From aeb56e3711657e47011007160b77749afcfa5b15 Mon Sep 17 00:00:00 2001 From: tegwick Date: Thu, 20 Aug 2026 23:16:51 +0200 Subject: [PATCH] RISK-WP-0003 T02/T03: state the retention periods, and write the intake route MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit T02 applies the dependency rule to this repo's own work: rather than wait on audit-core's co-residency horizon, RISK-REG-0001 now states target periods per category with the reasoning — 12 months for operator and agent security records, 3 years to year-end for counterparty transaction evidence, 8 years for accounting vouchers (shortened by BEG IV, flagged as worth confirming), 10 years for books, 6 for commercial letters, delete for anything with no ground. Targets, not achievements: the estate cannot demonstrate any of them while the real horizon is the maximum across every co-resident on platform-pg, and that gap is stated so the table cannot be read as a compliance claim. T03 writes the intake route from what audit-core did correctly without one: the question as a question, what already depends on it, what becomes expensive if the answer is no, and what you are not asking for. Co-Authored-By: Claude Opus 5 --- docs/regulatory/README.md | 30 +++++++++++ docs/regulatory/audit-retention-basis.md | 59 +++++++++++++++++++++ workplans/RISK-WP-0003-regulatory-intake.md | 2 +- 3 files changed, 90 insertions(+), 1 deletion(-) diff --git a/docs/regulatory/README.md b/docs/regulatory/README.md index fb3d8b7..c22ec74 100644 --- a/docs/regulatory/README.md +++ b/docs/regulatory/README.md @@ -18,3 +18,33 @@ Where a position is weak, the record says which part and why. | Record | Question | Finding | | --- | --- | --- | | `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` | + +## Routing a regulatory question here + +`RISK-WP-0003-T03`. `audit-core` did this correctly on 2026-08-18 without a +route existing, so the route is theirs written down rather than invented. + +**Send a message to `risk-nexus`** containing: + +1. **The question, as a question.** Not what you think the answer is. +2. **What you have already decided that depends on it.** `audit-core` named + `R4` as unreachable by design and said the exemption had been *assumed* — + that sentence is what made the question filable. +3. **What becomes expensive if the answer is no.** This is the field that sets + urgency. Their answer — that encrypt-then-hash is not retrofittable onto + events already accepted — is why the question could not wait. +4. **What you are not asking for.** They asked for an owner, not a legal + opinion. That boundary made it answerable. + +**What you get back:** a dated record in this directory stating what the +sources say, which ground the estate relies on, where the position is weak, and +what would change it. Plus a finding, if the answer changes what anyone should +do. + +**What you will not get:** legal advice, or a ruling on what your repo must +therefore do. `INTENT.md` keeps the second with you. A regulatory record states +the constraint; the response to it is the owning repo's design decision. + +**If nobody answers**, the wait is typed with a default and a date like every +other (`docs/method/dependencies.md`). The register will not hold your question +open indefinitely and call that progress. diff --git a/docs/regulatory/audit-retention-basis.md b/docs/regulatory/audit-retention-basis.md index 4183e18..cee7903 100644 --- a/docs/regulatory/audit-retention-basis.md +++ b/docs/regulatory/audit-retention-basis.md @@ -117,3 +117,62 @@ Reviewed every 90 days with `RISK-F-0008`, or immediately on any trigger. ## Reviews - **2026-08-20** — clean check: grounds unchanged; still waiting on audit-core's co-residency horizon. Cadence instant → 1h (1 clean in a row); next check 2026-08-20 11:02Z. + +--- + +# Amendment — 2026-08-20: retention periods, stated rather than deferred + +`RISK-WP-0003-T02`. The original record named duration as the weakest point in +the estate's position and left the period open, pending `audit-core`'s +co-residency horizon. + +`docs/method/dependencies.md`, written the same week, says the register never +waits to decide. Applying that here: **target periods are stated now**, with +what would change them recorded beside them. A position with a period somebody +can argue with is stronger than an honest blank. + +## Target periods, per category + +| Category | Target | Ground and reasoning | +| --- | --- | --- | +| Operator and agent security audit records | **12 months** | Art 6(1)(f) with Art 32. Twelve months covers an annual review cycle and the ordinary lag between an incident happening and being discovered. Longer needs a specific reason, per record class, not a habit. | +| Counterparty transaction evidence | **3 years, running to the end of the third calendar year** | Art 17(3)(e), defence of legal claims, tracking the general German limitation period (§195, §199 BGB — three years from the end of the year in which the claim arose). Evidence outliving the claim it could defend has no ground. | +| Accounting vouchers (*Buchungsbelege*) | **8 years** | §147 AO / §257 HGB. Shortened from ten years by the Fourth Bureaucracy Relief Act with effect from 2025. **Worth confirming before relied on** — it is recent and this repo has not verified it against the current text. | +| Books, inventories, annual accounts | **10 years** | §257 HGB, unchanged by that reform. | +| Commercial and business letters | **6 years** | §257 HGB. | +| Personal data in audit records falling in none of the above | **delete** | No ground identified means no retention. The operator's minimisation ruling of 2026-08-20 should mean this category is close to empty by construction. | + +## Target is not achieved, and the difference is the finding + +These are **targets**. The estate cannot currently state what it *achieves*, +for the reason `audit-core` gave: at `P1` the real erasure horizon is the +maximum across every co-resident on `platform-pg`, not the value any one +service declares. A service can declare twelve months and be unable to deliver +it because a neighbour's backup retention outlives it. + +So the position is: + +1. The estate **states** these targets and can defend the reasoning for each. +2. The estate **cannot yet demonstrate** that any of them is achieved. +3. The gap between the two is an infrastructure fact, not a legal one, and it + is what `RISK-F-0008` carries. + +That is a materially better position than having no period at all, and it is +worse than having a verified one. Both halves are stated so nobody reads the +table as a compliance claim. + +## What would change this + +- **`audit-core`'s co-residency horizon.** If the real maximum is longer than + the targets, the targets are aspirational and the table says so. +- **A keyed commitment working** (`RISK-F-0008`). Then erasure becomes + available and the retention argument narrows to the retained-by-obligation + rows only, which are the strong ones. +- **Confirmation of the eight-year voucher period.** Flagged above; the rest of + the table does not depend on it. +- **Any of the three triggers** for buying an external determination, which + remain unruled. + +Default if none of these arrives by 2026-11-17: this table stands as the +estate's stated position, with the achieved-versus-target gap recorded as +unresolved. diff --git a/workplans/RISK-WP-0003-regulatory-intake.md b/workplans/RISK-WP-0003-regulatory-intake.md index 5acad3e..d191dc9 100644 --- a/workplans/RISK-WP-0003-regulatory-intake.md +++ b/workplans/RISK-WP-0003-regulatory-intake.md @@ -4,7 +4,7 @@ type: workplan title: "Make regulatory intake a working remit rather than one record" domain: infotech repo: risk-nexus -status: proposed +status: active owner: the-custodian topic_slug: risk-nexus created: "2026-08-20"