The matching guidelines are part of the SPDX spec (Annex C):
I know we've gone back and forth on whether they should be kept in license-list-XML. I think that if they're staying in the spec itself, then we should only maintain them in spdx-spec, and remove them from license-list-XML (replacing them with a link to spdx-spec).
We should also compare the existing one in license-list-XML with what's in spdx-spec, to confirm on any changes that have happened and haven't been synced (if any).