For the complete documentation index, see llms.txt. This page is also available as Markdown.

XX. ASSURANCE

20.1 Risk Management Purpose

20.1.1 Risk Management as Charter-Level Institutional Discipline. 20.1.1(a) Risk management shall be a Charter-level institutional discipline of GCRI Canada and shall govern the identification, assessment, ownership, control, monitoring, escalation, correction, renewal, and assurance of risks affecting GCRI Canada’s public-benefit mission, lawful authority, evidence integrity, methods integrity, public trust, legal separateness, non-execution, Public-Good Stack role separation, data rights, cybersecurity, protected knowledge, public authority boundaries, finance-readiness boundaries, and Nexus interoperability.

20.1.1(b) Risk management shall not be treated as an optional administrative process, insurance exercise, reputational exercise, or after-the-fact incident response. It shall be an embedded governance discipline through which GCRI Canada anticipates, prevents, detects, corrects, and learns from risk across all material institutional functions.

20.1.1(c) Risk management shall apply to strategic decisions, Board decisions, officer delegations, programs, research, evidence, methods, data, AI systems, compute environments, cybersecurity, public-good software, Open Technical Baselines, technical releases, publications, dashboards, maps, controlled rooms, clean rooms, public authority learning, sponsorships, grants, donations, provider participation, community interfaces, and Nexus interfaces.

20.1.1(d) Risk management shall be read with GCRI Canada’s legal compliance, records, correctionability, data governance, cybersecurity, finance-boundary, public authority-boundary, publication, participation, governance, and fiscal provisions.

20.1.1(e) The controlling rule shall be that risk management is a constitutional safeguard of lawful public-benefit work.


20.1.2 Risk Management as Identification, Assessment, Ownership, Control, Monitoring, Escalation, Correction, and Renewal. 20.1.2(a) Risk management shall include identification, assessment, ownership, custody, classification, scoring where used, treatment, control design, control operation, monitoring, escalation, correction, assurance, renewal, and closure where appropriate.

20.1.2(b) Identification shall determine the nature of the risk, affected activity, affected records, affected persons, affected communities, affected Public Authorities, affected systems, affected data, affected publications, affected interfaces, affected obligations, and affected trust surfaces.

20.1.2(c) Assessment shall consider likelihood, severity, legal consequence, public-benefit consequence, public trust consequence, data sensitivity, AI risk, cybersecurity risk, protected knowledge risk, Public Authority sensitivity, finance sensitivity, cross-border exposure, technical complexity, and downstream reliance.

20.1.2(d) Ownership shall identify the accountable risk owner, operational custodian, control owner, escalation path, review cycle, and Board or committee reporting threshold.

20.1.2(e) Control shall include preventive, detective, corrective, compensating, procedural, technical, legal, governance, training, access, publication, public-safe, and records controls as appropriate.

20.1.2(f) Monitoring and renewal shall ensure that risks remain current as law, technology, data, participants, funding, public authority relationships, public claims, Nexus interfaces, and institutional scale change.

20.1.2(g) The controlling rule shall be that unmanaged risk is not merely unidentified exposure; it is a failure of institutional stewardship.


20.1.3 Risk Management as Applicable to Governance, Research, Evidence, Methods, Data, AI, Cybersecurity, Public-Good Software, Technical Baselines, Public Authority Interfaces, Finance Boundaries, Publications, Community Safeguards, Participants, Sponsors, Providers, Hosts, and Nexus Interfaces. 20.1.3(a) Risk management shall apply to governance, fiduciary duties, Board authority, officer authority, delegations, committees, councils, Working Groups, research, evidence, methods, observability, ontology, technical truth, public-good software, Open Technical Baselines, data, AI, compute, cybersecurity, technical assets, publications, public claims, dashboards, maps, Academy materials, public authority learning materials, and public-safe outputs.

20.1.3(b) Risk management shall apply to Public Authority interfaces, including observer status, regulator-listening status, public finance reader status, emergency-management participation, data contributions, public authority learning, public authority references, public authority rooms, dashboards, maps, and public-safe communications.

20.1.3(c) Risk management shall apply to finance boundaries, including GRA interfaces, Proof Pack inputs, capital-reader rooms, RNFD / NFD / UNFSD support, finance-sensitive data, public finance readers, insurance-readiness references, token / blockchain / DLT / DePIN interfaces, proof receipts, and finance-sensitive public claims.

20.1.3(d) Risk management shall apply to sponsors, donors, funders, providers, hosts, universities, laboratories, contractors, fellows, advisors, participants, contributors, communities, Indigenous knowledge holders, civil society, media, National Companies, Project SPVs, and Nexus actors.

20.1.3(e) The controlling rule shall be that risk management follows institutional activity wherever authority, data, technology, money, public meaning, or trust may move.


20.1.4 Risk Management as Public-Benefit Protection, Not Risk Transfer, Insurance Underwriting, Rating, Guarantee, or Public Authority Determination. 20.1.4(a) Risk management by GCRI Canada shall be a public-benefit protection discipline and shall not be treated as risk transfer, insurance underwriting, credit rating, guarantee, certification, public finance approval, public authority determination, emergency command, public warning, procurement approval, provider endorsement, or regulated professional risk service by default.

20.1.4(b) GCRI Canada may identify, classify, assess, monitor, mitigate, and correct risks affecting its own mission, records, evidence, methods, public-safe outputs, public authority learning, technical baselines, and Nexus interfaces, but such work shall not create external approval, insurability, creditworthiness, investment readiness, finance-readiness, maturity recognition, regulatory compliance, procurement eligibility, or public authority adoption.

20.1.4(c) Risk reports, registers, dashboards, maps, heat maps, risk notes, assurance findings, technical risk summaries, and public-safe risk communications shall include boundary language where necessary to prevent reliance as insurance, rating, guarantee, public warning, public authority decision, finance-readiness determination, or certification.

20.1.4(d) Where risk materials are read by capital readers, Public Authorities, providers, sponsors, communities, or media, GCRI Canada shall preserve role clarity, source limits, uncertainty, public-safe status, and correction paths.

20.1.4(e) The controlling rule shall be that GCRI Canada manages institutional risk to protect public trust, not to sell or assign risk status to others.


20.1.5 Risk Management as Distinct From Regulated Enterprise Risk Services Unless Separately Authorized and Properly Controlled. 20.1.5(a) GCRI Canada’s risk management shall be distinct from regulated enterprise risk services, professional advisory services, insurance services, investment advisory services, credit assessment services, engineering certification, compliance certification, public authority determination, public warning, emergency command, procurement advisory, and execution services unless separately authorized by competent authority and properly controlled outside GCRI Canada’s prohibited functions.

20.1.5(b) GCRI Canada shall not present its risk management outputs as enterprise risk ratings, investment risk ratings, insurance ratings, credit ratings, bankability opinions, procurement evaluations, regulatory compliance opinions, engineering certifications, public safety determinations, or official hazard notices.

20.1.5(c) Where GCRI Canada contributes risk evidence to another competent actor, such contribution shall be bounded by source authority, purpose, classification, limitations, role separation, permitted use, prohibited use, and correction path.

20.1.5(d) Any activity that may be interpreted as regulated risk service shall require legal review, role classification, boundary language, records, and refusal where the activity would exceed GCRI Canada’s lawful role.

20.1.5(e) The controlling rule shall be that risk literacy and evidence stewardship shall not become unauthorized professional or regulated risk activity.


20.1.6 Risk Management as Integrated With Validity-by-Record, Correctionability, Non-Execution, Public-Safe Publication, and Legal Separateness. 20.1.6(a) Risk management shall be integrated with validity-by-record, correctionability, non-execution, public-safe publication, legal separateness, controlled vocabulary, authoritative repositories, Gazette discipline where applicable, and no-silent-effect discipline.

20.1.6(b) A material risk position shall not be treated as institutionally valid unless recorded with owner, authority, scope, classification, evidence basis, review status, limitations, controls, treatment, escalation path, and correction path.

20.1.6(c) Risk management shall support correctionability by identifying outdated risk assessments, incorrect risk ratings, unsupported assumptions, failed controls, stale evidence, unsafe public materials, uncorrected incidents, and downstream dependencies requiring correction.

20.1.6(d) Risk management shall preserve non-execution by ensuring that risk outputs do not become commands, approvals, public authority actions, financial determinations, provider preferences, certification, procurement steering, or operational execution instructions.

20.1.6(e) Risk management shall preserve legal separateness by distinguishing GCRI Canada’s risks, records, controls, liabilities, and decisions from those of GCRI US, GRF, GRA, Protocol Authority, Nexus entities, National Companies, Project SPVs, providers, sponsors, hosts, Public Authorities, universities, and capital actors.

20.1.6(f) The controlling rule shall be that risk management is valid only when it is recorded, bounded, correctable, non-executing, and entity-specific.


20.1.7 Risk Management as Preventive, Detective, Corrective, and Learning-Oriented. 20.1.7(a) Risk management shall be preventive, detective, corrective, and learning-oriented.

20.1.7(b) Preventive risk management shall include policy, training, access controls, legal review, ethics review, data minimization, AI-use controls, cybersecurity controls, public claims review, Public Authority capacity classification, finance-boundary review, protected knowledge safeguards, contract clauses, and role separation.

20.1.7(c) Detective risk management shall include monitoring, assurance, register review, access review, publication review, incident reporting, anomaly detection, dashboard review, repository review, audit trails, issue registers, and stakeholder challenge pathways.

20.1.7(d) Corrective risk management shall include holds, quarantines, access restrictions, corrections, reclassifications, downgrades, suspensions, withdrawals, retractions, takedowns, public-safe notices, controlled notices, legal review, remediation, and assurance follow-up.

20.1.7(e) Learning-oriented risk management shall convert incidents, near misses, assurance findings, public challenges, participant grievances, technical failures, publication corrections, and legal changes into updated controls, training, registers, policies, and Board oversight.

20.1.7(f) The controlling rule shall be that risk management shall improve institutional behavior, not merely document institutional exposure.


20.1.8 Risk Management as Board, Officer, Committee, Staff, Fellow, Advisor, Contributor, Sponsor, Provider, Host, Public Authority, Community, and Participant Responsibility Where Relevant. 20.1.8(a) Risk management shall be a responsibility of the Board, Officers, committees, staff, contractors, fellows, advisors, contributors, maintainers, Working Groups, councils, sponsors, donors, funders, providers, hosts, universities, Public Authorities, communities, capital readers, and participants where relevant to their roles, access, authority, and activities.

20.1.8(b) The Board shall oversee enterprise-level risk governance, risk appetite where adopted, prohibited risks, material risk escalation, control assurance, mission drift risk, non-execution risk, legal separateness risk, and public trust risk.

20.1.8(c) Officers shall implement risk management through policies, procedures, controls, registers, training, incident response, escalation, correction, and reporting.

20.1.8(d) Committees and councils shall identify and escalate risks within their mandates but shall not assume Board authority, public authority, finance authority, certification authority, procurement authority, or execution authority by risk discussion.

20.1.8(e) External participants shall comply with risk controls, room rules, confidentiality, data rules, AI-use limits, public claims limits, Public Authority boundary language, finance-boundary language, conflict disclosures, and correction obligations.

20.1.8(f) The controlling rule shall be that risk responsibility is distributed by role, while risk authority remains governed by proper records and lawful delegation.


20.1.9 Risk Management as Proportionate to Public-Benefit Consequence, Legal Risk, Data Sensitivity, Technical Complexity, Public Authority Sensitivity, Finance Sensitivity, Community Sensitivity, and Public Trust Risk. 20.1.9(a) Risk management shall be proportionate to public-benefit consequence, legal risk, data sensitivity, technical complexity, AI complexity, cybersecurity exposure, Public Authority sensitivity, finance sensitivity, community sensitivity, protected knowledge sensitivity, cross-border exposure, publication reach, and public trust risk.

20.1.9(b) Higher-risk activities shall require heightened review, stronger records, clearer owners, tighter access controls, more explicit boundary language, legal review where required, public-safe review, Board or committee visibility, and assurance follow-up.

20.1.9(c) Lower-risk activities may use proportionate controls, provided that non-execution, records validity, privacy, cybersecurity, Public Authority boundaries, finance boundaries, provider neutrality, sponsor non-control, protected knowledge, and correctionability remain preserved.

20.1.9(d) Proportionality shall not be used to waive prohibited-function boundaries, legal obligations, privacy obligations, data protection obligations, cybersecurity obligations, protected knowledge safeguards, sanctions controls, export-control controls, or anti-inurement controls.

20.1.9(e) The controlling rule shall be that risk controls may scale by risk, but constitutional boundaries do not disappear at lower scale.


20.1.10 Risk Management Records as Material Constitutional Records. 20.1.10(a) Risk management records shall be material constitutional records of GCRI Canada.

20.1.10(b) Such records shall include risk registers, issue registers, control registers, risk assessments, treatment plans, accepted risk records, prohibited risk records, escalation records, incident records, assurance findings, corrective action plans, risk appetite statements where adopted, risk tolerance decisions, Board reports, committee reports, control testing records, exception records, and lessons-learned records.

20.1.10(c) Risk records shall identify owner, custodian, authority, scope, affected Charter Part, risk domain, evidence basis, classification, severity, likelihood where used, treatment, controls, residual risk, review cycle, escalation threshold, dependencies, limitations, public-safe status where applicable, and correction path.

20.1.10(d) Risk records shall be retained, classified, access-controlled, versioned, protected from silent edit, linked to relevant registers, and subject to legal hold where required.

20.1.10(e) The controlling rule shall be that risk governance must be provable by record before it can be relied upon.


20.2 Institutional Risk Register

20.2.1 Requirement to Maintain an Institutional Risk Register. 20.2.1(a) GCRI Canada shall maintain an Institutional Risk Register covering material risks to its mission, governance, legal compliance, public-benefit status, evidence integrity, methods integrity, data rights, AI governance, cybersecurity, public-safe publication, public authority boundaries, finance boundaries, community safeguards, technical assets, participants, support relationships, Nexus interfaces, continuity, reputation, and public trust.

20.2.1(b) The Institutional Risk Register shall identify risk title, risk description, domain, owner, custodian, affected Charter Parts, affected policies, affected records, affected systems, affected participants, affected Public Authorities, affected data classes, affected public materials, likelihood where used, severity, inherent risk, controls, residual risk, treatment plan, review date, escalation threshold, related issues, related incidents, and Board or committee reporting status.

20.2.1(c) The Register shall include current risks, emerging risks, systemic risks, cross-cutting risks, unresolved risks, accepted risks, prohibited risks, and risks under treatment.

20.2.1(d) The Register shall not be used to normalize prohibited functions or accept risks that the Charter forbids.

20.2.1(e) The controlling rule shall be that material institutional risks must be visible, owned, controlled, reviewed, and correctable.


20.2.2 Governance Risk. 20.2.2(a) Governance Risk means risk affecting Board stewardship, fiduciary duty, officer delegation, committee function, council function, conflict management, related-party controls, mission lock, legal separateness, records validity, and lawful authority.

20.2.2(b) Governance Risk may arise from informal decision-making, founder control, sponsor influence, provider influence, committee overreach, council overreach, unclear delegations, missing records, conflicts, recusal failures, stale policies, defective meetings, or unclear public claims authority.

20.2.2(c) Governance Risk controls may include Board-reserved matters, delegation registers, conflict registers, recusal records, committee charters, council terms, governance training, meeting records, decision packs, legal review, and governance assurance.

20.2.2(d) Governance Risk shall be escalated where institutional authority, legal compliance, mission lock, Board oversight, or public trust may be affected.

20.2.2(e) The controlling rule shall be that governance risk is constitutional risk because governance determines institutional authority.


20.2.3 Fiduciary Risk. 20.2.3(a) Fiduciary Risk means risk that Directors, Officers, or other persons exercising authority fail to act with required duty, care, loyalty, prudence, independence, good faith, mission fidelity, conflict discipline, or lawful oversight.

20.2.3(b) Fiduciary Risk may arise from inadequate information, conflicts, related-party transactions, private benefit, inurement, sponsor capture, provider capture, unreviewed legal risk, weak financial controls, failure to oversee data and cybersecurity, failure to correct, or failure to preserve non-execution.

20.2.3(c) Controls shall include Board training, briefing materials, legal review, financial review, conflict disclosure, recusal, independent review, Board minutes, committee reporting, risk reporting, assurance findings, and corrective action tracking.

20.2.3(d) Fiduciary Risk shall be treated as heightened where Board action could affect corporate status, tax status, public trust, legal separateness, restricted funds, Public Authority interfaces, finance-sensitive interfaces, protected knowledge, or major technical assets.

20.2.3(e) The controlling rule shall be that fiduciary risk must be controlled before judgment becomes institutional harm.


20.2.4 Mission Drift Risk. 20.2.4(a) Mission Drift Risk means risk that GCRI Canada moves away from its public-benefit, nonprofit, non-share, non-distributing, non-executing, evidence-and-methods, public-good technical mandate.

20.2.4(b) Mission Drift Risk may arise from commercial revenue pressure, sponsor expectations, provider expectations, grant conditions, public authority demand, capital-reader interest, media visibility, founder preference, operational convenience, technical enthusiasm, or Nexus role confusion.

20.2.4(c) Mission Drift Risk includes drift toward consultancy, execution, certification sales, finance-readiness sales, procurement advice, provider marketplace, public authority substitute, emergency command, public warning system, data brokerage, proprietary enclosure, or regulated financial activity.

20.2.4(d) Controls shall include mission-lock review, Board oversight, legal review, revenue review, contract review, public claims review, support-without-control rules, provider neutrality, finance-boundary review, public authority-boundary review, and correctionability.

20.2.4(e) The controlling rule shall be that mission drift must be identified early because drift often begins as useful work without boundaries.


20.2.5 Non-Execution Boundary Risk. 20.2.5(a) Non-Execution Boundary Risk means risk that GCRI Canada is described, used, relied upon, or structured as executing downstream operational, market, public authority, emergency, procurement, finance, infrastructure, provider, or project activities.

20.2.5(b) Such risk may arise from dashboards, maps, public authority learning, technical baselines, public-good software, evidence packs, room participation, public claims, project support, provider demonstrations, National Company interfaces, Project SPV interfaces, or capital-reader contexts.

20.2.5(c) Controls shall include non-execution language, role classification, public claims review, contract clauses, Public Authority capacity records, GRA routing, GRF role separation, Protocol Authority separation, provider neutrality, and legal review where risk exists.

20.2.5(d) Non-Execution Boundary Risk shall be escalated where materials could be read as command, approval, public warning, procurement recommendation, finance determination, certification, or execution instruction.

20.2.5(e) The controlling rule shall be that GCRI Canada may inform action but shall not become the actor by implication.


20.2.6 Public-Good Stack Role-Separation Risk. 20.2.6(a) Public-Good Stack Role-Separation Risk means risk that GCRI Canada’s role is merged, confused, overstated, or collapsed with GRF, GRA, Protocol Authority, Nexus entities, Public Authorities, National Companies, Project SPVs, providers, sponsors, or capital actors.

20.2.6(b) Such risk may arise through shared records, shared events, shared doctrine, shared branding, shared rooms, shared technical baselines, shared public authority interfaces, shared capital-reader materials, shared public claims, or shared participants.

20.2.6(c) Controls shall include controlled vocabulary, role language, legal-separateness clauses, interface records, shared-record boundaries, divergence logs, equivalence notes, public claims review, and entity-boundary assurance.

20.2.6(d) This risk shall be heightened where public audiences, Public Authorities, capital readers, sponsors, providers, or media may infer authority, recognition, finance-readiness, certification, protocol effect, procurement approval, or execution authority.

20.2.6(e) The controlling rule shall be that interoperability must never become role collapse.


20.2.7 Evidence Integrity Risk. 20.2.7(a) Evidence Integrity Risk means risk that evidence is inaccurate, unsupported, stale, misclassified, incomplete, biased, fabricated, altered, untraceable, overgeneralized, overclaimed, taken out of context, or used beyond source authority.

20.2.7(b) Evidence Integrity Risk may arise through weak source lineage, poor intake, missing metadata, AI hallucination, inadequate review, stale data, biased samples, provider influence, sponsor influence, Public Authority misdescription, missing limitations, or public claims inflation.

20.2.7(c) Controls shall include evidence intake records, source lineage, Case IDs, metadata standards, review gates, peer or expert review where appropriate, public-safe review, versioning, no-silent-edit rules, correction paths, and evidence registers.

20.2.7(d) Evidence Integrity Risk shall be escalated where evidence supports public materials, Public Authority learning, finance-sensitive materials, technical baselines, dashboards, maps, datasets, or GRA / GRF / Protocol Authority interfaces.

20.2.7(e) The controlling rule shall be that public-good evidence must remain source-valid, limitation-aware, and correctionable.


20.2.8 Methods Integrity Risk. 20.2.8(a) Methods Integrity Risk means risk that methods, frameworks, evaluation harnesses, ontology, controlled vocabulary, benchmarks, Truth Engine methods, Observatory methods, technical baselines, or public-good software are flawed, unreviewed, biased, unreproducible where reproducibility is required, misapplied, unversioned, unsafe, or overclaimed.

20.2.8(b) Such risk may arise through weak protocol design, untested assumptions, hidden dependencies, unclear definitions, translation drift, benchmark misuse, model drift, software bugs, insecure dependencies, or uncontrolled adaptation across jurisdictions.

20.2.8(c) Controls shall include method records, protocol records, controlled vocabulary governance, versioning, change logs, review gates, reproducibility packages where lawful, limitation statements, technical release controls, and correction procedures.

20.2.8(d) Methods Integrity Risk shall be heightened where methods influence public authority learning, finance-sensitive evidence, public-safe reports, dashboards, maps, datasets, software releases, or Nexus interoperability.

20.2.8(e) The controlling rule shall be that methods must be as governed as evidence because methods determine what evidence can mean.


20.2.9 Research Integrity Risk. 20.2.9(a) Research Integrity Risk means risk affecting research ethics, human-subjects protections, protocols, peer review, reproducibility, conflicts, independence, authorship, data governance, publication, correction, and protected knowledge safeguards.

20.2.9(b) Research Integrity Risk may arise from inadequate ethics review, consent gaps, vulnerable participant risk, community extraction, Indigenous or protected knowledge misuse, sponsor influence, provider influence, publication suppression, AI misuse, false citation, undisclosed conflicts, or failure to correct.

20.2.9(c) Controls shall include research protocols, ethics review, community review where appropriate, protected knowledge protocols, conflict disclosures, peer review, AI-use records, data governance, publication review, and research correction procedures.

20.2.9(d) Research Integrity Risk shall be escalated where research affects people, communities, health, Public Authorities, rights-bearing data, public-safe publications, dashboards, maps, or policy-facing materials.

20.2.9(e) The controlling rule shall be that research integrity protects both truth and the people affected by truth-seeking.


20.2.10 Publication and Public Claims Risk. 20.2.10(a) Publication and Public Claims Risk means risk that publications, reports, dashboards, maps, datasets, software releases, technical notes, Academy materials, public authority learning materials, media statements, websites, social media, or public claims are inaccurate, unsupported, misleading, unsafe, overbroad, defamatory, rights-infringing, or authority-inflating.

20.2.10(b) Such risk may include Public Authority overclaim, finance-readiness overclaim, certification overclaim, recognition overclaim, provider preference, sponsor validation, procurement implication, public warning implication, emergency command implication, technical claim overstatement, impact claim inflation, or unsupported “verified,” “validated,” “approved,” “trusted,” or “ready” language.

20.2.10(c) Controls shall include claims substantiation, controlled vocabulary, publication classes, review gates, legal review where risk exists, public-safe review, disclaimers, versioning, correction notices, withdrawal, and retraction.

20.2.10(d) Publication and Public Claims Risk shall be heightened where materials are public, media-facing, Public Authority-facing, capital-facing, provider-facing, sponsor-facing, community-facing, or relied upon downstream.

20.2.10(e) The controlling rule shall be that public language is a risk surface because public meaning can exceed institutional authority.


20.2.11 Data Rights and Privacy Risk. 20.2.11(a) Data Rights and Privacy Risk means risk affecting personal information, sensitive personal information, health-sensitive data, rights-bearing data, Public Authority Data, community-protected data, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, Protected Knowledge, cross-border data, sovereign data, and data rights.

20.2.11(b) Such risk may arise from over-collection, unclear lawful basis, missing notice, consent failure, unauthorized access, unauthorized sharing, improper AI use, uncontrolled embedding, cross-border transfer, stale retention, re-identification, public release error, weak deletion, or vendor misuse.

20.2.11(c) Controls shall include data classification, lawful basis review, purpose limitation, minimization, privacy notices, consent records where applicable, data rights processes, impact assessments, access controls, retention rules, deletion rules, breach response, and public-safe release review.

20.2.11(d) Data Rights and Privacy Risk shall be escalated where affected data is sensitive, rights-bearing, public authority-related, health-related, community-protected, protected knowledge-related, cross-border, AI-used, or public-facing.

20.2.11(e) The controlling rule shall be that data risk is rights risk, not merely information-management risk.


20.2.12 AI and Model Governance Risk. 20.2.12(a) AI and Model Governance Risk means risk arising from AI systems, models, embeddings, retrieval, inference, agentic AI, AI-assisted writing, AI-assisted coding, AI-assisted research, AI-assisted publication, AI dashboards, AI maps, AI outputs, AI vendors, and model-dependent workflows.

20.2.12(b) Such risk may include hallucination, false citation, bias, discrimination, data leakage, prompt leakage, unauthorized training, unauthorized fine-tuning, unauthorized embedding, unauthorized model improvement, stale retrieval, model drift, unsafe output, unauthorized agent action, overreliance, or AI-as-authority overclaim.

20.2.12(c) Controls shall include AI use inventory, model register, inference records, data authority review, vendor review, human review, impact review, bias review, safety review, AI-use restrictions, logging controls, deletion controls, and AI incident response.

20.2.12(d) AI and Model Governance Risk shall be heightened where AI affects Public Authorities, employment, research, health, finance-sensitive contexts, public-safe publications, dashboards, maps, rights-bearing data, or protected knowledge.

20.2.12(e) The controlling rule shall be that AI may support judgment but must not replace authority, review, records, or legal basis.


20.2.13 Cybersecurity and Technical Asset Risk. 20.2.13(a) Cybersecurity and Technical Asset Risk means risk affecting systems, repositories, public-good software, Open Technical Baselines, APIs, schemas, datasets, models, dashboards, maps, compute environments, controlled rooms, clean rooms, data rooms, secrets, keys, tokens, identities, release pipelines, SBOMs, dependencies, and technical infrastructure.

20.2.13(b) Such risk may include unauthorized access, weak authentication, credential compromise, secrets exposure, malicious pull request, repository compromise, insecure dependency, supply-chain attack, API compromise, dashboard compromise, AI leakage, insecure release, insufficient logging, backup failure, or vendor compromise.

20.2.13(c) Controls shall include system classification, identity and access management, MFA where appropriate, secrets management, repository security, secure development, secure release, vulnerability management, SBOMs, logging, incident response, backup, disaster recovery, and third-party security review.

20.2.13(d) Cybersecurity and Technical Asset Risk shall be escalated where Public Authority Data, personal information, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, controlled technology, public interfaces, or critical repositories are affected.

20.2.13(e) The controlling rule shall be that technical integrity is a public trust condition.


20.2.14 Public Authority Boundary Risk. 20.2.14(a) Public Authority Boundary Risk means risk that GCRI Canada participation, materials, public authority learning, dashboards, maps, reports, rooms, data contributions, or references are understood as endorsement, adoption, regulation, procurement approval, funding approval, public finance approval, public warning, emergency command, official guidance, or sovereign obligation.

20.2.14(b) This risk may arise through Public Authority attendance, logos, names, titles, quotes, photos, agency names, jurisdictions, data contributions, regulator-listening status, public finance reader status, emergency-management participation, or public infrastructure participation.

20.2.14(c) Controls shall include capacity classification, reference approval, Public Authority Data terms, non-endorsement language, no-public-warning language, no-command language, public authority room controls, public-safe review, and correction procedures.

20.2.14(d) Public Authority Boundary Risk shall be treated as heightened because public power can be implied by proximity.

20.2.14(e) The controlling rule shall be that Public Authority meaning must arise only from competent public authority action, not GCRI Canada context.


20.2.15 Finance-Readiness Boundary Risk. 20.2.15(a) Finance-Readiness Boundary Risk means risk that GCRI Canada materials, evidence, Proof Pack inputs, GRA interfaces, capital-reader rooms, RNFD / NFD / UNFSD support, dashboards, maps, public authority learning, technical baselines, token / DLT / DePIN systems, proof receipts, or public claims are understood as finance-readiness, investment advice, insurance approval, rating, guarantee, public finance approval, lending approval, capital commitment, or transaction recommendation.

20.2.15(b) This risk may arise through capital-reader audiences, sponsor materials, provider materials, project materials, public finance readers, insurance-sensitive language, “bankable,” “investable,” “ready,” “rated,” “guaranteed,” “approved,” or similar terms.

20.2.15(c) Controls shall include GRA routing, finance-safe language, capital-reader room controls, no-advice language, no-solicitation language, no-rating language, no-guarantee language, no-public-finance-approval language, legal review, and correction.

20.2.15(d) Finance-Readiness Boundary Risk shall be escalated where public or market reliance may occur.

20.2.15(e) The controlling rule shall be that technical evidence shall not become financial reliance by audience, phrasing, or repetition.


20.2.16 Sponsor, Donor, Funder, Provider, Host, and Participant Capture Risk. 20.2.16(a) Sponsor, Donor, Funder, Provider, Host, and Participant Capture Risk means risk that support, funding, in-kind contributions, facilities, technical tools, data, compute, participation, visibility, or access influence GCRI Canada’s governance, evidence, methods, publications, corrections, Public Authority access, technical baselines, public claims, or institutional priorities.

20.2.16(b) Capture risk may arise through restricted funding, sponsor review rights, provider tools, host dependence, donor preferences, grant conditions, publication pressure, correction suppression, platform dependency, data dependency, event dependency, or repeated informal influence.

20.2.16(c) Controls shall include support-without-control clauses, conflict review, independence review, public acknowledgment rules, provider neutrality, sponsor non-control, restricted fund controls, contract clauses, publication independence, correction rights, and assurance.

20.2.16(d) Capture risk shall be escalated where support appears to purchase outcomes, access, recognition, finance-readiness, certification, public authority proximity, provider status, or public meaning.

20.2.16(e) The controlling rule shall be that support may fund public-good infrastructure but shall not own institutional truth.


20.2.17 Community Safeguards and Protected Knowledge Risk. 20.2.17(a) Community Safeguards and Protected Knowledge Risk means risk of harm, extraction, misdescription, exposure, re-identification, stigmatization, cultural harm, ecological harm, unsafe mapping, protected person exposure, or misuse of Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, community-protected data, or Protected Knowledge.

20.2.17(b) Such risk may arise through research, data collection, dashboards, maps, AI outputs, public reports, datasets, repositories, media, public authority learning, sensor data, geospatial data, environmental data, or public-safe summaries.

20.2.17(c) Controls shall include consent and non-consent handling where applicable, community review, Indigenous or protected knowledge protocols, public-safe mapping review, aggregation, redaction, access limits, grievance pathways, correction pathways, and withdrawal or sealing where required.

20.2.17(d) This risk shall be escalated where vulnerable communities, remote communities, protected persons, sensitive sites, ecological vulnerabilities, public health issues, or cultural materials may be affected.

20.2.17(e) The controlling rule shall be that public-good evidence shall not be created by unsafe extraction from communities or protected knowledge holders.


20.2.18 Legal, Tax, Sanctions, Export-Control, Competition, Professional-Boundary, and Contract Risk. 20.2.18(a) Legal, Tax, Sanctions, Export-Control, Competition, Professional-Boundary, and Contract Risk means risk that GCRI Canada’s activities, relationships, funding, contracts, data, technology, publications, public claims, or interfaces breach applicable legal obligations or create unauthorized legal roles.

20.2.18(b) Such risk may include corporate noncompliance, tax-status drift, improper receipting, private benefit, inurement, sanctions exposure, export-control breach, restricted-party engagement, competition-sensitive exchange, procurement steering, professional advice overclaim, unauthorized legal advice, contract breach, grant breach, or platform-term breach.

20.2.18(c) Controls shall include legal review triggers, compliance calendars, screening registers, controlled technology registers, contract review, grant review, procurement neutrality controls, professional-boundary language, and compliance assurance.

20.2.18(d) Legal risk shall be escalated where ambiguity, regulated perimeter, cross-border activity, controlled technology, public authority involvement, finance sensitivity, or public harm exists.

20.2.18(e) The controlling rule shall be that legal compliance risk must be treated as institutional risk, not merely external advisory risk.


20.2.19 Operational, People, Continuity, Reputation, and Public Trust Risk. 20.2.19(a) Operational, People, Continuity, Reputation, and Public Trust Risk means risk affecting the availability, reliability, staffing, competence, culture, continuity, public understanding, reputation, legitimacy, and resilience of GCRI Canada.

20.2.19(b) Such risk may arise from key-person dependency, inadequate staffing, weak training, contractor misclassification, volunteer overreliance, platform dependency, funding dependency, system outage, repository failure, incident response weakness, public misdescription, media distortion, unresolved corrections, or public trust erosion.

20.2.19(c) Controls shall include workforce planning, role documentation, training, backup, succession planning, business continuity, disaster recovery, communications controls, public-safe correction, incident response, records assurance, and Board reporting.

20.2.19(d) Reputation Risk shall be assessed as public trust risk and shall not be used to suppress lawful correction, transparency, affected-person notice, protected knowledge remedy, or public-safe clarification.

20.2.19(e) The controlling rule shall be that institutional reputation is protected by truth, correction, continuity, and trustworthiness, not by concealment.


20.2.20 Risk Register Ownership, Review Cycle, Scoring, Treatment, and Board Reporting. 20.2.20(a) The Institutional Risk Register shall have a designated owner, custodian, review cycle, scoring method where adopted, treatment method, escalation criteria, and Board or committee reporting process.

20.2.20(b) Risk scoring, where used, shall be consistent, documented, proportionate, and capable of reflecting likelihood, severity, public-benefit consequence, legal consequence, public trust consequence, data sensitivity, Public Authority sensitivity, finance sensitivity, protected knowledge sensitivity, and control effectiveness.

20.2.20(c) Risk treatment shall include avoidance, mitigation, transfer where lawful and appropriate, acceptance where permitted, escalation, correction, monitoring, or refusal. Transfer shall not be used to transfer GCRI Canada’s mission duties, legal duties, correction duties, public authority boundaries, finance boundaries, data duties, or protected knowledge duties.

20.2.20(d) Material risks, prohibited risks, accepted risks, unresolved high risks, repeated issues, failed controls, and assurance findings shall be reported to the Board or authorized committee.

20.2.20(e) The controlling rule shall be that risk registers must drive governance action, not merely preserve institutional memory.


20.3 Issue Register

20.3.1 Requirement to Maintain an Issue Register for Active Problems. 20.3.1(a) GCRI Canada shall maintain an Issue Register for active problems, unresolved control failures, open corrective actions, emerging operational defects, known weaknesses, repeated exceptions, near misses, unresolved incidents, failed reviews, stale records, unsafe public materials, and other matters requiring active management.

20.3.1(b) The Issue Register shall differ from the Institutional Risk Register by tracking specific active issues requiring action, owner assignment, due dates, interim controls, correction, verification, and closeout.

20.3.1(c) Issues may arise from audits, assurance, incidents, complaints, grievances, legal review, public challenges, community feedback, Public Authority clarification, capital-reader confusion, publication correction, data review, AI review, cybersecurity review, or Board oversight.

20.3.1(d) Issues shall not remain unmanaged because they are small, inconvenient, politically sensitive, sponsor-sensitive, provider-sensitive, public authority-sensitive, finance-sensitive, or reputationally uncomfortable.

20.3.1(e) The controlling rule shall be that known problems must be owned, tracked, corrected, and closed by record.


20.3.2 Issue Intake. 20.3.2(a) Issue intake shall provide a defined pathway for reporting, recording, and triaging active problems.

20.3.2(b) Intake shall identify reporter, date, source, issue description, affected Charter Part, affected records, affected systems, affected persons, affected communities, affected Public Authorities, affected sponsors or providers, affected publications, affected data classes, urgency, suspected severity, and immediate controls needed.

20.3.2(c) Issue sources may include staff reports, participant reports, Board requests, committee findings, assurance findings, incident reports, community grievances, Public Authority feedback, sponsor or provider notices, legal reviews, cybersecurity alerts, privacy requests, and publication corrections.

20.3.2(d) Intake shall allow good-faith reporting without retaliation.

20.3.2(e) The controlling rule shall be that issue intake must make problems visible before they become incidents.


20.3.3 Issue Classification. 20.3.3(a) Issues shall be classified by domain, severity, urgency, affected authority, affected records, affected controls, affected obligations, affected public materials, affected data, affected technology, affected people, affected communities, affected Public Authorities, affected finance boundaries, and affected Nexus interfaces.

20.3.3(b) Issue domains may include governance, fiduciary, mission drift, non-execution, evidence, methods, research, records, correction, data, AI, cybersecurity, publication, Public Authority boundary, finance boundary, fiscal, legal, tax, sanctions, export control, competition, contract, IP, workforce, community safeguards, protected knowledge, continuity, reputation, and public trust.

20.3.3(c) Classification shall identify whether the issue is also an incident, legal matter, compliance issue, privacy matter, cybersecurity matter, financial matter, public claims matter, research matter, Public Authority matter, or protected knowledge matter.

20.3.3(d) Classification shall be updated where facts change.

20.3.3(e) The controlling rule shall be that issue classification determines the correct controls, not the preferred narrative.


20.3.4 Issue Severity. 20.3.4(a) Issue severity shall be determined using criteria proportionate to institutional risk.

20.3.4(b) Severity criteria shall consider legal consequence, public-benefit consequence, safety consequence, privacy consequence, cybersecurity consequence, Public Authority consequence, finance-boundary consequence, community consequence, protected knowledge consequence, reputational consequence, operational consequence, recurrence risk, and correction urgency.

20.3.4(c) Severity levels may include low, moderate, high, and critical, or another Board-approved scale, provided the scale is documented and applied consistently.

20.3.4(d) High or critical issues shall require escalation, interim controls, leadership visibility, Board or committee reporting where appropriate, and verified corrective action.

20.3.4(e) The controlling rule shall be that severity must reflect harm and authority risk, not internal discomfort.


20.3.5 Issue Owner and Custodian. 20.3.5(a) Each issue shall have an assigned owner and custodian.

20.3.5(b) The issue owner shall be accountable for corrective action, escalation, coordination, deadlines, verification, and closeout.

20.3.5(c) The issue custodian shall maintain the issue record, supporting materials, status updates, dependencies, interim controls, approvals, and closeout evidence.

20.3.5(d) Where an issue crosses domains, co-owners or supporting owners may be assigned, but one accountable owner shall remain identified.

20.3.5(e) The controlling rule shall be that no issue shall remain ownerless because it is cross-functional or politically sensitive.


20.3.6 Issue Root Cause. 20.3.6(a) Material issues shall receive root cause review proportionate to severity.

20.3.6(b) Root causes may include policy gap, training gap, authority ambiguity, weak recordkeeping, poor access control, unclear role language, inadequate legal review, sponsor pressure, provider pressure, public authority ambiguity, finance-boundary ambiguity, data control failure, AI misuse, cybersecurity weakness, technical defect, staffing gap, vendor failure, or governance failure.

20.3.6(c) Root cause review shall distinguish symptom, immediate cause, underlying cause, systemic cause, and recurrence pattern where appropriate.

20.3.6(d) Corrective action shall address root cause, not merely surface appearance.

20.3.6(e) The controlling rule shall be that repeated issues are evidence of control weakness until proven otherwise.


20.3.7 Issue Affected Records, Systems, Programs, Participants, Publications, Interfaces, or Public Materials. 20.3.7(a) Each issue shall identify affected records, systems, programs, participants, publications, dashboards, maps, datasets, repositories, rooms, public materials, contracts, grants, Public Authority interfaces, GRA interfaces, GRF interfaces, Protocol Authority interfaces, National Company interfaces, Project SPV interfaces, provider interfaces, sponsor interfaces, community interfaces, and Nexus interfaces where applicable.

20.3.7(b) Affected-record review shall identify whether any record requires correction, reclassification, hold, withdrawal, supersession, archive, sealing, deletion, legal hold, or public-safe notice.

20.3.7(c) Affected-system review shall identify whether access restriction, patching, configuration change, key rotation, vendor action, backup restoration, or system suspension is required.

20.3.7(d) Affected-public-material review shall identify whether public claims, publications, dashboards, maps, reports, social media, media materials, public authority references, sponsor references, or provider references require correction.

20.3.7(e) The controlling rule shall be that issues must be mapped to affected dependencies before they can be closed.


20.3.8 Issue Interim Controls, Holds, Quarantine, Access Restrictions, or Public-Safe Measures. 20.3.8(a) Interim controls shall be applied where an issue may create ongoing harm, reliance, legal exposure, data exposure, cybersecurity exposure, public authority confusion, finance overclaim, protected knowledge exposure, or public trust risk before final correction.

20.3.8(b) Interim controls may include activity hold, publication hold, public claims hold, data quarantine, AI-use restriction, model restriction, repository restriction, access suspension, controlled-room suspension, public authority reference hold, finance-sensitive material hold, payment hold, transfer block, or public-safe interim clarification.

20.3.8(c) Interim controls shall be proportionate, recorded, time-bound where appropriate, reviewed, and lifted only when conditions are met.

20.3.8(d) Interim controls shall not be used to conceal an issue or indefinitely avoid correction.

20.3.8(e) The controlling rule shall be that active issues require risk containment before final resolution where reliance or harm may continue.


20.3.9 Issue Corrective Action Plan. 20.3.9(a) Each material issue shall have a corrective action plan.

20.3.9(b) The corrective action plan shall identify issue, root cause, corrective action, responsible owner, due date, interim controls, affected records, affected systems, affected public materials, required approvals, required legal review, required public-safe review, required controlled notice, training updates, policy updates, register updates, verification method, and closeout criteria.

20.3.9(c) Corrective actions may include record correction, policy update, control redesign, training, access change, legal review, contract amendment, publication correction, public-safe notice, controlled notice, system patch, data deletion, AI restriction, provider remedy, sponsor correction, or participant discipline.

20.3.9(d) Corrective action shall be verified before closeout where the issue is material.

20.3.9(e) The controlling rule shall be that correction must be planned, assigned, verified, and recorded.


20.3.10 Issue Due Dates, Dependencies, Escalation Triggers, and Closeout. 20.3.10(a) Each issue shall identify due dates, dependencies, escalation triggers, and closeout requirements.

20.3.10(b) Due dates shall reflect severity, legal deadlines, public-safe urgency, data sensitivity, cybersecurity exposure, public authority sensitivity, finance sensitivity, protected knowledge risk, and operational feasibility.

20.3.10(c) Dependencies shall identify required approvals, legal review, Public Authority clarification, vendor action, participant action, Board action, technical work, data remediation, publication correction, or external notice.

20.3.10(d) Escalation triggers shall include missed deadlines, increased severity, failed interim controls, public reliance, legal notice obligation, repeated issue, unresolved owner dispute, or Board-level risk.

20.3.10(e) Closeout shall require evidence that corrective actions have been completed, verified, recorded, and linked to affected registers.

20.3.10(f) The controlling rule shall be that issues remain open until closure is evidenced, not merely asserted.


20.3.11 Issue Recurrence and Pattern Review. 20.3.11(a) GCRI Canada shall conduct recurrence and pattern review for issues.

20.3.11(b) Pattern review shall identify repeated control failures, repeated public claims overreach, repeated Public Authority confusion, repeated finance overclaim, repeated data handling errors, repeated AI misuse, repeated cybersecurity weakness, repeated training gaps, repeated policy exceptions, repeated sponsor or provider influence, and repeated record failures.

20.3.11(c) Recurrent issues shall be escalated as control failures, governance risks, training failures, cultural risks, or systemic risks where appropriate.

20.3.11(d) Pattern review may require policy redesign, control redesign, role redesign, system redesign, access restriction, relationship restriction, Board review, or assurance cycle changes.

20.3.11(e) The controlling rule shall be that recurrence converts an issue from isolated problem to systemic risk.


20.3.12 Issue Register Assurance and Board / Committee Reporting. 20.3.12(a) GCRI Canada shall conduct Issue Register Assurance and report material issues to the Board or authorized committee.

20.3.12(b) Assurance shall review whether issues are complete, correctly classified, owned, timely, controlled, escalated, corrected, verified, and closed with evidence.

20.3.12(c) Assurance shall identify stale issues, ownerless issues, overdue issues, repeated issues, under-classified issues, unresolved high-risk issues, ineffective corrective actions, and missing Board reporting.

20.3.12(d) Board or committee reporting shall include material issue status, trend analysis, overdue items, high-risk issues, corrective action progress, unresolved barriers, and recommended governance action.

20.3.12(e) The controlling rule shall be that issue management must be assured because known problems that remain unmanaged become governance failures.


20.4 Control Register

20.4.1 Requirement to Maintain a Control Register. 20.4.1(a) GCRI Canada shall maintain a Control Register identifying material controls used to prevent, detect, correct, monitor, and assure institutional risks.

20.4.1(b) The Control Register shall include governance controls, evidence controls, methods controls, research controls, publication controls, records controls, correction controls, data controls, AI controls, cybersecurity controls, technical asset controls, Public Authority boundary controls, finance-boundary controls, fiscal controls, sponsorship controls, grant controls, anti-inurement controls, community safeguard controls, protected knowledge controls, legal compliance controls, sanctions controls, export-control controls, competition controls, professional-boundary controls, workforce controls, and Nexus-interface controls.

20.4.1(c) Each control shall identify owner, custodian, purpose, risk mapped, policy source, procedure source, system source where applicable, frequency, evidence of operation, testing method, exceptions, failures, corrective actions, and review cycle.

20.4.1(d) Controls may be manual, automated, technical, legal, governance, procedural, training-based, access-based, publication-based, or assurance-based.

20.4.1(e) The controlling rule shall be that controls must be visible and testable before they can be relied upon.


20.4.2 Controls Mapped to Risks, Issues, Charter Parts, Policies, Procedures, Registers, Systems, Owners, and Review Cycles. 20.4.2(a) Controls shall be mapped to risks, issues, Charter Parts, Bylaw provisions, policies, procedures, registers, systems, repositories, rooms, data classes, AI systems, Public Authority interfaces, finance-sensitive interfaces, owners, custodians, and review cycles.

20.4.2(b) Control mapping shall show which controls mitigate which risks and which risks lack sufficient controls.

20.4.2(c) Control mapping shall identify preventive controls, detective controls, corrective controls, compensating controls, and assurance controls.

20.4.2(d) Where a control relies on another control, the dependency shall be recorded.

20.4.2(e) The controlling rule shall be that unmapped controls and uncontrolled risks both require governance attention.


20.4.3 Governance Controls. 20.4.3(a) Governance controls shall protect Board authority, fiduciary duty, officer delegation, committee mandates, council limits, conflicts, recusal, related-party transactions, decision records, legal separateness, and mission lock.

20.4.3(b) Governance controls may include Board-reserved matters, committee charters, delegation registers, decision packs, meeting minutes, conflict disclosures, recusal records, related-party review, independent review, governance training, Board evaluation, and governance assurance.

20.4.3(c) Governance controls shall prevent informal governance, no-record approvals, email governance, council overreach, officer overreach, sponsor control, provider control, founder control, and public authority confusion.

20.4.3(d) Governance controls shall be tested for operation, completeness, timeliness, and correction where defects occur.

20.4.3(e) The controlling rule shall be that governance controls preserve lawful authority before decisions are made.


20.4.4 Evidence and Methods Controls. 20.4.4(a) Evidence and methods controls shall protect source lineage, evidence integrity, methods integrity, ontology, controlled vocabulary, Observatory Methods, Truth Engine Methods, technical truth, benchmark discipline, and public-good technical baselines.

20.4.4(b) Controls may include evidence intake procedures, Case IDs, metadata standards, source-lineage records, method protocols, review gates, controlled vocabulary registers, versioning, change logs, reproducibility packages where lawful, limitation statements, and correction paths.

20.4.4(c) Evidence and methods controls shall prevent unsupported claims, stale evidence use, method drift, benchmark overclaim, AI hallucination, source fabrication, translation drift, and use beyond authority.

20.4.4(d) Controls shall be heightened where evidence or methods support public authority learning, finance-sensitive materials, public-safe publications, dashboards, maps, datasets, technical releases, or Nexus interfaces.

20.4.4(e) The controlling rule shall be that evidence and methods controls preserve the truth function of GCRI Canada.


20.4.5 Research and Publication Controls. 20.4.5(a) Research and publication controls shall protect research ethics, human-subjects protections, community safeguards, protected knowledge, peer review, reproducibility, publication accuracy, claims substantiation, public-safe release, and correctionability.

20.4.5(b) Controls may include research protocols, ethics review, community review, Indigenous and protected knowledge protocols, conflict disclosures, peer review, expert review, AI-use disclosure, publication classes, review gates, public-safe publication review, legal review where required, and correction notices.

20.4.5(c) Publication controls shall prevent defamation risk, misrepresentation, unsupported claims, public authority overclaim, finance overclaim, certification overclaim, provider preference, sponsor control implication, public warning confusion, sensitive-location exposure, and protected knowledge exposure.

20.4.5(d) Research and publication controls shall apply before release and after release through monitoring, correction, withdrawal, retraction, supersession, and archive.

20.4.5(e) The controlling rule shall be that research and publication controls must protect both accuracy and public-safe meaning.


20.4.6 Records and Correction Controls. 20.4.6(a) Records and correction controls shall protect validity-by-record, no-silent-effect discipline, authoritative repositories, official registers, Gazette notices where applicable, versioning, metadata, authority mapping, retention, legal hold, correctionability, supersession, withdrawal, retraction, and archive.

20.4.6(b) Controls may include Case ID requirements, minimum metadata standards, authority mapping, official registers, repository controls, versioning, change logs, no-silent-edit rules, correction processes, public-safe correction notices, controlled correction notices, retention schedules, access logs, and record assurance.

20.4.6(c) Records and correction controls shall prevent unrecorded decisions, stale public materials, unauthorized edits, unsupported claims, missing authority, uncontrolled documents, uncorrectable outputs, and public reliance beyond recorded authority.

20.4.6(d) Correction controls shall be triggered by factual error, method error, source error, data error, AI error, public authority misdescription, finance overclaim, provider overclaim, sponsor overclaim, protected knowledge issue, or public harm risk.

20.4.6(e) The controlling rule shall be that institutional meaning must remain record-valid and correctionable.


20.4.7 Data, AI, Cybersecurity, and Technical Asset Controls. 20.4.7(a) Data, AI, cybersecurity, and technical asset controls shall protect privacy, rights-bearing data, Public Authority Data, protected knowledge, AI governance, cybersecurity, repositories, software releases, technical baselines, compute environments, dashboards, maps, APIs, schemas, and public-good technical assets.

20.4.7(b) Controls may include data classification, lawful basis review, privacy notices, impact assessments, access controls, retention and deletion controls, AI use inventories, model registers, inference records, human review, vendor review, secure development, repository security, secrets management, vulnerability management, SBOMs, secure release, incident response, and business continuity.

20.4.7(c) Controls shall prevent unauthorized data access, unauthorized AI use, unauthorized training, unauthorized embedding, hallucination reliance, model drift, cybersecurity compromise, sensitive data leakage, insecure release, and technical asset enclosure.

20.4.7(d) Controls shall be heightened where Public Authority Data, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, protected knowledge, or controlled technology is involved.

20.4.7(e) The controlling rule shall be that technical systems must be governed as legal, ethical, and public trust systems.


20.4.8 Public Authority Boundary Controls. 20.4.8(a) Public Authority boundary controls shall prevent GCRI Canada materials, activities, relationships, rooms, dashboards, maps, data contributions, public authority learning, or references from being understood as endorsement, adoption, regulation, procurement approval, funding approval, public finance approval, public warning, emergency command, official guidance, or sovereign obligation.

20.4.8(b) Controls may include capacity classification, reference approval, Public Authority Data agreements, non-endorsement language, no-public-warning language, no-command language, procurement-neutrality controls, public finance boundary language, public authority room controls, and correction processes.

20.4.8(c) Public Authority boundary controls shall apply before using Public Authority names, logos, titles, quotes, photographs, agency names, jurisdictions, attendance, or data contributions in public or controlled materials.

20.4.8(d) Controls shall be heightened for regulator-listening contexts, procurement-sensitive contexts, public finance reader contexts, emergency-management contexts, public health contexts, infrastructure contexts, and public warning-like materials.

20.4.8(e) The controlling rule shall be that Public Authority proximity requires boundary controls before public meaning forms.


20.4.9 Finance-Boundary, Fiscal, Sponsorship, Grant, and Anti-Inurement Controls. 20.4.9(a) Finance-boundary, fiscal, sponsorship, grant, and anti-inurement controls shall protect GCRI Canada from financial-services drift, finance-readiness overclaim, sponsor control, donor control, grantor control, provider preference, public authority access purchase, procurement advantage, private benefit, inurement, restricted fund breach, and fiscal instability.

20.4.9(b) Controls may include budgets, restricted fund registers, donation registers, sponsorship registers, grant registers, in-kind contribution registers, signing authority, procurement registers, related-party review, compensation review, finance-safe language, GRA routing, capital-reader room controls, public finance boundary language, and fiscal assurance.

20.4.9(c) Controls shall prevent outcome purchase, publication suppression, correction suppression, finance-readiness purchase, recognition purchase, certification purchase, procurement advantage, and support-for-control arrangements.

20.4.9(d) Controls shall be heightened where funds, in-kind assets, Public Authority interfaces, capital-reader rooms, GRA materials, Proof Pack inputs, public finance readers, or provider participation create market or authority meaning.

20.4.9(e) The controlling rule shall be that financial support must remain lawful support, not control or financial authority.


20.4.10 Community Safeguard and Protected Knowledge Controls. 20.4.10(a) Community safeguard and protected knowledge controls shall protect communities, Indigenous knowledge holders, local knowledge holders, territorial knowledge holders, cultural knowledge holders, environmental knowledge holders, vulnerable participants, protected persons, confidential sources, sensitive sites, and community-protected information.

20.4.10(b) Controls may include consent and non-consent handling where applicable, community review, Indigenous-governed review where appropriate, protected knowledge protocols, public-safe mapping review, access restrictions, aggregation, redaction, resolution reduction, grievance pathways, non-retaliation protections, and correction pathways.

20.4.10(c) Controls shall prevent extraction, misdescription, exposure, stigmatization, re-identification, unsafe mapping, protected knowledge publication, AI misuse, dataset misuse, dashboard misuse, and media amplification harm.

20.4.10(d) Controls shall be heightened for remote communities, vulnerable communities, protected persons, youth, sensitive locations, cultural sites, ecological sites, public health vulnerabilities, and public safety contexts.

20.4.10(e) The controlling rule shall be that community trust and protected knowledge must be safeguarded before evidence is collected, visualized, published, or reused.


20.4.11 Legal Compliance, Sanctions, Export-Control, Competition, and Professional-Boundary Controls. 20.4.11(a) Legal compliance, sanctions, export-control, competition, and professional-boundary controls shall protect GCRI Canada from legal noncompliance, tax-status drift, restricted-party exposure, controlled technology transfer, competition-law risk, procurement-law risk, unauthorized professional practice, and regulated-perimeter breach.

20.4.11(b) Controls may include legal review triggers, compliance calendars, sanctions screening, restricted-party registers, export-control registers, controlled technology review, competition do-not-discuss rules, procurement-neutrality controls, professional-boundary language, contract templates, policy reviews, and compliance assurance.

20.4.11(c) Controls shall prevent unauthorized legal advice, investment advice, insurance advice, engineering certification, medical advice, public health direction, emergency command, public warning, procurement advice, compliance certification, rating, underwriting, or other regulated professional services.

20.4.11(d) Controls shall be heightened for international collaboration, controlled technology, Public Authority interfaces, finance-sensitive materials, policy-facing activity, public claims, and high-risk jurisdictions.

20.4.11(e) The controlling rule shall be that legal boundary controls preserve lawful mission activity before risk becomes noncompliance.


20.4.12 Control Testing, Exceptions, Failures, Corrective Actions, and Assurance. 20.4.12(a) Controls shall be tested, reviewed, and assured according to risk.

20.4.12(b) Control testing shall identify whether controls are designed, implemented, operating, documented, effective, current, and linked to relevant risks.

20.4.12(c) Control exceptions shall be recorded, narrow, time-bound where appropriate, approved by proper authority, risk-reviewed, and not used to permit prohibited functions, legal noncompliance, data misuse, AI misuse, cybersecurity weakness, protected knowledge exposure, public authority overclaim, finance overclaim, sponsor control, provider preference, or private inurement.

20.4.12(d) Control failures shall require issue registration, root cause review, corrective action, owner assignment, verification, and assurance follow-up.

20.4.12(e) The controlling rule shall be that a control that cannot be tested, evidenced, or corrected is not a reliable control.


20.5 Risk Appetite, Risk Tolerance, and Prohibited Risk

20.5.1 Risk Appetite as Board-Approved Institutional Guidance Where Adopted. 20.5.1(a) Risk appetite, where adopted, shall be Board-approved institutional guidance identifying the type and level of risk GCRI Canada may accept in pursuit of its public-benefit mission.

20.5.1(b) Risk appetite shall be consistent with law, articles, Bylaw, Charter, mission lock, nonprofit character, non-execution, public-good stack role separation, privacy, cybersecurity, protected knowledge safeguards, public authority boundaries, finance boundaries, anti-inurement, legal separateness, and correctionability.

20.5.1(c) Risk appetite shall not authorize prohibited functions, unlawful conduct, private inurement, intentional misrepresentation, sponsor control, provider preference, public authority confusion, finance-regulated activity, protected knowledge misuse, sanctions breach, export-control breach, or deliberate data misuse.

20.5.1(d) Risk appetite shall be reviewed periodically and after material changes in law, technology, data, funding, Public Authority interfaces, finance-sensitive interfaces, international collaboration, incidents, or assurance findings.

20.5.1(e) The controlling rule shall be that risk appetite may guide mission-aligned judgment but shall not override constitutional boundaries.


20.5.2 Risk Tolerance by Domain, Activity, Data Class, Public Audience, Public Authority Interface, Technology Class, and Nexus Interface. 20.5.2(a) Risk tolerance may be defined by domain, activity, data class, public audience, Public Authority interface, finance-sensitive interface, technology class, publication class, room type, participant category, jurisdiction, and Nexus interface.

20.5.2(b) Data risk tolerance shall consider whether data is public, public-safe, internal, confidential, restricted, personal, health-sensitive, Public Authority Data, cyber-sensitive, infrastructure-sensitive, finance-sensitive, community-protected, Indigenous or protected knowledge, controlled technology, or export-control-sensitive.

20.5.2(c) Technology risk tolerance shall consider AI systems, model use, embedding, retrieval, agentic AI, cyber tools, AI-RAN, DePIN, blockchain / DLT, geospatial systems, satellite systems, drones, robotics, autonomous systems, quantum-relevant systems, high-performance compute, public-good software, APIs, schemas, dashboards, maps, and technical baselines.

20.5.2(d) Public audience risk tolerance shall be lower where public materials may affect communities, Public Authorities, capital readers, media, providers, sponsors, vulnerable persons, protected knowledge, public safety, or public trust.

20.5.2(e) The controlling rule shall be that tolerance must be specific enough to guide actual decisions, not merely broad enough to sound prudent.


20.5.3 Low Tolerance for Evidence Misrepresentation. 20.5.3(a) GCRI Canada shall maintain low tolerance for evidence misrepresentation.

20.5.3(b) Evidence misrepresentation includes unsupported claims, false source attribution, stale evidence use, selective omission, inflated confidence, suppressed uncertainty, fabricated evidence, AI hallucination, false citation, misleading visualization, benchmark misuse, method overclaim, impact inflation, or use of evidence beyond source authority.

20.5.3(c) Evidence misrepresentation shall require correction, reclassification, withdrawal, retraction, public-safe notice, controlled notice, method review, publication review, training, or disciplinary action as appropriate.

20.5.3(d) Evidence misrepresentation shall be treated as heightened where Public Authorities, capital readers, communities, media, providers, sponsors, or public audiences may rely on the output.

20.5.3(e) The controlling rule shall be that evidence integrity is not reputational preference; it is the foundation of GCRI Canada’s public-benefit mandate.


20.5.4 Low Tolerance for Public Authority Confusion. 20.5.4(a) GCRI Canada shall maintain low tolerance for Public Authority confusion.

20.5.4(b) Public Authority confusion includes any statement, conduct, room, report, dashboard, map, public authority learning material, data contribution, quote, logo use, attendance reference, or public claim implying endorsement, adoption, regulation, procurement approval, funding approval, public finance approval, public warning, emergency command, official guidance, or sovereign obligation without proper authority.

20.5.4(c) Public Authority confusion shall require capacity clarification, reference correction, public-safe notice, controlled notice, takedown, access restriction, room redesign, legal review, or training as appropriate.

20.5.4(d) Public Authority confusion shall be treated as heightened where emergency management, public health, public infrastructure, procurement, regulatory, public finance, or public warning contexts are involved.

20.5.4(e) The controlling rule shall be that public power must not be implied by proximity, attendance, or public language.


20.5.5 Low Tolerance for Finance Overclaim. 20.5.5(a) GCRI Canada shall maintain low tolerance for finance overclaim.

20.5.5(b) Finance overclaim includes any implication that GCRI Canada provides investment advice, securities solicitation, brokerage, finder activity, placement activity, lending approval, guarantee, insurance approval, underwriting, rating, public finance approval, grant approval, budget approval, MDB / DFI approval, sovereign finance approval, capital commitment, transaction recommendation, token issuance, custody, payment intermediation, or market operation.

20.5.5(c) Finance overclaim also includes describing a project, provider, host, National Company, Project SPV, technology, evidence pack, technical baseline, dashboard, map, or public authority initiative as finance-ready, bankable, investable, creditworthy, insurable, rated, guaranteed, or approved by GCRI Canada.

20.5.5(d) Finance overclaim shall require immediate hold, legal review, GRA routing where appropriate, corrected language, public-safe clarification, controlled notice, access restriction, room redesign, withdrawal, or retraction as appropriate.

20.5.5(e) The controlling rule shall be that finance meaning must not arise from technical evidence, audience, or aspiration.


20.5.6 Low Tolerance for Privacy, Cybersecurity, Protected Knowledge, and Community Harm. 20.5.6(a) GCRI Canada shall maintain low tolerance for privacy, cybersecurity, protected knowledge, and community harm.

20.5.6(b) Such harm includes unauthorized access, unauthorized disclosure, over-collection, re-identification, unsafe mapping, sensitive-location exposure, Public Authority Data misuse, health-sensitive data misuse, cyber-sensitive data exposure, infrastructure-sensitive data exposure, protected knowledge exposure, community misdescription, stigmatization, AI data leakage, or cybersecurity compromise.

20.5.6(c) Low tolerance shall require strong preventive controls, rapid containment, legal review where required, affected-person or community consideration, Public Authority consideration where applicable, breach assessment, public-safe communication, correction, remediation, and assurance follow-up.

20.5.6(d) Privacy, cybersecurity, protected knowledge, and community harm risk shall not be accepted for convenience, speed, publication value, sponsor preference, provider preference, or public visibility.

20.5.6(e) The controlling rule shall be that public-benefit work must not create preventable rights, security, or community harms.


20.5.7 Low Tolerance for Sponsor Control, Provider Preference, and Private Inurement. 20.5.7(a) GCRI Canada shall maintain low tolerance for sponsor control, provider preference, donor control, funder control, host control, private inurement, improper private benefit, related-party abuse, pay-to-play, outcome purchase, and access purchase.

20.5.7(b) Sponsor control includes influence over governance, evidence, methods, publications, corrections, public authority access, technical baselines, public claims, or institutional priorities beyond recorded, lawful, mission-compatible terms.

20.5.7(c) Provider preference includes use of GCRI Canada participation, testing, benchmarking, demonstration, technical review, room access, public authority proximity, or public claims to imply preferred status, procurement advantage, certification, recognition, finance-readiness, or public authority approval.

20.5.7(d) Private inurement and improper private benefit shall require correction, return, repayment, repricing, rescission, access restriction, public claims correction, legal review, tax review, Board reporting, discipline, or termination where appropriate.

20.5.7(e) The controlling rule shall be that support and participation shall never purchase institutional truth, public authority proximity, market advantage, or private entitlement.


20.5.8 Zero or Near-Zero Tolerance for Prohibited Functions, Fraud, Retaliation, Bribery, Sanctions Breach, Export-Control Breach, Intentional Data Misuse, and Deliberate Public Misrepresentation. 20.5.8(a) GCRI Canada shall maintain zero or near-zero tolerance for prohibited functions, fraud, theft, bribery, corruption, retaliation, harassment, discrimination, sanctions breach, export-control breach, intentional data misuse, intentional AI misuse, deliberate cybersecurity misconduct, deliberate public misrepresentation, intentional protected knowledge misuse, and knowing public authority or finance overclaim.

20.5.8(b) Prohibited functions include public authority substitution, public warning issuance, emergency command, procurement authority, public finance approval, investment advice, securities solicitation, brokerage, lending, insurance placement, underwriting, rating, guarantee, certification by default, provider preference, sponsor control, and execution activity outside GCRI Canada’s lawful mandate.

20.5.8(c) Such risks shall not be accepted, normalized, waived, or treated as ordinary operational risk.

20.5.8(d) Response may include immediate hold, access suspension, investigation, legal review, notification where required, correction, withdrawal, retraction, termination, Board reporting, law enforcement or regulator interaction where appropriate, and assurance follow-up.

20.5.8(e) The controlling rule shall be that prohibited-risk conduct is not risk appetite; it is breach response.


20.5.9 Risk Acceptance Must Be Recorded, Time-Bound, Owned, Reviewed, and Escalated Where Material. 20.5.9(a) Risk acceptance shall be recorded, time-bound where appropriate, owned, reviewed, and escalated where material.

20.5.9(b) A risk acceptance record shall identify the risk, owner, authority, rationale, alternatives considered, controls in place, residual risk, duration, review date, conditions, monitoring, escalation triggers, affected records, affected persons or communities, affected Public Authorities, affected public materials, and Board or committee visibility where required.

20.5.9(c) Risk acceptance shall not be implied from inaction, silence, email, chat, informal meeting notes, repeated practice, sponsor pressure, provider pressure, funding pressure, public authority interest, or operational convenience.

20.5.9(d) Accepted risks shall be periodically reviewed and may be revoked, narrowed, escalated, corrected, or refused where conditions change.

20.5.9(e) The controlling rule shall be that accepted risk must be consciously authorized and continuously reviewable.


20.5.10 Prohibited Risk Cannot Be Accepted by Informal Approval or Operational Convenience. 20.5.10(a) Prohibited risk cannot be accepted by informal approval, operational convenience, funding need, sponsor preference, provider preference, grant deadline, public authority proximity, capital-reader interest, media opportunity, technical enthusiasm, founder preference, or repeated practice.

20.5.10(b) No Officer, Director, committee, council, Working Group, fellow, advisor, staff member, contractor, sponsor, provider, host, Public Authority participant, donor, funder, capital reader, National Company, Project SPV, or Nexus actor may authorize prohibited risk unless the Charter, law, and proper authority permit the activity; where the activity remains prohibited, it shall be refused.

20.5.10(c) Any attempted acceptance of prohibited risk shall be treated as an issue, incident, governance breach, compliance breach, or legal matter as appropriate.

20.5.10(d) Corrective action may include reversal, hold, correction, public-safe clarification, controlled notice, access restriction, legal review, Board reporting, training, discipline, termination, or relationship remedy.

20.5.10(e) The controlling rule shall be that no convenience, urgency, funding, or public-good aspiration can convert prohibited risk into permissible risk.

20.6 Stop-the-Line Authority

20.6.1 Stop-the-Line as Immediate Protective Authority. 20.6.1(a) Stop-the-Line Authority means the immediate protective authority to pause, hold, quarantine, restrict, suspend, freeze, escalate, or otherwise interrupt an activity, release, publication, communication, room, data flow, technical process, AI use, public claim, or institutional interface where a material risk to GCRI Canada’s mission, lawful authority, public-benefit character, public trust, non-execution, public authority boundary, finance boundary, data rights, cybersecurity, protected knowledge, community safeguards, evidence integrity, methods integrity, or legal separateness is reasonably identified.

20.6.1(b) Stop-the-Line Authority shall be protective, provisional, records-valid, non-retaliatory, and risk-based. It shall not be treated as a disciplinary finding, final decision, admission of liability, public position, or evidence that the underlying concern is confirmed.

20.6.1(c) Stop-the-Line Authority may be invoked before full investigation where delay could create public harm, legal exposure, privacy breach, cybersecurity exposure, Public Authority confusion, finance overclaim, protected knowledge exposure, reliance on unsupported materials, publication error, technical release error, or irreversible dissemination.

20.6.1(d) Stop-the-Line Authority shall preserve institutional truth, safety, lawful authority, public-safe publication, correctionability, and records integrity pending review.

20.6.1(e) The controlling rule shall be that where material harm or boundary failure may continue through action, publication, access, release, or silence, GCRI Canada shall have authority to pause first and review promptly.


20.6.2 Stop-the-Line May Be Invoked for Public Safety Risk, Public Authority Confusion, Public Warning Confusion, Finance Boundary Risk, Data Misuse, AI Misuse, Cybersecurity Risk, Protected Knowledge Risk, Community Harm Risk, Legal Noncompliance, Sponsor Control, Provider Preference, Publication Error, Technical Release Error, or Uncontrolled Public Claim. 20.6.2(a) Stop-the-Line Authority may be invoked where there is a reasonable concern involving public safety risk, Public Authority confusion, public warning confusion, emergency command confusion, finance-boundary risk, regulated financial-perimeter risk, data misuse, privacy risk, AI misuse, cybersecurity risk, protected knowledge risk, community harm risk, legal noncompliance, sanctions risk, export-control risk, competition risk, professional-boundary risk, sponsor control, donor control, funder control, provider preference, procurement overclaim, private inurement, publication error, technical release error, uncontrolled public claim, unsupported evidence, method error, dashboard error, map error, dataset release risk, or public-safe communication failure.

20.6.2(b) Stop-the-Line Authority may apply to Board or officer action pending proper authority, committee or council action pending mandate review, publication pending review, data access pending classification, AI use pending authorization, repository release pending security review, room participation pending boundary review, public authority reference pending approval, finance-sensitive material pending GRA or legal review, or sponsor / provider materials pending public claims review.

20.6.2(c) Stop-the-Line Authority may be invoked where the risk is observed directly, reported by a participant, identified through monitoring, detected by assurance, raised by a Public Authority, raised by a community or protected knowledge holder, identified by legal review, identified by technical review, or inferred from credible evidence.

20.6.2(d) Stop-the-Line Authority shall not require proof of final harm. A reasonable, good-faith, records-supported concern shall be sufficient to trigger provisional protection.

20.6.2(e) The controlling rule shall be that Stop-the-Line exists to prevent preventable harm before final certainty is available.


20.6.3 Authorized Stop-the-Line Persons and Escalation Channels. 20.6.3(a) Stop-the-Line Authority may be invoked by any Director, Officer, designated risk owner, legal or compliance lead, cybersecurity lead, data protection lead, research lead, publication lead, Public Authority interface lead, finance-boundary lead, protected knowledge or safeguards lead, room owner, repository owner, technical release owner, committee chair, or other person expressly authorized by policy, delegation, or emergency procedure.

20.6.3(b) Any employee, contractor, volunteer, fellow, advisor, contributor, Working Group participant, council participant, sponsor, provider, host, Public Authority participant, community participant, university participant, capital reader, or other participant may request Stop-the-Line review through the designated reporting channel where they identify a reasonable concern.

20.6.3(c) Policies may distinguish persons who may impose an immediate hold from persons who may request a hold, but shall ensure that urgent concerns can be raised without delay, intimidation, retaliation, or procedural obstruction.

20.6.3(d) Escalation channels shall identify primary and alternate contacts, emergency contacts, after-hours procedures where applicable, secure reporting pathways, anonymous or confidential reporting options where appropriate, and routing rules for legal, data, AI, cybersecurity, Public Authority, finance, community, protected knowledge, publication, and technical release concerns.

20.6.3(e) The controlling rule shall be that Stop-the-Line authority must be clear enough to be used when needed and broad enough to protect against silence.


20.6.4 Stop-the-Line Without Retaliation. 20.6.4(a) Good-faith invocation or request for Stop-the-Line review shall be protected from retaliation.

20.6.4(b) Retaliation includes dismissal, removal, demotion, contract termination, access denial, exclusion, harassment, intimidation, adverse assignment, reputational attack, funding penalty, publication penalty, authorship penalty, public claims retaliation, sponsor pressure, provider pressure, community pressure, or other adverse treatment because a person raised or supported a Stop-the-Line concern in good faith.

20.6.4(c) A person invoking Stop-the-Line in good faith shall not be required to prove that the concern is ultimately substantiated, provided the concern was reasonable, honestly held, and raised through appropriate channels or under circumstances requiring urgent protective action.

20.6.4(d) Retaliation or attempted retaliation for good-faith Stop-the-Line use shall be treated as a governance incident, conduct incident, participation incident, workforce incident, or contractual breach as appropriate.

20.6.4(e) The controlling rule shall be that GCRI Canada shall protect the person who pauses risk before protecting the convenience of the process that created risk.


20.6.5 Stop-the-Line Effect: Hold, Pause, Quarantine, Access Restriction, Publication Suspension, Release Freeze, Room Suspension, Data Transfer Hold, AI Use Hold, or Public Claims Hold. 20.6.5(a) Stop-the-Line effect may include hold, pause, quarantine, access restriction, publication suspension, technical release freeze, repository freeze, branch protection escalation, room suspension, clean-room hold, data-room hold, data transfer hold, AI-use hold, model restriction, retrieval restriction, embedding restriction, dashboard suspension, map suspension, dataset release hold, API freeze, schema release hold, public claims hold, media hold, Public Authority reference hold, finance-sensitive material hold, sponsor acknowledgment hold, provider reference hold, or procurement-sensitive communication hold.

20.6.5(b) The scope of the hold shall be proportionate to the risk and may apply to a single record, dataset, model, publication, interface, room, participant, system, repository, public statement, release, contract, activity, program, or relationship, or to a broader class of activity where the risk cannot be safely isolated.

20.6.5(c) Stop-the-Line action shall preserve records, evidence, metadata, logs, communications, versions, access records, and relevant materials pending triage and review.

20.6.5(d) Stop-the-Line action shall not be used to destroy records, suppress lawful complaints, conceal incidents, avoid correction, prevent legal notice, block affected-person rights, or retaliate against participants.

20.6.5(e) The controlling rule shall be that Stop-the-Line shall stop the risk pathway, preserve the evidence, and enable proper review.


20.6.6 Stop-the-Line Triage and Review. 20.6.6(a) A Stop-the-Line action shall be triaged promptly according to severity, affected domain, affected records, affected persons, affected communities, affected Public Authorities, affected data, affected systems, affected public materials, legal exposure, cybersecurity exposure, Public Authority consequence, finance consequence, protected knowledge consequence, public trust consequence, and need for immediate containment.

20.6.6(b) Triage shall determine whether the matter is an issue, incident, legal matter, privacy matter, AI matter, cybersecurity matter, publication matter, Public Authority matter, finance-boundary matter, protected knowledge matter, workforce matter, contract matter, grant matter, or governance matter.

20.6.6(c) Review shall identify the reason for the stop, authority invoked, materials affected, persons affected, interim controls, evidence to be preserved, reviewers required, escalation required, legal review required, Public Authority consultation required, community consultation required, and decision timeline.

20.6.6(d) Where the Stop-the-Line concerns urgent cybersecurity, privacy, data breach, public safety, legal notice, or protected knowledge exposure, containment shall proceed immediately while review continues.

20.6.6(e) The controlling rule shall be that Stop-the-Line must be triaged fast enough to prevent harm and reviewed carefully enough to preserve fairness and accuracy.


20.6.7 Stop-the-Line Decision, Continuation, Release, Correction, or Escalation. 20.6.7(a) Following triage and review, the Stop-the-Line action shall result in a decision to continue the hold, narrow the hold, release the hold, correct the affected matter, reclassify the matter, withdraw the matter, retract the matter, suspend the matter, escalate the matter, or convert the matter into an incident, issue, legal hold, investigation, or Board / committee matter.

20.6.7(b) A hold may be released only where the responsible authority determines, with appropriate records, that the risk has been resolved, controlled, accepted where permitted, corrected, or determined not to require continued restriction.

20.6.7(c) A hold shall continue where facts remain uncertain and continued activity could create material harm, reliance, legal exposure, data exposure, cybersecurity exposure, protected knowledge exposure, public authority confusion, finance overclaim, or public trust harm.

20.6.7(d) Correction may include revised record, revised publication, revised boundary language, public-safe notice, controlled notice, data deletion, access restriction, AI restriction, technical patch, release re-issue, room redesign, participant correction, sponsor correction, provider correction, Public Authority clarification, GRA routing, legal review, or Board action.

20.6.7(e) The controlling rule shall be that Stop-the-Line shall end only through recorded resolution, not through fatigue, pressure, or informal reassurance.


20.6.8 Stop-the-Line Records, Owner, Time, Scope, Reason, Affected Materials, and Closeout. 20.6.8(a) Each Stop-the-Line action shall be recorded.

20.6.8(b) The record shall identify requester, invoking person where different, date and time, authority, reason, affected activity, affected records, affected systems, affected data, affected persons, affected communities, affected Public Authorities, affected publications, affected rooms, affected repositories, affected public claims, affected contracts, affected sponsors or providers, scope, interim controls, owner, custodian, triage outcome, review outcome, decision, corrective action, escalation, and closeout.

20.6.8(c) Stop-the-Line records shall be classified, access-controlled, and linked to the Issue Register, Incident Register, Risk Register, Control Register, Publication Register, Data Register, AI Register, Cybersecurity Register, Public Authority Register, Finance Boundary Register, Legal Review Register, or other applicable register.

20.6.8(d) Closeout shall record final decision, evidence reviewed, corrective actions completed, notices issued, remaining risk, assurance follow-up, and lessons learned.

20.6.8(e) The controlling rule shall be that protective interruption must itself be record-valid and correctionable.


20.6.9 Abuse or Bad-Faith Use of Stop-the-Line. 20.6.9(a) Stop-the-Line shall not be abused or invoked in bad faith.

20.6.9(b) Abuse may include use of Stop-the-Line to retaliate, suppress lawful dissent, delay correction, conceal misconduct, gain commercial advantage, block publication for sponsor or provider convenience, prevent lawful Public Authority notice, obstruct investigation, harass a participant, manipulate procurement, influence finance-sensitive materials, or create strategic disruption without reasonable basis.

20.6.9(c) A finding that the underlying concern was not substantiated shall not by itself constitute abuse or bad faith.

20.6.9(d) Bad-faith use shall be reviewed according to conduct, workforce, participant, governance, contract, or legal procedures and may result in training, warning, access restriction, removal, discipline, contract remedy, termination, or legal action.

20.6.9(e) The controlling rule shall be that Stop-the-Line must protect good-faith caution while preventing weaponized obstruction.


20.6.10 Stop-the-Line Assurance and Training. 20.6.10(a) GCRI Canada shall maintain Stop-the-Line Assurance and training.

20.6.10(b) Training shall explain who may invoke Stop-the-Line, how concerns are raised, when immediate holds are appropriate, what non-retaliation means, how records are created, how triage occurs, how legal review is triggered, how holds are released, and how abuse is handled.

20.6.10(c) Assurance shall review Stop-the-Line records, timeliness, classification, interim controls, escalation, outcomes, retaliation concerns, repeated patterns, unresolved holds, improper releases, misuse, and training effectiveness.

20.6.10(d) Assurance findings may require policy updates, role clarification, reporting channel improvement, training refresh, access control changes, incident process updates, Board reporting, or corrective action.

20.6.10(e) The controlling rule shall be that Stop-the-Line authority must be trained and assured because protective authority fails if people fear using it or misuse it.


20.7 Incident Escalation

20.7.1 Incident Escalation as Mandatory for Material Boundary, Legal, Technical, Public-Safe, Data, AI, Cyber, Finance, Public Authority, Community, or Governance Incidents. 20.7.1(a) Incident escalation shall be mandatory for material boundary, legal, technical, public-safe, records, data, AI, cybersecurity, finance, Public Authority, community, protected knowledge, governance, research, publication, workforce, contract, grant, sponsorship, provider, host, participant, or Nexus-interface incidents.

20.7.1(b) Escalation shall ensure that incidents are reviewed by persons with proper authority, expertise, independence, legal awareness, technical competence, and institutional accountability.

20.7.1(c) Incident escalation shall not be delayed because the incident is reputationally sensitive, sponsor-sensitive, provider-sensitive, Public Authority-sensitive, finance-sensitive, media-sensitive, politically sensitive, cross-border, technically complex, or inconvenient.

20.7.1(d) Incident escalation shall preserve records, evidence, privilege where applicable, confidentiality, public-safe communication, non-retaliation, and correctionability.

20.7.1(e) The controlling rule shall be that material incidents move upward, across, or outward as required by risk, law, duty, and public trust.


20.7.2 Escalation to Officer. 20.7.2(a) Incidents shall be escalated to the appropriate Officer where they affect operations, programs, contracts, data, AI, cybersecurity, publications, public authority interfaces, finance boundaries, workforce, participants, sponsors, providers, hosts, research, technical releases, or public claims within that Officer’s delegated responsibility.

20.7.2(b) Officer escalation shall identify incident type, severity, affected materials, interim controls, legal review need, required notifications, correction pathway, and Board or committee reporting threshold.

20.7.2(c) Officers shall ensure immediate containment, assignment of incident owner, preservation of records, coordination with relevant leads, and timely reporting to higher authority where required.

20.7.2(d) An Officer with a conflict, implicated role, insufficient authority, or insufficient independence shall not be the sole decision-maker for escalation disposition.

20.7.2(e) The controlling rule shall be that operational incidents must reach an accountable Officer before they become unmanaged institutional exposure.


20.7.3 Escalation to Committee. 20.7.3(a) Incidents shall be escalated to an authorized committee where the incident falls within the committee’s mandate, requires multi-domain review, involves control failure, affects assurance, requires policy update, or exceeds ordinary officer authority.

20.7.3(b) Committees may include governance, finance, audit, internal controls, risk, legal compliance, data, AI, cybersecurity, research integrity, publication, safeguards, or other Board-approved committees.

20.7.3(c) Committee escalation shall be records-valid and shall include incident summary, severity, affected domains, immediate actions, legal review status, public-safe status, corrective action plan, unresolved decisions, and requested committee action.

20.7.3(d) Committees may recommend, monitor, review, or act within delegated authority, but shall not exceed Board-reserved matters or assume Public Authority, finance, certification, procurement, protocol, or execution authority.

20.7.3(e) The controlling rule shall be that committees support incident governance without becoming substitute authorities beyond their mandate.


20.7.4 Escalation to Board. 20.7.4(a) Incidents shall be escalated to the Board where they are high severity, critical, systemic, legally material, financially material, public-trust material, mission-lock material, governance-material, or Board-reserved.

20.7.4(b) Board escalation shall be required or appropriate for incidents involving prohibited functions, public authority confusion at material scale, finance-regulated-perimeter breach, major privacy breach, major cybersecurity incident, major protected knowledge exposure, sanctions or export-control risk, private inurement, fraud, bribery, retaliation, major public claims failure, material legal separateness breach, major litigation risk, or repeated control failure.

20.7.4(c) Board materials shall preserve legal privilege, confidentiality, public-safe status, privacy, cybersecurity, Public Authority sensitivity, finance sensitivity, employment sensitivity, and protected knowledge safeguards.

20.7.4(d) Board action may include direction, ratification where lawful, correction, withdrawal, reporting, policy amendment, investigation, independent review, resource allocation, relationship restriction, officer action, or strategic redesign.

20.7.4(e) The controlling rule shall be that the Board must see incidents that threaten mission, law, trust, or constitutional boundaries.


20.7.5 Escalation to Legal Counsel Where Required. 20.7.5(a) Incidents shall be escalated to legal counsel where legal review is required by law, contract, policy, legal review trigger, privilege need, regulatory risk, Public Authority risk, finance-regulated-perimeter risk, data breach, cybersecurity incident, sanctions risk, export-control risk, employment risk, IP risk, tax risk, contract risk, litigation risk, or professional-boundary risk.

20.7.5(b) Legal escalation shall occur before admissions of liability, settlement offers, external legal notices, regulatory responses, Public Authority responses, destruction of records, waiver of privilege, material public statements, or legally sensitive corrective actions, unless urgent containment is required and legal review follows promptly.

20.7.5(c) Legal counsel may advise on preservation, privilege, notification duties, breach duties, public-safe communications, contractual notices, insurance notice, regulatory interaction, employment action, dispute strategy, and correction obligations.

20.7.5(d) Legal escalation shall not be used to suppress lawful correction, conceal public harm, avoid affected-person notice, or prevent proper Board reporting.

20.7.5(e) The controlling rule shall be that legal review must protect lawful action and correction, not replace institutional accountability.


20.7.6 Escalation to Public Authority Where Required or Appropriate. 20.7.6(a) Incidents shall be escalated to a Public Authority where required by law, contract, public authority agreement, public authority data terms, breach notification rules, emergency conditions, public safety considerations, grant conditions, court order, regulatory obligation, or other competent authority requirement.

20.7.6(b) Escalation to Public Authority may also be appropriate where Public Authority Data is affected, a Public Authority reference is misused, public warning confusion exists, emergency command confusion exists, public infrastructure risk exists, public health risk exists, regulatory misdescription exists, public finance misdescription exists, or public reliance may affect public decision-making.

20.7.6(c) Public Authority escalation shall be authorized, accurate, timely, privilege-protective, confidentiality-protective, privacy-protective, cybersecurity-protective, public-safe, and records-valid.

20.7.6(d) GCRI Canada shall not use escalation to Public Authority to imply endorsement, adoption, regulatory approval, procurement approval, public finance approval, public warning, emergency command, or sovereign obligation.

20.7.6(e) The controlling rule shall be that Public Authority escalation shall occur where duty or public safety requires, while preserving GCRI Canada’s non-public-authority role.


20.7.7 Escalation to Affected Community, Participant, Partner, Provider, Sponsor, Host, University, GRF, GRA, Protocol Authority, Nexus Entity, National Company, or Project SPV Where Required or Appropriate. 20.7.7(a) Incidents shall be escalated to affected communities, participants, partners, providers, sponsors, hosts, universities, GRF, GRA, Protocol Authority, Nexus entities, National Companies, Project SPVs, or other affected actors where required by law, contract, safeguard protocol, data agreement, public authority term, room rule, grant term, sponsorship term, correction duty, or public trust duty.

20.7.7(b) Escalation may be appropriate where the incident affects shared records, shared data, shared publications, shared technical assets, public claims, Public Authority references, finance-sensitive materials, technical baselines, protected knowledge, community safeguards, participant rights, provider references, sponsor acknowledgments, or downstream dependencies.

20.7.7(c) Escalation shall identify affected scope, known facts, interim controls, required actions, confidentiality limits, public-safe constraints, correction pathway, and response expectations.

20.7.7(d) Escalation shall not transfer liability, authority, control, public authority meaning, finance authority, recognition authority, certification authority, protocol authority, procurement authority, or execution authority unless separate lawful records provide otherwise.

20.7.7(e) The controlling rule shall be that affected actors should be notified where required or appropriate, but notification shall not collapse roles.


20.7.8 Escalation Thresholds by Severity, Data Class, Public Harm, Public Authority Risk, Finance Risk, Cyber Risk, Protected Knowledge Risk, and Public Trust Risk. 20.7.8(a) Escalation thresholds shall be defined by severity, data class, public harm, Public Authority risk, finance risk, cybersecurity risk, protected knowledge risk, community risk, legal risk, records risk, publication risk, operational risk, and public trust risk.

20.7.8(b) High or critical severity incidents shall require escalation to Officers and, where appropriate, committees, legal counsel, Board, Public Authorities, affected communities, or affected actors.

20.7.8(c) Incidents involving restricted data, Public Authority Data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, community-protected data, protected knowledge, controlled technology, or personal information breach shall receive heightened escalation.

20.7.8(d) Incidents involving public authority confusion, public warning confusion, emergency command confusion, finance overclaim, public finance overclaim, certification overclaim, provider preference, sponsor control, procurement implication, or public reliance shall be escalated where material.

20.7.8(e) The controlling rule shall be that escalation thresholds must reflect harm, authority, sensitivity, and reliance, not organizational hierarchy alone.


20.7.9 Escalation Timing, Records, Notices, and Acknowledgments. 20.7.9(a) Escalation timing shall be proportionate to severity, legal deadlines, public harm risk, data exposure, cybersecurity exposure, public authority consequence, finance consequence, protected knowledge consequence, and public trust risk.

20.7.9(b) Critical incidents shall be escalated immediately or as soon as reasonably practicable. High severity incidents shall be escalated promptly. Moderate and low severity incidents shall be escalated according to policy, unless facts change.

20.7.9(c) Escalation records shall identify incident, severity, escalation recipient, time, method, content, attachments, confidentiality class, privilege status, required action, acknowledgment, follow-up, and closeout.

20.7.9(d) Required notices shall be tracked to completion and shall include confirmation where available.

20.7.9(e) The controlling rule shall be that escalation is incomplete until the right recipient has received and acknowledged the right information or a lawful alternative record exists.


20.7.10 Escalation Failure as Governance Incident. 20.7.10(a) Escalation failure shall be treated as a governance incident, compliance incident, records incident, workforce incident, participation incident, cybersecurity incident, privacy incident, or other incident as appropriate.

20.7.10(b) Escalation failure includes failure to report, late reporting, misclassification to avoid escalation, suppression of incident information, retaliation against reporter, failure to notify required persons, failure to preserve records, failure to involve legal counsel where required, or failure to inform the Board where Board reporting is required.

20.7.10(c) Escalation failure shall require root cause review, corrective action, training, access restriction, disciplinary action, contract remedy, policy update, Board reporting, or legal review where appropriate.

20.7.10(d) Escalation failure shall not be cured merely by later discovery where harm, reliance, legal exposure, or public trust consequence occurred.

20.7.10(e) The controlling rule shall be that failure to escalate a material incident is itself a material risk event.


20.8 Incident Management Integration

20.8.1 Incident Management Integrated Across Governance, Records, Research, Publication, Data, AI, Cybersecurity, Public Authority, Finance, Safeguards, Legal, and Participation Domains. 20.8.1(a) Incident management shall be integrated across governance, records, research, publication, data, AI, cybersecurity, Public Authority, finance, safeguards, legal, workforce, participation, fiscal, contract, grant, sponsorship, provider, host, community, protected knowledge, technical asset, and Nexus-interface domains.

20.8.1(b) Integration shall ensure that incidents are not fragmented, under-classified, double-counted without coordination, or closed in one domain while unresolved in another.

20.8.1(c) A single incident may require simultaneous treatment under privacy, cybersecurity, records, legal compliance, public claims, Public Authority boundary, finance-boundary, community safeguards, contract, and governance procedures.

20.8.1(d) Incident integration shall preserve domain-specific obligations, including legal privilege, breach notification, Public Authority notice, community consultation, protected knowledge safeguards, finance-safe language, public-safe notices, and Board reporting.

20.8.1(e) The controlling rule shall be that incidents shall be managed according to their full institutional meaning, not the first label assigned.


20.8.2 Common Incident Intake. 20.8.2(a) GCRI Canada shall maintain common incident intake procedures or interoperable intake pathways for material incidents.

20.8.2(b) Common intake shall capture reporter, date, source, incident description, affected domain, suspected severity, affected persons, affected communities, affected Public Authorities, affected data, affected systems, affected records, affected public materials, affected contracts, affected sponsors or providers, immediate containment needs, and legal review needs.

20.8.2(c) Intake shall allow incidents to be reported by Directors, Officers, staff, contractors, fellows, advisors, contributors, participants, Public Authorities, communities, providers, sponsors, hosts, universities, capital readers, and other affected actors.

20.8.2(d) Intake shall protect good-faith reporters from retaliation and shall include confidential reporting where appropriate.

20.8.2(e) The controlling rule shall be that common intake exists to make institutional risk visible before procedural routing narrows the issue.


20.8.3 Common Severity Classification. 20.8.3(a) GCRI Canada shall maintain common severity classification or interoperable severity criteria for incidents.

20.8.3(b) Severity classification shall consider legal consequence, public-benefit consequence, public trust consequence, public safety, data sensitivity, AI impact, cybersecurity impact, Public Authority implication, finance implication, protected knowledge implication, community harm, operational disruption, recurrence, and downstream reliance.

20.8.3(c) Severity classification shall be updated as facts change and shall not be held artificially low to avoid escalation, notice, correction, public-safe clarification, legal review, or Board reporting.

20.8.3(d) Severity classification shall identify whether immediate Stop-the-Line, legal hold, breach review, public-safe notice, controlled notice, or external notification is required.

20.8.3(e) The controlling rule shall be that severity follows potential consequence, not institutional embarrassment.


20.8.4 Common Triage Discipline. 20.8.4(a) GCRI Canada shall maintain common triage discipline for incidents.

20.8.4(b) Triage shall identify incident type, severity, owner, custodian, required reviewers, affected domains, containment actions, preservation needs, legal review needs, notification needs, correction needs, public-safe status, and escalation path.

20.8.4(c) Triage shall distinguish immediate containment from final determination and shall not require full fact-finding before protective controls are applied.

20.8.4(d) Triage shall include conflict review where the incident involves a person, sponsor, provider, host, Public Authority, donor, funder, officer, Director, or participant who may influence handling.

20.8.4(e) The controlling rule shall be that triage must route the incident to the right authority before informal handling becomes additional risk.


20.8.5 Common Containment and Preservation Discipline. 20.8.5(a) GCRI Canada shall maintain common containment and preservation discipline for incidents.

20.8.5(b) Containment may include access suspension, credential revocation, key rotation, data quarantine, publication hold, dashboard suspension, map suspension, AI-use restriction, model restriction, repository freeze, room suspension, contract hold, public claims hold, public authority reference hold, finance-sensitive material hold, or transfer block.

20.8.5(c) Preservation shall include relevant records, metadata, logs, versions, communications, repository history, prompt records, inference records, access logs, publication versions, data lineage, contract records, Public Authority records, room records, and correction records.

20.8.5(d) Containment and preservation shall be coordinated with legal hold, privilege, privacy, cybersecurity, Public Authority sensitivity, protected knowledge, employment, contract, and public-safe communication obligations.

20.8.5(e) The controlling rule shall be that incident response must stop the harm pathway and preserve the truth pathway.


20.8.6 Common Correction and Remediation Discipline. 20.8.6(a) GCRI Canada shall maintain common correction and remediation discipline for incidents.

20.8.6(b) Correction may include clarification, erratum, correction, reclassification, downgrade, upgrade, suspension, supersession, withdrawal, retraction, retirement, reinstatement, archive, sealing, deletion where lawful and required, public-safe notice, or controlled notice.

20.8.6(c) Remediation may include policy update, training update, access change, contract amendment, control redesign, technical patch, data deletion, AI restriction, vendor remedy, sponsor correction, provider correction, Public Authority clarification, community remedy, legal filing, or Board action.

20.8.6(d) Correction and remediation shall identify downstream dependencies, affected records, affected public materials, affected systems, affected actors, and verification steps.

20.8.6(e) The controlling rule shall be that incident closure requires corrected truth, corrected controls, and corrected reliance.


20.8.7 Common Public-Safe and Controlled Notice Discipline. 20.8.7(a) GCRI Canada shall maintain common public-safe and controlled notice discipline for incidents.

20.8.7(b) Public-safe notices shall be used where public materials, public reliance, public claims, public dashboards, public maps, public reports, public datasets, media statements, or public-safe outputs require correction without over-disclosing sensitive information.

20.8.7(c) Controlled notices shall be used where affected recipients require notice but materials involve confidential, personal, Public Authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, community-protected, protected knowledge, legal, employment, or security-sensitive information.

20.8.7(d) Notices shall identify scope, affected materials, correction state, effective date, replacement status, boundary language where relevant, and contact or challenge path where appropriate.

20.8.7(e) The controlling rule shall be that notice must prevent misunderstanding while avoiding additional harm.


20.8.8 Common Post-Incident Review and Learning Loop. 20.8.8(a) GCRI Canada shall conduct post-incident review and maintain a learning loop for material incidents.

20.8.8(b) Post-incident review shall identify facts, root cause, contributing factors, control failures, detection gaps, escalation performance, legal review performance, communication performance, correction performance, affected records, affected actors, unresolved risk, and recurrence prevention.

20.8.8(c) Lessons learned shall be translated into corrective action plans, policy updates, training updates, control updates, register updates, technical updates, contract updates, public claims updates, and assurance changes.

20.8.8(d) Post-incident review shall be proportionate and shall protect legal privilege, confidentiality, privacy, cybersecurity, Public Authority sensitivity, protected knowledge, and non-retaliation.

20.8.8(e) The controlling rule shall be that an incident is not fully resolved until the institution has learned from it.


20.8.9 Common Incident Register Cross-Reference. 20.8.9(a) Incident registers shall be cross-referenced to ensure complete institutional memory.

20.8.9(b) A material incident shall be linked, where applicable, to the Risk Register, Issue Register, Control Register, Records Incident Register, Correction Register, Publication Register, Data Breach Register, Privacy Register, AI Incident Register, Cybersecurity Incident Register, Public Authority Boundary Register, Finance Legal Boundary Register, Community Safeguards Register, Legal Review Register, Contract Register, Grant Register, Sponsorship Register, Workforce Register, and Board or committee records.

20.8.9(c) Cross-referencing shall identify primary register, secondary registers, owners, custodians, severity, status, corrective actions, notices, and closeout evidence.

20.8.9(d) Cross-referencing shall not expand access beyond lawful classification or privilege limits.

20.8.9(e) The controlling rule shall be that incident records must connect across domains without collapsing confidentiality or custody.


20.8.10 No Incident Shall Be Hidden, Reclassified, or Informally Resolved to Avoid Correction, Reporting, or Accountability. 20.8.10(a) No incident shall be hidden, minimized, misclassified, delayed, fragmented, informally resolved, silently edited, privately settled, or closed to avoid correction, reporting, notice, legal review, Board visibility, Public Authority escalation, affected-person notice, community remedy, sponsor accountability, provider accountability, or institutional responsibility.

20.8.10(b) Reclassification shall be permitted only where facts support reclassification and the reason is recorded.

20.8.10(c) Informal assurances, private apologies, verbal explanations, email exchanges, or chat messages shall not substitute for required incident records, correction records, notices, or Board / committee reporting.

20.8.10(d) Concealment or improper reclassification of an incident shall itself constitute a governance incident, compliance incident, records incident, or conduct incident as appropriate.

20.8.10(e) The controlling rule shall be that incident management protects public trust through correction, not concealment.


20.9 Monitoring, Evaluation, Assurance, Impact, and Renewal Framework

20.9.1 MEAIR as Monitoring, Evaluation, Assurance, Impact, and Renewal Framework. 20.9.1(a) GCRI Canada shall maintain a Monitoring, Evaluation, Assurance, Impact, and Renewal framework, which may be referred to as MEAIR.

20.9.1(b) MEAIR shall provide a structured institutional method for reviewing operations, controls, outputs, programs, publications, technical assets, public authority interfaces, finance boundaries, data practices, AI practices, cybersecurity practices, community safeguards, records, correction, and Nexus interfaces.

20.9.1(c) MEAIR shall connect monitoring, evaluation, assurance, impact review, corrective action, and renewal into a continuous governance loop.

20.9.1(d) MEAIR shall be public-benefit-oriented, evidence-based, limitation-aware, records-valid, correctionable, non-executing, and role-separated.

20.9.1(e) The controlling rule shall be that institutional learning must be structured, evidenced, and translated into renewal.


20.9.2 Monitoring as Ongoing Review of Operations, Controls, Outputs, and Interfaces. 20.9.2(a) Monitoring means ongoing or periodic review of operations, controls, outputs, systems, repositories, rooms, public materials, public claims, data flows, AI use, cybersecurity, technical releases, Public Authority interfaces, finance-sensitive interfaces, participant conduct, sponsor relationships, provider relationships, community safeguards, and Nexus interfaces.

20.9.2(b) Monitoring shall detect exceptions, anomalies, stale records, missing reviews, unauthorized access, boundary drift, unsupported claims, failed controls, repeated issues, incidents, overdue corrective actions, and emerging risks.

20.9.2(c) Monitoring may be manual, automated, sampled, continuous, event-triggered, register-based, dashboard-based, repository-based, audit-based, or assurance-based.

20.9.2(d) Monitoring shall produce records, alerts, issues, incidents, corrective actions, or assurance findings where appropriate.

20.9.2(e) The controlling rule shall be that monitoring must detect drift before drift becomes institutional practice.


20.9.3 Evaluation as Structured Review of Effectiveness, Fitness, Quality, and Public-Benefit Value. 20.9.3(a) Evaluation means structured review of effectiveness, fitness, quality, usefulness, proportionality, accessibility, public-benefit value, and alignment with mission.

20.9.3(b) Evaluation may apply to programs, research, evidence methods, observability methods, Truth Engine methods, technical baselines, public-good software, Academy materials, public authority learning materials, dashboards, maps, publications, rooms, data governance, AI governance, cybersecurity controls, community safeguards, and Nexus interfaces.

20.9.3(c) Evaluation shall consider whether the activity achieved its stated purpose, remained within role boundaries, protected affected persons and communities, used appropriate evidence, preserved limitations, respected public-safe requirements, and generated learning for improvement.

20.9.3(d) Evaluation shall not be used to inflate impact, market success, finance-readiness, recognition, certification, public authority adoption, provider preference, sponsor value, or procurement relevance beyond the evidence.

20.9.3(e) The controlling rule shall be that evaluation measures institutional fitness and public-benefit value without creating external status by implication.


20.9.4 Assurance as Evidence-Based Confidence That Controls Are Designed and Operating. 20.9.4(a) Assurance means evidence-based confidence that controls are appropriately designed, implemented, operating, documented, effective, reviewed, and corrected where needed.

20.9.4(b) Assurance may review governance controls, records controls, evidence controls, methods controls, research controls, publication controls, data controls, AI controls, cybersecurity controls, Public Authority boundary controls, finance-boundary controls, fiscal controls, sponsor controls, provider controls, community safeguards, legal compliance controls, and Nexus-interface controls.

20.9.4(c) Assurance shall test both control design and control operation and shall not treat written policy alone as proof of control effectiveness.

20.9.4(d) Assurance findings shall be recorded, assigned, corrected, verified, and reported according to risk.

20.9.4(e) The controlling rule shall be that assurance must be based on evidence of control operation, not confidence in intention.


20.9.5 Impact Review as Evidence-Based, Limitation-Aware, Non-Inflated Assessment of Public-Benefit Effects. 20.9.5(a) Impact review means evidence-based, limitation-aware, non-inflated assessment of public-benefit effects.

20.9.5(b) Impact review may consider evidence quality, public-benefit contribution, learning value, technical value, research value, public authority learning value, community safeguard value, publication usefulness, data governance improvement, AI governance improvement, cybersecurity improvement, records improvement, and Nexus interoperability improvement.

20.9.5(c) Impact review shall distinguish outputs, outcomes, contribution, attribution, correlation, causal inference, counterfactual uncertainty, limitations, assumptions, stage truth, and downstream dependency.

20.9.5(d) Impact review shall not claim that GCRI Canada caused public authority decisions, finance outcomes, procurement outcomes, market outcomes, insurance outcomes, recognition outcomes, certification outcomes, or execution outcomes unless proper evidence and authority support the exact statement.

20.9.5(e) The controlling rule shall be that impact claims must be more cautious than impact ambition.


20.9.6 Renewal as Updating of Policies, Methods, Records, Training, Systems, Technical Assets, Committees, Registers, and Public Materials. 20.9.6(a) Renewal means updating policies, procedures, methods, records, training, systems, repositories, technical assets, public-good software, Open Technical Baselines, controlled vocabulary, committees, councils, registers, room rules, contracts, public materials, dashboards, maps, datasets, publications, and public claims in response to monitoring, evaluation, assurance, impact review, incidents, legal changes, technical changes, public authority feedback, community feedback, or Nexus evolution.

20.9.6(b) Renewal may include correction, supersession, withdrawal, retraction, reclassification, redesign, retraining, contract amendment, access change, technical patch, method update, policy update, committee redesign, register update, or public-safe notice.

20.9.6(c) Renewal shall preserve versioning, change logs, authority records, effective dates, transition notes, dependency review, public-safe status, and correction paths.

20.9.6(d) Renewal shall not be used for silent edit, reputation management, sponsor appeasement, provider preference, public authority pressure, finance overclaim, or unrecorded authority expansion.

20.9.6(e) The controlling rule shall be that institutional renewal must be visible, authorized, recorded, and correctionable.


20.9.7 MEAIR as Internal Governance Function, Not Rating, Certification, Public Authority Approval, Finance-Readiness, or External Guarantee by Default. 20.9.7(a) MEAIR shall be an internal governance and public-benefit learning function and shall not constitute rating, certification, recognition, maturity status, public authority approval, regulatory approval, procurement approval, public finance approval, finance-readiness, insurance-readiness, external guarantee, provider endorsement, sponsor validation, or execution authority by default.

20.9.7(b) MEAIR findings may inform GCRI Canada governance, records, correction, public-safe summaries, Board reporting, and controlled learning, but shall not be marketed as external approval or assurance to third parties unless a separate lawful authority and proper records support the exact external use.

20.9.7(c) Where MEAIR summaries are shared externally, they shall include scope, limitations, public-safe status, role boundaries, and no-reliance language where appropriate.

20.9.7(d) MEAIR materials shall not be used by sponsors, providers, hosts, Public Authorities, capital readers, National Companies, Project SPVs, or Nexus actors to claim endorsement, finance-readiness, certification, procurement advantage, public authority adoption, or public approval.

20.9.7(e) The controlling rule shall be that internal confidence is not external status.


20.9.8 MEAIR as Periodic and Event-Triggered. 20.9.8(a) MEAIR shall be periodic and event-triggered.

20.9.8(b) Periodic MEAIR may occur annually, semi-annually, quarterly, monthly, by program cycle, by release cycle, by Board direction, by committee mandate, or by risk-based schedule.

20.9.8(c) Event-triggered MEAIR shall occur where material incidents, legal changes, public authority changes, finance-sensitive changes, major technical releases, major data changes, AI system changes, cybersecurity events, public claims issues, community concerns, protected knowledge concerns, sponsor or provider concerns, or Nexus-interface changes require review.

20.9.8(d) MEAIR schedules shall be recorded, owned, and linked to compliance calendars, risk registers, issue registers, control registers, and Board or committee reporting cycles.

20.9.8(e) The controlling rule shall be that review occurs both by calendar and by consequence.


20.9.9 MEAIR Records, Plans, Findings, Corrective Actions, and Public-Safe Summaries. 20.9.9(a) MEAIR records shall include monitoring plans, evaluation plans, assurance plans, impact review plans, renewal plans, findings, evidence reviewed, limitations, corrective actions, owners, due dates, verification methods, Board or committee reports, and public-safe summaries where appropriate.

20.9.9(b) Findings shall identify whether an issue relates to design weakness, operating failure, evidence weakness, public claims risk, data risk, AI risk, cybersecurity risk, Public Authority risk, finance-boundary risk, protected knowledge risk, legal risk, or public trust risk.

20.9.9(c) Corrective actions shall be assigned, tracked, verified, and linked to relevant registers.

20.9.9(d) Public-safe summaries may be issued where transparency is valuable and may summarize MEAIR activities without exposing legal privilege, confidential information, personal information, Public Authority Data, cybersecurity-sensitive information, finance-sensitive information, commercially sensitive information, community-protected information, or protected knowledge.

20.9.9(e) The controlling rule shall be that MEAIR must produce records and renewal, not merely observation.


20.9.10 MEAIR Assurance and Board / Committee Reporting. 20.9.10(a) GCRI Canada shall conduct MEAIR Assurance and report material MEAIR findings to the Board or authorized committee.

20.9.10(b) MEAIR Assurance shall review whether monitoring, evaluation, assurance, impact review, and renewal processes are planned, risk-based, timely, evidence-supported, corrective, non-inflating, records-valid, and linked to governance action.

20.9.10(c) Board or committee reporting shall include material findings, high-risk gaps, unresolved issues, repeated patterns, corrective action status, impact review limitations, renewal actions, public-safe summary recommendations, and resource needs.

20.9.10(d) MEAIR Assurance shall identify whether institutional learning is occurring or whether the same risks recur without control improvement.

20.9.10(e) The controlling rule shall be that MEAIR itself must be assured because learning systems can become ceremonial without evidence of renewal.


20.10 Monitoring

20.10.1 Monitoring of Governance Operations. 20.10.1(a) GCRI Canada shall monitor governance operations, including Board meetings, committee activity, council activity, Working Group activity, delegations, Board-reserved matters, officer authority, conflicts, recusals, related-party transactions, decision records, governance incidents, and governance corrective actions.

20.10.1(b) Monitoring shall identify defective authority, missing approvals, stale delegations, informal governance, missing conflict disclosures, recusal failures, committee overreach, council overreach, sponsor influence, provider influence, Public Authority confusion, finance overclaim, and records gaps.

20.10.1(c) Governance monitoring shall be linked to the Governance Register, Delegation Register, Conflict Register, Recusal Register, Board records, committee records, council records, Issue Register, Incident Register, and Risk Register.

20.10.1(d) Findings shall be escalated where lawful authority, fiduciary duty, mission lock, legal separateness, non-execution, or public trust may be affected.

20.10.1(e) The controlling rule shall be that governance must be monitored because authority can drift through routine practice.


20.10.2 Monitoring of Evidence, Methods, Observatory, and Truth Engine Operations. 20.10.2(a) GCRI Canada shall monitor evidence, methods, Observatory, and Truth Engine operations for source lineage, metadata completeness, review status, version currency, limitation statements, confidence levels, uncertainty, method integrity, controlled vocabulary use, public-safe status, and correction paths.

20.10.2(b) Monitoring shall identify unsupported evidence, stale evidence, source gaps, method drift, benchmark misuse, ontology drift, translation drift, AI-generated false citation, hallucinated source, missing review, dependency failure, and use beyond authority.

20.10.2(c) Monitoring shall apply to evidence packs, method records, ontology records, controlled vocabulary records, Observatory outputs, Truth Engine outputs, dashboards, maps, datasets, software outputs, technical baselines, and public-safe summaries.

20.10.2(d) Findings shall trigger correction, reclassification, method review, publication review, technical review, public-safe review, or Stop-the-Line where required.

20.10.2(e) The controlling rule shall be that evidence and methods must be monitored because technical truth can degrade through time, reuse, and context shift.


20.10.3 Monitoring of Research, Publications, Public Claims, Dashboards, Maps, and Communications. 20.10.3(a) GCRI Canada shall monitor research, publications, public claims, dashboards, maps, datasets, software releases, APIs, schemas, Academy materials, public authority learning materials, media statements, websites, social media, public-safe outputs, and controlled annexes.

20.10.3(b) Monitoring shall identify unsupported claims, stale materials, public authority overclaim, finance overclaim, certification overclaim, recognition overclaim, provider preference, sponsor validation, procurement implication, public warning implication, emergency command implication, defamation risk, privacy risk, IP risk, protected knowledge exposure, sensitive-location exposure, and misleading visualization.

20.10.3(c) Monitoring shall include post-publication review where reliance risk exists, including monitoring for third-party misuse, media misquotation, sponsor amplification, provider amplification, public authority misdescription, finance-sensitive misuse, and public misunderstanding.

20.10.3(d) Findings shall trigger correction, clarification, erratum, supersession, withdrawal, retraction, public-safe notice, controlled notice, takedown request, public claims correction, or legal review where required.

20.10.3(e) The controlling rule shall be that publication risk continues after publication.


20.10.4 Monitoring of Records, Registers, Gazette, Versioning, and Correction. 20.10.4(a) GCRI Canada shall monitor records, registers, Gazette where applicable, authoritative repositories, versioning, change logs, metadata, authority mapping, retention, legal holds, correction records, supersession chains, withdrawal records, retraction records, and archive records.

20.10.4(b) Monitoring shall identify missing Case IDs, incomplete metadata, ownerless records, stale registers, unauthorized edits, silent edits, missing change logs, missing authority source, uncontrolled documents, broken supersession chains, overdue corrections, unclosed incidents, and public materials inconsistent with current records.

20.10.4(c) Monitoring shall ensure that official registers are reconciled, repositories are authoritative, Gazette notices are accurate where used, and public-safe materials reflect current correction status.

20.10.4(d) Findings shall trigger record correction, register update, repository remediation, Gazette correction, public-safe notice, controlled notice, legal hold review, or assurance follow-up.

20.10.4(e) The controlling rule shall be that records must be monitored because institutional validity depends on current and correct records.


20.10.5 Monitoring of Data, AI, Cybersecurity, Technical Assets, Repositories, Controlled Rooms, and Secure Releases. 20.10.5(a) GCRI Canada shall monitor data, AI, cybersecurity, technical assets, repositories, controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, capital-reader rooms, no-download rooms, secure releases, software, APIs, schemas, dashboards, maps, datasets, models, compute environments, keys, tokens, secrets, and system access.

20.10.5(b) Monitoring shall identify unauthorized data access, stale access, excessive permissions, missing classification, unauthorized AI use, sensitive data in unauthorized AI systems, hallucination reliance, model drift, prompt leakage, embedding leakage, cybersecurity alerts, secrets exposure, repository compromise, insecure dependency, SBOM gaps, vulnerability backlog, insecure release, room misuse, and unauthorized downloads.

20.10.5(c) Monitoring shall be proportionate to data sensitivity, system criticality, Public Authority Data, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive materials, protected knowledge, and public trust risk.

20.10.5(d) Findings shall trigger access revocation, key rotation, data quarantine, model restriction, repository freeze, patching, incident response, breach assessment, public-safe release hold, or legal review where required.

20.10.5(e) The controlling rule shall be that technical monitoring is governance monitoring because systems carry institutional authority.


20.10.6 Monitoring of Public Authority Interfaces, Capacity Classifications, and Public Warning Boundaries. 20.10.6(a) GCRI Canada shall monitor Public Authority interfaces, capacity classifications, reference approvals, Public Authority Data terms, public authority rooms, public authority learning materials, dashboards, maps, public authority communications, public warning boundaries, emergency command boundaries, regulatory boundaries, procurement boundaries, funding boundaries, and public finance boundaries.

20.10.6(b) Monitoring shall identify missing capacity classification, unauthorized Public Authority reference, stale Public Authority approval, public authority overclaim, endorsement implication, adoption implication, regulatory implication, procurement implication, funding implication, public finance implication, public warning implication, emergency command implication, and sovereign obligation implication.

20.10.6(c) Monitoring shall apply to names, logos, titles, quotes, photographs, agency names, jurisdictions, attendance references, data contribution references, public authority learning materials, media statements, reports, dashboards, maps, and public-safe summaries.

20.10.6(d) Findings shall trigger reference correction, Public Authority clarification, public-safe notice, controlled notice, room redesign, access restriction, legal review, public claims correction, or Stop-the-Line where required.

20.10.6(e) The controlling rule shall be that Public Authority meaning must be monitored because public power can be inferred from repeated reference.


20.10.7 Monitoring of Finance Boundaries, GRA Interfaces, Capital-Reader Rooms, Sponsorship, Grants, Donations, and Procurement Neutrality. 20.10.7(a) GCRI Canada shall monitor finance boundaries, GRA interfaces, Proof Pack inputs, diligence gap maps, capital-reader rooms, RNFD / NFD / UNFSD materials, public finance reader participation, insurance-readiness references, sponsorships, grants, donations, restricted funds, in-kind contributions, procurement neutrality, related-party transactions, and anti-inurement controls.

20.10.7(b) Monitoring shall identify finance-readiness overclaim, investment advice implication, securities solicitation implication, brokerage implication, lending implication, insurance approval implication, rating implication, guarantee implication, public finance approval implication, capital commitment implication, token or payment implication, sponsor control, donor control, grantor control, provider preference, procurement steering, private benefit, and restricted fund misuse.

20.10.7(c) Monitoring shall apply to public materials, room materials, funder materials, sponsor materials, provider materials, grant reports, donor communications, public authority finance materials, capital-reader communications, and Nexus-interface materials.

20.10.7(d) Findings shall trigger GRA routing, finance-safe language correction, access restriction, room redesign, public-safe notice, controlled notice, legal review, fiscal correction, fund correction, public claims correction, or Board reporting.

20.10.7(e) The controlling rule shall be that finance meaning must be monitored because financial reliance can arise from audience, context, and repetition before formal transaction activity.


20.10.8 Monitoring of Participant Conduct, Conflicts, Access, and Public Claims. 20.10.8(a) GCRI Canada shall monitor participant conduct, conflicts, independence, access rights, confidentiality, data use, AI use, cybersecurity obligations, IP obligations, public claims, sponsor interactions, provider interactions, Public Authority interactions, finance-sensitive interactions, room behavior, and closeout obligations.

20.10.8(b) Monitoring shall identify conflict non-disclosure, recusal failure, unauthorized access, unauthorized data use, unauthorized AI use, confidentiality breach, cybersecurity weakness, public claims overreach, use of GCRI Canada name or materials without approval, sponsor influence, provider influence, procurement overclaim, finance overclaim, and Public Authority overclaim.

20.10.8(c) Monitoring shall apply to employees, contractors, fellows, advisors, volunteers, members where applicable, council participants, Working Group participants, contributors, maintainers, sponsors, donors, providers, hosts, universities, communities, Public Authorities, capital readers, National Companies, Project SPVs, and Nexus participants.

20.10.8(d) Findings shall trigger reminder, training, access restriction, conflict review, public claims correction, participant discipline, contract remedy, suspension, termination, or legal review where appropriate.

20.10.8(e) The controlling rule shall be that participant conduct must be monitored because people carry institutional authority into public and controlled spaces.


20.10.9 Monitoring of Community Safeguards and Protected Knowledge Controls. 20.10.9(a) GCRI Canada shall monitor community safeguards and protected knowledge controls.

20.10.9(b) Monitoring shall identify extraction risk, consent or non-consent failure where applicable, community misdescription, protected knowledge exposure, unsafe mapping, sensitive-location exposure, re-identification risk, group harm, cultural harm, ecological harm, vulnerable participant risk, whistleblower exposure, protected person exposure, and grievance pathway failure.

20.10.9(c) Monitoring shall apply to research, fieldwork, workshops, public authority learning, dashboards, maps, datasets, reports, media materials, AI outputs, repositories, public-safe summaries, Academy materials, and public claims involving communities or protected knowledge.

20.10.9(d) Findings shall trigger community consultation where appropriate, protected knowledge review, redaction, aggregation, access restriction, withdrawal, retraction, public-safe notice, controlled notice, grievance remedy, legal review, or Board / committee reporting where material.

20.10.9(e) The controlling rule shall be that community safeguards must be monitored because harm can arise after collection, through reuse, publication, visualization, or interpretation.


20.10.10 Monitoring Records, Exceptions, Alerts, and Escalations. 20.10.10(a) Monitoring records shall be maintained for material monitoring activities, exceptions, alerts, findings, escalations, corrective actions, and closeout.

20.10.10(b) Monitoring records shall identify monitoring activity, owner, custodian, date, scope, method, systems reviewed, records reviewed, exceptions found, severity, affected domains, affected records, affected persons, affected communities, affected Public Authorities, affected public materials, interim controls, issue registration, incident registration, escalation, corrective action, verification, and closeout.

20.10.10(c) Alerts shall be triaged according to severity and shall not be ignored, suppressed, or closed without review where they involve material risk.

20.10.10(d) Monitoring exceptions shall be linked to the Risk Register, Issue Register, Control Register, Incident Register, and applicable domain registers.

20.10.10(e) The controlling rule shall be that monitoring creates institutional duty to review, escalate, correct, and learn where signals show risk.

20.11 Evaluation

20.11.1 Evaluation of Mission Alignment. 20.11.1(a) GCRI Canada shall evaluate mission alignment across its governance, programs, research, evidence work, methods work, public-good software, Open Technical Baselines, data activities, AI activities, cybersecurity posture, publications, public authority learning, sponsorships, grants, participant relationships, community interfaces, and Nexus interfaces.

20.11.1(b) Evaluation of mission alignment shall determine whether an activity remains consistent with GCRI Canada’s Canadian public-benefit, nonprofit, non-share, non-distributing, non-executing, evidence-and-methods, observability, ontology, public-good R&D, public-good software, technical baseline, validity-by-record, correctionability, public-safe publication, and legal-separateness mandate.

20.11.1(c) Evaluation shall identify whether an activity has drifted toward consultancy, execution, provider preference, sponsor control, public authority substitution, finance-readiness activity, certification, procurement steering, market operation, public warning, emergency command, data brokerage, technical asset enclosure, or status-confusing Nexus role collapse.

20.11.1(d) Mission alignment evaluation shall consider purpose, authority, funding source, participants, outputs, public claims, data use, technical assets, downstream reliance, Public Authority proximity, finance sensitivity, community impact, and public trust consequence.

20.11.1(e) The controlling rule shall be that mission alignment must be evaluated by substance, not by label.


20.11.2 Evaluation of Public-Benefit Effectiveness. 20.11.2(a) GCRI Canada shall evaluate the public-benefit effectiveness of its activities.

20.11.2(b) Public-benefit effectiveness means the extent to which an activity advances lawful public-good evidence, methods, observability, ontology, technical truth, learning, transparency with protection, public-safe publication, institutional capacity, community safeguards, data rights, cybersecurity, correctionability, and Nexus-compatible public-good infrastructure.

20.11.2(c) Evaluation shall consider whether the activity addresses a real public-benefit need, is accessible to intended users where appropriate, avoids unnecessary complexity, preserves limitations, avoids extraction, supports correction, and improves institutional or public understanding without creating public authority, finance, certification, procurement, or provider-status overclaim.

20.11.2(d) Public-benefit effectiveness shall not be measured by publicity, capital interest, sponsor satisfaction, provider uptake, public authority attendance, media amplification, number of dashboards, number of publications, or technical sophistication alone.

20.11.2(e) The controlling rule shall be that public-benefit effectiveness is measured by useful, lawful, bounded, evidence-based contribution to public trust and public-good capacity.


20.11.3 Evaluation of Evidence Quality. 20.11.3(a) GCRI Canada shall evaluate evidence quality in material evidence records, evidence packs, publications, dashboards, maps, datasets, public-safe summaries, technical notes, research outputs, public authority learning materials, GRA inputs, GRF inputs, Protocol Authority inputs, and Nexus-interface materials.

20.11.3(b) Evidence quality evaluation shall consider source lineage, provenance, reliability, completeness, timeliness, representativeness, bias, uncertainty, confidence, limitations, review status, classification, access class, public-safe status, and correction path.

20.11.3(c) Evaluation shall identify unsupported evidence, stale evidence, overbroad evidence, misclassified evidence, misleading aggregation, missing source records, false citation, AI hallucination, public authority misdescription, sponsor influence, provider influence, and use beyond source authority.

20.11.3(d) Evidence quality findings shall trigger correction, reclassification, limitation update, review update, publication correction, dashboard correction, map correction, dataset correction, controlled notice, public-safe notice, or withdrawal where required.

20.11.3(e) The controlling rule shall be that evidence quality must be evaluated before evidence is reused, relied upon, or publicly communicated.


20.11.4 Evaluation of Method Fitness. 20.11.4(a) GCRI Canada shall evaluate method fitness for methods, protocols, ontology, controlled vocabulary, benchmarks, evaluation harnesses, Observatory Methods, Truth Engine Methods, technical baselines, public-good software, reference architectures, schemas, APIs, dashboards, maps, and public-safe analytical outputs.

20.11.4(b) Method fitness evaluation shall consider purpose fit, scope, assumptions, limitations, reproducibility where appropriate and lawful, review status, data requirements, technical dependencies, bias, failure modes, security implications, public-safe suitability, localization needs, translation risk, and correction path.

20.11.4(c) Evaluation shall identify method drift, uncontrolled adaptation, terminology drift, unsuitable benchmark use, hidden dependency, weak reproducibility, AI-generated method error, software defect, ontology inconsistency, public authority overmeaning, finance overmeaning, or public claims inflation.

20.11.4(d) Method fitness shall be evaluated when methods are created, materially changed, reused in a new context, localized to a new jurisdiction, connected to public authority learning, connected to finance-sensitive materials, or released publicly.

20.11.4(e) The controlling rule shall be that a method is fit only for its recorded purpose, scope, assumptions, and review status.


20.11.5 Evaluation of Research Integrity. 20.11.5(a) GCRI Canada shall evaluate research integrity in research design, evidence gathering, data use, participant engagement, human-subjects review, community review, Indigenous and protected knowledge protocols, analysis, peer review, publication, authorship, conflict management, AI use, and correction.

20.11.5(b) Research integrity evaluation shall consider ethics approval, consent or authority where applicable, participant protection, data minimization, research independence, sponsor and provider roles, conflicts, reviewer independence, reproducibility, limitation disclosure, publication controls, and correction history.

20.11.5(c) Evaluation shall identify fabrication, falsification, plagiarism, source misrepresentation, undisclosed conflict, sponsor influence, provider influence, data selection capture, publication suppression, AI false citation, unsupported conclusion, protected knowledge misuse, community extraction, or failure to correct.

20.11.5(d) Research integrity findings shall trigger ethics review, legal review, data remediation, publication correction, withdrawal, retraction, participant notice, community consultation, Public Authority notice, training, discipline, or Board / committee reporting where appropriate.

20.11.5(e) The controlling rule shall be that research integrity must protect truth, participants, communities, and public trust together.


20.11.6 Evaluation of Publication Quality and Public-Safe Communication. 20.11.6(a) GCRI Canada shall evaluate publication quality and public-safe communication for publications, reports, whitepapers, technical notes, dashboards, maps, datasets, software releases, API releases, schema releases, Academy materials, public authority learning materials, media statements, websites, social media, public-safe summaries, and controlled annexes.

20.11.6(b) Evaluation shall consider accuracy, claims substantiation, readability, accessibility, controlled vocabulary, boundary language, public-safe status, legal review status, evidence support, limitation disclosure, uncertainty, conflicts, sponsor and provider roles, AI use, Public Authority references, finance references, correction path, and public reliance risk.

20.11.6(c) Evaluation shall identify unsupported claims, stale claims, misleading visuals, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, provider preference, sponsor validation, public warning confusion, emergency command confusion, sensitive-location exposure, protected knowledge exposure, privacy risk, cybersecurity risk, and public harm risk.

20.11.6(d) Evaluation shall occur before release where risk exists and after release where public reliance, third-party reuse, media coverage, public authority use, or finance-sensitive reading may change meaning.

20.11.6(e) The controlling rule shall be that publication quality includes both factual accuracy and safe public meaning.


20.11.7 Evaluation of Data Governance, AI Governance, Cybersecurity, and Technical Asset Stewardship. 20.11.7(a) GCRI Canada shall evaluate data governance, AI governance, cybersecurity, and technical asset stewardship.

20.11.7(b) Data governance evaluation shall consider lawful basis, purpose limitation, minimization, classification, access, retention, deletion, cross-border transfer, sovereign data, Public Authority Data, rights-bearing data, community-protected data, protected knowledge, breach readiness, and public-safe release.

20.11.7(c) AI governance evaluation shall consider model register completeness, data authority, AI-use approvals, training and embedding limits, retrieval controls, inference records, human review, bias review, safety review, vendor terms, hallucination controls, and AI incident handling.

20.11.7(d) Cybersecurity and technical asset evaluation shall consider system classification, access controls, secrets management, repository security, secure development, secure release, SBOM status, vulnerability management, incident response, business continuity, dashboard security, API security, and technical baseline integrity.

20.11.7(e) Findings shall trigger control updates, access changes, data remediation, AI restrictions, security remediation, release correction, vendor review, training, legal review, or Board / committee reporting where required.

20.11.7(f) The controlling rule shall be that technical stewardship must be evaluated as legal, ethical, operational, and public-trust stewardship.


20.11.8 Evaluation of Public Authority Learning and Boundary Controls. 20.11.8(a) GCRI Canada shall evaluate public authority learning and boundary controls.

20.11.8(b) Evaluation shall consider whether public authority learning materials, rooms, dashboards, maps, simulations, scenario exercises, tabletop materials, technical outputs, public authority references, and public authority data uses remain educational, decision-supporting, public-safe, non-executing, and non-substitutive.

20.11.8(c) Evaluation shall identify whether Public Authority attendance, data contribution, access, quotes, names, logos, titles, agency names, jurisdiction references, or participation could be misunderstood as endorsement, adoption, procurement approval, regulatory approval, funding approval, public finance approval, public warning, emergency command, official guidance, or sovereign obligation.

20.11.8(d) Evaluation shall review capacity classifications, reference approvals, Public Authority Data terms, room rules, boundary language, publication controls, and correction history.

20.11.8(e) The controlling rule shall be that public authority learning must remain learning, not disguised public authority action.


20.11.9 Evaluation of Finance-Boundary Discipline and Fiscal Integrity. 20.11.9(a) GCRI Canada shall evaluate finance-boundary discipline and fiscal integrity.

20.11.9(b) Finance-boundary evaluation shall consider GRA interfaces, Proof Pack inputs, capital-reader rooms, RNFD / NFD / UNFSD support, public finance reader participation, insurance-readiness references, finance-sensitive materials, token / blockchain / DLT / DePIN references, proof receipts, sponsor materials, provider materials, and public claims.

20.11.9(c) Fiscal integrity evaluation shall consider budgets, restricted funds, donations, grants, sponsorships, in-kind contributions, cost recovery, procurement, related-party transactions, compensation, reimbursements, anti-inurement, private benefit, sanctions screening, export-control screening, and financial controls.

20.11.9(d) Evaluation shall identify finance-readiness overclaim, investment-advice implication, solicitation implication, lending implication, insurance approval implication, rating implication, guarantee implication, public finance implication, sponsor control, provider preference, restricted fund breach, private benefit, and fiscal control weakness.

20.11.9(e) The controlling rule shall be that financial support and finance-facing evidence must be evaluated to preserve public-benefit independence and regulated-perimeter discipline.


20.11.10 Evaluation of Community Safeguards, Accessibility, Inclusion, and Do-No-Harm. 20.11.10(a) GCRI Canada shall evaluate community safeguards, accessibility, inclusion, and do-no-harm.

20.11.10(b) Evaluation shall consider whether programs, research, publications, dashboards, maps, datasets, public authority learning, Academy materials, rooms, public claims, and Nexus interfaces protect vulnerable communities, remote communities, Indigenous knowledge holders, local knowledge holders, protected persons, confidential sources, youth, public officials in sensitive roles, and communities affected by risk evidence.

20.11.10(c) Evaluation shall review accessibility, language access, plain-language summaries, community context, consent or non-consent handling where applicable, grievance pathways, non-retaliation, protected knowledge controls, public-safe mapping, re-identification risk, group harm, cultural harm, ecological harm, and remedy pathways.

20.11.10(d) Evaluation shall identify where institutional outputs are technically accurate but socially unsafe, inaccessible, stigmatizing, extractive, misleading, or harmful through context loss.

20.11.10(e) The controlling rule shall be that public-good work must be evaluated for harm to affected communities, not only for benefit to institutional audiences.


20.11.11 Evaluation of Nexus Interface Effectiveness Without Legal Fusion. 20.11.11(a) GCRI Canada shall evaluate Nexus interface effectiveness without legal fusion.

20.11.11(b) Evaluation shall consider whether interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards / Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Risk Management, Regional Nexus Consortiums, National Nexus Consortiums, National Companies, Project SPVs, providers, sponsors, hosts, Public Authorities, universities, and communities are effective, lawful, role-separated, records-valid, and correctionable.

20.11.11(c) Evaluation shall identify whether shared records, shared rooms, shared events, shared methods, shared doctrine, shared ontology, shared public communications, shared technical assets, or shared participants create merger, agency, partnership, shared treasury, shared liability, shared employer, authority transfer, public authority confusion, finance-readiness drift, certification drift, protocol-authority confusion, or execution drift.

20.11.11(d) Evaluation shall review interface records, divergence logs, equivalence notes, shared-record boundaries, public claims, legal-separateness language, data interfaces, IP interfaces, and correction coordination.

20.11.11(e) The controlling rule shall be that Nexus interfaces are effective only when they increase interoperability without collapsing institutional roles.


20.11.12 Evaluation Records, Findings, Recommendations, and Renewal Actions. 20.11.12(a) Evaluation records shall be maintained for material evaluations.

20.11.12(b) Evaluation records shall identify evaluation purpose, scope, owner, custodian, method, evidence reviewed, participants, limitations, findings, recommendations, affected records, affected systems, affected public materials, affected communities, affected Public Authorities, affected finance-sensitive materials, corrective actions, renewal actions, due dates, approvals, and closeout.

20.11.12(c) Findings shall distinguish observation, weakness, issue, incident, control failure, public claims risk, legal risk, data risk, AI risk, cybersecurity risk, Public Authority risk, finance-boundary risk, protected knowledge risk, and public trust risk.

20.11.12(d) Recommendations shall be assigned, tracked, verified, linked to relevant registers, and escalated where material.

20.11.12(e) The controlling rule shall be that evaluation must result in recorded learning and renewal, not merely descriptive review.


20.12 Assurance

20.12.1 Assurance as Evidence-Based Review of Control Design and Operating Effectiveness. 20.12.1(a) Assurance shall mean evidence-based review of whether controls are properly designed, implemented, operating, documented, reviewed, corrected, and effective for their intended risk.

20.12.1(b) Assurance shall test both control design and operating effectiveness. A policy, procedure, framework, register, or commitment shall not be treated as an effective control unless evidence shows it is used, maintained, reviewed, and corrected.

20.12.1(c) Assurance may be periodic, event-triggered, risk-based, sample-based, system-based, register-based, repository-based, publication-based, room-based, or Board-directed.

20.12.1(d) Assurance shall produce findings, corrective actions, owners, deadlines, verification methods, escalation decisions, and Board or committee reporting where appropriate.

20.12.1(e) The controlling rule shall be that assurance converts control claims into evidence-backed confidence.


20.12.2 Governance Assurance. 20.12.2(a) Governance Assurance shall review Board authority, officer authority, committee mandates, council boundaries, delegations, Board-reserved matters, conflicts, recusals, related-party transactions, decision packs, meeting records, legal separateness, mission lock, and governance training.

20.12.2(b) Assurance shall identify informal governance, missing records, defective authority, stale delegations, committee overreach, council overreach, officer overreach, sponsor control, provider control, public authority confusion, finance overclaim, and mission drift.

20.12.2(c) Assurance shall review whether governance decisions are properly recorded, scoped, authorized, conflict-managed, and correctionable.

20.12.2(d) Findings may require Board action, governance correction, delegation update, committee charter update, recusal correction, training, legal review, or public-safe clarification.

20.12.2(e) The controlling rule shall be that governance assurance protects the lawful source of all institutional authority.


20.12.3 Evidence Rail Assurance. 20.12.3(a) Evidence Rail Assurance shall review evidence intake, Case IDs, metadata, source lineage, authority mapping, evidence classification, review status, limitations, versioning, public-safe status, use restrictions, and correction path.

20.12.3(b) Assurance shall test whether evidence records are complete, traceable, current, properly classified, supported, reviewed, and used within authority.

20.12.3(c) Assurance shall identify unsupported evidence, stale evidence, missing source lineage, missing metadata, AI-fabricated evidence, public authority misdescription, finance-sensitive misuse, and public claims inflation.

20.12.3(d) Findings may require evidence correction, reclassification, source update, limitation update, downstream dependency review, public-safe notice, controlled notice, or withdrawal from active use.

20.12.3(e) The controlling rule shall be that evidence rail assurance protects the validity of the institutional truth function.


20.12.4 Methods Assurance. 20.12.4(a) Methods Assurance shall review methods, protocols, ontology, controlled vocabulary, evaluation harnesses, benchmarks, technical baselines, software methods, analytical workflows, Observatory Methods, Truth Engine Methods, and public-safe transformation methods.

20.12.4(b) Assurance shall test whether methods are documented, versioned, reviewed, purpose-fit, limitation-aware, reproducible where appropriate and lawful, secure where technical, and correctionable.

20.12.4(c) Assurance shall identify method drift, uncontrolled localization, weak assumptions, benchmark misuse, translation drift, hidden dependencies, model drift, software defects, controlled vocabulary inconsistency, and use outside approved scope.

20.12.4(d) Findings may require method update, controlled vocabulary update, technical review, peer review, benchmark revision, software patch, public-safe limitation update, or supersession.

20.12.4(e) The controlling rule shall be that methods assurance protects the meaning of evidence before evidence becomes output.


20.12.5 Observatory and Truth Engine Assurance. 20.12.5(a) Observatory and Truth Engine Assurance shall review observability methods, data sources, sensing inputs, dashboards, maps, signals, indicators, models, AI-assisted workflows, confidence statements, uncertainty notes, source lineage, public-safe status, and correction paths.