RISK-F-0008 accepted: no external determination, policy set instead
The triggers survive as what ends the acceptance rather than as what starts a purchase. Accepted is not closed — it keeps its cadence, and audit-core's two questions stay open under it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
7f135f9e0f
commit
674bd41635
2 changed files with 43 additions and 13 deletions
|
|
@ -2,7 +2,7 @@
|
|||
id: RISK-F-0008
|
||||
type: finding
|
||||
title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established"
|
||||
status: open
|
||||
status: accepted
|
||||
reported_by: audit-core
|
||||
reported_via: audit-core
|
||||
routed_by: audit-core
|
||||
|
|
@ -29,17 +29,20 @@ publication_subtitle: "The estate retains personal data in audit records on grou
|
|||
revision: "graded-1"
|
||||
last_reviewed: "2026-08-20"
|
||||
review_interval: 6m
|
||||
escalation: required
|
||||
escalation: answered
|
||||
escalation_trigger: 2
|
||||
escalation_status: partially-answered
|
||||
escalation_status: answered
|
||||
accepted_by: the-custodian
|
||||
accepted_on: "2026-08-20"
|
||||
accepted_until: "the estate holds a real person's data, or a counterparty requires a stated position"
|
||||
escalation_answered: "2026-08-20"
|
||||
escalation_answered_by: the-custodian
|
||||
escalation_act: rule
|
||||
decision: "identity in audit records: opaque subject ids preferred, agent identifiers where possible, operator credentials only where necessary, policy decisions tracked to the responsible party; zone-level privacy guarantees may raise the floor"
|
||||
outstanding: "a defensible retention period per category (waits on audit-core's co-residency horizon), and the trigger list for buying an external answer"
|
||||
determination: RISK-REG-0001
|
||||
last_checked: "2026-08-20T10:02:41Z"
|
||||
next_check: "2026-08-20T10:02:41Z"
|
||||
last_checked: "2026-08-20T21:36:44Z"
|
||||
next_check: "2026-08-20T21:36:44Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
|
|
@ -49,12 +52,6 @@ waiting_on:
|
|||
would_change: "a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only"
|
||||
default: "encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable"
|
||||
default_at: "2026-11-17"
|
||||
- who: the-custodian
|
||||
what: "rule the trigger list for buying an external determination"
|
||||
since: "2026-08-19"
|
||||
would_change: "fixes when the estate stops running on an assumption"
|
||||
default: "the assumption is recorded in the register as an assumption"
|
||||
default_at: "2026-11-17"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-08-19-C
|
||||
---
|
||||
|
|
@ -328,3 +325,37 @@ waits on the co-residency horizon, and the trigger list for buying an external
|
|||
determination. The record is reviewed every 90 days with this finding, or
|
||||
immediately on any trigger.
|
||||
- **2026-08-20** — not clean: The determination now exists: RISK-REG-0001 states the grounds per category and names duration as the weak point. Cadence instant → instant; checked again immediately.
|
||||
|
||||
## Operator decision — 2026-08-20: no external determination, and a policy set instead
|
||||
|
||||
Ruled: **the estate will not buy an external determination while it is
|
||||
building.** The internal determination (`RISK-REG-0001`) stands as the recorded
|
||||
position, and the finding moves to `accepted` — deliberately carried, with a
|
||||
named accepter and a condition that ends it.
|
||||
|
||||
That is not the same as the trigger list being rejected. The triggers survive
|
||||
as what ends the acceptance: a real person's data, or a counterparty requiring
|
||||
a stated position. What was declined is spending money in advance of either.
|
||||
|
||||
**The compensating control is the thing that makes this defensible.** Rather
|
||||
than defer the question, the operator directed that the estate **define and
|
||||
keep a set of legal policies for reuse**, because future work contexts will
|
||||
need specific positions in place and should retrieve them rather than research
|
||||
them.
|
||||
|
||||
`docs/regulatory/policies/` now catalogues thirteen, keyed by activation
|
||||
condition. Two of them turned out to be **already active and unowned**:
|
||||
commercial and tax retention (`RISK-POL-0009`), and the e-invoicing receiving
|
||||
obligation (`RISK-POL-0012`), live since 2025 with no system in the estate
|
||||
named as the receiving point.
|
||||
|
||||
Finding an unnoticed live obligation in the first hour of building the
|
||||
catalogue is the argument for having built it. The reason this repo exists is
|
||||
that regulation was previously "consulted and discarded"; a set that answers
|
||||
"what applies if we do X" before anyone does X is the opposite of that.
|
||||
|
||||
**Still open under the acceptance**, and unchanged by this ruling: `audit-core`
|
||||
on whether a keyed commitment restores erasability, and the `platform-pg`
|
||||
co-residency horizon that decides whether the stated retention periods are
|
||||
achievable. An accepted risk still gets checked.
|
||||
- **2026-08-20** — not clean: Trigger list ruled: no external determination in build mode; accepted with the legal policy set as the compensating control. Cadence instant → instant; checked again immediately.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue