risk-nexus/docs/regulatory/README.md

51 lines
2.5 KiB
Markdown
Raw Normal View History

# Regulatory intake
Moved here from `policy-nexus` on 2026-08-17: deciding what an external rule
demands of the estate is a judgement about risk, not an act of publishing.
One file per question. Each record states **what a source says and when**, and
what the estate therefore relies on. What the estate must consequently *do* is
the owning repo's decision, not this repo's — `INTENT.md`.
A record carries `sources_read`, `determined`, `external_review` (usually
`none`, and it must say so rather than implying otherwise), and `review_by`.
A regulatory answer expires; that is why it is dated and reviewed rather than
consulted once and discarded, which is the failure that moved this remit here.
**These records are not legal advice** and this repo cannot make them into any.
Where a position is weak, the record says which part and why.
| Record | Question | Finding |
| --- | --- | --- |
| `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` |
## Routing a regulatory question here
`RISK-WP-0003-T03`. `audit-core` did this correctly on 2026-08-18 without a
route existing, so the route is theirs written down rather than invented.
**Send a message to `risk-nexus`** containing:
1. **The question, as a question.** Not what you think the answer is.
2. **What you have already decided that depends on it.** `audit-core` named
`R4` as unreachable by design and said the exemption had been *assumed*
that sentence is what made the question filable.
3. **What becomes expensive if the answer is no.** This is the field that sets
urgency. Their answer — that encrypt-then-hash is not retrofittable onto
events already accepted — is why the question could not wait.
4. **What you are not asking for.** They asked for an owner, not a legal
opinion. That boundary made it answerable.
**What you get back:** a dated record in this directory stating what the
sources say, which ground the estate relies on, where the position is weak, and
what would change it. Plus a finding, if the answer changes what anyone should
do.
**What you will not get:** legal advice, or a ruling on what your repo must
therefore do. `INTENT.md` keeps the second with you. A regulatory record states
the constraint; the response to it is the owning repo's design decision.
**If nobody answers**, the wait is typed with a default and a date like every
other (`docs/method/dependencies.md`). The register will not hold your question
open indefinitely and call that progress.