> For the complete documentation index, see [llms.txt](https://docs.therisk.global/organization/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.therisk.global/organization/organization/governance/bylaws/gcri-us/article-viii.-finance.md).

# ARTICLE VIII. FINANCE

### Section 222. Fiscal Stewardship Purpose

#### 222.1 Fiscal Stewardship Purpose

222.1.1 The fiscal governance of The Global Centre for Risk and Innovation - United States shall be conducted as a public-benefit, nonprofit, non-distributing, mission-locked, non-executing, records-supported, legally compliant, tax-disciplined, anti-capture, and correctionable stewardship function.

222.1.2 All funds, assets, revenue, reserves, grants, donations, sponsorships, subscriptions, fees, reimbursements, cost-recovery receipts, in-kind contributions, public-good infrastructure support, intellectual property, technical assets, software assets, data-related assets, restricted funds, board-designated funds, and institutional resources of the Corporation shall be held, administered, used, committed, invested where lawful, accounted for, reported, restricted, released, corrected, and archived solely in furtherance of the Corporation’s lawful public-benefit purposes and subject to this Bylaw.

222.1.3 Fiscal stewardship shall preserve the Corporation’s role as a United States public-benefit technical institution and North America anchor for evidence, methods, observability, ontology, technical truth, public-good R\&D, public-good software, open technical baselines, public authority learning, public-safe publication, community safeguards, verifiable compute and verifiable intelligence methods, and Nexus-compatible public-good stack support.

222.1.4 Fiscal governance shall not be used to convert the Corporation into a fund, bank, lender, insurer, underwriter, rating agency, broker, dealer, investment adviser, capital-placement entity, public finance approver, procurement body, certification body, recognition body, emergency command body, public warning authority, national company, Project SPV, qualified provider, asset owner, infrastructure operator, or enterprise execution vehicle.

#### 222.2 Public-Benefit Asset Stewardship

222.2.1 The assets of the Corporation are dedicated to the Corporation’s public-benefit purposes and shall not be distributed, diverted, encumbered, pledged, transferred, licensed, spent, or otherwise used for private inurement, impermissible private benefit, improper related-party benefit, sponsor control, provider preference, public authority access purchase, recognition purchase, finance-readiness purchase, certification purchase, procurement advantage, or enterprise-stack capture.

222.2.2 Asset stewardship includes stewardship of financial assets and non-financial public-good assets, including:

222.2.2(a) cash, deposits, receivables, grants, donations, sponsorship receipts, subscriptions, fees, and cost-recovery amounts;\
222.2.2(b) public-good software, repositories, schemas, APIs, SDKs, dashboards, data dictionaries, model cards, system cards, benchmark cards, evaluation harnesses, test vectors, technical baselines, reference architectures, proof receipts, controlled vocabulary, and technical profiles;\
222.2.2(c) datasets, data rights, data-sharing rights, model access rights, compute credits, cloud credits, AI tool access, cyber tools, software licenses, hardware, equipment, facilities access, and technical services received or developed by the Corporation;\
222.2.2(d) intellectual property, copyrights, trademarks, trade secrets where lawfully held, licenses, contributor rights, publication rights, research outputs, methods, whitepapers, public-safe reports, training materials, and Academy materials; and\
222.2.2(e) governance records, financial records, grant records, contract records, public authority capacity records, controlled-room records, evidence records, methods records, correction records, and public-safe publication records.

#### 222.3 Non-Distribution and No Private Inurement Rule

222.3.1 No part of the net earnings, assets, income, surplus, reserves, technical assets, public-good software value, grant value, donor value, sponsorship value, in-kind value, institutional opportunity, or public-good asset value of the Corporation shall inure to the benefit of any director, officer, member, non-voting member, supporter, subscriber, donor, sponsor, funder, provider, vendor, host, contractor, founder, employee, fellow, advisor, volunteer, contributor, maintainer, public authority participant, capital actor, national company, Project SPV, Related Party, or private person except through lawful, reasonable, mission-aligned, properly authorized, independently reviewed where required, and recorded arrangements.

222.3.2 Reasonable compensation, reimbursement, grants, stipends, scholarships, fellowships, awards, contractor payments, professional fees, licensing payments, and vendor payments may be permitted only where lawful, documented, approved within authority, not excessive, not disguised distribution, not tied to prohibited outcomes, and not inconsistent with nonprofit character, tax-exempt or tax-exempt-compatible posture, public-benefit purpose, and this Bylaw.

222.3.3 The Corporation shall not approve or tolerate excess benefit transactions, disguised distributions, insider enrichment, support-for-control, support-for-outcome, pay-to-play, access-for-money, related-party favoritism, improper compensation, improper reimbursement, private capture of public-good technical assets, or use of the Corporation’s fiscal systems for private or enterprise-stack advantage.

#### 222.4 Fiscal Non-Execution Rule

222.4.1 Fiscal stewardship by the Corporation shall be strictly non-executing. The Corporation may receive, hold, administer, budget, spend, account for, and report its own funds and assets for lawful public-benefit purposes, but it shall not act as a financial intermediary, fiduciary for investors, broker, dealer, finder, lender, insurer, underwriter, bank, escrow agent, trustee of third-party execution funds, public finance authority, procurement authority, capital allocator, investment sponsor, fund manager, guarantee provider, or Project SPV treasury unless separately and lawfully structured outside the prohibited functions of GCRI US and expressly authorized by competent governing record.

222.4.2 The Corporation shall not hold third-party project capital for investment, construction, insurance, lending, underwriting, public finance, procurement execution, commercial delivery, infrastructure deployment, enterprise operation, or Project SPV execution in a manner that creates regulated activity, public authority confusion, fiduciary execution responsibility, or enterprise-stack liability.

222.4.3 Any proposed fiscal function that may resemble securities activity, investment advice, capital placement, banking, lending, insurance, underwriting, rating, public finance approval, public grant approval, procurement execution, escrow, custody, guarantee, fiduciary execution, or enterprise delivery shall be stopped, held, quarantined, re-scoped, referred, externally structured, or terminated pending counsel, compliance, Board, and regulated-perimeter review.

#### 222.5 Role-Separation Fiscal Rule

222.5.1 Fiscal governance shall preserve separation between GCRI US, GCRI Canada, other GCRI entities, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, global, regional, national, state, territorial, Tribal, local, and sectoral consortiums, national companies, Project SPVs, qualified enterprise providers, hosts, sponsors, public authorities, universities, laboratories, capital actors, and enterprise-stack actors.

222.5.2 Shared mission, shared doctrine, shared ontology, shared methods, shared technical baselines, shared public-good software, shared publications, shared events, shared programs, shared records, shared personnel, shared systems, shared repositories, shared data rooms, shared controlled rooms, or shared Nexus interfaces shall not create shared treasury, shared liability, agency, partnership, joint venture, common employer status, fiscal consolidation, implied guarantee, mutual authority, or authority to bind another entity.

222.5.3 The Corporation shall maintain separate accounts, books, budgets, approvals, signatories, contracts, tax records, donor records, grant records, sponsorship records, support records, asset records, and financial statements unless a lawful shared-service or interface arrangement is expressly approved, properly documented, independently reviewed where required, and structured to preserve legal separateness.

#### 222.6 Fiscal Support-Without-Control Rule

222.6.1 Grants, donations, sponsorships, in-kind contributions, subscriptions, fees, public-good infrastructure support, public authority support, university support, laboratory support, provider support, host support, and enterprise support may be accepted only where support is lawful, mission-aligned, tax-compatible, nonprofit-compatible, conflict-reviewed, anti-capture-compliant, records-supported, and non-controlling.

222.6.2 No support relationship shall create or imply:

222.6.2(a) governance authority, Board authority, officer authority, committee authority, council authority, repository authority, publication authority, technical baseline authority, public authority authority, or Nexus-system authority;\
222.6.2(b) recognition, maturity standing, registry status, public-facing legitimacy, claims clearance, Docket approval, Grid guarantee, Nexus-compatible status, or GRF action;\
222.6.2(c) finance-readiness, capital-readability, proof-pack approval, insurance-readiness, bankability, investability, creditworthiness, underwriting approval, lending approval, public finance approval, rating, or GRA action;\
222.6.2(d) certification, accreditation, conformance approval, standards approval, procurement approval, vendor selection, provider preference, public authority endorsement, official adoption, public warning, emergency command, or professional advice; or\
222.6.2(e) veto rights, suppression rights, publication control, public authority access purchase, evidence conclusion purchase, method design purchase, outcome purchase, technical baseline control, data control, AI control, cyber control, protected knowledge access, or enterprise execution authority.

#### 222.7 Fiscal Records and Validity-by-Record

222.7.1 Fiscal acts shall be valid only where supported by competent authority, lawful purpose, budget authority or special approval where required, conflict review where required, segregation of duties where required, proper documentation, accounting entry, payment record, contract or grant record where applicable, restricted-fund record where applicable, and retention in the appropriate register or repository.

222.7.2 No oral statement, informal email, chat message, fundraising deck, sponsor conversation, public authority meeting, website description, AI summary, public statement, proposal, slide, program label, or Nexus reference shall create fiscal authority, spending authority, restricted-fund release, support acceptance, contract authority, payment obligation, reimbursement right, procurement decision, grant commitment, sponsorship benefit, public authority funding commitment, or treasury action unless supported by a competent record.

222.7.3 Fiscal records shall be maintained in a manner sufficient to support auditability, legal compliance, tax compliance, donor and funder accountability, Board oversight, public-safe transparency where approved, correctionability, and institutional continuity.

#### 222.8 Fiscal Correctionability

222.8.1 The Corporation shall correct fiscal records, approvals, allocations, classifications, statements, receipts, donor acknowledgments, sponsorship acknowledgments, grant reports, public claims, budget entries, fund restrictions, contract entries, procurement records, reimbursement records, accounting entries, and public-safe summaries where they are inaccurate, incomplete, misleading, unauthorized, stale, superseded, unlawful, noncompliant, or inconsistent with this Bylaw.

222.8.2 Correction may include reclassification, restatement, amended record, supplemental note, withdrawal, repayment, clawback, return of support, contract amendment, termination, public or controlled clarification, donor or funder notice, Board ratification where lawful, tax filing amendment where required, legal referral, or enforcement action.

222.8.3 A correction shall not be treated as discretionary where an uncorrected fiscal record may create private benefit, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, sponsor control, provider preference, restricted-fund misuse, donor misrepresentation, tax error, grant noncompliance, or public reliance risk.

#### 222.9 Fiscal Stewardship Records

222.9.1 The Corporation shall maintain Fiscal Stewardship Records, including fiscal policies, budget records, treasury records, account records, bank records, signatory records, accounting records, reconciliation records, financial statements, grant records, donation records, sponsorship records, in-kind contribution records, restricted-fund records, board-designated fund records, contract records, procurement records, reimbursement records, compensation records, insurance records, audit or review records, assurance records, impact records, correction records, and annual renewal records.

***

### Section 223. Treasury Governance and Institutional Funds

#### 223.1 Treasury Governance Purpose

223.1.1 Treasury governance shall ensure that the Corporation’s cash, deposits, receivables, reserves, institutional funds, restricted funds, board-designated funds, grant funds, donation funds, sponsorship receipts, subscription receipts, fee receipts, cost-recovery receipts, investment holdings where lawful, and other financial resources are protected, segregated where required, used for lawful public-benefit purposes, and managed under Board-approved controls.

223.1.2 The treasury function shall be conservative, mission-aligned, transparent to the Board, internally controlled, tax-disciplined, conflict-aware, anti-fraud, anti-capture, and non-executing.

223.1.3 Treasury governance shall not be used to manage third-party investment capital, execute project finance, pool investor funds, operate a lending facility, administer an insurance pool, guarantee obligations, custody assets for capital actors, or serve as the treasury of a national company, Project SPV, provider, sponsor, public authority, or enterprise-stack actor.

#### 223.2 Institutional Funds

223.2.1 Institutional funds include unrestricted operating funds, temporarily or permanently restricted funds where applicable, grant funds, donor-restricted funds, board-designated funds, reserve funds, program funds, Academy funds, research funds, public-good software funds, technical baseline funds, public authority learning funds, safeguards funds, data / AI / cyber funds, controlled-room funds, emergency reserve funds, capital replacement funds, continuity funds, and other funds established by competent authority.

223.2.2 Each institutional fund shall have a recorded purpose, authority, restriction status, funding source, custodian, budget treatment, accounting treatment, access treatment, release conditions, reporting requirements, review cycle, and closeout process.

223.2.3 No fund label shall create authority inconsistent with law, the Articles or Certificate, this Bylaw, tax status, donor restrictions, grant terms, nonprofit obligations, or public-benefit purpose.

#### 223.3 Unrestricted Operating Funds

223.3.1 Unrestricted operating funds may be used for lawful, Board-approved, budget-authorized, mission-aligned activities of the Corporation, including governance, staff, contractors, research, evidence work, methods work, observability support, ontology work, public-good software, open technical baselines, public authority learning, publications, Academy activities, safeguards, compliance, insurance, administration, technology, and reserves.

223.3.2 Unrestricted funds remain subject to public-benefit purpose, non-distribution, no-private-inurement, no-impermissible-private-benefit, non-execution, role-separation, public authority boundary, finance boundary, certification boundary, procurement neutrality, data / AI / cyber, safeguards, and records requirements.

#### 223.4 Restricted Funds

223.4.1 Restricted funds shall be accepted, recorded, used, released, reported, corrected, and closed only according to lawful restrictions, grant terms, donor terms, Board approvals, tax requirements, accounting standards, and this Bylaw.

223.4.2 The Corporation shall not accept restrictions that require or imply prohibited functions, sponsor control, provider preference, research finding purchase, publication veto, public authority access purchase, finance-readiness purchase, recognition purchase, certification purchase, procurement advantage, protected knowledge extraction, data misuse, AI misuse, cyber-risk concealment, or enterprise execution.

223.4.3 Where a restriction becomes unlawful, impossible, impracticable, misleading, harmful, inconsistent with public-benefit purpose, or inconsistent with this Bylaw, the Corporation shall seek lawful modification, clarification, refusal, return, reclassification, court or regulator process where required, or other appropriate remedy.

#### 223.5 Board-Designated Funds

223.5.1 The Board may designate unrestricted funds for specific public-benefit purposes, including reserves, research priorities, public-good software development, technical infrastructure, public authority learning, safeguards, data / AI / cyber controls, continuity, legal compliance, strategic initiatives, or North America anchor activities.

223.5.2 Board-designated funds remain internally designated and may be modified, released, reallocated, or dissolved by the Board unless law, grant terms, donor restrictions, or other binding records provide otherwise.

223.5.3 Board designation shall not be used to obscure restricted funds, bypass donor restrictions, conceal deficits, create off-budget authority, evade Board oversight, or create implied obligations to sponsors, donors, providers, public authorities, or enterprise actors.

#### 223.6 Reserve Funds

223.6.1 The Corporation may establish reserve funds to support financial sustainability, continuity of operations, emergency response, cybersecurity incidents, data incidents, legal compliance, audit and assurance, staff continuity, repository continuity, public-good software continuity, controlled-room continuity, public authority learning continuity, and orderly wind-down if necessary.

223.6.2 Reserve policy shall identify reserve purpose, target level, funding sources, permissible uses, release authority, replenishment approach, review cycle, and reporting requirements.

223.6.3 Reserve funds shall not be represented as guarantee funds, investor protection funds, insurance reserves, lending reserves, public finance reserves, project finance reserves, procurement guarantees, performance guarantees, revenue guarantees, or enterprise execution capital.

#### 223.7 Bank Accounts and Depository Authority

223.7.1 Bank accounts, deposit accounts, payment platforms, merchant accounts, custody accounts where lawful and internal only, investment accounts where permitted, and treasury platforms shall be opened, maintained, modified, or closed only under Board-approved or delegated authority.

223.7.2 Accounts shall be held in the legal name of the Corporation or another lawful recorded name approved for the account purpose, and shall not be held in the personal name of any director, officer, employee, contractor, founder, donor, sponsor, provider, host, or Related Party.

223.7.3 Each account shall have a recorded purpose, authorized signatories, approval thresholds, access rights, reconciliation requirements, security controls, fraud controls, reporting requirements, and closure procedure.

#### 223.8 Signing and Payment Authority

223.8.1 The Board shall approve or cause to be maintained a signing authority and payment authority matrix governing who may initiate, approve, release, sign, countersign, wire, transfer, reimburse, contract, commit, or otherwise authorize fiscal acts.

223.8.2 Signing authority shall be role-based, threshold-based, conflict-aware, revocable, recorded, and subject to segregation of duties.

223.8.3 No person shall approve the person’s own compensation, reimbursement, grant, fellowship, stipend, contract, vendor payment, related-party transaction, or benefit.

223.8.4 Dual approval, Board approval, committee approval, officer approval, counsel review, tax review, restricted-fund review, or funder approval may be required based on amount, risk, restriction, conflict, public authority involvement, related-party status, in-kind valuation, cross-border element, regulated-perimeter risk, data / AI / cyber sensitivity, or safeguards sensitivity.

#### 223.9 Investment of Institutional Funds Where Lawful

223.9.1 Institutional funds may be invested only where lawful, prudent, Board-authorized, mission-consistent, tax-compatible, risk-appropriate, liquidity-aware, conflict-reviewed, and consistent with nonprofit obligations.

223.9.2 The Corporation shall not invest funds in a manner that compromises liquidity needed for mission operations, violates donor or grant restrictions, creates private inurement, creates impermissible private benefit, creates conflicts, creates public authority confusion, creates finance-overclaim, creates reputational risk inconsistent with public-benefit purpose, or exposes the Corporation to excessive risk.

223.9.3 Investment activity by the Corporation shall be internal treasury management only and shall not be represented as investment advice, asset management for others, public finance execution, fund management, capital allocation for Nexus projects, Project SPV financing, or capital-readiness action.

#### 223.10 Segregation and Tracking of Funds

223.10.1 The Corporation shall maintain accounting and records systems sufficient to distinguish unrestricted funds, restricted funds, board-designated funds, grants, donations, sponsorships, in-kind contributions, program fees, subscriptions, reimbursements, cost-recovery receipts, and other fund categories.

223.10.2 Segregation may be by separate account, accounting class, ledger code, project code, fund code, restricted fund ledger, or other reliable system sufficient for auditability and compliance.

223.10.3 Commingling for banking convenience may be permitted only where accounting segregation remains reliable and lawful, and where no donor, grant, public authority, tax, accounting, or legal rule requires separate banking.

#### 223.11 Treasury Fraud, Cybersecurity, and Payment Controls

223.11.1 Treasury systems shall be protected by internal controls, identity controls, access controls, approval workflows, multi-factor authentication where appropriate, payment verification, vendor verification, bank reconciliation, audit logs, backup procedures, incident reporting, and fraud-response controls.

223.11.2 Treasury fraud controls shall address wire fraud, invoice fraud, impersonation, business email compromise, payment diversion, vendor spoofing, grant fraud, reimbursement fraud, duplicate payments, payroll fraud, credit-card misuse, unauthorized subscriptions, procurement manipulation, and related-party concealment.

223.11.3 Treasury cybersecurity incidents shall be escalated promptly and may trigger payment holds, account freezes, credential rotation, bank notice, insurance notice, legal review, donor or grantor notice, public authority notice where required, and Board notification.

#### 223.12 Treasury Records

223.12.1 The Corporation shall maintain Treasury Governance and Institutional Fund Records, including account records, bank resolutions, signatory records, payment authority records, fund records, reserve records, restricted fund records, investment records, reconciliation records, approval records, fraud-control records, cyber-control records, payment records, transfer records, account-opening records, account-closing records, access logs, and correction records.

***

### Section 224. Budget Cycle, Annual Budget, Multi-Year Planning, Amendments, Variance Review, and Financial Sustainability

#### 224.1 Budget Governance Purpose

224.1.1 The budget shall be the Corporation’s primary fiscal authorization, planning, mission-alignment, internal-control, sustainability, and Board-oversight instrument.

224.1.2 Budget governance shall ensure that the Corporation’s activities are financially disciplined, legally compliant, tax-compatible, public-benefit aligned, anti-capture, non-executing, properly staffed, operationally sustainable, and supported by reliable records.

224.1.3 No program, committee, officer, council, working group, controlled room, repository, public authority interface, Academy activity, Nexus interface, sponsor relationship, provider relationship, grant activity, or technical initiative shall operate as a fiscal authority outside the budget, a Board-approved amendment, or a recorded delegated authority.

#### 224.2 Annual Budget Requirement

224.2.1 The Board shall approve an annual budget before or near the beginning of each fiscal year, or as soon as practicable where formation, transition, emergency, or governance circumstances require.

224.2.2 The annual budget shall identify projected revenues, projected expenses, restricted funds, unrestricted funds, board-designated funds, grants, donations, sponsorships, subscriptions, fees, cost-recovery receipts, in-kind support where valued, staffing, contractors, program costs, technology costs, public-good software costs, research costs, public authority learning costs, safeguards costs, legal and compliance costs, insurance, reserves, capital needs, and contingency needs.

224.2.3 The annual budget shall distinguish operating expenses, program expenses, governance expenses, fundraising expenses, administrative expenses, restricted-fund spending, capital or technical asset investments, reserve allocations, and extraordinary or nonrecurring costs where material.

#### 224.3 Budget Preparation

224.3.1 Budget preparation shall be led by the Treasurer, Chief Financial Officer, Executive Director, Chief Executive Officer, President, or other authorized officer, under Board oversight and with input from relevant officers, committees, program leads, and records custodians.

224.3.2 Budget preparation shall include review of mission priorities, legal obligations, tax obligations, restricted-fund obligations, contractual obligations, staffing needs, public-good software needs, technical infrastructure needs, data / AI / cyber controls, safeguards obligations, public authority interface needs, North America anchor responsibilities, Nexus interface needs, insurance needs, compliance needs, and reserves.

224.3.3 Budget assumptions shall be documented, including revenue assumptions, grant probability, donation probability, sponsorship probability, fee assumptions, cost assumptions, staffing assumptions, inflation or cost escalation assumptions, foreign exchange exposure where applicable, restricted-fund timing, and known risks.

#### 224.4 Multi-Year Planning

224.4.1 The Corporation may maintain a multi-year financial plan to support sustainability, strategic continuity, staffing stability, public-good technical asset continuity, repository continuity, Academy continuity, safeguards continuity, public authority learning continuity, and North America anchor continuity.

224.4.2 Multi-year planning may include projected revenue scenarios, expense scenarios, reserve targets, grant pipelines, donor diversification, sponsorship controls, staffing plans, technical infrastructure needs, public-good software maintenance, repository succession, legal and compliance needs, insurance requirements, and wind-down or continuity scenarios.

224.4.3 Multi-year plans are planning instruments and shall not authorize spending beyond the approved budget unless expressly adopted as spending authority by competent record.

#### 224.5 Financial Sustainability

224.5.1 The Corporation shall pursue financial sustainability consistent with public-benefit purpose, nonprofit character, anti-capture discipline, donor and sponsor non-control, provider neutrality, and non-execution.

224.5.2 Financial sustainability may be supported through lawful grants, donations, sponsorships, subscriptions, fees, Academy fees, cost recovery, in-kind support, public-good infrastructure support, public authority support where lawful, university and laboratory support, and other lawful revenue or support sources.

224.5.3 Financial sustainability shall not be pursued through securities offerings, investment solicitation, brokerage, finder activity, lending, insurance placement, underwriting, rating, public finance approval, certification sale, recognition sale, procurement advantage sale, public authority access sale, provider preference sale, protected knowledge extraction, or enterprise execution.

#### 224.6 Budget Approval

224.6.1 The annual budget shall be approved by the Board or by another body only where law, the Articles or Certificate, and this Bylaw permit such approval and the Board has expressly delegated authority.

224.6.2 Budget approval shall be recorded in minutes or written consent and shall identify the version approved, fiscal year, revenue assumptions, expense authority, restricted-fund treatment, reserve treatment, major conditions, reporting requirements, and any Board-designated funds.

224.6.3 Approval of a budget does not waive conflict controls, procurement controls, contract controls, signing authority, restricted-fund requirements, public authority boundary review, finance-boundary review, data / AI / cyber review, safeguards review, sanctions review, export-control review, or Board reserved matters.

#### 224.7 Budget Amendments

224.7.1 A material budget amendment shall require Board approval unless a policy or resolution authorizes a defined officer or committee to approve amendments within recorded thresholds.

224.7.2 Budget amendments shall be required where changes materially affect total spending, restricted funds, reserves, staffing, major programs, major contracts, public authority interfaces, technical infrastructure, data / AI / cyber controls, safeguards, legal compliance, grants, sponsorships, or financial sustainability.

224.7.3 Budget amendment records shall identify the reason for amendment, affected lines, funding source, legal or restricted-fund implications, risk implications, approval authority, and effective date.

#### 224.8 Variance Review

224.8.1 The Corporation shall conduct periodic variance review comparing actual revenues and expenses to budget.

224.8.2 Variance review shall identify material differences, causes, corrective actions, restricted-fund issues, revenue shortfalls, expense overruns, delayed grants, donor concentration, sponsor concentration, provider dependence, staffing pressures, technical infrastructure pressures, compliance costs, and emerging sustainability risks.

224.8.3 Material adverse variance shall be escalated to the Board, Finance, Audit, Risk, and Internal Controls Committee where established, Treasurer, Chief Financial Officer, or other competent authority.

#### 224.9 Budget Controls and Spending Discipline

224.9.1 Spending shall be authorized only where it is within budget, within delegation, lawful, documented, mission-aligned, and consistent with the relevant fund restrictions.

224.9.2 Budget availability alone shall not authorize a transaction that requires separate contract approval, procurement review, conflict review, related-party review, Board reserved matter approval, sanctions review, export-control review, public authority boundary review, finance-boundary review, data / AI / cyber review, safeguards review, or legal review.

224.9.3 Off-budget spending, split transactions, artificial invoice division, unsupported reimbursement, unauthorized subscription, informal commitments, side letters, and unrecorded spending obligations are prohibited.

#### 224.10 Scenario Planning and Financial Stress

224.10.1 The Corporation may use scenario planning to assess revenue shortfalls, grant delays, sponsor withdrawal, donor concentration, legal claims, cyber incidents, repository continuity events, public authority interface changes, public-safe correction events, staff transitions, reserve needs, and wind-down scenarios.

224.10.2 Where financial stress may impair mission continuity, legal compliance, data / AI / cyber controls, safeguards, restricted-fund compliance, public authority trust, or public-good technical asset continuity, the matter shall be escalated to the Board or competent committee.

#### 224.11 Financial Reporting to the Board

224.11.1 The Board shall receive periodic financial reports at a frequency appropriate to the Corporation’s size, complexity, risk, funding model, restricted funds, and operational maturity.

224.11.2 Board financial reports may include statement of financial position, statement of activities, budget-to-actual report, cash-flow report, restricted-fund report, grant report, sponsorship report, donation report, accounts receivable report, accounts payable report, reserve report, variance report, and risk notes.

224.11.3 Reports involving confidential donor information, public authority information, protected knowledge, personnel information, legal advice, cyber incidents, investigations, or privileged matters may be provided in controlled form.

#### 224.12 Budget, Planning, Variance, and Sustainability Records

224.12.1 The Corporation shall maintain Budget, Multi-Year Planning, Variance Review, and Financial Sustainability Records, including draft budgets, approved budgets, assumptions, amendments, Board approvals, committee recommendations, budget-to-actual reports, variance analyses, corrective actions, reserve analyses, sustainability plans, scenario plans, financial reports, and closeout records.

***

### Section 225. Accounts, Books, Accounting Standards, Bank Accounts, Reconciliations, and Financial Statements

#### 225.1 Books and Accounts Purpose

225.1.1 The Corporation shall maintain complete, accurate, timely, reliable, auditable, and correctionable books and accounts reflecting all assets, liabilities, revenues, expenses, restrictions, grants, donations, sponsorships, in-kind contributions, receivables, payables, contracts, obligations, funds, reserves, and fiscal activities.

225.1.2 Books and accounts shall support Board oversight, fiduciary compliance, tax compliance, nonprofit compliance, restricted-fund compliance, grant compliance, donor accountability, sponsorship controls, internal controls, public-safe transparency where approved, audit or review, assurance, impact discipline, correctionability, and institutional continuity.

#### 225.2 Accounting Standards

225.2.1 The Corporation shall use accounting standards appropriate to its legal status, jurisdiction, tax posture, nonprofit character, size, funding model, restricted funds, grant obligations, audit requirements, and Board-approved financial reporting approach.

225.2.2 Where required, the Corporation shall prepare financial statements according to generally accepted accounting principles, applicable nonprofit accounting standards, fund accounting requirements, grant requirements, donor restrictions, tax reporting requirements, or other applicable standards.

225.2.3 The Board may approve cash-basis, accrual-basis, modified cash-basis, or other lawful accounting methods appropriate to the Corporation’s stage and obligations, provided that material restrictions, obligations, receivables, payables, and commitments are not misleadingly omitted.

#### 225.3 Chart of Accounts

225.3.1 The Corporation shall maintain a chart of accounts sufficient to classify revenues, expenses, assets, liabilities, net assets or fund balances, restricted funds, unrestricted funds, program activities, management and administration, fundraising, public-good software, technical baselines, research, Academy, public authority learning, data / AI / cyber, safeguards, and other material categories.

225.3.2 The chart of accounts shall support reporting by program, fund, restriction, grant, donor, sponsor, project, department, function, geography, state or territory where required, public authority interface where required, and Nexus interface where required.

#### 225.4 Revenue Recognition and Classification

225.4.1 Revenue and support shall be classified accurately according to source, restriction, purpose, tax treatment, accounting treatment, legal character, and public-benefit use.

225.4.2 Revenue categories may include grants, donations, sponsorships, subscriptions, program fees, Academy fees, training fees, cost recovery, publication fees where lawful, licensing revenue where lawful, in-kind support, investment income where lawful, public authority support where lawful, and other lawful receipts.

225.4.3 The Corporation shall not misclassify purchases, sponsorships, restricted grants, exchange transactions, donations, charitable contributions, membership fees, subscriptions, public authority payments, cost recovery, or in-kind support in a manner that misleads the Board, donors, sponsors, funders, public authorities, tax authorities, auditors, or the public.

#### 225.5 Expense Classification

225.5.1 Expenses shall be classified accurately by function, program, fund, restriction, purpose, budget line, grant, donor, sponsor, project, department, or other relevant category.

225.5.2 Expenses shall not be misclassified to conceal private benefit, related-party transactions, fundraising costs, administrative costs, restricted-fund misuse, provider preference, sponsor control, public authority access purchase, finance-boundary risk, certification-boundary risk, procurement risk, or enterprise-stack support.

#### 225.6 Bank Accounts

225.6.1 Bank accounts shall be authorized, opened, maintained, reconciled, secured, reviewed, and closed under the treasury controls of this Bylaw.

225.6.2 Each bank account shall be linked to the Corporation’s accounting records and shall be reconciled periodically by a person who is not the sole initiator and sole approver of transactions wherever feasible.

225.6.3 Bank account records shall include account purpose, institution, account number or protected identifier, authorized signatories, online access permissions, approval thresholds, opening authority, closing authority, reconciliation schedule, and security controls.

#### 225.7 Reconciliations

225.7.1 The Corporation shall reconcile bank accounts, payment platforms, credit cards, merchant accounts, grant ledgers, restricted-fund ledgers, investment accounts where applicable, receivables, payables, payroll, and other material accounts at intervals appropriate to risk, volume, and reporting needs.

225.7.2 Reconciliations shall identify outstanding items, errors, duplicate payments, unauthorized transactions, stale checks, unrecorded deposits, unrecorded liabilities, restricted-fund issues, grant coding issues, reimbursement issues, and suspicious activity.

225.7.3 Material reconciliation discrepancies shall be escalated promptly to the Treasurer, Chief Financial Officer, Executive Director, Chief Executive Officer, Finance, Audit, Risk, and Internal Controls Committee where established, Board, counsel, auditor, bank, insurer, or law enforcement where appropriate.

#### 225.8 Financial Statements

225.8.1 The Corporation shall prepare financial statements at intervals appropriate to its size, legal obligations, tax obligations, grant obligations, donor obligations, Board needs, and assurance requirements.

225.8.2 Financial statements may include statement of financial position, statement of activities, statement of cash flows, statement of functional expenses, budget-to-actual report, restricted-fund report, grant schedule, sponsorship schedule, donation schedule, in-kind contribution schedule, and notes.

225.8.3 Financial statements shall not imply recognition, finance-readiness, certification, procurement approval, public authority approval, public-good endorsement of supporters, or impact beyond the evidence and records supporting the statements.

#### 225.9 Supporting Documentation

225.9.1 Each material financial transaction shall be supported by appropriate documentation, including invoice, receipt, contract, grant agreement, donation record, sponsorship agreement, in-kind valuation record, reimbursement form, timesheet where applicable, payroll record, approval record, purchase order where applicable, delivery confirmation where applicable, and accounting entry.

225.9.2 Documentation shall be retained according to records policy, legal requirements, tax requirements, grant requirements, donor requirements, employment requirements, audit requirements, public authority requirements where applicable, and legal holds.

#### 225.10 Financial Record Integrity

225.10.1 No person shall falsify, conceal, alter, backdate, destroy, manipulate, misclassify, or omit financial records in a manner that is unlawful, misleading, unauthorized, or inconsistent with this Bylaw.

225.10.2 Financial record integrity violations include false invoices, false receipts, unsupported reimbursement, duplicate reimbursement, concealed related-party transactions, misclassified restricted funds, undisclosed sponsor benefits, false donor acknowledgments, improper valuation of in-kind support, unrecorded liabilities, hidden side agreements, and inaccurate public financial summaries.

#### 225.11 Financial Systems

225.11.1 The Corporation shall use financial systems appropriate to its scale, risk, funding model, restricted funds, internal controls, cybersecurity needs, privacy needs, and audit requirements.

225.11.2 Financial systems shall include access controls, user permissions, change logs, backup, exportability, retention, account security, and segregation of duties where feasible.

225.11.3 Financial records shall not be stored exclusively in personal accounts, uncontrolled spreadsheets, informal chats, unapproved cloud storage, unapproved AI systems, or systems lacking reasonable access and retention controls.

#### 225.12 Public-Safe Financial Transparency

225.12.1 The Corporation may publish public-safe financial summaries, annual reports, donor acknowledgments, sponsorship disclosures, grant summaries, impact summaries, or audited financial statements where approved and consistent with law, confidentiality, privacy, donor restrictions, sponsor terms, public authority restrictions, protected knowledge, privilege, cybersecurity, and public-safe claims discipline.

225.12.2 Public financial materials shall avoid overstating impact, authority, recognition, finance-readiness, certification, procurement approval, public authority endorsement, provider preference, or Nexus system control.

#### 225.13 Accounts, Books, Reconciliation, and Financial Statement Records

225.13.1 The Corporation shall maintain Accounts, Books, Accounting Standards, Bank Account, Reconciliation, and Financial Statement Records, including accounting policies, chart of accounts, ledgers, journals, bank records, reconciliation records, financial statements, supporting documentation, review records, correction records, system access logs, retention records, and audit trails.

***

### Section 226. Grants and Restricted Funds

#### 226.1 Grants and Restricted Funds Purpose

226.1.1 Grants and restricted funds shall be accepted, administered, spent, reported, modified, corrected, and closed in a manner that preserves public-benefit purpose, nonprofit integrity, tax compatibility, donor and funder intent where lawful, research independence, evidence integrity, methods integrity, public-good software integrity, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, safeguards, validity-by-record, and correctionability.

226.1.2 The Corporation may receive grants and restricted funds from lawful sources, including foundations, public charities, private foundations, public authorities where lawful, universities, laboratories, multilateral or development institutions where lawful, corporate philanthropy programs, donor-advised funds, public-good funds, research funders, and other funders, provided that the support satisfies legal, tax, mission, anti-capture, conflict, data / AI / cyber, public authority, finance-boundary, certification-boundary, procurement, sanctions, export-control, and safeguards review.

#### 226.2 Grant Acceptance Authority

226.2.1 Grant acceptance shall require approval by the Board, a Board committee, an authorized officer, or another competent authority under the approval thresholds and delegation matrix established by the Corporation.

226.2.2 Grants that are material by amount, strategic consequence, restriction, public authority involvement, cross-border scope, data sensitivity, AI use, cyber sensitivity, protected knowledge exposure, restricted fund complexity, related-party involvement, sponsor overlap, provider overlap, finance-boundary implication, certification-boundary implication, procurement implication, or reputational risk shall require heightened review and, where appropriate, Board approval.

226.2.3 No person shall accept a grant, sign a grant agreement, submit a binding grant proposal, certify compliance, commit matching funds, commit restricted deliverables, commit public authority access, commit publication outcomes, commit technical outputs, commit data use, or commit the Corporation to grant obligations without recorded authority.

#### 226.3 Restricted Fund Acceptance Test

226.3.1 Before accepting a restricted grant or restricted fund, the Corporation shall determine whether the restriction is lawful, mission-aligned, tax-compatible, nonprofit-compatible, administratively feasible, financially sustainable, records-supported, non-controlling, non-executing, and consistent with this Bylaw.

226.3.2 The restricted fund acceptance test shall include review of:

226.3.2(a) funder identity, legal status, sanctions status, export-control concerns, integrity concerns, public authority status, and related-party connections;\
226.3.2(b) restricted purpose, deliverables, reporting obligations, budget terms, payment schedule, match requirements, indirect cost treatment, cost-share treatment, reimbursement conditions, audit rights, and closeout obligations;\
226.3.2(c) tax treatment, charitable treatment, private foundation rules where applicable, public support implications, unrelated business income risk, charitable solicitation implications, and donor acknowledgment implications;\
226.3.2(d) research independence, evidence integrity, methods integrity, publication independence, correction rights, public-safe limitation language, data rights, AI-use rights, cyber controls, IP rights, confidentiality, and protected knowledge handling;\
226.3.2(e) public authority boundary, finance-boundary, certification-boundary, procurement-neutrality, recognition-boundary, provider-neutrality, and sponsor non-control implications; and\
226.3.2(f) whether the restriction creates private inurement, impermissible private benefit, support-for-control, support-for-outcome, pay-to-play, public authority access purchase, finance-readiness purchase, recognition purchase, certification purchase, procurement advantage, provider preference, or enterprise execution.

#### 226.4 Prohibited Grant Conditions

226.4.1 The Corporation shall not accept grant conditions that require, imply, or practically create:

226.4.1(a) control by the funder over governance, Board composition, officer appointment, committee membership, research agenda, evidence conclusions, methods, publications, technical baselines, public-good software, public authority access, controlled-room access, corrections, or public claims;\
226.4.1(b) predetermined research findings, favorable reports, publication veto, suppression, delayed correction, altered confidence scoring, hidden uncertainty, or public-safe reporting distortion;\
226.4.1(c) recognition, maturity standing, GRF action, Docket approval, Grid guarantee, Nexus-compatible status, certification, accreditation, conformance approval, procurement advantage, provider preference, public authority endorsement, or official adoption;\
226.4.1(d) finance-readiness, capital-readability, insurance-readiness, bankability, investability, underwriting approval, lending approval, rating, investment recommendation, public finance approval, or GRA action;\
226.4.1(e) public warning, emergency command, regulatory decision, public authority decision, legal compliance approval, permit approval, public funding approval, or sovereign obligation; or\
226.4.1(f) unauthorized use of personal information, health-sensitive data, infrastructure-sensitive data, cyber-sensitive materials, community-protected data, Tribal or Indigenous data, protected knowledge, AI training materials, or restricted public authority data.

#### 226.5 Grant Agreements

226.5.1 Grant agreements shall be written or otherwise recorded in a legally reliable form and shall identify the funder, recipient, purpose, amount, payment schedule, restrictions, budget, deliverables, reporting obligations, term, termination rights, modification process, audit rights, recordkeeping duties, confidentiality, IP rights, data rights, publication rights, AI-use restrictions, cyber controls, safeguards, public authority limitations, non-endorsement language, and correction rights where applicable.

226.5.2 Grant agreements shall preserve the Corporation’s independent judgment, public-benefit purpose, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, research integrity, evidence integrity, methods integrity, publication independence, and correctionability.

226.5.3 Grant agreements involving public authorities, cross-border funders, controlled technology, public authority data, health-sensitive data, infrastructure-sensitive data, AI systems, cyber-sensitive materials, Indigenous data, protected knowledge, export-controlled technology, sanctions-sensitive parties, or regulated-perimeter concerns shall receive legal, compliance, data / AI / cyber, safeguards, and Board or committee review where appropriate.

#### 226.6 Grant Budget and Restricted Fund Tracking

226.6.1 Each grant shall have a recorded budget or spending plan appropriate to its restrictions and reporting requirements.

226.6.2 Grant spending shall be tracked by fund, project, budget line, restriction, reporting category, period, deliverable, and cost type where required.

226.6.3 Restricted grant funds shall not be spent for unrelated purposes, unrestricted operating needs, unauthorized overhead, prohibited benefits, unrelated projects, unapproved contractors, unapproved public authority activities, unapproved AI or data uses, or enterprise-stack execution.

226.6.4 Where a grant permits indirect costs, administrative costs, overhead, cost recovery, or shared costs, allocation shall be reasonable, documented, consistently applied, and consistent with the grant terms.

#### 226.7 Grant Deliverables and Output Discipline

226.7.1 Grant deliverables shall be described, produced, reviewed, submitted, published, restricted, or closed in accordance with the grant agreement, public-benefit purpose, research integrity, evidence integrity, methods integrity, data / AI / cyber controls, safeguards, public-safe publication, and this Bylaw.

226.7.2 Deliverables shall not be framed to imply certification, recognition, finance-readiness, procurement approval, public authority decision, official adoption, provider preference, public warning, emergency command, legal compliance approval, professional advice, or enterprise execution unless a competent lawful authority has separately created such status and the Corporation is lawfully authorized to reference it.

226.7.3 Grant-funded outputs shall disclose funding, sponsor or funder involvement, limitations, conflicts, data sources, AI use, public authority involvement, and safeguards restrictions where necessary to prevent misleading reliance.

#### 226.8 Grant Reporting

226.8.1 Grant reporting shall be accurate, complete, timely, evidence-supported, budget-supported, public-safe, and consistent with grant terms.

226.8.2 Grant reports shall not exaggerate impact, conceal material limitations, misclassify spending, obscure restricted-fund issues, overstate public authority adoption, imply finance-readiness, imply certification, imply recognition, imply procurement advantage, or present unsupported evidence as final authority.

226.8.3 Where a grant report contains errors, omissions, outdated information, unauthorized claims, financial misclassification, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, safeguards defect, or data / AI / cyber issue, the Corporation shall correct the report through the appropriate funder notice, amended report, internal record, public-safe correction, or legal review.

#### 226.9 Public Authority Grants

226.9.1 Public authority grants, cooperative agreements, public funding, public-sector contracts, or public support shall be reviewed for corporate authority, public records obligations, procurement rules, grant rules, government ethics, lobbying restrictions, political activity restrictions, public authority boundary, public data restrictions, audit rights, reporting duties, public acknowledgement, indirect cost rules, and compliance obligations.

226.9.2 Acceptance of public authority funding shall not convert the Corporation into a public authority, regulator, public warning body, emergency command body, procurement body, public finance approver, grant administrator for third parties, or governmental decision-maker.

226.9.3 Public authority grant language shall distinguish learning, research, evidence, methods, technical support, public-safe reporting, and capacity-building from public authority action, official adoption, procurement, regulation, public finance approval, emergency command, or sovereign obligation.

#### 226.10 Cross-Border Grants

226.10.1 Cross-border grants shall be reviewed for applicable United States law, foreign law where relevant, tax treatment, charitable solicitation, anti-terrorism rules, sanctions, export-control, controlled technology, data transfer, privacy, AI, cyber, public authority restrictions, currency controls, grant restrictions, Indigenous and local knowledge safeguards, and conflict-of-law issues.

226.10.2 Cross-border funding shall not obscure the Corporation’s United States legal identity, North America anchor role, non-execution boundary, fiscal separateness from GCRI Canada or other GCRI entities, or role separation from GRF, GRA, Nexus entities, consortiums, national companies, Project SPVs, and enterprise actors.

#### 226.11 Grant Modifications

226.11.1 Material modifications to grant purpose, budget, term, deliverables, restrictions, reporting obligations, publication rights, IP rights, data rights, AI-use rights, public authority references, or closeout obligations shall require recorded approval by competent authority.

226.11.2 No officer, staff member, contractor, program lead, principal investigator, public authority interface lead, sponsor relationship lead, or technical lead shall informally modify grant obligations outside authorized processes.

226.11.3 Modifications shall be reviewed for public-benefit alignment, tax implications, restricted-fund implications, public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, data / AI / cyber controls, safeguards, and records requirements.

#### 226.12 Grant Closeout

226.12.1 Grant closeout shall include verification of spending, deliverables, reports, restrictions, records, unspent funds, return obligations, asset disposition, IP rights, data retention, AI-use restrictions, public-safe publication, safeguards, audit rights, and continuing obligations.

226.12.2 Unspent restricted funds shall be handled according to grant terms, donor restrictions, applicable law, and Board-approved process, including return, carryforward, modification, reclassification, or lawful release where permitted.

226.12.3 Grant closeout shall not eliminate continuing confidentiality, privacy, data, AI, cyber, IP, publication, public authority, safeguards, audit, tax, or records obligations.

#### 226.13 Restricted Fund Violations

226.13.1 A restricted fund violation includes unauthorized spending, misclassification, failure to track restrictions, use for unrelated purposes, unsupported cost allocation, improper reimbursement, failure to report, false reporting, public authority overclaim, grant condition breach, data misuse, AI misuse, protected knowledge misuse, or use of funds for prohibited functions.

226.13.2 Restricted fund violations shall be escalated promptly and may require hold, freeze, repayment, correction, amended report, funder notice, Board review, legal review, tax review, audit review, staff discipline, contract remedy, or referral where required.

#### 226.14 Grants and Restricted Funds Records

226.14.1 The Corporation shall maintain Grants and Restricted Funds Records, including grant proposals, approvals, agreements, budgets, restrictions, fund codes, spending records, deliverables, reports, modifications, correspondence, conflict reviews, related-party reviews, public authority reviews, finance-boundary reviews, data / AI / cyber reviews, safeguards reviews, restricted-fund releases, closeout records, violations, corrections, and archive status.

### Section 227. Sponsorship Controls

#### 227.1 Sponsorship Control Purpose

227.1.1 Sponsorships shall be governed as public-benefit support relationships and not as governance transactions, public authority access channels, provider-preference mechanisms, recognition pathways, finance-readiness signals, certification substitutes, procurement advantages, or enterprise execution relationships.

227.1.2 The Corporation may accept sponsorships only where lawful, mission-aligned, tax-compatible, nonprofit-compatible, conflict-reviewed, anti-capture-compliant, public-safe, non-controlling, and consistent with the Corporation’s role as a United States public-benefit technical institution and North America anchor for evidence, methods, observability, ontology, technical truth, public-good R\&D, public-good software, open technical baselines, public authority learning, and safeguards.

227.1.3 Sponsorship controls shall preserve:

227.1.3(a) independence of research, evidence, methods, publications, technical baselines, public-good software, public authority learning, public-safe reporting, and correction;\
227.1.3(b) legal separateness from sponsors, providers, hosts, public authorities, funders, donors, capital actors, national companies, Project SPVs, and enterprise actors;\
227.1.3(c) provider neutrality, procurement neutrality, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, recognition-boundary discipline, and non-execution; and\
227.1.3(d) public trust, data / AI / cyber integrity, civil rights, accessibility, community safeguards, Tribal and Indigenous protocol respect, protected knowledge stewardship, validity-by-record, and correctionability.

#### 227.2 Sponsorship Definition

227.2.1 A sponsorship means a financial, in-kind, technical, facility, event, program, publication, Academy, research, software, data, compute, cloud, cybersecurity, communications, media, logistics, or public-good support arrangement in which a person or entity provides support and receives acknowledgment, defined benefits, participation opportunities, visibility, access to general programming, or other lawful, bounded, non-controlling recognition.

227.2.2 Sponsorship shall be distinguished from donation, grant, contract for services, subscription, membership fee, cost-recovery payment, procurement, partnership, public authority agreement, fiscal sponsorship, research agreement, enterprise delivery agreement, or investment activity according to its substance, restrictions, consideration, public meaning, tax treatment, accounting treatment, and legal effect.

227.2.3 Where classification is uncertain, the Corporation shall apply the more restrictive review pathway until tax, legal, accounting, conflict, public authority, finance-boundary, certification-boundary, procurement, and safeguards implications are resolved by competent record.

#### 227.3 Sponsorship Acceptance Authority

227.3.1 Sponsorship acceptance shall require approval by the Board, a Board committee, an authorized officer, or another competent authority under the Corporation’s approval matrix.

227.3.2 Sponsorships shall require heightened review where they are material by amount, public visibility, restricted benefit, sponsor identity, sponsor concentration, provider overlap, public authority proximity, technical dependency, data contribution, AI or cyber tool contribution, controlled-room access, event centrality, cross-border scope, public claims risk, related-party involvement, capital actor involvement, national company or Project SPV involvement, procurement sensitivity, or safeguards sensitivity.

227.3.3 No director, officer, employee, contractor, fellow, advisor, volunteer, program lead, development lead, public authority interface lead, technical lead, repository lead, or controlled-room lead shall promise sponsorship benefits, public authority access, publication treatment, technical inclusion, controlled-room access, provider visibility, public claims, or acknowledgment language outside recorded authority.

#### 227.4 Sponsorship Acceptance Test

227.4.1 Before accepting a sponsorship, the Corporation shall determine whether the sponsorship is lawful, tax-compatible, nonprofit-compatible, mission-aligned, non-controlling, non-executing, provider-neutral, procurement-neutral, public-safe, conflict-reviewed, anti-capture-compliant, and administratively feasible.

227.4.2 The sponsorship acceptance test shall include review of:

227.4.2(a) sponsor identity, legal status, beneficial ownership or control where relevant, affiliations, sanctions status, export-control concerns, integrity concerns, public authority relationships, enterprise relationships, capital relationships, provider relationships, and Related Party connections;\
227.4.2(b) amount, value, form of support, payment timing, renewal pressure, dependency risk, concentration risk, restrictions, deliverables, benefits, acknowledgments, access expectations, and public visibility;\
227.4.2(c) tax treatment, sponsorship classification, charitable contribution implications where applicable, unrelated business income risk, donation receipt implications, and accounting classification;\
227.4.2(d) conflict, independence, related-party, anti-capture, sponsor non-control, provider neutrality, procurement neutrality, and support-without-control implications;\
227.4.2(e) public authority boundary, finance boundary, certification boundary, recognition boundary, Docket, Grid, GRF, GRA, and Nexus-compatible claim implications; and\
227.4.2(f) data, AI, cybersecurity, privacy, research integrity, publication integrity, public-safe reporting, community safeguards, Tribal and Indigenous protocol, protected knowledge, civil rights, accessibility, competition, sanctions, export-control, and controlled-technology implications.

#### 227.5 Prohibited Sponsorship Conditions

227.5.1 The Corporation shall not accept sponsorship conditions that create, imply, conceal, or practically produce:

227.5.1(a) governance rights, Board rights, officer rights, committee rights, council rights, working group control, agenda control, veto rights, suppression rights, publication approval rights, evidence conclusion rights, methods control, technical baseline control, software roadmap control, repository control, data control, AI control, cyber control, or correction control;\
227.5.1(b) public authority access purchase, public authority endorsement, official adoption, procurement opportunity, grant opportunity, regulatory approval, public finance approval, public warning, emergency command, sovereign obligation, or public-private partnership;\
227.5.1(c) provider preference, preferred vendor status, procurement advantage, certification, accreditation, conformance approval, standards approval, Nexus-compatible status, technical approval, or market recommendation;\
227.5.1(d) recognition, maturity status, standing, registry placement, public-facing legitimacy, Docket approval, Grid guarantee, claims clearance, or GRF action;\
227.5.1(e) finance-readiness, capital-readability, proof-pack approval, insurance-readiness, bankability, investability, underwriting suitability, lending approval, rating, public finance approval, or GRA action; or\
227.5.1(f) private inurement, impermissible private benefit, protected knowledge extraction, community access purchase, AI training on restricted materials, data misuse, cyber-risk concealment, public-safe distortion, or enterprise execution.

#### 227.6 Sponsorship Benefits

227.6.1 Permitted sponsorship benefits may include limited acknowledgment, name listing, logo display subject to approval, event recognition, public-good supporter description, general program access, educational access, non-exclusive participation opportunities, and other lawful benefits expressly approved by competent authority.

227.6.2 Sponsorship benefits shall be defined in writing or another reliable record and shall be bounded by:

227.6.2(a) non-control;\
227.6.2(b) non-endorsement;\
227.6.2(c) non-certification;\
227.6.2(d) non-recognition;\
227.6.2(e) non-procurement;\
227.6.2(f) non-finance-readiness;\
227.6.2(g) public authority non-delegation;\
227.6.2(h) provider neutrality;\
227.6.2(i) data / AI / cyber restrictions;\
227.6.2(j) safeguards restrictions; and\
227.6.2(k) public-safe claims discipline.

227.6.3 Sponsorship benefits shall not include voting rights, governance rights, appointment rights, public authority meeting rights, controlled-room rights, Docket rights, Grid rights, GRF-facing rights, GRA-facing rights, publication veto, technical baseline inclusion, provider ranking, exclusive market positioning, or preferred access to confidential materials unless separately and lawfully authorized for a non-sponsorship reason and recorded under the applicable controls.

#### 227.7 Sponsorship Acknowledgment and Public Language

227.7.1 Sponsorship acknowledgments shall be accurate, limited, public-safe, non-promotional to the extent required by tax or policy, non-misleading, and consistent with the sponsorship agreement.

227.7.2 A sponsorship acknowledgment shall not state or imply that the Corporation endorses, approves, certifies, recognizes, ranks, recommends, finances, insures, underwrites, procures, validates for market use, validates for public authority use, or grants Nexus-compatible status to the sponsor, its products, services, technologies, public authority relationships, financing structures, or enterprise activities.

227.7.3 Sponsor logos, marks, names, quotes, biographies, links, descriptions, and public references shall be reviewed where needed for tax, nonprofit, trademark, public-safe claims, procurement, public authority, finance, certification, recognition, provider-neutrality, or safeguards risk.

#### 227.8 Sponsored Events, Programs, Publications, and Technical Work

227.8.1 Sponsored events, programs, Academy activities, public authority learning sessions, publications, research activities, technical baselines, software projects, dashboards, datasets, controlled rooms, and Nexus-facing activities shall preserve independence and shall not be sponsor-controlled.

227.8.2 Where sponsorship is associated with an output, the output shall disclose sponsorship where necessary to prevent misleading reliance, preserve research integrity, maintain public trust, or satisfy legal, tax, funder, publication, public authority, or public-safe requirements.

227.8.3 Sponsored technical work shall not be structured so that the sponsor’s product, platform, dataset, model, cloud service, AI system, cyber tool, infrastructure, or method becomes the default, preferred, certified, procurement-approved, recognition-ready, finance-ready, or Nexus-compatible option by reason of sponsorship.

#### 227.9 Sponsor Access to Public Authorities, Controlled Rooms, Data, and Technical Assets

227.9.1 Sponsorship shall not entitle a sponsor to access public authorities, public authority rooms, regulator-listening rooms, public finance reader rooms, controlled rooms, clean rooms, data rooms, evidence rooms, no-download rooms, protected knowledge, restricted datasets, unpublished research, privileged materials, cyber-sensitive information, infrastructure-sensitive information, repositories, credentials, keys, tokens, model records, or technical release pipelines.

227.9.2 Any sponsor access to restricted environments shall require separate eligibility, capacity classification, conflict review, confidentiality terms, data / AI / cyber review, competition review, public authority boundary review, safeguards review, and access authorization independent of sponsorship.

227.9.3 Sponsorship shall not be used to bypass admission controls, room controls, repository controls, data controls, AI-use restrictions, sanctions screening, export-control screening, public authority protocols, or safeguards.

#### 227.10 Sponsor Concentration and Capture Review

227.10.1 The Corporation shall monitor sponsor concentration, renewal pressure, recurring access, visibility dependence, technical dependency, public authority proximity, in-kind dependency, staff dependency, venue dependency, cloud dependency, AI dependency, cyber dependency, repository dependency, and public narrative dependency.

227.10.2 Where sponsor concentration or capture risk becomes material, the Corporation may reduce benefits, diversify support, impose ring-fencing, restrict access, amend sponsorship terms, refuse renewal, return support, terminate the sponsorship, impose public-safe clarification, or escalate to the Board.

#### 227.11 Sponsorship Modification, Termination, and Return

227.11.1 Material changes to sponsorship amount, benefits, restrictions, public acknowledgment, sponsor access, term, deliverables, data contribution, technical contribution, public authority involvement, or public claims shall require competent approval and updated records.

227.11.2 The Corporation may refuse, return, restrict, suspend, terminate, or decline renewal of sponsorship where the sponsorship creates legal risk, tax risk, private benefit, sponsor control, provider preference, public authority confusion, finance overclaim, certification overclaim, recognition overclaim, procurement overclaim, safeguards risk, protected knowledge risk, reputational harm, sanctions risk, export-control risk, or conflict with this Bylaw.

#### 227.12 Sponsorship Records

227.12.1 The Corporation shall maintain Sponsorship Records, including sponsorship intake records, sponsor due diligence, beneficial ownership review where applicable, conflicts review, tax review, support value, benefit schedule, sponsorship agreement, public acknowledgment language, restricted access determinations, public authority review, finance-boundary review, certification-boundary review, procurement review, data / AI / cyber review, safeguards review, concentration review, invoices, receipts, accounting entries, modifications, refusals, returns, terminations, corrections, and closeout records.

***

### Section 228. In-Kind Contributions

#### 228.1 In-Kind Contribution Purpose

228.1.1 In-kind contributions shall be accepted and administered only where they support the Corporation’s public-benefit purposes, preserve independence, avoid private inurement and impermissible private benefit, maintain fiscal and accounting integrity, and do not create hidden control, technical lock-in, provider preference, public authority confusion, procurement advantage, recognition, finance-readiness, certification, or enterprise execution.

228.1.2 In-kind contribution controls apply to goods, services, software, cloud credits, compute credits, AI tools, cybersecurity tools, datasets, data access, model access, telecommunications capacity, AI-RAN or O-RAN equipment, DePIN infrastructure, DLT tools, sensors, hardware, facilities, staff time, consulting time, professional services, event support, travel support, media support, research support, publication support, public-good infrastructure support, and other non-cash value.

#### 228.2 In-Kind Contribution Definition

228.2.1 An in-kind contribution means a non-cash contribution of property, services, rights, access, infrastructure, personnel, technology, data, compute, tools, facilities, licenses, discounts, waivers, credits, equipment, or other value provided to the Corporation without full ordinary-course cash payment.

228.2.2 In-kind contributions shall be classified by substance as donation, sponsorship, grant, service arrangement, restricted support, discounted transaction, exchange transaction, technical contribution, host support, provider contribution, or other category as appropriate.

#### 228.3 Acceptance Authority

228.3.1 In-kind contributions shall require approval by competent authority under the Corporation’s approval matrix.

228.3.2 Heightened review shall be required for in-kind contributions involving:

228.3.2(a) data, AI systems, models, embeddings, retrieval systems, inference systems, compute, cloud, cybersecurity, identity systems, repositories, dashboards, sensors, telecom, AI-RAN, O-RAN, DePIN, DLT, blockchain, digital twins, geospatial systems, or mission-critical infrastructure;\
228.3.2(b) public authority data, personal information, health-sensitive data, cyber-sensitive information, infrastructure-sensitive information, community-protected data, Tribal or Indigenous data, protected knowledge, or controlled technology;\
228.3.2(c) provider, sponsor, host, public authority, capital actor, national company, Project SPV, Related Party, or enterprise actor contributions; or\
228.3.2(d) material value, long-term dependence, access rights, exclusivity, public claims, restricted use, IP implications, export-control implications, sanctions implications, procurement implications, or safeguards implications.

#### 228.4 In-Kind Contribution Acceptance Test

228.4.1 Before accepting an in-kind contribution, the Corporation shall determine whether the contribution is lawful, mission-aligned, tax-compatible, accounting-compatible, safe, secure, usable, non-controlling, non-exclusive unless justified, and consistent with public-benefit purpose.

228.4.2 The acceptance test shall include review of:

228.4.2(a) contributor identity, beneficial ownership or control where relevant, affiliations, sanctions status, export-control concerns, integrity concerns, conflicts, public authority relationships, provider relationships, sponsor relationships, capital relationships, and Related Party status;\
228.4.2(b) value, valuation method, restrictions, term, renewal, termination rights, usage limits, data rights, IP rights, AI-use terms, cybersecurity terms, support obligations, audit rights, access rights, and portability;\
228.4.2(c) technical security, vulnerability profile, dependency risk, lock-in risk, continuity risk, interoperability, documentation, maintenance burden, replacement cost, and exit feasibility; and\
228.4.2(d) public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, safeguards, protected knowledge, and public-safe claims implications.

#### 228.5 Prohibited In-Kind Conditions

228.5.1 The Corporation shall not accept in-kind contributions that require, imply, or practically create:

228.5.1(a) provider preference, exclusive use, procurement signal, public authority endorsement, certification, recognition, finance-readiness, Nexus-compatible status, standards outcome, public claims advantage, or enterprise-stack advantage;\
228.5.1(b) contributor control over research, evidence, methods, publications, technical baselines, software roadmap, repository access, data handling, AI processing, cyber posture, public authority access, controlled-room access, correction, or public-safe reporting;\
228.5.1(c) use of restricted data for AI training, uncontrolled model improvement, unauthorized embedding, public release, commercial reuse, profiling, surveillance, protected knowledge extraction, or public authority misuse; or\
228.5.1(d) technical dependence that prevents the Corporation from correcting, withdrawing, migrating, publishing, refusing, terminating, or preserving independent public-benefit judgment.

#### 228.6 Valuation and Accounting Treatment

228.6.1 In-kind contributions shall be valued and recorded according to applicable accounting standards, tax rules, donor acknowledgment rules, grant requirements, and Board-approved policy.

228.6.2 The Corporation shall not overvalue, undervalue, misclassify, or conceal in-kind contributions in a manner that misleads the Board, donors, sponsors, funders, tax authorities, auditors, public authorities, or the public.

228.6.3 Valuation shall distinguish donated goods, donated services, discounted services, volunteer services, professional services, software credits, cloud credits, compute credits, licenses, equipment, data access, and facility use where appropriate.

#### 228.7 Data, AI, Cloud, Cybersecurity, and Technical Contributions

228.7.1 Data, AI, cloud, cybersecurity, repository, software, hardware, telecom, sensor, AI-RAN, O-RAN, DePIN, DLT, blockchain, digital twin, and geospatial contributions shall be reviewed for security, privacy, legal rights, license terms, data rights, AI-use restrictions, no-training terms, retention, deletion, logging, auditability, portability, export-control, sanctions, vulnerability, incident response, and continuity.

228.7.2 The Corporation shall not accept technical contributions that create unacceptable vulnerability, hidden telemetry, undisclosed data extraction, unauthorized model training, uncontrolled dependency, secret access, unreviewed code, unreviewed credentials, unapproved public authority data exposure, protected knowledge exposure, or incompatible license obligations.

#### 228.8 Facilities, Host-Site, Equipment, and Staff-Time Contributions

228.8.1 Facilities, host-site access, equipment, staff time, event support, logistics, and operational support shall be reviewed for safety, security, accessibility, civil rights, insurance, liability, public authority implications, public claims, confidentiality, data access, protected knowledge, and operational control.

228.8.2 Host-site or facility support shall not create host control over research, publication, public authority participation, participant access, public-safe reporting, data custody, technical assets, or correction.

#### 228.9 Contributor Public Reference and Acknowledgment

228.9.1 Public acknowledgment of in-kind contributions shall be accurate, limited, public-safe, non-misleading, and consistent with tax, accounting, sponsorship, donation, grant, and public claims controls.

228.9.2 A contributor shall not use the contribution to claim endorsement, certification, recognition, procurement approval, public authority approval, finance-readiness, provider preference, standards approval, or Nexus-compatible status.

#### 228.10 Rejection, Quarantine, Return, Restriction, or Termination

228.10.1 The Corporation may reject, quarantine, restrict, return, terminate, disable, delete, migrate away from, or stop using an in-kind contribution where it creates legal risk, tax risk, accounting risk, security risk, data risk, AI risk, cyber risk, protected knowledge risk, public authority risk, finance overclaim, certification overclaim, procurement risk, provider preference, sponsor control, private benefit, dependency, or mission drift.

228.10.2 Technical contributions may be quarantined pending code review, license review, vulnerability review, provenance review, data rights review, AI-use review, export-control review, sanctions review, or safeguards review.

#### 228.11 In-Kind Contribution Records

228.11.1 The Corporation shall maintain In-Kind Contribution Records, including contributor identity, contribution description, value, valuation method, classification, restrictions, acceptance authority, agreement or terms, conflict review, related-party review, tax review, accounting treatment, data / AI / cyber review, technical review, license review, public authority review, finance-boundary review, certification-boundary review, procurement review, safeguards review, acknowledgment language, quarantine, rejection, return, termination, correction, and closeout.

***

### Section 229. Contracts

#### 229.1 Contracting Purpose

229.1.1 Contracting by the Corporation shall be lawful, mission-aligned, fiscally disciplined, internally controlled, conflict-reviewed, records-supported, non-executing, public-benefit oriented, anti-capture compliant, and consistent with the Corporation’s nonprofit character and public-good technical stewardship role.

229.1.2 Contracts shall not be used to create private inurement, impermissible private benefit, hidden related-party benefit, sponsor control, provider preference, public authority delegation, public warning authority, emergency command, procurement approval, finance-readiness, certification, recognition, standards authority, or enterprise execution.

#### 229.2 Contract Definition

229.2.1 A contract includes any written, electronic, click-through, platform, grant-related, sponsorship, donation, in-kind, vendor, contractor, consultant, employment, fellowship, advisory, research, publication, data-sharing, software, license, repository, cloud, AI, cybersecurity, facility, host, public authority, MoU, partnership, subscription, service, procurement, insurance, lease, confidentiality, or other agreement creating obligations, rights, restrictions, access, payment, deliverables, representations, warranties, indemnities, or public meaning.

229.2.2 Oral commitments, emails, chats, letters of intent, memoranda, proposal acceptances, statements of work, purchase orders, invoices, platform terms, click-wrap terms, public authority forms, and AI-platform terms may create contract risk and shall be treated as contracts where legally or operationally material.

#### 229.3 Contract Authority

229.3.1 Contracts may be negotiated, approved, signed, amended, renewed, terminated, or waived only by persons with recorded authority under the Board-approved authority matrix or applicable delegation.

229.3.2 Contract authority shall be subject to budget authority, spending authority, signing authority, procurement review, conflict review, related-party review, restricted-fund review, legal review where required, data / AI / cyber review where required, public authority review where required, finance-boundary review where required, certification-boundary review where required, safeguards review where required, and Board reserved matters.

229.3.3 No person shall bind the Corporation by title, seniority, technical centrality, founder status, authorship, public authority relationship, sponsor relationship, provider relationship, repository access, email signature, meeting attendance, or informal approval outside recorded authority.

#### 229.4 Contract Intake and Review

229.4.1 Material contracts shall proceed through a contract intake and review process that identifies the counterparty, purpose, amount, term, renewal, deliverables, funding source, restrictions, data, AI, cyber, IP, confidentiality, insurance, indemnity, liability, public authority, public claims, termination, and records implications.

229.4.2 Contract review shall classify the contract type and determine required approvals, including legal, tax, finance, procurement, conflict, related-party, public authority, sanctions, export-control, data / AI / cyber, IP, research integrity, safeguards, and Board review.

#### 229.5 Required Contract Protections

229.5.1 Contracts shall include protections appropriate to their purpose and risk, including:

229.5.1(a) accurate legal name and capacity;\
229.5.1(b) scope of work, deliverables, term, fees, payment terms, and budget reference;\
229.5.1(c) confidentiality, privacy, data protection, AI-use restrictions, cybersecurity, and incident notice;\
229.5.1(d) IP ownership, licenses, attribution, contributor rights, open-source terms, moral rights where applicable, and anti-enclosure protections;\
229.5.1(e) publication independence, public-safe claims, non-endorsement, public authority boundary, finance-boundary, certification-boundary, procurement-neutrality, and non-execution language;\
229.5.1(f) conflicts, related-party disclosure, anti-corruption, sanctions, export-control, competition, gifts, and procurement integrity clauses where appropriate;\
229.5.1(g) records, audit rights, reporting, correction, access restriction, suspension, termination, and survival clauses; and\
229.5.1(h) limitation of liability, indemnity, insurance, dispute resolution, governing law, venue, and compliance obligations where appropriate.

#### 229.6 Prohibited Contract Terms

229.6.1 The Corporation shall not enter into contract terms that require or imply:

229.6.1(a) public authority delegation, public warning, emergency command, procurement approval, public finance approval, regulatory approval, grant approval, sovereign obligation, or official adoption;\
229.6.1(b) securities activity, investment advice, broker-dealer activity, finder activity, capital placement, lending, insurance placement, underwriting, rating, guarantee, banking, or public finance execution;\
229.6.1(c) certification, accreditation, recognition, maturity standing, Docket approval, Grid guarantee, Nexus-compatible status, provider preference, standards outcome, or legal compliance approval;\
229.6.1(d) sponsor, donor, funder, provider, host, public authority, capital actor, national company, Project SPV, or enterprise control over governance, research, evidence, methods, publication, technical baselines, software, data, AI, cyber, public authority access, or correction;\
229.6.1(e) private inurement, impermissible private benefit, excessive compensation, related-party favoritism, or public-good asset enclosure; or\
229.6.1(f) waiver of safeguards, protected knowledge duties, civil rights, accessibility, public-safe publication discipline, data / AI / cyber controls, or correctionability.

#### 229.7 Procurement and Vendor Contracts

229.7.1 Vendor, contractor, consultant, provider, software, cloud, AI, cybersecurity, data processor, equipment, facilities, professional services, and technical-service contracts shall be reviewed for need, budget, value, competence, conflicts, related-party status, provider neutrality, security, privacy, data rights, AI-use terms, IP rights, export-control, sanctions, continuity, and termination.

229.7.2 Procurement may be competitive, comparative, sole-source, emergency, restricted, preferred-framework, or specialized where allowed by policy and justified by record.

229.7.3 Sole-source or noncompetitive contracts shall require justification where material, including urgency, specialized expertise, continuity, public-benefit need, compatibility, grant requirement, safeguards, or lack of reasonable alternatives.

#### 229.8 Public Authority Contracts

229.8.1 Public authority contracts, cooperative agreements, memoranda, public funding agreements, data-sharing agreements, public authority learning agreements, and public-sector interface instruments shall be reviewed for public authority capacity, public records, FOIA, state sunshine, open meetings, procurement, grant, lobbying, government ethics, public data, confidentiality, sovereign immunity, indemnity, insurance, audit rights, public claims, and non-execution.

229.8.2 Public authority contracts shall not convert the Corporation into a public authority, regulator, procurement body, public warning body, emergency command body, public finance approver, grant administrator for third parties, or governmental decision-maker.

#### 229.9 Research, Data, AI, Cyber, Software, and Technical Asset Contracts

229.9.1 Research, data, AI, cyber, software, repository, technical baseline, public-good software, cloud, compute, model, dashboard, benchmark, sensor, AI-RAN, O-RAN, DePIN, DLT, geospatial, digital twin, and technical asset contracts shall include appropriate terms for rights, restrictions, permitted use, security, privacy, AI training, embeddings, inference logging, retention, deletion, model improvement, publication, IP, open licensing, vulnerability disclosure, incident response, export-control, sanctions, and public-safe handling.

229.9.2 Technical contracts shall preserve the Corporation’s ability to correct, withdraw, supersede, migrate, fork, archive, disclose limitations, respond to incidents, and protect public-good technical assets.

#### 229.10 Contract Amendments, Renewals, Waivers, and Termination

229.10.1 Material amendments, renewals, extensions, waivers, assignments, novations, settlements, releases, or terminations shall require approval by competent authority.

229.10.2 Renewals shall not be automatic where the contract has become inconsistent with budget, mission, conflicts, provider neutrality, sponsor non-control, public authority boundaries, finance boundaries, certification boundaries, data / AI / cyber controls, safeguards, sanctions, export-control, tax posture, or legal compliance.

229.10.3 The Corporation may suspend, terminate, restrict, or re-scope a contract where continuation would create legal risk, fiscal risk, private benefit, public authority confusion, regulated-perimeter risk, provider preference, sponsor control, data / AI / cyber risk, protected knowledge risk, or public-trust harm.

#### 229.11 Contract Records

229.11.1 The Corporation shall maintain Contract Records, including intake records, drafts, redlines, executed versions, statements of work, approvals, authority records, budget references, procurement records, conflict reviews, related-party reviews, legal reviews, tax reviews, data / AI / cyber reviews, IP reviews, public authority reviews, finance-boundary reviews, certification-boundary reviews, safeguards reviews, insurance certificates, deliverables, invoices, payments, amendments, renewals, waivers, notices, breaches, corrections, terminations, and closeout.

***

### Section 230. IP and Licensing

#### 230.1 IP and Licensing Purpose

230.1.1 The Corporation shall steward intellectual property, licenses, public-good software, open technical baselines, datasets, schemas, APIs, SDKs, dashboards, methods, research outputs, publications, technical documentation, controlled vocabulary, trademarks, names, marks, and other technical assets in a manner that advances public-benefit purposes, preserves public-good access, prevents private enclosure, protects legal rights, maintains records, and avoids misleading authority claims.

230.1.2 IP and licensing governance shall preserve:

230.1.2(a) public-good software integrity;\
230.1.2(b) open technical baseline integrity;\
230.1.2(c) evidence, methods, observability, ontology, technical truth, and public-good R\&D continuity;\
230.1.2(d) secure development, release, and archive discipline;\
230.1.2(e) data / AI / cyber, privacy, protected knowledge, civil rights, accessibility, and safeguards duties; and\
230.1.2(f) non-execution, role separation, public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, validity-by-record, and correctionability.

#### 230.2 Intellectual Property Covered

230.2.1 Covered intellectual property includes copyrights, trademarks, service marks, trade names, logos, domain names, software, code, documentation, schemas, APIs, SDKs, datasets, data dictionaries, ontologies, taxonomies, controlled vocabulary, dashboards, user interfaces, models, model cards, system cards, benchmark cards, evaluation harnesses, test vectors, reference architectures, technical baselines, methods, reports, publications, training materials, Academy materials, research outputs, diagrams, media, proof receipts, repository artifacts, and related rights.

230.2.2 Trade secrets, confidential know-how, security-sensitive information, protected knowledge, and controlled technical information shall be protected where lawfully held and shall not be released merely because other public-good assets are open.

#### 230.3 Ownership and Chain of Title

230.3.1 The Corporation shall maintain chain-of-title records sufficient to establish ownership, license rights, contributor rights, assignment rights, work-for-hire status where applicable, moral rights treatment where applicable, third-party restrictions, open-source obligations, data rights, model rights, publication rights, and sublicensing authority.

230.3.2 No software, dataset, technical baseline, publication, method, dashboard, model, benchmark, or public-good technical asset shall be released, licensed, transferred, or represented as owned or controlled by the Corporation unless the relevant rights have been reviewed and recorded.

230.3.3 Where rights are uncertain, the asset shall be held, restricted, quarantined, corrected, re-licensed, replaced, withdrawn, or not released until the chain-of-title issue is resolved.

#### 230.4 Public-Good Licensing

230.4.1 The Corporation may license public-good software, open technical baselines, schemas, APIs, SDKs, documentation, methods, and other assets under open, public-good, permissive, copyleft, community, defensive, research, educational, restricted-use, or hybrid licenses where lawful and mission-aligned.

230.4.2 License selection shall consider public access, interoperability, security, anti-enclosure, contributor compatibility, standards compatibility, data rights, patent risk, commercial-use boundaries, public authority use, provider neutrality, safeguards, and long-term maintainability.

230.4.3 Public-good licensing shall not create certification, recognition, procurement approval, finance-readiness, public authority approval, legal compliance approval, emergency command, public warning, or Nexus-compatible status by itself.

#### 230.5 Restricted Licensing and Controlled Release

230.5.1 Restricted licensing or controlled release may be used where open release would create security risk, privacy risk, protected knowledge exposure, infrastructure exposure, cyber risk, misuse risk, export-control risk, sanctions risk, national security sensitivity, public authority restriction, contractual restriction, research-participant risk, community harm, or public-safe publication risk.

230.5.2 Restricted licensing shall be no broader than necessary to preserve lawful protection, public safety, safeguards, security, privacy, rights, and mission integrity.

230.5.3 Controlled release may use controlled rooms, no-download rooms, staged release, redacted releases, delayed release, aggregation, access agreements, restricted repositories, or qualified reviewer access.

#### 230.6 Contributor Rights and Terms

230.6.1 Contributors, developers, maintainers, authors, researchers, fellows, advisors, contractors, employees, volunteers, universities, laboratories, providers, sponsors, and public authority contributors shall be subject to written or recorded contribution terms appropriate to their role.

230.6.2 Contributor terms may include assignment, license, contributor license agreement, developer certificate of origin, confidentiality, IP warranty, provenance certification, security obligations, AI-use disclosure, data rights certification, export-control certification, sanctions certification, conflict disclosure, and public-safe claims limitations.

230.6.3 Contribution acceptance shall not grant governance authority, maintainer authority, certification authority, recognition authority, finance-readiness authority, procurement authority, public authority authority, or Nexus-compatible status unless separately and lawfully authorized.

#### 230.7 Open-Source and Third-Party Components

230.7.1 Open-source and third-party components shall be reviewed for license compatibility, security, provenance, vulnerability, maintenance status, dependency risk, export-control restrictions, patent risk, copyleft obligations, attribution obligations, and use restrictions.

230.7.2 The Corporation shall maintain SBOM, dependency, attribution, license, and vulnerability records where appropriate.

230.7.3 Components that create unacceptable license contamination, security risk, undocumented dependency, proprietary lock-in, provider preference, public authority restriction, or export-control risk may be rejected, replaced, isolated, or restricted.

#### 230.8 Trademarks, Names, Logos, Seals, Badges, and Public Marks

230.8.1 The Corporation shall control its legal name, approved short name, marks, logos, seals, badges, report marks, dataset marks, software marks, technical baseline marks, repository marks, Academy marks, and public-good asset identifiers.

230.8.2 Use of marks shall be governed by written permission, public-safe claims discipline, non-endorsement, non-certification, non-recognition, non-finance-readiness, non-procurement, public authority boundary language, and revocation rights.

230.8.3 No person may use the Corporation’s marks to imply authority, endorsement, certification, recognition, finance-readiness, procurement approval, provider preference, public authority approval, emergency command, or enterprise execution.

#### 230.9 Data, Model, and AI Licensing

230.9.1 Data, model, benchmark, evaluation, inference, embedding, retrieval, and AI-related licenses shall identify permitted uses, prohibited uses, training restrictions, fine-tuning restrictions, model-improvement restrictions, retention, deletion, publication, redistribution, attribution, privacy, public authority restrictions, protected knowledge restrictions, security controls, and audit rights where appropriate.

230.9.2 Rights-bearing data, public authority data, health-sensitive data, infrastructure-sensitive data, cyber-sensitive data, community-protected data, Tribal or Indigenous data, local or territorial knowledge, cultural knowledge, environmental knowledge, and protected knowledge shall not be licensed for unrestricted use without safeguards review and competent authorization.

#### 230.10 IP Transfers, Exclusive Licenses, and Asset Dispositions

230.10.1 Transfers, exclusive licenses, assignments, long-term encumbrances, royalty arrangements, private commercialization rights, or material dispositions of public-good technical assets shall require heightened review and, where material, Board approval.

230.10.2 No IP transfer or exclusive license shall be approved if it would undermine public-benefit purpose, anti-enclosure obligations, public-good software continuity, open technical baseline access, provider neutrality, public authority trust, safeguards, or Nexus-compatible public-good stack interoperability.

230.10.3 IP dispositions shall be reviewed for private benefit, tax, nonprofit, charitable asset, restricted-fund, grant, donor, sponsor, public authority, competition, export-control, sanctions, data / AI / cyber, and safeguards implications.

#### 230.11 IP Enforcement and Misuse Response

230.11.1 The Corporation may enforce IP rights, license terms, mark-use rules, public claims limits, confidentiality terms, repository rules, attribution terms, and anti-enclosure protections where necessary to preserve public-good assets and prevent misleading use.

230.11.2 Misuse may require notice, correction, takedown, license termination, access revocation, repository action, public clarification, contract remedy, legal action, or referral where appropriate.

#### 230.12 IP and Licensing Records

230.12.1 The Corporation shall maintain IP and Licensing Records, including asset registers, chain-of-title records, contributor agreements, license selections, license texts, approvals, attribution records, SBOMs, dependency records, open-source reviews, patent reviews, trademark permissions, mark-use records, data licenses, AI-use terms, model licenses, publication rights, restricted release records, controlled access records, transfers, exclusive license reviews, misuse notices, takedowns, corrections, and archive records.

***

### Section 231. Insurance and Indemnity

#### 231.1 Insurance and Indemnity Purpose

231.1.1 Insurance and indemnity shall be maintained and administered to protect the Corporation, its mission, assets, directors, officers, eligible personnel, programs, public-good technical assets, data / AI / cyber systems, public authority learning activities, research activities, events, controlled rooms, and public-benefit operations against lawful risks while preserving accountability, fiduciary duties, nonprofit integrity, and public trust.

231.1.2 Insurance and indemnity shall not be used to excuse bad faith, fraud, willful misconduct, knowing violation of law, private inurement, improper personal benefit, harassment, retaliation, intentional data misuse, intentional cyber misconduct, protected knowledge misuse, sponsor control, provider preference, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, or enterprise execution.

#### 231.2 Insurance Authority

231.2.1 The Board, Treasurer, Chief Financial Officer, Chief Legal, Compliance, and Risk Officer where appointed, Executive Director, Chief Executive Officer, or other authorized officer may obtain, renew, modify, claim under, or terminate insurance within approved authority, budget, and policy.

231.2.2 Material insurance decisions shall be escalated to the Board or competent committee where they affect directors’ and officers’ coverage, cyber coverage, professional liability, employment practices, fiduciary liability, crime, public authority activities, research, controlled rooms, cross-border operations, or material exclusions.

#### 231.3 Insurance Types

231.3.1 The Corporation may obtain insurance appropriate to its operations, including directors’ and officers’ liability, general liability, professional liability, errors and omissions, cyber liability, privacy liability, employment practices liability, fiduciary liability, crime, property, event, travel, volunteer, research, lab, media, publication, technology, intellectual property, workers’ compensation where required, and other coverage approved by competent authority.

231.3.2 Coverage selection shall consider the Corporation’s nonprofit status, public-benefit mission, public-good software, technical baselines, research activities, public authority learning, controlled rooms, data / AI / cyber risks, safeguards, community interfaces, cross-border operations, state and territorial operations, and Nexus interfaces.

#### 231.4 Coverage Review

231.4.1 Insurance coverage shall be reviewed periodically for adequacy, exclusions, deductibles, limits, claims-made periods, retroactive dates, notice requirements, defense obligations, consent-to-settle terms, public authority activities, cyber exclusions, AI exclusions, data exclusions, professional services exclusions, research exclusions, volunteer exclusions, sanctions exclusions, export-control exclusions, and cross-border limitations.

231.4.2 Material gaps shall be reported to the Board or competent committee, with recommended mitigation through coverage changes, contract controls, operational controls, reserves, risk transfer, activity restriction, or program redesign.

#### 231.5 Indemnification

231.5.1 The Corporation may indemnify directors, officers, employees, committee members, volunteers, fellows, advisors, contractors, representatives, and other eligible persons to the fullest extent permitted by applicable law, the Articles or Certificate, this Bylaw, and any Board-approved indemnification policy.

231.5.2 Indemnification shall be available only where the person acted in good faith, within authority, in a manner reasonably believed to be in or not opposed to the best interests of the Corporation, and otherwise satisfied applicable legal requirements.

231.5.3 Indemnification shall not be available where prohibited by law or governing instruments, including for conduct involving bad faith, fraud, willful misconduct, knowing violation of law, improper personal benefit, private inurement, intentional misconduct, or other excluded conduct.

#### 231.6 Advancement of Expenses

231.6.1 The Corporation may advance expenses to eligible persons where permitted by law, the Articles or Certificate, this Bylaw, and Board-approved policy.

231.6.2 Advancement may require a written undertaking to repay amounts advanced if it is ultimately determined that the person is not entitled to indemnification.

231.6.3 Advancement decisions shall be conflict-reviewed and approved by disinterested authority where required.

#### 231.7 Indemnity in Contracts

231.7.1 Contractual indemnities given by the Corporation shall be reviewed for legal authority, insurance compatibility, budget risk, public authority implications, data / AI / cyber risk, IP risk, research risk, event risk, controlled-room risk, cross-border risk, public-safe publication risk, and nonprofit compatibility.

231.7.2 The Corporation shall not provide indemnity that creates an unauthorized guarantee, finance obligation, public authority obligation, project execution obligation, enterprise-stack obligation, uninsured material risk, or private benefit inconsistent with public-benefit purpose.

231.7.3 Indemnities received by the Corporation shall be reviewed for adequacy, enforceability, exclusions, insurance backing, public authority limitations, and survival.

#### 231.8 Claims, Notices, and Incident Coordination

231.8.1 Potential claims, incidents, lawsuits, investigations, cyber incidents, data incidents, employment claims, public authority inquiries, public-safe publication claims, IP claims, event incidents, or other insured events shall be reported promptly according to policy and insurance terms.

231.8.2 Claim handling shall preserve privilege, confidentiality, evidence, logs, records, public authority obligations, data breach obligations, protected knowledge, public-safe communications, and non-retaliation.

#### 231.9 Insurance and Indemnity Records

231.9.1 The Corporation shall maintain Insurance and Indemnity Records, including policies, applications, binders, certificates, coverage summaries, renewals, exclusions, claims, notices, incident reports, Board approvals, indemnification determinations, advancement undertakings, contract indemnity reviews, insurance certificates from counterparties, coverage gap reviews, corrections, and closeout.

***

### Section 232. Sanctions and Export Controls

#### 232.1 Sanctions and Export-Control Purpose

232.1.1 The Corporation shall maintain sanctions, export-control, controlled-technology, anti-terrorism, restricted-party, national security sensitivity, and cross-border compliance discipline as mandatory legal and governance controls.

232.1.2 These controls apply to grants, donations, sponsorships, in-kind contributions, contracts, public authority interfaces, research collaborations, software releases, technical baselines, datasets, model access, AI tools, compute access, cloud services, cybersecurity tools, telecommunications equipment, AI-RAN / O-RAN components, DePIN systems, DLT systems, blockchain tools, sensors, geospatial systems, digital twins, controlled rooms, data rooms, public-good repositories, Academy activities, travel, payments, exports, re-exports, deemed exports, and cross-border collaboration.

232.1.3 The Corporation shall not permit its public-benefit status, public-good mission, open technology posture, educational activities, public authority learning role, Nexus interface, or humanitarian language to be used to bypass sanctions, export-control, restricted-party, anti-terrorism, controlled-technology, or national security-sensitive restrictions.

#### 232.2 Sanctions Screening

232.2.1 The Corporation shall conduct sanctions screening where required or prudent for donors, sponsors, funders, providers, vendors, contractors, employees, fellows, advisors, volunteers, contributors, public authority participants, universities, laboratories, hosts, partners, counterparties, grant recipients where applicable, payment recipients, controlled-room participants, repository participants, data recipients, AI users, and cross-border participants.

232.2.2 Screening may include review of restricted-party lists, ownership and control, jurisdictional nexus, transaction purpose, payment routing, goods or technology involved, services involved, public authority status, and known integrity concerns.

232.2.3 Where screening identifies a match, potential match, blocked person, prohibited jurisdiction, restricted transaction, or unresolved concern, the Corporation shall hold, stop, quarantine, re-scope, refuse, terminate, or escalate the matter pending review.

#### 232.3 Export-Control Review

232.3.1 Export-control review shall be required where the Corporation transfers, releases, publishes, shares, provides access to, trains on, demonstrates, or otherwise makes available controlled goods, software, technology, technical data, encryption, cybersecurity tools, AI models, compute methods, telecom methods, AI-RAN or O-RAN materials, DePIN materials, DLT tools, blockchain tools, sensor systems, geospatial tools, digital twin systems, infrastructure-sensitive materials, or other controlled technology.

232.3.2 Export-control review shall consider item classification, technology classification, software classification, destination, nationality of recipients where relevant, end use, end user, deemed export risk, re-export risk, public-domain or open-source treatment, encryption treatment, license exceptions, licensing requirements, public authority restrictions, and controlled-technology sensitivity.

#### 232.4 Controlled Technology and Deemed Export Controls

232.4.1 Controlled technology shall not be disclosed, uploaded, demonstrated, transferred, granted through repository access, shared in controlled rooms, embedded in training materials, released as open-source, or provided through AI systems without required review.

232.4.2 Deemed export risk shall be reviewed where foreign nationals, cross-border participants, remote contributors, cloud environments, AI systems, repositories, controlled rooms, universities, laboratories, public authorities, providers, sponsors, or contractors may access controlled technology.

232.4.3 Controlled-technology access may require nationality review where lawful, license review, access restriction, clean-room segregation, redaction, controlled annex treatment, export license, or exclusion.

#### 232.5 Open Source, Public-Domain, Research, and Educational Materials

232.5.1 Open-source, public-domain, research, educational, and public-good release status shall not be assumed to eliminate sanctions, export-control, cybersecurity, controlled-technology, public authority, or national security-sensitive obligations.

232.5.2 Before releasing software, datasets, technical baselines, methods, AI tools, cybersecurity tools, telecom methods, AI-RAN / O-RAN materials, DePIN materials, DLT tools, geospatial data, digital twin models, or infrastructure-sensitive materials, the Corporation shall review whether release is lawful, safe, public-benefit aligned, and not subject to restriction.

#### 232.6 Restricted Jurisdictions, End Users, and End Uses

232.6.1 The Corporation shall not knowingly support prohibited end users, prohibited end uses, restricted jurisdictions, sanctioned persons, terrorist organizations, weapons proliferation, unlawful surveillance, cyber abuse, human rights abuse, repression, evasion, procurement fraud, or other prohibited activities.

232.6.2 End-use review shall be required where materials or access could support military, intelligence, surveillance, cyber offense, critical infrastructure targeting, weapons development, sanctions evasion, export-control evasion, unauthorized public authority action, or harmful uses inconsistent with public-benefit purpose.

#### 232.7 Payments, Banking, Grants, Donations, and Sponsorships

232.7.1 Payments, banking, donations, grants, sponsorships, reimbursements, stipends, awards, scholarships, fellowships, vendor payments, contractor payments, refunds, and transfers shall be screened where required or prudent for sanctions and restricted-party risk.

232.7.2 The Corporation shall not accept, transmit, return, refund, or route funds in a manner that violates sanctions, anti-terrorism, export-control, banking, anti-money-laundering, or restricted-party rules.

#### 232.8 Public Authority, University, Laboratory, and Cross-Border Interfaces

232.8.1 Public authority, university, laboratory, international, cross-border, and North America interfaces shall be reviewed for sanctions, export-control, controlled-technology, public-sector restrictions, research security, foreign influence, data transfer, privacy, cyber, and protected knowledge implications.

232.8.2 Collaboration with public authorities, universities, laboratories, or foreign persons shall not create authority to share controlled technology, restricted data, or export-controlled materials without review and record.

#### 232.9 Sanctions and Export-Control Holds

232.9.1 The Corporation may impose immediate holds, stops, quarantines, access restrictions, payment freezes, publication freezes, repository freezes, data freezes, model freezes, controlled-room lockdowns, shipment holds, contract holds, grant holds, sponsorship holds, travel holds, or communication restrictions where sanctions or export-control risk exists.

232.9.2 Holds shall remain in effect until competent review determines that the matter is lawful, re-scoped, licensed, terminated, refused, or otherwise resolved.

#### 232.10 Violations and Corrective Action

232.10.1 Sanctions or export-control violations, suspected violations, near misses, attempted evasion, false certifications, restricted-party matches, unauthorized access, unauthorized release, or restricted payments shall be escalated promptly.

232.10.2 Corrective action may include access revocation, payment reversal where lawful, filing or notice where required, legal review, voluntary disclosure where appropriate, contract termination, repository takedown, publication withdrawal, technical quarantine, participant suspension, and Board notification.

#### 232.11 Sanctions and Export-Control Records

232.11.1 The Corporation shall maintain Sanctions and Export-Control Records, including screening records, restricted-party checks, export classifications, controlled-technology reviews, license determinations, access restrictions, public release reviews, cross-border reviews, payment reviews, holds, escalations, legal reviews, approvals, refusals, violations, corrective actions, notices, disclosures, and closeout records.

### Section 233. Fundraising Strategy, Development, and Public-Good Support

#### 233.1 Fundraising Strategy Purpose.

233.1.1 The Corporation shall maintain a fundraising, development, and public-good support strategy that advances its lawful public-benefit purposes, fiscal sustainability, institutional independence, nonprofit character, non-execution boundary, evidence integrity, methods integrity, public-good software continuity, public authority learning function, safeguards obligations, and North America anchor role.\
233.1.2 Fundraising strategy shall be treated as a governance-control function and not merely as revenue generation, communications, donor cultivation, sponsor packaging, or institutional visibility.\
233.1.3 The Corporation shall pursue support only in forms that preserve support-without-control, donor non-control, sponsor non-control, provider neutrality, procurement neutrality, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, recognition-boundary discipline, data / AI / cyber integrity, community safeguards, protected knowledge duties, validity-by-record, and correctionability.

#### 233.2 Public-Benefit Fundraising.

233.2.1 All fundraising and development activity shall be directed to the Corporation’s public-benefit purposes and shall not be structured, described, or implemented as private capital raising, investment solicitation, project finance execution, commercial sales, pay-to-play access, provider onboarding, certification sale, recognition sale, finance-readiness sale, procurement advantage, public authority access purchase, or enterprise-stack execution.\
233.2.2 Public-benefit fundraising may include lawful requests for grants, donations, sponsorships, subscriptions, program support, Academy support, research support, public-good software support, technical infrastructure support, public authority learning support, safeguards support, in-kind contributions, cost recovery, and other support approved by competent authority.\
233.2.3 Fundraising materials shall accurately describe the Corporation’s legal status, nonprofit character, tax posture, non-execution role, public-good technical institution character, and boundaries from The Global Risks Forum (GRF), The Global Risks Alliance (GRA), public authorities, providers, national companies, Project SPVs, and enterprise execution actors.

#### 233.3 Deliverables-Led Public-Good Support Strategy.

233.3.1 The Corporation may organize fundraising strategy around public-good deliverables, provided that such deliverables are mission-aligned, non-controlling, record-supported, public-safe, and not sold as outcomes purchased by the supporter.\
233.3.2 Deliverables-led support may relate to:\
233.3.2(a) evidence infrastructure;\
233.3.2(b) methods, ontology, and controlled vocabulary;\
233.3.2(c) observability methods;\
233.3.2(d) public-good software and open technical baselines;\
233.3.2(e) data, AI, cyber, privacy, and secure repository infrastructure;\
233.3.2(f) public authority learning;\
233.3.2(g) community safeguards and protected knowledge stewardship;\
233.3.2(h) Academy, fellowship, workforce, and competence formation;\
233.3.2(i) state, territorial, Tribal, local, and North America interface support; and\
233.3.2(j) core operating capacity.\
233.3.3 Deliverables-led support shall not grant the supporter control over research questions, evidence conclusions, methods, publication, software roadmap, technical baseline content, public authority access, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, correction, withdrawal, archive status, or Nexus-facing public meaning.

#### 233.4 Multi-Year Funding Strategy.

233.4.1 The Corporation may adopt a multi-year funding strategy to preserve continuity, reduce dependency, support long-horizon public-good assets, and avoid unstable reliance on a single donor, sponsor, funder, provider, host, public authority, capital actor, or enterprise actor.\
233.4.2 The multi-year funding strategy may include revenue diversification, reserve planning, grant pipelines, donor cultivation, sponsorship limits, unrestricted support targets, restricted support review, in-kind dependency controls, core operating support, and continuity funding for repositories, technical assets, safeguards, legal compliance, and public authority learning.\
233.4.3 Multi-year funding strategy shall not create binding spending authority, donor rights, sponsor rights, funder control, provider preference, or public authority commitment unless separately approved by competent record.

#### 233.5 Evidence Infrastructure Funding.

233.5.1 The Corporation may raise funds to support evidence infrastructure, including evidence intake systems, evidence repositories, provenance tools, chain-of-custody methods, evidence packs, proof receipts, source-lineage systems, reproducibility support, audit trails, evidence challenge pathways, and correction records.\
233.5.2 Evidence infrastructure funding shall preserve independence of evidence treatment and shall not permit any supporter to purchase favorable classification, favorable weighting, favorable visibility, suppression of uncertainty, exclusion of contrary evidence, or privileged correction avoidance.

#### 233.6 Methods and Ontology Funding.

233.6.1 The Corporation may raise funds to support methods, ontology, semantic interoperability, controlled vocabulary, taxonomies, schemas, data dictionaries, classification systems, risk categories, maturity concepts, technical profiles, public-safe language, and cross-document terminology discipline.\
233.6.2 Methods and ontology funding shall not permit supporters to redefine controlled terms, steer method design to favor a product or market position, create certification meaning, create recognition meaning, create finance-readiness meaning, or establish standards authority outside competent Nexus instruments.

#### 233.7 Observability Methods Funding.

233.7.1 The Corporation may raise funds for observability methods, including Nexus Observatory methods, node methods, hub methods, cluster methods, hotspot methods, regional cluster methods, national dense core methods, dashboard methods, sensor methods, AI-RAN and O-RAN signal interpretation, DePIN and DLT record interpretation, digital twin methods, cyber telemetry methods, geospatial methods, and degraded-mode awareness methods.\
233.7.2 Observability methods funding shall not authorize the Corporation to operate infrastructure as a public authority, issue public warnings, command emergency response, guarantee signal accuracy, certify system safety, or substitute for licensed operational or governmental decision-makers.

#### 233.8 Public-Good Software and Open Technical Baseline Funding.

233.8.1 The Corporation may raise funds for public-good software, open technical baselines, reference implementations, APIs, SDKs, schemas, dashboards, test harnesses, benchmark libraries, model cards, system cards, proof-receipt tools, repository infrastructure, software security, documentation, and maintenance.\
233.8.2 Public-good software and open technical baseline funding shall preserve anti-enclosure, provider neutrality, open access where lawful, security review, license compatibility, contributor discipline, correctionability, and release independence.\
233.8.3 No supporter shall receive technical baseline control, roadmap veto, private release priority, standards outcome, certification implication, provider preference, procurement advantage, or Nexus-compatible status by reason of such funding.

#### 233.9 Data / AI / Cyber Infrastructure Funding.

233.9.1 The Corporation may raise funds to support lawful data infrastructure, approved AI tools, verifiable compute methods, verifiable intelligence methods, cybersecurity controls, secure collaboration systems, controlled rooms, clean rooms, data rooms, identity systems, logging, auditability, privacy controls, incident response, and secure repository operations.\
233.9.2 Funding for data / AI / cyber infrastructure shall be subject to privacy, security, public authority data, protected knowledge, sanctions, export-control, controlled-technology, AI-use, no-training, retention, deletion, and access-control review.\
233.9.3 No funding arrangement shall permit unauthorized model training, unrestricted embedding, protected knowledge extraction, hidden telemetry, public authority data misuse, cyber-risk suppression, or technical dependency inconsistent with institutional independence.

#### 233.10 Public Authority Learning Funding.

233.10.1 The Corporation may raise funds to support public authority learning, including lawful capacity-building, technical literacy, public-safe evidence interpretation, observability literacy, risk-methods education, public-good software training, data / AI / cyber literacy, and cross-jurisdictional learning.\
233.10.2 Public authority learning funding shall not create public authority delegation, official adoption, procurement advantage, grant approval, regulatory approval, public finance approval, emergency command, public warning authority, sovereign obligation, or public-private partnership unless separately and lawfully constituted outside the Corporation’s non-execution role.\
233.10.3 Fundraising for public authority learning shall include public-safe language sufficient to prevent supporters, public authorities, capital readers, providers, or the public from misinterpreting learning support as official approval or institutional endorsement.

#### 233.11 Community Safeguards and Protected Knowledge Funding.

233.11.1 The Corporation may raise funds to support community safeguards, civil rights, accessibility, Tribal and Indigenous protocol respect, protected knowledge handling, grievance pathways, remedy design, non-retaliation, public-safe mapping, redaction, controlled publication, and safeguards review.\
233.11.2 Support for community safeguards and protected knowledge shall not purchase community access, protected knowledge access, trust relationships, attribution rights, publication rights, data rights, mapping rights, AI-use rights, or public narrative control.\
233.11.3 Where a supporter’s interests may conflict with affected communities, Indigenous governance, protected knowledge, civil rights, or accessibility, the Corporation shall apply heightened conflict, safeguards, and anti-capture review.

#### 233.12 Academy, Fellowship, Workforce, and Competence Formation Funding.

233.12.1 The Corporation may raise funds for Academy programs, fellowships, workforce formation, technical literacy, public authority learning, researcher training, competence formation, reviewer training, data / AI / cyber training, safeguards training, and public-good technical stewardship education.\
233.12.2 Funding for such activities shall not create credential sale, certification, professional licensure, employment guarantee, procurement preference, public authority preference, recognition, finance-readiness, or provider qualification unless separately authorized by competent record and lawful authority.\
233.12.3 Scholarships, fellowships, sponsored seats, training seats, and supported participation shall be governed by eligibility criteria, conflict review, influence aggregation, non-discrimination, accessibility, public authority boundary, and records discipline.

#### 233.13 Core Operating Support.

233.13.1 The Corporation may seek unrestricted or core operating support to preserve governance, staffing, administration, records, legal compliance, fiscal systems, insurance, cybersecurity, repository continuity, public-good software maintenance, public authority learning support, safeguards, and institutional resilience.\
233.13.2 Core operating support shall be preferred where it strengthens independence, reduces fragmentation, preserves public-benefit flexibility, and avoids narrow funder control.\
233.13.3 Core operating support shall not create general institutional control, appointment rights, Board influence, budget veto, staffing influence, agenda control, public authority access, or publication control.

#### 233.14 Restricted Program Support.

233.14.1 Restricted program support may be accepted only where the restriction satisfies the Support Acceptance Test, preserves public-benefit purpose, does not create prohibited control, and remains administratively feasible and records-supported.\
233.14.2 Restricted program support shall be coded, tracked, spent, reported, modified, corrected, and closed under restricted-fund controls.\
233.14.3 Restricted program support shall not be accepted where the restriction would distort mission, suppress correction, require unauthorized public authority action, imply finance-readiness, imply certification, imply recognition, create procurement advantage, or support enterprise execution.

#### 233.15 State, Territorial, Tribal, Local, and North America Interface Support.

233.15.1 The Corporation may raise funds for lawful state, territorial, Tribal, local, regional, cross-border, and North America interface support, including evidence methods, technical literacy, public authority learning, observability methods, safeguards, and public-good technical baseline adaptation.\
233.15.2 Such support shall preserve local law respect, Tribal and Indigenous governance respect, public authority capacity classification, cross-border compliance, non-extraterritorial effect, data localization, protected knowledge handling, and United States legal-seat discipline.\
233.15.3 Interface support shall not imply authority to act for any state, territory, Tribal Nation, local government, Canadian entity, Mexican entity, regional body, public authority, or cross-border institution.

#### 233.16 Board Oversight of Fundraising Strategy.

233.16.1 The Board shall oversee fundraising strategy at a level appropriate to the Corporation’s scale, risks, donor profile, sponsor profile, restricted funds, public authority interfaces, provider dependencies, in-kind contributions, cross-border activities, and public claims.\
233.16.2 Board oversight may include approval of development strategy, fundraising priorities, restricted support parameters, sponsor categories, donor concentration thresholds, public acknowledgment rules, benefit schedules, acceptance thresholds, refusal rules, and escalation triggers.\
233.16.3 Material fundraising risks shall be reported to the Board or competent committee, including donor concentration, sponsor concentration, provider dependency, public authority confusion, finance overclaim, certification overclaim, recognition overclaim, procurement risk, data / AI / cyber risk, safeguards risk, and reputational risk.

#### 233.17 No Fundraising That Implies Securities Offering, Investment Solicitation, Public Finance Approval, Procurement Preference, Certification, Recognition, Finance-Readiness Outcome, or Public Authority Endorsement.

233.17.1 Fundraising materials, conversations, proposals, grant applications, sponsorship packages, donor briefings, public statements, websites, decks, Academy materials, investor-adjacent materials, public authority materials, and Nexus-facing descriptions shall not state or imply that support to the Corporation creates:\
233.17.1(a) a securities offering, investment opportunity, investment solicitation, capital allocation pathway, investment recommendation, underwriting basis, lending basis, insurance basis, rating basis, or public finance approval;\
233.17.1(b) procurement preference, vendor qualification, provider preference, public contract advantage, grant advantage, or public-private partnership;\
233.17.1(c) certification, accreditation, legal compliance approval, standards approval, recognition, maturity standing, claims clearance, Docket approval, Grid guarantee, GRF action, or Nexus-compatible status;\
233.17.1(d) finance-readiness, capital-readability, proof-pack approval, bankability, investability, insurability, creditworthiness, underwriting suitability, GRA action, or public finance readiness; or\
233.17.1(e) public authority endorsement, official adoption, sovereign approval, public warning authority, emergency command authority, regulatory approval, or governmental decision.\
233.17.2 Any fundraising communication that creates such implication shall be corrected, withdrawn, restricted, clarified, or escalated.

#### 233.18 Fundraising Strategy Records.

233.18.1 The Corporation shall maintain Fundraising Strategy, Development, and Public-Good Support Records, including strategy documents, Board approvals, development plans, donor pipelines, sponsor pipelines, grant pipelines, public-good deliverable frameworks, support categories, acceptance criteria, refusal records, public acknowledgment language, fundraising materials, restricted support records, public authority learning support records, state and territorial interface support records, Tribal and Indigenous safeguards support records, North America interface support records, conflict reviews, concentration reviews, correction records, and closeout records.

***

### Section 234. Support Acceptance Test

#### 234.1 Acceptance Test Purpose.

234.1.1 The Support Acceptance Test shall govern whether the Corporation may accept, restrict, condition, return, refuse, terminate, or escalate any grant, donation, sponsorship, in-kind contribution, subscription, fee, cost-recovery amount, technical support, host support, public authority support, public-good infrastructure support, or other support.\
234.1.2 The Acceptance Test protects public-benefit purpose, nonprofit integrity, tax compatibility, legal compliance, independence, anti-capture discipline, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, donor non-control, data / AI / cyber controls, community safeguards, protected knowledge, validity-by-record, and correctionability.

#### 234.2 Legal Compliance Test.

234.2.1 Support shall not be accepted unless it is lawful for the Corporation to receive, hold, account for, use, acknowledge, report, restrict, return, and close the support under applicable federal, state, territorial, Tribal-interface, local, tax, nonprofit, charitable solicitation, contract, employment, privacy, AI, cybersecurity, sanctions, export-control, public authority, grant, procurement, lobbying, government ethics, and other relevant law.\
234.2.2 Where legal authority is unclear, the matter shall be held, narrowed, escalated to counsel, or refused pending competent review.

#### 234.3 Public-Benefit Purpose Test.

234.3.1 Support shall advance or be compatible with the Corporation’s public-benefit purposes, including evidence, methods, observability, ontology, technical truth, public-good R\&D, public-good software, open technical baselines, public authority learning, safeguards, and related lawful public-good functions.\
234.3.2 Support shall not be accepted where its practical effect is mission drift, private agenda advancement, sponsor control, provider preference, public authority confusion, finance overclaim, certification overclaim, recognition overclaim, procurement overclaim, or enterprise-stack execution.

#### 234.4 Nonprofit and Tax Compatibility Test.

234.4.1 Support shall be reviewed for nonprofit compatibility, tax treatment, restricted-fund treatment, public support implications, unrelated business income risk, sponsorship classification, donation acknowledgment, grant classification, cost-recovery treatment, and reporting requirements.\
234.4.2 No support shall be accepted where its structure would materially compromise the Corporation’s nonprofit character, tax-exempt or tax-exempt-compatible posture, non-distribution rule, or public-benefit purpose.

#### 234.5 Tax-Exempt or Tax-Exempt-Compatible Status Test.

234.5.1 Where the Corporation has obtained, seeks, or maintains a tax-exempt or tax-exempt-compatible status, support shall be reviewed for consistency with that status and with applicable federal, state, and local tax obligations.\
234.5.2 Support shall not be accepted where it creates excessive private benefit, prohibited campaign intervention, impermissible lobbying risk where applicable, unrelated business activity beyond permitted limits, false charitable receipting, improper donor benefit, or other tax incompatibility.

#### 234.6 No Private Inurement Test.

234.6.1 Support shall not result in net earnings, assets, opportunities, technical assets, institutional status, compensation, reimbursement, contracts, access, or public-good value inuring to the benefit of insiders or private persons in violation of applicable law or this Bylaw.\
234.6.2 Support connected to directors, officers, employees, founders, donors, sponsors, providers, Related Parties, national companies, Project SPVs, or enterprise actors shall receive heightened review.

#### 234.7 No Impermissible Private Benefit Test.

234.7.1 Support shall not confer impermissible private benefit on any supporter, provider, sponsor, donor, funder, host, public authority participant, capital actor, national company, Project SPV, enterprise actor, Related Party, or other private person.\
234.7.2 Any private benefit incidental to a lawful support arrangement must be reasonable, proportionate, mission-aligned, recorded, non-controlling, and not inconsistent with nonprofit character or public-benefit purpose.

#### 234.8 Anti-Capture Test.

234.8.1 Support shall be reviewed for capture risk, including financial concentration, technical dependency, public authority access pressure, narrative pressure, publication pressure, restricted-fund leverage, renewal leverage, staff dependency, repository dependency, cloud dependency, AI dependency, cybersecurity dependency, host dependency, and public visibility dependency.\
234.8.2 Support shall be refused, restricted, diversified, ring-fenced, returned, terminated, or escalated where capture risk cannot be mitigated.

#### 234.9 No Control-for-Cash Test.

234.9.1 Support shall not create direct or indirect control in exchange for cash, in-kind value, technical infrastructure, data, tools, compute, facilities, staff time, visibility, public authority proximity, or reputational benefit.\
234.9.2 Control-for-cash includes control over governance, Board decisions, officer decisions, committees, councils, research agenda, evidence treatment, methods, publications, public-good software, technical baselines, public authority access, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, correction, or public claims.

#### 234.10 Research Independence Test.

234.10.1 Support shall preserve research independence, including independence of research questions, design, evidence collection, methods, peer review, interpretation, limitation language, publication decisions, correction, withdrawal, and archive status.\
234.10.2 Sponsored or restricted research support may be accepted only where the supporter does not control conclusions, suppress unfavorable findings, prevent correction, distort uncertainty, or purchase public-safe meaning.

#### 234.11 Evidence and Methods Integrity Test.

234.11.1 Support shall preserve evidence and methods integrity, including provenance, chain of custody, reproducibility, confidence, uncertainty, source limitations, data quality, AI-use disclosure, model limitations, public-safe interpretation, and correction history.\
234.11.2 Support shall not purchase favorable evidence classification, method design, benchmark treatment, technical profile inclusion, observability interpretation, proof receipt, or technical baseline content.

#### 234.12 Public Authority Boundary Test.

234.12.1 Support shall not create or imply public authority delegation, public authority endorsement, official adoption, regulatory approval, procurement approval, grant approval, public finance approval, public warning authority, emergency command authority, sovereign obligation, or public-private partnership.\
234.12.2 Where support involves public authorities or public authority-facing work, the Corporation shall classify capacity, record authority surfaces, preserve public records and ethics controls where applicable, and use limitation language.

#### 234.13 Finance, Securities, Insurance, Lending, Rating, Public Finance, Procurement, Certification, Recognition, and Professional Boundary Test.

234.13.1 Support shall not create or imply securities activity, investment advice, broker-dealer activity, finder activity, capital placement, lending, banking, insurance, underwriting, rating, guarantee, public finance approval, procurement approval, certification, accreditation, recognition, maturity standing, professional advice, legal compliance approval, or execution instruction.\
234.13.2 Support connected to capital readers, investors, insurers, lenders, banks, underwriters, public finance actors, rating actors, procurement officials, providers, or professional firms shall be reviewed for regulated-perimeter, procurement, professional boundary, and public claims risk.

#### 234.14 Provider Neutrality Test.

234.14.1 Support shall not create provider preference, preferred vendor status, technical standard status, procurement signal, compatibility implication, certification, recognition, finance-readiness, public authority endorsement, or market recommendation.\
234.14.2 Provider support, technical contributions, cloud credits, AI tools, cybersecurity tools, datasets, equipment, and in-kind services shall be reviewed for dependency, lock-in, access rights, data rights, IP rights, public claims, procurement sensitivity, and neutrality.

#### 234.15 Sponsor, Donor, Funder, Host, and Enterprise Influence Test.

234.15.1 Support shall be reviewed for influence by sponsors, donors, funders, hosts, universities, laboratories, enterprise actors, national companies, Project SPVs, public authorities, and Related Parties.\
234.15.2 Influence may arise through conditions, side letters, renewal expectations, reporting pressure, benefit schedules, restricted purpose, staff secondment, host leverage, public acknowledgment, event visibility, public authority proximity, or technical dependency.

#### 234.16 Data / AI / Cyber / Privacy Test.

234.16.1 Support shall be reviewed for data, AI, cyber, privacy, repository, identity, logging, model, cloud, compute, inference, embedding, prompt, dashboard, API, and technical-system implications.\
234.16.2 No support shall be accepted where it would require unauthorized data access, unrestricted AI training, model improvement on restricted materials, hidden telemetry, weak cyber controls, public authority data misuse, protected knowledge exposure, privacy violation, or security dependency inconsistent with the Corporation’s duties.

#### 234.17 IP and Public-Good Technical Asset Test.

234.17.1 Support shall preserve the Corporation’s rights, licenses, public-good software continuity, open technical baseline access, anti-enclosure posture, chain-of-title discipline, contributor terms, open-source compliance, mark-use discipline, and correctionability.\
234.17.2 Support shall not give a supporter private control over public-good technical assets, exclusive rights inconsistent with public-benefit purpose, standards leverage, provider preference, or public-good asset enclosure.

#### 234.18 Community Safeguards, Civil Rights, Accessibility, Tribal / Indigenous, and Protected Knowledge Test.

234.18.1 Support shall be reviewed for civil rights, accessibility, community safeguards, Tribal and Indigenous protocols, Indigenous data governance, protected knowledge, local and territorial knowledge, public-safe mapping, consent, non-consent, withdrawal, grievance, remedy, and non-retaliation.\
234.18.2 Support shall be refused or restricted where it would expose vulnerable communities, purchase community access, pressure protected knowledge disclosure, weaken accessibility, create retaliation risk, or distort safeguards.

#### 234.19 Sanctions, Export-Control, Controlled Technology, National Security Sensitivity, Anti-Corruption, and Reputation Test.

234.19.1 Support shall be screened where required or prudent for sanctions, restricted-party status, export-control, controlled technology, anti-terrorism, anti-money-laundering, anti-corruption, bribery, fraud, national security sensitivity, human rights abuse, unlawful surveillance, cyber abuse, and reputational risk.\
234.19.2 Support shall be held, refused, returned, quarantined, terminated, or escalated where the source, purpose, routing, technology, end use, end user, jurisdiction, payment channel, or public meaning creates unresolved legal or integrity risk.

#### 234.20 Acceptance, Refusal, Restriction, Return, Termination, or Escalation.

234.20.1 Following the Support Acceptance Test, the Corporation may accept, conditionally accept, restrict, ring-fence, modify, hold, refuse, return, terminate, or escalate support.\
234.20.2 Conditions may include:\
234.20.2(a) non-control language;\
234.20.2(b) public-safe acknowledgment;\
234.20.2(c) restricted access;\
234.20.2(d) data / AI / cyber controls;\
234.20.2(e) publication independence;\
234.20.2(f) conflict mitigation;\
234.20.2(g) provider-neutrality protections;\
234.20.2(h) public authority limitation language;\
234.20.2(i) finance-boundary and certification-boundary disclaimers;\
234.20.2(j) safeguards conditions;\
234.20.2(k) Board review; and\
234.20.2(l) renewal review.

#### 234.21 Acceptance Test Records.

234.21.1 The Corporation shall maintain Support Acceptance Test Records identifying the support source, value, type, purpose, restrictions, benefits, related parties, conflicts, legal review, tax review, public-benefit review, anti-capture review, public authority review, finance-boundary review, certification-boundary review, procurement review, provider-neutrality review, data / AI / cyber review, IP review, safeguards review, sanctions and export-control review, decision, conditions, refusal, return, termination, escalation, correction, and closeout.

***

### Section 235. Support-Without-Control and No Control-for-Cash

#### 235.1 Support-Without-Control Principle.

235.1.1 The Corporation may accept lawful support only where support does not control governance, research, evidence, methods, publications, software, technical baselines, public authority interfaces, safeguards, correction, public claims, or Nexus-facing outputs.\
235.1.2 Support-without-control is a mandatory condition of fiscal integrity, public-benefit purpose, nonprofit discipline, non-execution, anti-capture, provider neutrality, sponsor non-control, donor non-control, and public trust.

#### 235.2 Sponsor Non-Control.

235.2.1 Sponsors shall not control Board decisions, officer decisions, committee work, council work, research design, evidence conclusions, methods, publication timing, public authority access, technical baselines, software releases, public-safe reports, correction, or public claims.\
235.2.2 Sponsorship may provide bounded acknowledgment and approved benefits only where such benefits are non-controlling, non-exclusive unless justified, recorded, and subject to public-safe limitations.

#### 235.3 Donor Non-Control.

235.3.1 Donors shall not control governance, staffing, research agenda, publication conclusions, public authority access, provider selection, technical outputs, correction, or institutional strategy by reason of donation.\
235.3.2 Donor intent may be honored only through lawful restrictions accepted by competent authority and consistent with public-benefit purpose, tax rules, nonprofit integrity, and this Bylaw.

#### 235.4 Funder Non-Control.

235.4.1 Funders shall not use grant terms, milestones, reporting, renewal expectations, public acknowledgment, or budget leverage to control evidence, methods, publication, public authority interfaces, software, technical baselines, safeguards, or correction.\
235.4.2 Funder-required deliverables shall be governed by grant controls and shall not purchase findings, recognition, finance-readiness, certification, procurement advantage, or public authority meaning.

#### 235.5 Provider Non-Control.

235.5.1 Providers shall not control technical baselines, public-good software, repositories, data environments, AI systems, cyber posture, public authority learning, procurement-sensitive content, or public claims.\
235.5.2 Provider support shall not create preferred provider status, procurement signal, compatibility approval, certification, recognition, finance-readiness, or Nexus-compatible status.

#### 235.6 Host Non-Control.

235.6.1 Hosts shall not control agenda, participant access, publication, evidence handling, public authority interfaces, protected knowledge, data custody, technical systems, or correction by reason of providing facilities, convening support, infrastructure, staff, or local relationships.\
235.6.2 Host support shall be governed by access, confidentiality, safety, public authority, data / AI / cyber, accessibility, civil rights, insurance, and safeguards controls.

#### 235.7 Investor, Insurer, Lender, Underwriter, Bank, Public Finance Actor, and Capital Reader Non-Control.

235.7.1 Capital actors shall not control the Corporation’s evidence, methods, public-safe reports, technical baselines, Docket inputs, Grid inputs, GRA-facing inputs, publication, public authority access, or public claims.\
235.7.2 Capital actor support or participation shall not create investment advice, underwriting approval, insurance approval, bankability, creditworthiness, rating, public finance approval, finance-readiness, or capital solicitation.

#### 235.8 Public Authority Non-Control Except Through Lawful Public Authority Action Outside GCRI US Governance.

235.8.1 Public authorities shall not control the Corporation’s internal governance except through lawful contracts, grants, legal requirements, or public authority actions properly applicable to the Corporation and recorded as such.\
235.8.2 Public authority support, participation, funding, data contribution, attendance, or learning engagement shall not convert the Corporation into a public authority, regulator, procurement body, public finance approver, emergency command body, or public warning authority.\
235.8.3 Lawful public authority requirements shall be distinguished from public authority preferences, informal expectations, political pressure, procurement interest, or official-capacity ambiguity.

#### 235.9 No Control Over Board Decisions.

235.9.1 No supporter shall have authority to appoint, remove, instruct, veto, direct, condition, pre-clear, or control directors or Board decisions unless such right is expressly permitted by applicable law, governing instruments, and Board-approved constitutional structure.\
235.9.2 Support arrangements shall not include Board observer rights, Board agenda rights, reserved matters, veto rights, approval rights, or informal governance rights unless independently lawful, non-controlling, conflict-reviewed, and expressly approved by competent authority.

#### 235.10 No Control Over Officer Decisions.

235.10.1 No supporter shall control officer decisions, delegated authority, staffing, contracting, payment, publication, public authority interface, technical release, repository permissions, safeguards action, or correction.\
235.10.2 Officers shall not accept side instructions, sponsor preferences, donor pressure, provider pressure, public authority expectations, funder demands, or host leverage inconsistent with their duties to the Corporation.

#### 235.11 No Control Over Research Agenda Except Through Accepted, Labeled, and Governed Program Scope.

235.11.1 A supporter may fund a defined program scope only where the program is lawful, mission-aligned, labeled where necessary, independently governed, and subject to research integrity, publication independence, methods integrity, safeguards, and correction.\
235.11.2 Accepted program scope shall not permit the supporter to dictate findings, exclude adverse evidence, suppress limitations, alter methods, prevent publication, or block correction.

#### 235.12 No Control Over Findings, Methods, Evidence, Publications, Software, Technical Baselines, Public Authority Access, Docket Inputs, Grid Inputs, GRF Inputs, GRA Inputs, or Nexus Interface Outputs.

235.12.1 Support shall not give any supporter control over:\
235.12.1(a) findings, evidence summaries, confidence scores, uncertainty statements, proof receipts, or evidence packs;\
235.12.1(b) methods, ontologies, controlled vocabulary, taxonomies, schemas, data dictionaries, benchmarks, model evaluations, or technical profiles;\
235.12.1(c) publications, public-safe reports, dashboards, maps, digital twins, Academy materials, or public statements;\
235.12.1(d) public-good software, open technical baselines, repositories, APIs, SDKs, reference implementations, release pipelines, or security notes;\
235.12.1(e) public authority access, public authority rooms, regulator-listening status, public finance reader status, or public authority references; or\
235.12.1(f) Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, Nexus-facing outputs, correction notices, withdrawal notices, or archive status.

#### 235.13 No Control Through Aggregated Seats, Affiliates, Related Parties, Sponsored Participants, In-Kind Dependency, or Critical Supplier Dependency.

235.13.1 Control may arise through aggregation, dependency, or coordinated influence even where no single instrument grants control.\
235.13.2 The Corporation shall review whether affiliates, Related Parties, sponsored seats, funded fellows, sponsored participants, technical contributors, host dependencies, cloud dependencies, AI dependencies, cybersecurity dependencies, repository dependencies, data processor dependencies, or critical supplier dependencies create practical control.\
235.13.3 Practical control shall be mitigated, ring-fenced, diversified, restricted, terminated, or escalated where necessary.

#### 235.14 No Pay-to-Play.

235.14.1 No person or entity shall purchase status, access, favorable review, favorable publication, controlled-room admission, public authority proximity, technical inclusion, Docket relevance, Grid relevance, GRF-facing relevance, GRA-facing relevance, Nexus-facing significance, or public-good legitimacy through support.\
235.14.2 Pay-to-play concerns shall trigger conflict intake, acceptance review, anti-capture review, and corrective action where appropriate.

#### 235.15 No Access-for-Money.

235.15.1 Access to directors, officers, committees, councils, staff, public authorities, controlled rooms, repositories, technical maintainers, public authority participants, GRF-facing pathways, GRA-facing pathways, or Nexus interfaces shall not be sold, promised, bundled, reserved, or preferentially granted as a financial benefit.\
235.15.2 Lawful participation benefits shall be bounded, non-exclusive unless justified, public-safe, non-governance, and recorded.

#### 235.16 No Outcome Purchase.

235.16.1 No support shall purchase or influence a desired outcome, including a favorable finding, favorable report, favorable method, favorable publication, favorable public-safe classification, favorable technical baseline, favorable Docket input, favorable Grid input, favorable GRF-facing input, favorable GRA-facing input, favorable public authority framing, or favorable correction outcome.\
235.16.2 The Corporation shall preserve the right to disagree with, correct, publish against, withdraw from, or terminate a support relationship where public-good integrity requires.

#### 235.17 No Veto or Suppression Right.

235.17.1 No supporter shall have a veto, suppression right, delay right, pre-clearance right, approval right, narrative control right, or correction-blocking right over the Corporation’s governance, evidence, methods, publications, software, technical baselines, public authority learning, safeguards, or correction.\
235.17.2 Confidentiality, privacy, privilege, public authority restrictions, cyber sensitivity, protected knowledge, and safeguards may justify lawful publication restrictions, but not supporter-driven suppression.

#### 235.18 Support-Without-Control Records.

235.18.1 The Corporation shall maintain Support-Without-Control Records identifying support source, support type, value, restrictions, benefits, affected programs, possible control surfaces, sponsor non-control review, donor non-control review, funder non-control review, provider non-control review, host non-control review, capital actor review, public authority review, aggregation review, dependency review, mitigation, ring-fencing, refusal, return, termination, correction, and closeout.

***

### Section 236. Influence Caps, Concentration Review, Aggregation, Dependency, and Capture Controls

#### 236.1 Influence Cap Purpose.

236.1.1 Influence caps, concentration review, aggregation rules, dependency controls, and capture controls shall prevent any supporter, provider, donor, funder, host, public authority participant, capital actor, national company, Project SPV, Related Party, affiliate group, or coordinated participant group from acquiring practical control over the Corporation.\
236.1.2 Influence controls shall assess financial influence, technical influence, data influence, public authority influence, reputational influence, personnel influence, host influence, infrastructure influence, and narrative influence.

#### 236.2 Sponsor Concentration Review.

236.2.1 The Corporation shall review whether sponsorship support is concentrated in a manner that creates dependency, agenda pressure, public visibility dependence, publication pressure, public authority access expectations, technical dependency, or reluctance to correct.\
236.2.2 Sponsor concentration review shall consider amount, recurrence, percentage of revenue, program centrality, public visibility, benefit scope, renewal risk, sponsor category, provider overlap, public authority proximity, and related-party status.

#### 236.3 Donor Concentration Review.

236.3.1 Donor concentration review shall assess whether a donor, donor family, donor-advised fund, foundation, affiliated donor group, or coordinated donor network has sufficient influence to affect governance, budget, staffing, strategy, evidence, methods, publication, safeguards, public authority interfaces, or public claims.\
236.3.2 Donor concentration shall not create governance rights, agenda rights, appointment rights, public authority access rights, publication rights, recognition, finance-readiness, certification, procurement advantage, or provider preference.

#### 236.4 Funder Concentration Review.

236.4.1 Funder concentration review shall assess grants, restricted funds, public funds, philanthropic funds, corporate philanthropy, institutional funds, cost-recovery arrangements, and sponsored projects for dependency and influence.\
236.4.2 Review shall consider funder restrictions, milestone control, reporting pressure, renewal expectations, indirect cost dependence, public acknowledgment pressure, public authority connections, strategic objectives, and mission drift risk.

#### 236.5 Provider Concentration Review.

236.5.1 Provider concentration review shall assess whether providers, vendors, contractors, integrators, cloud providers, AI providers, cybersecurity providers, repository providers, data processors, telecom providers, equipment suppliers, or technical partners have become too central to the Corporation’s operations, outputs, or public meaning.\
236.5.2 Provider concentration shall not create provider preference, procurement advantage, technical standard status, certification, recognition, finance-readiness, public authority endorsement, or control over technical baselines.

#### 236.6 Host Dependency Review.

236.6.1 Host dependency review shall assess reliance on host institutions, universities, laboratories, public authorities, facilities, event hosts, data hosts, compute hosts, controlled-room hosts, observability hosts, community hosts, and infrastructure hosts.\
236.6.2 Host dependency controls may include alternate venue planning, independent records custody, data portability, public-safe language, host agreement revision, access restrictions, safeguards review, and Board review.

#### 236.7 In-Kind Dependency Review.

236.7.1 In-kind dependency review shall assess whether donated or discounted goods, services, tools, credits, facilities, equipment, datasets, cloud services, AI tools, cybersecurity services, staff time, or technical support create dependency or hidden control.\
236.7.2 In-kind dependency shall be reviewed for valuation, replacement cost, switching cost, lock-in, data rights, IP rights, public claims, access rights, support obligations, termination risk, and concentration.

#### 236.8 Cloud, Compute, AI Provider, Cybersecurity Provider, Repository Provider, Data Processor, and Critical Supplier Dependency Review.

236.8.1 The Corporation shall review dependency on cloud, compute, AI, cybersecurity, repository, data processor, identity, logging, backup, payment, payroll, accounting, communications, publication, and other critical suppliers.\
236.8.2 Dependency review shall assess portability, continuity, exit rights, data export, audit logs, access controls, incident response, confidentiality, provider lock-in, sovereign data implications, cross-border transfers, sanctions, export-control, and public authority data restrictions.\
236.8.3 Critical suppliers shall not control incident classification, evidence custody, public statements, publication, technical releases, public authority notices, correction, or institutional continuity.

#### 236.9 Related-Party Funding Review.

236.9.1 Funding, sponsorship, donation, in-kind support, grants, contracts, or cost-recovery arrangements involving Related Parties shall receive heightened review for private inurement, impermissible private benefit, conflicts, influence aggregation, and Board oversight.\
236.9.2 Related-party funding shall not be accepted, renewed, or relied upon without disclosure, recusal, independent review, fairness determination where applicable, public-benefit purpose finding, anti-capture review, and records.

#### 236.10 Aggregation of Related Donors, Sponsors, Providers, Affiliates, Controlled Entities, Sponsored Seats, and Coordinated Participants.

236.10.1 The Corporation shall aggregate influence across related donors, sponsors, providers, affiliates, controlled entities, common-control groups, sponsored seats, funded fellows, public authority-connected actors, technical contributors, and coordinated participants.\
236.10.2 Aggregation shall prevent fragmentation of influence across nominally separate persons, entities, contracts, grants, sponsorships, in-kind contributions, access rights, public acknowledgments, or participation roles.

#### 236.11 Beneficial Owner and Common-Control Aggregation.

236.11.1 The Corporation may require disclosure of beneficial ownership, common control, funding source, affiliate relationships, donor-advised structures, foundation relationships, investment vehicle relationships, provider groups, and coordinated networks where needed to assess influence or legal risk.\
236.11.2 Refusal or inability to provide sufficient control information may support refusal, restriction, suspension, termination, or enhanced monitoring.

#### 236.12 Capture Risk Classification.

236.12.1 Capture risk shall be classified based on likelihood, severity, concentration, dependency, reversibility, public meaning, affected function, public authority implication, finance implication, certification implication, procurement implication, provider-neutrality implication, data / AI / cyber implication, safeguards implication, and correctionability.\
236.12.2 Capture risk classifications may include low, monitored, elevated, material, severe, prohibited, unresolved, under remediation, and closed.

#### 236.13 Mitigation Measures.

236.13.1 Mitigation measures may include:\
236.13.1(a) diversification of funding, providers, hosts, systems, reviewers, or public authority interfaces;\
236.13.1(b) ring-fencing of supporter influence;\
236.13.1(c) recusal, access restriction, role restriction, committee restriction, or voting restriction;\
236.13.1(d) independent review or external review;\
236.13.1(e) benefit reduction or acknowledgment limitation;\
236.13.1(f) contract amendment, exit rights, portability, migration, or transition planning;\
236.13.1(g) public-safe disclosure or controlled disclosure;\
236.13.1(h) monitoring, renewal review, or Board reporting; and\
236.13.1(i) refusal, return, suspension, termination, or correction.

#### 236.14 Refusal, Diversification, Ring-Fencing, Recusal, Access Restriction, Disclosure, Return, or Termination.

236.14.1 Where influence risk cannot be safely mitigated, the Corporation shall refuse support, diversify support, ring-fence influence, require recusal, restrict access, disclose limitations, return support, terminate relationships, migrate systems, or correct public claims.\
236.14.2 The Corporation shall prefer lawful refusal or termination over mission drift, private capture, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, provider preference, protected knowledge exposure, or loss of correctionability.

#### 236.15 Board Review of High Capture Risk.

236.15.1 High capture risk shall be escalated to the Board or a competent Board committee.\
236.15.2 Board review shall consider institutional independence, legal compliance, fiscal sustainability, public-benefit purpose, nonprofit integrity, role separation, public authority boundaries, finance boundaries, provider neutrality, safeguards, technical continuity, and reputational consequence.\
236.15.3 The Board may approve, condition, restrict, reject, return, terminate, or require restructuring of a high-capture-risk relationship.

#### 236.16 Influence Cap, Concentration, Dependency, and Capture Records.

236.16.1 The Corporation shall maintain Influence Cap, Concentration, Dependency, and Capture Records identifying the actor or group reviewed, support type, relationship type, financial concentration, technical concentration, data concentration, public authority concentration, host dependency, in-kind dependency, critical supplier dependency, related-party aggregation, beneficial ownership review, common-control review, capture classification, mitigation, Board review, refusal, return, termination, correction, monitoring, and closeout.

***

### Section 237. Public Acknowledgment, Sponsor Benefits, Donor Benefits, Visibility, Preview Windows, Training Seats, and Non-Endorsement Language

#### 237.1 Public Acknowledgment Purpose.

237.1.1 Public acknowledgment and supporter benefits shall recognize lawful public-good support while preventing endorsement, control, private benefit, public authority confusion, provider preference, finance-readiness implication, recognition implication, certification implication, procurement advantage, or misleading reliance.\
237.1.2 Acknowledgment is not approval. Visibility is not endorsement. Participation is not recognition. Support is not control.

#### 237.2 Public Acknowledgment Authority.

237.2.1 Public acknowledgment shall be approved by competent authority under the Corporation’s policies, support agreements, tax treatment, public-safe claims rules, and approval matrix.\
237.2.2 No person shall promise acknowledgment, logo placement, speaking role, training seat, preview window, advisory participation, controlled-room access, or public authority access outside recorded authority.

#### 237.3 Sponsor Benefit Schedule.

237.3.1 The Corporation may maintain a sponsor benefit schedule identifying permitted, prohibited, and approval-required benefits.\
237.3.2 Sponsor benefits may include bounded acknowledgment, logo placement, event recognition, general program access, training seats, preview windows, non-exclusive participation opportunities, and public-good supporter descriptions where lawful and approved.\
237.3.3 Sponsor benefits shall not include governance rights, publication control, public authority access rights, technical baseline control, certification, recognition, finance-readiness, procurement preference, provider preference, or veto rights.

#### 237.4 Donor Benefit Schedule.

237.4.1 The Corporation may maintain a donor benefit schedule governing acknowledgment, stewardship communications, donor reports, invitations, briefings, and public recognition.\
237.4.2 Donor benefits shall be reasonable, tax-compatible, non-controlling, non-exclusive unless justified, and not disproportionate to public-benefit purpose.\
237.4.3 Donor benefits shall not create private inurement, impermissible private benefit, agenda control, governance control, public authority access, publication control, or public claims advantage.

#### 237.5 Funder Benefit Schedule.

237.5.1 The Corporation may provide funders with reports, deliverables, meetings, briefings, acknowledgments, and program updates consistent with grant or restricted-fund terms.\
237.5.2 Funder benefits shall preserve research independence, evidence integrity, methods integrity, publication independence, correctionability, and public-safe limitations.\
237.5.3 Funder reporting shall not be used to create favorable findings, suppress limitations, misstate impact, or imply recognition, certification, finance-readiness, procurement, or public authority approval.

#### 237.6 Visibility Benefits.

237.6.1 Visibility benefits may include listing names, approved logos, sponsor categories, supporter descriptions, event recognition, program-page references, annual-report acknowledgment, or public-good supporter statements.\
237.6.2 Visibility benefits shall be accurate, limited, non-misleading, non-promotional to the extent required by tax or policy, and subject to non-endorsement language.\
237.6.3 Visibility shall not imply that the Corporation validates, recommends, certifies, recognizes, procures, finances, insures, rates, approves, or endorses the supporter or its products, services, technologies, policies, projects, financing structures, or public authority relationships.

#### 237.7 Logo and Name Placement.

237.7.1 Logo and name placement shall require approval and shall be governed by mark-use, trademark, tax, sponsorship, public-safe claims, accessibility, and non-endorsement controls.\
237.7.2 The Corporation may restrict size, location, order, category, duration, hyperlinking, descriptive text, and context of logos and names.\
237.7.3 Logo placement shall not be used in a manner that implies partnership, agency, endorsement, certification, recognition, finance-readiness, procurement approval, public authority approval, or provider preference.

#### 237.8 Speaking or Participation Opportunities.

237.8.1 Speaking or participation opportunities may be offered only where mission-aligned, non-controlling, fair, conflicts-reviewed where necessary, public-safe, and not sold as access to authority.\
237.8.2 Speaking opportunities shall not be conditioned on support in a manner that creates pay-to-play, outcome purchase, public authority access purchase, provider preference, procurement advantage, or misleading legitimacy.\
237.8.3 Speakers shall comply with competition-law discipline, public authority capacity discipline, sponsor and provider disclosure, non-endorsement rules, data / AI / cyber restrictions, safeguards, and public claims limitations.

#### 237.9 Training Seats.

237.9.1 Training seats may be provided to supporters, sponsors, donors, funders, public authorities, providers, universities, laboratories, community participants, or other participants where lawful, approved, and consistent with program rules.\
237.9.2 Training seats shall not create credentialing, certification, professional licensure, public authority approval, procurement advantage, provider qualification, recognition, finance-readiness, or Nexus-compatible status.\
237.9.3 Sponsored training seats shall be reviewed for influence aggregation, public authority rules, scholarships, accessibility, civil rights, conflicts, and supporter benefit limits.

#### 237.10 Preview Windows.

237.10.1 Preview windows may allow limited pre-release review of materials for factual accuracy, confidentiality, privacy, protected knowledge, public authority restrictions, IP, security, or legal risk.\
237.10.2 Preview windows shall not permit supporters to control conclusions, suppress criticism, delay correction, rewrite findings, influence public-safe classification, or obtain unfair market, procurement, finance, or public authority advantage.\
237.10.3 Preview recipients may be subject to confidentiality, embargo, no-trading, competition, public authority, data / AI / cyber, and public claims restrictions where appropriate.

#### 237.11 Advisory Participation.

237.11.1 Advisory participation may be permitted where the participant’s role is disclosed, non-controlling, conflict-reviewed, and governed by terms of reference.\
237.11.2 Advisory participation shall not create Board authority, officer authority, committee authority, public authority authority, standards authority, certification authority, recognition authority, finance-readiness authority, procurement authority, or execution authority.\
237.11.3 Advisory outputs shall be labeled and shall not be represented as independent validation where conflicts, sponsorship, provider interest, or funder interest exist.

#### 237.12 Controlled-Room Participation Where Authorized.

237.12.1 Controlled-room participation may be granted only through separate eligibility, confidentiality, access, data / AI / cyber, public authority, competition, safeguards, and conflict review.\
237.12.2 Sponsorship, donation, funding, host support, in-kind contribution, or public visibility shall not entitle any person to controlled-room participation.\
237.12.3 Controlled-room participants shall comply with no-download rules, access logs, use limits, non-retention, confidentiality, public claims restrictions, and correction obligations.

#### 237.13 No Benefit That Creates Control.

237.13.1 No benefit shall create control over governance, agenda, research, evidence, methods, publications, public-good software, technical baselines, public authority access, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, Nexus-facing outputs, safeguards, or correction.\
237.13.2 Any benefit that creates control shall be voidable, rejectable, narrowed, corrected, or escalated.

#### 237.14 No Benefit That Implies Endorsement.

237.14.1 No benefit shall imply that the Corporation endorses, recommends, validates, guarantees, certifies, recognizes, rates, finances, insures, procures, approves, or prefers a person, entity, product, service, technology, project, public authority position, investment, insurance product, financing structure, or commercial offering.\
237.14.2 Endorsement overclaims shall be corrected promptly.

#### 237.15 No Benefit That Implies Public Authority Approval.

237.15.1 No benefit shall imply public authority approval, official adoption, sovereign endorsement, regulatory approval, public finance approval, procurement approval, grant approval, public warning, emergency command, or public-private partnership.\
237.15.2 Public authority participants shall be identified by capacity where necessary and shall not be used in supporter materials to imply official status beyond the record.

#### 237.16 No Benefit That Implies Provider Preference, Certification, Recognition, Finance-Readiness, Procurement Advantage, Standards Outcome, or Public Authority Access Purchase.

237.16.1 No acknowledgment, logo placement, speaking role, training seat, preview window, advisory participation, controlled-room participation, report mention, technical contribution, repository contribution, or public-good supporter status shall imply provider preference, certification, accreditation, recognition, finance-readiness, procurement advantage, standards outcome, public authority access purchase, Docket approval, Grid guarantee, GRF action, GRA action, or Nexus-compatible status.

#### 237.17 Required Non-Endorsement Language.

237.17.1 Public acknowledgment materials shall include non-endorsement language where necessary to prevent misleading reliance.\
237.17.2 Non-endorsement language may state that acknowledgment of support does not constitute endorsement, certification, recognition, finance-readiness, procurement approval, public authority approval, investment advice, insurance approval, rating, legal compliance approval, or provider preference.\
237.17.3 The Corporation may require supporters to use approved language when referencing their support.

#### 237.18 Acknowledgment and Benefit Records.

237.18.1 The Corporation shall maintain Acknowledgment and Benefit Records identifying supporter, support type, value, benefit schedule, approval authority, acknowledgment text, logo placement, speaking opportunity, training seats, preview windows, advisory participation, controlled-room access if separately authorized, non-endorsement language, public authority limitations, finance-boundary limitations, certification-boundary limitations, procurement limitations, corrections, withdrawals, and closeout.

***

### Section 238. Procurement Controls

#### 238.1 Procurement Control Purpose.

238.1.1 Procurement controls shall ensure that the Corporation acquires goods, services, software, data, AI tools, cybersecurity services, cloud services, compute, equipment, facilities, professional services, consulting, research support, public-good technical support, and other resources lawfully, fairly, prudently, securely, and consistently with public-benefit purpose.\
238.1.2 Procurement shall preserve nonprofit integrity, fiscal discipline, value-for-money, conflicts discipline, related-party controls, provider neutrality, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, procurement neutrality, data / AI / cyber controls, accessibility, civil rights, safeguards, and records integrity.

#### 238.2 Procurement Policy Requirement.

238.2.1 The Board or authorized committee may adopt a procurement policy setting thresholds, approval requirements, competitive process requirements, sole-source rules, emergency procurement rules, vendor due diligence, contract review, conflict review, related-party review, and records requirements.\
238.2.2 Procurement policy shall not override this Bylaw, Board reserved matters, restricted-fund requirements, grant requirements, public authority requirements, sanctions, export-control, data / AI / cyber requirements, safeguards requirements, or applicable law.

#### 238.3 Fairness and Value-for-Money.

238.3.1 Procurement shall be conducted in a manner that is fair, reasonable, mission-aligned, value-conscious, and proportionate to risk, amount, urgency, specialization, and available market.\
238.3.2 Value-for-money may include price, quality, competence, security, privacy, accessibility, reliability, continuity, interoperability, open-source compatibility, sustainability, public-good alignment, safeguards capacity, and total cost of ownership.\
238.3.3 Lowest price shall not be required where another option better protects mission, security, continuity, data rights, public-good assets, safeguards, or long-term value.

#### 238.4 Public-Benefit Purpose Alignment.

238.4.1 Each material procurement shall support a lawful public-benefit purpose of the Corporation or a necessary operational, compliance, administrative, technical, governance, or continuity function.\
238.4.2 Procurement shall not be used to advance private benefit, sponsor preference, provider preference, staff convenience, public authority access purchase, finance-readiness overclaim, certification overclaim, recognition overclaim, procurement overclaim, or enterprise-stack execution.

#### 238.5 Budget Availability.

238.5.1 Procurement shall require budget availability, restricted-fund authority where applicable, grant authority where applicable, and approval under the Corporation’s signing and spending authority matrix.\
238.5.2 Budget availability alone shall not authorize procurement where separate review is required for conflicts, related parties, contracts, data / AI / cyber, IP, public authority matters, sanctions, export-control, accessibility, civil rights, safeguards, or Board reserved matters.

#### 238.6 Conflict Review.

238.6.1 Procurement shall be reviewed for conflicts of interest involving directors, officers, employees, contractors, fellows, advisors, volunteers, committee members, sponsors, donors, funders, providers, hosts, public authorities, capital actors, national companies, Project SPVs, and Related Parties.\
238.6.2 A conflicted person shall not control vendor selection, requirements, evaluation, negotiation, approval, payment, monitoring, renewal, or termination.

#### 238.7 Related-Party Review.

238.7.1 Related-party procurements shall require disclosure, recusal, independent review, fairness determination where applicable, public-benefit purpose finding, no-private-inurement finding, no-impermissible-private-benefit finding, anti-capture review, boundary-compliance review, and competent approval.\
238.7.2 Related-party procurement shall not proceed where fair process, reasonable value, independent judgment, or public trust cannot be preserved.

#### 238.8 Competitive Process Where Appropriate.

238.8.1 A competitive or comparative procurement process shall be used where appropriate based on amount, risk, availability of alternatives, grant requirements, public authority requirements, market conditions, and Board policy.\
238.8.2 Competitive process may include requests for proposals, requests for quotes, comparative bids, market scans, framework agreements, approved vendor lists, independent benchmarks, or documented alternative analysis.\
238.8.3 Competition shall be conducted without collusion, favoritism, bid steering, confidential information misuse, discriminatory exclusion, or provider preference.

#### 238.9 Sole-Source Justification Where Appropriate.

238.9.1 Sole-source, noncompetitive, emergency, or specialized procurement may be permitted where justified by record.\
238.9.2 Sole-source justification may include unique expertise, continuity, compatibility, security, urgency, grant requirement, public authority requirement, proprietary necessity, safeguards need, technical integration, limited market, or reasonable absence of alternatives.\
238.9.3 Sole-source justification shall not be used to conceal conflicts, related-party favoritism, sponsor pressure, provider preference, procurement steering, or convenience.

#### 238.10 Vendor Due Diligence.

238.10.1 Vendor due diligence shall be proportionate to risk and may include review of legal status, ownership, beneficial control, qualifications, experience, references, financial stability, integrity, conflicts, sanctions, export-control, anti-corruption, insurance, data / AI / cyber capacity, accessibility, civil rights, safeguards, and public claims history.\
238.10.2 Vendors presenting heightened legal, technical, public authority, data, AI, cyber, sanctions, export-control, protected knowledge, or reputational risk shall be escalated.

#### 238.11 Security and Privacy Review.

238.11.1 Procurement involving systems, software, platforms, repositories, collaboration tools, cloud services, data processing, AI tools, cybersecurity services, identity systems, payment systems, dashboards, maps, or technical infrastructure shall require security and privacy review proportionate to risk.\
238.11.2 Security and privacy review shall address access controls, encryption, logging, incident response, vulnerability management, data retention, deletion, backup, sub-processors, cross-border transfer, public authority data, protected knowledge, and contract controls.

#### 238.12 Data Processor Review.

238.12.1 Data processors shall be reviewed for lawful basis, processing purpose, data categories, sub-processors, data location, cross-border transfer, security controls, retention, deletion, audit rights, breach notice, confidentiality, public authority data restrictions, protected knowledge restrictions, and AI-use limitations.\
238.12.2 Data processor contracts shall prohibit unauthorized use, sale, disclosure, model training, profiling, secondary use, and onward transfer outside approved terms.

#### 238.13 AI Provider Review.

238.13.1 AI providers shall be reviewed for training terms, no-training options, model-improvement terms, prompt retention, inference logging, embeddings, retrieval, data leakage, explainability, human review, bias, model drift, security, public authority data, protected knowledge, export-control, and correctionability.\
238.13.2 AI tools shall not be procured or used where their terms or architecture defeat confidentiality, privilege, privacy, public authority restrictions, protected knowledge, no-training obligations, or secure handling requirements.

#### 238.14 Cloud Provider Review.

238.14.1 Cloud providers shall be reviewed for data residency, sovereign data zones, cross-border transfers, encryption, access controls, identity, logging, backup, disaster recovery, portability, uptime, incident response, sub-processors, support access, and exit rights.\
238.14.2 Cloud procurement shall not create lock-in, uncontrolled replication, public authority data exposure, protected knowledge exposure, or dependency inconsistent with continuity and public-benefit purpose.

#### 238.15 Cybersecurity Provider Review.

238.15.1 Cybersecurity providers shall be reviewed for competence, independence, access scope, confidentiality, privilege handling, incident-response capacity, forensic discipline, key management, logging access, export-control sensitivity, sanctions risk, and conflicts.\
238.15.2 Cybersecurity providers shall not control incident classification, Board notice, legal escalation, public authority notice, public statements, evidence correction, or protected knowledge handling except under express recorded authority.

#### 238.16 Repository Provider Review.

238.16.1 Repository providers shall be reviewed for access controls, branch protection, audit logs, exportability, backup, signing, provenance, issue tracking, dependency management, vulnerability reporting, contributor permissions, release controls, and archival continuity.\
238.16.2 Repository providers shall not acquire authority over public-good software, technical baselines, controlled vocabulary, proof receipts, official records, or Nexus-compatible meaning by technical custody.

#### 238.17 Export-Control, Sanctions, Controlled Technology, and National Security Sensitivity Review.

238.17.1 Procurement shall be screened where required or prudent for sanctions, restricted-party status, export-control, controlled technology, anti-terrorism, national security sensitivity, defense or dual-use concerns, prohibited end users, prohibited end uses, and restricted jurisdictions.\
238.17.2 Procurement involving AI, cybersecurity, encryption, telecom, AI-RAN, O-RAN, DePIN, DLT, blockchain, sensing, geospatial, digital twin, sovereign compute, high-performance compute, critical infrastructure, or controlled technical materials shall receive heightened review where appropriate.

#### 238.18 Public-Good Asset and IP Review.

238.18.1 Procurement involving software, data, IP, publications, technical baselines, schemas, APIs, SDKs, models, benchmarks, dashboards, methods, documentation, or public-good assets shall be reviewed for ownership, license rights, open-source compatibility, contributor rights, anti-enclosure, attribution, restrictions, sublicensing, warranties, indemnities, and termination.\
238.18.2 Procurement shall not grant vendors private control over public-good assets, technical baselines, controlled vocabulary, repositories, evidence records, public-safe reports, or correction pathways.

#### 238.19 Accessibility, Civil Rights, and Safeguards Review Where Applicable.

238.19.1 Procurement shall be reviewed for accessibility, civil rights, non-discrimination, language access, disability access, community safeguards, Tribal and Indigenous protocol respect, protected knowledge, public-safe mapping, and vulnerable-population risk where applicable.\
238.19.2 The Corporation shall not procure tools, facilities, platforms, services, or systems that create avoidable exclusion, discriminatory impact, inaccessible participation, protected knowledge exposure, retaliation risk, or public-safe publication defects where reasonable alternatives or mitigations exist.

#### 238.20 No Procurement by GCRI US as Public Authority Procurement.

238.20.1 Procurement by the Corporation is internal nonprofit procurement and shall not be represented as public authority procurement, public-sector award, public contract, government procurement, grant approval, public finance approval, official vendor selection, or sovereign decision.\
238.20.2 Public authorities participating in or funding Corporation activities shall not convert Corporation procurement into public authority procurement unless a separate lawful instrument expressly provides otherwise and all applicable public-sector rules are satisfied.

#### 238.21 No Contracting That Creates Provider Preference or Public Authority Confusion.

238.21.1 Contracts and procurement outcomes shall not create provider preference, preferred vendor status, certification, recognition, finance-readiness, procurement approval, public authority approval, standards outcome, Nexus-compatible status, or market recommendation.\
238.21.2 Vendors shall not use selection, contracting, participation, contribution, sponsorship, publication, or technical integration to make unsupported claims of endorsement, approval, certification, recognition, finance-readiness, or public authority adoption.\
238.21.3 Misleading vendor claims shall be corrected, restricted, subject to contract remedy, or publicly clarified where necessary.

#### 238.22 Procurement Records.

238.22.1 The Corporation shall maintain Procurement Records, including procurement policy, intake records, requisitions, budget authority, restricted-fund authority, specifications, competitive process records, proposals, quotes, evaluations, sole-source justifications, vendor due diligence, conflict reviews, related-party reviews, security reviews, privacy reviews, data processor reviews, AI provider reviews, cloud provider reviews, cybersecurity provider reviews, repository provider reviews, sanctions and export-control reviews, public-good asset and IP reviews, accessibility and safeguards reviews, approvals, contracts, purchase orders, invoices, delivery confirmations, payment records, renewals, terminations, vendor claims reviews, corrections, and closeout.

### Section 239. Contracting Controls

#### 239.1 Contracting Control Purpose.

239.1.1 Contracting controls shall ensure that every contract, agreement, memorandum, statement of work, purchase order, platform term, data instrument, technical instrument, public authority instrument, sponsorship instrument, grant instrument, in-kind support instrument, software instrument, license instrument, professional-services instrument, employment or contractor instrument, and other binding or potentially binding commitment entered into by or on behalf of the Corporation is lawful, authorized, mission-aligned, fiscally prudent, internally controlled, conflict-reviewed, records-supported, and consistent with the Corporation’s public-benefit purpose.\
239.1.2 Contracting controls shall preserve nonprofit integrity, tax-exempt or tax-exempt-compatible posture, non-distribution, no-private-inurement discipline, no-impermissible-private-benefit discipline, non-execution, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, recognition-boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, data / AI / cyber controls, community safeguards, protected knowledge duties, validity-by-record, and correctionability.\
239.1.3 No contract shall be used to create by implication what the Corporation is not authorized to perform directly, including public authority delegation, public warning, emergency command, procurement approval, finance-readiness, securities activity, investment advice, insurance activity, lending, underwriting, rating, public finance approval, certification, recognition, provider preference, legal compliance approval, professional advice, or enterprise execution.

#### 239.2 Written Contract Requirement Where Appropriate.

239.2.1 A written or reliably recorded contract shall be required where the matter involves material payment, continuing obligation, restricted funds, grants, sponsorships, in-kind support, public authority interface, data handling, AI use, cybersecurity access, IP rights, software release, repository access, public-good technical assets, facilities, employment, contracting, professional services, indemnity, insurance, confidentiality, public claims, cross-border activity, sanctions or export-control sensitivity, controlled technology, protected knowledge, or safeguards implications.\
239.2.2 Oral commitments, informal emails, chat messages, proposal acceptances, invoices, platform clicks, purchase orders, memoranda, letters of intent, meeting notes, AI-generated summaries, and public statements may create contract risk and shall be escalated where they purport to bind the Corporation.\
239.2.3 No person shall avoid written-contract discipline by splitting obligations, using informal channels, describing a commitment as preliminary, relying on relationship trust, or allowing performance to begin before authority and terms are recorded.

#### 239.3 Contract Authority.

239.3.1 Only persons with recorded authority under the Board-approved authority matrix, Board resolution, officer delegation, policy, or other competent record may negotiate, approve, sign, amend, renew, waive, terminate, or otherwise bind the Corporation.\
239.3.2 Contract authority shall be subject to budget authority, spending authority, restricted-fund authority, procurement controls, conflict controls, related-party controls, legal review where required, tax review where required, public authority review where required, finance-boundary review where required, certification-boundary review where required, data / AI / cyber review where required, IP review where required, safeguards review where required, sanctions review where required, export-control review where required, and Board reserved matters.\
239.3.3 Apparent authority shall not arise from title, seniority, founder status, technical centrality, authorship, repository access, controlled-room access, public authority contacts, sponsor relationship, provider relationship, donor relationship, host relationship, public visibility, or prior practice.\
239.3.4 Any purported contract entered into without authority may be refused, ratified only where lawful and appropriate, corrected, terminated, or treated as unauthorized.

#### 239.4 Contract Review.

239.4.1 Material contracts shall undergo contract review before signature, renewal, amendment, waiver, assignment, novation, settlement, release, or material performance.\
239.4.2 Contract review shall identify:\
239.4.2(a) the counterparty, beneficial owner or control person where relevant, and Related Party status;\
239.4.2(b) the purpose, scope, deliverables, term, renewal, termination, fees, payment schedule, and budget authority;\
239.4.2(c) the funding source, restricted-fund implications, grant implications, tax treatment, and accounting treatment;\
239.4.2(d) data, AI, cyber, privacy, IP, publication, public authority, finance-boundary, certification-boundary, procurement, safeguards, sanctions, export-control, controlled-technology, confidentiality, insurance, indemnity, liability, audit, and records implications; and\
239.4.2(e) required approvals, required clauses, risk conditions, and closeout requirements.\
239.4.3 Contract review shall be proportionate to risk, amount, public meaning, sensitivity, duration, role, technology, data class, public authority interface, and institutional consequence.

#### 239.5 Legal Review Where Required.

239.5.1 Legal review shall be required for contracts that are material, novel, high-risk, cross-border, public authority-facing, finance-adjacent, data-sensitive, AI-sensitive, cyber-sensitive, IP-sensitive, employment-related, tax-sensitive, insurance-related, indemnity-heavy, litigation-related, sanctions-sensitive, export-control-sensitive, controlled-technology-related, safeguards-sensitive, or otherwise likely to affect the Corporation’s legal rights, obligations, status, public claims, or regulated perimeter.\
239.5.2 Legal review shall be required where contract terms may create public authority delegation, procurement ambiguity, investment or finance ambiguity, certification ambiguity, recognition ambiguity, professional boundary risk, partnership, agency, joint venture, shared liability, fiduciary duty, guarantee, warranty, indemnity exposure, uncontrolled confidentiality waiver, or rights transfer.\
239.5.3 No operational urgency, funder deadline, sponsor expectation, provider preference, public authority request, event timing, technical dependency, or relationship pressure shall substitute for legal review where required.

#### 239.6 Financial Review.

239.6.1 Financial review shall be required for contracts involving payment obligations, revenue receipts, restricted funds, grants, sponsorships, donations, in-kind valuation, cost recovery, reimbursement, compensation, subscriptions, recurring fees, long-term commitments, termination costs, foreign currency, reserves, budget amendments, or material contingent liabilities.\
239.6.2 Financial review shall confirm budget authority, fund availability, spending authority, payment terms, value-for-money, accounting classification, tax treatment, restricted-fund treatment, invoicing requirements, revenue recognition, expense classification, and financial reporting implications.\
239.6.3 Financial review shall not be used to approve a contract that fails legal, public-benefit, conflict, related-party, public authority, finance-boundary, data / AI / cyber, IP, sanctions, export-control, or safeguards review.

#### 239.7 Tax Review Where Required.

239.7.1 Tax review shall be required where a contract may affect tax-exempt or tax-exempt-compatible status, unrelated business income, sponsorship classification, donation treatment, grant treatment, charitable solicitation where applicable, public support, private benefit, reasonable compensation, excess benefit, payroll tax, withholding, sales tax, use tax, cross-border tax, or indirect tax.\
239.7.2 Tax review shall assess whether the transaction is properly classified as grant, donation, sponsorship, exchange transaction, contract for services, membership or subscription fee, Academy or training fee, publication fee, cost recovery, in-kind contribution, license, reimbursement, compensation, award, stipend, scholarship, or other category.\
239.7.3 Any contract creating material tax uncertainty shall be held, narrowed, revised, escalated, or refused pending competent review.

#### 239.8 Data / AI / Cyber / Privacy Review.

239.8.1 Data / AI / cyber / privacy review shall be required for contracts involving personal information, public authority data, health-sensitive data, infrastructure-sensitive data, cyber-sensitive materials, community-protected data, Tribal or Indigenous data, protected knowledge, datasets, repositories, dashboards, AI systems, model providers, cloud providers, data processors, cybersecurity providers, identity systems, logging systems, APIs, SDKs, compute environments, or controlled rooms.\
239.8.2 Review shall assess lawful basis, permitted use, access controls, least privilege, confidentiality, privacy, security, encryption, retention, deletion, breach notice, incident response, sub-processors, cross-border transfers, sovereign data zones, AI training, fine-tuning, embeddings, prompt retention, inference logging, model-improvement terms, audit rights, and correction obligations.\
239.8.3 The Corporation shall not enter into contracts whose data, AI, cyber, or privacy terms defeat confidentiality, privilege, privacy, protected knowledge, public authority restrictions, no-training commitments, secure handling, sovereign data requirements, or correctionability.

#### 239.9 IP and Licensing Review.

239.9.1 IP and licensing review shall be required for contracts involving software, source code, documentation, datasets, schemas, APIs, SDKs, dashboards, methods, ontologies, controlled vocabulary, technical baselines, publications, research outputs, model cards, system cards, benchmark cards, proof receipts, marks, logos, names, domains, contributor rights, open-source components, patent rights, trade secrets, copyright, trademark, moral rights where applicable, sublicensing, or public-good technical assets.\
239.9.2 Review shall assess ownership, chain of title, license scope, assignment, work-for-hire treatment where applicable, contributor terms, open-source compatibility, attribution, royalty obligations, anti-enclosure protections, public-good access, restricted release, security-sensitive treatment, export-control treatment, and termination consequences.\
239.9.3 The Corporation shall not enter into IP terms that privately enclose public-good software, restrict open technical baselines contrary to mission, create provider control, create standards leverage, impair correction, or transfer public-good assets without competent review and authority.

#### 239.10 Public Authority Boundary Review.

239.10.1 Public authority boundary review shall be required for contracts involving federal, state, territorial, Tribal, local, District of Columbia, public infrastructure, public health, emergency management, public safety, public works, utility, port, water, energy, food, telecom, cyber, procurement, grant, regulatory, public finance, or other public authority actors.\
239.10.2 Review shall assess public authority capacity, public records, FOIA, state sunshine laws, open meetings, procurement rules, grant rules, lobbying rules, government ethics, gifts rules, public-sector confidentiality, public authority data restrictions, official-capacity limits, emergency-management implications, public warning implications, public finance implications, and non-execution.\
239.10.3 Public authority contracts shall state, where necessary, that the Corporation does not act as a public authority, regulator, procurement body, public finance approver, emergency command body, public warning authority, or sovereign decision-maker.

#### 239.11 Finance, Securities, Insurance, Lending, Rating, Public Finance, Procurement, Certification, Recognition, and Professional Boundary Review.

239.11.1 Finance, securities, insurance, lending, rating, public finance, procurement, certification, recognition, and professional boundary review shall be required where a contract may be interpreted as involving regulated finance, securities offering, investment advice, broker-dealer activity, finder activity, underwriting, insurance, lending, banking, rating, guarantee, public finance approval, procurement approval, certification, accreditation, recognition, maturity standing, legal compliance approval, professional advice, or execution instruction.\
239.11.2 Contracts shall not grant or imply finance-readiness, capital-readability, insurance-readiness, bankability, investability, creditworthiness, underwriting approval, rating, public finance approval, procurement qualification, certification, recognition, Docket approval, Grid guarantee, GRF action, GRA action, Nexus-compatible status, or professional reliance unless separately and lawfully authorized by competent body and clearly outside GCRI US’s prohibited functions.\
239.11.3 Where boundary risk cannot be resolved, the contract shall be re-scoped, externally routed, held, refused, or terminated.

#### 239.12 Community Safeguards, Civil Rights, Accessibility, Tribal / Indigenous, and Protected Knowledge Review.

239.12.1 Safeguards review shall be required for contracts affecting communities, civil rights, accessibility, Tribal or Indigenous governance, Indigenous data, protected knowledge, local or territorial knowledge, community-protected data, public-safe mapping, vulnerable populations, grievance pathways, consent, non-consent, withdrawal, non-retaliation, or remedy.\
239.12.2 Contracts shall not require protected knowledge disclosure, community access purchase, public-safe mapping without safeguards, inaccessible participation, discriminatory exclusion, retaliation risk, or publication of sensitive information without competent review.\
239.12.3 Where safeguards risk is material, the Corporation may require controlled-room handling, redaction, aggregation, public-safe limitation language, community or Tribal review where appropriate, non-attribution, withdrawal rights, correction rights, or refusal.

#### 239.13 Sanctions, Export-Control, Controlled Technology, and National Security Sensitivity Review.

239.13.1 Sanctions, export-control, controlled technology, and national security sensitivity review shall be required for contracts involving restricted jurisdictions, restricted parties, foreign persons where relevant, controlled technology, dual-use technology, AI, cybersecurity, encryption, telecom, AI-RAN, O-RAN, DePIN, DLT, blockchain, sensing, geospatial, digital twins, sovereign compute, high-performance compute, critical infrastructure, defense or dual-use contexts, public authority data, or sensitive end uses.\
239.13.2 Review shall assess restricted-party screening, beneficial ownership, end user, end use, item classification, technology classification, deemed export risk, re-export risk, license requirements, prohibited jurisdictions, anti-terrorism rules, anti-corruption risk, and national security sensitivity.\
239.13.3 Where review identifies unresolved risk, the Corporation shall impose a hold, access restriction, payment freeze, technical quarantine, publication freeze, refusal, termination, or legal escalation.

#### 239.14 Required Contract Clauses.

239.14.1 Contracts shall include clauses appropriate to their purpose and risk, including:\
239.14.1(a) accurate legal name, authority, capacity, scope, deliverables, term, renewal, fees, payment terms, and budget reference;\
239.14.1(b) confidentiality, privacy, data protection, AI-use restrictions, cybersecurity, breach notice, incident response, and access-control clauses;\
239.14.1(c) IP ownership, licensing, attribution, open-source, contributor, publication, mark-use, and anti-enclosure clauses;\
239.14.1(d) non-execution, public authority boundary, finance boundary, certification boundary, recognition boundary, procurement neutrality, provider neutrality, sponsor non-control, and non-endorsement clauses;\
239.14.1(e) conflicts, related-party disclosure, anti-corruption, sanctions, export-control, competition, gifts, government ethics, and procurement integrity clauses where appropriate;\
239.14.1(f) records, audit, reporting, correction, suspension, termination, closeout, survival, and cooperation clauses; and\
239.14.1(g) limitation of liability, indemnity, insurance, dispute resolution, governing law, venue, compliance, and notice clauses where appropriate.

#### 239.15 No-Merger, No-Agency, No-Partnership, No-Joint-Venture, No-Shared-Liability, Non-Execution, Public Authority Non-Endorsement, Finance Boundary, Procurement Neutrality, No-Certification, Provider Neutrality, Sponsor Non-Control, Data Protection, AI-Use, Cybersecurity, Confidentiality, IP, Public-Safe Claims, Correctionability, Records, Audit, Termination, and Closeout Clauses Where Applicable.

239.15.1 Contracts shall include no-merger, no-agency, no-partnership, no-joint-venture, no-shared-liability, and no-authority clauses where necessary to preserve legal separateness from counterparties, GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus institutions, consortiums, national companies, Project SPVs, providers, sponsors, hosts, funders, public authorities, universities, laboratories, and enterprise actors.\
239.15.2 Contracts shall include non-execution and boundary clauses where necessary to state that the Corporation does not provide securities offerings, investment advice, broker-dealer activity, finder activity, underwriting, lending, insurance, rating, public finance approval, procurement approval, certification, recognition, legal compliance approval, public authority approval, public warning, emergency command, or enterprise execution.\
239.15.3 Contracts shall include data protection, AI-use, cybersecurity, confidentiality, IP, public-safe claims, correctionability, records, audit, termination, and closeout clauses proportionate to the contract’s risk and operational consequences.

#### 239.16 Contract Signature.

239.16.1 Contracts shall be signed only by an authorized signatory with current authority, after required reviews and approvals are completed.\
239.16.2 Signature may be wet ink, electronic, platform-based, or other lawful form approved by policy, provided authenticity, authority, final text, version, date, and retention are preserved.\
239.16.3 No contract shall be signed where material terms are incomplete, side letters are undisclosed, approvals are missing, conflicts are unresolved, restricted-fund authority is absent, or boundary risks remain unresolved.

#### 239.17 Contract Management.

239.17.1 The Corporation shall manage contracts throughout their lifecycle, including obligation tracking, payment tracking, deliverable review, renewal review, compliance monitoring, records retention, amendment control, incident reporting, and correction.\
239.17.2 Contract owners shall monitor performance, public claims, data handling, AI use, cybersecurity obligations, confidentiality, IP obligations, public authority limitations, finance-boundary limitations, certification-boundary limitations, safeguards obligations, audit rights, and termination triggers.\
239.17.3 Material breaches, performance failures, misleading claims, data incidents, cyber incidents, unauthorized public authority claims, finance overclaims, certification overclaims, procurement overclaims, or safeguards defects shall be escalated promptly.

#### 239.18 Contract Closeout.

239.18.1 Contract closeout shall verify completion, payment, deliverables, data return or deletion, access revocation, credential rotation, IP delivery, license survival, confidentiality survival, records retention, audit rights, equipment return, public claims correction, unresolved disputes, and continuing obligations.\
239.18.2 Closeout shall not eliminate continuing confidentiality, privacy, data, AI, cyber, IP, public authority, finance-boundary, certification-boundary, procurement-neutrality, safeguards, audit, tax, or records duties.\
239.18.3 Contracts shall not remain dormant, auto-renewing, or informally continued where they create unmanaged risk, unauthorized spending, provider dependency, public authority confusion, or data / AI / cyber exposure.

#### 239.19 Contract Records.

239.19.1 The Corporation shall maintain Contracting Control Records, including intake records, drafts, redlines, final agreements, statements of work, authority records, approval records, legal reviews, financial reviews, tax reviews, procurement records, conflict reviews, related-party reviews, data / AI / cyber reviews, IP reviews, public authority reviews, finance-boundary reviews, certification-boundary reviews, safeguards reviews, sanctions and export-control reviews, signature records, amendments, renewals, waivers, notices, breach records, invoices, payments, deliverables, audits, terminations, closeout records, corrections, and archive status.

***

### Section 240. Related-Party Financial Transactions

#### 240.1 Related-Party Financial Transaction Purpose.

240.1.1 Related-party financial transaction controls shall prevent private inurement, impermissible private benefit, excess benefit, insider advantage, hidden compensation, related-party favoritism, sponsor capture, provider preference, donor control, public authority confusion, procurement distortion, finance overclaim, certification overclaim, recognition overclaim, and misuse of the Corporation’s fiscal systems.\
240.1.2 A Related-Party Financial Transaction includes any payment, reimbursement, compensation, stipend, award, scholarship, grant, contract, purchase, sale, lease, license, loan, guarantee, support relationship, donation, sponsorship, in-kind contribution, fee, subscription, cost-recovery arrangement, shared-service arrangement, IP arrangement, data arrangement, technical arrangement, or other financial arrangement involving a Related Party or conferring benefit on a Related Party.

#### 240.2 Disclosure Requirement.

240.2.1 A Related-Party Financial Transaction shall not proceed unless the relationship, interest, benefit, transaction type, value, affected matter, decision authority, and relevant facts are disclosed before deliberation, recommendation, approval, signature, payment, performance, renewal, amendment, or public reliance.\
240.2.2 Disclosure shall be event-based and continuing. A Covered Person shall update the disclosure promptly if the facts change or if a prior disclosure becomes incomplete, stale, or misleading.\
240.2.3 Failure to disclose may require hold, recusal, access restriction, reconsideration, rescission, repayment, correction, suspension, removal, contract remedy, or legal review.

#### 240.3 Independent Review.

240.3.1 Related-party financial transactions shall receive independent review by persons who are disinterested, competent, and not subject to the influence of the interested person or Related Party.\
240.3.2 Independent review shall assess lawful authority, public-benefit purpose, necessity, value, fairness, conflicts, private benefit, tax implications, procurement implications, support-without-control, data / AI / cyber implications, IP implications, public authority implications, finance-boundary implications, certification-boundary implications, and safeguards implications.\
240.3.3 Independent review may require external counsel, tax advisor, accountant, auditor, valuation expert, technical reviewer, safeguards reviewer, or other external reviewer where internal independence or competence is insufficient.

#### 240.4 Disinterested Approval.

240.4.1 Approval of a Related-Party Financial Transaction shall be made only by disinterested directors, a disinterested committee, a disinterested authorized officer, or another disinterested competent authority permitted by law and governing instruments.\
240.4.2 Interested persons shall not approve, vote on, sign, process, supervise, negotiate, recommend, document, release payment for, or control review of the transaction except for limited factual input approved and recorded by disinterested authority.\
240.4.3 The approval record shall identify the approving authority, recusals, conflicts of reviewers, materials reviewed, findings made, conditions imposed, and monitoring requirements.

#### 240.5 Fairness Determination.

240.5.1 A fairness determination shall assess whether the transaction is fair to the Corporation, reasonable in scope, necessary or useful for public-benefit purposes, free from prohibited control, and not structured to transfer improper benefit.\
240.5.2 Fairness shall be assessed by substance, not form. A transaction may be unfair even if documented, budgeted, or priced within apparent market range where it creates capture, dependency, private benefit, public authority confusion, finance overclaim, certification overclaim, procurement distortion, or public trust harm.

#### 240.6 Reasonableness Determination.

240.6.1 A reasonableness determination shall assess the amount, timing, duration, scope, deliverables, alternatives, budget impact, restricted-fund compatibility, contract terms, compensation terms, payment terms, renewal terms, termination rights, and public-benefit justification.\
240.6.2 Reasonableness shall be reviewed in light of the Corporation’s nonprofit character, fiscal condition, mission need, public-good asset stewardship, and available alternatives.

#### 240.7 Comparability Review Where Appropriate.

240.7.1 Comparability review shall be required where appropriate for compensation, contractor fees, consulting fees, professional services, rent, licenses, IP transactions, data transactions, software arrangements, in-kind valuation, grants, awards, stipends, fellowships, and other benefit arrangements involving Related Parties.\
240.7.2 Comparability evidence may include market rates, nonprofit benchmarks, independent quotes, salary surveys, expert valuation, prior transactions, grant terms, published rates, public-sector benchmarks, technical-scarcity analysis, and documented alternatives.\
240.7.3 Absence of perfect comparability shall not prevent approval where a reasonable basis is recorded, but absence of reliable support shall require heightened review.

#### 240.8 Public-Benefit Purpose Finding.

240.8.1 A Related-Party Financial Transaction shall require a finding that the transaction advances a lawful public-benefit purpose of the Corporation or a necessary operational, governance, compliance, technical, safeguards, educational, research, evidence, public-good software, or public authority learning function.\
240.8.2 The finding shall identify the public-benefit purpose and shall not rely solely on convenience, relationship history, donor preference, sponsor pressure, provider familiarity, public authority request, or internal habit.

#### 240.9 No Private Inurement Finding.

240.9.1 Approval shall require a finding that the transaction does not cause net earnings, assets, opportunities, rights, institutional value, public-good technical assets, or fiscal benefit to inure improperly to insiders or private persons.\
240.9.2 Where private inurement risk exists and cannot be resolved, the transaction shall be refused, restructured, terminated, or escalated.

#### 240.10 No Impermissible Private Benefit Finding.

240.10.1 Approval shall require a finding that any private benefit is incidental, lawful, reasonable, proportionate, mission-aligned, and not inconsistent with nonprofit character, tax posture, or public-benefit purpose.\
240.10.2 Benefit to a supporter, provider, donor, funder, host, public authority participant, capital actor, national company, Project SPV, enterprise actor, or Related Party shall not be permitted where it becomes a substantial non-public purpose of the transaction.

#### 240.11 Tax-Exempt Compatibility Finding.

240.11.1 Where applicable, approval shall require a finding that the transaction is compatible with the Corporation’s tax-exempt or tax-exempt-compatible posture, including reasonable compensation, excess benefit rules, unrelated business income, donor restrictions, private foundation rules where relevant, charitable solicitation, sponsorship treatment, and public support implications.\
240.11.2 Transactions with uncertain tax treatment shall be reviewed by competent tax advisor or held pending clarification.

#### 240.12 Conflict Mitigation.

240.12.1 Mitigation may include disclosure, recusal, access restriction, role restriction, independent review, comparability support, contract conditions, payment limits, public-safe disclosure, controlled disclosure, renewal review, monitoring, Board review, or transaction denial.\
240.12.2 Mitigation shall be proportionate to the transaction’s value, authority surface, public meaning, Related Party status, public authority implications, technical implications, data / AI / cyber implications, safeguards implications, and reputational risk.

#### 240.13 Recusal.

240.13.1 Interested persons shall recuse from deliberation, recommendation, approval, vote, signature, payment authorization, contract administration, monitoring, renewal, and closeout unless disinterested authority authorizes limited factual input under recorded restrictions.\
240.13.2 Recusal shall prevent back-channel influence, staff direction, agenda shaping, document editing, reviewer selection, AI-generated influence, public statement pressure, or indirect control.

#### 240.14 Access Restriction.

240.14.1 Access restriction shall be imposed where necessary to protect confidential materials, financial records, personnel records, public authority materials, data, AI systems, cyber-sensitive materials, IP, protected knowledge, privileged materials, procurement records, or deliberative records.\
240.14.2 Access restriction may include document controls, room exclusion, repository permission limits, payment-system limits, accounting-system limits, clean-room handling, and logging.

#### 240.15 Monitoring.

240.15.1 Approved Related-Party Financial Transactions shall be monitored where ongoing, material, high-risk, compensation-related, contract-related, restricted-fund-related, public authority-related, data / AI / cyber-related, or safeguards-related.\
240.15.2 Monitoring shall review compliance with terms, payment limits, deliverables, conflict conditions, public-safe claims, data restrictions, IP restrictions, safeguards, renewal conditions, and continuing reasonableness.

#### 240.16 Reconsideration, Rescission, Return, Termination, or Correction Where Required.

240.16.1 Where a Related-Party Financial Transaction was approved on incomplete, false, stale, or misleading information, or where the transaction later becomes unfair, excessive, unlawful, noncompliant, improperly beneficial, or inconsistent with this Bylaw, the Corporation may reconsider, rescind, amend, suspend, terminate, require return of benefit, require repayment, issue correction, or refer the matter for legal or tax review.\
240.16.2 Corrective action shall be recorded and shall preserve records sufficient to support audit, tax compliance, public-safe correction, and recurrence prevention.

#### 240.17 Related-Party Financial Transaction Records.

240.17.1 The Corporation shall maintain Related-Party Financial Transaction Records identifying the Covered Person, Related Party, relationship type, transaction type, value, affected matter, disclosure, recusal, independent review, disinterested approval, fairness determination, reasonableness determination, comparability review, public-benefit purpose finding, no-private-inurement finding, no-impermissible-private-benefit finding, tax-exempt compatibility finding, mitigation, access restriction, monitoring, reconsideration, rescission, return, termination, correction, and closeout.

***

### Section 241. Compensation, Reimbursement, Stipends, Fellowships, Awards, Scholarships, and Benefits

#### 241.1 Compensation Principle.

241.1.1 Compensation, reimbursement, stipends, fellowships, awards, scholarships, honoraria, benefits, and expense payments shall be lawful, reasonable, mission-aligned, properly classified, fiscally prudent, tax-compliant, approved within authority, and supported by adequate records.\
241.1.2 No compensation or benefit shall create private inurement, excess benefit, impermissible private benefit, sponsor control, provider selection pressure, public authority access purchase, finance-readiness outcome, certification outcome, recognition outcome, procurement advantage, or regulated execution.

#### 241.2 Reasonableness Requirement.

241.2.1 Compensation and benefits shall be reasonable in relation to role, scope, time, responsibility, expertise, deliverables, market context, nonprofit context, budget, restricted-fund terms, and the Corporation’s fiscal condition.\
241.2.2 Reasonableness shall be assessed before approval, at renewal where appropriate, and when material changes occur.

#### 241.3 Board or Delegated Approval.

241.3.1 Compensation and benefit arrangements shall be approved by the Board, a Board committee, an authorized officer, or another competent authority under a Board-approved delegation and approval matrix.\
241.3.2 Approval shall be recorded and shall identify the role, amount or range, basis, funding source, term, classification, conditions, and reviewer authority.\
241.3.3 No person shall approve the person’s own compensation, reimbursement, stipend, award, scholarship, honorarium, benefit, or related payment.

#### 241.4 Independent Approval for Senior Roles.

241.4.1 Compensation for senior officers, key employees, highly compensated employees, executives, and other senior roles designated by policy shall require independent or disinterested approval.\
241.4.2 Independent approval shall consider comparability, reasonableness, public-benefit need, fiscal sustainability, tax treatment, conflicts, related-party status, and no-private-inurement discipline.\
241.4.3 Senior-role compensation records shall be sufficient to support Board oversight, tax compliance, audit or review, and public trust.

#### 241.5 Comparability Review Where Appropriate.

241.5.1 Comparability review shall be conducted where appropriate for senior compensation, officer compensation, specialized contractor fees, fellow stipends, professional services, awards, scholarships, and unusual benefit arrangements.\
241.5.2 Comparability may include nonprofit salary benchmarks, market surveys, independent quotes, professional-rate schedules, academic benchmarks, public-sector benchmarks, technical-scarcity analysis, scope comparisons, and grant terms.\
241.5.3 The Corporation may approve compensation without perfect comparability where the basis is reasonable, documented, conflict-reviewed, and consistent with public-benefit purpose.

#### 241.6 Employee Compensation.

241.6.1 Employee compensation shall comply with employment law, payroll tax, withholding, classification, wage and hour rules, benefits law, workplace rules, non-discrimination, accessibility, and applicable policies.\
241.6.2 Employee compensation shall be set by authorized persons using role descriptions, budget authority, reasonableness review, and conflict controls.\
241.6.3 Employment compensation shall not be disguised as reimbursement, stipend, scholarship, contractor payment, grant, award, or in-kind benefit.

#### 241.7 Officer Compensation.

241.7.1 Officer compensation shall be approved in accordance with law, the Articles or Certificate, this Bylaw, Board policy, tax requirements, conflicts policy, and any applicable independent review process.\
241.7.2 Officers shall not participate in approving their own compensation or compensation payable to Related Parties.\
241.7.3 Officer compensation shall not be tied to fundraising success in a manner that creates private benefit, mission drift, public authority access sale, support-for-control, or regulated activity risk.

#### 241.8 Contractor Compensation.

241.8.1 Contractor compensation shall be governed by written or recorded contract, scope of work, deliverables, payment terms, tax classification, insurance where required, IP terms, data / AI / cyber terms where applicable, and conflict review.\
241.8.2 Contractor classification shall be reviewed for employment-law, tax, worker-classification, benefits, and control implications.\
241.8.3 Contractor compensation shall not be used to avoid employee protections, payroll obligations, procurement controls, related-party review, or compensation reasonableness.

#### 241.9 Fellow Stipends.

241.9.1 Fellow stipends may be paid where lawful, mission-aligned, budget-authorized, tax-reviewed where required, and governed by fellowship terms.\
241.9.2 Fellowship terms shall identify purpose, eligibility, term, amount, duties if any, non-employment status where applicable, IP terms, publication terms, confidentiality, data / AI / cyber access, public claims limits, and safeguards obligations.\
241.9.3 Fellow stipends shall not purchase public authority access, research conclusions, publication outcomes, certification, recognition, finance-readiness, procurement advantage, or provider preference.

#### 241.10 Scholarships.

241.10.1 Scholarships may be awarded for Academy, training, research, public authority learning, workforce formation, community participation, safeguards participation, or other public-benefit purposes where lawful and approved.\
241.10.2 Scholarship criteria shall be documented, fair, non-discriminatory, accessible, mission-aligned, and consistent with donor or grant restrictions where applicable.\
241.10.3 Scholarships shall not create employment, certification, recognition, credential guarantee, procurement preference, public authority endorsement, finance-readiness, or provider qualification.

#### 241.11 Awards and Prizes.

241.11.1 Awards and prizes may be granted where lawful, mission-aligned, budget-authorized, criteria-based, and recorded.\
241.11.2 Award criteria shall be public-safe, fair, non-discriminatory, conflict-reviewed, and not structured to create private inurement, provider preference, certification, recognition, finance-readiness, procurement advantage, or public authority approval.\
241.11.3 Awards shall not constitute endorsement, warranty, certification, legal compliance approval, safety approval, or market recommendation unless expressly and lawfully authorized and accurately described.

#### 241.12 Volunteer Reimbursement.

241.12.1 Volunteers may be reimbursed for reasonable, necessary, approved, documented, mission-related expenses.\
241.12.2 Reimbursement shall not be used as disguised compensation, donor benefit, sponsor benefit, provider benefit, public authority access purchase, or private distribution.\
241.12.3 Volunteer reimbursement shall comply with policy, budget authority, tax treatment, and records requirements.

#### 241.13 Advisor Honoraria Where Approved.

241.13.1 Advisor honoraria may be paid where lawful, reasonable, mission-aligned, budget-authorized, conflict-reviewed, tax-reviewed where required, and approved by competent authority.\
241.13.2 Honoraria shall not be paid to influence governance decisions, public authority access, evidence conclusions, methods, publications, provider selection, sponsor treatment, certification, recognition, finance-readiness, procurement, or regulated activity.\
241.13.3 Honoraria involving public officials, public employees, public authority participants, procurement officials, grant officials, or regulator-listening participants shall require government ethics and public authority review where applicable.

#### 241.14 Benefits.

241.14.1 Benefits may include health, retirement, leave, professional development, equipment, remote work support, wellness, travel support, insurance, and other benefits approved by competent authority and lawful for the relevant role.\
241.14.2 Benefits shall be administered fairly, consistently, non-discriminatorily, tax-compliantly, and in accordance with employment, contractor, volunteer, fellowship, or advisory classification.\
241.14.3 Benefits shall not be used to reward improper influence, conceal compensation, create related-party benefit, or bypass approval controls.

#### 241.15 Expense Reimbursement.

241.15.1 Expense reimbursement shall require documented business purpose, receipt or substantiation where required, policy compliance, budget authority, approval by a person other than the claimant where feasible, and timely submission.\
241.15.2 Reimbursable expenses may include approved travel, lodging, meals, event costs, software, supplies, communications, accessibility supports, public authority learning costs, research costs, and other mission-related expenses.\
241.15.3 Non-reimbursable expenses include personal expenses, excessive costs, unauthorized upgrades, unsupported charges, duplicate claims, gifts outside policy, lobbying or political expenses where prohibited, and expenses inconsistent with restricted funds or this Bylaw.

#### 241.16 Travel and Event Expenses.

241.16.1 Travel and event expenses shall be reasonable, mission-aligned, policy-compliant, budget-authorized, and recorded.\
241.16.2 Travel involving public authorities, sponsors, providers, funders, donors, hosts, capital actors, cross-border activity, Tribal or Indigenous interfaces, community safeguards, protected knowledge, controlled rooms, or sensitive sites shall be reviewed for conflicts, public authority rules, gifts, security, privacy, accessibility, safety, sanctions, export-control, and public claims.\
241.16.3 Sponsored travel shall not be accepted or reimbursed where it creates improper influence, access purchase, provider preference, sponsor control, public authority confusion, finance overclaim, certification overclaim, recognition overclaim, procurement advantage, or safeguards risk.

#### 241.17 Payroll, Tax, Withholding, and Reporting Compliance.

241.17.1 Payroll, compensation, stipends, awards, scholarships, reimbursements, honoraria, contractor payments, and benefits shall be administered in compliance with applicable payroll, tax, withholding, reporting, employment, contractor, benefits, and information-return requirements.\
241.17.2 The Corporation shall maintain systems and records sufficient to support classification, payment, withholding, reporting, and auditability.\
241.17.3 Misclassification, underreporting, false reimbursement, concealed compensation, unsupported benefits, or improper tax treatment shall be corrected promptly.

#### 241.18 No Excess Benefit.

241.18.1 Compensation and benefits shall not constitute an excess benefit transaction or equivalent improper benefit under applicable law.\
241.18.2 Where excess benefit risk is identified, the Corporation shall hold, reduce, restructure, deny, recover, correct, or escalate the arrangement.

#### 241.19 No Private Inurement.

241.19.1 No compensation, reimbursement, stipend, fellowship, award, scholarship, honorarium, or benefit shall inure improperly to the benefit of any director, officer, insider, Related Party, donor, sponsor, provider, funder, host, capital actor, national company, Project SPV, enterprise actor, or private person.\
241.19.2 No payment shall be made because of insider status, support history, public authority proximity, provider relationship, donor relationship, sponsor relationship, or informal influence.

#### 241.20 Compensation Not Tied to Sponsor Control, Provider Selection, Public Authority Access, Finance-Readiness, Certification, Recognition, Procurement, or Regulated Execution.

241.20.1 Compensation and benefits shall not be tied to securing sponsor control, donor control, funder control, provider selection, public authority access, finance-readiness, certification, recognition, procurement advantage, capital activity, insurance activity, lending activity, rating activity, public finance approval, or regulated execution.\
241.20.2 Performance metrics may reward lawful fundraising, program delivery, research quality, public-good software maintenance, public authority learning, safeguards, compliance, and operational excellence only where metrics do not encourage boundary breaches, misleading claims, pay-to-play, or private benefit.

#### 241.21 Compensation, Reimbursement, Stipend, Award, Scholarship, and Benefit Records.

241.21.1 The Corporation shall maintain Compensation, Reimbursement, Stipend, Fellowship, Award, Scholarship, and Benefit Records, including role descriptions, approval records, comparability data, compensation determinations, stipend terms, scholarship criteria, award criteria, reimbursement claims, receipts, payroll records, tax records, withholding records, contractor records, benefit records, travel records, public authority gift reviews, conflict reviews, related-party reviews, corrections, repayments, and closeout.

***

### Section 242. Reserve Policy, Investment of Reserves, Cash Management, and Prohibition on Capital Execution

#### 242.1 Reserve Policy Purpose.

242.1.1 Reserve policy shall preserve the Corporation’s fiscal resilience, continuity, public-benefit mission, legal compliance, operational stability, public-good technical asset continuity, safeguards capacity, and ability to withstand funding volatility, cyber incidents, legal events, public-safe correction events, and institutional transitions.\
242.1.2 Reserve policy shall be conservative, prudent, mission-aligned, Board-overseen, records-supported, and non-executing.\
242.1.3 Reserves are internal institutional funds and shall not be represented as investment capital, guarantee funds, insurance reserves, lending reserves, public finance reserves, Project SPV reserves, procurement guarantees, performance guarantees, or enterprise execution capital.

#### 242.2 Operating Reserve.

242.2.1 The Corporation may maintain an Operating Reserve to support ordinary operating continuity, including payroll, contractors, rent, systems, insurance, legal compliance, accounting, governance, records, cybersecurity, publications, and essential administration.\
242.2.2 The Operating Reserve shall be used only under authority and conditions approved by the Board or policy.\
242.2.3 Use of the Operating Reserve shall not conceal structural deficits, unsupported spending, restricted-fund misuse, or fiscal mismanagement.

#### 242.3 Research Continuity Reserve.

242.3.1 The Corporation may maintain a Research Continuity Reserve to support continuity of evidence work, methods work, observability methods, ontology, technical truth, public-good R\&D, publications, peer review, and correction work during funding interruptions or transition periods.\
242.3.2 Research Continuity Reserve funds shall not be used to purchase research conclusions, sponsor outcomes, provider preference, recognition, finance-readiness, certification, or procurement advantage.

#### 242.4 Technology and Cybersecurity Reserve.

242.4.1 The Corporation may maintain a Technology and Cybersecurity Reserve to support secure systems, repositories, controlled rooms, cloud continuity, AI-use controls, cyber incident response, vulnerability remediation, identity systems, logging, backup, disaster recovery, and technical migration.\
242.4.2 Technology and Cybersecurity Reserve use shall be reviewed for security, privacy, data / AI / cyber controls, procurement, sanctions, export-control, IP, and provider-dependency risk where applicable.

#### 242.5 Legal and Risk Reserve.

242.5.1 The Corporation may maintain a Legal and Risk Reserve to support legal advice, regulatory-perimeter review, tax review, audit or review, investigations, public-safe corrections, insurance deductibles, employment matters, contract disputes, data incidents, cyber incidents, and other legal or risk matters.\
242.5.2 Legal and Risk Reserve use shall preserve privilege, confidentiality, Board oversight, records integrity, and non-retaliation.

#### 242.6 Public Authority Learning Reserve.

242.6.1 The Corporation may maintain a Public Authority Learning Reserve to support lawful public authority learning, technical literacy, public-safe evidence interpretation, observability literacy, data / AI / cyber literacy, and cross-jurisdictional learning continuity.\
242.6.2 Public Authority Learning Reserve use shall not create public authority delegation, procurement approval, regulatory approval, public finance approval, public warning authority, emergency command authority, or sovereign obligation.

#### 242.7 Safeguards and Protected Knowledge Reserve.

242.7.1 The Corporation may maintain a Safeguards and Protected Knowledge Reserve to support civil rights, accessibility, Tribal and Indigenous protocol respect, protected knowledge handling, public-safe mapping, grievance pathways, remedy design, redaction, controlled publication, and safeguards review.\
242.7.2 Use of such reserve shall prioritize do-no-harm, non-retaliation, privacy, protected participation, and correctionability.

#### 242.8 Public-Good Technical Asset Maintenance Reserve.

242.8.1 The Corporation may maintain a Public-Good Technical Asset Maintenance Reserve to support public-good software, open technical baselines, repositories, documentation, schemas, APIs, SDKs, dashboards, proof-receipt tools, model cards, system cards, benchmark cards, security patches, license compliance, and archival continuity.\
242.8.2 The reserve shall not be used to create exclusive provider advantage, private enclosure, proprietary lock-in, certification implication, procurement advantage, or standards control outside competent authority.

#### 242.9 Reserve Targets.

242.9.1 The Board may establish reserve targets expressed as months of operating expense, fixed dollar amounts, percentage of budget, risk-based categories, or other reasonable measures.\
242.9.2 Reserve targets shall consider funding volatility, restricted-fund exposure, donor concentration, sponsor concentration, public-good technical asset obligations, legal risk, cyber risk, insurance deductibles, staff continuity, and wind-down obligations.\
242.9.3 Failure to meet a reserve target shall not by itself invalidate operations, but material reserve shortfall shall be reported and addressed through sustainability planning.

#### 242.10 Reserve Use Authority.

242.10.1 Reserve use shall require authority under Board policy, Board resolution, budget amendment, or delegated approval.\
242.10.2 Reserve use shall identify the reserve category, purpose, amount, expected duration, replenishment approach, accounting treatment, and reporting requirements.\
242.10.3 Reserve use shall not bypass conflict review, procurement review, contract review, restricted-fund rules, sanctions review, export-control review, data / AI / cyber review, safeguards review, or legal review where applicable.

#### 242.11 Investment of Reserves Where Lawful.

242.11.1 Reserves may be invested only where lawful, prudent, mission-aligned, Board-authorized, tax-compatible, liquidity-aware, and consistent with nonprofit duties.\
242.11.2 Investment of reserves shall prioritize safety, liquidity, preservation of capital, diversification, and availability for mission needs.\
242.11.3 Investment of reserves shall not create regulated investment activity for third parties, capital execution, public finance activity, asset management for others, or speculative activity inconsistent with nonprofit duties.

#### 242.12 Prudent Investment of Institutional Funds.

242.12.1 Institutional funds may be invested under a Board-approved investment policy or other competent authority, subject to applicable law, donor restrictions, grant restrictions, liquidity requirements, risk tolerance, conflict controls, and mission alignment.\
242.12.2 Investment decisions shall be made for the Corporation’s internal treasury purposes and not as market advice, investment recommendation, investment product, fund strategy, or capital allocation service for others.\
242.12.3 Conflicts involving investment advisors, banks, custodians, donors, directors, officers, Related Parties, or capital actors shall be disclosed and managed.

#### 242.13 Liquidity, Safety, Diversification, and Mission Alignment.

242.13.1 Cash management and reserve investment shall preserve adequate liquidity for operations, restricted obligations, payroll, tax obligations, grant obligations, contract obligations, insurance obligations, public-good technical asset continuity, legal compliance, and emergency needs.\
242.13.2 Funds shall be held or invested with attention to safety, diversification, bank risk, account limits, custodial risk, counterparty risk, cyber risk, fraud risk, sanctions risk, and liquidity risk.\
242.13.3 Mission alignment may be considered, provided that mission alignment does not justify imprudent concentration, excessive risk, speculative exposure, private benefit, or violation of fiduciary duties.

#### 242.14 No Speculation Inconsistent With Nonprofit Duties.

242.14.1 The Corporation shall not speculate with reserves or institutional funds in a manner inconsistent with nonprofit duties, liquidity needs, restricted-fund obligations, donor trust, public-benefit purpose, or fiscal prudence.\
242.14.2 Prohibited speculative activity includes excessive leverage, high-risk trading, unsupported derivatives, illiquid commitments inconsistent with reserve needs, insider-driven investments, supporter-driven investment schemes, and investments creating public authority, finance, or reputational confusion.

#### 242.15 No Investment Adviser Activity for Third Parties.

242.15.1 The Corporation shall not provide investment advice, portfolio advice, asset allocation advice, investment suitability determinations, transaction recommendations, or investment-management services for third parties through reserve management or any treasury activity.\
242.15.2 No internal reserve practice, investment policy, treasury discussion, financial report, public-good support strategy, GRA-facing input, or Nexus-facing document shall be represented as investment advice.

#### 242.16 No Fund Management for Third Parties.

242.16.1 The Corporation shall not manage investment funds, pooled funds, project funds, donor-advised investment pools, capital vehicles, public finance pools, Project SPV funds, or enterprise funds for third parties.\
242.16.2 Treasury management is limited to the Corporation’s own funds and assets and shall not be extended into fiduciary management of capital for investors, sponsors, providers, national companies, Project SPVs, public authorities, or enterprise actors.

#### 242.17 No Custody or Control of Third-Party Capital.

242.17.1 The Corporation shall not take custody or control of third-party capital for investment, lending, insurance, underwriting, public finance, project finance, infrastructure execution, procurement execution, escrow, settlement, or enterprise delivery.\
242.17.2 Any proposal requiring custody, escrow, settlement, or control of third-party capital shall be stopped, held, referred, externalized, or terminated pending legal and regulated-perimeter review.

#### 242.18 No Capital Execution by Reserve Management.

242.18.1 Reserve management shall not be used to execute capital strategy, finance projects, guarantee projects, underwrite risks, fund Project SPVs, provide bridge financing, support securities offerings, provide public finance approvals, or create investment products.\
242.18.2 The Corporation may support finance-readiness-facing or capital-readability-facing work only within its bounded evidence, methods, observability, ontology, and public-good technical support role and without controlling capital execution.

#### 242.19 Reserve and Investment Records.

242.19.1 The Corporation shall maintain Reserve and Investment Records, including reserve policy, reserve targets, reserve balances, reserve uses, approvals, replenishment plans, investment policy, investment account records, cash management records, liquidity analyses, bank records, custodian records, conflict reviews, investment advisor reviews, Board reports, restricted-fund considerations, corrections, and closeout records.

***

### Section 243. Audit, Review Engagement, Compilation, Financial Review, Internal Controls Testing, and Tax Reporting

#### 243.1 Audit Purpose.

243.1.1 Audit, review engagement, compilation, financial review, internal controls testing, and tax reporting controls shall preserve fiscal integrity, Board oversight, legal compliance, tax compliance, donor and funder trust, restricted-fund discipline, public-safe transparency, internal controls, and institutional credibility.\
243.1.2 Assurance activity shall be scaled to the Corporation’s legal obligations, funding model, restricted funds, public authority interfaces, donor expectations, sponsor profile, operational complexity, risk level, and public trust needs.

#### 243.2 Audit Requirement Where Required by Law, Board, Members, Funders, Grantors, or Public Trust.

243.2.1 The Corporation shall obtain an audit where required by law, tax rules, state registration, charitable solicitation rules, grant terms, funder terms, member requirements where applicable, Board resolution, lender or insurer requirement where lawful, or public trust considerations.\
243.2.2 The Board may require an audit even where not legally mandated if the Corporation’s size, funding sources, restricted funds, public authority funding, donor concentration, sponsor concentration, related-party transactions, public claims, or risk profile warrants audit-level assurance.\
243.2.3 Audit requirement records shall identify the basis, period, auditor, scope, reporting date, and responsible authority.

#### 243.3 Review Engagement Where Appropriate.

243.3.1 The Corporation may obtain a review engagement where audit is not required but limited assurance is appropriate.\
243.3.2 Review engagement may be appropriate for Board oversight, funder reporting, public-safe financial summaries, restricted-fund confidence, donor trust, and internal maturity.\
243.3.3 A review engagement shall not be described as an audit and shall not overstate the assurance provided.

#### 243.4 Compilation Where Appropriate.

243.4.1 The Corporation may obtain a compilation where financial statement preparation support is appropriate and no assurance is required or represented.\
243.4.2 Compiled financial statements shall be labeled accurately and shall not be described as audited, reviewed, independently verified, or assurance-backed unless such assurance has actually been provided.\
243.4.3 Compilation does not replace internal controls, Board review, tax reporting, or restricted-fund oversight.

#### 243.5 Internal Financial Review.

243.5.1 The Corporation shall conduct internal financial review appropriate to its size and risk, including review of budget-to-actuals, restricted funds, grants, sponsorships, donations, in-kind contributions, accounts, reconciliations, payments, payroll, reimbursements, contracts, procurement, reserves, and financial statements.\
243.5.2 Internal financial review may be conducted by the Treasurer, Chief Financial Officer, Executive Director, Finance, Audit, Risk, and Internal Controls Committee, Board, or other competent authority.\
243.5.3 Internal financial review shall not be controlled by persons whose transactions, compensation, reimbursements, or related-party matters are under review.

#### 243.6 Auditor or Reviewer Selection.

243.6.1 Auditors, reviewers, accountants, tax preparers, and assurance providers shall be selected through a fair, competent, conflict-reviewed, and authority-approved process proportionate to the Corporation’s needs.\
243.6.2 Selection shall consider independence, qualifications, nonprofit experience, public-benefit experience, grant experience, restricted-fund experience, tax competence, cybersecurity and technology-sector awareness where relevant, cost, availability, and reputation.\
243.6.3 Related-party relationships with auditors, reviewers, accountants, or tax preparers shall be disclosed and reviewed before engagement.

#### 243.7 Auditor Independence.

243.7.1 Auditors and reviewers providing assurance shall be independent as required by applicable standards, law, grant terms, funder terms, and Board policy.\
243.7.2 Auditor independence review shall consider financial relationships, employment relationships, consulting relationships, family relationships, prior service, non-audit services, fee dependence, sponsor relationships, donor relationships, provider relationships, public authority relationships, and conflicts.\
243.7.3 Independence impairments shall be resolved by safeguards, role separation, engagement limitation, replacement, or refusal.

#### 243.8 Management Representations.

243.8.1 Management representations provided to auditors, reviewers, accountants, tax preparers, Board, funders, grantors, or public authorities shall be accurate, complete, not misleading, and supported by records.\
243.8.2 No officer, employee, contractor, or representative shall conceal liabilities, restricted-fund issues, related-party transactions, donor conditions, sponsorship benefits, in-kind contributions, control weaknesses, fraud, cyber incidents, data incidents, tax issues, or public claims issues from auditors, reviewers, accountants, tax preparers, or the Board.\
243.8.3 False or misleading management representations shall trigger investigation, correction, and possible enforcement.

#### 243.9 Board Review of Audit or Review Results.

243.9.1 The Board or competent committee shall review audit results, review engagement results, compilations where relevant, financial statements, management letters, internal control findings, tax filings where appropriate, and corrective action plans.\
243.9.2 The Board shall review material weaknesses, significant deficiencies, restricted-fund findings, related-party findings, fraud indicators, tax issues, late filings, financial sustainability concerns, management override concerns, and unresolved auditor recommendations.\
243.9.3 Board review shall be recorded in minutes or written consent.

#### 243.10 Corrective Action.

243.10.1 Audit, review, compilation, internal financial review, internal controls testing, or tax reporting findings shall be corrected through a recorded corrective action process.\
243.10.2 Corrective action may include accounting correction, restatement, policy amendment, control redesign, reimbursement, repayment, funder notice, donor notice, tax filing amendment, Board action, staff training, system change, segregation of duties, legal review, disciplinary action, contract remedy, public-safe clarification, or referral.\
243.10.3 Corrective actions shall identify responsible person, deadline, verification method, and closeout status.

#### 243.11 Internal Controls Testing.

243.11.1 The Corporation may conduct internal controls testing to assess authorization, segregation of duties, reconciliations, procurement controls, contract controls, payment controls, payroll controls, reimbursement controls, restricted-fund controls, grant controls, sponsorship controls, in-kind controls, tax controls, data / AI / cyber financial controls, and fraud controls.\
243.11.2 Internal controls testing may be periodic, risk-based, event-driven, grant-required, auditor-recommended, Board-directed, or incident-driven.\
243.11.3 Testing results shall be reported to competent authority and corrected where deficiencies are identified.

#### 243.12 Federal Tax Reporting.

243.12.1 The Corporation shall file required federal tax returns, information returns, exemption-related filings, payroll tax filings, withholding filings, and other federal tax reports accurately and timely.\
243.12.2 Federal tax reporting shall reflect correct revenue classification, expense classification, restricted funds, compensation, related-party transactions, unrelated business income, public support, donor acknowledgments, lobbying where applicable, and tax-exempt status where applicable.\
243.12.3 Late, inaccurate, incomplete, or materially misleading filings shall be corrected promptly.

#### 243.13 State Tax Reporting.

243.13.1 The Corporation shall file required state tax, franchise tax, annual fee, sales tax, payroll tax, withholding, exemption, registration, and information reports where applicable.\
243.13.2 State tax compliance shall be reviewed in connection with all-states-and-territories operations, employees, contractors, events, fundraising, charitable solicitation, sales, Academy programs, subscriptions, and public authority interfaces.

#### 243.14 Charitable Solicitation Reporting Where Applicable.

243.14.1 Where charitable solicitation registration or reporting applies, the Corporation shall register, renew, report, and disclose as required by applicable state, territorial, and local law.\
243.14.2 Fundraising materials shall accurately describe tax status, charitable status where applicable, non-charitable status where applicable, donor benefits, sponsorship benefits, and use of funds.\
243.14.3 No person shall solicit contributions in a jurisdiction where required registration, exemption, or legal review has not been completed unless permitted by law.

#### 243.15 Grant and Funder Reporting.

243.15.1 Grant and funder reporting shall be accurate, complete, timely, evidence-supported, budget-supported, and consistent with grant terms, fund restrictions, public-safe claims, data / AI / cyber obligations, safeguards, and correctionability.\
243.15.2 Grant and funder reports shall not overstate impact, public authority adoption, recognition, finance-readiness, certification, procurement advantage, provider neutrality, or execution outcomes.\
243.15.3 Errors or omissions shall be corrected through amended report, funder notice, Board notice, accounting correction, or legal review where appropriate.

#### 243.16 Public-Safe Financial Summary Where Approved.

243.16.1 The Corporation may publish public-safe financial summaries, annual financial summaries, donor summaries, sponsorship summaries, grant summaries, audited financial statements, reviewed financial statements, or other financial transparency materials where approved.\
243.16.2 Public-safe financial summaries shall respect privacy, confidentiality, donor restrictions, grant restrictions, public authority restrictions, protected knowledge, privilege, cybersecurity, tax limitations, and public claims discipline.\
243.16.3 Public financial summaries shall not imply endorsement of supporters, public authority approval, finance-readiness, certification, recognition, procurement approval, provider preference, or guaranteed impact.

#### 243.17 Audit, Review, Internal Controls, and Tax Reporting Records.

243.17.1 The Corporation shall maintain Audit, Review, Internal Controls, and Tax Reporting Records, including audit engagement letters, review engagement letters, compilation records, financial statements, management letters, auditor independence reviews, Board review records, internal financial review records, internal controls testing records, corrective action plans, federal tax filings, state tax filings, charitable solicitation filings, grant reports, funder reports, public-safe financial summaries, amendments, corrections, and closeout records.

***

### Section 244. Tax, Charitable Solicitation, UBIT, Sales Tax, Payroll Tax, and State Registration Controls

#### 244.1 Tax Compliance Purpose.

244.1.1 Tax, charitable solicitation, unrelated business income, sales tax, payroll tax, indirect tax, and state registration controls shall preserve legal compliance, nonprofit integrity, tax-exempt or tax-exempt-compatible status, donor trust, public trust, Board oversight, and fiscal discipline.\
244.1.2 Tax compliance shall be treated as a governance obligation and not merely as accounting administration.\
244.1.3 Tax classification, tax filings, registration, exemption status, and public representations shall be accurate, records-supported, timely, and correctionable.

#### 244.2 Federal Tax Filing.

244.2.1 The Corporation shall file all required federal tax returns, information returns, exemption applications, exemption updates, payroll returns, withholding returns, and other federal filings accurately and timely.\
244.2.2 Federal filings shall be prepared using accurate books, appropriate classification, competent review, and complete records.\
244.2.3 The Corporation shall correct federal filings where required or appropriate due to error, omission, misclassification, changed facts, or legal determination.

#### 244.3 IRS Determination or Status Records.

244.3.1 The Corporation shall maintain IRS determination records, exemption application records, tax classification records, employer identification records, correspondence, status notices, exemption revocation notices if any, reinstatement records if any, and public representation controls.\
244.3.2 The Corporation shall not represent itself as holding a federal tax-exempt status, charitable status, deductibility status, or special tax status unless the status is supported by competent record.\
244.3.3 If status is pending, uncertain, revoked, changed, or limited, public materials, fundraising materials, donor communications, sponsorship materials, contracts, and grant applications shall describe the status accurately.

#### 244.4 State Tax Filing.

244.4.1 The Corporation shall file required state tax reports, exemption filings, franchise tax reports, annual reports, sales tax filings, use tax filings, payroll tax filings, withholding filings, information returns, and other state filings where applicable.\
244.4.2 State filing obligations shall be assessed based on incorporation state, principal office, registered office, employees, contractors, revenue, fundraising, events, programs, Academy activities, sales, subscriptions, public authority interfaces, and operations.\
244.4.3 State filings shall be maintained in a state compliance calendar or equivalent record.

#### 244.5 Franchise Tax or Annual Fee Where Applicable.

244.5.1 Franchise tax, annual fee, annual report, registered agent, corporate status, and good-standing obligations shall be monitored and satisfied where applicable.\
244.5.2 Failure to maintain good standing shall be escalated promptly and corrected through filings, payments, reinstatement, legal review, Board notice, or public-safe correction where necessary.\
244.5.3 No person shall ignore state or territorial filing obligations on the assumption that the Corporation’s public-benefit purpose excuses compliance.

#### 244.6 Sales Tax, Use Tax, GST/HST Interface Where Applicable, and Other Indirect Tax Review.

244.6.1 Sales tax, use tax, gross receipts tax, VAT, GST/HST interface where applicable, and other indirect tax obligations shall be reviewed for subscriptions, Academy programs, training, publications, software, licensing, merchandise, event fees, cost recovery, benchmark access, repository access, public-good tool access, and cross-border transactions.\
244.6.2 The Corporation shall determine whether exemptions apply and shall maintain records supporting exemption, collection, remittance, or non-collection.\
244.6.3 Cross-border indirect tax issues shall be escalated where services, digital products, training, public authority programs, or subscriptions involve Canada, Mexico, the Caribbean, or other jurisdictions.

#### 244.7 Payroll Tax and Withholding.

244.7.1 The Corporation shall comply with payroll tax, withholding, unemployment, workers’ compensation, benefits reporting, employee classification, and wage reporting obligations where applicable.\
244.7.2 Payroll systems shall be accurate, secure, and reviewed for employee location, remote work, state tax nexus, local tax obligations, benefit treatment, and cross-border employment implications.\
244.7.3 Payroll errors shall be corrected promptly through payroll adjustment, tax amendment, employee notice where required, and record correction.

#### 244.8 Independent Contractor Reporting.

244.8.1 Independent contractor payments shall be reviewed for worker classification, tax reporting, information returns, withholding where applicable, backup withholding, cross-border reporting, and contract documentation.\
244.8.2 The Corporation shall not use contractor classification to evade employment law, payroll tax, benefits obligations, supervision controls, conflict review, procurement controls, or related-party controls.\
244.8.3 Contractor reporting records shall be maintained with contracts, invoices, payment records, tax forms, classification reviews, and corrections.

#### 244.9 Charitable Solicitation Registration Where Applicable.

244.9.1 The Corporation shall review charitable solicitation registration, exemption, renewal, disclosure, and reporting requirements before soliciting donations, grants, sponsorships, or public support in any state, territory, or jurisdiction where such requirements may apply.\
244.9.2 Solicitation materials shall contain required disclosures where applicable and shall accurately state tax status, charitable status, deductibility, use of funds, restrictions, sponsor benefits, donor benefits, and non-endorsement.\
244.9.3 Charitable solicitation compliance shall be maintained in a jurisdictional register or equivalent record.

#### 244.10 State Foreign Qualification Where Required.

244.10.1 The Corporation shall review whether foreign qualification, registration to do business, registered agent appointment, annual report filing, charitable solicitation registration, employment registration, tax registration, or other state or territorial registration is required based on operations, employees, contractors, events, offices, fundraising, programs, public authority interfaces, and revenue activity.\
244.10.2 No program, state interface, territorial interface, public authority interface, or fundraising campaign shall assume that the Corporation may operate in a jurisdiction without registration or exemption review.\
244.10.3 Foreign qualification and registration records shall be maintained and periodically reviewed.

#### 244.11 Unrelated Business Income Tax Review.

244.11.1 The Corporation shall review revenue activities for unrelated business income tax risk, including sponsorships, advertising, subscriptions, training fees, Academy fees, licensing, publications, benchmark access, repository access, consulting-like services, data services, software services, event revenue, and cost recovery.\
244.11.2 Activities generating unrelated business income risk shall be classified, tracked, reported, taxed where required, limited, restructured, or refused where inconsistent with tax-exempt or tax-exempt-compatible posture.\
244.11.3 UBIT review shall not be used to justify mission drift or private benefit merely because tax may be payable.

#### 244.12 Donation Receipt Review.

244.12.1 Donation receipts, acknowledgments, written substantiation, quid pro quo disclosures, tax-deductibility statements, and donor letters shall be accurate, timely, and records-supported.\
244.12.2 No receipt shall state or imply tax deductibility, charitable status, exemption status, or no-goods-and-services treatment unless supported by competent record and applicable law.\
244.12.3 Donor benefits shall be reviewed for valuation, disclosure, tax treatment, and private benefit.

#### 244.13 Sponsorship Revenue Tax Treatment.

244.13.1 Sponsorship revenue shall be reviewed for qualified sponsorship treatment, advertising treatment, unrelated business income, donor acknowledgment, benefit valuation, public acknowledgment language, and public claims risk.\
244.13.2 Sponsorship benefits shall not include substantial return benefit, promotional advertising, exclusivity, endorsement, provider preference, public authority access purchase, certification, recognition, finance-readiness, procurement advantage, or control unless lawfully structured and approved.\
244.13.3 Sponsorship records shall support tax classification and public-safe acknowledgment.

#### 244.14 Membership, Subscription, Training, Academy, Program, Publication, Benchmarking, Repository, and Cost-Recovery Fee Tax Treatment.

244.14.1 Membership, subscription, training, Academy, program, publication, benchmarking, repository, licensing, technical access, and cost-recovery fees shall be reviewed for tax classification, exchange-transaction treatment, unrelated business income risk, sales tax, public support, private benefit, and public claims.\
244.14.2 Fee structures shall not imply certification, recognition, finance-readiness, procurement advantage, public authority approval, provider qualification, or professional licensure.\
244.14.3 Fee waivers, scholarships, subsidized seats, and sponsored seats shall be reviewed for private benefit, accessibility, fairness, tax treatment, and influence aggregation.

#### 244.15 Cross-Border Tax Review.

244.15.1 Cross-border tax review shall be required where the Corporation receives or pays funds across borders, conducts activities outside the United States, coordinates with GCRI Canada, Mexico, Caribbean, Arctic, or other North America interfaces, engages foreign contractors, receives foreign grants, accepts foreign sponsorships, provides digital services abroad, or handles foreign tax withholding, VAT, GST/HST, transfer pricing, permanent establishment, or local registration risk.\
244.15.2 Cross-border tax review shall preserve United States legal-seat discipline, legal separateness from GCRI Canada and other entities, no shared treasury, no agency, no partnership, no joint venture, and no public authority confusion.

#### 244.16 Tax Calendar.

244.16.1 The Corporation shall maintain a tax and registration calendar identifying federal, state, territorial, local, charitable solicitation, payroll, sales tax, foreign qualification, annual report, grant, and other filing deadlines.\
244.16.2 The calendar shall identify responsible persons, preparers, reviewers, approval dates, filing dates, payment dates, extension dates, and confirmation records.\
244.16.3 Missed or threatened deadlines shall be escalated promptly.

#### 244.17 Tax and Registration Records.

244.17.1 The Corporation shall maintain Tax and Registration Records, including federal filings, state filings, territorial filings, local filings, IRS status records, state exemption records, sales tax records, payroll tax records, withholding records, contractor reporting records, charitable solicitation registrations, foreign qualifications, annual reports, franchise tax filings, UBIT reviews, donation receipt records, sponsorship tax reviews, fee tax reviews, cross-border tax reviews, tax calendar records, notices, amendments, corrections, and closeout.

***

### Section 245. Fraud Controls, Anti-Corruption, Bribery, Kickbacks, Gifts, Hospitality, and Financial Misconduct

#### 245.1 Fraud Control Purpose.

245.1.1 Fraud controls, anti-corruption controls, bribery controls, kickback controls, gifts and hospitality controls, and financial misconduct controls shall protect the Corporation’s assets, public-benefit purpose, nonprofit integrity, donor and funder trust, public authority trust, fiscal systems, procurement integrity, support-without-control discipline, provider neutrality, sponsor non-control, records integrity, and public-safe claims.\
245.1.2 Financial misconduct includes fraud, theft, embezzlement, bribery, kickbacks, facilitation payments where prohibited, false invoices, false receipts, duplicate reimbursement, expense abuse, payroll fraud, procurement manipulation, grant misuse, restricted-fund misuse, sponsorship misuse, donation misrepresentation, in-kind valuation manipulation, payment diversion, conflict concealment, related-party concealment, and false financial reporting.

#### 245.2 Fraud Prevention.

245.2.1 The Corporation shall maintain fraud prevention controls proportionate to its size, complexity, funding model, payment volume, restricted funds, public authority interfaces, digital systems, and risk profile.\
245.2.2 Fraud prevention controls may include segregation of duties, approval thresholds, vendor verification, payment verification, bank reconciliations, restricted-fund tracking, expense policies, corporate card controls, procurement controls, contract controls, payroll controls, conflict disclosures, gift registers, audit trails, access controls, training, and whistleblower protections.\
245.2.3 No person shall override fraud controls for convenience, urgency, relationship trust, sponsor pressure, provider pressure, public authority request, technical dependency, or fundraising opportunity.

#### 245.3 Fraud Detection.

245.3.1 The Corporation shall maintain fraud detection measures appropriate to its operations, including reconciliation review, variance review, exception reporting, duplicate payment checks, vendor change review, unusual transaction review, restricted-fund review, procurement sampling, expense sampling, payroll review, access-log review, and audit or internal control testing.\
245.3.2 Indicators of fraud or misconduct shall be escalated promptly and shall not be dismissed because the amount appears small, the person is senior, the supporter is important, or the transaction is mission-adjacent.

#### 245.4 Fraud Reporting.

245.4.1 The Corporation shall maintain reporting channels for suspected fraud, corruption, bribery, kickbacks, gifts violations, procurement integrity violations, expense abuse, payment diversion, restricted-fund misuse, financial misstatement, related-party concealment, and other financial misconduct.\
245.4.2 Reports may be made by directors, officers, employees, contractors, fellows, advisors, volunteers, donors, sponsors, funders, providers, public authority participants, community participants, or other affected persons.\
245.4.3 Good-faith reporting shall be protected from retaliation.

#### 245.5 Anti-Corruption.

245.5.1 The Corporation shall prohibit corrupt conduct, including offering, promising, giving, requesting, receiving, authorizing, or concealing anything of value to obtain improper advantage, influence decision-making, secure public authority action, steer procurement, affect grants, influence research, control publication, obtain provider preference, create finance-readiness claims, obtain certification, obtain recognition, or suppress correction.\
245.5.2 Anti-corruption controls apply to domestic and cross-border activity, public authority interfaces, sponsors, donors, funders, providers, vendors, contractors, hosts, universities, laboratories, capital actors, national companies, Project SPVs, and enterprise actors.\
245.5.3 The Corporation shall not permit public-good language, nonprofit status, educational programming, public authority learning, or Nexus alignment to be used as a channel for corrupt influence.

#### 245.6 Bribery Prohibition.

245.6.1 Bribery is prohibited. No person acting for or with the Corporation shall offer, promise, give, request, accept, authorize, reimburse, conceal, or facilitate any bribe.\
245.6.2 Bribery includes cash, gifts, hospitality, travel, employment opportunities, consulting opportunities, donations, sponsorships, grants, in-kind benefits, public authority access, speaking roles, training seats, preview windows, controlled-room access, technical access, favorable publication, provider preference, procurement advantage, certification implication, recognition implication, or finance-readiness implication offered or received for improper influence.\
245.6.3 Suspected bribery shall trigger immediate escalation, preservation of evidence, interim controls, and legal review.

#### 245.7 Kickback Prohibition.

245.7.1 Kickbacks are prohibited. No person shall request, receive, offer, pay, route, disguise, or facilitate any payment, benefit, rebate, commission, referral fee, success fee, discount, gift, employment opportunity, consulting opportunity, or other value in exchange for awarding, renewing, influencing, approving, or performing a contract, grant, sponsorship, procurement, payment, publication, access right, or institutional action.\
245.7.2 Kickback concerns shall trigger procurement review, contract review, payment hold, conflict review, related-party review, and enforcement action where appropriate.

#### 245.8 Facilitation Payment Prohibition Where Applicable.

245.8.1 Facilitation payments are prohibited where prohibited by law or policy and shall not be made to expedite, secure, or influence routine or discretionary action by public officials, public employees, public authorities, vendors, providers, funders, hosts, or counterparties.\
245.8.2 Any request for a facilitation payment shall be escalated to legal or compliance authority.\
245.8.3 Where personal safety is at immediate risk, emergency action may be taken as necessary, but the matter shall be reported and recorded promptly.

#### 245.9 Gifts and Hospitality Policy.

245.9.1 The Corporation shall maintain gifts and hospitality controls governing the offering, acceptance, disclosure, approval, refusal, return, donation, or reimbursement of gifts, meals, travel, lodging, entertainment, event access, honoraria, speaking fees, sponsored attendance, and other benefits.\
245.9.2 Gifts and hospitality shall be modest, lawful, mission-related, non-controlling, non-repeated in a manner creating dependency, and not connected to an affected decision unless approved under policy.\
245.9.3 Gifts and hospitality involving public officials, public employees, procurement officials, grant officials, regulator-listening participants, public finance actors, or emergency-management personnel shall be reviewed under applicable government ethics and public authority rules.

#### 245.10 Gift Register.

245.10.1 The Corporation shall maintain a Gift Register for gifts offered, received, declined, returned, donated, reimbursed, or approved where recording is required by policy, law, funder rule, public authority rule, or risk.\
245.10.2 Gift Register entries shall identify source, recipient, description, value, date, purpose, affected matter, approval authority, disposition, related-party status, public authority implications, procurement implications, finance-boundary implications, certification-boundary implications, and correction where applicable.

#### 245.11 Hospitality Register.

245.11.1 The Corporation shall maintain a Hospitality Register for meals, travel, lodging, event access, sponsored attendance, entertainment, receptions, speaking fees, honoraria, and hosted benefits where recording is required by policy, law, funder rule, public authority rule, or risk.\
245.11.2 Hospitality Register entries shall identify source, recipient, value, event, purpose, date, affected matter, approval authority, conflicts, public authority implications, procurement implications, sponsor or provider implications, disposition, and correction where applicable.

#### 245.12 Procurement Integrity.

245.12.1 Procurement integrity shall prohibit bid rigging, bid steering, favoritism, undisclosed conflicts, related-party concealment, confidential information misuse, vendor coercion, sponsor pressure, provider pressure, public authority pressure, kickbacks, gifts intended to influence, false scoring, manipulated requirements, artificial sole-source justification, and split procurements.\
245.12.2 Procurement integrity violations may require procurement cancellation, re-solicitation, vendor exclusion, contract termination, repayment, correction, investigation, legal referral, or public-safe clarification.

#### 245.13 Government Ethics Interface Where Public Authorities Are Involved.

245.13.1 Where public authorities, public officials, public employees, procurement officials, grant officials, public finance actors, regulators, emergency-management personnel, or public infrastructure operators are involved, the Corporation shall review government ethics, gifts, lobbying, procurement, grant, public records, conflicts, and official-capacity rules.\
245.13.2 The Corporation shall not offer or provide anything of value to influence public authority action, procurement, grants, regulation, public finance, public warning, emergency command, official adoption, or sovereign decision.\
245.13.3 Public authority gift or hospitality issues shall be recorded and escalated where required.

#### 245.14 Corporate Card Controls.

245.14.1 Corporate cards, debit cards, purchasing cards, payment cards, virtual cards, and platform payment methods shall be issued, used, reviewed, reconciled, suspended, and canceled under Board-approved or officer-approved controls.\
245.14.2 Card use shall be limited to authorized business expenses and shall require receipts, business purpose, timely reconciliation, approval, and policy compliance.\
245.14.3 Personal use, cash advances, unsupported charges, split transactions, prohibited gifts, prohibited political activity, excessive hospitality, unauthorized subscriptions, and restricted-fund misuse are prohibited.

#### 245.15 Expense Abuse Controls.

245.15.1 Expense abuse includes false claims, inflated claims, duplicate claims, personal expenses, unsupported claims, excessive costs, unauthorized upgrades, fabricated receipts, improper mileage, unapproved travel, prohibited gifts, disguised compensation, and restricted-fund misuse.\
245.15.2 Expense abuse may result in denial, repayment, reimbursement hold, access restriction, discipline, contract remedy, removal, legal referral, or correction.\
245.15.3 Expense approvals shall be performed by persons with authority and not by the claimant.

#### 245.16 Payment Diversion Controls.

245.16.1 The Corporation shall maintain payment diversion controls to prevent wire fraud, business email compromise, vendor impersonation, bank account substitution, invoice manipulation, payroll diversion, grant diversion, refund diversion, and donation-routing fraud.\
245.16.2 Payment diversion controls may include independent verification of bank changes, callback procedures, dual approval, vendor master controls, payment holds, domain checks, invoice matching, segregation of duties, account alerts, and post-payment review.\
245.16.3 Suspected payment diversion shall trigger immediate hold, bank notice, access review, credential rotation, cyber review, insurance notice where appropriate, legal review, and Board notice where material.

#### 245.17 Financial Misconduct Intake.

245.17.1 The Corporation shall maintain financial misconduct intake channels for suspected fraud, bribery, kickbacks, corruption, gifts violations, hospitality violations, procurement violations, expense abuse, payroll fraud, payment diversion, restricted-fund misuse, false reporting, related-party concealment, and public claims misuse.\
245.17.2 Intake records shall receive a case identifier, classification, triage, interim controls, reviewer assignment, conflict review, evidence preservation, and escalation path.\
245.17.3 Intake shall protect confidentiality, privilege, non-retaliation, reporter safety, employment obligations, public authority obligations, and investigation integrity.

#### 245.18 Investigation, Recovery, Correction, Disclosure, Insurance Claim, Legal Referral, Public Authority Referral, Funder Referral, or Law Enforcement Referral Where Required or Appropriate.

245.18.1 Financial misconduct may be investigated by the Board, a Board committee, authorized officers, counsel, compliance function, finance function, internal reviewer, external investigator, auditor, insurer, or other competent authority.\
245.18.2 Remedies may include:\
245.18.2(a) transaction hold, payment freeze, access restriction, card suspension, procurement hold, contract hold, or publication freeze;\
245.18.2(b) repayment, clawback, recovery, reimbursement denial, insurance claim, funder notice, donor notice, public authority notice, or tax correction;\
245.18.2(c) contract amendment, contract termination, vendor exclusion, procurement cancellation, or re-solicitation;\
245.18.2(d) employment discipline, contractor termination, officer action, director action where lawful, role restriction, or removal where permitted;\
245.18.2(e) accounting correction, financial statement correction, grant report correction, public-safe correction, or controlled correction; and\
245.18.2(f) legal referral, regulatory referral, public authority referral, funder referral, insurer referral, or law enforcement referral where required or appropriate.\
245.18.3 Investigation and remedy shall preserve evidence, confidentiality, privilege, non-retaliation, due process where applicable, public-safe communications, and correctionability.

#### 245.19 Fraud, Anti-Corruption, Gift, Hospitality, and Financial Misconduct Records.

245.19.1 The Corporation shall maintain Fraud, Anti-Corruption, Gift, Hospitality, and Financial Misconduct Records, including policies, training records, fraud controls, detection records, reports, intake records, case identifiers, investigation records, evidence records, interim measures, gift registers, hospitality registers, corporate card records, expense records, payment diversion records, procurement integrity records, government ethics reviews, findings, remedies, recoveries, insurance claims, legal referrals, public authority referrals, funder referrals, law enforcement referrals, corrections, closeout, and recurrence-prevention records.

### Section 246. Donor, Funder, Sponsor, Grantor, and Public-Good Support Reporting

#### 246.1 Reporting Purpose.

246.1.1 Donor, funder, sponsor, grantor, and public-good support reporting shall be conducted as a records-based accountability function that preserves fiscal integrity, public-benefit purpose, nonprofit discipline, support-without-control, restricted-fund compliance, public-safe transparency, evidence integrity, methods integrity, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, donor non-control, safeguards, and correctionability.

246.1.2 Reporting shall be accurate, complete in relation to the relevant reporting duty, timely, evidence-supported, financially supported, public-safe, legally compliant, and consistent with the Corporation’s role as a non-executing public-benefit technical institution.

246.1.3 No report to a donor, funder, sponsor, grantor, public authority, supporter, partner, capital reader, provider, or public-facing audience shall be used to imply that the Corporation has sold, granted, certified, recognized, financed, insured, procured, guaranteed, underwritten, rated, approved, endorsed, or executed any project, provider, technology, public authority action, national company, Project SPV, or enterprise-stack activity.

#### 246.2 Grantor Reporting.

246.2.1 Grantor reporting shall be prepared and submitted in accordance with the applicable grant agreement, restricted-fund terms, approved budget, reporting calendar, legal requirements, tax requirements, accounting records, and public-benefit purpose.

246.2.2 Grantor reports shall identify, as applicable, approved use of funds, expenditures, deliverables, milestones, variances, limitations, delays, corrective actions, restricted-fund status, public-safe outputs, data / AI / cyber issues, safeguards issues, publication status, and closeout status.

246.2.3 Grantor reports shall not conceal material noncompliance, misclassify spending, overstate deliverables, understate risks, imply public authority adoption, imply finance-readiness, imply certification, imply recognition, imply procurement advantage, or represent public-good technical work as enterprise execution.

#### 246.3 Donor Reporting.

246.3.1 Donor reporting may be provided to donors where lawful, appropriate, approved, and consistent with donor restrictions, charitable solicitation rules, tax treatment, privacy, confidentiality, public-safe claims discipline, and the Corporation’s support-without-control rule.

246.3.2 Donor reports may describe use of funds, program activity, public-good outputs, financial summaries, restricted-fund status, public-safe impact, governance maturity, safeguards activity, Academy activity, public authority learning activity, public-good software continuity, and operational needs where supported by records.

246.3.3 Donor reporting shall not create donor control, donor veto, donor approval rights, donor access rights, donor public authority privileges, donor publication control, donor recognition rights beyond approved acknowledgment, or donor authority over the Corporation’s agenda, evidence, methods, software, technical baselines, or correction.

#### 246.4 Funder Reporting.

246.4.1 Funder reporting shall comply with the applicable funding instrument, restricted-fund classification, accounting treatment, Board-approved reporting controls, and applicable law.

246.4.2 Funder reports shall distinguish facts, outputs, activities, expenditures, limitations, assumptions, uncertainties, and future plans. They shall not present aspirations, proposals, projections, learning outcomes, early evidence, AI-assisted summaries, or preliminary methods as final institutional determinations.

246.4.3 Funder reporting shall preserve research independence, evidence integrity, publication independence, public-safe limitation language, correction rights, data / AI / cyber restrictions, protected knowledge restrictions, and safeguards obligations.

#### 246.5 Sponsor Reporting.

246.5.1 Sponsor reporting shall be limited to approved sponsorship benefits, public-good support summaries, event or program reporting, acknowledgment verification, benefit delivery records, and public-safe activity summaries.

246.5.2 Sponsor reports shall not include confidential Board materials, controlled-room materials, public authority materials, protected knowledge, restricted datasets, unpublished evidence, privileged material, procurement-sensitive information, finance-sensitive material, or provider-sensitive materials unless separately authorized through the applicable access and confidentiality controls.

246.5.3 Sponsor reports shall not provide public authority access confirmation, procurement positioning, provider evaluation advantage, technical baseline control, publication control, recognition implication, finance-readiness implication, certification implication, or Nexus-compatible status.

#### 246.6 Restricted Fund Reporting.

246.6.1 Restricted fund reporting shall identify funds received, restrictions, budget lines, expenditures, remaining balances, release conditions, deliverables, reporting periods, variances, approved modifications, unspent amounts, carryforward treatment, return obligations, and closeout requirements.

246.6.2 Restricted fund reports shall be reconciled to the Corporation’s books and accounting records and shall not rely solely on narrative summaries or program memory.

246.6.3 Any restricted fund reporting error, misclassification, unauthorized use, unsupported cost allocation, or reporting omission shall be corrected through an amended report, funder notice, internal correction, accounting correction, Board notice, legal review, or other appropriate action.

#### 246.7 Use-of-Funds Reporting.

246.7.1 Use-of-funds reporting shall describe how support was used in relation to the applicable purpose, budget, restriction, program, public-good deliverable, or operational need.

246.7.2 Use-of-funds reporting shall distinguish direct program costs, shared costs, overhead, administrative costs, fundraising costs, legal and compliance costs, safeguards costs, public-good software costs, public authority learning costs, technical infrastructure costs, and reserves where material and appropriate.

246.7.3 Use-of-funds reporting shall not be used to recharacterize restricted support as unrestricted, unrestricted support as restricted, sponsorship as donation where inaccurate, donation as sponsorship where inaccurate, in-kind support as cash, or cost recovery as charitable contribution.

#### 246.8 Milestone Reporting.

246.8.1 Milestone reporting shall identify milestones achieved, partially achieved, delayed, revised, superseded, withdrawn, or no longer appropriate.

246.8.2 Milestone reporting shall include material limitations, dependencies, variance explanations, data limitations, AI limitations, public authority boundary limitations, safeguards limitations, technical constraints, and correction status where relevant.

246.8.3 Milestone completion shall not imply certification, recognition, finance-readiness, procurement approval, public authority adoption, or enterprise execution unless a separate competent authority has created such status by record.

#### 246.9 Deliverable Reporting.

246.9.1 Deliverable reporting shall identify deliverables produced, submitted, published, restricted, held, revised, corrected, withdrawn, or closed.

246.9.2 Deliverables shall be reported according to their actual status, including draft, internal, controlled, public-safe, final, superseded, corrected, withdrawn, archived, or restricted.

246.9.3 A deliverable shall not be represented as public-safe, independently verified, peer-reviewed, publicly adopted, technically validated, finance-ready, certified, recognized, procurement-ready, or Nexus-compatible unless the supporting record authorizes that description.

#### 246.10 Impact Reporting With Evidence and Limitation Controls.

246.10.1 Impact reporting shall be evidence-supported, public-safe, method-aware, and limitation-controlled. It shall distinguish outputs, outcomes, influence, learning, capacity, adoption, use, reliance, contribution, attribution, and projected impact.

246.10.2 Impact reporting shall not overclaim causation, public authority adoption, community benefit, risk reduction, technological maturity, financial readiness, procurement readiness, recognition, certification, or execution.

246.10.3 Where impact claims are uncertain, preliminary, model-assisted, qualitative, geographically limited, community-sensitive, data-limited, sponsor-supported, or dependent on third-party action, the report shall include limitation language sufficient to prevent misleading reliance.

#### 246.11 Public-Safe Scoreboards Where Approved.

246.11.1 The Corporation may use public-safe scoreboards where approved by competent authority and where the scoreboard is evidence-supported, limitation-controlled, non-misleading, non-certifying, non-recognizing unless authorized by the competent recognition body, non-finance-readiness, non-procurement, and consistent with public authority boundary discipline.

246.11.2 Public-safe scoreboards may describe activity status, reporting status, deliverable status, funding status, publication status, correction status, safeguards status, or operational maturity where supported by records.

246.11.3 Scoreboards shall not rank providers for procurement, approve projects for investment, certify technologies, recognize entities, rate financial quality, imply public authority approval, or expose protected knowledge.

#### 246.12 Annual Audit-Ready Donor Report Where Approved.

246.12.1 The Corporation may prepare an annual audit-ready donor report where approved by the Board or competent authority.

246.12.2 An annual audit-ready donor report may include financial summaries, support categories, use-of-funds summaries, restricted-fund summaries, public-good output summaries, public-safe impact summaries, sponsorship acknowledgments, donor recognition where lawful, grant summaries, and correction notes.

246.12.3 Audit-ready donor reporting shall be reconciled to accounting records, grant records, restricted fund records, sponsorship records, donation records, in-kind contribution records, and public-safe transparency controls.

#### 246.13 Public-Safe Financial Summaries Where Approved.

246.13.1 The Corporation may include public-safe financial summaries in donor, funder, sponsor, grantor, annual, or public-good support reports where approved and consistent with law, accounting records, privacy, confidentiality, restricted-fund terms, public authority restrictions, protected knowledge, cybersecurity, privilege, and public-safe claims discipline.

246.13.2 Public-safe financial summaries shall not disclose sensitive donor information, protected knowledge, public authority confidential information, personal information, cyber-sensitive information, privileged material, or restricted funder information unless lawful and authorized.

#### 246.14 No Report as Outcome Purchase Confirmation.

246.14.1 No report shall be drafted, delivered, framed, acknowledged, or used as confirmation that a supporter purchased or influenced an outcome.

246.14.2 Reports shall not state or imply that support purchased findings, evidence conclusions, methods, publication timing, technical baseline inclusion, public-good software roadmap priority, public authority access, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, public-safe score, public visibility, or correction outcome.

#### 246.15 No Report as Recognition, Finance-Readiness, Certification, Procurement, Provider Preference, or Public Authority Approval.

246.15.1 No donor, funder, sponsor, grantor, or public-good support report shall be used as recognition, maturity standing, registry status, finance-readiness, capital-readability, insurance-readiness, bankability, investability, creditworthiness, underwriting approval, rating, public finance approval, certification, accreditation, procurement eligibility, provider preference, public authority approval, public warning, emergency command, or public-private partnership.

246.15.2 Where a report may reasonably be misread for any such purpose, the Corporation shall include limitation language, restrict circulation, revise the report, issue correction, or refuse the reporting format.

#### 246.16 Redaction, Confidentiality, Public Authority, Data / AI / Cyber, Protected Knowledge, and Privilege Controls.

246.16.1 Reports shall be redacted, restricted, delayed, segmented, or issued through controlled annexes where necessary to protect confidentiality, privacy, privilege, public authority restrictions, data / AI / cyber controls, protected knowledge, personal information, health-sensitive information, infrastructure-sensitive information, cyber-sensitive information, community-protected data, Tribal or Indigenous data, or safeguards.

246.16.2 Redaction shall not distort meaning. Where material context is withheld, the report shall include limitation language sufficient to avoid misleading reliance.

246.16.3 No person shall upload confidential reporting materials, donor reports, grant reports, public authority materials, protected knowledge, or privileged materials into unapproved AI systems.

#### 246.17 Correction and Supersession of Donor Reports.

246.17.1 Donor, funder, sponsor, grantor, and support reports shall be corrected or superseded where they contain inaccurate, incomplete, misleading, stale, unauthorized, unsupported, or unsafe statements.

246.17.2 Correction may include amended report, correction notice, supersession note, funder notice, donor notice, sponsor notice, public-safe clarification, restricted annex correction, financial correction, accounting correction, grant correction, public authority clarification, or withdrawal.

246.17.3 Correction records shall preserve prior versions, correction rationale, approval authority, affected audience, and closeout status.

#### 246.18 Donor, Funder, Sponsor, Grantor, and Support Reporting Records.

246.18.1 The Corporation shall maintain Donor, Funder, Sponsor, Grantor, and Support Reporting Records, including reporting obligations, calendars, draft reports, final reports, financial reconciliations, use-of-funds schedules, milestone reports, deliverable reports, impact reports, scoreboards, public-safe financial summaries, audit-ready donor reports, redactions, controlled annexes, approvals, corrections, supersessions, withdrawals, delivery records, acknowledgments, and closeout records.

***

### Section 247. Public-Safe Financial Transparency

#### 247.1 Public-Safe Financial Transparency Purpose.

247.1.1 Public-safe financial transparency shall support public-benefit trust, fiscal accountability, donor and funder confidence, Board accountability, nonprofit integrity, and correctionability while protecting lawful confidentiality, privacy, cybersecurity, public authority restrictions, restricted-fund obligations, protected knowledge, privilege, and public-safe claims discipline.

247.1.2 Public-safe financial transparency shall be accurate, record-supported, limitation-controlled, and consistent with the Corporation’s non-executing role.

247.1.3 Public-safe financial transparency shall not convert the Corporation’s financial statements, funding summaries, donor reports, sponsorship summaries, grant summaries, audits, reviews, or public reports into finance-readiness determinations, credit opinions, investment materials, procurement eligibility statements, certification instruments, recognition instruments, public authority endorsements, or enterprise execution documents.

#### 247.2 Transparency Consistent With Public-Benefit Trust.

247.2.1 The Corporation may provide financial transparency through annual reports, audited financial statements where available, reviewed financial statements where available, compiled statements where clearly labeled, public-safe financial summaries, funding source summaries, donor recognition summaries, sponsorship summaries, grant summaries, restricted fund summaries, program summaries, and public-good support reports.

247.2.2 Transparency shall be designed to make the Corporation’s fiscal stewardship understandable without compromising legal compliance, donor or funder confidentiality, public authority trust, protected knowledge, privacy, cybersecurity, or institutional safety.

247.2.3 Public-facing financial materials shall distinguish audited, reviewed, compiled, management-prepared, unaudited, estimated, preliminary, projected, and narrative information.

#### 247.3 Transparency Subject to Law, Privacy, Confidentiality, Security, Public Authority, Grant, Donor, Sponsor, Protected Knowledge, and Privilege Limits.

247.3.1 Public-safe financial transparency is subject to applicable law, tax rules, charitable solicitation rules, privacy law, employment confidentiality, contract confidentiality, grant terms, donor restrictions, sponsorship terms, public authority restrictions, cybersecurity restrictions, protected knowledge restrictions, attorney-client privilege, work product protection, and Board-approved records controls.

247.3.2 The Corporation shall not publish sensitive donor information, personal information, employee compensation detail beyond required or approved disclosure, public authority confidential information, protected knowledge, security-sensitive information, bank information, account information, payment routing information, confidential contract terms, privileged material, or investigation-sensitive information unless lawful and authorized.

#### 247.4 Annual Financial Summary Where Approved.

247.4.1 The Corporation may publish an annual financial summary where approved by the Board or competent authority.

247.4.2 An annual financial summary may include revenue categories, expense categories, program categories, public-good support categories, restricted fund categories, reserve status, audit or review status, public-good deliverable summaries, and correction notes.

247.4.3 The annual financial summary shall be reconciled to accounting records and shall not misstate the Corporation’s financial condition, public-benefit activity, support dependencies, restricted fund status, or assurance level.

#### 247.5 Public-Safe Funding Source Summary Where Approved.

247.5.1 The Corporation may publish a public-safe funding source summary identifying categories of support, major funding categories, public-good support themes, sponsor categories, grant categories, donor categories, in-kind categories, and other support types.

247.5.2 Funding source summaries may aggregate or anonymize supporters where lawful and appropriate to preserve privacy, safety, confidentiality, donor restrictions, public authority sensitivity, protected knowledge, or security.

247.5.3 Funding source summaries shall not imply that supporters control the Corporation or that supporters are endorsed, approved, certified, recognized, finance-ready, procurement-ready, or publicly authorized by the Corporation.

#### 247.6 Public-Safe Grant and Program Summary Where Approved.

247.6.1 The Corporation may publish public-safe grant and program summaries describing grant-supported or fund-supported public-benefit activities, deliverables, timelines, restrictions, outputs, public-good relevance, and limitations.

247.6.2 Grant and program summaries shall respect funder restrictions, public authority limits, protected knowledge, data restrictions, AI-use restrictions, cyber sensitivity, publication controls, and safeguards.

247.6.3 Grant and program summaries shall not overstate adoption, impact, recognition, maturity, finance-readiness, certification, procurement approval, public authority endorsement, or execution outcomes.

#### 247.7 Sponsor Acknowledgment Summary Where Approved.

247.7.1 The Corporation may publish sponsor acknowledgment summaries where lawful, tax-compatible, public-safe, and approved.

247.7.2 Sponsor acknowledgment summaries shall include non-endorsement language where necessary and shall not describe sponsors as preferred, certified, recognized, procurement-ready, finance-ready, public authority-approved, or Nexus-compatible by reason of sponsorship.

247.7.3 Sponsor acknowledgment summaries may be corrected, withdrawn, redacted, or revised where sponsor status changes, support is returned, claims are misleading, or continuation would create public-trust risk.

#### 247.8 Donor Recognition Summary Where Approved and Lawful.

247.8.1 The Corporation may publish donor recognition summaries where lawful, approved, donor-consented where required, and consistent with privacy, safety, confidentiality, charitable solicitation rules, tax treatment, and donor restrictions.

247.8.2 Donor recognition may be categorical, named, anonymous, aggregated, or omitted depending on law, donor preference, safety, confidentiality, and public-benefit considerations.

247.8.3 Donor recognition shall not imply donor control, donor endorsement, donor approval of findings, donor access rights, donor public authority status, or donor authority over the Corporation.

#### 247.9 Restricted Fund Summary Where Public-Safe.

247.9.1 Restricted fund summaries may be published where public-safe and approved, including summaries of restricted purposes, expenditures, remaining balances, deliverables, closeout status, and limitations.

247.9.2 Restricted fund summaries shall not disclose confidential grant terms, sensitive program details, protected knowledge, public authority data, cyber-sensitive information, or personnel-sensitive information beyond lawful and approved scope.

#### 247.10 Audit or Review Summary Where Approved.

247.10.1 The Corporation may publish an audit or review summary where approved and where the summary accurately describes the type of assurance obtained.

247.10.2 Audit or review summaries shall not overstate the scope, opinion, procedures, limitations, or assurance provided.

247.10.3 Management-prepared summaries of audited or reviewed materials shall be accurate and shall not omit material findings necessary to prevent misleading reliance.

#### 247.11 No Public-Safe Financial Summary as Finance-Readiness, Creditworthiness, Investment Suitability, Rating, Public Finance Approval, Procurement Eligibility, or Public Authority Endorsement.

247.11.1 No public-safe financial summary, donor report, grant summary, sponsor summary, audit summary, review summary, annual report, public-good support report, reserve summary, or impact summary shall be used as finance-readiness, creditworthiness, investment suitability, rating, public finance approval, procurement eligibility, public authority endorsement, certification, recognition, maturity standing, provider preference, or enterprise execution signal.

247.11.2 Public-safe financial materials shall include limitation language where necessary to prevent use by investors, insurers, lenders, underwriters, banks, public finance actors, procurement actors, providers, sponsors, public authorities, national companies, Project SPVs, or enterprise actors as regulated or reserved determinations.

#### 247.12 Correction of Financial Public Materials.

247.12.1 Public financial materials shall be corrected where they are inaccurate, incomplete, misleading, stale, unauthorized, unsupported, unsafe, inconsistent with accounting records, inconsistent with audited or reviewed records, inconsistent with grant records, inconsistent with donor restrictions, or inconsistent with public-safe claims discipline.

247.12.2 Correction may include revised publication, correction notice, supersession note, takedown, restricted access, public-safe clarification, donor notice, sponsor notice, funder notice, public authority clarification, Board notice, or legal review.

#### 247.13 Public-Safe Financial Transparency Records.

247.13.1 The Corporation shall maintain Public-Safe Financial Transparency Records, including annual financial summaries, funding source summaries, grant summaries, program summaries, sponsor acknowledgment summaries, donor recognition summaries, restricted fund summaries, audit summaries, review summaries, approvals, redactions, public-safe reviews, legal reviews, confidentiality reviews, corrections, supersessions, withdrawals, and closeout records.

***

### Section 248. Financial Stop-the-Line, Payment Holds, Support Holds, Contract Holds, and Treasury Escalation

#### 248.1 Financial Stop-the-Line Purpose.

248.1.1 Financial stop-the-line authority shall protect the Corporation from unlawful expenditure, unauthorized commitments, fraud, payment diversion, restricted-fund misuse, private inurement, impermissible private benefit, support-with-control, public authority confusion, finance-boundary violation, certification-boundary violation, procurement distortion, provider preference, sponsor capture, data / AI / cyber compromise, protected knowledge exposure, and public-trust harm.

248.1.2 Financial stop-the-line authority may be exercised before payment, acceptance, contract signature, procurement award, publication, report delivery, access grant, reimbursement, reserve use, restricted-fund release, or other fiscal action.

248.1.3 A stop-the-line action shall be protective, record-supported, time-aware, and reviewed promptly by competent authority.

#### 248.2 Payment Hold Trigger.

248.2.1 A payment hold shall be triggered where a payment may be unauthorized, unsupported, duplicative, fraudulent, excessive, misclassified, restricted-fund-inconsistent, related-party-sensitive, conflict-affected, procurement-noncompliant, contract-noncompliant, tax-noncompliant, sanction-sensitive, export-control-sensitive, public authority-sensitive, data / AI / cyber-sensitive, or inconsistent with this Bylaw.

248.2.2 Payment holds may apply to vendor payments, contractor payments, employee reimbursements, stipends, awards, scholarships, honoraria, refunds, grant disbursements where applicable, subscription payments, software payments, cloud payments, AI tool payments, cyber payments, travel payments, and wire transfers.

#### 248.3 Support Acceptance Hold Trigger.

248.3.1 A support acceptance hold shall be imposed where a grant, donation, sponsorship, in-kind contribution, subscription, fee, cost-recovery payment, public authority support, technical support, host support, or other support may fail the Support Acceptance Test.

248.3.2 Support acceptance holds shall be required where support may create sponsor control, donor control, funder control, provider preference, public authority access purchase, finance-readiness implication, certification implication, recognition implication, procurement advantage, protected knowledge exposure, data misuse, AI misuse, cyber risk, sanctions risk, export-control risk, or enterprise execution.

#### 248.4 Contract Hold Trigger.

248.4.1 A contract hold shall be triggered where required reviews are incomplete, authority is unclear, material terms are missing, side letters are undisclosed, conflicts are unresolved, related-party issues exist, restricted-fund authority is absent, public authority boundaries are unclear, finance boundaries are unclear, certification boundaries are unclear, safeguards issues are unresolved, or data / AI / cyber terms are unsafe.

248.4.2 Contract performance shall not begin during a hold unless competent authority authorizes limited protective or emergency action by record.

#### 248.5 Procurement Hold Trigger.

248.5.1 A procurement hold shall be triggered where procurement integrity, conflicts, related-party status, fair process, vendor due diligence, sole-source justification, security review, privacy review, AI provider review, cloud review, cybersecurity review, export-control review, sanctions review, accessibility review, safeguards review, budget authority, or contract authority is incomplete or disputed.

248.5.2 Procurement holds may suspend solicitation, evaluation, award, contract signature, purchase order issuance, payment, renewal, or vendor access.

#### 248.6 Restricted Fund Hold Trigger.

248.6.1 A restricted fund hold shall be triggered where proposed spending, reporting, reclassification, modification, release, carryforward, closeout, or public statement may violate grant terms, donor restrictions, funder restrictions, accounting rules, tax rules, public authority requirements, or this Bylaw.

248.6.2 Restricted fund holds shall remain until competent review determines lawful use, modification, return, reclassification, correction, or refusal.

#### 248.7 Fraud or Payment Diversion Trigger.

248.7.1 Fraud or payment diversion indicators shall trigger immediate hold, including suspicious invoice, duplicate invoice, changed bank details, unusual payment routing, urgent payment pressure, domain mismatch, vendor impersonation, unsupported reimbursement, false receipt, payroll diversion, card misuse, grant diversion, refund diversion, or unusual access pattern.

248.7.2 The Corporation may freeze payments, revoke payment authority, notify the bank, preserve logs, rotate credentials, suspend accounts, notify insurers, initiate cyber review, and escalate to counsel or law enforcement where appropriate.

#### 248.8 Private Inurement or Private Benefit Trigger.

248.8.1 A hold shall be imposed where a transaction may create private inurement, excess benefit, impermissible private benefit, insider advantage, related-party benefit, disguised compensation, excessive reimbursement, improper award, improper scholarship, or public-good asset diversion.

248.8.2 The hold shall not be released until independent review, fairness review, tax review, or Board review has resolved the concern.

#### 248.9 Sanctions or Export-Control Trigger.

248.9.1 A hold shall be imposed where a transaction involves a restricted party, possible restricted party, restricted jurisdiction, prohibited end user, prohibited end use, controlled technology, export-controlled software, AI system, cybersecurity tool, encryption, telecom system, AI-RAN / O-RAN material, DePIN or DLT material, geospatial system, digital twin system, sovereign compute, high-performance compute, or national security-sensitive material.

248.9.2 Payment, access, publication, shipment, contract execution, repository access, and controlled-room participation shall remain held until sanctions and export-control review is complete.

#### 248.10 Public Authority Boundary Trigger.

248.10.1 A hold shall be imposed where a transaction, report, contract, support arrangement, public statement, payment, public authority room, learning session, or public-facing output may imply public authority endorsement, official adoption, procurement approval, grant approval, regulatory approval, public finance approval, public warning, emergency command, sovereign obligation, or public-private partnership.

248.10.2 Public authority boundary holds shall be reviewed for capacity classification, ethics rules, public records rules, procurement rules, grant rules, government ethics, public authority data restrictions, and public-safe limitation language.

#### 248.11 Finance, Securities, Insurance, Lending, Rating, Public Finance, Procurement, Certification, Recognition, Provider-Preference, or Public Warning Boundary Trigger.

248.11.1 A hold shall be imposed where a fiscal action, contract, report, technical output, public-safe publication, public authority material, donor material, sponsor material, or Nexus-facing communication may be read as securities activity, investment advice, broker-dealer activity, finder activity, lending, insurance, underwriting, rating, public finance approval, procurement approval, certification, accreditation, recognition, maturity standing, provider preference, public warning, emergency command, professional advice, or regulated execution.

248.11.2 Boundary-triggered holds shall be released only after limitation language, re-scoping, withdrawal, referral, legal review, or competent authority action resolves the risk.

#### 248.12 Sponsor, Donor, Funder, Provider, Host, or Capture Trigger.

248.12.1 A hold shall be imposed where support, procurement, contract, payment, publication, access, or reporting may create sponsor control, donor control, funder control, provider preference, host leverage, critical supplier dependency, public authority access purchase, outcome purchase, or institutional capture.

248.12.2 Capture-triggered holds may require concentration review, aggregation review, related-party review, sponsor non-control review, provider-neutrality review, ring-fencing, diversification, support return, or termination.

#### 248.13 Data / AI / Cyber / Privacy or Protected Knowledge Trigger.

248.13.1 A hold shall be imposed where a transaction or action may expose personal information, public authority data, health-sensitive data, infrastructure-sensitive data, cyber-sensitive materials, community-protected data, Tribal or Indigenous data, protected knowledge, credentials, keys, tokens, repositories, model prompts, inference logs, embeddings, or controlled-room materials.

248.13.2 The hold may apply to payment, contract signature, procurement, system access, publication, AI processing, data transfer, repository release, dashboard release, or report delivery.

#### 248.14 Emergency Escalation.

248.14.1 Emergency escalation shall occur where delay may cause financial loss, data breach, cyber compromise, protected knowledge exposure, public authority harm, public safety risk, legal violation, fraud loss, sanctions violation, restricted-fund misuse, or irreparable public-trust harm.

248.14.2 Emergency authority may permit immediate protective action, including payment freeze, bank notice, account lockdown, credential rotation, system isolation, contract suspension, publication suspension, controlled-room lockdown, data quarantine, or public-safe warning within the Corporation’s lawful non-public-authority role.

248.14.3 Emergency action shall be reported to competent authority as soon as practicable and recorded.

#### 248.15 Review, Release, Re-Scope, Refusal, Return, Termination, or Correction.

248.15.1 After review, a hold may be released, conditionally released, re-scoped, extended, escalated, refused, returned, terminated, corrected, or referred.

248.15.2 Conditions may include additional approvals, revised contract language, access restrictions, payment controls, public-safe limitation language, support return, restricted-fund correction, Board approval, legal opinion, tax review, sanctions clearance, export-control review, safeguards review, cyber remediation, or public / controlled correction.

#### 248.16 Financial Stop-the-Line and Hold Records.

248.16.1 The Corporation shall maintain Financial Stop-the-Line and Hold Records, including trigger, date, affected matter, affected payment, affected support, affected contract, affected procurement, affected fund, affected system, hold authority, interim measures, reviewers, review findings, release conditions, refusal, return, termination, correction, escalation, emergency action, and closeout.

***

### Section 249. Fiscal Records, Financial Registers, Retention, Access, Confidentiality, and Secure Disposal

#### 249.1 Fiscal Record Requirement.

249.1.1 The Corporation shall maintain complete, accurate, timely, secure, auditable, accessible to authorized persons, and correctionable fiscal records sufficient to support legal compliance, tax compliance, nonprofit compliance, Board oversight, donor and funder accountability, restricted-fund discipline, internal controls, public-safe transparency, audit or review, assurance, and institutional continuity.

249.1.2 Fiscal records shall be governed by records policy, retention schedules, access controls, confidentiality classifications, privilege protections, cybersecurity controls, public authority restrictions, donor restrictions, grant terms, privacy requirements, protected knowledge safeguards, legal holds, and secure disposal procedures.

#### 249.2 Budget Records.

249.2.1 Budget records shall include draft budgets, approved budgets, budget assumptions, amendments, budget-to-actual reports, variance reports, Board approvals, committee recommendations, reserve allocations, restricted-fund budgets, program budgets, and corrective actions.

#### 249.3 Account Records.

249.3.1 Account records shall include chart of accounts, ledger records, fund codes, accounting classes, journal entries, receivables, payables, revenue classifications, expense classifications, restricted-fund classifications, net asset classifications, and accounting corrections.

#### 249.4 Bank Records.

249.4.1 Bank records shall include account-opening documents, authorized signatories, online access records, bank statements, deposit records, payment records, wire records, ACH records, merchant account records, custody records where lawful, investment account records where lawful, account closure records, bank confirmations, and fraud notices.

#### 249.5 Reconciliation Records.

249.5.1 Reconciliation records shall include bank reconciliations, payment-platform reconciliations, credit-card reconciliations, merchant reconciliations, payroll reconciliations, grant reconciliations, restricted-fund reconciliations, investment reconciliations where applicable, outstanding item logs, discrepancy investigations, and correction records.

#### 249.6 Financial Statement Records.

249.6.1 Financial statement records shall include management-prepared statements, audited statements, reviewed statements, compiled statements, statement of financial position, statement of activities, statement of cash flows, statement of functional expenses, notes, schedules, management reports, and public-safe summaries.

#### 249.7 Audit or Review Records.

249.7.1 Audit or review records shall include engagement letters, auditor independence records, reviewer independence records, management representations, working-paper access records, audit reports, review reports, compilation reports, management letters, internal control findings, Board review records, and corrective action plans.

#### 249.8 Tax Records.

249.8.1 Tax records shall include federal filings, state filings, territorial filings, local filings, payroll filings, withholding records, sales tax records, use tax records, franchise tax records, annual fee records, IRS determination records, exemption records, UBIT reviews, donation receipt records, sponsorship tax reviews, fee tax reviews, cross-border tax reviews, tax calendar records, notices, amendments, and corrections.

#### 249.9 Grant Records.

249.9.1 Grant records shall include proposals, applications, agreements, award letters, budgets, restrictions, fund codes, deliverables, reports, correspondence, modifications, expenditure records, match records, indirect cost records, public authority reviews, data / AI / cyber reviews, safeguards reviews, closeout records, and corrections.

#### 249.10 Donation Records.

249.10.1 Donation records shall include donor identity where known and lawfully recorded, donation amount, date, restriction, acknowledgment, receipt, donor benefit, quid pro quo disclosure where applicable, donor intent, donor communications, donor reports, anonymity or confidentiality terms, return records, and corrections.

#### 249.11 Sponsorship Records.

249.11.1 Sponsorship records shall include sponsor intake, sponsor due diligence, beneficial ownership review where applicable, agreement, benefit schedule, public acknowledgment language, invoices, receipts, tax classification, public-safe claims review, concentration review, access restrictions, modifications, returns, terminations, and corrections.

#### 249.12 Restricted Fund Records.

249.12.1 Restricted fund records shall include restriction source, restricted purpose, fund code, budget, spending, releases, modifications, unspent balances, carryforward, return obligations, reporting requirements, closeout, and violation or correction records.

#### 249.13 In-Kind Contribution Records.

249.13.1 In-kind contribution records shall include contributor identity, contribution description, value, valuation method, classification, restrictions, acceptance authority, agreement or terms, tax treatment, accounting treatment, data / AI / cyber review, IP review, license review, public acknowledgment, quarantine, return, termination, and correction records.

#### 249.14 Subscription and Fee Records.

249.14.1 Subscription and fee records shall include subscription terms, membership or non-membership classification, Academy fees, training fees, program fees, publication fees, benchmarking fees, repository access fees, cost-recovery records, fee waivers, scholarships, tax treatment, public claims limitations, invoices, payments, refunds, and corrections.

#### 249.15 Procurement and Contract Records.

249.15.1 Procurement and contract records shall include requisitions, specifications, quotes, proposals, evaluations, sole-source justifications, vendor due diligence, approvals, contracts, statements of work, purchase orders, invoices, payment approvals, amendments, renewals, waivers, breaches, terminations, and closeout.

#### 249.16 Signing Authority and Payment Records.

249.16.1 Signing authority and payment records shall include authority matrices, delegations, Board resolutions, signatory records, approval thresholds, payment approvals, dual approvals, wire approvals, ACH approvals, card approvals, reimbursement approvals, access permissions, and authority revocation records.

#### 249.17 Compensation and Reimbursement Records.

249.17.1 Compensation and reimbursement records shall include role descriptions, compensation approvals, comparability records, payroll records, contractor payment records, stipend records, scholarship records, award records, reimbursement claims, receipts, travel records, benefits records, tax records, withholding records, and corrections.

#### 249.18 Fraud, Anti-Corruption, Gift, Hospitality, and Financial Incident Records.

249.18.1 Fraud, anti-corruption, gift, hospitality, and financial incident records shall include fraud reports, misconduct intake, investigation records, evidence preservation, gift registers, hospitality registers, corporate card records, expense abuse records, payment diversion records, procurement integrity records, government ethics reviews, findings, remedies, insurance claims, legal referrals, public authority referrals, funder referrals, law enforcement referrals, and recurrence-prevention records.

#### 249.19 Donor and Funder Reporting Records.

249.19.1 Donor and funder reporting records shall include reporting calendars, donor reports, funder reports, grantor reports, sponsor reports, use-of-funds reports, milestone reports, deliverable reports, impact reports, public-safe scoreboards, redactions, controlled annexes, delivery records, corrections, and supersessions.

#### 249.20 Public-Safe Financial Transparency Records.

249.20.1 Public-safe financial transparency records shall include annual financial summaries, funding source summaries, grant summaries, program summaries, sponsor acknowledgment summaries, donor recognition summaries, restricted fund summaries, audit summaries, review summaries, approvals, public-safe reviews, corrections, supersessions, and withdrawals.

#### 249.21 Closeout Records.

249.21.1 Closeout records shall include grant closeout, contract closeout, sponsorship closeout, donation closeout where applicable, restricted fund closeout, in-kind closeout, procurement closeout, project closeout, public authority interface closeout, data return or deletion records, access revocation records, payment finalization, correction status, and continuing obligation records.

#### 249.22 Retention, Access, Confidentiality, Sealing, Redaction, Archival, and Secure Disposal of Fiscal Records.

249.22.1 Fiscal records shall be retained for the period required by law, tax rules, grant terms, donor restrictions, contract obligations, employment law, audit requirements, public authority restrictions, litigation holds, investigation holds, Board policy, and institutional need.

249.22.2 Access to fiscal records shall be role-based and limited to persons with lawful and institutional need. Sensitive records may be sealed, redacted, segmented, privileged, or placed in controlled annexes.

249.22.3 Secure disposal shall occur only after retention obligations expire and no legal hold, audit, investigation, donor restriction, grant obligation, public authority obligation, correction obligation, or unresolved dispute remains.

249.22.4 Disposal shall be documented and shall protect confidentiality, privacy, cybersecurity, protected knowledge, public authority trust, donor confidentiality, and privilege.

***

### Section 250. Enforcement of Article VIII

#### 250.1 Article VIII Enforcement Purpose.

250.1.1 Enforcement of this Article shall protect the Corporation’s fiscal integrity, nonprofit character, public-benefit purpose, tax compliance, restricted-fund discipline, donor and funder trust, Board oversight, support-without-control rule, procurement integrity, contracting discipline, internal controls, anti-fraud posture, anti-corruption posture, public authority boundary discipline, finance-boundary discipline, certification-boundary discipline, provider neutrality, sponsor non-control, data / AI / cyber controls, safeguards, validity-by-record, and correctionability.

250.1.2 Enforcement shall be substantive and records-based. Fiscal violations shall not be treated as minor administrative defects where they affect public trust, legal compliance, private benefit, donor restrictions, public authority meaning, finance meaning, certification meaning, procurement meaning, data security, protected knowledge, or institutional independence.

#### 250.2 Fiscal Misconduct Review.

250.2.1 Fiscal misconduct review may be initiated for suspected fraud, unauthorized expenditure, false record, false invoice, false receipt, duplicate reimbursement, restricted-fund misuse, improper compensation, related-party concealment, support-with-control, payment diversion, procurement manipulation, tax misclassification, public financial overclaim, or other fiscal violation.

250.2.2 Review shall identify affected persons, records, funds, accounts, contracts, grants, donors, sponsors, public authorities, technical systems, and public-facing materials.

#### 250.3 Unauthorized Expenditure Review.

250.3.1 Unauthorized expenditure review shall be initiated where spending may lack budget authority, signing authority, payment authority, restricted-fund authority, contract authority, procurement authority, Board approval, or required review.

250.3.2 Remedies may include payment hold, reimbursement denial, repayment, accounting correction, ratification only where lawful and appropriate, contract correction, discipline, or legal review.

#### 250.4 Unauthorized Contract Review.

250.4.1 Unauthorized contract review shall be initiated where a person may have bound or attempted to bind the Corporation without authority or without required review.

250.4.2 The Corporation may refuse performance, terminate, amend, ratify only where lawful and appropriate, issue corrective notice, restrict authority, revoke access, discipline the actor, or refer to counsel.

#### 250.5 Restricted Fund Violation Review.

250.5.1 Restricted fund violation review shall be initiated where restricted funds may have been spent, reported, classified, modified, released, carried forward, returned, or closed inconsistently with restrictions, grant terms, donor intent, accounting rules, tax requirements, public authority requirements, or this Bylaw.

250.5.2 Remedies may include spending hold, accounting correction, funder notice, donor notice, amended report, repayment, return, reclassification, Board review, legal review, tax review, audit review, or staff discipline.

#### 250.6 Grant, Donation, Sponsorship, In-Kind, Subscription, Fee, or Cost-Recovery Violation Review.

250.6.1 Review shall be initiated where support was accepted, acknowledged, classified, reported, spent, valued, restricted, returned, or publicly described inconsistently with law, tax treatment, support acceptance controls, sponsor controls, donor controls, in-kind controls, public-safe claims, or this Bylaw.

250.6.2 Remedies may include correction, reclassification, amended receipt, amended acknowledgment, support return, benefit restriction, sponsorship termination, grant modification, public-safe clarification, tax review, or Board notice.

#### 250.7 Support-Without-Control Violation Review.

250.7.1 Support-without-control violation review shall be initiated where a supporter may have received or exercised control over governance, research, evidence, methods, publication, software, technical baselines, public authority access, safeguards, correction, Docket inputs, Grid inputs, GRF-facing inputs, GRA-facing inputs, or Nexus-facing outputs.

250.7.2 Remedies may include ring-fencing, benefit reduction, access restriction, recusal, contract amendment, support return, termination, public or controlled correction, and Board review.

#### 250.8 Private Inurement or Private Benefit Review.

250.8.1 Private inurement or private benefit review shall be initiated where insiders, Related Parties, supporters, providers, sponsors, donors, funders, hosts, capital actors, national companies, Project SPVs, enterprise actors, or private persons may have received improper benefit.

250.8.2 Review may require tax analysis, comparability review, fairness determination, repayment, clawback, contract amendment, rescission, termination, excess benefit correction, Board review, public-safe correction, or legal referral.

#### 250.9 Procurement Violation Review.

250.9.1 Procurement violation review shall be initiated where procurement may involve bid steering, artificial sole-source justification, unfair exclusion, undisclosed conflict, related-party favoritism, confidential information misuse, vendor pressure, sponsor pressure, provider preference, kickback, gift violation, false scoring, split procurement, or missing required review.

250.9.2 Remedies may include procurement cancellation, re-solicitation, vendor exclusion, contract amendment, contract termination, repayment, access restriction, discipline, correction, or legal referral.

#### 250.10 Fraud, Bribery, Kickback, Gift, Hospitality, or Expense Violation Review.

250.10.1 Review shall be initiated where fraud, bribery, kickback, improper gift, excessive hospitality, expense abuse, corporate card misuse, payment diversion, false receipt, false invoice, duplicate reimbursement, payroll fraud, or financial misconduct is alleged or suspected.

250.10.2 Review may require immediate payment hold, card suspension, access restriction, bank notice, credential rotation, cyber review, insurance notice, evidence preservation, legal review, public authority referral, funder notice, or law enforcement referral where required or appropriate.

#### 250.11 Tax, Charitable Solicitation, UBIT, Payroll, or State Registration Violation Review.

250.11.1 Review shall be initiated where the Corporation may have failed to file, registered incorrectly, misstated tax status, issued inaccurate donation receipts, misclassified sponsorship revenue, failed to collect or remit tax, misclassified workers, failed payroll withholding, created UBIT risk, solicited without required registration, failed state qualification, or misrepresented charitable status.

250.11.2 Remedies may include filing, amendment, registration, reinstatement, payment, penalty review, donor correction, public correction, Board notice, tax advisor review, legal review, or operational restriction.

#### 250.12 Public Authority, Finance, Procurement, Certification, Recognition, Provider-Preference, Sponsor-Control, or Public Warning Boundary Violation Review.

250.12.1 Review shall be initiated where a fiscal record, contract, report, support relationship, public statement, acknowledgment, procurement action, payment, or technical output may imply public authority endorsement, official adoption, public finance approval, procurement approval, certification, recognition, finance-readiness, provider preference, sponsor control, public warning, emergency command, professional advice, or regulated execution.

250.12.2 Remedies may include public-safe correction, controlled correction, withdrawal, takedown, limitation language, contract amendment, access restriction, support return, termination, public authority notice, GRF or GRA clarification where appropriate, or legal review.

#### 250.13 Data / AI / Cyber / Privacy, Protected Knowledge, or Confidentiality Violation Review.

250.13.1 Review shall be initiated where fiscal, contracting, procurement, support, reporting, or transparency activity may have caused unauthorized access, data exposure, AI misuse, model training on restricted materials, cyber incident, protected knowledge exposure, breach of confidentiality, privilege waiver, public authority data misuse, or privacy violation.

250.13.2 Remedies may include access revocation, credential rotation, system isolation, data deletion, model-use restriction, incident response, breach notice, public authority notice where required, safeguards review, legal review, public-safe correction, contract remedy, or termination.

#### 250.14 Corrective Action.

250.14.1 Corrective action shall be proportionate to violation, harm, intent, materiality, recurrence, public meaning, affected funds, affected records, affected persons, affected communities, affected public authorities, affected supporters, affected technical systems, and need for deterrence.

250.14.2 Corrective action may include accounting correction, report correction, public-safe correction, disclosure correction, policy amendment, internal control redesign, training, monitoring, repayment, clawback, return of funds, contract remedy, procurement remedy, access restriction, discipline, Board action, legal action, or referral.

#### 250.15 Payment Hold, Contract Hold, Support Hold, Access Restriction, Recusal, Suspension, Termination, Return of Funds, Rescission, Restitution, Insurance Claim, Public or Controlled Correction, or Legal Action.

250.15.1 The Corporation may impose payment holds, contract holds, support holds, procurement holds, restricted-fund holds, access restrictions, recusals, role restrictions, committee restrictions, system restrictions, controlled-room restrictions, suspensions, terminations, return of funds, rescission, restitution, insurance claims, public corrections, controlled corrections, legal claims, or other remedies permitted by law and governing instruments.

250.15.2 Remedies may be imposed on directors, officers, employees, contractors, fellows, advisors, volunteers, committee members, council members, supporters, donors, sponsors, funders, providers, vendors, hosts, public authority participants, capital actors, national companies, Project SPVs, enterprise actors, and Related Parties where applicable.

#### 250.16 Referral to Counsel, Auditor, Regulator, Public Authority, Funder, Grantor, Law Enforcement, or Other Body Where Required or Appropriate.

250.16.1 The Corporation shall refer matters to counsel, auditor, tax advisor, insurer, regulator, public authority, funder, grantor, law enforcement, or another competent body where required by law, contract, grant terms, insurance terms, public authority requirements, fiduciary duty, Board determination, or severity of the matter.

250.16.2 Referrals shall preserve confidentiality, privilege, evidence, records, non-retaliation, public-safe communication, protected knowledge, public authority trust, and legal compliance.

#### 250.17 Enforcement Records.

250.17.1 The Corporation shall maintain Article VIII Enforcement Records, including intake records, case identifiers, allegations, affected persons, affected funds, affected transactions, affected contracts, affected reports, affected systems, evidence preservation, interim measures, reviewers, reviewer conflicts, findings, corrective actions, payment holds, support holds, contract holds, access restrictions, repayments, returns, rescissions, restitution, insurance claims, public or controlled corrections, referrals, closeout, and recurrence-prevention records.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.therisk.global/organization/organization/governance/bylaws/gcri-us/article-viii.-finance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
