{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ERR",
  "title": "Executive Risk Report",
  "definitionRef": {
    "artifactId": "ERR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ERR.artifactDefinition.v2",
    "title": "Executive Risk Report"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Executive Risk Report",
        "Document ID": "EXEC-RISK-RPT-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management / Risk Committee",
        "Classification": "Confidential",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Executive Risk Report",
        "Document ID: EXEC-RISK-RPT-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management / Risk Committee",
        "Classification: Confidential",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This report summarises the organisation’s information-security risk posture for Top Management. It highlights the most material risks, treatment status, residual risk above appetite, overdue actions, emerging threats and decisions required from leadership. It is an executive decision and oversight artefact, not an external-requirements register. This plan is the live Arcfield Platform programme in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management / Risk Committee"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management / Risk Committee"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "report_template_content",
      "title": "Report",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this plan is",
          "level": 1,
          "text": "This document is Arcfield's Executive Risk Report. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. It is not the governing policy, the live register or the completion record of a later cycle. This plan applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, RR, CAR) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this plan": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this plan": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, RR, CAR."
            },
            {
              "In this plan": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this plan": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "executive_summary",
          "heading": "Executive summary",
          "level": 1,
          "text": "Executive summary is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Executive summary states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — executive summary",
              "Rule applied": "Executive summary binds the named production system and a named owner. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions.",
              "Evidence": "ERR-executive_summary-PROD"
            },
            {
              "Arcfield case": "Customer data / support — executive summary",
              "Rule applied": "Support attachments and tenant configuration inherit this executive summary rule; they are not out of scope because they are temporary.",
              "Evidence": "ERR-executive_summary-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — executive summary",
              "Rule applied": "Name the shared-responsibility split for executive summary on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "ERR-executive_summary-SUP"
            }
          ]
        },
        {
          "id": "top_risks_table",
          "heading": "Top risks table",
          "level": 1,
          "text": "Top risks table is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Top risks table states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — top risks table",
              "Rule applied": "Top risks table binds the named production system and a named owner. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions.",
              "Evidence": "ERR-top_risks_table-PROD"
            },
            {
              "Arcfield case": "Customer data / support — top risks table",
              "Rule applied": "Support attachments and tenant configuration inherit this top risks table rule; they are not out of scope because they are temporary.",
              "Evidence": "ERR-top_risks_table-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — top risks table",
              "Rule applied": "Name the shared-responsibility split for top risks table on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "ERR-top_risks_table-SUP"
            }
          ]
        },
        {
          "id": "treatment_and_residual_risk",
          "heading": "Treatment and residual risk",
          "level": 1,
          "text": "Treatment and residual risk is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Treatment and residual risk states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — treatment and residual risk",
              "Rule applied": "Treatment and residual risk binds the named production system and a named owner. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions.",
              "Evidence": "ERR-treatment_and_residual_risk-PROD"
            },
            {
              "Arcfield case": "Customer data / support — treatment and residual risk",
              "Rule applied": "Support attachments and tenant configuration inherit this treatment and residual risk rule; they are not out of scope because they are temporary.",
              "Evidence": "ERR-treatment_and_residual_risk-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — treatment and residual risk",
              "Rule applied": "Name the shared-responsibility split for treatment and residual risk on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "ERR-treatment_and_residual_risk-SUP"
            }
          ]
        },
        {
          "id": "trend",
          "heading": "Trend",
          "level": 1,
          "text": "Trend is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Trend states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — trend",
              "Rule applied": "Trend binds the named production system and a named owner. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions.",
              "Evidence": "ERR-trend-PROD"
            },
            {
              "Arcfield case": "Customer data / support — trend",
              "Rule applied": "Support attachments and tenant configuration inherit this trend rule; they are not out of scope because they are temporary.",
              "Evidence": "ERR-trend-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — trend",
              "Rule applied": "Name the shared-responsibility split for trend on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "ERR-trend-SUP"
            }
          ]
        },
        {
          "id": "decisions_required",
          "heading": "Decisions required",
          "level": 1,
          "text": "Decisions required is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Decisions required states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — decisions required",
              "Rule applied": "Decisions required binds the named production system and a named owner. Provide Top Management with a concise, evidence-linked view of ISMS risk status and required decisions.",
              "Evidence": "ERR-decisions_required-PROD"
            },
            {
              "Arcfield case": "Customer data / support — decisions required",
              "Rule applied": "Support attachments and tenant configuration inherit this decisions required rule; they are not out of scope because they are temporary.",
              "Evidence": "ERR-decisions_required-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — decisions required",
              "Rule applied": "Name the shared-responsibility split for decisions required on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "ERR-decisions_required-SUP"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "href": "RR_Risk_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CAR_Corrective_Actions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "DPIA Data Protection Impact Assessment (Dual Compliance, ISO 27001 & EU Data Act)",
              "href": "DPIA_Data_Protection_Impact_Assessment_Plan.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "href": "ELAI_Evidence_Log_Audit_Pack_Index.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Leadership & Management (Clause 5)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Plan",
    "role": "Live programme for the surveillance window"
  }
}
