T02 applies the dependency rule to this repo's own work: rather than wait on audit-core's co-residency horizon, RISK-REG-0001 now states target periods per category with the reasoning — 12 months for operator and agent security records, 3 years to year-end for counterparty transaction evidence, 8 years for accounting vouchers (shortened by BEG IV, flagged as worth confirming), 10 years for books, 6 for commercial letters, delete for anything with no ground. Targets, not achievements: the estate cannot demonstrate any of them while the real horizon is the maximum across every co-resident on platform-pg, and that gap is stated so the table cannot be read as a compliance claim. T03 writes the intake route from what audit-core did correctly without one: the question as a question, what already depends on it, what becomes expensive if the answer is no, and what you are not asking for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2.5 KiB
Regulatory intake
Moved here from policy-nexus on 2026-08-17: deciding what an external rule
demands of the estate is a judgement about risk, not an act of publishing.
One file per question. Each record states what a source says and when, and
what the estate therefore relies on. What the estate must consequently do is
the owning repo's decision, not this repo's — INTENT.md.
A record carries sources_read, determined, external_review (usually
none, and it must say so rather than implying otherwise), and review_by.
A regulatory answer expires; that is why it is dated and reviewed rather than
consulted once and discarded, which is the failure that moved this remit here.
These records are not legal advice and this repo cannot make them into any. Where a position is weak, the record says which part and why.
| Record | Question | Finding |
|---|---|---|
audit-retention-basis.md |
On what basis are audit records retained against an erasure request? | RISK-F-0008 |
Routing a regulatory question here
RISK-WP-0003-T03. audit-core did this correctly on 2026-08-18 without a
route existing, so the route is theirs written down rather than invented.
Send a message to risk-nexus containing:
- The question, as a question. Not what you think the answer is.
- What you have already decided that depends on it.
audit-corenamedR4as unreachable by design and said the exemption had been assumed — that sentence is what made the question filable. - What becomes expensive if the answer is no. This is the field that sets urgency. Their answer — that encrypt-then-hash is not retrofittable onto events already accepted — is why the question could not wait.
- What you are not asking for. They asked for an owner, not a legal opinion. That boundary made it answerable.
What you get back: a dated record in this directory stating what the sources say, which ground the estate relies on, where the position is weak, and what would change it. Plus a finding, if the answer changes what anyone should do.
What you will not get: legal advice, or a ruling on what your repo must
therefore do. INTENT.md keeps the second with you. A regulatory record states
the constraint; the response to it is the owning repo's design decision.
If nobody answers, the wait is typed with a default and a date like every
other (docs/method/dependencies.md). The register will not hold your question
open indefinitely and call that progress.