For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XV. PROTECTION

426.1.1 Legal Compliance shall require the Corporation to operate in accordance with applicable law, governing instruments, Board resolutions, contractual duties, grant terms, public authority restrictions, privacy and data protection obligations, AI governance obligations, cybersecurity obligations, research ethics requirements, employment and workplace requirements, civil rights and accessibility requirements, sanctions and export-control requirements, competition and antitrust requirements, professional boundary requirements, nonprofit duties, tax requirements, charitable solicitation requirements where applicable, and all other legal obligations applicable to the Corporation’s activities.

426.1.2 Legal Compliance shall be interpreted as a public-benefit governance obligation, an institutional protection obligation, and a boundary-preservation obligation. It shall support the Corporation’s non-executing role as a United States nonprofit public-good technical institution and shall prevent any activity from being mischaracterized as public authority action, finance-readiness, investment advice, securities activity, insurance activity, lending activity, rating, procurement approval, certification, recognition, emergency command, public warning, provider preference, or enterprise execution.

426.1.3 Legal Compliance shall be records-based. No person shall rely on informal custom, mission urgency, sponsor preference, provider preference, public authority interest, technical enthusiasm, AI-generated interpretation, or Nexus coordination language to bypass required legal review, approval, filing, registration, restriction, disclosure, consent, license, permission, notice, hold, or corrective action.

426.2 Corporate Compliance Purpose.

426.2.1 Corporate Compliance shall preserve the Corporation’s valid existence, good standing, governance integrity, separate legal personality, records discipline, Board authority, officer authority, committee authority, delegation controls, registered office, registered agent, principal office records, minute books, registers, state filings, foreign qualification status where required, and lawful corporate capacity.

426.2.2 Corporate Compliance shall support legal separateness from GCRI Canada, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, public authorities, sponsors, providers, national companies, Project SPVs, universities, laboratories, communities, and partners.

426.3 Nonprofit Compliance Purpose.

426.3.1 Nonprofit Compliance shall ensure that the Corporation’s assets, programs, funds, grants, sponsorships, donations, contracts, public-good software, technical baselines, evidence outputs, methods, publications, and Nexus coordination activities remain aligned with the Corporation’s nonprofit and public-benefit purposes.

426.3.2 Nonprofit Compliance shall prevent private inurement, impermissible private benefit, mission drift, public-good capture, sponsor control, provider control, insider benefit, excess benefit transactions where applicable, misuse of restricted funds, and conversion of public-good resources into unauthorized enterprise stack advantage.

426.4 Tax-Exempt or Tax-Exempt-Compatible Compliance Purpose.

426.4.1 Tax-Exempt or Tax-Exempt-Compatible Compliance shall ensure that the Corporation maintains any applicable federal, state, territorial, or local tax status, exemption, classification, filing status, public support position, charitable status, or nonprofit tax posture lawfully obtained or sought.

426.4.2 Where the Corporation has not yet obtained a particular tax-exempt status, compliance shall require that programs, records, transactions, fundraising, sponsorships, grants, publications, public authority interfaces, and enterprise stack interfaces be structured to remain compatible with the Corporation’s intended or applicable nonprofit tax posture, subject to competent tax review.

426.5 Charitable Solicitation Compliance Purpose Where Applicable.

426.5.1 Charitable Solicitation Compliance shall ensure that fundraising, donations, public support, campaigns, sponsorship acknowledgments, grant solicitation, donor communications, online giving, event fundraising, and public-facing support requests comply with applicable federal, state, territorial, local, platform, and contractual requirements where applicable.

426.5.2 Charitable solicitation materials shall be accurate, public-safe, non-misleading, and consistent with the Corporation’s nonprofit role, and shall not imply public authority endorsement, public finance approval, recognition, certification, procurement advantage, finance-readiness, provider preference, sponsor control, or purchase of outcomes.

426.6 Privacy and Data Protection Compliance Purpose.

426.6.1 Privacy and Data Protection Compliance shall ensure lawful and rights-respecting processing of personal information, sensitive personal information, health-sensitive data, public authority data, youth data, education data, rights-bearing data, community-protected data, Tribal / Indigenous data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, research data, and other protected data.

426.6.2 Compliance shall include lawful basis, authority records, permission records, consent where required, notice where required, purpose limitation, data minimization, classification, access control, retention, deletion, transfer control, cross-border review, incident response, breach notification, and public-safe publication review.

426.7 AI Governance Compliance Purpose.

426.7.1 AI Governance Compliance shall ensure that AI systems, AI-assisted research, AI-generated content, automated outputs, agentic AI tools, model registers, dataset cards, model cards, system cards, benchmark cards, inference records, compute workload records, proof receipts, embeddings, retrieval systems, fine-tuning, model improvement, and evaluation harnesses are governed according to applicable law, policy, contract, data authority, public-safe requirements, and human review requirements.

426.7.2 AI Governance Compliance shall prevent unauthorized AI training, unauthorized fine-tuning, unauthorized embeddings, unauthorized model improvement, sensitive data leakage, hallucination overclaim, automated public authority communication, unauthorized public claims, algorithmic discrimination, unsafe outputs, and agentic action beyond recorded authority.

426.8 Cybersecurity Compliance Purpose.

426.8.1 Cybersecurity Compliance shall protect the Corporation’s systems, repositories, technical assets, datasets, models, cloud services, identity systems, controlled rooms, public authority data, public-good software, dashboards, maps, proof receipts, ledgers, secrets, keys, tokens, credentials, and sensitive configurations.

426.8.2 Cybersecurity Compliance shall include secure development, access control, asset inventory, vulnerability management, repository security, supply-chain assurance, logging, monitoring, incident response, backup, disaster recovery, business continuity, vendor security, and secure release controls.

426.9 Research Ethics Compliance Purpose.

426.9.1 Research Ethics Compliance shall ensure that research, evidence work, methods work, observability work, public authority learning, community engagement, human-subjects research, public health research, biosecurity research, youth-related research, vulnerable population research, health-sensitive research, and rights-bearing data work comply with applicable ethical, legal, institutional, contractual, community, Tribal / Indigenous, and public-safe requirements.

426.9.2 Research Ethics Compliance shall preserve accuracy, honesty, transparency, method documentation, source integrity, limitation disclosure, uncertainty disclosure, conflict management, sponsor and provider independence, participant protection, consent where required, withdrawal where applicable, grievance pathways, and correctionability.

426.10 Employment, Contractor, Volunteer, Fellow, Advisor, and Workplace Compliance Purpose.

426.10.1 Employment, Contractor, Volunteer, Fellow, Advisor, and Workplace Compliance shall ensure that persons performing work for or with the Corporation are properly classified, onboarded, supervised, trained, compensated where applicable, protected, restricted, reviewed, and separated according to applicable law, contract, policy, role, access, and risk.

426.10.2 Compliance shall address worker classification, confidentiality, IP assignment, contributor terms, conflicts, anti-harassment, anti-retaliation, workplace safety, remote work, repository access, data access, AI-use duties, cybersecurity duties, public-safe claims duties, accessibility, civil rights, and termination or offboarding.

426.11 Civil Rights, Accessibility, and Non-Discrimination Compliance Purpose.

426.11.1 Civil Rights, Accessibility, and Non-Discrimination Compliance shall require the Corporation to conduct programs, research, publications, digital channels, training, events, public authority learning, community interfaces, fellowships, volunteer activity, workforce activity, dashboards, maps, and technical assets in a manner consistent with applicable civil rights, accessibility, non-discrimination, equal opportunity, anti-retaliation, and public accommodation requirements.

426.11.2 Compliance shall include accessibility review, inclusive participation, language access where appropriate, disability access, anti-discrimination controls, bias review, public-safe mapping review, civil rights impact review where appropriate, and correction of exclusionary or harmful outputs.

426.12 Public Authority Interface Compliance Purpose.

426.12.1 Public Authority Interface Compliance shall ensure lawful and accurate interaction with federal, state, District of Columbia, territorial, Tribal, Indigenous, local, county, municipal, metropolitan, public health, emergency management, public safety, public works, public infrastructure, regulatory, procurement, public finance, legislative, judicial, oversight, public university, and public laboratory actors.

426.12.2 Compliance shall preserve capacity classification, official capacity records, observer status, regulator-listening status, public finance reader status, public authority data controls, public authority reference approvals, public records considerations, FOIA and sunshine considerations, procurement neutrality, public finance boundaries, regulatory boundaries, public warning boundaries, emergency command boundaries, and no public authority substitution.

426.13 Sanctions and Export-Control Compliance Purpose.

426.13.1 Sanctions and Export-Control Compliance shall ensure that the Corporation’s programs, data transfers, software access, repository access, technical baselines, controlled technology, cybersecurity materials, AI systems, encryption materials, geospatial materials, telecom materials, semiconductor-related materials, cross-border collaborations, payments, funding, sponsorships, grants, and counterparties comply with applicable sanctions, export-control, import-control, controlled technology, and restricted-party requirements.

426.13.2 Compliance shall include screening, classification, access restriction, transfer review, publication review, controlled-room review, legal review, denial of access where required, and incident response for restricted or prohibited activity.

426.14 Competition and Antitrust Compliance Purpose.

426.14.1 Competition and Antitrust Compliance shall ensure that consortiums, working groups, provider interfaces, sponsor interfaces, public authority rooms, standards discussions, technical baseline work, data exchanges, capital-reader rooms, sector interfaces, and enterprise stack coordination are not used for price fixing, bid coordination, market allocation, group boycott, exclusionary conduct, provider preference, procurement manipulation, competitively sensitive information exchange, or sponsor capture.

426.14.2 Competition compliance shall preserve open participation where appropriate, provider neutrality, procurement neutrality, public-good independence, boundary discipline, and accurate records.

426.15 Professional Boundary Compliance Purpose.

426.15.1 Professional Boundary Compliance shall ensure that the Corporation does not provide legal advice, investment advice, tax advice, accounting advice, engineering certification, medical advice, public health orders, cybersecurity certification, insurance placement, underwriting, lending, rating, broker-dealer activity, municipal advisory services, procurement advice for public authorities, regulated professional services, or other professional services requiring licensure or authorization unless separately and lawfully authorized.

426.15.2 Professional boundary controls shall require limitation language, referral to qualified professionals where appropriate, non-reliance statements, and correction of overclaims.

426.16 Risk Management and Institutional Protection Purpose.

426.16.1 Legal Compliance shall support institutional risk management by identifying, preventing, mitigating, correcting, documenting, and escalating legal, operational, financial, reputational, public authority, data, AI, cyber, privacy, research, employment, nonprofit, tax, IP, sanctions, export-control, competition, and public-safe risks.

426.16.2 Institutional protection shall not be used to suppress valid challenges, conceal errors, avoid correction, retaliate against reporters, or compromise public-benefit duties.

426.17.1 The Corporation shall maintain Legal Compliance Records, including legal compliance purpose records, corporate compliance records, nonprofit compliance records, tax-exempt or tax-exempt-compatible compliance records, charitable solicitation records where applicable, privacy and data protection compliance records, AI governance compliance records, cybersecurity compliance records, research ethics compliance records, employment / contractor / volunteer / fellow / advisor / workplace compliance records, civil rights / accessibility / non-discrimination compliance records, public authority interface compliance records, sanctions and export-control compliance records, competition and antitrust compliance records, professional boundary compliance records, risk management and institutional protection records, legal reviews, approvals, filings, notices, corrective actions, holds, referrals, and archive records.


Section 427. Corporate, Nonprofit, Governance, and Good-Standing Compliance

427.1 Corporate Compliance Requirement.

427.1.1 The Corporation shall maintain corporate compliance sufficient to preserve its lawful existence, nonprofit status, good standing, governance validity, legal separateness, authority to operate, and capacity to carry out its public-benefit purposes.

427.1.2 Corporate compliance shall be overseen by the Board, implemented by officers or authorized delegates, recorded in the Corporation’s books and records, and reviewed periodically according to risk, filing cycles, organizational growth, jurisdictional activity, and legal requirements.

427.2 Governing State Nonprofit Corporation Law Compliance.

427.2.1 The Corporation shall comply with the nonprofit corporation law of its governing state of formation, including requirements concerning corporate powers, directors, officers, members where applicable, meetings, consents, records, amendments, filings, registered office, registered agent, reporting, dissolution, indemnification, conflicts, and other required matters.

427.2.2 Where Nexus activities occur outside the governing state, the Corporation shall assess whether additional state, territorial, local, or foreign qualification, registration, tax, solicitation, employment, privacy, public authority, or other obligations apply.

427.3 Certificate or Articles Compliance.

427.3.1 The Corporation shall comply with its certificate of incorporation, articles of incorporation, certificate of formation, charter, or equivalent formation instrument.

427.3.2 No bylaw, resolution, contract, grant, policy, federation instrument, public authority interface, or Nexus coordination activity shall be interpreted to override the Corporation’s formation instrument unless lawfully amended through competent process.

427.4 Bylaw Compliance.

427.4.1 The Corporation shall comply with these Bylaws and shall ensure that Board actions, officer actions, committee actions, member actions where applicable, delegations, programs, publications, records, contracts, public authority interfaces, and Nexus coordination activities remain consistent with these Bylaws.

427.4.2 Bylaw ambiguity shall be resolved in favor of lawful public-benefit purpose, non-execution, role separation, public-good stack integrity, legal separateness, validity-by-record, correctionability, public authority boundary discipline, finance boundary discipline, procurement neutrality, provider neutrality, and sponsor non-control.

427.5 Board Resolution Compliance.

427.5.1 The Corporation shall comply with Board resolutions, written consents, delegated authorities, committee charters, officer appointment records, policy approvals, program approvals, and other Board-authorized actions.

427.5.2 Board resolutions shall be recorded with sufficient clarity to identify authority, scope, effective date, limitations, delegation, expiration where applicable, and required follow-up.

427.6 Member Approval Compliance Where Applicable.

427.6.1 Where the Corporation has members with statutory, charter, or bylaw approval rights, the Corporation shall obtain member approval for actions requiring such approval.

427.6.2 Member approvals shall be recorded, and no person shall represent that member approval has been obtained unless competent records support the statement.

427.7 Registered Office Maintenance.

427.7.1 The Corporation shall maintain a registered office as required by applicable law.

427.7.2 Changes to the registered office shall be approved, filed, recorded, and communicated as required by law and internal records procedures.

427.8 Registered Agent Maintenance.

427.8.1 The Corporation shall maintain a registered agent as required by applicable law.

427.8.2 Registered agent information shall be current, monitored, and capable of receiving service of process, official notices, tax notices, state communications, and other legal communications.

427.9 Principal Office Records.

427.9.1 The Corporation shall maintain records identifying its principal office, mailing address, operational addresses where applicable, digital office records where appropriate, and contact points for legal, governance, compliance, public authority, and records matters.

427.9.2 Principal office records shall be updated when changes occur and shall be consistent with public filings where required.

427.10 Annual Reports and State Filings.

427.10.1 The Corporation shall timely prepare, approve where required, file, and retain annual reports, biennial reports, information statements, nonprofit filings, charitable filings, foreign qualification filings, registered agent filings, officer / director updates, and other state or territorial filings required by applicable law.

427.10.2 Filing obligations shall be tracked in a compliance calendar or equivalent register.

427.11 Franchise Tax or Annual Fee Where Applicable.

427.11.1 The Corporation shall identify and pay franchise taxes, annual fees, filing fees, registered agent fees, state nonprofit fees, foreign qualification fees, and related charges where applicable.

427.11.2 Nonpayment or late payment risk shall be escalated to an officer and corrected promptly.

427.12 Foreign Qualification in States and Territories Where Required.

427.12.1 The Corporation shall assess whether activities in any state, District of Columbia, territory, Tribal jurisdiction, or other jurisdiction require foreign qualification, registration, charitable solicitation registration, tax registration, employment registration, data protection registration, public authority filing, or other authorization.

427.12.2 Activities creating potential qualification obligations may include offices, employees, contractors, regular programs, public fundraising, public authority contracts, grants, events, controlled rooms, data processing, repository operations, or other sustained operations.

427.13 Corporate Minute Book.

427.13.1 The Corporation shall maintain a corporate minute book or equivalent governance record system containing formation documents, bylaws, amendments, Board minutes, consents, committee minutes, officer appointments, delegations, conflict records, policies, major approvals, member records where applicable, and legally significant governance records.

427.13.2 The minute book may be physical, digital, or hybrid, provided authenticity, completeness, access control, retention, and auditability are preserved.

427.14 Director and Officer Registers.

427.14.1 The Corporation shall maintain current registers of directors and officers, including name, role, term, appointment date, resignation or removal date where applicable, contact information, conflict disclosures, committee roles, delegations, and required training status.

427.15 Member Register Where Applicable.

427.15.1 Where the Corporation has members, it shall maintain a member register identifying member class, admission, rights, voting status, term, resignation or removal, contact information, approval rights, restrictions, and records required by law and the Bylaws.

427.16 Committee and Delegation Registers.

427.16.1 The Corporation shall maintain registers of committees, councils, working groups, panels, advisory bodies, and delegated authorities, including charter, scope, members, chair, authority, limitations, reporting duties, term, records requirements, and revocation path.

427.16.2 Delegations shall be interpreted narrowly and shall not include authority to amend Bylaws, bind the Corporation beyond scope, approve public authority commitments, issue finance-readiness, issue recognition, certify, approve procurement, or execute enterprise activities unless expressly authorized.

427.17 Good Standing Monitoring.

427.17.1 The Corporation shall monitor good standing in its formation jurisdiction and other jurisdictions where it is registered, qualified, licensed, exempt, or otherwise required to maintain status.

427.17.2 Loss of good standing, delinquency, administrative dissolution risk, revocation risk, filing deficiency, registered agent issue, tax notice, or qualification defect shall be escalated promptly and corrected.

427.18 Corporate Compliance Records.

427.18.1 The Corporation shall maintain Corporate Compliance Records, including corporate compliance requirement records, governing state nonprofit corporation law compliance records, certificate or articles compliance records, bylaw compliance records, Board resolution compliance records, member approval records where applicable, registered office records, registered agent records, principal office records, annual reports and state filings, franchise tax or annual fee records where applicable, foreign qualification records, corporate minute book records, director and officer registers, member registers where applicable, committee and delegation registers, good standing monitoring records, notices, corrective actions, filings, and archive records.


Section 428. Federal Tax, State Tax, Tax-Exempt, Nonprofit, Private Benefit, and Charitable Solicitation Compliance

428.1 Federal Tax Compliance.

428.1.1 The Corporation shall comply with applicable federal tax requirements, including filing, reporting, withholding, information return, unrelated business income, donor acknowledgment, grant reporting, payroll, contractor reporting, and tax status maintenance obligations.

428.1.2 Federal tax compliance shall be reviewed in connection with major grants, sponsorships, donations, restricted funds, enterprise stack interfaces, intellectual property licensing, software licensing, foreign activities, lobbying, political activity, transactions with insiders, and revenue-generating activities.

428.2 IRS Status Records.

428.2.1 The Corporation shall maintain IRS Status Records, including employer identification number records, tax classification records, tax-exempt application records where applicable, determination letters where applicable, correspondence, filings, public inspection copies where required, and status-change records.

428.3 Tax-Exempt Application, Determination, Maintenance, or Change Where Applicable.

428.3.1 Where the Corporation seeks, holds, modifies, or relinquishes tax-exempt status, it shall maintain records of application, determination, maintenance, changes, public support, activities, amendments, transactions, unrelated business review, lobbying review, and compliance obligations.

428.3.2 Any material change in purposes, activities, governance, public-good stack role, enterprise stack interface, revenue model, grant structure, sponsorship structure, or foreign activity shall be reviewed for tax status implications.

428.4 Section 501(c)(3) Compliance Where Applicable.

428.4.1 Where the Corporation is recognized or operates as seeking recognition under Section 501(c)(3) of the Internal Revenue Code or a successor provision, it shall operate exclusively for exempt purposes within the meaning of applicable law and shall avoid private inurement, impermissible private benefit, excessive lobbying, political campaign intervention, and activities inconsistent with its exempt purposes.

428.4.2 Public-good software, open technical baselines, evidence outputs, public authority learning, publications, grants, sponsorships, and enterprise stack interfaces shall be structured to preserve charitable, educational, scientific, or other exempt purpose compatibility where applicable.

428.5 Other Federal Tax Classification Compliance Where Applicable.

428.5.1 Where the Corporation has or seeks another federal tax classification, it shall comply with the requirements applicable to that classification.

428.5.2 The Corporation shall not represent that it holds a particular federal tax classification unless competent IRS or legal records support the representation.

428.6 State Tax Compliance.

428.6.1 The Corporation shall comply with applicable state tax obligations, including exemption applications, annual filings, franchise or entity taxes, sales and use tax, payroll withholding, employment taxes, income tax where applicable, property tax where applicable, and state charitable or nonprofit tax rules.

428.7 Local Tax Compliance Where Applicable.

428.7.1 The Corporation shall comply with applicable local tax obligations where activities, offices, events, employees, contractors, property, grants, or transactions create local tax duties.

428.8 Sales, Use, Indirect, Payroll, and Withholding Tax Compliance Where Applicable.

428.8.1 The Corporation shall review sales, use, indirect, gross receipts, VAT-like, payroll, withholding, contractor reporting, and employment tax obligations where it sells materials, licenses technical assets, receives fees, conducts events, operates online programs, pays employees, pays contractors, or carries out taxable activity.

428.9 Unrelated Business Income Review.

428.9.1 The Corporation shall review revenue-generating activities for unrelated business income risk, including sponsorships, licensing, software services, technical assistance, events, training fees, publication sales, data access, repository services, enterprise stack interfaces, and commercial collaborations.

428.9.2 Activities with unrelated business risk shall be structured, documented, reported, taxed, restricted, or discontinued as required.

428.10 Donation Receipting Compliance Where Applicable.

428.10.1 The Corporation shall issue donation receipts, acknowledgments, quid pro quo disclosures, restricted gift acknowledgments, and substantiation materials where required by law and policy.

428.10.2 Donation receipts shall be accurate and shall not overstate tax deductibility, public authority endorsement, program outcomes, recognition, finance-readiness, procurement advantage, certification, or sponsor control.

428.11 Charitable Solicitation Registration Compliance Where Applicable.

428.11.1 The Corporation shall assess, obtain, maintain, renew, or terminate charitable solicitation registrations, exemptions, notices, disclosures, commercial fundraiser filings, online fundraising compliance, and related filings in jurisdictions where fundraising activity requires them.

428.11.2 Solicitation materials shall include required disclosures and shall be reviewed where statements concerning Nexus, public authorities, sponsors, providers, grants, public-good software, technical baselines, or public impact could be misunderstood.

428.12 Restricted Fund and Grant Tax Compliance.

428.12.1 Restricted funds, grants, public grants, donor-restricted contributions, sponsor-restricted support, and program-specific funds shall be recorded, used, reported, and released according to applicable law, grant terms, donor restrictions, accounting rules, tax requirements, public authority restrictions, and Board policy.

428.12.2 Restricted funds shall not be used for private benefit, provider preference, sponsor control, political campaign intervention, unauthorized lobbying, regulated finance activity, procurement advantage, or enterprise execution outside approved purpose.

428.13 Private Inurement Prohibition.

428.13.1 No part of the Corporation’s net earnings, assets, restricted funds, public-good resources, technical assets, data rights, software, repositories, grants, donations, sponsorships, or program benefits shall inure to the private benefit of directors, officers, insiders, disqualified persons where applicable, substantial contributors, sponsors, providers, employees, contractors, or related persons except through lawful, fair, documented, and authorized compensation or transactions.

428.14 Impermissible Private Benefit Prohibition.

428.14.1 The Corporation shall not operate for impermissible private benefit, including by giving sponsors, providers, national companies, Project SPVs, enterprise actors, insiders, donors, funders, or partners disproportionate control, economic advantage, procurement advantage, finance-readiness advantage, recognition advantage, certification advantage, data advantage, technical baseline control, public authority access advantage, or public-good asset enclosure.

428.14.2 Incidental private benefit may be permitted only where lawful, necessary or appropriate to public-benefit purpose, proportionate, documented, and not inconsistent with nonprofit or tax-exempt obligations.

428.15 Excess Benefit Transaction Review Where Applicable.

428.15.1 Where excess benefit transaction rules or similar nonprofit conflict and compensation rules apply, the Corporation shall review compensation, contracts, grants, reimbursements, licensing, IP transfers, related-party transactions, sponsorship arrangements, and other benefits involving insiders or related persons.

428.15.2 Review may require comparability data, conflict disclosure, recusal, Board approval, documentation, correction, repayment, contract modification, tax reporting, or legal advice.

428.16 Tax Status Change Escalation.

428.16.1 Any event that may affect tax status, exemption, public charity status, private foundation status, nonprofit status, charitable solicitation status, unrelated business income exposure, private benefit analysis, lobbying limits, political activity limits, or charitable purpose shall be escalated to the Board or authorized officer.

428.16.2 Material tax status risks shall be reviewed before public announcement, transaction execution, grant acceptance, sponsor acceptance, enterprise stack interface, public authority agreement, major publication, or structural change.

428.17 Tax and Nonprofit Compliance Records.

428.17.1 The Corporation shall maintain Tax and Nonprofit Compliance Records, including federal tax compliance records, IRS status records, tax-exempt application / determination / maintenance / change records where applicable, Section 501(c)(3) compliance records where applicable, other federal tax classification records where applicable, state tax compliance records, local tax compliance records where applicable, sales / use / indirect / payroll / withholding tax records where applicable, unrelated business income review records, donation receipting records, charitable solicitation registration records where applicable, restricted fund and grant tax compliance records, private inurement records, private benefit review records, excess benefit transaction review records where applicable, tax status change escalation records, filings, receipts, correspondence, corrective actions, and archive records.


Section 429. Privacy, Data Protection, AI Governance, Cybersecurity, and Technology Compliance

429.1 Privacy Compliance.

429.1.1 The Corporation shall comply with applicable privacy and data protection laws, regulations, contractual requirements, public authority restrictions, grant conditions, ethical requirements, community protocols, Tribal / Indigenous protocols, and internal policies governing personal information, sensitive personal information, health-sensitive data, rights-bearing data, public authority data, research data, community-protected data, protected knowledge, and technology-derived data.

429.1.2 Privacy Compliance shall include privacy by design, purpose limitation, data minimization, lawful basis, notice, consent where required, rights handling where applicable, access restriction, retention, deletion, transfer control, public-safe review, and incident response.

429.2 Federal Privacy Law Compliance Where Applicable.

429.2.1 The Corporation shall comply with applicable federal privacy, confidentiality, sectoral, consumer protection, health, education, children’s, communications, cybersecurity, breach notification, grant, research, and public authority data rules where applicable to its activities.

429.2.2 Federal privacy compliance shall be reviewed before receiving, processing, publishing, mapping, transferring, training on, embedding, or externally sharing protected or rights-bearing data.

429.3 State Privacy Law Compliance Where Applicable.

429.3.1 The Corporation shall comply with applicable state privacy, consumer data protection, biometric, breach notification, health privacy, genetic data, children’s privacy, education data, data broker, cybersecurity, public records, and related laws where applicable.

429.3.2 The Corporation shall maintain state-specific localization notes where state privacy requirements materially affect data practices, public-safe publication, public authority interfaces, or digital channels.

429.4 Territorial Privacy Law Compliance Where Applicable.

429.4.1 The Corporation shall comply with applicable privacy, data protection, breach notification, public records, health, youth, public authority, and cybersecurity requirements of territories where its activities create obligations.

429.4.2 Territorial privacy compliance shall account for language access, disaster context, public health context, infrastructure sensitivity, public authority restrictions, and cross-border or offshore processing where relevant.

429.5 Sectoral Privacy Compliance Where Applicable.

429.5.1 The Corporation shall identify and comply with sector-specific privacy and data protection duties involving health, education, children and youth, public health, human subjects, financial data, employment data, telecommunications, geospatial data, biometric data, cyber data, infrastructure data, public authority data, and research data.

429.6 Health, Education, Youth, Public Authority, and Rights-Bearing Data Compliance Where Applicable.

429.6.1 Health, education, youth, public authority, and rights-bearing data shall receive heightened review for lawful basis, consent or permission, notice, minimization, access control, confidentiality, AI-use restrictions, publication restrictions, retention, deletion, transfer, public-safe mapping, breach notification, and correction.

429.6.2 Youth, vulnerable population, health-sensitive, and rights-bearing data shall not be used for unauthorized AI training, embeddings, public mapping, finance-readiness inputs, provider benefit, sponsor benefit, or publication beyond competent authority.

429.7 Cross-Border Data Transfer Compliance.

429.7.1 Cross-border data transfers shall be reviewed for privacy law, public authority restrictions, data sovereignty, Tribal / Indigenous protocols, community protocols, export-control, sanctions, controlled technology, cybersecurity, contractual restrictions, public-safe publication, and conflict-of-law concerns.

429.7.2 Where lawful transfer cannot be confirmed, data shall remain localized, segmented, aggregated, anonymized where appropriate, controlled-roomed, or withheld.

429.8 Data Sovereignty and Tribal / Indigenous Data Governance Considerations.

429.8.1 The Corporation shall respect Tribal Data Sovereignty, Indigenous Data Safeguards, Indigenous Knowledge protocols, community data governance, local knowledge restrictions, protected knowledge restrictions, and community permission structures where applicable.

429.8.2 Tribal / Indigenous and protected knowledge data shall not be presumed open, transferable, publishable, mappable, trainable, embeddable, translatable, or commercially reusable by reason of receipt, public availability, or technical accessibility.

429.9.1 The Corporation shall monitor applicable AI governance laws, regulations, public authority guidance, contractual requirements, sector standards, risk management frameworks, procurement rules, civil rights requirements, privacy rules, cybersecurity requirements, and public authority AI-use obligations that may affect its AI-related activities.

429.9.2 Monitoring shall inform policy updates, model register requirements, human review requirements, AI-use restrictions, vendor review, public-safe publication, incident response, and training.

429.10 AI Use, Model Governance, Inference, and Automated Output Compliance.

429.10.1 AI Use, Model Governance, Inference, and Automated Output Compliance shall require model register records where material, AI use-case review, dataset authority, training restrictions, fine-tuning restrictions, embedding restrictions, retrieval restrictions, inference records, compute workload records, human review, bias review, safety review, hallucination review, prompt-injection review, leakage review, and output limitation language.

429.10.2 Automated or AI-assisted outputs shall not be used as public authority communications, public warnings, emergency commands, finance-readiness determinations, certification determinations, recognition determinations, procurement approvals, public-safe publications, or official truth without required records and human review.

429.11.1 The Corporation shall comply with cybersecurity obligations imposed by law, contract, grant, public authority agreement, data-sharing instrument, vendor agreement, repository platform, insurance requirement where applicable, controlled-room instrument, and internal policy.

429.11.2 Compliance shall include access control, secure configuration, endpoint security, cloud security, repository security, logging, monitoring, vulnerability management, secure development, incident response, backup, disaster recovery, vendor security, and training.

429.12 Incident and Breach Notification Compliance.

429.12.1 The Corporation shall maintain incident and breach notification processes sufficient to assess, escalate, contain, investigate, document, notify, correct, remediate, and close out data incidents, privacy incidents, personal information breaches, public authority data incidents, health-sensitive data incidents, cyber incidents, AI incidents, publication incidents, and protected knowledge incidents.

429.12.2 Notification decisions shall be based on applicable law, contract, grant terms, public authority restrictions, affected person rights, public-safe communication, confidentiality, privilege, cybersecurity, and harm mitigation.

429.13 Public Authority Data Compliance.

429.13.1 Public Authority Data Compliance shall require authority records, capacity records, contribution agreements where appropriate, dataset descriptions, permitted uses, prohibited uses, classifications, confidentiality restrictions, AI-use restrictions, publication restrictions, retention and deletion terms, transfer restrictions, public records considerations, and correction pathways.

429.14 Cyber-Sensitive and Infrastructure-Sensitive Data Compliance.

429.14.1 Cyber-sensitive and infrastructure-sensitive data shall be subject to heightened classification, access restriction, public-safe review, controlled-room handling where appropriate, publication restriction, AI-use restriction, transfer restriction, and incident response.

429.14.2 Such data shall not be published, mapped, visualized, summarized, trained on, embedded, or shared in a manner that exposes vulnerabilities, enables targeting, compromises resilience, or creates public safety risk.

429.15 Community-Protected and Protected Knowledge Data Compliance.

429.15.1 Community-protected and protected knowledge data shall be governed by consent, non-consent, attribution, non-attribution, withdrawal, restriction, correction, grievance, public-safe mapping, transfer, publication, and AI-use rules appropriate to the community, Tribal / Indigenous, local, territorial, cultural, environmental, or protected knowledge context.

429.15.2 The Corporation shall apply heightened safeguards where publication, mapping, AI processing, or translation could expose, distort, appropriate, commodify, or harm protected knowledge.

429.16 Technology Vendor Compliance.

429.16.1 Technology Vendor Compliance shall require review of data processors, AI providers, cloud providers, cybersecurity providers, repository providers, software vendors, hosting providers, subprocessors, and other technology vendors.

429.16.2 Vendor review shall address security, privacy, data protection, AI-use restrictions, training restrictions, subprocessor disclosure, incident notification, audit rights where appropriate, exit rights, portability, data deletion, confidentiality, export-control, sanctions, controlled technology, and public authority restrictions.

429.17 Privacy, AI, Cybersecurity, and Technology Compliance Records.

429.17.1 The Corporation shall maintain Privacy, AI, Cybersecurity, and Technology Compliance Records, including privacy compliance records, federal privacy law compliance records where applicable, state privacy law compliance records where applicable, territorial privacy law compliance records where applicable, sectoral privacy compliance records where applicable, health / education / youth / public authority / rights-bearing data compliance records where applicable, cross-border data transfer compliance records, data sovereignty and Tribal / Indigenous data governance records, AI governance legal and regulatory monitoring records, AI use / model governance / inference / automated output compliance records, cybersecurity legal and contractual compliance records, incident and breach notification compliance records, public authority data compliance records, cyber-sensitive and infrastructure-sensitive data compliance records, community-protected and protected knowledge data compliance records, technology vendor compliance records, reviews, approvals, notices, restrictions, incidents, corrective actions, and archive records.


Section 430. Research Ethics, Human-Subjects, Public Health, Biosecurity, Community, Tribal / Indigenous, and Protected Knowledge Compliance

430.1 Research Ethics Compliance.

430.1.1 The Corporation shall conduct and support research, evidence work, methods work, observability work, public-good software work, public authority learning, public-safe publication, datasets, dashboards, maps, digital twins, AI-related analysis, biosecurity-related analysis, public health-related analysis, community engagement, and protected knowledge work in accordance with applicable research ethics, legal, contractual, public authority, institutional, community, Tribal / Indigenous, and public-safe requirements.

430.1.2 Research Ethics Compliance shall require accuracy, honesty, transparency, method documentation, source integrity, conflict disclosure, sponsor and provider independence, participant protection, data minimization, limitation disclosure, uncertainty disclosure, public-safe framing, challengeability, and correctionability.

430.2 Human-Subjects Review Compliance.

430.2.1 Human-subjects research, or activity reasonably likely to require human-subjects review, shall be reviewed before commencement under applicable law, institutional policy, grant requirements, public authority requirements, and ethical standards.

430.2.2 No person shall avoid human-subjects review by re-labeling research as observability, learning, dashboarding, public authority support, AI analysis, community engagement, pilot activity, or technical assistance where applicable rules require review.

430.3 Institutional Review Board or Equivalent Review Where Required.

430.3.1 Where Institutional Review Board review, ethics committee review, research ethics board review, public authority ethics review, community review, Tribal / Indigenous review, or equivalent review is required or appropriate, the Corporation shall obtain such review before conducting or relying on the covered activity.

430.3.2 Review records shall identify protocol, purpose, population, data, consent, risks, safeguards, public-safe publication, confidentiality, AI use, withdrawal, correction, and grievance pathways.

430.4 Public Health Research Compliance Where Applicable.

430.4.1 Public health research or public health-sensitive activity shall comply with applicable public health, privacy, human-subjects, public authority, data protection, publication, and ethics requirements.

430.4.2 Public health research outputs shall not constitute public health orders, clinical guidance, emergency alerts, public warnings, treatment instructions, diagnostic instructions, public authority decisions, or emergency command by GCRI US.

430.5 Biosecurity Research Compliance Where Applicable.

430.5.1 Biosecurity research, biological risk analysis, pathogen-related analysis, dual-use research concern, synthetic biology-related analysis, public health security analysis, or biosecurity-sensitive publication shall receive heightened legal, ethics, biosafety, biosecurity, public authority, export-control, sanctions, controlled technology, public-safe publication, and information hazard review where applicable.

430.5.2 The Corporation shall restrict, redact, delay, withhold, or control access to biosecurity-sensitive materials where publication or dissemination could create misuse, public safety, public health, or security risk.

430.6 Youth, Vulnerable Population, Health-Sensitive, and Rights-Bearing Research Compliance.

430.6.1 Research involving youth, vulnerable populations, health-sensitive data, rights-bearing data, affected communities, displaced persons, marginalized communities, protected classes, public authority-dependent persons, or persons facing retaliation risk shall receive heightened review for consent, assent where applicable, permission, minimization, confidentiality, risk mitigation, accessibility, non-coercion, non-retaliation, withdrawal, correction, grievance, and public-safe publication.

430.7 Community Review Where Appropriate.

430.7.1 Community review shall be used where research, evidence, mapping, observability, AI analysis, publication, dashboarding, or public authority learning materially affects a community, relies on community-provided information, represents local conditions, or may create stigma, targeting, extraction, misinterpretation, or harm.

430.7.2 Community review shall be structured to respect local context, avoid tokenism, protect dissent, preserve non-attribution where appropriate, and provide correction and grievance pathways.

430.8 Tribal and Indigenous Protocol Compliance Where Applicable.

430.8.1 Tribal and Indigenous protocol compliance shall be required where research, data, knowledge, mapping, observability, publication, AI processing, training, embedding, translation, transfer, or public authority interface involves Tribal / Indigenous governments, communities, data, knowledge, lands, waters, cultural resources, environmental knowledge, ecological knowledge, sacred knowledge, or protected knowledge.

430.8.2 Such compliance shall respect sovereignty, governance, permission, protocols, consultation where applicable, consent or non-consent, attribution or non-attribution, withdrawal, restriction, correction, grievance pathways, and public-safe mapping.

430.9 Indigenous Data and Indigenous Knowledge Safeguards Compliance.

430.9.1 Indigenous data and Indigenous knowledge safeguards shall prevent unauthorized access, extraction, publication, mapping, translation, AI processing, training, embedding, transfer, commercialization, or reuse.

430.9.2 The Corporation shall not assume that technical access, public availability, prior publication, academic citation, or third-party possession authorizes use inconsistent with Indigenous data or knowledge safeguards.

430.10 Local, Territorial, Cultural, Environmental, and Protected Knowledge Safeguards Compliance.

430.10.1 Local, territorial, cultural, environmental, and protected knowledge safeguards shall apply where information concerns local practices, cultural resources, sacred or sensitive sites, ecological knowledge, environmental conditions, community vulnerabilities, infrastructure vulnerabilities, disaster vulnerabilities, or place-based knowledge that could be misused, appropriated, stigmatized, or harmfully disclosed.

430.10.2 Such materials shall be reviewed for public-safe mapping, attribution, non-attribution, access class, AI-use restrictions, publication restrictions, transfer restrictions, and correction.

430.11.1 The Corporation shall maintain processes for consent where required, non-consent where applicable, attribution where authorized, non-attribution where required or appropriate, withdrawal where available, restriction, correction, grievance, and remedy in research, community engagement, protected knowledge, human-subjects, public authority data, and rights-bearing data activities.

430.11.2 Withdrawal or restriction requests shall be reviewed promptly and honored where required by law, protocol, consent terms, contract, ethics approval, public-safe review, or policy.

430.12 Public-Safe Mapping Compliance.

430.12.1 Public-safe mapping compliance shall require review of maps, dashboards, geospatial layers, digital twins, public-safe visualizations, AI-generated maps, sensor-derived maps, infrastructure maps, cyber maps, public health maps, community maps, Tribal / Indigenous maps, environmental maps, and risk maps before publication or external sharing.

430.12.2 Review shall address re-identification, targeting, infrastructure exposure, cyber exposure, protected knowledge exposure, community stigma, public warning confusion, emergency command confusion, public authority overclaim, and false precision.

430.13 Research Misconduct Review Compliance.

430.13.1 Research misconduct allegations, including fabrication, falsification, plagiarism, source omission, unsupported confidence claim, suppression of material limitation, misleading public-safe summary, sponsor distortion, provider distortion, AI-generated fabrication, or technical truth misrepresentation, shall be reviewed under the Corporation’s research integrity, evidence challenge, correction, and enforcement procedures.

430.13.2 Review may require investigation, interim measures, publication hold, dataset hold, repository hold, method hold, correction, supersession, withdrawal, retraction, suspension, termination, referral, or public clarification.

430.14 Sponsored Research Independence Compliance.

430.14.1 Sponsored research shall preserve independence of research agenda, evidence conclusions, methods, publication review, correction decisions, data classification, public authority boundaries, finance boundaries, and public-safe framing.

430.14.2 Sponsors, donors, funders, providers, hosts, public authorities, capital actors, national companies, Project SPVs, or enterprise actors shall not control findings, suppress limitations, purchase favorable conclusions, dictate recognition, create finance-readiness, obtain procurement advantage, or prevent necessary correction.

430.15 Publication Integrity Compliance.

430.15.1 Publication Integrity Compliance shall require that research publications, evidence packs, method notes, dashboards, maps, datasets, software releases, technical baselines, public-safe summaries, Academy materials, public authority learning materials, and media materials be substantiated, reviewed, limitation-aware, public-safe, access-classified where appropriate, corrected where necessary, and free of fabrication, falsification, plagiarism, misleading omission, overclaim, sponsor distortion, provider distortion, public authority overclaim, finance overclaim, certification overclaim, recognition overclaim, procurement overclaim, public warning implication, or emergency command implication.

430.16 Research Ethics and Protected Knowledge Compliance Records.

430.16.1 The Corporation shall maintain Research Ethics and Protected Knowledge Compliance Records, including research ethics compliance records, human-subjects review compliance records, Institutional Review Board or equivalent review records where required, public health research compliance records where applicable, biosecurity research compliance records where applicable, youth / vulnerable population / health-sensitive / rights-bearing research compliance records, community review records where appropriate, Tribal and Indigenous protocol compliance records where applicable, Indigenous data and Indigenous knowledge safeguards compliance records, local / territorial / cultural / environmental / protected knowledge safeguards compliance records, consent / non-consent / attribution / withdrawal / restriction / correction / grievance / remedy compliance records, public-safe mapping compliance records, research misconduct review compliance records, sponsored research independence compliance records, publication integrity compliance records, corrective actions, restrictions, holds, referrals, and archive records.

Section 431. Employment, Contractor, Volunteer, Fellow, Advisor, Workplace, Safety, Civil Rights, Accessibility, and Non-Discrimination Compliance

431.1 Employment Compliance.

431.1.1 The Corporation shall comply with applicable employment laws governing employees, officers who are employees, temporary employees, part-time employees, remote employees, hybrid employees, and any other personnel treated as employees under applicable law.

431.1.2 Employment Compliance shall include lawful hiring, onboarding, supervision, compensation, payroll, tax withholding, benefits administration where applicable, workplace policies, anti-harassment controls, anti-discrimination controls, accessibility, reasonable accommodation where applicable, workplace safety, protected participation, non-retaliation, confidentiality, intellectual property, data protection, AI-use duties, cybersecurity duties, public-safe claims duties, disciplinary procedures, separation, and offboarding.

431.1.3 No person shall be treated as outside employment compliance merely because the person works remotely, works across state or territorial lines, works in a technical role, works on a fellowship-like basis, participates in a public-good program, contributes to a repository, receives grant-funded compensation, or performs work through a hybrid institutional arrangement.

431.2 Contractor Classification Compliance.

431.2.1 The Corporation shall classify contractors, consultants, professional service providers, technical contributors, maintainers, researchers, writers, developers, reviewers, advisors, and other non-employee personnel according to applicable law, contract, tax requirements, labor standards, and the actual substance of the relationship.

431.2.2 Contractor Classification Compliance shall require review of control, independence, economic dependence, work integration, duration, exclusivity, tools, supervision, deliverables, payment method, confidentiality duties, IP terms, data access, public authority exposure, repository access, and whether the role should lawfully be treated as employment.

431.2.3 No contractor designation shall be used to avoid wage, hour, tax, benefits, workplace, safety, civil rights, accessibility, anti-harassment, non-retaliation, data, AI, cybersecurity, confidentiality, or IP obligations where applicable law requires employee or worker treatment.

431.3 Volunteer Compliance.

431.3.1 The Corporation may permit volunteers to support lawful public-benefit activities where volunteer participation is consistent with nonprofit law, labor law, workplace law, tax law, insurance requirements, safeguarding requirements, and the Corporation’s public-good mission.

431.3.2 Volunteer roles shall be documented by role, scope, access, duties, supervision, confidentiality, IP treatment, data access, AI-use restrictions, cybersecurity obligations, public-safe claims restrictions, conflict disclosure, safety requirements, non-retaliation protections, and termination or withdrawal procedures.

431.3.3 Volunteer status shall not be used to obtain uncompensated labor for commercial execution, enterprise stack delivery, sponsor benefit, provider benefit, procurement advantage, finance-facing activity, regulated activity, or work that applicable law requires to be compensated.

431.4 Fellow, Advisor, Intern, Visiting Researcher, and Seconded Personnel Compliance.

431.4.1 Fellows, advisors, interns, visiting researchers, seconded personnel, externs, scholars-in-residence, technical residents, policy residents, and analogous participants shall be governed by written terms appropriate to role, duration, supervision, compensation where applicable, institutional affiliation, deliverables, access, confidentiality, IP, publication rights, conflicts, data, AI, cybersecurity, public-safe claims, and offboarding.

431.4.2 Fellow, Advisor, Intern, Visiting Researcher, and Seconded Personnel Compliance shall preserve the distinction among learning participation, advisory participation, research participation, employment, contractor service, institutional representation, public authority participation, and enterprise stack participation.

431.4.3 No fellowship, advisory appointment, internship, visiting role, or secondment shall confer authority to bind the Corporation, speak for the Corporation, approve publications, access restricted data, alter technical baselines, represent public authority participation, issue finance-readiness, issue recognition, certify, approve procurement, or make public-safe claims except within recorded authority.

431.5 Workplace Policy Compliance.

431.5.1 The Corporation shall maintain workplace policies appropriate to its nonprofit public-good technical role, including policies addressing conduct, anti-harassment, anti-discrimination, accessibility, reasonable accommodation where applicable, conflicts, confidentiality, IP, data governance, AI use, cybersecurity, public-safe publication, public authority interactions, finance boundaries, procurement neutrality, professional boundaries, remote work, travel, expenses, gifts, safety, incident reporting, and offboarding.

431.5.2 Workplace policies shall apply to employees and, where appropriate, contractors, volunteers, fellows, advisors, interns, visiting researchers, seconded personnel, contributors, maintainers, reviewers, committee participants, council participants, and controlled-room participants.

431.6 Wage, Hour, Payroll, Benefits, and Tax Compliance Where Applicable.

431.6.1 The Corporation shall comply with wage, hour, overtime, minimum wage, pay frequency, payroll tax, withholding, benefits, leave, unemployment, workers’ compensation, contractor reporting, expense reimbursement, and tax reporting obligations where applicable.

431.6.2 Payroll and compensation practices shall be documented, authorized, non-discriminatory, consistent with nonprofit and tax obligations, and subject to conflict review where insiders, related persons, directors, officers, fellows, contractors, or sponsored personnel are involved.

431.7 Workplace Safety Compliance.

431.7.1 The Corporation shall maintain workplace safety compliance for physical, remote, hybrid, event-based, travel-based, laboratory-adjacent, fieldwork, controlled-room, public authority, community, technical, cybersecurity, and digital work environments.

431.7.2 Workplace Safety Compliance shall address physical safety, psychological safety, harassment prevention, emergency procedures, fieldwork risks, travel risks, event risks, data security risks, cyber safety, doxxing or retaliation risks, vulnerable participant risks, public authority interface risks, and protected knowledge risks.

431.7.3 No person shall be required to participate in unsafe work, coercive work, retaliatory work, unlawful surveillance, unauthorized public exposure, unsafe fieldwork, unsafe public authority engagement, or uncontrolled handling of sensitive materials.

431.8 Anti-Harassment Compliance.

431.8.1 The Corporation shall prohibit harassment, sexual harassment, discriminatory harassment, bullying, intimidation, coercion, retaliation, hostile conduct, abusive conduct, and misuse of authority in all workplace, digital, repository, controlled-room, research, fellowship, council, committee, public authority, event, travel, community, and partner environments.

431.8.2 Anti-Harassment Compliance shall include reporting pathways, protected reporting, prompt review, interim measures where appropriate, confidentiality to the extent lawful and practical, non-retaliation, corrective action, training, and records.

431.9 Anti-Discrimination Compliance.

431.9.1 The Corporation shall prohibit unlawful discrimination in hiring, assignment, compensation, promotion, supervision, discipline, termination, participation, fellowship selection, volunteer engagement, committee access, council access, controlled-room admission, training, publication opportunity, repository access, public authority learning, and program participation.

431.9.2 Anti-Discrimination Compliance shall cover protected characteristics under applicable law and shall be interpreted consistently with the Corporation’s civil rights, accessibility, public-benefit, community safeguards, and non-retaliation obligations.

431.10 Civil Rights Compliance.

431.10.1 The Corporation shall comply with applicable civil rights laws and shall structure programs, publications, datasets, AI systems, dashboards, maps, training, fellowships, community interfaces, public authority learning, and technical assets to avoid unlawful discrimination, exclusion, disparate treatment, retaliation, coercive participation, inaccessible participation, or harmful public-safe outputs.

431.10.2 Civil Rights Compliance shall include civil rights review where activities may materially affect protected classes, vulnerable communities, rights-bearing persons, public authority services, infrastructure access, public health, emergency management, housing, education, employment, or public-safe mapping.

431.11 Accessibility Compliance.

431.11.1 The Corporation shall comply with applicable accessibility laws and shall use reasonable accessibility practices in governance instruments, digital channels, public-facing publications, training, events, meetings, fellowships, controlled participation, dashboards, maps, software documentation, public authority learning materials, and communications.

431.11.2 Accessibility Compliance shall include accessible formats, reasonable digital accessibility, event accessibility, disability access, language access where appropriate, plain-language summaries where appropriate, and accessible correction pathways.

431.12 Reasonable Accommodation Process Where Applicable.

431.12.1 The Corporation shall maintain a reasonable accommodation process where applicable for employees, applicants, fellows, interns, volunteers, participants, event attendees, and other covered persons.

431.12.2 The accommodation process shall be timely, interactive where required, confidential to the extent lawful and practical, documented, non-retaliatory, and designed to preserve meaningful participation without compromising essential safety, data, AI, cyber, confidentiality, public authority, or protected knowledge safeguards.

431.13 Whistleblowing, Protected Participation, and Non-Retaliation Compliance.

431.13.1 The Corporation shall protect good-faith reporting, whistleblowing, protected participation, dissent, challenge, correction requests, ethics complaints, privacy complaints, cybersecurity reports, research integrity reports, public authority boundary concerns, finance-boundary concerns, procurement concerns, harassment reports, discrimination reports, civil rights concerns, accessibility concerns, sanctions concerns, export-control concerns, and professional boundary concerns.

431.13.2 Retaliation is prohibited against any person who reports, refuses unlawful conduct, participates in an investigation, requests correction, raises a challenge, invokes stop-authority, identifies protected knowledge risk, or objects to overclaim in good faith.

431.14 Confidentiality, IP, Data, AI, Cyber, and Public-Safe Claims Terms for Personnel.

431.14.1 Personnel terms shall require confidentiality, IP assignment or licensing where appropriate, data protection, AI-use restrictions, cybersecurity compliance, repository security, controlled-room compliance, export-control compliance where applicable, sanctions compliance where applicable, public authority boundary compliance, finance boundary compliance, certification boundary compliance, procurement neutrality, recognition boundary compliance, professional boundary compliance, and public-safe claims discipline.

431.14.2 Personnel shall not use Corporation data, technical assets, models, repositories, proof receipts, public authority interfaces, protected knowledge, or publications for unauthorized personal, commercial, sponsor, provider, political, financial, research, AI-training, or external purposes.

431.15 Offboarding and Access Revocation Compliance.

431.15.1 The Corporation shall maintain offboarding procedures for employees, contractors, volunteers, fellows, advisors, interns, visiting researchers, seconded personnel, contributors, maintainers, reviewers, committee members, council participants, controlled-room participants, and any other person with institutional access.

431.15.2 Offboarding shall include role termination, access revocation, repository access removal, credential revocation, key and token rotation where appropriate, device and document return where applicable, confidentiality reminder, IP and work-product confirmation, records transfer, controlled-room exit, public representation update, publication authority termination, and conflict or restriction continuation where applicable.

431.16 Personnel Compliance Records.

431.16.1 The Corporation shall maintain Personnel Compliance Records, including employment compliance records, contractor classification records, volunteer records, fellow / advisor / intern / visiting researcher / seconded personnel records, workplace policy records, wage / hour / payroll / benefits / tax records where applicable, workplace safety records, anti-harassment records, anti-discrimination records, civil rights records, accessibility records, reasonable accommodation records where applicable, whistleblowing / protected participation / non-retaliation records, confidentiality / IP / data / AI / cyber / public-safe claims terms, offboarding and access revocation records, complaints, investigations, corrective actions, training records, and archive records.


Section 432. Lobbying, Political Activity, Government Ethics, Gifts, Procurement Integrity, Public Grants, and Public-Sector Compliance

432.1 Lobbying Compliance Purpose.

432.1.1 Lobbying Compliance shall ensure that any communication, meeting, testimony, submission, policy discussion, public authority learning activity, legislative engagement, regulatory engagement, grant engagement, public finance engagement, procurement-adjacent engagement, or public-sector communication involving the Corporation is reviewed and classified according to applicable lobbying, nonprofit, tax, government ethics, procurement integrity, public records, public finance, and public authority boundary requirements.

432.1.2 The Corporation may engage in nonpartisan research, education, public authority learning, technical literacy, evidence literacy, public-benefit communication, and lawful policy participation within its mission, but shall not engage in prohibited political campaign activity, unregistered lobbying where registration is required, public authority substitution, procurement influence, public finance approval, or partisan activity inconsistent with law or tax status.

432.2 Federal Lobbying Review Where Applicable.

432.2.1 Federal lobbying review shall be required where communications with federal legislative, executive, regulatory, grant, public finance, procurement, oversight, or public authority actors may constitute lobbying, reportable lobbying contacts, covered advocacy, grant-influencing activity, or other regulated activity.

432.2.2 Review shall identify communicator, public authority, subject matter, purpose, requested action, funding source, tax implications, registration implications, reporting implications, nonpartisan status, and required records.

432.3 State Lobbying Review Where Applicable.

432.3.1 State lobbying review shall be required where state-level communications, meetings, testimony, comments, public authority learning, public finance discussions, procurement-related discussions, grant-related discussions, or policy communications may trigger state lobbying, ethics, gift, procurement, campaign, reporting, or registration rules.

432.4 Territorial and Local Lobbying Review Where Applicable.

432.4.1 Territorial and local lobbying review shall be required where District of Columbia, territorial, county, municipal, metropolitan, utility, port, public health, emergency management, public safety, public works, school, transit, housing, water, energy, telecom, cyber, infrastructure, or local public authority communications may trigger local lobbying, ethics, registration, reporting, procurement, public records, or public meeting requirements.

432.5 Lobbying Registration Review.

432.5.1 The Corporation shall assess whether lobbying registration, reporting, disclosure, expenditure tracking, client identification, grassroots reporting, gift reporting, public official communication reporting, or other filings are required before engaging in covered activity.

432.5.2 No person shall avoid lobbying registration review by describing lobbying-adjacent conduct as education, technical briefing, public authority learning, partnership development, public-good coordination, evidence sharing, or Nexus outreach where applicable law treats the conduct as lobbying or reportable activity.

432.6 Political Campaign Activity Controls.

432.6.1 The Corporation shall not participate or intervene in any political campaign on behalf of, or in opposition to, any candidate for public office where prohibited by applicable law or tax status.

432.6.2 Political Campaign Activity Controls shall prohibit use of Corporation funds, staff time, technical assets, publications, digital channels, events, datasets, public authority learning surfaces, controlled rooms, donor communications, or Nexus name references for prohibited campaign intervention.

432.6.3 Nonpartisan voter education, civic education, public-benefit research, and policy analysis may occur only where lawful, nonpartisan, mission-consistent, records-based, and reviewed for tax, lobbying, public authority, and reputational boundaries.

432.7 Nonpartisan Research, Education, Public Authority Learning, and Public-Benefit Communication Controls.

432.7.1 Nonpartisan research, education, public authority learning, and public-benefit communication shall be evidence-based, balanced where appropriate, public-safe, non-misleading, mission-consistent, and not designed as disguised lobbying, campaign intervention, procurement support, finance approval, regulatory direction, or public authority substitution.

432.7.2 Such activities shall preserve GCRI US as an evidence, methods, observability, ontology, public-good R&D, public-good software, and technical truth steward and shall not imply that the Corporation has recognition authority, finance-readiness authority, certification authority, procurement authority, regulatory authority, public warning authority, or emergency command authority.

432.8 Government Ethics Compliance.

432.8.1 The Corporation shall comply with applicable government ethics rules in interactions with public officials, public employees, regulators, procurement officials, grant officials, public finance officials, public university personnel, public laboratory personnel, public infrastructure operators, emergency management personnel, public health personnel, public safety personnel, and other public-sector actors.

432.8.2 Government Ethics Compliance shall address gifts, meals, travel, honoraria, sponsored attendance, speaking invitations, advisory participation, employment discussions, revolving-door considerations, procurement integrity, conflicts of interest, public records, public sector confidentiality, and capacity classification.

432.9 Public Official Gift, Travel, Honoraria, and Hospitality Controls.

432.9.1 The Corporation shall not provide gifts, meals, travel, lodging, honoraria, event access, sponsored attendance, hospitality, benefits, or anything of value to public officials or public employees except where lawful, permitted by applicable ethics rules, reasonable, documented, non-corrupt, non-procurement-related unless lawfully allowed, and approved where required.

432.9.2 Public official benefit controls shall be applied conservatively where procurement, grants, public finance, regulation, public authority data, public warning, emergency management, public health, public safety, or official capacity participation is involved.

432.10 Procurement Integrity Compliance.

432.10.1 The Corporation shall preserve procurement neutrality and shall not act as a public procurement authority, vendor selector, bid evaluator, preferred provider list operator, procurement scoring body, public tender designer for provider advantage, or procurement approval body.

432.10.2 Procurement Integrity Compliance shall prohibit improper access to procurement-sensitive information, improper influence over public tender specifications, improper steering toward sponsors or providers, use of Nexus participation as public tender advantage, and any statement implying that GCRI US approval, technical baseline, evidence review, public authority learning, or public-good software use creates procurement eligibility.

432.11 Public Grant Compliance.

432.11.1 Public Grant Compliance shall require that public grants, public funding, cooperative agreements, subawards, public support, public authority contributions, and government-funded programs be reviewed for eligibility, use restrictions, reporting, audit, records, lobbying restrictions, procurement restrictions, conflicts, cost allowability, publication terms, data rights, IP rights, public authority references, and non-execution boundaries.

432.11.2 Public grant acceptance shall not create public authority delegation, public finance approval, sovereign obligation, procurement authority, recognition, finance-readiness, certification, public warning authority, emergency command authority, or provider preference.

432.12 Cooperative Agreement Compliance.

432.12.1 Cooperative agreements with public authorities or public-sector actors shall define role, scope, authority, records, data, IP, publication, confidentiality, public records, public authority references, reporting, audit, termination, correction, and non-execution boundaries.

432.12.2 Cooperative Agreement Compliance shall prevent public authority capture, sponsor capture, provider preference, procurement implication, regulatory implication, finance implication, public warning implication, emergency command implication, and public-private partnership implication unless separately and lawfully recorded.

432.13 Public Records, FOIA, Sunshine, Open Meetings, and Public-Sector Confidentiality Considerations.

432.13.1 The Corporation shall review public records, FOIA, sunshine, open meetings, public-sector confidentiality, public authority data, privilege, trade secret, procurement-sensitive, cyber-sensitive, infrastructure-sensitive, personal, health-sensitive, community-protected, Tribal / Indigenous, and protected knowledge considerations where public authorities participate, provide data, attend rooms, review materials, fund programs, or are referenced in publications.

432.13.2 No person shall assume that Corporation records are public records except where law requires, and no person shall assume that public authority involvement authorizes disclosure of sensitive, confidential, privileged, protected, or restricted Corporation records.

432.14 Public Authority Capacity Classification Compliance.

432.14.1 Public Authority Capacity Classification Compliance shall require classification of public authority participants as official participants, institutional representatives, delegated representatives, observers, regulator-listening participants, public finance readers, emergency-management participants, public health participants, public safety participants, public infrastructure operator participants, public works participants, personal-capacity participants, non-attributable participants, data providers, reviewers, or other approved roles.

432.14.2 Capacity classification shall control access, attribution, public references, name use, logo use, quote use, publication language, data contribution statements, confidentiality, public records considerations, and correction duties.

432.15 Public Authority Reference Compliance.

432.15.1 Public Authority Reference Compliance shall require approval before using public authority names, logos, titles, quotes, attendance references, photographs, recordings, event references, data contribution statements, official capacity language, observer language, regulator-listening language, public finance reader language, or emergency learning language.

432.15.2 Public authority references shall not imply endorsement, adoption, funding approval, procurement approval, regulatory approval, public finance approval, sovereign obligation, public-private partnership, public warning, emergency command, recognition, finance-readiness, certification, provider preference, or official decision unless competent public authority record expressly supports the statement.

432.16 Lobbying, Political Activity, Government Ethics, and Public-Sector Compliance Records.

432.16.1 The Corporation shall maintain Lobbying, Political Activity, Government Ethics, and Public-Sector Compliance Records, including lobbying compliance purpose records, federal lobbying review records where applicable, state lobbying review records where applicable, territorial and local lobbying review records where applicable, lobbying registration review records, political campaign activity control records, nonpartisan research / education / public authority learning / public-benefit communication records, government ethics compliance records, public official gift / travel / honoraria / hospitality records, procurement integrity compliance records, public grant compliance records, cooperative agreement compliance records, public records / FOIA / sunshine / open meetings / public-sector confidentiality consideration records, public authority capacity classification records, public authority reference compliance records, filings, disclosures, approvals, refusals, corrections, and archive records.


Section 433. Sanctions Screening and Restricted-Party Compliance

433.1 Sanctions Compliance Purpose.

433.1.1 Sanctions Compliance shall prevent the Corporation from engaging in prohibited dealings, support, transfers, access, payments, services, technology sharing, data sharing, software releases, controlled-room access, repository access, grant activity, sponsorship activity, donor activity, provider activity, or partnership activity involving restricted persons, restricted entities, restricted jurisdictions, blocked property, prohibited end uses, prohibited end users, sanctions evasion, or other sanctions-sensitive circumstances.

433.1.2 Sanctions Compliance shall apply to directors, officers, employees, fellows, advisors, volunteers, contributors, maintainers, reviewers, contractors, consultants, donors, sponsors, funders, providers, vendors, hosts, partners, public authorities, universities, laboratories, communities, civil society actors, media actors, controlled-room participants, repository participants, and other persons or entities where screening is required or appropriate.

433.2 Restricted-Party Screening.

433.2.1 Restricted-party screening shall be conducted where required or appropriate before accepting funds, entering contracts, granting access, sharing technology, sharing data, admitting controlled-room participants, onboarding vendors, permitting repository access, approving collaborations, transferring technical materials, or engaging in cross-border activity.

433.2.2 Screening shall consider applicable sanctions lists, restricted-party lists, denied-party lists, blocked-person lists, sectoral sanctions, ownership and control rules, public authority advisories, contractual restrictions, grant restrictions, export-control restrictions, and jurisdictional restrictions.

433.3 Donor Screening.

433.3.1 Donor Screening shall be conducted where required or appropriate for monetary donations, in-kind donations, restricted gifts, major gifts, anonymous gifts, foreign gifts, pass-through gifts, digital contributions, event support, and donor-advised or intermediary contributions.

433.3.2 Donor Screening shall evaluate sanctions, ownership and control, source of funds, restricted conditions, reputation risk, mission consistency, public authority implications, sponsor-control risk, private benefit risk, and whether acceptance could compromise public-good integrity.

433.4 Sponsor Screening.

433.4.1 Sponsor Screening shall be conducted before accepting sponsorship, program support, event support, technical support, cloud credits, data access, platform support, in-kind support, equipment, software, compute, telecommunications support, or public-facing sponsor affiliation.

433.4.2 Sponsor Screening shall include sanctions, restricted-party status, ownership and control, conflicts, sponsor influence risk, provider preference risk, procurement advantage risk, public authority access risk, data rights, AI-use restrictions, public claims, public-safe publication, and anti-capture controls.

433.5 Funder Screening.

433.5.1 Funder Screening shall apply to grantors, public funders, philanthropic funders, development funders, research funders, institutional funders, universities, laboratories, public authorities, foundations, and intermediaries.

433.5.2 Funder Screening shall evaluate sanctions, restrictions, eligibility, source of funds, reporting requirements, publication conditions, data conditions, IP conditions, lobbying restrictions, public authority boundaries, private benefit, sponsor-control risk, and compatibility with nonprofit and public-benefit purpose.

433.6 Provider, Vendor, Contractor, and Consultant Screening.

433.6.1 Providers, vendors, contractors, consultants, technology suppliers, cloud providers, AI providers, cybersecurity providers, repository providers, data processors, subprocessors, professional service providers, and outsourced service providers shall be screened where required or appropriate for sanctions, restricted-party status, ownership and control, cybersecurity risk, data protection risk, export-control risk, controlled technology risk, public authority restrictions, conflicts, and service criticality.

433.7 Host and Partner Screening.

433.7.1 Hosts and partners, including event hosts, program hosts, observatory hosts, controlled-room hosts, infrastructure hosts, data hosts, university hosts, laboratory hosts, community hosts, public authority hosts, and enterprise stack hosts, shall be screened where required or appropriate for sanctions, restricted-party status, ownership and control, authority, safeguards, public authority status, data rights, cybersecurity, conflicts, public-safe publication, and boundary risk.

433.8 Public Authority, University, Laboratory, Community, Civil Society, and Media Screening Where Appropriate.

433.8.1 Public authorities, universities, laboratories, communities, civil society organizations, media organizations, and analogous actors may be screened where legal, contractual, sanctions, export-control, public authority, funding, controlled-room, technology, data, or safeguards risks require review.

433.8.2 Screening shall be conducted in a manner that respects lawful engagement, public authority status, academic independence, media independence, community safeguards, Tribal / Indigenous protocols, protected knowledge, and non-discrimination obligations.

433.9 Director, Officer, Employee, Fellow, Advisor, Volunteer, Contributor, Maintainer, Reviewer, and Controlled-Room Participant Screening Where Appropriate.

433.9.1 Directors, officers, employees, fellows, advisors, volunteers, contributors, maintainers, reviewers, committee members, council participants, controlled-room participants, repository participants, and other persons may be screened where required or appropriate based on role, access, authority, export-control exposure, sanctions exposure, financial authority, public authority interface, data access, protected knowledge access, repository access, or controlled technology access.

433.9.2 Screening shall be proportionate, lawful, non-discriminatory, privacy-protective, and recorded.

433.10 Beneficial Owner and Control Screening Where Appropriate.

433.10.1 Beneficial owner and control screening shall be conducted where required or appropriate for donors, sponsors, funders, vendors, providers, partners, hosts, contractors, consultants, entities, intermediaries, and any actor whose ownership or control may create sanctions, export-control, corruption, foreign influence, public authority, data, procurement, or reputational risk.

433.10.2 The Corporation shall not rely solely on surface legal name where ownership, control, intermediary structure, nominee arrangement, parent-subsidiary relationship, affiliate relationship, or indirect control may be material.

433.11 Jurisdiction Screening.

433.11.1 Jurisdiction Screening shall evaluate whether a country, territory, region, public authority, legal regime, data location, cloud region, transfer destination, event location, repository access location, vendor location, or participant location creates sanctions, export-control, data transfer, controlled technology, security, public authority, or conflict-of-law risk.

433.12 Transaction Screening.

433.12.1 Transaction Screening shall apply to payments, reimbursements, grants, donations, sponsorships, contracts, licenses, technology transfers, data transfers, software access, repository access, controlled-room access, service delivery, equipment provision, cloud credits, compute support, and other exchanges where sanctions or restricted-party risk may exist.

433.13 Cross-Border Transfer Screening.

433.13.1 Cross-Border Transfer Screening shall be conducted before transferring or permitting access to data, technical materials, software, models, source code, cybersecurity materials, cryptographic materials, AI systems, geospatial materials, telecom materials, satellite or sensing materials, controlled technology, or protected knowledge across jurisdictions where sanctions, export-control, privacy, public authority, Indigenous, protected knowledge, or national security sensitivity may arise.

433.14 Ongoing Monitoring.

433.14.1 Sanctions and restricted-party compliance shall include ongoing monitoring proportionate to risk, including rescreening at renewal, payment, access grant, release, material change, ownership change, jurisdiction change, incident, adverse media, regulatory update, or other risk trigger.

433.15 Hit Resolution.

433.15.1 Potential screening hits shall be reviewed before proceeding with the affected relationship, transaction, access, transfer, or activity.

433.15.2 Hit resolution shall identify whether the hit is true, false positive, unresolved, ownership-related, control-related, jurisdiction-related, transaction-related, or requires legal review.

433.15.3 Unresolved material hits shall result in hold, refusal, restriction, escalation, or termination until resolved by competent authority.

433.16.1 Where sanctions or restricted-party risk is confirmed, unresolved, or materially credible, the Corporation may impose a hold, refuse funds, return funds where lawful and appropriate, deny access, restrict access, terminate a relationship, suspend a transaction, block transfer, quarantine materials, revoke credentials, freeze activity, or escalate to legal counsel or public authority where required.

433.16.2 No person shall continue activity in reliance on mission urgency, sponsor pressure, partner assurances, public authority interest, technical convenience, or prior relationship where sanctions compliance requires hold or refusal.

433.17 Sanctions Screening Records.

433.17.1 The Corporation shall maintain Sanctions Screening Records, including sanctions compliance purpose records, restricted-party screening records, donor screening records, sponsor screening records, funder screening records, provider / vendor / contractor / consultant screening records, host and partner screening records, public authority / university / laboratory / community / civil society / media screening records where appropriate, director / officer / employee / fellow / advisor / volunteer / contributor / maintainer / reviewer / controlled-room participant screening records where appropriate, beneficial owner and control screening records where appropriate, jurisdiction screening records, transaction screening records, cross-border transfer screening records, ongoing monitoring records, hit resolution records, hold / refusal / return / termination / legal escalation records, legal reviews, corrective actions, and archive records.


Section 434. Export Controls, Controlled Technology, Dual-Use, Cryptography, Cyber, Telecom, Geospatial, AI, Robotics, Drones, Quantum-Relevant Systems, and National Security Sensitivity Review

434.1 Export-Control Compliance Purpose.

434.1.1 Export-Control Compliance shall ensure that the Corporation’s research, software, source code, datasets, models, technical baselines, reference architectures, schemas, APIs, SDKs, cybersecurity materials, cryptographic materials, telecom materials, AI-RAN / O-RAN materials, geospatial materials, satellite materials, robotics materials, drone materials, sensing materials, cyber-physical systems materials, quantum-relevant materials, sovereign compute materials, HPC materials, semiconductor materials, advanced manufacturing materials, energy materials, biosecurity materials, critical infrastructure materials, controlled technology, and public-good technical assets are classified, accessed, transferred, published, and shared according to applicable export-control, sanctions, controlled technology, national security, public authority, contract, grant, and public-safe requirements.

434.1.2 Export-Control Compliance shall apply to physical exports, digital exports, deemed exports, remote access, foreign person access where applicable, public repository release, public-good software release, controlled-room access, cross-border transfer, cloud-region access, model access, technical assistance, training, publications, and technical discussions.

434.2 Controlled Technology Review.

434.2.1 Controlled Technology Review shall identify whether technical data, software, models, source code, algorithms, designs, specifications, hardware, systems, prototypes, methods, datasets, telemetry, test harnesses, benchmark libraries, cryptographic materials, cybersecurity details, infrastructure details, telecom details, geospatial details, robotics details, drone details, quantum-relevant materials, biosecurity materials, or critical infrastructure materials are subject to control or heightened sensitivity.

434.2.2 Controlled technology shall be classified, access-controlled, transfer-controlled, publication-reviewed, repository-restricted, and corrected or withdrawn where improper disclosure occurs.

434.3 Dual-Use Technology Review.

434.3.1 Dual-Use Technology Review shall apply where materials, methods, models, data, tools, software, systems, or technical guidance may have both public-benefit and harmful, military, surveillance, cyber-offensive, coercive, biosecurity-sensitive, infrastructure-disruptive, or national security-sensitive uses.

434.3.2 Dual-use review may require redaction, controlled access, delay, segmentation, public-safe summary, legal review, public authority consultation where appropriate, denial of release, or controlled-room handling.

434.4 Cryptography Review.

434.4.1 Cryptography Review shall apply to encryption software, cryptographic protocols, signing systems, key-management systems, secure communications, identity systems, proof receipts, ledger systems, blockchain components, smart licenses, credential systems, and cybersecurity tools involving cryptographic functions.

434.4.2 Review shall address export controls, public release permissions, repository access, key custody, algorithm selection, vulnerability exposure, public-safe documentation, and whether cryptographic materials may be safely published or shared.

434.5 Cybersecurity Technology Review.

434.5.1 Cybersecurity Technology Review shall apply to vulnerability information, exploit-relevant materials, red-team outputs, penetration testing materials, malware analysis, incident artifacts, threat intelligence, detection rules, security tools, repository security tools, telemetry, infrastructure-sensitive details, and cyber-sensitive datasets.

434.5.2 Cybersecurity materials shall not be published, transferred, mapped, demonstrated, or released in a manner that enables harm, exploitation, targeting, evasion, or compromise of systems, public authorities, critical infrastructure, communities, or protected persons.

434.6 Telecom, AI-RAN, O-RAN, and Mission-Critical Connectivity Review.

434.6.1 Telecom, AI-RAN, O-RAN, and Mission-Critical Connectivity Review shall apply to materials involving radio access networks, private wireless, open radio access networks, edge compute, network automation, spectrum-related systems, network slicing, telecom orchestration, mission-critical communications, public safety communications, energy communications, water communications, port communications, transportation communications, and related resilience systems.

434.6.2 Review shall address export-control sensitivity, cyber sensitivity, infrastructure sensitivity, public authority sensitivity, provider neutrality, procurement neutrality, public-safe publication, national security sensitivity, and no operational command implication.

434.7 Geospatial, Earth Observation, Satellite, Remote Sensing, and Mapping Review.

434.7.1 Geospatial, Earth Observation, Satellite, Remote Sensing, and Mapping Review shall apply to maps, satellite imagery, remote sensing data, drone imagery, location data, infrastructure layers, sensitive site data, public health layers, disaster layers, border layers, port layers, energy layers, water layers, food layers, climate layers, environmental layers, Tribal / Indigenous lands, protected knowledge, and public-safe visualizations.

434.7.2 Review shall address export controls, national security sensitivity, infrastructure exposure, cyber exposure, re-identification risk, protected knowledge exposure, community harm, public-safe mapping, public warning confusion, and emergency command confusion.

434.8 AI, Machine Learning, Model, Dataset, Evaluation, and Compute Review.

434.8.1 AI, Machine Learning, Model, Dataset, Evaluation, and Compute Review shall apply to AI systems, foundation models, fine-tuned models, model weights, model artifacts, training datasets, evaluation datasets, benchmark sets, red-team results, prompts, system cards, model cards, dataset cards, inference records, compute workload records, embeddings, retrieval systems, model improvement workflows, and verifiable intelligence outputs.

434.8.2 Review shall address export controls, controlled technology, sensitive data, model capability, misuse potential, cyber risk, biosecurity risk, civil rights risk, public authority risk, public-safe publication, unauthorized training, and leakage.

434.9 Robotics, Drones, Autonomous Systems, Sensors, and Cyber-Physical Systems Review.

434.9.1 Robotics, Drones, Autonomous Systems, Sensors, and Cyber-Physical Systems Review shall apply to autonomous systems, robotic platforms, drone systems, sensor networks, edge sensing, cyber-physical systems, industrial control systems, digital twins, telemetry systems, actuation systems, and mission-critical automation.

434.9.2 Review shall address dual-use risk, public safety risk, infrastructure sensitivity, export controls, public authority boundaries, operational command boundaries, human oversight, AI controls, cyber risk, and public-safe release.

434.10 Quantum-Relevant Systems and Post-Quantum Readiness Review.

434.10.1 Quantum-Relevant Systems and Post-Quantum Readiness Review shall apply to quantum-adjacent methods, post-quantum cryptography, quantum-resilience planning, quantum-sensitive cryptographic migration, high-performance simulation, optimization methods, and technical materials that may materially affect cybersecurity, national security, critical infrastructure, or controlled technology.

434.11 Sovereign Compute and HPC Review.

434.11.1 Sovereign Compute and HPC Review shall apply to sovereign compute environments, high-performance computing systems, cloud compute, edge compute, secure enclaves, compute-to-data environments, AI compute, verifiable compute, public authority compute, controlled rooms, sensitive workloads, and cross-border compute access.

434.11.2 Review shall address jurisdiction, data localization, cross-border access, export controls, model access, workload records, proof receipts, cybersecurity, public authority restrictions, protected knowledge, and vendor controls.

434.12 Semiconductor, Advanced Manufacturing, Materials, Energy, Biosecurity, and Critical Infrastructure Technology Review.

434.12.1 Semiconductor, Advanced Manufacturing, Materials, Energy, Biosecurity, and Critical Infrastructure Technology Review shall apply to materials, methods, data, models, designs, processes, supply-chain information, infrastructure information, operational technology, industrial systems, energy systems, water systems, food systems, biosecurity-sensitive systems, and related technical assets.

434.12.2 Review shall address export-control status, dual-use status, national security sensitivity, critical infrastructure exposure, biosecurity information hazards, public-safe publication, public authority interface, and controlled-room handling.

434.13 Public-Good Software Release Review.

434.13.1 Public-Good Software Release Review shall be required before release of public-good software, open technical baselines, reference implementations, APIs, SDKs, schemas, technical profiles, dashboards, maps, test harnesses, proof receipt tools, evaluation harnesses, benchmark libraries, model tools, or repository materials where export-control, sanctions, cyber, privacy, controlled technology, public authority, protected knowledge, or public-safe risk may arise.

434.13.2 Release may be approved, delayed, restricted, redacted, segmented, licensed with restrictions, released in controlled form, or denied.

434.14 Cross-Border Data and Technical Transfer Review.

434.14.1 Cross-Border Data and Technical Transfer Review shall apply to transfer, access, publication, remote access, cloud replication, repository access, model access, technical assistance, training, or controlled-room participation involving data, software, technology, models, source code, technical materials, or protected knowledge across jurisdictions.

434.15 Foreign Person Access Review Where Applicable.

434.15.1 Foreign Person Access Review shall be conducted where applicable law, contract, grant, controlled technology classification, export-control rule, public authority restriction, national security sensitivity, or data classification requires review of access by non-U.S. persons, foreign persons, foreign entities, foreign-controlled entities, or persons in particular jurisdictions.

434.15.2 Review shall be lawful, non-discriminatory where required, classification-based, role-based, and limited to compliance requirements.

434.16 Controlled-Room and Repository Access Review.

434.16.1 Controlled-Room and Repository Access Review shall apply where access to controlled rooms, clean rooms, evidence rooms, data rooms, no-download rooms, restricted repositories, controlled repositories, technical baselines, source code, datasets, models, cybersecurity materials, protected knowledge, or public authority data may implicate export-control, sanctions, controlled technology, national security, privacy, or safeguards concerns.

434.17 National Security Sensitivity Escalation.

434.17.1 National Security Sensitivity Escalation shall be required where materials, systems, data, maps, telemetry, AI outputs, infrastructure information, cyber information, geospatial information, telecom information, biosecurity information, or controlled technology may create national security, public safety, critical infrastructure, foreign interference, or misuse risk.

434.17.2 Escalation may require legal review, technical review, public authority interface review, controlled access, publication hold, repository hold, redaction, transfer denial, or external referral where required or appropriate.

434.18 Export-Control and Controlled Technology Records.

434.18.1 The Corporation shall maintain Export-Control and Controlled Technology Records, including export-control compliance purpose records, controlled technology review records, dual-use technology review records, cryptography review records, cybersecurity technology review records, telecom / AI-RAN / O-RAN / mission-critical connectivity review records, geospatial / Earth observation / satellite / remote sensing / mapping review records, AI / machine learning / model / dataset / evaluation / compute review records, robotics / drones / autonomous systems / sensors / cyber-physical systems review records, quantum-relevant systems and post-quantum readiness review records, sovereign compute and HPC review records, semiconductor / advanced manufacturing / materials / energy / biosecurity / critical infrastructure technology review records, public-good software release review records, cross-border data and technical transfer review records, foreign person access review records where applicable, controlled-room and repository access review records, national security sensitivity escalation records, restrictions, approvals, denials, corrective actions, and archive records.


Section 435. Competition, Antitrust, Unfair Competition, Benchmarking, Data Sharing, Standards Support, and Clean-Room Compliance

435.1 Competition Compliance Purpose.

435.1.1 Competition Compliance shall ensure that the Corporation’s public-good work, committees, councils, forums, working groups, panels, labs, benchmarking, research consortia, data sharing, standards support, public authority learning, enterprise interfaces, sponsor interfaces, provider interfaces, technical baseline work, and Nexus coordination do not facilitate unlawful coordination, anticompetitive conduct, unfair competition, procurement steering, exclusionary conduct, collusion, or misuse of competitively sensitive information.

435.1.2 Competition Compliance shall preserve provider neutrality, sponsor non-control, open public-good integrity, procurement neutrality, non-exclusion, public authority boundary discipline, and lawful collaboration.

435.2 Federal Antitrust Compliance.

435.2.1 The Corporation shall comply with applicable federal antitrust laws and shall structure meetings, data sharing, benchmarking, standards support, public authority learning, provider engagement, sponsor engagement, and enterprise stack interfaces to avoid agreements, understandings, information exchanges, or conduct that may restrain competition unlawfully.

435.3 State Antitrust and Unfair Competition Compliance.

435.3.1 The Corporation shall comply with applicable state antitrust, unfair competition, consumer protection, procurement integrity, nonprofit, and market-conduct rules where its activities, participants, programs, publications, or interfaces create obligations.

435.4 Application to Committees, Councils, Forums, Working Groups, Panels, Labs, Benchmarking, Research Consortia, Data Sharing, Standards-Support, Public Authority Learning, and Enterprise Interfaces.

435.4.1 Competition Compliance shall apply to all Corporation-sponsored or Corporation-associated environments where competitors, providers, sponsors, vendors, operators, public authorities, utilities, infrastructure operators, universities, laboratories, consortiums, national companies, Project SPVs, capital actors, insurers, lenders, or enterprise stack actors may interact.

435.4.2 The existence of a public-good purpose, research purpose, standards-support purpose, public authority learning purpose, technical baseline purpose, or resilience purpose shall not excuse anticompetitive conduct.

435.5 Do-Not-Discuss Topics.

435.5.1 The Corporation shall maintain Do-Not-Discuss controls for competition-sensitive environments.

435.5.2 Do-Not-Discuss topics include: 435.5.2(a) current or future prices, fees, margins, discounts, rebates, costs, wages, compensation, benefits, or pricing strategy; 435.5.2(b) bids, bid strategy, bid timing, bid participation, tender strategy, procurement response, customer allocation, supplier allocation, territory allocation, or market allocation; 435.5.2(c) capacity plans, output restrictions, expansion plans, production limits, hiring limitations, boycotts, refusals to deal, exclusion strategies, or provider-suppression strategies; 435.5.2(d) non-public competitively sensitive business plans, customer lists, supplier terms, contract terms, pipeline information, proprietary cost data, trade secrets, or market-moving information; and 435.5.2(e) any agreement, understanding, signal, or coordinated strategy that could restrict competition, steer procurement, disadvantage non-participants, or create provider preference.

435.6 No Price, Margin, Cost, Bid, Wage, Customer, Supplier, Market Allocation, Capacity, Exclusion, Boycott, Procurement Steering, or Collusive Strategy.

435.6.1 The Corporation shall not permit any meeting, room, council, committee, working group, benchmark process, standards-support process, data-sharing process, or Nexus interface to be used for price coordination, margin coordination, cost coordination, bid coordination, wage coordination, customer allocation, supplier allocation, market allocation, capacity restriction, exclusion, boycott, procurement steering, provider preference, or collusive strategy.

435.7 Competitively Sensitive Information Controls.

435.7.1 Competitively sensitive information shall be identified, restricted, aggregated, delayed, de-identified, anonymized, controlled-roomed, clean-teamed, independently administered, or excluded as appropriate.

435.7.2 Competitively sensitive information shall not be shared merely because participants are mission-aligned, public-good-facing, sponsor-associated, public authority-adjacent, or participating in a Nexus room.

435.8 Aggregation, De-Identification, Delay, and Independent Administration.

435.8.1 Aggregation, de-identification, delay, and independent administration may be used to reduce competition risk in benchmarking, research, evidence work, standards support, and public authority learning.

435.8.2 Such controls shall be designed to prevent reconstruction of participant-specific competitively sensitive information, reverse engineering of current commercial strategy, or procurement steering.

435.9 Clean-Team Structures.

435.9.1 Clean-Team Structures may be used where competitively sensitive information must be reviewed for lawful public-good, research, benchmarking, evidence, or technical purposes.

435.9.2 Clean teams shall have defined membership, independence controls, confidentiality terms, permitted-use limits, prohibited-use limits, output review, no-download rules where appropriate, and records.

435.10 Clean-Room Structures.

435.10.1 Clean-Room Structures may be used where sensitive datasets, benchmark materials, provider data, sponsor data, public authority data, infrastructure data, or enterprise stack data must be processed without exposing raw or competitively sensitive information to unauthorized participants.

435.10.2 Clean rooms shall include charter, owner, custodian, admission criteria, data classes, competition controls, data / AI / cyber / privacy controls, output review, public-safe review, closeout, and correction path.

435.11 Agenda and Minutes Controls.

435.11.1 Meetings involving competition risk shall use agendas appropriate to the risk class, identify permitted topics, exclude prohibited topics, designate a chair or facilitator, record attendance, maintain minutes, and document any intervention, stop-meeting action, or corrective instruction.

435.11.2 Minutes shall be accurate, sufficiently specific to demonstrate lawful purpose, and not sanitized to conceal competition concerns.

435.12 Stop-Meeting Authority.

435.12.1 Any chair, officer, counsel, compliance lead, designated facilitator, or trained participant may invoke stop-meeting authority where prohibited topics, competitively sensitive exchanges, procurement steering, provider preference, exclusionary discussion, or collusive conduct arises or appears likely.

435.12.2 Stop-meeting authority may include warning, topic redirection, removal of materials, suspension of discussion, adjournment, legal escalation, incident report, or corrective notice.

435.12.3 Good-faith invocation of stop-meeting authority shall not be grounds for retaliation.

435.13 Benchmarking Controls.

435.13.1 Benchmarking shall be structured to avoid unlawful exchange of competitively sensitive information, current pricing, current costs, bid strategy, individualized market data, procurement positioning, or provider rankings that create anticompetitive effect.

435.13.2 Benchmarking outputs shall be public-good, evidence-based, limitation-aware, aggregated or delayed where appropriate, non-exclusionary, and not represented as certification, procurement approval, provider preference, finance-readiness, recognition, rating, or public authority decision.

435.14 Standards-Support Competition Controls.

435.14.1 Standards-support activities, technical baseline work, interoperability profiles, test harnesses, reference architectures, public-good software, schemas, APIs, SDKs, and compatibility discussions shall be conducted in a fair, open where appropriate, non-exclusionary, provider-neutral, sponsor-non-controlled, and competition-compliant manner.

435.14.2 Standards-support work shall not be used to exclude competitors, lock in sponsor technology, create procurement mandates, create closed capture of open interoperability commitments, or create false Nexus-compatible claims.

435.15 Provider Neutrality and Non-Exclusion.

435.15.1 Provider Neutrality shall require the Corporation to avoid preferential treatment, exclusion, procurement advantage, public authority access advantage, certification implication, recognition implication, finance-readiness implication, or public-good identity advantage for any provider, sponsor, vendor, contractor, national company, Project SPV, operator, host, or enterprise actor except where a lawful, objective, recorded, and non-discriminatory basis permits differential treatment.

435.16 Competition Incident Response.

435.16.1 Competition incidents shall be reported, triaged, contained, investigated, corrected, and recorded.

435.16.2 Remedies may include meeting suspension, minutes correction, participant warning, access restriction, clean-room redesign, data withdrawal, publication hold, benchmark hold, standards-support hold, legal review, public or controlled correction, training, termination, or referral where required.

435.17 Competition Training.

435.17.1 Directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, maintainers, committee members, council participants, working group participants, sponsors, providers, hosts, public authority participants, and enterprise stack participants shall receive competition training where their role presents competition risk.

435.17.2 Training shall cover prohibited topics, competitively sensitive information, meeting discipline, benchmarking controls, clean teams, clean rooms, provider neutrality, procurement neutrality, stop-meeting authority, and incident reporting.

435.18 Competition Compliance Records.

435.18.1 The Corporation shall maintain Competition Compliance Records, including competition compliance purpose records, federal antitrust compliance records, state antitrust and unfair competition compliance records, application records for committees / councils / forums / working groups / panels / labs / benchmarking / research consortia / data sharing / standards support / public authority learning / enterprise interfaces, Do-Not-Discuss topic records, no-price / margin / cost / bid / wage / customer / supplier / market allocation / capacity / exclusion / boycott / procurement steering / collusive strategy records, competitively sensitive information control records, aggregation / de-identification / delay / independent administration records, clean-team records, clean-room records, agenda and minutes control records, stop-meeting authority records, benchmarking control records, standards-support competition control records, provider neutrality and non-exclusion records, competition incident response records, competition training records, corrective actions, and archive records.


Section 436. Securities, Investment Adviser, Broker-Dealer, Finder, Banking, Lending, Insurance, Rating, Public Finance, and Regulated-Activity Boundary Compliance

436.1 Regulated Financial Activity Boundary Purpose.

436.1.1 Regulated Financial Activity Boundary Compliance shall preserve the Corporation’s non-executing public-good role and prevent the Corporation, its directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, maintainers, reviewers, committees, councils, working groups, publications, dashboards, maps, proof receipts, technical baselines, public authority learning materials, or Nexus coordination outputs from being used or represented as securities activity, investment advice, broker-dealer activity, finder activity, banking, lending, insurance, rating, public finance approval, capital execution, or other regulated financial activity.

436.1.2 The Corporation may support technical evidence, methods, public-good software, open technical baselines, observability, ontology, public authority learning, and correction signals that may be used by GRA or other lawful actors within their own boundaries, but the Corporation shall not make finance-readiness, capital-readability, insurance-readiness, investment, lending, rating, underwriting, public finance, or capital execution determinations.

436.2 No Securities Offering.

436.2.1 The Corporation shall not offer securities, solicit securities purchases, sell securities, structure securities as issuer or placement participant, prepare securities offering materials as issuer or placement participant, or use Nexus materials to create a securities offering by implication.

436.2.2 No Project SPV, national company, provider, sponsor, host, investor, funder, or capital actor shall use Corporation name, materials, evidence, proof receipts, technical baselines, dashboards, maps, public authority learning outputs, or publications as securities offering endorsement or approval.

436.3 No Securities Solicitation.

436.3.1 The Corporation shall not solicit investment, recommend investment, invite subscription, promote securities, market securities, circulate offering materials as placement actor, or encourage purchase or sale of securities.

436.3.2 Public-good publications, proof packs, evidence materials, or Nexus coordination outputs shall include non-reliance language where finance-facing reliance risk exists.

436.4 No Broker-Dealer Activity.

436.4.1 The Corporation shall not act as a broker, dealer, placement agent, underwriter, intermediary, market maker, exchange, trading venue, transaction arranger, or securities compensation recipient.

436.4.2 The Corporation shall not receive transaction-based compensation, success fees, placement fees, brokerage fees, underwriting fees, or compensation tied to securities transactions unless separately and lawfully authorized, and such authorization shall require Board approval and legal review.

436.5 No Finder Activity.

436.5.1 The Corporation shall not act as a finder, introduce investors for compensation, arrange capital meetings as transaction intermediary, facilitate securities transactions, or hold itself out as able to connect projects with capital for investment execution.

436.5.2 Capital-reader learning rooms, public-good evidence discussions, and GRA coordination shall not be structured as finder activity by GCRI US.

436.6 No Investment Adviser Activity.

436.6.1 The Corporation shall not provide investment advice, securities advice, asset allocation advice, portfolio advice, investment strategy, investment recommendations, manager selection, project investment recommendations, or advice concerning the value of securities or advisability of investing in, purchasing, selling, or holding securities.

436.7 No Investment Recommendation.

436.7.1 No Corporation output shall recommend investment in any company, Project SPV, fund, instrument, issuer, provider, sponsor, host, asset, technology, geography, sector, platform, or project.

436.7.2 Evidence quality, technical readiness, observability, proof receipts, public-good software, technical baselines, public authority learning, or public-safe reports shall not be represented as investment recommendation, endorsement, rating, bankability conclusion, or financeability determination.

436.8 No Asset Management or Portfolio Management.

436.8.1 The Corporation shall not manage assets, manage portfolios, exercise investment discretion, allocate capital, select investments, rebalance portfolios, custody assets, control investor funds, manage public funds, manage grant portfolios as investment manager, or operate funds.

436.9 No Banking, Deposit-Taking, Custody, Clearing, Settlement, Escrow, or Third-Party Fund Control.

436.9.1 The Corporation shall not engage in banking, deposit-taking, custody, clearing, settlement, escrow, third-party fund control, payment intermediation, money transmission, treasury management for others, or any equivalent regulated financial infrastructure role.

436.9.2 Corporation accounts shall be used only for the Corporation’s lawful nonprofit operations and not as pass-through accounts, escrow accounts, investment accounts, fund accounts, project treasury accounts, or public authority treasury accounts for others.

436.10 No Lending, Credit Origination, Credit Brokerage, Credit Approval, Debt Guarantee, Revenue Guarantee, or Performance Guarantee.

436.10.1 The Corporation shall not originate loans, broker credit, approve credit, recommend lenders, guarantee debt, guarantee revenues, guarantee technical performance, guarantee resilience outcomes, guarantee repayment, guarantee savings, or provide credit enhancement.

436.10.2 Evidence packs, proof receipts, readiness inputs, technical baselines, public-safe reports, dashboards, maps, or GRA-facing technical inputs shall not be described as credit approval or guarantee.

436.11 No Insurance Placement, Binding, Underwriting, Pricing, Claims Handling, or Approval.

436.11.1 The Corporation shall not place insurance, bind coverage, underwrite risk, price insurance, approve insurance, handle claims, adjust claims, recommend coverage, guarantee insurability, or act as insurance intermediary.

436.11.2 The Corporation may provide technical evidence or methods that may inform lawful insurance literacy or GRA insurance-readiness work, but shall not make insurance-readiness or insurability determinations.

436.12 No Rating, Credit Opinion, Investment Grade Opinion, Resilience Rating, Insurability Rating, Bankability Rating, or Financeability Determination.

436.12.1 The Corporation shall not issue ratings, credit opinions, investment grade opinions, resilience ratings, insurability ratings, bankability ratings, financeability determinations, creditworthiness determinations, issuer ratings, project ratings, or provider rankings.

436.12.2 Metrics, KPIs, evidence quality indicators, benchmark outputs, public-safe summaries, maturity inputs, observability outputs, and proof receipts shall not be represented as ratings or rating substitutes.

436.13 No Public Finance Approval, Grant Approval, Budget Allocation, Appropriation, Tax Credit Approval, MDB / DFI Approval, Public Guarantee, Public Credit, or Sovereign Obligation.

436.13.1 The Corporation shall not approve public finance, approve grants, allocate budgets, make appropriations, approve tax credits, approve MDB or DFI financing, issue public guarantees, issue public credit, create sovereign obligations, approve public-private partnerships, or represent that public authority funds are committed.

436.13.2 Public finance reader participation, public authority learning, public grant coordination, technical evidence, public-safe reports, or Nexus rooms shall not imply public finance approval or sovereign obligation.

436.14 GRA Role-Separation Compliance.

436.14.1 The Corporation shall preserve role separation with The Global Risks Alliance (GRA), which may steward capital-readability, finance-readiness, proof-pack, insurance-readiness, diligence-translation, and capital-reader functions within its own authority.

436.14.2 GCRI US technical evidence support, methods support, observability support, ontology support, public-good software support, technical baseline support, proof receipt support, or correction signals to GRA shall not become GCRI US finance-readiness, capital-readability, insurance-readiness, investment advice, rating, lending, underwriting, public finance, or capital execution authority.

436.14.3 GRA shall not control GCRI US evidence, methods, research findings, publication integrity, correction decisions, data classification, public authority boundaries, or public-safe publication.

436.15 Regulated-Activity Perimeter Review.

436.15.1 Regulated-Activity Perimeter Review shall be required where any activity, output, room, publication, proof pack, public authority interface, capital-reader interface, sponsor interface, provider interface, Project SPV interface, national company interface, dashboard, map, technical baseline, or public statement could reasonably be interpreted as regulated financial activity or finance-facing reliance material.

436.15.2 Review shall identify activity type, audience, compensation, reliance risk, regulated terms, public authority implications, GRA interface, disclaimers, required controls, and whether the activity must be held, re-scoped, externalized, referred, or terminated.

436.16 Hold, Re-Scope, Externalize, Refer, or Terminate.

436.16.1 Where regulated financial activity risk exists, the Corporation may hold, re-scope, externalize to a lawful actor, refer to GRA or qualified professionals, restrict access, revise language, cancel publication, withdraw materials, terminate a relationship, or prohibit the activity.

436.16.2 No business opportunity, sponsor request, provider request, public authority interest, capital actor interest, project urgency, or Nexus growth objective shall override the regulated-activity boundary.

436.17 Regulated-Activity Boundary Records.

436.17.1 The Corporation shall maintain Regulated-Activity Boundary Records, including regulated financial activity boundary purpose records, no-securities-offering records, no-securities-solicitation records, no-broker-dealer-activity records, no-finder-activity records, no-investment-adviser-activity records, no-investment-recommendation records, no-asset-management-or-portfolio-management records, no-banking / deposit-taking / custody / clearing / settlement / escrow / third-party-fund-control records, no-lending / credit-origination / credit-brokerage / credit-approval / debt-guarantee / revenue-guarantee / performance-guarantee records, no-insurance-placement / binding / underwriting / pricing / claims-handling / approval records, no-rating / credit-opinion / investment-grade-opinion / resilience-rating / insurability-rating / bankability-rating / financeability-determination records, no-public-finance-approval / grant-approval / budget-allocation / appropriation / tax-credit-approval / MDB / DFI-approval / public-guarantee / public-credit / sovereign-obligation records, GRA role-separation compliance records, regulated-activity perimeter review records, hold / re-scope / externalize / refer / terminate records, corrections, and archive records.


Section 437. Professional Boundary Compliance

437.1 Professional Boundary Purpose.

437.1.1 Professional Boundary Compliance shall preserve the Corporation’s role as a public-good evidence, methods, observability, ontology, public-good R&D, public-good software, open technical baseline, verifiable compute, verifiable intelligence, and public authority learning support institution, and shall prevent its outputs from being misused as licensed professional advice, regulated professional services, public authority determinations, finance determinations, certification determinations, procurement approvals, or operational commands.

437.1.2 Professional Boundary Compliance shall apply to publications, reports, technical notes, method notes, evidence packs, dashboards, maps, datasets, software, technical baselines, training, Academy materials, public authority learning materials, controlled rooms, consultations, meetings, AI outputs, proof receipts, public statements, and personnel communications.

437.2.1 The Corporation shall not provide legal advice by default, and no report, publication, technical baseline, evidence pack, public authority learning material, dashboard, map, AI output, proof receipt, training, meeting, or discussion shall be represented as legal advice, legal opinion, compliance approval, regulatory approval, legal risk clearance, or substitute for counsel.

437.2.2 Legal information or legal literacy materials may be provided only as general public-benefit education or institutional boundary support and shall include appropriate limitation language where reliance risk exists.

437.3 No Engineering Opinion by Default.

437.3.1 The Corporation shall not provide licensed engineering opinions, engineering certifications, safety certifications, design approvals, infrastructure approvals, structural approvals, operational approvals, or professional engineering seals by default.

437.3.2 Technical evidence, methods, reference architectures, observability outputs, AI-RAN / O-RAN profiles, digital twin outputs, cyber-physical systems materials, dashboards, maps, and technical baselines shall not be represented as engineering approval or substitute for licensed engineering review where required.

437.4 No Clinical, Medical, or Public Health Advice by Default.

437.4.1 The Corporation shall not provide clinical advice, medical advice, diagnosis, treatment instruction, public health order, emergency health direction, patient-specific guidance, clinical decision support as licensed provider, or substitute for public health authority.

437.4.2 Public health research, biosecurity analysis, health-sensitive evidence, dashboards, maps, observability outputs, AI outputs, or public-safe summaries shall not be represented as clinical guidance, public health order, official public warning, emergency command, or substitute for qualified medical or public health professionals.

437.5 No Accounting or Tax Advice by Default.

437.5.1 The Corporation shall not provide accounting advice, audit opinions, tax advice, tax opinions, tax credit approval, financial statement assurance, valuation opinions, or substitute for accountants, auditors, tax advisers, or public tax authorities.

437.5.2 Nonprofit compliance materials, grant materials, finance-boundary materials, public finance reader materials, and public-benefit education shall not be represented as tax, accounting, audit, or valuation advice.

437.6 No Investment, Insurance, Banking, Lending, Rating, or Public Finance Advice.

437.6.1 The Corporation shall not provide investment advice, insurance advice, banking advice, lending advice, rating advice, underwriting advice, public finance advice, municipal advisory services, capital allocation advice, project finance advice, or equivalent regulated professional advice.

437.6.2 Evidence, methods, proof receipts, GRA-facing technical inputs, capital-reader literacy materials, insurance-literacy materials, and public finance reader materials shall be limited to public-good technical support and shall not be used as recommendations, ratings, approvals, underwriting conclusions, or financeability determinations.

437.7 No Licensed Professional Service Unless Separately Authorized, Licensed, Contracted, Supervised, and Recorded.

437.7.1 The Corporation shall not provide any licensed professional service unless the service is separately authorized by the Board or competent delegated authority, lawful under applicable law, performed by appropriately licensed or qualified persons, contracted under appropriate terms, supervised where required, insured where required, and recorded.

437.7.2 Any such authorized professional service shall remain limited to its recorded scope and shall not expand the Corporation’s general role or convert public-good outputs into regulated advice.

437.8 Public-Good Research and Education Distinct From Professional Advice.

437.8.1 Public-good research, education, public authority learning, technical literacy, evidence literacy, methods support, observability support, and publication activity shall be distinguished from professional advice.

437.8.2 Such materials may improve understanding, comparability, preparedness, and evidence quality, but shall not direct a person or institution to take legal, medical, engineering, investment, tax, insurance, lending, procurement, regulatory, public health, emergency, or public finance action without independent professional or public authority review where required.

437.9 Technical Evidence Distinct From Professional Certification.

437.9.1 Technical evidence, proof receipts, compute records, inference records, observability outputs, benchmarks, test harnesses, model cards, dataset cards, system cards, technical baselines, reference architectures, dashboards, maps, and public-good software shall not constitute professional certification, engineering certification, cybersecurity certification, legal compliance certification, safety certification, procurement approval, public authority adoption, finance-readiness, recognition, rating, or guarantee.

437.10 Public Authority Learning Distinct From Public Authority Advice or Decision.

437.10.1 Public Authority Learning shall support evidence literacy, methods literacy, technical literacy, public-safe decision-support literacy, observability literacy, AI literacy, cyber literacy, resilience literacy, and public-good coordination.

437.10.2 Public Authority Learning shall not constitute official advice to a public authority, regulatory guidance, procurement recommendation, funding recommendation, public finance approval, public warning, emergency command, public health order, safety command, public authority decision, or substitution for public officials.

437.11 Required Disclaimers.

437.11.1 Required disclaimers, limitation statements, non-reliance language, boundary language, or public-safe interpretation language shall be used where materials, meetings, dashboards, maps, publications, technical baselines, proof receipts, or public authority learning outputs could reasonably be misread as professional advice, public authority decision, certification, finance-readiness, procurement approval, rating, public warning, emergency command, or legal compliance approval.

437.11.2 Disclaimers shall be accurate, visible where appropriate, proportionate to reliance risk, and consistent with the substance of the activity. Disclaimers shall not be used to legitimize conduct that should be prohibited, re-scoped, referred, or stopped.

437.12 Escalation to Qualified Professionals.

437.12.1 Where a matter requires legal, engineering, medical, public health, accounting, tax, investment, insurance, banking, lending, cybersecurity certification, public finance, procurement, regulatory, or other professional determination, the Corporation shall route, refer, or advise consultation with qualified professionals or competent public authorities as appropriate.

437.12.2 Escalation shall be recorded where the professional boundary risk is material.

437.13 Professional Boundary Incident Review.

437.13.1 Professional Boundary Incident Review shall be initiated where any person alleges or the Corporation identifies that a Corporation output, statement, meeting, publication, dashboard, map, proof receipt, technical baseline, public authority learning material, AI output, or personnel communication was used or could reasonably be understood as unauthorized professional advice or licensed professional service.

437.13.2 Review may result in correction, limitation language, retraction, withdrawal, publication hold, access restriction, personnel training, referral to qualified professionals, termination of unauthorized activity, public clarification, controlled clarification, or legal escalation.

437.14 Professional Boundary Records.

437.14.1 The Corporation shall maintain Professional Boundary Records, including professional boundary purpose records, no-legal-advice records, no-engineering-opinion records, no-clinical / medical / public-health-advice records, no-accounting-or-tax-advice records, no-investment / insurance / banking / lending / rating / public-finance-advice records, licensed professional service authorization records where applicable, public-good research and education distinction records, technical evidence distinction records, public authority learning distinction records, required disclaimer records, escalation-to-qualified-professionals records, professional boundary incident review records, corrections, referrals, clarifications, restrictions, and archive records.

Section 438. Contracts, Grants, Procurement-by-GCRI-US, Vendor, Insurance, Indemnity, and Risk-Transfer Compliance

438.1 Contract Compliance Purpose.

438.1.1 Contract Compliance shall ensure that every agreement, undertaking, commitment, grant, procurement, vendor relationship, sponsorship, donation arrangement, public authority instrument, technology instrument, data instrument, AI instrument, cybersecurity instrument, insurance instrument, indemnity undertaking, and risk-transfer arrangement entered into by or for GCRI US is lawful, authorized, mission-compatible, nonprofit-compatible, public-benefit-compatible, financially prudent, role-separated, records-based, and consistent with the Corporation’s non-executing public-good technical role.

438.1.2 Contract Compliance shall apply to all memoranda of understanding, letters of intent, term sheets, grants, cooperative agreements, public grants, private grants, sponsored research agreements, sponsorship agreements, donation agreements, restricted gift agreements, vendor agreements, technology agreements, cloud agreements, AI-provider agreements, cybersecurity agreements, data-processing agreements, data-sharing agreements, model-sharing agreements, software agreements, repository agreements, contributor agreements, maintainer agreements, license agreements, publication agreements, research agreements, controlled-room instruments, clean-room instruments, no-download room instruments, public authority interface agreements, consortium interface agreements, enterprise stack interface agreements, consulting agreements, employment-related agreements, contractor agreements, fellowship agreements, advisor agreements, event agreements, venue agreements, hosting agreements, insurance agreements, indemnity agreements, releases, waivers, settlements, and any other written or electronic instrument that creates, modifies, waives, or terminates obligations of the Corporation.

438.1.3 Contract Compliance shall preserve the Corporation’s public-good independence and shall prevent any contract from being used to: 438.1.3(a) collapse the public-good stack and enterprise stack; 438.1.3(b) convert GCRI US into an enterprise execution actor, project owner, public authority substitute, procurement authority, certification authority, recognition authority, finance-readiness authority, public warning authority, emergency command body, regulated financial actor, or provider-selection body; 438.1.3(c) transfer control over GCRI US evidence, methods, research agenda, observability outputs, ontology, public-good software, technical baselines, publications, public authority learning materials, or correction decisions to any sponsor, donor, provider, funder, host, public authority, national company, Project SPV, capital actor, or partner; or 438.1.3(d) create private inurement, impermissible private benefit, sponsor capture, provider preference, procurement advantage, finance-readiness implication, recognition implication, certification implication, public authority endorsement implication, or public-safe publication distortion.

438.2 Contract Authority Requirement.

438.2.1 No person may sign, approve, modify, extend, renew, terminate, waive, assign, novate, settle, interpret, or materially perform any contract on behalf of the Corporation unless authorized by these Bylaws, Board resolution, officer delegation, approved policy, written authority matrix, or other competent authority record.

438.2.2 Contract authority shall be interpreted narrowly by amount, subject matter, counterparty, term, jurisdiction, funding source, data exposure, AI exposure, cybersecurity exposure, IP exposure, public authority exposure, finance exposure, procurement exposure, recognition exposure, certification exposure, sanctions exposure, export-control exposure, controlled technology exposure, protected knowledge exposure, insurance exposure, indemnity exposure, and operational consequence.

438.2.3 Apparent authority shall not arise from title, email domain, participation in Nexus, public authority engagement, sponsor engagement, provider engagement, repository access, controlled-room access, meeting attendance, prior involvement, public statement, draft exchange, or use of GCRI US marks unless authority is supported by competent records.

438.2.4 Any contract executed without authority may be rejected, corrected, ratified, limited, suspended, terminated, or otherwise addressed by the Board or authorized officer, subject to applicable law, equity, reliance considerations, and institutional protection.

438.3 Contract Review Requirement.

438.3.1 Material contracts shall be reviewed before execution for legal authority, corporate authority, nonprofit compatibility, tax compatibility, public-benefit compatibility, mission alignment, financial prudence, conflict of interest, private benefit, sponsor control, provider neutrality, public authority boundary, finance boundary, procurement neutrality, recognition boundary, certification boundary, data governance, AI governance, cybersecurity, privacy, IP, confidentiality, insurance, indemnity, export-control, sanctions, controlled technology, competition, public-safe publication, protected knowledge, accessibility, civil rights, records retention, audit, termination, dispute resolution, and correctionability.

438.3.2 Review may be performed by an officer, counsel, compliance lead, finance lead, data steward, technology lead, research integrity lead, public authority boundary reviewer, safeguards reviewer, or other qualified reviewer according to risk class and approved authority.

438.3.3 Contracts involving public authorities, public grants, public finance readers, capital readers, GRA-facing proof-pack materials, GRF-facing recognition or standing inputs, Nexus Standards or protocol authority interfaces, controlled rooms, restricted data, health-sensitive data, public authority data, cyber-sensitive data, infrastructure-sensitive data, protected knowledge, export-controlled materials, controlled technology, or material indemnity shall receive heightened review before execution.

438.4 Board Approval for Material Contracts.

438.4.1 Board approval, or approval under a Board-approved delegation, shall be required for material contracts, including contracts that involve substantial financial obligations, unusual liability, material indemnity, long-term commitments, public authority interface risk, public grant obligations, cross-border obligations, high-risk data, AI systems, cybersecurity-sensitive systems, controlled technology, major IP rights, public-good software licensing strategy, open technical baselines, enterprise stack interfaces, GRA-facing finance-boundary risk, GRF-facing recognition-boundary risk, or material deviation from approved templates.

438.4.2 The Board may require legal review, tax review, audit review, insurance review, finance review, data / AI / cyber / privacy review, public authority boundary review, finance-boundary review, procurement neutrality review, IP review, export-control review, sanctions review, competition review, protected knowledge review, public-safe publication review, or conflict review before approval.

438.4.3 Board approval shall be recorded with sufficient detail to identify contract name, counterparty, purpose, amount, term, authority, key obligations, material risks, required restrictions, responsible officer, reporting obligations, and any conditions precedent to execution or performance.

438.5 Officer Approval Within Delegation.

438.5.1 Officers may approve contracts within the scope of Board-approved authority, budget authorization, policy, and delegation.

438.5.2 Officer approval shall not include authority to bind the Corporation to material public authority commitments, finance-facing commitments, certification commitments, recognition commitments, procurement commitments, capital execution, public warning obligations, emergency command obligations, enterprise execution obligations, material indemnities, unusual liabilities, or material IP transfers unless expressly authorized.

438.5.3 Officers shall escalate any contract whose risk exceeds delegation or whose meaning is ambiguous in relation to public-good stack integrity, non-execution, finance boundaries, public authority boundaries, certification boundaries, procurement neutrality, recognition boundaries, provider neutrality, sponsor non-control, or legal separateness.

438.6 Contract Templates and Clause Library.

438.6.1 The Corporation may maintain approved templates, clause libraries, schedules, exhibits, data protection addenda, AI-use addenda, cybersecurity addenda, public authority boundary clauses, finance-boundary clauses, recognition-boundary clauses, certification-boundary clauses, procurement neutrality clauses, sponsor non-control clauses, provider neutrality clauses, public-safe publication clauses, IP clauses, confidentiality clauses, export-control clauses, sanctions clauses, controlled technology clauses, competition clauses, insurance clauses, indemnity clauses, and correctionability clauses.

438.6.2 Material deviation from an approved template or required clause shall require review and approval proportionate to risk.

438.6.3 Template use shall not replace substantive review where the counterparty, activity, jurisdiction, data class, technology class, public authority interface, finance interface, protected knowledge, or risk profile requires additional controls.

438.7 Grants and Cooperative Agreements.

438.7.1 Grants and cooperative agreements shall be reviewed for eligibility, lawful purpose, public-benefit alignment, nonprofit compatibility, tax implications, restricted fund requirements, allowable costs, matching obligations, reporting obligations, audit obligations, data rights, IP rights, publication rights, public authority references, lobbying restrictions, political activity restrictions, procurement requirements, subaward requirements, conflict requirements, public records implications, termination rights, and correctionability.

438.7.2 No grant or cooperative agreement shall give a funder, public authority, sponsor, provider, host, capital actor, national company, Project SPV, or enterprise actor control over GCRI US evidence conclusions, methods, research agenda, technical baselines, public-good software roadmap, public-safe publication, public authority learning materials, or correction decisions.

438.7.3 Acceptance of a grant or cooperative agreement shall not create public authority delegation, public finance approval, sovereign obligation, recognition, finance-readiness, certification, procurement approval, provider preference, public warning authority, emergency command authority, or enterprise execution authority.

438.8 Public Grant and Government-Funding Instruments.

438.8.1 Public grant and government-funding instruments shall be reviewed for public authority boundary discipline, grant compliance, cost allowability, reporting, audit, procurement, public records, FOIA, sunshine, open meetings, data rights, IP rights, publication restrictions, cybersecurity obligations, privacy obligations, public authority reference controls, lobbying restrictions, political activity restrictions, gift rules, ethics rules, and termination.

438.8.2 Public funding shall not permit a public authority to control the Corporation’s evidence conclusions, methods, correction decisions, publication integrity, public-safe framing, provider neutrality, sponsor non-control, recognition boundaries, finance boundaries, certification boundaries, or procurement neutrality.

438.8.3 Public funding shall not be described as public authority endorsement, adoption, procurement approval, public finance approval, regulatory approval, sovereign obligation, public-private partnership, public warning, emergency command, recognition, finance-readiness, certification, or provider preference unless competent public authority records expressly support the statement.

438.9 Sponsorship, Donation, Restricted Gift, and Funder Agreements.

438.9.1 Sponsorship, donation, restricted gift, and funder agreements shall be reviewed for donor restrictions, sponsorship recognition, public acknowledgment, naming rights, data access, publication rights, public authority access, sponsor influence, provider neutrality, private benefit, charitable solicitation, tax, sanctions, conflicts, public-safe claims, and mission compatibility.

438.9.2 Sponsor or donor support shall not purchase outcomes, findings, favorable evidence, favorable methods, publication suppression, public authority access, provider preference, procurement advantage, recognition, finance-readiness, certification, public legitimacy, Grid status, Docket priority, or Nexus-compatible status.

438.9.3 Sponsor acknowledgments shall be factual, proportionate, non-misleading, public-safe, and shall not imply endorsement, control, certification, recognition, finance-readiness, procurement advantage, public authority approval, or outcome purchase.

438.10 Procurement by GCRI US.

438.10.1 Procurement by GCRI US shall be lawful, prudent, mission-aligned, budget-aware, conflict-reviewed, provider-neutral, documented, and proportionate to risk and value.

438.10.2 The Corporation may procure goods, services, software, cloud services, AI tools, cybersecurity services, professional services, event services, insurance, equipment, data services, hosting, communications, and other operational support necessary for its public-benefit functions.

438.10.3 Procurement by GCRI US shall not be confused with public procurement, public authority procurement approval, approved vendor status, provider qualification for public authorities, Nexus provider preference, certification, recognition, finance-readiness, or public authority adoption.

438.10.4 Where the Corporation procures from a sponsor, donor, provider, director-related party, officer-related party, insider, national company, Project SPV, or Nexus participant, heightened conflict, private benefit, provider neutrality, procurement neutrality, and documentation review shall apply.

438.11 Vendor Selection and Vendor Due Diligence.

438.11.1 Vendor selection shall consider mission need, capability, cost, reliability, security, privacy, data protection, AI-use restrictions, IP terms, license terms, export-control, sanctions, accessibility, availability, support, termination, portability, conflicts, insurance, indemnity, and public authority restrictions where applicable.

438.11.2 Vendor due diligence shall be proportionate to risk and may include restricted-party screening, beneficial ownership review, cybersecurity review, privacy review, AI review, insurance review, references, financial stability review, conflict review, data processor review, subprocessor review, controlled technology review, and public authority data review.

438.11.3 Vendor selection shall not confer external endorsement, procurement eligibility, public authority approval, provider preference, certification, recognition, finance-readiness, Nexus-compatible status, or public-good legitimacy status.

438.12 Technology, Cloud, AI, Data Processor, Repository, and Cybersecurity Vendor Contracts.

438.12.1 Technology, cloud, AI, data processor, repository, and cybersecurity vendor contracts shall include controls appropriate to data classification, AI-use restrictions, cybersecurity risk, public authority data, personal information, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, model access, repository access, uptime, incident response, breach notification, audit rights where appropriate, deletion, portability, subprocessor controls, business continuity, export-control, sanctions, controlled technology, and termination assistance.

438.12.2 Contracts with AI vendors shall prohibit unauthorized training, fine-tuning, embeddings, model improvement, external reuse, or disclosure of Corporation data unless expressly authorized by recorded authority and reviewed for lawful basis, data rights, public-safe status, and sensitivity.

438.12.3 Contracts with repository, cloud, and cybersecurity vendors shall require security controls, access controls, logging, vulnerability handling, incident notification, secure configuration, secrets protection, data location review, backup and recovery expectations, and exit rights proportionate to risk.

438.13 Data-Sharing, Data-Processing, Model-Sharing, and AI-Use Agreements.

438.13.1 Data-sharing, data-processing, model-sharing, and AI-use agreements shall specify source authority, lawful basis, permission, consent where required, data classes, permitted use, prohibited use, AI-use restrictions, training restrictions, fine-tuning restrictions, embedding restrictions, retrieval restrictions, publication restrictions, transfer restrictions, retention, deletion, incident response, correction path, audit rights where appropriate, and termination obligations.

438.13.2 No such agreement shall authorize unauthorized AI training, unauthorized model improvement, public mapping, public-safe publication, finance-readiness inputs, recognition inputs, certification inputs, procurement implications, sponsor benefit, provider benefit, or external sharing beyond recorded authority.

438.14 Intellectual Property, Licensing, Public-Good Software, Technical Baseline, and Repository Contracts.

438.14.1 IP, licensing, public-good software, technical baseline, and repository contracts shall identify ownership, license, contributor terms, assignment, moral rights treatment where applicable, attribution, derivative rights, sublicensing, commercial use restrictions, open-source obligations, data rights, model rights, documentation rights, patent rights, trademark rights, confidentiality, security, vulnerability disclosure, release governance, correction paths, and termination.

438.14.2 Public-good software, open technical baselines, schemas, APIs, SDKs, reference architectures, dashboards, maps, model cards, dataset cards, system cards, benchmark cards, and test harnesses shall not be licensed or contracted in a manner that encloses public-good baselines, grants sponsor control, creates provider preference, creates procurement advantage, implies certification, implies recognition, implies finance-readiness, or permits misleading Nexus-compatible claims.

438.15 Research, Publication, Event, Training, and Academy Contracts.

438.15.1 Research contracts shall preserve research integrity, methods integrity, evidence integrity, ethics review where required, sponsor and provider independence, data rights, IP rights, publication rights, confidentiality, public-safe publication, participant protection, conflict disclosure, correctionability, and misconduct review.

438.15.2 Publication contracts shall preserve claims substantiation, source lineage, attribution, non-attribution, copyright, license, public authority reference review, finance-boundary review, recognition-boundary review, certification-boundary review, procurement-boundary review, data / AI / cyber / privacy review, safeguards review, accessibility, correction, withdrawal, retraction, and archive.

438.15.3 Event, training, Academy, fellowship, and workforce contracts shall address role, scope, access, content approval, public-safe claims, accessibility, speaker authority, public authority references, sponsor references, provider references, recording, photography, privacy, confidentiality, safety, cancellation, insurance, and correction.

438.16 Public Authority, Consortium, Enterprise Stack, Controlled-Room, and Federation Interface Contracts.

438.16.1 Public authority contracts and interface instruments shall include capacity classification, official capacity records, public records considerations, public authority data controls, confidentiality limits, name and logo use, quote use, publication restrictions, public authority boundary language, procurement neutrality, public finance boundary language, regulatory boundary language, public warning boundary language, emergency command boundary language, and correction pathways.

438.16.2 Consortium contracts shall preserve legal separateness, no agency, no partnership, no joint venture, no shared liability, no control by either party absent express authority, public-good stack alignment, provider neutrality, sponsor non-control, safeguards, and correctionability.

438.16.3 Enterprise stack interface contracts shall preserve public-good stack and enterprise stack separation, no project ownership by default, no enterprise delivery by default, no provider selection for public authorities, no investment advice, no lending, no insurance placement, no rating, no public finance approval, no procurement approval, no certification, no recognition, no finance-readiness, and no operational control by GCRI US.

438.16.4 Controlled-room, clean-room, data-room, evidence-room, public authority room, regulator-listening room, public finance reader room, emergency learning room, and no-download room contracts shall include room charter, owner, custodian, participant capacity, admission criteria, confidentiality, no-download rules, AI-use restrictions, logging where appropriate, data / AI / cyber / privacy controls, competition controls, public authority boundary controls, finance and procurement boundary controls, safeguards review, publication controls, closeout, and correction.

438.17 Insurance Procurement and Coverage Review.

438.17.1 The Corporation shall maintain insurance coverage appropriate to its size, activities, assets, public authority interfaces, technology activities, data risks, AI risks, cyber risks, publication risks, event risks, travel risks, employment risks, contractor risks, volunteer risks, director and officer risks, professional boundary risks, fiduciary risks, general liability risks, crime risks, property risks, and other institutional risks where commercially reasonable and mission-compatible.

438.17.2 Insurance coverage may include directors and officers liability, employment practices liability, general liability, cyber liability, technology errors and omissions where appropriate, professional liability where appropriate, media liability where appropriate, crime coverage, property coverage, event coverage, travel coverage, workers’ compensation where required, and other appropriate coverage.

438.17.3 Insurance procurement shall not imply that the Corporation provides insurance, places insurance, underwrites insurance, guarantees insurability, issues insurance-readiness, or controls risk-transfer decisions of any other actor.

438.18 Indemnity, Limitation of Liability, Waiver, Release, and Risk Allocation.

438.18.1 Indemnity provisions shall be reviewed for scope, covered parties, covered claims, exclusions, defense control, settlement authority, caps, insurance alignment, public policy, nonprofit compatibility, public authority restrictions, data / AI / cyber exposure, IP exposure, confidentiality exposure, publication exposure, and protected knowledge exposure.

438.18.2 The Corporation shall not accept unlimited, uncapped, unusual, indirect, consequential, punitive, public authority, regulated financial, enterprise execution, operational, cybersecurity, data breach, IP, or third-party indemnity risk without Board approval or approval under Board-authorized risk controls.

438.18.3 Limitation of liability, waiver, release, assumption of risk, warranty disclaimer, non-reliance, and force majeure provisions shall be used where appropriate to preserve non-execution, public-good role separation, professional boundaries, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, recognition boundaries, and technical limitation discipline.

438.18.4 No indemnity or risk allocation provision shall be used to excuse intentional misconduct, fraud, bad faith, unlawful retaliation, knowing violation of law, or conduct that cannot lawfully be indemnified.

438.19 Warranties, Representations, Covenants, and Non-Reliance.

438.19.1 Warranties, representations, and covenants made by the Corporation shall be accurate, limited, record-supported, authorized, and consistent with the Corporation’s public-good technical role.

438.19.2 The Corporation shall not warrant or represent that any evidence output, method, technical baseline, public-good software, dashboard, map, model, dataset, proof receipt, observability output, publication, Academy material, public authority learning material, public-safe summary, Docket input, Grid input, GRA input, or GRF input constitutes certification, recognition, finance-readiness, procurement approval, public authority adoption, public warning, emergency command, legal compliance approval, rating, guarantee, or operational correctness.

438.19.3 Contracts shall include non-reliance language where counterparties, public authorities, providers, sponsors, capital readers, funders, or enterprise actors may otherwise rely on GCRI US materials beyond their intended public-good technical support function.

438.20 Audit, Reporting, Records, and Monitoring Obligations.

438.20.1 Contracts shall identify audit rights, reporting obligations, records obligations, inspection rights, public authority reporting, grant reporting, financial reporting, technical reporting, data reporting, cybersecurity reporting, incident reporting, publication reporting, and correction reporting where applicable.

438.20.2 The Corporation shall monitor material contract obligations, deadlines, deliverables, reporting dates, renewal dates, termination dates, data return dates, deletion dates, insurance certificate dates, audit dates, and corrective action dates through a contract register or equivalent compliance system.

438.20.3 No report shall be submitted to a funder, sponsor, public authority, provider, capital reader, insurer, or partner if it materially misstates evidence, methods, outcomes, limitations, finances, expenditures, public authority participation, procurement meaning, recognition meaning, finance-readiness meaning, certification meaning, or correction status.

438.21.1 Contracts involving directors, officers, insiders, related persons, substantial contributors, sponsors, providers, funders, public authority participants, national companies, Project SPVs, vendors, contractors, consultants, universities, laboratories, or partners with material relationships shall be reviewed for conflict of interest, private benefit, private inurement, excess benefit where applicable, sponsor control, provider control, procurement advantage, public authority access advantage, data advantage, and reputational risk.

438.21.2 Conflict review may require disclosure, recusal, independent review, comparability evidence, Board approval, contract modification, rejection, monitoring, public-safe disclosure, or correction.

438.21.3 No contract shall permit a sponsor or provider to control GCRI US evidence, methods, technical baselines, public-good software, publication, public authority learning, public-safe summaries, correction decisions, Docket-facing inputs, Grid-facing inputs, GRF-facing inputs, or GRA-facing inputs.

438.22 Contract Lifecycle, Amendments, Renewals, Termination, Suspension, and Closeout.

438.22.1 Contract lifecycle management shall include intake, review, approval, execution, storage, obligation tracking, performance monitoring, amendment, renewal, suspension, termination, closeout, record retention, and post-termination obligations.

438.22.2 Amendments, renewals, extensions, waivers, change orders, statements of work, exhibits, schedules, and side letters shall be reviewed and approved with the same discipline as the underlying contract where they materially affect risk, obligations, authority, term, amount, data, IP, publication, public authority interfaces, finance interfaces, recognition interfaces, certification interfaces, procurement implications, or protected knowledge.

438.22.3 The Corporation may suspend or terminate a contract where required or appropriate because of breach, loss of authority, sanctions risk, export-control risk, data incident, AI incident, cybersecurity incident, public authority boundary violation, finance-boundary violation, procurement-boundary violation, recognition-boundary violation, certification-boundary violation, protected knowledge violation, research integrity violation, sponsor control, provider preference, misconduct, nonpayment, impossibility, force majeure, mission incompatibility, or legal risk.

438.22.4 Closeout shall address final deliverables, final reports, financial reconciliation, return or deletion of data, repository access removal, credential revocation, publication status, IP status, confidentiality survival, indemnity survival, insurance survival, audit survival, correction obligations, public-safe notices, and archive.

438.23 Contract Register and Records.

438.23.1 The Corporation shall maintain a Contract Register or equivalent record system for material contracts, identifying contract title, counterparty, purpose, contract class, owner, responsible officer, authority, approval record, effective date, expiration date, renewal date, amount, funding source, risk class, data class, AI exposure, cybersecurity exposure, IP exposure, public authority exposure, finance exposure, procurement exposure, recognition exposure, certification exposure, protected knowledge exposure, insurance requirements, indemnity exposure, reporting obligations, audit obligations, correction path, and status.

438.23.2 The Corporation shall retain Contract Compliance Records, including contract compliance purpose records, contract authority records, contract review records, Board approval records, officer approval records, template and clause records, grant and cooperative agreement records, public grant records, sponsorship / donation / restricted gift / funder agreement records, procurement-by-GCRI-US records, vendor selection and due diligence records, technology / cloud / AI / data processor / repository / cybersecurity vendor contract records, data-sharing / data-processing / model-sharing / AI-use agreement records, IP / licensing / public-good software / technical baseline / repository contract records, research / publication / event / training / Academy contract records, public authority / consortium / enterprise stack / controlled-room / federation interface contract records, insurance procurement and coverage review records, indemnity / limitation of liability / waiver / release / risk allocation records, warranty / representation / covenant / non-reliance records, audit / reporting / monitoring records, conflict / related-party / private-benefit / sponsor-provider-control records, lifecycle / amendment / renewal / termination / suspension / closeout records, Contract Register records, corrective actions, notices, disputes, and archive records.

438.24 Enforcement of Contract Compliance.

438.24.1 Contract Compliance violations may include unauthorized signature, unauthorized commitment, performance beyond authority, missing review, missing Board approval, template deviation without approval, public authority overclaim, finance overclaim, recognition overclaim, certification overclaim, procurement implication, sponsor control, provider preference, private benefit, prohibited data use, unauthorized AI use, cybersecurity noncompliance, IP misuse, protected knowledge misuse, sanctions violation, export-control violation, competition violation, insurance deficiency, indemnity overexposure, reporting misstatement, or failure to correct.

438.24.2 Remedies may include contract hold, performance hold, payment hold, access restriction, data hold, repository hold, publication hold, controlled-room hold, amendment, waiver refusal, correction, public or controlled clarification, termination, suspension, vendor restriction, sponsor restriction, provider restriction, Board review, legal referral, public authority referral, regulator referral, funder referral, insurer notice, law enforcement referral where required or appropriate, personnel discipline, training, or recurrence-prevention controls.

438.24.3 The Corporation shall maintain Contract Enforcement Records, including violation reviews, findings, corrective actions, holds, amendments, terminations, referrals, notices, closeout, recurrence-prevention measures, and archive records.

Section 439. Finance, Accounting, Budgeting, Internal Controls, Restricted Funds, Treasury, and Financial Records Compliance

439.1 Financial Management Compliance Purpose.

439.1.1 Financial Management Compliance shall ensure that the Corporation’s funds, assets, grants, donations, sponsorships, restricted funds, unrestricted funds, contracts, procurements, reimbursements, payroll, contractor payments, vendor payments, public authority funds, program funds, public-good technical asset expenditures, software expenditures, technology expenditures, controlled-room expenditures, event expenditures, and Nexus coordination expenditures are managed lawfully, prudently, transparently, accurately, and consistently with the Corporation’s nonprofit public-benefit purposes.

439.1.2 Financial Management Compliance shall preserve fiduciary discipline, nonprofit compatibility, tax compatibility, restricted-fund discipline, grant compliance, sponsor non-control, provider neutrality, procurement neutrality, public authority boundary discipline, finance-boundary discipline, private-benefit controls, internal control integrity, auditability, correctionability, and legal separateness.

439.1.3 No financial arrangement, accounting treatment, budget allocation, grant receipt, sponsor support, vendor credit, cloud credit, in-kind contribution, public authority support, or Nexus coordination arrangement shall be used to create private inurement, impermissible private benefit, sponsor control, provider preference, procurement advantage, finance-readiness, recognition, certification, public authority endorsement, public finance approval, public warning authority, emergency command authority, or enterprise execution.

439.2 Accounting System Requirement.

439.2.1 The Corporation shall maintain an accounting system appropriate to its size, activities, funding sources, grants, restricted funds, public authority interfaces, technology assets, contracts, tax status, reporting duties, audit requirements, and public-benefit mission.

439.2.2 The accounting system shall support accurate recording of revenues, expenses, assets, liabilities, restricted funds, unrestricted funds, program costs, management and general costs, fundraising costs where applicable, grant costs, contract costs, in-kind contributions, reimbursements, payables, receivables, deferred revenue where applicable, prepaid expenses, fixed assets where applicable, and commitments.

439.2.3 The accounting system shall preserve source documentation, approval records, transaction records, reconciliations, budget records, donor restrictions, grant restrictions, contract restrictions, reporting classifications, and retention requirements.

439.3 Books and Records Requirement.

439.3.1 The Corporation shall maintain complete and accurate financial books and records sufficient to support Board oversight, officer accountability, tax filings, grant reporting, donor reporting, audit or review, restricted fund compliance, public authority reporting where applicable, charitable solicitation compliance, internal controls, and institutional memory.

439.3.2 Financial records shall include general ledger records, bank records, investment records where applicable, invoices, receipts, contracts, grant agreements, donor restrictions, reimbursement records, payroll records, contractor payment records, vendor records, procurement records, approval records, expense reports, allocation records, reconciliation records, budget records, tax records, audit records, and corrective action records.

439.4 Budget Preparation.

439.4.1 The Corporation shall prepare budgets appropriate to its annual operations, programs, grants, public-good software work, technical baseline work, research agenda, public authority learning, Nexus coordination, staffing, contractors, vendors, technology costs, insurance, legal compliance, audit or review costs, fundraising where applicable, and reserves.

439.4.2 Budgets shall distinguish restricted funds and unrestricted funds, committed and uncommitted resources, program and administrative costs, one-time and recurring costs, cash and non-cash support, grant-funded and unrestricted activities, and public-good stack and enterprise stack boundaries where relevant.

439.4.3 Budgets shall not be structured to conceal private benefit, sponsor control, provider preference, procurement advantage, public authority dependence, enterprise execution, or regulated financial activity.

439.5 Budget Approval.

439.5.1 The Board, or a Board-authorized committee or officer within recorded delegation, shall approve the annual budget and any material amendments.

439.5.2 Budget approval shall not by itself authorize contracts, restricted fund use, public authority commitments, debt, guarantees, hiring, major procurement, enterprise stack activity, finance-facing activity, or public authority-facing commitments beyond the approved delegation and applicable review requirements.

439.5.3 Budget variances that materially affect legal compliance, cash position, restricted funds, grant obligations, public authority commitments, staffing, insurance, taxes, or program continuity shall be reported to the Board or authorized committee according to risk.

439.6 Internal Financial Controls.

439.6.1 The Corporation shall maintain internal financial controls appropriate to its risk profile, including segregation of duties where practicable, approval thresholds, dual review for material payments, bank reconciliation, budget monitoring, restricted fund tracking, expense documentation, procurement review, conflict review, contract review, payroll review, grant cost review, and records retention.

439.6.2 Where the Corporation’s size makes full segregation of duties impracticable, compensating controls shall be used, including Board review, external bookkeeping support, independent reconciliation review, periodic financial reporting, dual approval for material transactions, and documented oversight.

439.6.3 Internal controls shall be designed to prevent unauthorized payments, fraud, misappropriation, restricted fund misuse, private benefit, duplicate payments, false invoices, unsupported reimbursements, procurement steering, sponsor control, provider preference, and misreporting.

439.7 Approval Thresholds and Delegated Financial Authority.

439.7.1 The Board may establish approval thresholds for expenditures, contracts, commitments, grants, reimbursements, procurement, payroll actions, vendor payments, technology purchases, insurance purchases, and other financial transactions.

439.7.2 Delegated financial authority shall be recorded by role, amount, transaction class, funding source, term, counterparty, risk category, and limitation.

439.7.3 No delegated authority shall include authority to approve self-dealing, private benefit, excess benefit, public authority obligations, debt, guarantees, material indemnities, regulated financial activity, enterprise execution, recognition, certification, finance-readiness, procurement approval, or public warning activity unless expressly and lawfully authorized.

439.8 Bank Accounts and Treasury Controls.

439.8.1 The Corporation shall maintain bank accounts, treasury accounts, payment systems, and financial platforms in the Corporation’s name and subject to access controls, approval controls, reconciliation, signatory records, and Board oversight.

439.8.2 Bank accounts shall not be used as pass-through accounts, escrow accounts, project treasuries, investment vehicles, public authority treasuries, Project SPV treasuries, sponsor-controlled accounts, provider-controlled accounts, or third-party fund custody accounts unless separately and lawfully authorized by the Board and reviewed for regulatory, tax, nonprofit, fiduciary, and risk implications.

439.8.3 Bank signatories, payment approvers, cardholders, platform administrators, and finance system users shall be approved, access-controlled, periodically reviewed, and promptly removed when authority ends.

439.9 Cash Management and Reserves.

439.9.1 The Corporation shall manage cash and reserves prudently to support continuity, grant obligations, payroll, vendor payments, public-good technical asset maintenance, compliance obligations, legal obligations, insurance obligations, and mission continuity.

439.9.2 Reserve policies may be adopted to address operating reserves, restricted reserves, board-designated reserves, technology reserves, legal compliance reserves, emergency reserves, and program continuity reserves.

439.9.3 Reserves shall not be used to guarantee third-party debt, subsidize enterprise execution, create provider preference, fund regulated financial activity, or support sponsor-controlled outcomes outside approved public-benefit purposes.

439.10 Restricted Funds and Donor Restrictions.

439.10.1 Restricted funds shall be recorded, tracked, used, reported, released, and retained according to donor restrictions, grant terms, sponsorship terms, public authority requirements, accounting rules, tax obligations, Board policy, and applicable law.

439.10.2 Restricted funds shall not be diverted to unrelated purposes, private benefit, sponsor-preferred outcomes, provider-preferred outcomes, procurement advantage, finance-readiness support outside authority, recognition manipulation, certification implication, public authority overclaim, enterprise execution, or prohibited activity.

439.10.3 Where a restriction becomes impossible, impracticable, unlawful, wasteful, mission-incompatible, or inconsistent with public-good integrity, the Corporation shall seek lawful modification, release, reclassification, return, or other remedy.

439.11 Grant Cost Tracking.

439.11.1 Grant costs shall be tracked according to grant budget, allowable cost rules, cost categories, reporting periods, matching obligations, indirect cost rules where applicable, cost-sharing rules, subaward rules, procurement rules, and documentation requirements.

439.11.2 Costs shall not be charged to a grant unless supported by authority, allocability, allowability, reasonableness, documentation, and compliance with grant terms.

439.11.3 Grant mischarges, questioned costs, unsupported costs, or unallowable costs shall be corrected, disclosed, repaid, reallocated, or otherwise addressed as required.

439.12 Program Cost Allocation.

439.12.1 The Corporation shall allocate shared costs among programs, grants, management and general functions, fundraising where applicable, public-good software work, research work, public authority learning, Nexus coordination, and other activities using reasonable, documented, consistently applied allocation methods.

439.12.2 Allocation methods shall not be manipulated to conceal private benefit, overstate program efficiency, mischarge grants, misstate public support, misstate fundraising cost, misstate public-good technical asset costs, or shift costs to public authority or restricted funds improperly.

439.13 Expense Reimbursement and Corporate Card Controls.

439.13.1 Expense reimbursement and corporate card use shall require business purpose, documentation, approval, timely submission, policy compliance, conflict review where applicable, and review for public authority gift restrictions, sponsor restrictions, grant restrictions, tax rules, and public-safe optics.

439.13.2 Reimbursement shall not be made for personal expenses, unauthorized gifts, improper public official benefits, political campaign activity, regulated financial activity, prohibited lobbying costs, private benefit, undocumented expenses, or expenses inconsistent with mission or law.

439.14 Payroll, Contractor, and Consultant Payment Controls.

439.14.1 Payroll, contractor, consultant, fellowship, stipend, honorarium, advisor, and vendor payments shall be supported by approved engagement records, classification review, compensation approval, tax documentation, deliverables where applicable, time or work records where required, conflict review where applicable, and payment authorization.

439.14.2 Payments to directors, officers, insiders, related persons, major contributors, sponsors, providers, public authority participants, or affiliated entities shall receive heightened conflict, private benefit, excess benefit where applicable, and documentation review.

439.15 In-Kind Contributions, Credits, Discounts, Cloud Credits, Compute Credits, Software Credits, and Donated Services.

439.15.1 In-kind contributions, credits, discounts, cloud credits, compute credits, software credits, data access, equipment, hosting, professional services, venue support, public authority support, and donated services shall be reviewed for valuation, restrictions, accounting treatment, donor acknowledgment, sponsor recognition, tax implications, data rights, AI-use restrictions, cybersecurity risk, provider neutrality, sponsor non-control, and public-safe claims.

439.15.2 Acceptance of in-kind support shall not create provider preference, procurement advantage, sponsor control, public authority endorsement, finance-readiness, certification, recognition, Nexus-compatible status, or public-good identity control.

439.16 Financial Reporting to Board and Management.

439.16.1 Officers or authorized finance personnel shall provide periodic financial reports to the Board or authorized committee appropriate to the Corporation’s size, risk, activity, grant obligations, cash position, restricted funds, program commitments, and compliance obligations.

439.16.2 Financial reports may include statement of financial position, statement of activities, budget-to-actual reports, cash position, grant status, restricted fund status, accounts payable, accounts receivable, contract commitments, forecast, reserves, compliance matters, and material variances.

439.16.3 Financial reports shall be accurate, timely, non-misleading, and corrected where material errors are discovered.

439.17 Financial Misconduct, Fraud, Waste, Abuse, and Misuse Review.

439.17.1 Allegations or evidence of fraud, theft, misappropriation, waste, abuse, false reporting, false invoicing, duplicate payment, unauthorized expense, restricted fund misuse, grant misuse, procurement steering, kickback, bribery, private benefit, sponsor control, provider preference, public authority gift violation, or financial conflict shall be reported, triaged, investigated, corrected, and recorded.

439.17.2 Remedies may include payment hold, access restriction, procurement hold, contract suspension, grant notice, donor notice, public authority notice, insurer notice, repayment, correction, termination, referral, law enforcement referral, or other action where required or appropriate.

439.18 Financial Records.

439.18.1 The Corporation shall maintain Financial Records, including financial management purpose records, accounting system records, books and records, budget preparation records, budget approval records, internal control records, delegated financial authority records, bank and treasury records, cash management and reserve records, restricted fund records, grant cost tracking records, program cost allocation records, reimbursement and corporate card records, payroll / contractor / consultant payment records, in-kind contribution and credit records, financial reporting records, financial misconduct review records, corrective actions, and archive records.


Section 440. Audit, Assurance, Tax Filings, Public Inspection, Transparency, Reporting, and Financial Disclosure Compliance

440.1 Audit and Assurance Purpose.

440.1.1 Audit and Assurance Compliance shall support financial integrity, governance accountability, grant compliance, tax compliance, donor trust, public-benefit accountability, internal control improvement, risk management, and correctionability.

440.1.2 Audit and assurance activities shall be proportionate to the Corporation’s size, revenue, funding sources, public grants, state requirements, charitable solicitation requirements, donor requirements, Board requirements, contract requirements, public authority requirements, and institutional risk.

440.2 Audit Requirement Where Required.

440.2.1 The Corporation shall obtain an independent audit where required by law, grant terms, public authority agreement, donor restriction, contract, Board resolution, lender or insurer requirement where applicable, or other competent requirement.

440.2.2 The audit shall be conducted by an appropriately qualified independent professional, and the Corporation shall provide access to records, personnel, reconciliations, schedules, grant records, restricted fund records, and internal control materials as required.

440.3 Review or Compilation Where Appropriate.

440.3.1 Where an audit is not required but financial risk, donor expectation, Board oversight, grant complexity, public authority interface, or institutional growth warrants, the Board may require a review, compilation, agreed-upon procedures engagement, internal assurance review, external bookkeeping review, grant compliance review, or targeted control review.

440.4 Internal Audit or Internal Assurance.

440.4.1 The Corporation may conduct internal audit or internal assurance reviews of finance, accounting, grants, procurement, contracts, data governance, AI governance, cybersecurity, public authority interfaces, restricted funds, public-good technical assets, publication controls, and Nexus coordination records.

440.4.2 Internal assurance shall identify findings, risk ratings, responsible owners, corrective actions, target dates, verification methods, closure criteria, and escalation requirements.

440.5 Audit Committee or Finance Committee Interface Where Constituted.

440.5.1 Where an Audit Committee, Finance Committee, or similar committee is constituted, it may oversee financial reporting, budgets, internal controls, audits, assurance reviews, tax filings, restricted funds, reserves, investment policy where applicable, risk management, and corrective actions.

440.5.2 Committee authority shall be defined by charter, Board resolution, or delegation and shall not displace full Board responsibilities unless lawfully authorized.

440.6 Auditor Independence.

440.6.1 Auditors and assurance providers shall be independent where required and shall disclose conflicts, related-party relationships, prohibited non-audit services where applicable, financial interests, employment relationships, and other independence matters.

440.6.2 The Corporation shall not pressure auditors to suppress findings, alter conclusions, ignore restrictions, conceal errors, or avoid required disclosures.

440.7 Management Representations.

440.7.1 Management representations to auditors, reviewers, tax preparers, funders, public authorities, donors, insurers, or other assurance parties shall be accurate, complete to the best of responsible knowledge, records-supported, and corrected where errors are discovered.

440.7.2 No person shall knowingly provide false, incomplete, misleading, or unsupported representations concerning finances, restrictions, grants, public authority funds, internal controls, related-party transactions, private benefit, tax status, contracts, legal compliance, data incidents, cybersecurity incidents, or contingent liabilities.

440.8 Audit Findings and Corrective Action.

440.8.1 Audit findings, management letter comments, internal control deficiencies, significant deficiencies, material weaknesses, questioned costs, compliance exceptions, restricted fund issues, filing issues, grant issues, tax issues, or reporting issues shall be reviewed by management and reported to the Board or authorized committee.

440.8.2 Corrective action shall identify finding, severity, owner, root cause, corrective steps, deadline, verification, reporting obligation, and closure record.

440.9 Tax Return Preparation and Filing.

440.9.1 The Corporation shall prepare and timely file required federal, state, territorial, local, payroll, information, charitable, sales and use, unrelated business income, withholding, and other tax returns and filings.

440.9.2 Tax filings shall be based on accurate books and records, reviewed by responsible officers or qualified professionals where appropriate, and retained according to records policy.

440.9.3 Any late filing, rejected filing, notice, penalty, inquiry, audit, or tax controversy shall be escalated and corrected.

440.10 Form 990 or Equivalent Public Return Where Applicable.

440.10.1 Where the Corporation is required to file Form 990, Form 990-EZ, Form 990-N, Form 990-PF, or equivalent public information return, the filing shall be prepared accurately and consistently with the Corporation’s books, governance records, program descriptions, compensation records, grants, related-party transactions, public support records, lobbying records, political activity records, fundraising records, and tax status.

440.10.2 Public descriptions in tax returns shall be reviewed to avoid misleading statements concerning public authority endorsement, finance-readiness, recognition, certification, procurement approval, provider preference, public warning, emergency command, enterprise execution, or Nexus role separation.

440.11 Public Inspection Compliance Where Applicable.

440.11.1 The Corporation shall comply with public inspection requirements applicable to tax-exempt applications, determination letters, annual information returns, and related materials where required by law.

440.11.2 Public inspection compliance shall not require disclosure of materials lawfully protected as confidential, privileged, trade secret, security-sensitive, public authority restricted, personal, health-sensitive, cyber-sensitive, infrastructure-sensitive, community-protected, Tribal / Indigenous, protected knowledge, or otherwise exempt from disclosure.

440.12 Donor, Grantor, Sponsor, Funder, and Public Authority Reporting.

440.12.1 Donor, grantor, sponsor, funder, and public authority reporting shall be accurate, timely, records-supported, limitation-aware where technical outputs are involved, and consistent with restrictions, public-safe publication controls, privacy, confidentiality, data rights, IP rights, and boundary language.

440.12.2 Reports shall not misstate outcomes, overstate impact, conceal limitations, imply public authority endorsement, imply finance-readiness, imply recognition, imply certification, imply procurement approval, imply provider preference, or suppress required corrections.

440.13 Public Transparency Reports Where Approved.

440.13.1 The Corporation may issue public transparency reports concerning governance, programs, finances, grants, public-good technical assets, public-safe publications, corrections, public authority learning, and Nexus coordination where approved.

440.13.2 Public transparency reports shall be public-safe, accurate, non-misleading, appropriately aggregated, access-classified where necessary, and reviewed for confidentiality, public authority restrictions, privacy, data protection, cybersecurity, infrastructure sensitivity, protected knowledge, finance-boundary language, recognition-boundary language, certification-boundary language, procurement-boundary language, and correctionability.

440.14 Financial Transparency Without Misleading Reliance.

440.14.1 Financial transparency shall support accountability and trust but shall not be used to imply public authority endorsement, public finance approval, donor endorsement beyond fact, sponsor control, provider preference, investment opportunity, securities offering, finance-readiness, recognition, certification, procurement approval, rating, public warning, emergency command, or guaranteed impact.

440.14.2 Financial summaries shall distinguish audited and unaudited information, restricted and unrestricted funds, committed and uncommitted funds, cash and in-kind support, public grants and private support, and actual and projected figures where material.

440.15 Corrections to Financial Reports and Public Filings.

440.15.1 Material errors in financial reports, tax filings, public filings, donor reports, grant reports, sponsor reports, public authority reports, public transparency reports, or Board reports shall be corrected promptly.

440.15.2 Correction may require amended filings, supplemental disclosures, donor notice, grantor notice, Board notice, public authority notice, auditor notice, public clarification, controlled clarification, repayment, reclassification, or other remedy where required or appropriate.

440.16 Audit, Tax, Reporting, and Transparency Records.

440.16.1 The Corporation shall maintain Audit, Tax, Reporting, and Transparency Records, including audit and assurance purpose records, audit requirement records, review / compilation / agreed-upon procedures records, internal assurance records, Audit Committee or Finance Committee records where constituted, auditor independence records, management representation records, audit findings and corrective action records, tax return preparation and filing records, Form 990 or equivalent public return records where applicable, public inspection compliance records, donor / grantor / sponsor / funder / public authority reporting records, public transparency report records where approved, financial transparency records, correction records, filings, notices, and archive records.


441.1 Records Management Purpose.

441.1.1 Records Management Compliance shall ensure that the Corporation creates, receives, stores, protects, classifies, indexes, retrieves, retains, seals, redacts, archives, deletes, and securely disposes of records according to law, governing instruments, contracts, grants, public authority restrictions, privacy obligations, cybersecurity obligations, research ethics, public-good technical memory, validity-by-record, correctionability, and public-safe publication requirements.

441.1.2 Records Management Compliance shall apply to corporate records, financial records, tax records, governance records, contracts, grants, personnel records, donor records, sponsor records, public authority records, research records, evidence records, method records, ontology records, observability records, datasets, models, inference records, compute workload records, proof receipts, technical baselines, repositories, software records, publication records, controlled-room records, compliance records, incident records, correction records, and Nexus coordination records.

441.2 Record Classification.

441.2.1 Records shall be classified according to content, authority, sensitivity, access class, legal obligation, public authority status, privacy status, cybersecurity status, infrastructure sensitivity, finance sensitivity, research sensitivity, protected knowledge, IP rights, publication status, and retention requirement.

441.2.2 Approved classifications may include public, public-safe, internal, controlled, confidential, restricted, public authority, research, evidence-room, data-room, clean-room, no-download, community-protected, Tribal / Indigenous, finance-sensitive, cyber-sensitive, infrastructure-sensitive, health-sensitive, controlled technology, export-controlled, sanctions-sensitive, privileged, work product, sealed, archived, and other classifications adopted by policy.

441.3 Records Ownership and Custodianship.

441.3.1 Material records shall identify owner, custodian, system of record, access class, correction path, retention category, and authority record where practicable.

441.3.2 Custodians shall maintain records according to approved controls and shall not delete, alter, transfer, disclose, publish, train on, embed, map, or externally share records beyond recorded authority.

441.4 Retention Schedule.

441.4.1 The Corporation shall maintain a retention schedule appropriate to legal, tax, corporate, financial, employment, contract, grant, public authority, research, privacy, cybersecurity, IP, publication, technical memory, correctionability, and audit requirements.

441.4.2 Retention periods may vary by record class and shall account for statutes of limitation, grant periods, audit periods, tax periods, public authority restrictions, research obligations, consent terms, data subject rights, protected knowledge restrictions, technical dependency, and correction history.

441.5 Minimum Retention Requirements.

441.5.1 The Corporation shall retain formation documents, bylaws, Board minutes, core governance records, tax-exempt status records where applicable, major contracts, major grants, audit records, financial statements, core technical baseline records, major publication records, correction records, and other permanent or long-term records according to law and policy.

441.5.2 Records shall not be destroyed where needed for legal compliance, audit, litigation, investigation, public authority inquiry, research integrity, technical memory, correctionability, or unresolved challenge.

441.6.1 Legal holds shall be issued where litigation, investigation, audit, subpoena, public authority inquiry, regulatory inquiry, employment claim, contract dispute, grant dispute, data incident, cybersecurity incident, research misconduct review, public authority boundary incident, finance-boundary incident, protected knowledge incident, or other legal matter requires preservation.

441.6.2 Legal holds shall suspend deletion, alteration, overwriting, secure disposal, auto-deletion, archive destruction, and routine retention expiration for covered records.

441.6.3 Legal holds shall identify scope, custodians, systems, record classes, start date, responsible person, review cycle, and release process.

441.7 Regulatory, Audit, Grant, and Public Authority Holds.

441.7.1 Regulatory, audit, grant, and public authority holds shall be issued where required by audit, grant terms, public funding requirements, public authority data restrictions, tax inquiry, public records inquiry, government investigation, data breach notification review, or other oversight requirement.

441.7.2 Such holds shall be coordinated with confidentiality, privilege, privacy, cybersecurity, protected knowledge, and public-safe publication controls.

441.8 Privilege and Work Product Protection.

441.8.1 The Corporation shall protect attorney-client privilege, attorney work product, common interest protections where applicable, mediation privilege, settlement privilege, and other applicable legal protections.

441.8.2 Privileged records shall be labeled, access-controlled, shared only with authorized persons, and not published, summarized, uploaded, trained on, embedded, or externally disclosed without legal review.

441.8.3 Privilege shall not be used to conceal nonprivileged facts, suppress required corrections, retaliate against reporters, or avoid lawful reporting duties.

441.9 Confidentiality Controls.

441.9.1 Confidential records shall be protected through access restrictions, confidentiality agreements where appropriate, system controls, need-to-know rules, secure transmission, logging where appropriate, no-download restrictions where appropriate, and incident response.

441.9.2 Confidentiality obligations may arise from law, contract, grant, public authority restriction, research ethics, data rights, employment, contractor terms, controlled-room terms, protected knowledge protocols, or Board policy.

441.10 Sealing and Restricted Access.

441.10.1 Records may be sealed or access-restricted where they contain privileged materials, legal risk, personal information, health-sensitive data, public authority restricted information, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, confidential sponsor materials, confidential provider materials, finance-sensitive information, procurement-sensitive information, controlled technology, or other high-risk content.

441.10.2 Sealing shall identify basis, authority, scope, duration, reviewer, access conditions, and review date where appropriate.

441.11 Redaction.

441.11.1 Redaction shall be used to permit lawful and public-safe disclosure while protecting sensitive information.

441.11.2 Redactions shall be accurate, documented where material, reviewed for sufficiency, and applied to protect personal information, health-sensitive data, public authority data, cyber-sensitive data, infrastructure-sensitive data, protected knowledge, confidential business information, finance-sensitive information, procurement-sensitive information, privileged content, controlled technology, and other protected content.

441.12 Archival and Technical Memory.

441.12.1 Archival records shall preserve institutional memory, technical memory, evidence lineage, method evolution, ontology history, publication history, software history, correction history, governance history, public authority interface history, and Nexus coordination history.

441.12.2 Archival status shall not imply current validity, current approval, current authority, current public-safe status, current technical baseline status, current finance-readiness, current recognition, current certification, current procurement eligibility, or current public authority adoption.