ARTICLE IV. BOARD
Section 103. Board Authority and Role
103.1 Board as Governing Authority. The Board of Directors shall be the governing authority of the Corporation and shall exercise ultimate supervision, direction, fiduciary stewardship, constitutional oversight, mission-lock protection, public-benefit accountability, records discipline, and institutional boundary control over the affairs of The Global Centre for Risk and Innovation - United States.
The Board shall act as the highest internal authority of the Corporation except to the extent that applicable law, the Articles or Certificate, this Bylaw, or any member approval right required by law assigns a matter to another competent authority. The Board’s authority shall include the power and duty to govern the Corporation’s purposes, strategy, legal status, officers, committees, councils, finances, records, policies, public-good assets, evidence systems, methods, observability functions, ontology functions, technical baselines, public-good software, public authority learning interfaces, safeguards, Nexus interfaces, public-safe publications, and correction systems.
The Board shall not be a symbolic, advisory, ceremonial, sponsor-facing, public authority-facing, or technical-review body. It shall be the fiduciary governance organ of the Corporation and shall remain responsible for ensuring that all corporate powers are exercised lawfully, prudently, independently, transparently where appropriate, and consistently with the Corporation’s nonprofit, non-distributing, non-executing, public-benefit, evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baseline, verifiable compute, verifiable intelligence, public authority learning, and Nexus-compatible public-good stewardship purposes.
The Board may act directly, through duly authorized officers, through Board committees, through authorized councils, through approved policies, through delegated authority matrices, through approved operating instruments, or through lawful written instruments; however, delegation shall not relieve the Board of its oversight duties, fiduciary responsibilities, boundary-protection responsibilities, or duty to preserve the Corporation’s legal and institutional character.
103.2 Authority Subject to Applicable Law. The Board’s authority shall be subject at all times to applicable law, including the governing nonprofit corporation statute of the Corporation’s state of incorporation or organization, applicable United States federal law, state law, territorial law, District of Columbia law where applicable, local law where applicable, Tribal and Indigenous governance respect obligations where lawfully engaged, federal tax law, state tax law, charitable solicitation law where applicable, employment law, privacy law, data protection law, cybersecurity law, AI-related legal requirements where applicable, export-control law, sanctions law, competition and antitrust law, government ethics law where applicable, lobbying and political activity law where applicable, grant compliance rules, public authority interaction rules, public records sensitivities where applicable, professional-boundary rules, and any other legal requirement binding upon the Corporation.
The Board shall not authorize, ratify, permit, tolerate, or fail to correct any act that is unlawful merely because the act is mission-aligned, technically valuable, sponsor-supported, funder-supported, publicly useful, urgent, strategically important, requested by a public authority, requested by a partner, beneficial to Nexus alignment, or convenient for implementation. Legal compliance shall be a condition of Board authority, not an external formality.
Where a proposed Board act, officer act, committee act, publication, technical release, controlled-room activity, public authority interface, finance-adjacent output, public-safe report, data handling activity, AI use, cyber operation, software release, grant, sponsorship, donation, provider interface, host interface, cross-border engagement, or Nexus interface raises legal uncertainty, the Board shall cause the matter to be reviewed through an appropriate legal, compliance, risk, safeguards, or counsel process before authorizing reliance, publication, launch, scaling, or public representation.
103.3 Authority Subject to Certificate or Articles of Incorporation. The Board’s authority shall be subject to the Articles or Certificate of Incorporation, charter, or other constituting instrument of the Corporation. The Board shall preserve the purposes, limitations, nonprofit character, public-benefit character, non-distribution character, corporate powers, member rights where applicable, director rules, dissolution requirements, and any other mandatory corporate-law provisions contained in the Articles or Certificate.
No Board resolution, policy, committee charter, officer delegation, program instrument, grant agreement, sponsorship agreement, public authority memorandum, Nexus interface instrument, repository rule, technical profile, proof receipt, controlled vocabulary, public-safe notice, operating procedure, or external communication shall amend, override, narrow, expand, or contradict the Articles or Certificate unless the Articles or Certificate are lawfully amended by competent authority and all required records, approvals, filings, notices, and effective-date conditions are satisfied.
Where the Articles or Certificate and this Bylaw appear to conflict, the Articles or Certificate shall control to the extent required by law, and the Board shall promptly cause the inconsistency to be reviewed, corrected, clarified, amended, superseded, or otherwise resolved through lawful governance action.
103.4 Authority Subject to This Bylaw. The Board shall exercise its authority subject to this Bylaw. This Bylaw shall govern the internal legal authority, fiduciary structure, public-benefit duties, governance processes, role boundaries, committee and council architecture, officer delegations, records discipline, evidence and methods stewardship, public-safe publication, data / AI / cyber controls, community safeguards, public authority boundaries, finance boundaries, certification boundaries, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, Nexus interface discipline, validity-by-record, correctionability, and amendment processes of the Corporation.
The Board shall not exercise authority by informal custom, operational convenience, leadership assumption, technical centrality, sponsor expectation, provider expectation, public authority expectation, funding pressure, grant milestone, public statement, website description, board-deck reference, AI-generated summary, repository practice, or Nexus alignment unless such authority is supported by applicable law, the Articles or Certificate, this Bylaw, and a competent record.
The Board shall preserve this Bylaw as a binding governance instrument and shall ensure that lower-order instruments implement rather than alter it. Where an officer, committee, council, program, working group, controlled room, technical repository, public authority session, public-good software release, or Nexus interface acts inconsistently with this Bylaw, the Board shall cause the matter to be held, corrected, restricted, superseded, withdrawn, re-scoped, escalated, or otherwise remediated.
103.5 Authority Subject to Member Approval Where Required. Where the Corporation has statutory members, voting members, or any other member category with approval rights under applicable law, the Articles or Certificate, this Bylaw, or a competent corporate record, the Board shall respect such rights and shall not treat Board approval as sufficient where member approval is legally required.
Member approval may be required, depending on applicable law and governing instruments, for matters including amendment of the Articles or Certificate, merger, consolidation, conversion, dissolution, sale or disposition of substantially all assets, amendment or repeal of certain bylaws, election or removal of directors, changes to membership rights, or other fundamental corporate actions. The Board shall identify and record any member approval requirement before acting on a matter that may trigger such rights.
No officer, committee, council, sponsor, donor, funder, provider, public authority participant, Nexus entity, advisor, staff member, contractor, contributor, host, university, laboratory, national company, Project SPV, or enterprise actor shall substitute for a member approval where member approval is required by law or governing instrument.
103.6 Authority Subject to Federal Tax-Exempt or Tax-Exempt-Compatible Obligations. The Board shall exercise its authority in a manner consistent with the Corporation’s federal tax status, tax-exempt application status, tax-exempt-compatible posture, or other tax classification as recorded by the Corporation. The Board shall protect the Corporation against private inurement, impermissible private benefit, excess benefit transactions, improper political activity, unlawful lobbying activity where applicable, unrelated business activity risks where applicable, donor misrepresentation, improper receipting, restricted-fund misuse, and any act that may jeopardize tax-exempt or tax-exempt-compatible status.
The Board shall ensure that grants, donations, sponsorships, subscriptions, fees, cost recovery, in-kind support, fellowships, scholarships, awards, challenge support, public-good infrastructure support, and restricted funds are accepted, used, recorded, acknowledged, and reported in a manner consistent with applicable tax rules, nonprofit obligations, donor restrictions, public-benefit purposes, anti-capture controls, sponsor non-control, provider neutrality, public authority boundaries, and this Bylaw.
The Board shall not permit tax status to be represented inaccurately. If the Corporation has not obtained a particular tax-exempt status, charitable status, public charity status, private foundation status, supporting organization status, fiscal sponsorship status, or other legal classification, no Board member, officer, employee, contractor, donor, sponsor, funder, supporter, participant, or public-facing material shall represent that such status exists without competent record.
103.7 Authority Subject to State Nonprofit Corporate Obligations. The Board shall preserve the Corporation’s good standing and compliance under the governing state nonprofit corporation law and any other state, territorial, District of Columbia, or local law applicable to the Corporation’s activities. The Board shall ensure that the Corporation maintains required filings, registered agent records, registered office records, annual or periodic reports, franchise tax filings where applicable, charitable solicitation registrations where applicable, state tax records, director and officer records, minutes, resolutions, corporate books, member records where applicable, conflict records, and other legally required corporate records.
Where the Corporation operates, fundraises, employs personnel, contracts, maintains programs, conducts public authority learning, runs controlled rooms, receives data, publishes materials, hosts events, or otherwise represents itself in multiple states or territories, the Board shall require review of qualification, registration, charitable solicitation, tax, employment, privacy, procurement, public records, lobbying, government ethics, grant, contracting, and local-law obligations where applicable.
No all-states-and-territories operating posture shall be treated as legal permission to operate everywhere without required qualification, registration, review, safeguards, localized limitation language, or compliance records.
103.8 Authority Subject to Charitable Solicitation, Grant, Donation, Public Support, and Restricted Fund Obligations Where Applicable. The Board shall oversee charitable solicitation compliance where applicable, grant compliance, donation handling, sponsorship handling, restricted fund management, public support records, donor acknowledgment, funder reporting, sponsor acknowledgment, and in-kind contribution handling. The Board shall ensure that all such support is accepted and used only for lawful nonprofit, public-benefit, tax-compatible, mission-faithful, non-executing, anti-capture, provider-neutral, sponsor non-control, public-safe, and record-supported purposes.
The Board shall not permit any grant, donation, sponsorship, restricted fund, in-kind contribution, subscription, fee, or public-good support arrangement to purchase, condition, control, influence, suppress, predetermine, or distort:
a) research findings;
b) evidence classifications;
c) methods outcomes;
d) observability outputs;
e) ontology or controlled vocabulary meaning;
f) public-good software releases;
g) open technical baseline content;
h) public-safe publication decisions;
i) public authority access;
j) provider preference;
k) certification, recognition, finance-readiness, procurement advantage, Grid status, Docket status, or Nexus-compatible claim;
l) committee or council outcomes;
m) Board decisions; or
n) the Corporation’s legal, tax, public-benefit, non-execution, or Nexus role-separation posture.
Where a support arrangement creates risk of control, capture, private benefit, public authority confusion, finance overclaim, provider preference, procurement implication, certification implication, recognition implication, or protected knowledge harm, the Board shall require refusal, narrowing, restriction, ring-fencing, independent review, modified acknowledgment, return, termination, correction, or public-safe clarification.
103.9 Board Responsibility for Mission Lock. The Board shall preserve the Corporation’s mission lock. Mission lock means the binding governance obligation to maintain the Corporation as a United States nonprofit, nonstock or non-share, non-distributing, public-benefit, non-executing technical institution and United States / North America anchor for evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baselines, verifiable compute and intelligence methods, public authority learning, community safeguards, and public-safe publication.
The Board shall reject any interpretation, transaction, program, partnership, technical integration, public authority interface, support arrangement, operating instrument, or Nexus interface that would convert the Corporation into:
a) a regulator;
b) an emergency command body;
c) an official public warning authority;
d) a procurement authority;
e) a certification or accreditation body by default;
f) a recognition or public-facing legitimacy body;
g) a finance-readiness, insurance-readiness, bankability, rating, or capital-readability body;
h) an investment adviser, broker, dealer, finder, lender, insurer, underwriter, rating agency, fund, bank, marketplace, or public finance approver;
i) a public authority or delegated governmental decision-maker;
j) a National Consortium Company, state or regional operating company, Project SPV, provider, operator, asset owner, or enterprise execution vehicle; or
k) a standards monopoly or protocol authority unless separately and lawfully constituted by competent authority and consistent with the Articles or Certificate and this Bylaw.
Mission lock shall be preserved through Board oversight, controlled vocabulary, authority matrices, approval thresholds, public-safe notices, policy review, legal review, records discipline, correctionability, and periodic review of institutional drift.
103.10 Board Responsibility for Public-Benefit Purpose. The Board shall ensure that the Corporation is operated for public-benefit purposes and not for private gain, private control, sponsor advantage, provider advantage, public authority substitution, political capture, market positioning, capital execution, procurement advantage, or institutional self-expansion inconsistent with its purposes.
The Board shall require that major programs, publications, technical releases, research initiatives, public authority learning sessions, controlled rooms, grants, sponsorships, data activities, AI activities, cyber activities, public-good software projects, observability work, ontology work, Nexus interfaces, and stakeholder participation systems be assessed for public-benefit alignment. Public-benefit alignment shall include, as applicable:
a) evidence integrity;
b) methods integrity;
c) research integrity;
d) public-good technical utility;
e) public authority learning value without public authority substitution;
f) community safeguards;
g) civil rights and accessibility protection;
h) Indigenous, Tribal, local, territorial, cultural, environmental, and protected knowledge respect;
i) public-safe publication;
j) correctionability;
k) validity-by-record;
l) anti-capture discipline;
m) provider neutrality;
n) sponsor non-control; and
o) consistency with the Corporation’s nonprofit and non-executing character.
The Board shall not permit public-benefit language to be used as a pretext for unlawful activity, private benefit, unsupported claims, unsafe publication, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, or enterprise execution.
103.11 Board Responsibility for Nonprofit and Non-Distribution Character. The Board shall protect the Corporation’s nonprofit and non-distribution character. The Board shall ensure that no part of the Corporation’s net earnings, assets, funds, technical assets, software assets, data assets, intellectual property assets, repository assets, public-good assets, restricted funds, or public-support resources inures to the benefit of any director, officer, member, sponsor, donor, funder, provider, host, contractor, founder, related party, private person, enterprise actor, national company, Project SPV, or other private interest except as lawful, reasonable, documented, conflict-reviewed, purpose-aligned, and permitted by applicable law and governing instruments.
The Board may authorize reasonable compensation, reimbursement, grants, stipends, scholarships, awards, fellowships, contractor payments, vendor payments, public-good support, and program expenditures where lawful and documented. Such payments shall not be used to disguise private inurement, sponsor control, provider preference, improper private benefit, procurement advantage, finance-readiness purchase, recognition purchase, certification purchase, or public authority access purchase.
The Board shall maintain or require appropriate records showing that the Corporation’s assets are dedicated to lawful public-benefit purposes and that any distribution, transfer, payment, license, grant, contract, support arrangement, or asset use is consistent with nonprofit law, tax posture, fiduciary duty, and this Bylaw.
103.12 Board Responsibility for Evidence, Methods, Observability, Ontology, Technical Truth, Public-Good R&D, Public-Good Software, and Open Technical Baselines. The Board shall oversee the Corporation’s core public-good technical functions, including evidence doctrine, methods stewardship, observability, ontology, semantic interoperability, technical truth methods, public-good research and development, public-good software, open technical baselines, verifiable compute and verifiable intelligence methods, public authority learning tools, public-safe publications, and correctionable technical memory.
The Board shall ensure that these functions are governed by records, source lineage, versioning, custodianship, method status, confidence and uncertainty handling, data quality controls, human review rules, public-safe classification, access classification, correction pathways, and boundary language. The Board shall require heightened review where outputs relate to AI, agentic AI, AI-RAN, O-RAN, private wireless, DePIN, DLT, blockchain, Web3, sovereign compute, edge compute, HPC, cybersecurity, cyber-physical systems, robotics, drones, sensors, geospatial systems, Earth observation, digital twins, biosecurity, climate, nature, biodiversity, energy, water, food, health, disaster resilience, telecommunications, supply chains, ports, borders, advanced manufacturing, semiconductors, quantum-relevant systems, public trust, or other exponential and mission-critical technologies.
The Board shall ensure that no evidence output, method, observability signal, ontology term, technical truth output, public-good software release, technical baseline, benchmark, proof receipt, dashboard, model output, digital twin, sensor signal, AI-RAN signal, DePIN record, DLT or blockchain entry, or public-safe report is represented as public authority action, public warning, emergency command, recognition, maturity status, finance-readiness, insurance-readiness, rating, certification, procurement approval, provider approval, or enterprise execution unless separately and lawfully authorized by competent authority and supported by record.
103.13 Board Responsibility for United States All-States-and-Territories Posture. The Board shall oversee the Corporation’s United States all-states-and-territories posture. This posture permits the Corporation, where lawful and properly recorded, to operate, engage, learn, publish, convene, support public-good technical work, coordinate with public authorities, and maintain interfaces across the fifty states, the District of Columbia, Puerto Rico, Guam, the U.S. Virgin Islands, American Samoa, the Northern Mariana Islands, Tribal and Indigenous governance contexts where lawfully and respectfully engaged, and local, county, municipal, metropolitan, utility, port, public health, emergency management, public safety, public works, telecom, energy, water, food, cyber, and infrastructure contexts.
The Board shall ensure that all-states-and-territories posture does not become an assertion of state authority, territorial authority, Tribal authority, federal authority, public finance authority, procurement authority, regulatory authority, emergency command authority, public warning authority, certification authority, recognition authority, or operational control. The Board shall require state-specific, territorial-specific, District of Columbia-specific, Tribal-interface, local, and sectoral review where activities may trigger legal, public authority, privacy, public records, open meetings, procurement, lobbying, charitable solicitation, tax, employment, data, AI, cyber, accessibility, civil rights, protected knowledge, or public-safe communication obligations.
The Board shall cause the Corporation to maintain records sufficient to show where and how the Corporation operates, represents itself, solicits support, convenes programs, handles data, engages public authorities, publishes outputs, maintains controlled rooms, or interfaces with Nexus systems within the United States and its territories.
103.14 Board Responsibility for North America Anchor Role. The Board shall oversee the Corporation’s North America anchor role as a bounded public-good technical function. The North America anchor role may support evidence architecture, methods continuity, observability and ontology alignment, public-good software, open technical baselines, Nexus Observatory methods, Nexus Truth Engine methods, verifiable compute and intelligence methods, public authority learning, technical literacy, cross-border learning, and safeguards for North America-relevant risk and resilience contexts.
The Board shall ensure that North America anchor language is used only where lawful, accurate, record-supported, and not legally confusing. The North America anchor role shall not imply that the Corporation owns, governs, controls, represents, supervises, or binds GCRI Canada, any Mexico-facing interface, Caribbean interface, Arctic interface, Great Lakes interface, Pacific interface, Atlantic interface, Gulf interface, Indigenous government, public authority, regional Nexus body, national Nexus body, university, laboratory, sponsor, provider, host, Project SPV, national company, or enterprise actor.
The Board shall ensure that the North America anchor role is not represented as North America sovereign authority, treaty authority, intergovernmental authority, public finance authority, regional regulator, public procurement authority, public warning authority, emergency command authority, certification authority, recognition authority, finance-readiness authority, protocol authority, or enterprise execution authority. Cross-border coordination shall be lawful, bounded, recorded, public-safe, and compatible with the legal separateness of GCRI US, GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus entities, public authorities, and enterprise actors.
103.15 Board Responsibility for Nexus Role Separation. The Board shall preserve role separation within the Nexus public-good architecture. The Board shall ensure that the Corporation remains within the GCRI function as evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baseline, verifiable compute and intelligence methods, public authority learning, and research-integrity steward.
The Board shall ensure that the Corporation does not collapse or assume the functions of:
a) The Global Risks Forum (GRF), which is the public-good registry, recognition, maturity-records, standing, claims-discipline, stakeholder-formation, public-safe reporting, and public-facing legitimacy steward;
b) The Global Risks Alliance (GRA), which is the finance-readiness, capital-readability, proof-pack, insurance-readiness, diligence-translation, RNFD, NFD, UNFSD, capital-reader-room, and regulated-perimeter discipline steward;
c) Nexus Standards or any protocol authority where separately constituted;
d) Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, or Nexus Competence Cells;
e) Global, regional, national, state, territorial, Tribal, metropolitan, local, or sectoral Nexus consortiums;
f) National Consortium Companies, state or regional operating companies, Project SPVs, Qualified Enterprise Providers, hosts, sponsors, vendors, contractors, operators, asset owners, investors, insurers, lenders, underwriters, banks, public finance actors, or enterprise execution vehicles; or
g) public authorities or regulated decision-makers.
The Board shall require compatibility notes, divergence logs, interface records, controlled vocabulary, limitation language, public-safe notices, and correction pathways where Nexus interfaces create risk of role confusion.
103.16 Board Responsibility for Non-Execution. The Board shall preserve the Corporation’s non-execution character. The Corporation may produce evidence, methods, public-good software, technical baselines, controlled vocabulary, observability methods, ontology structures, public authority learning materials, public-safe publications, proof-support materials, Nexus-compatible technical inputs, and correction signals; however, it shall not execute regulated or reserved functions unless separately and lawfully authorized in a manner consistent with applicable law, the Articles or Certificate, this Bylaw, and competent records.
The Board shall ensure that the Corporation does not conduct, offer, arrange, intermediate, broker, advise on as a regulated actor, underwrite, distribute, custody, clear, settle, guarantee, insure, reinsure, lend, rate, procure, certify, recognize, command, warn as a public authority, regulate, approve legal compliance, approve public finance, approve investment, select providers for public authorities, operate infrastructure as public authority, or execute enterprise delivery by implication, technical integration, controlled-room design, data-room operation, dashboard display, AI output, digital twin, proof receipt, blockchain record, DePIN record, AI-RAN signal, public-safe report, grant relationship, sponsor relationship, public authority participation, or Nexus association.
Where non-execution risk arises, the Board shall require hold, quarantine, legal review, re-scoping, externalization to a lawful actor, referral to a competent authority, corrected language, withdrawal, or termination.
103.17 Board Responsibility for Public Authority Boundaries. The Board shall ensure that the Corporation’s public authority interfaces remain learning, evidence, methods, technical literacy, public-safe communication, and public-good support interfaces only, unless a lawful and recorded instrument establishes a narrower and permitted role.
The Board shall ensure that public authority participation, public authority room attendance, regulator-listening participation, public finance reader participation, emergency-management learning participation, public infrastructure operator participation, simulation participation, tabletop exercises, after-action learning, public authority data contribution, public authority comments, public authority requests, or public authority familiarity do not create public authority delegation, official adoption, public procurement approval, funding approval, regulatory approval, public finance approval, sovereign obligation, public-private partnership status, public warning authority, emergency command authority, or authority to speak for a public authority.
The Board shall require public authority capacity classification, official-reference controls, public-safe notices, meeting records, access controls, limitation language, and correction mechanisms for material public authority interfaces.
103.18 Board Responsibility for Finance, Securities, Insurance, Lending, Rating, Public Finance, Procurement, and Certification Boundaries. The Board shall oversee and preserve the Corporation’s finance, securities, insurance, lending, rating, public finance, procurement, certification, accreditation, recognition, and professional-boundary discipline. The Board shall ensure that the Corporation does not act as an investment adviser, broker, dealer, finder, underwriter, lender, bank, fund, marketplace, insurer, reinsurer, insurance producer, rating agency, credit opinion provider, public finance approver, procurement authority, certification body, accreditation body, or legal compliance approver unless a future lawful instrument expressly and narrowly authorizes a function consistent with applicable law and this Bylaw.
The Board shall ensure that GCRI US outputs, including evidence records, methods, technical baselines, observability outputs, proof receipts, public-good software, dashboards, risk categories, resilience indicators, benchmark outputs, public authority learning materials, controlled-room materials, and Nexus interface inputs, are not represented as:
a) securities offerings;
b) investment recommendations;
c) financing approvals;
d) capital-readability determinations;
e) finance-readiness determinations;
f) insurance-readiness determinations;
g) bankability determinations;
h) ratings;
i) credit opinions;
j) underwriting bases;
k) public finance approvals;
l) procurement approvals;
m) vendor selections;
n) certification or accreditation outcomes;
o) recognition or maturity status; or
p) public authority approvals.
The Board shall require review of finance-adjacent, procurement-adjacent, certification-adjacent, rating-adjacent, public finance-adjacent, and public authority-adjacent materials before publication, controlled release, sponsor use, provider use, grant use, capital-reader use, or public representation.
103.19 Board Responsibility for Data / AI / Cyber / Privacy Controls. The Board shall oversee the Corporation’s data governance, privacy, AI governance, cybersecurity, secure compute, model governance, inference record, compute workload, repository, software release, controlled-room, data-room, public authority data, rights-bearing data, and incident-response controls.
The Board shall ensure that the Corporation maintains appropriate policies, registers, access controls, security measures, privacy controls, AI-use rules, model registers, inference records, compute workload records, dataset cards, model cards, system cards, benchmark cards, SBOM records, vulnerability records, key and credential controls, incident records, backup and disaster recovery plans, business continuity plans, legal holds, retention rules, deletion rules, and correction pathways.
The Board shall require heightened review for personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, public authority-sensitive data, commercially sensitive data, finance-sensitive data, community-protected data, Tribal or Indigenous data, local or territorial knowledge, protected knowledge, cross-border data, sovereign-sensitive data, AI training or fine-tuning materials, embedding or retrieval systems, agentic AI workflows, public repositories, open releases, public dashboards, public maps, on-chain artifacts, DLT records, DePIN records, digital twins, and AI-RAN or O-RAN signals.
No AI system, automated workflow, model output, agentic action, dashboard state, ledger entry, proof receipt, digital twin, sensor output, AI-RAN signal, DePIN record, or cyber telemetry output shall be treated as Board decision, officer decision, public authority decision, public warning, emergency command, certification, recognition, finance-readiness, procurement approval, provider approval, or final institutional truth unless supported by competent human authorization, record, review, limitation, and correction pathway.
103.20 Board Responsibility for Community, Tribal, Indigenous, Local, Territorial, Protected Knowledge, Civil Rights, Accessibility, and Public-Safe Safeguards. The Board shall oversee safeguards for communities, Tribal and Indigenous interfaces, local and territorial knowledge, cultural knowledge, environmental knowledge, protected knowledge, civil rights, non-discrimination, accessibility, vulnerable persons, remote communities, protected participants, whistleblowers, confidential sources, public-safe mapping, grievance pathways, remedy pathways, protected participation, and non-retaliation.
The Board shall ensure that the Corporation does not extract, expose, publish, tokenize, commercialize, map, operationalize, train AI on, transfer, or repurpose protected knowledge, Indigenous knowledge, Tribal data, local knowledge, territorial knowledge, community-protected information, sensitive environmental information, sensitive cultural information, or rights-bearing data except under recorded authority, lawful basis, safeguards, access controls, limitation language, and correction pathways.
The Board shall ensure that accessibility and civil rights are treated as substantive governance obligations and not as secondary communications preferences. Where the Corporation’s activities may affect persons, communities, public authorities, protected participants, or knowledge holders, the Board shall require review proportionate to the risk of harm, exposure, discrimination, stigmatization, displacement, retaliation, surveillance, re-identification, cultural harm, public safety harm, or protected knowledge misuse.
103.21 Board Responsibility for Provider Neutrality and Sponsor Non-Control. The Board shall preserve provider neutrality and sponsor non-control. The Corporation may interact with providers, vendors, contractors, sponsors, donors, funders, hosts, universities, laboratories, public authorities, national companies, Project SPVs, and enterprise actors where lawful and mission-aligned; however, no such actor shall control the Corporation’s governance, agenda, evidence, methods, observability, ontology, technical baselines, public-good software, public-safe publications, public authority access, controlled rooms, research findings, committee outcomes, Board decisions, personnel appointments, Nexus interface outputs, or correction processes.
The Board shall ensure that provider participation does not create preferred provider status, required provider status, procurement advantage, public authority endorsement, certification, recognition, finance-readiness, Grid status, Docket status, Nexus-compatible status, or technical monopoly. The Board shall ensure that sponsor, donor, funder, or host support does not create agenda control, outcome purchase, publication veto, public authority access purchase, provider preference, research finding purchase, recognition purchase, finance-readiness purchase, certification purchase, procurement advantage, or public-safe claim control.
Where a provider, sponsor, donor, funder, host, contractor, investor, insurer, lender, national company, Project SPV, or enterprise actor relationship creates actual, potential, or perceived capture risk, the Board shall require disclosure, independent review, recusal, ring-fencing, influence caps, diversification, access restriction, limitation language, public-safe clarification, refusal, return of support, termination, or other corrective action.
103.22 Board Responsibility for Validity-by-Record. The Board shall preserve validity-by-record as a governing principle of the Corporation. No material institutional claim, authority, status, publication, record, approval, delegation, appointment, technical baseline, method, evidence output, observability output, public-safe report, public authority capacity, controlled-room status, public-good software release, proof receipt, correction, supersession, withdrawal, or Nexus interface output shall be treated as valid merely by assertion, reputation, seniority, authorship, technical centrality, sponsor use, provider use, public authority familiarity, website presence, repository presence, meeting reference, AI-generated summary, or repeated practice.
Validity shall arise from competent authority, recorded process, evidence, provenance, source lineage, version control, custody, approval, effective date, review, limitation, public-safe classification, access classification, correction history, and accountable stewardship.
The Board shall require that material governance and technical acts be traceable to records sufficient to show:
a) who acted;
b) under what authority;
c) on what evidence;
d) under what method or policy;
e) with what limitations;
f) with what public-safe status;
g) with what access and publication class;
h) with what correction pathway;
i) with what effective date; and
j) with what supersession, withdrawal, archival, or review status.
103.23 Board Responsibility for Correctionability. The Board shall preserve correctionability as a binding institutional discipline. The Corporation’s governance records, evidence records, methods, observability outputs, ontology terms, technical truth outputs, public-good software, open technical baselines, public-safe publications, dashboards, maps, proof receipts, model outputs, compute outputs, public authority learning materials, controlled-room records, Nexus interface inputs, public claims, and participation records shall be correctable where error, incompleteness, ambiguity, overclaim, misuse, boundary breach, data issue, AI issue, cyber issue, research integrity issue, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, protected knowledge issue, civil rights issue, accessibility issue, safeguards concern, or legal defect is identified.
The Board shall ensure that correction mechanisms include, as applicable:
a) challenge intake;
b) review;
c) hold;
d) access restriction;
e) clarification;
f) correction;
g) limitation;
h) supersession;
i) withdrawal;
j) suspension;
k) downgrade;
l) retraction;
m) takedown;
n) archival;
o) public-safe notice;
p) controlled notice;
q) legal or safeguards escalation;
r) post-correction review; and
s) recurrence prevention.
The Board shall ensure that correction is not treated as reputational weakness. Correctionability is a condition of public trust, evidence integrity, technical truth, public-safe reporting, and Nexus-compatible legitimacy.
103.24 Board Authority Records. The Corporation shall maintain Board Authority Records sufficient to demonstrate the lawful source, scope, exercise, delegation, limitation, review, and correction of Board authority.
Board Authority Records shall include, as applicable:
a) Articles or Certificate records, bylaw records, Board resolution records, member approval records where applicable, adoption records, amendment records, restatement records, supersession records, withdrawal records, and effective-date records;
b) director register records, officer register records, committee charter records, council charter records, delegation matrix records, authority matrix records, reserved matter records, policy approval records, protocol approval records, schedule approval records, technical profile approval records, controlled vocabulary approval records, and public-safe notice library approval records;
c) mission-lock records, public-benefit purpose records, nonprofit character records, non-distribution records, private inurement review records, private benefit review records, tax-exempt or tax-exempt-compatible records, charitable solicitation records, grant records, donation records, sponsorship records, restricted fund records, and public support records;
d) evidence oversight records, methods oversight records, observability oversight records, ontology oversight records, technical truth oversight records, public-good R&D oversight records, public-good software oversight records, open technical baseline oversight records, verifiable compute oversight records, verifiable intelligence oversight records, Nexus Truth Engine methods oversight records, Nexus Observatory methods oversight records, and public-safe publication oversight records;
e) United States all-states-and-territories records, state qualification records, territorial records, District of Columbia records, Tribal-interface records, local interface records, North America anchor records, cross-border records, GCRI Canada interface records, GRF interface records, GRA interface records, Nexus interface records, compatibility notes, divergence logs, and equivalence notes;
f) non-execution records, public authority boundary records, finance-boundary records, securities-boundary records, insurance-boundary records, lending-boundary records, rating-boundary records, public finance-boundary records, procurement-neutrality records, certification-boundary records, recognition-boundary records, provider-neutrality records, sponsor non-control records, anti-capture records, and regulatory-perimeter review records;
g) data governance records, privacy records, AI governance records, cybersecurity records, secure compute records, model register records, inference record records, compute workload records, repository records, software release records, SBOM records, vulnerability records, incident records, business continuity records, disaster recovery records, access records, and controlled-room records;
h) community safeguard records, Tribal and Indigenous protocol records, Indigenous data safeguard records, protected knowledge records, local and territorial knowledge records, civil rights records, accessibility records, public-safe mapping records, grievance records, remedy records, protected participation records, non-retaliation records, and stop-the-line records;
i) records of Board review, Board deliberation, Board vote, Board abstention, Board recusal, Board dissent where recorded, Board ratification, Board correction, Board hold, Board quarantine, Board restriction, Board withdrawal, Board public-safe clarification, Board legal referral, and Board escalation; and
j) responsible owner, custodian, authority, version, effective date, review date, repository location, access class, publication class, retention class, legal hold status, deletion status, archive status, and metadata.
The governing rule of this Section is that the Board is the Corporation’s fiduciary and constitutional governance authority, but its authority is bounded. The Board may govern, steward, supervise, approve, delegate, correct, and preserve the Corporation’s public-benefit technical mission; it may not use governance authority to authorize prohibited execution, public authority substitution, finance-readiness determinations, certification, procurement approval, recognition, provider preference, sponsor control, private inurement, unsafe publication, protected knowledge misuse, or Nexus role collapse. Board authority shall be lawful, recorded, bounded, reviewable, public-safe where relevant, and correctionable.
Section 104. Fiduciary Duties of Directors
104.1 Fiduciary Duty Purpose. Each director shall serve the Corporation as a fiduciary and shall exercise the powers of office in a manner consistent with applicable law, the Articles or Certificate, this Bylaw, Board resolutions, duly adopted policies, the Corporation’s public-benefit purposes, nonprofit and non-distribution character, tax-exempt or tax-exempt-compatible obligations, mission lock, non-execution perimeter, public authority boundaries, finance and regulated-activity boundaries, data / AI / cyber controls, community safeguards, public-safe publication discipline, validity-by-record, correctionability, and Nexus role separation.
The fiduciary duties of directors shall be interpreted in light of the Corporation’s institutional character as a United States nonprofit, public-benefit, non-executing technical institution and North America anchor for evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baselines, verifiable compute and intelligence methods, public authority learning, community safeguards, and public-safe reporting support. A director’s duty shall not be measured only by ordinary corporate efficiency, fundraising success, market influence, technical output, sponsor satisfaction, public authority attention, provider adoption, or ecosystem visibility, but by faithful stewardship of the Corporation’s lawful public-good mandate and the controls required to preserve trust.
Directors shall govern with disciplined independence, informed judgment, recorded process, lawful authority, public-benefit orientation, and correctionable decision-making. A director shall not use the office to advance private interest, sponsor interest, provider interest, political interest, public authority substitution, finance-readiness overclaim, recognition overclaim, certification overclaim, procurement influence, enterprise execution, or any other purpose inconsistent with the Corporation’s mission lock.
104.2 Duty of Care. Each director shall discharge the duties of office with the care that an ordinarily prudent person in a comparable position would reasonably exercise under similar circumstances, taking into account the Corporation’s nonprofit, public-benefit, technical, evidence, research, public authority learning, data / AI / cyber, safeguards, multi-jurisdictional, and Nexus-interface context.
The duty of care shall require a director, as applicable, to:
a) prepare for Board meetings and material decisions;
b) review relevant materials with sufficient diligence;
c) ask reasonable questions;
d) consider legal, financial, technical, evidence, public authority, safeguards, data, AI, cyber, privacy, competition, sanctions, export-control, protected knowledge, public-safe publication, and Nexus role-separation risks;
e) request additional information where the record is materially incomplete;
f) cause expert, counsel, technical, compliance, financial, safeguards, or community review where reasonably necessary;
g) monitor implementation of Board decisions;
h) require correction where facts, methods, authority, boundary assumptions, or outputs prove defective;
i) preserve institutional records sufficient to demonstrate informed decision-making; and
j) avoid passive approval of matters that materially affect the Corporation’s mission, legal status, tax posture, public-benefit purpose, public authority boundaries, finance boundaries, certification boundaries, data / AI / cyber controls, safeguards, public-safe claims, or Nexus interfaces.
A director may rely in good faith on officers, employees, committees, counsel, accountants, technical experts, safeguards experts, researchers, public authority interface records, or other competent persons where such reliance is reasonable, informed, conflict-reviewed where appropriate, and not contradicted by facts known to the director.
104.3 Duty of Loyalty. Each director shall act loyally in the best interests of the Corporation and its public-benefit purposes, and shall not subordinate the Corporation’s interests to personal, professional, financial, political, institutional, sponsor, donor, funder, provider, host, contractor, public authority, investor, insurer, lender, national company, Project SPV, university, laboratory, employer, affiliate, or enterprise interests.
The duty of loyalty shall require a director to:
a) disclose actual, potential, and perceived conflicts of interest;
b) disclose related-party relationships;
c) disclose dual roles across GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus entities, public authorities, sponsors, providers, national companies, Project SPVs, universities, laboratories, hosts, donors, funders, investors, insurers, lenders, contractors, or enterprise actors;
d) refrain from using confidential, privileged, controlled, technical, research, protected knowledge, public authority, data-room, clean-room, controlled-room, repository, or Board information for personal or third-party advantage;
e) refrain from diverting corporate opportunities, public-good opportunities, grants, donors, sponsors, technical assets, software assets, datasets, repositories, public authority relationships, research opportunities, or Nexus interfaces for private or conflicted advantage;
f) refrain from causing the Corporation to prefer a provider, sponsor, donor, funder, host, employer, affiliate, national company, Project SPV, or enterprise actor without lawful, recorded, conflict-reviewed, mission-aligned basis; and
g) submit to recusal, access restriction, independent review, or other mitigation where required.
A director shall not use loyalty to the broader Nexus mission as a basis to weaken loyalty to the Corporation’s legal separateness, fiduciary governance, United States nonprofit obligations, Board authority, records discipline, or mission lock.
104.4 Duty of Obedience to Mission and Law Where Applicable. Each director shall owe a duty of obedience to the Corporation’s lawful purposes, applicable law, the Articles or Certificate, this Bylaw, and the Corporation’s public-benefit mission. The duty of obedience shall require directors to ensure that the Corporation acts within its purposes and does not drift into prohibited, unauthorized, unlawful, or role-collapsing activity.
The duty of obedience shall include the duty to preserve:
a) the Corporation’s nonprofit, nonstock or non-share, non-distributing, and public-benefit character;
b) tax-exempt or tax-exempt-compatible purposes;
c) evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and open technical baseline functions;
d) non-execution;
e) public authority boundary discipline;
f) finance, securities, insurance, lending, rating, public finance, procurement, certification, accreditation, recognition, and professional-boundary discipline;
g) data / AI / cyber / privacy controls;
h) research integrity and public-safe publication;
i) community safeguards, civil rights, accessibility, Tribal and Indigenous protocol respect, and protected knowledge safeguards;
j) GCRI / GRF / GRA role separation;
k) public-good stack and enterprise stack separation;
l) United States all-states-and-territories localization without fragmentation;
m) North America anchor role boundaries;
n) validity-by-record; and
o) correctionability.
A director shall not knowingly approve or fail to challenge an act that converts the Corporation into a regulator, emergency command body, public warning authority, procurement body, certification body, recognition body, finance-readiness body, broker, dealer, finder, investment adviser, lender, insurer, rating agency, public finance approver, public authority, provider, operator, asset owner, national company, Project SPV, or enterprise execution vehicle.
104.5 Duty of Good Faith. Each director shall act in good faith, with honest purpose, lawful intent, public-benefit orientation, institutional seriousness, and reasonable belief that the action taken is in the best interests of the Corporation and consistent with its mission and governing instruments.
Good faith shall not exist where a director knowingly:
a) authorizes unlawful action;
b) ignores material legal, financial, technical, safeguards, data, AI, cyber, privacy, public authority, finance, certification, procurement, recognition, competition, sanctions, export-control, protected knowledge, or public-safe publication risk;
c) conceals conflicts;
d) permits sponsor or provider control;
e) approves private inurement or impermissible private benefit;
f) tolerates unsupported status claims;
g) permits public authority confusion;
h) permits finance-readiness, certification, procurement, or recognition overclaim;
i) suppresses material corrections;
j) allows misleading public statements;
k) permits misuse of the Corporation’s name, marks, records, reports, datasets, software, technical baselines, controlled rooms, proof receipts, public authority references, or Nexus-compatible claims; or
l) treats institutional convenience, fundraising pressure, sponsor preference, provider pressure, publication urgency, technical momentum, public authority request, or reputational concern as superior to law, mission lock, fiduciary duty, and this Bylaw.
Good faith shall require timely escalation where a director becomes aware of a material boundary issue, conflict, defect, misuse, harm, legal issue, technical vulnerability, safeguards breach, data incident, AI incident, cyber incident, public-safe publication issue, or correction need.
104.6 Duty of Prudence. Each director shall act prudently in the stewardship of the Corporation’s assets, relationships, technical systems, records, public-good software, datasets, repositories, controlled rooms, public authority interfaces, grants, donations, sponsorships, restricted funds, human resources, intellectual property, public reputation, and Nexus interfaces.
Prudence shall require directors to consider:
a) whether an activity is lawful and within corporate purposes;
b) whether it creates undue financial, operational, technical, cyber, data, AI, privacy, legal, public authority, safeguards, public-safe publication, or reputation risk;
c) whether the Corporation has adequate capacity, controls, budget, personnel, insurance, records, counsel, technical safeguards, and governance oversight;
d) whether the activity creates sponsor, donor, funder, provider, host, public authority, investor, insurer, lender, national company, Project SPV, or enterprise capture risk;
e) whether public-good assets are protected against enclosure, misuse, misrepresentation, unsupported commercialization, unauthorized licensing, or technical compromise;
f) whether restricted funds and public support are used for permitted purposes;
g) whether public authority and finance-adjacent materials are properly bounded;
h) whether data, AI, cyber, privacy, and protected knowledge risks are controlled; and
i) whether correction pathways exist.
Prudence shall not require risk elimination, but shall require risks to be identified, bounded, recorded, monitored, escalated, and corrected in proportion to their seriousness.
104.7 Duty of Diligence. Each director shall exercise diligence in attending meetings, reviewing materials, monitoring the Corporation’s condition, participating in Board deliberations, discharging committee assignments where applicable, reviewing major risks, and following up on material matters within the director’s knowledge or assigned responsibilities.
Diligence shall include attention to:
a) Board agendas and materials;
b) financial reports and budgets;
c) grant, donation, sponsorship, restricted fund, and public support reports;
d) legal and compliance reports;
e) tax status and state compliance reports;
f) risk, issue, incident, and control registers;
g) evidence, methods, observability, ontology, technical truth, public-good software, and technical baseline reports;
h) data / AI / cyber / privacy reports;
i) safeguards and protected knowledge reports;
j) public authority interface reports;
k) finance-boundary, procurement-neutrality, certification-boundary, recognition-boundary, provider-neutrality, and sponsor non-control reports;
l) Nexus interface, compatibility note, divergence log, and correction reports; and
m) Board action items and implementation records.
Persistent failure to participate, persistent failure to review materials, persistent failure to disclose conflicts, or persistent failure to engage with known material risks may constitute a breach of duty and may be grounds for corrective action, restriction, non-renewal, or removal where permitted by law and governing instruments.
104.8 Duty of Independence. Each director shall exercise independent judgment and shall not permit judgment to be compromised by personal benefit, employment relationship, consulting relationship, funding relationship, political pressure, public authority relationship, sponsor relationship, provider relationship, host relationship, investor relationship, insurer relationship, lender relationship, national company relationship, Project SPV relationship, institutional affiliation, reputational interest, social pressure, technical allegiance, donor preference, or Nexus ecosystem pressure.
Independence shall require directors to distinguish between:
a) the Corporation’s legal interests and the interests of GCRI Canada;
b) the Corporation’s evidence and methods function and the recognition function of The Global Risks Forum (GRF);
c) the Corporation’s technical input function and the finance-readiness function of The Global Risks Alliance (GRA);
d) the Corporation’s public-good technical stewardship and any Nexus Standards or protocol authority function;
e) the Corporation’s non-executing role and the execution role of national companies, Project SPVs, providers, operators, sponsors, hosts, or enterprise actors;
f) public authority learning and public authority action; and
g) public-good support and sponsor control.
A director who cannot exercise independent judgment on a matter shall disclose the limitation and shall submit to recusal, access restriction, abstention, independent review, committee exclusion, or other mitigation as determined under the Corporation’s conflict and independence rules.
104.9 Duty to Act in the Best Interests of GCRI US. Each director shall act in the best interests of The Global Centre for Risk and Innovation - United States as a separate legal entity. The best interests of the Corporation shall be understood through its lawful purposes, public-benefit mission, nonprofit character, tax posture, fiduciary obligations, records discipline, mission lock, institutional separateness, and public-good role.
A director shall not treat the best interests of any other person or entity as equivalent to the best interests of the Corporation, including:
a) any founder;
b) any director or officer;
c) any member or participant;
d) GCRI Canada;
e) any other GCRI entity;
f) The Global Risks Forum (GRF);
g) The Global Risks Alliance (GRA);
h) Nexus Network, Nexus Standards, or any Nexus entity;
i) any public authority;
j) any sponsor, donor, funder, host, provider, vendor, contractor, university, laboratory, investor, insurer, lender, underwriter, public finance actor, national company, Project SPV, or enterprise actor; or
k) any political, commercial, professional, or community group.
Coordination, shared mission, shared doctrine, shared methods, shared ontology, shared public-good technical assets, shared events, shared councils, shared records, or shared Nexus interfaces shall not eliminate the director’s duty to act in the best interests of the Corporation as a legally separate entity.
104.10 Duty to Preserve Public-Benefit Purpose. Each director shall preserve the Corporation’s public-benefit purpose and shall ensure that programs, transactions, publications, technical releases, controlled rooms, public authority interfaces, data activities, AI activities, cyber activities, research initiatives, grants, sponsorships, donations, contracts, and Nexus interfaces serve lawful public-good purposes.
The duty to preserve public-benefit purpose shall require directors to prevent the Corporation from being used primarily for:
a) private gain;
b) sponsor advantage;
c) provider advantage;
d) donor or funder control;
e) public authority substitution;
f) political or partisan advantage;
g) procurement influence;
h) capital placement;
i) investment, insurance, lending, rating, or public finance execution;
j) certification or recognition sales;
k) technology marketing;
l) enterprise delivery;
m) extraction of protected knowledge;
n) reputational laundering;
o) unsupported public claims; or
p) any purpose inconsistent with the Corporation’s lawful mission.
Where a public-benefit rationale is asserted for a material action, the Board may require a public-benefit record identifying the purpose, beneficiaries, risks, safeguards, legal basis, funding source, conflicts, limitations, and correction pathway.
104.11 Duty to Preserve Nonprofit Character. Each director shall preserve the Corporation’s nonprofit character and shall ensure that the Corporation is not operated for private profit, shareholder return, dividend distribution, enterprise capture, or private control.
The duty to preserve nonprofit character shall include responsibility to prevent:
a) private inurement;
b) impermissible private benefit;
c) excess benefit transactions;
d) disguised distributions;
e) unreasonable compensation;
f) unmanaged related-party transactions;
g) use of restricted funds outside their lawful purpose;
h) sponsor or provider purchase of influence;
i) public-good asset enclosure for private advantage;
j) public authority access purchase;
k) certification, recognition, finance-readiness, or procurement outcome purchase; and
l) conversion of public-good assets into private enterprise assets without lawful authority, independent review, and recorded public-benefit justification.
A director shall support financial controls, compensation review, conflict review, independent approval, restricted fund tracking, audit or review processes, and accurate tax and nonprofit records necessary to preserve nonprofit character.
104.12 Duty to Prevent Private Inurement. Each director shall have an affirmative duty to prevent private inurement to directors, officers, members, founders, related parties, donors, sponsors, funders, providers, hosts, contractors, employees, volunteers, fellows, advisors, public authority participants, universities, laboratories, national companies, Project SPVs, enterprise actors, or other private persons.
Private inurement may arise through direct or indirect transfers, excessive compensation, preferential contracts, below-market asset transfers, inflated service arrangements, controlled access to public-good assets, intellectual property capture, exclusive licensing without public-benefit justification, technical baseline capture, dataset enclosure, software enclosure, sponsored findings, publication suppression, provider preference, sponsor control, public authority access sale, or any other arrangement that improperly diverts the Corporation’s resources or mission.
A director who has reason to believe that private inurement may exist shall cause the matter to be disclosed, reviewed, documented, corrected, restricted, unwound, reported, or escalated as required by law, this Bylaw, tax rules, conflict policy, or Board process.
104.13 Duty to Prevent Impermissible Private Benefit. Each director shall have an affirmative duty to prevent impermissible private benefit. Incidental private benefit may occur in lawful public-benefit programs, but any private benefit shall be no more than incidental, reasonable, necessary, proportionate, recorded, and consistent with the Corporation’s purposes.
Directors shall require review of private benefit risk in connection with:
a) grants, donations, sponsorships, restricted funds, and in-kind support;
b) provider, vendor, contractor, host, and technical partner relationships;
c) public-good software, datasets, dashboards, repositories, technical baselines, and open technology assets;
d) controlled rooms, data rooms, clean rooms, evidence rooms, public authority rooms, and no-download rooms;
e) public authority learning sessions;
f) benchmark, index, challenge, lab, Academy, fellowship, or training programs;
g) public-safe reports, maps, dashboards, and publications;
h) Nexus Docket, Grid, GRF-facing, and GRA-facing technical inputs;
i) use of the Corporation’s name, marks, proof receipts, public authority references, or Nexus-compatible claims; and
j) contracts or arrangements involving related parties or financially interested persons.
Where private benefit risk cannot be cured through limitation, independent review, narrowing, pricing, safeguards, non-exclusivity, open licensing, public-safe notice, or other controls, the Board shall refuse, withdraw, terminate, or restructure the activity.
104.14 Duty to Preserve Tax-Exempt or Tax-Exempt-Compatible Status. Each director shall preserve the Corporation’s tax-exempt or tax-exempt-compatible status as applicable and as recorded. The Board shall ensure that the Corporation does not represent, use, or rely upon a tax classification that has not been obtained, maintained, or recorded.
Directors shall oversee, as applicable:
a) federal tax filings;
b) state tax filings;
c) charitable solicitation registrations;
d) donor acknowledgment practices;
e) grant compliance;
f) restricted fund accounting;
g) unrelated business income review;
h) lobbying and political activity limits;
i) private foundation or public charity classification issues where applicable;
j) fiscal sponsorship or sponsored project issues where applicable;
k) compensation reasonableness;
l) excess benefit transaction controls;
m) dissolution asset restrictions;
n) public support records; and
o) tax status change controls.
A director shall not knowingly approve an activity that materially threatens tax status without appropriate review, recorded mitigation, and Board approval where required.
104.15 Duty to Preserve Non-Execution. Each director shall preserve the Corporation’s non-execution perimeter. The Corporation’s role shall remain evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baseline, public authority learning, and public-safe technical stewardship unless a lawful and recorded change is made by competent authority and is consistent with the Articles or Certificate and this Bylaw.
Directors shall ensure that the Corporation does not conduct or hold itself out as conducting:
a) securities offerings, solicitations, brokerage, dealer activity, finder activity, underwriting, or capital placement;
b) investment advice, asset management, portfolio management, suitability determinations, or transaction recommendations;
c) banking, deposit-taking, payment intermediation, clearing, settlement, escrow, custody, or third-party fund control;
d) lending, credit origination, credit approval, credit brokerage, guarantees, or revenue guarantees;
e) insurance placement, underwriting, pricing, binding, claims handling, approval, or risk-bearing intermediation;
f) ratings, credit opinions, bankability opinions, insurability opinions, financeability determinations, or resilience ratings;
g) public finance approval, grant approval, budget allocation, appropriation, tax credit approval, public guarantee, MDB / DFI approval, or sovereign finance approval;
h) procurement award, vendor selection, procurement approval, or procurement preference;
i) certification, accreditation, legal compliance approval, conformance approval, or regulatory safe harbor;
j) recognition, standing, maturity determination, public-facing legitimacy determination, or Grid / Docket approval; or
k) emergency command, official public warning, evacuation instruction, dispatch, incident management, public health order, safety command, regulation, enforcement, permit issuance, or public authority decision.
A director shall cause suspected execution drift to be held, quarantined, reviewed, re-scoped, externalized, referred, corrected, or terminated.
104.16 Duty to Preserve Nexus Role Separation. Each director shall preserve the separation of functions among GCRI US, GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, global, regional, national, state, territorial, Tribal, metropolitan, local, and sectoral consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, and enterprise actors.
Directors shall ensure that:
a) GCRI US does not assume GRF’s recognition, registry, maturity-records, standing, claims-discipline, stakeholder-formation, public-safe reporting, or public-facing legitimacy function;
b) GCRI US does not assume GRA’s finance-readiness, capital-readability, proof-pack, insurance-readiness, diligence-translation, RNFD, NFD, UNFSD, capital-reader-room, or regulated-perimeter discipline function;
c) GCRI US does not assume Nexus Standards or protocol authority functions unless separately and lawfully designated;
d) GCRI US does not assume public authority functions;
e) GCRI US does not assume enterprise execution functions;
f) evidence inputs are not converted into recognition determinations;
g) technical inputs are not converted into finance-readiness determinations;
h) public-good software and technical baselines are not converted into procurement mandates or certification outcomes; and
i) Nexus-compatible language is used only with authority, limitation, and record.
Directors shall require role-separation records, compatibility notes, divergence logs, controlled vocabulary, public-safe notices, and correction pathways where confusion may arise.
104.17 Duty to Preserve United States Legal Separateness. Each director shall preserve the Corporation’s United States legal separateness. GCRI US shall remain a separate legal person governed by its own Articles or Certificate, this Bylaw, Board, officers, records, funds, obligations, contracts, tax records, policies, and fiduciary duties.
Directors shall not permit shared mission, shared doctrine, shared ontology, shared methods, shared technical baselines, shared records, shared personnel, shared events, shared systems, shared public materials, shared websites, shared repositories, shared councils, shared controlled rooms, shared public authority interfaces, shared funders, shared sponsors, or shared Nexus interfaces to create or imply legal merger, alter ego status, branch status, agency, partnership, joint venture, common treasury, single employer status, joint employer status, mutual authority, or shared liability without express lawful instrument and Board approval where required.
The Board shall require clear public descriptions, contract clauses, repository notices, governance records, public-safe statements, and correction mechanisms to preserve separateness.
104.18 Duty to Preserve Separateness From GCRI Canada, GRF, GRA, Nexus Entities, National Companies, Project SPVs, Providers, Sponsors, Hosts, and Public Authorities. Each director shall ensure that the Corporation’s legal, financial, operational, governance, records, technical, and public-facing separateness is preserved from GCRI Canada, other GCRI entities, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus entities, national companies, state or regional operating companies, Project SPVs, providers, sponsors, hosts, donors, funders, universities, laboratories, public authorities, and enterprise actors.
Separateness shall be preserved through:
a) distinct corporate records;
b) distinct Board and officer authority;
c) distinct bank accounts and financial controls;
d) distinct contracting authority;
e) distinct tax and filing records;
f) distinct employment or contractor arrangements where applicable;
g) distinct public authority capacity records;
h) distinct role descriptions;
i) distinct intellectual property, data, software, and repository authority records;
j) distinct grant, donation, sponsorship, and restricted fund records;
k) distinct risk, incident, and correction records; and
l) public-safe limitation language.
Coordination shall not be confused with merger. Alignment shall not be confused with control. Interoperability shall not be confused with shared authority. Public-good partnership shall not be confused with shared liability.
104.19 Duty to Preserve Evidence Integrity. Each director shall preserve evidence integrity. Evidence integrity means that evidence-related outputs, records, methods, classifications, confidence statements, uncertainty statements, source-lineage statements, provenance records, proof receipts, public-safe reports, dashboards, maps, and technical inputs shall be produced, reviewed, versioned, limited, corrected, and communicated in a manner that is accurate, supportable, transparent to the degree appropriate, public-safe, and bounded by authority.
Directors shall ensure that evidence integrity is protected from:
a) sponsor influence;
b) provider influence;
c) donor or funder pressure;
d) public authority pressure;
e) political pressure;
f) research misconduct;
g) data misuse;
h) AI hallucination or automated-output inflation;
i) selective publication;
j) suppressed uncertainty;
k) overstated confidence;
l) unsupported validation claims;
m) misleading visualizations;
n) public authority overclaim;
o) finance-readiness overclaim;
p) certification or procurement overclaim;
q) recognition overclaim;
r) protected knowledge misuse; and
s) failure to correct.
Evidence shall remain evidence. It shall not be transformed by Board silence, public repetition, technical packaging, public authority participation, sponsor use, provider use, or Nexus reference into final authority, public warning, recognition, finance-readiness, certification, procurement approval, rating, or emergency command.
104.20 Duty to Preserve Research Integrity. Each director shall preserve research integrity across the Corporation’s research, education, Academy, fellowship, laboratory, challenge, evaluation, benchmark, methods, public-good software, technical baseline, and publication activities.
Research integrity shall require, as applicable:
a) truthful design, conduct, recording, analysis, and reporting;
b) appropriate research ethics review;
c) human-subjects review where required;
d) community review where appropriate;
e) Tribal, Indigenous, local, territorial, health-sensitive, youth, vulnerable population, civil rights, accessibility, and protected knowledge review where applicable;
f) sponsor and funder disclosure;
g) conflict disclosure;
h) peer review or technical review where appropriate;
i) reproducibility and replication discipline where appropriate;
j) AI-use disclosure where material;
k) data rights and privacy compliance;
l) publication integrity;
m) correction, supersession, withdrawal, retraction, takedown, and archive pathways; and
n) protection against retaliation and research suppression.
Directors shall not permit research to be used as a disguised commercial endorsement, provider preference, public authority approval, finance-readiness input overclaim, certification substitute, procurement tool, recognition purchase, or protected knowledge extraction mechanism.
104.21 Duty to Preserve Data / AI / Cyber / Privacy Integrity. Each director shall preserve data, AI, cyber, and privacy integrity. The Board shall ensure that the Corporation’s data, AI, compute, cybersecurity, repository, controlled-room, software, dashboard, sensor, digital twin, DePIN, DLT, blockchain, AI-RAN, O-RAN, and public authority data activities are governed by lawful authority, appropriate controls, access classification, security classification, privacy review, AI governance, cyber safeguards, logging, retention, deletion, incident response, and correction pathways.
The duty shall require directors to oversee, as applicable:
a) data minimization;
b) lawful basis and consent where required;
c) data-use limitation;
d) public authority data controls;
e) health-sensitive, cyber-sensitive, infrastructure-sensitive, commercially sensitive, finance-sensitive, community-protected, Tribal / Indigenous, local, territorial, cultural, environmental, and protected knowledge controls;
f) model registers;
g) inference records;
h) compute workload records;
i) dataset cards, model cards, system cards, benchmark cards, and evaluation records;
j) secure development lifecycle;
k) SBOM, dependency, signing, provenance, vulnerability, key, token, and credential controls;
l) identity and access management;
m) incident response;
n) disaster recovery and business continuity; and
o) restrictions on uploading controlled materials to unapproved AI systems.
Directors shall ensure that no AI, model, dashboard, digital twin, proof receipt, ledger entry, DePIN signal, AI-RAN signal, sensor output, cyber telemetry, or automated score is treated as institutional authority without competent human review, record support, limitation, and correction pathway.
104.22 Duty to Preserve Public Authority Boundary Discipline. Each director shall preserve public authority boundary discipline. The Corporation may support public authority learning, evidence literacy, technical literacy, scenario learning, simulation, tabletop exercises, after-action learning, capacity classification, public-safe reporting support, and public authority interface records, but shall not become or substitute for a public authority.
Directors shall prevent the Corporation from:
a) issuing official public warnings;
b) commanding emergency response;
c) issuing evacuation or dispatch instructions;
d) making public health orders;
e) making regulatory decisions;
f) issuing permits;
g) approving legal compliance;
h) enforcing law;
i) approving public procurement;
j) approving public finance;
k) allocating public budgets;
l) creating sovereign obligations;
m) representing public-private partnership status without lawful authority;
n) speaking on behalf of a public authority without written authorization; or
o) converting public authority participation into official adoption.
The Board shall require capacity classification, public authority reference review, limitation language, meeting records, public-safe notices, and correction pathways for material public authority interfaces.
104.23 Duty to Preserve Finance and Regulated-Activity Boundary Discipline. Each director shall preserve finance and regulated-activity boundary discipline. The Corporation shall not be used to conduct securities, investment advisory, brokerage, dealer, finder, underwriting, lending, banking, insurance, rating, public finance, procurement, certification, or other regulated execution activity outside lawful authority.
Directors shall require heightened review for any activity involving:
a) capital readers;
b) investors;
c) insurers;
d) lenders;
e) underwriters;
f) banks;
g) public finance actors;
h) grant-making public authorities;
i) procurement authorities;
j) ratings, scores, rankings, or maturity claims;
k) finance-readiness, insurance-readiness, bankability, investability, capital-readability, or proof-pack language;
l) Docket, Grid, Nexus-compatible, recognition, certification, accreditation, compliance, or conformance claims;
m) sponsor, provider, host, or enterprise actor materials that may be used in financing, procurement, insurance, grant, or public authority settings; and
n) public-safe reports or technical baselines with potential reliance by third parties.
Directors shall ensure that GRA-facing technical inputs remain technical inputs and do not become finance-readiness determinations by GCRI US. Directors shall ensure that GRF-facing evidence inputs remain evidence inputs and do not become recognition or public-facing legitimacy determinations by GCRI US.
104.24 Duty to Preserve Community Safeguards and Protected Knowledge. Each director shall preserve community safeguards and protected knowledge. The Corporation shall not pursue technical, evidence, public authority, public-safe publication, sponsor, provider, or Nexus objectives in a manner that disregards civil rights, accessibility, Indigenous governance respect, Tribal protocols, local and territorial knowledge, community safeguards, protected knowledge, vulnerable persons, or public safety.
Directors shall require safeguards review where activities involve:
a) Tribal or Indigenous knowledge;
b) Indigenous data;
c) local or territorial knowledge;
d) cultural, environmental, sacred, sensitive, or community-protected information;
e) health-sensitive or youth-related data;
f) vulnerable or remote communities;
g) disaster-exposed or climate-exposed communities;
h) infrastructure-sensitive locations;
i) public-safe mapping;
j) surveillance or re-identification risk;
k) AI training or model improvement using protected materials;
l) publication of maps, dashboards, datasets, or digital twins;
m) sponsor or provider access to community information;
n) grievance, remedy, protected participation, or non-retaliation issues; and
o) public authority or media use of community information.
The Board shall ensure that protected knowledge is not extracted, exposed, commercialized, tokenized, mapped, trained on, transferred, or repurposed without lawful authority, recorded safeguards, and appropriate respect for consent, non-consent, attribution, restriction, withdrawal, correction, and remedy pathways.
104.25 Duty to Disclose Conflicts. Each director shall disclose actual, potential, and perceived conflicts of interest in accordance with law, this Bylaw, the conflict policy, Board procedures, and any applicable committee or controlled-room rules.
Conflict disclosure shall include, as applicable:
a) financial interests;
b) employment, consulting, advisory, board, officer, fiduciary, or ownership roles;
c) sponsor, donor, funder, provider, host, contractor, vendor, investor, insurer, lender, underwriter, bank, public finance actor, public authority, national company, Project SPV, university, laboratory, or enterprise relationships;
d) family, household, close personal, professional, or institutional relationships;
e) research conflicts;
f) publication conflicts;
g) data, AI, cyber, repository, software, technical asset, or intellectual property conflicts;
h) public authority conflicts;
i) political, lobbying, campaign, or government ethics conflicts where applicable;
j) conflicts relating to Tribal, Indigenous, community, protected knowledge, civil rights, accessibility, or safeguards matters;
k) dual roles with GCRI Canada, GRF, GRA, Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, or hosts; and
l) any circumstance that may reasonably affect independent judgment or public trust.
Disclosure shall be timely, complete, updated when circumstances change, and recorded. Failure to disclose may constitute a breach of fiduciary duty and may support corrective action, recusal, access restriction, committee restriction, non-renewal, removal, or other remedy where lawful.
104.26 Duty to Recuse Where Required. Each director shall recuse from deliberation, recommendation, access, voting, approval, oversight, or implementation where required by law, this Bylaw, Board policy, conflict policy, committee charter, controlled-room rule, counsel determination, independent review, or Board decision.
Recusal may require:
a) abstention from voting;
b) exclusion from deliberation;
c) exclusion from confidential materials;
d) exclusion from controlled-room or data-room access;
e) exclusion from committee participation;
f) restriction from officer or staff instruction;
g) restriction from external communication;
h) restriction from public authority interaction;
i) restriction from sponsor, provider, donor, funder, host, national company, Project SPV, or enterprise interface;
j) restriction from publication approval;
k) restriction from technical release approval;
l) restriction from correction decision-making; or
m) other mitigation appropriate to the conflict.
A recused director shall not attempt to influence the matter indirectly through informal communications, staff pressure, sponsor or provider channels, public authority relationships, technical contributors, public statements, social pressure, funding leverage, or Nexus-interface channels.
104.27 Duty to Support Correction and Supersession. Each director shall support correctionability and supersession discipline. Where a director becomes aware of a material error, incomplete record, unsupported claim, misleading publication, defective method, unreliable evidence, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, recognition overclaim, provider preference claim, sponsor control issue, data misuse, AI misuse, cyber issue, privacy issue, protected knowledge concern, safeguards issue, conflict, authority defect, or governance defect, the director shall cause the matter to be escalated through appropriate channels.
The duty to support correction shall include, as applicable:
a) preserving evidence;
b) avoiding concealment;
c) notifying the Chair, Secretary, relevant officer, committee, counsel, compliance function, safeguards function, or Board;
d) supporting hold, quarantine, restriction, or publication freeze where needed;
e) supporting review and root-cause analysis;
f) supporting correction, clarification, limitation, supersession, withdrawal, retraction, takedown, archive, or public-safe notice where appropriate;
g) supporting affected-person, public authority, funder, sponsor, provider, or community notice where required and lawful;
h) supporting recurrence prevention; and
i) ensuring that corrections are recorded and linked to affected records.
No director shall suppress, delay, weaken, or conceal a correction to protect reputation, funding, sponsor relationship, provider relationship, public authority relationship, personal interest, or institutional convenience.
104.28 Fiduciary Duty Records. The Corporation shall maintain Fiduciary Duty Records sufficient to demonstrate that directors have been appointed, informed, trained, disclosed, recused, deliberated, decided, monitored, corrected, and held accountable in accordance with law, the Articles or Certificate, this Bylaw, Board policies, and fiduciary standards.
Fiduciary Duty Records shall include, as applicable:
a) director consent records, appointment records, election records, qualification records, independence records, fit-and-proper records, training records, certification-of-understanding records, and director register entries;
b) Board meeting notices, agendas, materials, minutes, attendance records, quorum records, vote records, abstention records, recusal records, dissent records where recorded, executive session records, controlled-session records, and written consent records;
c) conflict disclosures, related-party disclosures, independence reviews, dual-role reviews, recusal determinations, access restrictions, conflict mitigation records, and conflict violation records;
d) records of legal review, tax review, nonprofit review, public authority boundary review, finance-boundary review, certification-boundary review, procurement-neutrality review, recognition-boundary review, provider-neutrality review, sponsor non-control review, safeguards review, data / AI / cyber review, privacy review, research integrity review, competition review, sanctions review, export-control review, and controlled-technology review;
e) mission-lock records, public-benefit purpose records, nonprofit character records, non-distribution records, private inurement review records, private benefit review records, tax-exempt or tax-exempt-compatible records, all-states-and-territories records, North America anchor records, GCRI Canada interface records, GRF interface records, GRA interface records, Nexus interface records, compatibility notes, divergence logs, and equivalence notes;
f) evidence integrity records, research integrity records, methods records, observability records, ontology records, technical truth records, public-good R&D records, public-good software records, open technical baseline records, verifiable compute records, verifiable intelligence records, proof receipt records, public-safe publication records, correction records, supersession records, withdrawal records, retraction records, takedown records, and archive records;
g) data governance records, privacy records, AI governance records, cybersecurity records, secure compute records, model register records, inference record records, compute workload records, repository records, software release records, SBOM records, vulnerability records, key and credential records, incident records, disaster recovery records, and business continuity records;
h) community safeguard records, Tribal and Indigenous protocol records, Indigenous data safeguard records, protected knowledge records, local and territorial knowledge records, civil rights records, accessibility records, public-safe mapping records, grievance records, remedy records, protected participation records, non-retaliation records, and stop-the-line records;
i) records of fiduciary concern, director inquiry, Board follow-up, corrective action, legal hold, investigation, escalation, restriction, removal, ratification, clarification, public-safe notice, and recurrence prevention; and
j) responsible owner, custodian, authority, version, effective date, review date, repository location, access class, publication class, retention class, legal hold status, deletion status, archive status, and metadata.
The governing rule of this Section is that a director’s fiduciary duties are not merely formal corporate duties; they are the legal and institutional discipline by which the Corporation preserves public trust, public-benefit purpose, lawful nonprofit status, evidence integrity, technical truth, public-safe operation, data / AI / cyber integrity, community safeguards, Nexus role separation, non-execution, validity-by-record, and correctionability. Each director shall serve with care, loyalty, obedience, good faith, prudence, diligence, independence, candor, and correctional responsibility, and every material exercise of fiduciary judgment shall be lawful, recorded, bounded, reviewable, public-safe where relevant, and correctionable.
Section 105. Board Composition, Number, Structure, Independence, and Skills Mix
105.1 Board Composition Purpose. The Board shall be composed, structured, maintained, reviewed, renewed, and, where necessary, rebalanced to provide competent fiduciary governance for the Corporation as a United States nonprofit, non-distributing, public-benefit, non-executing technical institution and United States / North America anchor for evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baselines, verifiable compute and intelligence methods, public authority learning, community safeguards, and Nexus-compatible public-good stewardship.
Board composition shall be designed to support informed judgment, fiduciary independence, legal compliance, public-benefit purpose, tax-exempt or tax-exempt-compatible discipline, all-states-and-territories awareness, North America interface awareness, public authority boundary discipline, finance and regulated-activity boundary discipline, data / AI / cyber integrity, research integrity, community safeguards, provider neutrality, sponsor non-control, validity-by-record, correctionability, and durable institutional trust.
The Board shall not be composed for ceremonial prestige, fundraising optics, sponsor satisfaction, provider influence, public authority signaling, political positioning, technical popularity, founder control, affiliate control, ecosystem control, capital-reader influence, or enterprise execution advantage. Board composition shall be mission-governance composition, not marketing composition.
The Board shall maintain a composition sufficient to exercise real oversight over:
a) corporate governance, fiduciary duties, nonprofit compliance, tax posture, corporate records, conflicts, compensation, and internal controls;
b) evidence doctrine, methods stewardship, observability, ontology, technical truth, public-safe publication, public-good R&D, public-good software, open technical baselines, and correction systems;
c) data governance, privacy, AI governance, cybersecurity, secure compute, verifiable compute, verifiable intelligence, model registers, inference records, compute workload records, repositories, software release, SBOM, vulnerability, incident response, and business continuity;
d) public authority learning, public authority capacity classification, regulator-listening participation, public finance reader participation, emergency-management learning participation, public infrastructure operator participation, and public authority boundary records;
e) community safeguards, Tribal and Indigenous protocol respect, Indigenous data safeguards, local and territorial knowledge, protected knowledge, civil rights, accessibility, public-safe mapping, grievance, remedy, protected participation, and non-retaliation;
f) finance, securities, investment adviser, broker-dealer, finder, banking, lending, insurance, underwriting, rating, public finance, procurement, certification, accreditation, recognition, provider-neutrality, sponsor non-control, anti-capture, and regulated-perimeter discipline; and
g) GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, and enterprise-stack interfaces.
105.2 Minimum Number of Directors. The Board shall have not fewer than the minimum number of directors required by applicable law, the Articles or Certificate, or this Bylaw. If applicable law permits a lower number, the Corporation shall nevertheless maintain a Board size sufficient to support independent fiduciary judgment, lawful quorum, committee formation where needed, conflict recusal capacity, emergency continuity, and oversight of the Corporation’s technical, legal, public-benefit, safeguards, data / AI / cyber, public authority, and Nexus-interface obligations.
The minimum number of directors shall not be set or maintained at a level that creates material risk of:
a) founder control;
b) sponsor control;
c) provider control;
d) donor or funder control;
e) public authority confusion;
f) related-party dominance;
g) inability to form independent review;
h) inability to maintain quorum after recusals;
i) inability to supervise officers;
j) inability to review major transactions;
k) inability to oversee data / AI / cyber, safeguards, public authority, finance-boundary, certification-boundary, procurement-neutrality, recognition-boundary, or Nexus role-separation matters; or
l) inability to preserve continuity during vacancies, emergencies, resignations, removals, conflicts, or access restrictions.
If the number of directors falls below the required minimum, the remaining directors shall act only to the extent permitted by law and this Bylaw to restore lawful governance, fill vacancies, preserve records, maintain essential legal and fiduciary functions, protect assets, prevent harm, and avoid prohibited functions.
105.3 Maximum Number of Directors. The Board may have a maximum number of directors as fixed by the Articles or Certificate, this Bylaw, or Board resolution where lawful. The maximum number shall be set to preserve effective governance, deliberative quality, confidentiality, fiduciary accountability, quorum discipline, conflict management, Board security, and efficient decision-making.
The Board shall not be expanded merely to accommodate sponsors, donors, funders, providers, hosts, public authorities, investors, insurers, lenders, public finance actors, national companies, Project SPVs, universities, laboratories, media figures, political actors, technical vendors, institutional affiliates, or prestige appointments unless each director is independently eligible, mission-aligned, conflict-reviewed, and capable of discharging fiduciary duties to the Corporation.
A large Board shall not be used to dilute accountability, obscure control, create informal factions, mask sponsor or provider influence, create public authority signaling, manufacture legitimacy, avoid difficult fiduciary decisions, or convert advisory participation into governance. Where stakeholder breadth is useful but fiduciary governance would be impaired by Board enlargement, the Corporation may use advisory councils, Helix Councils, public authority forums, scientific panels, working groups, expert panels, or competence cells with clearly bounded non-governance authority.
105.4 Number Fixed by Articles, Bylaw, Board Resolution, or Member Action Where Required. The number of directors shall be fixed in accordance with applicable law, the Articles or Certificate, this Bylaw, Board resolution, member action where required, or other competent governance record. No website statement, public deck, grant proposal, sponsor agreement, donor letter, public authority memorandum, committee charter, advisory council listing, working group roster, Nexus interface record, repository file, AI summary, public announcement, or informal practice shall change the authorized number of directors.
Any action fixing, increasing, reducing, or otherwise modifying the number of directors shall be recorded in the Board Authority Records and shall identify, as applicable:
a) the legal authority for the change;
b) the prior number or range of directors;
c) the new number or range of directors;
d) the effective date;
e) whether member approval is required;
f) whether amendment of the Articles or Certificate or this Bylaw is required;
g) the governance reason for the change;
h) the effect on quorum;
i) the effect on committees;
j) the effect on independence and conflicts;
k) the effect on skills coverage;
l) the effect on continuity and vacancies; and
m) any transition, savings, or implementation rule.
A reduction in the number of directors shall not shorten the term of any incumbent director unless permitted by law and properly recorded. A change in Board size shall not be used to remove a director indirectly, alter voting outcomes improperly, avoid recusals, defeat member rights, concentrate control, or impair independent oversight.
105.5 Independent Director Standard. The Board shall maintain a meaningful independent director standard appropriate to the Corporation’s public-benefit, nonprofit, technical, safeguards, public authority, and Nexus-interface functions. A director shall be considered independent only if the director is capable of exercising objective fiduciary judgment for the Corporation without material compromise by financial interest, employment interest, consulting interest, donor interest, sponsor interest, provider interest, host interest, public authority interest, political interest, investor interest, insurer interest, lender interest, national company interest, Project SPV interest, affiliate interest, family interest, or other relationship that could reasonably impair independence.
Independence shall be assessed with respect to:
a) compensation from the Corporation or related entities;
b) contracts, grants, sponsorships, donations, restricted funds, in-kind support, or other financial arrangements;
c) employment, consulting, advisory, board, officer, fiduciary, or ownership relationships;
d) relationships with GCRI Canada, GRF, GRA, Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, contractors, investors, insurers, lenders, underwriters, banks, public finance actors, and enterprise-stack actors;
e) participation in matters that may generate recognition, finance-readiness, certification, procurement advantage, provider preference, public authority access, technical baseline influence, or public-safe claim value;
f) personal, family, household, professional, or institutional relationships;
g) research conflicts and publication interests;
h) data, AI, cyber, software, repository, intellectual property, model, dataset, or technical asset interests;
i) political, lobbying, campaign, government ethics, or public authority relationships where relevant; and
j) any other circumstance that could reasonably create actual, potential, or perceived capture.
The Board may adopt independence categories, including independent, non-independent, conflicted for specific matters, conditionally independent subject to mitigation, or not eligible for Board service. Independence shall be reviewed at appointment, annually, and upon material change in circumstances.
105.6 Public-Benefit Governance Competence. The Board shall include directors who collectively possess competence in public-benefit governance. Public-benefit governance competence means the ability to govern an institution whose legitimacy depends on public-good purpose, mission fidelity, fiduciary independence, anti-capture discipline, community safeguards, public trust, transparent records where appropriate, correctionability, and lawful restraint.
The Board shall ensure that its members collectively understand that public-benefit governance is not equivalent to commercial growth governance, public relations governance, sponsor relationship management, political access management, public authority substitution, or enterprise delivery governance. Public-benefit governance requires attention to:
a) public mission;
b) beneficiaries and affected communities;
c) trust-preserving boundaries;
d) lawful public-interest purpose;
e) conflict discipline;
f) stakeholder participation without stakeholder control;
g) transparency balanced with confidentiality, privacy, cyber, legal, public authority, and protected knowledge limits;
h) harm avoidance;
i) safeguards;
j) public-safe publication; and
k) correction and accountability.
At least a meaningful portion of the Board shall be able to interrogate whether a proposed strategy, transaction, program, publication, technical release, public authority interface, sponsor arrangement, provider relationship, or Nexus alignment is genuinely public-benefit aligned and not merely public-benefit described.
105.7 United States Nonprofit Governance Competence. The Board shall include directors who collectively possess competence in United States nonprofit governance, including the structure, duties, limitations, records, fiduciary obligations, and compliance expectations of a United States nonprofit corporation.
Such competence shall include awareness of:
a) governing state nonprofit corporation law;
b) Articles or Certificate control;
c) bylaws and Board resolutions;
d) director duties;
e) officer authority;
f) committee authority;
g) member rights where applicable;
h) conflict-of-interest discipline;
i) related-party transaction review;
j) compensation review;
k) private inurement and private benefit rules;
l) corporate records;
m) state qualification and good-standing obligations;
n) charitable solicitation obligations where applicable;
o) restricted fund discipline; and
p) dissolution and public-good asset rules.
The Board shall not rely solely on technical excellence, founder vision, public authority relationships, sponsor support, philanthropic reputation, or Nexus ecosystem familiarity as substitutes for nonprofit governance competence.
105.8 Federal Tax and State Nonprofit Law Competence. The Board shall include, retain access to, or obtain competent advice concerning federal tax and state nonprofit law matters relevant to the Corporation’s status, operations, support arrangements, revenue, compensation, transactions, publications, and public representations.
The Board’s collective competence or advisory access shall cover, as applicable:
a) federal tax-exempt or tax-exempt-compatible status;
b) charitable or non-charitable nonprofit classification;
c) Section 501(c)(3), 501(c)(4), 501(c)(6), fiscal sponsorship, supporting organization, sponsored project, or other classification issues where relevant;
d) private inurement;
e) impermissible private benefit;
f) excess benefit transactions;
g) unrelated business income;
h) donor acknowledgments;
i) sponsorship and advertising distinctions where relevant;
j) restricted funds;
k) public support tests where relevant;
l) lobbying and political activity limits where relevant;
m) state tax and registration obligations;