{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "AI",
  "title": "Asset Inventory",
  "definitionRef": {
    "artifactId": "AI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "AI.artifactDefinition.v2",
    "title": "Asset Inventory"
  },
  "organization": "Arcfield",
  "examplePurpose": "Realistic curated example data for the Asset Inventory register, aligned with the checklist examples and existing ISMS process/object context.",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Asset Inventory",
        "Register ID": "AI-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Asset Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Asset Inventory",
        "Register ID: AI-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Asset Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "The Asset Inventory is the authoritative register for information assets, systems, repositories, services, and supporting infrastructure in the ISMS scope. It records ownership, classification, CIA needs, hosting, suppliers, personal-data relevance, lifecycle status, review dates, linked risks, access dependencies, and evidence references so that ISO 27001 asset controls can be sampled and audited. This inventory is the in-scope Arcfield Platform set on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001. The footprint is Arcfield Platform (one multi-tenant product) plus four supporting services, cloud-native on Kubernetes in two regions.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "values": {
        "Purpose": "Maintain an authoritative and audit-ready inventory of information assets and associated ownership, classification, lifecycle, risk, and evidence information.",
        "Used by": "Asset Manager, Asset Owners, System Owners, IT Operations, ISMS Manager, Internal Auditor",
        "Maintained by": "Asset Manager",
        "Evidence role": "ISO 27001 asset management and control evidence",
        "ISO reference": "ISO/IEC 27001:2022 A.5.9, A.5.10, A.5.11, A.5.12, A.5.13, A.5.14, A.5.15, A.5.23",
        "Review cadence": "Quarterly, after onboarding of critical assets, after major architecture or supplier changes, and before audit sampling"
      },
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain an authoritative and audit-ready inventory of information assets and associated ownership, classification, lifecycle, risk, and evidence information."
        },
        {
          "Property": "Used by",
          "Value": "Asset Manager, Asset Owners, System Owners, IT Operations, ISMS Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Asset Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "ISO 27001 asset management and control evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.9, A.5.10, A.5.11, A.5.12, A.5.13, A.5.14, A.5.15, A.5.23"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly, after onboarding of critical assets, after major architecture or supplier changes, and before audit sampling"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Register every in-scope information asset, system, repository, data store, critical service, and relevant supporting infrastructure.",
        "Assign a business owner, asset owner, technical custodian, and review owner for every active asset.",
        "Record classification, confidentiality, integrity, and availability needs using controlled values.",
        "Link assets to business process, hosting location, supplier, personal-data processing relevance, risks, access controls, backup or continuity dependencies, and evidence.",
        "Maintain lifecycle status, last review date, next review date, and review result.",
        "Treat missing owner, missing classification, missing review date, or missing evidence for critical assets as audit blockers.",
        "Retire or archive assets only when ownership, data retention, access removal, and evidence requirements have been closed.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "text": "Use one row per asset or asset group. The register should be specific enough to support risk assessment, access control, classification, supplier review, continuity planning, and audit evidence.",
      "contentType": "ordered_list"
    },
    {
      "id": "register_schema",
      "title": "Register schema",
      "schemaRef": {
        "definitionId": "AI.artifactDefinition.v2",
        "sectionId": "register_schema",
        "requiredColumnsRef": "sections.register_schema.requiredColumns"
      },
      "columns": [
        "Column",
        "Type",
        "Required",
        "Description",
        "Example"
      ],
      "rows": [
        {
          "Column": "Asset ID",
          "Type": "text",
          "Required": "yes",
          "Description": "Stable unique asset identifier used across registers and evidence.",
          "Example": "AST-001"
        },
        {
          "Column": "Asset name",
          "Type": "text",
          "Required": "yes",
          "Description": "Business-readable asset name.",
          "Example": "Production platform"
        },
        {
          "Column": "Asset type",
          "Type": "select",
          "Required": "yes",
          "Description": "Asset category such as application, repository, database, device, service, supplier-hosted platform, or documentation repository.",
          "Example": "Application"
        },
        {
          "Column": "Business process",
          "Type": "text",
          "Required": "yes",
          "Description": "Process or service supported by the asset.",
          "Example": "Customer onboarding"
        },
        {
          "Column": "Business owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Accountable business role.",
          "Example": "Head of Product Operations"
        },
        {
          "Column": "Asset owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Role accountable for asset accuracy, classification, and review.",
          "Example": "Service Owner"
        },
        {
          "Column": "Technical custodian",
          "Type": "text",
          "Required": "yes",
          "Description": "Role maintaining or operating the asset.",
          "Example": "IT Operations"
        },
        {
          "Column": "Classification",
          "Type": "select",
          "Required": "yes",
          "Description": "Information classification.",
          "Example": "Confidential"
        },
        {
          "Column": "Confidentiality need",
          "Type": "select",
          "Required": "yes",
          "Description": "Confidentiality protection need.",
          "Example": "High"
        },
        {
          "Column": "Integrity need",
          "Type": "select",
          "Required": "yes",
          "Description": "Integrity protection need.",
          "Example": "High"
        },
        {
          "Column": "Availability need",
          "Type": "select",
          "Required": "yes",
          "Description": "Availability protection need.",
          "Example": "High"
        },
        {
          "Column": "Location / hosting",
          "Type": "text",
          "Required": "yes",
          "Description": "Hosting model, location, or repository location.",
          "Example": "EU cloud production environment"
        },
        {
          "Column": "Supplier",
          "Type": "text",
          "Required": "conditional",
          "Description": "Supplier or platform provider where relevant.",
          "Example": "CloudHost EU"
        },
        {
          "Column": "Contains personal data?",
          "Type": "select",
          "Required": "yes",
          "Description": "Whether the asset stores or processes personal data.",
          "Example": "Yes"
        },
        {
          "Column": "Related risk",
          "Type": "text",
          "Required": "conditional",
          "Description": "Linked risk register entry.",
          "Example": "RISK-2026-014"
        },
        {
          "Column": "Related access control",
          "Type": "text",
          "Required": "conditional",
          "Description": "Linked access matrix or access register entry.",
          "Example": "ACM-APP-CRM-001"
        },
        {
          "Column": "Backup / continuity dependency",
          "Type": "text",
          "Required": "conditional",
          "Description": "Backup, recovery, or continuity dependency.",
          "Example": "Backup job BKP-CRM-001"
        },
        {
          "Column": "Lifecycle status",
          "Type": "select",
          "Required": "yes",
          "Description": "Asset lifecycle status.",
          "Example": "Active"
        },
        {
          "Column": "Last review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Date of last owner review.",
          "Example": "2026-08-29"
        },
        {
          "Column": "Next review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Planned next review date.",
          "Example": "2026-11-29"
        },
        {
          "Column": "Review result",
          "Type": "select",
          "Required": "yes",
          "Description": "Result of the last review.",
          "Example": "Confirmed"
        },
        {
          "Column": "Evidence reference",
          "Type": "text",
          "Required": "yes",
          "Description": "Evidence log, ticket, snapshot, or register reference.",
          "Example": "AI-AST-001-2026-Q3"
        },
        {
          "Column": "Notes",
          "Type": "text",
          "Required": "no",
          "Description": "Additional context, open items, or assumptions.",
          "Example": "Supplier contact update pending."
        }
      ],
      "text": "This section defines the columns that must exist in the Asset Inventory workbook.",
      "contentType": "schema_table"
    },
    {
      "id": "asset_inventory_entries",
      "title": "Asset inventory entries",
      "schemaRef": {
        "definitionId": "AI.artifactDefinition.v2",
        "sectionId": "asset_inventory_entries",
        "columnsRef": "sections.asset_inventory_entries.columns"
      },
      "rows": [
        {
          "Asset ID": "AST-001",
          "Asset name": "Production platform",
          "Asset type": "Application",
          "Business process": "Customer onboarding",
          "Business owner": "Head of Product Operations",
          "Asset owner": "Service Owner",
          "Technical custodian": "IT Operations",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "High",
          "Location / hosting": "EU cloud production environment",
          "Supplier": "CloudHost EU",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-014",
          "Related access control": "ACM-APP-CRM-001",
          "Backup / continuity dependency": "Backup job BKP-CRM-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed with action",
          "Evidence reference": "AI-AST-001-2026-Q3",
          "Notes": "Supplier contact update pending."
        },
        {
          "Asset ID": "AST-002",
          "Asset name": "Customer Portal",
          "Asset type": "SaaS application",
          "Business process": "Customer support and onboarding",
          "Business owner": "Head of Customer Success",
          "Asset owner": "Product Systems Owner",
          "Technical custodian": "IT Operations",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "Medium",
          "Availability need": "High",
          "Location / hosting": "EU SaaS tenant",
          "Supplier": "Arcfield SaaS Platform",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-018",
          "Related access control": "ACM-CUSTPORTAL-001",
          "Backup / continuity dependency": "DRP-CUSTPORTAL-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed",
          "Evidence reference": "AI-AST-002-2026-Q3",
          "Notes": "Access reviewed through ARR and UAI."
        },
        {
          "Asset ID": "AST-003",
          "Asset name": "ISMS evidence repository",
          "Asset type": "Information repository",
          "Business process": "ISMS evidence management",
          "Business owner": "ISMS Manager",
          "Asset owner": "ISMS Manager",
          "Technical custodian": "Workspace Administrator",
          "Classification": "Internal",
          "Confidentiality need": "Medium",
          "Integrity need": "High",
          "Availability need": "Medium",
          "Location / hosting": "Document workspace",
          "Supplier": "Not applicable",
          "Contains personal data?": "No",
          "Related risk": "RISK-2026-021",
          "Related access control": "ACM-EVIDENCE-001",
          "Backup / continuity dependency": "Export backup BKP-EVID-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-28",
          "Next review date": "2026-11-28",
          "Review result": "Confirmed",
          "Evidence reference": "EVID-LOG-2026-Q3",
          "Notes": "Repository used for audit pack preparation."
        },
        {
          "Asset ID": "AST-004",
          "Asset name": "Customer Portal source repository",
          "Asset type": "Code repository",
          "Business process": "Secure software development",
          "Business owner": "Engineering Lead",
          "Asset owner": "Engineering Lead",
          "Technical custodian": "DevOps Engineer",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "Medium",
          "Location / hosting": "Repository platform",
          "Supplier": "CodeHost EU",
          "Contains personal data?": "No",
          "Related risk": "RISK-2026-027",
          "Related access control": "ACM-REPO-001",
          "Backup / continuity dependency": "Repository backup policy BKP-REPO-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-27",
          "Next review date": "2026-11-27",
          "Review result": "Confirmed",
          "Evidence reference": "SI-REPO-2026-014",
          "Notes": "Linked to S-SDLC release evidence."
        },
        {
          "Asset ID": "AST-005",
          "Asset name": "Identity provider tenant",
          "Asset type": "Identity service",
          "Business process": "Identity and access management",
          "Business owner": "CISO",
          "Asset owner": "IT Operations Manager",
          "Technical custodian": "IT Operations",
          "Classification": "Restricted",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "High",
          "Location / hosting": "EU identity cloud",
          "Supplier": "IdentityCloud EU",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-031",
          "Related access control": "ACM-IDP-001",
          "Backup / continuity dependency": "Break-glass and recovery procedure IAM-DR-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-29",
          "Review result": "Confirmed",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "Notes": "Privileged access reviewed monthly."
        },
        {
          "Asset ID": "AST-006",
          "Asset name": "HR personnel file repository",
          "Asset type": "Information repository",
          "Business process": "HR onboarding and offboarding",
          "Business owner": "HR Manager",
          "Asset owner": "HR Manager",
          "Technical custodian": "HR Operations",
          "Classification": "Restricted",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "Medium",
          "Location / hosting": "HR SaaS tenant",
          "Supplier": "PeopleOps Cloud",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-033",
          "Related access control": "ACM-HR-001",
          "Backup / continuity dependency": "HR retention schedule RRS-HR-001",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Review result": "Confirmed",
          "Evidence reference": "HR-ONB-2026-023",
          "Notes": "Supports ONC and OFC examples."
        },
        {
          "Asset ID": "AST-011",
          "Asset name": "CI/CD",
          "Asset type": "Infrastructure service",
          "Business process": "Secure change to production",
          "Business owner": "Engineering Lead",
          "Asset owner": "Engineering Lead",
          "Technical custodian": "IT Operations",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "High",
          "Location / hosting": "EU cloud CI/CD project",
          "Supplier": "Arcfield engineering",
          "Contains personal data?": "No",
          "Related risk": "RISK-2026-014",
          "Related access control": "ACM-CICD-001",
          "Backup / continuity dependency": "Pipeline config backup",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed",
          "Evidence reference": "CICD-CTRL-2026-Q3",
          "Notes": "Signed deploy path into Arcfield Platform production. Named from SAS."
        },
        {
          "Asset ID": "AST-012",
          "Asset name": "Logging and detection",
          "Asset type": "Infrastructure service",
          "Business process": "Detection and incident evidence",
          "Business owner": "Security Lead",
          "Asset owner": "Security Lead",
          "Technical custodian": "IT Operations",
          "Classification": "Restricted",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "High",
          "Location / hosting": "EU cloud logging stack",
          "Supplier": "CloudHost EU",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-018",
          "Related access control": "ACM-LOG-001",
          "Backup / continuity dependency": "Log retention rule",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed",
          "Evidence reference": "LMP-CTRL-2026-Q3",
          "Notes": "Auth, privileged-access and deploy events. Named from SAS."
        },
        {
          "Asset ID": "AST-013",
          "Asset name": "Backup and restore",
          "Asset type": "Infrastructure service",
          "Business process": "Continuity and restore",
          "Business owner": "Engineering Lead",
          "Asset owner": "Engineering Lead",
          "Technical custodian": "IT Operations",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "High",
          "Availability need": "High",
          "Location / hosting": "EU backup account, same region as production",
          "Supplier": "CloudHost EU",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-014",
          "Related access control": "ACM-BKP-001",
          "Backup / continuity dependency": "Restore-test record",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed",
          "Evidence reference": "BKP-CTRL-2026-Q3",
          "Notes": "Encrypted production backups. Named from SAS."
        },
        {
          "Asset ID": "AST-014",
          "Asset name": "Support platform",
          "Asset type": "Supplier-hosted platform",
          "Business process": "Customer support and onboarding",
          "Business owner": "Head of Customer Success",
          "Asset owner": "Product Systems Owner",
          "Technical custodian": "IT Operations",
          "Classification": "Confidential",
          "Confidentiality need": "High",
          "Integrity need": "Medium",
          "Availability need": "High",
          "Location / hosting": "Provider EU region",
          "Supplier": "Support SaaS",
          "Contains personal data?": "Yes",
          "Related risk": "RISK-2026-018",
          "Related access control": "ACM-SUP-001",
          "Backup / continuity dependency": "Ticket retention rule",
          "Lifecycle status": "Active",
          "Last review date": "2026-08-29",
          "Next review date": "2026-11-29",
          "Review result": "Confirmed",
          "Evidence reference": "SUP-CTRL-2026-Q3",
          "Notes": "Tickets and attachments. Named from SAS."
        }
      ],
      "text": "The following rows are realistic example records that reuse the same process and object context used by the related checklist examples.",
      "contentType": "register_table"
    },
    {
      "id": "review_and_maintenance",
      "title": "Review and maintenance",
      "rows": [
        {
          "Review item": "Critical asset owner review",
          "Owner": "Asset Manager",
          "Frequency / trigger": "Quarterly",
          "Required evidence": "Owner confirmation and updated review date",
          "Example evidence reference": "AI-AST-001-2026-Q3",
          "Evidence reference": "AI-AST-001-2026-Q3"
        },
        {
          "Review item": "Classification review",
          "Owner": "Asset Owner",
          "Frequency / trigger": "Annually or after data/process change",
          "Required evidence": "Classification confirmation",
          "Example evidence reference": "CLASS-AST-001-2026-Q3",
          "Evidence reference": "CLASS-AST-001-2026-Q3"
        },
        {
          "Review item": "Access dependency review",
          "Owner": "IT Operations",
          "Frequency / trigger": "Quarterly or after access model change",
          "Required evidence": "Access matrix and access review evidence",
          "Example evidence reference": "ACM-APP-CRM-001",
          "Evidence reference": "ACM-APP-CRM-001"
        },
        {
          "Review item": "Supplier dependency review",
          "Owner": "Supplier Manager",
          "Frequency / trigger": "Annually or after supplier/service change",
          "Required evidence": "Supplier inventory and contract evidence",
          "Example evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3"
        },
        {
          "Review item": "Lifecycle retirement review",
          "Owner": "Asset Owner",
          "Frequency / trigger": "Before retirement or archive",
          "Required evidence": "Access removal, retention, and evidence closure",
          "Example evidence reference": "RET-AST-OLD-2026-001",
          "Evidence reference": "RET-AST-OLD-2026-001"
        }
      ],
      "text": "The Asset Inventory must be reviewed at planned intervals and whenever a material change affects ownership, classification, hosting, supplier dependency, risk, or lifecycle status.",
      "contentType": "review_table"
    },
    {
      "id": "lifecycle_linkage",
      "title": "Lifecycle linkage",
      "rows": [
        {
          "Linked record": "Risk Register",
          "Reference": "RISK-2026-014",
          "Owner": "Risk Manager",
          "Status": "Updated",
          "Evidence reference": "RISK-2026-014"
        },
        {
          "Linked record": "Access Control Matrix",
          "Reference": "ACM-APP-CRM-001",
          "Owner": "IT Operations",
          "Status": "Updated",
          "Evidence reference": "ACM-APP-CRM-001"
        },
        {
          "Linked record": "Users and Access Inventory",
          "Reference": "UAI-CUSTPORTAL-2026-Q3",
          "Owner": "IT Operations",
          "Status": "Updated",
          "Evidence reference": "UAI-CUSTPORTAL-2026-Q3"
        },
        {
          "Linked record": "Supplier Inventory",
          "Reference": "SINV-CLOUDHOST-2026-Q3",
          "Owner": "Supplier Manager",
          "Status": "Pending contact update",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3"
        },
        {
          "Linked record": "Evidence Log / Audit Pack Index",
          "Reference": "EVID-AI-2026-Q3",
          "Owner": "ISMS Manager",
          "Status": "Created",
          "Evidence reference": "EVID-AI-2026-Q3"
        },
        {
          "Linked record": "Business Continuity Plan",
          "Reference": "BCP-CUSTPORTAL-2026",
          "Owner": "Business Continuity Manager",
          "Status": "Linked",
          "Evidence reference": "BCP-CUSTPORTAL-2026"
        }
      ],
      "text": "The Asset Inventory should link to the main operational and assurance registers that depend on accurate asset information.",
      "contentType": "linkage_table"
    },
    {
      "id": "register_completeness_decision",
      "title": "Register completeness decision",
      "values": {
        "Completeness result": "Conditionally complete",
        "Reviewed by": "ISMS Manager",
        "Open blocker decision": "No audit blocker; supplier contact update remains open",
        "Critical assets without owner": "0",
        "Critical assets without classification": "0",
        "Critical assets without review date": "0",
        "Critical assets without evidence reference": "0",
        "Final status": "Audit-ready with non-blocking follow-up",
        "Decision date": "2026-08-29",
        "Evidence reference": "AI-COMPLETE-2026-Q3"
      },
      "rows": [
        {
          "Field": "Completeness result",
          "Value": "Conditionally complete",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Open blocker decision",
          "Value": "No audit blocker; supplier contact update remains open",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Critical assets without owner",
          "Value": "0",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Critical assets without classification",
          "Value": "0",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Critical assets without review date",
          "Value": "0",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Critical assets without evidence reference",
          "Value": "0",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Final status",
          "Value": "Audit-ready with non-blocking follow-up",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Evidence reference",
          "Value": "AI-COMPLETE-2026-Q3",
          "Evidence reference": "AI-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        }
      ],
      "text": "This section records whether the Asset Inventory is complete enough to support audit sampling.",
      "contentType": "decision_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Risk Register](RR_Risk_Register.xlsx) — Live CIA risks that cite Asset IDs from this inventory.",
            "[Systems Architecture Statement](SAS_Systems_Architecture_Statement.docx) — In-scope Arcfield Platform systems named as Asset IDs.",
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — Required documented information, including this inventory."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Performance, Monitoring & Audit (Clause 9)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ACM Access Control Matrix (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "qaNotes": "Example uses realistic ISMS asset, risk, access, supplier, backup, and evidence references. It avoids generic sample placeholders and aligns with the rendered Body.",
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Inventory",
    "role": "In-scope Arcfield Platform inventory on the freeze"
  }
}
