RISK-WP-0003 T02/T03: state the retention periods, and write the intake route
T02 applies the dependency rule to this repo's own work: rather than wait on audit-core's co-residency horizon, RISK-REG-0001 now states target periods per category with the reasoning — 12 months for operator and agent security records, 3 years to year-end for counterparty transaction evidence, 8 years for accounting vouchers (shortened by BEG IV, flagged as worth confirming), 10 years for books, 6 for commercial letters, delete for anything with no ground. Targets, not achievements: the estate cannot demonstrate any of them while the real horizon is the maximum across every co-resident on platform-pg, and that gap is stated so the table cannot be read as a compliance claim. T03 writes the intake route from what audit-core did correctly without one: the question as a question, what already depends on it, what becomes expensive if the answer is no, and what you are not asking for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
d3aefefdc0
commit
aeb56e3711
3 changed files with 90 additions and 1 deletions
|
|
@ -18,3 +18,33 @@ Where a position is weak, the record says which part and why.
|
|||
| Record | Question | Finding |
|
||||
| --- | --- | --- |
|
||||
| `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` |
|
||||
|
||||
## Routing a regulatory question here
|
||||
|
||||
`RISK-WP-0003-T03`. `audit-core` did this correctly on 2026-08-18 without a
|
||||
route existing, so the route is theirs written down rather than invented.
|
||||
|
||||
**Send a message to `risk-nexus`** containing:
|
||||
|
||||
1. **The question, as a question.** Not what you think the answer is.
|
||||
2. **What you have already decided that depends on it.** `audit-core` named
|
||||
`R4` as unreachable by design and said the exemption had been *assumed* —
|
||||
that sentence is what made the question filable.
|
||||
3. **What becomes expensive if the answer is no.** This is the field that sets
|
||||
urgency. Their answer — that encrypt-then-hash is not retrofittable onto
|
||||
events already accepted — is why the question could not wait.
|
||||
4. **What you are not asking for.** They asked for an owner, not a legal
|
||||
opinion. That boundary made it answerable.
|
||||
|
||||
**What you get back:** a dated record in this directory stating what the
|
||||
sources say, which ground the estate relies on, where the position is weak, and
|
||||
what would change it. Plus a finding, if the answer changes what anyone should
|
||||
do.
|
||||
|
||||
**What you will not get:** legal advice, or a ruling on what your repo must
|
||||
therefore do. `INTENT.md` keeps the second with you. A regulatory record states
|
||||
the constraint; the response to it is the owning repo's design decision.
|
||||
|
||||
**If nobody answers**, the wait is typed with a default and a date like every
|
||||
other (`docs/method/dependencies.md`). The register will not hold your question
|
||||
open indefinitely and call that progress.
|
||||
|
|
|
|||
|
|
@ -117,3 +117,62 @@ Reviewed every 90 days with `RISK-F-0008`, or immediately on any trigger.
|
|||
## Reviews
|
||||
|
||||
- **2026-08-20** — clean check: grounds unchanged; still waiting on audit-core's co-residency horizon. Cadence instant → 1h (1 clean in a row); next check 2026-08-20 11:02Z.
|
||||
|
||||
---
|
||||
|
||||
# Amendment — 2026-08-20: retention periods, stated rather than deferred
|
||||
|
||||
`RISK-WP-0003-T02`. The original record named duration as the weakest point in
|
||||
the estate's position and left the period open, pending `audit-core`'s
|
||||
co-residency horizon.
|
||||
|
||||
`docs/method/dependencies.md`, written the same week, says the register never
|
||||
waits to decide. Applying that here: **target periods are stated now**, with
|
||||
what would change them recorded beside them. A position with a period somebody
|
||||
can argue with is stronger than an honest blank.
|
||||
|
||||
## Target periods, per category
|
||||
|
||||
| Category | Target | Ground and reasoning |
|
||||
| --- | --- | --- |
|
||||
| Operator and agent security audit records | **12 months** | Art 6(1)(f) with Art 32. Twelve months covers an annual review cycle and the ordinary lag between an incident happening and being discovered. Longer needs a specific reason, per record class, not a habit. |
|
||||
| Counterparty transaction evidence | **3 years, running to the end of the third calendar year** | Art 17(3)(e), defence of legal claims, tracking the general German limitation period (§195, §199 BGB — three years from the end of the year in which the claim arose). Evidence outliving the claim it could defend has no ground. |
|
||||
| Accounting vouchers (*Buchungsbelege*) | **8 years** | §147 AO / §257 HGB. Shortened from ten years by the Fourth Bureaucracy Relief Act with effect from 2025. **Worth confirming before relied on** — it is recent and this repo has not verified it against the current text. |
|
||||
| Books, inventories, annual accounts | **10 years** | §257 HGB, unchanged by that reform. |
|
||||
| Commercial and business letters | **6 years** | §257 HGB. |
|
||||
| Personal data in audit records falling in none of the above | **delete** | No ground identified means no retention. The operator's minimisation ruling of 2026-08-20 should mean this category is close to empty by construction. |
|
||||
|
||||
## Target is not achieved, and the difference is the finding
|
||||
|
||||
These are **targets**. The estate cannot currently state what it *achieves*,
|
||||
for the reason `audit-core` gave: at `P1` the real erasure horizon is the
|
||||
maximum across every co-resident on `platform-pg`, not the value any one
|
||||
service declares. A service can declare twelve months and be unable to deliver
|
||||
it because a neighbour's backup retention outlives it.
|
||||
|
||||
So the position is:
|
||||
|
||||
1. The estate **states** these targets and can defend the reasoning for each.
|
||||
2. The estate **cannot yet demonstrate** that any of them is achieved.
|
||||
3. The gap between the two is an infrastructure fact, not a legal one, and it
|
||||
is what `RISK-F-0008` carries.
|
||||
|
||||
That is a materially better position than having no period at all, and it is
|
||||
worse than having a verified one. Both halves are stated so nobody reads the
|
||||
table as a compliance claim.
|
||||
|
||||
## What would change this
|
||||
|
||||
- **`audit-core`'s co-residency horizon.** If the real maximum is longer than
|
||||
the targets, the targets are aspirational and the table says so.
|
||||
- **A keyed commitment working** (`RISK-F-0008`). Then erasure becomes
|
||||
available and the retention argument narrows to the retained-by-obligation
|
||||
rows only, which are the strong ones.
|
||||
- **Confirmation of the eight-year voucher period.** Flagged above; the rest of
|
||||
the table does not depend on it.
|
||||
- **Any of the three triggers** for buying an external determination, which
|
||||
remain unruled.
|
||||
|
||||
Default if none of these arrives by 2026-11-17: this table stands as the
|
||||
estate's stated position, with the achieved-versus-target gap recorded as
|
||||
unresolved.
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Make regulatory intake a working remit rather than one record"
|
||||
domain: infotech
|
||||
repo: risk-nexus
|
||||
status: proposed
|
||||
status: active
|
||||
owner: the-custodian
|
||||
topic_slug: risk-nexus
|
||||
created: "2026-08-20"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue