XIX. COMPLIANCE
19.1 Legal Compliance Purpose
19.1.1 Legal Compliance as a Charter-Level Institutional Duty. 19.1.1(a) Legal compliance shall be a Charter-level institutional duty of GCRI Canada and shall apply to all governance, operations, programs, research, evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, Open Technical Baselines, data governance, AI governance, cybersecurity, compute environments, public-safe publication, public authority learning, Academy materials, dashboards, maps, controlled rooms, clean rooms, grants, donations, sponsorships, in-kind contributions, contracts, procurement, fiscal controls, employment, contractor relationships, volunteer participation, public claims, and Nexus interfaces.
19.1.1(b) Legal compliance shall be understood as a constitutional operating discipline through which GCRI Canada preserves its Canadian public-benefit, nonprofit, non-share, non-distributing, non-executing, evidence-and-methods, public-good technical institution character.
19.1.1(c) Legal compliance shall not be treated as a narrow administrative function. It shall be treated as an institutional safeguard protecting lawful authority, public trust, legal separateness, mission lock, non-execution, data rights, public authority boundaries, finance boundaries, cybersecurity, protected knowledge, community safeguards, anti-inurement, and correctionability.
19.1.1(d) Compliance duties shall apply whether the relevant obligation arises from statute, regulation, common law, corporate instrument, contract, grant, donor restriction, sponsorship term, public authority arrangement, platform term, professional boundary, data obligation, research protocol, or Board-approved governance instrument.
19.1.1(e) The controlling rule shall be that GCRI Canada’s public-benefit mission must be pursued through lawful institutional conduct, proper records, appropriate review, and correction where required.
19.1.2 Legal Compliance as Corporate, Nonprofit, Tax, Charity Where Applicable, Privacy, Data Protection, AI, Cybersecurity, Employment, Contractor, Volunteer, Research, Ethics, IP, Contract, Grant, Sponsorship, Public Authority, Sanctions, Export-Control, Competition, Professional, Publication, and Public-Safe Compliance. 19.1.2(a) Legal compliance shall include corporate, nonprofit, tax, charitable-status-compatibility where applicable, privacy, data protection, AI, cybersecurity, employment, contractor, volunteer, research, ethics, IP, contract, grant, sponsorship, public authority, sanctions, export-control, competition, professional-boundary, publication, public-safe, accessibility, human rights, consumer-facing where applicable, and public-benefit compliance.
19.1.2(b) Corporate compliance shall preserve GCRI Canada’s lawful existence, governing instruments, Board authority, officer authority, statutory records, filings, registered office, member records where applicable, meeting discipline, resolutions, delegations, and legal capacity.
19.1.2(c) Nonprofit, tax, and charitable-status-compatibility compliance shall preserve GCRI Canada’s nonprofit and public-benefit character, anti-inurement, private benefit discipline, lawful receipting, fundraising accuracy, restricted fund compliance, grant compliance, public reporting, and status-compatible activities.
19.1.2(d) Privacy, data protection, AI, cybersecurity, research, ethics, and public-safe publication compliance shall preserve lawful basis, purpose limitation, data minimization, rights-bearing data safeguards, Public Authority Data controls, sovereign data controls, protected knowledge safeguards, secure systems, responsible AI use, human review, review gates, correction, withdrawal, and safe release.
19.1.2(e) IP, contract, grant, sponsorship, procurement, sanctions, export-control, competition, professional-boundary, and finance-boundary compliance shall preserve lawful collaboration, technical asset stewardship, anti-capture, non-execution, no financial-services drift, no improper transfer, and no market or public authority overclaim.
19.1.2(f) The controlling rule shall be that legal compliance must cover every legal surface through which institutional authority, money, data, technology, people, publications, or public meaning may move.
19.1.3 Legal Compliance as Mission-Enabling, Not Mission-Blocking. 19.1.3(a) Legal compliance shall be mission-enabling and shall not be misdescribed as an obstacle to public-benefit work.
19.1.3(b) Compliance exists to allow GCRI Canada to conduct public-benefit evidence work, technical work, research, public authority learning, public-safe publication, and Nexus interoperability in a manner that is lawful, trustworthy, durable, correctionable, and safe.
19.1.3(c) Officers, Directors, staff, contractors, fellows, advisors, councils, Working Groups, sponsors, providers, donors, hosts, universities, communities, and participants shall not treat legal compliance as optional, ceremonial, after-the-fact, or subordinate to speed, funding, visibility, media opportunity, technical opportunity, sponsor preference, provider preference, public authority proximity, or capital-reader interest.
19.1.3(d) Where legal review narrows, delays, conditions, redirects, or refuses an activity, such action shall be understood as preserving institutional capacity and public trust, not as weakening mission.
19.1.3(e) The controlling rule shall be that lawful execution of the mission is stronger than fast action that later requires correction, withdrawal, or legal repair.
19.1.4 Legal Compliance as Distinct From Regulatory Authority by GCRI Canada. 19.1.4(a) Legal compliance by GCRI Canada shall be distinct from regulatory authority by GCRI Canada.
19.1.4(b) GCRI Canada may comply with law, interpret legal obligations for its own conduct, seek legal advice, apply policies, train participants, structure lawful interfaces, and maintain compliance records without becoming a regulator, public authority, compliance certifier, professional regulator, permitting body, enforcement body, procurement authority, public finance authority, or official guidance issuer.
19.1.4(c) Legal compliance materials, public authority learning materials, technical baselines, reports, dashboards, maps, Academy materials, and controlled-room materials shall not be described as regulatory guidance, safe harbor, permit, approval, compliance determination, enforcement position, procurement requirement, funding approval, public finance approval, or public authority decision by GCRI Canada.
19.1.4(d) Where GCRI Canada provides legal-boundary or compliance-oriented education, such materials shall remain educational, public-safe, and non-authoritative unless a competent public or legal authority separately creates legal effect.
19.1.4(e) The controlling rule shall be that GCRI Canada must comply with law without pretending to make law.
19.1.5 Legal Compliance as Applicable to Governance, Programs, Research, Evidence, Methods, Public-Good Software, Technical Baselines, Data, AI, Compute, Cyber, Observatory Methods, Truth Engine Methods, Academy Materials, Public Authority Learning, Publications, Dashboards, Maps, Rooms, Grants, Sponsorships, Contracts, and Nexus Interfaces. 19.1.5(a) Legal compliance shall apply to governance, programs, research, evidence, methods, public-good software, technical baselines, data, AI, compute, cyber, Observatory Methods, Truth Engine Methods, Academy materials, public authority learning, publications, dashboards, maps, rooms, grants, sponsorships, contracts, procurement, fiscal governance, employment, contractor relationships, participation, and Nexus interfaces.
19.1.5(b) Governance compliance shall ensure that decisions, delegations, committees, councils, conflicts, records, corrections, and Board-reserved matters follow applicable law, articles, Bylaw, Charter, policies, and proper authority.
19.1.5(c) Technical and research compliance shall ensure lawful handling of data, AI systems, compute, software, repositories, IP, export-controlled technology, cyber-sensitive materials, public-safe releases, research ethics, human subjects where applicable, protected knowledge, and community safeguards.
19.1.5(d) Program, publication, dashboard, map, and room compliance shall ensure public-safe release, access controls, disclaimers, public authority boundary language, finance-boundary language, no certification by default, no public warning by default, no emergency command, and correction paths.
19.1.5(e) Fiscal, grant, sponsorship, contract, and Nexus-interface compliance shall ensure lawful authority, anti-inurement, sponsor non-control, provider neutrality, procurement neutrality, GRA role separation, GRF role separation, Protocol Authority separation, shared-record boundaries, and legal separateness.
19.1.5(f) The controlling rule shall be that compliance follows the activity, not the department label.
19.1.6 Legal Compliance as Applicable Across Canadian, Provincial, Territorial, Indigenous, Local, Foreign, International, Contractual, Public Authority, Donor, Grantor, and Platform Obligations Where Applicable. 19.1.6(a) Legal compliance shall apply across Canadian federal, provincial, territorial, Indigenous, local, foreign, international, contractual, public authority, donor, grantor, sponsor, provider, host, university, platform, repository, cloud, software, data, AI, cybersecurity, and Nexus-interface obligations where applicable.
19.1.6(b) Canadian legal obligations shall be assessed in light of GCRI Canada’s legal status, registered jurisdiction, operating locations, participants, data locations, public authority interfaces, employment or contractor relationships, tax status, corporate filings, privacy obligations, research contexts, and public-facing activities.
19.1.6(c) Provincial, territorial, municipal, Indigenous, community, and local contexts shall be respected where GCRI Canada’s work affects data, land, knowledge, public authorities, public health, emergency management, infrastructure, education, community participation, cultural materials, protected knowledge, or public-safe mapping.
19.1.6(d) Foreign and international obligations may arise through cross-border funding, data transfers, cloud services, compute access, research collaboration, sanctions, export controls, contracts, foreign participants, platform terms, or Nexus interfaces, and shall be reviewed where material.
19.1.6(e) The controlling rule shall be that legal compliance shall be localized to the applicable obligation while preserving Nexus interoperability and GCRI Canada’s Canadian legal identity.
19.1.7 Legal Compliance as a Board, Officer, Committee, Staff, Contractor, Fellow, Advisor, Participant, Provider, Sponsor, Donor, Host, and Partner Responsibility. 19.1.7(a) Legal compliance shall be a responsibility of the Board, Officers, committees, staff, contractors, fellows, advisors, council participants, Working Group participants, members where applicable, participants, providers, sponsors, donors, funders, grantors, hosts, universities, partners, Public Authorities where participating under recorded terms, and Nexus interface actors according to their roles.
19.1.7(b) The Board shall oversee legal compliance as part of fiduciary stewardship, mission lock, risk governance, internal controls, public trust, records discipline, correctionability, and institutional continuity.
19.1.7(c) Officers shall implement legal compliance through delegated authority, policies, procedures, controls, training, escalation, records, correction, and Board reporting.
19.1.7(d) Committees, councils, Working Groups, fellows, advisors, contractors, and participants shall comply with role-specific legal obligations, confidentiality, data rules, AI rules, cybersecurity rules, public claims rules, public authority boundaries, finance boundaries, protected knowledge safeguards, and correction duties.
19.1.7(e) Sponsors, donors, funders, providers, hosts, universities, and partners shall comply with recorded terms, public claims limits, data obligations, IP obligations, confidentiality, no-control rules, no-overclaim rules, and correction obligations.
19.1.7(f) The controlling rule shall be that legal compliance is shared as duty, but authority to decide legal matters remains limited to proper roles and records.
19.1.8 Legal Compliance as Records-Valid, Risk-Based, Escalation-Aware, and Correctionable. 19.1.8(a) Legal compliance shall be records-valid, risk-based, escalation-aware, and correctionable.
19.1.8(b) Records-valid compliance requires that material legal approvals, reviews, advice, decisions, exceptions, filings, contracts, consents, restrictions, notices, incidents, corrections, and closeouts be recorded in appropriate registers or repositories.
19.1.8(c) Risk-based compliance requires that legal effort be proportionate to likelihood, impact, public trust consequence, data sensitivity, Public Authority involvement, finance-boundary risk, cross-border risk, controlled-technology risk, participant vulnerability, protected knowledge exposure, and public-safe release risk.
19.1.8(d) Escalation-aware compliance requires timely escalation where ambiguity, regulated-perimeter risk, public harm risk, legal uncertainty, conflict-of-law risk, public authority risk, finance risk, data risk, AI risk, cybersecurity risk, protected knowledge risk, or institutional trust risk exists.
19.1.8(e) Correctionable compliance requires that legal errors, noncompliance, overclaims, stale materials, invalid approvals, unauthorized acts, unsafe releases, and boundary breaches be corrected, superseded, withdrawn, retracted, disclosed where required, and learned from.
19.1.8(f) The controlling rule shall be that legal compliance must be capable of being proven, escalated, and corrected.
19.1.9 Legal Compliance as Requiring Legal Review Where Material Ambiguity, Regulated-Perimeter Risk, Cross-Border Risk, Public Authority Risk, Finance Risk, Controlled Technology Risk, or Public Harm Risk Exists. 19.1.9(a) Legal review shall be required where material ambiguity, regulated-perimeter risk, cross-border risk, public authority risk, finance risk, controlled technology risk, public harm risk, privacy risk, AI risk, cybersecurity risk, IP risk, employment risk, tax-status risk, sanctions risk, export-control risk, competition risk, professional-boundary risk, or protected knowledge risk exists.
19.1.9(b) Legal review may be required for contracts, grants, sponsorships, donations, restricted funds, in-kind contributions, data sharing, AI systems, compute access, controlled technology, software releases, public authority interfaces, capital-reader rooms, GRA interfaces, RNFD / NFD / UNFSD support, public reports, dashboards, maps, public claims, employment matters, contractor arrangements, related-party transactions, and incidents.
19.1.9(c) Where legal review is required, the relevant activity may be paused, narrowed, classified, restricted, reframed, routed, refused, or escalated until legal review is complete.
19.1.9(d) Legal review shall identify conditions, limitations, required approvals, required records, required notices, required disclaimers, required safeguards, correction paths, and residual risk.
19.1.9(e) The controlling rule shall be that material legal ambiguity is a stop-and-review condition, not an invitation to proceed informally.
19.1.10 Legal Compliance Records as Material Constitutional Records. 19.1.10(a) Legal compliance records shall be material constitutional records of GCRI Canada where they evidence lawful authority, institutional status, Board or officer authority, regulated-perimeter boundaries, data rights, public authority boundaries, finance boundaries, IP rights, contract obligations, public-safe release, correction obligations, or public trust.
19.1.10(b) Such records may include legal review records, compliance calendars, filings, registers, licenses where applicable, permits where applicable, corporate records, tax records, privacy records, data protection records, AI-use records, cybersecurity records, research ethics records, contracts, grant records, sponsorship records, donation records, sanctions screening records, export-control records, competition review records, public authority reference approvals, publication approvals, incident records, correction records, and Board or committee reports.
19.1.10(c) Legal compliance records shall identify owner, custodian, authority, obligation, jurisdiction, scope, risk, review status, decision, conditions, limitations, effective date, review cycle, related records, correction path, and closeout.
19.1.10(d) Legal compliance records shall be retained, classified, access-controlled, versioned, protected from silent edit, archived, and subject to legal hold where required.
19.1.10(e) The controlling rule shall be that legal compliance must be recorded because lawful authority must survive memory, personnel change, dispute, audit, and correction.
19.2 Canadian Legal Character and Localization
19.2.1 GCRI Canada as a Canadian Public-Benefit Institution Governed by Applicable Canadian Law and Its Governing Instruments. 19.2.1(a) GCRI Canada shall be understood as a Canadian public-benefit institution governed by applicable Canadian law, its articles, Bylaw, Charter, Board resolutions, policies, procedures, registers, records, and lawful contracts.
19.2.1(b) GCRI Canada’s legal character shall be Canadian, nonprofit, non-share, non-distributing, non-executing, public-benefit, evidence-and-methods, public-good technical, legally separate, and records-valid.
19.2.1(c) GCRI Canada shall not be interpreted as a branch, agent, subsidiary, alter ego, shared treasury, public authority, regulated intermediary, finance actor, execution company, National Company, Project SPV, provider, sponsor, or foreign entity merely because it participates in the wider Nexus architecture.
19.2.1(d) Canadian law and GCRI Canada’s governing instruments shall control the corporation’s legal authority, governance, filings, Board powers, officer powers, member rights where applicable, records, contracts, liabilities, employment, tax status, privacy obligations, and legal compliance.
19.2.1(e) The controlling rule shall be that GCRI Canada’s global interoperability shall operate through, not around, its Canadian legal identity.
19.2.2 Canadian Localization of Nexus Doctrine. 19.2.2(a) Nexus doctrine shall be localized for GCRI Canada through Canadian law, Canadian institutional practice, Canadian public-benefit purpose, Canadian data and privacy obligations, Canadian federal, provincial, territorial, Indigenous, municipal, and public authority contexts, and GCRI Canada’s governing instruments.
19.2.2(b) Localization shall preserve Nexus interoperability, role separation, One Rail / Two Stacks discipline, Public-Good Stack alignment, Public-Good Firewall, non-execution, validity-by-record, correctionability, controlled vocabulary, public-safe publication, and legal separateness.
19.2.2(c) Localization shall not permit fragmentation, uncontrolled local variation, role inflation, public authority confusion, finance-readiness drift, sponsor capture, provider capture, protected knowledge extraction, or inconsistency with Canadian legal requirements.
19.2.2(d) Where Nexus doctrine uses global terms, GCRI Canada shall interpret them through Canadian legal meaning, Canadian institutional role, applicable law, and recorded local equivalents.
19.2.2(e) The controlling rule shall be that Nexus doctrine becomes operational in Canada only through lawful Canadian localization.
19.2.3 Canadian Localization of Evidence, Methods, Observability, Ontology, Technical Truth, Public-Good R&D, Public-Good Software, Data Governance, AI Governance, Cybersecurity, Public-Safe Publication, and Public Authority Learning. 19.2.3(a) GCRI Canada shall localize evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, Open Technical Baselines, data governance, AI governance, cybersecurity, public-safe publication, and public authority learning to Canadian legal, institutional, technical, regional, linguistic, Indigenous, community, and public authority contexts.
19.2.3(b) Evidence and methods shall account for Canadian source authority, federalism, public authority capacity, regional conditions, local knowledge, protected knowledge, data rights, research ethics, public-safe release, and correction pathways.
19.2.3(c) Data, AI, compute, and cybersecurity governance shall account for Canadian privacy, data protection, cybersecurity, sovereign data, public authority data, health-sensitive data, community-protected data, Indigenous knowledge, cross-border transfer, compute-to-data, and secure release requirements.
19.2.3(d) Public authority learning shall account for Canadian federal, provincial, territorial, municipal, Indigenous, public health, emergency management, infrastructure, regulatory, procurement, public finance, and public administration contexts without converting GCRI Canada into a public authority.
19.2.3(e) The controlling rule shall be that technical truth must be legally and institutionally legible in Canada before it is used in Canadian contexts.
19.2.4 Canadian Federal, Provincial, Territorial, Indigenous, Municipal, Public Authority, University, Tax, Privacy, Research Ethics, Employment, and Corporate Contexts. 19.2.4(a) GCRI Canada shall recognize Canadian federal, provincial, territorial, Indigenous, municipal, public authority, university, tax, privacy, research ethics, employment, contractor, corporate, nonprofit, public-benefit, and community contexts in its governance and operations.
19.2.4(b) Where activities involve provinces, territories, municipalities, Indigenous governments, Indigenous organizations, local authorities, universities, health bodies, emergency management bodies, public infrastructure operators, regulators, public finance bodies, or other Public Authorities, GCRI Canada shall classify capacity, authority, applicable law, data terms, public-safe release requirements, and reference approvals.
19.2.4(c) University and research collaborations shall respect Canadian research ethics, institutional policies, human-subjects requirements where applicable, IP rules, publication practices, student protections, community safeguards, and data governance.
19.2.4(d) Employment, contractor, volunteer, fellow, and participant relationships shall be structured according to applicable Canadian and local legal requirements and shall not be disguised to avoid legal duties.
19.2.4(e) The controlling rule shall be that Canadian localization requires attention to the specific Canadian institutional level affected by the work.
19.2.5 Canadian Localization Without Fragmentation of Nexus Interoperability. 19.2.5(a) Canadian localization shall occur without fragmentation of Nexus interoperability.
19.2.5(b) GCRI Canada may adapt terminology, procedures, data handling, public authority protocols, legal review, publication controls, and safeguard profiles for Canadian law and context while preserving common rail compatibility, controlled vocabulary alignment, evidence comparability, records interoperability, correction paths, and role separation.
19.2.5(c) Localization shall not create incompatible forks, uncontrolled variants, duplicate authority, conflicting maturity meanings, conflicting finance-readiness meanings, conflicting recognition meanings, conflicting protocol meanings, or contradictory public claims.
19.2.5(d) Where Canadian localization differs materially from global or other national Nexus instruments, GCRI Canada shall maintain divergence logs, equivalence notes, localization notes, and public-safe summaries where appropriate.
19.2.5(e) The controlling rule shall be that localization shall make Nexus lawful and meaningful in Canada without breaking the shared system.
19.2.6 Canadian Law Supremacy Where Required Over Inconsistent Nexus Documents, External Practices, Foreign Expectations, Sponsor Terms, Provider Terms, Donor Terms, or Public Materials. 19.2.6(a) Applicable Canadian law and GCRI Canada’s lawful governing instruments shall prevail where required over inconsistent Nexus documents, external practices, foreign expectations, sponsor terms, provider terms, donor terms, grantor terms, platform terms, public materials, informal commitments, or foreign institutional assumptions.
19.2.6(b) No external doctrine, global template, sponsor request, provider requirement, donor condition, foreign legal expectation, GRA interface, GRF interface, Protocol Authority interface, National Company practice, Project SPV practice, or public communication shall override Canadian legal requirements applicable to GCRI Canada.
19.2.6(c) Where inconsistency exists, GCRI Canada shall narrow, localize, amend, reject, condition, supersede, or refuse the inconsistent provision, practice, or claim.
19.2.6(d) Where public materials have misstated Canadian legal effect or imported non-Canadian authority into GCRI Canada, correction, public-safe clarification, controlled notice, or withdrawal shall occur as appropriate.
19.2.6(e) The controlling rule shall be that interoperability cannot require illegality or Canadian role confusion.
19.2.7 Canadian Public-Benefit Character as Distinct From U.S., Regional, International, Enterprise, Project SPV, Provider, or Public Authority Roles. 19.2.7(a) GCRI Canada’s Canadian public-benefit character shall remain distinct from U.S., regional, international, enterprise, Project SPV, provider, sponsor, public authority, capital-reader, and other Nexus roles.
19.2.7(b) GCRI Canada is not GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards / Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, a National Consortium Company, a Project SPV, a qualified provider, a sponsor, a donor, a funder, a host, a Public Authority, or a capital actor.
19.2.7(c) Shared terminology, shared public-good mission, shared records, shared methods, shared rail, shared events, shared rooms, shared technical assets, or shared Nexus architecture shall not create merger, agency, partnership, joint venture, parent-subsidiary status, shared treasury, shared employer, shared liability, or authority transfer.
19.2.7(d) Public materials shall distinguish GCRI Canada’s Canadian evidence-and-methods role from the roles of other entities and actors.
19.2.7(e) The controlling rule shall be that Canadian public-benefit identity must remain visible wherever Nexus appears global.
19.2.8 Canadian Language, Accessibility, Public-Safe Communication, Indigenous and Local Context, and Regional Context Considerations. 19.2.8(a) GCRI Canada shall consider Canadian language, accessibility, public-safe communication, Indigenous and local context, regional context, northern and remote contexts, and community context in its legal and institutional localization.
19.2.8(b) Where appropriate, GCRI Canada may provide plain-language summaries, French-language materials, accessible formats, community-specific explanations, controlled translations, regional notes, or public-safe summaries, provided that such materials preserve legal meaning, boundary language, controlled vocabulary, limitations, and correction paths.
19.2.8(c) Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge shall not be translated, summarized, mapped, modeled, published, or reused without safeguards, authority, consent or non-consent handling where applicable, and public-safe review.
19.2.8(d) Regional context shall not be simplified in ways that create public harm, public authority confusion, community misdescription, public warning implication, procurement implication, finance implication, or protected knowledge exposure.
19.2.8(e) The controlling rule shall be that Canadian localization must be legible without becoming reductive or unsafe.
19.2.9 Canadian Localization Records, Divergence Logs, Equivalence Notes, and Public-Safe Summaries. 19.2.9(a) GCRI Canada shall maintain Canadian localization records, divergence logs, equivalence notes, and public-safe summaries where material.
19.2.9(b) Localization records shall identify source doctrine, Canadian adaptation, legal basis, institutional basis, public authority context, data context, controlled vocabulary treatment, effective date, owner, custodian, review status, and correction path.
19.2.9(c) Divergence logs shall identify where Canadian law, policy, institutional practice, data protection, Public Authority context, tax status, nonprofit status, language, Indigenous safeguards, or public-safe communication materially differs from global or other national Nexus treatment.
19.2.9(d) Equivalence notes shall explain how Canadian terms, records, procedures, or safeguard profiles align with common Nexus rail meanings without creating legal fusion.
19.2.9(e) Public-safe summaries may explain Canadian localization without exposing legal advice, protected knowledge, confidential public authority material, security-sensitive material, or restricted data.
19.2.9(f) The controlling rule shall be that localization differences must be recorded so interoperability remains honest.
19.2.10 Canadian Localization Assurance. 19.2.10(a) GCRI Canada shall conduct Canadian Localization Assurance.
19.2.10(b) Assurance shall review whether GCRI Canada’s governance, programs, data practices, AI practices, cybersecurity controls, publications, public authority learning materials, contracts, public claims, Nexus interfaces, and public-safe summaries remain consistent with Canadian law, Canadian public-benefit purpose, local context, and Nexus interoperability.
19.2.10(c) Assurance shall identify imported terms that misfit Canadian law, public authority misdescription, U.S. or foreign-law assumptions, stale localization notes, missing divergence logs, uncontrolled translations, inaccessible public materials, Indigenous or protected knowledge risks, and public-safe communication gaps.
19.2.10(d) Findings may require legal review, localization update, divergence log update, equivalence note update, translation correction, public-safe clarification, controlled notice, training, policy amendment, or Board reporting.
19.2.10(e) The controlling rule shall be that localization must be periodically assured because law, language, public authority context, and Nexus practice evolve.
19.3 Corporate Compliance
19.3.1 Corporate Compliance With Articles, Bylaw, Charter, Board Resolutions, Registers, Policies, and Applicable Law. 19.3.1(a) GCRI Canada shall maintain corporate compliance with its articles, Bylaw, Charter, Board resolutions, registers, policies, procedures, schedules, annexes, delegations, contracts, and applicable law.
19.3.1(b) Corporate compliance shall include lawful corporate existence, proper governance, Board authority, officer authority, member rights where applicable, statutory records, filings, registered office, corporate name use, signing authority, corporate representations, meeting discipline, conflict records, and corporate register integrity.
19.3.1(c) The Charter shall guide mission interpretation and institutional discipline, but corporate mechanics shall comply with applicable law, articles, and Bylaw.
19.3.1(d) Corporate compliance failures shall be corrected through filing remediation, record correction, ratification where lawful, rescission where required, legal review, Board action, or public-safe clarification where public materials are affected.
19.3.1(e) The controlling rule shall be that mission cannot be lawfully advanced through defective corporate authority.
19.3.2 Registered Office, Corporate Filings, Annual Returns, Director Records, Officer Records, Member Records Where Applicable, Corporate Minute Book, and Statutory Registers. 19.3.2(a) GCRI Canada shall maintain its registered office, corporate filings, annual returns, Director records, Officer records, member records where applicable, corporate minute book, statutory registers, and related corporate records as required by law and governing instruments.
19.3.2(b) Corporate records shall identify Directors, Officers, members where applicable, registered office, articles, Bylaw, resolutions, meeting minutes, written resolutions, consents, resignations, removals, appointments, delegations, filings, annual returns, and statutory notices.
19.3.2(c) Corporate records shall be accurate, current, retained, access-controlled, and available to authorized persons according to law, Bylaw, privacy, confidentiality, and records policy.
19.3.2(d) Errors or omissions in corporate records shall be corrected promptly through proper authority and record.
19.3.2(e) The controlling rule shall be that corporate existence and authority must be visible in the corporate record.
19.3.3 Board Meetings, Member Meetings Where Applicable, Notices, Quorum, Voting, Written Resolutions, Minutes, and Records. 19.3.3(a) Board meetings, member meetings where applicable, notices, quorum, voting, written resolutions, minutes, and records shall comply with applicable law, articles, Bylaw, Board procedures, member procedures where applicable, and records requirements.
19.3.3(b) Meeting records shall identify date, notice, attendance, quorum, capacity, conflicts, recusals, materials reviewed, decisions made, votes where required, dissent where recorded, conditions, delegations, actions, and correction path.
19.3.3(c) Written resolutions shall identify authority, text, approvals, effective date, signatories, conditions, and repository location.
19.3.3(d) Defective notice, quorum, voting, or recordkeeping shall be escalated for legal review and corrected or ratified only where lawful and appropriate.
19.3.3(e) The controlling rule shall be that Board and member authority requires lawful procedure, not informal agreement.
19.3.4 Director Eligibility, Consent, Appointment, Resignation, Removal, Term, and Conflict Records. 19.3.4(a) Director eligibility, consent, appointment, resignation, removal, term, renewal, independence, conflict, recusal, training, and good-standing records shall be maintained in accordance with applicable law, articles, Bylaw, Charter, Board policy, and records requirements.
19.3.4(b) Director records shall include eligibility review, consent to act, appointment authority, term, role, committee assignments, independence review, conflict disclosures, related-party disclosures, training completion, resignations, removals, and public-safe public biographies where applicable.
19.3.4(c) Director appointment and removal shall not be controlled by founders, sponsors, donors, providers, hosts, Public Authorities, capital readers, National Companies, Project SPVs, or Nexus actors unless lawful governance instruments expressly provide a role consistent with mission lock and public-benefit duties.
19.3.4(d) Director conflicts shall be disclosed, reviewed, recorded, mitigated, and subject to recusal where required.
19.3.4(e) The controlling rule shall be that Directors hold fiduciary office, not stakeholder entitlement.
19.3.5 Officer Appointment, Delegation, Authority, Resignation, Removal, Compensation, and Conflict Records. 19.3.5(a) Officer appointment, delegation, authority, resignation, removal, compensation, conflict, recusal, training, performance, and closeout records shall be maintained in accordance with law, articles, Bylaw, Charter, Board resolutions, delegations, and policies.
19.3.5(b) Officer records shall identify appointment authority, title, role, reporting line, delegated authority, limits, budget authority, signing authority, public claims authority, data access, AI access, cybersecurity responsibilities, Public Authority interface authority, finance-boundary duties, compensation approval, conflicts, and termination or resignation.
19.3.5(c) Officer authority shall not arise by title alone where Board approval, delegation, policy, or law requires specific authority.
19.3.5(d) Officer compensation and related-party issues shall be reviewed for reasonableness, conflicts, anti-inurement, private benefit, and proper approval.
19.3.5(e) The controlling rule shall be that Officer power must be appointed, delegated, scoped, recorded, and accountable.
19.3.6 Corporate Name Use, Seal Where Applicable, Signing Authority, and Corporate Representations. 19.3.6(a) Corporate name use, seal use where applicable, signing authority, and corporate representations shall be controlled.
19.3.6(b) GCRI Canada’s name, logo, marks, titles, seal where applicable, public descriptions, signatures, letterhead, certificates, reports, public-safe summaries, contracts, and public materials shall be used only under proper authority and in a manner consistent with legal status, mission, non-execution, role separation, public authority boundaries, finance boundaries, and public claims discipline.
19.3.6(c) Signing authority shall be registered, scoped, limited, and reviewed. No person shall sign or represent GCRI Canada without lawful authority, delegation, or approval.
19.3.6(d) Corporate representations shall not imply that GCRI Canada is a regulator, public authority, finance actor, insurer, lender, broker, certification body by default, procurement authority, emergency command body, public warning authority, provider, sponsor, National Company, Project SPV, or execution actor.
19.3.6(e) The controlling rule shall be that the corporate name is an authority surface and must be protected from misuse.
19.3.7 Corporate Authority for Contracts, Bank Accounts, Grants, Sponsorships, Donations, Data Agreements, IP Licenses, and Nexus Interfaces. 19.3.7(a) Corporate authority for contracts, bank accounts, grants, sponsorships, donations, data agreements, IP licenses, employment arrangements, contractor engagements, procurement, public authority interfaces, GRA interfaces, GRF interfaces, Protocol Authority interfaces, and Nexus interfaces shall be established through law, articles, Bylaw, Board resolutions, policies, delegations, and proper records.
19.3.7(b) Material corporate commitments shall identify authority source, approver, signer, scope, limits, risk review, conflict review, legal review where required, and repository location.
19.3.7(c) No contract, account, grant, sponsorship, donation, data agreement, IP license, or Nexus interface shall be entered through informal consensus, email alone, chat alone, verbal assurance, draft term sheet, meeting note, slide deck, or unauthorized platform workflow.
19.3.7(d) Unauthorized corporate commitments shall be escalated for legal review, correction, ratification where lawful, rescission, withdrawal, public-safe clarification, or controlled notice.
19.3.7(e) The controlling rule shall be that corporate commitments require corporate authority before effect.
19.3.8 Corporate Compliance Calendar and Filing Responsibilities. 19.3.8(a) GCRI Canada shall maintain a corporate compliance calendar and assign filing responsibilities.
19.3.8(b) The compliance calendar shall identify annual returns, corporate filings, tax filings, information returns where applicable, registered office updates, Director updates, Officer updates, member filings where applicable, charitable or nonprofit status filings where applicable, licenses or permits where applicable, insurance renewals, audit or review deadlines, grant reporting deadlines, and other recurring obligations.
19.3.8(c) Each filing obligation shall identify owner, custodian, due date, preparer, reviewer, approval authority, supporting records, submission method, confirmation record, correction path, and escalation threshold.
19.3.8(d) Missed, late, incomplete, or inaccurate filings shall be escalated, corrected, and reported where material.
19.3.8(e) The controlling rule shall be that corporate compliance must be calendared because legal status depends on recurring acts.
19.3.9 Corporate Noncompliance Correction, Ratification Where Lawful, Filing Remediation, and Legal Review. 19.3.9(a) Corporate noncompliance shall require correction, ratification where lawful, filing remediation, legal review, Board reporting, public-safe clarification, controlled notice, or governance redesign where appropriate.
19.3.9(b) Corporate noncompliance may include missed filings, defective meetings, defective notices, lack of quorum, unauthorized signatures, stale registers, incorrect Director or Officer records, improper member records, invalid delegations, unauthorized contracts, corporate name misuse, or public status misdescription.
19.3.9(c) Ratification shall be used only where lawful, appropriate, properly recorded, conflict-reviewed, and not used to conceal misconduct or prohibited functions.
19.3.9(d) Filing remediation shall identify error, affected period, required filing, authority, correction made, confirmation received, public-safe consequence, and prevention measure.
19.3.9(e) The controlling rule shall be that corporate defects must be corrected through lawful records, not ignored as technicalities.
19.3.10 Corporate Compliance Register and Assurance. 19.3.10(a) GCRI Canada shall maintain a Corporate Compliance Register and Corporate Compliance Assurance process.
19.3.10(b) The Register shall identify articles, Bylaw, Charter, Board resolutions, filings, annual returns, registered office records, Director records, Officer records, member records where applicable, minute book records, statutory registers, meeting records, written resolutions, delegations, signing authorities, corporate name use approvals, corporate commitments, filing obligations, noncompliance events, corrections, and closeout.
19.3.10(c) Assurance shall review whether corporate records, filings, meetings, notices, quorum, voting, delegations, authority, registers, and corporate representations comply with applicable law and governing instruments.
19.3.10(d) Assurance findings may require filing remediation, record correction, legal review, Board action, training, delegation update, public claims correction, or policy amendment.
19.3.10(e) The controlling rule shall be that corporate compliance must be assured because lawful authority depends on corporate form being maintained.
19.4 Nonprofit, Charitable, and Tax Status Compatibility
19.4.1 GCRI Canada Shall Operate Consistently With Its Applicable Nonprofit, Public-Benefit, Tax, and Charitable Status Where Applicable. 19.4.1(a) GCRI Canada shall operate consistently with its applicable nonprofit, public-benefit, tax, and charitable status where applicable.
19.4.1(b) Where GCRI Canada is non-charitable unless lawfully changed, it shall not represent itself as a registered charity, charitable donee, tax-credit issuer, or charitable receipting body unless and until lawful status and authority support such representation.
19.4.1(c) If GCRI Canada obtains, applies for, or becomes subject to charitable, qualified donee, tax-exempt, nonprofit, or other special status requirements, it shall comply with applicable restrictions, filings, receipting rules, fundraising rules, activity limits, private benefit limits, political activity limits, and reporting duties.
19.4.1(d) Public materials, donor materials, sponsorship materials, grant materials, invoices, receipts, financial reports, and public-safe summaries shall accurately state GCRI Canada’s status.
19.4.1(e) The controlling rule shall be that legal and tax status must be stated and operated exactly, not aspirationally.
19.4.2 Purposes, Activities, Fundraising, Grants, Donations, Sponsorships, Memberships, Fees, Cost Recovery, Restricted Funds, In-Kind Contributions, Contracts, IP Licensing, and Public-Good Support Shall Be Reviewed for Status Compatibility Where Material. 19.4.2(a) Purposes, activities, fundraising, grants, donations, sponsorships, memberships, fees, cost recovery, restricted funds, in-kind contributions, contracts, IP licensing, public-good support, public authority learning, Academy programs, technical releases, room access, and Nexus interfaces shall be reviewed for nonprofit, public-benefit, tax, and charitable-status compatibility where material.
19.4.2(b) Review shall assess whether an activity supports stated purposes, creates commercial drift, creates private benefit, creates inurement, creates unrelated business risk where applicable, misstates charitable or tax status, creates fundraising compliance risk, creates political or lobbying risk, or creates public trust risk.
19.4.2(c) Revenue-generating activities shall be reviewed to ensure that fees, dues, cost recovery, subscriptions, training fees, sponsorships, and service-like support remain mission-compatible and do not convert GCRI Canada into a commercial execution provider, finance actor, certification seller, procurement intermediary, or sponsor service desk.
19.4.2(d) IP licensing and technical asset arrangements shall preserve public-good reuse, anti-enclosure, nonprofit purpose, public-benefit alignment, and no improper private benefit.
19.4.2(e) The controlling rule shall be that every material value flow must be compatible with GCRI Canada’s legal and tax status.
19.4.3 No Improper Private Inurement. 19.4.3(a) GCRI Canada shall not permit improper private inurement.
19.4.3(b) No Director, Officer, member where applicable, founder, employee, contractor, fellow, advisor, sponsor, donor, provider, host, related party, National Company, Project SPV, or private person shall receive improper distribution of income, assets, surplus, opportunities, access, technical assets, data, public authority interfaces, public claims value, or institutional value.
19.4.3(c) Compensation, benefits, reimbursements, contracts, procurement, related-party transactions, IP licenses, data access, technical asset access, visibility, and support relationships shall be reviewed for inurement risk.
19.4.3(d) Improper inurement shall require correction, repayment, return of benefit, repricing, rescission, termination, legal review, tax review, Board reporting, and public-safe correction where appropriate.
19.4.3(e) The controlling rule shall be that nonprofit resources must not be diverted into private entitlement.
19.4.4 No Improper Private Benefit. 19.4.4(a) GCRI Canada shall not permit improper private benefit.
19.4.4(b) Incidental private benefit may occur only where lawful, reasonable, mission-compatible, public-benefit-aligned, documented, and subordinate to GCRI Canada’s public-benefit purposes.
19.4.4(c) Improper private benefit may arise through preferential access, sponsor benefit, provider preference, public authority access, procurement advantage, finance signal, certification implication, recognition implication, data access, technical asset access, IP rights, publications, acknowledgments, or Nexus interfaces.
19.4.4(d) Private benefit review shall occur where material value, status, access, data, technology, public claim, or influence may be conferred.
19.4.4(e) The controlling rule shall be that private benefit must remain incidental, lawful, bounded, and recorded.
19.4.5 No Mission-Incompatible Commercial Drift. 19.4.5(a) GCRI Canada shall not permit mission-incompatible commercial drift.
19.4.5(b) Commercial drift includes transformation of GCRI Canada into a consultancy, vendor, sponsor service desk, provider marketing platform, managed service provider, implementation company, public authority contractor by default, financial intermediary, certification seller, procurement adviser, data broker, software vendor by default, or event brand detached from public-benefit evidence function.
19.4.5(c) Revenue, cost recovery, service-like support, sponsorship, grants, in-kind contributions, technical asset licensing, training fees, Academy fees, and subscriptions shall be reviewed for whether they support mission or reorient the institution toward commercial delivery.
19.4.5(d) Where drift risk exists, GCRI Canada shall narrow the activity, add boundary language, change fee structure, route execution to competent actors, restrict public claims, or refuse the activity.
19.4.5(e) The controlling rule shall be that sustainability must not be purchased by abandoning the mission being sustained.
19.4.6 No Political, Partisan, Lobbying, Public Policy, or Advocacy Activity Beyond Legal and Status-Compatible Limits Where Applicable. 19.4.6(a) GCRI Canada shall not engage in political, partisan, lobbying, public policy, or advocacy activity beyond legal and status-compatible limits where applicable.
19.4.6(b) GCRI Canada may engage in evidence-based public-benefit education, technical literacy, public authority learning, research publication, public-safe reporting, and policy-relevant knowledge sharing where lawful and consistent with its mission, but shall not misstate such work as partisan, electoral, lobbying, regulatory direction, official public guidance, or public authority decision.
19.4.6(c) Any lobbying, advocacy, legislative engagement, regulatory comment, public policy submission, election-adjacent communication, or public campaign activity shall be reviewed for legal authority, tax-status compatibility, public-benefit purpose, Board approval where required, public-safe status, and records.
19.4.6(d) GCRI Canada shall not permit sponsors, providers, donors, Public Authorities, political actors, or Nexus actors to use GCRI Canada to launder political influence, regulatory pressure, procurement advantage, or public authority access.
19.4.6(e) The controlling rule shall be that public-good evidence may inform public understanding without converting GCRI Canada into a partisan or improper lobbying vehicle.
19.4.7 Donation Receipting, Restricted Gift, Grant, and Fundraising Compliance Where Applicable. 19.4.7(a) Donation receipting, restricted gift, grant, and fundraising compliance shall be maintained where applicable.
19.4.7(b) Receipts, acknowledgments, fundraising solicitations, donor communications, grant applications, sponsorship proposals, public campaigns, and public support materials shall accurately state GCRI Canada’s legal status, tax treatment, deductibility, use of funds, restrictions, public-benefit purpose, and non-control rules.
19.4.7(c) Restricted gifts and grants shall be accepted, tracked, spent, reported, modified, returned, and closed out according to law, donor terms, grant terms, Board policy, and records requirements.
19.4.7(d) Fundraising materials shall not imply charitable status, tax benefit, public authority approval, finance-readiness, certification, recognition, procurement advantage, provider preference, public warning authority, emergency command, or execution authority unless lawfully and records-validly supported.
19.4.7(e) The controlling rule shall be that fundraising truth is a legal and public trust obligation.
19.4.8 Cross-Border Funding and Foreign Support Review. 19.4.8(a) Cross-border funding and foreign support shall require review where material.
19.4.8(b) Review shall address donor or funder jurisdiction, source of funds where appropriate, sanctions, export controls, anti-bribery, anti-corruption, tax, foreign reporting, currency, payment routes, data obligations, IP obligations, public claims, Public Authority implications, political sensitivity, and public trust.
19.4.8(c) Foreign support shall not override Canadian law, GCRI Canada’s governing instruments, data sovereignty requirements, protected knowledge safeguards, publication independence, correctionability, or non-execution boundaries.
19.4.8(d) Where foreign support creates legal, reputational, public authority, data, controlled technology, or political risk, GCRI Canada may refuse, restrict, segregate, return, or terminate support.
19.4.8(e) The controlling rule shall be that cross-border support must be lawful in both receipt and consequence.
19.4.9 Tax Filings, Returns, Information Records, and Public Reporting Where Required. 19.4.9(a) GCRI Canada shall maintain tax filings, returns, information records, and public reporting where required by applicable law, status, contract, grant, donor obligation, Board policy, or public-benefit reporting commitment.
19.4.9(b) Tax records shall include income, expenses, payroll or contractor reporting where applicable, sales or indirect tax where applicable, donation treatment, grant treatment, sponsorship treatment, in-kind contribution treatment, restricted fund treatment, compensation, benefits, related-party transactions, and public reporting requirements.
19.4.9(c) Filings shall be accurate, timely, supported by records, reviewed by qualified persons where appropriate, and retained according to law and policy.
19.4.9(d) Errors in tax filings, information returns, receipts, public reports, or status representations shall be corrected through lawful process, amended filings where required, notices where appropriate, and Board reporting where material.
19.4.9(e) The controlling rule shall be that tax and status records must match financial reality and public representations.
19.4.10 Tax Status Risk Escalation, Correction, and Board Reporting. 19.4.10(a) Tax status risk shall be escalated, corrected, and reported to the Board where material.
19.4.10(b) Tax status risk may arise from private benefit, inurement, commercial drift, improper receipting, inaccurate fundraising, political or lobbying activity, foreign support, unrelated revenue, related-party transactions, sponsorship treatment, in-kind valuation, grant noncompliance, public claims, or filing failure.
19.4.10(c) Escalation shall identify risk, affected activity, affected records, affected filings, affected donors or funders, legal review, corrective options, public-safe implications, and prevention measures.
19.4.10(d) Correction may include filing amendment, receipt correction, donor notice, public-safe clarification, activity redesign, funds return, policy amendment, training, contract amendment, or Board action.
19.4.10(e) The controlling rule shall be that tax status risk must be treated as mission risk, not only accounting risk.
19.5 Contracting Authority and Contract Governance
19.5.1 Contracts Shall Be Entered Only Under Proper Authority and Delegation. 19.5.1(a) Contracts shall be entered only under proper authority and delegation.
19.5.1(b) Proper authority may arise from applicable law, articles, Bylaw, Board resolution, approved budget, policy, officer delegation, committee authority, or specific approval record.
19.5.1(c) No person shall bind GCRI Canada by contract, memorandum, letter of intent, term sheet, purchase order, platform click-through, data sharing arrangement, grant agreement, sponsorship agreement, IP license, public authority arrangement, room access terms, repository terms, cloud terms, AI tool terms, or Nexus interface agreement without authority.
19.5.1(d) Apparent urgency, sponsor pressure, provider pressure, donor pressure, public authority interest, capital-reader interest, technical need, event timing, or operational convenience shall not substitute for proper authority.
19.5.1(e) The controlling rule shall be that contract authority must precede contractual commitment.
19.5.2 Contract Review Shall Address Purpose, Scope, Authority, Consideration, Term, Termination, Payment, Deliverables, IP, Data, AI, Cybersecurity, Confidentiality, Public Authority References, Publication Rights, Publicity, Indemnity, Liability, Insurance, Sanctions, Export Controls, Tax, Dispute Resolution, Governing Law, and Closeout. 19.5.2(a) Contract review shall address purpose, scope, authority, consideration, term, termination, payment, deliverables, IP, data, AI, cybersecurity, confidentiality, Public Authority references, publication rights, publicity, indemnity, liability, insurance, sanctions, export controls, tax, dispute resolution, governing law, jurisdiction, amendments, assignment, subcontracting, audit rights, breach, remedies, records, correction, and closeout.
19.5.2(b) Data review shall address lawful basis, classification, permitted use, prohibited use, AI-use limits, cross-border transfer, sovereign data, Public Authority Data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, protected knowledge, retention, deletion, sealing, breach notice, and correction.
19.5.2(c) AI review shall address model use, training prohibitions, fine-tuning prohibitions, embedding restrictions, retrieval controls, inference records, prompt and output handling, vendor use of data, human review, and AI incident response.
19.5.2(d) Cybersecurity review shall address access control, logging, encryption, vulnerability management, incident notice, secure development, repository security, subprocessor controls, business continuity, backup, exit, and secure disposal.
19.5.2(e) Publicity and public authority reference review shall ensure that names, logos, quotes, titles, photos, agency names, jurisdictions, attendance, data contributions, sponsorships, and provider references are used only with approval and boundary language.
19.5.2(f) The controlling rule shall be that contract review must cover the full legal and public-meaning lifecycle of the arrangement.
19.5.3 Contracts Shall Preserve Mission Lock, Non-Execution, Public-Good Stack Role Separation, Sponsor Non-Control, Provider Neutrality, Public Authority Boundaries, Finance Boundaries, Research Integrity, Data Rights, Cybersecurity, Protected Knowledge, and Correctionability. 19.5.3(a) Contracts shall preserve mission lock, non-execution, Public-Good Stack role separation, One Rail / Two Stacks discipline, Public-Good Firewall, sponsor non-control, donor non-control, grantor non-control, provider neutrality, procurement neutrality, Public Authority boundaries, finance boundaries, research integrity, publication independence, data rights, cybersecurity, protected knowledge, anti-inurement, legal separateness, and correctionability.
19.5.3(b) Contracts shall not require GCRI Canada to perform prohibited functions, including public authority substitution, public warning, emergency command, procurement authority, public finance approval, investment advice, securities solicitation, brokerage, lending, insurance placement, underwriting, rating, guarantee, certification by default, provider preference, sponsor control, or execution activity.
19.5.3(c) Contracts shall include boundary clauses where role confusion, public claims, Public Authority participation, finance-sensitive materials, sponsorship, provider participation, technical baselines, data access, or Nexus interfaces create risk.
19.5.3(d) Contracts shall preserve GCRI Canada’s right and duty to correct, supersede, withdraw, retract, clarify, restrict access, issue public-safe notices, issue controlled notices, and update records where required.
19.5.3(e) The controlling rule shall be that contracts must serve the Charter and may not contract around the Charter’s safeguards.
19.5.4 Contracts Shall Not Create Merger, Agency, Partnership, Joint Venture, Parent-Subsidiary Status, Shared Treasury, Shared Employer, Shared Liability, Public Authority Delegation, or Financial-Services Role Unless Lawfully, Expressly, and Board-Approved Where Required. 19.5.4(a) Contracts shall not create merger, agency, partnership, joint venture, parent-subsidiary status, alter ego, shared treasury, shared employer, joint employer status, shared liability, authority transfer, Public Authority delegation, or financial-services role unless lawfully, expressly, and Board-approved where required.
19.5.4(b) Shared purpose, shared records, shared rooms, shared methods, shared funding, shared public descriptions, shared events, shared technical assets, shared staff support, shared contractors, or shared Nexus references shall not create legal fusion by implication.
19.5.4(c) Interface agreements with GCRI US, GRF, GRA, Protocol Authority, Nexus entities, National Companies, Project SPVs, providers, sponsors, hosts, Public Authorities, universities, and partners shall include legal-separateness and no-agency clauses where risk exists.
19.5.4(d) Any agreement that intentionally creates agency, partnership, joint venture, shared liability, public authority delegation, or finance-related role shall require legal review, Board approval where required, explicit scope, risk assessment, insurance review, tax review, public claims review, and records.
19.5.4(e) The controlling rule shall be that legal fusion never arises accidentally.
19.5.5 Contracts Shall Not Grant Control Over Evidence, Methods, Publications, Corrections, Public-Safe Claims, Technical Baselines, or Public Authority Access Except Narrow, Lawful, Mission-Compatible, Safety-Justified, and Recorded Controls. 19.5.5(a) Contracts shall not grant control over evidence, methods, research findings, source selection, data interpretation, peer review, expert review, publications, public-safe summaries, correction decisions, withdrawal decisions, retraction decisions, supersession decisions, public-safe claims, technical baselines, public-good software, controlled vocabulary, Public Authority access, GRA inputs, GRF inputs, Protocol Authority inputs, or Nexus interface meaning except narrow, lawful, mission-compatible, safety-justified, rights-protective, and recorded controls.
19.5.5(b) Narrow review rights may be permitted for factual accuracy of name, logo, role, contribution, confidential information, IP, security-sensitive information, personal information, Public Authority Data, protected knowledge, or legally restricted material.
19.5.5(c) Such review rights shall not become veto rights over findings, suppression rights, sponsor approval rights, provider approval rights, publication suppression, correction suppression, or public authority access control.
19.5.5(d) Any clause that could restrict correction, restrict public-safe notice, suppress unfavorable findings, control technical baselines, purchase public authority access, create provider preference, or shape institutional truth shall be escalated and rejected unless lawful, narrow, mission-compatible, and Board-approved where material.
19.5.5(e) The controlling rule shall be that contracts may protect legitimate rights but shall not transfer institutional truth.
19.5.6 Contract Templates, Playbooks, Standard Clauses, Boundary Clauses, Data Clauses, AI Clauses, Cyber Clauses, IP Clauses, Sponsorship Clauses, Grant Clauses, Provider Clauses, and Public Authority Clauses. 19.5.6(a) GCRI Canada may maintain contract templates, playbooks, standard clauses, boundary clauses, data clauses, AI clauses, cyber clauses, IP clauses, sponsorship clauses, grant clauses, donation clauses, provider clauses, public authority clauses, finance-boundary clauses, public-safe publication clauses, correction clauses, and Nexus interface clauses.
19.5.6(b) Standard clauses shall reflect mission lock, non-execution, role separation, sponsor non-control, provider neutrality, public authority boundaries, finance boundaries, data rights, AI-use restrictions, cybersecurity, confidentiality, IP, anti-inurement, public claims, correctionability, and legal separateness.
19.5.6(c) Templates shall not be used mechanically where transaction risk, jurisdiction, Public Authority involvement, finance-sensitive context, controlled technology, cross-border transfer, protected knowledge, or unusual obligations require bespoke review.
19.5.6(d) Playbooks shall identify required approvals, fallback positions, escalation triggers, prohibited terms, acceptable variations, and required records.
19.5.6(e) The controlling rule shall be that templates create discipline but do not replace judgment.
19.5.7 Contract Deviation Review and Legal Escalation. 19.5.7(a) Material deviations from approved templates, standard clauses, boundary clauses, data clauses, AI clauses, cyber clauses, IP clauses, sponsorship clauses, grant clauses, provider clauses, public authority clauses, finance-boundary clauses, or correction clauses shall require deviation review and legal escalation where appropriate.
19.5.7(b) Deviations requiring review include clauses affecting liability, indemnity, governing law, jurisdiction, IP ownership, data rights, AI training, confidentiality, publication rights, publicity, public authority references, finance references, sponsorship benefits, provider status, audit rights, termination, assignment, subcontracting, export controls, sanctions, correction rights, and public-safe notices.
19.5.7(c) Deviation records shall identify the proposed change, reason, risk, reviewer, decision, conditions, approver, affected obligations, and correction path.
19.5.7(d) Unapproved deviations shall not be treated as accepted merely because an agreement was signed unless legal review determines lawful effect and corrective action.
19.5.7(e) The controlling rule shall be that deviations from protective clauses must be visible before they become institutional risk.
19.5.8 Contract Performance, Amendment, Renewal, Termination, Breach, Dispute, and Closeout. 19.5.8(a) Contract performance, amendment, renewal, termination, breach, dispute, and closeout shall be governed by records-valid procedures.
19.5.8(b) Contract owners shall monitor deliverables, deadlines, payments, restrictions, data obligations, IP obligations, publication rights, confidentiality, security controls, reporting duties, public claims limits, correction obligations, renewal dates, termination dates, and closeout duties.
19.5.8(c) Amendments and renewals shall require authority, review, updated risk assessment, conflict review where applicable, budget review, legal review where required, and records.
19.5.8(d) Breaches and disputes shall be escalated according to severity, legal risk, public trust risk, data risk, cybersecurity risk, Public Authority risk, finance risk, and protected knowledge risk.
19.5.8(e) Closeout shall include final deliverables, final payments, return or deletion of data, revocation of access, IP confirmation, confidentiality continuation, public claims correction, records deposit, unresolved issue review, and archive.
19.5.8(f) The controlling rule shall be that contracts must be governed after signature, not merely reviewed before signature.
19.5.9 Contract Overclaim, Unauthorized Publicity, or Boundary Breach Requires Correction. 19.5.9(a) Contract overclaim, unauthorized publicity, or boundary breach shall require correction.
19.5.9(b) Overclaim includes statements that a contract, MOU, grant, sponsorship, provider agreement, public authority agreement, university agreement, technical agreement, data agreement, GRA interface, GRF interface, Protocol Authority interface, Nexus interface, National Company interface, or Project SPV interface creates endorsement, certification, recognition, finance-readiness, public authority approval, procurement advantage, public warning authority, emergency command, protocol effect, Nexus-compatible status, shared liability, or execution authority beyond the contract.
19.5.9(c) Unauthorized publicity includes unapproved use of GCRI Canada’s name, logo, marks, quotes, reports, dashboards, maps, datasets, software, technical baselines, public authority references, sponsor references, provider references, or Nexus references.
19.5.9(d) Boundary breach includes contractual conduct that creates or risks sponsor control, provider preference, public authority confusion, finance overclaim, procurement steering, data misuse, AI misuse, cybersecurity weakness, protected knowledge exposure, or correction suppression.
19.5.9(e) Corrective action may include revised language, takedown request, public-safe clarification, controlled notice, contract amendment, access restriction, suspension, termination, legal review, Board reporting, or damages pursuit where appropriate.
19.5.9(f) The controlling rule shall be that contracts must not be used to claim authority they do not grant.
19.5.10 Contract Register and Assurance. 19.5.10(a) GCRI Canada shall maintain a Contract Register and Contract Assurance process.
19.5.10(b) The Contract Register shall identify contract title, counterparty, contract type, authority, owner, custodian, purpose, scope, value, term, renewal date, termination date, payment terms, deliverables, IP terms, data terms, AI terms, cybersecurity terms, confidentiality, publication rights, publicity rights, public authority references, finance-boundary clauses, sponsor or provider clauses, liability, indemnity, insurance, sanctions, export controls, governing law, dispute resolution, deviations, approvals, amendments, breaches, corrections, closeout, and archive status.
19.5.10(c) Contract Assurance shall review whether contracts are authorized, current, mission-compatible, legally compliant, data-safe, AI-safe, cybersecurity-safe, IP-safe, public-safe, finance-safe, public authority-safe, sponsor-non-controlling, provider-neutral, correctionable, and records-valid.
19.5.10(d) Assurance findings may require contract amendment, legal review, access restriction, public claims correction, data remediation, cybersecurity remediation, payment hold, termination, training, register update, or Board reporting.
19.5.10(e) The controlling rule shall be that contracts must be registered and assured because written obligations can quietly reshape institutional role.
19.6 Employment, Contractor, Volunteer, Fellow, and Advisor Compliance
19.6.1 Employment and Workforce Compliance Shall Follow Applicable Law, Contracts, Policies, and Public-Benefit Mission. 19.6.1(a) Employment, contractor, volunteer, fellow, advisor, intern, student, secondee, resident, scholar, trainee, and similar workforce or participation arrangements shall follow applicable law, contracts, policies, Board-approved procedures, public-benefit mission, non-execution, data protection, AI governance, cybersecurity, confidentiality, IP, public claims, safeguarding, and records requirements.
19.6.1(b) GCRI Canada shall structure workforce relationships to preserve lawful classification, role clarity, mission alignment, public-good stewardship, anti-inurement, private benefit discipline, conflict management, legal separateness, non-control, and correctionability.
19.6.1(c) Workforce arrangements shall not be used to create hidden governance authority, hidden compensation, hidden contractor control, sponsor influence, provider preference, Public Authority access purchase, finance-readiness influence, publication influence, data access without lawful basis, technical asset capture, or execution drift.
19.6.1(d) Persons serving GCRI Canada shall act only within their role, authority, agreement, delegation, training, and access class, and shall not bind GCRI Canada unless expressly authorized.
19.6.1(e) The controlling rule shall be that every workforce relationship must be lawful in form, clear in role, bounded in authority, and aligned with public-benefit purpose.
19.6.2 Employee Classification, Contractor Classification, Volunteer Status, Fellow Status, Intern Status, Advisor Status, and Student Status. 19.6.2(a) Employee classification, contractor classification, volunteer status, fellow status, intern status, advisor status, student status, secondee status, resident status, scholar status, trainee status, and any hybrid status shall be determined and recorded according to applicable law, institutional policy, role substance, control, compensation, duties, supervision, duration, access, and risk.
19.6.2(b) GCRI Canada shall not misclassify workers, contractors, volunteers, fellows, advisors, interns, students, or secondees to avoid employment standards, tax, withholding, workplace safety, benefits, termination, confidentiality, IP, data protection, cybersecurity, or safeguarding obligations.
19.6.2(c) Classification review shall consider whether the person is subject to direction and control, integrated into operations, economically dependent, paid, supervised, assigned institutional duties, given access to systems or data, authorized to represent GCRI Canada, or performing work essential to operations.
19.6.2(d) Fellow, advisor, volunteer, intern, student, or contributor labels shall not be used to disguise employment, contractor status, procurement, related-party transactions, or compensation arrangements.
19.6.2(e) The controlling rule shall be that workforce status follows legal substance and recorded role, not convenience label.
19.6.3 Offer Letters, Employment Agreements, Contractor Agreements, Volunteer Agreements, Fellowship Terms, Advisor Terms, Internship Terms, and Secondment Terms Where Applicable. 19.6.3(a) Offer letters, employment agreements, contractor agreements, volunteer agreements, fellowship terms, advisor terms, internship terms, student placement terms, secondment terms, scholar terms, resident terms, and trainee terms shall be used where applicable and proportionate to role, risk, duration, access, compensation, jurisdiction, and legal requirements.
19.6.3(b) Such instruments shall identify role, title, status, authority, reporting line, duties, compensation or unpaid status, stipend or reimbursement terms, term, termination, confidentiality, IP, moral rights where applicable, data access, AI-use restrictions, cybersecurity obligations, conflict disclosure, public claims limits, publication rules, safeguarding duties, records duties, and closeout obligations.
19.6.3(c) Agreements for persons with access to personal information, Public Authority Data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, protected knowledge, repositories, AI systems, dashboards, maps, or controlled rooms shall include heightened access, security, confidentiality, and correction obligations.
19.6.3(d) Agreements shall not grant authority to bind GCRI Canada, issue public claims, approve publications, access Public Authorities, approve finance-facing materials, certify providers, approve technical baselines, or execute downstream activity unless proper authority, delegation, and records exist.
19.6.3(e) The controlling rule shall be that workforce terms must make role, authority, rights, duties, and closeout clear before work begins.
19.6.4 Compensation, Reimbursement, Benefits, Stipends, Taxes, Withholding, Workplace Safety, Accessibility, Accommodation, Harassment, Discrimination, Non-Retaliation, and Termination Compliance. 19.6.4(a) Compensation, reimbursement, benefits, stipends, honoraria, taxes, withholding, reporting, workplace safety, accessibility, accommodation, harassment prevention, discrimination prevention, non-retaliation, discipline, suspension, and termination shall comply with applicable law, agreements, policies, public-benefit mission, records requirements, and anti-inurement controls.
19.6.4(b) Compensation and stipends shall be reasonable, authorized, documented, budget-supported, conflict-reviewed, tax-reviewed where applicable, and not used to purchase influence, silence, publication outcomes, data access, Public Authority access, sponsor benefit, provider preference, or institutional loyalty.
19.6.4(c) Reimbursements shall require mission purpose, documentation, approval, and policy compliance, and shall not become hidden compensation or improper private benefit.
19.6.4(d) GCRI Canada shall maintain respectful, inclusive, accessible, non-discriminatory, harassment-free, non-retaliatory, and safe work and participation environments consistent with applicable law and institutional safeguards.
19.6.4(e) Termination, suspension, discipline, or closeout shall be handled lawfully, proportionately, records-validly, and with attention to access revocation, confidentiality continuation, data disposition, IP confirmation, public claims correction, and non-retaliation.
19.6.4(f) The controlling rule shall be that workforce compliance protects both people and institutional integrity.
19.6.5 Confidentiality, IP Assignment, Moral Rights, Data Access, AI Use, Cybersecurity, Public Claims, Conflict Disclosure, and Records Duties. 19.6.5(a) Workforce and participant agreements shall address confidentiality, IP assignment or licensing, moral rights where applicable, attribution, data access, AI use, cybersecurity, public claims, conflicts, records, correction, and closeout duties.
19.6.5(b) Confidentiality obligations shall protect corporate records, legal materials, grant materials, donor materials, sponsor materials, Public Authority Data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, community-protected information, protected knowledge, and unpublished research.
19.6.5(c) IP provisions shall preserve public-good software, Open Technical Baselines, methods, ontology, documentation, datasets, models, schemas, APIs, research outputs, technical notes, and other mission assets from enclosure, unauthorized reuse, or unclear ownership.
19.6.5(d) Data and AI obligations shall prohibit unauthorized collection, processing, transfer, publication, training, fine-tuning, embedding, retrieval, model improvement, prompt disclosure, output reliance, or use of unauthorized AI systems.
19.6.5(e) Public claims duties shall prevent unauthorized statements implying recognition, certification, finance-readiness, public authority approval, procurement advantage, provider preference, sponsor validation, Nexus-compatible status, public warning authority, emergency command, protocol effect, or execution authority.
19.6.5(f) The controlling rule shall be that access to GCRI Canada work carries continuing confidentiality, rights, security, claims, and correction duties.
19.6.6 Cross-Border Work, Remote Work, Immigration, Work Authorization, Tax, Employment Standards, Worker Safety, and Local Law Review Where Applicable. 19.6.6(a) Cross-border work, remote work, immigration, work authorization, tax, employment standards, worker safety, benefits, payroll, contractor status, data access, cybersecurity, insurance, and local law shall be reviewed where applicable.
19.6.6(b) GCRI Canada shall not permit a person to perform work, access systems, access data, represent the institution, travel, receive compensation, or participate in controlled activities in a manner that violates work authorization, immigration, tax, employment, export-control, sanctions, data protection, cybersecurity, or local legal requirements.
19.6.6(c) Remote work arrangements shall address jurisdiction, device security, network security, data residency, access controls, confidentiality, records, AI-use limits, cybersecurity obligations, incident reporting, health and safety where applicable, and closeout.
19.6.6(d) Cross-border arrangements involving Public Authority Data, personal information, health-sensitive data, controlled technology, protected knowledge, or cyber-sensitive materials shall require heightened legal, data, cybersecurity, and export-control review.
19.6.6(e) The controlling rule shall be that distributed work must remain lawful where the person is, where the institution is, and where the data or technology resides.
19.6.7 Contractor Misclassification and Shadow Employment Controls. 19.6.7(a) GCRI Canada shall maintain contractor misclassification and shadow employment controls.
19.6.7(b) Contractor arrangements shall be reviewed for scope, control, supervision, exclusivity, duration, integration, tools, payment method, substitution rights, business independence, deliverables, risk, tax treatment, and legal classification.
19.6.7(c) Shadow employment risk may arise where contractors, fellows, advisors, volunteers, interns, students, or contributors perform employee-like duties without appropriate status, protections, agreements, compensation treatment, tax treatment, or workplace controls.
19.6.7(d) Where misclassification risk exists, GCRI Canada shall reclassify, amend agreements, narrow scope, change supervision, adjust payment terms, obtain legal review, or terminate the arrangement as appropriate.
19.6.7(e) The controlling rule shall be that the institution shall not build public-good infrastructure on legally unstable labour arrangements.
19.6.8 Workforce Access, Onboarding, Training, Performance, Discipline, Suspension, Termination, and Closeout. 19.6.8(a) Workforce access, onboarding, training, performance, discipline, suspension, termination, and closeout shall be governed by records-valid procedures proportionate to role and risk.
19.6.8(b) Onboarding shall include role classification, agreement execution, conflict disclosure, confidentiality acknowledgment, data handling training, AI-use training, cybersecurity training, public claims training, safeguarding training, Public Authority boundary training, finance-boundary training, records training, and access provisioning.
19.6.8(c) Performance and discipline processes shall address role duties, conduct, conflicts, confidentiality, data handling, AI use, cybersecurity, public claims, research integrity, publication discipline, and correction cooperation.
19.6.8(d) Suspension or termination shall include access revocation, credential revocation, key and token revocation, return of devices, return or deletion of data, repository access removal, room access removal, confidentiality continuation, IP confirmation, public claims correction, and records closeout.
19.6.8(e) The controlling rule shall be that workforce lifecycle governance begins before access and ends only after closeout duties are complete.
19.6.9 Workforce Compliance Incidents, Grievances, Complaints, Investigations, and Remedies. 19.6.9(a) Workforce compliance incidents, grievances, complaints, investigations, and remedies shall be handled lawfully, fairly, records-validly, confidentially where appropriate, non-retaliatorily, and proportionately to risk.
19.6.9(b) Incidents may include harassment, discrimination, retaliation, workplace safety issues, compensation errors, misclassification, confidentiality breach, data breach, AI misuse, cybersecurity breach, IP breach, conflict breach, public claims breach, sponsor influence, provider influence, protected knowledge misuse, or unauthorized authority.
19.6.9(c) Investigations shall identify facts, affected persons, affected records, affected systems, legal obligations, interim measures, confidentiality needs, safeguarding needs, correction needs, and remedies.
19.6.9(d) Remedies may include correction, accommodation, discipline, suspension, termination, payment correction, access restriction, training, policy revision, public-safe clarification, controlled notice, legal review, or referral to competent authority where required.
19.6.9(e) The controlling rule shall be that workforce issues must be handled with dignity, lawful process, non-retaliation, and institutional correction.
19.6.10 Workforce Register and Assurance. 19.6.10(a) GCRI Canada shall maintain a Workforce Register and Workforce Compliance Assurance process.
19.6.10(b) The Register shall identify employees, contractors, volunteers, fellows, advisors, interns, students, secondees, residents, scholars, trainees, role classifications, agreements, terms, authority, compensation or stipend status, reimbursement status, benefits where applicable, access rights, training, conflicts, confidentiality, IP terms, data access, AI access, cybersecurity access, public claims authority, start date, end date, suspension, termination, and closeout.
19.6.10(c) Assurance shall review classification, agreements, compensation, reimbursements, access, training, conflicts, confidentiality, IP, data, AI, cybersecurity, public claims, grievances, complaints, incidents, and closeout.
19.6.10(d) Assurance findings may require reclassification, agreement update, payment correction, access revocation, training, policy amendment, legal review, discipline, termination, or Board / committee reporting.
19.6.10(e) The controlling rule shall be that workforce compliance must be registered and assured because people are the primary carriers of institutional authority, data, and trust.
19.7 Research Ethics and Legal Compliance
19.7.1 Research Shall Comply With Applicable Research Ethics, Human-Subjects, Privacy, Health, Public Authority, University, Grant, Community, Indigenous, and Protected Knowledge Requirements. 19.7.1(a) Research conducted, supported, funded, hosted, reviewed, published, or relied upon by GCRI Canada shall comply with applicable research ethics, human-subjects, privacy, health, public authority, university, grant, community, Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge requirements.
19.7.1(b) Research compliance shall apply to protocols, evidence intake, methods development, observability work, Truth Engine methods, public-good software, datasets, models, benchmarks, dashboards, maps, fieldwork, interviews, surveys, workshops, simulations, community participation, public authority learning, publications, and controlled annexes.
19.7.1(c) Research shall preserve informed participation where applicable, consent and non-consent rules where applicable, dignity, privacy, rights-bearing data protections, community safeguards, Indigenous knowledge protocols, source lineage, limitation disclosure, conflict disclosure, publication review, and correctionability.
19.7.1(d) Research compliance shall not be bypassed because work is public-good, technical, exploratory, urgent, unfunded, AI-assisted, community-sourced, public authority-adjacent, or conducted through Nexus interfaces.
19.7.1(e) The controlling rule shall be that public-benefit research must remain lawful, ethical, rights-protective, and correctionable.
19.7.2 Research Ethics Review Where Required or Appropriate. 19.7.2(a) Research ethics review shall be required where applicable law, institutional policy, university policy, grant terms, human-subjects involvement, health-sensitive data, vulnerable participants, community-protected knowledge, Indigenous knowledge, public authority data, rights-bearing data, or public harm risk requires or makes review appropriate.
19.7.2(b) Ethics review may be internal, external, university-based, community-based, Indigenous-governed, Public Authority-based, or otherwise appropriate to the research context.
19.7.2(c) Review shall address purpose, participants, risks, benefits, consent, confidentiality, data governance, AI use, cybersecurity, publication, public-safe release, community safeguards, protected knowledge, conflict of interest, researcher independence, and correction path.
19.7.2(d) Conditions imposed by ethics review shall be recorded, implemented, monitored, and reflected in publication and data release decisions.
19.7.2(e) The controlling rule shall be that research ethics review is required when the work affects people, communities, rights, safety, protected knowledge, or public trust.
19.7.3 Human-Subjects Review Where Required. 19.7.3(a) Human-subjects review shall be required where research involves living individuals, identifiable private information, interviews, surveys, observations, behavioral data, health data, biometric data, location data, mobility data, sensor data, community narratives, vulnerable participants, public officials in sensitive roles, or other human-subjects contexts.
19.7.3(b) Human-subjects review shall address consent, capacity, voluntariness, withdrawal, risk, confidentiality, privacy, data minimization, retention, de-identification, re-identification risk, compensation, accessibility, accommodations, vulnerable participant protections, and grievance pathways.
19.7.3(c) Participation in GCRI Canada programs, rooms, workshops, simulations, public authority learning, Academy activities, or community processes shall not be used as research participation without appropriate notice, authority, review, and consent where required.
19.7.3(d) Human-subjects data shall not be published, mapped, embedded, trained on, shared, or used in AI systems beyond recorded authority and safeguards.
19.7.3(e) The controlling rule shall be that people are not evidence inputs unless lawful, ethical, and protected conditions exist.
19.7.4 Community Review Where Required or Appropriate. 19.7.4(a) Community review shall be required or appropriate where research materially affects communities, vulnerable groups, remote communities, Indigenous communities, local knowledge holders, protected persons, community-protected information, culturally sensitive sites, environmental knowledge, public health vulnerabilities, or public-safe mapping risks.
19.7.4(b) Community review may address purpose, context, benefit, risk, representation, consent or non-consent, withdrawal, grievance, remedy, publication, mapping, data reuse, public-safe summaries, and correction paths.
19.7.4(c) Community participation shall not be treated as extraction, endorsement, public authority approval, permission for unrestricted publication, or consent for unrelated reuse.
19.7.4(d) Where community review identifies risk of harm, misdescription, exposure, stigmatization, re-identification, cultural harm, ecological harm, or protected knowledge misuse, GCRI Canada shall narrow, restrict, redesign, pause, or refuse the research as appropriate.
19.7.4(e) The controlling rule shall be that affected communities must not be converted into unprotected research surfaces.
19.7.5 Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, and Protected Knowledge Protocols. 19.7.5(a) Research involving Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, community-held knowledge, sacred knowledge, culturally sensitive information, ecological knowledge, land-based knowledge, or Protected Knowledge shall comply with applicable protocols, authority, consent or non-consent requirements, restrictions, confidentiality, data sovereignty expectations, and public-safe review.
19.7.5(b) Such knowledge shall not be extracted, mapped, modeled, translated, summarized, published, digitized, embedded, trained on, commercialized, or reused without proper safeguards and recorded authority.
19.7.5(c) GCRI Canada shall respect restrictions on location precision, attribution, access, seasonal knowledge, cultural context, community ownership, ceremonial knowledge, ecological sensitivity, and intergenerational knowledge.
19.7.5(d) Research outputs shall not expose protected persons, sensitive sites, ecological vulnerabilities, infrastructure vulnerabilities, community-protected information, or protected knowledge through dashboards, maps, reports, datasets, AI outputs, or public repositories.
19.7.5(e) The controlling rule shall be that protected knowledge remains protected even when it is relevant to public-good evidence.
19.7.6 Health-Sensitive, Public Health, Biosecurity, Sensor, Geospatial, Mobility, AI, and Rights-Bearing Data Legal Review Where Applicable. 19.7.6(a) Legal review shall be required where research involves health-sensitive data, public health data, biosecurity data, clinical data, environmental health data, wastewater data, sensor data, geospatial data, mobility data, biometric data, AI-derived data, rights-bearing data, Public Authority Data, cyber-sensitive data, infrastructure-sensitive data, or vulnerable population data where risk exists.
19.7.6(b) Review shall address lawful basis, ethics approval, consent or authority, purpose limitation, minimization, classification, security, retention, de-identification, aggregation, re-identification risk, cross-border transfer, sovereign data, AI-use limits, publication limits, public-safe mapping, and correction.
19.7.6(c) Health-sensitive and biosecurity research shall be assessed for public harm, stigmatization, misuse, dual-use risk, misinformation risk, public warning confusion, emergency command confusion, and Public Authority boundary concerns.
19.7.6(d) AI use in such research shall require model register entries, data authority, human review, bias review, output validation, inference records where material, and prohibition on unauthorized training or embedding.
19.7.6(e) The controlling rule shall be that high-impact data research requires heightened legal and safeguard review before collection, analysis, release, or reuse.
19.7.7 Publication, Public-Safe Mapping, Dashboards, and Public Reports Legal Review Where Risk Exists. 19.7.7(a) Publication, public-safe mapping, dashboards, datasets, technical notes, whitepapers, reports, public authority learning materials, media materials, and public-safe summaries shall receive legal review where risk exists.
19.7.7(b) Review shall address privacy, confidentiality, data rights, Public Authority references, public warning boundaries, emergency command boundaries, finance boundaries, certification boundaries, IP, defamation risk, public harm, cybersecurity, infrastructure sensitivity, protected knowledge, controlled technology, sanctions, export controls, and research ethics.
19.7.7(c) Maps and dashboards shall be reviewed for sensitive-location exposure, over-precision, stale data, misleading visualization, public authority implication, public warning implication, finance implication, provider implication, and correction path.
19.7.7(d) Public reports shall preserve limitations, uncertainty, confidence, source lineage, conflicts, sponsor roles, provider roles, AI use, public-safe status, and boundary language.
19.7.7(e) The controlling rule shall be that publication legality must be reviewed before public reliance is invited.
19.7.8 Research Misconduct, Ethics Breach, Consent Breach, Data Breach, or Protected Knowledge Breach Requires Correction and Remediation. 19.7.8(a) Research misconduct, ethics breach, consent breach, data breach, privacy breach, AI misuse, publication breach, Public Authority Data breach, community safeguard breach, or Protected Knowledge breach shall require correction and remediation.
19.7.8(b) Research misconduct may include fabrication, falsification, plagiarism, undisclosed conflicts, suppressed uncertainty, improper authorship, improper peer review, data manipulation, source misrepresentation, AI-generated false citation, or failure to correct known errors.
19.7.8(c) Corrective action may include research hold, data quarantine, publication withdrawal, retraction, correction, participant notice, community consultation, Public Authority notice, ethics board notice, funder notice, legal review, access revocation, discipline, training, and policy amendment.
19.7.8(d) Remediation shall protect participants, communities, protected knowledge, public trust, data rights, legal obligations, and downstream dependencies.
19.7.8(e) The controlling rule shall be that research breach correction is part of research integrity, not reputational failure.
19.7.9 Research Compliance Records, Ethics Approvals, Conditions, Deviations, Incidents, and Closeout. 19.7.9(a) GCRI Canada shall maintain research compliance records, ethics approvals, conditions, deviations, incidents, corrections, and closeout records.
19.7.9(b) Records shall identify research title, Case ID where applicable, protocol, owner, custodian, investigators, participants where appropriate, ethics review status, approvals, conditions, consent materials, data classes, AI use, cybersecurity controls, Public Authority involvement, community review, protected knowledge safeguards, publication status, deviations, incidents, corrections, and closeout.
19.7.9(c) Deviations shall be documented and reviewed for whether they require ethics notification, participant notice, legal review, public-safe correction, controlled notice, or research suspension.
19.7.9(d) Closeout shall include data disposition, publication status, access revocation, repository status, correction path, retention, archive, and unresolved issue review.
19.7.9(e) The controlling rule shall be that research compliance must be traceable from protocol through closeout and correction.
19.7.10 Research Legal Compliance Assurance. 19.7.10(a) GCRI Canada shall conduct Research Legal Compliance Assurance.
19.7.10(b) Assurance shall review protocols, ethics approvals, human-subjects review, community review, Indigenous and protected knowledge protocols, data governance, AI use, cybersecurity, conflicts, peer review, publication review, grant terms, incidents, corrections, and closeout.
19.7.10(c) Assurance shall identify missing review, expired approvals, unapproved deviations, consent gaps, data misuse, protected knowledge risks, publication overclaim, public-safe mapping risks, AI misuse, and unresolved corrections.
19.7.10(d) Findings may require ethics review, legal review, data remediation, publication correction, access restriction, community consultation, Public Authority clarification, training, policy amendment, or Board / committee reporting.
19.7.10(e) The controlling rule shall be that research compliance must be assured because research risk changes as data, methods, participants, and publications evolve.
19.8 Privacy and Data Protection Compliance
19.8.1 GCRI Canada Shall Comply With Applicable Canadian and Other Relevant Privacy and Data Protection Laws. 19.8.1(a) GCRI Canada shall comply with applicable Canadian and other relevant privacy and data protection laws, contractual obligations, public authority terms, research ethics conditions, grant terms, donor restrictions, platform terms, data sharing agreements, and internal policies.
19.8.1(b) Privacy and data protection compliance shall apply to collection, creation, receipt, access, use, analysis, storage, transfer, sharing, publication, retention, deletion, sealing, archiving, AI use, embedding, retrieval, model use, dashboarding, mapping, dataset release, and correction.
19.8.1(c) GCRI Canada shall treat privacy as a constitutional safeguard of dignity, rights, public trust, lawful authority, and public-safe publication, not merely as administrative compliance.
19.8.1(d) Privacy obligations shall apply to employees, contractors, fellows, advisors, volunteers, participants, Public Authorities, communities, research subjects, donors, sponsors, providers, hosts, users, website visitors where applicable, and other persons whose information may be processed.
19.8.1(e) The controlling rule shall be that data may be used only where lawful authority, purpose, safeguards, security, and correction paths exist.
19.8.2 Personal Information, Sensitive Personal Information, Health-Sensitive Data, Public Authority Data, Rights-Bearing Data, Community-Protected Data, and Protected Knowledge Require Lawful Basis, Purpose Limitation, Minimization, Classification, Security, Retention, Access, Correction, and Deletion Controls. 19.8.2(a) Personal information, sensitive personal information, health-sensitive data, Public Authority Data, rights-bearing data, community-protected data, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, and Protected Knowledge shall require lawful basis, authority, purpose limitation, minimization, classification, security, retention, access, correction, deletion, sealing, and public-safe controls.
19.8.2(b) Data shall not be collected or retained merely because it may be useful, interesting, technically available, publicly accessible, sponsor-provided, provider-provided, AI-generated, scraped, inferred, or convenient.
19.8.2(c) Data classification shall determine access rights, handling class, release class, retention, AI-use restrictions, cross-border transfer limits, publication restrictions, and correction path.
19.8.2(d) Public-safe transformation may include aggregation, redaction, generalization, masking, de-identification, synthetic data, metadata-only release, controlled annexes, or restricted access, subject to re-identification and group harm review.
19.8.2(e) The controlling rule shall be that sensitive, rights-bearing, public authority, community, and protected knowledge data require heightened stewardship from intake to deletion.
19.8.3 Privacy Notices, Consent Where Applicable, Data Rights Requests, Complaints, and Remedies. 19.8.3(a) GCRI Canada shall provide privacy notices, consent mechanisms where applicable, data rights request processes, complaint pathways, grievance pathways, and remedies consistent with applicable law, research ethics, public authority terms, community safeguards, and institutional policy.
19.8.3(b) Privacy notices shall describe purposes, data categories, sources, uses, disclosures, AI use where material, retention, rights, contact points, cross-border transfers where applicable, safeguards, and correction routes in a clear and accessible manner.
19.8.3(c) Consent, where required or used, shall be informed, specific enough for the context, voluntary, recorded, revocable where applicable, and not obtained through coercion, hidden bundling, public authority pressure, sponsor influence, provider influence, or unequal participation conditions.
19.8.3(d) Data rights requests may include access, correction, deletion, restriction, objection, portability, withdrawal, complaint, grievance, or equivalent rights where applicable, and shall be verified, logged, reviewed, answered, denied only on lawful grounds, and remedied where appropriate.
19.8.3(e) The controlling rule shall be that people and communities affected by data must have lawful pathways to understand, challenge, correct, restrict, or remedy its use where applicable.
19.8.4 Privacy Impact Assessments or Equivalent Reviews Where Required or Appropriate. 19.8.4(a) Privacy Impact Assessments or equivalent reviews shall be conducted where required or appropriate for material data activities, high-risk processing, Public Authority Data, health-sensitive data, rights-bearing data, AI systems, cross-border transfers, dashboards, maps, datasets, controlled rooms, clean rooms, data sharing, vendor processing, or public-safe releases.
19.8.4(b) Assessment shall identify purpose, authority, data categories, individuals or communities affected, data flows, systems, vendors, AI use, access rights, security controls, retention, deletion, cross-border transfer, publication risk, re-identification risk, group harm risk, and mitigation.
19.8.4(c) Assessment conditions shall be recorded and implemented before launch, release, sharing, transfer, or publication where risk requires.
19.8.4(d) Assessments shall be renewed where purpose, data class, system, vendor, jurisdiction, AI use, publication class, or risk materially changes.
19.8.4(e) The controlling rule shall be that high-risk data use requires impact review before institutional reliance.
19.8.5 Cross-Border Transfers, Data Localization, Sovereign Data Zones, and Compute-to-Data Legal Review. 19.8.5(a) Cross-border transfers, data localization, sovereign data zones, compute-to-data arrangements, cloud hosting, remote access, AI vendor processing, repository storage, and data-room operation shall receive legal review where risk or law requires.
19.8.5(b) Review shall address jurisdiction, lawful authority, consent or notice where applicable, Public Authority terms, Indigenous or community data expectations, contractual protections, subprocessor access, foreign access risk, security, encryption, deletion, retention, audit, and public-safe release.
19.8.5(c) Sovereign data zones and compute-to-data methods may be required or preferred where Public Authority Data, health-sensitive data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, or community-protected data should not move.
19.8.5(d) Cross-border data movement shall not occur through convenience tools, unauthorized AI systems, uncontrolled repositories, personal accounts, email attachments, informal file sharing, or unapproved cloud services.
19.8.5(e) The controlling rule shall be that data location and access are legal controls, not merely technical choices.
19.8.6 Data Processing Agreements, Data Sharing Agreements, Public Authority Data Agreements, Research Data Agreements, Vendor Agreements, and Subprocessor Agreements. 19.8.6(a) Data processing agreements, data sharing agreements, Public Authority Data agreements, research data agreements, vendor agreements, cloud agreements, AI provider agreements, repository agreements, clean-room agreements, data-room agreements, and subprocessor agreements shall be used where appropriate.
19.8.6(b) Such agreements shall define data categories, roles, authority, purpose, permitted use, prohibited use, AI-use limits, confidentiality, security, access, retention, deletion, return, transfer, subprocessors, breach notice, audit, publication, public-safe release, correction, and closeout.
19.8.6(c) Public Authority Data agreements shall include capacity, authority, scope, permitted use, AI-use limits, retention, transfer, publication, reference approval, correction, and non-endorsement provisions.
19.8.6(d) Vendor and subprocessor agreements shall prohibit unauthorized model training, product improvement, marketing, resale, secondary use, or onward transfer of GCRI Canada data unless lawfully authorized and recorded.
19.8.6(e) The controlling rule shall be that data shared without enforceable terms becomes uncontrolled institutional risk.
19.8.7 AI Data Use, Training, Fine-Tuning, Embedding, Retrieval, Model Improvement, Logs, and Inference Records. 19.8.7(a) AI data use, training, fine-tuning, embedding, retrieval, model improvement, prompts, outputs, logs, inference records, evaluation data, synthetic data, and agentic AI operations shall be governed by legal authority, data classification, AI-use review, cybersecurity controls, human review, and records.
19.8.7(b) No personal information, Public Authority Data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, protected knowledge, confidential materials, or controlled technology shall be entered into unauthorized AI systems or used for unauthorized training, fine-tuning, embedding, retrieval, or model improvement.
19.8.7(c) Material AI outputs shall identify source data, model or system used, authority, prompt or workflow records where appropriate, inference record, human reviewer, limitations, bias review where applicable, public-safe status, and correction path.
19.8.7(d) Embedding stores, retrieval sources, logs, and outputs shall be access-controlled, retained or deleted according to policy, and reviewed for leakage, stale information, unauthorized reuse, and public claims risk.
19.8.7(e) The controlling rule shall be that AI use of data must be legally authorized before it becomes technically possible.
19.8.8 Breach Notification, Incident Response, Remediation, and Public-Safe Communication. 19.8.8(a) Data breaches and privacy incidents shall be handled through breach notification, incident response, remediation, and public-safe communication according to applicable law, contracts, public authority terms, research ethics, community safeguards, and policy.
19.8.8(b) Incidents may include unauthorized access, disclosure, loss, alteration, deletion, download, transfer, publication, AI use, re-identification, embedding leakage, prompt disclosure, inference leakage, or improper public release.
19.8.8(c) Response shall include containment, evidence preservation, classification, impact assessment, legal review, notification assessment, affected person or community assessment, Public Authority assessment, vendor coordination, correction, remediation, and closeout.
19.8.8(d) Public-safe communication shall avoid over-disclosure of personal information, public authority sensitive information, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, or information that would worsen harm.
19.8.8(e) The controlling rule shall be that breach response must protect people, records, systems, public trust, and lawful notification duties.
19.8.9 Privacy Compliance Records, Processing Register, Impact Assessments, Rights Requests, Breach Register, and Corrective Actions. 19.8.9(a) GCRI Canada shall maintain privacy compliance records, a processing register, impact assessments, data rights request records, complaint records, breach register, data sharing records, cross-border transfer records, AI data use records, and corrective action records.
19.8.9(b) Records shall identify processing activity, owner, custodian, purpose, lawful basis or authority, data classes, affected persons or communities, systems, vendors, transfers, retention, deletion, access controls, AI use, public-safe status, review status, incidents, corrections, and closeout.
19.8.9(c) Rights request records shall identify request type, requester verification, date, decision, response, denial grounds where applicable, remedy, escalation, and closure.
19.8.9(d) Breach records shall identify incident, date, affected data, affected persons or communities, containment, notification analysis, notices, remediation, legal review, public-safe communication, and lessons learned.
19.8.9(e) The controlling rule shall be that privacy compliance must be register-valid because data rights depend on traceability.
19.8.10 Privacy Compliance Assurance. 19.8.10(a) GCRI Canada shall conduct Privacy Compliance Assurance.
19.8.10(b) Assurance shall review processing activities, lawful basis, privacy notices, consent records, data classification, minimization, retention, deletion, cross-border transfers, Public Authority Data, rights-bearing data, protected knowledge, AI data use, vendor processing, rights requests, breaches, corrective actions, and public-safe releases.
19.8.10(c) Assurance shall identify unauthorized processing, over-collection, stale data, missing notices, consent gaps, incomplete impact assessments, uncontrolled vendors, unauthorized AI use, missing deletion, public release risk, and unresolved incidents.
19.8.10(d) Findings may require data deletion, sealing, access restriction, notice update, agreement amendment, impact assessment, vendor review, AI restriction, breach remediation, training, policy amendment, legal review, or Board / committee reporting.
19.8.10(e) The controlling rule shall be that privacy compliance must be assured because data risk changes as data moves, systems change, and outputs are reused.
19.9 AI Governance Legal Readiness
19.9.1 AI Governance Legal Readiness as Emerging and Dynamic Compliance Area. 19.9.1(a) AI governance legal readiness shall be treated as an emerging and dynamic compliance area requiring monitoring, review, adaptation, records, training, and correction.
19.9.1(b) GCRI Canada shall recognize that AI legal obligations may arise from Canadian law, provincial or territorial requirements, public-sector rules, privacy law, human rights law, employment law, procurement rules, contractual terms, research ethics, cybersecurity duties, sectoral obligations, foreign law where applicable, and platform terms.
19.9.1(c) AI governance legal readiness shall apply to generative AI, predictive AI, agentic AI, machine learning, foundation models, retrieval systems, embedding systems, model evaluation, AI-assisted research, AI-assisted publication, AI-assisted coding, AI-assisted analysis, AI-assisted translation, dashboards, maps, Truth Engine methods, Observatory methods, and public authority learning.
19.9.1(d) GCRI Canada shall not rely on technological novelty, vendor assurances, public availability, open-source status, or public-good purpose as substitute for legal review where risk exists.
19.9.1(e) The controlling rule shall be that AI compliance must be adaptive because AI law, AI capability, and AI risk evolve.
19.9.2 Monitoring of Applicable AI Laws, Public-Sector AI Rules, Procurement Rules, Contractual AI Requirements, Research Ethics Rules, Privacy Rules, Cybersecurity Rules, Human Rights Rules, and Sectoral Obligations. 19.9.2(a) GCRI Canada shall monitor applicable AI laws, public-sector AI rules, procurement rules, contractual AI requirements, research ethics rules, privacy rules, cybersecurity rules, human rights rules, accessibility rules, employment rules, intellectual property rules, platform terms, and sectoral obligations.
19.9.2(b) Monitoring shall be risk-based and shall focus on jurisdictions, sectors, systems, data classes, Public Authority interfaces, research contexts, employment contexts, health contexts, finance contexts, cyber contexts, and rights-bearing contexts relevant to GCRI Canada.
19.9.2(c) Monitoring may result in policy updates, model restrictions, vendor restrictions, training updates, impact assessment requirements, human review requirements, public-safe publication changes, contract clause changes, or suspension of particular AI uses.
19.9.2(d) Material changes in AI law or obligations shall be escalated to Officers, relevant committees, and the Board where governance action is required.
19.9.2(e) The controlling rule shall be that AI rules must be tracked before outdated practice becomes noncompliance.
19.9.3 AI Use Inventory, Model Register, Inference Records, Human Review, Impact Review, Bias Review, Safety Review, and Incident Records. 19.9.3(a) GCRI Canada shall maintain an AI use inventory, model register, inference records where material, human review records, impact review records, bias review records, safety review records, vendor review records, and AI incident records.
19.9.3(b) The AI use inventory shall identify AI system, purpose, owner, custodian, data classes, model provider, deployment context, access, use limits, approved users, outputs, human review requirements, public-safe status, and correction path.
19.9.3(c) Model register entries shall identify model name, version where known, provider, purpose, data inputs, restrictions, training or fine-tuning status, embedding or retrieval use, logging, retention, security, review status, and limitations.
19.9.3(d) Material AI outputs shall be human-reviewed before reliance, publication, public authority use, finance-sensitive use, employment use, research claim use, dashboard use, map use, or public-safe release.
19.9.3(e) Bias, safety, and impact review shall be heightened where AI affects rights-bearing data, vulnerable persons, communities, public authority learning, employment, health, finance-sensitive contexts, protected knowledge, or public claims.
19.9.3(f) The controlling rule shall be that AI systems and outputs must be inventoried before they can be governed.
19.9.4 AI Training, Fine-Tuning, Embedding, Retrieval, Model Improvement, Vendor Processing, and Agentic AI Legal Review Where Applicable. 19.9.4(a) AI training, fine-tuning, embedding, retrieval, model improvement, vendor processing, agentic AI, automated tool use, autonomous workflow actions, and AI integration with repositories, dashboards, maps, APIs, data rooms, or public authority materials shall receive legal review where applicable.
19.9.4(b) Review shall address data authority, consent or non-consent where applicable, privacy, Public Authority Data, protected knowledge, IP, confidentiality, trade secrets, cyber-sensitive information, controlled technology, vendor terms, retention, logging, model improvement, secondary use, output ownership, and deletion.
19.9.4(c) Agentic AI shall require heightened review where it can retrieve, modify, publish, message, approve, transact, deploy code, alter records, access systems, access repositories, access rooms, or act across organizational boundaries.
19.9.4(d) AI systems shall not be authorized to make material governance, legal, public authority, finance, procurement, employment, research ethics, publication, correction, certification, recognition, or execution decisions.
19.9.4(e) The controlling rule shall be that the legal risk of AI increases when AI acts, learns, retrieves, stores, or is connected to institutional systems.
19.9.5 AI Outputs Shall Not Be Used as Authority Without Proper Human Review, Record, and Legal Basis. 19.9.5(a) AI outputs shall not be used as authority without proper human review, record, and legal basis.
19.9.5(b) AI-generated summaries, classifications, risk scores, evidence notes, dashboard outputs, map outputs, code, citations, translations, public authority learning materials, public claims, legal summaries, finance-sensitive summaries, or technical recommendations shall be treated as draft or support outputs until reviewed and adopted by authorized persons.
19.9.5(c) AI outputs shall not create recognition, certification, finance-readiness, public authority approval, public warning, emergency command, procurement recommendation, provider preference, sponsor validation, legal advice, investment advice, rating, insurance approval, or execution authority.
19.9.5(d) AI hallucination, false citation, unsupported inference, bias, discriminatory output, stale source use, overconfident summary, or boundary overclaim shall require correction before reliance.
19.9.5(e) The controlling rule shall be that AI may assist institutional work but shall not become institutional authority.
19.9.6 AI-Assisted Public Authority Learning, Dashboards, Maps, Evidence Packs, Publications, and Public-Safe Outputs Require Boundary Controls. 19.9.6(a) AI-assisted public authority learning, dashboards, maps, evidence packs, publications, public-safe outputs, Academy materials, technical notes, datasets, software documentation, and controlled annexes shall require boundary controls.
19.9.6(b) Boundary controls shall address AI use disclosure where material, human review, source verification, confidence, uncertainty, limitations, public-safe status, Public Authority boundary language, public warning boundary language, finance-boundary language, no certification by default, no provider preference, no sponsor control, and correction path.
19.9.6(c) AI-assisted dashboards and maps shall be reviewed for stale data, misleading visualization, over-precision, bias, source gaps, public authority implication, public warning implication, protected knowledge exposure, and re-identification risk.
19.9.6(d) Public-safe outputs shall not hide material AI use where disclosure is required or necessary to prevent misunderstanding.
19.9.6(e) The controlling rule shall be that AI-assisted public materials must be more carefully bounded because automation can amplify authority signals.
19.9.7 AI Use in Employment, Participation, Research, Public Authority Contexts, Health Contexts, Finance Contexts, and Rights-Bearing Contexts Requires Heightened Review Where Applicable. 19.9.7(a) AI use in employment, participation, research, Public Authority contexts, health contexts, finance contexts, insurance contexts, procurement contexts, rights-bearing contexts, community contexts, protected knowledge contexts, and vulnerable-person contexts shall require heightened review where applicable.
19.9.7(b) Employment-related AI use shall not be used for hiring, evaluation, discipline, termination, access, or classification decisions without legal review, human review, bias review, privacy review, and proper records where required.
19.9.7(c) Research and health-related AI use shall require review for ethics, consent, lawful basis, bias, explainability where appropriate, accuracy, public harm, health sensitivity, and public-safe publication.
19.9.7(d) Finance-sensitive AI use shall not generate investment advice, ratings, insurance approvals, public finance approvals, lending decisions, capital-reader recommendations, or transaction recommendations by GCRI Canada.
19.9.7(e) Public Authority and rights-bearing AI use shall preserve lawful public decision-making, non-discrimination, due process concerns where applicable, capacity classification, and no public authority substitution.
19.9.7(f) The controlling rule shall be that AI use affecting rights, public authority, health, employment, finance, or protected knowledge requires heightened legal readiness.
19.9.8 AI Incidents, Unsafe Outputs, Bias, Discrimination, Hallucination, Data Leakage, Model Drift, Unauthorized Agent Actions, and Public Overclaim Require Correction. 19.9.8(a) AI incidents, unsafe outputs, bias, discrimination, hallucination, false citation, source fabrication, data leakage, prompt leakage, embedding leakage, retrieval leakage, model drift, unauthorized agent actions, unauthorized training, unauthorized fine-tuning, unauthorized model improvement, public overclaim, or boundary breach shall require correction.
19.9.8(b) Correction may include output withdrawal, publication correction, model restriction, access revocation, data deletion, embedding deletion, prompt and log review, vendor notice, incident response, public-safe notice, controlled notice, legal review, retraining prohibition, system suspension, or termination of use.
19.9.8(c) AI incidents shall be assessed for affected data, affected persons, affected communities, affected Public Authorities, affected publications, affected finance-sensitive materials, affected public claims, and downstream reliance.
19.9.8(d) Repeated AI incidents shall trigger model review, vendor review, policy amendment, training, system replacement, or prohibition of the use case.
19.9.8(e) The controlling rule shall be that AI errors must be corrected at the output, system, data, and governance levels.
19.9.9 AI Legal Readiness Register and Monitoring. 19.9.9(a) GCRI Canada shall maintain an AI Legal Readiness Register and monitoring process.
19.9.9(b) The Register shall identify applicable AI obligations, monitored jurisdictions, systems, use cases, models, vendors, data classes, impact reviews, human review requirements, bias reviews, public-safe controls, Public Authority controls, finance-boundary controls, incidents, corrections, policy updates, training updates, and review cycles.
19.9.9(c) Monitoring shall track legal developments, public-sector rules, contractual AI requirements, vendor terms, platform terms, research ethics rules, privacy obligations, cybersecurity obligations, human rights obligations, and sectoral requirements.
19.9.9(d) Register entries shall be updated where law, model behavior, vendor terms, data classes, use cases, public claims, or risk materially changes.
19.9.9(e) The controlling rule shall be that AI legal readiness must be recorded because AI obligations can change faster than institutional habits.
19.9.10 AI Governance Compliance Assurance. 19.9.10(a) GCRI Canada shall conduct AI Governance Compliance Assurance.
19.9.10(b) Assurance shall review AI inventories, model registers, AI-use approvals, data authority, vendor terms, training prohibitions, embedding controls, retrieval controls, inference records, human review, impact assessments, bias reviews, safety reviews, public-safe outputs, incidents, corrections, and legal monitoring.
19.9.10(c) Assurance shall identify unauthorized AI tools, sensitive data in unauthorized systems, missing model records, missing human review, hallucination risk, public overclaim, bias risk, vendor misuse, uncontrolled agentic actions, missing deletion, and unresolved incidents.
19.9.10(d) Findings may require access restriction, model restriction, vendor restriction, data deletion, output correction, publication withdrawal, policy update, training, legal review, Board / committee reporting, or prohibition of particular AI uses.
19.9.10(e) The controlling rule shall be that AI governance must be assured because AI risk is operational, legal, technical, and semantic at the same time.
19.10 Cybersecurity Legal and Contractual Compliance
19.10.1 Cybersecurity Compliance Shall Be Proportionate to Data Sensitivity, System Criticality, Public Authority Data, Infrastructure Sensitivity, Cyber-Sensitive Materials, Community-Protected Knowledge, and Public Trust Risk. 19.10.1(a) Cybersecurity compliance shall be proportionate to data sensitivity, system criticality, Public Authority Data, infrastructure sensitivity, cyber-sensitive materials, community-protected knowledge, protected knowledge, rights-bearing data, public trust risk, legal obligations, contractual obligations, grant obligations, and Nexus interface risk.
19.10.1(b) Cybersecurity compliance shall apply to systems, repositories, cloud services, compute environments, AI tools, dashboards, maps, APIs, datasets, controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, capital-reader rooms, endpoints, identities, keys, tokens, secrets, software releases, and public-good technical assets.
19.10.1(c) Security controls shall be risk-based, records-valid, access-controlled, monitored where appropriate, incident-ready, correctionable, and aligned with privacy, data protection, public-safe publication, protected knowledge, and legal separateness.
19.10.1(d) Public-good purpose, open-source intent, academic collaboration, sponsor support, provider support, volunteer contribution, or urgent public-interest context shall not excuse disproportionate cybersecurity weakness.
19.10.1(e) The controlling rule shall be that cybersecurity is a legal and constitutional safeguard wherever digital systems carry trust.
19.10.2 Compliance With Applicable Cybersecurity Laws, Contractual Security Obligations, Grant Conditions, Public Authority Requirements, Data Processing Requirements, and Repository / Platform Requirements. 19.10.2(a) GCRI Canada shall comply with applicable cybersecurity laws, contractual security obligations, grant conditions, Public Authority requirements, data processing requirements, vendor security obligations, repository requirements, platform requirements, insurance conditions, and internal policies.
19.10.2(b) Security obligations may arise from privacy law, data protection law, public authority agreements, research data agreements, grant agreements, sponsorship agreements, vendor contracts, cloud terms, AI provider terms, software repository terms, insurance policies, and participant agreements.
19.10.2(c) Security requirements shall be translated into operational controls, including identity and access management, MFA where appropriate, encryption, logging, monitoring, vulnerability management, secure development, secrets management, backup, incident response, breach handling, secure release, and vendor controls.
19.10.2(d) Failure to implement contractual or legal security obligations shall be treated as a compliance incident and corrected.
19.10.2(e) The controlling rule shall be that cybersecurity promises must become implemented controls and auditable records.
19.10.3 Security Program, Incident Response, Breach Handling, Vulnerability Management, Secure Development, Secure Release, and Business Continuity. 19.10.3(a) GCRI Canada shall maintain a security program proportionate to its risk, including incident response, breach handling, vulnerability management, secure development, secure release, repository security, secrets management, business continuity, disaster recovery, third-party security, and training.
19.10.3(b) Incident response shall provide intake, triage, severity classification, containment, evidence preservation, investigation, legal review, privacy review, Public Authority review, communications review, remediation, notification, correction, and closeout.
19.10.3(c) Vulnerability management shall address discovery, reporting, triage, remediation, patching, disclosure, public-safe advisories, dependency updates, SBOM where applicable, and secure release.
19.10.3(d) Secure development and secure release shall address code review, AI-generated code review, dependency review, branch protection, signing, hashing, secrets scanning, sensitive data scanning, export-control review, release notes, known issues, and rollback.
19.10.3(e) Business continuity shall address critical systems, repositories, records, controlled rooms, data rooms, public-good software, technical baselines, incident communications, backups, restoration, vendor dependency, platform dependency, and key-person risk.
19.10.3(f) The controlling rule shall be that cybersecurity compliance requires a functioning program, not isolated controls.
19.10.4 Cyber-Sensitive Research and Vulnerability Disclosure Legal Review. 19.10.4(a) Cyber-sensitive research and vulnerability disclosure shall receive legal review where risk exists.
19.10.4(b) Cyber-sensitive research may include vulnerability discovery, exploit analysis, malware analysis, offensive-security methods, penetration testing, threat intelligence, infrastructure scans, cyber incident analysis, AI security testing, telecom security, AI-RAN security, DePIN security, repository compromise analysis, and supply-chain security research.
19.10.4(c) Legal review shall address authorization, scope, permission, responsible disclosure, publication risk, dual-use risk, export controls, sanctions, law enforcement sensitivity, public authority sensitivity, infrastructure sensitivity, data protection, and public-safe release.
19.10.4(d) Vulnerability disclosure shall be coordinated, lawful, public-safe, time-bound where appropriate, records-valid, and protective of affected systems, users, Public Authorities, providers, hosts, communities, and technical dependencies.
19.10.4(e) The controlling rule shall be that cybersecurity research must not create the harm it seeks to reduce.
19.10.5 Controlled Technology, Export Controls, Sanctions, Cryptography, AI-RAN, DePIN, Cyber Tools, Geospatial, Satellite, Drone, Robotics, Autonomous Systems, Quantum-Relevant Systems, and Dual-Use Cyber Review. 19.10.5(a) Controlled technology, export controls, sanctions, cryptography, AI-RAN, O-RAN, private wireless, DePIN, cyber tools, geospatial systems, satellite and Earth observation systems, drones, robotics, autonomous systems, quantum-relevant systems, dual-use cyber tools, controlled technical data, model weights, source code, secure enclaves, and high-performance compute shall receive review where applicable.
19.10.5(b) Review shall address item classification, jurisdiction, destination, end use, end user, deemed export risk, controlled technical data, publication, repository access, cloud access, compute access, model access, foreign person access where applicable, open-source release, controlled room participation, and public-safe publication.
19.10.5(c) GCRI Canada shall not transfer, publish, release, upload, train, embed, route, or provide access to controlled technology or restricted technical data without lawful authority and proper records.
19.10.5(d) Public-good technical baseline work shall be structured to preserve lawful openness while respecting controlled-technology restrictions.
19.10.5(e) The controlling rule shall be that advanced technical stewardship must be open where lawful and controlled where required.
19.10.6 Third-Party, Vendor, Provider, Cloud, AI Provider, Repository Provider, and Subprocessor Security Terms. 19.10.6(a) Third-party, vendor, provider, cloud, AI provider, repository provider, software provider, data room provider, clean-room provider, compute provider, and subprocessor security terms shall be reviewed and controlled.
19.10.6(b) Security terms shall address confidentiality, access control, MFA where appropriate, encryption, logging, breach notice, incident cooperation, vulnerability management, subprocessor limits, data residency, deletion, return, backup, audit rights, AI-use restrictions, model-training restrictions, product-improvement restrictions, business continuity, exit rights, and secure disposal.
19.10.6(c) Providers shall not use GCRI Canada data, prompts, embeddings, outputs, logs, Public Authority Data, protected knowledge, or confidential materials for model training, product improvement, marketing, resale, or secondary use unless lawfully authorized and recorded.
19.10.6(d) Third-party security failures shall require incident response, access restriction, remediation, contract remedy, termination, notice, or public-safe correction where appropriate.
19.10.6(e) The controlling rule shall be that outsourcing technology does not outsource GCRI Canada’s security duty.
19.10.7 Security Incidents, Breach Notifications, Public-Safe Advisories, and Corrective Actions. 19.10.7(a) Security incidents, breach notifications, public-safe advisories, and corrective actions shall be handled according to applicable law, contract, policy, insurance terms, public authority terms, data protection requirements, and public-safe communication rules.
19.10.7(b) Security incidents may include unauthorized access, credential compromise, key compromise, token exposure, repository compromise, malware, ransomware, supply-chain attack, vulnerability exposure, data leakage, AI data leakage, dashboard compromise, API compromise, sensor compromise, room breach, or provider incident.
19.10.7(c) Notifications shall be assessed for affected persons, affected communities, Public Authorities, vendors, providers, sponsors, donors, grantors, insurers, regulators, and other required recipients.
19.10.7(d) Public-safe advisories shall avoid exposing exploit details, sensitive systems, protected knowledge, personal information, Public Authority Data, or infrastructure vulnerabilities beyond what is necessary to reduce harm.
19.10.7(e) Corrective actions shall include remediation, patching, access revocation, key rotation, credential reset, data deletion, publication correction, vendor remedy, training, control updates, and assurance follow-up.
19.10.7(f) The controlling rule shall be that security incident response must repair systems, records, duties, communications, and trust.
19.10.8 Cybersecurity Audit, Review, Testing, and Assurance Where Required. 19.10.8(a) Cybersecurity audit, review, testing, assessment, penetration testing, vulnerability scanning, configuration review, repository review, secure release review, third-party review, or assurance shall be conducted where required by law, contract, grant, Public Authority terms, insurance, Board policy, risk profile, or public trust.
19.10.8(b) Testing shall be authorized, scoped, documented, lawful, proportionate, and coordinated to avoid service disruption, privacy breach, public authority harm, protected knowledge exposure, or uncontrolled vulnerability disclosure.
19.10.8(c) Audit and testing findings shall be classified, assigned, remediated, verified, and reported according to risk.
19.10.8(d) High-risk findings involving Public Authority Data, personal information, protected knowledge, controlled technology, repository compromise, supply-chain risk, AI leakage, or public interfaces shall be escalated.
19.10.8(e) The controlling rule shall be that cybersecurity assurance must be lawful, scoped, and corrective.
19.10.9 Cybersecurity Compliance Records and Incident Register. 19.10.9(a) GCRI Canada shall maintain cybersecurity compliance records and a Cybersecurity Incident Register.
19.10.9(b) Records shall include system registers, asset registers, identity and access records, privileged access records, key / token / secret records, repository security records, vulnerability records, patch records, SBOM records, secure release records, third-party security records, incident records, breach records, business continuity records, disaster recovery records, audit records, testing records, and corrective action records.
19.10.9(c) Incident records shall identify incident type, date, reporter, affected systems, affected data, affected persons or communities, severity, containment, investigation, legal review, notification analysis, remediation, public-safe communication, corrective actions, and closeout.
19.10.9(d) Security records shall be classified, access-controlled, retained, archived, and protected from silent edit according to risk.
19.10.9(e) The controlling rule shall be that cybersecurity compliance must be provable by record before it can be trusted.
19.10.10 Cybersecurity Legal Compliance Assurance. 19.10.10(a) GCRI Canada shall conduct Cybersecurity Legal Compliance Assurance.
19.10.10(b) Assurance shall review applicable legal and contractual security obligations, system classifications, access controls, key management, repository security, secure collaboration, controlled rooms, clean rooms, AI systems, cloud systems, vendor terms, incident response, breach handling, vulnerability management, secure release, business continuity, and training.
19.10.10(c) Assurance shall identify missing controls, unimplemented contractual obligations, stale access, weak authentication, unrotated secrets, missing incident records, unresolved vulnerabilities, unauthorized tools, insecure releases, vendor gaps, AI leakage risk, and missing breach notification analysis.
19.10.10(d) Findings may require access restriction, key rotation, contract amendment, vendor review, security remediation, incident correction, training, policy update, legal review, Board / committee reporting, or suspension of affected systems.
19.10.10(e) The controlling rule shall be that cybersecurity legal compliance must be assured because legal duties, systems, vendors, threats, and public trust risk continuously change.
19.16 Finance and Regulated Financial Perimeter
19.16.1 GCRI Canada Shall Maintain Regulated Financial-Perimeter Discipline. 19.16.1(a) GCRI Canada shall maintain regulated financial-perimeter discipline in all activities involving evidence, methods, technical baselines, Proof Pack inputs, GRA interfaces, capital-reader rooms, RNFD / NFD / UNFSD support, public finance reader participation, public authority learning, grants, donations, sponsorships, in-kind contributions, cost recovery, technical releases, blockchain, DLT, DePIN, tokenized records, proof infrastructure, finance-sensitive data, and public claims.
19.16.1(b) Regulated financial-perimeter discipline means that GCRI Canada shall not, by design, practice, communication, interface, room, record, publication, dashboard, map, data release, technical baseline, proof receipt, evidence pack, or public statement, cross into activity requiring authorization as a financial adviser, securities dealer, broker, finder, placement agent, investment fund manager, portfolio manager, lender, guarantor, insurer, insurance broker, underwriter, rating agency, payment intermediary, custodian, market operator, exchange, clearing system, digital asset issuer, token issuer, or public finance approval body.
19.16.1(c) GCRI Canada may steward technical evidence, methods, observability, ontology, public-good R&D, public-good software, Open Technical Baselines, technical truth, public-safe summaries, controlled annexes, and public authority learning materials, but such functions shall not become financial-services activity by implication.
19.16.1(d) Any activity capable of being understood as financial advice, investment recommendation, transaction intermediation, insurance approval, rating, guarantee, public finance approval, or capital solicitation shall be reviewed, narrowed, routed to competent actors, corrected, or refused.
19.16.1(e) The controlling rule shall be that GCRI Canada may make technical evidence legible but shall not make capital decisions.
19.16.2 No Investment Advice, Securities Offering, Solicitation, Brokerage, Finder Activity, Placement, Lending, Guarantee, Insurance Placement, Underwriting, Rating, Public Finance Approval, Fund Management, Asset Management, Payment Intermediation, Custody, Token Issuance, or Market Operation by Default. 19.16.2(a) GCRI Canada shall not provide investment advice, securities advice, securities offering materials, solicitation, brokerage, finder activity, placement activity, capital raising, lending, guarantee, insurance placement, underwriting, rating, credit approval, public finance approval, grant approval, budget approval, MDB / DFI approval, sovereign finance approval, fund management, asset management, payment intermediation, custody, token issuance, exchange operation, market operation, clearing, settlement, or transaction execution by default.
19.16.2(b) No evidence record, technical baseline, dashboard, map, report, public-safe summary, Proof Pack input, diligence gap map, GRA interface, RNFD / NFD / UNFSD material, capital-reader room material, public authority learning material, or technical note shall be interpreted as any such regulated or finance-execution activity unless a separate lawful authority, outside GCRI Canada’s prohibited functions, expressly supports that exact role.
19.16.2(c) GCRI Canada shall not describe any project, National Company, Project SPV, provider, host, sponsor, public authority initiative, technology, infrastructure proposal, dataset, technical system, or Nexus activity as investable, bankable, finance-ready, insurance-ready, creditworthy, rated, guaranteed, underwritten, approved for public finance, approved for grant funding, approved for procurement, or capital-committed by GCRI Canada.
19.16.2(d) Any request that would require GCRI Canada to opine on investment suitability, pricing, securities, debt, equity, insurance coverage, credit support, guarantees, ratings, public finance eligibility, token value, or transaction structure shall be declined, reframed as bounded technical evidence support, or routed to a competent actor where lawful.
19.16.2(e) The controlling rule shall be that financial status cannot arise from GCRI Canada evidence, proximity, support, or technical review.
19.16.3 Finance-Readiness Evidence Inputs Shall Be Routed Through GRA Where Applicable and Controlled With Finance-Safe Language. 19.16.3(a) Finance-readiness evidence inputs shall be routed through The Global Risks Alliance (GRA) where applicable and controlled with finance-safe language.
19.16.3(b) GCRI Canada may provide bounded evidence inputs, methods notes, source-lineage records, technical baseline inputs, observability evidence, Truth Engine outputs, public-good software notes, data governance notes, AI governance notes, cybersecurity notes, host readiness evidence, safeguards notes, limitations, uncertainty statements, public-safe summaries, controlled annexes, and correction records to GRA-facing processes.
19.16.3(c) Each input shall identify source authority, scope, version, date, owner, custodian, confidence, limitations, dependencies, public-safe status, finance-safe status, permitted use, prohibited use, and correction path.
19.16.3(d) Finance-safe language shall state, where risk exists, that GCRI Canada inputs are not investment advice, securities solicitation, brokerage, placement, lending approval, insurance approval, rating, guarantee, public finance approval, grant approval, procurement approval, provider endorsement, sponsor validation, or transaction recommendation.
19.16.3(e) The controlling rule shall be that GRA may receive GCRI Canada evidence, but GCRI Canada shall not become GRA or a regulated finance actor through that interface.
19.16.4 Capital-Reader Rooms Shall Be Reading and Learning Environments Only Unless Separately and Lawfully Structured by Proper Actors Outside GCRI Canada’s Prohibited Functions. 19.16.4(a) Capital-reader rooms involving GCRI Canada materials shall be reading and learning environments only unless separately and lawfully structured by proper actors outside GCRI Canada’s prohibited functions.
19.16.4(b) Capital-reader rooms may allow controlled review of evidence, methods, technical baselines, diligence gap maps, public-safe summaries, controlled annexes, risk evidence, cybersecurity notes, data governance notes, AI governance notes, public authority learning materials, and GRA-routed materials, subject to access controls and finance-boundary language.
19.16.4(c) Capital-reader room participation shall not create investment recommendation, securities solicitation, lending approval, insurance approval, rating, guarantee, public finance approval, grant approval, capital commitment, transaction allocation, underwriting, brokerage, placement, or finder activity by GCRI Canada.
19.16.4(d) Capital-reader room controls shall include participant classification, purpose statement, materials index, access class, handling class, no-solicitation language, no-advice language, no-rating language, no-guarantee language, no-public-finance-approval language, no-commitment language, confidentiality, logging where appropriate, copy controls, AI-use restrictions, and closeout.
19.16.4(e) The controlling rule shall be that capital readers may read GCRI Canada evidence, but reading shall not become reliance on GCRI Canada as a capital actor.
19.16.5 Token, Blockchain, DLT, DePIN, Digital Asset, Payment, Identity, Registry, and Proof Infrastructure Activities Require Regulated-Perimeter Review Where Applicable. 19.16.5(a) Token, blockchain, DLT, Web3, DePIN, digital asset, payment, identity, registry, proof receipt, proof infrastructure, on-chain anchoring, smart license, entitlement state, digital credential, wallet, custody, payment, staking, reward, or tokenized record activities shall require regulated-perimeter review where applicable.
19.16.5(b) Review shall address whether the activity could involve securities, derivatives, commodities, payment services, money transmission, custody, wallet services, exchange activity, investment contracts, token issuance, fundraising, market operation, financial promotion, identity regulation, privacy, consumer protection, sanctions, anti-money-laundering duties, export controls, tax, or public authority implications.
19.16.5(c) GCRI Canada shall maintain no-PII-on-chain discipline and shall not place personal information, Public Authority Data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, Indigenous or Protected Knowledge, confidential materials, or controlled technology on-chain unless lawful authority, risk review, safeguards, and public-safe or controlled handling expressly support the method.
19.16.5(d) Proof receipts, hashes, signatures, timestamps, anchors, tokenized references, or registry entries shall be treated as technical receipts and shall not become legal authority, finance-readiness, recognition, certification, public authority approval, procurement approval, or execution authority by default.
19.16.5(e) The controlling rule shall be that proof infrastructure may support record integrity but shall not create regulated financial, public authority, or market effect without proper authority.
19.16.6 Public Finance Reader Participation Does Not Create Public Finance Approval. 19.16.6(a) Public finance reader participation does not create public finance approval.
19.16.6(b) Attendance, observation, data review, evidence review, dashboard access, map access, capital-reader room participation, RNFD / NFD / UNFSD participation, public authority learning, GRA interface participation, or receipt of GCRI Canada materials by finance ministries, public finance bodies, MDBs, DFIs, grant bodies, public guarantee bodies, public credit bodies, or other public finance actors shall not create budget allocation, grant approval, public finance approval, sovereign finance approval, public guarantee, public credit, MDB / DFI commitment, public debt, public-private partnership, public adoption, or public procurement approval.
19.16.6(c) Public finance reader materials shall include capacity classification, no-approval language, no-commitment language, no-guarantee language, no-budget language, no-public-debt language, no-procurement language, no-adoption language, and no-sovereign-obligation language where risk exists.
19.16.6(d) Public finance reader references in public materials shall require approval and shall not be used as evidence of endorsement, commitment, adoption, funding, procurement, or public authority support.
19.16.6(e) The controlling rule shall be that public finance meaning arises only through competent public finance authority, not through GCRI Canada proximity.
19.16.7 Financial-Law Risk Requires Legal Review. 19.16.7(a) Financial-law risk shall require legal review where material.
19.16.7(b) Financial-law risk may arise from Proof Packs, diligence gap maps, insurance-readiness inputs, GRA interfaces, RNFD / NFD / UNFSD support, capital-reader rooms, public finance readers, public authority finance materials, tokenized records, digital assets, DLT systems, DePIN incentives, payment features, custody-like arrangements, financing references, project funding references, investment references, insurance references, ratings-like language, grant readiness, bankability, capital-readability, or transaction-adjacent communications.
19.16.7(c) Legal review shall address applicable securities, investment, insurance, lending, banking, payments, custody, digital asset, public finance, anti-money-laundering, sanctions, tax, consumer protection, professional advice, and public authority requirements.
19.16.7(d) Pending review, the activity may be held, narrowed, reclassified, restricted, routed to GRA, routed to competent financial or public authority actors, corrected, or refused.
19.16.7(e) The controlling rule shall be that financial-law ambiguity is a stop-and-review condition.
19.16.8 Financial-Perimeter Breach Requires Hold, Correction, Withdrawal, Retraction, Legal Review, and Remediation. 19.16.8(a) A financial-perimeter breach shall require hold, correction, withdrawal, retraction, legal review, remediation, access restriction, public-safe clarification, controlled notice, Board or committee reporting, and training where appropriate.
19.16.8(b) Breach includes any statement, material, room practice, public claim, sponsor claim, provider claim, public authority claim, GRA interface claim, token claim, proof receipt claim, dashboard claim, map claim, report claim, or participant conduct suggesting that GCRI Canada has provided investment advice, securities solicitation, brokerage, finder activity, lending approval, guarantee, insurance approval, underwriting, rating, public finance approval, grant approval, MDB / DFI approval, sovereign finance approval, capital commitment, token issuance, payment intermediation, custody, or market operation.
19.16.8(c) Corrective review shall identify affected materials, affected rooms, affected audiences, affected Public Authorities, affected capital readers, affected sponsors, affected providers, affected GRA records, affected public claims, reliance risk, and legal exposure.
19.16.8(d) Remediation may include revised boundary language, public-safe notice, controlled notice, takedown request, materials withdrawal, room redesign, access revocation, relationship remedy, legal notification where required, and assurance follow-up.
19.16.8(e) The controlling rule shall be that financial-perimeter breaches must be corrected before evidence becomes financial reliance.
19.16.9 Finance Legal Boundary Register. 19.16.9(a) GCRI Canada shall maintain a Finance Legal Boundary Register.
19.16.9(b) The Register shall identify finance-sensitive activities, GRA interfaces, Proof Pack inputs, diligence gap maps, insurance-readiness inputs, capital-reader rooms, RNFD / NFD / UNFSD interfaces, public finance reader participation, token / blockchain / DLT / DePIN / proof infrastructure activities, payment-adjacent activities, digital asset references, public finance references, finance-sensitive data, legal reviews, boundary language, permitted uses, prohibited uses, incidents, corrections, and closeout.
19.16.9(c) The Register shall distinguish technical evidence inputs from finance-readiness outputs, public authority learning from public finance approval, capital-reader access from solicitation, proof receipts from legal authority, and finance-sensitive data from public release.
19.16.9(d) The Register shall link to GRA interface records, public authority records, room records, publication records, contract records, grant records, sponsorship records, data records, correction records, and financial incident records where applicable.
19.16.9(e) The controlling rule shall be that finance-boundary risk must be separately registered because finance meaning can arise from context, repetition, and audience.
19.16.10 Finance Legal Boundary Assurance. 19.16.10(a) GCRI Canada shall conduct Finance Legal Boundary Assurance.
19.16.10(b) Assurance shall review finance-sensitive activities, GRA interfaces, Proof Pack inputs, capital-reader rooms, public finance reader participation, RNFD / NFD / UNFSD materials, token / blockchain / DLT / DePIN / proof infrastructure activities, public claims, sponsor claims, provider claims, public authority references, room materials, boundary language, legal reviews, incidents, and corrections.
19.16.10(c) Assurance shall identify financial-services drift, investment-advice implication, securities-solicitation implication, brokerage implication, finder implication, lending implication, guarantee implication, insurance implication, rating implication, public finance implication, token issuance implication, payment implication, custody implication, market-operation implication, and uncorrected overclaim.
19.16.10(d) Findings may require legal review, GRA routing, material correction, room redesign, access restriction, public-safe notice, controlled notice, policy update, training, relationship remedy, suspension, termination, or Board reporting.
19.16.10(e) The controlling rule shall be that finance-boundary compliance must be assured because finance risk often appears through language, audience, and interface design before formal transaction activity occurs.
19.17 Intellectual Property, Licensing, and Open Release Legal Compliance
19.17.1 IP Ownership, Assignment, Licensing, Contribution, Moral Rights, Attribution, Third-Party Rights, Patent, Defensive Publication, Data Rights, Model Rights, and Software Rights Shall Be Governed by Law and Agreements. 19.17.1(a) IP ownership, assignment, licensing, contribution, moral rights, attribution, third-party rights, patent rights, defensive publication, data rights, model rights, software rights, database rights, documentation rights, schema rights, API rights, benchmark rights, evaluation harness rights, technical baseline rights, and public-good software rights shall be governed by applicable law, agreements, contributor terms, employment terms, contractor terms, grant terms, sponsorship terms, university terms, repository terms, and Board-approved policies.
19.17.1(b) GCRI Canada shall identify and record ownership, license, use rights, contribution rights, publication rights, sublicensing rights, attribution requirements, moral rights treatment where applicable, restrictions, public-good reuse rights, anti-enclosure protections, and correction obligations for material IP and technical assets.
19.17.1(c) IP governance shall apply to research outputs, methods, ontology, controlled vocabulary, Observatory Methods, Truth Engine Methods, public-good software, Open Technical Baselines, reports, datasets, models, cards, benchmarks, schemas, APIs, dashboards, maps, training materials, Academy materials, public authority learning materials, and repository materials.
19.17.1(d) IP rights shall not be used to create sponsor control, provider capture, public-good asset enclosure, technical baseline lock-in, public authority access purchase, finance-readiness purchase, certification purchase, or improper private benefit.
19.17.1(e) The controlling rule shall be that public-good technical stewardship requires clear rights, lawful reuse, anti-enclosure, and correctionability.
19.17.2 Open Source, Open Data, Public-Good Licensing, Research Licensing, Standards-Support Licensing, Restricted Licensing, and Dual Licensing Require Legal and Mission Review Where Material. 19.17.2(a) Open source, open data, public-good licensing, research licensing, standards-support licensing, restricted licensing, controlled licensing, dual licensing, contributor licensing, patent licensing, model licensing, dataset licensing, API licensing, schema licensing, and documentation licensing shall require legal and mission review where material.
19.17.2(b) Review shall assess mission compatibility, public-benefit purpose, anti-enclosure, permitted uses, prohibited uses, attribution, copyleft or permissive terms, patent grants, warranty disclaimers, liability disclaimers, export controls, sanctions, privacy, protected knowledge, data rights, AI-use limits, commercial use, public claims, and compatibility with grants or third-party rights.
19.17.2(c) Open release shall not be used for personal information, Public Authority Data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, Indigenous or Protected Knowledge, confidential materials, controlled technology, or security-sensitive materials unless lawful authority and public-safe review support release.
19.17.2(d) Dual licensing or commercial-use permissions shall not create improper private benefit, provider preference, sponsor benefit, certification implication, finance-readiness implication, or public authority approval implication.
19.17.2(e) The controlling rule shall be that openness is a public-good strategy, not a waiver of law, safeguards, or mission boundaries.
19.17.3 Third-Party IP Review Before Publication, Repository Release, Software Release, Dataset Release, Model Release, Benchmark Release, Technical Baseline Release, or Public-Safe Publication. 19.17.3(a) Third-party IP review shall occur before material publication, repository release, software release, dataset release, model release, benchmark release, evaluation harness release, technical baseline release, dashboard release, map release, API release, schema release, Academy material release, public authority learning release, or public-safe publication where risk exists.
19.17.3(b) Review shall identify third-party code, libraries, data, images, maps, models, weights, prompts, outputs, papers, standards text, proprietary materials, trademarks, logos, patents, confidential information, contractual restrictions, open-source licenses, attribution requirements, and derivative-work issues.
19.17.3(c) Materials shall not be released where GCRI Canada lacks rights, permissions, licenses, public-safe authority, or lawful basis.
19.17.3(d) Third-party logos, names, marks, screenshots, quotes, and materials shall be used only where permitted and shall not imply endorsement, sponsorship, certification, provider preference, public authority approval, or finance-readiness.
19.17.3(e) The controlling rule shall be that public-good release must respect the rights and restrictions embedded in its inputs.
19.17.4 Contributor Terms Shall Address IP, Confidentiality, Data Rights, AI-Generated Contributions, Security, and Conflicts. 19.17.4(a) Contributor terms shall address IP, license grants, assignments where applicable, moral rights where applicable, attribution, confidentiality, data rights, AI-generated contributions, security, conflicts, public claims, export controls, sanctions, contributor authority, and correction obligations.
19.17.4(b) Contributors shall represent, where appropriate, that they have authority to contribute the materials, that contributions do not knowingly infringe third-party rights, that confidential or protected materials are not contributed without authority, and that sensitive data is not included without review.
19.17.4(c) AI-generated contributions shall be reviewed for source provenance, license risk, originality risk, confidentiality risk, privacy risk, hallucination, hidden dependency, security vulnerability, and false attribution.
19.17.4(d) Contributions involving code, data, models, benchmarks, documentation, technical baselines, methods, ontology, or public-safe materials shall be reviewed before adoption, release, or reliance.
19.17.4(e) The controlling rule shall be that contribution is not acceptance until rights, provenance, security, and conflicts are reviewed.
19.17.5 Protected Knowledge Shall Not Be Treated as Ordinary IP or Open Data by Default. 19.17.5(a) Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, community-protected knowledge, sacred knowledge, site-specific knowledge, ecological knowledge, and Protected Knowledge shall not be treated as ordinary IP, ordinary data, open data, public domain material, or unrestricted content by default.
19.17.5(b) Such knowledge shall require authority, consent or non-consent handling where applicable, community safeguards, access controls, attribution or non-attribution rules, publication limits, mapping limits, reuse limits, AI-use limits, and correction paths.
19.17.5(c) GCRI Canada shall not rely on technical accessibility, public availability, prior publication, third-party possession, or open internet availability as sufficient authority to reuse protected knowledge.
19.17.5(d) Licensing or release of materials containing protected knowledge shall require safeguards review and may require community review, Indigenous-governed review, legal review, or refusal of release.
19.17.5(e) The controlling rule shall be that protected knowledge is governed by relationship, authority, dignity, and safeguards, not merely by copyright analysis.
19.17.6 Patent and Standards-Relevant IP Strategies Shall Preserve Anti-Enclosure and Public-Good Access. 19.17.6(a) Patent and standards-relevant IP strategies shall preserve anti-enclosure and public-good access.
19.17.6(b) GCRI Canada may use defensive publication, public-good licensing, patent pledges, non-assertion commitments, standards-compatible licensing, open technical baselines, reference implementations, or restricted licensing where appropriate to prevent enclosure, capture, misappropriation, or unsafe use.
19.17.6(c) Patent, standards, and technical baseline strategies shall not permit sponsors, providers, donors, funders, National Companies, Project SPVs, or private actors to control public-good technical baselines, interoperability surfaces, proof infrastructure, schemas, APIs, or methods.
19.17.6(d) Participation in standards-support work shall not create certification, protocol effect, provider preference, procurement approval, or public authority meaning unless proper authority and records support the exact status.
19.17.6(e) The controlling rule shall be that IP strategy must defend public-good access without becoming proprietary gatekeeping.
19.17.7 IP Disputes, Takedowns, Misattribution, License Breaches, and Fork Misuse Require Response. 19.17.7(a) IP disputes, takedowns, misattribution, plagiarism claims, license breaches, contributor disputes, third-party rights claims, unauthorized reuse, unauthorized fork misuse, trademark misuse, logo misuse, dataset misuse, model misuse, software misuse, or technical baseline misuse shall require response.
19.17.7(b) Response may include intake, legal review, preservation of records, access restriction, takedown, correction, attribution update, license cure, repository change, release suspension, withdrawal, retraction, fork clarification, public-safe notice, controlled notice, or dispute resolution.
19.17.7(c) Fork misuse includes use of GCRI Canada materials to imply endorsement, certification, recognition, finance-readiness, public authority approval, procurement advantage, Nexus-compatible status, protocol effect, or official GCRI Canada status.
19.17.7(d) IP disputes involving protected knowledge, personal information, Public Authority Data, controlled technology, or cyber-sensitive materials shall receive heightened review.
19.17.7(e) The controlling rule shall be that IP incidents must correct rights, attribution, public meaning, and downstream reliance.
19.17.8 Commercial Use of Technical Assets Requires License Compliance and Boundary Controls. 19.17.8(a) Commercial use of GCRI Canada technical assets shall require license compliance and boundary controls.
19.17.8(b) Technical assets include public-good software, Open Technical Baselines, schemas, APIs, dashboards, maps, datasets, models, benchmark materials, documentation, methods, ontology, controlled vocabulary, proof infrastructure components, and reference architectures.
19.17.8(c) Commercial use shall not imply endorsement, certification, recognition, finance-readiness, insurance-readiness, public authority approval, procurement advantage, provider preference, sponsor validation, Nexus-compatible status, protocol effect, warranty, guarantee, or execution authority by GCRI Canada.
19.17.8(d) Where commercial use creates public claims risk, provider preference risk, safety risk, data risk, protected knowledge risk, cybersecurity risk, or finance-boundary risk, GCRI Canada may require approved language, restricted use, correction, takedown, license enforcement, or termination of access.
19.17.8(e) The controlling rule shall be that public-good technical assets may be reused only within lawful license, truthful claims, and safeguard boundaries.
19.17.9 IP Legal Register and Release Review Records. 19.17.9(a) GCRI Canada shall maintain an IP Legal Register and release review records.
19.17.9(b) The Register shall identify material IP assets, owners, custodians, contributors, rights sources, license terms, assignments, moral rights treatment, attribution, third-party components, open-source dependencies, dataset rights, model rights, benchmark rights, patent issues, defensive publications, standards-relevant IP, restrictions, release status, public-safe status, correction path, and archive status.
19.17.9(c) Release review records shall identify material title, version, authority, rights review, third-party review, license review, data review, AI review, cybersecurity review, export-control review where applicable, protected knowledge review, public claims review, approval, release date, and closeout.
19.17.9(d) The Register shall link to repository records, software release records, dataset records, model records, publication records, contributor records, contract records, grant records, sponsorship records, and correction records.
19.17.9(e) The controlling rule shall be that IP compliance must be traceable from creation and contribution through release and reuse.
19.17.10 IP Compliance Assurance. 19.17.10(a) GCRI Canada shall conduct IP Compliance Assurance.
19.17.10(b) Assurance shall review ownership, assignments, licenses, contributor terms, third-party rights, open-source compliance, open-data compliance, protected knowledge controls, release reviews, attribution, repository practices, fork misuse, commercial-use claims, patent issues, standards-relevant IP, and IP incidents.
19.17.10(c) Assurance shall identify missing rights, unclear ownership, license incompatibility, unapproved third-party content, missing attribution, AI-generated content risk, protected knowledge exposure, improper commercial reuse, public claims misuse, and unresolved disputes.
19.17.10(d) Findings may require license correction, attribution correction, release withdrawal, repository remediation, contributor agreement update, takedown, public-safe notice, controlled notice, legal review, training, or Board / committee reporting.
19.17.10(e) The controlling rule shall be that IP assurance is necessary because technical assets can be enclosed, misused, or overclaimed after release.
19.18 Publication, Defamation, Misrepresentation, and Public Claims Legal Safety
19.18.1 Publications, Reports, Dashboards, Maps, Public Claims, Media Statements, Websites, Social Media, Technical Notes, and Public-Safe Outputs Shall Be Legally Reviewed Where Risk Exists. 19.18.1(a) Publications, reports, dashboards, maps, datasets, software releases, APIs, schemas, technical notes, whitepapers, public authority learning materials, Academy materials, media statements, websites, social media, public-safe outputs, controlled annexes, public claims, sponsor references, provider references, Public Authority references, and Nexus references shall be legally reviewed where risk exists.
19.18.1(b) Legal review shall address accuracy, substantiation, defamation, misrepresentation, privacy, Public Authority permissions, public warning boundaries, emergency command boundaries, finance boundaries, certification boundaries, procurement boundaries, provider preference, sponsor control, IP, protected knowledge, cybersecurity, infrastructure sensitivity, competition, and public harm.
19.18.1(c) Public-facing materials shall identify scope, authority, evidence basis, limitations, confidence, uncertainty, public-safe status, version, date, and correction path where appropriate.
19.18.1(d) Materials shall not be released where legal risk, safety risk, privacy risk, protected knowledge risk, Public Authority risk, finance risk, or public harm risk remains unresolved beyond approved tolerance.
19.18.1(e) The controlling rule shall be that public communication must be truthful, lawful, safe, bounded, and correctable before reliance is invited.
19.18.2 Claims Shall Be Accurate, Evidence-Based, Substantiated, Limitation-Aware, and Non-Misleading. 19.18.2(a) Claims made by or about GCRI Canada shall be accurate, evidence-based, substantiated, limitation-aware, non-misleading, records-valid, public-safe, and consistent with controlled vocabulary.
19.18.2(b) Technical claims shall be supported by evidence records, methods records, version records, testing conditions, benchmark limitations, review status, public-safe status, and correction path.
19.18.2(c) Impact claims shall preserve attribution discipline, uncertainty, causal limits, counterfactual limits, sponsor role disclosures, provider role disclosures, Public Authority role precision, and stage truth.
19.18.2(d) Claims shall not omit material limitations where omission would mislead a public audience, Public Authority, capital reader, sponsor, provider, community, participant, or media actor.
19.18.2(e) The controlling rule shall be that every material public claim must be supportable by record and safe in context.
19.18.3 Defamation, Misrepresentation, Consumer-Protection, Passing-Off, Trademark, Publicity, Privacy, Public Authority, Public Warning, Finance, Certification, Provider Preference, Sponsor, and Procurement Risks Shall Be Reviewed Where Applicable. 19.18.3(a) Defamation, misrepresentation, consumer-protection, passing-off, trademark, publicity, privacy, Public Authority, public warning, emergency command, finance, insurance, rating, certification, recognition, provider preference, sponsor, procurement, competition, public finance, IP, protected knowledge, and public harm risks shall be reviewed where applicable.
19.18.3(b) Review shall be heightened where materials identify or imply facts about persons, companies, Public Authorities, providers, sponsors, hosts, communities, technologies, incidents, risks, vulnerabilities, safety, legality, maturity, readiness, finance-readiness, insurance-readiness, public authority adoption, procurement, or compliance.
19.18.3(c) Comparative statements, rankings, benchmarks, maturity references, failure descriptions, risk maps, incident reports, or public-safe warnings-like materials shall be reviewed for accuracy, fairness, context, limitations, and harmful overstatement.
19.18.3(d) Materials that could be understood as official public warning, public authority guidance, certification, finance advice, procurement recommendation, provider endorsement, or sponsor validation shall include boundary language or be restricted, revised, or refused.
19.18.3(e) The controlling rule shall be that legal safety requires review of both words and likely meaning.
19.18.4 Public Authority Names, Logos, Titles, Quotes, Photographs, and Data Contributions Require Permission and Capacity Records. 19.18.4(a) Public Authority names, logos, titles, agency names, jurisdictions, quotes, photographs, attendance, data contributions, maps, dashboards, reports, public authority learning references, and public authority participation references shall require permission and capacity records where applicable.
19.18.4(b) Capacity records shall identify whether the Public Authority participant acted as observer, learner, technical reviewer, public finance reader, regulator-listening participant, emergency-management participant, data contributor, public infrastructure participant, public health participant, personal-capacity participant, or another recorded capacity.
19.18.4(c) Public Authority references shall not imply endorsement, adoption, public warning, public finance approval, grant approval, procurement approval, regulatory approval, safe harbor, compliance determination, emergency command, or sovereign obligation.
19.18.4(d) Public Authority references shall be corrected where misdescribed, overclaimed, unauthorized, stale, or confusing.
19.18.4(e) The controlling rule shall be that public authority meaning must be permissioned, capacity-classified, and boundary-safe.
19.18.5 Sponsor, Provider, Host, University, Partner, National Company, Project SPV, and Capital-Reader References Require Role Precision. 19.18.5(a) Sponsor, provider, host, university, partner, National Company, Project SPV, capital-reader, donor, funder, grantor, contractor, contributor, and Nexus actor references shall require role precision.
19.18.5(b) References shall distinguish support, funding, donation, sponsorship, grant participation, in-kind contribution, hosting, technical contribution, research collaboration, advisory participation, provider participation, public authority learning, capital reading, enterprise execution, and formal authority.
19.18.5(c) References shall not imply endorsement, certification, recognition, finance-readiness, insurance-readiness, provider preference, procurement advantage, public authority approval, public-private partnership, public adoption, protocol effect, Nexus-compatible status, sponsor control, or execution authority unless proper authority and records support the exact statement.
19.18.5(d) Role references shall be reviewed where public-facing, finance-sensitive, procurement-sensitive, public authority-sensitive, or sponsor / provider-sensitive.
19.18.5(e) The controlling rule shall be that participation language must describe role, not inflate status.
19.18.6 Public-Safe Maps and Sensitive Visualizations Require Harm Review. 19.18.6(a) Public-safe maps, dashboards, geospatial outputs, sensor visualizations, satellite outputs, remote sensing outputs, AI outputs, digital twins, risk maps, infrastructure maps, community maps, health maps, cyber visualizations, environmental visualizations, and sensitive data visualizations shall require harm review.
19.18.6(b) Harm review shall address privacy, re-identification, group harm, sensitive locations, infrastructure vulnerabilities, cyber risk, public warning implication, public authority implication, community stigma, protected knowledge exposure, Indigenous and local knowledge exposure, ecological harm, commercial sensitivity, finance sensitivity, and misuse risk.
19.18.6(c) Visualizations shall use redaction, aggregation, generalization, resolution reduction, delayed release, controlled access, or non-release where necessary.
19.18.6(d) Legends, captions, disclaimers, confidence indicators, uncertainty notes, update status, and correction paths shall be used where needed to prevent misinterpretation.
19.18.6(e) The controlling rule shall be that visual truth can create harm if precision, context, or authority meaning is uncontrolled.
19.18.7 Media Misquotation or Third-Party Misdescription Requires Correction Where Material. 19.18.7(a) Media misquotation, third-party misdescription, sponsor misdescription, provider misdescription, public authority misdescription, capital-reader misdescription, partner misdescription, social media distortion, or public claims misuse shall require correction where material.
19.18.7(b) Material misdescription includes statements implying GCRI Canada endorsement, recognition, finance-readiness, certification, public authority approval, procurement advantage, public warning authority, emergency command, investment advice, insurance approval, public finance approval, provider preference, sponsor control, protocol effect, Nexus-compatible status, or execution authority.
19.18.7(c) Corrective action may include private correction, public-safe clarification, controlled notice, takedown request, revised quote, media correction request, updated website language, participant discipline, access restriction, or legal response.
19.18.7(d) GCRI Canada shall preserve records of the misdescription, requested correction, response, unresolved risk, and closeout.
19.18.7(e) The controlling rule shall be that public meaning must be corrected where third parties put GCRI Canada into roles it does not hold.
19.18.8 Publication Legal Incident Requires Hold, Correction, Withdrawal, Retraction, Public-Safe Notice, or Legal Response. 19.18.8(a) A publication legal incident shall require hold, correction, withdrawal, retraction, public-safe notice, controlled notice, legal response, access restriction, or other remedy proportionate to risk.
19.18.8(b) Publication legal incidents include defamation risk, false statement, misrepresentation, unsupported claim, Public Authority misdescription, finance overclaim, certification overclaim, provider preference, sponsor overclaim, privacy breach, data breach, protected knowledge exposure, IP infringement, security-sensitive disclosure, public warning confusion, emergency command confusion, procurement overclaim, or media misquotation.
19.18.8(c) Immediate hold may apply to affected publications, dashboards, maps, datasets, software releases, websites, social media, media materials, room materials, and downstream materials.
19.18.8(d) Corrective review shall identify affected materials, affected audiences, reliance risk, legal risk, public harm risk, downstream dependencies, correction state, notice requirements, and archive status.
19.18.8(e) The controlling rule shall be that publication incidents must correct public meaning and prevent further reliance.
19.18.9 Publication Legal Safety Register. 19.18.9(a) GCRI Canada shall maintain a Publication Legal Safety Register.
19.18.9(b) The Register shall identify public materials, legal review status, public claims review, defamation review where applicable, Public Authority reference approvals, sponsor / provider / partner reference approvals, finance-boundary review, certification-boundary review, procurement-boundary review, privacy review, IP review, protected knowledge review, public-safe mapping review, publication incidents, corrections, withdrawals, retractions, notices, and closeout.