From 8b204d0411ed42d2f110a98d75ba248484927863 Mon Sep 17 00:00:00 2001 From: tegwick Date: Thu, 20 Aug 2026 07:26:08 +0200 Subject: [PATCH] Point RISK-F-0008 at its determination Co-Authored-By: Claude Opus 5 --- ...008-audit-retention-legal-basis-assumed.md | 32 ++++++++++++++++++- 1 file changed, 31 insertions(+), 1 deletion(-) diff --git a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md index 5b5d65b..09d85ac 100644 --- a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md +++ b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md @@ -30,7 +30,8 @@ escalation_answered: "2026-08-20" escalation_answered_by: the-custodian escalation_act: rule decision: "identity in audit records: opaque subject ids preferred, agent identifiers where possible, operator credentials only where necessary, policy decisions tracked to the responsible party; zone-level privacy guarantees may raise the floor" -outstanding: "the written determination of the retention basis, and the trigger list for buying an external answer" +outstanding: "a defensible retention period per category (waits on audit-core's co-residency horizon), and the trigger list for buying an external answer" +determination: RISK-REG-0001 last_reviewed: "2026-08-19" review_by: "2026-11-17" graded_by: risk-nexus @@ -276,3 +277,32 @@ keep listing it. **Routed to `audit-core` on 2026-08-20**, together with the keyed-commitment question — which remains theirs to judge, because they know their chain. + +## The determination exists — 2026-08-20 + +`docs/regulatory/RISK-REG-0001` (`audit-retention-basis.md`). The estate now +has a written position rather than an assumption, which was this finding's +substance. + +What it says, in short: Art 6(1)(f) with Art 32 for operator and agent audit +records; Art 17(3)(e) for records evidencing a counterparty transaction; +Art 17(3)(b) only where a commercial or tax retention duty independently +applies, and not extended to application logs generally. + +**The weak part is duration, not existence**, and the record says so rather +than sounding confident. A position of the form "we keep audit forever because +it is audit" is the one that fails; a period per category is what holds. The +estate does not have one yet, and the reason is `audit-core`'s own question 2 — +at `P1` the real horizon is the maximum across every co-resident on +`platform-pg`, not the declared value. **That infrastructure fact is the most +likely point of failure in the whole position.** + +The operator's minimisation ruling improves this materially: it shrinks the +category whose retention is hardest to justify, leaving mostly the row where +the ground is strong. A weak argument avoided by holding less data beats a +strong one relied upon. + +The finding stays open. What remains is a retention period per category, which +waits on the co-residency horizon, and the trigger list for buying an external +determination. The record is reviewed every 90 days with this finding, or +immediately on any trigger.