risk-nexus/docs/regulatory
tegwick 7a3d97ecfe RISK-REG-0001: write down the retention basis, and open regulatory intake
The outstanding half of RISK-F-0008 that needed no authorisation. Grounds
stated per category rather than as a blanket exemption: Art 6(1)(f) with
Art 32 for operator and agent records, Art 17(3)(e) for counterparty
transaction evidence, Art 17(3)(b) only where a commercial or tax duty
independently applies. The weak part is named as duration rather than
existence, and audit-core's co-residency horizon is identified as the
most likely point of failure in the whole position. Not legal advice, and
the record says so.

Also opens docs/regulatory/ with the record format — dated, sourced, and
reviewed, because a regulatory answer expires.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:25:42 +02:00
..
audit-retention-basis.md RISK-REG-0001: write down the retention basis, and open regulatory intake 2026-08-20 07:25:42 +02:00
README.md RISK-REG-0001: write down the retention basis, and open regulatory intake 2026-08-20 07:25:42 +02:00

Regulatory intake

Moved here from policy-nexus on 2026-08-17: deciding what an external rule demands of the estate is a judgement about risk, not an act of publishing.

One file per question. Each record states what a source says and when, and what the estate therefore relies on. What the estate must consequently do is the owning repo's decision, not this repo's — INTENT.md.

A record carries sources_read, determined, external_review (usually none, and it must say so rather than implying otherwise), and review_by. A regulatory answer expires; that is why it is dated and reviewed rather than consulted once and discarded, which is the failure that moved this remit here.

These records are not legal advice and this repo cannot make them into any. Where a position is weak, the record says which part and why.

Record Question Finding
audit-retention-basis.md On what basis are audit records retained against an erasure request? RISK-F-0008