21 lines
1,016 B
Markdown
21 lines
1,016 B
Markdown
|
|
# Regulatory intake
|
||
|
|
|
||
|
|
Moved here from `policy-nexus` on 2026-08-17: deciding what an external rule
|
||
|
|
demands of the estate is a judgement about risk, not an act of publishing.
|
||
|
|
|
||
|
|
One file per question. Each record states **what a source says and when**, and
|
||
|
|
what the estate therefore relies on. What the estate must consequently *do* is
|
||
|
|
the owning repo's decision, not this repo's — `INTENT.md`.
|
||
|
|
|
||
|
|
A record carries `sources_read`, `determined`, `external_review` (usually
|
||
|
|
`none`, and it must say so rather than implying otherwise), and `review_by`.
|
||
|
|
A regulatory answer expires; that is why it is dated and reviewed rather than
|
||
|
|
consulted once and discarded, which is the failure that moved this remit here.
|
||
|
|
|
||
|
|
**These records are not legal advice** and this repo cannot make them into any.
|
||
|
|
Where a position is weak, the record says which part and why.
|
||
|
|
|
||
|
|
| Record | Question | Finding |
|
||
|
|
| --- | --- | --- |
|
||
|
|
| `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` |
|