Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
7.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | depends_on_workplans | state_hub_workstream_id | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RISK-WP-0003 | workplan | Make regulatory intake a working remit rather than one record | infotech | risk-nexus | finished | the-custodian | risk-nexus | 2026-08-20 | 2026-08-20 |
|
a86026f4-5dfa-559a-b9ee-e59ff83b3bb5 |
RISK-WP-0003 — regulatory intake
Draft. The half of this repo's remit that RISK-WP-0001 deliberately did
not touch.
Goal
INTENT.md says regulation was previously "consulted and discarded" — the same
question asked twice and the answer silently expiring. RISK-REG-0001 is one
record against that. Make it a remit: a format that expires, a way for repos to
ask, and the open items that record is carrying.
Done means: the retention question is answered as far as it can be without buying advice, the trigger list for buying advice is ruled, and a repo with a regulatory question knows where to put it.
The open items this inherits
From RISK-REG-0001 and RISK-F-0008, both already written down:
- A defensible retention period per category. The determination names this as the weakest point in the estate's whole position: supervisory practice accepts audit logging under legitimate interest and then asks how long, and "we keep audit because it is audit" is the form that fails.
audit-core's co-residency horizon. AtP1the real erasure horizon is the maximum across every co-resident onplatform-pg, not the declared value. An infrastructure fact is doing load-bearing work in a legal position, which is an uncomfortable place for it to be. Blocked onaudit-core.- The trigger list. First real person's data, first counterparty contract requiring a stated position, first Art 17 request. Proposed 2026-08-19, not ruled.
Tasks
T01 — Rule the trigger list
id: RISK-WP-0003-T01
status: done
priority: high
state_hub_task_id: "a2980efd-fc39-5baf-847f-570b17070536"
Custodian decision. Cheap, and it is what stops the estate either buying advice
it does not need or discovering it needed it. Until it is ruled, RISK-F-0008
stays escalated as partially-answered.
Completed 2026-08-20. Ruled: no external determination while building. The three triggers survive, not as what starts a purchase but as what ends the acceptance — RISK-F-0008 moves to accepted with a named accepter and an end condition rather than sitting open on an assumption.
The ruling came with a direction that turned a deferral into an asset: define and keep a set of legal policies for reuse, because work contexts will need specific positions in place and should retrieve them rather than research them. docs/regulatory/policies/ — thirteen entries keyed by activation condition, with a retrieval table so a context pulls a slice.
Two entries turned out to be already active and unowned: commercial and tax retention (RISK-POL-0009) and the e-invoicing receiving obligation (RISK-POL-0012), live since 2025 with no system in the estate named as the receiving point. Finding a live obligation in the first hour of writing the catalogue is the argument for the catalogue.
T02 — Retention periods per category
id: RISK-WP-0003-T02
status: done
priority: high
state_hub_task_id: "69d45a18-0626-592b-8b5b-599ad5fff290"
State a period and a reason per category in RISK-REG-0001, or state plainly
that the estate cannot yet and why. The second is an acceptable outcome and a
better record than a number nobody can defend.
Depends on audit-core answering the co-residency horizon, which has been
asked for. If they cannot, that dependency is itself the answer to record.
Completed 2026-08-20 — and completed by applying this repo's own dependency rule to itself. Rather than wait on audit-core's co-residency horizon, RISK-REG-0001 now states target periods per category with the reasoning: 12 months for operator and agent security records, 3 years to year-end for counterparty transaction evidence, 8 years for accounting vouchers (shortened by the Fourth Bureaucracy Relief Act, flagged as worth confirming), 10 years for books and annual accounts, 6 for commercial letters, and delete for anything with no ground identified.
They are targets, not achievements, and the record says so in its own text: the estate cannot demonstrate any of them while the real erasure horizon is the maximum across every co-resident on platform-pg. The gap between stated and achieved is the thing RISK-F-0008 carries, and it is an infrastructure fact rather than a legal one.
T03 — Intake route for regulatory questions
id: RISK-WP-0003-T03
status: done
priority: medium
state_hub_task_id: "6d2a09fa-cc9a-586c-9b1a-3dd94650e306"
audit-core routed theirs by messaging this repo and asking for an owner,
which worked. Write that down as the route rather than leaving it as one repo's
good instinct: what a regulatory question needs when it arrives, what it gets
back, and what this repo will not answer (legal advice, and what the owning
repo must therefore do).
Extend findings/README.md or give docs/regulatory/README.md the reporter's
half. Do not invent an intake system.
Completed 2026-08-20. docs/regulatory/README.md carries the reporter's half, written from what audit-core did correctly before a route existed: the question as a question, what you have already decided that depends on it, what becomes expensive if the answer is no, and what you are not asking for. Their "we need an owner, not a legal opinion" is what made the question answerable, and it is now the documented shape.
T04 — Expiry
id: RISK-WP-0003-T04
status: done
priority: medium
state_hub_task_id: "8f4a718f-dd5c-5c0c-9750-ee7e322490c3"
Regulatory records expire; that is why the remit moved here. Put them on the
same cadence ladder as findings (docs/method/review.md) rather than inventing
a second review mechanism — a record that has held still for a quarter is
making the same statement a finding at 1q makes.
make check should report a regulatory record due for a check exactly as it
reports a finding.
Closed by reference 2026-08-20. Done under RISK-WP-0004-T06: regulatory records ride the findings cadence ladder rather than getting a second review mechanism. RISK-REG-0001 carries cadence, clean_streak, last_checked and next_check, and make check reports regulatory records due exactly as it reports findings.
Non-goals
- No legal advice.
INTENT.md, and the records say so in their own text. - No survey of every regime that might apply. Regulation is scoped to rules bearing on data the estate holds, markets it sells into, or obligations it has taken on. A general compliance programme is not this.
- No answering what a repo must therefore do. That is the owning repo's.
Risks
The remit becomes a compliance function. Mitigation: records answer questions that were actually asked, by a repo, with a date.
A record states a legal conclusion with false confidence. Mitigation: every
record names where it is weak, and external_review: none is a required field
rather than an omission.