> For the complete documentation index, see [llms.txt](https://docs.therisk.global/organization/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.therisk.global/organization/organization/governance/charter-us/ix.-activities.md).

# IX. Activities

### 184. Purpose, Constitutional Function, and Governing Rule&#x20;

#### 184.1 Purpose&#x20;

Part IX establishes the fiduciary, corporate, trustee, officer, reserved-matters, delegation, records, and board-oversight architecture for GCRI US. It governs how corporate authority is constituted, exercised, limited, recorded, reviewed, delegated, corrected, and protected from informality, personality, sponsor influence, executive drift, and mission dilution.

Part IX shall operate as the controlling corporate-governance map for:

a) the membership authority or general assembly function, where applicable;\
b) the Board of Trustees or Board of Directors, as the primary fiduciary oversight organ;\
c) trustees, directors, officers, committee members, senior management, and governance-spine functions;\
d) reserved matters, corporate records, written authorities, delegations, signature rules, and decision validity;\
e) board committees, risk oversight, audit, safeguards, security, finance, nominations, and integrity oversight;\
f) election, appointment, removal, succession, emergency governance, and continuity rules; and\
g) the relationship between corporate governance, technical stewardship, public-benefit programs, membership systems, and cross-entity interfaces.

#### 184.2 Relationship of Part IX to Mission Lock, Public-Benefit Mandate, and Constitutional Architecture

Part IX shall be read subject to the mission lock, public-benefit mandate, nonprofit discipline, non-execution boundary, asset-lock logic, safeguards duties, security requirements, financial anti-capture rules, membership controls, and public-good stewardship obligations of GCRI US. Corporate governance is not separate from those constitutional commitments. It is the machinery through which they are preserved.

Accordingly, no Board decision, officer act, committee action, executive instruction, delegation, consent, resolution, emergency measure, public statement, or corporate record may be read to authorize:

a) breach of nonprofit purpose;\
b) private inurement or improper private benefit;\
c) donor, sponsor, vendor, member, founder, state, sector, or executive capture;\
d) regulated execution, market intermediation, custody, underwriting, settlement, brokerage, insurance, investment advice, or transaction-linked activity;\
e) weakening of safeguards, privacy, security, restricted-handling, or whistleblower protections;\
f) enclosure or privatization of public-good assets;\
g) unrecorded authority, shadow governance, or informal reserved-matter decisions; or\
h) public claims beyond the Corporation’s recorded authority and actual capacity.

Corporate form shall serve mission. It shall not become a device for mission drift, control concentration, or convenience-based waiver of constitutional discipline.

#### 184.3 Corporate Governance as a Control Surface for Legitimacy, Continuity, and Accountability

Corporate governance within GCRI US shall be treated as a control surface for legitimacy, continuity, accountability, and lawful authority. It is the structure by which decisions become valid, duties become traceable, oversight becomes effective, and institutional power remains bounded.

This requires:

a) clear allocation of authority among members, Board, officers, committees, executive management, and delegated functions;\
b) formal treatment of reserved matters;\
c) disciplined meetings, notices, agendas, minutes, resolutions, and written consents;\
d) recorded delegations and signature authority;\
e) segregation of duties, conflict controls, and recusal discipline;\
f) reliable corporate books, records, registers, and authoritative instruments;\
g) continuity rules for vacancies, emergencies, incapacity, or transition; and\
h) board-level oversight of risk, finance, compliance, security, safeguards, and executive accountability.

A corporation may have excellent programs and still be institutionally weak if governance authority is unclear. Part IX prevents that weakness by making authority visible, procedural, and reviewable.

#### 184.4 Fiduciary Governance Distinct From Program Delivery, Technical Stewardship, and Public Narrative

Fiduciary governance shall be distinct from program delivery, technical stewardship, public communications, membership engagement, advisory work, and external narrative. Trustees and officers may oversee these functions, but they shall not confuse program momentum or public visibility with lawful corporate authority.

The following distinctions shall be preserved:

a) the Board governs and oversees; it does not replace management in ordinary operations unless required by reserved matter or emergency condition;\
b) management executes within delegated authority; it does not create corporate authority by habit;\
c) technical teams steward methods, repositories, standards, and outputs within approved mandates; they do not override fiduciary duties or legal controls;\
d) public narrative communicates institutional position; it does not create authority not recorded in governance instruments;\
e) councils, members, advisers, and working groups contribute expertise and legitimacy; they do not become the fiduciary apex; and\
f) cross-entity interfaces coordinate interoperability; they do not merge legal authority or erase corporate separateness.

No program success, technical sophistication, founder prestige, public attention, donor relationship, or external recognition shall alter the allocation of corporate authority under this Part.

#### 184.5 Binding Effect of Part IX Across the Membership Authority, Board, Officers, Committees, Secretariat, and All Delegated Governance Surfaces

Part IX shall bind the membership authority or general assembly function where applicable, the Board, trustees, directors, officers, committee members, senior management, secretariat functions, governance-spine offices, delegated authorities, signatories, representatives, and any person or body exercising or claiming corporate governance authority for GCRI US.

Its binding effect extends to:

a) corporate meetings and written resolutions;\
b) Board and committee proceedings;\
c) trustee and officer conduct;\
d) election, appointment, resignation, removal, and succession;\
e) reserved matters and non-delegable decisions;\
f) budgets, financial plans, contracts, funding, compensation, and related-party approvals;\
g) risk, audit, security, safeguards, compliance, and incident oversight;\
h) corporate records, notices, minutes, resolutions, registers, and authoritative copies;\
i) delegations, mandates, signature authority, and emergency powers; and\
j) public statements describing governance, authority, office, approval, or institutional position.

No person may avoid this Part by describing an act as informal, operational, strategic, technical, founding, emergency, advisory, or reputational where the act has corporate-governance effect.

#### 184.6 Governing Rule of Part IX

The governing rule of Part IX is as follows: corporate authority within GCRI US shall be fiduciary, recorded, procedurally valid, mission-bound, non-capturing, non-executionary, and exercised only by the organ, office, committee, or delegate that has lawful and recorded authority for the matter at issue.

Accordingly:

a) no office creates unlimited authority;\
b) no committee may exercise reserved matters unless expressly authorized;\
c) no executive habit may become corporate mandate;\
d) no founder, donor, sponsor, member, or public figure may govern by prestige;\
e) no emergency may permanently alter authority without proper amendment;\
f) no decision has full institutional effect without traceable authority and record; and\
g) ambiguity resolves toward narrower authority, stronger fiduciary discipline, and better record integrity.

#### 184.7 Interpretive Rule for Purpose, Constitutional Function, and Governing Rule of Part IX

This Section shall be interpreted to preserve a controlling proposition: Part IX exists to ensure that GCRI US is governed through lawful fiduciary organs, formal authority, recorded decisions, clear delegations, reserved-matter discipline, and accountable oversight, not through personality, convenience, shadow structures, or operational drift.

Where ambiguity exists, the interpretation that better preserves fiduciary duty, mission lock, corporate separateness, authority mapping, reserved-matter discipline, procedural validity, and record integrity shall prevail unless a contrary result is required by law.

### 185. Foundational Corporate Governance Doctrine (GCRI United States)

#### 185.1 GCRI US as a United States Nonprofit Corporation With Formal Governing Organs

GCRI US shall be governed as a United States nonprofit corporation with formal governing organs, recorded authority, fiduciary duties, corporate records, officer roles, reserved matters, and lawful decision procedures. Its corporate governance shall not be treated as a loose project structure, informal coalition, founder-led initiative, advisory network, program platform, technical community, or voluntary association without legal consequence.

The Corporation’s governing architecture shall recognize, as applicable:

a) the members or membership authority, where membership rights are formally created;\
b) the Board as the primary fiduciary oversight organ;\
c) trustees or directors as fiduciaries of the Corporation and its public-benefit mission;\
d) officers as holders of defined corporate functions, not unlimited institutional authority;\
e) committees as delegated or advisory governance bodies acting within written charters;\
f) executive management as operational leadership acting within delegated authority;\
g) governance-spine offices as high-integrity control functions; and\
h) corporate records as the evidence of lawful authority and institutional continuity.

The Corporation shall preserve corporate form because its mission depends on legitimacy. Public-good stewardship, research independence, safeguarding, nonprofit integrity, donor neutrality, public trust, and non-execution discipline require a governance system that can prove who decided what, under what authority, through what procedure, with what record, and subject to what constraints.

***

#### 185.2 Corporate Governance as Distinct From Informal Influence, Founding Prestige, or Technical Centrality

Corporate governance authority shall be distinct from informal influence, founding prestige, technical centrality, donor importance, public visibility, strategic relevance, intellectual contribution, or operational indispensability. A person or institution may be important to the Corporation’s history, strategy, funding, knowledge base, public profile, or technical architecture without thereby holding corporate authority.

Accordingly:

a) founders do not hold continuing governance authority unless appointed or elected to a current role;\
b) donors and sponsors do not govern by financial contribution;\
c) technical architects do not override Board fiduciary authority by expertise;\
d) senior advisers do not bind the Corporation without delegated authority;\
e) members do not acquire corporate control through participation;\
f) public officials, academics, corporate leaders, or institutional partners do not govern by prestige; and\
g) management does not acquire reserved-matter authority through repeated practice.

This distinction is central to the GCRI US model. The Corporation is designed to steward public-good infrastructure while resisting capture by any founder, funder, sector, vendor, state, political bloc, technical community, or executive personality. Corporate governance must therefore remain formal, fiduciary, recorded, and bounded.

***

#### 185.3 No Governance by Courtesy, Proximity, Sponsorship, or Shadow Structures

GCRI US shall prohibit governance by courtesy, proximity, sponsorship, informal leadership circles, executive convenience, donor preference, private side discussions, messaging groups, standing calls, unrecorded committees, or shadow structures. Governance authority exists only where created by law, governing instruments, Board resolution, membership action where applicable, officer appointment, committee charter, delegation instrument, or other recorded authority.

The Corporation shall not permit:

a) informal founder councils to control institutional direction;\
b) donors or sponsors to shape decisions outside approved reporting channels;\
c) advisers to operate as de facto executives without appointment;\
d) technical teams to make constitutional, financial, or legal decisions by operational necessity;\
e) executives to rely on repeated practice as authority for reserved matters;\
f) members to organize unofficial voting blocs with institutional effect outside proper procedures;\
g) staff or contractors to bind the Corporation through emails, proposals, or public statements without signature authority; or\
h) external partners to treat working relationships as governance authority.

Shadow governance is particularly dangerous in a public-good institution because it allows influence without accountability, decisions without record, and power without fiduciary duty. Any governance-relevant discussion occurring outside formal process shall be routed back into the proper organ and recorded before it has effect.

***

#### 185.4 No Organ May Exceed Its Recorded Authority or Reserved-Matter Boundary

No organ, office, committee, officer, trustee, executive, member body, secretariat function, working group, council, program team, technical body, or delegated actor may exceed its recorded authority or reserved-matter boundary. Authority shall be interpreted according to the governing instrument that created it, the applicable delegation, the matter class, the approval threshold, the conflict rules, and the record of decision.

Reserved matters shall remain with the Board, members, or other competent body where law, charter, bylaws, policy, or resolution so requires. A committee may study, recommend, monitor, or prepare a matter, but may not decide a reserved matter unless expressly authorized. Management may implement an approved budget, contract, program, or policy, but may not approve the reserved matter itself by operational execution.

Where authority is uncertain, the actor shall pause and escalate. GCRI US shall not treat urgency, donor timing, partner expectation, reputational opportunity, or operational pressure as authority to bypass reserved-matter controls.

Any act outside authority may be treated as void, voidable, provisional, non-binding, subject to ratification, subject to correction, or subject to remedial action, depending on law, reliance, harm, and institutional risk.

***

#### 185.5 Corporate Form Must Remain Subordinate to Public-Benefit Purpose and Mission Lock

Corporate form exists to serve the Corporation’s public-benefit purpose and mission lock. It shall not be used to defeat the very mission it is designed to protect. The Board, officers, members, committees, and management shall interpret corporate powers in a manner consistent with nonprofit character, public-good stewardship, safeguards, asset protection, security, financial independence, and non-execution.

Corporate powers shall not be used to:

a) convert public-good assets into private advantage;\
b) authorize regulated execution outside the Corporation’s lawful role;\
c) create improper private benefit or inurement;\
d) privilege funders, sponsors, vendors, insiders, or founders;\
e) suppress protected reporting or safeguards concerns;\
f) conceal material risk, financial weakness, or governance failure;\
g) overstate institutional authority, maturity, capacity, or public recognition; or\
h) subordinate mission to revenue, prestige, convenience, or growth.

The Corporation may evolve, expand, partner, publish, convene, receive funds, employ staff, enter contracts, and participate in national or global public-good systems. But every such corporate act must remain subordinate to mission lock and constitutional discipline.

***

#### 185.6 Most-Restrictive Reading Where Governance Ambiguity Could Expand Authority, Weaken Controls, or Distort Institutional Character

Where governance ambiguity could expand authority, weaken controls, blur the non-execution boundary, distort institutional character, create public overclaim, bypass reserved matters, permit private benefit, undermine safeguards, or allow capture, the most restrictive reading shall apply until the competent authority clarifies the matter.

This rule applies where ambiguity exists concerning:

a) whether a matter is reserved to the Board;\
b) whether an officer may sign or commit the Corporation;\
c) whether a committee has decision authority or only recommendation authority;\
d) whether management may proceed without Board approval;\
e) whether a public statement has been authorized;\
f) whether a person speaks for GCRI US or another entity;\
g) whether a funding, contract, or partnership arrangement creates governance consequences;\
h) whether an emergency measure may continue; and\
i) whether a technical, program, or membership act has corporate effect.

The restrictive reading is not designed to paralyze the Corporation. It is designed to prevent accidental constitutional change through ambiguity. Authority may be broadened, delegated, clarified, or ratified only through proper process and record.

***

#### 185.7 Records-First and Forms-First Rules Apply to Corporate Governance Acts

GCRI US shall follow a records-first and forms-first discipline for corporate governance acts. Governance must be legible before it is relied upon. The Corporation shall use appropriate forms, resolutions, minutes, written consents, delegations, registers, notices, certificates, officer records, committee charters, mandate instruments, and authoritative copies to evidence corporate action.

Corporate governance acts requiring records may include:

a) Board and committee meetings;\
b) member or assembly actions where applicable;\
c) trustee and officer appointments, resignations, removals, and succession;\
d) adoption or amendment of bylaws, policies, charters, annexes, and schedules;\
e) approval of budgets, contracts, funding, compensation, related-party matters, and reserved transactions;\
f) creation of committees, offices, delegations, signature matrices, and authority thresholds;\
g) emergency actions and ratification;\
h) conflict disclosures, recusals, and independence determinations;\
i) dissolution, wind-down, asset transfer, or successor stewardship decisions; and\
j) public statements of institutional position where formal approval is required.

If the form is missing, incomplete, unsigned, inconsistent, or not retained, the Corporation shall cure the record before reliance where practicable. Informal communication may support background understanding, but it shall not substitute for the authoritative governance record.

***

#### 185.8 No Valid Governance Effect Without Proper Authority, Procedure, and Record

No governance act shall have valid institutional effect unless it is supported by proper authority, proper procedure, and proper record. These three elements are cumulative.

Proper authority requires that the correct organ, office, committee, officer, trustee, executive, member body, or delegate has power to act. Proper procedure requires that notice, agenda, quorum, conflict, voting, consent, controlled-room, publication, and decision rules are followed. Proper record requires that the act is documented in a manner sufficient to prove the decision, authority, effective date, scope, conditions, and continuing obligations.

Where one element is missing:

a) the act may be ineffective;\
b) the act may be provisional only;\
c) the act may require ratification;\
d) the act may require correction or re-approval;\
e) the act may be voidable;\
f) the act may require notice to affected parties; and\
g) the actor may be subject to review if the failure was material, repeated, negligent, or intentional.

A governance system that cannot prove authority cannot sustain public trust. GCRI US shall therefore treat validity-by-record as a constitutional control, not clerical preference.

***

#### 185.9 Corporate Governance Must Preserve the Two-Stack Firewall and Non-Execution Perimeter

GCRI US corporate governance shall preserve the strict distinction between nonprofit public-good stewardship and any execution-side, regulated, commercial, transaction, market, insurance, securities, lending, custody, settlement, or financial-delivery activity conducted by separate lawful actors outside the Corporation’s remit.

The Board and officers shall ensure that no corporate act causes GCRI US to:

a) bind, broker, underwrite, place, arrange, custody, settle, insure, guarantee, lend, advise on, or intermediate regulated products or transactions;\
b) operate as a payment, market, exchange, investment, insurance, banking, or regulated financial actor;\
c) accept transaction-linked, success-linked, or execution-linked revenue inconsistent with nonprofit boundaries;\
d) supervise execution-side actors beyond lawful public-good, governance, standards, research, evidence, or assurance-related interfaces;\
e) use nonprofit assets to subsidize execution-side private advantage; or\
f) create public confusion that GCRI US itself executes, guarantees, or approves market activity.

Corporate governance must therefore examine not only what the Corporation intends, but how a decision may be read by regulators, funders, members, public authorities, counterparties, and the public. If a governance act could blur the firewall, it shall be narrowed, disclaimed, restructured, or refused.

***

#### 185.10 Board Primacy in Fiduciary Oversight Does Not Eliminate Member, Officer, Committee, or Management Functions

The Board shall be the primary fiduciary oversight organ, but Board primacy shall not eliminate properly assigned member, officer, committee, executive, secretariat, or management functions. Governance must be both disciplined and workable.

Accordingly:

a) members may exercise membership rights where the governing instruments assign them;\
b) officers may perform defined corporate functions;\
c) committees may prepare, review, recommend, monitor, and decide matters within delegated scope;\
d) executive leadership may manage operations within approved budget and delegated authority;\
e) governance-spine functions may escalate integrity, records, compliance, security, and safeguards matters; and\
f) technical and program teams may perform work within approved mandates.

The Board shall not micromanage ordinary operations where management has authority. Management shall not usurp reserved matters. Committees shall not become substitute boards. Members shall not become fiduciary managers. The doctrine is functional separation under Board oversight.

***

#### 185.11 Fiduciary Governance Must Be Evidence-Informed, Not Personality-Led

GCRI US shall require fiduciary governance to be evidence-informed, documented, and deliberative. Corporate decisions shall not be made by charisma, urgency, loyalty, reputation, hierarchy, or personal confidence alone. Trustees and officers shall request, receive, question, and record sufficient information to make informed decisions.

Evidence for fiduciary decisions may include:

a) management reports;\
b) financial statements and budget materials;\
c) legal analysis;\
d) risk assessments;\
e) audit findings;\
f) safeguards reports;\
g) security and privacy assessments;\
h) conflict disclosures;\
i) stakeholder or member inputs where relevant;\
j) technical assessments; and\
k) public-benefit rationale.

The Board may rely on management, experts, committees, counsel, auditors, and technical advisers where reliance is reasonable. But reliance does not mean abdication. Where information is incomplete, conflicted, promotional, or materially uncertain, the Board shall seek clarification or impose conditions before acting.

***

#### 185.12 Corporate Governance Must Be Capable of Operating Under Growth, Stress, and Transition

The corporate governance doctrine of GCRI US shall be designed for growth, stress, leadership transition, funding volatility, public scrutiny, emergency conditions, cross-border complexity, and institutional maturation. Governance that works only when the institution is small, founder-led, and informal is not adequate for the Corporation’s mission.

The governance system shall therefore include:

a) scalable Board and committee structures;\
b) clear officer succession;\
c) emergency governance controls;\
d) continuity of corporate records;\
e) delegation matrices;\
f) reserve and financial oversight discipline;\
g) protected reporting routes;\
h) authority mapping for rapid decision-making;\
i) conflict and capture controls; and\
j) mechanisms for lawful amendment and institutional learning.

The Corporation shall not confuse speed with informality. High-quality governance enables speed by making authority clear before crisis.

***

#### 185.13 Interpretive Rule for Foundational Corporate Governance Doctrine

This Section shall be interpreted to preserve a controlling proposition: GCRI US shall be governed through formal corporate organs, fiduciary authority, recorded procedure, reserved-matter discipline, mission lock, and evidence-informed oversight, not through informal influence, founding prestige, donor leverage, operational habit, technical centrality, or shadow governance.

Where ambiguity exists, the interpretation that better preserves:

a) corporate form and public-benefit purpose;\
b) Board fiduciary oversight;\
c) no governance by proximity or sponsorship;\
d) reserved-matter boundaries;\
e) records-first and forms-first discipline;\
f) validity through authority, procedure, and record;\
g) non-execution firewall protection; and\
h) resilience under growth, stress, and transition

shall prevail unless a contrary result is required by law.

### 186. Membership Authority / General Assembly — Nature, Role, and Constitutional Position (GCRI United States)

#### 186.1 Membership Authority as the Formal Member Organ Where Membership Rights Are Created

Where GCRI US establishes voting members, statutory members, classes of members with governance rights, or a formal General Assembly equivalent, that membership authority shall operate as a formal corporate organ only to the extent created by the Articles, Bylaws, Board-approved membership instruments, applicable law, or a recorded constitutional instrument.

The membership authority shall not arise merely because GCRI US has members in a programmatic, advisory, network, council, donor, affiliate, or participation sense. Membership for engagement is distinct from membership as a legal governance organ. Only members expressly granted governance rights may exercise governance functions.

Accordingly, the Corporation shall distinguish:

a) members with voting or statutory rights, where such rights exist;\
b) non-voting members;\
c) institutional participants;\
d) observers;\
e) affiliates;\
f) donors, sponsors, partners, or supporters;\
g) council participants; and\
h) Registry-authorized service persons.

No person or institution may claim General Assembly standing unless the Corporation’s authoritative record confirms that such standing exists for the relevant class, matter, and status state.

#### 186.2 Membership Authority as a Constitutional Organ Rather Than a Ceremonial Forum

Where constituted, the membership authority shall be a constitutional organ, not a ceremonial forum, promotional gathering, annual showcase, donor convening, or program event. Its function is to exercise specific governance rights assigned to members, receive accountability information where applicable, and provide a formal legitimacy channel within the limits of nonprofit corporate law and the Corporation’s Bylaws.

The membership authority may support institutional legitimacy by:

a) confirming that formal members remain informed of major institutional developments;\
b) receiving annual reports, accountability packs, audit summaries, and governance updates where assigned;\
c) exercising election, confirmation, amendment, or reserved approval rights where assigned;\
d) providing a formal channel for member questions, objections, dissent, and recorded accountability; and\
e) maintaining a visible distinction between lawful member authority and informal stakeholder influence.

The membership authority shall not become a substitute Board, management committee, technical council, funding committee, political assembly, or public narrative platform. Its legitimacy depends on disciplined scope.

#### 186.3 Scope of Membership Authority

The scope of membership authority shall be limited to matters expressly assigned by applicable law, the Articles, these Bylaws, membership class instruments, or recorded Board-approved governance instruments. No member body may enlarge its own powers by practice, custom, turnout, political pressure, donor alignment, or public expectation.

The scope may include, where expressly assigned:

a) election, confirmation, or removal of trustees or directors;\
b) approval of certain constitutional amendments;\
c) receipt of annual reports and audited or reviewed financial statements;\
d) approval of dissolution or successor stewardship matters where member approval is legally or constitutionally required;\
e) approval of high-order mission or structural changes where assigned;\
f) member resolutions or advisory statements within defined limits; and\
g) other matters reserved to members by law or governing instrument.

Unless expressly assigned, the membership authority shall not approve ordinary operations, contracts, hiring, procurement, publication decisions, technical releases, restricted handling, litigation strategy, security incident response, donor acceptance, or program execution.

#### 186.4 Membership Authority Distinct From Board, Officers, Secretariat, Councils, and Program Structures

The membership authority shall be distinct from the Board, officers, senior management, Secretariat, councils, committees, technical teams, working groups, Academy structures, research programs, public convenings, and cross-entity interfaces.

The distinction shall operate as follows:

a) the Board bears fiduciary oversight and reserved-matter responsibility;\
b) officers perform defined corporate functions;\
c) management administers operations within delegated authority;\
d) committees act within Board-approved charters;\
e) councils and working bodies contribute expertise or structured participation where authorized;\
f) the Registry controls service eligibility and access-linked roles; and\
g) the membership authority exercises only formal member powers assigned to it.

A person may appear in multiple contexts, but each context must be governed by its own authority. Participation in a council does not confer member voting rights. Membership does not confer Board authority. Secretariat support does not create decision authority. Public attendance does not create membership standing.

#### 186.5 No Expansion of Membership Authority Beyond Recorded Instruments

No membership authority, General Assembly, member meeting, caucus, member forum, member consultation, or member resolution shall expand the powers of the members beyond recorded instruments. A member vote outside scope shall not bind the Corporation. A member recommendation may be valuable, but it remains advisory unless the governing record makes it operative.

GCRI US shall reject attempts to expand member authority through:

a) informal resolutions;\
b) public pressure campaigns;\
c) donor-aligned member blocs;\
d) claims of “founding member” superiority;\
e) statements that member consensus overrides Board duties;\
f) informal annual meeting traditions;\
g) unrecorded side agreements; or\
h) claims that broad participation equals governance mandate.

Where members express views on matters outside their authority, the Board or competent body may receive, consider, publish, route, or decline those views, but fiduciary responsibility remains with the proper organ.

#### 186.6 Relationship Between Membership Legitimacy and Fiduciary Governance

Membership legitimacy and fiduciary governance shall reinforce one another without merging. The membership authority may strengthen legitimacy by ensuring accountability, participation, and structured member voice. The Board preserves fiduciary governance by ensuring that member preferences do not breach mission lock, public-benefit duty, legal obligations, safeguards, non-execution boundaries, asset stewardship, or the rights of protected participants.

The Board shall respect member authority where validly exercised. Members shall respect Board authority where the matter belongs to fiduciary oversight, legal compliance, risk management, security, finance, employment, contractual commitments, or reserved Board judgment.

Where member sentiment conflicts with fiduciary duty, fiduciary duty shall prevail. The Board may not implement a member preference that is unlawful, unsafe, financially imprudent, inconsistent with nonprofit status, damaging to public-good assets, or contrary to these Bylaws.

Legitimacy is not majoritarianism alone. In the GCRI US model, legitimacy requires participation plus fiduciary discipline, transparency plus privacy protection, member voice plus safeguards, and public-benefit commitment plus lawful corporate form.

#### 186.7 Membership Authority and the Nexus Public-Good Model

In the Nexus public-good model, GCRI US may convene members from academia, civil society, community institutions, public authorities, professional bodies, technical communities, private sector actors, and other mission-aligned institutions. The membership authority must therefore be designed to prevent three predictable risks:

a) capture risk, where larger, better-funded, better-connected, or more visible members seek to dominate the institution;\
b) overclaim risk, where membership is publicly described as recognition, endorsement, certification, market routeability, or public authority approval; and\
c) perimeter risk, where members attempt to convert public-good participation into execution-side, procurement, commercial, political, or regulated influence.

The membership authority shall therefore operate within the same firewall doctrine that governs the rest of the Corporation. It may create voice, accountability, and legitimacy. It shall not create execution authority, private advantage, market preference, or institutional control outside recorded governance rights.

#### 186.8 Member Resolutions, Advisory Statements, and Institutional Response

Where permitted, members may propose resolutions, advisory statements, questions, requests for accountability, nominations, objections, or recommendations. Such member actions shall be governed by admissibility rules, notice requirements, agenda discipline, conflict controls, class eligibility, and publication rules.

Member statements shall be classified as:

a) binding member action, only where the governing instruments assign binding effect;\
b) advisory recommendation, where the matter is within member concern but outside binding authority;\
c) accountability request, where members seek explanation or reporting from the Board or management;\
d) dissent or minority statement, where members request preservation of objection; or\
e) inadmissible matter, where the request exceeds scope, violates law, compromises confidentiality, harms protected participants, or intrudes into reserved Board or management authority.

The Corporation shall maintain a process for routing valid member actions to the Board or appropriate body. A member statement shall not acquire binding effect merely because it is popular, public, unanimous, or urgent.

#### 186.9 Membership Authority in Emergency, Sensitive, or Controlled Matters

Certain matters may be too sensitive for ordinary member deliberation because they involve security, privacy, legal privilege, personnel matters, whistleblowing, investigations, sanctions, protected participants, Indigenous or community-sensitive information, public-authority-sensitive matters, controlled-room records, financial distress, or live incident response.

Where a matter assigned to members has sensitive elements, GCRI US may use:

a) controlled summaries;\
b) redacted materials;\
c) restricted member sessions;\
d) closed voting procedures;\
e) independent scrutineers;\
f) legal or audit briefings;\
g) role-marker participation;\
h) publication-class restrictions; and\
i) Board certification of confidential facts.

Member authority does not create unlimited access to sensitive information. The Corporation shall provide enough information for valid action where required, while preserving security, privacy, privilege, safeguards, and legal duties.

#### 186.10 Interpretive Rule for Membership Authority / General Assembly

This Section shall be interpreted to preserve a controlling proposition: the GCRI US membership authority, where constituted, is a formal and scope-limited corporate organ that supports legitimacy and accountability without displacing Board fiduciary duties, management authority, Registry controls, safeguards, or the Corporation’s non-execution public-good boundary.

Where ambiguity exists, the interpretation that better preserves:

a) formal member authority over informal stakeholder influence;\
b) narrow scope of member powers;\
c) Board fiduciary primacy where required;\
d) separation from councils, programs, and public narrative;\
e) anti-capture controls;\
f) accurate public meaning; and\
g) safe handling of sensitive matters

shall prevail unless a contrary result is required by law.

### 187. Composition, Membership, and Seating of the Membership Authority / General Assembly (GCRI United States)

#### 187.1 Composition by Eligible Membership Classes

The Membership Authority or General Assembly of GCRI US, where constituted, shall be composed only of those membership classes that have been expressly granted assembly standing, voting standing, observer standing, consultative standing, or other formal participation rights under the Articles, these Bylaws, a Board-approved membership schedule, or another recorded governance instrument.

The existence of a membership class shall not automatically mean that the class forms part of the Membership Authority. GCRI US may maintain several forms of membership or participation, including voting members, non-voting members, institutional members, observer participants, affiliates, fellows, program participants, council contributors, donors, sponsors, and service-role holders. Only those categories expressly assigned assembly rights shall be seated for assembly purposes.

The composition rules shall identify, for each eligible class:

a) whether the class has voting, non-voting, observer, consultative, or limited participation rights;\
b) whether the class may attend ordinary, special, extraordinary, or emergency meetings;\
c) whether the class may submit motions, questions, nominations, objections, or advisory statements;\
d) whether the class may receive full, restricted, redacted, or public-safe meeting materials;\
e) whether the class may participate through a delegate, alternate, adviser, or observer;\
f) whether the class is subject to sector, jurisdiction, affiliation, or anti-capture caps; and\
g) whether special safeguards apply to public authorities, Indigenous institutions, community bodies, vulnerable participants, or high-sensitivity representatives.

Composition shall be designed to preserve legitimacy, balance, mission alignment, and institutional independence. It shall not be designed to maximize impressive names, donor visibility, or sector dominance.

#### 187.2 Seating Requirements and Verification of Good Standing

No member shall be seated in the Membership Authority unless the Corporation verifies that the member is in the required standing state for the relevant meeting, matter, vote, consent, consultation, or assembly function. Seating is a validity condition. A person or institution may be known to GCRI US and still be ineligible to sit for a particular assembly act if its status, class, mandate, dues condition, representative authority, or access condition is deficient.

Before seating, GCRI US shall verify, as applicable:

a) current membership class;\
b) active or otherwise eligible status state;\
c) payment, waiver, scholarship, service-credit, or alternative good-standing condition;\
d) absence of suspension, lapse, termination, access hold, or unresolved at-risk condition affecting assembly rights;\
e) valid representative or delegate mandate;\
f) voting eligibility, if any;\
g) conflict, recusal, or excluded-vote conditions;\
h) publication class and access eligibility for meeting materials; and\
i) any special conditions imposed at admission, renewal, reinstatement, or prior review.

A member whose good standing is unclear may be seated conditionally, seated for observation only, excluded from voting, held pending cure, or deferred until verification is complete. GCRI US shall not rely on informal familiarity, historic participation, founding contribution, or public listing as a substitute for current good-standing verification.

#### 187.3 Rights of Voting Members, Non-Voting Members, and Observers in Assembly Context

The Corporation shall distinguish clearly among voting members, non-voting members, observers, invited guests, advisers, staff, auditors, counsel, scrutineers, and other participants in assembly contexts. The distinction shall be reflected in notices, attendance records, meeting materials, minutes, voting lists, public summaries, and seating records.

Voting members may exercise voting rights only where the matter is within their assigned authority, the member is in the required standing state, the representative is properly mandated, and no conflict or disqualification applies.

Non-voting members may attend, receive information, ask questions, submit comments, or participate in discussion only to the extent assigned by their class and the meeting rules. Non-voting participation shall not be recorded or described as approval, consent, vote, ratification, or institutional adoption.

Observers may observe only within the scope approved for the meeting or matter. Observer status shall not include voting, nomination, motion, amendment, approval, consent, controlled-access, or speaking rights unless expressly granted for the specific meeting. Observers may be excluded from confidential, controlled, privileged, personnel, legal, security, financial, or safeguards-sensitive segments.

Where the attendance record includes multiple categories, the record shall state the category of each participant. Ambiguous attendance records create governance risk and shall be corrected.

#### 187.4 Representation of Institutions Through Authorized Delegates Only

Institutional members shall participate in the Membership Authority only through authorized delegates, representatives, alternates, or other persons whose authority is current, recorded, and sufficient for the specific assembly act. Employment, seniority, prior participation, institutional email, professional title, or personal relationship shall not be enough.

A delegate may be authorized to:

a) attend;\
b) receive notice;\
c) speak;\
d) submit questions or comments;\
e) propose or second motions where permitted;\
f) vote;\
g) consent;\
h) object or record dissent;\
i) receive restricted materials; or\
j) bind the member to procedural undertakings.

Each power must be express where the consequence is material. Authority to attend shall not imply authority to vote. Authority to speak shall not imply authority to consent. Authority to submit views shall not imply authority to waive rights. Authority to represent the member shall not imply authority to represent GCRI US.

Where a member sends more than one participant, the Corporation shall identify which person is the voting delegate, which persons are alternates, which persons are advisers, and which persons are observers. If multiple persons purport to act for the same member and authority is contested or unclear, GCRI US may suspend the member’s voting or speaking recognition until the mandate is resolved.

#### 187.5 Credential Verification, Challenge, and Cure Before Seating

GCRI US shall maintain a credential verification process for assembly participation. The process shall ensure that each member and delegate is eligible to be seated, that voting lists are accurate, that conflicts and recusals are reflected, and that no person participates with authority they do not possess.

Credential verification may include review of:

a) member status record;\
b) mandate letter or delegation instrument;\
c) dues or good-standing record;\
d) class rights;\
e) access class;\
f) conflict disclosures;\
g) representative identity;\
h) proxy or alternate designation, if permitted; and\
i) any suspension, hold, or restriction.

A credential challenge may be raised by the Corporation, a member, a delegate, the chair, the secretary, the scrutineer, counsel, or another authorized person. Challenges shall be handled promptly, fairly, and in a manner that protects meeting integrity.

Where a credential defect is curable, the Corporation may allow cure before seating or before a vote is counted. Cure may include updated mandate confirmation, proof of good standing, corrected representative designation, conflict clarification, or class-status correction. Where cure is not available in time, the member may be seated without vote, seated conditionally, excluded from the affected matter, or treated as not present for quorum and voting purposes.

#### 187.6 Suspension, Exclusion, or Conditional Seating for Integrity, Perimeter, or Safeguards Reasons

GCRI US may suspend, exclude, or conditionally seat a member, delegate, representative, observer, adviser, or guest where participation would create material integrity, security, privacy, safeguards, public-description, perimeter, conflict, capture, disruption, or legal risk. Such action shall be proportionate, recorded, and reviewable where appropriate.

Grounds for suspension, exclusion, or conditional seating may include:

a) unresolved membership standing deficiency;\
b) invalid, expired, or contested delegate authority;\
c) conflict or recusal condition affecting the matter;\
d) sanctions, corruption, fraud, financial-crime, or public-integrity concern;\
e) breach or threatened breach of confidentiality, privacy, security, or controlled-handling rules;\
f) harassment, intimidation, retaliation, or unsafe participation conduct;\
g) attempt to use the assembly for procurement, commercial, political, execution-side, or market-facing purposes;\
h) misuse of GCRI US name, marks, membership language, or public authority;\
i) donor, sponsor, vendor, sector, or bloc pressure inconsistent with assembly neutrality; or\
j) emergency protective need.

Conditional seating may permit observation but not voting, discussion but not access to controlled materials, attendance in public segments but exclusion from restricted segments, or participation subject to role-marker and no-public-claim conditions.

Exclusion shall not be used to suppress good-faith dissent, minority positions, protected reporting, or legitimate criticism. The purpose is protection of the assembly’s lawful function, not management of disagreement.

#### 187.7 Public Description and Publication Class Rules for Assembly Composition

The composition of the Membership Authority, attendance lists, delegate identities, member classes, observer categories, voting results, dissent records, and meeting summaries shall be assigned appropriate publication classes. GCRI US shall distinguish between information suitable for public transparency and information requiring restricted handling.

Public disclosure may include:

a) the existence of an annual or special assembly;\
b) approved public-safe description of participating member classes;\
c) public-safe attendance summaries where appropriate;\
d) certified voting results where public release is authorized;\
e) annual accountability statements; and\
f) approved reports or resolutions.

Restricted or controlled handling may be required for:

i) sensitive member identities;\
ii) public-authority or Indigenous participation requiring care;\
iii) protected participants;\
iv) security-sensitive or privacy-sensitive attendance records;\
v) member status disputes;\
vi) disciplinary, sanctions, or integrity matters;\
vii) controlled-room agenda segments;\
viii) confidential financial, legal, personnel, or incident matters; and\
ix) dissent records where disclosure may expose participants to harm.

Public materials shall not list applicants, observers, non-voting participants, guests, advisers, or former members as voting members. They shall not imply government endorsement, Indigenous consent, public-authority adoption, corporate partnership, certification, routeability, or institutional support beyond recorded status.

#### 187.8 Assembly Seating Register and Attendance Record

GCRI US shall maintain an assembly seating register for each meeting of the Membership Authority. The seating register shall be the authoritative record of who was entitled to attend, who attended, who was seated with vote, who was seated without vote, who was present as observer or adviser, who was excluded or conditionally seated, and who held authority to act for each institutional member.

The seating register shall include, as applicable:

a) meeting identifier, date, time, and modality;\
b) member name and class;\
c) member status and good-standing confirmation;\
d) delegate name, role, and authority basis;\
e) voting eligibility;\
f) proxy or alternate status, if permitted;\
g) conflicts, recusals, or excluded matters;\
h) attendance status;\
i) conditional seating terms;\
j) challenge or cure notes;\
k) publication class; and\
l) certification by the secretary, chair, scrutineer, or designated authority.

The seating register shall link to the minutes, voting record, notice record, agenda, credential file, and any controlled-room attendance record. If seating is defective, the validity of votes or proceedings may be affected. Therefore, the seating register shall be prepared before or at the beginning of the meeting and finalized after credential challenges are resolved.

#### 187.9 Quorum Relationship to Composition and Seating

Quorum shall be calculated only by reference to members or delegates properly entitled to be counted for the relevant matter. Persons present without voting rights, persons seated as observers, persons whose credentials are defective, persons recused from a matter, persons excluded from a controlled segment, and persons whose status is suspended or lapsed shall not be counted toward quorum unless the applicable rule expressly permits.

Where different matters require different voting classes or thresholds, quorum shall be assessed separately for each matter. A meeting may have quorum for ordinary business but not for a special resolution. It may have quorum for a public session but not for a controlled member vote. It may have quorum before recusal but lose quorum after conflicted members are excluded.

If quorum is lost, the chair or secretary shall record the loss and determine whether the meeting may continue for discussion only, adjourn, defer the item, seek cure, or proceed with non-decision business. No decision requiring quorum shall be treated as valid after quorum is lost.

#### 187.10 Assembly Composition as an Anti-Capture Control

The composition and seating of the Membership Authority shall function as an anti-capture control. The Corporation shall monitor whether the assembly is becoming structurally dominated by a donor bloc, corporate bloc, state-linked bloc, sector group, regional group, founding group, affiliate cluster, or other aligned constituency.

Anti-capture review may examine:

a) concentration of voting rights;\
b) concentration of dues or financial support;\
c) repeated control of motions, agenda items, or votes;\
d) affiliate aggregation;\
e) public-authority or corporate overrepresentation;\
f) exclusion or chilling of civil-society, Indigenous, community, academic, youth, or under-resourced participation;\
g) alignment between sponsors and voting outcomes; and\
h) attempts to use assembly process for procurement, execution, political, or public-claim advantage.

Where imbalance emerges, GCRI US may adjust class rules, seating rules, caps, rotation, observer categories, voting thresholds, conflict rules, or participation supports, subject to lawful amendment and due process. Assembly legitimacy depends on disciplined composition, not numerical attendance alone.

#### 187.11 Accessibility, Inclusion, and Safe Participation in Seating

Seating rules shall be administered in a manner consistent with accessibility, inclusion, safe participation, dignity, and non-retaliation. GCRI US shall not design credentialing or seating rules that unnecessarily exclude under-resourced, disabled, community-based, Indigenous, remote, multilingual, or otherwise legitimate participants.

The Corporation may provide:

a) remote participation;\
b) accessible meeting formats;\
c) interpretation or translation where feasible;\
d) role-marker participation for sensitive delegates;\
e) support for protected participants;\
f) flexible mandate verification for non-standard institutional forms; and\
g) alternative participation routes where security or safety prevents ordinary attendance.

Inclusion shall not override authority verification, security, privacy, safeguards, or voting integrity. The model is not open-door informality. It is disciplined accessibility: legitimate participants should be enabled to participate safely and lawfully, while invalid authority, unsafe access, and misleading claims remain controlled.

#### 187.12 Interpretive Rule for Composition, Membership, and Seating of the Membership Authority

This Section shall be interpreted to preserve a controlling proposition: only members and delegates with the correct class, status, mandate, standing, credentials, and publication clearance may be seated in the GCRI US Membership Authority for the rights and matters assigned to them, and seating shall be administered as a validity, legitimacy, anti-capture, and safe-participation control.

Where ambiguity exists, the interpretation that better preserves:

a) class-specific assembly composition;\
b) good-standing verification;\
c) clear distinction between voting, non-voting, observer, and adviser roles;\
d) authorized institutional delegation;\
e) credential challenge and cure discipline;\
f) protective suspension or conditional seating where needed;\
g) accurate publication-class treatment;\
h) quorum integrity;\
i) anti-capture balance; and\
j) accessible but controlled participation

shall prevail unless a contrary result is required by law.

### 188. Powers and Reserved Matters of the Membership Authority / General Assembly (GCRI United States)

#### 188.1 Scope of Powers Must Be Expressly Assigned

The Membership Authority or General Assembly of GCRI US, where constituted, shall exercise only those powers expressly assigned to it by applicable law, the Articles, these Bylaws, a Board-approved membership instrument, a class schedule, or another recorded constitutional instrument. The existence of members does not itself create unlimited member power. The existence of an assembly does not itself create authority over every matter of institutional importance.

The powers of the Membership Authority shall be interpreted narrowly and functionally. It may act where a matter has been reserved to it, where member approval is legally required, where the governing instruments assign a specific right to members, or where the Board has properly submitted a matter for member action. It shall not act merely because members have strong views, because a matter is public, because a donor or sector bloc demands a vote, or because a membership forum is the most visible audience.

The record shall identify whether a matter before the Membership Authority is:

a) a binding member decision;\
b) a statutory or bylaw approval;\
c) an election or confirmation;\
d) an advisory resolution;\
e) a report-receipt or accountability item;\
f) a consultative item;\
g) a dissent or objection record; or\
h) an informational matter with no decision effect.

Where the classification is unclear, the item shall be treated as non-binding until the proper authority confirms otherwise.

#### 188.2 Approval of Foundational Constitutional Instruments Where Assigned

The Membership Authority may approve, confirm, receive, or amend foundational constitutional instruments only where that power is expressly assigned. Such instruments may include the Articles, Bylaws, mission-lock provisions, membership class provisions, asset-lock provisions, dissolution provisions, fiduciary governance provisions, or other constitutional instruments requiring member approval under law or governing record.

Where member approval is required, the approval process shall include:

a) proper notice;\
b) identification of the instrument or amendment;\
c) explanation of purpose and effect;\
d) statement of threshold required;\
e) disclosure of whether the matter affects member rights, Board authority, public-good assets, nonprofit status, or mission lock;\
f) conflict and recusal review where relevant;\
g) voting eligibility verification;\
h) certified result; and\
i) authoritative record of the adopted instrument.

No constitutional instrument shall be altered by informal member consensus, public event discussion, donor-requested edits, unrecorded assembly sentiment, or operational practice. Constitutional change requires formal authority and recorded procedure.

Where a proposed constitutional change could weaken mission lock, public-benefit purpose, non-execution discipline, asset stewardship, safeguards, protected participation, privacy, security, anti-capture controls, or fiduciary oversight, the Board shall provide a risk assessment before the matter is submitted to members.

#### 188.3 Election or Confirmation of Trustees and Other Offices Where Assigned

The Membership Authority may elect, confirm, remove, or otherwise participate in the appointment of trustees, directors, officers, committee members, or other governance roles only where such authority is expressly assigned. The election or confirmation role of members shall be governed by eligibility, nomination, fit-and-proper, conflict, anti-capture, voting, and records rules.

Where members have election or confirmation authority, the process shall ensure that candidates are assessed for:

a) fiduciary suitability;\
b) independence and conflict profile;\
c) mission alignment;\
d) capacity to preserve nonprofit and non-execution boundaries;\
e) financial, legal, risk, security, safeguards, or governance competence relevant to the role;\
f) absence of prohibited overlaps;\
g) ability to exercise informed judgment; and\
h) willingness to serve the Corporation rather than a member constituency, donor, sector, founder, or external institution.

A trustee elected by members shall owe duties to GCRI US and its public-benefit mission, not to the class, constituency, donor, institution, region, sector, or bloc that supported the election. Member election shall not create delegate trusteeship. Fiduciary duty remains institutional and corporate.

No election or confirmation shall be valid where voting eligibility, quorum, notice, candidate disclosure, conflict handling, or certification of results is materially defective unless lawfully cured.

#### 188.4 Approval of Major Constitutional Amendments and Reserved Changes

The Membership Authority may approve major constitutional amendments and reserved changes where approval is required by law or the governing instruments. Such matters may include amendments affecting mission, purposes, member rights, Board composition, dissolution, asset disposition, amendment thresholds, membership voting rights, or other high-order constitutional provisions.

Major changes shall not be presented to members as routine administrative updates. The notice and materials shall clearly state:

a) the existing provision;\
b) the proposed change;\
c) the reason for the change;\
d) the institutional effect;\
e) the risks and safeguards;\
f) whether the change affects nonprofit status, public-benefit mandate, membership rights, fiduciary authority, or public-good assets;\
g) whether legal, tax, audit, or safeguards review has occurred; and\
h) whether the Board recommends, opposes, or neutrally submits the matter.

No major constitutional change may be used to launder capture, weaken fiduciary oversight, grant special rights to a donor or member group, convert public-good assets into private advantage, or shift GCRI US toward regulated execution. A member-approved change that would violate law, nonprofit duties, or non-execution discipline shall not be implemented.

#### 188.5 Approval of Dissolution, Asset Lock Exceptions, or Successor Stewardship Matters Where Assigned

Where applicable law or these Bylaws require member approval for dissolution, wind-down, merger, asset transfer, successor stewardship, or treatment of restricted or public-good assets, the Membership Authority shall act only through a controlled, fully informed, and recorded process.

Such matters shall require clear materials addressing:

a) reason for dissolution, transfer, merger, or successor arrangement;\
b) financial position and liabilities;\
c) treatment of restricted funds and donor obligations;\
d) treatment of public-good assets, repositories, publications, records, data, and intellectual-property interests;\
e) successor eligibility, mission compatibility, and safeguards capacity;\
f) protection against private benefit or improper inurement;\
g) records, archival, and continuity plan;\
h) legal and tax implications; and\
i) Board recommendation and any dissenting fiduciary view.

Member approval shall not authorize distribution of assets to insiders, members, donors, founders, private parties, or execution-side actors except as lawful payment of legitimate obligations. Public-good assets shall be preserved for compatible public-benefit use wherever possible.

Dissolution authority is not a member exit dividend. It is a stewardship duty at the end of corporate life or a major transition.

#### 188.6 Approval of High-Order Mission, Structural, or Federation Questions Where Assigned

The Membership Authority may be assigned approval, confirmation, or consultative rights for high-order mission, structural, or federation questions. Such questions may include material changes to the Corporation’s public-good role, federation posture, institutional alignment, membership architecture, regional or national participation interfaces, or relationship to related bodies, provided that the governing instruments assign the matter to members.

High-order mission or federation questions shall be framed with precision. Members shall be told whether they are being asked to approve a binding change, provide advice, confirm direction, or receive accountability information. The Corporation shall avoid submitting broad or rhetorical questions whose legal effect is unclear.

Such matters shall be assessed against:

a) mission lock;\
b) nonprofit status;\
c) U.S. legal and tax posture;\
d) two-stack firewall;\
e) non-execution boundary;\
f) public-good asset stewardship;\
g) data, security, and safeguards implications;\
h) cross-entity separateness;\
i) anti-capture and competition neutrality; and\
j) continuity of governance and records.

Where federation or interoperability matters involve GCRI Canada, GRF, GRA, protocol authorities, hosts, or national systems, member action by GCRI US shall not bind those entities unless they separately approve through their own lawful processes.

#### 188.7 Receipt of Annual Reports, Audit Outputs, and Accountability Packs

The Membership Authority may receive annual reports, audit outputs, public-benefit reports, membership reports, financial summaries, risk reports, safeguards summaries, security summaries, governance reports, or accountability packs where assigned by the Board or governing instruments. Receipt of a report shall not be confused with approval of every underlying action unless the governing instrument expressly provides for approval.

Reports to the Membership Authority may include:

a) mission and program activity;\
b) financial position and use of resources;\
c) restricted and unrestricted funding overview;\
d) reserves and continuity posture;\
e) governance changes;\
f) Board and committee composition;\
g) membership health and anti-capture indicators;\
h) safeguards, whistleblowing, and grievance summaries;\
i) security, privacy, and controlled-handling summaries;\
j) public-good asset stewardship; and\
k) forward-looking priorities.

Sensitive information may be redacted, summarized, aggregated, delayed, or handled in restricted session where needed to protect privacy, security, privilege, protected participants, Indigenous or community-sensitive information, donor confidentiality, personnel matters, or live investigations.

The right to receive accountability information does not create unlimited access to internal records.

#### 188.8 No Membership Authority Act May Breach Mission Lock, Non-Execution, Safeguards, or Rights Constraints

No act of the Membership Authority shall be valid to the extent it breaches mission lock, nonprofit purpose, public-benefit obligations, non-execution discipline, safeguards, protected participation, privacy, security, restricted-handling rules, asset lock, fiduciary duties, or applicable law.

The Membership Authority may not:

a) direct the Corporation to undertake regulated execution or market-facing activity;\
b) authorize private benefit or improper inurement;\
c) override protected reporting or safeguards processes;\
d) compel disclosure of protected, privileged, controlled, or rights-bearing information;\
e) impose donor, sponsor, vendor, sector, or political control over the Corporation;\
f) mandate publication of unverified, unsafe, defamatory, confidential, or misleading material;\
g) approve use of public-good assets for private advantage; or\
h) impair fiduciary duties of trustees or directors.

If members pass or request a measure inconsistent with these constraints, the Board shall refuse implementation, explain the incompatibility to the extent safe and lawful, and record the matter. Member authority is real only within constitutional boundaries.

#### 188.9 No Membership Authority Decision May Substitute for Competent Board, Legal, Officer, or Management Authority Where Law Requires Otherwise

A member decision shall not substitute for Board action, officer certification, legal review, management execution, committee review, audit approval, regulatory filing, or other competent authority where law or the governing instruments require that separate act. Member approval may be necessary but not sufficient.

For example:

a) members may approve a constitutional amendment, but the proper officers may still need to execute filings;\
b) members may elect trustees, but the Corporation must still update records and confirm eligibility;\
c) members may approve dissolution, but the Board must conduct lawful wind-down;\
d) members may receive financial reports, but auditors and finance officers retain their own duties;\
e) members may approve certain structural changes, but legal and tax compliance must still be satisfied; and\
f) members may provide advice on strategy, but management may act only within delegated authority and approved budget.

The Corporation shall maintain authority sequencing. A decision is not complete merely because one organ has acted. Each required authority must perform its own role.

#### 188.10 Member Reserved Matters, Board Reserved Matters, and Non-Delegable Boundaries

GCRI US shall distinguish member reserved matters from Board reserved matters and non-delegable boundaries. Some matters may require member approval. Some matters belong to the Board alone. Some matters require both. Some matters cannot be done at all because they violate mission, law, or constitutional constraints.

The Corporation shall maintain a reserved-matters map identifying:

a) matters reserved to members;\
b) matters reserved to the Board;\
c) matters requiring both Board and member approval;\
d) matters delegated to committees;\
e) matters delegated to management or officers;\
f) matters requiring legal, audit, security, safeguards, or finance clearance; and\
g) matters prohibited regardless of approval.

The reserved-matters map shall be used before agenda items are admitted, before votes are noticed, and before decisions are implemented. Where the map is silent or ambiguous, the most protective reading shall apply and the matter shall be escalated.

#### 188.11 Advisory Powers and Member Voice Without Fiduciary Displacement

Members may have advisory powers or structured voice even where they do not hold binding authority. Advisory participation can strengthen legitimacy, surface risk, improve strategy, test public-benefit relevance, and ensure that the Corporation remains accountable to its mission environment.

Advisory powers may include:

a) submitting questions to the Board;\
b) requesting accountability discussion;\
c) providing comments on annual plans;\
d) proposing non-binding resolutions;\
e) nominating candidates where permitted;\
f) submitting minority reports or dissent statements;\
g) recommending policy or program priorities; and\
h) identifying risks, safeguards concerns, or public-good needs.

Advisory powers shall not displace fiduciary judgment. The Board may accept, modify, defer, or reject advisory inputs where required by mission, law, risk, resources, or strategic discipline. Where the Board declines a material member recommendation, it may provide a reasoned response where appropriate and safe.

#### 188.12 Challenge, Invalidity, and Cure of Member Decisions Outside Authority

Where a member decision is alleged to be outside authority, procedurally defective, conflicted, improperly noticed, improperly seated, improperly counted, contrary to law, or inconsistent with constitutional constraints, GCRI US shall provide a challenge and cure process proportionate to the matter’s significance.

A challenge may concern:

a) eligibility of voters;\
b) quorum;\
c) notice;\
d) agenda admissibility;\
e) conflict or recusal;\
f) threshold;\
g) credential defects;\
h) mandate authority;\
i) publication or information defects;\
j) procedural irregularity; or\
k) substantive ultra vires action.

Cure may include re-notice, re-vote, ratification where lawful, corrected certification, exclusion of invalid votes, revised minutes, Board review, legal review, or declaration that the purported decision has no effect.

No defective member act shall be allowed to stand merely because correction is inconvenient or politically sensitive.

#### 188.13 Interpretive Rule for Powers and Reserved Matters of the Membership Authority

This Section shall be interpreted to preserve a controlling proposition: the GCRI US Membership Authority may exercise only those powers expressly assigned to it, and every member act must remain within mission lock, nonprofit law, fiduciary discipline, reserved-matter mapping, safeguards, non-execution boundaries, and proper corporate procedure.

Where ambiguity exists, the interpretation that better preserves:

a) express assignment of member powers;\
b) constitutional amendment discipline;\
c) lawful election and confirmation processes;\
d) asset-lock and successor-stewardship integrity;\
e) accountable report receipt without over-access;\
f) no breach of mission or safeguards;\
g) no substitution for Board or legal authority;\
h) clear reserved-matter mapping; and\
i) challenge and cure of defective member action

shall prevail unless a contrary result is required by law.

### 189. Meetings of the Membership Authority / General Assembly (GCRI United States)

#### 189.1 Ordinary Annual Meeting of the Membership Authority

GCRI US may convene an ordinary annual meeting of the Membership Authority or General Assembly where such meeting is required by law, the Articles, these Bylaws, membership class instruments, or Board-approved governance policy. The annual meeting shall be treated as a formal corporate governance event, not as an annual conference, donor showcase, public campaign moment, or program convening.

The annual meeting may be used to:

a) receive the annual report, financial summary, audit or review outputs, and accountability pack where assigned;\
b) elect, confirm, or receive notice of trustees, officers, or committee roles where member action is required;\
c) consider member-reserved matters properly noticed for decision;\
d) receive Board, management, risk, safeguards, membership, registry, security, and public-good stewardship updates;\
e) provide structured opportunity for member questions, objections, and advisory input;\
f) certify membership authority records, seating, quorum, and voting outcomes; and\
g) preserve institutional continuity through a formal annual record.

The annual meeting shall be scheduled, noticed, conducted, recorded, and certified according to the applicable authority rules. Its purpose is not only to inform members. It is to maintain a legally and constitutionally reliable accountability channel between the Corporation and those members who have formal standing.

#### 189.2 Special and Extraordinary Meetings

GCRI US may convene special or extraordinary meetings of the Membership Authority where a matter requires member consideration before the next annual meeting or where law, these Bylaws, the Board, a required member threshold, or another competent authority calls such a meeting.

Special or extraordinary meetings may address:

a) constitutional amendments;\
b) trustee election, confirmation, removal, or vacancy matters where assigned;\
c) dissolution, merger, successor stewardship, or asset-lock matters where assigned;\
d) urgent mission, structural, or membership-rights questions;\
e) material governance corrections;\
f) member challenge, appeal, or ratification matters; or\
g) any other matter reserved to members that cannot prudently wait.

The notice for a special or extraordinary meeting shall identify the business to be considered. No unrelated matter shall be decided unless the notice, consent rules, and applicable law permit it. The Corporation shall not use special meetings to rush sensitive decisions without adequate materials, credential verification, and procedural safeguards.

#### 189.3 Emergency Membership Authority Sessions and Threshold for Use

Emergency meetings of the Membership Authority may be convened only where delay would create material risk to the Corporation, its mission, legal status, public-good assets, governance continuity, member rights, or public trust, and where the matter properly falls within member authority or requires member awareness under the governing instruments.

Emergency sessions may be appropriate for:

a) imminent dissolution, continuity, or successor-stewardship matters requiring member approval;\
b) urgent constitutional cure where delay would impair validity;\
c) serious governance failure requiring member-reserved action;\
d) legal or regulatory requirement with short response time;\
e) emergency election or confirmation where governance continuity depends on member action; or\
f) other high-order matters expressly permitted by the governing record.

Emergency use shall not be invoked for convenience, reputational timing, donor pressure, media pressure, program deadlines, or ordinary operational urgency. Emergency sessions shall remain subject to minimum notice, quorum, credential, conflict, records, and information requirements. Where ordinary notice cannot be given, the record shall explain why, identify the reduced process used, and provide ratification or cure where required.

#### 189.4 Notice Requirements, Time Periods, and Content of Notice

Notice of meetings of the Membership Authority shall comply with applicable law, the Articles, these Bylaws, membership instruments, and Board-approved procedures. Notice shall be sufficient to allow eligible members to understand the nature of the meeting, determine whether they are entitled to participate, prepare responsibly, verify delegate authority, and identify conflicts or concerns.

Notice shall include, as applicable:

a) meeting date, time, time zone, and modality;\
b) place or secure access method;\
c) meeting type, including annual, special, extraordinary, emergency, public, restricted, or hybrid;\
d) agenda and classification of each item as decision, advisory, report, election, consent, or information;\
e) text or summary of proposed resolutions;\
f) voting threshold, quorum requirement, and eligible voting classes;\
g) credential and delegate submission deadline;\
h) access, confidentiality, and publication-class requirements;\
i) materials to be reviewed before the meeting;\
j) proxy, alternate, remote participation, or electronic voting rules if permitted;\
k) conflict disclosure and recusal requirements; and\
l) process for questions, challenges, late items, amendments, and objections.

The Corporation shall avoid vague notices such as “strategic update” where a decision is intended. Members must know when institutional authority is being exercised.

#### 189.5 Agenda Discipline, Admissibility of Items, and Late-Item Controls

The agenda of a Membership Authority meeting shall be governed by agenda discipline. Only matters within member authority, properly noticed, procedurally admissible, and classified by decision type may be submitted for decision. The agenda shall distinguish between governance acts and informational programming.

An agenda item shall be admissible only if:

a) it falls within member authority or proper advisory scope;\
b) it has been submitted through the required process;\
c) the responsible authority has classified it correctly;\
d) required materials are available or appropriately summarized;\
e) confidentiality, legal, safeguards, and security constraints can be respected;\
f) voting eligibility and thresholds can be determined; and\
g) the item does not attempt to bypass Board reserved matters, legal review, fiduciary duties, or non-execution boundaries.

Late items shall be controlled. A late item may be added only where permitted by law and governing rules, where urgency justifies it, and where affected members receive adequate information. No major constitutional, fiduciary, financial, dissolution, membership-rights, or reserved matter shall be decided as a late item unless the governing record clearly permits that treatment and the record explains the necessity.

#### 189.6 Quorum Requirements and Loss of Quorum Rules

Quorum for a Membership Authority meeting shall be calculated according to the applicable law, Articles, Bylaws, class rules, and matter-specific thresholds. Quorum shall be based only on persons or members eligible to be counted for the relevant matter.

Quorum rules shall address:

a) ordinary quorum for general business;\
b) special quorum for constitutional amendments, dissolution, elections, or other reserved matters;\
c) class-specific quorum where only certain classes vote;\
d) quorum effects of recusals, conflicts, and excluded votes;\
e) quorum in virtual or hybrid settings;\
f) quorum for written consents or electronic voting where permitted; and\
g) loss of quorum during a meeting.

Where quorum is lost, no further decision requiring quorum shall be taken unless quorum is restored. The meeting may continue for discussion, reporting, or non-decision business only if the chair determines that doing so is lawful and useful. The minutes shall record the time and effect of quorum loss.

Quorum is not a formality. It is evidence that the required membership authority is actually present.

#### 189.7 In-Person, Virtual, and Hybrid Meetings

GCRI US may hold Membership Authority meetings in person, virtually, or in hybrid format where permitted by law and governing rules. The chosen modality shall support accessibility, security, identity verification, participation fairness, voting integrity, records discipline, and safe handling of sensitive materials.

Virtual and hybrid meetings shall include controls for:

a) identity verification;\
b) delegate and credential confirmation;\
c) secure access links;\
d) attendance logging;\
e) voting verification;\
f) prevention of unauthorized recording or attendance where restricted;\
g) management of observers, advisers, and non-voting participants;\
h) accessibility and language support where feasible;\
i) backup procedures for technical failure; and\
j) preservation of minutes, chat records, polls, ballots, or other meeting artifacts where required.

The Corporation shall not choose virtual convenience at the expense of voting validity or sensitive handling. Nor shall it use in-person requirements to exclude legitimate members who can participate safely and lawfully through remote means.

#### 189.8 Accessibility, Language Accommodation, and Safe Participation Requirements

Membership Authority meetings shall be designed to support accessibility, dignity, inclusion, and safe participation consistent with the Corporation’s mission and legal obligations. Participation systems shall not unnecessarily exclude members because of disability, geography, language, digital access, institutional form, resource limitations, safety concerns, or protected status.

Accessibility and safe participation measures may include:

a) remote participation options;\
b) accessible documents and meeting platforms;\
c) interpretation, translation, or plain-language summaries where feasible;\
d) advance circulation of materials;\
e) structured question submission;\
f) respectful conduct rules;\
g) non-retaliation reminders;\
h) role-marker participation where identities require protection;\
i) special handling for Indigenous, community, public-authority, or protected participants; and\
j) procedures for reporting intimidation, harassment, or unsafe conduct.

Accessibility does not eliminate credentialing, quorum, security, or confidentiality requirements. The correct standard is controlled inclusion: participation should be enabled, but institutional authority and protected handling must remain intact.

#### 189.9 Controlled-Room and Restricted Agenda Segmentation Where Necessary

Where a Membership Authority meeting includes sensitive matters, GCRI US may segment the agenda into public, member-only, restricted, confidential, controlled-room, or clean-room portions. Segmentation shall be used to preserve lawful participation while protecting information that cannot be broadly disclosed.

Segmentation may be required for:

a) legal privilege;\
b) personnel matters;\
c) whistleblower or grievance matters;\
d) security, privacy, or incident matters;\
e) financial distress, fraud, or investigation matters;\
f) public-authority-sensitive information;\
g) Indigenous or community-sensitive information;\
h) controlled evidence, restricted technical information, or sensitive data;\
i) trustee, officer, or member conduct matters; and\
j) dissolution, continuity, or successor-stewardship matters containing protected details.

Only persons with the required standing, mandate, access class, and need-to-know may attend restricted segments. The meeting record shall indicate that segmentation occurred without unnecessarily disclosing protected content. Public or general minutes may include a controlled summary where appropriate.

#### 189.10 Validity, Cure, and Re-Notice Rules for Defective Meeting Process

Where a Membership Authority meeting suffers from defective notice, agenda error, quorum defect, credential error, voting irregularity, access failure, publication-class breach, conflict-handling defect, technical failure, or other procedural problem, GCRI US shall determine whether the defect affects validity and what cure is required.

Possible cures may include:

a) correction of minutes;\
b) supplemental notice;\
c) re-notice and reconvening;\
d) re-vote;\
e) exclusion or correction of invalid votes;\
f) ratification where legally permissible;\
g) revised certification of results;\
h) legal review;\
i) member challenge process; or\
j) declaration that the purported decision has no effect.

A defect shall be treated as material where it may have affected eligibility, quorum, voting outcome, member rights, fairness, protected participation, legal compliance, or public trust. The Corporation shall not ignore defects because the outcome was preferred. Validity must be earned through process.

#### 189.11 Chairing, Facilitation, and Meeting Authority

Membership Authority meetings shall be chaired or facilitated by the person or body designated under the governing instruments, Board resolution, meeting rules, or applicable law. The chair’s role is procedural stewardship, not personal control over member authority.

The chair shall:

a) confirm meeting authority and agenda;\
b) ensure credential and quorum verification;\
c) manage speaking order and time;\
d) enforce conduct, confidentiality, and competition rules;\
e) rule on procedural admissibility subject to appeal where permitted;\
f) identify decision thresholds and voting procedures;\
g) protect minority, dissenting, and vulnerable participants from improper exclusion or intimidation;\
h) coordinate controlled-room segmentation; and\
i) ensure the secretary or designated recorder captures decisions accurately.

The chair shall not suppress lawful dissent, force votes outside scope, introduce unnotified major matters, ignore conflicts, or treat procedural authority as substantive governance power.

#### 189.12 Meeting Materials, Board Packs, and Member Information Rights

Meeting materials shall be prepared in a form appropriate to the matter and the rights of the members. Where members are asked to decide, the materials shall provide enough information for a reasonable member to understand the decision. Where members are asked to receive or discuss, the materials shall clearly state that no decision is being requested.

Materials may include:

a) agenda;\
b) draft resolutions;\
c) explanatory memoranda;\
d) annual reports;\
e) financial summaries;\
f) audit or review summaries;\
g) candidate packets;\
h) amendment redlines;\
i) risk assessments;\
j) public-benefit rationale;\
k) legal or fiduciary summary where appropriate; and\
l) controlled summaries of sensitive matters.

Member information rights shall not override privilege, privacy, security, safeguards, personnel confidentiality, whistleblower protection, controlled-room rules, or legal restrictions. Where full disclosure is unsafe, the Corporation may provide redacted, aggregated, summarized, or independent-review materials.

#### 189.13 Minutes, Certifications, and Meeting Records

Every formal meeting of the Membership Authority shall have minutes or an equivalent authoritative record. The record shall capture the meeting’s validity, attendance, quorum, agenda, actions taken, decisions made, voting results, recusals, objections, dissent records, procedural rulings, and any controlled or restricted segments.

The record shall include, as applicable:

a) meeting identifier;\
b) date, time, location or modality;\
c) chair and secretary or recorder;\
d) notice confirmation;\
e) attendance and seating register reference;\
f) quorum confirmation;\
g) agenda items;\
h) resolutions considered;\
i) votes and thresholds;\
j) recusals, exclusions, or conflicts;\
k) challenges and rulings;\
l) dissent or minority statements where permitted;\
m) controlled-room segmentation notation; and\
n) certification of results.

Minutes shall not become narrative advocacy. They are governance evidence. They shall be accurate, concise, complete enough for validity, and classified appropriately.

#### 189.14 Interpretive Rule for Meetings of the Membership Authority

This Section shall be interpreted to preserve a controlling proposition: GCRI US Membership Authority meetings are formal governance events that require proper notice, agenda discipline, credentialing, quorum, safe participation, controlled handling, accurate minutes, and cure of defects before any member action can be relied upon.

Where ambiguity exists, the interpretation that better preserves:

a) formal meeting validity;\
b) notice and agenda clarity;\
c) quorum and credential integrity;\
d) accessibility with control;\
e) controlled-room segmentation where needed;\
f) accurate voting and meeting records;\
g) fair chairing; and\
h) cure or re-notice of defective process

shall prevail unless a contrary result is required by law.

### 190. Voting, Consent, and Dissent in the Membership Authority / General Assembly (GCRI United States)

#### 190.1 Voting Rights by Membership Class and Standing

Voting rights in the Membership Authority of GCRI US shall exist only where expressly granted to a membership class by law, the Articles, these Bylaws, a Board-approved membership schedule, or another recorded governance instrument. No person or institution shall vote merely because it is a member, donor, sponsor, program participant, council participant, adviser, observer, affiliate, founding contributor, public authority, technical contributor, or high-visibility supporter.

Before any vote is taken, GCRI US shall confirm:

a) the class of members entitled to vote on the matter;\
b) the status state required for voting;\
c) whether the member is in good standing;\
d) whether the representative has voting authority;\
e) whether any conflict, recusal, suspension, or exclusion applies;\
f) whether quorum has been met for the matter;\
g) the threshold required for approval; and\
h) the method of voting and result certification.

Voting is a corporate authority act. It shall not be treated as applause, sentiment, consultation, survey preference, workshop feedback, or public endorsement. If a vote is intended to have legal or governance effect, the voting record must prove that only eligible voters participated and that the required procedure was followed.

#### 190.2 Ordinary, Special, and Supermajority Thresholds

GCRI US shall define voting thresholds by matter class. Ordinary matters, special matters, constitutional matters, reserved matters, dissolution matters, member-rights matters, and other high-consequence matters may require different approval thresholds.

Thresholds may include:

a) simple majority of votes cast;\
b) majority of eligible voting members present;\
c) majority of all eligible voting members;\
d) class approval by affected membership class;\
e) special majority;\
f) supermajority;\
g) unanimous written consent where required; or\
h) any other threshold required by law or governing instrument.

No matter shall be approved under a lower threshold than the governing rule requires. Where the threshold is uncertain, the matter shall be deferred, treated as not approved, or escalated for legal and governance review.

Major constitutional, mission, dissolution, asset-lock, member-rights, or fiduciary-sensitive matters shall not be passed through ambiguous threshold language. The threshold must be stated in the notice, repeated before the vote, and recorded in the certification.

#### 190.3 Secret Ballots, Recorded Votes, and Consent-Gated Decisions

GCRI US may use secret ballots, recorded votes, written consents, electronic ballots, class votes, roll-call votes, or consent-gated decision procedures where appropriate and lawful. The voting method shall be selected based on legal requirement, matter sensitivity, need for auditability, risk of retaliation, public-trust needs, and member-rights implications.

Secret ballots may be appropriate for:

a) contested elections;\
b) removal or confidence matters;\
c) sensitive membership decisions;\
d) matters where retaliation risk exists; or\
e) other votes where anonymity protects free and safe participation.

Recorded votes may be appropriate for:

i) constitutional amendments;\
ii) dissolution or asset-stewardship matters;\
iii) class-rights changes;\
iv) fiduciary accountability matters;\
v) public-interest transparency; or\
vi) decisions where the institutional record must show who voted and how.

Consent-gated decisions shall be used where the matter requires express agreement by affected members, a class, a supermajority, or all eligible members. Silence shall not be treated as consent unless the governing instrument clearly permits negative-consent procedures and the notice expressly states the consequence of silence.

#### 190.4 Abstentions, Conflicted Votes, and Excluded Votes

Abstentions, conflicted votes, disqualified votes, excluded votes, and non-responses shall be treated according to the governing voting rule. The voting record shall state how each category is counted for quorum, threshold, and result certification.

A member or delegate may be excluded from voting where:

a) the member is not in good standing;\
b) the member’s class lacks voting rights for the matter;\
c) representative authority is defective;\
d) a conflict or recusal applies;\
e) the member is suspended, lapsed, terminated, or conditionally restricted;\
f) the member is subject to a voting hold;\
g) the member has a direct financial or institutional interest requiring exclusion; or\
h) applicable law or governing instruments require exclusion.

A conflicted member may be allowed to provide factual information where appropriate, but shall not participate in deliberation, pressure other members, or vote where recusal is required. Conflicted votes cast in breach of recusal rules may be disregarded, corrected, or trigger re-vote where material.

#### 190.5 Remote Voting, Verification, and Auditability

Remote voting may be used where permitted by law and governing instruments, provided that GCRI US can verify identity, eligibility, authority, vote integrity, timing, and auditability. Remote voting shall not be used if the Corporation cannot confirm who voted, whether they were entitled to vote, or whether the vote was cast under proper authority.

Remote voting procedures shall address:

a) secure voting platform or method;\
b) credential verification;\
c) member and delegate identity confirmation;\
d) proxy and alternate rules where permitted;\
e) ballot secrecy where required;\
f) timestamping and closing time;\
g) duplicate vote prevention;\
h) vote change or correction rules before close;\
i) scrutineer or certification process; and\
j) retention of voting records.

If technical failure, unauthorized access, platform malfunction, identity uncertainty, or vote-integrity concern may have affected the result, the Corporation shall pause certification, investigate, and determine whether cure, recount, re-vote, or re-notice is required.

#### 190.6 Written Resolutions and Written Consent Procedures

Where permitted, GCRI US may use written resolutions or written consent procedures for member action. Written action shall be governed with the same seriousness as a meeting vote and shall not be used to bypass deliberation, notice, information rights, conflicts, thresholds, or safe participation.

A written resolution or consent process shall identify:

a) the exact text of the proposed action;\
b) the members entitled to participate;\
c) the threshold required;\
d) deadline for response;\
e) effect of consent, refusal, abstention, or non-response;\
f) materials provided;\
g) conflict and recusal requirements;\
h) method for authenticating signatures or electronic approvals; and\
i) record certification.

Written consent shall be especially controlled where the matter affects mission, member rights, Board composition, constitutional instruments, dissolution, asset stewardship, or high-sensitivity governance. Written action shall not be used to create surprise approval of matters members did not understand.

#### 190.7 Dissent Capture, Minority Reports, and Request for Recorded Objection

GCRI US shall preserve mechanisms for dissent capture, minority reports, recorded objections, and reasoned reservations in appropriate Membership Authority matters. Dissent is not a governance failure. Properly recorded dissent can strengthen fiduciary awareness, preserve institutional memory, improve risk review, and protect minority, community, Indigenous, civil-society, or under-resourced participation from erasure.

Members may request, where permitted:

a) recording of objection to a decision;\
b) notation of abstention for stated reason;\
c) submission of a short dissent statement;\
d) inclusion of minority report in internal records;\
e) Board review of a member concern; or\
f) preservation of procedural objection for challenge.

Dissent mechanisms shall not be used to defame, disclose confidential information, intimidate participants, relitigate settled matters indefinitely, or publish controlled content. The chair or secretary may require dissent statements to be concise, relevant, respectful, and classified appropriately.

Where a dissent relates to safeguards, protected participation, public authority, Indigenous representation, financial integrity, or non-execution risk, the matter shall be routed to the appropriate oversight lane.

#### 190.8 Certification of Results and Challenge Windows

Every formal vote, consent, election, amendment, or member decision shall be certified by the secretary, scrutineer, chair, inspector of election, or other designated authority. Certification shall confirm that the result was determined according to the governing rules.

The certification shall state, as applicable:

a) matter voted upon;\
b) date and method of vote;\
c) voting classes entitled to vote;\
d) quorum;\
e) threshold;\
f) total votes eligible;\
g) votes cast;\
h) votes for, against, abstaining, excluded, invalid, or spoiled;\
i) recusals and disqualifications;\
j) whether the measure passed or failed; and\
k) challenge window and finality date.

The Corporation shall define challenge windows for voting irregularities, credential disputes, counting errors, threshold disputes, conflict violations, remote voting defects, or procedural defects. Challenges filed within the window shall be reviewed before final reliance where the issue may affect validity. Late challenges may be considered only where required by law or where the defect is serious enough to affect institutional integrity.

#### 190.9 No Valid Vote Without Credential, Standing, Authority, and Procedural Compliance

No vote shall be valid unless the voting member had the required class right, good standing, credential, representative mandate, voting authority, absence of disqualifying conflict, and procedural compliance at the time of the vote. The Corporation shall not validate a vote merely because the person intended to vote, was known to staff, attended the meeting, or previously voted in similar matters.

A vote may be invalid or voidable where:

a) the member was not eligible;\
b) the member was not in good standing;\
c) the delegate lacked voting authority;\
d) quorum was not satisfied;\
e) notice was defective;\
f) the matter exceeded member authority;\
g) the wrong threshold was applied;\
h) conflict or recusal rules were breached;\
i) remote voting integrity failed; or\
j) the result was certified incorrectly.

Where invalid votes may have affected the outcome, GCRI US shall correct the count, re-certify, re-vote, re-notice, or declare the matter not approved as required.

#### 190.10 Proxy, Alternate, and Delegate Voting Controls

Proxy, alternate, or delegate voting may be permitted only where expressly authorized by law and governing instruments. The Corporation shall not assume proxy voting is available merely because it is convenient or common in other settings.

Where permitted, proxy or alternate voting shall require:

a) written proxy or alternate mandate;\
b) identification of the member granting authority;\
c) identification of the proxy-holder or alternate;\
d) scope of authority;\
e) meeting or matter covered;\
f) expiration date;\
g) revocation procedure;\
h) conflict disclosure; and\
i) authentication sufficient for the voting context.

Proxy use shall not become a tool for bloc control, vote harvesting, donor pressure, or hidden influence. GCRI US may impose limits, verification, disclosure, or scrutineer review where proxy concentration threatens legitimacy.

#### 190.11 Voting Integrity in the Nexus Public-Good Model

Because GCRI US operates as a public-good steward in a multi-sector and cross-border ecosystem, voting integrity must address risks beyond ordinary corporate mechanics. The voting system must prevent powerful actors from translating financial support, technical dependency, public authority, corporate scale, media visibility, or geopolitical influence into uncontrolled institutional authority.

Voting integrity therefore requires:

a) clear class rights;\
b) anti-capture caps where adopted;\
c) affiliate aggregation where necessary;\
d) conflict and recusal discipline;\
e) protected dissent;\
f) safeguards for community, Indigenous, civil-society, and under-resourced voices;\
g) separation between membership voting and Board fiduciary duties;\
h) no voting on execution-side or prohibited matters; and\
i) public-description discipline after results.

A vote may create internal governance effect only within its lawful scope. It shall not be publicly described as universal sector endorsement, government adoption, Indigenous consent, regulatory approval, market validation, or public mandate unless the record supports that precise statement.

#### 190.12 Voting Records, Retention, and Publication Class

Voting records shall be retained according to their legal, governance, and historical significance. The Corporation shall distinguish between public result disclosure, internal voting records, confidential ballots, scrutineer records, credential files, dissent statements, and controlled voting materials.

Retention shall preserve:

a) notice;\
b) agenda;\
c) voting list;\
d) credential verification;\
e) ballots or consent records where required;\
f) proxy records if permitted;\
g) vote tally;\
h) certification;\
i) challenge records;\
j) corrections or re-certifications; and\
k) final authoritative result.

Publication class shall be assigned carefully. Some voting results may be public. Some may be internal. Secret ballot details shall remain confidential unless disclosure is legally required. Votes involving sensitive public authorities, Indigenous institutions, protected participants, security matters, personnel issues, or disputes may require restricted handling.

#### 190.13 Interpretive Rule for Voting, Consent, and Dissent

This Section shall be interpreted to preserve a controlling proposition: GCRI US member voting, consent, and dissent shall be valid only when class rights, good standing, delegate authority, quorum, threshold, conflict rules, voting method, result certification, and records all support the act, and no vote may be used to exceed mission, fiduciary, safeguards, or non-execution limits.

Where ambiguity exists, the interpretation that better preserves express voting rights, verified authority, correct thresholds, safe dissent, remote-vote integrity, certification discipline, challenge windows, anti-capture controls, and accurate public meaning shall prevail unless a contrary result is required by law.

### 191. The Board of Trustees — Nature, Role, and Fiduciary Position (GCRI United States)

#### 191.1 Board of Trustees as the Primary Fiduciary Oversight Organ

The Board of Trustees shall be the primary fiduciary oversight organ of GCRI US. It shall hold ultimate corporate responsibility for the Corporation’s mission integrity, nonprofit character, public-benefit mandate, corporate law compliance, financial stewardship, risk oversight, executive accountability, and constitutional continuity.

The Board shall not be understood as an honorary council, advisory panel, ambassadorial circle, donor board, technical committee, founder circle, program committee, or symbolic legitimacy body. It is the fiduciary organ responsible for ensuring that GCRI US remains lawful, solvent, mission-aligned, independent, safe, accountable, and institutionally coherent.

The Board shall exercise oversight over:

a) mission lock and public-benefit purpose;\
b) nonprofit status and non-inurement discipline;\
c) strategic direction and institutional priorities;\
d) financial integrity, budget, reserves, audit, and sustainability;\
e) risk appetite, control environment, safeguards, security, and privacy;\
f) executive appointment, evaluation, delegation, and accountability;\
g) major contracts, funding, related-party matters, and reserved transactions;\
h) public-good asset stewardship, publications, repositories, and institutional records;\
i) emergency governance, continuity, and wind-down readiness; and\
j) cross-entity interfaces where GCRI US’s authority, reputation, assets, or obligations may be affected.

The Board may delegate management and operational execution, but it shall not delegate away its fiduciary responsibility.

#### 191.2 Board as Custodian of Mission Lock, Corporate Integrity, and Long-Horizon Stewardship

The Board shall serve as custodian of mission lock, corporate integrity, and long-horizon stewardship. Its duty is not limited to approving annual plans or reviewing financial statements. It must preserve the institutional architecture that allows GCRI US to operate as a public-good steward across changing leadership, funding conditions, political environments, technological shifts, and cross-border pressures.

The Board shall protect:

a) the Corporation’s public-benefit identity;\
b) the strict non-execution boundary;\
c) independence from donor, sponsor, vendor, member, founder, political, state, sectoral, and executive capture;\
d) public-good assets from enclosure, misuse, or private appropriation;\
e) safeguards, protected participation, and non-retaliation systems;\
f) privacy, security, restricted handling, and controlled-room discipline;\
g) evidence integrity, publication discipline, and truthful public claims; and\
h) continuity of governance records, offices, and decision validity.

Long-horizon stewardship requires the Board to ask not only whether an action is useful today, but whether it preserves the Corporation’s legitimacy, independence, and public-good value over time.

#### 191.3 Board’s Role Distinct From Membership Authority, Secretariat, Technical Teams, and Partner Ecosystem

The Board’s role shall be distinct from the Membership Authority, Secretariat, technical teams, councils, working groups, program structures, executive management, host institutions, members, donors, sponsors, partners, and cross-entity bodies.

This distinction shall be maintained as follows:

a) the Membership Authority exercises only those member powers expressly assigned to it;\
b) the Board exercises fiduciary oversight and reserved corporate authority;\
c) officers perform defined corporate functions;\
d) executive management manages operations within delegated authority;\
e) committees assist or decide only within approved charters;\
f) the Secretariat supports governance administration and records but does not become the fiduciary apex;\
g) technical teams and working groups contribute expertise and outputs but do not override Board authority; and\
h) partners and related entities cooperate through written instruments but do not govern GCRI US.

The Board may receive advice from all these surfaces. It may not allow any of them to substitute for its fiduciary judgment. A technically sophisticated recommendation, a member consensus, a donor preference, a public-authority signal, or a partner request does not become corporate decision until processed through proper authority.

#### 191.4 Board as Guardian of Reserved Matters, Perimeter Discipline, and Public-Benefit Continuity

The Board shall act as guardian of reserved matters, perimeter discipline, and public-benefit continuity. Reserved matters are those decisions that cannot be left to ordinary management, informal agreement, program teams, donors, sponsors, members, or external partners because they affect the Corporation’s constitutional identity, risk profile, financial condition, legal obligations, public-good assets, or long-term continuity.

The Board shall ensure that reserved matters include, at minimum where applicable:

a) annual budget, material budget amendments, reserves, and financial controls;\
b) appointment, evaluation, compensation, suspension, or removal of the chief executive or equivalent senior executive;\
c) major contracts, funding arrangements, restricted grants, sponsorships, and related-party transactions above thresholds;\
d) constitutional amendments, policies, charters, annexes, and structural changes;\
e) major public-good infrastructure commitments, repositories, controlled releases, or asset transfers;\
f) high-sensitivity security, privacy, safeguards, whistleblowing, or legal-risk matters;\
g) dissolution, wind-down, merger, successor stewardship, or material continuity actions;\
h) major inter-entity agreements with GCRI Canada, GRF, GRA, protocol authorities, hosts, or other bodies; and\
i) any matter that may blur the non-execution boundary.

The Board shall not permit reserved matters to be decided by operational momentum. If a matter belongs to the Board, it must come to the Board.

#### 191.5 Board Oversight of Financial Integrity, Risk, Security, Compliance, and Executive Accountability

The Board shall oversee financial integrity, institutional risk, security, compliance, audit, safeguards, and executive accountability. These duties shall be active, periodic, and evidence-informed. The Board shall not wait for crisis before exercising oversight.

Board oversight shall include:

a) review of financial reports, budgets, cash flow, reserves, restricted funds, and audit findings;\
b) oversight of funding concentration, donor conditions, private-benefit risk, and anti-capture controls;\
c) review of material contracts, procurement risks, vendor dependencies, and shared-service arrangements;\
d) oversight of cybersecurity, privacy, access controls, controlled-room procedures, and incident response;\
e) review of safeguards, protected participation, whistleblower reports, grievances, and retaliation risks;\
f) review of risk taxonomy, risk appetite, key risk indicators, stress tests, and remediation plans;\
g) supervision of executive performance, succession, compensation, and authority limits; and\
h) verification that corrective actions are completed, not merely promised.

The Board shall ensure that control functions have protected escalation routes. A serious report concerning finance, safeguards, security, legal compliance, executive misconduct, or capture shall be capable of reaching the Board or an independent committee without suppression by management.

#### 191.6 Board as Protector of the Two-Stack Firewall and Non-Execution Perimeter

The Board shall protect the two-stack firewall that separates GCRI US’s nonprofit public-good stewardship from any execution-side activity carried out by separate lawful actors. The Board shall ensure that GCRI US remains a research, standards, evidence, education, governance, publication, and public-benefit institution, and does not become an execution-side market actor by contract, funding model, program design, public statement, or operational habit.

The Board shall prevent GCRI US from:

a) arranging, brokering, placing, underwriting, settling, guaranteeing, insuring, lending, advising on, or intermediating regulated financial products or transactions;\
b) operating as market operator, exchange, broker, dealer, investment adviser, insurer, lender, custodian, payment processor, fund manager, or regulated intermediary;\
c) accepting transaction-linked, success-linked, execution-linked, or market-outcome-linked compensation inconsistent with its nonprofit role;\
d) allowing public-good assets to become privileged tools for private execution advantage;\
e) giving members, donors, sponsors, vendors, or related entities preferential routeability or market access; or\
f) using public narrative to imply that GCRI US executes, approves, guarantees, or supervises financial outcomes.

Where a proposed arrangement is finance-adjacent, execution-adjacent, market-adjacent, insurance-adjacent, public-sector-adjacent, or platform-adjacent, the Board shall require perimeter review before approval.

#### 191.7 Board Oversight Without Operational Substitution

The Board shall oversee management but shall not ordinarily substitute itself for management. Effective governance requires the Board to preserve role clarity. Trustees shall set direction, approve reserved matters, monitor performance, ask hard questions, require evidence, ensure control integrity, and intervene where necessary. They shall not casually direct staff, bypass the executive, negotiate operational commitments, alter program priorities informally, or manage daily work unless properly authorized by emergency action or specific Board mandate.

The Board may establish management delegations, reporting requirements, budget limits, performance expectations, and escalation triggers. Management shall operate within those delegations. Where management exceeds authority, fails to report material matters, suppresses control functions, or allows drift, the Board shall intervene.

The Board’s discipline is therefore twofold:

a) it must not abdicate oversight; and\
b) it must not create confusion by unmanaged operational interference.

#### 191.8 Trustees Serve the Corporation, Not Constituencies, Sponsors, or Appointing Channels

Every trustee shall serve GCRI US and its public-benefit mission as a whole. A trustee shall not serve as delegate of a donor, member class, appointing institution, sector, government, region, technical community, founder group, sponsor, vendor, or personal network.

Trustees may bring knowledge, geography, professional background, institutional experience, and stakeholder sensitivity into Board deliberation. They may not treat Board service as representative bargaining. Once seated, the trustee’s fiduciary duty is to the Corporation.

A trustee shall not:

a) use Board access to benefit a member, donor, sponsor, vendor, employer, affiliate, or related party;\
b) share confidential Board information with an appointing institution or external network;\
c) vote according to external instruction where fiduciary judgment requires otherwise;\
d) seek procurement, funding, hiring, publication, or access advantage;\
e) use Board status to imply endorsement of external projects; or\
f) personalize the institution or treat Board service as ownership.

The Corporation’s model depends on fiduciaries who can absorb external complexity without becoming vehicles for external control.

#### 191.9 Board Independence From Founders, Executives, Donors, and Technical Dependency

The Board shall preserve independence from founders, executives, donors, sponsors, vendors, technical architects, platform providers, major members, public authorities, and affiliated bodies. This does not mean adversarial distance. It means that the Board must retain capacity to make independent judgments, refuse incompatible funding, discipline executives, replace vendors, correct technical direction, reject public overclaims, and preserve mission over relationships.

Board independence requires:

a) sufficient information not filtered solely through one executive or founder;\
b) access to finance, legal, audit, safeguards, security, and records functions where required;\
c) independent committee review of conflicts, compensation, related-party matters, and high-risk transactions;\
d) no donor or sponsor veto over Board matters;\
e) no technical dependency that makes governance unable to change direction;\
f) no executive control over Board agenda, minutes, or access to critical reports; and\
g) protected reporting channels into the Board.

Where the Board becomes dependent on a single person, funder, platform, vendor, or narrative, it shall treat that dependency as a governance risk and adopt corrective measures.

#### 191.10 Board Relationship to Public Claims, Institutional Narrative, and External Positioning

The Board shall oversee the integrity of major public claims concerning GCRI US’s mission, authority, capacity, partnerships, funding, governance, public-good assets, and institutional role. The Board does not need to approve every ordinary communication unless policy requires it, but it shall ensure that public narrative remains truthful, bounded, non-misleading, and aligned with constitutional limits.

Board oversight is especially required where public statements may imply:

a) government endorsement or adoption;\
b) regulatory approval;\
c) Indigenous or community consent;\
d) certification, recognition, or routeability;\
e) execution-side capacity;\
f) secured funding not yet received;\
g) partnership or affiliation beyond the record;\
h) Board approval not actually given; or\
i) institutional maturity, scale, or capacity beyond reality.

The Board shall require correction where public narrative gets ahead of institutional fact. Trust is built by precision, not exaggeration.

#### 191.11 Board Duty to Preserve Institutional Continuity and Succession

The Board shall preserve institutional continuity and succession. GCRI US shall not be structurally dependent on a single founder, executive, chair, treasurer, secretary, technical lead, donor, vendor, or informal records-holder. The Board shall ensure that the Corporation can continue operating lawfully if a key person becomes unavailable, conflicted, removed, incapacitated, or unsuitable.

Continuity duties include:

a) succession planning for chair, secretary, treasurer, executive leadership, and critical officers;\
b) continuity of bank authority, financial controls, records access, and filings;\
c) backup access to corporate books, registers, policies, contracts, and critical systems;\
d) emergency governance procedures;\
e) Board vacancy and incomplete-Board rules;\
f) offboarding and access revocation;\
g) preservation of institutional knowledge; and\
h) continuity plans for public-good assets and repositories.

A serious public-good institution cannot depend on personal memory, private inboxes, or informal trust chains.

#### 191.12 Board Evaluation, Learning, and Corrective Self-Governance

The Board shall periodically evaluate its own performance, composition, committee effectiveness, fiduciary discipline, meeting quality, information quality, risk oversight, conflict handling, and adherence to reserved-matter rules. The Board must be able to govern itself before it can govern the Corporation effectively.

Board evaluation may consider:

a) whether trustees understand mission lock and non-execution boundaries;\
b) whether Board packs are sufficient and timely;\
c) whether risk, finance, security, safeguards, and compliance matters receive adequate attention;\
d) whether committees report effectively;\
e) whether conflicts are disclosed and managed;\
f) whether dissent is respected and recorded;\
g) whether Board decisions are implemented and tracked;\
h) whether the Board is too passive, too operational, or too dependent on one person; and\
i) whether Board composition matches the Corporation’s stage and risk profile.

Where weaknesses are identified, the Board shall adopt corrective actions, including training, committee redesign, additional trustees, independent review, improved reporting, revised delegations, or governance policy updates.

#### 191.13 Interpretive Rule for the Board of Trustees

This Section shall be interpreted to preserve a controlling proposition: the Board of Trustees is the fiduciary apex of GCRI US, responsible for mission lock, nonprofit integrity, public-benefit stewardship, reserved matters, risk oversight, executive accountability, non-execution discipline, and continuity, while remaining distinct from membership voice, management execution, technical work, and public narrative.

Where ambiguity exists, the interpretation that better preserves:

a) Board fiduciary primacy;\
b) mission and asset stewardship;\
c) reserved-matter discipline;\
d) non-execution firewall protection;\
e) oversight without operational confusion;\
f) trustee duty to the Corporation rather than constituencies;\
g) independence from founders, funders, executives, vendors, and technical dependency;\
h) public-claim integrity; and\
i) continuity and succession

shall prevail unless a contrary result is required by law.

### 192. Composition, Structure, and Design of the Board of Trustees (GCRI United States)

#### 192.1 Number of Trustees and Range of Board Size

The Board of Trustees of GCRI US shall be composed of the number of trustees fixed by the Articles, these Bylaws, Board resolution, or other governing instrument, within any minimum and maximum range permitted by applicable law. The Board size shall be large enough to support fiduciary competence, independence, continuity, committee coverage, and diversity of judgment, but not so large that accountability, confidentiality, meeting discipline, or decision quality is weakened.

The Board shall be designed to cover the Corporation’s core fiduciary risk surfaces, including:

a) nonprofit governance and U.S. corporate compliance;\
b) finance, audit, reserves, tax, and restricted-fund oversight;\
c) public-good research, evidence, standards, and publication integrity;\
d) cybersecurity, privacy, restricted handling, and controlled-room governance;\
e) safeguards, whistleblowing, protected participation, and non-retaliation;\
f) public-sector, academic, civil-society, Indigenous, community, and cross-border legitimacy;\
g) anti-capture, conflict-of-interest, procurement-neutrality, and donor-independence controls;\
h) technology, open-source infrastructure, data governance, and public-good asset stewardship; and\
i) institutional continuity, succession, executive accountability, and risk governance.

The Board shall periodically assess whether its size remains fit for the Corporation’s stage, complexity, funding posture, geographic reach, risk profile, and public-benefit obligations. A start-up Board may be smaller, provided it can still discharge core duties. A mature Board should be sufficiently structured to support committees, independent oversight, and succession.

#### 192.2 Ex Officio, Elected, Appointed, and Independent Trustee Categories

The Board may include ex officio, elected, appointed, nominated, confirmed, or independent trustee categories only where such categories are expressly created and defined in the governing instruments. Each category shall identify the authority source, eligibility conditions, term, voting rights, removal rules, conflict standards, and fiduciary duties applicable to the trustee.

An ex officio trustee may serve because they hold a specified office, such as chair, president, executive officer, or other role recognized by the governing instruments. Ex officio status shall not create immunity from fiduciary duty, conflict rules, removal where permitted, or suitability review. If the underlying office ends, the ex officio Board status shall end or be reviewed according to the governing rule.

An elected trustee may be elected by members or another lawful constituency where such election is assigned. Election shall not make the trustee a delegate of the electing group. The trustee’s duty is to GCRI US and its mission.

An appointed trustee may be appointed by the Board, a committee, a founding process, a nominating mechanism, or another body where the governing instruments authorize appointment. Appointment shall be recorded and shall not be treated as personal ownership of a seat.

An independent trustee shall be selected to strengthen impartial fiduciary oversight and shall be free from relationships that materially impair judgment. Independence shall be assessed substantively, not merely by title.

No trustee category shall be used to create hidden vetoes, donor seats, sponsor control, founder entrenchment, public-authority overclaim, or sectoral capture.

#### 192.3 Independence Expectations and Balance of Expertise

The Board shall maintain an appropriate balance of independence and expertise. Independence without competence is insufficient. Expertise without independence may create capture. The Board must contain enough independent judgment to challenge management, founders, donors, vendors, members, technical teams, and external partners when necessary.

The Board’s expertise mix should include, as appropriate:

a) nonprofit corporate governance;\
b) U.S. tax-exempt organization compliance;\
c) finance, audit, treasury, reserves, and risk management;\
d) law, contracts, intellectual property, data protection, and public-benefit accountability;\
e) public-good research, science, evidence systems, and standards governance;\
f) cybersecurity, secure software, AI governance, data architecture, and technology controls;\
g) public policy, public institutions, development finance, resilience, and global risk governance;\
h) safeguards, human rights, Indigenous and community engagement, grievance, and protected participation;\
i) communications integrity, public claims, media risk, and transparency; and\
j) organizational growth, executive oversight, and institutional design.

The Board shall avoid overconcentration in any single discipline. A Board composed only of technical experts may miss legal, financial, safeguards, and fiduciary risk. A Board composed only of public figures may lack operational understanding. A Board composed only of donors or executives may lack independence. The design goal is balanced fiduciary judgment.

#### 192.4 Eligibility, Suitability, and Disqualification Requirements

Every trustee shall satisfy eligibility, suitability, and disqualification requirements set by law, the Articles, these Bylaws, Board policy, and any applicable fit-and-proper framework. A trustee shall be capable of exercising fiduciary judgment, understanding the Corporation’s mission and boundaries, handling confidential information, disclosing conflicts, and participating in Board oversight responsibly.

Eligibility and suitability review shall consider:

a) legal eligibility to serve;\
b) identity, background, and institutional affiliations;\
c) relevant experience and competence;\
d) integrity, reliability, and judgment;\
e) conflicts of interest, related-party relationships, and prohibited overlaps;\
f) donor, sponsor, vendor, member, public-authority, or cross-entity relationships;\
g) ability to preserve confidentiality, security, and restricted handling;\
h) commitment to safeguards, protected participation, and non-retaliation;\
i) understanding of the non-execution boundary and public-good role; and\
j) availability and willingness to perform Board duties.

Disqualification may arise from legal prohibition, serious misconduct, fraud, corruption, sanctions exposure, undisclosed conflict, breach of confidentiality, retaliation, incapacity to serve, repeated non-attendance, refusal to comply with Board duties, private-benefit risk, or conduct materially inconsistent with public trust.

A trustee shall not be seated merely because they are influential, famous, connected, technically brilliant, wealthy, politically useful, or historically important. Board service requires fiduciary suitability.

#### 192.5 Geographic, Functional, Institutional, and Stakeholder Diversity Considerations

The Board shall pursue geographic, functional, institutional, and stakeholder diversity consistent with the Corporation’s U.S. nonprofit status, global public-good mission, and cross-border Nexus role. Diversity shall strengthen judgment, legitimacy, risk awareness, and resilience. It shall not be used as symbolic decoration or as a substitute for competence and fiduciary duty.

The Board should consider diversity across:

a) professional expertise;\
b) gender, background, and lived experience;\
c) public, nonprofit, academic, technical, community, legal, financial, and civil-society perspectives;\
d) U.S. and international experience, where appropriate;\
e) risk, resilience, sustainability, technology, governance, and development finance knowledge;\
f) communities affected by systemic risk, climate stress, infrastructure fragility, digital harm, and institutional exclusion; and\
g) Indigenous, local, community, and rights-aware perspectives where mission-relevant and safely represented.

Diversity shall be administered with care. A trustee shall not be expected to represent an entire population, geography, community, discipline, or sector unless a formal representative mandate exists. Trustees bring perspective, but fiduciary duty remains to GCRI US as a whole.

#### 192.6 Separation From Management, High-Risk Counterparties, and Conflicted Service Positions

The Board shall maintain appropriate separation from management, high-risk counterparties, vendors, donors, sponsors, regulated execution-side actors, and conflicted service positions. Some overlap may be lawful and useful at an early stage, but unmanaged overlap can weaken oversight, compromise independence, and blur fiduciary accountability.

The Board shall manage or restrict situations where a trustee is also:

a) a paid executive or employee of GCRI US;\
b) a contractor, consultant, vendor, or service provider;\
c) an officer or controlling person of a major donor or sponsor;\
d) an officer or controlling person of a vendor seeking procurement;\
e) an execution-side actor whose interests may intersect with the Corporation’s public-good work;\
f) a representative of a member seeking influence over standards, publications, or programs;\
g) a public official subject to public-law, ethics, lobbying, or procurement restrictions;\
h) a director, officer, or employee of a related entity such as GCRI Canada, GRF, GRA, protocol authorities, hosts, or national entities; or\
i) a person holding access-heavy technical, registry, repository, or controlled-room roles that require independent oversight.

Where overlap is permissible, the Board shall impose disclosure, recusal, information barriers, independent review, role limits, or non-voting treatment as appropriate. Certain overlaps may be prohibited because they undermine independence or the two-stack firewall.

#### 192.7 Vacancy, Incomplete Board, and Temporary Composition Rules

The governing instruments shall define how vacancies, incomplete Board composition, resignations, removals, incapacity, deaths, term expiries, disqualifications, and temporary absences are handled. GCRI US shall not allow governance continuity to depend on informal availability or personal goodwill.

Vacancy rules shall address:

a) who may fill vacancies;\
b) whether member approval or Board appointment is required;\
c) whether interim trustees may be appointed;\
d) term of a replacement trustee;\
e) minimum number of trustees required for valid action;\
f) whether committees may continue operating during vacancies;\
g) quorum implications;\
h) emergency authority if vacancies threaten continuity; and\
i) public and internal notice of changes.

If the Board falls below the required minimum, it shall act only to the extent permitted by law and governing instruments, typically to restore governance capacity, preserve records, protect assets, satisfy filings, maintain payroll, prevent harm, or take emergency actions. It shall not use an incomplete Board to push through major structural, financial, or constitutional decisions unless legally required and properly controlled.

#### 192.8 Publication, Registry, and Record Requirements for Board Composition

GCRI US shall maintain authoritative records of Board composition, including trustee names, categories, terms, offices, committee assignments, independence determinations, conflicts, recusals, appointment authority, resignation or removal dates, and publication status. The authoritative Board record shall govern over websites, biographies, pitch decks, event materials, social media, public announcements, and outdated rosters.

Board composition records shall include:

a) appointment or election instrument;\
b) acceptance of office;\
c) term start and end date;\
d) trustee category;\
e) voting status, if any distinctions exist;\
f) officer or committee role;\
g) conflict disclosures and recusals;\
h) training and onboarding status;\
i) resignation, removal, lapse, or succession record; and\
j) public-description language.

Public disclosure of Board composition shall be accurate and safe. Some trustee information may require restricted handling where safety, public-authority sensitivity, privacy, security, or protected participation requires it. However, the Corporation shall not mislead the public by listing former, conditional, nominee, adviser, observer, or unconfirmed persons as current trustees.

#### 192.9 Board Composition as an Anti-Capture and Continuity Control

Board composition shall be treated as a core anti-capture and continuity control. The Board shall be designed to prevent domination by any founder, donor, sponsor, executive, technical team, vendor, public authority, member class, corporate bloc, philanthropic bloc, state-linked bloc, professional network, regional bloc, or related-entity cluster.

Anti-capture controls may include:

a) independence requirements;\
b) term limits and rotation;\
c) conflict and related-party screening;\
d) limits on trustees affiliated with the same institution or related group;\
e) limits on trustees linked to major donors, vendors, or execution-side actors;\
f) independent committee chairs for audit, governance, compensation, and integrity functions;\
g) recusal and information-barrier rules;\
h) board evaluation and composition review; and\
i) succession planning that prevents personality dependence.

Continuity controls shall ensure that institutional knowledge is preserved without entrenching individuals permanently. The Board must remain stable enough to steward mission and flexible enough to adapt as the Corporation matures.

#### 192.10 Trustee Onboarding, Orientation, and Constitutional Literacy

Every trustee shall receive onboarding and orientation sufficient to perform fiduciary duties within the GCRI US model. Trustees shall not be expected to infer the Corporation’s unique architecture from ordinary nonprofit experience alone.

Onboarding shall cover:

a) mission lock and public-benefit mandate;\
b) U.S. nonprofit duties and fiduciary obligations;\
c) two-stack firewall and non-execution boundary;\
d) financial integrity, restricted funds, reserves, and anti-capture rules;\
e) safeguards, protected participation, whistleblowing, and non-retaliation;\
f) security, privacy, controlled rooms, clean rooms, and restricted handling;\
g) public-good asset stewardship, open-source discipline, publication controls, and IP boundaries;\
h) membership, representation, and Registry authorization systems;\
i) conflict-of-interest, related-party, recusal, and prohibited-overlap controls;\
j) cross-entity separateness with GCRI Canada, GRF, GRA, and other bodies; and\
k) Board procedures, reserved matters, committees, records, and delegation matrix.

A trustee who does not understand the Corporation’s constitutional architecture cannot effectively protect it. Orientation is therefore a fiduciary control.

#### 192.11 Board Composition Review and Remediation

The Board shall periodically review its own composition and determine whether it remains fit for the Corporation’s mission, risks, stage, and strategy. This review shall be candid and evidence-informed.

The review shall assess:

a) whether required expertise is present;\
b) whether independence is sufficient;\
c) whether conflicts or affiliations are concentrated;\
d) whether diversity of perspective is adequate;\
e) whether committees can function competently;\
f) whether attendance and participation are adequate;\
g) whether succession is credible;\
h) whether the Board is overdependent on any individual;\
i) whether any trustee should rotate, resign, be removed, or change role; and\
j) whether new trustees should be recruited.

Where gaps exist, the Board shall adopt a recruitment, training, committee restructuring, advisory support, or succession plan. Composition problems shall not be ignored until crisis.

#### 192.12 Interpretive Rule for Board Composition, Structure, and Design

This Section shall be interpreted to preserve a controlling proposition: the GCRI US Board shall be composed and structured to deliver independent, competent, diverse, conflict-managed, mission-literate, and continuity-ready fiduciary oversight of a nonprofit public-good institution operating under strict anti-capture and non-execution discipline.

Where ambiguity exists, the interpretation that better preserves:

a) adequate Board size;\
b) clear trustee categories;\
c) independence and expertise balance;\
d) eligibility and suitability controls;\
e) diversity of fiduciary judgment;\
f) separation from management and high-risk counterparties;\
g) vacancy and continuity discipline;\
h) accurate Board records;\
i) anti-capture design; and\
j) trustee onboarding and constitutional literacy

shall prevail unless a contrary result is required by law.

### 193. Fiduciary Duties and Trustee Standards (GCRI United States)

#### 193.1 Duty of Loyalty to GCRI US and Its Public-Benefit Mission

Each trustee shall owe a duty of loyalty to GCRI US and to the Corporation’s public-benefit mission. This duty requires the trustee to act in the best interests of the Corporation as a nonprofit public-good institution, not in the interest of any founder, donor, sponsor, member, employer, sector, public authority, vendor, affiliate, related entity, technical community, political constituency, or personal network.

The duty of loyalty shall require each trustee to:

a) place the Corporation’s mission and legal obligations ahead of personal, institutional, financial, reputational, or external interests;

b) preserve the Corporation’s independence from improper influence;

c) avoid using Board information, Board status, or Board access for private benefit or third-party advantage;

d) disclose conflicts, related-party interests, and outside roles that may affect fiduciary judgment;

e) refuse donor, sponsor, vendor, member, or political pressure inconsistent with the Corporation’s constitutional boundaries;

f) protect the Corporation’s name, assets, records, publications, repositories, and public-good infrastructure from misuse; and

g) ensure that no trustee uses the Board as a platform for personal authority, market positioning, institutional leverage, or reputational laundering.

Trustees may bring perspective from their professional, institutional, geographic, technical, academic, community, public, or civil-society experience. They may not act as instructed delegates of those constituencies unless the governing instruments expressly create such a limited representative role, and even then fiduciary duties to GCRI US shall prevail.

#### 193.2 Duty of Care, Diligence, and Informed Judgment

Each trustee shall exercise care, diligence, and informed judgment in the discharge of Board duties. Trustees shall prepare for meetings, review materials, ask appropriate questions, challenge assumptions, request clarification where information is incomplete, and participate with the seriousness required by a public-benefit institution operating in risk, resilience, standards, evidence, technology, and governance domains.

The duty of care shall require trustees to:

a) understand the matter before voting or consenting;

b) read Board materials with sufficient attention to risk, law, finance, safeguards, security, and mission implications;

c) require clear distinction between facts, assumptions, forecasts, commitments, and aspirations;

d) ensure that major decisions are supported by adequate legal, financial, technical, safeguards, and risk analysis;

e) avoid approving matters based solely on reputation, urgency, trust, or institutional momentum;

f) require management to disclose material uncertainty, dissenting analysis, and unresolved risks;

g) insist that decisions be recorded with sufficient clarity; and

h) revisit decisions where facts materially change.

Informed judgment does not require perfection. It requires disciplined attention, reasonable inquiry, and refusal to treat Board service as passive endorsement.

#### 193.3 Duty to Preserve Mission Lock, Asset Integrity, and Public Trust

Each trustee shall preserve the mission lock, asset integrity, and public trust of GCRI US. The Corporation’s assets include not only cash and tangible property, but also its public-good intellectual property, publications, standards work, records, repositories, data structures, credibility, institutional relationships, governance architecture, and public-benefit identity.

Trustees shall ensure that:

a) public-good assets are not transferred, licensed, enclosed, commercialized, or used for private advantage in a manner inconsistent with the Corporation’s mission;

b) restricted funds and purpose-bound resources are used only for their permitted purposes;

c) institutional resources are not diverted to execution-side, political, private, or donor-controlled activity;

d) public statements accurately describe the Corporation’s authority, capacity, funding, partnerships, and outputs;

e) the Corporation does not overstate government, regulator, Indigenous, community, multilateral, academic, corporate, or member endorsement;

f) the Corporation maintains correction discipline where public meaning becomes inaccurate; and

g) the Corporation’s long-term trust is valued above short-term visibility or fundraising advantage.

A trustee who protects assets but permits trust to be distorted has not fulfilled the full duty of stewardship. In the GCRI US model, trust is an institutional asset.

#### 193.4 Duty to Protect the Non-Execution Boundary and Public-Good Distinctness

Each trustee shall protect the strict non-execution boundary of GCRI US. The Corporation may conduct research, standards development, evidence stewardship, education, public-good infrastructure work, governance design, policy engagement, convening, publication, and related nonprofit functions. It shall not conduct regulated execution, market intermediation, underwriting, brokerage, custody, settlement, insurance, lending, investment advice, transaction routing, or other execution-side activity except where expressly lawful and consistent with its nonprofit status, and only if the governing instruments are lawfully amended to permit it.

Trustees shall scrutinize proposed activities, contracts, partnerships, funding models, technical products, public statements, and cross-entity arrangements for execution drift. Particular care shall be required where a proposal involves:

a) financial institutions, insurers, reinsurers, exchanges, markets, funds, banks, fintech platforms, custodians, payment systems, brokers, or market intermediaries;

b) transaction-linked fees, success fees, placement fees, routing fees, revenue shares, commissions, or outcome-linked compensation;

c) claims that GCRI US has approved, validated, guaranteed, routed, ranked, certified, or made a financial instrument investable;

d) privileged access by execution-side actors to public-good infrastructure;

e) shared services with for-profit or regulated delivery entities;

f) public-private initiatives where GCRI US’s governance role could be misread as execution authority; or

g) products, platforms, models, or evidence packs that may be used downstream in regulated markets.

Trustees shall require disclaimers, structural separation, legal review, contractual boundaries, public-description limits, and Board approval where perimeter risk is material. Boundary discipline is a fiduciary duty, not a technical preference.

#### 193.5 Duty to Oversee Risk, Compliance, Safeguards, and Security

Each trustee shall contribute to Board oversight of risk, compliance, safeguards, and security. The Corporation’s risk environment includes financial risk, legal risk, tax risk, nonprofit-status risk, cybersecurity risk, privacy risk, data-sovereignty risk, public-claims risk, procurement risk, donor-capture risk, membership risk, publication risk, cross-entity risk, safeguards risk, and continuity risk.

The Board shall require a control environment capable of identifying, escalating, and remediating such risks. Trustees shall ensure that:

a) risk appetite is defined and not left to operational instinct;

b) material risks are reported to the Board or relevant committee;

c) control functions have direct escalation routes where management is conflicted or inactive;

d) audits, reviews, incidents, and grievances produce corrective action;

e) security and privacy controls are funded and not treated as optional overhead;

f) protected participation and whistleblowing channels are safe and credible;

g) high-sensitivity materials are handled through controlled-room or clean-room procedures where required;

h) public-good technical assets are protected through secure release, access, and repository governance; and

i) systemic or recurring failures are treated as structural issues, not isolated events.

Trustees need not personally manage every risk. They must ensure the Corporation has a serious system to govern them.

#### 193.6 Duty to Avoid and Disclose Conflicts and Improper Influence

Each trustee shall avoid conflicts where possible, disclose conflicts where they arise, and comply with recusal, information-barrier, and review requirements. Conflicts shall be understood broadly. They include financial interests, employment relationships, donor or sponsor relationships, vendor relationships, public roles, political roles, family or personal relationships, cross-entity positions, intellectual-property interests, publication interests, procurement interests, and any circumstance that could reasonably affect judgment or public confidence.

A trustee shall disclose:

a) direct and indirect financial interests;

b) relationships with donors, sponsors, vendors, contractors, grantees, members, public authorities, or related entities;

c) employment, consulting, advisory, fiduciary, or governance roles outside GCRI US;

d) interests in entities that may benefit from GCRI US decisions;

e) involvement in execution-side or regulated activities adjacent to GCRI US work;

f) personal relationships that may affect judgment;

g) confidential information obtained elsewhere that may constrain participation; and

h) any pressure, inducement, request, or expectation from an external actor.

Disclosure alone is not always enough. Where required, the trustee shall recuse from deliberation, access, vote, approval, or influence. The Board shall record the conflict and the mitigation. A conflict managed only informally remains a governance weakness.

#### 193.7 Duty to Preserve Records, Validity, and Auditability of Board Action

Each trustee shall support records-first governance and validity-by-record. Board action shall be traceable through notice, agenda, materials, quorum, deliberation, conflicts, votes, resolutions, minutes, written consents, delegations, and authoritative copies.

Trustees shall ensure that:

a) decisions are not made through informal side conversations where formal Board action is required;

b) Board materials identify the decision requested and the authority for the decision;

c) minutes capture decisions, thresholds, recusals, dissent, and conditions accurately;

d) written resolutions state the exact action approved;

e) delegations are documented, time-bounded, and revocable;

f) emergency actions are ratified or reviewed according to the required clock;

g) records are preserved in institutional systems rather than personal accounts; and

h) material corrections are made through recorded supersession, not silent editing.

The Board shall not rely on memory, email trails, or public announcements as substitutes for corporate records. If a decision cannot be proven, it cannot safely be relied upon.

#### 193.8 Duty to Speak Truthfully About Institutional State and Capacity

Each trustee shall speak truthfully and carefully about GCRI US’s institutional state, authority, capacity, resources, approvals, partnerships, funding, public recognition, outputs, and limitations. Trustees shall not exaggerate the Corporation’s maturity, scale, government relationships, regulatory status, financial strength, implementation capacity, or endorsement base.

When speaking internally or externally, trustees shall distinguish:

a) approved Board decisions from proposals;

b) secured funding from prospective, conditional, pledged, or in-kind support;

c) active members from applicants, observers, former members, or informal participants;

d) adopted publications from drafts;

e) public-good stewardship from execution-side delivery;

f) GCRI US positions from personal views or views of related entities;

g) formal partnerships from discussions or exploratory relationships; and

h) lawful authority from strategic ambition.

Trustees shall correct or escalate inaccurate public claims when they become aware of them. Truthful institutional speech is part of fiduciary duty because public trust can be damaged by overstatement as much as by misconduct.

#### 193.9 Duty to Escalate Material Misconduct, Drift, or Perimeter Risk

Each trustee shall escalate material misconduct, governance drift, perimeter risk, financial irregularity, public-claims distortion, safeguards failure, security weakness, privacy breach, conflict concealment, donor pressure, executive overreach, or other matter that may materially affect the Corporation. Silence in the face of known risk may itself become a fiduciary failure.

Escalation shall occur where a trustee becomes aware of:

a) unauthorized commitments or signatures;

b) spending outside approved authority;

c) misleading funding, partnership, or endorsement claims;

d) suppression of whistleblower, safeguards, audit, security, or finance reports;

e) related-party transactions not properly reviewed;

f) pressure by donors, sponsors, vendors, members, public authorities, or executives to alter institutional judgment;

g) technical or programmatic activity drifting toward regulated execution;

h) unauthorized access to restricted materials;

i) unresolved conflict or prohibited overlap;

j) material weakness in records or filings; or

k) misconduct by a trustee, officer, executive, delegate, member, or partner.

Escalation may be to the Chair, committee chair, Secretary, Treasurer, integrity function, audit function, safeguards function, legal counsel, full Board, or other proper channel. Where the ordinary route is conflicted, trustees shall use protected escalation.

#### 193.10 Survival of Fiduciary Duties for Certain Matters After Departure

Certain fiduciary-related obligations shall survive a trustee’s resignation, removal, term expiry, disqualification, or departure to the extent required by law, these Bylaws, Board policy, confidentiality undertakings, access rules, or the nature of the matter.

Surviving duties may include:

a) confidentiality of Board materials and controlled information;

b) non-use of confidential information for private or third-party benefit;

c) return, deletion, or secure handling of Board records;

d) cooperation with audits, investigations, regulatory inquiries, or litigation holds;

e) correction of public claims suggesting current Board status;

f) non-retaliation toward persons involved in Board matters;

g) preservation of privileged or protected information;

h) compliance with post-service conflict or cooling-off restrictions where adopted; and

i) truthful description of former service.

A former trustee may accurately state prior Board service where permitted, but shall not imply current authority, current access, GCRI US endorsement, or continuing representation.

#### 193.11 Trustee Duty to Maintain Constitutional Literacy

Each trustee shall maintain sufficient understanding of the Corporation’s constitutional architecture to discharge fiduciary duties effectively. GCRI US is not an ordinary nonprofit with a narrow program footprint. It is designed as a public-good steward operating across evidence, standards, risk governance, open infrastructure, membership, controlled handling, and cross-entity interfaces. Trustees must understand the architecture they are responsible for protecting.

Trustees shall maintain literacy in:

a) mission lock and nonprofit purpose;

b) two-stack firewall and non-execution doctrine;

c) financial anti-capture controls;

d) public-good asset stewardship;

e) membership, representation, and Registry authorization;

f) safeguards, protected reporting, and non-retaliation;

g) security, privacy, controlled rooms, and clean rooms;

h) public claims, marks, and external communications discipline;

i) cross-entity separateness with GCRI Canada, GRF, GRA, and other bodies; and

j) reserved matters, delegations, Board records, and officer authority.

The Board may require orientation, refresher training, attestations, or targeted briefings. A trustee who repeatedly fails to understand core constitutional constraints may be unsuitable for continued service.

#### 193.12 Trustee Duty to Preserve Independence of High-Integrity Functions

Each trustee shall protect the independence and escalation capacity of high-integrity functions, including finance, audit, records, compliance, legal, safeguards, security, privacy, controlled handling, whistleblowing, and integrity functions. These functions must not be suppressed by management convenience, donor pressure, program urgency, public-relations concerns, or trustee discomfort.

Trustees shall ensure that high-integrity functions can:

a) report material issues to the Board or relevant committee;

b) preserve records without interference;

c) escalate misconduct or control failures;

d) recommend holds, corrections, or restrictions;

e) request independent review where needed;

f) maintain confidentiality and protected reporting channels;

g) resist pressure to alter findings; and

h) receive adequate resources relative to risk.

If control functions are under-resourced, ignored, or subordinated to growth narratives, the Board shall treat that condition as a governance risk.

#### 193.13 Trustee Duty to Prevent Personalization of the Institution

Trustees shall prevent personalization of GCRI US by any founder, chair, executive, donor, sponsor, trustee, technical lead, public figure, member, or partner. The Corporation’s identity, authority, assets, records, and reputation belong to the institution, not to individuals.

Personalization risk exists where:

a) decisions depend on personal approval outside formal authority;

b) records are held in private accounts or personal repositories;

c) public communications present the institution as the project of one person;

d) donors, members, or partners believe one person can override governance;

e) staff or participants fear reporting concerns because of personal loyalty structures;

f) public-good assets are tied to individual control rather than institutional stewardship;

g) succession planning is absent; or

h) Board oversight is weakened by deference to charisma, expertise, or history.

Trustees shall institutionalize authority, records, and succession. Personal leadership may be valuable, but it shall never become the governance system.

#### 193.14 Collective and Individual Responsibility of Trustees

The Board acts collectively, but trustees also carry individual responsibilities. A trustee cannot avoid responsibility by passive attendance, silent acquiescence, failure to read materials, habitual deference, or assumption that another trustee is handling the matter.

Each trustee shall:

a) attend meetings with reasonable regularity;

b) review materials;

c) ask questions where risk is unclear;

d) disclose conflicts;

e) vote or abstain responsibly;

f) request dissent to be recorded where necessary;

g) escalate serious concerns;

h) respect confidentiality; and

i) ensure their own conduct does not compromise the Corporation.

The Board’s collective authority depends on individual fiduciary seriousness. A strong Board is not merely a list of distinguished names. It is a working fiduciary body.

#### 193.15 Interpretive Rule for Fiduciary Duties and Trustee Standards

This Section shall be interpreted to preserve a controlling proposition: trustees of GCRI US owe active, informed, loyal, independent, mission-bound, and records-disciplined fiduciary duties to the Corporation and its public-benefit purpose, and those duties require protection of mission lock, nonprofit integrity, non-execution discipline, safeguards, security, financial controls, truthfulness, and institutional continuity.

Where ambiguity exists, the interpretation that better preserves:

a) loyalty to the Corporation over external constituencies;

b) informed and diligent judgment;

c) mission lock and asset integrity;

d) non-execution boundary protection;

e) risk, safeguards, compliance, and security oversight;

f) conflict disclosure and recusal;

g) records-first Board action;

h) truthful institutional speech;

i) escalation of misconduct or drift;

j) post-service confidentiality and correction duties;

k) constitutional literacy;

l) independence of high-integrity functions; and

m) prevention of institutional personalization

shall prevail unless a contrary result is required by law.

### 194. Reserved Matters of the Board of Trustees (GCRI United States)

#### 194.1 Reserved Matters as Non-Ordinary Corporate Authority

Reserved matters of the Board of Trustees are matters that, by law, by these Bylaws, by Board policy, by fiduciary duty, or by institutional risk profile, may not be treated as ordinary management decisions. They require Board approval, Board oversight, Board ratification, or Board-directed process because they affect the Corporation’s mission lock, nonprofit status, public-benefit mandate, financial integrity, public-good assets, institutional independence, legal exposure, safeguards obligations, security posture, or long-term continuity.

Reserved matters shall not be downgraded into routine operational acts because a program deadline is urgent, a donor expects movement, a public opportunity is attractive, a technical team is ready, a partner is pressing, or management has acted similarly in the past. If a matter belongs to the Board, it shall come to the Board before binding action is taken, unless emergency authority expressly permits temporary action subject to ratification.

Reserved-matter discipline shall apply to:

a) high-consequence decisions;\
b) high-risk commitments;\
c) matters affecting constitutional boundaries;\
d) matters involving institutional independence or capture risk;\
e) matters involving public-good asset stewardship;\
f) matters involving material financial, legal, security, privacy, or safeguards risk; and\
g) matters expressly classified as reserved by the governing record.

No person shall use operational execution to create facts on the ground that force Board approval after the fact.

#### 194.2 Approval of Budget, Financial Plan, Reserves, and Material Financial Controls

The Board shall approve the annual budget, material budget amendments, financial plan, reserve policy, liquidity thresholds, major financial controls, and any material departure from approved financial parameters. The budget is not merely an accounting document. It is the financial expression of the Corporation’s mission, risk appetite, staffing model, public-benefit priorities, and institutional independence.

Board approval shall cover, as appropriate:

a) annual operating budget;\
b) program budgets;\
c) restricted and unrestricted fund treatment;\
d) reserve targets and reserve draw rules;\
e) cash-flow assumptions and runway;\
f) major revenue assumptions;\
g) dues, grants, donations, sponsorships, contracts, and in-kind support;\
h) staffing, contractor, and professional-service budgets;\
i) security, privacy, audit, compliance, legal, safeguards, and records costs;\
j) material technology, repository, infrastructure, or cloud commitments; and\
k) contingency and wind-down cost visibility.

The Board shall not approve budgets that depend on speculative funding without transparent classification. Secured, conditional, pledged, prospective, restricted, unrestricted, cash, and in-kind resources shall be distinguished. The Board shall require management to disclose funding concentration, donor conditions, restricted-fund exposure, and any budget assumption that could pressure the Corporation toward mission drift or execution-boundary breach.

Material financial controls, including approval thresholds, banking controls, signatory authority, procurement controls, restricted-fund controls, expense policies, reserve draw procedures, and fraud-prevention controls, shall be approved by the Board or an authorized Board committee where permitted. No financial system shall rely on personal trust where institutional control is required.

#### 194.3 Approval of Executive Appointments, Removals, Compensation, and Authority Where Assigned

The Board shall approve the appointment, suspension, removal, compensation, authority scope, performance review, and succession arrangements for the chief executive, executive director, president, or equivalent senior executive where such role exists. The Board may also reserve approval over other senior management or high-integrity roles where the Corporation’s risk profile requires it.

This reserved matter exists because executive leadership can shape the Corporation’s money, staff, public narrative, partnerships, technical direction, membership systems, controlled access, and institutional culture. Executive authority shall therefore be explicitly granted, reviewed, and bounded.

Board approval shall address:

a) role description and authority limits;\
b) reporting line and Board oversight cadence;\
c) reserved matters that remain outside executive authority;\
d) compensation, benefits, expense authority, and conflicts;\
e) performance objectives tied to mission, governance, safeguards, and financial integrity;\
f) termination, suspension, leave, incapacity, and interim replacement rules;\
g) succession plan;\
h) access to records, systems, and funds; and\
i) authority to speak publicly or bind the Corporation.

No executive may acquire additional corporate authority by habit, charisma, founder status, external reputation, donor confidence, operational necessity, or repeated practice. Authority must be delegated and recorded.

#### 194.4 Approval of Major Contracts, Material Funding, and Related-Party Transactions Above Threshold

The Board shall approve major contracts, material funding arrangements, restricted grants, sponsorships, donations with conditions, shared-service agreements, leases, technology commitments, employment or consulting arrangements above threshold, vendor commitments, inter-entity arrangements, and related-party transactions where they exceed approved thresholds or present material risk.

Board review shall determine whether the arrangement:

a) is mission-consistent;\
b) is financially prudent;\
c) preserves nonprofit status and non-inurement;\
d) avoids improper private benefit;\
e) preserves non-execution discipline;\
f) contains appropriate termination and control rights;\
g) contains confidentiality, data, security, IP, audit, and records clauses;\
h) avoids donor, vendor, member, sponsor, founder, or executive capture;\
i) is properly priced or justified;\
j) has been reviewed for conflicts and related-party interests; and\
k) has been classified correctly for public claims.

Related-party transactions shall receive heightened scrutiny and shall require disclosure, recusal, independent review, and documented fairness. The Board shall not allow a related-party arrangement to proceed merely because it is convenient, urgent, familiar, donated, discounted, or historically used.

Material funding arrangements shall be reviewed not only for amount, but for conditions, public meaning, dependence, concentration, and ability to affect institutional judgment.

#### 194.5 Approval of Major Strategic Plans, Structural Changes, and Public-Good Infrastructure Commitments

The Board shall approve major strategic plans, multi-year institutional priorities, structural changes, national or cross-border expansion plans, public-good infrastructure commitments, material repository or platform commitments, major publications with institutional consequences, and any strategic shift that materially affects the Corporation’s mission, resources, risk, or public meaning.

Strategic approval shall consider:

a) mission alignment;\
b) institutional capacity;\
c) funding realism;\
d) staffing and operational readiness;\
e) security, privacy, and restricted-handling requirements;\
f) safeguards and protected-participation implications;\
g) public-good asset stewardship;\
h) technical sustainability and vendor dependency;\
i) cross-entity separateness;\
j) public claims and communications risks; and\
k) exit, continuity, and correction arrangements.

In the GCRI US model, strategic plans may involve evidence rails, standards development, risk intelligence, technical repositories, membership systems, host-institution interfaces, and Nexus-aligned public-good architecture. The Board must ensure that such plans remain nonprofit, open, mission-aligned, non-executionary, and properly resourced.

No strategic plan shall be approved if it relies on public overclaim, unfunded obligations, uncontrolled technical dependency, or blurred authority with related entities.

#### 194.6 Approval of High-Sensitivity Security, Safeguards, Privacy, and Legal Risk Responses Where Assigned

The Board shall approve or oversee high-sensitivity security, safeguards, privacy, whistleblower, legal, regulatory, litigation, sanctions, public-authority, Indigenous, community-sensitive, or incident-response matters where the risk is material, institution-wide, executive-level, reputational, constitutional, or otherwise reserved.

Such matters may include:

a) major cybersecurity or privacy incident;\
b) controlled-room breach;\
c) whistleblower or retaliation matter involving senior leadership or trustees;\
d) safeguards failure affecting protected persons or communities;\
e) high-risk public-authority or Indigenous representation dispute;\
f) litigation, government inquiry, subpoena, or regulatory notice;\
g) sanctions or financial-crime concern;\
h) public correction of materially misleading institutional claims;\
i) significant breach of confidentiality or privileged information; and\
j) legal settlement or admission affecting institutional reputation or obligations.

The Board shall ensure that management cannot suppress, understate, or public-relations-manage serious integrity matters. Where management is implicated, the matter shall be routed to an independent Board committee, counsel, or external reviewer.

Board oversight of sensitive matters shall preserve confidentiality, privilege, safety, and due process while ensuring that the Corporation acts lawfully and responsibly.

#### 194.7 Approval of Dissolution, Wind-Down, Continuity, and Successor Stewardship Steps Where Assigned

The Board shall approve dissolution, wind-down, merger, asset transfer, program closure, successor stewardship, major continuity planning, and any action that materially affects the Corporation’s existence, public-good assets, records, obligations, or long-term stewardship.

Board approval shall address:

a) legal basis;\
b) financial condition;\
c) liabilities and contingent obligations;\
d) restricted funds and donor terms;\
e) public-good assets, repositories, publications, records, data, and IP;\
f) staff, contractor, vendor, and partner obligations;\
g) member and public notice;\
h) successor eligibility;\
i) non-inurement and asset-lock compliance;\
j) archives, retention, and controlled-handling obligations; and\
k) final reporting and audit.

The Board shall not allow disorderly abandonment of corporate obligations. If GCRI US must pause, scale down, transfer, merge, or dissolve, it shall do so through disciplined stewardship.

#### 194.8 Approval of Constitutional Amendments, Policies, Charters, Annexes, and Schedules Where Assigned

The Board shall approve amendments to Bylaws, governance protocols, policy frameworks, committee charters, delegation matrices, membership schedules, financial controls, security policies, safeguards rules, publication rules, and other constitutional or quasi-constitutional instruments where approval is assigned to the Board.

The Board shall determine whether the amendment:

a) changes mission, powers, membership rights, Board authority, officer authority, or reserved matters;\
b) affects nonprofit, tax, or public-benefit obligations;\
c) changes public-good asset stewardship or IP rules;\
d) affects safeguards, privacy, security, whistleblower, or controlled-handling duties;\
e) affects financial controls, funding acceptance, reserves, or procurement;\
f) affects cross-entity relationships or the two-stack firewall;\
g) requires member approval;\
h) requires legal review or filing; and\
i) requires transition, training, or public notice.

No constitutional amendment shall be made through silent edit, document replacement, informal agreement, or operational practice. Supersession must be recorded.

#### 194.9 Approval of Inter-Entity Instruments With Major Governance, Financial, or Continuity Consequences

The Board shall approve inter-entity instruments with major governance, financial, legal, reputational, security, continuity, public-good, or cross-entity consequences. This includes agreements or memoranda with GCRI Canada, GRF, GRA, protocol authorities, host institutions, national entities, universities, public authorities, funders, vendors, or other related bodies where the arrangement affects corporate authority, assets, costs, risk, public meaning, data, or institutional separateness.

Board review shall ensure that inter-entity instruments:

a) preserve legal separateness;\
b) do not create hidden agency or control;\
c) allocate costs fairly and audibly;\
d) protect public-good assets and records;\
e) define data, privacy, security, IP, and publication responsibilities;\
f) maintain non-execution boundaries;\
g) prevent donor or partner capture;\
h) include termination and exit rights;\
i) avoid public overclaim; and\
j) clearly identify who may bind whom.

The Board shall pay particular attention to arrangements that involve shared services, shared branding, shared infrastructure, common personnel, role overlaps, or cross-border systems. Efficiency shall not become legal confusion.

#### 194.10 Any Matter Expressly Classified as Reserved by Law, Charter, Policy, or Board Resolution

Any matter expressly classified as reserved by law, Articles, Bylaws, Board resolution, committee charter, policy, delegation matrix, funding instrument, legal agreement, audit requirement, insurance requirement, or other binding instrument shall be treated as reserved to the Board or other named authority.

Management, officers, committees, or staff shall not proceed on the theory that a reserved matter is operational merely because:

a) the matter is urgent;\
b) the amount is small but risk is high;\
c) the transaction is routine in other organizations;\
d) the donor or partner expects speed;\
e) the Board previously approved similar matters;\
f) a committee discussed the matter;\
g) a trustee informally indicated support; or\
h) delay may reduce an opportunity.

Reserved status follows the governing instrument and risk profile, not convenience.

#### 194.11 Non-Delegability Rule for Core Reserved Matters Except Where Explicitly Authorized

Core reserved matters shall not be delegated unless the governing instruments expressly permit delegation and the delegation is written, scope-limited, time-bound, and subject to reporting or ratification. Even where a matter is delegated, the Board remains responsible for oversight.

Non-delegable or presumptively non-delegable matters include:

a) mission-lock changes;\
b) dissolution or asset-lock decisions;\
c) approval of annual budget and reserve policy;\
d) appointment or removal of the chief executive where assigned to the Board;\
e) major related-party transactions;\
f) amendments to Bylaws or core governance instruments;\
g) entry into regulated-execution activity or boundary-changing arrangements;\
h) major public-good asset transfer;\
i) fundamental membership rights changes; and\
j) major legal, security, or safeguards matters requiring fiduciary judgment.

The Board may delegate preparation, negotiation, review, diligence, and implementation. It shall not delegate away the decision where the decision is reserved.

#### 194.12 Reserved-Matter Intake, Classification, and Escalation Procedure

GCRI US shall maintain an intake, classification, and escalation procedure for identifying reserved matters before commitments are made. Management, officers, committees, and staff shall be trained to recognize matters that require Board or committee approval.

The intake process shall ask:

a) Does the matter affect mission, nonprofit status, or public-benefit purpose?\
b) Does the matter create financial commitment above threshold?\
c) Does it involve restricted funds, donor conditions, sponsorship, or related-party risk?\
d) Does it affect public-good assets, IP, repositories, data, or publications?\
e) Does it involve legal, regulatory, sanctions, privacy, or security risk?\
f) Does it involve safeguards, protected persons, Indigenous or community-sensitive matters?\
g) Does it involve cross-entity authority or shared services?\
h) Does it involve public claims, branding, or government/public-authority meaning?\
i) Does it approach the non-execution boundary?\
j) Is Board approval required by any instrument?

Where uncertainty exists, the matter shall be escalated. No one shall proceed on silence as approval.

#### 194.13 Board Pack Standards for Reserved Matters

Reserved matters shall be presented to the Board with sufficient information for informed fiduciary judgment. A reserved-matter Board pack shall be clear, complete, and decision-ready.

It should include:

a) decision requested;\
b) authority basis;\
c) background and alternatives;\
d) mission and public-benefit rationale;\
e) financial effect;\
f) legal and tax considerations;\
g) risk assessment;\
h) safeguards and privacy implications;\
i) security and data implications;\
j) conflict and related-party disclosures;\
k) non-execution and perimeter analysis;\
l) public-claims implications;\
m) implementation plan;\
n) monitoring and reporting requirements; and\
o) draft resolution.

The Board shall not be asked to approve vague strategic language where concrete obligations are being created. If the Board cannot identify what it is approving, the matter is not ready.

#### 194.14 Emergency Action on Reserved Matters and Ratification Discipline

Emergency action on a reserved matter may occur only where immediate action is required to prevent material harm and the governing instruments permit interim action. Emergency authority shall be narrow, time-bound, recorded, and subject to prompt Board review or ratification.

Emergency reserved-matter action may be appropriate to:

a) contain a security incident;\
b) preserve records;\
c) protect funds;\
d) prevent legal default;\
e) suspend unsafe access;\
f) preserve payroll or critical operations;\
g) respond to urgent legal process; or\
h) prevent harm to protected participants.

Emergency action shall not be used to approve major strategic shifts, new revenue models, boundary-changing arrangements, constitutional amendments, permanent structural changes, or donor-driven commitments without proper Board process.

The record shall state what happened, who acted, why emergency action was necessary, what authority was used, what limits applied, and when Board ratification or review occurred.

#### 194.15 Unauthorized Reserved-Matter Acts, Cure, and Remedies

Any act taken without required Board approval on a reserved matter shall be reviewed. Depending on law, reliance, harm, and institutional risk, the act may be treated as void, voidable, non-binding, ratifiable, correctable, terminable, or subject to remedial action.

The review shall consider:

a) who acted;\
b) what authority was claimed;\
c) whether the actor knew approval was required;\
d) whether third parties relied on the act;\
e) financial, legal, security, safeguards, and reputational impact;\
f) whether conflicts or improper influence were present;\
g) whether urgent circumstances existed;\
h) whether ratification is lawful and prudent; and\
i) what controls failed.

Remedies may include ratification, contract amendment, termination, public correction, financial recovery, access revocation, discipline, delegation revision, training, or Board policy update. Ratification shall not be granted automatically. It shall be a fiduciary decision.

#### 194.16 Interpretive Rule for Reserved Matters of the Board

This Section shall be interpreted to preserve a controlling proposition: matters affecting GCRI US’s mission, nonprofit integrity, financial condition, public-good assets, executive authority, legal exposure, safeguards, security, cross-entity posture, or non-execution boundary require Board-level control and may not be converted into ordinary operational decisions by urgency, habit, prestige, donor pressure, or convenience.

Where ambiguity exists, the interpretation that better preserves:

a) Board approval of budgets and controls;\
b) executive accountability;\
c) scrutiny of material contracts, funding, and related-party transactions;\
d) strategic and public-good infrastructure oversight;\
e) high-sensitivity risk response;\
f) dissolution and successor-stewardship control;\
g) constitutional amendment discipline;\
h) inter-entity separateness;\
i) non-delegability of core matters;\
j) reserved-matter intake and escalation;\
k) informed Board packs;\
l) emergency ratification discipline; and\
m) remedy for unauthorized acts

shall prevail unless a contrary result is required by law.

### 195. Meetings of the Board of Trustees (GCRI United States)

#### 195.1 Ordinary Meetings and Annual Governance Calendar

The Board of Trustees shall meet at intervals sufficient to discharge its fiduciary duties, supervise management, approve reserved matters, monitor risk, review financial condition, preserve mission lock, and maintain institutional continuity. Ordinary Board meetings shall not be treated as ceremonial check-ins. They shall be structured governance events through which trustees receive evidence, test assumptions, review institutional condition, approve matters within authority, and hold management accountable.

The Board shall maintain an annual governance calendar that identifies the expected cadence for:

a) annual budget approval and mid-year budget review;\
b) financial reporting, reserve review, and cash-flow monitoring;\
c) audit, review, or financial assurance matters;\
d) risk appetite, risk register, and key risk indicator review;\
e) safeguards, whistleblowing, protected participation, and grievance reporting;\
f) cybersecurity, privacy, controlled-room, and restricted-handling review;\
g) membership, Registry, representation, and anti-capture review;\
h) executive performance, compensation, and succession review;\
i) committee reports and committee workplans;\
j) policy, bylaw, delegation, and reserved-matter review; and\
k) annual report, public-claim integrity, and public-good asset stewardship review.

The annual governance calendar shall remain flexible enough to respond to urgent matters, but it shall be disciplined enough to ensure that core fiduciary duties are not displaced by program activity, donor engagement, public events, or operational urgency.

#### 195.2 Special Meetings and Time-Sensitive Convening

Special meetings of the Board may be convened where a matter requires Board attention before the next ordinary meeting. A special meeting may be called for a reserved matter, urgent contract, material funding decision, executive matter, legal issue, security incident, safeguards concern, public-claim correction, financial stress, cross-entity decision, or other matter requiring fiduciary review.

A special meeting shall be limited to the business identified in the notice unless the governing rules permit additional business and all required procedural safeguards are satisfied. The Corporation shall not use special meetings to rush complex matters without adequate materials, legal review, conflict review, or trustee preparation.

Where time-sensitive convening is required, the notice and Board pack shall clearly identify:

a) why the matter cannot wait;\
b) what decision is requested;\
c) what authority the Board is exercising;\
d) what risks, constraints, and alternatives exist;\
e) whether legal, finance, safeguards, security, or conflicts review has occurred; and\
f) whether ratification, follow-up, or monitoring will be required.

Urgency shall justify speed only where governance discipline remains intact.

#### 195.3 Emergency Board Meetings and Protective Use Limits

Emergency Board meetings may be convened where immediate Board action is required to prevent or mitigate material harm to the Corporation, its assets, people, records, public-good infrastructure, legal position, security posture, safeguards obligations, financial condition, nonprofit status, or public trust.

Emergency meetings may be appropriate for:

a) cybersecurity or privacy incidents;\
b) serious financial irregularity or liquidity stress;\
c) whistleblower, retaliation, or safeguards emergencies;\
d) material legal demand, subpoena, regulatory inquiry, or litigation event;\
e) unauthorized public claim requiring correction;\
f) suspected fraud, corruption, sanctions, or financial-crime matter;\
g) executive misconduct, incapacity, or sudden departure;\
h) controlled-room breach or restricted-information exposure;\
i) urgent continuity, bank authority, or records-preservation need; or\
j) any event that may impair mission lock or constitutional boundaries if delayed.

Emergency governance shall be protective and temporary. It shall not be used to permanently reconfigure corporate authority, approve major strategic shifts, adopt constitutional amendments, accept incompatible funding, alter membership rights, transfer public-good assets, or enter execution-side activity without the required ordinary or special approval process.

The emergency record shall state the emergency trigger, the reduced procedure used, the persons present, the decisions made, the authority relied upon, the time limits imposed, and the ratification or review clock.

#### 195.4 Notice, Agenda, and Board Packet Requirements

Board meetings shall be preceded by notice that complies with applicable law, these Bylaws, Board policy, and any applicable waiver or emergency provisions. Notice shall be sufficient to allow trustees to prepare, assess conflicts, request additional information, and understand whether the meeting includes ordinary business, reserved matters, controlled-room segments, executive sessions, or emergency action.

A Board notice or packet shall identify, as applicable:

a) date, time, time zone, and modality;\
b) meeting type;\
c) agenda items;\
d) decision items and information items;\
e) resolutions proposed;\
f) authority basis for reserved matters;\
g) materials to be reviewed;\
h) conflict and recusal prompts;\
i) confidentiality and publication class;\
j) controlled-room or executive-session segments;\
k) expected attendees, advisers, counsel, auditors, or management participants; and\
l) actions requested of trustees before the meeting.

A Board packet shall be accurate, decision-ready, and proportionate to the matter. It shall not obscure material risks through promotional writing, selective facts, excessive jargon, or omission of dissenting analysis. Where information is incomplete, the packet shall state what is unknown and what assumptions are being made.

#### 195.5 Quorum, Attendance, and Continuity of Meeting Validity

The Board may act only where quorum is present, unless law or the governing instruments permit a narrower emergency or procedural action. Quorum shall be determined according to the Articles, these Bylaws, Board policy, and any special quorum rule for the matter.

Quorum shall be assessed at the start of the meeting and, where material, before each decision. A trustee who is recused from a matter, disqualified from voting, or excluded from a controlled segment shall be treated according to the applicable quorum rule for that matter.

Where quorum is lost:

a) no further decision requiring quorum shall be taken;\
b) the loss shall be recorded;\
c) the Board may continue discussion only where permitted;\
d) the matter may be deferred, adjourned, or re-noticed; and\
e) any attempted decision after loss of quorum shall be voidable unless lawfully cured.

Trustee attendance shall be recorded. Repeated non-attendance shall be treated as a governance concern because fiduciary service requires active participation, not name-only association.

#### 195.6 In-Person, Virtual, and Hybrid Participation

Board meetings may be conducted in person, virtually, or through hybrid participation where permitted by law and governing instruments. The meeting modality shall support identity verification, confidentiality, trustee participation, voting integrity, controlled-room discipline, and accurate records.

Virtual and hybrid meetings shall include controls for:

a) secure access;\
b) trustee identity confirmation;\
c) attendance logging;\
d) management of guests, advisers, counsel, auditors, and observers;\
e) prevention of unauthorized recording or attendance;\
f) secure distribution of Board materials;\
g) confidential executive sessions;\
h) voting verification;\
i) technical fallback where connectivity fails; and\
j) preservation of meeting records.

Trustees shall participate from locations and devices suitable for Board confidentiality. A trustee shall not participate in a sensitive Board meeting from a public place, unsecured device, shared screen, or environment where confidential discussion may be overheard.

#### 195.7 Accessibility, Language Accommodation, and Safe Participation in Board Context

Board meetings shall be conducted in a manner that enables trustees to participate effectively, safely, and with dignity. Accessibility and language accommodation shall be provided where reasonably required and feasible, consistent with confidentiality, security, and meeting validity.

Board participation discipline shall include:

a) accessible formats for Board materials where needed;\
b) adequate time for review;\
c) clear meeting structure;\
d) respectful deliberation;\
e) protection of dissent and minority reasoning;\
f) no retaliation for questions, objections, or escalation;\
g) controlled handling of sensitive personal, public-authority, Indigenous, community, or whistleblower matters; and\
h) procedures for trustees to raise concerns outside management presence.

Board safe participation is essential because trustees must be able to challenge management, donors, founders, committee chairs, executives, and each other without fear of retaliation, exclusion, or reputational penalty.

#### 195.8 Controlled-Room Segmentation for Sensitive Board Matters

The Board shall use controlled-room segmentation where Board matters involve sensitive information requiring restricted attendance, special handling, limited notes, confidentiality controls, legal privilege, or heightened security. Controlled-room treatment may apply within a Board meeting, as a separate Board session, or through a restricted committee process.

Controlled-room segmentation may be required for:

a) legal privilege and litigation strategy;\
b) executive compensation, performance, suspension, or removal;\
c) whistleblower, retaliation, grievance, or safeguards matters;\
d) cybersecurity, privacy, or restricted-information incidents;\
e) sanctions, fraud, corruption, or financial-crime concerns;\
f) controlled evidence or sensitive research materials;\
g) public-authority, Indigenous, or community-sensitive matters;\
h) related-party transactions and conflicts;\
i) merger, dissolution, wind-down, or asset-transfer matters; and\
j) any matter where broad distribution would increase harm.

The controlled-room record shall identify the designation, participants, matter scope, access limits, note-taking rules, materials used, decisions made, and closure conditions. Public or ordinary Board minutes may include a sanitized summary where appropriate.

#### 195.9 Executive Sessions Without Management or Conflicted Participants

The Board may meet in executive session without management, staff, conflicted trustees, advisers, guests, or other persons where independent deliberation is necessary. Executive sessions are a governance tool for preserving fiduciary independence, not a signal of distrust by default.

Executive sessions may address:

a) executive performance and compensation;\
b) management accountability;\
c) audit or financial-control concerns;\
d) legal advice;\
e) conflict or related-party matters;\
f) whistleblower or integrity reports;\
g) Board self-evaluation;\
h) succession planning; and\
i) any matter where open management presence would impair candid fiduciary deliberation.

The Board shall record that an executive session occurred, the general category of matter, who was present, and any formal decision made. Detailed content may be restricted where confidentiality, privilege, or safety requires.

#### 195.10 Minute Standards, Record of Deliberation, and Resolution Certification

Board minutes shall be accurate, concise, and sufficient to evidence lawful action. They shall not be advocacy documents, transcripts, or public-relations narratives. They shall capture the matters necessary to prove authority, process, deliberation, decision, and accountability.

Minutes shall include, as applicable:

a) meeting identifier;\
b) date, time, location or modality;\
c) trustees present and absent;\
d) guests, advisers, management, counsel, or auditors present;\
e) quorum confirmation;\
f) agenda items;\
g) conflicts disclosed and recusals;\
h) materials reviewed;\
i) decisions taken;\
j) resolutions adopted;\
k) votes, abstentions, and dissents where recorded;\
l) conditions, follow-up actions, responsible persons, and deadlines;\
m) controlled-room or executive-session notation; and\
n) certification by the Secretary or authorized recorder.

Where a formal resolution is adopted, the resolution shall state the decision, authority, effective date, scope, conditions, delegation if any, and record of approval. The certified resolution shall be preserved as an authoritative instrument.

#### 195.11 Defective Process, Cure, Ratification, and Reconsideration Rules

Where a Board meeting or decision suffers from defective notice, agenda omission, quorum defect, conflict-handling failure, voting error, insufficient materials, unauthorized attendance, publication-class breach, technical failure, or recording error, the Board shall determine whether the defect affects validity and what cure is required.

Possible cures may include:

a) supplemental minutes;\
b) correction of scrivener’s error;\
c) re-circulation of materials;\
d) re-notice;\
e) re-vote;\
f) ratification where legally permitted;\
g) rescission or replacement of a resolution;\
h) conflict review and re-approval without conflicted participation;\
i) legal review; and\
j) notification to affected parties where reliance occurred.

Ratification shall not be used to hide misconduct or normalize bypassing Board process. It shall be used only where lawful, informed, and institutionally appropriate.

#### 195.12 Board Meeting Confidentiality and Information Discipline

Board meeting materials, deliberations, minutes, executive-session content, controlled-room records, and trustee communications shall be handled according to their classification. Trustees shall preserve confidentiality and shall not disclose Board information to employers, members, donors, sponsors, public authorities, media, affiliated entities, or personal networks unless disclosure is authorized.

Information discipline requires trustees to:

a) use approved channels for Board materials;\
b) avoid forwarding Board materials without authority;\
c) avoid storing Board records in uncontrolled systems;\
d) avoid unauthorized AI processing of sensitive Board materials;\
e) preserve privilege and confidentiality;\
f) return or delete materials where required;\
g) report suspected information exposure; and\
h) refrain from public commentary on confidential Board matters.

Board transparency shall occur through approved reporting, annual reports, public summaries, or formal communications, not through informal trustee disclosure.

#### 195.13 Board Action Tracking and Management Follow-Up

Board decisions shall be tracked after approval. The Board shall not treat adoption of a resolution as the end of governance. Implementation, conditions, reporting, and closure must be monitored where the matter is material.

Action tracking shall identify:

a) decision or resolution;\
b) responsible executive, officer, committee, or trustee;\
c) deadline or review point;\
d) conditions precedent;\
e) reporting requirements;\
f) risk or control dependencies;\
g) budget implications;\
h) required filings, notices, or public statements; and\
i) closure evidence.

Management shall report on implementation. The Board shall review overdue, partially completed, or failed actions. A Board decision that is never implemented, never monitored, or never closed creates governance risk.

#### 195.14 Interpretive Rule for Meetings of the Board of Trustees

This Section shall be interpreted to preserve a controlling proposition: Board meetings of GCRI US are fiduciary decision environments that require proper notice, adequate materials, quorum, conflict discipline, secure participation, controlled handling, accurate minutes, certified resolutions, cure of defects, confidentiality, and implementation tracking.

Where ambiguity exists, the interpretation that better preserves formal Board validity, informed trustee judgment, secure and safe deliberation, reserved-matter control, accurate recordkeeping, executive accountability, and fiduciary continuity shall prevail unless a contrary result is required by law.

### 196. Voting, Decisions, and Written Resolutions of the Board (GCRI United States)

#### 196.1 Ordinary and Supermajority Thresholds for Board Decisions

Board decisions of GCRI US shall be approved only under the voting threshold applicable to the matter. The Board shall distinguish ordinary decisions from reserved matters, constitutional matters, emergency matters, conflict-sensitive matters, related-party matters, dissolution or wind-down matters, executive compensation matters, and other high-consequence decisions requiring heightened approval.

Ordinary Board decisions may be approved by the default threshold established by law, the Articles, these Bylaws, or Board policy. Special matters may require a higher threshold because they affect mission lock, nonprofit status, public-good assets, fiduciary structure, financial integrity, member rights, security posture, safeguards obligations, executive authority, or institutional continuity.

The Board shall identify the threshold before voting. The meeting record shall state:

a) the decision being taken;

b) the authority under which the Board is acting;

c) the trustees eligible to vote;

d) any trustees recused, conflicted, absent, or disqualified;

e) the quorum applicable to the matter;

f) the threshold required;

g) the vote result; and

h) whether the decision passed, failed, was deferred, or was conditionally approved.

No decision shall be treated as approved where the wrong threshold was used. Where threshold uncertainty exists, the matter shall be deferred, escalated for governance or legal review, or treated under the more protective threshold.

#### 196.2 Recorded Vote, Consensus, and Formal Resolution Pathways

The Board may decide matters through recorded vote, consensus, unanimous consent, formal resolution, written resolution, or another lawful decision pathway. The pathway selected shall match the legal importance, risk level, and required auditability of the matter.

Consensus may be appropriate for low-risk procedural matters or matters where all trustees clearly support the action and no formal counted vote is required. However, consensus shall not be used to avoid recording opposition, obscure abstentions, bypass thresholds, or approve high-consequence decisions without clear evidence.

Formal resolutions shall be used for material matters, including:

a) approval of budgets, reserves, and material financial controls;

b) appointment, removal, compensation, or authority of senior executives or officers;

c) major contracts, funding arrangements, and related-party transactions;

d) adoption or amendment of bylaws, policies, charters, annexes, schedules, or delegation instruments;

e) establishment or dissolution of committees;

f) approval of material public statements, filings, reports, or institutional positions where required;

g) controlled-room, legal, safeguards, or security matters requiring formal authorization;

h) dissolution, wind-down, successor stewardship, merger, or major asset transfer; and

i) any matter for which an authoritative instrument is required.

The resolution shall state the operative action in full sentence form, identify the authority and effective date, specify conditions and limits, and name any person or office authorized to implement the decision.

#### 196.3 Written Resolutions and Unanimity Rules Where Applicable

Written resolutions and written consents may be used where permitted by law and governing instruments. Written action shall be treated as equivalent to Board action only if all procedural requirements are satisfied. It shall not be used to avoid discussion of difficult matters, conceal conflict, pressure trustees into rapid approval, or bypass proper Board meeting discipline.

A written resolution shall include:

a) exact text of the proposed action;

b) explanation of the matter and authority;

c) relevant supporting materials;

d) conflicts and recusal instructions;

e) required approval threshold;

f) deadline for response;

g) method of execution or electronic approval;

h) effect of non-response;

i) certification process; and

j) record retention location.

Where unanimity is required by law or governing instruments, unanimity means affirmative written approval by every trustee entitled to vote, excluding only those lawfully recused or disqualified if the governing rule permits exclusion. Silence, non-response, informal email acknowledgment, or absence of objection shall not equal consent unless the governing rule expressly permits that mechanism.

Written resolutions for high-risk matters shall include enough materials for informed fiduciary judgment. Trustees shall be permitted to request discussion before signing where the matter is not suitable for written approval.

#### 196.4 Abstentions, Recusals, and Disqualified Votes

Abstentions, recusals, and disqualified votes shall be handled with precision. The Board shall not blur these categories.

An abstention means a trustee is present and entitled to vote but chooses not to vote for or against. A recusal means a trustee is excluded from deliberation, access, vote, or some combination of those elements because of conflict or other disqualification. A disqualified vote means the trustee is not entitled to vote on the matter because of law, governing instruments, conflict, status, or other restriction.

The record shall state:

a) who abstained;

b) who was recused;

c) whether the recused trustee left the meeting, left the room, left the digital session, or was excluded from materials;

d) whether the recused trustee was counted for quorum, if applicable;

e) whether any vote was excluded; and

f) the basis for material recusals or disqualifications.

A trustee who is conflicted shall not influence other trustees privately, receive controlled materials unnecessarily, or participate through informal channels. Recusal is not merely abstention from the final vote. It may require exclusion from discussion, access, preparation, and follow-up.

#### 196.5 Validity Requirements for Remote Voting and Electronic Resolution

Remote voting and electronic Board resolutions may be used where lawful and where the Corporation can ensure identity, authority, confidentiality, vote integrity, and record preservation. Electronic convenience shall not weaken fiduciary discipline.

Remote voting systems shall support:

a) secure trustee authentication;

b) confirmation of eligibility to vote;

c) identification of matter and resolution text;

d) recording of vote, abstention, or refusal;

e) confirmation of timestamp;

f) protection from unauthorized access or alteration;

g) preservation of the vote record;

h) management of conflicts and recusals; and

i) ability to certify the result.

Trustees shall not vote through unsecured channels where the matter is sensitive. For high-sensitivity matters, the Board may require encrypted tools, controlled-room process, executive session, counsel-supervised vote, or signed written consent.

If electronic voting integrity is compromised or uncertain, the Board shall pause reliance on the result and determine whether re-vote, re-notice, ratification, or correction is required.

#### 196.6 Challenge, Reopening, and Scrivener’s Error Correction

The Board shall maintain a disciplined process for challenging, reopening, correcting, or clarifying Board decisions where a material issue arises. The process shall distinguish between clerical error, procedural defect, substantive reconsideration, and legal invalidity.

A challenge may be appropriate where:

a) notice was defective;

b) quorum was not present;

c) the wrong threshold was applied;

d) a conflicted trustee participated improperly;

e) trustees lacked material information;

f) the resolution text did not match the Board’s actual decision;

g) the decision exceeded Board authority;

h) the decision required member approval, legal review, or additional clearance;

i) a vote was counted incorrectly; or

j) the record fails to prove the decision.

Scrivener’s errors may be corrected through a certified correction where the correction does not change the substance of the Board’s decision. Substantive corrections shall require Board approval or lawful ratification.

Reopening shall not be used casually to relitigate settled matters. It shall be used where new facts, procedural defect, legal issue, fiduciary concern, or material implementation failure justifies reconsideration.

#### 196.7 Dissent Preservation and Request for Recorded Reasoning

Trustees may request that dissent, abstention, reservations, or reasoning be recorded where appropriate. Dissent preservation is a fiduciary safeguard. It protects institutional memory, clarifies risk, and prevents false appearance of unanimity.

A trustee may request recording of:

a) objection to a decision;

b) concern about process;

c) concern about conflicts or recusals;

d) concern about legal, financial, safeguards, security, or perimeter risk;

e) objection to insufficient information;

f) abstention with stated reason;

g) minority position; or

h) request for further review.

The minutes shall record dissent in a concise and fair manner. The Board may classify dissent records as confidential where they contain sensitive information. Dissent shall not be used for public campaigning, retaliation, disclosure of privileged information, or personal attack.

A Board culture that suppresses dissent is structurally weak. A Board culture that records principled dissent is stronger and more trustworthy.

#### 196.8 No Board Decision Has Effect Absent Proper Record and Authority Mapping

No Board decision shall have full institutional effect unless it is supported by proper authority mapping and record. A verbal agreement, informal call, text message, email chain, meeting sentiment, chair summary, donor discussion, executive instruction, or public announcement shall not substitute for Board action where Board action is required.

Authority mapping shall identify:

a) the organ acting;

b) the matter class;

c) the source of authority;

d) whether the matter is reserved;

e) whether member approval or external filing is required;

f) whether officer action is required to implement;

g) whether committee recommendation preceded the decision;

h) whether conflicts were managed;

i) whether the decision creates delegation or signature authority; and

j) whether follow-up reporting is required.

The record shall make the decision usable by future trustees, officers, auditors, counsel, regulators, donors, members, and successors without relying on personal memory.

#### 196.9 Conditional Approvals and Authority to Implement

The Board may grant conditional approvals where implementation depends on satisfaction of specific conditions. Conditional approval shall be explicit. Management or officers shall not treat a conditional approval as unconditional authority.

Conditions may include:

a) legal review;

b) budget confirmation;

c) donor-condition clarification;

d) conflict clearance;

e) safeguards review;

f) security or privacy assessment;

g) final contract review;

h) member approval where required;

i) public-description approval;

j) funding receipt; or

k) Board committee sign-off.

A conditional approval shall identify who may determine whether conditions are satisfied, what evidence is required, what deadline applies, and whether the matter returns to the Board before implementation. If conditions are not satisfied, authority shall expire or remain suspended.

#### 196.10 Ratification of Prior Acts

The Board may ratify prior acts only where ratification is lawful, informed, consistent with fiduciary duty, and not used to conceal misconduct or normalize unauthorized conduct. Ratification is a remedy, not a governance shortcut.

Before ratifying a prior act, the Board shall consider:

a) who acted;

b) what authority was absent or uncertain;

c) whether the act was within corporate powers;

d) whether third parties relied on the act;

e) whether conflicts existed;

f) whether private benefit or capture risk arose;

g) whether legal, financial, security, or safeguards harm occurred;

h) whether correction or termination is preferable;

i) whether disciplinary or structural remediation is required; and

j) whether future controls must be changed.

Ratification shall be recorded with clear statement of the act ratified, effective date, limits, reasons, and any remedial conditions. Some acts shall not be ratified because they are unlawful, mission-inconsistent, ultra vires, or constitutionally incompatible.

#### 196.11 Trustee Participation, Debate, and Deliberative Integrity

Board decisions shall be made through deliberative integrity. Trustees must have a meaningful opportunity to understand, question, challenge, and debate material matters before voting. Deliberation shall not be replaced by pre-cooked conclusions, executive pressure, donor urgency, founder authority, or procedural choreography designed to produce predetermined approval.

Deliberative integrity requires:

a) adequate materials;

b) sufficient time relative to the matter’s importance;

c) disclosure of material risks and alternatives;

d) opportunity for questions;

e) ability to hear dissenting or technical views where relevant;

f) management response to trustee concerns;

g) conflict-free discussion where required;

h) controlled executive session where needed; and

i) no retaliation for opposing, abstaining, or requesting more information.

A trustee may vote against, abstain, request deferral, request independent review, or request dissent notation without being treated as disloyal. Fiduciary loyalty is owed to the Corporation, not to unanimity.

#### 196.12 Decision Registers and Implementation Evidence

The Corporation shall maintain a Board decision register or equivalent system that tracks material Board decisions, resolutions, conditions, delegated implementation authority, responsible persons, due dates, and closure evidence. A decision register shall help ensure that Board action is implemented, monitored, and auditable.

The register may include:

a) decision identifier;

b) meeting or written consent reference;

c) resolution text or summary;

d) matter class;

e) approval threshold and result;

f) implementation owner;

g) conditions precedent;

h) deadlines;

i) related contracts, policies, filings, or public statements;

j) reporting requirements;

k) closure status; and

l) supersession or amendment history.

The Board shall periodically review open decisions and unresolved conditions. A decision that has not been implemented or has become outdated shall be closed, amended, superseded, or reapproved as appropriate.

#### 196.13 Interpretive Rule for Voting, Decisions, and Written Resolutions of the Board

This Section shall be interpreted to preserve a controlling proposition: Board decisions of GCRI US are valid only when the correct trustees act under the correct authority, with the correct threshold, conflict discipline, deliberative integrity, record, and implementation controls, whether the decision is made in meeting, remotely, electronically, by written resolution, or by lawful ratification.

Where ambiguity exists, the interpretation that better preserves:

a) correct voting thresholds;

b) formal resolution discipline;

c) valid written consent;

d) recusal and disqualified-vote control;

e) secure remote voting;

f) correction of defects without concealment;

g) dissent preservation;

h) proper authority mapping;

i) conditional approval discipline;

j) lawful ratification only where appropriate;

k) deliberative integrity; and

l) decision-register tracking

shall prevail unless a contrary result is required by law.

### 197. Officers of GCRI US

#### 197.1 Officer Structure and Categories

GCRI US may maintain officer roles necessary to administer the Corporation’s legal, fiduciary, financial, records, operational, governance, and continuity functions. Officer structure shall be established by the Articles, these Bylaws, Board resolution, employment or appointment instrument, delegation matrix, or other recorded authority.

Officer roles may include:

a) Chair of the Board;\
b) Vice-Chair or Deputy Chair;\
c) Secretary;\
d) Treasurer;\
e) President, Chief Executive Officer, Executive Director, or equivalent executive officer;\
f) additional corporate officers created by the Board; and\
g) acting, interim, assistant, deputy, or delegated officer roles where expressly authorized.

Officer titles shall be functional, not ornamental. Each office shall have a defined authority surface, reporting line, term or service condition, appointment authority, removal rule, signature authority, record obligations, conflict duties, and succession arrangement.

No person shall acquire officer authority through informal usage of title, public biography, email signature, meeting attendance, founder status, management habit, donor confidence, or external perception. Officer status exists only where lawfully created, appointed, accepted, and recorded.

#### 197.2 Officers as Custodians of Specific Corporate Functions

Officers shall serve as custodians of specific corporate functions. They do not own those functions. They are entrusted with authority to help the Corporation operate lawfully, coherently, and accountably under Board oversight.

Officer functions may include:

a) convening and procedural leadership;\
b) corporate records and notices;\
c) financial stewardship and reporting;\
d) legal and filing coordination;\
e) execution of approved contracts and instruments;\
f) implementation of Board decisions;\
g) management reporting;\
h) bank, treasury, and payment controls within approved authority;\
i) safeguarding of official statements and corporate seals or marks where applicable; and\
j) escalation of risks to the Board.

An officer shall not treat delegated authority as personal discretion detached from mission, records, financial controls, conflict rules, or Board direction. The officer’s function is fiduciary-adjacent and record-bound.

#### 197.3 Chair of the Board

The Chair of the Board shall serve as the procedural and stewardship leader of the Board, subject to the collective authority of the Board. The Chair shall help ensure that the Board meets, receives adequate information, addresses reserved matters, preserves fiduciary discipline, and maintains orderly deliberation.

The Chair may be responsible for:

a) convening Board meetings;\
b) approving or coordinating agendas with the Secretary and executive leadership;\
c) ensuring that Board materials are timely and decision-ready;\
d) facilitating trustee deliberation;\
e) ensuring that conflicts, recusals, quorum, and voting rules are respected;\
f) supporting Board evaluation, trustee onboarding, and succession;\
g) coordinating executive sessions where appropriate;\
h) helping ensure that Board decisions are implemented and tracked; and\
i) serving as an authorized spokesperson only where the Board or governing instruments permit.

The Chair shall not unilaterally substitute for the Board. The Chair shall not approve reserved matters, bind the Corporation outside delegated authority, alter minutes, suppress dissent, prevent protected escalation, or treat procedural leadership as executive control.

#### 197.4 Vice-Chair or Deputy Chair

The Vice-Chair or Deputy Chair, where appointed, shall support Board continuity, assist the Chair, and act where the Chair is absent, conflicted, incapacitated, unavailable, or otherwise unable to perform duties, subject to the limits of the governing instruments.

The Vice-Chair may perform:

a) acting chair duties for a meeting or matter;\
b) support for agenda preparation;\
c) trustee coordination;\
d) succession and continuity support;\
e) oversight of Board evaluation or governance initiatives where assigned; and\
f) other duties delegated by the Board.

The Vice-Chair shall not acquire independent authority simply because the role exists. Acting authority shall be tied to specific absence, recusal, delegation, or Board instruction. The Vice-Chair may not override the Chair, Board, Secretary, Treasurer, or executive leadership except where the governing record gives authority.

#### 197.5 Secretary

The Secretary shall serve as custodian of corporate record integrity, notices, minutes, resolutions, authoritative copies, Board and member records, and governance-document discipline. The Secretary’s role is central to validity-by-record.

The Secretary shall be responsible, directly or through controlled delegation, for:

a) issuing or supervising corporate notices;\
b) maintaining minutes of Board, committee, and member meetings where applicable;\
c) preserving resolutions, written consents, registers, and authoritative instruments;\
d) maintaining trustee, officer, member, committee, and delegation records;\
e) certifying records where authorized;\
f) managing correction, supersession, and authoritative copy discipline;\
g) supporting filings and governance calendars;\
h) ensuring that meeting records reflect conflicts, recusals, quorum, decisions, and voting results; and\
i) protecting corporate records from informal alteration, loss, or uncontrolled distribution.

The Secretary shall not silently amend records, erase dissent, alter decisions after approval, or allow public-facing materials to contradict the authoritative record. Where the Secretary is pressured to distort records, the Secretary shall have a protected escalation route to the Board or appropriate committee.

#### 197.6 Treasurer

The Treasurer shall serve as an officer of financial oversight, discipline, and Board-facing financial stewardship. The Treasurer shall support the Board’s ability to understand the Corporation’s financial condition, budget adherence, reserves, restricted-fund obligations, financial controls, and material financial risks.

The Treasurer may be responsible for:

a) reviewing financial reports before Board presentation;\
b) supporting budget preparation and monitoring;\
c) reviewing reserve levels, liquidity, and cash-flow posture;\
d) overseeing banking, signatory, payment, and segregation-of-duties discipline within Board-approved rules;\
e) supporting audit, review, tax filing, and financial reporting processes;\
f) escalating financial irregularities, fraud concerns, restricted-fund issues, or donor-condition risks;\
g) helping ensure that financial claims are accurate; and\
h) supporting Board review of major funding, spending, and related-party matters.

The Treasurer shall not bypass Board approval for reserved matters. The Treasurer shall not approve payments to themselves, related parties, conflicted vendors, or unauthorized commitments. The Treasurer shall not be the sole control point for money, records, banking, and reconciliation where segregation of duties is required.

#### 197.7 Additional Officers Created by Board or Bylaw

The Board may create additional officer roles where necessary for the Corporation’s growth, risk profile, legal obligations, or institutional architecture. Such roles may include, for example, Chief Operating Officer, Chief Financial Officer, Chief Legal Officer, Chief Compliance Officer, Chief Risk Officer, Chief Security Officer, Chief Safeguards Officer, Chief Records Officer, Chief Technology Steward, or other titles appropriate to nonprofit governance and management.

Any additional officer role shall be created through recorded action specifying:

a) title;\
b) purpose;\
c) appointing authority;\
d) reporting line;\
e) scope of authority;\
f) signature authority, if any;\
g) budget or spending authority, if any;\
h) access to records and systems;\
i) escalation duties;\
j) conflict and confidentiality obligations;\
k) term, removal, and succession rules; and\
l) relationship to existing officers and management.

No new title shall be adopted merely for prestige, fundraising optics, public positioning, or external credibility. Officer titles must correspond to real accountability.

#### 197.8 Distinction Between Officers and Senior Management / Executive Staff

GCRI US shall distinguish officers from senior management and executive staff. Some individuals may hold both officer and management roles, but the capacities shall be recorded separately. Officer authority derives from corporate appointment and governing instruments. Management authority derives from employment, contract, executive delegation, budget authority, or operational mandate.

This distinction matters because:

a) an employee may manage programs without being an officer;\
b) an officer may hold corporate duties without managing daily operations;\
c) a senior executive may have operational authority but still require Board approval for reserved matters;\
d) a corporate officer may certify records or sign instruments only within defined authority; and\
e) a public title may create apparent authority if not carefully controlled.

Where one person holds multiple capacities, the Corporation shall specify which capacity is being exercised for each act. A person signing a contract, issuing a public statement, approving a payment, certifying minutes, or instructing staff shall be acting under a defined authority source.

#### 197.9 No Officer Title Alone Confers Unbounded Corporate Authority

No officer title shall confer unbounded corporate authority. Titles such as Chair, President, Chief Executive Officer, Executive Director, Secretary, Treasurer, Chief Officer, Director, or equivalent shall be read subject to the Articles, Bylaws, Board resolutions, delegation matrix, signature authority, employment terms, conflict rules, and reserved-matter boundaries.

An officer may not, without proper authority:

a) approve a reserved matter;\
b) bind the Corporation to a major contract;\
c) accept incompatible funding;\
d) alter constitutional instruments;\
e) authorize public claims beyond recorded facts;\
f) create membership rights;\
g) grant controlled-room access;\
h) waive conflict or safeguards rules;\
i) approve related-party transactions;\
j) transfer public-good assets;\
k) commit the Corporation to regulated execution; or\
l) override Board, committee, legal, finance, security, or safeguards controls.

The Corporation shall control officer apparent authority through signature matrices, public-description rules, contract procedures, banking controls, and internal training. Third parties shall not be allowed to assume that a title alone is enough.

#### 197.10 Appointment, Acceptance, Removal, and Resignation of Officers

Officers shall be appointed, elected, confirmed, removed, or replaced according to the governing instruments and Board-approved procedures. Officer appointment shall be recorded and shall not be inferred from performance of duties.

An officer record shall include:

a) appointment authority;\
b) title and role description;\
c) effective date;\
d) term or service condition;\
e) acceptance of office;\
f) authority limits;\
g) reporting line;\
h) signature authority;\
i) compensation or employment linkage, if any;\
j) conflict disclosures;\
k) required training and attestations; and\
l) resignation, removal, or succession terms.

An officer may resign by written notice. The Board may remove an officer where permitted by law and governing instruments, with or without cause depending on the role and applicable terms, provided that removal respects contractual, employment, due process, and protected-reporting obligations. If removal affects corporate continuity, the Board shall appoint an acting or interim officer promptly.

#### 197.11 Officer Conflicts, Recusal, and Related-Party Discipline

Officers shall comply with conflict-of-interest, related-party, recusal, non-inurement, confidentiality, and anti-capture rules. Officer conflicts may be especially consequential because officers often control records, payments, contracts, communications, staff direction, or implementation.

An officer shall disclose:

a) financial interests;\
b) outside employment or consulting;\
c) donor, sponsor, vendor, member, public-authority, or related-entity relationships;\
d) family or personal relationships affecting judgment;\
e) ownership or control interests in counterparties;\
f) cross-entity roles; and\
g) any pressure or inducement that may affect officer duties.

Where a conflict exists, the officer may be restricted from access, deliberation, negotiation, approval, signature, payment, certification, or public communication relating to the matter. A conflicted officer shall not self-clear. The matter shall be routed to the Board, committee, Chair, Secretary, Treasurer, legal counsel, or other proper authority depending on the conflict.

#### 197.12 Officer Duty to Escalate Material Risk, Drift, or Misconduct

Every officer shall have a duty to escalate material risk, governance drift, misconduct, financial irregularity, security incident, privacy concern, safeguards failure, public-claims error, conflict concealment, unauthorized commitment, controlled-room breach, or non-execution boundary concern.

An officer shall not remain silent because the issue is inconvenient, politically sensitive, donor-linked, founder-linked, executive-linked, or reputationally uncomfortable. The officer’s duty is to the Corporation and its mission.

Escalation may be to:

a) the Chair;\
b) the Board;\
c) a Board committee;\
d) the Secretary;\
e) the Treasurer;\
f) legal counsel;\
g) safeguards or integrity function;\
h) audit or finance function;\
i) security or privacy function; or\
j) another protected reporting route where ordinary channels are conflicted.

An officer who suppresses, delays, manipulates, or fails to escalate material risk may be subject to removal, discipline, access restriction, or other remedy.

#### 197.13 Acting, Interim, Assistant, and Deputy Officer Roles

The Board may appoint acting, interim, assistant, or deputy officers where necessary for continuity, workload, succession, absence, conflict, emergency, or institutional growth. Such roles shall be carefully defined to avoid authority confusion.

An acting or interim officer role shall specify:

a) reason for appointment;\
b) scope of authority;\
c) start date and expected end date;\
d) decisions permitted;\
e) decisions requiring Board approval;\
f) signature authority;\
g) reporting line;\
h) access to systems and records;\
i) restrictions; and\
j) ratification or transition obligations.

Assistant or deputy officers may support the principal officer, but shall not assume full officer powers unless the governing record grants them. The Corporation shall not allow deputy titles to create shadow authority.

#### 197.14 Officer Records, Public Description, and Authority Mapping

GCRI US shall maintain authoritative records of officer appointments, authority, terms, resignations, removals, acting roles, delegations, and public-description language. Public-facing officer lists, websites, biographies, press releases, funding materials, and filings shall match the authoritative record.

Officer records shall map:

a) title;\
b) legal or internal status;\
c) authority source;\
d) signature authority;\
e) reporting line;\
f) public spokesperson authority, if any;\
g) financial authority, if any;\
h) controlled access, if any;\
i) conflicts and recusals;\
j) term and expiry; and\
k) successor or acting arrangement.

No person shall be publicly presented as an officer before appointment is effective. No former officer shall continue to use current officer language after resignation, removal, term expiry, or transition.

#### 197.15 Interpretive Rule for Officers of GCRI US

This Section shall be interpreted to preserve a controlling proposition: officers of GCRI US are formal holders of defined corporate functions, appointed and recorded under Board authority, and no officer title creates unlimited power, reserved-matter authority, public-speaking authority, financial authority, or execution-side capacity beyond the specific authority granted.

Where ambiguity exists, the interpretation that better preserves:

a) formal officer appointment;\
b) functional role clarity;\
c) Secretary records discipline;\
d) Treasurer financial stewardship;\
e) Chair procedural leadership without unilateral control;\
f) distinction between officer and management authority;\
g) no title-based apparent authority;\
h) conflict and escalation duties;\
i) continuity through acting and deputy roles; and\
j) accurate public officer records

shall prevail unless a contrary result is required by law.

### 198. Chair of the Board (GCRI United States)

#### 198.1 Role of the Chair as Procedural and Stewardship Leader of the Board

The Chair of the Board shall serve as the procedural and stewardship leader of the Board of Trustees. The Chair’s office exists to strengthen collective fiduciary governance, not to replace it. The Chair shall help ensure that the Board is properly convened, adequately informed, procedurally disciplined, mission-focused, risk-aware, and capable of exercising independent judgment.

The Chair shall act as guardian of Board process in relation to:

a) meeting discipline;\
b) agenda integrity;\
c) trustee participation;\
d) conflict and recusal handling;\
e) executive-session discipline;\
f) reserved-matter routing;\
g) Board pack quality;\
h) decision certification;\
i) follow-up tracking; and\
j) trustee onboarding, evaluation, and succession.

The Chair shall not be the owner of the Corporation, the substitute for the Board, the personal supervisor of all institutional activity, or the unilateral interpreter of mission. The Chair leads the Board’s process so that the Board can govern as a fiduciary body.

#### 198.2 Convening, Agenda, and Board Process Duties

The Chair shall support the proper convening of Board meetings and the preparation of agendas that reflect the Corporation’s governance calendar, reserved matters, risk profile, financial condition, compliance needs, executive accountability, and public-benefit obligations.

In performing this function, the Chair shall ensure that:

a) matters requiring Board approval are placed before the Board in time;\
b) urgent matters are not delayed because they are uncomfortable;\
c) sensitive matters are not buried in ordinary updates;\
d) trustees receive sufficient materials to exercise informed judgment;\
e) financial, legal, security, safeguards, and conflict implications are surfaced;\
f) management reports distinguish facts, assumptions, forecasts, and requests for decision;\
g) Board agendas include adequate time for fiduciary discussion; and\
h) the Board is not reduced to passive receipt of management narrative.

The Chair may coordinate with the Secretary, Treasurer, executive leadership, committee chairs, and governance-spine functions to prepare the agenda. The Chair shall not use agenda control to suppress dissent, block protected escalation, shield management, avoid audit or safeguards issues, or prevent trustees from considering matters properly within Board authority.

#### 198.3 Relationship to Trustees, Officers, and Executive Leadership

The Chair shall maintain a disciplined relationship with trustees, officers, and executive leadership. The Chair shall support trustees in fulfilling their duties, coordinate with officers in their defined functions, and engage executive leadership in a manner that preserves Board oversight without creating unmanaged operational interference.

The Chair’s relationship to executive leadership shall be structured by:

a) the executive’s approved role description;\
b) Board delegations;\
c) reporting requirements;\
d) performance objectives;\
e) reserved-matter boundaries;\
f) escalation protocols; and\
g) applicable employment or service terms.

The Chair may provide guidance, feedback, and coordination to the executive leader, but shall not privately alter Board decisions, grant authority outside delegation, approve compensation or contracts alone, suppress reporting to the Board, or create personal dependency between the executive and the Chair.

The Chair shall also ensure that trustees are not excluded from fiduciary information through over-centralization. The Chair may facilitate Board flow, but the Board remains collective.

#### 198.4 No Unilateral Substitution for Collective Board Authority

The Chair shall not unilaterally substitute for collective Board authority. Unless expressly authorized by the governing instruments or a Board resolution, the Chair may not approve reserved matters, bind the Corporation to material commitments, amend governance instruments, approve budgets, appoint or remove executives, accept material funding, approve related-party transactions, issue institutional positions, authorize controlled access, or alter corporate records.

The Chair shall not claim authority based on:

a) title;\
b) founder status;\
c) donor confidence;\
d) urgency;\
e) operational convenience;\
f) repeated practice;\
g) personal relationship with management;\
h) external expectations; or\
i) absence of immediate objection from other trustees.

Where the Chair acts under delegated authority, the delegation shall be written, specific, limited, recorded, and subject to reporting. Where the Chair acts under emergency authority, the action shall be time-bound and subject to ratification or review.

#### 198.5 Tie-Break, Emergency, and Interim Powers Only Where Expressly Granted

Any tie-break, emergency, interim, acting, or protective power of the Chair shall exist only where expressly granted by law, the Articles, these Bylaws, Board policy, or Board resolution. Such powers shall be narrowly construed.

A tie-break power, if granted, shall specify:

a) matters where it applies;\
b) matters where it does not apply;\
c) whether it applies to reserved matters;\
d) whether conflicted matters are excluded;\
e) whether supermajority matters are excluded; and\
f) how the tie-break is recorded.

Emergency or interim powers, if granted, shall specify:

i) the emergency trigger;\
ii) permitted protective acts;\
iii) prohibited acts;\
iv) time limit;\
v) reporting requirement;\
vi) ratification clock; and\
vii) record requirements.

The Chair shall not use emergency authority to make permanent constitutional changes, approve major strategic commitments, accept incompatible funding, transfer public-good assets, enter execution-side activity, or bypass Board oversight. Emergency authority preserves the institution until the Board can act; it does not replace the Board.

#### 198.6 Succession, Temporary Absence, and Acting Chair Rules

GCRI US shall maintain succession, temporary absence, and acting Chair rules so that Board leadership does not depend on one person. Where the Chair is absent, conflicted, incapacitated, unavailable, removed, resigned, or otherwise unable to act, the Vice-Chair, Deputy Chair, designated trustee, or other person identified by the governing instruments may act within the defined scope.

Acting Chair rules shall specify:

a) trigger for acting authority;\
b) person entitled to act;\
c) duration of acting authority;\
d) powers included;\
e) powers excluded;\
f) notice to trustees;\
g) record of transition; and\
h) process for restoration or permanent replacement.

Where the Chair is conflicted in a matter, another trustee shall chair that matter if required. A conflicted Chair shall not control agenda, materials, debate, access, minutes, or voting procedure for the affected matter.

Succession rules are a governance continuity control. They prevent procedural paralysis and prevent personal office from becoming institutional dependency.

#### 198.7 Conduct, Neutrality, and Conflict Standards for the Chair

The Chair shall be held to heightened conduct, neutrality, and conflict standards because the Chair influences agenda, meeting flow, trustee participation, executive relationship, and public meaning. The Chair shall act with fairness, restraint, confidentiality, independence, and fidelity to the Corporation’s mission.

The Chair shall:

a) treat trustees fairly;\
b) protect lawful dissent;\
c) ensure conflicts are disclosed and managed;\
d) avoid retaliatory agenda control;\
e) preserve confidentiality;\
f) avoid public overclaim;\
g) prevent dominance by founders, donors, sponsors, executives, members, or technical teams;\
h) support safe escalation of concerns; and\
i) model disciplined adherence to Board process.

The Chair shall not use the office to reward loyalty, punish questions, suppress minority views, favour a donor, protect management from accountability, overstate institutional authority, or create informal governance outside the Board.

#### 198.8 Chair’s Role in Mission Lock and Non-Execution Discipline

The Chair shall ensure that the Board remains attentive to mission lock and non-execution discipline. Because GCRI US operates in a Nexus-aligned environment where evidence, standards, finance-adjacent systems, resilience infrastructure, technology, and public-sector interfaces may intersect, the Chair shall ensure that boundary questions reach the Board before the Corporation is exposed.

The Chair shall route to the Board or appropriate committee any matter that may involve:

a) execution-side activity;\
b) transaction-linked revenue;\
c) regulated financial or insurance activity;\
d) public-good asset enclosure;\
e) donor or sponsor influence;\
f) related-party arrangement;\
g) public claim of endorsement, certification, routeability, or government adoption;\
h) controlled evidence or restricted data; or\
i) cross-entity authority confusion.

The Chair’s procedural leadership shall therefore include boundary vigilance. A Chair who allows mission drift to remain operationally hidden fails the stewardship function of the office.

#### 198.9 Chair’s Role in Board Culture, Evaluation, and Trustee Development

The Chair shall help cultivate a Board culture capable of serious fiduciary oversight. This requires more than orderly meetings. It requires informed trustees, honest risk discussion, respectful challenge, good records, learning, and collective responsibility.

The Chair shall support:

a) trustee onboarding;\
b) constitutional literacy;\
c) annual Board evaluation;\
d) committee performance review;\
e) succession planning;\
f) improvement of Board packs;\
g) trustee attendance and engagement;\
h) corrective action where Board process is weak; and\
i) recruitment of needed skills and perspectives.

The Chair shall not treat Board culture as unity at all costs. A healthy Board can disagree, record dissent, ask difficult questions, and still act collectively. The Chair’s task is to make disciplined disagreement possible.

#### 198.10 Chair’s Relationship to Public Statements and External Representation

The Chair may represent GCRI US externally only where authorized. Chair title alone shall not create unlimited spokesperson authority. Public statements by the Chair shall remain accurate, mission-bound, non-executionary, and aligned with approved communication rules.

The Chair shall not publicly state or imply that:

a) GCRI US has adopted positions not approved;\
b) governments, regulators, Indigenous institutions, members, or partners have endorsed GCRI US beyond recorded authority;\
c) funding has been secured where it is only prospective;\
d) GCRI US executes financial, insurance, market, or regulated activity;\
e) member participation equals certification or recognition; or\
f) related entities are legally merged or controlled by GCRI US.

Where the Chair speaks personally, that capacity shall be clear. Where the Chair speaks institutionally, the statement shall reflect Board-approved authority or delegated communication authority.

#### 198.11 Chair’s Duty to Protect Records and Board Independence

The Chair shall protect the integrity of Board records and Board independence. The Chair shall not direct the Secretary to alter minutes improperly, omit dissent, erase conflicts, backdate decisions, overstate approvals, or create records inconsistent with what the Board actually did.

The Chair shall also ensure that management, donors, founders, or external actors do not control Board materials, Board access to information, or Board deliberation in a manner that compromises independence.

Where the Chair becomes aware that Board records are inaccurate or that trustees are being denied material information, the Chair shall act to correct the issue or escalate it to the Board.

#### 198.12 Removal, Review, or Restriction of Chair Authority

The Board may review, restrict, suspend, replace, or remove the Chair where the Chair fails to perform duties, exceeds authority, suppresses Board oversight, mishandles conflicts, breaches confidentiality, retaliates, misrepresents the Corporation, weakens records, blurs the non-execution boundary, or otherwise becomes unsuitable for the office.

Measures may include:

a) warning or corrective instruction;\
b) agenda co-approval requirement;\
c) independent meeting facilitation;\
d) appointment of acting chair for specific matters;\
e) recusal from affected matters;\
f) restriction of spokesperson authority;\
g) removal from committee roles;\
h) removal as Chair; or\
i) removal from the Board where grounds exist.

The Chair is accountable to the Board. The office does not sit above the Board.

#### 198.13 Interpretive Rule for Chair of the Board

This Section shall be interpreted to preserve a controlling proposition: the Chair of the Board of GCRI US is a procedural and stewardship leader of the Board’s collective fiduciary work, not a unilateral governor, executive substitute, founder proxy, donor channel, record controller, or unbounded spokesperson.

Where ambiguity exists, the interpretation that better preserves:

a) collective Board authority;\
b) agenda integrity;\
c) trustee participation and dissent;\
d) conflict and recusal discipline;\
e) narrow emergency and interim authority;\
f) succession and acting-chair clarity;\
g) mission lock and non-execution vigilance;\
h) truthful public representation;\
i) record integrity; and\
j) Chair accountability to the Board

shall prevail unless a contrary result is required by law.

### 199. Vice-Chair and Other Board Leadership Roles (GCRI United States)

#### 199.1 Role of the Vice-Chair in Continuity and Support

The Vice-Chair of the Board, where appointed, shall serve as a continuity, support, and stewardship officer within the Board’s governance architecture. The Vice-Chair shall strengthen the Board’s ability to function when the Chair is absent, conflicted, unavailable, overloaded, or otherwise unable to perform procedural leadership duties.

The Vice-Chair shall support:

a) continuity of Board meetings and governance calendar;\
b) preparation for Board deliberation where assigned;\
c) support to trustees requiring process clarification;\
d) succession planning for Board leadership;\
e) continuity during emergencies, conflicts, incapacity, or transition;\
f) Board evaluation and governance improvement where assigned;\
g) protected escalation where the Chair is conflicted or unavailable; and\
h) preservation of collective Board authority.

The Vice-Chair shall not be a parallel Chair, shadow executive, informal chief of staff, donor liaison with governance authority, or independent source of corporate approval. The role exists to support Board resilience, not to create a second center of unbounded authority.

#### 199.2 Acting Authority in Chair Absence, Recusal, or Incapacity

The Vice-Chair may act as Chair only where the Chair is absent, recused, incapacitated, unavailable, conflicted, removed, suspended, or otherwise unable to act, and only within the scope authorized by the Bylaws, Board resolution, succession rule, meeting rule, or specific delegation.

Acting authority may include:

a) convening or chairing a Board meeting;\
b) chairing a specific agenda item where the Chair is conflicted;\
c) coordinating agenda finalization with the Secretary and executive leadership;\
d) preserving meeting order and voting procedure;\
e) ensuring that conflicts, recusals, and controlled-room restrictions are observed;\
f) signing or certifying documents where expressly authorized; and\
g) supporting continuity until the Chair resumes authority or a replacement is appointed.

Acting authority shall be recorded. The record shall identify why the Vice-Chair acted, the scope of authority, the time period, the matter covered, and any limits. The Vice-Chair shall not use temporary acting status to make permanent changes, approve reserved matters, alter Board records, expand personal authority, or create commitments beyond the authority granted.

#### 199.3 Limits on Unilateral Action by the Vice-Chair

The Vice-Chair shall not exercise unilateral corporate authority except where expressly granted. The Vice-Chair’s title shall not create power to bind the Corporation, approve contracts, direct management, commit funds, issue institutional positions, remove officers, grant access, alter records, approve public statements, or decide reserved matters.

The Vice-Chair may not rely on:

a) Board leadership title;\
b) familiarity with trustees;\
c) operational convenience;\
d) donor or partner expectation;\
e) urgency absent emergency authority;\
f) prior involvement in discussions;\
g) informal instruction by the Chair; or\
h) public perception of seniority

as authority to act.

Where the Chair asks the Vice-Chair to perform a task, the Vice-Chair shall confirm whether the task is procedural support, delegated Board authority, management action, or reserved matter. If the task exceeds the Chair’s own authority, the Chair cannot validly delegate it to the Vice-Chair.

#### 199.4 Additional Board Leadership Roles and Their Scope Where Created

The Board may create additional Board leadership roles where needed for governance effectiveness, including Lead Independent Trustee, Committee Coordinating Trustee, Governance Lead, Risk Oversight Lead, Safeguards Liaison, Security Oversight Liaison, Board Evaluation Lead, or other role-specific leadership positions.

Each additional leadership role shall be created through recorded authority and shall specify:

a) title;\
b) purpose;\
c) appointing authority;\
d) term or review date;\
e) scope of duties;\
f) authority limits;\
g) relationship to the Chair, Vice-Chair, committees, officers, and management;\
h) access to information;\
i) reporting obligations;\
j) conflicts and recusal requirements; and\
k) public-description rules.

No leadership role shall be created for prestige alone. A Board leadership role must solve a governance problem, improve oversight, strengthen continuity, support independence, or manage a defined fiduciary surface.

#### 199.5 Lead Independent Trustee and Independence Safeguards

Where the Chair is not independent, holds an executive role, has founder status, has a material relationship with a donor, sponsor, member, vendor, related entity, or other high-influence actor, or where Board independence otherwise requires reinforcement, the Board may appoint a Lead Independent Trustee.

The Lead Independent Trustee may support:

a) executive sessions without management or conflicted leadership;\
b) Board evaluation of the Chair;\
c) trustee communication where the Chair is conflicted;\
d) independent review of related-party or donor-sensitive matters;\
e) escalation of concerns involving the Chair or executive leadership;\
f) oversight of Board information flow; and\
g) protection of dissent and trustee independence.

The Lead Independent Trustee shall not become a rival executive or informal veto-holder. The role exists to preserve fiduciary independence and provide a safe governance channel where ordinary leadership channels are conflicted.

#### 199.6 Committee Chairs as Board Leadership Roles

Committee chairs shall be Board leadership roles for the committees they lead. A committee chair shall facilitate committee work, ensure the committee operates within its charter, report to the Board, and preserve records of committee recommendations, findings, and decisions.

A committee chair shall not:

a) exceed the committee charter;\
b) approve Board reserved matters unless expressly delegated;\
c) suppress committee dissent;\
d) act as management;\
e) conceal material findings from the Board;\
f) allow conflicts to remain unmanaged; or\
g) publicly represent committee conclusions before Board approval where required.

Committee chair authority is charter-based. It does not arise from seniority, expertise, or relationship with management.

#### 199.7 Succession and Temporary Delegation Rules

The Board shall maintain clear succession and temporary delegation rules for Board leadership. These rules shall identify who acts when the Chair, Vice-Chair, committee chair, Secretary, Treasurer, or other leadership role-holder is absent, conflicted, incapacitated, removed, or unavailable.

Succession rules shall address:

a) order of acting authority;\
b) trigger events;\
c) scope of acting authority;\
d) duration;\
e) notice to trustees;\
f) matters excluded from acting authority;\
g) record requirements; and\
h) process for appointment of permanent replacement.

Temporary delegation shall be narrow, recorded, and time-bound. It shall not create permanent authority or alter the governance structure. Temporary leadership shall preserve continuity while returning authority to the proper organ as soon as practicable.

#### 199.8 Board Leadership Role in Protected Escalation and Sensitive Matters

Board leadership roles shall support protected escalation in sensitive matters. Where a concern involves the Chair, executive leadership, donor pressure, financial irregularity, security incident, safeguards failure, public-claims distortion, retaliation, or governance misconduct, trustees and officers must have a path to raise the concern without routing it through a conflicted person.

The Vice-Chair, Lead Independent Trustee, committee chair, Secretary, Treasurer, or other designated leader may receive or route protected escalation where the ordinary path is conflicted.

Such escalation shall be handled with:

a) confidentiality;\
b) need-to-know discipline;\
c) non-retaliation;\
d) records preservation;\
e) prompt routing to the proper committee or Board process;\
f) conflict screening; and\
g) protective measures where needed.

Board leadership must never become a shield against accountability. It must be a structure through which accountability can reach the Board.

#### 199.9 Public Description of Board Leadership Roles

Public description of Board leadership roles shall be accurate, current, and non-misleading. A person may be described as Chair, Vice-Chair, Lead Independent Trustee, Committee Chair, or another Board leadership role only where the role is current, recorded, and approved for public description.

Public description shall not imply:

a) unilateral authority;\
b) executive management authority unless separately held;\
c) ownership or founder control;\
d) authority over related entities;\
e) endorsement of external projects;\
f) ability to bind the Corporation without Board approval; or\
g) authority beyond the specific role.

Former or acting leadership roles shall be described with dates and limits where necessary. Public materials shall be corrected promptly when leadership changes.

#### 199.10 Review, Restriction, or Removal of Board Leadership Roles

The Board may review, restrict, suspend, or remove a Vice-Chair or other Board leadership role-holder where the person fails to perform duties, exceeds authority, mishandles conflicts, suppresses information, misrepresents the Corporation, breaches confidentiality, weakens Board independence, or becomes unsuitable for leadership.

Possible measures include:

a) role clarification;\
b) corrective instruction;\
c) recusal from a matter;\
d) suspension of leadership authority;\
e) appointment of another trustee to chair a matter;\
f) removal from committee chair or leadership role;\
g) independent review; and\
h) further trustee removal process where warranted.

Board leadership roles are entrusted functions. They may be changed when institutional integrity requires it.

#### 199.11 Interpretive Rule for Vice-Chair and Other Board Leadership Roles

This Section shall be interpreted to preserve a controlling proposition: Vice-Chair and Board leadership roles in GCRI US exist to support continuity, independence, process integrity, protected escalation, and fiduciary effectiveness, and do not create unilateral corporate authority, executive power, public-speaking authority, or reserved-matter authority beyond the recorded grant.

Where ambiguity exists, the interpretation that better preserves role clarity, collective Board authority, acting-authority limits, leadership succession, committee charter discipline, independence safeguards, protected escalation, and accurate public description shall prevail unless a contrary result is required by law.

### 200. Secretary and Records Governance Functions (GCRI United States)

#### 200.1 Secretary as Custodian of Corporate Record Integrity

The Secretary shall serve as the principal custodian of corporate record integrity for GCRI US. This office protects the legal memory of the Corporation by ensuring that notices, meetings, resolutions, minutes, written consents, officer records, trustee records, committee records, delegations, registers, authoritative copies, and corporate instruments are created, preserved, classified, corrected, and retrieved through disciplined process.

The Secretary’s function is constitutional in effect. Without reliable records, the Corporation cannot prove authority, confirm decisions, demonstrate compliance, preserve fiduciary continuity, or protect public trust. The Secretary shall therefore ensure that corporate records answer the essential governance questions:

a) who had authority;\
b) what decision was made;\
c) when the decision became effective;\
d) what procedure was followed;\
e) what conflicts or recusals applied;\
f) what conditions or limits were attached;\
g) who was authorized to implement;\
h) what record is authoritative; and\
i) whether the act remains current, amended, superseded, expired, or revoked.

The Secretary shall not be treated as a clerical recorder only. The office is a high-integrity governance function.

#### 200.2 Notice, Minutes, Resolution, and Authoritative Copy Responsibilities

The Secretary shall be responsible for ensuring that notices, minutes, resolutions, written consents, certifications, and authoritative copies are properly prepared and maintained. The Secretary may be supported by staff, counsel, governance officers, or approved systems, but the records function shall remain subject to controlled oversight.

The Secretary shall ensure that notices identify the meeting or action, date, time, modality, agenda, decision items, required materials, confidentiality class, voting thresholds, quorum requirements, and any special procedures. Minutes shall capture attendance, quorum, conflicts, recusals, deliberation sufficient for governance purposes, resolutions, votes, dissent where recorded, executive sessions, controlled-room segmentation, and follow-up actions.

Authoritative copies shall be maintained for:

a) Articles and amendments;\
b) Bylaws and schedules;\
c) Board and committee charters;\
d) Board and member resolutions;\
e) officer appointments and delegations;\
f) signature matrices;\
g) conflict disclosures and recusal records;\
h) policy instruments;\
i) major contracts and approvals;\
j) annual filings and reports; and\
k) supersession and correction records.

Where multiple copies circulate, the Secretary shall identify which version is authoritative.

#### 200.3 Record Authentication, Version Integrity, and Repository Discipline

The Secretary shall maintain authentication and version integrity for corporate records. No governance document shall be silently edited, replaced, backdated, selectively excerpted, or circulated as current if it has been superseded or remains in draft.

Repository discipline shall require:

a) version identifiers;\
b) effective dates;\
c) approval authority;\
d) supersession notes;\
e) change logs;\
f) access controls;\
g) retention classification;\
h) authoritative-copy marking; and\
i) clear separation between draft, approved, archived, superseded, and public versions.

Where a document is corrected, the correction shall be traceable. Where an instrument is superseded, the prior version shall be preserved unless lawful destruction is required. Where a public version differs from the internal authoritative version because of redaction or confidentiality, the record shall indicate that relationship.

#### 200.4 Interface With Gazette, Register, Registry, or Other Official Notice Systems

The Secretary shall coordinate the corporate records function with any Gazette, register, Registry, official notice system, membership system, council registry, public roster, controlled-room register, or cross-entity records interface used by GCRI US. Corporate records and public-facing notice systems must remain consistent.

This interface shall ensure that:

a) trustee and officer changes are reflected accurately;\
b) membership authority decisions are linked to corporate records;\
c) Board resolutions are not misrepresented in public summaries;\
d) Registry authorizations do not conflict with Board decisions;\
e) committee charters and delegations are current;\
f) public notices reflect approved language;\
g) controlled-room decisions remain classified where required; and\
h) superseded authorities are removed from operational use.

Where a mismatch exists between an authoritative corporate record and a register, roster, website, public notice, meeting pack, or Registry entry, the Secretary shall initiate correction or escalation. Public trust depends on alignment between internal authority and external representation.

#### 200.5 Delegation to Secretariat Staff Under Recorded Control

The Secretary may delegate administrative or preparatory tasks to Secretariat staff, governance staff, counsel, records personnel, contractors, or approved technology systems where appropriate. Such delegation shall be recorded and controlled. Delegation of tasks shall not equal abdication of responsibility.

Delegated tasks may include:

a) preparing draft minutes;\
b) circulating notices;\
c) maintaining calendars;\
d) organizing Board packs;\
e) managing document repositories;\
f) maintaining registers;\
g) tracking resolutions and action items;\
h) supporting filings; and\
i) preparing certified extracts for review.

The Secretary shall ensure that delegated personnel understand confidentiality, version control, classification, retention, and correction rules. No staff member or contractor may alter corporate records outside authorized workflow. Access to sensitive records shall be need-to-know and revocable.

#### 200.6 No Informal Alteration, Silent Edit, or Unrecorded Correction of Board Acts

No Board act, member act, officer appointment, delegation, resolution, minute, committee record, or authoritative instrument may be informally altered, silently edited, backdated, or corrected without record. The Secretary shall prevent record manipulation, whether intentional or accidental.

Corrections shall be classified as:

a) clerical correction;\
b) scrivener’s error correction;\
c) clarification;\
d) supplemental minute;\
e) substantive amendment;\
f) supersession; or\
g) ratification record.

Clerical corrections may be made through controlled procedure. Substantive corrections require proper authority. If minutes do not accurately reflect the decision, the Board or relevant body shall approve correction. If a resolution was defective, it shall be corrected, ratified, rescinded, or reapproved through proper process.

Silent edits are prohibited because they destroy the evidentiary chain of governance.

#### 200.7 Continuity and Succession of Secretary Functions

GCRI US shall maintain continuity and succession arrangements for the Secretary function. Corporate records shall not depend on one person’s personal device, inbox, memory, private archive, or informal filing habits.

Continuity arrangements shall include:

a) secure repository access for authorized successors;\
b) documented records map;\
c) backup procedures;\
d) filing calendar;\
e) Board and committee records index;\
f) delegation and signature authority index;\
g) controlled-room and restricted records index;\
h) retention and destruction schedule; and\
i) emergency access protocol.

Where the Secretary resigns, is removed, becomes unavailable, or is conflicted, the Board shall appoint an acting Secretary or assign records custody under controlled terms. The outgoing Secretary shall cooperate in orderly transition, subject to confidentiality and legal obligations.

#### 200.8 Secretary’s Role in Governance Validity and Decision Readiness

The Secretary shall support governance validity before, during, and after decisions. Before a meeting, the Secretary shall help confirm notice, agenda classification, quorum requirements, voting thresholds, decision authority, conflicts process, and record template. During a meeting, the Secretary shall ensure that decisions are captured accurately. After a meeting, the Secretary shall certify or route the record for approval, update registers, track actions, and preserve authoritative copies.

For reserved matters, the Secretary shall ensure that the Board pack or resolution identifies:

a) authority basis;\
b) decision requested;\
c) required threshold;\
d) implementation authority;\
e) conditions;\
f) follow-up actions; and\
g) records affected.

The Secretary shall be empowered to flag procedural deficiencies. If a decision cannot be properly recorded because authority, quorum, threshold, conflict status, or decision wording is unclear, the Secretary shall request clarification before the record is finalized.

#### 200.9 Secretary’s Protected Escalation Duty

The Secretary shall have a protected escalation duty where corporate records, notices, minutes, resolutions, registers, delegations, or authoritative instruments are being distorted, suppressed, altered, withheld, backdated, destroyed, or used in a misleading way.

Escalation may be required where:

a) management pressures the Secretary to omit material information;\
b) a Chair seeks to alter minutes inconsistently with the meeting;\
c) a trustee or officer attempts to rely on authority not granted;\
d) public materials contradict authoritative records;\
e) a delegation or signature is being misused;\
f) records are withheld from trustees entitled to receive them;\
g) conflict or recusal records are missing;\
h) a decision is implemented before approval; or\
i) corporate records are at risk of loss or unauthorized access.

The Secretary may escalate to the Chair, Vice-Chair, Lead Independent Trustee, Board, Governance Committee, Audit and Risk Committee, counsel, or other protected channel where ordinary routing is conflicted.

#### 200.10 Secretary’s Role in Public Claims and Corporate Status Verification

The Secretary shall support verification of corporate status, Board composition, officer authority, committee authority, member authority, and adopted instruments where public statements depend on such facts. Communications, fundraising, partnership announcements, filings, websites, reports, and public rosters shall not contradict the authoritative corporate record.

The Secretary may be asked to confirm whether:

a) a person is a current trustee or officer;\
b) a committee exists and has a charter;\
c) a policy has been adopted;\
d) a resolution has been approved;\
e) a delegation remains active;\
f) a public statement refers to an approved position;\
g) a member vote occurred; or\
h) an instrument has been superseded.

Where public claims exceed the record, the Secretary shall support correction. The Corporation shall not let communications outrun governance.

#### 200.11 Secretary and Cross-Entity Record Separateness

The Secretary shall preserve separateness between GCRI US records and records of GCRI Canada, GRF, GRA, protocol authorities, hosts, members, or other related bodies. Cross-entity cooperation may exist, but each entity’s authority must be separately recorded.

The Secretary shall ensure that:

a) GCRI US resolutions are not presented as resolutions of another entity;\
b) another entity’s approval is not treated as GCRI US approval;\
c) shared documents identify the approving entity;\
d) cross-entity memoranda preserve legal separateness;\
e) common personnel or trustees do not collapse records; and\
f) public summaries distinguish institutional authority.

Where a matter requires approval by multiple entities, the Secretary shall track GCRI US approval separately from external approvals. Interoperability does not equal merger.

#### 200.12 Interpretive Rule for Secretary and Records Governance Functions

This Section shall be interpreted to preserve a controlling proposition: the Secretary of GCRI US is the guardian of corporate record integrity, authoritative copies, notice discipline, minutes, resolutions, delegations, version control, and governance validity, and no corporate act may rely on informal memory, silent edits, uncontrolled copies, or unrecorded authority.

Where ambiguity exists, the interpretation that better preserves records-first governance, authoritative-copy control, version integrity, accurate minutes, traceable corrections, protected escalation, continuity of records, and cross-entity separateness shall prevail unless a contrary result is required by law.

### 201. Treasurer and Financial Stewardship Functions (GCRI United States)

#### 201.1 Treasurer as Officer of Financial Oversight and Discipline

The Treasurer shall serve as the principal Board-facing officer for financial oversight, financial discipline, financial reporting integrity, reserve awareness, restricted-fund stewardship, and escalation of material financial risk within GCRI US. The Treasurer shall not be treated as a ceremonial office or as a substitute bookkeeper. The role is a fiduciary-control function that helps the Board understand whether the Corporation’s resources, commitments, controls, funding assumptions, and financial records remain consistent with its nonprofit mission, public-benefit mandate, and long-horizon continuity.

The Treasurer shall support the Board in ensuring that:

a) the Corporation’s financial condition is accurately reported;\
b) approved budgets are followed or properly amended;\
c) reserves, liquidity, and runway are visible;\
d) restricted and unrestricted funds are distinguished;\
e) grants, donations, sponsorships, dues, contracts, and in-kind support are properly recorded;\
f) spending authority and approval thresholds are respected;\
g) financial controls prevent fraud, private benefit, unauthorized commitments, and conflicts;\
h) financial decisions do not compromise mission lock, non-execution discipline, or public-good independence; and\
i) material financial risks are escalated to the Board before they become institutional crises.

The Treasurer’s role shall be performed with independence, accuracy, restraint, and records discipline. Financial optimism shall not substitute for financial evidence. Strategic ambition shall not substitute for cash-flow discipline. Public-good mission shall not excuse weak financial control.

#### 201.2 Relationship to Board, Audit Functions, and Management

The Treasurer shall operate in a defined relationship with the Board, the Audit and Risk Committee or equivalent committee where established, executive management, finance staff, external accountants, auditors, bookkeepers, tax advisers, grant administrators, and other financial-control functions. This relationship shall preserve both operational efficiency and fiduciary oversight.

Management may prepare budgets, process transactions, maintain books, manage accounts payable, coordinate grants, and administer ordinary finance operations within approved authority. The Treasurer shall not replace management in routine finance administration unless specifically assigned. The Treasurer shall, however, help the Board test whether management’s financial reporting is complete, accurate, timely, and decision-useful.

The Treasurer shall work with audit or review functions to ensure that:

a) financial statements are prepared in accordance with applicable standards;\
b) external filings and tax returns are timely and accurate;\
c) internal control weaknesses are identified and remediated;\
d) restricted funds are tracked and used properly;\
e) related-party transactions are disclosed and reviewed;\
f) bank authority and signatory controls remain current; and\
g) financial records are preserved in institutional systems rather than personal accounts or informal spreadsheets.

The Treasurer shall have access to the financial information reasonably necessary to perform the role, subject to confidentiality, privacy, legal, and segregation-of-duties controls.

#### 201.3 Review of Budget, Reserves, Material Funding, and Financial Controls

The Treasurer shall support Board review of the annual budget, budget amendments, reserve policy, material funding arrangements, financial controls, and sustainability posture. The Treasurer shall help ensure that the Board sees the Corporation’s actual financial condition, not only its preferred growth narrative.

Budget review shall consider:

a) whether revenue assumptions are secured, conditional, pledged, prospective, restricted, unrestricted, cash, or in-kind;\
b) whether expenses match mission priorities and approved plans;\
c) whether critical control functions are adequately funded, including legal, accounting, audit, compliance, records, safeguards, security, privacy, and insurance;\
d) whether staffing and contractor costs are realistic;\
e) whether public-good repositories, technical infrastructure, data systems, and publications have sustainable support;\
f) whether restricted funds are used only for permitted purposes;\
g) whether the Corporation has sufficient runway and reserves; and\
h) whether the budget creates donor dependency, execution-boundary risk, or pressure toward private benefit.

Reserve review shall consider liquidity, continuity, wind-down obligations, payroll exposure, critical vendor dependency, insurance deductibles, legal contingencies, and public-good asset preservation. A reserve policy is not merely prudent finance. It is a mission-continuity instrument.

Material funding review shall consider donor conditions, sponsor visibility, naming rights, restricted purposes, reporting obligations, reputational risks, concentration risk, private-benefit concerns, and compatibility with nonprofit status. GCRI US shall not accept money that purchases influence, weakens independence, distorts public claims, or pushes the Corporation toward execution-side activity.

#### 201.4 No Treasurer Authority to Bypass Board Reserved Matters or Segregation of Duties

The Treasurer shall not have authority to bypass Board reserved matters, approve commitments outside delegated thresholds, waive financial controls, approve conflicts, self-authorize payments, or override segregation-of-duties requirements. The Treasurer’s office strengthens financial discipline; it does not concentrate unchecked financial power.

The Treasurer shall not, without proper authority:

a) approve the annual budget or material budget amendment;\
b) approve major contracts, grants, sponsorships, or funding arrangements;\
c) approve related-party transactions;\
d) authorize payments to themselves or related parties;\
e) create bank accounts or change banking controls without required approval;\
f) waive dual-control requirements;\
g) accept restricted funds with conditions not approved by the competent authority;\
h) authorize borrowing, guarantees, or long-term commitments beyond authority;\
i) commit the Corporation to regulated or execution-side financial activity; or\
j) alter financial records to match preferred narratives.

Segregation of duties shall apply to initiation, approval, payment, reconciliation, reporting, and review. Where staffing constraints make full segregation difficult, the Board shall adopt compensating controls, such as dual trustee approval, external bookkeeping review, bank alerts, monthly reconciliations, or committee review.

#### 201.5 Financial Incident Escalation, Reporting, and Remediation Duties

The Treasurer shall have a duty to escalate material financial incidents, irregularities, control failures, suspected fraud, restricted-fund breaches, unauthorized commitments, bank irregularities, payment errors, financial misstatements, donor-condition breaches, or significant liquidity concerns.

Financial incidents may include:

a) unauthorized expenditure or commitment;\
b) payment outside approval thresholds;\
c) missing or unreconciled bank activity;\
d) suspected fraud, theft, diversion, or misuse of assets;\
e) related-party payment without review;\
f) restricted funds used for unauthorized purpose;\
g) inaccurate financial reporting to the Board, donors, members, or public;\
h) payroll, tax, insurance, or filing failure;\
i) failure to maintain adequate records for audit;\
j) donor-imposed condition inconsistent with mission or governance; and\
k) financial pressure to misstate capacity, funding, or institutional readiness.

Escalation may be to the Chair, Audit and Risk Committee, full Board, legal counsel, external accountant, auditor, integrity function, or other appropriate authority. Where the Chair or management is implicated, the Treasurer shall use a protected escalation route.

Remediation shall be tracked. It may include correction of records, repayment, revised controls, Board ratification where lawful, disciplinary action, donor notice, filing correction, insurance notification, audit review, or policy amendment.

#### 201.6 Continuity and Succession of Treasurer Functions

GCRI US shall maintain continuity and succession arrangements for the Treasurer function. Financial control must not depend on one person’s private knowledge, personal banking access, informal spreadsheets, or undocumented relationships with accountants, donors, or vendors.

Continuity arrangements shall include:

a) current list of bank accounts and authorized signatories;\
b) payment approval workflow;\
c) accounting system access map;\
d) bookkeeping and reconciliation procedures;\
e) grant and restricted-fund tracking;\
f) audit, tax, and filing calendar;\
g) budget and reserve policy records;\
h) contract and recurring payment schedule;\
i) insurance and compliance renewal calendar;\
j) emergency payment and payroll continuity plan; and\
k) process for appointing an acting or interim Treasurer.

Where the Treasurer resigns, is removed, is unavailable, or is conflicted, the Board shall ensure that financial access is transitioned, bank authority is updated, records are preserved, and any related risk is reviewed. The departing Treasurer shall cooperate with transition subject to legal, confidentiality, and conflict rules.

#### 201.7 Treasurer’s Role in Restricted Funds, Grants, and Donor Conditions

The Treasurer shall help ensure that restricted funds, grants, donations, sponsorships, and conditional funding are tracked and used according to their lawful and approved terms. Restricted funding shall not be treated as general operating flexibility unless the restriction permits such use.

The Treasurer shall ensure that financial systems can identify:

a) donor or funder;\
b) restricted purpose;\
c) permitted and prohibited uses;\
d) reporting obligations;\
e) spending period;\
f) matching or co-funding requirements;\
g) remaining balance;\
h) staff or overhead treatment;\
i) return or clawback exposure; and\
j) public-description restrictions.

Where donor conditions conflict with mission, independence, safeguards, public-benefit purpose, non-execution discipline, or Board authority, the Treasurer shall escalate before funds are accepted or used. The Corporation shall not accept funds that require it to misstate results, privilege a donor, suppress findings, provide private benefit, or blur public-good boundaries.

#### 201.8 Treasurer’s Role in Anti-Capture, Funding Concentration, and Financial Independence

The Treasurer shall support Board oversight of financial anti-capture controls. A nonprofit can be captured not only through formal governance rights, but through financial dependence, restricted funding, sponsor leverage, platform dependency, in-kind control, or repeated donor rescue.

The Treasurer shall help monitor:

a) percentage of revenue from top donors or sponsors;\
b) dependence on one funder, vendor, executive, member, or related entity;\
c) restricted versus unrestricted funding mix;\
d) donor conditions affecting agenda, publication, staffing, or public claims;\
e) in-kind support that creates operational dependency;\
f) shared services or subsidized infrastructure from conflicted actors;\
g) revenue models that create execution-boundary risk; and\
h) financial stress that may pressure the Corporation toward unsafe commitments.

Where concentration risk is material, the Treasurer shall recommend controls, diversification, reserves, spending limits, independence safeguards, or Board review before further dependence deepens.

#### 201.9 Treasurer’s Role in Public Financial Claims and Institutional Capacity Statements

The Treasurer shall help ensure that public statements about funding, financial capacity, budget, grants, sponsorships, reserves, audited status, institutional scale, or program readiness are accurate and not misleading. Financial overclaim can damage public trust, mislead members and donors, and create legal or reputational exposure.

Public financial claims shall distinguish:

a) cash received from pledged or expected funds;\
b) unrestricted funds from restricted funds;\
c) grant awards from applications;\
d) budgeted activity from funded activity;\
e) in-kind support from cash support;\
f) audited statements from management accounts;\
g) current reserves from target reserves; and\
h) Board-approved commitments from proposed plans.

The Treasurer shall support correction where financial claims exceed the record. A public-good institution must not inflate its financial position to appear more mature, secure, or widely backed than it is.

#### 201.10 Treasurer’s Role in Payments, Banking, and Signature Controls

The Treasurer shall support Board-approved banking, payment, and signature controls. Such controls shall ensure that no individual can initiate, approve, pay, reconcile, and report the same transaction without oversight, unless compensating controls are recorded.

Payment controls shall address:

a) approval thresholds;\
b) dual approval requirements;\
c) documentation required before payment;\
d) vendor onboarding and verification;\
e) employee and contractor expense rules;\
f) related-party payment review;\
g) recurring payments;\
h) emergency payments;\
i) bank-signatory updates;\
j) reconciliation schedule; and\
k) fraud monitoring.

The Treasurer shall not personally hold sole access to bank accounts or payment systems where institutional control requires dual access. Bank credentials, tokens, and financial systems shall be protected under security rules.

#### 201.11 Treasurer’s Role in Audit, Review, Tax, and External Reporting

The Treasurer shall support audit, independent review, tax filing, charitable or nonprofit reporting, government filings, donor reports, and other external financial reporting required for GCRI US. The Treasurer shall help ensure that external reporting is consistent with internal records and Board-approved positions.

The Treasurer shall coordinate with accountants, auditors, tax advisers, management, and the Audit and Risk Committee where applicable to ensure that:

a) financial statements are complete and accurate;\
b) supporting records are available;\
c) restricted funds are properly classified;\
d) related-party transactions are disclosed;\
e) significant estimates are reasonable;\
f) weaknesses or findings are reported to the Board;\
g) tax filings are timely;\
h) donor reports match accounting records; and\
i) corrective actions are tracked.

The Treasurer shall not pressure auditors, accountants, or reviewers to suppress findings or alter conclusions. External assurance is an accountability instrument, not a public-relations exercise.

#### 201.12 Treasurer’s Role in Emergency Financial Controls

Where a financial emergency arises, the Treasurer may support protective measures within the authority granted by the Board or emergency governance rules. Emergency financial action may be necessary to preserve funds, prevent fraud, maintain payroll, satisfy urgent legal obligations, protect records, or prevent operational collapse.

Emergency financial measures may include:

a) freezing or restricting payment authority;\
b) contacting banks or payment providers;\
c) preserving transaction records;\
d) suspending vendor payments pending review;\
e) authorizing emergency payment within approved limits;\
f) securing financial systems;\
g) notifying the Chair, Audit and Risk Committee, or Board; and\
h) initiating investigation or external review.

Emergency authority shall be recorded and reviewed. It shall not be used to bypass Board approval for ordinary commitments, new strategic spending, related-party transactions, or major funding arrangements.

#### 201.13 Interpretive Rule for Treasurer and Financial Stewardship Functions

This Section shall be interpreted to preserve a controlling proposition: the Treasurer of GCRI US is a financial stewardship and oversight officer who supports Board fiduciary control, budget discipline, reserves, restricted-fund integrity, audit readiness, anti-capture monitoring, accurate financial claims, and escalation of financial risk, without holding unilateral authority to bypass Board reserved matters or segregation of duties.

Where ambiguity exists, the interpretation that better preserves financial accuracy, Board oversight, restricted-fund discipline, reserve awareness, payment controls, anti-capture protection, truthful financial reporting, audit integrity, emergency financial protection, and continuity of finance functions shall prevail unless a contrary result is required by law.

### 202. Chief Executive / Executive Director / Senior Management Interface (GCRI United States)

#### 202.1 Executive Leadership as Management Rather Than Fiduciary Apex

The Chief Executive, Executive Director, President, senior executive, or equivalent management leader of GCRI US shall serve as the principal management officer of the Corporation where such role is created by the Board. Executive leadership shall manage operations, implement approved strategy, supervise staff and contractors, prepare budgets and plans, coordinate programs, support institutional development, and report to the Board within the scope of authority expressly delegated.

Executive leadership shall not be the fiduciary apex of GCRI US. The Board remains the primary fiduciary oversight organ. The executive may lead management, but shall not substitute for the Board, approve reserved matters, alter constitutional instruments, waive safeguards, bypass financial controls, change membership rights, grant unrecorded authority, or redefine the Corporation’s public-good mission by operational practice.

The executive function shall therefore be understood as:

a) operational leadership under Board oversight;\
b) implementation authority within approved delegations;\
c) management responsibility for staff, contractors, programs, and ordinary administration;\
d) reporting responsibility to the Board;\
e) escalation responsibility where risk, drift, or misconduct arises; and\
f) stewardship responsibility for the Corporation’s mission within management’s scope.

The executive may be visionary, entrepreneurial, and externally visible. Those qualities do not create unlimited corporate authority. Executive leadership must remain institutionally bounded.

#### 202.2 Appointment, Review, and Removal Authority

The Board shall approve the appointment, review, compensation, suspension, removal, succession, and authority framework of the Chief Executive, Executive Director, President, or equivalent senior executive where such role exists. This responsibility may be supported by a Governance and Nominations Committee, Remuneration or Human Resources Committee, Audit and Risk Committee, external counsel, or independent adviser, but the Board shall retain ultimate responsibility where the role is Board-appointed.

The appointment record shall identify:

a) official title;\
b) reporting line;\
c) scope of management authority;\
d) reserved matters requiring Board approval;\
e) financial and signature authority;\
f) public-speaking authority;\
g) authority to hire, contract, and supervise personnel;\
h) authority to prepare but not finally approve budgets;\
i) duty to report risks and material developments;\
j) compensation and expense terms;\
k) conflict and confidentiality obligations;\
l) performance objectives; and\
m) removal, resignation, incapacity, and interim replacement procedures.

Executive review shall be periodic and evidence-based. It shall assess performance against mission, governance, finance, risk, safeguards, records, staff management, public claims, donor discipline, program delivery, security, and Board reporting. The Board shall not evaluate the executive only by growth, visibility, fundraising, or activity volume. In the GCRI US model, good executive performance includes boundary discipline, truthfulness, control maturity, and institutionalization.

Removal or suspension may occur where performance, misconduct, loss of confidence, incapacity, conflict, breach, mission drift, financial irregularity, retaliation, security failure, public overclaim, or governance breakdown requires action. Removal shall follow applicable law, contract, employment rules, and Board process, while preserving the Board’s ability to protect the Corporation.

#### 202.3 Scope of Management Authority and Operational Responsibility

Executive management shall have authority to manage ordinary operations within the budget, policies, delegations, signature matrix, employment terms, and Board-approved strategy. Operational responsibility includes turning Board-approved direction into disciplined work without requiring Board intervention in every ordinary matter.

Management authority may include:

a) day-to-day administration;\
b) staff and contractor supervision within approved structure;\
c) preparation of budgets, plans, reports, and Board materials;\
d) implementation of approved programs;\
e) coordination of member services and public-benefit activities;\
f) preparation of funding proposals within approved boundaries;\
g) ordinary vendor management within thresholds;\
h) maintenance of operational policies;\
i) support for records, compliance, finance, security, and safeguards functions; and\
j) external engagement within approved public-description and authority limits.

Management shall not use operational responsibility to create corporate commitments outside authority. A management act becomes excessive where it commits funds beyond threshold, changes constitutional position, binds the Corporation to material obligations, affects reserved matters, alters public-good assets, creates public overclaim, weakens security or safeguards, or approaches regulated execution.

Management must be empowered enough to operate and bounded enough to protect the institution.

#### 202.4 Duty of Management to Respect Board Reserved Matters and Reporting Controls

Executive management shall respect Board reserved matters and reporting controls. Management shall not fragment a major decision into smaller steps to avoid thresholds, use preliminary documents to create binding expectations, negotiate commitments before approval, present the Board with irreversible facts, or rely on silence as consent.

Management shall escalate to the Board or relevant committee before action where a matter involves:

a) budget approval or material budget deviation;\
b) major funding, restricted grants, sponsorships, or donor conditions;\
c) major contracts, leases, technology commitments, or vendor dependencies;\
d) executive compensation, senior hiring, or material personnel risk;\
e) related-party transactions;\
f) legal, tax, sanctions, regulatory, or litigation risk;\
g) privacy, security, controlled-room, or incident response risk;\
h) safeguards, whistleblowing, retaliation, or protected-participation matters;\
i) public-good asset transfer, licensing, repository control, or publication risk;\
j) cross-entity commitments with GCRI Canada, GRF, GRA, protocol authorities, hosts, or members;\
k) public statements implying endorsement, government adoption, certification, routeability, or execution capacity; or\
l) any matter affecting the non-execution boundary.

Reporting controls shall require management to provide the Board with timely, accurate, complete, and decision-useful information. Management shall not filter reports to avoid scrutiny.

#### 202.5 No Management Authority by Habit Beyond Express Delegation

Management authority shall not expand by habit, repeated practice, founder status, public visibility, staff reliance, donor expectation, urgency, external confidence, or absence of Board objection. If management has repeatedly performed an act outside written authority, the repetition shall not cure the defect. It shall trigger review and correction.

The Corporation shall identify and document management authority through:

a) job descriptions;\
b) employment or service agreements;\
c) Board resolutions;\
d) delegation matrix;\
e) signature authority schedule;\
f) financial thresholds;\
g) public communications policy;\
h) procurement rules;\
i) controlled-access rules; and\
j) reporting requirements.

Where management authority is unclear, management shall seek clarification before acting. Where management has acted beyond authority, the Board shall determine whether to ratify, revise, restrict, discipline, or remediate.

A mature institution does not depend on executives “knowing what they can do.” It records what they can do.

#### 202.6 Reporting, Escalation, and Performance Accountability to the Board

Executive management shall report to the Board at a frequency and level of detail appropriate to the Corporation’s stage, risk profile, financial condition, and institutional obligations. Reporting shall support fiduciary oversight and shall not be limited to positive updates.

Management reports shall include, as appropriate:

a) operational progress;\
b) budget-to-actual performance;\
c) cash flow and runway;\
d) funding pipeline and restricted-fund status;\
e) key risks and incidents;\
f) staffing and contractor matters;\
g) legal, tax, filing, and compliance updates;\
h) security, privacy, and restricted-handling matters;\
i) safeguards, grievance, and protected-reporting matters;\
j) membership, Registry, and anti-capture indicators;\
k) public-good asset and repository status;\
l) public communications and claims risks; and\
m) decisions requiring Board or committee approval.

Management shall escalate material risks promptly and not wait for scheduled meetings. A serious issue becomes worse when management attempts to manage Board perception rather than Board responsibility.

Performance accountability shall consider both results and means. Achieving growth through weak controls, public overclaim, donor dependency, staff burnout, informal commitments, or mission drift shall not be treated as success.

#### 202.7 Executive Relationship to Staff, Contractors, and Secretariat Functions

Executive leadership may supervise staff, contractors, consultants, vendors, program teams, and Secretariat functions within approved authority. Such supervision shall be consistent with employment law, contract terms, budget, personnel policies, safeguarding duties, non-retaliation rules, and Board oversight.

Management shall ensure that staff and contractors understand:

a) who may bind the Corporation;\
b) which matters require Board or officer approval;\
c) how to handle confidential and restricted information;\
d) how to escalate security, privacy, safeguards, financial, or legal concerns;\
e) how to avoid public overclaim;\
f) how to preserve records;\
g) how to respect membership and Registry boundaries; and\
h) how to avoid execution-side, procurement, or market-facing confusion.

The executive shall not instruct staff or contractors to bypass controls, use personal systems for institutional records, make unauthorized public statements, pressure protected reporters, conceal risks, or proceed with unapproved commitments.

#### 202.8 Executive Role in Public Communications and External Engagement

Executive leadership may represent GCRI US externally only within authority granted by the Board, communications policy, delegation matrix, employment terms, or specific approval. External visibility shall be disciplined because public statements can create apparent authority, donor expectations, member reliance, government misunderstanding, market confusion, or reputational risk.

The executive may be authorized to:

a) describe approved mission and programs;\
b) engage funders and partners within approved boundaries;\
c) represent management in public events;\
d) issue operational updates;\
e) coordinate with members, hosts, and stakeholders; and\
f) support public-good advocacy consistent with approved positions.

The executive may not, without proper approval:

i) announce Board decisions not made;\
ii) imply government, regulator, Indigenous, community, or member endorsement beyond the record;\
iii) claim certification, routeability, recognition, or execution capacity;\
iv) accept funding conditions orally;\
v) commit the Corporation to partnerships or contracts beyond authority;\
vi) speak for GCRI Canada, GRF, GRA, protocol authorities, or other entities; or\
vii) represent personal views as institutional positions.

Public communications shall remain accurate, bounded, and correctable.

#### 202.9 Executive Role in Funding, Sponsorship, and Donor Engagement

Executive leadership may lead or support fundraising, grant development, sponsorship discussions, donor engagement, and revenue development within Board-approved boundaries. Funding activity shall be governed by mission compatibility, donor-independence rules, restricted-fund discipline, anti-capture safeguards, financial controls, and public-claim accuracy.

Management shall ensure that funding discussions do not promise:

a) governance influence;\
b) Board seats;\
c) standards influence;\
d) publication control;\
e) procurement preference;\
f) preferential access to public-good assets;\
g) confidential information;\
h) certification or recognition;\
i) execution-side routeability; or\
j) public endorsement beyond approved language.

Material funding arrangements, unusual donor conditions, naming rights, restricted grants, sponsorships, in-kind dependency, related-party support, and concentration risks shall be escalated before acceptance. The executive may cultivate support, but the Corporation shall not be sold.

#### 202.10 Executive Role in Cross-Entity Interfaces

Executive leadership may coordinate with GCRI Canada, GRF, GRA, protocol authorities, host institutions, national entities, regional bodies, members, and other related or aligned entities where approved. Such coordination shall preserve legal separateness, authority mapping, records discipline, public-description accuracy, and non-execution boundaries.

The executive shall ensure that cross-entity engagement does not:

a) bind GCRI US without authority;\
b) bind another entity without that entity’s authority;\
c) merge records or accounts;\
d) confuse staff roles;\
e) create shared liabilities without approval;\
f) transfer public-good assets without Board authorization;\
g) create execution-side exposure;\
h) make public claims of unified authority beyond the record; or\
i) use one entity’s approval as substitute for another entity’s approval.

Where cross-entity arrangements involve shared services, shared branding, common officers, common technology, joint funding, or public announcements, the executive shall route the matter for legal and Board review as required.

#### 202.11 Executive Duty to Institutionalize, Not Personalize, the Corporation

Executive leadership shall build institutional capacity rather than personal dependency. The executive shall not hold essential authority, records, relationships, passwords, donor communications, technical systems, Board information, or public narrative in a way that makes the Corporation dependent on one individual.

Institutionalization requires:

a) documented processes;\
b) staff and role clarity;\
c) Board reporting;\
d) records in institutional repositories;\
e) succession planning;\
f) bank and system access controls;\
g) delegation matrices;\
h) contract files;\
i) grant files;\
j) public-claims controls; and\
k) continuity plans.

The executive’s success shall be measured partly by whether the Corporation can continue lawfully and coherently without the executive. Personal indispensability is a governance risk, not an achievement.

#### 202.12 Succession Planning and Interim Executive Arrangements

The Board shall maintain succession planning and interim executive arrangements for the chief executive or equivalent senior management role. The Corporation must remain capable of operating if the executive resigns, is removed, becomes incapacitated, is conflicted, or is unavailable.

Succession planning shall address:

a) acting executive authority;\
b) emergency management coverage;\
c) delegation of essential functions;\
d) bank and payment continuity;\
e) staff supervision;\
f) contract and funding continuity;\
g) records and systems access;\
h) public communications;\
i) Board reporting; and\
j) search or appointment process for permanent replacement.

An interim executive shall have written authority, defined scope, time limits, reporting requirements, and restrictions. Interim status shall not become indefinite unreviewed authority.

#### 202.13 Executive Misconduct, Overreach, and Corrective Board Action

Where executive misconduct, overreach, suppression, retaliation, conflict concealment, financial irregularity, public overclaim, boundary drift, or failure to report material risk is alleged or detected, the Board shall act through an appropriate process. The Board shall not permit executive indispensability, founder status, public visibility, fundraising success, or technical knowledge to prevent review.

Corrective actions may include:

a) instruction or warning;\
b) authority restriction;\
c) spending or signature hold;\
d) access restriction;\
e) independent review;\
f) investigation;\
g) executive session without management;\
h) suspension;\
i) termination;\
j) public correction;\
k) records preservation; and\
l) control redesign.

Where management is implicated in a matter, reporting and investigation shall not be routed solely through management. Board independence is essential.

#### 202.14 Interpretive Rule for Chief Executive / Executive Director / Senior Management Interface

This Section shall be interpreted to preserve a controlling proposition: executive leadership of GCRI US manages the Corporation within delegated authority under Board oversight, and may not convert operational leadership into fiduciary apex authority, reserved-matter approval, unbounded public representation, donor-controlled influence, personal institutional ownership, or execution-side activity.

Where ambiguity exists, the interpretation that better preserves Board fiduciary primacy, recorded executive delegation, reserved-matter discipline, truthful reporting, financial and safeguards escalation, public-claim control, cross-entity separateness, institutionalization, succession, and corrective Board authority shall prevail unless a contrary result is required by law.

### 203. Board Committees (GCRI United States)

#### 203.1 Authority to Constitute Committees

The Board of Trustees may constitute standing committees, special committees, advisory committees, task groups, investigation committees, independent review bodies, or time-bound Board working groups where such bodies are necessary to support fiduciary oversight, deepen subject-matter review, manage risk, preserve independence, or improve Board effectiveness. Committee authority shall arise only through the Articles, these Bylaws, Board resolution, committee charter, or another recorded governance instrument.

A committee shall not exist merely because trustees, officers, advisers, members, donors, staff, or external partners regularly meet on a topic. A recurring meeting does not become a Board committee unless the Board creates it. A committee title shall not create authority unless the committee’s mandate, membership, reporting line, decision rights, and limits are recorded.

Each committee-creation record shall identify:

a) committee name and purpose;\
b) whether it is standing, special, advisory, investigative, or time-bound;\
c) appointing authority;\
d) membership and eligibility requirements;\
e) chair and reporting line;\
f) delegated authority, if any;\
g) matters reserved to the full Board;\
h) quorum and meeting rules;\
i) confidentiality and publication class;\
j) records requirements;\
k) term, review date, or sunset; and\
l) escalation duties.

Committees exist to strengthen Board judgment. They shall not fragment fiduciary responsibility or allow material issues to disappear inside smaller bodies.

#### 203.2 Audit and Risk Committee

The Board may establish an Audit and Risk Committee to support oversight of financial reporting, internal controls, audit or review processes, reserves, restricted funds, risk management, compliance, incident oversight, and institutional control maturity. The committee shall be designed to provide disciplined review of the Corporation’s financial and risk condition before matters reach the full Board.

The Audit and Risk Committee may oversee or review:

a) annual financial statements, management accounts, audit or independent review outputs, and tax filings;\
b) budget-to-actual performance, reserves, cash flow, and liquidity risk;\
c) restricted funds, grant compliance, donor conditions, and in-kind valuation;\
d) internal financial controls, bank controls, payment approvals, procurement controls, and segregation of duties;\
e) fraud risk, financial irregularities, related-party transactions, and material control failures;\
f) institutional risk taxonomy, key risk indicators, risk appetite, and remediation tracking;\
g) cybersecurity, privacy, technology, operational resilience, and continuity risks where not assigned to another committee;\
h) insurance, legal exposure, sanctions, and financial-crime risk where relevant; and\
i) corrective action plans arising from audits, incidents, complaints, or internal reviews.

The Audit and Risk Committee shall not be used to isolate financial concerns from the full Board. Material findings, unresolved risks, control failures, financial stress, or management resistance shall be escalated promptly. The committee may recommend; it may decide only where authority is expressly delegated.

#### 203.3 Governance and Nominations Committee

The Board may establish a Governance and Nominations Committee to support Board composition, trustee recruitment, nominations, officer succession, committee design, Board evaluation, governance policy review, bylaw maintenance, delegation discipline, conflict controls, and institutional design.

The Governance and Nominations Committee may be responsible for:

a) identifying Board skill, independence, diversity, and succession needs;\
b) developing trustee candidate profiles;\
c) conducting nomination, fit-and-proper, conflict, and suitability review;\
d) recommending trustee, officer, committee, and leadership appointments where assigned;\
e) overseeing Board evaluation and trustee onboarding;\
f) reviewing committee charters, Board policies, reserved-matter maps, and delegation matrices;\
g) monitoring governance maturity as the Corporation scales;\
h) maintaining constitutional coherence across bylaws, schedules, annexes, and operating instruments; and\
i) recommending corrective action where informal authority, shadow governance, or personality dependence emerges.

The committee shall not become a gatekeeping body used to entrench insiders, exclude dissenters, preserve founder control, or favour donor-aligned candidates. Its duty is to strengthen fiduciary legitimacy and institutional resilience.

#### 203.4 Remuneration, Human Resources, and Executive Compensation Committee Where Applicable

The Board may establish a Remuneration, Human Resources, or Executive Compensation Committee where the Corporation has paid executives, employees, contractors, senior consultants, fellows, officers receiving compensation, or other compensation arrangements requiring independent oversight.

This committee may oversee or recommend:

a) executive compensation;\
b) officer compensation where applicable;\
c) senior management performance and compensation review;\
d) compensation philosophy and pay equity;\
e) contractor and consultant compensation frameworks;\
f) reimbursement, honoraria, stipend, and volunteer payment policies;\
g) benefits and employment policies;\
h) conflict review for compensation involving insiders or related parties;\
i) succession planning and interim executive arrangements; and\
j) human-resources risks affecting institutional integrity.

Compensation decisions shall be reasonable, documented, comparable where appropriate, consistent with nonprofit requirements, and free from private inurement or improper private benefit. No person shall approve their own compensation. Compensation shall not be used to reward loyalty, silence concerns, purchase influence, or create disguised private distribution.

#### 203.5 Safeguards, Ethics, Integrity, and Protected Participation Committee Where Applicable

The Board may establish a Safeguards, Ethics, Integrity, and Protected Participation Committee to oversee the Corporation’s systems for ethical conduct, conflicts, whistleblowing, non-retaliation, protected participation, grievance routing, dignity, representation integrity, public-claims discipline, and safe participation.

This committee may oversee:

a) protected reporting and whistleblower systems;\
b) retaliation risk and interim protective measures;\
c) safeguards incidents and grievance trends;\
d) trustee, officer, executive, member, delegate, and representative conduct matters;\
e) conflict-of-interest and related-party escalation;\
f) Indigenous, community, vulnerable-person, and public-authority representation safeguards;\
g) claims-governance incidents involving membership, endorsement, certification, or public authority;\
h) integrity investigations where management is conflicted; and\
i) policy updates arising from misconduct, near misses, or systemic risk.

The committee shall operate with confidentiality, independence, fairness, and protected escalation. It shall not be used to suppress dissent, protect leadership from accountability, or transform protected reporting into a reputational problem. Its purpose is to keep the Corporation safe, truthful, and worthy of trust.

#### 203.6 Security, Technology, Privacy, and Infrastructure Oversight Committee Where Applicable

The Board may establish a Security, Technology, Privacy, and Infrastructure Oversight Committee to supervise high-consequence technology, cybersecurity, privacy, data governance, repository stewardship, secure release, controlled-room systems, AI tooling, access governance, and public-good technical infrastructure.

This committee may oversee:

a) cybersecurity posture and incident readiness;\
b) privacy and rights-bearing data controls;\
c) repository access, release governance, and public-good code stewardship;\
d) secure software development, provenance, dependency, and supply-chain controls;\
e) AI-tool use, automated processing, and sensitive-data restrictions;\
f) controlled-room and clean-room technical environments;\
g) identity and access management;\
h) vendor and cloud dependency risk;\
i) data localization, compute-to-data, and cross-border data issues; and\
j) technical resilience, backup, disaster recovery, and continuity.

Because GCRI US operates in an evidence, standards, risk-intelligence, and public-good infrastructure environment, technology governance is not an IT support function only. It is a constitutional control surface. The committee shall ensure that technical capability does not outrun security, privacy, records, safeguards, or non-execution boundaries.

#### 203.7 Special Committees and Time-Bound Board Task Groups

The Board may constitute special committees or time-bound task groups to address specific matters requiring focused attention, independence, urgency, confidentiality, or technical review. Such bodies may be used for investigations, executive search, major contract review, strategic review, wind-down planning, public-claims correction, cyber incident response, related-party review, or controlled-room matters.

A special committee shall have a written mandate specifying:

a) matter assigned;\
b) authority to investigate, recommend, negotiate, or decide;\
c) membership and independence requirements;\
d) access to records, counsel, auditors, advisers, or experts;\
e) confidentiality and controlled-room requirements;\
f) reporting timeline;\
g) budget or authority to retain advisers;\
h) decision limits; and\
i) sunset or closure conditions.

A special committee shall not become a permanent informal governance center. When the mandate is complete, the committee shall report, close, preserve records, and return authority to the Board.

#### 203.8 Committee Charters, Membership, Quorum, and Reporting Duties

Every standing committee shall have a charter approved by the Board. Every special committee shall have a mandate approved by the Board. The charter or mandate shall define the committee’s purpose, scope, membership, chair, quorum, meeting cadence, decision rights, reporting obligations, confidentiality, recordkeeping, conflict rules, and review cycle.

Committee membership shall be designed for competence and independence. A committee may include trustees, officers, management, advisers, external experts, or observers where permitted, but voting authority and access shall be carefully controlled. Non-trustee participants may advise, support, or provide expertise, but shall not exercise Board authority unless lawfully permitted and expressly granted.

Committees shall report to the Board through written reports, minutes, recommendations, risk summaries, decision memoranda, or oral reports recorded in Board minutes. Material committee findings shall not remain trapped at committee level. The Board must see what it needs to discharge fiduciary duties.

#### 203.9 No Committee May Exercise Board Reserved Matters Except as Expressly Delegated

No committee may exercise Board reserved matters unless expressly authorized by the Articles, these Bylaws, Board resolution, committee charter, or applicable law. A committee may review, prepare, recommend, monitor, investigate, or negotiate a reserved matter, but the final decision shall remain with the Board unless delegation is lawful and recorded.

Committees shall not approve, unless expressly delegated:

a) annual budgets or reserve policies;\
b) constitutional amendments;\
c) dissolution, merger, or major asset transfer;\
d) appointment or removal of the chief executive where reserved to the Board;\
e) major related-party transactions;\
f) major contracts or funding arrangements above threshold;\
g) high-sensitivity legal, security, safeguards, or public-claim matters;\
h) entry into boundary-changing arrangements; or\
i) any matter expressly reserved to the full Board.

Where a committee recommendation is presented to the Board, the Board shall retain responsibility for its own decision. Committee approval cannot replace Board deliberation where Board approval is required.

#### 203.10 Committee Recordkeeping, Publication Class, and Auditability

Committees shall maintain records sufficient to evidence their work, recommendations, decisions where authorized, conflicts, recusals, materials reviewed, attendance, quorum, and escalation. Committee records shall be classified according to sensitivity and preserved in the Corporation’s record system.

Committee records may include:

a) charter or mandate;\
b) membership and chair appointment;\
c) meeting notices and agendas;\
d) attendance and quorum;\
e) minutes or notes;\
f) materials reviewed;\
g) conflicts and recusals;\
h) recommendations and reports;\
i) decisions made under delegated authority;\
j) matters escalated to the Board; and\
k) closure or sunset records.

Publication class shall be carefully assigned. Audit and risk records, executive compensation records, safeguards records, security records, legal records, and investigation records may require restricted or controlled handling. Public summaries may be issued only where approved and safe.

#### 203.11 Committee Independence, Information Rights, and Use of Advisers

Committees charged with audit, risk, governance, compensation, safeguards, security, related-party review, investigation, or high-integrity functions shall have sufficient independence and information rights to perform their duties. They shall not depend exclusively on management-filtered information where management is implicated or where independent review is required.

A committee may be authorized to:

a) request documents and records;\
b) meet without management;\
c) obtain reports from officers or control functions;\
d) retain external counsel, auditors, accountants, security specialists, or other experts;\
e) interview staff, trustees, officers, members, or relevant participants;\
f) preserve records; and\
g) escalate directly to the full Board.

Use of advisers shall be recorded and conflict-screened. Advisers shall not be allowed to become shadow decision-makers. Their role is to support informed fiduciary judgment.

#### 203.12 Committee Coordination and Prevention of Oversight Gaps

The Board shall ensure that committee mandates are coordinated and that no material risk falls between committees. Complex matters may involve finance, legal, security, safeguards, membership, technology, and public claims at once. GCRI US shall designate a lead committee or joint review process where matters overlap.

Committee coordination shall prevent:

a) duplicate review with inconsistent conclusions;\
b) gaps where each committee assumes another is responsible;\
c) conflicting instructions to management;\
d) fragmentation of incident response;\
e) inconsistent public statements;\
f) failure to connect financial, security, and safeguards implications; and\
g) unresolved escalation of serious matters.

The Board shall periodically review committee architecture to ensure it remains fit for the Corporation’s stage and risk profile.

#### 203.13 Committee Evaluation, Renewal, and Sunset

Committees shall be reviewed periodically to determine whether their mandates remain necessary, effective, properly scoped, and adequately resourced. Standing committees shall be renewed or revised through charter review. Special committees shall sunset when their mandate is complete unless the Board extends them through recorded action.

Committee evaluation may consider:

a) quality and timeliness of reports;\
b) attendance and participation;\
c) independence and conflict management;\
d) usefulness to Board decision-making;\
e) recordkeeping quality;\
f) whether the committee has exceeded or underperformed its mandate;\
g) whether its mandate overlaps improperly with another body; and\
h) whether membership or chairing should rotate.

Committees shall not become permanent power centers through inertia. They are instruments of Board governance and must remain accountable to the Board.

#### 203.14 Interpretive Rule for Board Committees

This Section shall be interpreted to preserve a controlling proposition: Board committees of GCRI US exist to strengthen fiduciary oversight, subject-matter review, independence, risk control, and decision readiness, but they remain charter-bound, record-bound, conflict-managed, and subordinate to the Board’s reserved authority unless lawful delegation expressly provides otherwise.

Where ambiguity exists, the interpretation that better preserves clear committee creation, charter discipline, reserved-matter control, committee independence where needed, accurate reporting, controlled records, coordinated oversight, and periodic review shall prevail unless a contrary result is required by law.

### 204. Governance Spine Offices and High-Integrity Functions (GCRI United States)

#### 204.1 Governance Spine Functions as Distinct From Program Delivery

GCRI US shall maintain governance spine functions as high-integrity control functions distinct from program delivery, public communications, technical production, membership growth, fundraising, partnership development, and executive management. These functions exist to protect the Corporation’s legality, records, safeguards, security, financial integrity, mission lock, public-benefit character, non-execution boundary, and institutional truth.

Governance spine functions may include:

a) records and corporate secretary functions;\
b) compliance and legal coordination;\
c) conflict-of-interest and ethics review;\
d) safeguards, grievance, protected participation, and whistleblower routing;\
e) security, privacy, controlled-room, and access governance;\
f) financial controls, restricted-fund tracking, audit readiness, and anti-fraud oversight;\
g) membership, representation, Registry, and public-claims controls;\
h) risk, incident, and corrective-action tracking; and\
i) publication, repository, public-good asset, and authoritative-copy discipline.

These functions shall not be subordinated to program velocity. A program may be urgent, visible, donor-supported, or strategically important, but it shall not override the control functions that determine whether the program is lawful, safe, financially disciplined, properly authorized, and accurately described.

#### 204.2 Records, Register, Compliance, Safeguards, Security, and Related High-Integrity Offices

The Board may create or recognize high-integrity offices, officer-equivalent functions, staff roles, committee-supported functions, or outsourced professional supports necessary to maintain the Corporation’s governance spine. Such roles shall be defined by written mandate, reporting line, authority limits, confidentiality class, escalation rights, and protection from improper interference.

High-integrity functions may include:

a) Records and Register Office, responsible for corporate books, authoritative instruments, Board and committee records, membership records, Registry linkage, delegations, minutes, resolutions, and supersession discipline;

b) Compliance and Legal Coordination Function, responsible for supporting nonprofit compliance, filings, policy adherence, contract review, legal-risk routing, sanctions awareness, tax-exempt constraints, and perimeter escalation;

c) Safeguards and Protected Participation Function, responsible for grievance routing, whistleblower protection, non-retaliation, dignity, community-sensitive participation, Indigenous safeguards, protected reporting, and safe participation design;

d) Security and Handling Function, responsible for access control, controlled rooms, clean rooms, restricted materials, privacy, cybersecurity coordination, incident escalation, and secure collaboration discipline;

e) Ethics and Conflict Function, responsible for conflict disclosures, recusals, related-party review, prohibited overlaps, donor influence, member influence, and anti-capture controls;

f) Financial Control and Audit Readiness Function, responsible for budget control support, restricted-fund discipline, payment controls, financial documentation, audit coordination, and fraud-risk escalation; and

g) Public Claims and Communications Integrity Function, responsible for ensuring that external statements, rosters, marks, publications, funding descriptions, partnership claims, and institutional narratives match the authoritative record.

The Board may combine functions in early-stage operations where resources are limited, but functional combination shall not erase accountability. Where one person holds multiple high-integrity duties, the Board shall apply compensating controls, independent review, and conflict management.

#### 204.3 Reporting Lines, Independence Requirements, and Escalation Rights

Governance spine functions shall have reporting lines sufficient to preserve independence, institutional integrity, and access to the Board. They may report operationally to executive management for day-to-day coordination, but they shall have protected escalation rights to the Board, Chair, Lead Independent Trustee, Audit and Risk Committee, Governance Committee, Safeguards or Integrity Committee, or other proper body where the matter requires independence from management.

Reporting-line design shall ensure that:

a) management cannot suppress material finance, records, safeguards, security, legal, compliance, or integrity concerns;\
b) a conflicted executive cannot control the reporting of a matter involving that executive;\
c) a donor, sponsor, vendor, member, public authority, or partner cannot prevent escalation of concerns;\
d) records officers can correct or flag false governance records;\
e) safeguards officers can protect reporting persons;\
f) security officers can restrict access where risk requires; and\
g) financial-control functions can report irregularities without retaliation.

Independence does not mean isolation from management. It means that control functions can cooperate operationally while retaining authority to escalate when institutional integrity requires it.

#### 204.4 Protection From Operational Pressure, Sponsor Influence, or Executive Suppression

Governance spine functions shall be protected from operational pressure, sponsor influence, donor pressure, executive suppression, founder pressure, member pressure, public-relations pressure, and technical-team pressure. The Corporation shall not permit control functions to be treated as obstacles to growth, fundraising, public visibility, or program delivery.

Improper pressure may include:

a) asking records personnel to backdate, omit, soften, or alter minutes;\
b) asking finance personnel to treat conditional funds as secured;\
c) asking communications personnel to imply endorsement or government adoption beyond the record;\
d) asking safeguards personnel to delay or bury complaints;\
e) asking security personnel to grant access before authorization;\
f) asking compliance personnel to approve execution-adjacent arrangements without review;\
g) asking Registry personnel to activate roles without fit-and-proper clearance;\
h) asking staff to use personal accounts or uncontrolled tools for sensitive records; or\
i) asking any control function to avoid escalation because the issue is reputationally inconvenient.

Such pressure shall itself be treated as a governance concern. Where repeated or serious, it may trigger Board review, executive discipline, access restriction, funding review, or external professional support.

#### 204.5 Duty to Escalate Constitutional, Perimeter, or Integrity Breaches

Governance spine functions shall have an affirmative duty to escalate constitutional, perimeter, financial, safeguards, security, records, membership, Registry, or public-claims breaches. Silence or passive observation shall not be sufficient where a function becomes aware of a material issue within its domain.

Escalation shall be required where there is credible concern of:

a) unauthorized Board, officer, executive, or member action;\
b) reserved-matter bypass;\
c) misleading corporate, funding, partnership, or public-authority claim;\
d) regulated execution drift or non-execution boundary breach;\
e) donor, sponsor, vendor, member, state, founder, or executive capture;\
f) misuse of restricted funds or unauthorized financial commitment;\
g) security, privacy, controlled-room, or data-handling breach;\
h) retaliation, safeguards failure, or suppression of protected reporting;\
i) conflict concealment, prohibited overlap, or related-party abuse;\
j) manipulation of records, minutes, Registry entries, or public rosters; or\
k) threat to public-good assets, repositories, publications, or authoritative instruments.

Escalation shall be proportionate and routed to the proper authority. Where ordinary reporting lines are implicated, alternate protected escalation shall be used.

#### 204.6 Board Access and Protected Reporting Routes for High-Integrity Functions

High-integrity functions shall have defined Board-access and protected-reporting routes. The Board shall identify when such functions may report directly to the Board or a committee, when they must report, and what protections apply.

Direct Board or committee reporting may be required for:

a) material financial irregularities;\
b) audit findings or control failures;\
c) executive misconduct or retaliation;\
d) serious safeguards or whistleblower matters;\
e) cybersecurity or privacy incidents;\
f) legal demands or regulatory concerns;\
g) serious public-claims overstatement;\
h) controlled-room breach;\
i) conflict or related-party matters involving trustees, officers, executives, or major funders; and\
j) any matter that management cannot fairly or safely handle.

The Board shall not penalize control functions for good-faith escalation. Retaliation against a governance spine actor for raising a material concern shall be treated as a serious governance breach.

#### 204.7 Minimum Mandate Contents for Governance Spine Functions

Each governance spine function shall have a written mandate or role description sufficient to prevent confusion, underreach, and overreach. The mandate shall identify the function’s purpose, authority, reporting line, confidentiality obligations, escalation rights, interaction with management, records responsibilities, and limits.

A mandate shall state, as applicable:

a) role title and function;\
b) scope of responsibility;\
c) matters the function may decide, recommend, hold, or escalate;\
d) access to records and systems;\
e) independence and reporting protections;\
f) conflict and confidentiality duties;\
g) relationship to Board committees;\
h) interaction with executive management;\
i) emergency authority, if any;\
j) documentation and retention obligations; and\
k) review, renewal, and removal rules.

No high-integrity function shall operate entirely by informal understanding. The more sensitive the function, the more precise the mandate must be.

#### 204.8 Governance Spine Role in the Nexus Public-Good Model

In the Nexus public-good model, governance spine functions are essential because GCRI US may operate across research, standards, risk intelligence, technical infrastructure, evidence systems, public-sector engagement, membership networks, cross-border collaboration, open-source assets, and finance-adjacent policy environments. These environments create high public-trust value and high misinterpretation risk.

The governance spine shall therefore protect against:

a) treating evidence or standards work as execution-side validation;\
b) treating member participation as endorsement;\
c) treating public authority engagement as state adoption;\
d) treating technical capability as governance approval;\
e) treating donor support as agenda authority;\
f) treating public-good infrastructure as private asset;\
g) treating cross-entity cooperation as legal merger;\
h) treating AI, data, or repository access as open-ended entitlement; and\
i) treating rapid global expansion as exemption from records, safeguards, and compliance.

The governance spine is the system that makes scale safe. Without it, the Corporation’s ambition would exceed its institutional reliability.

#### 204.9 Interaction With Board Committees and Management

Governance spine functions shall interact with both Board committees and management according to defined channels. Management may coordinate operational implementation, but Board committees shall receive independent reporting where their oversight remit is affected.

For example:

a) financial-control findings may route to the Treasurer and Audit and Risk Committee;\
b) conflict and related-party matters may route to the Governance Committee or Ethics Committee;\
c) whistleblower and safeguards concerns may route to the Safeguards or Integrity Committee;\
d) cybersecurity incidents may route to the Security or Audit and Risk Committee;\
e) records defects may route to the Secretary and Governance Committee; and\
f) public-claims issues may route to communications leadership, the Secretary, and the Board where material.

Where multiple committees are implicated, a lead committee shall be designated. Governance spine functions shall not be forced to repeat concerns across fragmented channels without clear ownership.

#### 204.10 Resources, Competence, and Professional Support

The Board shall ensure that governance spine functions have resources and competence proportionate to the Corporation’s risk profile. A public-good institution handling sensitive records, cross-border participation, controlled access, public claims, and financial stewardship cannot operate safely with under-resourced control functions.

Resources may include:

a) qualified staff or consultants;\
b) external counsel;\
c) accountants or auditors;\
d) cybersecurity support;\
e) privacy and data-protection advice;\
f) records-management systems;\
g) secure collaboration infrastructure;\
h) whistleblower or grievance channels;\
i) training and templates; and\
j) Board committee support.

Under-resourcing of control functions shall be treated as a governance risk. The Board shall not approve growth plans that materially expand risk without corresponding control capacity.

#### 204.11 Records and Auditability of Governance Spine Actions

Governance spine actions shall be recorded where they affect authority, access, status, risk, compliance, safeguards, security, finance, public claims, or institutional decision-making. Records shall be classified appropriately and preserved in controlled systems.

Records may include:

a) escalation notes;\
b) hold decisions;\
c) access restrictions;\
d) conflict reviews;\
e) recusal records;\
f) incident logs;\
g) corrective-action plans;\
h) audit findings;\
i) public-claims corrections;\
j) Registry updates;\
k) policy interpretations; and\
l) Board or committee reports.

These records shall not be used for retaliation or unnecessary surveillance. They exist to prove that control functions acted, that risks were routed, and that the Corporation learned from issues.

#### 204.12 Interpretive Rule for Governance Spine Offices and High-Integrity Functions

This Section shall be interpreted to preserve a controlling proposition: GCRI US shall maintain protected, competent, records-based governance spine functions that can identify, hold, escalate, and remediate risks to mission lock, fiduciary integrity, financial control, safeguards, security, records, public claims, membership authority, and the non-execution perimeter.

Where ambiguity exists, the interpretation that better preserves:

a) separation between control functions and program delivery;\
b) independence of records, compliance, safeguards, security, finance, ethics, and claims functions;\
c) protected escalation to the Board;\
d) resistance to operational, donor, sponsor, executive, or founder pressure;\
e) concrete mandate clarity;\
f) adequate resources;\
g) cross-committee coordination; and\
h) auditability of control actions

shall prevail unless a contrary result is required by law.

### 205. Election, Appointment, and Removal of Trustees and Officers (GCRI United States)

#### 205.1 Election and Appointment Map

GCRI US shall maintain a formal election and appointment map for trustees, officers, Board leadership roles, committee chairs, committee members, executive leadership, and any other governance role whose creation, renewal, removal, or replacement affects corporate authority. The map shall identify who appoints, elects, confirms, removes, suspends, replaces, or fills vacancies for each role.

The election and appointment map shall distinguish:

a) trustees elected by members, where member election rights exist;\
b) trustees appointed by the Board, where Board appointment authority exists;\
c) ex officio trustees, where service depends on holding another office;\
d) independent trustees selected for fiduciary oversight and independence;\
e) officers appointed by the Board;\
f) committee chairs and committee members appointed under committee charters;\
g) executive leadership appointed, reviewed, and removed by the Board;\
h) interim, acting, assistant, deputy, or temporary role-holders; and\
i) registry-linked governance participants whose authorization is separate from corporate office.

No person shall hold a trustee or officer role unless the governing record shows the appointment or election authority, effective date, term, role category, acceptance of office, and any limits on authority.

#### 205.2 Nomination Process, Candidate Packets, and Fit-and-Proper Review

Trustee and officer nominations shall be governed by a disciplined process that protects mission, independence, competence, diversity, fiduciary readiness, and anti-capture controls. Nominations shall not be driven by prestige, donor influence, founder preference, political convenience, sector pressure, or public visibility alone.

A candidate packet should include:

a) candidate identity and contact details;\
b) professional background and qualifications;\
c) mission alignment statement;\
d) role sought and authority expectations;\
e) independence assessment;\
f) conflict-of-interest and related-party disclosures;\
g) affiliations with donors, sponsors, vendors, members, public authorities, related entities, or execution-side actors;\
h) experience relevant to nonprofit governance, finance, risk, safeguards, security, public-good infrastructure, law, evidence, standards, or institutional development;\
i) availability and commitment;\
j) public-description consent and restrictions; and\
k) required attestations.

Fit-and-proper review shall assess whether the candidate can serve the Corporation with integrity, informed judgment, confidentiality, independence, constitutional literacy, and respect for non-execution discipline. A candidate may be brilliant, influential, wealthy, well-connected, or strategically useful and still be unsuitable for fiduciary office if conflicts, capture risk, conduct risk, or boundary risk cannot be managed.

#### 205.3 Election Conduct, Campaigning Discipline, and Anti-Capture Controls

Where trustees or other offices are elected, the election process shall be conducted fairly, transparently, and with anti-capture discipline. Campaigning, nominations, endorsements, candidate communications, member outreach, and voting shall not be used to purchase influence, organize donor blocs, mislead members, intimidate participants, or transform fiduciary office into constituency representation.

Election conduct rules shall prohibit:

a) false or misleading candidate claims;\
b) promises of private benefit, procurement advantage, standards influence, publication control, or member preference;\
c) donor-funded campaigning that distorts fairness;\
d) intimidation, retaliation, or exclusion of opposing candidates;\
e) use of confidential member or Registry information for campaigning;\
f) claims that a candidate will represent a funder, member class, sector, state, region, or external institution rather than GCRI US;\
g) undisclosed conflicts or related-party support; and\
h) misuse of GCRI US marks, mailing lists, platforms, or official channels.

Elected trustees shall owe fiduciary duties to GCRI US as a whole. Election support shall not create a mandate to serve external interests.

#### 205.4 Voting, Quorum, Certification, and Challenge Windows

Election or appointment decisions requiring a vote shall be governed by the applicable quorum, voting threshold, credential, class, recusal, and certification rules. The Corporation shall identify eligible voters, confirm good standing, verify delegate authority, and manage conflicts before votes are counted.

Certification of an election shall state:

a) office or seat being filled;\
b) authority for the election;\
c) eligible voters;\
d) quorum;\
e) voting method;\
f) threshold required;\
g) candidates considered;\
h) votes cast and result;\
i) recusals, invalid votes, or exclusions;\
j) challenge window; and\
k) effective date of appointment or election.

A challenge may be filed for credential defects, improper campaigning, undisclosed conflict, counting error, ineligible candidate, defective notice, quorum failure, voting-platform failure, or other material irregularity. Where a challenge could affect the result, GCRI US shall not finalize reliance until the challenge is resolved or the competent authority determines that the defect is immaterial.

#### 205.5 Appointment to Fill Vacancies or Interim Service Needs

Vacancies in trustee, officer, committee, or Board leadership roles shall be filled according to the governing instruments. The Board may appoint persons to fill vacancies or interim service needs where authorized, especially where continuity of governance, finance, records, safeguards, security, or executive oversight requires timely action.

A vacancy appointment record shall identify:

a) vacancy cause;\
b) authority to fill the vacancy;\
c) person appointed;\
d) role and scope;\
e) effective date;\
f) term or interim period;\
g) voting or non-voting status, where applicable;\
h) required training, attestations, and conflict disclosures;\
i) whether member confirmation is required; and\
j) public-description language.

Interim appointments shall not be used to bypass ordinary election or nomination requirements indefinitely. They are continuity tools and must remain time-bound or subject to review.

#### 205.6 Removal for Cause, Loss of Standing, Conflict, or Structural Unsuitability

A trustee, officer, committee chair, committee member, or other governance role-holder may be removed, suspended, restricted, or not renewed where grounds exist under law, the Articles, these Bylaws, appointment instrument, employment terms, committee charter, or Board policy.

Grounds may include:

a) breach of fiduciary duty;\
b) serious conflict of interest or related-party abuse;\
c) loss of eligibility or legal capacity;\
d) material misconduct, fraud, corruption, harassment, retaliation, or confidentiality breach;\
e) repeated non-attendance or non-performance;\
f) failure to disclose conflicts or affiliations;\
g) misuse of title, marks, records, funds, or institutional access;\
h) public overclaim or misrepresentation of authority;\
i) interference with records, audit, safeguards, security, or protected reporting;\
j) unresolved sanctions, financial-crime, regulatory, or public-integrity concern;\
k) conduct inconsistent with mission lock or non-execution discipline; or\
l) structural unsuitability arising from new employment, affiliation, donor role, vendor role, public office, or cross-entity conflict.

Removal shall not be used to punish good-faith dissent, protected reporting, minority reasoning, or fiduciary challenge. Where removal is proposed, the process shall provide appropriate notice, conflict-free review, opportunity to respond where required, and accurate record of decision.

#### 205.7 Resignation, Incapacity, and Temporary Unavailability

A trustee or officer may resign according to the governing instruments and any applicable employment, contract, or appointment terms. Resignation shall be in writing or otherwise recorded in an acceptable form, with effective date and transition obligations.

Where a trustee or officer is incapacitated, unavailable, conflicted, on leave, unreachable, or unable to serve, the Corporation may activate temporary arrangements to preserve continuity. Such arrangements may include acting officers, interim committee chairs, temporary delegation, emergency Board meeting, restricted authority, or vacancy appointment.

The record shall identify:

a) reason for absence or incapacity;\
b) role affected;\
c) authority suspended or continuing;\
d) acting person or interim arrangement;\
e) access changes;\
f) duration and review date; and\
g) transition or return conditions.

Incapacity or temporary unavailability shall not leave bank authority, records, filings, staff supervision, security, or Board process dependent on a missing person.

#### 205.8 Public and Internal Notice Discipline for Changes in Office

Changes in trustee, officer, committee, or executive office shall be communicated internally and publicly with discipline. The Corporation shall ensure that records, websites, rosters, filings, public biographies, bank mandates, access systems, signature matrices, committee lists, email groups, and public descriptions are updated promptly.

Internal notices shall identify:

a) office affected;\
b) person entering or leaving office;\
c) effective date;\
d) authority status;\
e) interim arrangements;\
f) access changes;\
g) records and handover obligations; and\
h) any confidentiality or public-description limits.

Public notices, where issued, shall be accurate and proportionate. They shall not imply removal for cause where no such determination has been made. They shall not conceal a change where continued public listing would mislead. Former officeholders may be described historically only where accurate, dated, and not suggestive of current authority.

#### 205.9 Handover, Offboarding, and Access Revocation

Every departure, removal, resignation, term expiry, or transition of a trustee, officer, committee chair, executive, or other governance role-holder shall include handover and offboarding steps appropriate to the role.

Offboarding may require:

a) return or deletion of confidential materials;\
b) transfer of records and work files;\
c) revocation of system, repository, bank, email, document, and controlled-room access;\
d) update to signature authority;\
e) removal from public and internal rosters;\
f) handover of pending matters;\
g) confirmation of continuing confidentiality, non-use, and claims duties;\
h) preservation of records subject to audit, legal hold, investigation, or Board review; and\
i) exit briefing where appropriate.

A former role-holder shall not continue to act through legacy access, old titles, personal relationships, or retained records. Authority ends when the record says it ends.

#### 205.10 Interpretive Rule for Election, Appointment, and Removal of Trustees and Officers

This Section shall be interpreted to preserve a controlling proposition: trustees and officers of GCRI US may be elected, appointed, renewed, removed, replaced, or transitioned only through recorded authority, fit-and-proper review, conflict discipline, valid voting or appointment process, and accurate public and internal recordkeeping.

Where ambiguity exists, the interpretation that better preserves nomination integrity, fiduciary suitability, anti-capture election controls, proper certification, vacancy continuity, removal for cause where warranted, protection of dissent and whistleblowing, accurate notice, disciplined offboarding, and access revocation shall prevail unless a contrary result is required by law.

### 206. Terms, Renewal Limits, Rotation, and Succession Planning (GCRI United States)

#### 206.1 Term Lengths by Office and Role Class

GCRI US shall define term lengths for trustees, officers, Board leadership roles, committee chairs, committee members, executive roles, and other governance positions in the Articles, these Bylaws, Board resolutions, committee charters, appointment instruments, or other recorded authorities. No governance role shall continue indefinitely by silence, habit, personal centrality, or administrative oversight.

Term rules shall identify:

a) the role covered;\
b) the appointing or electing authority;\
c) the term commencement date;\
d) the term expiry date;\
e) whether renewal is permitted;\
f) whether renewal is automatic, discretionary, or prohibited;\
g) whether interim or partial terms count toward term limits;\
h) whether the role continues until successor appointment; and\
i) the conditions under which the role may be suspended, vacated, or ended before term expiry.

Term design shall reflect the function of the office. Trustees and Board leadership roles require enough time for institutional understanding and continuity. Committee roles require enough time for oversight effectiveness. High-integrity functions require continuity but must not become unreviewable personal control points. Interim roles require short and specific duration. Emergency roles require immediate expiry or ratification.

A role without a clear term is a governance vulnerability because it becomes difficult to know whether authority remains current.

#### 206.2 Renewal Limits and Concentration Control

Renewal of trustees, officers, committee chairs, committee members, and other governance roles shall be governed by renewal limits and concentration controls. Renewal may preserve institutional knowledge, but repeated renewal without review can create entrenchment, dependency, capture, or stagnation.

Renewal review shall consider:

a) performance and attendance;\
b) continued suitability;\
c) independence and conflict profile;\
d) contribution to fiduciary oversight;\
e) compliance with confidentiality, records, and conflict duties;\
f) continued constitutional literacy;\
g) committee and Board needs;\
h) succession readiness;\
i) concentration of influence; and\
j) whether renewal would weaken public trust or institutional balance.

No trustee, officer, committee chair, or governance leader shall be renewed merely because replacement is inconvenient, the person is historically important, a donor prefers continuity, management is comfortable with them, or the role-holder is viewed as indispensable.

Renewal shall be an affirmative governance decision. It shall not be a default reward for prior service.

#### 206.3 Rotation as an Anti-Capture and Continuity Device

Rotation shall be used as an anti-capture and continuity device. It prevents personal ownership of offices, refreshes judgment, develops future leaders, reduces dependency, and demonstrates that GCRI US is an institution rather than a personality-led platform.

Rotation may apply to:

a) Board chair and vice-chair roles;\
b) committee chair roles;\
c) committee membership;\
d) audit, risk, safeguards, governance, and compensation oversight roles;\
e) spokesperson or public-facing governance roles;\
f) controlled-room or high-access roles; and\
g) other roles where long tenure creates influence concentration.

Rotation shall be implemented carefully. Excessive rotation can destroy institutional memory. No rotation can create entrenchment. The Board shall therefore use staggered terms, succession planning, onboarding, deputy roles, committee pipelines, and documented handover to preserve continuity while preventing capture.

Rotation is not a sign of instability. It is a sign that the institution can survive leadership change.

#### 206.4 Cooling-Off and Re-Eligibility Rules Where Needed

GCRI US may impose cooling-off periods and re-eligibility rules where necessary to protect independence, reduce capture, prevent conflicts, preserve audit integrity, or avoid repeated concentration of authority.

Cooling-off rules may apply where a person has served:

a) as Chair, Vice-Chair, Treasurer, Secretary, committee chair, or executive;\
b) on an audit, risk, safeguards, compensation, governance, or integrity committee;\
c) in a high-access controlled-room or registry role;\
d) in a role involving procurement, funding, compensation, investigation, or related-party review; or\
e) in a cross-entity role creating recurring conflict.

During a cooling-off period, the person may be restricted from returning to the same role, chairing a related committee, receiving certain access, participating in review of their prior decisions, or serving in a role that would compromise independence.

Re-eligibility shall require fresh review. Prior service may be valuable, but it shall not create automatic entitlement to return.

#### 206.5 Vacancy Management and Interim Continuity

GCRI US shall maintain vacancy management rules to preserve governance continuity when a trustee, officer, committee chair, executive, or high-integrity role-holder resigns, is removed, becomes incapacitated, is conflicted, reaches term expiry, loses eligibility, or becomes unavailable.

Vacancy management shall identify:

a) who determines that a vacancy exists;\
b) who may appoint or elect a replacement;\
c) whether interim service is permitted;\
d) what authority the interim role-holder has;\
e) what actions require full Board or member approval;\
f) how access and signature authority are updated;\
g) how records and pending matters are transferred; and\
h) how public description is corrected.

Vacancy rules shall be especially strict for the Chair, Secretary, Treasurer, executive leader, audit chair, safeguards chair, security oversight role, and any person holding bank, records, controlled-room, or public-claims authority.

A vacancy shall not be filled informally by the person most available. It shall be filled by the authority entitled to act.

#### 206.6 Succession Plans for Chair, Treasurer, Secretary, and Executive Leadership

The Board shall maintain succession plans for roles whose disruption could impair governance validity, financial control, record integrity, executive continuity, or institutional trust. At minimum, succession planning shall cover the Chair, Treasurer, Secretary, and chief executive or equivalent senior management role where one exists.

Succession plans shall include:

a) emergency acting authority;\
b) interim appointment process;\
c) handover records;\
d) access transition;\
e) bank and payment continuity;\
f) corporate records continuity;\
g) Board meeting continuity;\
h) executive decision continuity;\
i) public communications protocol; and\
j) search or permanent appointment pathway.

For the Chair, succession planning shall preserve Board convening and procedural leadership. For the Treasurer, it shall preserve financial oversight, bank controls, and reporting. For the Secretary, it shall preserve authoritative records, notices, minutes, and filings. For executive leadership, it shall preserve operations, staff supervision, donor and partner communications, contracts, and Board reporting.

Succession planning shall be reviewed periodically and after any material change in personnel, systems, funding, or risk.

#### 206.7 No Perpetual Officeholding by Default or Informal Practice

No trustee, officer, committee chair, committee member, executive, or governance role-holder shall hold office perpetually by default, silence, repeated renewal without review, founder status, donor preference, management reliance, public familiarity, or informal practice. Perpetual officeholding creates capture risk, weakens succession, narrows institutional imagination, and turns public-good stewardship into personal tenure.

GCRI US shall therefore prohibit:

a) indefinite continuation without recorded renewal;\
b) title use after term expiry;\
c) continued signature authority after office ends;\
d) continued access after role closure;\
e) committee leadership without review;\
f) executive authority without Board evaluation; and\
g) public description of expired roles as current.

If the Corporation intentionally permits a role to continue until successor appointment, the record shall say so and shall include a review requirement. Continuation until successor is appointed shall not become indefinite avoidance of succession.

#### 206.8 Term Tracking, Alerts, and Governance Calendar Integration

The Secretary or designated governance function shall maintain term tracking for all trustees, officers, Board leaders, committee chairs, committee members, executive roles, and other governance positions requiring term control. Term tracking shall be integrated into the governance calendar so that renewals, rotations, vacancies, and succession decisions occur before authority lapses.

Term records shall include:

a) role-holder;\
b) role;\
c) appointment or election authority;\
d) effective date;\
e) term expiry;\
f) renewal eligibility;\
g) maximum renewals or term limits;\
h) cooling-off requirements;\
i) public-description status;\
j) access and signature consequences; and\
k) review or decision deadline.

Term alerts should be issued far enough in advance to permit nomination, review, Board action, member action where required, and orderly handover. Failure to track terms is not an administrative inconvenience. It is an authority risk.

#### 206.9 Succession as Institutional Resilience, Not Personal Replacement

Succession planning shall be understood as institutional resilience, not merely replacement of a person. The purpose is to preserve corporate memory, fiduciary continuity, public trust, financial control, records integrity, safeguards, and mission alignment through transition.

Succession planning shall therefore include:

a) documented duties;\
b) process maps;\
c) records repositories;\
d) deputy or backup capability;\
e) training and onboarding;\
f) relationship handover;\
g) risk registers;\
h) pending decision lists;\
i) public-claim and communications continuity; and\
j) secure transfer of credentials and institutional knowledge.

The Board shall treat excessive dependency on a single individual as a risk finding. A person may be exceptional, but the institution must remain governable without them.

#### 206.10 Transition, Handover, and Knowledge Preservation

Every planned transition in trustee, officer, committee, executive, or high-integrity roles shall include handover and knowledge preservation. The outgoing role-holder shall transfer institutional information, current matters, records, commitments, risks, contacts, deadlines, and unresolved issues to the successor or designated custodian.

A transition file may include:

a) role description;\
b) current responsibilities;\
c) pending matters;\
d) key decisions and approvals;\
e) open risks;\
f) key contacts;\
g) committee or Board calendar;\
h) records index;\
i) access list;\
j) obligations requiring follow-up; and\
k) recommendations for successor attention.

Handover shall not transfer personal authority. It transfers knowledge. Authority arises only through appointment, election, delegation, and record.

#### 206.11 Interpretive Rule for Terms, Renewal Limits, Rotation, and Succession Planning

This Section shall be interpreted to preserve a controlling proposition: governance roles in GCRI US shall be time-bounded, reviewable, renewable only through affirmative decision, rotated where needed to prevent capture, and supported by succession planning sufficient to preserve institutional continuity without perpetual officeholding or personal dependency.

Where ambiguity exists, the interpretation that better preserves defined terms, renewal discipline, anti-capture rotation, cooling-off where needed, vacancy control, succession readiness, term tracking, access correction, and institutional resilience shall prevail unless a contrary result is required by law.

### 207. Delegation of Authority and Signature Matrix (GCRI United States)

#### 207.1 Delegation Principles and Non-Implied Authority Rule

GCRI US shall maintain a formal delegation-of-authority framework that identifies who may approve, sign, commit, certify, publish, spend, hire, contract, access, release, escalate, or otherwise act on behalf of the Corporation. Delegation shall be treated as a constitutional control surface. It converts Board-approved authority into operational capability while preventing unauthorized commitments, title-based overreach, informal promises, and apparent authority.

Delegation shall be governed by the following principles:

a) authority must be express, recorded, and traceable to a lawful source;\
b) delegated authority must be limited by scope, amount, duration, matter class, role, and conditions;\
c) reserved matters remain with the Board unless delegation is expressly permitted;\
d) no title alone creates authority;\
e) no course of dealing, repeated practice, email habit, founder role, executive confidence, donor expectation, or staff reliance creates authority beyond the record;\
f) authority must be matched to competence, controls, and segregation of duties;\
g) delegations must be revocable, reviewable, and auditable; and\
h) any ambiguity shall be resolved toward narrower authority until clarified.

GCRI US shall reject implied authority where reliance would weaken mission lock, financial control, nonprofit integrity, public-good asset stewardship, safeguards, security, records discipline, or the non-execution boundary.

#### 207.2 Authority Surfaces and Decision Classes

The delegation framework shall map authority surfaces and decision classes so that the Corporation can determine the correct approval path before action is taken. Different decisions create different risks and therefore require different authority.

Authority surfaces may include:

a) governance authority, including Board, committee, member, officer, and constitutional decisions;\
b) financial authority, including budgets, expenditures, banking, reimbursements, grants, reserves, and restricted funds;\
c) contractual authority, including vendor contracts, employment contracts, consulting agreements, grant agreements, sponsorships, memoranda of understanding, data agreements, and inter-entity instruments;\
d) public communications authority, including press statements, website statements, public rosters, institutional positions, claims of partnership, and use of marks;\
e) membership and Registry authority, including admissions, suspensions, renewals, access classes, role authorizations, and public-description approvals;\
f) security, privacy, and controlled-access authority, including controlled rooms, clean rooms, restricted repositories, incident response, and access revocation;\
g) publication and repository authority, including release of reports, standards drafts, technical materials, code, data schemas, and public-good instruments; and\
h) emergency authority, including protective action under time-bound conditions.

Decision classes shall include ordinary, material, reserved, emergency, sensitive, restricted, related-party, cross-entity, public-authority-sensitive, Indigenous or community-sensitive, and non-execution-perimeter-sensitive matters. Each decision class shall be assigned an approval route.

#### 207.3 Signature Matrix for Governance, Finance, Security, Contracts, and Public Statements

GCRI US shall maintain a signature matrix identifying who may sign or approve which categories of instruments and under what limits. The signature matrix shall be approved by the Board or the competent authority and shall be updated whenever roles, officers, bank authority, financial thresholds, or governance structures change.

The signature matrix shall cover, as applicable:

a) corporate resolutions and certificates;\
b) Board and committee records;\
c) annual filings, tax filings, and regulatory forms;\
d) bank account openings, bank mandates, payment approvals, and treasury instructions;\
e) vendor contracts, consulting agreements, employment agreements, and procurement documents;\
f) grant agreements, sponsorship agreements, donation acknowledgements, and restricted-fund instruments;\
g) memoranda of understanding, partnership instruments, inter-entity agreements, and host-institution instruments;\
h) data-sharing, confidentiality, security, IP, repository, and publication instruments;\
i) controlled-room designations, access approvals, incident notices, and security actions;\
j) public statements, press releases, member rosters, partnership announcements, and official positions; and\
k) emergency authorizations and ratification records.

The matrix shall identify whether one signature, two signatures, committee approval, Board approval, legal review, Treasurer review, Secretary certification, or external professional review is required. A person may sign only within the matrix. Signing outside authority shall trigger review.

#### 207.4 Segregation of Duties and Dual-Control Requirements

Delegation shall preserve segregation of duties and dual-control requirements. GCRI US shall not allow one person to initiate, approve, execute, pay, record, reconcile, and report the same matter where the risk requires separation. Segregation protects the Corporation from error, fraud, capture, coercion, and personal dependency.

Dual-control shall be required or considered for:

a) payments above threshold;\
b) bank authority changes;\
c) related-party payments;\
d) restricted-fund releases;\
e) material contracts;\
f) grant acceptance with conditions;\
g) public-good asset transfers;\
h) controlled-room access approvals;\
i) sensitive repository or system access;\
j) public statements with high institutional consequence; and\
k) emergency actions requiring later ratification.

Where the Corporation’s early-stage capacity makes full segregation difficult, the Board shall adopt compensating controls such as external bookkeeping review, trustee co-approval, bank alerts, monthly reconciliation, transaction logs, after-the-fact Board review, or spending holds.

No person shall use urgency or small-team constraints as justification for uncontrolled authority where material risk exists.

#### 207.5 Spending, Approval, and Commitment Thresholds

The Board shall establish spending, approval, and commitment thresholds for GCRI US. Thresholds shall define which commitments may be approved by management, officers, committees, the Treasurer, the Chair, or the full Board. Thresholds shall consider amount, duration, restricted-fund status, risk, related-party status, data sensitivity, public meaning, and perimeter implications.

Thresholds shall apply not only to cash payments, but also to:

a) multi-year obligations;\
b) recurring subscriptions;\
c) in-kind commitments;\
d) staff and contractor commitments;\
e) vendor dependencies;\
f) grant-match obligations;\
g) public commitments to provide services or outputs;\
h) technology infrastructure costs;\
i) indemnities, warranties, or liability exposure; and\
j) revenue-sharing, sponsorship, or conditional funding terms.

Management shall not split commitments to avoid thresholds. Commitments shall be aggregated where they relate to the same counterparty, project, period, instrument, or purpose. A low-dollar commitment may still require higher approval if it creates legal, security, data, reputational, related-party, or non-execution risk.

#### 207.6 Emergency Delegations, Timeboxing, and Ratification Clocks

Emergency delegations may be created only to protect the Corporation during urgent conditions where delay would create material harm. Emergency authority shall be narrow, timeboxed, recorded, and subject to ratification or review by the Board or competent committee.

Emergency delegations may permit limited action to:

a) preserve funds or prevent fraud;\
b) secure records or systems;\
c) revoke unsafe access;\
d) respond to cybersecurity, privacy, or controlled-room incidents;\
e) satisfy urgent legal or filing obligations;\
f) protect employees, participants, whistleblowers, or vulnerable persons;\
g) maintain payroll or essential operations; or\
h) prevent immediate reputational or public-claims harm through corrective notice.

Emergency delegations shall not permit permanent structural change, constitutional amendment, major funding acceptance, major contract approval, transfer of public-good assets, entry into execution-side activity, or creation of new governance rights unless the ordinary authority later approves through proper process.

The emergency record shall identify the trigger, actor, authority, action taken, time limit, notice to the Board, and ratification clock. Failure to ratify within the required time shall cause the authority to lapse unless law or Board action provides otherwise.

#### 207.7 No Apparent Authority, No Shadow Signatures, and No Informal Commitments

GCRI US shall prohibit apparent authority, shadow signatures, and informal commitments. No person may bind or appear to bind the Corporation through statements, emails, letters, proposals, conversations, pitch decks, unsigned drafts, event remarks, public posts, side messages, or relationship signals unless they hold actual recorded authority.

The Corporation shall reject:

a) “subject to final paperwork” commitments made without authority;\
b) informal promises to donors, sponsors, vendors, members, or partners;\
c) public announcements before approval;\
d) letters of support implying commitments beyond authority;\
e) memoranda of understanding signed without review;\
f) side agreements not entered into the records system;\
g) emails that commit funds, access, partnership, or publication without signature authority; and\
h) verbal commitments later presented as institutional fact.

All external counterparties should be informed, where appropriate, that GCRI US is bound only by instruments signed by authorized persons under the signature matrix and subject to required approvals.

#### 207.8 Delegation Records, Expiry, Revocation, and Auditability

Every material delegation shall be recorded. Delegation records shall identify who granted the authority, who received it, what authority was granted, what limits apply, when it begins, when it expires, what conditions apply, and how it may be revoked.

Delegation records shall include, as applicable:

a) authority source;\
b) delegate name and role;\
c) matter class;\
d) financial threshold;\
e) signature authority;\
f) access authority;\
g) publication authority;\
h) sub-delegation permission or prohibition;\
i) conflict restrictions;\
j) reporting obligations;\
k) effective date and expiry date;\
l) revocation triggers; and\
m) audit trail.

Delegations shall be reviewed periodically and upon role change, resignation, suspension, termination, conflict emergence, policy change, threshold change, or institutional restructuring. Expired delegations shall not remain active through operational inertia. Revoked authority shall be removed from bank systems, signature lists, repositories, access systems, contract workflows, public directories, and internal instructions.

#### 207.9 Unauthorized Acts, Cure, and Remedy Procedures

Where a person acts without required authority, exceeds delegated limits, signs outside the signature matrix, creates an informal commitment, bypasses thresholds, or misrepresents authority, GCRI US shall review the act and determine its legal and institutional effect.

The review shall consider:

a) whether the act was within corporate powers;\
b) whether the actor had any actual authority;\
c) whether apparent authority was created by the Corporation;\
d) whether third parties relied in good faith;\
e) whether the act creates financial, legal, security, safeguards, public-claims, or non-execution risk;\
f) whether the act involved conflict, private benefit, donor pressure, or misconduct;\
g) whether ratification is lawful and prudent; and\
h) what control failure allowed the act.

Remedies may include refusal, termination, ratification, contract amendment, payment hold, public correction, access revocation, officer restriction, staff discipline, counterparty notice, Board review, or policy revision. Ratification shall be used carefully. It shall not reward unauthorized conduct or normalize bypass of authority.

#### 207.10 Delegation in Cross-Entity and Nexus-Aligned Contexts

Delegation shall be especially controlled where GCRI US interacts with GCRI Canada, GRF, GRA, protocol authorities, host institutions, national entities, regional bodies, public authorities, universities, donors, members, or execution-side actors. Cross-entity environments create high risk of authority confusion.

A GCRI US delegate shall not:

a) bind GCRI Canada, GRF, GRA, or any other entity;\
b) rely on another entity’s approval as GCRI US approval;\
c) sign a joint statement without authority from all named entities;\
d) commit shared resources without written approval;\
e) merge public-good and execution-side responsibilities;\
f) represent that GCRI US approves regulated activity;\
g) grant access to another entity’s systems; or\
h) transfer data, IP, records, or public-good assets without proper authority.

Every cross-entity instrument shall identify which entity is acting, who signs for that entity, what obligations are assumed, what obligations are excluded, what public-description limits apply, and what approvals are required.

#### 207.11 Delegation and Public Communications Authority

Public communications authority shall be separately delegated. Authority to manage operations, raise funds, chair a meeting, run a program, or participate in a partnership discussion shall not automatically authorize public statements on behalf of GCRI US.

Public communications delegations shall define:

a) who may speak;\
b) on what subjects;\
c) through what channels;\
d) whether prior review is required;\
e) whether Board approval is required;\
f) whether legal, security, safeguards, finance, or Secretary review is required;\
g) what claims are prohibited; and\
h) what correction process applies.

Statements concerning funding, partnerships, government engagement, member participation, publications, standards, certifications, execution boundaries, public-good assets, or cross-entity relationships shall be subject to heightened review. Public speech can create institutional reliance even when no contract is signed.

#### 207.12 Delegation and Controlled Access Authority

Authority to approve access to restricted information, controlled rooms, clean rooms, repositories, financial systems, membership records, Registry records, or sensitive materials shall be separately delegated and subject to least-privilege rules. Operational convenience shall not create access authority.

Access delegations shall specify:

a) information class;\
b) systems or rooms covered;\
c) approving role;\
d) prerequisites, including training and attestation;\
e) duration;\
f) logging requirements;\
g) revocation triggers; and\
h) escalation rules.

No person shall grant themselves access. No person shall grant access to a donor, sponsor, member, vendor, public authority, partner, or adviser merely because the relationship is important. Access authority must follow role, need-to-know, fit-and-proper suitability, and records discipline.

#### 207.13 Signature Matrix Review, Training, and Operational Publication

The signature matrix and delegation framework shall be reviewed periodically and whenever the Corporation changes officers, executives, bank accounts, committee structures, staffing, funding model, technology systems, or cross-entity arrangements. The matrix shall be communicated internally to all persons who may negotiate, approve, sign, spend, publish, or grant access.

Training shall ensure that trustees, officers, executives, staff, contractors, and relevant volunteers understand:

a) what they may approve;\
b) what they may not approve;\
c) when Board or committee approval is required;\
d) when legal, finance, security, safeguards, or Secretary review is required;\
e) how to document approvals;\
f) how to avoid apparent authority; and\
g) how to escalate uncertainty.

The matrix need not be fully public, but counterparties may receive confirmation that only authorized signatures bind the Corporation. Internally, the matrix shall be easy to find and use. A delegation system that no one understands will fail.

#### 207.14 Interpretive Rule for Delegation of Authority and Signature Matrix

This Section shall be interpreted to preserve a controlling proposition: GCRI US may act only through actual, recorded, scope-limited authority, and no person may bind, spend, sign, publish, access, commit, or represent the Corporation outside the delegation framework, signature matrix, reserved-matter rules, and constitutional boundaries.

Where ambiguity exists, the interpretation that better preserves express authority, narrow delegation, Board reserved matters, spending controls, dual control, emergency time limits, no apparent authority, cross-entity separateness, public-communications discipline, controlled-access discipline, and auditability shall prevail unless a contrary result is required by law.

### 208. Written Authorities, Mandates, and Instruments of Delegation (GCRI United States)

#### 208.1 All Material Delegations Must Be Written and Recorded

All material delegations of corporate authority within GCRI US shall be written, approved, recorded, and preserved in the Corporation’s authoritative records system. No material authority shall arise by implication, habit, oral instruction, informal email, title, trust, founder status, public visibility, donor confidence, staff reliance, or operational convenience.

A written authority shall be required where any person is empowered to:

a) sign contracts, grants, sponsorships, memoranda, filings, certificates, reports, or public statements;\
b) approve expenditures, reimbursements, vendor payments, restricted-fund use, or bank instructions;\
c) accept funding, donor conditions, sponsorship terms, or in-kind support;\
d) create or modify membership, Registry, access, controlled-room, or public-description status;\
e) approve publication, repository release, technical release, data access, or public-good asset use;\
f) appoint staff, consultants, advisers, delegates, working groups, or temporary role-holders;\
g) represent GCRI US externally;\
h) act in emergency; or\
i) exercise any authority that may affect mission, legal obligations, financial exposure, safeguards, security, public trust, or the non-execution boundary.

A written authority must be specific enough that a later trustee, officer, auditor, counsel, funder, member, or successor can determine what was authorized and what was not. Ambiguous delegation is not institutional flexibility. It is governance risk.

#### 208.2 Minimum Required Clauses for Delegation Instruments

Every material delegation instrument shall contain minimum clauses sufficient to define authority, limits, accountability, and duration. The instrument shall be prepared in a form appropriate to the authority granted and the risk involved.

A delegation instrument shall identify:

a) the authority source, including Board resolution, officer authority, committee charter, policy, or bylaw provision;\
b) the delegating organ or person;\
c) the delegate or role-holder;\
d) the purpose of the delegation;\
e) the scope of permitted acts;\
f) excluded acts and reserved matters;\
g) financial thresholds, if any;\
h) signature authority, if any;\
i) access authority, if any;\
j) public communications authority, if any;\
k) confidentiality, records, conflicts, safeguards, security, and non-execution duties;\
l) reporting and escalation requirements;\
m) effective date, expiry date, and review date;\
n) sub-delegation permissions or prohibitions;\
o) revocation triggers; and\
p) record location and authoritative copy.

Where the delegation involves high-risk matters, the instrument shall also include conditions precedent, required legal or finance review, dual-control requirements, ratification obligations, and publication-class restrictions.

#### 208.3 Scope, Duration, Limitations, and Revocation Triggers

Every written authority shall define its scope, duration, limitations, and revocation triggers. GCRI US shall avoid open-ended delegations except where a continuing office requires continuing authority and the authority is subject to periodic review.

Scope shall identify the subject matter, decision class, counterparty type, financial amount, document type, access class, public statement category, or operational function covered. Duration shall identify whether authority is permanent until revoked, term-based, role-based, matter-specific, emergency-based, project-based, or time-limited.

Limitations may include:

a) no authority over Board reserved matters;\
b) no related-party approvals;\
c) no execution-side commitments;\
d) no public claims of endorsement, certification, routeability, or government adoption;\
e) no access to controlled rooms without separate approval;\
f) no spending above threshold;\
g) no sub-delegation;\
h) no acceptance of donor restrictions;\
i) no transfer of public-good assets; and\
j) no action where the delegate has a conflict.

Revocation may occur automatically or by recorded decision upon role change, term expiry, resignation, removal, suspension, conflict, breach, failure to report, loss of good standing, change in law, Board decision, or completion of the delegated purpose.

#### 208.4 Sub-Delegation Rules and Prohibitions

No delegate may sub-delegate authority unless the original delegation expressly permits sub-delegation. Sub-delegation shall be narrow, written, recorded, and consistent with the original authority. A person cannot sub-delegate authority that they do not possess.

Sub-delegation shall be prohibited or tightly restricted for:

a) Board reserved matters;\
b) signature of major contracts;\
c) bank authority and payment approval;\
d) related-party transactions;\
e) controlled-room and clean-room access;\
f) public-good asset transfer;\
g) publication approval;\
h) public claims with institutional consequence;\
i) safeguards, whistleblower, or protected-participation matters;\
j) security incident response; and\
k) any authority involving non-execution boundary risk.

Where sub-delegation is permitted, the record shall identify the sub-delegate, authority granted, limits, duration, reporting line, and revocation terms. Informal assignment of work shall not be confused with sub-delegation of authority. A staff member may prepare a document without having authority to approve or sign it.

#### 208.5 Public, Internal, and Restricted Classification of Delegated Authorities

Delegation instruments shall be classified as public, internal, restricted, confidential, controlled, or otherwise classified according to the sensitivity of the authority and related information. Some delegations may be public-facing, such as officer authority to sign routine documents. Others may require restricted handling, such as security, whistleblower, controlled-room, bank, legal, or incident-response authority.

Public delegations may identify who may represent or sign for the Corporation in ordinary contexts. Internal delegations may guide staff and contractors. Restricted delegations may govern sensitive systems, finance controls, legal response, or emergency authority.

Classification shall consider:

a) whether disclosure could create security risk;\
b) whether disclosure could expose bank or system controls;\
c) whether the delegation involves protected persons or whistleblowing;\
d) whether the delegation involves legal privilege;\
e) whether the authority could be misused by external parties;\
f) whether public knowledge is needed for counterparties to verify authority; and\
g) whether transparency is required to prevent apparent-authority confusion.

Even where a delegation is restricted, the Corporation shall maintain sufficient internal traceability to prove authority and prevent misuse.

#### 208.6 Registry, Repository, and Gazette Linkage Where Applicable

Delegations shall be linked to the appropriate Registry, corporate repository, public notice system, controlled-room register, signature matrix, finance system, or internal authority map. A delegation that is approved but not operationally reflected can create failure. A delegation that is operationally reflected but not approved can create unauthorized authority.

Linkage shall ensure that:

a) current authority is visible to those who must rely on it;\
b) expired authority is removed;\
c) signature matrices match Board records;\
d) banking systems match officer authority;\
e) access systems match access delegations;\
f) public rosters match public-description authority;\
g) Registry roles match governance authorization; and\
h) superseded delegations are archived but not used.

Where GCRI US uses a Gazette, internal register, Council Registry, or authoritative notice system, delegation changes affecting public or operational reliance shall be recorded there according to publication-class rules.

#### 208.7 Written Authority for Public Statements and Institutional Positions

Any authority to issue public statements, institutional positions, consultation submissions, public reports, press releases, website statements, partnership announcements, funding announcements, membership claims, or official correspondence shall be written and bounded. Public communications can create reliance, reputational exposure, legal risk, donor expectations, public-authority confusion, and non-execution boundary risk.

A public-statement authority shall specify:

a) the person or office authorized to speak;\
b) the topics covered;\
c) whether the statement must be pre-approved;\
d) whether Board, legal, safeguards, security, finance, or Secretary review is required;\
e) prohibited claims;\
f) required disclaimers;\
g) whether the authority is ongoing or matter-specific; and\
h) correction obligations.

No person may announce partnerships, funding, government engagement, certification, recognition, standards adoption, routeability, public-good release, or execution-related implications unless the statement matches the authoritative record and the speaker has authority.

#### 208.8 Written Authority for Financial, Contractual, and Funding Instruments

Financial, contractual, and funding instruments shall require written authority matched to financial thresholds, risk class, counterparty type, and matter type. A person negotiating a contract does not necessarily have authority to sign it. A person discussing funding does not necessarily have authority to accept terms. A person managing a program does not necessarily have authority to incur obligations.

Written authority shall be required for:

a) contracts;\
b) grant agreements;\
c) sponsorship agreements;\
d) donation agreements with conditions;\
e) procurement commitments;\
f) consulting and employment agreements;\
g) reimbursement approvals;\
h) bank mandates;\
i) payment approvals;\
j) restricted-fund use;\
k) inter-entity instruments; and\
l) memoranda that may create reliance.

Where an instrument includes indemnities, warranties, confidentiality obligations, data-sharing, IP terms, exclusivity, public claims, restricted funding, related-party issues, or non-execution boundary risk, heightened approval shall be required regardless of dollar amount.

#### 208.9 Written Authority for Security, Access, and Controlled-Room Acts

Security, access, controlled-room, clean-room, repository, identity, and sensitive-data authorities shall be written and operationally enforced. No person shall grant themselves access or grant access to others without recorded authority.

Written access authority shall specify:

a) system, repository, room, data set, or material covered;\
b) access class;\
c) need-to-know basis;\
d) user or role authorized;\
e) prerequisite training or attestation;\
f) permitted actions, including view, edit, download, share, approve, or administer;\
g) logging requirements;\
h) expiry;\
i) revocation triggers; and\
j) incident escalation duties.

Controlled-room authority shall be matter-specific. Access to one sensitive matter shall not become general access. Where a participant’s role changes, access shall be reviewed and revoked if no longer justified.

#### 208.10 Written Authority for Emergency Action

Emergency authority shall be written wherever practicable and pre-defined in advance through Board policy, delegation schedule, incident-response plan, or continuity instrument. Where an emergency prevents advance writing, the acting person shall create a contemporaneous record as soon as practicable.

Emergency authority shall specify:

a) emergency trigger;\
b) permitted protective acts;\
c) prohibited acts;\
d) person or office authorized;\
e) spending or commitment limit;\
f) access or security powers;\
g) notification requirements;\
h) ratification deadline;\
i) expiration; and\
j) record and reporting obligations.

Emergency authority shall be interpreted narrowly. It shall preserve the Corporation, not redesign it. It shall not become a back door for permanent commitments, constitutional changes, donor-driven action, execution-side exposure, or public overclaim.

#### 208.11 Defective, Ambiguous, Expired, or Conflicting Delegation Instruments

Where a delegation instrument is defective, ambiguous, expired, conflicting, incomplete, inconsistent with Board records, or inconsistent with law or these Bylaws, GCRI US shall pause reliance and resolve the defect before further action where practicable.

A defect may include:

a) unclear authority source;\
b) missing approval;\
c) missing effective date;\
d) no expiry or review date where required;\
e) unclear scope;\
f) conflict with signature matrix;\
g) conflict with reserved-matter rules;\
h) unauthorized sub-delegation;\
i) missing conflict or security conditions;\
j) public version inconsistent with internal version; or\
k) authority assigned to a person no longer in role.

Resolution may require clarification, amendment, replacement, ratification, revocation, correction of operational systems, notice to counterparties, or Board review. Ambiguity shall not be used to expand authority.

#### 208.12 Delegation Instrument Archive, Supersession, and Audit Trail

GCRI US shall maintain an archive of current and superseded delegation instruments. The archive shall preserve auditability of authority at the time an act occurred. A person reviewing a past contract, payment, public statement, access grant, or emergency action must be able to determine whether the actor had authority at that time.

The archive shall include:

a) current delegation instrument;\
b) prior versions;\
c) approval record;\
d) effective and expiry dates;\
e) revocation record;\
f) supersession note;\
g) related signature matrix entry;\
h) linked Board or committee resolution;\
i) operational system updates; and\
j) related incidents or corrections.

Superseded delegations shall be marked so they cannot be mistaken for current authority. Archive integrity is essential to corporate defensibility.

#### 208.13 Interpretive Rule for Written Authorities, Mandates, and Instruments of Delegation

This Section shall be interpreted to preserve a controlling proposition: material authority within GCRI US must be written, recorded, scope-limited, time-bounded where appropriate, classified, operationally linked, revocable, auditable, and incapable of expansion through implication, title, habit, urgency, or informal instruction.

Where ambiguity exists, the interpretation that better preserves written authority, clear delegation clauses, sub-delegation control, classification discipline, Registry and repository linkage, public-statement control, financial and access authority limits, emergency timeboxing, defect cure, and audit trail integrity shall prevail unless a contrary result is required by law.

### 209. Corporate Records, Notices, and Authoritative Instruments (GCRI United States)

#### 209.1 Corporate Books and Records of GCRI US

GCRI US shall maintain corporate books and records sufficient to prove its legal existence, fiduciary decisions, nonprofit compliance, Board authority, officer authority, membership authority where applicable, financial stewardship, public-benefit accountability, and institutional continuity. Corporate records shall not be treated as administrative residue. They are the evidentiary foundation of lawful governance.

The corporate books and records shall include, as applicable:

a) Articles of incorporation, amendments, certificates, filings, and organizational records;

b) Bylaws, schedules, annexes, policies, protocols, charters, and supersession records;

c) Board minutes, committee minutes, written consents, resolutions, and decision registers;

d) membership records, assembly records, voting records, seating registers, and member-rights instruments where applicable;

e) trustee, officer, committee, executive, delegation, and signature authority records;

f) financial statements, budgets, reserves, bank records, audit or review materials, tax filings, restricted-fund records, and grant records;

g) conflict-of-interest disclosures, recusal records, related-party approvals, and prohibited-overlap determinations;

h) contracts, memoranda, funding instruments, sponsorship agreements, inter-entity instruments, and material correspondence;

i) public-good asset, repository, publication, intellectual-property, data, and controlled-access records;

j) safeguards, whistleblowing, protected participation, grievance, incident, and remedy records; and

k) security, privacy, controlled-room, clean-room, access, and restricted-handling records.

The Corporation shall preserve these records in secure institutional repositories, not in personal inboxes, uncontrolled drives, informal messaging threads, private devices, or memory-dependent systems.

#### 209.2 Notice, Resolution, Minutes, and Authoritative Instrument Standards

Corporate notices, resolutions, minutes, written consents, certificates, approvals, and instruments shall be prepared in a form that allows later users to determine what action was taken, by whom, under what authority, through what procedure, and with what effect.

A notice shall identify the meeting, action, body, date, time, modality, agenda, materials, decision items, voting or consent rules, confidentiality class, and any special participation requirements. A resolution shall state the decision clearly, identify the approving authority, effective date, implementation authority, conditions, limits, and required follow-up. Minutes shall capture attendance, quorum, materials reviewed, conflicts, recusals, deliberation sufficient for governance purposes, decisions, votes, dissent where recorded, controlled segments, and action items.

An authoritative instrument shall include, where applicable:

a) title and instrument type;

b) issuing authority;

c) approval date and effective date;

d) version number;

e) scope and legal effect;

f) superseded instruments, if any;

g) implementation authority;

h) publication class;

i) retention requirement; and

j) certification or signature.

No instrument shall be relied upon where it is materially incomplete, unsigned where signature is required, uncertified where certification is required, superseded, expired, or inconsistent with the controlling record.

#### 209.3 Authoritative Copy Rule and Control of Copies

GCRI US shall maintain an authoritative copy rule for all constitutional, corporate, financial, governance, membership, Registry, policy, contract, publication, and controlled-access instruments. The authoritative copy is the version that governs. Working drafts, circulated copies, extracted sections, presentation slides, public summaries, archived versions, and redacted versions shall not control unless expressly designated as authoritative for a defined purpose.

The authoritative copy rule shall require:

a) clear identification of current approved version;

b) storage in an approved repository;

c) version number or date;

d) approval authority and effective date;

e) access and publication class;

f) supersession note;

g) document owner or custodian;

h) change history; and

i) method for verifying authenticity.

Where public, internal, redacted, and controlled versions coexist, the relationship among them shall be recorded. A public summary may explain a policy, but it shall not override the approved policy. A redacted version may be disclosed, but it shall not erase obligations contained in the controlled version. A draft may be discussed, but it shall not be implemented.

#### 209.4 Record Preservation, Access Rights, and Retention Schedules

GCRI US shall maintain record preservation and retention schedules that reflect legal obligations, nonprofit compliance, financial audit needs, donor requirements, tax requirements, employment obligations, contract obligations, security obligations, safeguards obligations, and public-good stewardship needs. Records shall be retained long enough to support accountability and defensibility, but not longer than lawful, necessary, or safe.

Retention schedules shall classify records by type, sensitivity, retention period, custodian, access rights, legal hold status, destruction method, and archive requirements. Certain records may require long-term or permanent retention, including Articles, Bylaws, Board resolutions, annual reports, major contracts, audit materials, dissolution records, public-good asset records, and critical governance instruments.

Access rights shall be role-based and need-to-know. Trustees shall receive records needed for fiduciary oversight. Officers shall receive records needed for their functions. Staff and contractors shall receive records needed for assigned work. Members, donors, partners, public authorities, or external parties shall receive records only where law, governing instruments, contractual rights, or approved disclosure permits.

Record preservation shall stop ordinary destruction where litigation, investigation, audit, complaint, whistleblower matter, security incident, financial irregularity, governance dispute, or legal hold requires preservation.

#### 209.5 Linkage Between Board Records and Broader Governance Record Systems

Board records shall be linked to broader governance record systems, including membership records, Council Registry records, delegation records, access-control records, committee records, financial records, public-claims records, publication records, controlled-room records, and cross-entity instruments. A Board decision is often the source of later operational authority; therefore, operational systems must be able to trace back to the Board record.

Linkage shall ensure that:

a) approved delegations update the signature matrix;

b) officer appointments update public and internal records;

c) committee charters update committee records and workplans;

d) budget approvals update finance systems;

e) access decisions update identity and repository systems;

f) public-statement approvals update communications records;

g) membership decisions update member status and rosters;

h) controlled-room decisions update access lists; and

i) cross-entity approvals are linked to the relevant counterpart records.

Where records are not linked, the Corporation risks implementing old authority, missing conditions, misrepresenting status, or allowing access to persist after revocation. Record linkage is therefore a governance control, not an administrative preference.

#### 209.6 No Valid Corporate Act Without Traceable Record of Authority and Effect

No material corporate act of GCRI US shall be treated as valid and reliable unless there is a traceable record of authority and effect. The record must show the source of authority, the action taken, the procedure followed, the effective date, the scope, and the implementation authority.

This rule applies to:

a) trustee and officer appointments;

b) Board and member decisions;

c) committee creation and delegation;

d) contracts and funding instruments;

e) payments, bank authority, and financial commitments;

f) public statements and institutional positions;

g) publication approvals and repository releases;

h) membership and Registry status changes;

i) controlled-room and access decisions;

j) emergency actions; and

k) amendments, corrections, supersessions, and ratifications.

Where a material act lacks a reliable record, the Corporation shall not rely on personal recollection or informal practice. It shall reconstruct, cure, ratify where lawful, correct, or decline reliance. Validity must be demonstrable.

#### 209.7 Correction, Clarification, and Supersession of Corporate Acts

GCRI US shall maintain a disciplined process for correcting, clarifying, superseding, rescinding, or ratifying corporate acts. Errors are inevitable in complex institutions. Silent correction is not acceptable. The integrity of correction matters as much as the original act.

Corrections shall distinguish among:

a) clerical errors;

b) scrivener’s errors;

c) formatting or numbering errors;

d) incomplete references;

e) inaccurate minutes;

f) conflicting versions;

g) substantive defects;

h) authority defects;

i) procedural defects; and

j) legal invalidity.

Clerical corrections may be made through controlled records procedure. Substantive corrections require the authority that made the original act or another competent authority. Supersession shall identify the prior instrument, the new instrument, the effective date, and the continuing effect of prior actions. Rescission shall identify what is withdrawn and whether any reliance must be addressed. Ratification shall be used only where lawful and prudent.

#### 209.8 Notice Systems, Service of Notice, and Proof of Delivery

GCRI US shall maintain notice systems capable of proving that required notices were issued to the correct persons, in the correct form, within the required timeframe, and through approved channels. Notice is a validity condition for many corporate acts.

Notice systems shall support:

a) Board meeting notices;

b) committee meeting notices;

c) member meeting notices;

d) election and voting notices;

e) conflict, recusal, and challenge notices;

f) suspension, termination, reinstatement, and appeal notices;

g) officer or trustee transition notices;

h) policy adoption or supersession notices;

i) controlled-room or restricted-access notices; and

j) legal, audit, or compliance notices.

Proof of notice may include email logs, delivery confirmations, certified mail records, platform logs, signature acknowledgements, calendar notices, register entries, or Secretary certification. Where notice fails, the Corporation shall determine whether waiver, cure, re-notice, or ratification is required.

#### 209.9 Records Classification, Confidentiality, and Publication Discipline

Corporate records shall be classified according to sensitivity, legal requirements, public-benefit transparency, security, privacy, safeguards, privilege, donor confidentiality, financial sensitivity, public-authority sensitivity, Indigenous or community sensitivity, and controlled-room requirements.

Classification levels may include public, internal, restricted, confidential, privileged, controlled, clean-room, or other approved categories. Classification shall govern who may access the record, how it may be stored, whether it may be copied, whether it may be shared, whether it may be quoted, and when it may be destroyed or archived.

Publication discipline shall prevent both over-secrecy and over-disclosure. Public transparency may be appropriate for annual reports, general governance summaries, public policies, and approved statements. Restricted handling may be required for Board deliberations, personnel matters, legal advice, security incidents, whistleblower reports, financial irregularities, donor-sensitive records, controlled technical information, and protected-participant matters.

The Corporation shall not publish sensitive records to appear transparent where doing so would harm persons, breach obligations, or compromise integrity. Nor shall it hide records where lawful disclosure is required or where public correction is necessary to prevent misleading claims.

#### 209.10 Records Integrity in Digital, AI-Assisted, and Cloud-Based Environments

GCRI US may use digital systems, cloud repositories, collaboration platforms, electronic signatures, AI-assisted drafting tools, automated indexing, and knowledge-management systems, provided that records integrity, confidentiality, retention, access control, and authoritative-copy discipline are preserved.

Digital records controls shall include:

a) role-based access;

b) multi-factor authentication where appropriate;

c) version history;

d) audit logs;

e) backup and recovery;

f) retention policies;

g) export capability;

h) legal hold capability;

i) data residency consideration where relevant; and

j) restrictions on unauthorized AI processing of confidential, privileged, personal, sovereign-sensitive, Indigenous, community-sensitive, or controlled materials.

AI-assisted tools may support drafting, indexing, summarization, classification, or retrieval only where permitted by policy and data-handling rules. AI-generated summaries shall not replace authoritative records. Automated outputs shall be reviewed before reliance in governance contexts.

#### 209.11 Corporate Records and Cross-Entity Separateness

Corporate records of GCRI US shall remain separate from records of GCRI Canada, GRF, GRA, protocol authorities, host institutions, members, donors, vendors, or other entities, even where there are aligned missions, shared personnel, shared templates, shared systems, or common public narratives.

Cross-entity record discipline shall ensure that:

a) each entity’s approval is separately recorded;

b) each entity’s obligations are separately stated;

c) shared instruments identify parties and capacities clearly;

d) public statements distinguish institutional positions;

e) shared repositories preserve access boundaries;

f) financial records do not mix funds or obligations;

g) Board records do not imply authority over another entity; and

h) another entity’s record is not treated as GCRI US authorization.

Where a multi-entity decision is required, GCRI US shall retain its own decision record. Institutional alignment shall not erase legal separateness.

#### 209.12 Interpretive Rule for Corporate Records, Notices, and Authoritative Instruments

This Section shall be interpreted to preserve a controlling proposition: GCRI US corporate authority must be evidenced through complete, authentic, classified, retained, and traceable records, and no corporate act, notice, delegation, decision, public claim, or instrument may rely on uncontrolled copies, personal memory, silent edits, unlinked systems, or unverified digital artifacts.

Where ambiguity exists, the interpretation that better preserves corporate books and records, notice validity, authoritative-copy discipline, retention, Board-record linkage, traceable authority, correction and supersession integrity, digital records control, publication discipline, and cross-entity separateness shall prevail unless a contrary result is required by law.

### 210. Conflict of Interest, Recusal, and Trustee / Officer Integrity (GCRI United States)

#### 210.1 Conflict-of-Interest Duties of Trustees, Officers, and Senior Governance Participants

Trustees, officers, executives, committee members, governance-spine personnel, senior advisers, and any person exercising corporate governance authority for GCRI US shall comply with conflict-of-interest duties at all times. These duties apply before appointment, during service, during deliberation, at decision points, during implementation, and after departure where continuing duties apply.

A conflict of interest exists where a person’s judgment, access, influence, duty, loyalty, or public meaning may be affected by a personal, financial, institutional, professional, political, family, donor, sponsor, vendor, member, public-authority, related-party, or cross-entity interest. The standard is not limited to actual misconduct. It includes actual conflict, potential conflict, perceived conflict, structural conflict, and prohibited overlap.

Each covered person shall:

a) disclose material interests fully and promptly;

b) update disclosures when facts change;

c) avoid participating in matters where independence is impaired;

d) comply with recusal and information-barrier requirements;

e) refrain from using office, access, records, or institutional influence for private or third-party advantage;

f) avoid creating public confusion about whose interests they serve;

g) protect the Corporation from donor, sponsor, vendor, member, founder, executive, or sector capture; and

h) accept Board, committee, or governance-spine determinations concerning restrictions.

Conflict discipline protects both the Corporation and the individual. It allows GCRI US to benefit from high-level expertise without allowing expertise to become influence capture.

#### 210.2 Duty to Disclose Material Interests, Outside Roles, and Potential Capture Points

Covered persons shall disclose all material interests, outside roles, affiliations, financial relationships, fiduciary positions, advisory roles, consulting arrangements, employment relationships, ownership interests, donor relationships, sponsor relationships, vendor relationships, public offices, political roles, family relationships, intellectual-property interests, and cross-entity positions that may affect or appear to affect their service.

Disclosure shall include, as applicable:

a) employment, consulting, advisory, fiduciary, board, committee, or officer roles;

b) ownership, investment, compensation, fee, grant, gift, reimbursement, or sponsorship interests;

c) relationships with donors, sponsors, funders, vendors, contractors, members, applicants, grantees, universities, public authorities, or related entities;

d) positions in GCRI Canada, GRF, GRA, protocol authorities, host institutions, national entities, regional bodies, execution-side entities, or affiliated platforms;

e) participation in regulated financial, insurance, market, technology, data, AI, infrastructure, or consulting activities adjacent to GCRI US work;

f) personal, family, professional, or institutional relationships that may affect judgment;

g) public commitments or advocacy positions that may materially constrain impartiality;

h) confidential obligations to another organization that may limit participation; and

i) any pressure, inducement, expectation, or request from an external actor seeking influence.

Disclosure shall occur at onboarding, annually, before relevant decisions, and whenever circumstances change. A person shall not wait to be asked if they know a material interest exists.

#### 210.3 Recusal Rules for Deliberation, Access, and Vote

Where a conflict exists, recusal shall be applied to the aspects of participation necessary to protect institutional integrity. Recusal may apply to access, preparation, deliberation, recommendation, vote, approval, implementation, public communication, or follow-up.

A conflicted person may be required to:

a) leave the meeting or digital room;

b) refrain from receiving certain materials;

c) refrain from influencing staff, management, trustees, members, or committee participants;

d) abstain from discussion;

e) abstain from voting;

f) refrain from signing, approving, certifying, or implementing;

g) refrain from contacting counterparties on behalf of GCRI US;

h) refrain from participating in public communications; or

i) comply with an information barrier.

Recusal shall be recorded. The record shall state the person, matter, nature or category of conflict where safe to disclose, scope of recusal, whether the person was absent from deliberation, whether the person received materials, whether the person voted, and whether quorum or threshold was affected.

Recusal is not personal punishment. It is a governance mechanism that preserves trust.

#### 210.4 Recusal Register and Recorded Participation Restrictions

GCRI US shall maintain a recusal register or equivalent record for material conflicts affecting trustees, officers, executives, committee members, and senior governance participants. The register shall be sufficiently detailed to enforce restrictions while protecting sensitive personal, legal, financial, security, or protected-participation information.

The recusal register may include:

a) person and role;

b) matter affected;

c) conflict category;

d) date of disclosure;

e) decision-maker or reviewing authority;

f) restrictions imposed;

g) duration or review date;

h) access restrictions;

i) voting or participation effect;

j) related meeting, committee, or decision record; and

k) closure or supersession note.

The register shall be operationally linked to Board agendas, committee agendas, access lists, voting lists, procurement files, funding decisions, publication workflows, controlled-room records, and decision registers where relevant. A recusal recorded but not enforced is not effective.

#### 210.5 Prohibited Overlaps, Incompatibilities, and Independence Requirements

Certain role combinations, relationships, and interests shall be prohibited or presumptively incompatible because they defeat independence, fiduciary duty, safeguards, audit integrity, procurement neutrality, public-good distinctness, or the non-execution boundary.

Prohibited or restricted overlaps may include:

a) trustee or officer approving a contract with an entity from which they benefit;

b) executive or trustee controlling both vendor selection and vendor payment;

c) donor or sponsor representative controlling publication findings, standards direction, or agenda content;

d) vendor serving on the committee evaluating that vendor;

e) officer approving their own compensation, reimbursement, contract, or related-party payment;

f) trustee or officer using GCRI US access to benefit an execution-side entity;

g) person serving simultaneously in assurance, standards, evidence, or public-good stewardship role and execution-side role for the same matter without mitigation;

h) person controlling records or Registry entries concerning their own status;

i) conflicted person investigating or adjudicating a complaint involving themselves; and

j) public official or public-authority representative participating in a manner that violates ethics, procurement, lobbying, or public-law constraints.

Where an overlap is prohibited, recusal alone may not be sufficient. The person may need to resign one role, be removed from a matter, lose access, or be excluded from the affected decision surface.

#### 210.6 Exceptions, Mitigations, and Board-Level Review of Edge Cases

Some conflicts or overlaps may be manageable through disclosure, recusal, independent review, information barriers, dual approval, public-description limits, restricted access, or time-limited conditions. GCRI US shall distinguish between non-waivable conflicts and manageable conflicts.

Mitigation may include:

a) independent trustee or committee review;

b) external legal, audit, valuation, security, or safeguards review;

c) exclusion from deliberation and vote;

d) no-access restrictions;

e) alternative signatory;

f) competitive process or documented sole-source justification;

g) public-safe disclosure where appropriate;

h) restricted public-claims language;

i) monitoring and periodic review; and

j) Board ratification after full disclosure where lawful.

Edge cases shall be escalated to the Board or appropriate committee where the conflict involves trustees, officers, executives, major funders, major vendors, related entities, public authorities, regulated or execution-side actors, or matters affecting public trust.

A conflict shall not be minimized merely because the person is valuable, senior, trusted, under-resourced, or historically important.

#### 210.7 Breach, Cure, and Enforcement for Governance-Level Conflict Failures

Failure to disclose a material conflict, breach of recusal, improper influence, related-party misuse, private-benefit conduct, or prohibited overlap shall be treated as a governance-level integrity failure. The seriousness of the breach shall depend on intent, materiality, harm, recurrence, concealment, reliance, and institutional risk.

Consequences may include:

a) correction of minutes or decision records;

b) exclusion of tainted votes;

c) re-deliberation or re-approval without conflicted participation;

d) contract review, amendment, termination, or recovery;

e) access restriction;

f) suspension or removal from committee or office;

g) trustee or officer removal process;

h) public correction where claims were misleading;

i) referral to audit, legal, safeguards, or law enforcement where required; and

j) policy, training, or control redesign.

Cure shall not be used to excuse intentional concealment or private benefit. Where a conflicted act cannot be cured safely, the Corporation shall unwind, rescind, or refuse reliance to the extent lawful and practical.

#### 210.8 Conflict Controls for Donors, Sponsors, Vendors, Members, and Related Entities

GCRI US shall apply heightened conflict controls where a trustee, officer, executive, committee member, or senior governance participant has relationships with donors, sponsors, vendors, members, applicants, host institutions, related entities, or execution-side actors. These relationships can create subtle capture even where no direct payment exists.

The Corporation shall assess whether the relationship could affect:

a) funding acceptance;

b) agenda-setting;

c) procurement;

d) publication independence;

e) standards development;

f) membership admission or renewal;

g) access to controlled information;

h) public claims or branding;

i) staffing or contractor selection;

j) cross-entity instruments; or

k) non-execution boundary integrity.

A donor may fund work, but may not control findings. A vendor may supply services, but may not govern procurement. A member may participate, but may not convert membership into approval authority. A related entity may coordinate, but may not blur legal separateness. These distinctions shall be enforced through conflict controls.

#### 210.9 Conflict Controls in Technical, Evidence, Standards, and Publication Work

Because GCRI US may steward public-good research, evidence systems, standards, technical infrastructure, open-source repositories, and publication processes, conflict controls shall apply to technical and knowledge-production contexts as well as corporate finance contexts.

Conflicts may arise where a person:

a) reviews a method, standard, repository, model, or publication from which they or their institution may benefit;

b) controls a technical release affecting a vendor or execution-side actor with which they are affiliated;

c) edits a report concerning their employer, funder, sponsor, or public authority;

d) handles evidence relevant to an entity with which they have a relationship;

e) influences publication timing for reputational or funding reasons;

f) has IP interests in a tool or framework being adopted; or

g) uses restricted technical knowledge for external advantage.

The Corporation shall apply disclosure, reviewer independence, publication notes, recusal, editorial separation, external review, and repository access controls where necessary. Technical neutrality requires governance controls, not only technical competence.

#### 210.10 Conflict Controls in Public-Authority and Indigenous Participation Contexts

Where trustees, officers, or governance participants hold public-authority, government, regulatory, Indigenous, community, or quasi-public roles, GCRI US shall apply heightened conflict and public-description discipline. Such roles may carry legal, political, procurement, ethics, sovereignty, rights, or public-meaning implications.

The Corporation shall assess:

a) whether the person participates personally or officially;

b) whether public-law, ethics, lobbying, gifts, procurement, or records rules apply;

c) whether participation could imply government endorsement or Indigenous consent;

d) whether the person may vote or should observe only;

e) whether confidential information can be received;

f) whether a public statement requires separate approval;

g) whether recusal is required from matters affecting the person’s public authority or community; and

h) whether role-marker or restricted handling is necessary.

GCRI US shall not use public or Indigenous participation to create symbolic legitimacy beyond actual authority. Conflict and representation safeguards shall work together.

#### 210.11 Annual Certification and Trigger-Based Updates

Trustees, officers, executives, committee members, and senior governance participants shall complete periodic conflict certifications and trigger-based updates. Annual certification shall not be the only control. A person shall update disclosures promptly when facts change.

Annual certification shall confirm:

a) current outside roles;

b) financial interests;

c) related-party relationships;

d) donor, sponsor, vendor, member, and public-authority links;

e) cross-entity roles;

f) execution-side affiliations;

g) confidential obligations;

h) changes since prior certification; and

i) acknowledgment of conflict and recusal duties.

Trigger-based updates shall occur before relevant decisions, upon new employment, upon acceptance of a new board or advisory role, upon entering a consulting or vendor relationship, upon family or financial change affecting a matter, upon public appointment, upon donor or sponsorship relationship, or upon any other event that may affect independence.

#### 210.12 Interpretive Rule for Conflict of Interest, Recusal, and Trustee / Officer Integrity

This Section shall be interpreted to preserve a controlling proposition: GCRI US trustees, officers, executives, committee members, and senior governance participants must disclose, manage, recuse from, and where necessary avoid conflicts, related-party interests, prohibited overlaps, and improper influence so that fiduciary judgment, public-good stewardship, safeguards, financial integrity, technical independence, and non-execution discipline remain intact.

Where ambiguity exists, the interpretation that better preserves full disclosure, independent review, recusal enforcement, prohibited-overlap control, donor and vendor neutrality, public-authority care, technical and publication integrity, annual certification, trigger-based updates, and effective remedies for conflict breaches shall prevail unless a contrary result is required by law.

### 211. Protected Participation, Whistleblowing, and Board-Level Escalation (GCRI United States)

#### 211.1 Protected Reporting to the Board and Relevant Committees

GCRI US shall maintain protected reporting routes to the Board and relevant Board committees for concerns that affect fiduciary integrity, mission lock, financial control, safeguards, security, privacy, records integrity, executive conduct, conflict-of-interest discipline, public-claims accuracy, donor influence, or the non-execution boundary. Protected reporting shall be available to trustees, officers, executives, employees, contractors, volunteers, members, delegates, Registry persons, advisers, controlled-room participants, and other persons participating in or affected by the Corporation’s governance system.

Protected reporting to the Board may concern:

a) executive misconduct, overreach, suppression, retaliation, or concealment;\
b) trustee, officer, committee, member, donor, sponsor, vendor, or related-party misconduct;\
c) financial irregularity, unauthorized commitment, restricted-fund misuse, fraud, or private benefit;\
d) conflicts of interest, prohibited overlaps, undisclosed related-party interests, or capture risk;\
e) false or misleading public claims concerning funding, endorsement, partnership, certification, routeability, government engagement, Indigenous participation, or institutional capacity;\
f) security, privacy, controlled-room, clean-room, repository, or access-control breach;\
g) safeguards failure, harassment, intimidation, discrimination, retaliation, or unsafe participation;\
h) manipulation of minutes, records, registers, delegations, votes, or Board materials;\
i) pressure to enter execution-side, regulated, market-facing, insurance, finance, transaction-routing, or non-permitted activity; and\
j) any matter that management cannot safely, independently, or credibly handle.

The reporting system shall not require a person to report to the person implicated in the concern. Where the ordinary reporting path is conflicted, the report may be routed to the Chair, Vice-Chair, Lead Independent Trustee, Audit and Risk Committee, Governance Committee, Safeguards and Integrity Committee, external counsel, or another protected recipient designated by the Board.

#### 211.2 Safe Escalation of Executive Misconduct, Capture Risk, Financial Irregularity, or Safeguards Failure

GCRI US shall provide safe escalation for matters that may threaten the Corporation’s fiduciary independence or public-benefit legitimacy. The Board shall treat executive misconduct, capture risk, financial irregularity, and safeguards failure as governance-level matters, not as ordinary personnel or operational issues to be contained informally.

Safe escalation shall be available where there is concern that:

a) an executive has exceeded authority, suppressed information, retaliated against staff or participants, misled the Board, or bypassed reserved matters;\
b) a donor, sponsor, vendor, member, public authority, founder, executive, or related entity is exerting improper influence;\
c) financial records, restricted funds, payments, bank authority, budgets, grants, or public funding claims are inaccurate or unsafe;\
d) a whistleblower, complainant, Indigenous participant, community representative, employee, contractor, delegate, or protected participant has been threatened, excluded, punished, or silenced;\
e) a controlled-room or restricted-handling breach has occurred;\
f) public claims have outrun the authoritative record; or\
g) a program, partnership, or technical initiative is drifting toward execution-side conduct.

The Board shall ensure that such reports are received by persons capable of acting independently. Where the concern involves senior leadership, the Board shall preserve records, restrict access where necessary, prevent retaliation, and consider independent review.

#### 211.3 Board Duty to Receive, Protect, and Route Serious Reports

The Board shall have a duty to receive, protect, and route serious reports. It shall not dismiss, delay, bury, or reroute serious concerns into channels controlled by conflicted persons. The Board may delegate investigation or handling, but it may not delegate away accountability for ensuring that serious reports are properly addressed.

Upon receipt of a serious report, the Board or designated committee shall determine:

a) whether immediate protective measures are required;\
b) whether management is conflicted;\
c) whether records must be preserved;\
d) whether access, payment, publication, or delegation holds are required;\
e) whether legal counsel, auditor, security expert, safeguards expert, or independent reviewer should be engaged;\
f) whether the matter implicates protected persons or retaliation risk;\
g) whether public correction or restricted notice may be needed;\
h) which body or officer shall lead the response; and\
i) what reporting and closure timeline applies.

The Board shall distinguish between concerns that require investigation, concerns that require immediate control action, concerns that require policy correction, and concerns that require no further action after review. Even unsubstantiated reports may reveal process weakness.

#### 211.4 No Retaliation by Trustees, Officers, Management, Members, or Related Parties

GCRI US shall prohibit retaliation by trustees, officers, executives, management, staff, contractors, members, delegates, donors, sponsors, vendors, advisers, related entities, or any person acting through or in relation to the Corporation. Retaliation may be direct or indirect, formal or informal, overt or subtle.

Retaliation includes:

a) removal, suspension, demotion, non-renewal, exclusion, or access restriction because of protected reporting;\
b) withdrawal of assignments, invitations, committee roles, speaking roles, membership access, or program opportunities for retaliatory reasons;\
c) intimidation, harassment, reputational attack, public disparagement, blacklisting, or social exclusion;\
d) pressure on a reporter’s employer, institution, funder, community, public authority, or professional network;\
e) misuse of confidentiality, security, conflict, or conduct rules to punish a reporter;\
f) denial of payment, reimbursement, dues waiver, scholarship, or participation support for retaliatory reasons;\
g) manipulation of records, minutes, performance reviews, or role status; and\
h) threats or adverse treatment directed at a person who cooperates, gives evidence, supports a reporter, or raises related concerns.

The Corporation shall treat retaliation as an independent breach, regardless of whether the underlying report is ultimately substantiated. Protection is attached to good-faith reporting, not to guaranteed correctness.

#### 211.5 Interim Protective Measures and Confidentiality Requirements

Where a protected report raises credible risk, GCRI US may impose interim protective measures while the matter is reviewed. Interim measures are protective, not punitive, and shall be proportionate to the risk.

Interim measures may include:

a) preservation of records and legal hold;\
b) temporary removal of access to systems, repositories, controlled rooms, financial tools, or records;\
c) recusal or temporary reassignment of implicated persons;\
d) non-contact or meeting-protocol rules;\
e) executive session without management;\
f) suspension of public statements, publications, payments, contracts, or implementation steps pending review;\
g) appointment of an independent reviewer;\
h) protected reporting route outside ordinary management;\
i) temporary alternate supervisor or reporting line; and\
j) confidentiality instructions to all persons involved.

Confidentiality shall be managed carefully. It shall protect reporters, witnesses, affected persons, privileged information, sensitive records, and review integrity. It shall not be used to silence lawful escalation, conceal misconduct, or prevent Board oversight.

#### 211.6 Recordkeeping, Publication Class, and Auditability of Protected Governance Reports

Protected reports, Board responses, interim measures, investigation steps, findings, remedies, and closure records shall be documented and classified appropriately. These records may contain sensitive personal, employment, financial, security, legal, whistleblower, Indigenous, community, public-authority, donor, or governance information.

The record shall include, as appropriate:

a) report identifier;\
b) intake channel and date;\
c) reporter category, if disclosed;\
d) issue category;\
e) persons, offices, systems, records, funds, or decisions affected;\
f) immediate risk assessment;\
g) conflicts and recusals;\
h) protective measures;\
i) reviewing authority;\
j) investigative steps;\
k) findings or disposition;\
l) corrective action;\
m) retaliation-risk review;\
n) Board or committee reporting; and\
o) closure and recurrence-prevention actions.

Publication shall be restricted unless disclosure is required by law, necessary to protect stakeholders, necessary to correct public misinformation, or approved through the proper authority. Public transparency shall be balanced with safety, privacy, privilege, and fairness.

#### 211.7 Independent Review, Counsel, and External Assurance Where Required

The Board may appoint independent counsel, auditors, forensic specialists, safeguards experts, security experts, investigators, or other external reviewers where the matter requires independence, technical competence, legal privilege, public trust, or management separation.

Independent review shall be considered where:

a) trustees, officers, or executive leadership are implicated;\
b) financial irregularity, fraud, restricted-fund misuse, or related-party concern is alleged;\
c) retaliation or safeguards failure involves senior persons;\
d) security, privacy, or controlled-room breach is material;\
e) public claims may have misled donors, members, public authorities, or the public;\
f) conflict or capture risk is institutionally significant;\
g) the Corporation’s nonprofit status, legal position, or public trust may be affected; or\
h) the Board lacks internal capacity to review credibly.

External reviewers shall have a clear mandate, confidentiality obligations, access limits, reporting line, conflict clearance, and deliverable scope. They shall support Board judgment; they shall not replace it.

#### 211.8 Board Response, Remedy, and Corrective Action

Where a protected report is substantiated or reveals control weakness, GCRI US shall take corrective action proportionate to the issue. Corrective action shall focus on remedy, recurrence prevention, accountability, and restoration of institutional trust.

Corrective actions may include:

a) correction of records, minutes, public claims, rosters, or filings;\
b) access revocation or restriction;\
c) repayment, recovery, contract amendment, or transaction reversal where lawful;\
d) disciplinary action, suspension, removal, or termination;\
e) policy revision, training, or control redesign;\
f) Board or committee restructuring;\
g) independent monitoring;\
h) apology, remedy, or support for harmed persons;\
i) public-safe disclosure where necessary; and\
j) referral to counsel, auditor, regulator, law enforcement, or other authority where required.

The Board shall track corrective actions until closure. A report is not resolved merely because it is discussed.

#### 211.9 Protection Against Misuse of Reporting Systems

Protected reporting systems shall not be misused for knowingly false accusations, harassment, strategic disruption, competitive harm, personal retaliation, or governance manipulation. GCRI US shall handle such misuse through fair process and careful evidence review.

However, the Corporation shall not label a report as bad faith merely because it is critical, uncomfortable, mistaken, difficult to prove, embarrassing, directed at senior leadership, or ultimately unsubstantiated. Good-faith reporting shall remain protected.

The Board shall distinguish:

a) substantiated misconduct;\
b) unsubstantiated but good-faith concern;\
c) concern revealing process weakness;\
d) misunderstanding requiring clarification;\
e) interpersonal conflict requiring mediation or management; and\
f) knowingly false or abusive reporting.

This distinction preserves both safety for reporters and fairness for persons accused.

#### 211.10 Relationship to Membership, Registry, Employment, and Committee Processes

Protected reports may intersect with membership discipline, Registry authorization, employment action, trustee removal, officer restriction, committee review, access controls, public-claims correction, or legal proceedings. GCRI US shall coordinate these processes without fragmenting responsibility or exposing sensitive information unnecessarily.

Where a report affects membership, the membership process shall not be used to retaliate. Where it affects Registry authorization, the Registry may impose protective holds. Where it affects employment, employment process shall respect whistleblower and non-retaliation protections. Where it affects trustees or officers, Board-level process shall apply. Where it affects committees, conflicted committee members shall be recused.

The Corporation shall designate a lead handling route and ensure that related systems remain synchronized.

#### 211.11 Interpretive Rule for Protected Participation, Whistleblowing, and Board-Level Escalation

This Section shall be interpreted to preserve a controlling proposition: GCRI US shall maintain protected, independent, Board-accessible reporting channels so that serious concerns involving fiduciary integrity, executive conduct, financial irregularity, safeguards, security, records, conflicts, capture, public claims, or non-execution drift can reach the proper authority without retaliation or suppression.

Where ambiguity exists, the interpretation that better preserves protected reporting, safe escalation, Board responsibility, non-retaliation, interim protection, confidentiality with fairness, independent review where needed, corrective action, and auditability shall prevail unless a contrary result is required by law.

### 212. Indemnification, Advancement, Insurance, and Protected Service (GCRI United States)

#### 212.1 Purpose of Indemnification and Protected Service

GCRI US may provide indemnification, advancement of expenses, insurance, and related protected-service arrangements to trustees, officers, committee members, employees, volunteers, agents, and other authorized persons to the fullest extent permitted by applicable law and approved governing instruments. The purpose of such protection is to enable qualified persons to serve the Corporation with independence, courage, diligence, and good-faith judgment without unreasonable personal exposure for properly authorized service.

Indemnification shall protect lawful and good-faith service. It shall not protect misconduct, fraud, bad faith, knowing illegality, private inurement, improper private benefit, retaliation, intentional confidentiality breach, unauthorized execution-side activity, willful misuse of funds, or deliberate misrepresentation of the Corporation’s authority.

Protected service exists because GCRI US operates in complex areas involving nonprofit governance, public-good infrastructure, risk evidence, technical systems, controlled information, public-sector engagement, cross-border participation, membership discipline, safeguards, security, and public claims. Trustees and officers must be able to make difficult decisions in these domains. Protection is appropriate where the person acted within authority, in good faith, and in a manner reasonably believed to be in the interests of the Corporation.

#### 212.2 Persons Eligible for Protection

The Corporation may extend protection to persons serving or formerly serving in authorized roles, including:

a) trustees and former trustees;\
b) officers and former officers;\
c) committee members acting under Board-approved charters;\
d) employees and senior management acting within assigned authority;\
e) volunteers acting under recorded mandate;\
f) authorized agents, representatives, or delegates acting for the Corporation;\
g) persons serving another entity at the written request of GCRI US;\
h) governance-spine personnel, including records, safeguards, security, finance, ethics, compliance, and Registry functions; and\
i) other persons approved by the Board where lawful and appropriate.

Protection shall not arise merely because a person is a member, donor, sponsor, adviser, observer, applicant, public participant, technical contributor, or external partner. The person must be acting in an authorized capacity for or at the request of GCRI US.

#### 212.3 Conditions for Indemnification

Indemnification shall be available only where the person acted in good faith, within actual or reasonably understood authority, for a legitimate corporate purpose, and in a manner reasonably believed to be in or not opposed to the best interests of GCRI US. Where the matter involves criminal, regulatory, financial-crime, sanctions, corruption, or intentional misconduct concerns, indemnification shall be subject to any additional legal requirements and Board review.

In determining eligibility, the Corporation may consider:

a) whether the person acted under a valid office, delegation, committee mandate, employment role, or Board instruction;\
b) whether the person acted honestly and with reasonable care;\
c) whether the person disclosed conflicts;\
d) whether the person complied with recusal, confidentiality, security, safeguards, and financial controls;\
e) whether the person exceeded authority or acted for private benefit;\
f) whether the person cooperated with review or investigation;\
g) whether indemnification would violate law, nonprofit restrictions, donor restrictions, or public policy; and\
h) whether the claim concerns protected service or personal conduct outside the Corporation.

Indemnification shall not convert unauthorized conduct into authorized conduct. Where authority was absent, the Board shall determine whether any protection is legally and institutionally appropriate.

#### 212.4 Advancement of Expenses

GCRI US may advance reasonable expenses to an eligible person in connection with a proceeding, investigation, inquiry, claim, or matter arising from protected service, subject to applicable law and Board-approved conditions. Advancement may be necessary to ensure that trustees, officers, and other protected persons can defend lawful service without immediate personal financial hardship.

Advancement may require:

a) written request;\
b) description of the matter;\
c) confirmation that the matter arises from authorized service;\
d) undertaking to repay amounts if final determination shows that indemnification is not permitted;\
e) conflict review;\
f) Board or committee approval;\
g) spending cap or budget;\
h) counsel selection or approval; and\
i) reporting of material developments.

Advancement shall not be automatic where credible evidence indicates fraud, bad faith, knowing illegality, intentional harm, private benefit, retaliation, or conduct outside authority. The Board may condition, suspend, or deny advancement where protection would be unsafe, unlawful, or inconsistent with the Corporation’s mission and public trust.

#### 212.5 Indemnification Exclusions and Non-Protected Conduct

GCRI US shall not indemnify or advance expenses where prohibited by law or where the conduct is outside the permissible scope of protection. Non-protected conduct may include:

a) fraud, theft, embezzlement, corruption, bribery, or intentional financial misconduct;\
b) knowing violation of law;\
c) intentional breach of fiduciary duty;\
d) improper private inurement or private benefit;\
e) retaliation against whistleblowers, complainants, protected participants, employees, members, or delegates;\
f) intentional misuse or disclosure of confidential, privileged, controlled, personal, Indigenous, community-sensitive, or sovereign-sensitive information;\
g) deliberate falsification of records, minutes, filings, financial reports, or public claims;\
h) unauthorized execution-side, regulated, market-facing, insurance, securities, lending, custody, settlement, or transaction-routing activity;\
i) acts taken for personal, donor, sponsor, vendor, member, political, or third-party benefit rather than the Corporation; and\
j) conduct occurring outside the person’s authorized role.

Where a matter includes both protected and non-protected conduct, the Corporation may allocate costs, limit advancement, seek repayment, or provide partial protection only for covered service.

#### 212.6 Insurance and Risk Transfer

The Board may authorize directors and officers insurance, employment practices liability insurance, cyber insurance, professional liability insurance, fiduciary liability coverage, crime coverage, general liability coverage, event coverage, and other insurance appropriate to the Corporation’s risk profile, budget, and stage of development.

Insurance review shall consider:

a) Board and officer exposure;\
b) employment, volunteer, and contractor risk;\
c) public events and convenings;\
d) publications, reports, and public claims;\
e) cybersecurity, privacy, and controlled-information risk;\
f) financial fraud and crime exposure;\
g) safeguards, retaliation, and grievance risk;\
h) cross-border participation;\
i) technology, repository, and public-good infrastructure risks; and\
j) exclusions that may affect the non-execution boundary.

Insurance shall not be treated as a substitute for governance controls. It supports resilience, but it does not excuse weak records, poor financial controls, unaddressed conflicts, unsafe access, or public overclaim.

#### 212.7 Board Approval and Conflict-Free Determination

Indemnification, advancement, and insurance decisions shall be made through a conflict-free process. A person seeking protection shall not participate in the decision except to provide information where requested. If multiple trustees are implicated, the Board may use disinterested trustees, an independent committee, external counsel, or another lawful mechanism to determine eligibility.

The approval record shall state:

a) person seeking protection;\
b) role and authority basis;\
c) matter covered;\
d) protection requested;\
e) legal authority;\
f) conflict review;\
g) decision-maker;\
h) conditions, caps, or repayment undertaking; and\
i) final determination or review schedule.

Where the matter involves a trustee, officer, executive, donor, sponsor, vendor, or related party, heightened documentation shall be required.

#### 212.8 Protected Service for Cross-Entity Roles

Where a person serves another entity, body, host institution, committee, coalition, or related public-good initiative at the written request of GCRI US, the Corporation may provide protection only to the extent the service was authorized, lawful, mission-aligned, and within the request. The protection shall not extend to the person’s independent service for that other entity or to acts outside the GCRI US mandate.

Cross-entity protected service shall require clarity on:

a) which entity requested service;\
b) which capacity the person held;\
c) which duties were owed to which entity;\
d) what information could be shared;\
e) what indemnity, insurance, or protection the other entity provides;\
f) whether conflicts or prohibited overlaps exist; and\
g) whether public descriptions could imply agency or merger.

GCRI US shall not assume unlimited responsibility for activities conducted by GCRI Canada, GRF, GRA, protocol authorities, hosts, members, or execution-side actors unless it has lawfully and expressly agreed to do so.

#### 212.9 Continuing Cooperation and Repayment Obligations

A person receiving indemnification or advancement shall cooperate with the Corporation, counsel, insurers, auditors, investigators, and the Board in connection with the matter. Cooperation may include preserving records, providing truthful information, avoiding unauthorized public statements, maintaining confidentiality, and complying with litigation holds.

Where advancement is provided subject to repayment, the person shall repay amounts if a final determination establishes that indemnification is not permitted. The Corporation may also seek repayment where the person materially misrepresented facts, concealed conflicts, failed to cooperate, or used advanced funds for non-covered purposes.

Protection is reciprocal. The Corporation may protect good-faith service, and the protected person must protect the Corporation’s integrity.

#### 212.10 Interpretive Rule for Indemnification, Advancement, Insurance, and Protected Service

This Section shall be interpreted to preserve a controlling proposition: GCRI US may protect trustees, officers, and other authorized persons for lawful, good-faith, mission-aligned service, but shall not use indemnification, advancement, or insurance to shield fraud, bad faith, private benefit, retaliation, unauthorized authority, record manipulation, or non-execution boundary breach.

Where ambiguity exists, the interpretation that better preserves lawful service protection, Board independence, conflict-free determination, nonprofit integrity, public trust, repayment discipline, cross-entity clarity, and exclusion of misconduct shall prevail unless a contrary result is required by law.

### 213. Board and Officer Accountability, Evaluation, and Corrective Governance (GCRI United States)

#### 213.1 Accountability as a Continuing Governance Obligation

Accountability of trustees, officers, Board leaders, committee chairs, committee members, executives, and high-integrity function holders shall be a continuing governance obligation of GCRI US. Accountability shall not arise only after failure. It shall be built into appointment, onboarding, reporting, evaluation, renewal, rotation, removal, succession, and recordkeeping.

Accountability shall require each governance actor to remain answerable for:

a) performance of assigned duties;\
b) compliance with fiduciary standards;\
c) respect for mission lock and nonprofit purpose;\
d) observance of non-execution discipline;\
e) protection of public-good assets;\
f) accuracy of public claims;\
g) disclosure and management of conflicts;\
h) protection of records, confidentiality, safeguards, and security;\
i) cooperation with Board, committee, audit, legal, and integrity processes; and\
j) corrective action when weaknesses are identified.

The Corporation shall not treat distinguished service, founding contribution, technical importance, donor confidence, public profile, or personal relationship as exemption from accountability. Authority and accountability shall travel together.

#### 213.2 Board Self-Evaluation and Collective Performance Review

The Board shall periodically evaluate its collective performance. Board self-evaluation shall assess whether the Board is fulfilling its fiduciary role as the primary oversight organ of GCRI US, and whether it remains capable of governing a nonprofit public-good institution operating across evidence, standards, risk, technology, membership, controlled handling, and cross-border interfaces.

Board self-evaluation shall consider:

a) quality of fiduciary deliberation;\
b) adequacy of Board materials and decision packs;\
c) attendance, preparation, and trustee engagement;\
d) effectiveness of financial, audit, risk, safeguards, security, and records oversight;\
e) quality of executive supervision;\
f) ability to manage conflicts, related-party matters, and capture risk;\
g) understanding of mission lock and non-execution boundaries;\
h) protection of dissent and safe escalation;\
i) quality of meeting minutes, resolutions, and action tracking;\
j) committee effectiveness;\
k) succession readiness; and\
l) whether the Board is too passive, too operational, too dependent on one person, or too slow to address material risk.

The Board shall record evaluation outcomes at an appropriate level of detail and shall adopt improvement actions where needed. Evaluation without corrective action shall not be sufficient.

#### 213.3 Individual Trustee and Officer Performance Review

GCRI US may review the performance of individual trustees and officers where appropriate to confirm continued suitability, contribution, attendance, preparedness, independence, conflict discipline, confidentiality, and mission alignment. Such review shall be fair, evidence-informed, and proportionate to the role.

Individual review may consider whether the trustee or officer:

a) attends meetings and participates meaningfully;\
b) reviews materials and asks informed questions;\
c) complies with confidentiality and records rules;\
d) discloses conflicts and observes recusal requirements;\
e) respects Board, officer, and management boundaries;\
f) avoids public overclaim or misuse of title;\
g) contributes constructively to risk, finance, safeguards, or mission oversight;\
h) supports rather than suppresses dissent and protected reporting;\
i) remains suitable under fit-and-proper standards; and\
j) cooperates with evaluations, investigations, audits, and corrective processes.

Individual review shall not be used to punish principled dissent, minority reasoning, whistleblowing, or legitimate challenge to management or Board leadership. It shall be used to ensure that governance roles remain effective and trustworthy.

#### 213.4 Officer and Committee Accountability to the Board

Officers and committees shall be accountable to the Board for the functions assigned to them. A committee or officer shall not become a self-governing island. Each shall operate within a charter, mandate, delegation, or office description and shall report to the Board in a manner sufficient for fiduciary oversight.

Officer accountability shall include:

a) performance against office duties;\
b) compliance with authority limits;\
c) accurate reporting;\
d) escalation of material risks;\
e) records integrity;\
f) conflict management; and\
g) cooperation with Board review.

Committee accountability shall include:

i) operation within charter;\
ii) timely reporting;\
iii) recordkeeping;\
iv) escalation of material findings;\
v) conflict and recusal management;\
vi) closure of assigned tasks; and\
vii) periodic charter review.

Where an officer or committee fails to perform, exceeds authority, suppresses information, or creates confusion, the Board may clarify mandate, restrict authority, replace leadership, amend charter, require reporting, or dissolve the committee.

#### 213.5 Executive Accountability and Management Performance Review

The chief executive, executive director, president, or equivalent senior management leader shall be accountable to the Board. Executive accountability shall cover both results and means. GCRI US shall not evaluate executive performance solely by fundraising, visibility, speed, public reach, or activity volume. The Corporation’s model requires disciplined growth under nonprofit, safeguards, records, security, and non-execution controls.

Executive performance review shall assess:

a) mission delivery;\
b) financial stewardship and budget discipline;\
c) quality and candor of Board reporting;\
d) respect for Board reserved matters;\
e) staff, contractor, and operational management;\
f) risk, compliance, safeguards, security, and privacy performance;\
g) accuracy of public statements and funding claims;\
h) donor, sponsor, member, vendor, and partner boundary discipline;\
i) institutionalization of systems rather than personal dependency;\
j) ability to build diverse, safe, competent teams;\
k) responsiveness to audit, legal, and governance-spine concerns; and\
l) conduct consistent with public-benefit leadership.

The Board may use written objectives, annual reviews, 360-degree input, committee reports, financial metrics, risk dashboards, staff feedback, and independent review where appropriate. Performance review shall be recorded and linked to compensation, renewal, succession, or corrective action where relevant.

#### 213.6 Corrective Governance Measures

Where evaluation, audit, incident review, whistleblowing, financial reporting, safeguards review, security review, or Board deliberation identifies weakness, GCRI US shall apply corrective governance measures. Corrective governance is not punishment by default. It is the means by which the Corporation learns, repairs, strengthens, and preserves public trust.

Corrective measures may include:

a) clarification of authority;\
b) revision of delegation matrix;\
c) additional trustee or officer training;\
d) improved Board packs or reporting cadence;\
e) committee redesign;\
f) replacement of committee chair or officer;\
g) executive performance plan;\
h) conflict-management remediation;\
i) access restriction;\
j) financial-control strengthening;\
k) records correction or supersession;\
l) public-claims correction;\
m) independent review;\
n) suspension or removal where necessary; and\
o) amendment of bylaws, policies, schedules, or charters.

Corrective action shall be tracked until closure. A corrective action that is not assigned, dated, monitored, and verified remains only an intention.

#### 213.7 Accountability for Public Claims, Institutional Narrative, and External Positioning

Trustees, officers, executives, and Board leaders shall be accountable for the accuracy of public claims and institutional narrative within their authority. GCRI US shall not permit public communications to overstate its authority, funding, partnerships, government engagement, membership, certification role, standards status, public-good maturity, technical capacity, or execution-side involvement.

Accountability shall apply where public statements imply:

a) Board approval not granted;\
b) secured funding where funding is prospective or conditional;\
c) government, regulator, Indigenous, community, academic, member, or partner endorsement beyond the record;\
d) certification, recognition, routeability, or conformance authority not granted;\
e) regulated execution capacity;\
f) cross-entity authority over GCRI Canada, GRF, GRA, or other entities;\
g) current officeholder status after departure; or\
h) public-good asset release, adoption, or approval not completed.

Where public claims are inaccurate, the responsible office shall correct them promptly. Public correction is not reputational weakness. It is institutional strength.

#### 213.8 Accountability for Records, Access, and Controlled Information

Trustees, officers, executives, committee members, and governance-spine personnel shall be accountable for preserving records, respecting access controls, and protecting controlled information. The Corporation’s authority depends on its ability to prove decisions and protect sensitive materials.

Accountability shall apply where a person:

a) stores corporate records in uncontrolled locations;\
b) withholds records from the Secretary or Board;\
c) deletes or alters records without authority;\
d) shares confidential Board materials externally;\
e) grants access without authorization;\
f) uses controlled information for another role;\
g) fails to revoke access after role change;\
h) uses unauthorized AI or cloud tools for restricted materials; or\
i) fails to report a records, access, or information incident.

Corrective measures may include training, access restriction, record recovery, incident review, Board reporting, disciplinary action, or removal from role.

#### 213.9 Accountability for Mission Drift and Non-Execution Boundary Breach

GCRI US shall hold trustees, officers, executives, committees, and delegated actors accountable for mission drift and non-execution boundary breach. Such breaches may occur gradually through contracts, funding models, public language, technical releases, partner arrangements, advisory activities, or member expectations.

Accountability shall apply where a governance actor permits or advances:

a) transaction-linked or success-linked compensation inconsistent with nonprofit role;\
b) market, insurance, securities, lending, custody, settlement, or brokerage activity;\
c) public claims that GCRI US approves or guarantees execution-side outcomes;\
d) privileged access by execution-side actors to public-good infrastructure;\
e) standards or evidence work controlled by beneficiaries;\
f) use of nonprofit assets for private market advantage; or\
g) cross-entity structures that blur public-good and regulated delivery stacks.

Where boundary drift is identified, the Board shall require legal review, public-description correction, contract amendment, program redesign, delegation restriction, or termination of the unsafe activity.

#### 213.10 Evaluation Records, Confidentiality, and Use Limits

Evaluation and accountability records shall be classified and handled carefully. They may contain sensitive trustee, officer, employee, financial, legal, safeguards, security, whistleblower, or performance information. The Corporation shall preserve enough record to support accountability while avoiding unnecessary exposure.

Evaluation records may include:

a) evaluation tools;\
b) self-assessments;\
c) committee reports;\
d) performance objectives;\
e) findings;\
f) corrective actions;\
g) Board discussion summaries;\
h) conflict or recusal notes;\
i) training or renewal decisions; and\
j) closure records.

Such records shall not be used for retaliation, gossip, factional advantage, or public embarrassment. They exist to strengthen governance and preserve institutional responsibility.

#### 213.11 Corrective Governance and Due Process

Corrective governance measures affecting a person’s office, role, reputation, compensation, access, or membership-related status shall be administered with due process appropriate to the seriousness of the matter. The Corporation shall provide notice, opportunity to respond, conflict-free review, and appeal or review where required by law or policy.

Due process shall be balanced with protective action. Where immediate risk exists, interim restrictions may be imposed before final determination, but they shall be recorded, reviewed, and limited to protective purpose.

The Corporation shall not weaponize accountability against dissenters. Nor shall it avoid accountability for powerful insiders. The standard is fair, recorded, non-retaliatory governance.

#### 213.12 Interpretive Rule for Board and Officer Accountability, Evaluation, and Corrective Governance

This Section shall be interpreted to preserve a controlling proposition: GCRI US governance authority shall remain accountable through continuing evaluation, performance review, corrective action, public-claim discipline, records and access controls, boundary oversight, and fair process, so that trustees, officers, executives, and committees serve the institution rather than themselves or external interests.

Where ambiguity exists, the interpretation that better preserves active accountability, Board self-evaluation, individual suitability review, executive performance control, corrective action, truthful public narrative, record and access integrity, mission-drift control, confidentiality of evaluations, and due process shall prevail unless a contrary result is required by law.

### 214. Emergency Governance, Continuity, and Institutional Resilience (GCRI United States)

#### 214.1 Emergency Governance as Protective Authority, Not Parallel Governance

Emergency governance within GCRI US shall exist only to protect the Corporation, its mission, people, records, funds, systems, public-good assets, legal status, safeguards obligations, and continuity during urgent conditions. Emergency governance shall not create a parallel governance system, permanent concentration of authority, executive override, founder override, donor override, or informal suspension of constitutional discipline.

Emergency authority may be used only where delay would create material harm and where ordinary governance procedures cannot be completed in time without unacceptable risk. Such authority shall be narrow, time-bound, documented, and subject to prompt Board review, ratification, correction, or termination.

Emergency governance may be invoked for matters such as:

a) cybersecurity, privacy, repository, access, or controlled-room incidents;\
b) fraud, theft, bank compromise, payment failure, or financial-control breakdown;\
c) serious safeguards, retaliation, whistleblower, harassment, or protected-participation risk;\
d) urgent legal demand, subpoena, regulatory communication, sanctions concern, or litigation risk;\
e) executive incapacity, resignation, removal, conflict, disappearance, or misconduct;\
f) loss of key records, systems, domains, credentials, bank access, or corporate files;\
g) public misinformation or unauthorized claim requiring immediate correction;\
h) severe funding, payroll, insurance, filing, or operational continuity risk; and\
i) any circumstance threatening the Corporation’s lawful existence, public-benefit mandate, or institutional integrity.

Emergency governance shall preserve the institution until proper authority can act. It shall not redesign the institution by crisis.

#### 214.2 Emergency Authority Triggers and Thresholds

Emergency authority shall be triggered only by a defined event, material risk, or urgent condition requiring immediate protective action. The threshold shall be higher than ordinary inconvenience, reputational discomfort, donor pressure, media attention, staff preference, or program deadline.

A valid emergency trigger shall involve at least one of the following:

a) imminent risk of unlawful action, financial loss, data exposure, public harm, or institutional breach;\
b) inability to convene the ordinary authority in time;\
c) need to preserve records, funds, systems, access, or legal position;\
d) need to protect a person from retaliation, harassment, exposure, or unsafe participation;\
e) need to stop unauthorized public claims or apparent authority;\
f) need to maintain payroll, insurance, tax, filing, or bank continuity; or\
g) need to suspend unsafe access, delegation, signature authority, publication, payment, or contract action.

The person invoking emergency authority shall record the trigger, facts known, action taken, authority relied upon, persons notified, limits imposed, and next review step. If the trigger is later found insufficient, the Board shall review the action, correct any improper effect, and revise controls where needed.

#### 214.3 Emergency Board Convening and Reduced Notice

Where emergency conditions require Board action, the Chair, Vice-Chair, Lead Independent Trustee, Secretary, Treasurer, or other person authorized by the governing instruments may convene an emergency Board meeting with reduced notice to the extent permitted by law and these Bylaws.

Emergency Board convening shall preserve:

a) notice to all trustees where practicable;\
b) clear statement of emergency matter;\
c) identification of decisions requested;\
d) quorum or emergency quorum requirements;\
e) conflict and recusal handling;\
f) secure meeting channel;\
g) controlled-room treatment where needed;\
h) minutes or emergency action record; and\
i) ratification or follow-up process.

Reduced notice shall not permit unrelated major business. The Board shall decide only what is necessary to address the emergency unless all procedural requirements for broader action are satisfied.

#### 214.4 Interim Protective Measures

GCRI US may impose interim protective measures during an emergency before final determination of responsibility or final Board action. Interim measures are designed to prevent further harm, preserve evidence, maintain continuity, and protect persons and assets.

Interim protective measures may include:

a) suspension or narrowing of delegated authority;\
b) temporary access revocation or hold;\
c) bank, payment, or signatory hold;\
d) litigation hold or records-preservation notice;\
e) controlled-room lockdown;\
f) password, credential, domain, repository, or system reset;\
g) temporary replacement of a conflicted or unavailable officer;\
h) pause on public statements, publications, contracts, payments, or membership decisions;\
i) non-contact, meeting, or communications protocol;\
j) protective reassignment of reporting lines; and\
k) emergency public-safe correction of false authority or public claim.

Interim measures shall be proportionate, recorded, and reviewed. They shall not be used to retaliate against whistleblowers, silence dissent, punish criticism, or seize power for unrelated purposes.

#### 214.5 Continuity of Board, Officer, Records, Finance, and Executive Functions

GCRI US shall maintain continuity plans for essential governance functions. The Corporation must be able to operate if a key trustee, Chair, Secretary, Treasurer, executive leader, finance officer, records custodian, system administrator, or other critical person becomes unavailable or unsuitable.

Continuity planning shall cover:

a) Board convening and quorum;\
b) acting Chair and acting Secretary arrangements;\
c) Treasurer and banking continuity;\
d) emergency payment and payroll authority;\
e) access to corporate records and authoritative instruments;\
f) secure access to domains, repositories, collaboration systems, and identity tools;\
g) executive management transition;\
h) legal, tax, insurance, filing, and audit deadlines;\
i) communications authority during emergency; and\
j) protection of controlled-room, whistleblower, safeguards, and security records.

No essential function shall depend solely on one person’s personal email, personal device, private storage, memory, informal relationship, or unshared credential. Personal dependency is a continuity failure.

#### 214.6 Crisis Communications and Public-Claims Discipline

Emergency conditions shall not excuse inaccurate public communications. Crisis communications shall be factual, bounded, approved by the proper authority, and aligned with legal, security, safeguards, privacy, and public-claims controls.

Emergency public statements shall distinguish:

a) confirmed facts from preliminary assessment;\
b) Board-approved action from management action;\
c) institutional position from personal comment;\
d) active investigation from final finding;\
e) public-safe information from restricted information; and\
f) GCRI US authority from the authority of GCRI Canada, GRF, GRA, protocol authorities, members, hosts, or public bodies.

No emergency communication shall imply government endorsement, regulatory approval, certification, routeability, execution capacity, or resolved facts beyond the record. Where public correction is required, the Corporation shall correct accurately without disclosing protected information unnecessarily.

#### 214.7 Emergency Financial Controls and Treasury Protection

Where an emergency affects funds, bank access, payments, restricted funds, grants, payroll, fraud risk, or financial records, the Treasurer, Audit and Risk Committee, Chair, or other authorized person may initiate emergency financial controls within approved authority.

Emergency financial controls may include:

a) freezing payment authority;\
b) revoking or changing bank signatories;\
c) suspending vendor payments pending review;\
d) preserving transaction records;\
e) notifying banks or payment providers;\
f) conducting emergency reconciliation;\
g) restricting reimbursement or credit-card access;\
h) notifying insurers, auditors, accountants, counsel, or the Board;\
i) preserving restricted funds; and\
j) approving essential payments within emergency limits.

Emergency financial controls shall be documented and reviewed by the Board or Audit and Risk Committee. No emergency shall be used to authorize unrelated spending, related-party payments, new financial commitments, or funding arrangements outside proper approval.

#### 214.8 Emergency Security, Privacy, and Controlled-Access Response

Where an emergency affects security, privacy, controlled-room integrity, repository access, personal data, restricted information, AI tool use, cloud systems, public-good code, or sensitive records, the Corporation shall implement an incident-response process proportionate to the risk.

Emergency security response may include:

a) access lockdown;\
b) credential reset;\
c) repository freeze;\
d) log preservation;\
e) breach assessment;\
f) containment of unauthorized disclosure;\
g) notification to affected persons where required;\
h) legal and privacy review;\
i) forensic support;\
j) public-safe communications; and\
k) corrective action.

Where controlled-room or clean-room materials are exposed, the Corporation shall determine what was accessed, by whom, under what authority, what onward disclosure occurred, and what remedial steps are required. Controlled materials shall not be treated as ordinary documents simply because they were mistakenly shared.

#### 214.9 Emergency Safeguards and Protected Participation Response

Where an emergency involves retaliation, harassment, intimidation, threats, unsafe participation, whistleblower exposure, Indigenous or community-sensitive harm, public-authority sensitivity, or protected-person risk, GCRI US shall apply safeguards-first emergency response.

Protective action may include:

a) immediate separation of affected persons;\
b) temporary access or meeting restrictions;\
c) non-contact instructions;\
d) role-marker participation;\
e) protection of reporter identity;\
f) safe alternate reporting channel;\
g) temporary suspension of implicated authority;\
h) referral to independent reviewer;\
i) support for affected participant; and\
j) Board or committee notification.

The Corporation shall not require a protected person to continue participating in an unsafe process merely to preserve schedule, optics, donor expectations, or procedural convenience.

#### 214.10 Emergency Succession and Temporary Role Activation

Emergency succession may be used where a key officeholder is unavailable, incapacitated, conflicted, removed, under review, or unable to perform essential duties. Emergency succession shall be recorded and limited.

Temporary role activation shall identify:

a) role activated;\
b) person appointed;\
c) authority granted;\
d) authority excluded;\
e) effective date and expiry;\
f) reporting requirement;\
g) access and signature implications;\
h) Board or committee review; and\
i) permanent succession pathway.

Temporary authority shall not continue indefinitely. If the emergency persists, the Board shall move from emergency continuity to formal interim or permanent appointment procedures.

#### 214.11 Emergency Ratification, Review, and After-Action Learning

All emergency actions shall be reviewed after the immediate risk is contained. Where the action required Board approval, the Board shall ratify, amend, reject, supersede, or unwind the action as lawful and appropriate. Emergency action without review is unacceptable.

After-action review shall assess:

a) whether emergency authority was properly invoked;\
b) whether the action was proportionate;\
c) whether records were preserved;\
d) whether notice and escalation occurred;\
e) whether any person was harmed or rights affected;\
f) whether funds, records, systems, or public claims were protected;\
g) whether controls failed before the emergency;\
h) whether policies, training, access, delegation, or continuity plans require revision; and\
i) whether public or internal correction is required.

The Corporation shall treat emergencies as learning events. Repeated emergencies of the same type indicate structural weakness.

#### 214.12 Prohibited Uses of Emergency Governance

Emergency governance shall not be used to:

a) avoid Board deliberation;\
b) silence dissent;\
c) punish whistleblowers;\
d) remove trustees or officers without process except where immediate protective suspension is permitted;\
e) accept donor terms without review;\
f) approve major contracts outside authority;\
g) amend constitutional instruments;\
h) change membership rights;\
i) transfer public-good assets;\
j) enter regulated or execution-side activity;\
k) suppress financial, security, safeguards, or records concerns; or\
l) convert temporary authority into permanent control.

Any use of emergency authority for these purposes shall be treated as a serious governance breach.

#### 214.13 Interpretive Rule for Emergency Governance, Continuity, and Institutional Resilience

This Section shall be interpreted to preserve a controlling proposition: emergency governance in GCRI US exists only to protect mission, people, records, funds, systems, public-good assets, legal status, safeguards, and continuity through narrow, time-bound, recorded authority subject to prompt Board review and correction.

Where ambiguity exists, the interpretation that better preserves limited emergency authority, continuity of essential functions, protected participation, financial control, secure access, accurate public communications, ratification discipline, and prevention of emergency power abuse shall prevail unless a contrary result is required by law.

### 215. Corporate Risk Governance and Board Oversight (GCRI United States)

#### 215.1 Board Oversight of Risk Appetite, Risk Taxonomy, and Control Environment

The Board of Trustees shall maintain ultimate oversight of the risk appetite, risk taxonomy, and control environment of GCRI US. This oversight shall be treated as a core fiduciary duty and shall not be reduced to an annual compliance exercise, management update, audit appendix, or program risk note. The source outline requires a dedicated corporate risk-governance section after protected participation and before continuity and cross-surface governance, and this Section completes that missing Part IX requirement in the GCRI US sequence.

The Board shall ensure that the Corporation maintains a risk taxonomy covering, at minimum:

a) mission-drift and public-benefit risk;\
b) nonprofit-status, tax, and private-benefit risk;\
c) fiduciary and corporate-authority risk;\
d) financial, liquidity, reserve, restricted-fund, and fraud risk;\
e) donor, sponsor, vendor, member, founder, executive, sector, and public-authority capture risk;\
f) non-execution perimeter and regulated-activity risk;\
g) cybersecurity, privacy, controlled-room, repository, and data-handling risk;\
h) safeguards, whistleblowing, retaliation, protected-participation, and dignity risk;\
i) public-claims, endorsement, certification, routeability, and reputational risk;\
j) cross-entity, inter-entity, federation, and legal-separateness risk;\
k) operational resilience, staffing, succession, business-continuity, and system-dependency risk; and\
l) publication, evidence, standards, research-integrity, and public-good asset risk.

Risk appetite shall state what types of risk the Corporation may accept, mitigate, transfer, avoid, or prohibit. GCRI US may accept reasonable programmatic uncertainty, research uncertainty, fundraising uncertainty, and innovation risk. It shall not accept uncontrolled fiduciary risk, private-benefit risk, retaliation risk, unsafe data handling, false public claims, execution-side drift, or authority without record.

#### 215.2 Oversight of Perimeter, Safeguards, Security, Funding, and Continuity Risks

The Board shall provide active oversight of the risk domains most capable of impairing GCRI US’s constitutional architecture. These include perimeter risk, safeguards risk, security risk, funding risk, and continuity risk.

Perimeter risk shall include any activity, agreement, platform design, public statement, funding model, member relationship, evidence product, standard, technical release, or cross-entity arrangement that may cause GCRI US to be mistaken for, or to operate as, a regulated execution actor. The Board shall ensure that the Corporation remains a nonprofit public-good steward and does not become an insurer, lender, broker, dealer, adviser, market operator, custodian, payment processor, underwriter, settlement agent, or transaction router.

Safeguards risk shall include retaliation, unsafe participation, harassment, intimidation, protected-person exposure, Indigenous or community misrepresentation, whistleblower suppression, grievance mishandling, and exclusion of under-resourced or vulnerable participants from meaningful participation.

Security risk shall include cybersecurity, identity access, repository access, controlled-room breach, clean-room failure, unauthorized AI processing, personal-data exposure, privileged-information exposure, sovereign-sensitive or community-sensitive data exposure, and system-dependency risk.

Funding risk shall include donor concentration, restricted-fund distortion, sponsor influence, conditional funding inconsistent with mission, in-kind dependency, underfunded control functions, misleading public funding claims, and revenue models that create execution-boundary pressure.

Continuity risk shall include dependency on one founder, executive, trustee, officer, donor, vendor, repository, cloud system, bank signatory, records custodian, or technical administrator.

#### 215.3 Receipt and Review of KRIs, KPIs, Incidents, and Assurance Findings

The Board shall receive and review key risk indicators, key performance indicators, incident reports, audit findings, safeguards reports, security findings, financial-control findings, membership and Registry findings, public-claims findings, and other assurance outputs at a cadence proportionate to the Corporation’s scale and risk profile.

The Board shall ensure that reporting distinguishes:

a) confirmed facts from assumptions;\
b) actual risk from theoretical risk;\
c) open incidents from closed incidents;\
d) corrected findings from unresolved findings;\
e) management view from independent review;\
f) high-risk matters from ordinary operational issues; and\
g) public-safe summaries from restricted findings.

KRIs may include donor concentration, reserve runway, restricted-fund exposure, overdue filings, unresolved audit findings, high-risk public claims, stale delegations, expired Registry roles, unresolved conflicts, late access revocations, controlled-room incidents, unresolved whistleblower reports, and unresolved security vulnerabilities.

KPIs may include timely Board reporting, audit completion, policy adoption, training completion, access-review completion, incident-response timing, corrective-action closure, membership-health indicators, publication-review discipline, and public-good asset stewardship metrics.

Incidents shall not be hidden because they are reputationally uncomfortable. Assurance findings shall not be softened to protect management, donors, founders, trustees, or partners.

#### 215.4 Corrective Action Plans, Remediation Tracking, and Escalation

The Board shall require corrective action plans for material risk findings, incidents, audit weaknesses, safeguards failures, security weaknesses, financial irregularities, public-claims errors, delegation failures, conflict breaches, and perimeter concerns. Corrective actions shall be assigned, dated, tracked, and verified.

A corrective action plan shall identify:

a) risk or finding;\
b) root cause;\
c) immediate containment;\
d) long-term remediation;\
e) accountable owner;\
f) required resources;\
g) deadline;\
h) reporting cadence;\
i) verification method; and\
j) closure evidence.

Where management owns remediation, the Board or relevant committee shall monitor completion. Where management is implicated, remediation shall be overseen independently. Where a risk remains unresolved beyond the approved timeline, escalation shall occur to the Board, Audit and Risk Committee, Governance Committee, Safeguards and Integrity Committee, Security Committee, counsel, auditor, or another competent authority.

A risk is not remediated because it has been discussed. It is remediated only when the control weakness has been corrected and the correction has been verified.

#### 215.5 Relationship Between Risk Governance and Strategic Planning

Risk governance shall be integrated into strategic planning. GCRI US shall not approve ambitious programs, public-good infrastructure commitments, membership expansion, cross-border activity, technical repositories, public campaigns, funding models, or inter-entity arrangements without examining risk capacity.

Strategic planning shall assess:

a) whether the Corporation has adequate staff, budget, records systems, legal support, security controls, safeguards capacity, finance controls, and Board oversight to execute the plan safely;\
b) whether the plan increases donor dependency or sponsor influence;\
c) whether the plan expands sensitive data, repository, controlled-room, or public-claims exposure;\
d) whether the plan creates regulated-perimeter or execution-side confusion;\
e) whether the plan affects GCRI Canada, GRF, GRA, protocol authorities, host institutions, members, public authorities, Indigenous institutions, or related entities; and\
f) whether the Corporation can exit, pause, correct, or wind down the plan if conditions change.

Growth without risk capacity shall not be treated as success. For GCRI US, institutional maturity means that strategic ambition is matched by governance controls, records, reserves, security, safeguards, and truthful public positioning.

#### 215.6 No Delegation of Core Oversight Duty Even Where Operations Are Delegated

The Board may delegate operational risk management to management, committees, officers, advisers, staff, vendors, or professional service providers, but it shall not delegate away its core oversight duty. Delegation may improve execution. It does not eliminate fiduciary responsibility.

Accordingly:

a) management may operate risk processes, but the Board must oversee material risk;\
b) the Audit and Risk Committee may review findings, but the Board must understand major institutional exposure;\
c) security personnel may manage technical controls, but the Board must oversee material cyber and privacy risk;\
d) safeguards functions may handle complaints, but the Board must oversee retaliation, protected participation, and serious safeguards failures;\
e) finance staff may prepare reports, but the Board must oversee solvency, reserves, restricted funds, and financial integrity; and\
f) counsel may advise on legal risk, but the Board must make fiduciary decisions.

The Board shall ask whether the Corporation’s risk systems are real, resourced, independent enough, and producing decisions. A delegated risk system that cannot reach the Board is not an adequate control system.

#### 215.7 Risk Register, Risk Ownership, and Board-Level Risk Map

GCRI US shall maintain a risk register or equivalent Board-level risk map. The register shall identify material risks, owners, severity, likelihood, controls, residual risk, trend, open actions, and escalation status.

The risk register shall include, as applicable:

a) risk category;\
b) risk description;\
c) affected constitutional principle or operational area;\
d) inherent risk;\
e) existing controls;\
f) control owner;\
g) residual risk;\
h) risk trend;\
i) incidents or near misses;\
j) corrective actions;\
k) Board or committee reporting route; and\
l) next review date.

The register shall not be an ornamental dashboard. It shall inform Board agendas, budget decisions, policy updates, committee workplans, executive performance review, funding decisions, and strategic planning.

#### 215.8 Risk Governance for the Nexus Public-Good Model

Because GCRI US operates within the Nexus public-good model, risk governance shall address risks that arise from evidence-to-capital interfaces, open public-good infrastructure, standards work, technical repositories, AI-enabled analysis, risk intelligence, membership systems, cross-border institutional cooperation, and finance-adjacent policy environments.

The Board shall ensure that risk controls prevent:

a) evidence work being misused as investment, insurance, lending, or procurement approval;\
b) standards drafts being marketed as certification before adoption;\
c) public-good technical assets being captured by private execution stacks;\
d) open-source infrastructure being released without security, license, and maintenance discipline;\
e) membership being used as endorsement;\
f) public-authority participation being overstated as government adoption;\
g) cross-entity coordination being misread as merger or agency;\
h) donor support shaping research outcomes or publication timing; and\
i) AI or data tools processing restricted information outside approved environments.

Nexus-aligned work requires stronger, not weaker, risk governance because its public value depends on institutional trust.

#### 215.9 Board Reporting Thresholds and Stop-the-Line Authority

GCRI US shall define Board reporting thresholds and stop-the-line authority for risks that require immediate pause, escalation, or protective action. Stop-the-line authority may be exercised by designated officers, control functions, committee chairs, or emergency governance actors where continuing an activity would create material harm.

Stop-the-line triggers may include:

a) suspected execution-side or regulated-activity breach;\
b) serious security or privacy incident;\
c) controlled-room breach;\
d) suspected fraud or restricted-fund misuse;\
e) retaliation or serious safeguards risk;\
f) public claim materially exceeding the record;\
g) unauthorized contract, funding, or public announcement;\
h) material conflict or related-party breach;\
i) serious record manipulation; or\
j) imminent public-good asset misuse.

Stop-the-line action shall be recorded, reviewed, and either lifted, narrowed, escalated, or converted into corrective action. No person shall be penalized for good-faith stop-the-line action taken to protect the Corporation.

#### 215.10 Interpretive Rule for Corporate Risk Governance and Board Oversight

This Section shall be interpreted to preserve a controlling proposition: the Board of GCRI US shall oversee a living, evidence-based risk governance system that identifies, classifies, reports, escalates, remediates, and learns from risks to mission lock, nonprofit integrity, financial control, safeguards, security, continuity, public claims, public-good assets, cross-entity separateness, and the non-execution perimeter.

Where ambiguity exists, the interpretation that better preserves risk taxonomy, risk appetite, Board-level oversight, control independence, KRI and KPI reporting, incident escalation, corrective-action tracking, strategic-risk integration, stop-the-line authority, and non-delegation of core fiduciary oversight shall prevail unless a contrary result is required by law.

### 216. Relationship Between Corporate Governance and Other Institutional Surfaces (GCRI United States)

#### 216.1 Corporate Governance Distinct From Councils, Programs, Academy, Observatory, Platforms, and Public Narrative

Corporate governance of GCRI US shall remain distinct from councils, programs, working groups, Academy activities, observatory functions, research initiatives, technical platforms, public campaigns, member convenings, stakeholder consultations, media narratives, and external partnership activity. These institutional surfaces may be important to mission delivery, public legitimacy, learning, standards development, and ecosystem-building, but they shall not become corporate governing organs unless the governing instruments expressly create such authority.

Accordingly:

a) a council may advise, consult, deliberate, recommend, or contribute expertise, but it shall not exercise Board authority unless expressly delegated and legally permitted;\
b) a program may deliver public-benefit activity, but it shall not create corporate commitments outside approved authority;\
c) an Academy may train, credential, convene, or build capacity, but it shall not create officer, trustee, member, or certification authority by implication;\
d) an observatory may monitor, analyze, publish, or support evidence work, but it shall not become a fiduciary or execution body;\
e) a technical platform may support governance, evidence, records, or public-good infrastructure, but it shall not decide institutional authority;\
f) a public campaign may communicate mission, but it shall not amend governance instruments or create public-authority endorsement; and\
g) a partner ecosystem may collaborate, but it shall not govern GCRI US.

Corporate authority must remain traceable to the Articles, Bylaws, Board, membership authority where applicable, officers, committees, written delegations, and recorded instruments.

#### 216.2 No Program Success, Technical Sophistication, or External Prestige Alters Governance Allocation

No program success, technical sophistication, public visibility, donor recognition, media coverage, academic prestige, government engagement, multilateral participation, or external endorsement shall alter the allocation of corporate authority within GCRI US. Institutional credibility may increase through performance, but corporate power shall not migrate through reputation.

This rule is essential because GCRI US may build high-value work across systemic risk, resilience, evidence infrastructure, AI-enabled analysis, public-good standards, risk intelligence, and cross-border cooperation. Such work may attract public attention and participation by senior experts, public authorities, private institutions, universities, civil society, and technical communities. None of that attention shall create governance authority unless formally recorded.

A highly successful program shall not become a corporate organ. A widely used technical framework shall not become a substitute for Board approval. A major partner shall not acquire reserved-matter influence. A donor-funded initiative shall not gain governance preference. A prominent public event shall not create institutional adoption of positions not approved through proper authority.

The Corporation shall distinguish achievement from authority. Achievement strengthens the case for trust. It does not replace governance.

#### 216.3 Board Oversight of, But Not Substitution For, Specialist Functions

The Board shall oversee specialist functions without substituting itself for those functions in ordinary course. Specialist functions may include finance, audit, legal, safeguards, security, privacy, technical stewardship, repository governance, publication review, membership administration, Registry administration, communications integrity, and program management.

The Board shall ensure that specialist functions are properly mandated, resourced, independent where needed, and capable of escalation. The Board shall not casually perform technical, operational, or staff functions that belong to management or specialist roles, except where emergency action, investigation, or governance failure requires temporary intervention.

The correct relationship is:

a) specialist functions produce evidence, analysis, recommendations, controls, and implementation;\
b) management coordinates operations within delegated authority;\
c) committees review specialized matters and prepare Board decisions;\
d) officers preserve corporate functions such as records and finance; and\
e) the Board governs through oversight, approval, challenge, reserved decisions, and accountability.

The Board shall ask whether specialist work is reliable, independent, aligned, lawful, and properly recorded. It shall not confuse oversight with micromanagement or abdication.

#### 216.4 Clear Routing and Non-Substitution Between Board, Secretariat, Integrity Functions, and Cross-Entity Interfaces

GCRI US shall maintain clear routing between the Board, Secretariat, governance-spine functions, committees, officers, management, councils, programs, and cross-entity interfaces. Each matter shall be routed to the organ or function with lawful authority and competence to handle it.

Routing discipline shall ensure that:

a) Board reserved matters go to the Board;\
b) committee matters go to the proper committee;\
c) officer matters go to the relevant officer;\
d) records matters go to the Secretary or records function;\
e) financial-control matters go to the Treasurer, finance function, Audit and Risk Committee, or Board as appropriate;\
f) safeguards and whistleblower matters go to protected channels;\
g) security and privacy matters go to security, privacy, or incident-response channels;\
h) member and Registry matters go to membership and Registry authorities;\
i) communications and public-claims matters go to approved communications and Secretary review channels; and\
j) cross-entity matters are routed separately through each entity’s lawful authority.

No function shall be used as a substitute for another where doing so would bypass authority, weaken independence, suppress reporting, or obscure responsibility. The Secretariat shall not become the Board. A committee shall not become management. A council shall not become a fiduciary organ. A cross-entity meeting shall not become approval by GCRI US.

#### 216.5 No Confusion Between Corporate Authority and Federation Interoperability

GCRI US may participate in federation, interoperability, standards alignment, shared public-good architecture, cross-entity coordination, and Nexus-aligned institutional cooperation. Such interoperability shall not be confused with corporate merger, agency, delegated authority, joint control, shared liability, or unified governance unless expressly documented and lawfully approved.

Federation interoperability may include:

a) shared terminology;\
b) interoperable standards;\
c) common templates;\
d) aligned public-good principles;\
e) coordinated workplans;\
f) reciprocal learning;\
g) shared technical patterns;\
h) cross-reference of public documents; and\
i) coordinated participation in global risk and resilience work.

Corporate authority remains entity-specific. GCRI US does not govern GCRI Canada, GRF, GRA, protocol authorities, host institutions, national entities, regional bodies, members, or execution-side actors unless a lawful instrument expressly provides a defined relationship. Likewise, those entities do not govern GCRI US by alignment, shared mission, common personnel, or public association.

Where a document, event, platform, or public statement involves more than one entity, it shall identify capacity, approval route, legal separateness, public-description limits, and any non-agency disclaimer required.

#### 216.6 Corporate Governance Interface With GCRI Canada, GRF, GRA, and Nexus-Aligned Entities

The corporate governance interface between GCRI US and GCRI Canada, GRF, GRA, protocol authorities, host institutions, national nodes, regional bodies, and other Nexus-aligned entities shall preserve separateness while enabling coherent cooperation. GCRI US may coordinate with those bodies on public-good research, standards literacy, evidence infrastructure, policy development, membership learning, capacity-building, publications, and shared governance patterns, but such coordination shall not collapse corporate identity or authority.

Any material interface shall be governed by an appropriate instrument, such as a memorandum of understanding, participation agreement, shared-services agreement, data-handling agreement, publication protocol, joint-statement approval record, or Board-approved inter-entity instrument.

Such instruments shall specify:

a) parties and capacities;\
b) purpose and scope;\
c) authority of each entity;\
d) what is shared and what remains separate;\
e) cost allocation;\
f) records custody;\
g) data, privacy, security, and access rules;\
h) publication and public-claims rules;\
i) conflict and related-party controls;\
j) termination and exit rights; and\
k) non-agency, non-merger, and non-execution limitations.

The Board shall review inter-entity instruments that materially affect governance, finance, risk, public-good assets, records, or public meaning.

#### 216.7 Relationship Between Corporate Governance and Public-Good Technical Architecture

GCRI US may steward, support, or contribute to public-good technical architecture, open-source infrastructure, evidence systems, data schemas, AI governance tools, risk intelligence methods, standards templates, and repository-based assets. Corporate governance shall determine the authority under which such assets are adopted, released, maintained, licensed, corrected, archived, or retired.

Technical architecture shall not govern itself outside institutional authority. A repository maintainer, technical steward, working group, developer community, or external contributor may have technical responsibility, but shall not have corporate authority unless recorded. Public-good technical work shall therefore be linked to:

a) approved mission purpose;\
b) repository governance rules;\
c) license and intellectual-property discipline;\
d) security review;\
e) publication and release controls;\
f) privacy and data-handling controls;\
g) correction and supersession processes;\
h) conflict and sponsor-influence controls; and\
i) Board or committee oversight where the asset is material.

The more consequential the technical asset, the stronger the governance record must be. A public-good rail, standard, schema, or evidence tool can create reliance even where it is open source. Governance must therefore accompany technical release.

#### 216.8 Relationship Between Corporate Governance and Membership, Registry, and Council Systems

Corporate governance shall sit above and coordinate with membership, Registry, and council systems without collapsing into them. Members may provide legitimacy, resources, expertise, and participation. The Registry may authorize service roles and access. Councils may provide structured deliberation and sectoral or regional expertise. None of these systems shall override Board fiduciary authority or corporate reserved matters.

The Board shall ensure that:

a) membership rights are created only by recorded instruments;\
b) Registry authorization does not create Board or officer authority unless expressly linked;\
c) council participation does not create governance ownership;\
d) member-service offerings do not imply certification, endorsement, or routeability;\
e) council outputs are adopted as corporate positions only through proper authority;\
f) public rosters accurately distinguish members, observers, advisers, trustees, officers, and Registry persons; and\
g) member or council pressure does not compromise fiduciary judgment.

The membership and Registry systems help the institution scale safely. They shall not become informal political systems that displace corporate governance.

#### 216.9 Relationship Between Corporate Governance and Public Communications

Public communications shall follow corporate governance. They shall not create corporate governance. GCRI US may publish statements, reports, webpages, campaigns, announcements, consultation submissions, member communications, social media posts, and public narratives. Such communications must align with approved authority, public-description controls, records, and non-execution discipline.

Communications shall not:

a) announce unapproved Board decisions;\
b) imply funding not secured;\
c) present draft policies as adopted;\
d) list nominees as trustees before appointment;\
e) describe members as partners or certified entities without authority;\
f) imply government, regulator, Indigenous, community, or institutional endorsement beyond the record;\
g) claim execution-side capacity;\
h) merge GCRI US with related entities; or\
i) overstate maturity, capacity, or deployment status.

Where public communication diverges from the authoritative record, the record controls and the communication shall be corrected. The Board shall treat repeated public-claims drift as a governance risk.

#### 216.10 Relationship Between Corporate Governance and Funding, Sponsorship, and Resource Mobilization

Funding, sponsorship, donations, grants, memberships, service revenues, in-kind support, and resource mobilization shall remain subordinate to corporate governance. Money shall support mission. It shall not purchase authority, access, narrative control, standard-setting influence, publication control, procurement advantage, Board seats, or exceptions to safeguards.

Corporate governance shall ensure that funding arrangements:

a) are approved at the correct authority level;\
b) preserve nonprofit status;\
c) avoid improper private benefit;\
d) distinguish restricted and unrestricted funds;\
e) avoid sponsor control of outputs;\
f) avoid donor overclaim;\
g) preserve publication independence;\
h) protect public-good assets;\
i) avoid execution-side compensation structures; and\
j) are accurately described in public materials.

The Corporation may be ambitious in resource mobilization, but never ambiguous in authority. Financial support is welcome only where it is compatible with mission lock and governance integrity.

#### 216.11 Relationship Between Corporate Governance and Legal / Regulatory Interfaces

GCRI US may engage with public authorities, regulators, policymakers, standards bodies, multilateral institutions, universities, civil-society groups, and private-sector actors. Corporate governance shall control how those engagements are authorized, documented, described, and limited.

Where engagement involves a legal or regulatory interface, the Corporation shall clarify:

a) whether it is providing public-good research, policy input, consultation, education, or technical information;\
b) whether it is speaking officially or through an individual expert;\
c) whether lobbying, advocacy, charitable, nonprofit, or tax restrictions apply;\
d) whether public authority participation is official, observer-based, technical, personal, or institutional;\
e) whether public records, ethics, procurement, gifts, or conflict rules apply;\
f) whether any statement could be misread as regulatory approval; and\
g) whether counsel review is required.

Corporate governance shall ensure that engagement remains lawful, accurate, non-partisan where required, non-procurement-distorting, and non-executionary.

#### 216.12 Interpretive Rule for Relationship Between Corporate Governance and Other Institutional Surfaces

This Section shall be interpreted to preserve a controlling proposition: GCRI US corporate governance remains the authority map for the Corporation even when the institution operates through councils, programs, Academy activity, observatories, platforms, public campaigns, technical repositories, membership systems, cross-entity cooperation, funding relationships, and public narratives.

Where ambiguity exists, the interpretation that better preserves:

a) corporate authority over program informality;\
b) Board oversight without role confusion;\
c) clear routing among Board, Secretariat, committees, officers, integrity functions, and management;\
d) legal separateness from other Nexus-aligned entities;\
e) governance control of public-good technical architecture;\
f) membership and Registry non-substitution;\
g) public-claims accuracy;\
h) funding subordination to mission; and\
i) lawful legal and regulatory engagement

shall prevail unless a contrary result is required by law.

### 217. Corporate Filings, Legal Compliance Calendar, and Regulatory Discipline (GCRI United States)

#### 217.1 Continuous Legal Compliance as a Board-Level Obligation

GCRI US shall maintain continuous legal compliance across all applicable federal, state, and local requirements. Legal compliance shall not be treated as a periodic filing exercise or an outsourced administrative function. It is a Board-level fiduciary obligation and a core condition of lawful existence, nonprofit status, and institutional credibility.

The Board shall ensure that:

a) the Corporation remains in good standing in its state of incorporation;\
b) all required filings are made accurately and on time;\
c) nonprofit tax status is preserved and not jeopardized by activities, funding structures, or public claims;\
d) financial, governance, and operational records support all filings; and\
e) compliance responsibility is clearly assigned, monitored, and verified.

Failure to maintain compliance may result in penalties, loss of nonprofit status, reputational damage, loss of funding, legal exposure, and disruption of operations. These risks are unacceptable for a public-good institution.

#### 217.2 Corporate Compliance Calendar and Filing Discipline

GCRI US shall maintain a formal compliance calendar covering all statutory, regulatory, contractual, governance, and operational filing obligations. The compliance calendar shall be treated as a living system, not a static checklist.

The compliance calendar shall include, as applicable:

a) state annual reports and corporate renewals;\
b) federal tax filings (including IRS Form 990 or applicable equivalents);\
c) state tax or charitable registration filings, if required;\
d) payroll, employment, and benefits filings;\
e) audit, review, or financial reporting deadlines;\
f) insurance renewals and disclosures;\
g) grant reporting obligations;\
h) donor-restricted reporting obligations;\
i) Board and committee meeting cadence and records requirements;\
j) policy review cycles;\
k) delegation and signature matrix review cycles;\
l) access and security review cycles; and\
m) cross-entity reporting or coordination obligations where applicable.

Each calendar item shall identify:

i) responsible person or function;\
ii) due date;\
iii) preparation timeline;\
iv) required inputs;\
v) approval authority;\
vi) submission method; and\
vii) record location.

Missed deadlines shall trigger escalation and corrective review. A pattern of missed deadlines shall be treated as a governance failure.

#### 217.3 Assignment of Compliance Responsibility and Verification

The Board shall assign responsibility for maintaining the compliance calendar and ensuring completion of filings. This responsibility may be held by the Secretary, Treasurer, executive leadership, finance function, or a designated compliance officer, depending on organizational structure.

However:

a) assignment of responsibility does not remove Board oversight;\
b) the Board shall receive confirmation of completion for material filings;\
c) the Board shall review high-risk filings or filings affecting nonprofit status, financial reporting, or public claims;\
d) no filing shall be submitted where material uncertainty exists without appropriate review; and\
e) compliance records shall be preserved in the authoritative repository.

Verification may include internal checklists, officer certification, external accountant review, legal review, or audit confirmation.

#### 217.4 Accuracy, Completeness, and Consistency of Filings

All filings made by or on behalf of GCRI US shall be accurate, complete, and consistent with corporate records, financial records, Board resolutions, delegation authority, and public claims.

The Corporation shall ensure that:

a) financial figures reconcile with internal accounting and bank records;\
b) governance descriptions match the actual Board, officer, and committee structure;\
c) compensation disclosures, if required, are accurate;\
d) related-party disclosures are complete;\
e) program descriptions reflect actual activity;\
f) public-benefit narrative is truthful and not overstated;\
g) cross-entity relationships are described accurately and without implying merger or agency; and\
h) restricted funds and grants are properly classified and reported.

No filing shall be used to create a narrative that differs from the underlying record. Regulatory filings are not marketing documents. They are legal statements.

#### 217.5 Interface With External Accountants, Auditors, and Legal Counsel

GCRI US may engage external accountants, auditors, tax advisers, and legal counsel to support compliance, reporting, and governance. Such professionals shall support, but not replace, internal accountability.

The Board shall ensure that:

a) professionals are appropriately qualified and independent where required;\
b) scope of work is clearly defined;\
c) management provides complete and accurate information;\
d) material findings are escalated to the Board;\
e) recommendations are considered and acted upon; and\
f) engagement does not create dependency that weakens internal controls.

External professionals shall not be used to legitimize weak records, unclear authority, or unsupported claims. Their work depends on the integrity of the Corporation’s internal systems.

#### 217.6 Legal Compliance and Non-Execution Boundary Protection

Legal compliance shall include protection of the non-execution boundary. GCRI US shall not enter regulated activities such as insurance underwriting, securities issuance, lending, brokerage, custody, settlement, payment processing, or transaction routing.

Compliance controls shall ensure that:

a) contracts do not create regulated obligations;\
b) public statements do not imply regulated capacity;\
c) funding arrangements do not resemble investment or underwriting activity;\
d) partnerships do not create execution authority;\
e) technical platforms are not used as transaction systems; and\
f) cross-entity arrangements preserve separation between public-good governance and regulated delivery stacks.

Where a proposed activity raises regulatory ambiguity, the Corporation shall seek legal review before proceeding.

#### 217.7 Recordkeeping and Audit Trail for Filings and Compliance Actions

All filings, submissions, renewals, certifications, and compliance actions shall be recorded and preserved. The Corporation shall maintain an audit trail sufficient to demonstrate:

a) what was filed;\
b) when it was filed;\
c) by whom it was prepared and approved;\
d) what authority supported the filing;\
e) what supporting documents were used; and\
f) where the authoritative copy is stored.

The audit trail shall support internal review, external audit, regulatory inquiry, donor verification, and Board oversight. Records shall not depend on personal email, local storage, or undocumented submission processes.

#### 217.8 Correction, Amendment, and Late Filing Procedures

Where a filing is found to be inaccurate, incomplete, late, or inconsistent with the authoritative record, GCRI US shall take corrective action. Correction shall be prompt, transparent to the appropriate authority, and properly recorded.

Correction procedures may include:

a) filing an amended return or report;\
b) notifying the relevant authority;\
c) correcting internal records;\
d) reviewing root cause;\
e) updating controls; and\
f) reporting the issue to the Board or relevant committee.

Late filings shall be escalated and explained. Repeated late filings shall trigger governance review.

#### 217.9 Compliance Culture and Training

GCRI US shall maintain a culture of compliance supported by training, clarity of responsibility, accessible systems, and Board reinforcement. Trustees, officers, executives, and relevant staff shall understand:

a) the importance of compliance;\
b) their role in maintaining it;\
c) the consequences of failure; and\
d) the relationship between compliance, public trust, and mission integrity.

Compliance shall not be seen as a barrier to innovation. It is the condition that allows innovation to be trusted.

#### 217.10 Interpretive Rule for Corporate Filings, Legal Compliance Calendar, and Regulatory Discipline

This Section shall be interpreted to preserve a controlling proposition: GCRI US shall maintain continuous, accurate, and verifiable legal compliance through a structured compliance calendar, clear assignment of responsibility, Board oversight, accurate filings, preserved records, and disciplined correction processes, while protecting its nonprofit status and non-execution boundary.

Where ambiguity exists, the interpretation that better preserves:

a) timely and accurate filings;\
b) Board-level oversight of compliance;\
c) integrity of financial and governance disclosures;\
d) auditability of compliance actions;\
e) separation from regulated activity; and\
f) continuous improvement of compliance systems

shall prevail unless a contrary result is required by law.

### 218. Constitutional Effect of Part IX (GCRI United States)

#### 218.1 Part IX as the Governing Fiduciary and Corporate Governance Map for GCRI US

Part IX shall constitute the governing fiduciary and corporate governance map for GCRI US. It shall control how the Corporation’s membership authority, Board, trustees, officers, committees, executive leadership, governance-spine offices, delegated actors, records systems, risk functions, emergency authorities, and corporate instruments are constituted, authorized, limited, reviewed, corrected, and made effective.

Part IX shall govern:

a) corporate authority and reserved matters;\
b) Board fiduciary oversight;\
c) trustee and officer duties;\
d) membership authority where formal member rights exist;\
e) committee structure and delegated mandates;\
f) executive-management interface;\
g) records, notices, written authorities, and authoritative instruments;\
h) financial stewardship and Treasurer functions;\
i) conflict-of-interest, recusal, whistleblowing, safeguards, and integrity escalation;\
j) emergency governance and continuity;\
k) corporate risk governance;\
l) legal compliance and filing discipline; and\
m) the relationship between corporate governance and all other institutional surfaces.

Part IX shall be read as an integrated control system. No section shall be read in isolation to weaken another section. The Board’s fiduciary role, the Secretary’s records function, the Treasurer’s financial stewardship, the executive’s management authority, the committees’ specialist review, the membership authority’s formal rights, and the governance-spine functions’ protected escalation duties are mutually reinforcing parts of one corporate architecture.

#### 218.2 No Practice, Personality, or Informal Arrangement May Override Part IX

No practice, personality, custom, founding role, donor relationship, sponsor expectation, member preference, executive habit, technical centrality, public prestige, institutional familiarity, emergency narrative, or informal arrangement may override Part IX.

Accordingly:

a) a founder may contribute vision but does not govern outside recorded authority;\
b) a donor may support mission but does not acquire governance rights;\
c) a sponsor may fund activity but does not control agenda, publication, or standards direction;\
d) a member may participate but does not acquire ownership or Board authority;\
e) an executive may manage but does not become the fiduciary apex;\
f) a committee may review but does not replace the Board unless lawful delegation expressly permits action;\
g) a technical team may develop public-good infrastructure but does not create corporate authority; and\
h) a public statement may communicate an approved position but does not create approval.

Where informal practice has drifted from Part IX, the practice shall be corrected. The existence of a practice is not proof of validity.

#### 218.3 No Office, Committee, Executive Function, or Program Surface May Claim Unrecorded Authority

No office, committee, executive function, program, council, Academy activity, observatory, platform, working group, public campaign, technical repository, external partnership, or cross-entity interface may claim unrecorded authority.

Authority must be traceable to:

a) law;\
b) Articles;\
c) Bylaws;\
d) Board resolution;\
e) member action where applicable;\
f) committee charter;\
g) officer appointment;\
h) executive delegation;\
i) signature matrix;\
j) written authority; or\
k) other approved corporate instrument.

Where authority cannot be traced, the action shall be treated as unauthorized, advisory, provisional, voidable, subject to ratification, or without effect, depending on law and institutional risk. GCRI US shall not allow unrecorded authority to mature into accepted governance through silence.

#### 218.4 Ambiguity Resolves Toward Stronger Fiduciary Discipline, Clearer Authority Mapping, and Greater Record Integrity

Any ambiguity under Part IX shall resolve toward stronger fiduciary discipline, clearer authority mapping, narrower implied authority, greater record integrity, stronger conflict controls, safer participation, stricter non-execution discipline, and better protection of public-good assets.

This interpretive rule applies where ambiguity exists concerning:

a) whether a matter is reserved to the Board;\
b) whether a member vote has binding effect;\
c) whether an officer may sign or approve an act;\
d) whether management authority is sufficient;\
e) whether a committee may decide or only recommend;\
f) whether a conflict requires recusal;\
g) whether a public statement has been approved;\
h) whether a delegation has expired;\
i) whether emergency authority is available;\
j) whether a cross-entity instrument binds GCRI US; and\
k) whether a technical, programmatic, or membership action has corporate effect.

Ambiguity shall never be used to expand authority. Authority may be expanded only through the competent organ, proper procedure, and authoritative record.

#### 218.5 Failure to Respect Part IX as a Constitutional Governance Failure

A material failure to respect Part IX shall constitute a constitutional governance failure, not a minor procedural defect. Such failures may create unauthorized authority, invalid decisions, financial exposure, private benefit, regulatory confusion, unsafe participation, record unreliability, donor capture, public overclaim, non-execution boundary breach, or loss of public trust.

Material failures include:

a) Board reserved matters decided outside Board authority;\
b) trustee, officer, or executive action without recorded delegation;\
c) false or incomplete minutes, resolutions, filings, or public statements;\
d) failure to disclose or manage conflicts;\
e) committee action beyond charter;\
f) executive suppression of Board reporting;\
g) emergency powers used for non-emergency governance change;\
h) financial commitments outside thresholds;\
i) public-good assets transferred or enclosed without authority;\
j) retaliation against protected reporters;\
k) uncontrolled cross-entity authority; and\
l) failure to preserve corporate records.

Where such failure occurs, GCRI US shall investigate, correct records, cure or void affected acts where appropriate, impose restrictions, notify affected persons where required, revise controls, and take accountability measures proportionate to the breach.

#### 218.6 Binding Effect on Future Corporate Governance Design

Part IX shall bind future corporate governance design unless lawfully amended. Future bylaws, schedules, policies, committee charters, delegation matrices, membership instruments, executive mandates, inter-entity agreements, public-good infrastructure arrangements, funding instruments, and emergency procedures shall be drafted consistently with this Part.

Future design shall preserve:

a) formal corporate organs;\
b) fiduciary Board primacy;\
c) defined membership authority;\
d) written officer and executive authority;\
e) committee charter discipline;\
f) records-first validity;\
g) reserved-matter control;\
h) anti-capture safeguards;\
i) protected reporting;\
j) financial stewardship;\
k) non-execution boundary protection; and\
l) corporate separateness.

Innovation in governance systems may be adopted where it strengthens accountability, speed, transparency, resilience, and public trust. It shall not be adopted where it weakens legal authority, record integrity, fiduciary control, safeguards, or the firewall between public-good stewardship and execution-side activity.

#### 218.7 Closing Rule of Part IX

Part IX confirms that GCRI US shall be governed as a serious nonprofit public-good corporation: fiduciary in authority, precise in records, disciplined in finance, independent in judgment, protected in reporting, cautious at regulated perimeters, safe in participation, and resilient under stress.

The controlling rule is therefore:

No authority without record. No decision without procedure. No governance without fiduciary duty. No growth without controls. No public-good stewardship without independence. No emergency without review. No title without limits. No participation without safeguards. No corporate act that compromises mission lock, nonprofit integrity, public trust, or the non-execution boundary.

<br>

<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.therisk.global/organization/organization/governance/charter-us/ix.-activities.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
