risk-nexus/docs/regulatory/README.md
tegwick 7a3d97ecfe RISK-REG-0001: write down the retention basis, and open regulatory intake
The outstanding half of RISK-F-0008 that needed no authorisation. Grounds
stated per category rather than as a blanket exemption: Art 6(1)(f) with
Art 32 for operator and agent records, Art 17(3)(e) for counterparty
transaction evidence, Art 17(3)(b) only where a commercial or tax duty
independently applies. The weak part is named as duration rather than
existence, and audit-core's co-residency horizon is identified as the
most likely point of failure in the whole position. Not legal advice, and
the record says so.

Also opens docs/regulatory/ with the record format — dated, sourced, and
reviewed, because a regulatory answer expires.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:25:42 +02:00

20 lines
1,016 B
Markdown

# Regulatory intake
Moved here from `policy-nexus` on 2026-08-17: deciding what an external rule
demands of the estate is a judgement about risk, not an act of publishing.
One file per question. Each record states **what a source says and when**, and
what the estate therefore relies on. What the estate must consequently *do* is
the owning repo's decision, not this repo's — `INTENT.md`.
A record carries `sources_read`, `determined`, `external_review` (usually
`none`, and it must say so rather than implying otherwise), and `review_by`.
A regulatory answer expires; that is why it is dated and reviewed rather than
consulted once and discarded, which is the failure that moved this remit here.
**These records are not legal advice** and this repo cannot make them into any.
Where a position is weak, the record says which part and why.
| Record | Question | Finding |
| --- | --- | --- |
| `audit-retention-basis.md` | On what basis are audit records retained against an erasure request? | `RISK-F-0008` |