risk-nexus/docs/regulatory
tegwick 56b8d61583 Work the register due list, and add the one-check-per-sitting rule
Nine records checked. Five clean and climbed to 1h: RISK-F-0003, 0004,
0005, 0006, 0009 and RISK-REG-0001. Three moved and stay at instant —
RISK-F-0002 (RISK-V-0001 found the flex-auth-ops-warden policy admits no
ingress, so the live question there is now availability rather than
attestation), RISK-F-0007 (the on-request path walked for the first time
as RISK-V-0002), RISK-F-0008 (the determination now exists).

The rule: a finding recorded as moved is not clean-checked in the same
sitting. Re-reading your own keystrokes and climbing produces a rung that
says the world held still when what held still was the last five minutes.
The rung carries stability information or it carries nothing.

record_check.py now handles regulatory records as well as findings.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 12:03:12 +02:00
..
audit-retention-basis.md Work the register due list, and add the one-check-per-sitting rule 2026-08-20 12:03:12 +02:00
README.md RISK-REG-0001: write down the retention basis, and open regulatory intake 2026-08-20 07:25:42 +02:00

Regulatory intake

Moved here from policy-nexus on 2026-08-17: deciding what an external rule demands of the estate is a judgement about risk, not an act of publishing.

One file per question. Each record states what a source says and when, and what the estate therefore relies on. What the estate must consequently do is the owning repo's decision, not this repo's — INTENT.md.

A record carries sources_read, determined, external_review (usually none, and it must say so rather than implying otherwise), and review_by. A regulatory answer expires; that is why it is dated and reviewed rather than consulted once and discarded, which is the failure that moved this remit here.

These records are not legal advice and this repo cannot make them into any. Where a position is weak, the record says which part and why.

Record Question Finding
audit-retention-basis.md On what basis are audit records retained against an erasure request? RISK-F-0008