T02 applies the dependency rule to this repo's own work: rather than wait on audit-core's co-residency horizon, RISK-REG-0001 now states target periods per category with the reasoning — 12 months for operator and agent security records, 3 years to year-end for counterparty transaction evidence, 8 years for accounting vouchers (shortened by BEG IV, flagged as worth confirming), 10 years for books, 6 for commercial letters, delete for anything with no ground. Targets, not achievements: the estate cannot demonstrate any of them while the real horizon is the maximum across every co-resident on platform-pg, and that gap is stated so the table cannot be read as a compliance claim. T03 writes the intake route from what audit-core did correctly without one: the question as a question, what already depends on it, what becomes expensive if the answer is no, and what you are not asking for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
50 lines
2.5 KiB
Markdown
50 lines
2.5 KiB
Markdown
# Regulatory intake
|
|
|
|
Moved here from `policy-nexus` on 2026-08-17: deciding what an external rule
|
|
demands of the estate is a judgement about risk, not an act of publishing.
|
|
|
|
One file per question. Each record states **what a source says and when**, and
|
|
what the estate therefore relies on. What the estate must consequently *do* is
|
|
the owning repo's decision, not this repo's — `INTENT.md`.
|
|
|
|
A record carries `sources_read`, `determined`, `external_review` (usually
|
|
`none`, and it must say so rather than implying otherwise), and `review_by`.
|
|
A regulatory answer expires; that is why it is dated and reviewed rather than
|
|
consulted once and discarded, which is the failure that moved this remit here.
|
|
|
|
**These records are not legal advice** and this repo cannot make them into any.
|
|
Where a position is weak, the record says which part and why.
|
|
|
|
| Record | Question | Finding |
|
|
| --- | --- | --- |
|
|
| `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` |
|
|
|
|
## Routing a regulatory question here
|
|
|
|
`RISK-WP-0003-T03`. `audit-core` did this correctly on 2026-08-18 without a
|
|
route existing, so the route is theirs written down rather than invented.
|
|
|
|
**Send a message to `risk-nexus`** containing:
|
|
|
|
1. **The question, as a question.** Not what you think the answer is.
|
|
2. **What you have already decided that depends on it.** `audit-core` named
|
|
`R4` as unreachable by design and said the exemption had been *assumed* —
|
|
that sentence is what made the question filable.
|
|
3. **What becomes expensive if the answer is no.** This is the field that sets
|
|
urgency. Their answer — that encrypt-then-hash is not retrofittable onto
|
|
events already accepted — is why the question could not wait.
|
|
4. **What you are not asking for.** They asked for an owner, not a legal
|
|
opinion. That boundary made it answerable.
|
|
|
|
**What you get back:** a dated record in this directory stating what the
|
|
sources say, which ground the estate relies on, where the position is weak, and
|
|
what would change it. Plus a finding, if the answer changes what anyone should
|
|
do.
|
|
|
|
**What you will not get:** legal advice, or a ruling on what your repo must
|
|
therefore do. `INTENT.md` keeps the second with you. A regulatory record states
|
|
the constraint; the response to it is the owning repo's design decision.
|
|
|
|
**If nobody answers**, the wait is typed with a default and a date like every
|
|
other (`docs/method/dependencies.md`). The register will not hold your question
|
|
open indefinitely and call that progress.
|