ownership, licenses, moral rights, patent issues, dependency review, vulnerability disclosure, anti-enclosure, secure release, deprecation, retirement, and archival. The Committee shall not confer certification, procurement approval, provider endorsement, public authority approval, finance-readiness, or warranty through technical asset review.
463.9 Public Authority Learning and Public-Safe Communications Committee. The Public Authority Learning and Public-Safe Communications Committee may support public authority protocols, capacity classification, official-capacity records, public authority learning, regulator-listening, public finance reader status, emergency-management learning, public infrastructure operator learning, public authority data contribution, public authority references, public-safe publication, media protocol, dashboards, maps, disclaimers, public statements, non-endorsement language, public authority corrections, and public-safe annual reporting. The Committee shall not issue public warnings, emergency commands, public authority decisions, regulatory approvals, procurement approvals, funding approvals, public finance approvals, or sovereign obligations.
463.10 Executive Committee Where Needed. An Executive Committee may be established where needed to support urgent Board work, continuity, emergency governance, officer coordination, implementation oversight, and time-sensitive decisions within authority delegated by the Board and permitted by law. The Executive Committee shall not exercise powers that cannot lawfully be delegated, amend this Bylaw except where expressly permitted and lawful, approve matters reserved to members, alter mission lock, suspend non-execution, confer recognition, determine finance-readiness, certify, approve procurement, or replace full Board oversight for material matters.
463.11 Interim Committee Charters. During initial implementation or transition, the Board may approve interim committee charters. Interim charters shall identify committee purpose, authority, limits, membership, chair, quorum where applicable, meeting cadence, reporting, confidentiality, conflicts, records, decision lanes, escalation, sunset or review date, and relationship to permanent charters. Interim charters shall not create hidden governance, sponsor-controlled committees, provider-controlled committees, public authority-controlled committees, or authority inconsistent with this Bylaw.
463.12 Committee Membership. Committee membership shall be determined by the Board or authorized authority according to law, the Articles, this Bylaw, committee charter, independence needs, expertise, conflicts, confidentiality capacity, data / AI / cyber fitness, safeguards fitness, public authority boundary understanding, finance-boundary understanding, and public-benefit commitment. Membership may include directors, officers, staff, contractors, fellows, advisors, external experts, public authority participants, community participants, or technical contributors where appropriate, but non-director participation shall not create Board authority or fiduciary status unless lawfully established.
463.13 Committee Workplans. Each priority committee shall maintain a workplan proportionate to its mandate. Workplans may identify annual priorities, policy reviews, register reviews, assurance sampling, training, incidents, corrective actions, public material reviews, technical asset reviews, public authority reviews, safeguards reviews, Board reporting, and renewal actions. Workplans shall be living governance tools and shall not substitute for Board approval where required. Workplans shall include owners, timelines, outputs, and records.
463.14 Committee Reporting. Priority committees shall report to the Board at intervals and in forms determined by the Board or committee charter. Reports shall identify decisions, recommendations, findings, risks, conflicts, recusals, unresolved issues, corrective actions, policy updates, training needs, public authority concerns, finance-boundary concerns, safeguards concerns, data / AI / cyber concerns, technical asset concerns, and matters requiring Board action. Reporting shall be candid, record-supported, confidential where required, and public-safe where external summary is approved.
463.15 Priority Committee Records. GCRI Canada shall maintain priority committee records, including committee establishment purpose records, Governance and Nominating Committee records, Finance / Audit / Risk Committee records, Evidence and Methods Committee records, Research Integrity and Ethics Committee records, Data / AI / Cybersecurity / Verifiable Compute Committee records, Ethics / Safeguards / Accessibility / Community / Indigenous / Protected Knowledge Committee records, Public-Good Technical Assets / Software / Open Baselines / IP Committee records, Public Authority Learning and Public-Safe Communications Committee records, Executive Committee records where needed, interim committee charter records, membership records, workplan records, reporting records, minutes, resolutions, conflicts, recusals, action items, corrective actions, closeouts, and archives.
Section 464. Priority Registers and Records
464.1 Priority Register Purpose. GCRI Canada shall establish and maintain priority registers and records to support validity-by-record, public-benefit governance, legal compliance, nonprofit and tax compliance, conflicts management, financial control, research integrity, evidence integrity, methods integrity, ontology stewardship, data / AI / cyber governance, public-good technical asset stewardship, public-safe publication, public authority boundary discipline, risk management, incident response, correctionability, enforcement, and Nexus interface alignment. Registers shall have identified custodians, access controls, classification, review cycles, versioning, correction paths, and retention rules.
464.2 Corporate Register. The corporate register shall include constituting documents, Articles, Bylaws, amendments, special resolutions, member approvals where applicable, registered office records, corporate filings, annual returns, certificates, directors’ resolutions, officer appointments, committee charters, policies, legal opinions where appropriate, insurance records, tax status records, and other corporate records. The corporate register shall be treated as an authoritative record source for corporate governance and shall be protected against unauthorized alteration.
464.3 Director and Officer Register. The director and officer register shall record directors, officers, terms, appointments, resignations, removals, consents, qualifications, disqualifications, independence status, conflicts, training, confidentiality acknowledgments, committee memberships, signing authority, delegations, contact information, emergency contact protocols, and closeout. The register shall support legal compliance, Board continuity, fiduciary oversight, succession, and records discipline.
464.4 Member, Supporter, Participant, and Contributor Registers. Where applicable, GCRI Canada shall maintain member, supporter, subscriber, affiliate, institutional participant, fellow, advisor, volunteer, developer, maintainer, technical contributor, open-source participant, Academy participant, public authority participant, sponsor, provider, host, partner, and other participation registers. Registers shall identify status, rights, duties, capacity, access, training, good standing, conflicts, confidentiality, public statement authority, termination, suspension, closeout, and correction. Participation registers shall not inflate participation into governance rights where no lawful record provides such rights.
464.5 Conflict, Recusal, Related-Party, Gifts, Hospitality, and Independence Registers. GCRI Canada shall maintain registers for conflicts, recusals, related-party matters, gifts, hospitality, benefits, independence, sponsor relationships, provider relationships, donor relationships, funder relationships, host relationships, public authority roles, IP interests, finance interests, procurement interests, certification interests, recognition interests, research interests, and employment or consulting relationships. These registers shall support disclosure, management, recusal, Board oversight, audit, enforcement, and correction.
464.6 Grant, Donation, Sponsorship, Restricted Fund, In-Kind, and Support Registers. GCRI Canada shall maintain registers for grants, donations, sponsorships, restricted funds, subscriptions, cost recovery, in-kind support, compute credits, cloud credits, software credits, facility support, public-good infrastructure support, donor restrictions, sponsorship benefit schedules, public acknowledgments, source-of-funds review, sanctions screening, related-party review, tax treatment, public language, renewal, termination, and return of funds. Registers shall support support-without-control, anti-capture, financial controls, and public-safe reporting.
464.7 Research Register. The research register shall identify research projects, research leads, public-benefit purpose, ethics review status, human-subjects review where applicable, community review, Indigenous rights review where applicable, protected knowledge review, data sources, AI-use status, sponsor or provider influence controls, conflicts, peer review, publication status, correction status, withdrawal or retraction status, and archive status. The register shall support research integrity, public-safe publication, and correctionability.
464.8 Evidence Register. The evidence register shall identify evidence packs, source records, provenance, custody, timestamps, permissions, authority, classification, confidence, uncertainty, public-safe status, public authority data terms, protected knowledge restrictions, data / AI / cyber restrictions, dashboard or map dependencies, publication dependencies, correction status, supersession status, withdrawal status, and archive status. The register shall support evidence integrity and prevent stale, unsupported, or misclassified evidence from being relied upon.
464.9 Methods Register. The methods register shall identify method notes, protocols, observability methods, risk methods, dashboard methods, map methods, AI governance methods, cyber methods, safeguards methods, publication methods, evidence methods, benchmark methods, test harnesses, assumptions, validation status, limitations, version, owner, custodian, public-safe status, controlled annexes, correction path, supersession, deprecation, and archive status. The register shall support reproducibility, public-safe limitations, and method correction.
464.10 Ontology and Controlled Vocabulary Register. The ontology and controlled vocabulary register shall identify taxonomies, controlled vocabularies, schemas, data dictionaries, risk ontologies, maturity concepts, evidence classifications, technology families, exponential technology categories, mission-critical system categories, public authority capacity terms, finance-boundary terms, recognition-boundary terms, certification-boundary terms, procurement-boundary terms, AI-readable knowledge structures, semantic versions, compatibility notes, divergence logs, and semantic corrections. The register shall prevent semantic drift and overclaim.
464.11 Data Processing and Access Register. The data processing and access register shall identify datasets, data sources, lawful basis, purpose, classification, personal information, health-sensitive information, public authority data, protected knowledge, Indigenous / local / territorial knowledge, access rights, AI-use permissions, transfer restrictions, retention, deletion, processors, subprocessors, cross-border transfer, data localization, privacy rights requests, incidents, and corrections. The register shall support privacy, public authority terms, safeguards, and data minimization.
464.12 Model Register. The model register shall identify AI systems, AI assistants, machine learning models, generative AI tools, embedding systems, retrieval systems, vector stores, evaluation harnesses, agentic systems, automation services, transcription tools, translation tools, coding assistants, simulation models, digital twins, owners, custodians, providers, versions where known, approved uses, prohibited uses, data classes, risk classification, public-safe status, human review requirements, vendor terms, security review, privacy review, model training status, suspension, deprecation, retirement, incidents, and correction paths.
464.13 Software and Public-Good Technical Asset Register. The software and public-good technical asset register shall identify software, public-good software, internal software, restricted software, schemas, APIs, SDKs, dashboards, data dictionaries, ontology files, model cards, dataset cards, system cards, benchmark cards, reference architectures, interoperability profiles, evidence profiles, Observatory profiles, AI governance profiles, cybersecurity profiles, test harnesses, gold vectors, negative tests, technical baselines, repositories, owners, stewards, maintainers, licenses, versions, security status, dependency status, public-safe status, correction path, deprecation, retirement, and archive status.
464.14 Publication Register. The publication register shall identify websites, articles, social media posts, speeches, decks, reports, whitepapers, datasets, software releases, public dashboards, public maps, public repositories, donor reports, sponsor materials, provider materials, public authority-facing materials, capital-reader materials, publication owners, approvers, source records, methods records, public authority review, finance-boundary review, certification-boundary review, procurement-boundary review, safeguards review, AI-use review, disclaimers, publication dates, versions, corrections, withdrawals, retractions, supersessions, and archive status.
464.15 Public Authority Capacity and Reference Register. The public authority capacity and reference register shall identify public authority participants, capacity classifications, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management status, public infrastructure operator status, public authority data contributions, public authority reference permissions, logos, quotes, attendance references, public authority-facing materials, non-endorsement language, notice obligations, correction records, and public-safe status. The register shall prevent public authority overclaim and support correction.
464.16 Risk, Issue, Control, Incident, Correction, and Enforcement Registers. GCRI Canada shall maintain risk, issue, control, incident, correction, and enforcement registers to track legal risk, governance risk, public authority boundary risk, finance-boundary risk, procurement risk, certification risk, recognition risk, data / AI / cyber risk, safeguards risk, sponsor capture risk, provider capture risk, research integrity risk, publication risk, technical asset risk, operational risk, incidents, severity, controls, corrective actions, enforcement matters, appeals, probation, reinstatement, closeouts, residual risks, and lessons learned.
464.17 Register Custodians. Each priority register shall have a custodian responsible for accuracy, access control, versioning, review cycle, retention, correction, and closeout. Custodians may be officers, secretariat personnel, legal leads, finance leads, research leads, evidence leads, methods leads, data / AI / cyber leads, safeguards leads, publication leads, technical asset stewards, public authority interface owners, or other authorized persons. Register custody shall not imply authority to alter legal status, approve records, conceal defects, or override this Bylaw.
464.18 Priority Register Records. GCRI Canada shall maintain priority register records, including priority register purpose records, corporate register records, director and officer register records, member / supporter / participant / contributor register records, conflict / recusal / related-party / gifts / hospitality / independence register records, grant / donation / sponsorship / restricted fund / in-kind / support register records, research register records, evidence register records, methods register records, ontology and controlled vocabulary register records, data processing and access register records, model register records, software and public-good technical asset register records, publication register records, public authority capacity and reference register records, risk / issue / control / incident / correction / enforcement register records, custodian records, review records, corrections, closeouts, and archives.
Section 465. Initial Nexus Alignment
465.1 Initial Nexus Alignment Purpose. GCRI Canada shall undertake initial Nexus alignment to ensure that, upon adoption and implementation of this Bylaw, GCRI Canada’s internal governance, public-benefit purpose, public-good stack role, evidence and methods architecture, observability role, ontology stewardship, public-good software, open technical baselines, public-safe publication, Academy and competence support, public authority protocol, finance-boundary discipline, safeguards, data / AI / cyber controls, federation instruments, and correction records are coherently aligned with Nexus-compatible architecture to the extent consistent with Canadian law, the Articles, and this Bylaw. Initial Nexus alignment shall be a disciplined implementation process, not an external takeover, merger, public authority delegation, finance-readiness determination, certification, recognition, procurement approval, or execution mandate.
465.2 Acknowledgment of Nexus Constitutional Doctrines Where Consistent With Canadian Law. GCRI Canada may acknowledge Nexus constitutional doctrines, including public-benefit orientation, one-rail / two-stack architecture, public-good stack and enterprise stack separation, role separation, non-execution, validity-by-record, correctionability, public authority capacity classification, public-safe publication, support-without-control, provider neutrality, finance-boundary discipline, safeguards, ontology discipline, and interoperability, where consistent with Canadian law and GCRI Canada’s Articles. Such acknowledgment shall guide interpretation, alignment, and interoperability, but shall not override Canadian legal requirements, Board authority, member approval where required, or GCRI Canada internal corporate governance primacy.
465.3 Public-Good Stack Role-Separation Alignment. GCRI Canada shall align its initial implementation with the public-good stack by confirming that its activities remain within research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, technical literacy, Academy support, competence formation support, public authority learning support, safeguards, and correction records. The alignment shall distinguish these public-good functions from enterprise execution, finance execution, procurement, certification, recognition, maturity determination, public authority decision-making, public warning, emergency command, provider selection, National Consortium Company functions, and Project SPV functions.
465.4 GCRI / GRF / GRA Interface Alignment. Initial alignment shall identify and document GCRI Canada’s interface with GCRI US, The Global Risks Forum (GRF), and The Global Risks Alliance (GRA). The alignment shall preserve GCRI Canada’s upstream technical evidence and methods role, GRF’s public-good registry / recognition / standing / maturity-record / claims-discipline / stakeholder-formation / public-safe reporting / public-facing legitimacy role, and GRA’s finance-readiness / capital-readability / finance-interface role where separately governed. GCRI Canada shall record what it may provide as inputs, what it may not determine, how corrections are routed, and what public language is permitted.
465.5 GCRI US Interface Alignment. GCRI Canada shall document its initial alignment with GCRI US, including compatible research, evidence, methods, observability, ontology, public-good software, technical baseline, data / AI / cyber, publication, safeguards, and correction practices. The alignment shall identify shared terminology, Canadian localization, separate legal authority, separate Board authority, separate records, separate treasury, separate liabilities, separate public authority relationships, and divergence logs where Canadian requirements differ. GCRI US alignment shall not create merger, agency, common employer status, shared fiduciary authority, or automatic adoption of GCRI US decisions.
465.6 Nexus Standards and Protocol Authority Interface Alignment. Initial alignment shall identify how GCRI Canada may contribute research, methods, evidence, ontology, schemas, APIs, profiles, test harnesses, public-good software, technical baselines, and correction inputs to Nexus Standards or protocol authority functions. The alignment shall preserve the distinction between technical contribution and formal adoption, approval, protocol authority, certification, accreditation, conformance approval, compliance approval, procurement approval, public authority approval, finance-readiness, recognition, or maturity determination. Versioning, controlled vocabulary, compatibility notes, divergence logs, and correction paths shall be recorded.
465.7 Nexus Network Interface Alignment. GCRI Canada shall document its initial interface with Nexus Network, including participation surfaces, role classification, node relationships, public-good collaboration, technical asset exchange, Academy and competence support, public authority learning, safeguards, data / AI / cyber controls, public language, and correction paths. Nexus Network alignment shall preserve legal separateness, no shared treasury, no shared liability, no informal membership creation, no public authority delegation, no sponsor or provider capture, and no authority to bind GCRI Canada through network participation alone.
465.8 Nexus Observatory Interface Alignment. Initial alignment shall identify how GCRI Canada supports Nexus Observatory methods, observability records, telemetry methods, sensing methods, AI-RAN / O-RAN methods, DePIN methods, digital twin methods, geospatial methods, cyber evidence methods, sovereign compute methods, degraded-mode awareness, verifiable intelligence records, dashboard limitations, map limitations, public-safe outputs, and correction records. The alignment shall state that GCRI Canada does not operate emergency command, issue public warnings, make public authority decisions, certify Observatory signals, approve procurement, determine finance-readiness, or guarantee Observatory performance.
465.9 Nexus Universe Interface Alignment. GCRI Canada shall document its initial alignment with Nexus Universe architecture, including universe-level doctrine, institutional narrative, regional and national pathways, public-good activation surfaces, observatory nodes, hubs, clusters, hotspots, national dense cores, regional clusters, public authority learning, host readiness evidence, Academy pathways, competence formation, and public-safe storytelling. Nexus Universe alignment shall be localized to Canada and shall not imply public authority adoption, sovereign obligation, public-private partnership, provider preference, sponsor control, finance-readiness, certification, recognition, or execution by GCRI Canada.
465.10 Nexus Rails, Grid, Academy, and Competence Cell Interface Alignment. Initial alignment shall identify GCRI Canada’s relationship to Nexus Rails, Nexus Grid, Nexus Academy, and Nexus Competence Cells. Rails alignment shall be limited to technical evidence inputs, methods inputs, observability inputs, technical baseline inputs, and correction inputs without finance-readiness determination. Grid alignment shall be limited to evidence inputs, methods inputs, observability inputs, research inputs, baseline inputs, and correction signals without maturity determination. Academy and Competence Cell alignment shall be limited to learning, training, evidence literacy, research integrity, data / AI / cyber literacy, public authority literacy, safeguards literacy, train-the-trainer materials, public-safe playbooks, and competence pathways without professional certification by default.
465.11 Regional and National Consortium Interface Alignment. GCRI Canada shall document initial alignment with regional and national consortium interfaces, including public-good coordination, regional hazard evidence, national public authority learning, national public-good evidence architecture, observability methods, host readiness evidence, community safeguards, protected knowledge protocols, regional Nexus Universe hubs, national dense cores, compatibility notes, divergence logs, and correction records. Consortium alignment shall not create control over GCRI Canada, public authority delegation to GCRI Canada, regional supremacy over Canadian governance, national execution authority, public-private partnership, finance approval, procurement authority, certification authority, or shared liability.
465.12 National Company and Project SPV Interface Boundary Alignment. Initial alignment shall document boundaries between GCRI Canada and any National Consortium Company, National Consortium Company formation mandate, Project SPV, implementation vehicle, or enterprise-stack actor. The alignment shall state that GCRI Canada is not the company, SPV, operator, sponsor vehicle, capital vehicle, procurement vehicle, underwriter, insurer, lender, guarantor, or execution body by default. Any interface shall be governed by role separation, conflicts, non-reliance, provider neutrality, finance-boundary language, public authority boundaries, data / AI / cyber controls, safeguards, records, and correction.
465.13 Qualified Provider Interface Boundary Alignment. GCRI Canada shall document initial qualified provider interface boundaries to ensure that provider participation, technical contribution, software contribution, cloud support, AI support, cybersecurity support, telecom support, lab support, Academy support, challenge participation, benchmark participation, or public authority learning participation does not create provider preference, procurement approval, certification, finance-readiness, recognition, maturity, public authority endorsement, technical warranty, or control of GCRI Canada outputs. Provider-facing language shall be reviewed, approved, and corrected where necessary.
465.14 Public Authority and Community Safeguards Interface Alignment. Initial alignment shall document public authority and community safeguards interfaces, including public authority capacity classification, official-capacity records, observer status, regulator-listening, public finance reader status, emergency-management participation, public infrastructure operator participation, public authority data contribution, public authority references, non-endorsement language, no-delegation, no-PPP, no-public-warning, no-emergency-command, community protocols, Indigenous rights, Indigenous data, local and territorial knowledge, protected knowledge, public-safe mapping, accessibility, grievance, remedy, non-retaliation, and correction paths. Public authority and community alignment shall prioritize clarity, safety, lawful authority, and do-no-harm.
465.15 Compatibility Notes. GCRI Canada shall prepare compatibility notes where needed to document how its initial Nexus alignment is consistent with Canadian law, the Articles, this Bylaw, public-benefit purpose, public-good stack role, non-execution, role separation, public authority boundaries, finance boundaries, data / AI / cyber controls, safeguards, and correctionability. Compatibility notes may address GCRI US, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Companies, Project SPVs, providers, hosts, public authorities, communities, universities, laboratories, and partners.
465.16 Divergence Logs. GCRI Canada shall prepare divergence logs where its initial implementation differs from Nexus-compatible doctrine, global practice, regional practice, affiliate practice, public-good stack practice, enterprise-stack practice, technical practice, or public language because of Canadian law, provincial or territorial requirements, Indigenous rights, public authority terms, privacy, tax status, nonprofit posture, data localization, AI governance, cybersecurity, safeguards, sanctions, export controls, competition, research ethics, public-safe publication, Board decision, or operational risk. Divergence logs shall identify reason, authority, affected materials, review cycle, public-safe language, and correction path.
465.17 Initial Nexus Alignment Records. GCRI Canada shall maintain initial Nexus alignment records, including initial alignment purpose records, Nexus constitutional doctrine acknowledgment records, public-good stack role-separation alignment records, GCRI / GRF / GRA interface alignment records, GCRI US interface alignment records, Nexus Standards and protocol authority interface alignment records, Nexus Network interface alignment records, Nexus Observatory interface alignment records, Nexus Universe interface alignment records, Nexus Rails / Grid / Academy / Competence Cell interface alignment records, regional and national consortium interface alignment records, National Company and Project SPV boundary alignment records, qualified provider boundary alignment records, public authority and community safeguards interface alignment records, compatibility notes, divergence logs, corrections, closeouts, and archives.
Section 466. Initial Public Materials Review
466.1 Initial Public Materials Review Purpose. GCRI Canada shall conduct an initial public materials review to identify, classify, correct, supersede, withdraw, clarify, or approve public-facing and externally circulated materials in light of this Bylaw. The review shall ensure that websites, decks, proposals, public reports, whitepapers, social media, press materials, media responses, public authority references, sponsor and donor references, provider and partner references, technical claims, finance-readiness references, certification-adjacent references, recognition-adjacent references, procurement-adjacent references, Docket / Grid / Nexus-compatible claims, AI claims, dashboard claims, Observatory claims, digital twin claims, DePIN claims, AI-RAN claims, and proof-receipt claims are lawful, accurate, public-safe, non-executing, evidence-supported, limitation-bearing, role-separated, data / AI / cyber reviewed where required, safeguards reviewed where required, and correctionable. The initial review shall prevent inherited drafts, legacy public language, aspirational materials, fundraising materials, technical narratives, public authority-facing decks, or Nexus ecosystem language from operating as misleading statements of GCRI Canada authority, status, function, recognition, finance-readiness, certification, procurement relevance, public authority endorsement, public warning capacity, emergency command authority, or execution mandate.
466.2 Website Review. GCRI Canada shall review all websites, landing pages, domain pages, public profiles, online directories, public project pages, public program pages, Academy pages, public repository pages, public dashboard pages, public map pages, sponsor acknowledgment pages, provider reference pages, public authority-facing pages, donation or subscription pages, and any other digital presence controlled by or attributed to GCRI Canada. Website review shall verify official name use, legal status, public-benefit purpose, nonprofit and non-distribution posture, non-execution language, public authority non-endorsement language, finance non-reliance language where relevant, certification and procurement boundary language, sponsor and provider non-control language, data / AI / cyber notices, privacy links, correction contact, version date where appropriate, and consistency with this Bylaw. Any website language implying public authority adoption, finance-readiness, investment recommendation, provider preference, certification, recognition, maturity, public warning, emergency command, official Nexus-wide authority, or operational execution shall be corrected, withdrawn, or qualified.
466.3 Deck Review. GCRI Canada shall review all public, investor-facing, donor-facing, sponsor-facing, provider-facing, host-facing, public authority-facing, academic-facing, community-facing, media-facing, and Nexus-facing decks, whether final, draft, legacy, archived, or circulating. Deck review shall examine titles, diagrams, institutional maps, one-rail / two-stack explanations, role descriptions, timelines, activation dockets, proof-pack references, Rails or Grid references, Observatory diagrams, Nexus Universe illustrations, implementation pathways, sponsor slides, provider slides, public authority logos, public authority attendance statements, financial diagrams, capital-readiness language, and technical architecture slides. Decks shall be corrected where visual presentation could imply merger, shared liability, public authority delegation, procurement approval, finance-readiness determination, certification, recognition, provider endorsement, sponsor control, emergency command, public warning, or project execution by GCRI Canada.
466.4 Proposal Review. GCRI Canada shall review proposals, concept notes, grant applications, sponsorship proposals, partnership proposals, public authority proposals, host proposals, consortium proposals, Academy proposals, lab proposals, challenge proposals, benchmarking proposals, public-good software proposals, technical baseline proposals, Observatory proposals, Nexus Universe proposals, and public-private collaboration proposals before continued use. Proposal review shall confirm that proposed activities fall within GCRI Canada’s lawful public-benefit role, or are clearly allocated to another competent actor where outside GCRI Canada’s role. Proposals shall not promise public authority outcomes, public finance approval, procurement outcomes, investment outcomes, certification, recognition, maturity status, provider selection, official warnings, emergency functions, regulated professional services, or enterprise execution unless separately lawful and not attributed to GCRI Canada by default.
466.5 Public Report Review. GCRI Canada shall review public reports, annual reports, assurance summaries, impact reports, research reports, Observatory reports, risk reports, technical reports, public authority learning summaries, public-safe summaries, donor reports, sponsor reports, provider-facing reports, and consortium reports. Public report review shall test source support, method support, public-benefit claims, impact claims, public authority language, finance language, sponsor and provider references, technical claims, safeguards content, protected knowledge handling, personal information, cyber-sensitive content, infrastructure-sensitive content, AI-generated content, correction history, supersession status, and archive status. Public reports shall include limitation language and shall not overstate causality, authority, adoption, readiness, safety, security, resilience, maturity, recognition, finance-readiness, or public legitimacy.
466.6 Whitepaper Review. GCRI Canada shall review whitepapers, doctrine papers, technical notes, market baseline papers, public-good architecture papers, AI governance papers, cyber papers, data papers, Observatory papers, Nexus Rails papers, Nexus Grid papers, Nexus Academy papers, Nexus Universe papers, and sector papers. Whitepaper review shall distinguish explanatory, analytical, methods, evidence, and public-safe outputs from standards, certifications, procurement specifications, public authority decisions, finance-readiness determinations, regulated professional opinions, and execution instructions. Whitepapers shall use controlled vocabulary, disclose assumptions and limitations, preserve role separation, and include correction paths. Any whitepaper containing technical claims or diagrams capable of market reliance shall receive heightened review.
466.7 Social Media Review. GCRI Canada shall review social media posts, reposts, profiles, bios, banners, public comments, campaign materials, video descriptions, captions, short-form explainers, event announcements, speaker promotions, sponsor acknowledgments, provider acknowledgments, public authority references, and impact claims. Social media review shall prevent compressed public language from creating overclaim through omission of boundaries. Social media shall not imply public authority endorsement, public warning, emergency command, procurement approval, finance-readiness, investment opportunity, certification, recognition, maturity, provider preference, sponsor control, public-private partnership, or official adoption by attendance, tagging, logo use, or proximity.
466.8 Press and Media Materials Review. GCRI Canada shall review press releases, media kits, media statements, interview briefs, spokesperson notes, quote sheets, event releases, crisis communications, public corrections, public clarifications, public authority-facing announcements, sponsor announcements, provider announcements, and partner announcements. Press and media materials shall be approved by authorized persons and shall use precise boundary language. Media materials shall not allow journalistic simplification, promotional language, sponsor-driven framing, provider-driven framing, or public authority proximity to misstate GCRI Canada’s legal status, role, authority, public-benefit function, non-execution posture, finance boundary, certification boundary, procurement neutrality, recognition boundary, or public authority boundary.
466.9 Public Authority Reference Review. GCRI Canada shall review all references to governments, departments, ministries, municipalities, Crown entities, regulators, public institutions, utilities, ports, telecom operators, public health bodies, public safety bodies, public works bodies, public finance bodies, emergency-management bodies, public infrastructure operators, public officials, titles, logos, seals, flags, photos, quotes, attendance, data contributions, facility access, workshops, simulations, controlled-room sessions, and public authority-facing materials. References shall be capacity-classified, authorized where required, non-endorsing, and public-safe. No public authority reference shall imply endorsement, adoption, delegation, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, official policy adoption, or public infrastructure adoption.
466.10 Sponsor and Donor Reference Review. GCRI Canada shall review sponsor and donor names, logos, quotes, acknowledgments, benefit descriptions, public reports, website references, event materials, program materials, Academy materials, challenge materials, donor reports, restricted-fund references, and public-good support statements. Sponsor and donor references shall be factual, proportionate, approved, benefit-schedule compliant, non-controlling, non-exclusive unless lawfully approved and not misleading, and consistent with public-benefit purpose. References shall not imply that sponsorship or donation purchases governance influence, research outcomes, public authority access, public claims, finance-readiness, recognition, certification, procurement advantage, provider preference, or avoidance of correction.
466.11 Provider and Partner Reference Review. GCRI Canada shall review provider and partner references, including vendor names, technology references, software references, cloud references, AI provider references, cybersecurity provider references, telecom references, implementation references, university and laboratory references, host references, consortium references, National Consortium Company references, Project SPV references, and partner logos. References shall preserve provider neutrality, procurement neutrality, no endorsement, no warranty, no certification, no finance-readiness, no public authority approval, no shared liability, no agency, and no execution by GCRI Canada. Provider or partner participation shall not be framed as qualification, approval, preferred status, procurement readiness, interoperability certification, or public authority endorsement.
466.12 Technical Claim Review. GCRI Canada shall review technical claims concerning AI, AI-RAN, O-RAN, DePIN, DLT, blockchain, Web3, cyber, sovereign compute, verifiable compute, geospatial systems, Earth observation, digital twins, sensors, telemetry, robotics, drones, autonomous systems, telecom, critical infrastructure, quantum-adjacent systems, semiconductors, advanced manufacturing, climate / nature / WEFH systems, public-good software, APIs, schemas, test harnesses, technical baselines, Observatory methods, proof methods, and verifiable intelligence. Technical claims shall be evidence-supported, scoped, versioned, limitation-bearing, public-safe, security-reviewed where required, and not overstated as guarantee, certification, public authority approval, procurement approval, finance-readiness, maturity, safety determination, security determination, or performance warranty.
466.13 Finance-Readiness Reference Review. GCRI Canada shall review all finance-readiness, capital-readability, capital-reader, proof-pack, GRA interface, Nexus Rails, insurance-readiness, bankability, investability, public finance, public finance reader, RNFD, NFD, UNFSD, underwriting, guarantee, rating, funding, and investment-adjacent references. Finance-readiness references shall be limited to technical evidence inputs, methods support, public-safe evidence records, non-reliance language, and correction paths where applicable. No material shall state or imply that GCRI Canada provides investment advice, securities solicitation, capital placement, brokerage, finder activity, underwriting, lending, insurance placement, rating, public finance approval, bankability determination, investability determination, or finance-readiness determination.
466.14 Certification, Recognition, Procurement, Docket, Grid, and Nexus-Compatible Claim Review. GCRI Canada shall review any claim that could imply certification, accreditation, compliance approval, conformance approval, procurement approval, vendor selection, preferred provider status, recognition, standing, maturity, Docket validity, Grid status, Nexus-compatible official status, public legitimacy, safety approval, security approval, technical approval, or public authority adoption. Materials shall distinguish participation, evidence input, method contribution, technical baseline use, Academy attendance, competence record, Docket reference, Grid interface, or Nexus-compatible language from formal authority. Any claim that cannot be supported by a competent record and proper role authority shall be corrected, withdrawn, or qualified.
466.15 AI, Dashboard, Observatory, Digital Twin, DePIN, AI-RAN, and Proof Receipt Authority Claim Review. GCRI Canada shall review claims concerning AI outputs, dashboards, Observatory signals, digital twins, DePIN records, AI-RAN / O-RAN signals, sensor telemetry, proof receipts, verifiable intelligence records, public-safe maps, degraded-mode awareness, and technical evidence receipts. Such materials shall state or imply only what the underlying record supports and shall not convert signals, outputs, scores, proofs, receipts, or dashboards into public authority decisions, public warnings, emergency commands, certifications, finance-readiness determinations, procurement approvals, recognition, maturity status, safety guarantees, security guarantees, or operational instructions. Proof receipt shall mean record support within stated scope only and shall not mean legal approval, technical correctness, market readiness, or public authority adoption.
466.16 Disclaimer and Boundary Language Review. GCRI Canada shall review all public materials for required disclaimers and boundary language, including non-execution, non-public-warning, non-emergency-command, non-regulatory, non-certification, non-procurement, non-finance, non-investment-advice, non-insurance, non-rating, non-public-finance-approval, public authority non-endorsement, sponsor non-control, provider neutrality, AI limitation, dashboard limitation, map limitation, Observatory limitation, evidence limitation, methods limitation, confidence and uncertainty limitation, and correction language. Disclaimer placement shall be sufficiently visible and proximate to the relevant claim. Boundary language shall be specific enough to prevent misunderstanding and shall not be buried in a manner that defeats public-safe purpose.
466.17 Correction, Withdrawal, Supersession, or Clarification. Where initial public materials review identifies inaccurate, unsupported, stale, unsafe, overclaiming, misclassified, unauthorized, sponsor-inflated, provider-preferential, public authority-misdescriptive, finance-boundary-violating, certification-implying, procurement-implying, recognition-implying, public-warning-implying, emergency-command-implying, AI-fabricated, data-leaking, cyber-sensitive, infrastructure-sensitive, protected-knowledge-exposing, or otherwise problematic material, GCRI Canada shall correct, withdraw, supersede, retract, clarify, archive, restrict, or replace the material. Corrective action shall include downstream dependency review, notice where required, public-safe clarification where appropriate, controlled notice where appropriate, sponsor or provider correction where necessary, public authority correction where required, and archive traceability.
466.18 Initial Public Materials Review Records. GCRI Canada shall maintain initial public materials review records, including review purpose records, website review records, deck review records, proposal review records, public report review records, whitepaper review records, social media review records, press and media materials review records, public authority reference review records, sponsor and donor reference review records, provider and partner reference review records, technical claim review records, finance-readiness reference review records, certification / recognition / procurement / Docket / Grid / Nexus-compatible claim review records, AI / dashboard / Observatory / digital twin / DePIN / AI-RAN / proof receipt authority claim review records, disclaimer and boundary language review records, correction / withdrawal / supersession / clarification records, approvals, holds, public-safe notices, controlled notices, closeouts, and archives.
Section 467. Initial Risk Register
467.1 Initial Risk Register Purpose. GCRI Canada shall establish an initial risk register to identify, classify, own, control, review, and correct material risks arising during initial implementation of this Bylaw and early institutional operation. The initial risk register shall cover legal risk, corporate and tax risk, governance risk, fiscal risk, research integrity risk, evidence and methods risk, data governance risk, privacy risk, AI governance risk, cybersecurity risk, public authority boundary risk, finance / insurance / investment / procurement / certification / recognition / public warning boundary risk, sponsor / donor / provider / host / partner / capture risk, community safeguards and protected knowledge risk, public-safe publication risk, Nexus interface and role-separation risk, operational and continuity risk, and any other material risk identified by the Board, officers, committees, counsel, reviewers, public authority terms, safeguards review, or incident history. The register shall support Board oversight, management accountability, corrective action, assurance, and renewal.
467.2 Legal Risk. The initial risk register shall identify legal risks affecting GCRI Canada, including corporate compliance, nonprofit compliance, tax compliance, privacy law, public authority terms, research ethics obligations, contract obligations, employment and contractor matters, IP ownership, open-source obligations, sanctions, export controls, controlled technology, competition and antitrust, procurement neutrality, human rights, accessibility, Indigenous rights where applicable, public-sector data restrictions, regulated professional boundaries, public claims, and litigation or dispute exposure. Legal risks shall identify responsible owner, legal review need, severity, likelihood, controls, deadlines, and escalation path.
467.3 Corporate and Tax Risk. The register shall identify corporate and tax risks, including incomplete records, defective authority, missing Board approvals, missing member approvals where applicable, incomplete filings, unclear officer authority, weak delegation matrix, improper private benefit, non-distribution risk, restricted-fund misuse, donor restriction ambiguity, sponsorship treatment risk, subscription treatment risk, charitable status misdescription where applicable, related-party transactions, and public claims inconsistent with tax or nonprofit posture. Controls shall include records correction, Board resolutions, policy adoption, legal review, financial controls, and public language correction.
467.4 Governance Risk. The register shall identify governance risks, including unclear Board composition, director qualification gaps, independence gaps, conflicts, recusal gaps, committee ambiguity, council authority inflation, advisory body overreach, informal governance, hidden parallel governance, undocumented delegations, officer overreach, weak minutes, weak resolutions, missing action owners, and continuity gaps. Governance risk controls shall preserve validity-by-record, fiduciary oversight, mission lock, non-execution, role separation, and anti-capture.
467.5 Fiscal Risk. The register shall identify fiscal risks, including cash-flow risk, budgeting gaps, grant dependency, sponsor concentration, donor concentration, restricted-fund restrictions, in-kind support dependency, cloud or compute credit dependency, inadequate reserves, uncontrolled spending, payment fraud, weak segregation of duties, insufficient insurance, audit readiness gaps, tax filing risk, and financial sustainability risk. Fiscal controls shall avoid finance-readiness overclaim, investment activity, capital solicitation, improper private benefit, and sponsor or donor control.
467.6 Research Integrity Risk. The register shall identify research integrity risks, including agenda capture, sponsor influence, provider influence, public authority pressure, conflicts, inadequate ethics review, human-subjects risk, community research risk, protected knowledge risk, AI-use nondisclosure, weak peer review, weak reproducibility, authorship disputes, data integrity issues, negative result suppression, publication pressure, misconduct allegations, and correction delays. Controls shall include research integrity policy, conflict review, ethics review, safeguards review, peer review, publication review, and correction procedures.
467.7 Evidence and Methods Risk. The register shall identify evidence and methods risks, including weak source lineage, uncertain provenance, custody gaps, stale evidence, incomplete evidence, inaccurate evidence, unpermissioned evidence, misclassified evidence, AI-fabricated evidence, fabricated citations, weak methods notes, method drift, false precision, unsupported technical truth claims, missing limitations, weak reproducibility, dashboard method risk, map method risk, Observatory method risk, risk model risk, and correction backlog. Controls shall include evidence registers, methods registers, review gates, versioning, public-safe classification, and correction paths.
467.8 Data Governance Risk. The register shall identify data governance risks, including missing lawful basis, purpose creep, over-collection, weak minimization, weak classification, uncontrolled access, uncontrolled disclosure, retention uncertainty, deletion failure, unapproved transfer, unapproved AI processing, public authority data misuse, protected knowledge exposure, unclear data ownership, cross-border transfer issues, data localization requirements, vendor processing risk, dashboard data risk, map data risk, and derived-output risk. Controls shall include data governance policy, access registers, processing registers, transfer reviews, and incident response.
467.9 Privacy Risk. The register shall identify privacy risks, including personal information over-collection, inadequate notice, weak consent where required, privacy rights response gaps, employee or contractor privacy gaps, participant privacy gaps, donor or subscriber privacy gaps, health-sensitive information risk, public authority participant privacy, data breach risk, re-identification risk, cross-border access, AI leakage, vendor processing, retention and deletion gaps, and public disclosure risk. Controls shall include privacy policy, privacy notices, access controls, privacy impact review, breach response, and training.
467.10 AI Governance Risk. The register shall identify AI governance risks, including unapproved AI tools, personal account AI use, restricted-material upload, model training risk, fine-tuning risk, embedding leakage, retrieval leakage, hallucination, fabricated citation, unsafe output, bias, discriminatory output, drift, prompt injection, unauthorized agent action, unreviewed AI publication, model register gaps, vendor term risk, public authority data AI use, protected knowledge AI use, and AI output overclaim. Controls shall include AI-use policy, model register, human review, source verification, tool approval, incident response, and training.
467.11 Cybersecurity Risk. The register shall identify cybersecurity risks, including asset inventory gaps, weak MFA, excessive access, weak least privilege, cloud misconfiguration, repository exposure, secrets exposure, credential compromise, endpoint weakness, network weakness, application vulnerabilities, dependency vulnerabilities, insufficient logging, weak monitoring, delayed patching, vendor breach, ransomware, dashboard compromise, map compromise, technical asset compromise, backup failure, disaster recovery gaps, and incident response gaps. Controls shall include cybersecurity baseline, secure configuration, vulnerability management, repository security, backup testing, and incident response.
467.12 Public Authority Boundary Risk. The register shall identify public authority boundary risks, including unclear capacity classification, official-capacity ambiguity, observer status overclaim, regulator-listening misdescription, public finance reader misdescription, emergency-management overclaim, public infrastructure operator overclaim, data contribution misinterpretation, logo misuse, quote misuse, attendance overclaim, public authority endorsement implication, public authority delegation implication, public warning implication, emergency command implication, procurement approval implication, funding approval implication, public finance approval implication, sovereign obligation implication, public-private partnership implication, and public authority correction delay. Controls shall include public authority protocol, reference register, approved language, and correction process.
467.13 Finance, Insurance, Investment, Procurement, Certification, Recognition, and Public Warning Boundary Risk. The register shall identify boundary risks relating to finance-readiness, insurance-readiness, investment advice, securities solicitation, capital placement, brokerage, finder activity, underwriting, lending, rating, public finance approval, procurement approval, vendor selection, provider preference, certification, accreditation, compliance approval, conformance approval, recognition, standing, maturity, Docket status, Grid status, public warning, emergency command, public authority decision, and official adoption. Controls shall include boundary reviews, non-reliance language, provider-neutrality controls, procurement-neutrality controls, public-safe publication review, and corrective action.
467.14 Sponsor, Donor, Provider, Host, Partner, and Capture Risk. The register shall identify risks of sponsor control, donor control, funder control, provider preference, host pressure, partner authority inflation, pay-to-play, control-for-cash, outcome purchase, public authority access purchase, funding dependency, concentration, related-party funding, benefit schedule abuse, logo misuse, public acknowledgment overclaim, provider marketing misuse, host endorsement implication, partner shared-liability implication, and correction resistance. Controls shall include support acceptance policy, conflict review, benefit schedules, public claims review, concentration monitoring, and termination rights.
467.15 Community Safeguards and Protected Knowledge Risk. The register shall identify safeguards risks, including Indigenous rights risk, Indigenous data misuse, Indigenous knowledge exposure, local and territorial knowledge exposure, cultural site exposure, environmental knowledge exposure, vulnerable community harm, remote community burden, accessibility gaps, consent gaps, non-consent failure, withdrawal failure, FPIC issues where applicable, protected knowledge mapping risk, sponsor or provider access risk, public authority misuse risk, AI inference harm, grievance gaps, remedy gaps, retaliation risk, and do-no-harm failures. Controls shall include safeguards policy, protected knowledge review, public-safe mapping review, grievance process, and stop-the-line procedures.
467.16 Public-Safe Publication Risk. The register shall identify publication risks, including unsupported claims, stale materials, missing limitations, weak disclaimers, public authority overclaim, finance overclaim, procurement implication, certification implication, recognition implication, public warning implication, emergency command implication, sponsor-inflated statements, provider-preferential statements, AI-fabricated content, data leakage, privacy exposure, cyber-sensitive disclosure, infrastructure-sensitive disclosure, protected knowledge disclosure, inaccurate impact claims, weak correction process, and uncontrolled social media. Controls shall include publication policy, claims review, public-safe classification, authorized spokespersons, and correction workflow.
467.17 Nexus Interface and Role-Separation Risk. The register shall identify Nexus interface risks, including merger implication, shared liability, shared treasury implication, GCRI US ambiguity, GRF recognition confusion, GRA finance-readiness confusion, Nexus Standards authority confusion, Nexus Observatory public warning confusion, Nexus Rails finance confusion, Nexus Grid maturity confusion, Nexus Academy credential inflation, competence cell certification implication, consortium control implication, National Consortium Company control risk, Project SPV execution risk, provider interface risk, sponsor interface risk, and public language drift. Controls shall include compatibility notes, divergence logs, interface records, role-separation training, and public language review.
467.18 Operational and Continuity Risk. The register shall identify operational and continuity risks, including incomplete staffing, officer unavailability, Board unavailability, vendor dependency, cloud outage, repository outage, domain loss, payment system disruption, loss of records, weak backups, technical asset maintenance gaps, policy backlog, training backlog, public material backlog, unresolved corrections, incident response capacity, insurance gaps, facility disruption, communications disruption, and transition overload. Controls shall include continuity plans, successor administration, critical function inventory, RTO / RPO targets, backup testing, prioritization, and Board reporting.
467.19 Initial Risk Owners, Controls, and Review Dates. Each initial risk shall have an owner, control set, current status, severity, likelihood, residual risk, review date, escalation threshold, and corrective action where required. Owners may include officers, directors, committee chairs, program leads, legal leads, finance leads, data / AI / cyber leads, safeguards leads, research leads, publication leads, technical asset stewards, public authority interface owners, or other authorized persons. Risks without owners shall be escalated. Review dates shall be realistic and risk-based, and overdue risk reviews shall be reported.
467.20 Initial Risk Register Records. GCRI Canada shall maintain initial risk register records, including register purpose records, legal risk records, corporate and tax risk records, governance risk records, fiscal risk records, research integrity risk records, evidence and methods risk records, data governance risk records, privacy risk records, AI governance risk records, cybersecurity risk records, public authority boundary risk records, finance / insurance / investment / procurement / certification / recognition / public warning boundary risk records, sponsor / donor / provider / host / partner / capture risk records, community safeguards and protected knowledge risk records, public-safe publication risk records, Nexus interface and role-separation risk records, operational and continuity risk records, owner records, control records, review-date records, corrective action records, closeouts, and archives.
Section 468. Initial Training
468.1 Initial Training Purpose. GCRI Canada shall provide initial training to directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, committee members, council participants, developers, maintainers, public authority interface owners, publication approvers, data / AI / cyber users, safeguards participants, and other relevant persons to support lawful implementation of this Bylaw. Initial training shall establish a shared understanding of public-benefit purpose, fiduciary and governance duties, non-execution, Nexus role separation, validity-by-record, correctionability, data / AI / cyber / privacy controls, public authority boundaries, finance / insurance / investment / procurement / certification / recognition / public warning boundaries, research integrity, public-safe claims, community safeguards, Indigenous knowledge, protected knowledge, accessibility, grievance, non-retaliation, and role-specific responsibilities. Training shall be proportionate to role and risk and shall not create professional certification, regulated credential, public authority qualification, procurement preference, finance-readiness status, recognition, maturity, or provider endorsement.
468.2 Director Training. Directors shall receive initial training on fiduciary duties, duty of care, duty of loyalty, duty of prudence, public-benefit fidelity, nonprofit and non-distribution posture, Board authority, member approval where applicable, conflicts, recusals, minutes, resolutions, corporate records, legal separateness, mission lock, non-execution, role separation, anti-capture, public authority boundaries, finance boundaries, data / AI / cyber oversight, safeguards oversight, research integrity oversight, public-safe publication oversight, technical asset stewardship oversight, emergency governance, continuity, amendment authority, and correctionability. Director training shall support informed Board oversight and shall be recorded.
468.3 Officer Training. Officers shall receive initial training on delegated authority, signing authority, financial controls, records custody, policy implementation, public material approval, public authority protocols, data / AI / cyber controls, privacy obligations, cybersecurity, incident response, publication holds, correction procedures, sponsor and provider boundaries, grants and restricted funds, public-safe communications, emergency governance activation within limits, Board reporting, and prohibition on officer-only amendment of the Bylaw. Officer training shall emphasize that operational authority is bounded by law, the Articles, this Bylaw, Board resolutions, and records.
468.4 Staff and Contractor Training. Staff and contractors shall receive role-based training on their duties, confidentiality, records, conflicts, approved tools, data handling, AI-use limits, cybersecurity, public-safe publication, public authority references, sponsor and provider interactions, research integrity, safeguards, access controls, incident reporting, correction paths, and non-retaliation. Contractors shall also receive training on scope limits, IP terms, work product records, data access restrictions, AI-use restrictions, secure development where applicable, and offboarding obligations. Training shall be completed before access to restricted functions where risk warrants.
468.5 Fellow, Advisor, Volunteer, and Contributor Training. Fellows, advisors, volunteers, developers, maintainers, technical contributors, open-source contributors, reviewers, and other contributors shall receive training appropriate to their role, including public-benefit purpose, role limits, advisory status limits, no authority to bind GCRI Canada without delegation, confidentiality, conflicts, IP and contributor terms, data / AI / cyber rules, repository rules, secure development, public statement limits, publication review, public authority boundaries, finance boundaries, provider neutrality, safeguards, protected knowledge, correction obligations, and offboarding. Participation shall not create governance authority or professional credential.
468.6 Committee and Council Training. Committee members, council participants, advisory body members, working group participants, expert panel members, peer review board members, model review panel members, and competence cell participants shall receive training on mandate, authority limits, advisory status, voting semantics where applicable, conflicts, recusals, confidentiality, records, output limits, public statement limits, public authority boundaries, finance boundaries, procurement neutrality, certification boundaries, recognition boundaries, sponsor and provider controls, safeguards, data / AI / cyber controls, controlled-room rules, and correction paths. Training shall prevent committee or council authority inflation.
468.7 Bylaw Duties Training. Initial training shall include training on duties imposed by this Bylaw, including governance duties, record duties, conflict duties, confidentiality duties, data duties, AI duties, cyber duties, research duties, publication duties, public authority boundary duties, finance-boundary duties, safeguards duties, public-safe claims duties, correction duties, notice duties, and escalation duties. Training shall identify where duties are role-specific and where all participants have baseline obligations, including duty to avoid overclaim, duty to protect restricted materials, duty to report incidents, and duty not to misrepresent authority.
468.8 Fiduciary and Public-Benefit Training. Directors, officers, committee participants where relevant, and senior personnel shall receive training on fiduciary principles, public-benefit governance, nonprofit discipline, anti-capture, private benefit avoidance, related-party controls, sponsor non-control, donor non-control, provider neutrality, public authority boundaries, finance-boundary discipline, mission lock, and public-good stewardship. The training shall emphasize that public-benefit value is not measured by visibility, funding, sponsor satisfaction, provider adoption, capital attention, public authority proximity, or publication volume unless supported by mission-consistent evidence and boundaries.
468.9 Non-Execution Training. Initial training shall explain that GCRI Canada is a non-executing upstream public-benefit technical institution and does not by default operate projects, public infrastructure, emergency systems, public warnings, procurement processes, finance processes, insurance placement, underwriting, lending, ratings, certification, recognition, maturity determinations, provider selection, National Consortium Companies, Project SPVs, or regulated professional services. Training shall use concrete examples covering dashboards, maps, Observatory signals, AI outputs, public authority sessions, proof packs, technical baselines, Academy records, public reports, and partner materials.
468.10 Nexus Role-Separation Training. Initial training shall cover role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, donors, hosts, public authorities, universities, laboratories, communities, and partners. Training shall explain what GCRI Canada may provide as evidence, methods, observability, ontology, technical baseline, public-safe publication, training, safeguards, and correction input, and what it may not decide or imply.
468.11 Validity-by-Record and Correctionability Training. Initial training shall explain that authority, approval, status, capacity, access, publication, public authority reference, finance-boundary status, certification-boundary status, procurement-boundary status, recognition-boundary status, technical asset status, AI-use authorization, data permission, and amendment effectiveness depend on competent records where records are required. Training shall also explain correctionability, including how to identify errors, report concerns, issue corrections, supersede materials, withdraw unsafe outputs, archive prior versions, update downstream materials, and avoid retaliation against persons who raise correction needs.
468.12 Data / AI / Cyber / Privacy Training. Initial training shall cover lawful basis, purpose limitation, minimization, classification, access controls, confidentiality, retention, deletion, cross-border transfer, data localization, public authority data, personal information, health-sensitive information, protected knowledge, Indigenous / local / territorial knowledge, approved tools, shadow IT, AI-use authorization, model registers, hallucination risks, fabricated citation risks, prompt injection, data leakage, agentic AI controls, cybersecurity baseline, MFA, least privilege, repository security, secrets, incident reporting, breach response, and secure disposal.
468.13 Public Authority Boundary Training. Initial training shall cover public authority capacity classification, official-capacity records, observer status, regulator-listening status, public finance reader status, emergency-management participation, public infrastructure operator participation, public authority data contribution, public authority references, logos, quotes, attendance, non-endorsement language, no-delegation, no-public-warning, no-emergency-command, no-procurement, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, no-PPP, and public authority correction. Training shall emphasize that public authority proximity does not equal approval.
468.14 Finance, Insurance, Investment, Procurement, Certification, Recognition, and Public Warning Boundary Training. Initial training shall cover prohibited or boundary-sensitive claims and activities concerning finance-readiness, insurance-readiness, investment advice, securities solicitation, capital placement, brokerage, finder activity, underwriting, lending, guarantees, ratings, public finance approval, procurement approval, vendor selection, provider preference, certification, accreditation, compliance approval, conformance approval, recognition, standing, maturity, Docket status, Grid status, public warning, emergency command, public authority decision, and official adoption. Training shall include required non-reliance and boundary language for relevant roles.
468.15 Research Integrity Training. Initial training shall cover research agenda independence, evidence integrity, methods integrity, research ethics, human-subjects review where applicable, community review, Indigenous rights review where applicable, protected knowledge review, sponsor and provider influence controls, conflict disclosure, peer review, reproducibility, replication, AI-use disclosure, authorship, attribution, negative results, misconduct reporting, publication review, correction, withdrawal, retraction, and archive status. Training shall emphasize that correction is an integrity function and not an institutional failure to be hidden.
468.16 Public-Safe Claims Training. Initial training shall cover public-safe publication, claims substantiation, source verification, limitation language, public authority reference review, finance-boundary review, certification-boundary review, procurement-boundary review, recognition-boundary review, sponsor and provider reference review, technical claim review, impact claim review, AI-assisted content review, dashboard and map limitation language, media protocol, social media discipline, public corrections, controlled notices, and archive status. Training shall emphasize that public-facing brevity does not excuse boundary omissions.
468.17 Community Safeguards, Indigenous Knowledge, Protected Knowledge, Accessibility, Grievance, and Non-Retaliation Training. Initial training shall cover Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, community protocols, consent, non-consent, FPIC where applicable, withdrawal, attribution, non-attribution, public-safe mapping, vulnerable communities, remote communities, accessibility, inclusive participation, grievance, remedy, protected participation, whistleblowing, dissent, anti-retaliation, stop-work, stop-the-line, do-no-harm, sponsor and provider access restrictions, public authority misuse prevention, and AI inference harm. Training shall be adapted to role and risk.
468.18 Initial Training Records. GCRI Canada shall maintain initial training records, including training purpose records, director training records, officer training records, staff and contractor training records, fellow / advisor / volunteer / contributor training records, committee and council training records, Bylaw duties training records, fiduciary and public-benefit training records, non-execution training records, Nexus role-separation training records, validity-by-record and correctionability training records, data / AI / cyber / privacy training records, public authority boundary training records, finance / insurance / investment / procurement / certification / recognition / public warning boundary training records, research integrity training records, public-safe claims training records, community safeguards / Indigenous knowledge / protected knowledge / accessibility / grievance / non-retaliation training records, attendance, learning outcomes, renewal requirements, revocations where applicable, and archives.
Section 469. Transitional Authority and Transition Closeout
469.1 Transitional Authority Purpose. Transitional authority shall permit GCRI Canada to implement this Bylaw, correct legacy materials, establish priority policies, form priority committees, create priority registers, review public materials, conduct initial training, classify public authority participation, implement data / AI / cyber controls, establish safeguards, update federation instruments, and close out inconsistent practices in an orderly, lawful, public-benefit aligned, non-executing, role-separated, and record-supported manner. Transitional authority shall be temporary and shall not create permanent authority, amend this Bylaw, override the Articles, waive required approvals, authorize prohibited functions, or excuse urgent correction.
469.2 Interim Officer Authority. During the transitional period, officers may exercise interim authority within Board-approved limits to organize implementation, prepare records, update registers, collect conflicts, issue internal notices, coordinate public material review, restrict outdated materials, implement approved policies, coordinate training, update repository records, prepare committee materials, classify public authority references, coordinate data / AI / cyber controls, coordinate safeguards, and report to the Board. Interim officer authority shall not include authority to determine finance-readiness, certify, recognize, approve procurement, issue public warnings, command emergencies, accept sponsor control, confer provider preference, or bind GCRI Canada beyond delegated authority.
469.3 Interim Committee Authority. Interim committees may be established to support transition, including governance, finance, audit, risk, evidence, methods, research integrity, data, AI, cybersecurity, safeguards, technical assets, public authority learning, and public-safe communications functions. Interim committees may review, recommend, draft, monitor, and escalate transitional matters within chartered scope. Interim committee authority shall not substitute for Board approval, member approval where required, officer authority, legal requirements, or adoption authority. Interim committees shall be sunset, confirmed, revised, or replaced through Board action.
469.4 Interim Secretariat Authority. The interim secretariat may compile the official Bylaw, maintain version control, organize records, establish document control, circulate notices, mark drafts, archive superseded materials, maintain transition action logs, coordinate meeting records, support Board and committee processes, update templates, collect acknowledgments, and support closeout. Interim secretariat authority is administrative and does not include amendment authority, public claims approval, public authority approval, finance authority, certification authority, recognition authority, or execution authority.
469.5 Interim Delegation Matrix. GCRI Canada may adopt an interim delegation matrix to identify who may approve spending, contracts, publications, data access, AI use, technical releases, public authority references, sponsor acknowledgments, provider references, controlled-room access, emergency measures, policies, training, and records updates during transition. The interim delegation matrix shall include thresholds, dual approvals, prohibited commitments, conflict controls, ratification requirements, sunset date, and Board reporting. It shall be replaced or confirmed by a permanent signing authority and delegation matrix.
469.6 Interim Spending Authority. Interim spending authority may be established to permit necessary implementation expenditures, including legal review, accounting, filings, insurance, cybersecurity, repository controls, records systems, training, privacy controls, data / AI / cyber tools, public material correction, safeguards support, accessibility, and transition administration. Interim spending shall preserve financial controls, segregation of duties, budget discipline, restricted-fund compliance, nonprofit posture, and anti-capture. Interim spending shall not authorize investment activity, capital placement, underwriting, lending, insurance placement, improper private benefit, or sponsor-controlled expenditure.
469.7 Interim Contracting Authority. Interim contracting authority may permit approved officers or authorized persons to enter into limited contracts necessary for implementation, including legal, accounting, insurance, cybersecurity, privacy, records, software, repository, training, accessibility, public-safe publication, safeguards, and administrative support contracts. Interim contracts shall include appropriate confidentiality, data / AI / cyber, IP, privacy, public authority, protected knowledge, sanctions, export-control, termination, records, and correction provisions. Interim contracting shall not create public-private partnership, agency, shared liability, public authority delegation, provider preference, finance-readiness, certification, recognition, or procurement approval.
469.8 Interim Publication Authority. Interim publication authority may permit designated persons to correct, withdraw, supersede, archive, restrict, or publish transitional materials necessary to implement this Bylaw and prevent public misunderstanding. Interim publication authority shall be limited by public-safe publication review, public authority boundary review, finance-boundary review, certification-boundary review, procurement-neutrality review, sponsor and provider reference review, data / AI / cyber review, safeguards review, and authorized spokesperson rules. No new high-risk public claim shall be issued under interim authority without appropriate review.
469.9 Interim Data / AI / Cyber Authority. Interim data / AI / cyber authority may permit designated persons to classify data, restrict access, approve limited tools, suspend unapproved tools, create data and model registers, impose AI-use restrictions, prohibit restricted-material uploads, implement MFA, review repositories, rotate credentials, freeze releases, update vendor controls, establish incident response contacts, and correct data or cyber weaknesses. Interim authority shall be risk-based, least-privilege, recorded, and subject to Board or committee oversight where material.
469.10 Interim Public Authority Interface Authority. Interim public authority interface authority may permit designated persons to classify public authority participants, correct public authority references, issue non-endorsement language, update public authority data contribution records, review public authority-facing materials, coordinate required notices, and prevent public authority overclaim during transition. Interim authority shall not permit GCRI Canada to accept public authority delegation, issue public warnings, command emergencies, approve procurement, approve funding, approve public finance, make regulatory decisions, or imply public authority adoption.
469.11 Interim Emergency Authority. Interim emergency authority may permit temporary holds, freezes, restrictions, publication suspensions, repository freezes, access revocations, AI tool suspensions, data quarantines, controlled-room defaults, public-safe clarifications, and urgent Board or officer actions where delay could materially worsen legal, public authority, finance-boundary, data / AI / cyber, safeguards, publication, or Nexus interface risk. Interim emergency authority shall be narrow, recorded, ratified where required, time-reviewed, and subject to sunset. It shall not become permanent authority without review.
469.12 Ratification of Transitional Acts Where Required. Transitional acts requiring Board ratification, member approval where applicable, legal review, committee review, officer confirmation, filing, public authority notice, or contract approval shall be submitted for ratification or correction within the required period. Ratification shall identify the act, authority relied upon, reason for interim action, conflicts, risks, records, boundaries, and whether correction is required. Acts that cannot lawfully be ratified shall be reversed, corrected, limited, withdrawn, or otherwise remedied.
469.13 Sunset of Transitional Authority. Transitional authority shall sunset on the date or event specified by the Board, upon transition closeout, or upon replacement by permanent policies, committees, delegations, registers, and procedures. Sunset shall not terminate unresolved corrective actions, legal duties, data deletion obligations, public authority notices, safeguards remedies, public material corrections, technical remediation, or records completion. After sunset, ordinary authority rules shall govern unless the Board expressly extends a defined transitional authority for recorded reasons.
469.14 Transition Closeout Criteria. Transition closeout criteria shall include adoption or scheduling of priority policies, establishment or intentional deferral of priority committees, creation of priority registers, completion of initial public materials review for high-risk materials, establishment of public authority reference controls, implementation of minimum data / AI / cyber controls, completion of initial training for high-risk roles, creation of initial risk register, correction of material overclaims, establishment of amendment and notice records, and assignment of owners and deadlines for residual risks. Closeout criteria shall be risk-based and shall be approved by the Board or delegated authority.
469.15 Board Certification of Transition Closeout. The Board may certify transition closeout by resolution after reviewing the transition closeout report, residual risk, unresolved corrective actions, policy status, committee status, register status, public material status, training status, data / AI / cyber status, safeguards status, public authority boundary status, finance-boundary status, and Nexus alignment status. Board certification shall not mean that no risks remain. It shall mean that GCRI Canada has moved from transitional implementation into ordinary governance with identified residual actions.
469.16 Transition Closeout Report. The transition closeout report shall summarize actions completed, actions deferred, unresolved risks, residual corrective actions, public materials corrected, public authority references corrected, policies adopted, committees established, registers created, training completed, technical controls implemented, safeguards implemented, Nexus alignment records created, compatibility notes, divergence logs, and Board decisions. The report may include controlled annexes for confidential, privileged, public authority-sensitive, cyber-sensitive, finance-sensitive, protected knowledge, personnel, or security matters. The report shall be retained as a governance record.
469.17 Transitional Authority and Closeout Records. GCRI Canada shall maintain transitional authority and closeout records, including transitional authority purpose records, interim officer authority records, interim committee authority records, interim secretariat authority records, interim delegation matrix records, interim spending authority records, interim contracting authority records, interim publication authority records, interim data / AI / cyber authority records, interim public authority interface authority records, interim emergency authority records, ratification records, sunset records, transition closeout criteria records, Board certification records, transition closeout reports, residual risk records, corrective action records, closeouts, and archives.
Section 470. Dissolution Authority
470.1 Dissolution Authority. GCRI Canada may be dissolved, wound up, continued, amalgamated, liquidated, or otherwise terminated only in accordance with applicable Canadian law, the Articles, this Bylaw, member approval where required, Board approval, court approval where required, regulator or government approval where required, tax requirements, grant restrictions, donor restrictions, contractual obligations, public authority terms, data obligations, safeguards obligations, and competent corporate records. Dissolution authority shall be exercised as a formal legal act and shall not arise by inactivity, funding loss, sponsor withdrawal, public authority request, provider request, federation decision, consortium decision, Nexus interface action, program termination, or operational convenience alone.
470.2 Board Approval. The Board shall approve any proposed dissolution, wind-up, liquidation, continuation, amalgamation, or equivalent termination process to the extent required by law and the Articles. Board approval shall be based on a dissolution plan, legal review, financial review, asset inventory, liability inventory, restricted-fund review, public-good technical asset review, data / AI / cyber review, public authority material review, protected knowledge review, records review, employee and contractor closeout review where applicable, contract closeout review, public-safe communications plan, and member approval requirements where applicable. Board approval shall be recorded by resolution.
470.3 Member Approval Where Required by Law or Articles. Where member approval, special resolution, class approval, or other statutory member action is required for dissolution or related acts, such approval shall be obtained before the dissolution becomes effective. Member materials shall include the proposed dissolution plan, reasons, legal consequences, asset disposition, restricted-fund treatment, public-good technical asset disposition, data and protected knowledge handling, creditor handling, public-benefit asset distribution, and any required public-safe communications. No Board action, officer action, sponsor request, donor request, funder condition, or Nexus interface decision shall substitute for required member approval.
470.4 Court, Regulator, or Government Approval Where Required. Where court, regulator, government, corporate registry, tax authority, charity regulator where applicable, public authority, grantor, or other approval is required for dissolution, wind-up, asset distribution, restricted-fund handling, data transfer, public authority material disposition, or other dissolution-related act, GCRI Canada shall obtain or address the required approval before completing the relevant act. Approval requirements shall be identified through legal review and recorded. Dissolution shall not be used to evade legal duties, public authority terms, data obligations, grant restrictions, donor restrictions, or creditor rights.
470.5 Notice Requirements. GCRI Canada shall provide dissolution-related notices required by law, the Articles, contracts, grants, donations, sponsorships, subscriptions, public authority terms, employment arrangements, contractor agreements, research agreements, data-sharing agreements, model-sharing agreements, evidence-sharing agreements, community protocols, Indigenous governance protocols, funder terms, insurance policies, vendor agreements, or Board direction. Notices may be public, internal, controlled, creditor-facing, member-facing, public authority-facing, community-facing, donor-facing, sponsor-facing, provider-facing, host-facing, partner-facing, or repository-facing as appropriate. Notices shall be accurate, public-safe, limitation-bearing, and non-misleading.
470.6 Dissolution Plan. The dissolution plan shall identify legal authority, approval requirements, responsible persons, timeline, asset inventory, liability inventory, creditor handling, contract closeout, employee and contractor closeout where applicable, restricted funds, donor restrictions, grant restrictions, sponsorship closeout, in-kind contribution closeout, public-good technical asset disposition, software disposition, data disposition, public authority material disposition, protected knowledge disposition, records preservation, legal holds, tax filings, insurance, public-safe communications, successor stewards where appropriate, distribution recipients where applicable, and closeout records. The dissolution plan shall preserve public-benefit purpose and lawful non-distribution.
470.7 Wind-Up Authority. Upon approval of dissolution or wind-up, the Board or authorized winding-up lead may take lawful acts necessary to wind up GCRI Canada’s affairs, including collecting assets, paying liabilities, closing contracts, handling restricted funds, transferring or archiving public-good technical assets, preserving records, notifying stakeholders, disposing of data lawfully, addressing public authority materials, protecting protected knowledge, filing required documents, maintaining insurance where needed, and distributing remaining assets in accordance with law, the Articles, tax status, donor restrictions, grant restrictions, and public-benefit purpose. Wind-up authority shall not authorize private distribution contrary to law.
470.8 Appointment of Liquidator or Winding-Up Lead Where Appropriate. The Board may appoint a liquidator, winding-up lead, officer, committee, professional advisor, external administrator, or other authorized person to manage dissolution or wind-up where appropriate and lawful. The appointment shall define authority, duties, reporting, conflicts, compensation, confidentiality, data / AI / cyber access, public authority material access, protected knowledge access, signing authority, asset disposition authority, records obligations, and closeout requirements. The appointee shall act within law, the Articles, this Bylaw, Board direction, and the dissolution plan.
470.9 Protection of Restricted Funds. Restricted funds shall be identified, segregated, reviewed, and handled according to donor restrictions, grant restrictions, sponsorship terms, public authority terms, accounting requirements, tax requirements, and applicable law. Restricted funds shall not be redirected, distributed, transferred, or used for inconsistent purposes without lawful authority. Where restrictions cannot be fulfilled, GCRI Canada shall seek required consents, court direction, regulator direction, grantor direction, donor direction, or other lawful resolution. Restricted-fund handling shall be recorded.
470.10 Protection of Public-Good Technical Assets. Dissolution planning shall protect public-good technical assets, including software, open technical baselines, schemas, APIs, SDKs, dashboards, data dictionaries, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, gold vectors, negative tests, repositories, documentation, licenses, contributor terms, dependency records, vulnerability records, release records, and correction records. Assets may be transferred, archived, maintained, deprecated, sealed, restricted, deleted, or retired according to law, IP rights, data rights, public-safe status, security, export controls, protected knowledge, and public-benefit continuity.
470.11 Protection of Data, Public Authority Materials, Community-Protected Materials, and Protected Knowledge. Dissolution shall include specific plans for data, public authority materials, community-protected materials, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, protected knowledge, personal information, health-sensitive information, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive records, research data, AI records, model records, embeddings, retrieval indexes, dashboards, maps, and controlled annexes. Such materials shall be transferred, returned, deleted, sealed, archived, anonymized, aggregated, restricted, or retained only where lawful and consistent with applicable permissions, public authority terms, privacy, safeguards, community protocols, Indigenous governance protocols, and public-safe requirements.
470.12 Protection of Records and Legal Holds. GCRI Canada shall preserve records required by law, corporate governance, tax, audit, grants, donor restrictions, research integrity, public authority terms, privacy, data / AI / cyber, safeguards, technical asset stewardship, litigation holds, investigations, disputes, insurance, employment, contracts, and correctionability. Legal holds shall override routine destruction. Records shall be classified, access-controlled, transferred to lawful custodians where appropriate, archived, sealed, or securely disposed according to retention obligations. Dissolution shall not erase records needed for accountability.
470.13 Public-Safe Communications. Dissolution communications shall be factual, authorized, public-safe, limitation-bearing, non-executing, non-endorsing, and boundary-compliant. Communications may describe dissolution, transition, asset disposition, public-good technical asset status, repository status, data disposition, contact points, public material archive status, correction paths, and successor stewards where lawful. Communications shall not imply public authority action, public warning, emergency command, finance-readiness, certification, recognition, procurement approval, provider endorsement, sponsor control, or continuation of authority after dissolution.
470.14 No Dissolution Distribution Contrary to Law, Articles, Tax Status, Donor Restrictions, Grant Restrictions, or Public-Benefit Purpose. No dissolution distribution shall be made contrary to applicable law, the Articles, tax status, nonprofit and non-distribution requirements, donor restrictions, grant restrictions, public authority terms, restricted-fund obligations, court orders, regulator directions, creditor rights, or public-benefit purpose. Except for lawful payment of debts, compensation, reimbursements, contractual obligations, refunds where required, or other lawful obligations, assets shall not be distributed to directors, officers, members, sponsors, donors, funders, providers, hosts, partners, founders, related parties, or private persons. Remaining assets shall be distributed only as permitted by law and applicable constituting instruments.
470.15 Dissolution Authority Records. GCRI Canada shall maintain dissolution authority records, including dissolution authority records, Board approval records, member approval records where required, court / regulator / government approval records where required, notice records, dissolution plan records, wind-up authority records, liquidator or winding-up lead appointment records, restricted fund protection records, public-good technical asset protection records, data / public authority material / community-protected material / protected knowledge protection records, records and legal hold protection records, public-safe communications records, no-improper-distribution records, filings, tax records, creditor records, closeouts, and archives.
Section 471. Wind-Up, Public-Benefit Asset Distribution, Restricted Funds, Donor Restrictions, Grant Restrictions, and Legal Requirements
471.1 Wind-Up Purpose. Wind-up shall be conducted to close GCRI Canada’s affairs lawfully, orderly, transparently, and consistently with public-benefit purpose, nonprofit and non-distribution obligations, creditor rights, restricted-fund obligations, donor restrictions, grant restrictions, public authority terms, data / AI / cyber obligations, safeguards, technical asset stewardship, records preservation, and correctionability. Wind-up shall prioritize lawful satisfaction of liabilities, protection of restricted and sensitive assets, preservation or responsible disposition of public-good technical assets, protection of protected knowledge, and distribution of remaining assets only to permitted public-benefit or legally qualified recipients.
471.2 Asset Inventory. GCRI Canada shall prepare an asset inventory identifying cash, accounts, receivables, grants, restricted funds, donations, sponsorship funds, subscriptions, prepaid assets, deposits, equipment, furniture, hardware, domains, software, public-good technical assets, repositories, datasets, dashboards, maps, publications, IP, licenses, contracts, insurance rights, claims, records, public authority materials, community-protected materials, protected knowledge, and other assets. The inventory shall identify owner, custodian, restrictions, classification, public-safe status, security status, transferability, encumbrances, donor or grant terms, public authority terms, data rights, IP rights, and disposition plan.
471.3 Liability Inventory. GCRI Canada shall prepare a liability inventory identifying debts, payables, contractual obligations, payroll or contractor obligations, tax obligations, lease obligations, vendor obligations, grant obligations, donor obligations, sponsorship obligations, subscription obligations, refund obligations, indemnification obligations, insurance deductibles, litigation risks, regulatory obligations, public authority obligations, data obligations, privacy obligations, research obligations, IP obligations, repository obligations, technical asset obligations, and contingent liabilities. Liabilities shall be prioritized according to law and wind-up plan.
471.4 Creditor Handling. Creditors shall be identified, notified where required, verified, prioritized, disputed where appropriate, paid or resolved according to law, and recorded. Creditor handling shall preserve restricted funds, donor restrictions, grant restrictions, tax obligations, employee or contractor obligations where applicable, and court or regulator requirements. GCRI Canada shall not distribute remaining assets until creditors and lawful liabilities are addressed to the extent required by law. Disputed claims shall be handled through lawful process and records.
471.5 Contract Closeout. Contracts shall be reviewed and closed out according to their terms and applicable law. Contract closeout may include termination, assignment where lawful, novation where lawful, consent, notice, payment, refund, return of materials, deletion of data, confidentiality continuation, IP license survival, public authority term compliance, protected knowledge handling, audit rights, vendor exit assistance, insurance notice, release, and archive. Contracts involving public authority data, protected knowledge, AI systems, technical assets, sponsors, providers, hosts, universities, laboratories, National Consortium Companies, Project SPVs, or public-good assets shall receive heightened review.
471.6 Employee, Contractor, Fellow, Advisor, Volunteer, and Participant Closeout. GCRI Canada shall close out relationships with employees, contractors, fellows, advisors, volunteers, contributors, committee participants, council participants, Academy participants, public authority participants, sponsors, providers, hosts, partners, and other participants according to law, agreements, confidentiality, IP, data access, AI-use restrictions, repository access, public statement limits, expense reimbursement, final payments, return of materials, access revocation, records, and non-retaliation. Closeout shall not impair rights to report concerns, whistleblowing rights, grievance processes, legal rights, or correction processes.
471.7 Restricted Fund Handling. Restricted funds shall be identified, segregated, reconciled, and used, transferred, returned, or otherwise handled according to restrictions, law, donor direction where required, grantor direction where required, court direction where required, regulator direction where required, or Board-approved legal resolution. Restricted funds shall not be used for general wind-up expenses unless permitted. Where restrictions relate to public-good technical assets, research, Academy programs, public authority learning, safeguards, or technical baselines, disposition shall preserve the restricted purpose where lawful and feasible.
471.8 Donor Restriction Compliance. Donor restrictions shall be reviewed and honored according to law, gift terms, public-benefit purpose, tax treatment, and any required consent or court / regulator direction. Donor restrictions shall not be used to direct assets to private benefit, sponsor control, provider preference, donor-controlled entities, related parties, or purposes inconsistent with GCRI Canada’s nonprofit posture. Where donor restrictions cannot be fulfilled, GCRI Canada shall seek lawful modification, release, return, transfer, or other appropriate resolution.
471.9 Grant Restriction Compliance. Grant restrictions shall be reviewed and honored according to grant agreements, funder terms, public authority terms where applicable, reporting obligations, audit obligations, permitted use, unspent funds, deliverables, IP terms, publication rights, data rights, public-good asset terms, termination provisions, and closeout obligations. Grant-funded assets, data, technical assets, or publications shall be disposed of only in accordance with grant terms and law. Unspent or misapplied grant funds shall be addressed through lawful repayment, reallocation, permission, or correction.
471.10 Sponsorship Closeout. Sponsorships shall be closed out according to sponsorship agreements, benefit schedules, public acknowledgment rules, non-control provisions, public claims controls, unused benefits, refunds where required, logo use termination, sponsor material correction, public authority access restrictions, data restrictions, confidentiality, and records. Sponsorship closeout shall not permit sponsor control over dissolution, asset distribution, research records, public-good technical assets, public authority records, protected knowledge, or correction decisions.
471.11 In-Kind Contribution Closeout. In-kind contributions, including compute credits, cloud credits, software licenses, facility access, staff time, equipment, data access, professional support, technical support, and event support, shall be closed out according to contribution terms, ownership, license, restrictions, security, data rights, public authority terms, protected knowledge, confidentiality, tax treatment, and records. In-kind contributors shall not obtain control over assets, records, public claims, public authority access, technical baselines, or protected materials by reason of contribution.
471.12 Public-Benefit Asset Distribution. After liabilities and restrictions are addressed, remaining assets shall be distributed in accordance with applicable law, the Articles, tax status, donor restrictions, grant restrictions, court or regulator direction where required, and public-benefit purpose. Public-benefit asset distribution shall prioritize recipients capable of preserving or advancing public-good research, evidence, methods, observability, ontology, public-good software, open technical baselines, public-safe publication, public authority learning, safeguards, education, research, or public-benefit technical capacity, subject to legal eligibility and restrictions.
471.13 Distribution to Qualified Public-Benefit, Nonprofit, Charitable, Educational, Research, or Public-Good Organizations Where Required or Appropriate. Where required or appropriate, assets may be distributed to qualified public-benefit, nonprofit, charitable, educational, research, public-good technical, public-interest, university, laboratory, community, Indigenous-governed, or comparable organizations that can lawfully receive and steward the assets. Recipient selection shall consider legal eligibility, mission compatibility, non-distribution, capacity, data / AI / cyber readiness, safeguards capability, public authority term compliance, protected knowledge handling, IP stewardship, public-good technical asset maintenance, and correctionability. Distribution shall not be used to benefit insiders or captured entities.
471.14 No Distribution to Directors, Officers, Members, Sponsors, Donors, Funders, Providers, Hosts, Partners, Founders, Related Parties, or Private Persons Except Lawful Payment of Debts, Compensation, Reimbursements, or Contractual Obligations. No wind-up distribution shall be made to directors, officers, members, sponsors, donors, funders, providers, hosts, partners, founders, related parties, employees, contractors, fellows, advisors, volunteers, contributors, or private persons except for lawful payment of debts, compensation, reimbursements, refunds where required, indemnification where lawful, contractual obligations, or other lawful obligations. This prohibition shall apply regardless of contribution, status, influence, visibility, relationship, public authority proximity, technical contribution, funding history, or perceived entitlement. Any related-party payment shall be reviewed and recorded.
471.15 Tax and Legal Review. Wind-up and distribution shall receive tax and legal review proportionate to the assets, liabilities, restrictions, corporate form, tax status, grants, donations, sponsorships, public authority terms, contracts, data, protected knowledge, IP, technical assets, and public claims involved. Tax and legal review shall identify filings, notices, approvals, distributions, restrictions, liabilities, employee or contractor obligations, GST / HST or other tax matters where applicable, charitable issues where applicable, related-party issues, and post-dissolution record obligations. No distribution shall proceed where legal or tax review identifies unresolved mandatory conditions.
471.16 Wind-Up and Distribution Records. GCRI Canada shall maintain wind-up and distribution records, including wind-up purpose records, asset inventory records, liability inventory records, creditor handling records, contract closeout records, employee / contractor / fellow / advisor / volunteer / participant closeout records, restricted fund handling records, donor restriction compliance records, grant restriction compliance records, sponsorship closeout records, in-kind contribution closeout records, public-benefit asset distribution records, qualified recipient distribution records, no-private-distribution records, tax and legal review records, approvals, notices, filings, payments, transfers, returns, deletions, archives, closeouts, and final records.
Section 472. Public-Good Technical Assets, Software, Open Technical Baselines, Datasets, Schemas, Ontologies, Publications, Model Records, and Technical Records on Dissolution
472.1 Public-Good Technical Asset Disposition Purpose. On dissolution, wind-up, transfer, orderly closure, or discontinuance of relevant activities, GCRI Canada shall dispose of public-good technical assets in a manner that preserves public-benefit purpose, lawful ownership, IP rights, contributor terms, license obligations, data rights, privacy, public authority terms, Indigenous rights, community safeguards, protected knowledge, cybersecurity, export controls, sanctions controls, public-safe publication, technical integrity, correctionability, and archive traceability. Disposition may include open-license continuation, successor stewardship, transfer, repository archival, sealing, restriction, deletion, deprecation, retirement, or controlled preservation, depending on asset class and risk.
472.2 Software Disposition. Software disposition shall address public-good software, internal software, restricted software, scripts, automation tools, AI tools, repository code, deployment tools, dashboards, map tools, APIs, SDKs, test tools, and supporting documentation. Disposition shall identify ownership, license, contributor rights, third-party dependencies, vulnerabilities, secrets, data exclusions, public authority materials, protected knowledge, export-control issues, public-safe status, maintainer status, successor steward, archive plan, and correction path. Software shall not be transferred or released where it contains restricted data, secrets, protected knowledge, unauthorized third-party IP, controlled technology, or unsafe cyber capability without appropriate controls.
472.3 Open Technical Baseline Disposition. Open technical baselines shall be reviewed for public-good value, license status, maintenance status, version, evidence support, methods support, test harness support, security, documentation, limitations, public-safe status, and successor stewardship. Where lawful and public-safe, open technical baselines may be transferred to a qualified public-benefit steward, archived with clear historical status, or maintained under open license. Where unsafe, obsolete, unsupported, or misleading, baselines shall be deprecated, retired, restricted, or accompanied by limitation and archive notices.
472.4 Dataset Disposition. Dataset disposition shall identify dataset ownership, lawful basis, permissions, licenses, data subjects, privacy status, public authority terms, health sensitivity, protected knowledge, Indigenous / local / territorial knowledge, confidentiality, AI-use restrictions, publication restrictions, transfer restrictions, retention requirements, deletion requirements, anonymization or aggregation options, archive status, and successor custody. Datasets shall not be treated as open or transferable merely because they supported public-good work. Restricted datasets shall be returned, deleted, sealed, transferred only to authorized custodians, or retained only where lawfully required.
472.5 Schema Disposition. Schema disposition shall address data schemas, API schemas, ontology-linked schemas, evidence schemas, public authority data schemas, dashboard schemas, map schemas, model metadata schemas, public-safe publication schemas, technical baseline schemas, and interoperability schemas. Schemas may be preserved as public-good technical assets where they do not expose restricted data, protected knowledge, public authority-sensitive fields, cyber-sensitive architecture, or unsafe inference pathways. Schema disposition shall include versioning, license, public-safe status, successor stewardship, and correction records.
472.6 Ontology and Controlled Vocabulary Disposition. Ontology and controlled vocabulary disposition shall address taxonomies, controlled vocabularies, data dictionaries, risk ontologies, maturity concepts, evidence classifications, technology family terms, public authority capacity terms, finance-boundary terms, certification-boundary terms, procurement-boundary terms, recognition-boundary terms, safeguards terms, and AI-readable knowledge structures. Where public-safe, these assets may be preserved or transferred as public-good semantic infrastructure. Where terms could create overclaim, public authority confusion, finance confusion, certification confusion, procurement confusion, recognition confusion, or protected knowledge exposure, disposition shall include limitation, restriction, correction, or controlled archive.
472.7 API, SDK, Dashboard, Test Harness, Gold Vector, Negative Test, and Reference Implementation Disposition. APIs, SDKs, dashboards, dashboard code, map tools, test harnesses, gold vectors, negative tests, reference implementations, benchmark tooling, evaluation harnesses, and technical profiles shall be disposed of according to license, security, dependency, data rights, public authority terms, protected knowledge, export controls, public-safe status, maintenance capacity, and successor stewardship. Dashboards and maps shall not remain public if their data is stale, unsupported, unsafe, public authority-sensitive, protected-knowledge-sensitive, or likely to be mistaken for official warning or decision systems. Test assets shall be reviewed for controlled technology and cyber misuse risk.
472.8 Model Register and Model Record Disposition. Model registers and model records shall be retained, transferred, sealed, or deleted according to legal requirements, vendor terms, privacy, public authority terms, protected knowledge, research integrity, AI governance, incident response needs, and archive obligations. Disposition shall address model identity, approved uses, prohibited uses, versions, provider terms, data classes, human review requirements, AI incidents, restrictions, suspensions, deprecations, retirements, correction records, prompts or inference records where retained, embeddings, retrieval indexes, and vector stores. Model records shall not be publicly released where they expose sensitive data, protected knowledge, security weaknesses, or misuse pathways.
472.9 Dataset Card, Model Card, System Card, Benchmark Card, and Evaluation Harness Disposition. Dataset cards, model cards, system cards, benchmark cards, evaluation harnesses, method libraries, and related AI governance artifacts shall be reviewed for public-safe release, transfer, archive, sealing, or deletion. These artifacts shall preserve transparency and correctionability where lawful while protecting confidential, public authority-sensitive, protected knowledge, cyber-sensitive, infrastructure-sensitive, privacy-sensitive, or export-controlled information. Public versions may be redacted or summarized. Disposition shall not imply certification, safety approval, public authority approval, procurement approval, finance-readiness, or guarantee.
472.10 Publication Disposition. Publications shall be reviewed on dissolution for current, superseded, withdrawn, retracted, archived, public-safe, controlled, restricted, or confidential status. Websites, reports, whitepapers, decks, datasets, public dashboards, maps, repositories, articles, social media, public authority materials, sponsor materials, provider materials, and annual reports shall be preserved, redirected, archived, corrected, withdrawn, or marked historical as appropriate. Publications shall include archive status, correction path, non-reliance language, and boundary language where needed. Unsafe or misleading publications shall not remain active without correction.
472.11 Research Record Disposition. Research records shall be disposed of according to law, research ethics, agreements, public authority terms, data rights, privacy, human-subjects requirements, community protocols, Indigenous rights, protected knowledge, sponsor or funder terms, publication obligations, correctionability, misconduct obligations, retention requirements, and archive rules. Research records may be transferred to qualified custodians only where authorized. Records required for integrity, reproducibility, disputes, legal holds, or correction shall be preserved under appropriate access controls.
472.12 Evidence and Methods Record Disposition. Evidence and methods records shall be preserved, transferred, sealed, restricted, deleted, or archived according to source permissions, data rights, classification, public authority terms, protected knowledge restrictions, reproducibility needs, correction needs, public-safe publication needs, and legal requirements. Evidence packs, source records, provenance records, custody records, timestamps, method notes, limitations, confidence records, uncertainty records, correction records, supersession records, and downstream dependency records shall remain traceable where lawful and necessary. Evidence and methods records shall not be used post-dissolution to imply current GCRI Canada authority.
472.13 Repository Transfer. Repository transfer may occur where lawful and appropriate to preserve public-good technical assets, maintain open technical baselines, support successor stewardship, or satisfy grant, donor, contract, or public-benefit obligations. Transfer shall require review of ownership, licenses, contributor terms, secrets, access rights, branch protections, issue histories, pull requests, release artifacts, dependencies, vulnerabilities, public authority materials, protected knowledge, export controls, sanctions, public-safe status, and recipient capacity. Repository transfer shall include transfer records, successor obligations, public language, and correction path.
472.14 Repository Archival. Repository archival may be used where transfer or continued maintenance is not appropriate. Archival shall mark status clearly as archived, superseded, deprecated, retired, historical, restricted, or no longer maintained. Repository archival shall remove or rotate secrets, restrict sensitive issues, preserve licenses, preserve release history where lawful, identify vulnerabilities where appropriate, include limitation language, identify successor resources where any, and prevent reliance on archived materials as current. Archive status shall be visible to users.
472.15 Open-License Continuity Where Lawful and Public-Safe. Where lawful, consistent with IP rights, contributor terms, data rights, security, public authority terms, protected knowledge, export controls, and public-safe status, GCRI Canada may preserve open-license continuity for public-good software, schemas, ontologies, controlled vocabularies, technical baselines, test harnesses, documentation, and publications. Open-license continuity shall not apply to restricted data, protected knowledge, confidential materials, public authority-sensitive materials, cyber-sensitive materials, controlled technology, or materials that would create unsafe reliance. Open materials shall include archive status and limitations where needed.
472.16 Restricted Asset Sealing, Transfer, Deletion, or Retirement. Restricted assets shall be sealed, transferred, deleted, retired, or otherwise controlled according to law, contract, privacy, public authority terms, protected knowledge restrictions, Indigenous governance protocols, community protocols, cybersecurity, export controls, sanctions controls, legal holds, and records obligations. Restricted assets may include confidential records, public authority materials, personal information, health-sensitive data, protected knowledge, cyber-sensitive information, infrastructure-sensitive materials, finance-sensitive evidence, controlled annexes, model records, embeddings, retrieval indexes, and unpublished research. Disposition shall be documented and verified.
472.17 Successor Steward Designation Where Lawful and Appropriate. GCRI Canada may designate a successor steward for public-good technical assets, publications, repositories, datasets, schemas, ontologies, controlled vocabularies, evidence and methods records, or other assets where lawful and appropriate. A successor steward shall be selected based on legal eligibility, public-benefit mission compatibility, technical capacity, data / AI / cyber readiness, safeguards capability, public authority term compliance, IP capability, repository capacity, correctionability, and non-capture. Successor stewardship shall not create merger, agency, shared liability, public authority delegation, finance-readiness, certification, recognition, procurement approval, or provider preference.
472.18 Public-Good Technical Asset Disposition Records. GCRI Canada shall maintain public-good technical asset disposition records, including disposition purpose records, software disposition records, open technical baseline disposition records, dataset disposition records, schema disposition records, ontology and controlled vocabulary disposition records, API / SDK / dashboard / test harness / gold vector / negative test / reference implementation disposition records, model register and model record disposition records, dataset card / model card / system card / benchmark card / evaluation harness disposition records, publication disposition records, research record disposition records, evidence and methods record disposition records, repository transfer records, repository archival records, open-license continuity records, restricted asset sealing / transfer / deletion / retirement records, successor steward designation records, legal review records, public-safe notices, closeouts, and archives.
Section 473. Data, Public Authority Materials, Community-Protected Materials, Protected Knowledge, Records, Legal Holds, and Privacy Duties on Dissolution
473.1 Data Disposition Purpose. On dissolution, wind-up, discontinuance, transfer, archival, or orderly closure of GCRI Canada or any material program, repository, data room, controlled room, public-good technical asset, Observatory interface, Academy activity, research activity, public authority interface, or Nexus-compatible interface, GCRI Canada shall dispose of data and records in a lawful, secure, privacy-protective, public-safe, role-separated, non-executing, and correctionable manner. Data disposition shall preserve applicable Canadian law, public authority terms, privacy rights, Indigenous rights, community protocols, research ethics, confidentiality, cybersecurity, legal holds, litigation holds, regulatory holds, public-benefit purpose, public-good asset stewardship, and Nexus role separation. No dissolution-related urgency shall justify uncontrolled disclosure, unsafe transfer, unapproved AI processing, loss of custody, deletion contrary to legal hold, public authority misdescription, protected knowledge exposure, or weakening of correctionability.
473.2 Personal Information Disposition. Personal information held by GCRI Canada shall be identified, classified, minimized, retained, transferred, returned, deleted, anonymized, sealed, or archived in accordance with applicable privacy law, notices, consents where applicable, contracts, records policies, legal holds, public authority terms, research obligations, employment or contractor obligations, and the dissolution plan. Personal information may include information concerning directors, officers, members where applicable, employees, contractors, fellows, advisors, volunteers, contributors, subscribers, donors, sponsors, providers, hosts, partners, Academy participants, public authority participants, research participants, community participants, complainants, whistleblowers, and other identifiable persons. Personal information shall not be transferred to a successor, custodian, vendor, archive, federation entity, public authority, sponsor, provider, National Consortium Company, Project SPV, or partner unless lawful authority, purpose, privacy review, confidentiality, security, and records support the transfer.
473.3 Rights-Bearing Data Disposition. Rights-bearing data, including data connected to persons, communities, Indigenous Peoples, public authorities, vulnerable communities, protected participants, employees, contractors, research participants, health-related contexts, public-sector contexts, or other rights-bearing relationships, shall receive heightened disposition review. Rights-bearing data disposition shall identify the rights affected, lawful basis, consent or non-consent status where applicable, withdrawal rights, access and correction rights, confidentiality, safeguards, public authority restrictions, Indigenous or community governance requirements, AI-use restrictions, transfer restrictions, retention obligations, deletion obligations, and remedy pathways. Rights-bearing data shall not be treated as ordinary institutional property merely because it is held in GCRI Canada systems.
473.4 Public Authority Data Disposition. Public authority data shall be disposed of according to the relevant public authority data contribution terms, lawful basis, permitted use, prohibited use, AI-use restrictions, publication restrictions, transfer restrictions, retention and deletion requirements, classification, confidentiality, cybersecurity, public authority review rights where applicable, public-safe release controls, and correction path. Public authority data may require return to the public authority, deletion, sealing, restricted archival, transfer to an authorized successor, or continued retention under legal hold. Dissolution shall not convert public authority data into open data, federation-common data, sponsor-accessible data, provider-accessible data, finance-reader material, AI-training material, or public-safe publication material.
473.5 Health-Sensitive Data Disposition. Health-sensitive data, including personal health information, public health information, health-system data, health-related research data, health facility data, health workforce data, health infrastructure data, and health-sensitive community data, shall be disposed of under heightened privacy, confidentiality, public authority, research ethics, cybersecurity, and safeguards review. Such data shall not be transferred, archived, disclosed, anonymized, aggregated, AI-processed, mapped, or published unless lawful authority, data rights, privacy protections, public authority terms, health-specific requirements, and public-safe review support the action. Where disposition risk cannot be adequately controlled, deletion, return, sealing, or restricted custody shall be preferred.
473.6 Cyber-Sensitive Data Disposition. Cyber-sensitive data, including vulnerability records, security telemetry, incident records, access logs, credential records, secrets histories, penetration testing records, repository security findings, threat intelligence, infrastructure exposure data, model-security findings, AI prompt-injection findings, supplier security findings, and cybersecurity incident materials, shall be disposed of under cybersecurity and legal review. Cyber-sensitive data may require restricted archival, sealing, secure deletion, transfer to a qualified custodian, insurer or counsel preservation, or public authority notice where required. It shall not be disclosed publicly, transferred casually, included in public reports, or released to successors without need, competence, security controls, and records.
473.7 Infrastructure-Sensitive Data Disposition. Infrastructure-sensitive data, including information about utilities, ports, telecom systems, energy systems, water systems, food systems, public works, health systems, cyber systems, transport systems, AI-RAN / O-RAN infrastructure, DePIN systems, sensors, digital twins, geospatial layers, Earth observation outputs, critical facilities, dependencies, vulnerabilities, degraded-mode conditions, or public infrastructure operators, shall be disposed of in a manner that prevents physical, cyber, public safety, market, or public authority harm. Such data shall be reviewed for aggregation, masking, redaction, return, sealing, deletion, restricted transfer, or controlled archival. It shall not remain publicly accessible merely because it supported a public-good activity.
473.8 Community-Protected Data Disposition. Community-protected data shall be disposed of according to applicable community protocols, consent, non-consent, withdrawal, confidentiality, attribution, non-attribution, public-safe mapping restrictions, safeguards, grievance outcomes, remedy commitments, data-sharing terms, and do-no-harm obligations. Community-protected data may include community vulnerability information, local hazard memory, environmental observations, cultural context, community participation records, location-sensitive materials, and data whose misuse could stigmatize, expose, burden, or harm a community. Disposition shall prioritize community protection, not institutional convenience, public visibility, sponsor reporting, provider reuse, or technical preservation.
473.9 Indigenous / Local / Territorial Knowledge Disposition. Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, land-use knowledge, water knowledge, cultural site information, environmental knowledge, treaty- or rights-relevant information, and knowledge held under Indigenous, local, territorial, or community governance shall be disposed of only in accordance with applicable law, Indigenous governance protocols, community protocols, consent or non-consent, FPIC where applicable, custodianship requirements, attribution or non-attribution rules, withdrawal rights, transfer restrictions, AI-use restrictions, mapping restrictions, publication restrictions, and public-safe safeguards. Such knowledge shall not be transferred to successor stewards, public repositories, AI systems, sponsors, providers, public authority interfaces, or technical baselines unless authority and safeguards clearly support the action.
473.10 Protected Knowledge Disposition. Protected knowledge shall be identified, classified, and disposed of under heightened safeguards review. Protected knowledge may require return to the knowledge holder, deletion, sealing, masking, aggregation, restricted archival, restricted transfer to an authorized custodian, exclusion from public materials, exclusion from AI systems, exclusion from technical baselines, or preservation under legal hold. Protected knowledge shall not be treated as an asset available for distribution, open licensing, sponsor reporting, provider learning, model training, public mapping, public dashboards, or finance-reader materials. Any disposition decision shall record the authority, safeguards basis, public-safe basis, and correction path.
473.11 Whistleblower and Protected Participant Record Disposition. Whistleblower records, protected participant records, grievance records, dissent records, anti-retaliation records, confidential reporting records, complaint records, investigation records, remedy records, and related identity-sensitive materials shall be disposed of in a manner that protects confidentiality, non-retaliation, legal rights, privacy, evidentiary integrity, legal holds, and remedy obligations. These records shall not be transferred, disclosed, or archived in a manner that exposes reporters, complainants, witnesses, affected persons, vulnerable participants, or protected participants to retaliation, stigma, legal risk, public authority misuse, sponsor misuse, provider misuse, or reputational harm. Access shall be strictly limited.
473.12 Legal Holds. Legal holds shall suspend deletion, alteration, transfer, destruction, or routine disposal of records and data subject to actual or reasonably anticipated litigation, investigation, claim, audit, regulatory inquiry, public authority request, insurance matter, employment matter, contract dispute, research integrity matter, public authority dispute, data incident, cyber incident, AI incident, safeguards matter, whistleblower matter, or other legal process. Legal holds shall identify scope, custodian, affected systems, affected repositories, affected data rooms, affected controlled rooms, affected archives, preservation instructions, review dates, and release conditions. Legal holds shall survive dissolution to the extent required by law or competent authority.
473.13 Regulatory Holds. Regulatory holds shall preserve records, data, communications, technical materials, financial records, public authority records, privacy records, AI records, cyber records, research records, sanctions records, export-control records, competition records, public-safe publication records, or other materials subject to regulator, government, court, corporate registry, tax authority, privacy commissioner, funder, public authority, or other competent authority requirement. Regulatory holds shall override routine deletion and shall be coordinated with legal review, records custodians, technical administrators, and successor custodians where relevant.
473.14 Litigation Holds. Litigation holds shall preserve records, data, correspondence, drafts, notes, logs, system records, repository history, publication records, evidence records, methods records, public authority records, sponsor and provider records, employee and contractor records, and other materials relevant to litigation or anticipated litigation. Litigation holds shall be documented, communicated to affected custodians, technically implemented where necessary, and monitored for compliance. Dissolution shall not be used to delete or transfer litigation-hold materials outside appropriate custody.
473.15 Deletion. Deletion shall be used where required by law, privacy obligation, data-sharing term, public authority term, community protocol, Indigenous governance protocol, contract, retention schedule, risk review, or dissolution plan, and where no legal hold, regulatory hold, litigation hold, archival duty, research integrity duty, public authority duty, or correctionability duty requires retention. Deletion shall be secure, verifiable where appropriate, documented, and proportionate to data sensitivity. Deletion shall include primary systems, backups where feasible and required, repositories, AI tool memory, embeddings, vector stores, caches, exports, local copies, personal drives, temporary files, dashboards, maps, and third-party processors where applicable.
473.16 Sealing. Sealing may be used where records must be preserved but access must be restricted because of confidentiality, privilege, public authority sensitivity, protected knowledge, privacy, whistleblower protection, cyber sensitivity, infrastructure sensitivity, finance sensitivity, research integrity, personnel sensitivity, sanctions, export controls, or legal hold. Sealed records shall identify sealing authority, reason, access conditions, review date, custodian, retention period, permitted disclosures, and unsealing conditions. Sealing shall not be used to conceal misconduct, avoid correction, frustrate lawful rights, or hide public-safe overclaims.
473.17 Archival. Archival may be used to preserve records, datasets, publications, technical assets, evidence, methods, corporate records, public authority records, research records, correction records, and dissolution records where retention is lawful and necessary for accountability, public-good continuity, legal compliance, research integrity, technical traceability, or correctionability. Archives shall be classified, access-controlled, versioned, marked with status, protected against unauthorized alteration, and reviewed for secure disposal when retention expires. Archived materials shall not be presented as current, operative, endorsed, public authority-approved, finance-ready, certified, recognized, or execution-capable.
473.18 Transfer to Authorized Successor. Data or records may be transferred to an authorized successor only where lawful authority, Board approval or delegated authority, data rights, IP rights, privacy review, public authority terms, Indigenous or community protocols, protected knowledge safeguards, cybersecurity, export-control review, sanctions review, confidentiality, recipient capacity, public-safe status, and correction path support the transfer. Transfer instruments shall identify scope, permitted use, prohibited use, AI-use restrictions, publication restrictions, access controls, retention, deletion, onward transfer, breach response, correction obligations, and closeout. A successor shall not receive greater authority than GCRI Canada had.
473.19 Notice Where Required. GCRI Canada shall provide notice of data or record disposition where required by law, contract, privacy notice, public authority term, research ethics approval, community protocol, Indigenous governance protocol, data-sharing instrument, model-sharing instrument, evidence-sharing instrument, employment or contractor agreement, grant agreement, donor restriction, sponsor agreement, court order, regulator requirement, or Board direction. Notices shall be role-specific, accurate, limitation-bearing, public-safe, and shall not imply public authority endorsement, public warning, finance-readiness, certification, recognition, procurement approval, or successor endorsement unless lawfully recorded.
473.20 Data and Records Disposition Logs. GCRI Canada shall maintain data and records disposition logs, including data disposition purpose records, personal information disposition records, rights-bearing data disposition records, public authority data disposition records, health-sensitive data disposition records, cyber-sensitive data disposition records, infrastructure-sensitive data disposition records, community-protected data disposition records, Indigenous / local / territorial knowledge disposition records, protected knowledge disposition records, whistleblower and protected participant record disposition records, legal hold records, regulatory hold records, litigation hold records, deletion records, sealing records, archival records, authorized successor transfer records, notice records, verification records, residual risk records, closeouts, and archives.
Section 474. Contracts, Liabilities, Employees, Contractors, Leases, Licenses, Software, Cloud Resources, Insurance, and Closeout
474.1 Contract Closeout Purpose. On dissolution, wind-up, discontinuance, transfer, or orderly closure, GCRI Canada shall close out contracts, liabilities, employment and contractor relationships, leases, licenses, software services, cloud resources, repository services, AI providers, data processors, technical services, insurance, access rights, credentials, keys, tokens, secrets, and related obligations in a lawful, orderly, secure, financially disciplined, public-benefit aligned, non-executing, and record-supported manner. Contract closeout shall preserve creditor rights, restricted-fund obligations, donor restrictions, grant restrictions, sponsor terms, public authority terms, data / AI / cyber obligations, IP rights, confidentiality, protected knowledge safeguards, legal holds, correctionability, and public-safe communications.
474.2 Contract Inventory. GCRI Canada shall prepare a contract inventory identifying all active, dormant, expired-but-surviving, disputed, contingent, oral, draft-but-relied-upon, and renewal-pending arrangements, including grants, donations, sponsorships, subscriptions, service agreements, research agreements, data-sharing agreements, model-sharing agreements, evidence-sharing agreements, public authority interface agreements, MOUs, federation instruments, authorization packs, IP agreements, license agreements, employment agreements, contractor agreements, leases, software agreements, cloud agreements, AI provider agreements, repository agreements, insurance policies, vendor agreements, host agreements, provider agreements, partner agreements, and confidentiality agreements. The inventory shall identify parties, term, termination rights, survival clauses, payment obligations, data obligations, IP obligations, notice obligations, and closeout owner.
474.3 Liability Inventory. GCRI Canada shall prepare a liability inventory identifying debts, accounts payable, accrued liabilities, payroll or contractor obligations, tax liabilities, lease liabilities, vendor obligations, grant obligations, donor obligations, sponsorship obligations, subscription obligations, refund obligations, indemnity obligations, insurance obligations, litigation or dispute exposures, privacy obligations, cyber incident obligations, data disposition obligations, public authority obligations, research obligations, IP obligations, employment obligations, contractual survival obligations, and contingent liabilities. Each liability shall be assigned an owner, status, priority, evidence, payment or resolution plan, legal review need, and closeout record.
474.4 Grant Agreement Closeout. Grant agreements shall be closed out according to grant terms, reporting obligations, eligible-use restrictions, deliverable requirements, audit rights, unspent fund treatment, repayment obligations, IP terms, publication terms, data terms, public authority terms where applicable, confidentiality, research integrity, public-benefit purpose, and records. Grant closeout shall identify completed deliverables, incomplete deliverables, permitted substitutions, unspent balances, restricted assets, public-good technical assets, data disposition, publication disposition, and final reporting. GCRI Canada shall not use dissolution to avoid grant accountability or convert grant-funded assets to private benefit.
474.5 Donation Agreement Closeout. Donation agreements and restricted gifts shall be closed out according to donor restrictions, gift terms, public-benefit purpose, tax treatment, accounting treatment, refund or reallocation rules, naming or acknowledgment rules, confidentiality, public claims controls, and applicable law. Donor closeout shall not permit donor control over GCRI Canada governance, research conclusions, public authority relationships, public-good technical assets, protected knowledge, publication corrections, or asset distribution except as lawfully provided in the donor restriction. Any unresolved donor restriction shall receive legal review.
474.6 Sponsorship Agreement Closeout. Sponsorship agreements shall be closed out according to sponsorship terms, benefit schedules, acknowledgment language, logo use, event obligations, unused benefits, refund obligations where any, confidentiality, public claims controls, sponsor non-control, public authority access restrictions, data restrictions, and records. Sponsor closeout shall include removal or correction of sponsor references where required, discontinuation of benefits, access revocation, correction of overclaims, and archive notation. Sponsorship shall not confer asset distribution rights, governance rights, public authority access rights, finance-readiness influence, certification influence, procurement advantage, or correction veto rights.
474.7 Service Agreement Closeout. Service agreements with vendors, consultants, professional advisors, technical providers, cloud providers, AI providers, cybersecurity providers, software providers, communications providers, payment processors, records systems, event providers, and other service providers shall be closed out according to termination terms, payment obligations, data return, data deletion, confidentiality, IP ownership, licenses, work product transfer, security obligations, incident notice, audit rights, transition assistance, access revocation, and records. Service providers handling sensitive materials shall provide deletion or return certification where appropriate.
474.8 Research Agreement Closeout. Research agreements shall be closed out according to research scope, deliverables, ethics approvals, human-subjects obligations where applicable, community protocols, Indigenous rights, protected knowledge, data rights, publication rights, IP terms, authorship, attribution, sponsor or funder terms, confidentiality, research records, correction obligations, and archive requirements. Research closeout may require transfer to authorized custodians, deletion, sealing, publication hold, correction, or retraction. Research agreements shall not be closed in a manner that suppresses negative findings, erases misconduct records, or exposes protected participants.
474.9 Data-Sharing Agreement Closeout. Data-sharing agreements shall be closed out according to permitted use, prohibited use, retention, deletion, return, transfer restrictions, AI-use restrictions, publication restrictions, public authority terms, privacy, cybersecurity, protected knowledge, cross-border transfer, processor obligations, breach response, and correction. Closeout shall identify all copies, extracts, summaries, embeddings, derived data, backups, dashboards, maps, AI tool inputs, repository files, and downstream dependencies. Data-sharing closeout shall be verified where appropriate.
474.10 Public Authority Interface Agreement Closeout. Public authority interface agreements, MOUs, data contribution records, public authority learning records, controlled-room records, regulator-listening records, public finance reader records, emergency-management participant records, public infrastructure operator records, and public authority-facing instruments shall be closed out with attention to notice, capacity classification, public authority data disposition, reference permissions, confidentiality, public-safe publication, non-endorsement language, no-delegation, no-PPP, no-public-warning, no-emergency-command, no-procurement, no-funding-approval, no-public-finance-approval, and correction. Public authority closeout shall not imply adoption, approval, or continuation of authority.
474.11 IP and License Agreement Closeout. IP and license agreements shall be closed out by identifying ownership, assignments, licenses, sublicenses, contributor terms, moral rights waivers or consents where applicable, open-source obligations, patent terms, trademark and marks rights, copyright notices, repository rights, technical asset rights, documentation rights, third-party IP, derivative works, background IP, foreground IP, data rights, survival terms, termination rights, public-good asset transfer, and archive rights. IP closeout shall prevent unauthorized release, enclosure of public-good assets contrary to terms, private appropriation, license breach, and loss of correctionability.
474.12 Employee Closeout. Employee closeout, where applicable, shall comply with employment law, contracts, payroll obligations, benefits, expense reimbursement, statutory obligations, confidentiality, IP assignment, return of property, return or deletion of data, access revocation, keys and credentials, records, privacy, non-retaliation, protected reporting, references, and final communications. Employee closeout shall protect personal information and shall not impair legal rights, whistleblower rights, grievance rights, or ongoing obligations. Any employment-related legal hold shall be preserved.
474.13 Contractor and Consultant Closeout. Contractor and consultant closeout shall address final deliverables, work product, IP ownership, licenses, moral rights where applicable, confidentiality, data return or deletion, AI-use restrictions, repository access, public authority data, protected knowledge, invoices, expenses, tax records, conflicts, public statement limits, non-retaliation, and final certification or attestation where appropriate. Contractors and consultants shall return or securely dispose of GCRI Canada materials and shall not retain restricted materials, unpublished records, public authority materials, protected knowledge, credentials, or technical assets except as lawfully authorized.
474.14 Fellow, Advisor, Volunteer, and Participant Closeout. Fellows, advisors, volunteers, contributors, reviewers, committee participants, council participants, Academy participants, public authority participants, community participants, sponsors, providers, hosts, partners, and other participants shall be closed out according to their role, agreement, confidentiality, IP terms, public statement limits, access rights, data rights, public authority terms, protected knowledge restrictions, training status, expense reimbursement, records, and offboarding requirements. Closeout shall clarify that participation status does not survive as authority to represent GCRI Canada, bind GCRI Canada, claim certification, claim recognition, claim finance-readiness, claim procurement advantage, or use GCRI Canada marks except as authorized.
474.15 Leases and Facilities Closeout. Leases, facilities, labs, host sites, offices, controlled rooms, data rooms, event spaces, Academy spaces, storage areas, and equipment locations shall be closed out according to lease terms, host terms, safety obligations, security, insurance, asset removal, data removal, equipment return, environmental obligations, access revocation, public authority terms, protected knowledge, records retrieval, signage removal, and public reference updates. Facilities closeout shall confirm that no paper records, devices, storage media, credentials, protected knowledge, or controlled materials remain unsecured.
474.16 Software, Cloud, Repository, AI Provider, Data Processor, and Technical Service Closeout. Software, cloud, repository, AI provider, data processor, technical service, communications, storage, ticketing, collaboration, domain, certificate, monitoring, backup, dashboard, map, payment, and publication platform closeout shall address export, backup, data return, data deletion, account closure, access revocation, administrator transfer, logs, billing, API keys, tokens, secrets, model training settings, AI retention settings, subprocessor obligations, region settings, incident records, repository archives, dependency records, public-safe status, and successor access where lawful. Technical service closeout shall be verified and recorded.
474.17 Insurance Tail Coverage or Runoff Review. GCRI Canada shall review whether insurance tail coverage, runoff coverage, extended reporting periods, directors’ and officers’ coverage, cyber coverage, professional liability, errors and omissions, employment practices, general liability, fiduciary liability, property coverage, event coverage, or other insurance should be maintained after dissolution, wind-up, transfer, or discontinuance. Review shall consider claims-made policies, incident reporting, known circumstances, potential claims, directors and officers, employees, contractors, volunteers, fellows, advisors, public authority interfaces, cyber incidents, data incidents, publication claims, safeguards claims, and contractual obligations. Insurance decisions shall be recorded.
474.18 Access Revocation. GCRI Canada shall revoke or transition access to systems, records, repositories, data rooms, controlled rooms, dashboards, maps, cloud services, AI tools, communication channels, finance systems, payment systems, domains, public websites, social media, password managers, encryption keys, signing keys, code repositories, publication platforms, and physical locations upon closeout, termination, transfer, or dissolution. Access revocation shall be role-based, sequenced to preserve records, and verified. No person shall retain access because of prior status, public authority title, sponsor role, provider role, founder role, technical contribution, host role, or perceived continuing relationship.
474.19 Credential, Key, Token, and Secret Revocation. Credentials, keys, tokens, API keys, signing keys, encryption keys, SSH keys, cloud keys, repository tokens, AI provider keys, payment keys, certificate keys, recovery codes, administrator credentials, service accounts, secrets, passwords, and machine credentials shall be revoked, rotated, archived, transferred, or destroyed according to security review, successor needs, legal holds, and continuity requirements. Secret revocation shall include scanning repositories, build systems, documentation, local devices, CI / CD systems, cloud environments, backups where feasible, and third-party integrations. Exposed or unverified secrets shall be treated as security risk.
474.20 Contract and Liability Closeout Records. GCRI Canada shall maintain contract and liability closeout records, including contract closeout purpose records, contract inventory records, liability inventory records, grant agreement closeout records, donation agreement closeout records, sponsorship agreement closeout records, service agreement closeout records, research agreement closeout records, data-sharing agreement closeout records, public authority interface agreement closeout records, IP and license agreement closeout records, employee closeout records, contractor and consultant closeout records, fellow / advisor / volunteer / participant closeout records, lease and facilities closeout records, software / cloud / repository / AI provider / data processor / technical service closeout records, insurance tail or runoff review records, access revocation records, credential / key / token / secret revocation records, final payments, notices, certifications, corrective actions, closeouts, and archives.
Section 475. Public Claims Closeout, Website Updates, Archive Notices, Transfer Notices, and Discontinuation Notices
475.1 Public Claims Closeout Purpose. On dissolution, wind-up, discontinuance, transfer, archival, repository closure, program closure, dashboard closure, map closure, publication withdrawal, or termination of material GCRI Canada activities, GCRI Canada shall close out public claims in a manner that prevents public misunderstanding, outdated reliance, authority inflation, public authority misdescription, finance overclaim, procurement implication, certification implication, recognition implication, maturity implication, provider preference, sponsor control implication, public warning implication, emergency command implication, or false continuation of institutional activity. Public claims closeout shall ensure that public materials are corrected, archived, redirected, withdrawn, marked historical, or replaced with public-safe notices.
475.2 Website Update. GCRI Canada shall update websites, landing pages, public profiles, donation pages, subscription pages, program pages, Academy pages, public authority-facing pages, sponsor pages, provider pages, public-good technical asset pages, public dashboard pages, map pages, repository links, and public reports to reflect dissolution, wind-up, suspension, transfer, discontinuance, archive status, or successor stewardship where applicable. Website updates shall identify what remains current, what is archived, what is discontinued, what has transferred, what correction path remains, and what limitations apply. Website language shall preserve non-execution, non-endorsement, non-finance, non-certification, non-procurement, non-recognition, and non-public-warning boundaries.
475.3 Public Repository Notice. Public repositories shall include notices where repositories are archived, transferred, deprecated, retired, no longer maintained, security-restricted, license-changed, superseded, or successor-stewarded. Repository notices shall identify maintenance status, archive status, vulnerabilities where public-safe, security reporting path if any, license status, successor steward where any, data exclusions, public authority exclusions, protected knowledge exclusions, export-control limitations, no warranty, no certification, no procurement approval, no finance-readiness, no public authority approval, and correction or issue reporting path where any. Stale repositories shall not appear active by default.
475.4 Publication Archive Notice. Archived publications shall be marked with archive status, effective date, supersession status, withdrawal or retraction status where applicable, historical period covered, limitation language, correction history, and replacement materials where any. Publication archive notices shall prevent reliance on outdated materials as current GCRI Canada policy, official position, public authority-approved material, finance-ready material, certified material, procurement-approved material, recognized status, maturity status, public warning, emergency instruction, or operational guidance. Controlled publications shall be archived under appropriate access restrictions.
475.5 Program Discontinuation Notice. Program discontinuation notices shall be used where programs, pilots, labs, Academy pathways, fellowships, competence cells, challenges, benchmarking subscriptions, public authority learning activities, activation dockets, adoption windows, replication sprints, host activations, or other activities are discontinued, suspended, transferred, or wound down. Notices shall identify program status, effective date, participant effect, deliverable status, records status, data disposition, public authority effect, sponsor or provider effect, refund or closeout terms where any, contact point, and correction path. Notices shall not imply failure, endorsement, successor authority, public warning, procurement outcome, finance outcome, certification, or recognition.
475.6 Controlled Room Closure Notice. Controlled room, clean room, data room, evidence room, public authority room, protected knowledge room, finance-sensitive room, cyber-sensitive room, research room, or technical review room closure notices shall identify closure date, access termination, data disposition, export restrictions, confidentiality survival, AI-use restrictions, public authority terms, protected knowledge terms, deletion or return obligations, output review, surviving restrictions, and contact point. Closure notices shall not authorize participants to retain, publish, disclose, reuse, train models on, or transfer controlled-room materials unless expressly permitted by the governing instrument.
475.7 Public Authority Reference Update. GCRI Canada shall update public authority references to reflect dissolution, wind-up, discontinuance, transfer, archive status, or correction. Updates shall address public authority names, titles, agency references, logos, quotes, photos, attendance, data contributions, workshops, public authority learning, dashboards, maps, controlled-room participation, public infrastructure operator references, regulator-listening references, public finance reader references, and emergency-management references. Updates shall include non-endorsement and no-delegation language where needed and shall avoid implying continuing public authority participation, approval, adoption, funding, procurement, public finance approval, public warning, emergency command, or sovereign obligation.
475.8 Sponsor, Donor, Funder, Provider, Host, Partner, and Participant Reference Update. GCRI Canada shall update references to sponsors, donors, funders, providers, hosts, partners, participants, universities, laboratories, communities, National Consortium Companies, Project SPVs, and other stakeholders where dissolution or discontinuance affects the reference. Updates shall remove or qualify outdated acknowledgments, logos, partner language, provider descriptions, host descriptions, sponsor benefits, donor reports, participant lists, and public claims. Updates shall prevent any implication that a sponsor, donor, funder, provider, host, partner, or participant controls dissolution, inherits authority, receives endorsement, receives procurement preference, receives certification, receives recognition, receives finance-readiness, or assumes GCRI Canada status.
475.9 GCRI US, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Consortium, National Company, Project SPV, and Provider Interface Notice Where Relevant. Where dissolution, wind-up, discontinuance, transfer, archive, or repository closure affects interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, National Consortium Companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, or partners, GCRI Canada may issue interface notices. Interface notices shall preserve legal separateness, no shared treasury, no shared liability, no merger, no agency, no substitution, no GRF recognition by GCRI Canada, no GRA finance-readiness by GCRI Canada, no protocol authority by GCRI Canada unless separately lawful, and no enterprise execution by GCRI Canada.
475.10 Transfer Notice Where Assets or Records Transfer. Where assets, records, repositories, public-good technical assets, datasets, schemas, ontologies, publications, public authority materials, protected knowledge, research records, evidence records, methods records, software, technical baselines, or other materials transfer to an authorized successor, GCRI Canada shall provide transfer notice where required or appropriate. Transfer notice shall identify transferred materials, excluded materials, recipient, authority, effective date, permitted use, limitations, public-safe status, data / AI / cyber restrictions, public authority terms, protected knowledge restrictions, correction path, and contact point. Transfer notice shall not imply endorsement of the successor beyond the transfer record.
475.11 Archive Notice Where Assets or Records Archive. Where assets, records, publications, repositories, technical baselines, dashboards, maps, datasets, reports, public authority materials, research records, or evidence and methods records are archived, GCRI Canada shall provide archive notice where required or appropriate. Archive notice shall identify status as historical, superseded, discontinued, deprecated, retired, withdrawn, restricted, or no longer maintained; effective date; access terms; limitations; correction path; and successor materials where any. Archive notice shall prevent users from treating archived materials as current or operative.
475.12 Discontinuation Notice Where Services, Programs, Repositories, Dashboards, or Publications End. Where services, programs, repositories, dashboards, maps, publications, Academy offerings, subscriptions, benchmarking activities, challenge programs, controlled rooms, data rooms, or public-good technical assets end, GCRI Canada shall provide discontinuation notice where required or appropriate. Discontinuation notice shall identify what is ending, when, why if public-safe, participant effect, data effect, access effect, public authority effect, sponsor and provider effect, refund or closeout path where any, correction path, and archive status. Discontinuation notice shall be factual and shall not create reliance on continued support.
475.13 Non-Reliance and Non-Execution Language in Closeout Notices. Closeout notices shall include non-reliance and non-execution language where the materials could be used to infer current status, authority, approval, certification, finance-readiness, procurement suitability, public authority decision, public warning, emergency command, technical warranty, safety guarantee, or operational instruction. Language shall state, as applicable, that GCRI Canada materials are not investment advice, insurance advice, underwriting, lending approval, rating, public finance approval, procurement approval, certification, accreditation, recognition, maturity determination, public authority decision, official warning, emergency command, provider endorsement, or execution instruction.
475.14 Correction of Outdated Public Claims. GCRI Canada shall correct outdated public claims discovered during closeout, including claims repeated by third parties where GCRI Canada has reasonable ability to request correction. Correction may include website update, repository notice, archive notice, public-safe clarification, controlled notice, sponsor or provider notice, public authority clarification, social media correction, media correction, search-result correction request where appropriate, downstream material update, or replacement publication. GCRI Canada shall prioritize correction of claims involving public authority approval, finance-readiness, certification, procurement, recognition, public warning, emergency command, protected knowledge, data leakage, or cyber-sensitive disclosure.
475.15 Public Claims Closeout Records. GCRI Canada shall maintain public claims closeout records, including public claims closeout purpose records, website update records, public repository notice records, publication archive notice records, program discontinuation notice records, controlled room closure notice records, public authority reference update records, sponsor / donor / funder / provider / host / partner / participant reference update records, Nexus interface notice records, transfer notice records, archive notice records, discontinuation notice records, non-reliance and non-execution language records, outdated public claim correction records, approvals, notices, public-safe communications, controlled communications, closeouts, and archives.
Section 476. Survival of Confidentiality, Privacy, Data Protection, Cybersecurity, IP, Records, Correctionability, Non-Execution, Non-Endorsement, Public Authority Boundaries, Finance Boundaries, and Dispute Provisions
476.1 Survival Purpose. Dissolution, wind-up, termination, transfer, program closeout, repository archival, participant offboarding, contract termination, sponsorship closeout, provider closeout, public authority interface closeout, or discontinuance of GCRI Canada activities shall not extinguish duties that by law, contract, policy, equity, public-benefit purpose, data rights, public authority terms, safeguards, records discipline, or this Bylaw must survive. Survival provisions shall protect confidentiality, privacy, data protection, cybersecurity, IP, records, legal holds, correctionability, non-execution, non-endorsement, public authority boundaries, finance boundaries, procurement boundaries, certification boundaries, recognition boundaries, non-reliance, limitation language, dispute processes, enforcement, indemnification, insurance, and liability protections where lawful.
476.2 Confidentiality Survival. Confidentiality obligations shall survive dissolution, wind-up, closeout, termination, transfer, offboarding, archive, or discontinuance to the extent required by law, contract, policy, public authority terms, research ethics, protected knowledge safeguards, legal privilege, whistleblower protections, personnel obligations, sponsor or donor terms, provider terms, host terms, partner terms, or Board-approved records. Confidential information shall not become public merely because GCRI Canada dissolves or a program ends. Former directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, participants, sponsors, providers, hosts, partners, and committee or council participants shall remain bound where obligations survive.
476.3 Privacy Duty Survival. Privacy duties shall survive dissolution and closeout to the extent required by law, privacy notices, consent terms, contracts, records policies, public authority terms, research obligations, employment obligations, or data disposition plans. Surviving privacy duties may include confidentiality, access protection, correction rights, deletion obligations, breach response, processor obligations, retention, secure disposal, notice, and complaint handling. Personal information shall not be used, disclosed, transferred, AI-processed, archived, or published post-dissolution except as lawfully authorized.
476.4 Data Protection Survival. Data protection obligations shall survive where data, records, backups, archives, repositories, logs, dashboards, maps, AI records, public authority materials, protected knowledge, research data, or technical assets remain in existence or under successor custody. Surviving duties may include classification, access control, purpose limitation, transfer restrictions, retention, deletion, encryption, audit logs, processor controls, breach response, public authority terms, protected knowledge restrictions, and correction paths. Data protection shall not lapse because active operations have ceased.
476.5 Cybersecurity Duty Survival. Cybersecurity duties shall survive for systems, repositories, archives, domains, email accounts, cloud accounts, AI tools, dashboards, maps, backups, technical assets, credentials, keys, tokens, secrets, and records that remain active, archived, transferred, or accessible after dissolution or closeout. Surviving duties may include access revocation, credential rotation, repository archival, vulnerability notice, secure configuration, monitoring where feasible, incident response, backup protection, deletion verification, and secure disposal. Dormant systems shall not be left exposed.
476.6 Protected Knowledge Duty Survival. Duties relating to protected knowledge, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural site information, environmental knowledge, community-protected materials, vulnerable community information, remote community information, and protected participation records shall survive dissolution, transfer, archive, or closeout according to law, consent, non-consent, FPIC where applicable, community protocols, Indigenous governance protocols, safeguards, confidentiality, data-sharing terms, and public-safe commitments. Protected knowledge shall not lose protection because a project, program, repository, or organization ends.
476.7 Public Authority Data Duty Survival. Public authority data duties shall survive according to law, contract, data contribution terms, public authority records, confidentiality, cybersecurity, retention, deletion, transfer restrictions, publication restrictions, AI-use restrictions, public-safe review requirements, and correction obligations. Public authority data shall not be treated as abandoned, common, open, successor-owned, sponsor-accessible, provider-accessible, or unrestricted upon dissolution. Any successor custodian shall be bound by public authority terms to the extent permitted and required.
476.8 IP and License Duty Survival. IP ownership, licenses, open-source obligations, contributor terms, moral rights waivers or consents where applicable, patent terms, trademark and marks restrictions, copyright notices, repository licenses, confidentiality restrictions, third-party IP obligations, and technical asset licenses shall survive dissolution or closeout according to their terms and law. Survival shall protect public-good continuity where lawful and prevent unauthorized enclosure, misuse of marks, license breach, false endorsement, misattribution, or public claims beyond the license. GCRI Canada marks shall not be used post-dissolution except as authorized.
476.9 Records Duty Survival. Records duties shall survive where records must be preserved for corporate law, tax, audit, grants, donations, sponsorships, contracts, public authority terms, privacy, data / AI / cyber, research integrity, safeguards, legal holds, litigation, insurance, employment, IP, public-safe publication, correctionability, or dissolution closeout. Surviving records duties may include retention, access control, archival, sealing, secure disposal, version history, chain of custody, correction records, and final custodian designation. Records shall remain traceable and protected.
476.10 Legal Hold Survival. Legal holds, regulatory holds, litigation holds, audit holds, investigation holds, public authority holds, privacy holds, cyber incident holds, AI incident holds, safeguards holds, research misconduct holds, whistleblower holds, and insurance holds shall survive dissolution or closeout until lawfully released by competent authority. No dissolution, asset distribution, repository archival, data deletion, system closure, or successor transfer shall defeat an active hold. Hold release shall be documented.
476.11 Correctionability Survival. Correctionability shall survive dissolution and closeout to the extent records, public materials, archived materials, transferred assets, public-good technical assets, repositories, publications, public authority references, sponsor references, provider references, dashboards, maps, datasets, software, technical baselines, evidence records, methods records, or Nexus interface records continue to exist or be relied upon. Surviving correctionability may include public-safe clarification, archive note, erratum, withdrawal note, repository notice, successor notice, public authority clarification, sponsor or provider correction request, and final custodian correction process.
476.12 Non-Execution Boundary Survival. The non-execution boundary shall survive dissolution, closeout, transfer, archive, and successor stewardship. No former activity, public material, repository, dashboard, map, technical baseline, proof receipt, Academy record, program record, public authority session, sponsor material, provider material, or successor transfer shall imply that GCRI Canada acted or continues to act as an operator, public authority, emergency command body, public warning body, procurement agent, finance arranger, insurer, lender, underwriter, rating agency, certification body, recognition body, provider selector, National Consortium Company, Project SPV, or execution vehicle.
476.13 Non-Endorsement Survival. Non-endorsement obligations shall survive with respect to sponsors, donors, funders, providers, hosts, partners, public authorities, universities, laboratories, communities, National Consortium Companies, Project SPVs, successors, repositories, technical assets, publications, and participants. No archived reference, prior acknowledgment, logo, quote, attendance record, participation record, public authority reference, technical contribution, donation, sponsorship, grant, host relationship, or successor stewardship shall imply endorsement, approval, control, public authority adoption, procurement preference, provider preference, certification, recognition, maturity, finance-readiness, or public legitimacy unless separately lawful and accurately stated.
476.14 Public Authority Boundary Survival. Public authority boundary language and duties shall survive dissolution and closeout. Public authority participation, data contribution, attendance, regulator-listening, public finance reader status, emergency-management participation, public infrastructure operator participation, logos, quotes, and public authority-facing materials shall not be reinterpreted after dissolution as endorsement, adoption, delegation, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, public policy adoption, or public infrastructure adoption. Corrections shall be issued where post-dissolution misunderstanding arises and a correction path exists.
476.15 Finance, Insurance, Investment, Lending, Underwriting, Rating, Public Finance, Procurement, Certification, Recognition, and Public Warning Boundary Survival. Boundary duties concerning finance-readiness, insurance-readiness, investment advice, securities solicitation, capital placement, brokerage, finder activity, underwriting, lending, guarantee, rating, public finance approval, procurement approval, vendor selection, certification, accreditation, compliance approval, conformance approval, recognition, standing, maturity, Docket status, Grid status, public warning, emergency command, public authority decision, and official adoption shall survive dissolution and closeout. Archived or transferred materials shall not be used to imply these statuses. Non-reliance and boundary language shall remain operative where needed.
476.16 Non-Reliance and Limitation Language Survival. Non-reliance, limitation, uncertainty, evidence limitation, methods limitation, AI limitation, dashboard limitation, map limitation, Observatory limitation, proof receipt limitation, technical baseline limitation, public authority non-endorsement, sponsor non-control, provider neutrality, non-finance, non-certification, non-procurement, non-recognition, non-public-warning, and non-execution language shall survive for archived, transferred, public, controlled, or successor-stewarded materials where needed to prevent reliance beyond scope. Removal of limitation language from archived materials is prohibited unless lawfully approved and not misleading.
476.17 Dispute, Enforcement, Indemnification, Insurance, and Liability Provision Survival Where Lawful. Dispute resolution, enforcement, remedies, sanctions, appeals, indemnification, advancement, insurance, limitation of liability, confidentiality, IP, data protection, records, audit, investigation, and cooperation provisions shall survive to the extent permitted by law, contract, insurance terms, Board resolutions, and dissolution instruments. Survival may protect directors, officers, employees, contractors, volunteers, fellows, advisors, committee participants, and other eligible persons where lawful. Survival shall not protect bad faith, fraud, willful misconduct, knowing legal violation, improper private benefit, data misuse, cyber misconduct, protected knowledge breach, retaliation, or other excluded conduct where law or contract excludes protection.
476.18 Survival Records. GCRI Canada shall maintain survival records, including survival purpose records, confidentiality survival records, privacy duty survival records, data protection survival records, cybersecurity duty survival records, protected knowledge duty survival records, public authority data duty survival records, IP and license duty survival records, records duty survival records, legal hold survival records, correctionability survival records, non-execution boundary survival records, non-endorsement survival records, public authority boundary survival records, finance / insurance / investment / lending / underwriting / rating / public finance / procurement / certification / recognition / public warning boundary survival records, non-reliance and limitation language survival records, dispute / enforcement / indemnification / insurance / liability survival records, final custodian records, successor steward records, correction records, closeouts, and archives.
Section 477. Final Dissolution Records, Filings, Asset Distributions, Data Disposition, Contract Closeout, and Final Reports
477.1 Final Dissolution Record Requirement. GCRI Canada shall maintain final dissolution records sufficient to evidence that dissolution, wind-up, asset distribution, liability closeout, data disposition, public authority material disposition, protected knowledge disposition, contract closeout, public claims closeout, filings, notices, final reports, archives, and legal closure were completed lawfully, accurately, securely, and consistently with public-benefit purpose, nonprofit and non-distribution obligations, the Articles, this Bylaw, applicable law, donor restrictions, grant restrictions, public authority terms, privacy, safeguards, records duties, legal holds, and correctionability. Final dissolution records shall be treated as permanent or long-term records unless law, retention schedule, or Board-approved legal review provides otherwise.
477.2 Dissolution Approval Records. Final dissolution records shall include Board approvals, committee recommendations where any, legal review, financial review, dissolution plan, wind-up plan, approval dates, decision materials, conflicts, recusals, votes, resolutions, conditions, responsible persons, implementation authority, and final certification of completion. Approval records shall identify whether dissolution was voluntary, court-supervised, regulator-supervised, member-approved, merger-related, continuation-related, wind-up-related, or otherwise legally characterized. Approval records shall preserve the authority chain.
477.3 Member Approval Records Where Applicable. Where member approval, special resolution, class approval, written resolution, member meeting, or other member action was required, final records shall include notice, text circulated, explanatory materials, meeting records, written resolutions, quorum records, voting threshold, votes, abstentions, class approvals, conflict disclosures where applicable, approval date, effective date, filings, and certification. If members did not exist or member approval was not required, the record shall state the basis for that conclusion where material.
477.4 Regulatory, Court, Government, or Filing Records Where Required. Final dissolution records shall include corporate registry filings, court orders, regulator approvals, government approvals, tax authority filings, charity regulator filings where applicable, public authority approvals where required, grantor approvals where required, funder approvals where required, notices, certificates, receipts, confirmations, dissolution certificates, cancellation records, continuance records, amalgamation records, or equivalent legal closure records. Filing records shall identify effective dates and remaining post-dissolution obligations.
477.5 Final Financial Statements. GCRI Canada shall prepare final financial statements, financial summaries, closing statements, or comparable final financial records as required by law, accounting practice, Board direction, member rights where applicable, grant terms, donor restrictions, sponsor terms, funder terms, tax requirements, or dissolution plan. Final financial statements shall identify assets, liabilities, restricted funds, revenue, expenses, distributions, payments, reserves, contingent liabilities, tax obligations, and remaining obligations. Public-safe financial summaries may be prepared where approved, but shall not imply financial guarantee, public finance approval, investment suitability, or continuing operations.
477.6 Final Tax Filings. GCRI Canada shall complete final tax filings, information returns, payroll filings where applicable, GST / HST or other indirect tax filings where applicable, charitable filings where applicable, nonprofit filings, employer filings, contractor reporting, donor reporting, grant reporting, and other tax or fiscal filings required by law. Final tax records shall address dissolution date, final activity period, asset distribution, restricted funds, private benefit review, compensation, reimbursements, related-party payments, and any post-dissolution filing obligations. Tax filings shall be retained with dissolution records.
477.7 Final Asset Distribution Records. Final asset distribution records shall identify each asset distributed, recipient, recipient eligibility, legal authority, Board approval, member approval where applicable, donor or grant restriction, public-benefit rationale, fair value where required, transfer instrument, effective date, conditions, limitations, restricted status, public-safe status, tax treatment, and confirmation of receipt. Asset distribution records shall confirm that no improper private distribution was made and that distributions complied with law, Articles, tax status, donor restrictions, grant restrictions, public authority terms, and public-benefit purpose.
477.8 Restricted Fund Disposition Records. Restricted fund disposition records shall identify each restricted fund, source, restriction, balance, permitted use, actual use, transfer, return, release, modification, court or regulator direction where any, donor or grantor consent where any, public authority term where any, final disposition, and remaining obligation. Restricted fund records shall confirm that restricted funds were not diverted to inconsistent purposes, private benefit, sponsor control, provider preference, or unauthorized wind-up expenses.
477.9 Public-Good Technical Asset Disposition Records. Public-good technical asset disposition records shall identify software, public-good software, internal software, restricted software, open technical baselines, datasets, schemas, APIs, SDKs, dashboards, data dictionaries, ontology files, model cards, system cards, benchmark cards, reference architectures, profiles, test harnesses, gold vectors, negative tests, repositories, publications, licenses, contributor terms, dependency status, vulnerability status, public-safe status, export-control status, protected knowledge status, successor steward, transfer record, archive record, deprecation record, retirement record, deletion record, sealing record, and correction path.
477.10 Data Disposition Records. Data disposition records shall identify datasets, personal information, rights-bearing data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, research data, public authority data, protected knowledge, Indigenous / local / territorial knowledge, AI records, embeddings, vector stores, retrieval indexes, logs, dashboards, maps, backups, exports, derived data, copies, processors, subprocessors, deletion, transfer, return, sealing, archival, anonymization, aggregation, retention, legal holds, public authority terms, privacy review, safeguards review, and verification. Data disposition records shall be sufficient to demonstrate lawful handling.
477.11 Public Authority Material Disposition Records. Public authority material disposition records shall identify public authority data, public authority communications, public authority references, logos, quotes, attendance records, controlled-room records, public authority learning records, public finance reader records, regulator-listening records, emergency-management records, public infrastructure operator records, public authority-facing publications, dashboards, maps, data-sharing instruments, return, deletion, transfer, sealing, public authority notices, public authority review rights, non-endorsement language, and correction records. These records shall preserve no-delegation, no-public-warning, no-emergency-command, no-procurement, no-funding-approval, and no-public-finance-approval boundaries.
477.12 Community-Protected and Protected Knowledge Disposition Records. Community-protected and protected knowledge disposition records shall identify Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural site information, environmental knowledge, community vulnerability information, protected participation records, consent records, non-consent records, withdrawal records, FPIC records where applicable, community protocols, Indigenous governance protocols, public-safe mapping controls, access restrictions, deletion, return, sealing, restricted transfer, archival, notice where appropriate, remedy, grievance closeout, and safeguards review. Records shall protect confidentiality and shall not expose protected knowledge through the record itself.
477.13 Contract Closeout Records. Contract closeout records shall identify each contract, counterparty, termination date, notice, payment, refund, deliverable status, IP disposition, data disposition, confidentiality survival, insurance survival, audit rights, dispute status, public authority terms, sponsor terms, provider terms, host terms, partner terms, vendor exit assistance, access revocation, credential revocation, and final release where any. Contract closeout records shall identify unresolved obligations and surviving provisions.
477.14 Liability Closeout Records. Liability closeout records shall identify liabilities paid, resolved, disputed, settled, released, transferred where lawful, reserved, insured, contingent, or surviving. Records shall include creditors, employees, contractors, vendors, tax authorities, grantors, donors, sponsors, public authorities, insurers, litigants, claimants, and other affected parties. Liability records shall include payment evidence, settlement records, releases, legal review, Board approval where required, and residual risk.
477.15 Employee, Contractor, Fellow, Advisor, Volunteer, Participant, Committee, Council, and Member Closeout Records. Final closeout records shall identify offboarding of employees, contractors, fellows, advisors, volunteers, contributors, participants, committee members, council participants, advisory body members, public authority participants, sponsors, providers, hosts, partners, Academy participants, subscribers, supporters, and members where applicable. Records shall include final payments, reimbursements, access revocation, confidentiality reminders, IP confirmations, data return, training status, public statement limitations, records return, grievance preservation, non-retaliation, member notices where applicable, and final status.
477.16 Public Claims Closeout Records. Public claims closeout records shall identify website updates, repository notices, publication archive notices, program discontinuation notices, controlled-room closure notices, public authority reference updates, sponsor / donor / funder / provider / host / partner / participant reference updates, Nexus interface notices, transfer notices, archive notices, discontinuation notices, non-reliance language, non-execution language, outdated claim corrections, social media corrections, media corrections, public-safe clarifications, controlled notices, and archive status. Records shall confirm that public materials no longer imply current authority where none exists.
477.17 Final Public-Safe Report Where Approved or Required. GCRI Canada may prepare a final public-safe report where approved by the Board or required by law, grant terms, donor terms, public authority terms, or public-benefit considerations. The final public-safe report may summarize dissolution, wind-up, public-benefit activities, asset disposition, public-good technical asset status, repository status, data disposition at a high level, public authority material handling at a high level, protected knowledge safeguards at a high level, remaining correction path, successor stewards, and archive locations where public-safe. The report shall exclude confidential, privileged, privacy-sensitive, public authority-sensitive, protected knowledge, cyber-sensitive, infrastructure-sensitive, finance-sensitive, or security-sensitive information and shall include non-reliance and non-execution language.
477.18 Final Archive. GCRI Canada shall maintain a final archive or designate an authorized archive custodian for final dissolution records, corporate records, financial records, tax records, legal records, Board records, member records where applicable, grant records, donor records, sponsor records, public authority records, data disposition records, technical asset disposition records, publication records, correction records, legal hold records, insurance records, and other required records. The final archive shall be classified, access-controlled, retention-governed, protected against alteration, and capable of supporting lawful access, correction, dispute resolution, audit, and historical traceability.
477.19 Final Custodian or Successor Steward Record. Final dissolution records shall identify the final custodian or successor steward for records, archives, public-good technical assets, repositories, datasets, schemas, ontologies, publications, correction paths, public authority materials, protected knowledge, legal holds, insurance records, and other surviving obligations. The record shall identify authority, scope, access rights, duties, restrictions, confidentiality, data / AI / cyber controls, public authority terms, safeguards, correction responsibilities, retention obligations, contact information, and termination or replacement process. A custodian or successor steward shall not receive authority beyond the transfer instrument.
477.20 Final Legal Closure Record. The final legal closure record shall confirm completion of required approvals, filings, notices, asset distributions, liability closeout, tax filings, data disposition, public authority material disposition, protected knowledge disposition, contract closeout, access revocation, credential revocation, public claims closeout, final archive, final custodian or successor steward designation, insurance review, legal hold status, and surviving obligations. The final legal closure record shall identify the legal closure date, remaining obligations, responsible custodian, correction contact, and archive location. Final legal closure shall not extinguish surviving duties, legal holds, correctionability, confidentiality, privacy, public authority boundaries, finance boundaries, or protected knowledge obligations where they continue by law, contract, or this Bylaw.
Last updated
Was this helpful?