{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "IAPC.artifactDefinition.v2",
  "artifactId": "IAPC",
  "title": "Internal Audit Program & Checklist",
  "artifactType": "Checklist",
  "format": "docx",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable template/example maintained in the Artifact Candidate page",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture",
    "mdDefinition": "generated output",
    "mdExample": "generated output"
  },
  "purpose": "Provide auditable evidence for Internal Audit Program & Checklist.",
  "hintPolicy": {
    "storage": "Each content section stores its hint in this JSON Definition.",
    "visualization": "Generated Office and Markdown outputs render each hint as a visually highlighted callout after the section content.",
    "minimumRule": "Every content section except formal title/document-control sections should have one context-specific hint. Hints must not be generic or mechanically repeated.",
    "format": {
      "requiredParts": [
        "short practical explanation",
        "detailed book reference"
      ]
    }
  },
  "controlledValues": {
    "result": [
      "Successful",
      "Failed",
      "Pending",
      "Not applicable"
    ],
    "yesNo": [
      "Yes",
      "No"
    ],
    "completionStatus": [
      "Complete",
      "Conditionally complete",
      "Pending",
      "Rejected"
    ],
    "priority": [
      "Critical",
      "High",
      "Medium",
      "Low"
    ],
    "evidenceQuality": [
      "Complete",
      "Partial",
      "Missing",
      "Not applicable"
    ]
  },
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null,
      "fields": [
        {
          "name": "Document Title",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Document ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Version",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Organization",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Approver",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Classification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Effective Date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Next Review Date",
          "type": "date",
          "required": "yes"
        }
      ],
      "intro": "Use this section to identify the document and its control context."
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "requiredContent": "Explain the purpose of the Internal Audit Program & Checklist and the evidence it creates for ISO 27001 implementation and audit readiness.",
      "hint": {
        "text": "Use this checklist as an auditable control record. It should show context, checks performed, evidence reviewed, open items, and final decision for Internal Audit Program & Checklist.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null,
      "fields": [
        {
          "name": "Purpose",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Used by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Maintained by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence role",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "ISO reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Review cadence",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "Record ownership, approval, classification, version, review cadence, and evidence context."
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "requiredContent": "1. Identify the owner responsible for maintaining this checklist.\n2. Complete the context section before starting the checks.\n3. Record every check with owner, date, result, evidence, and notes.\n4. Escalate failed or pending mandatory checks as blockers unless an approved exception exists.\n5. Sign off only after evidence, open items, lifecycle links, and completion decision are reviewed.",
      "intro": "Explain how to complete, maintain, review, and use this checklist as operational evidence.",
      "hint": {
        "text": "Treat this section as the operating instruction for the checklist owner. It defines the evidence standard and when Internal Audit Program & Checklist cannot be closed.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 6,
      "id": "audit_program",
      "title": "Audit program",
      "contentType": "field_table",
      "required": true,
      "fields": [
        {
          "name": "Audit period",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Audit scope",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Criteria",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Method",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Lead auditor",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Auditor independence confirmed?",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Auditees",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Reporting date",
          "type": "date",
          "required": "yes"
        }
      ],
      "intro": "Define audit scope, criteria, methods, responsibilities, independence, and reporting expectations.",
      "hint": {
        "text": "A good audit checklist starts with a defensible audit program: scope, criteria, independence, timing, and responsibilities.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 7,
      "id": "audit_plan",
      "title": "Audit plan and sampling",
      "contentType": "evidence_table",
      "required": true,
      "columns": [
        {
          "name": "Audit area",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Requirement / control",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Sample population",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Sample size",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Sampling rationale",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Auditor",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Planned date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence expected",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "Plan audit tests and evidence sampling before execution.",
      "hint": {
        "text": "Sampling rationale is important audit evidence. Record why the sample is sufficient for the requirement or control being tested.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 8,
      "id": "audit_checklist",
      "title": "Audit checklist",
      "contentType": "evidence_log_table",
      "required": true,
      "columns": [
        {
          "name": "Check ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Area",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Requirement",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Audit test",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence examined",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Performed by",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Date",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Result",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Finding reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "Use this table as the main internal-audit execution trail.",
      "hint": {
        "text": "Each audit test should show the requirement, evidence examined, test result, auditor, date, and finding reference.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 9,
      "id": "findings",
      "title": "Findings classification",
      "contentType": "evidence_table",
      "required": true,
      "columns": [
        {
          "name": "Finding ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Requirement",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Classification",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Description",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Evidence",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Due date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Corrective action reference",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        }
      ],
      "intro": "Classify audit findings and link them to owners, corrective actions, and follow-up evidence.",
      "hint": {
        "text": "Findings must be specific, evidence-based, assigned, and linked to corrective action where needed.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 10,
      "id": "follow_up_tracking",
      "title": "Follow-up tracking",
      "contentType": "action_table",
      "required": true,
      "columns": [
        {
          "name": "Action ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Finding ID",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Action",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Due date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Status",
          "type": "select",
          "required": "yes",
          "valueSet": "domain.status.generic",
          "options": [
            "Draft",
            "In Progress",
            "Under Review",
            "Approved",
            "Closed",
            "Deferred"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Verification result",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Closure evidence",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Notes",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "Track audit follow-up actions through verification and closure.",
      "hint": {
        "text": "Internal audit is incomplete until findings are followed up and closure evidence is verified.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 11,
      "id": "audit_conclusion",
      "title": "Audit conclusion",
      "contentType": "decision_table",
      "required": true,
      "fields": [
        {
          "name": "Overall result",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Lead auditor conclusion",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Management attention required?",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Open blocker decision",
          "type": "text",
          "required": "yes"
        },
        {
          "name": "Report date",
          "type": "date",
          "required": "yes"
        },
        {
          "name": "Evidence reference",
          "type": "text",
          "required": "yes"
        }
      ],
      "intro": "State the final audit conclusion and report status.",
      "hint": {
        "text": "The conclusion should distinguish conformities, nonconformities, opportunities for improvement, and unresolved blockers.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 12,
      "id": "validation_checklist",
      "title": "Validation checklist",
      "contentType": "section",
      "required": true,
      "hint": {
        "text": "Recovered during enrichment.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 13,
      "id": "evidence_reviewed",
      "title": "Evidence reviewed",
      "contentType": "section",
      "required": true,
      "hint": {
        "text": "Recovered during enrichment.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 14,
      "id": "validation_decision",
      "title": "Validation decision",
      "contentType": "section",
      "required": true,
      "hint": {
        "text": "Recovered during enrichment.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    },
    {
      "order": 15,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 2, S-07-05-00 Internal Audit & Management Review"
      }
    }
  ],
  "validationRules": [
    "Body MD, JSON Definition, and JSON Example must use the same section order and compatible section titles.",
    "Each section must have an intro that explains the practical purpose of the section before data/content is rendered.",
    "Every non-formal content section must have a context-specific hint stored in the JSON Definition and rendered as a callout after the section content.",
    "Checklist sections must capture what was done, who performed it, when it was done, the result, evidence reference, and notes where applicable.",
    "Do not include a separate Book reference chapter; book linkage belongs inside the section hint.",
    "Example data must look realistic and audit-ready, but must not contain real personal data.",
    "JSON Example must contain definitionRef pointing to IAPC.artifactDefinition.v2."
  ],
  "instructionsForGenerator": [
    "Use this JSON Definition as the machine-readable contract.",
    "Use JSON Example as the curated realistic example data source.",
    "Use Body MD as the canonical human-readable source.",
    "Generate MD Definition and MD Example downstream; do not treat them as curated source relations.",
    "Render section intros before content and section hints as callouts after content."
  ],
  "enrichment": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Completes Contract JSON from MD-only schema/sections, removes duplicate alias sections, and normalizes string columns into structured column objects."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this file by version."
      },
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-07-05-00",
        "chapterTitle": "Internal Audit & Management Review",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": false,
        "role": "Documented information, review and version discipline.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "purpose": "Provide auditable evidence for Internal Audit Program & Checklist.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this document versus neighbouring records",
      "terms as a first-class group",
      "worked Arcfield example",
      "practical examples, pitfalls, evidence and external references"
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "ISO",
        "longForm": "International Organization for Standardization"
      },
      {
        "abbr": "AI",
        "longForm": "Artificial Intelligence"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "CISO",
        "longForm": "Chief Information Security Officer"
      },
      {
        "abbr": "CRM",
        "longForm": "Customer Relationship Management"
      },
      {
        "abbr": "DR",
        "longForm": "Disaster Recovery"
      },
      {
        "abbr": "HR",
        "longForm": "Human Resources"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "RTP",
        "longForm": "Risk Treatment Plan"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      }
    ],
    "must": [
      "This file's function is: Provide auditable evidence for Internal Audit Program & Checklist. It must not be rewritten as a generic operating-rules essay.",
      "Identify the checklist owner and the object, process, person, control, or release being reviewed.",
      "Complete the context and evidence sections before recording the final decision.",
      "For each check, capture what was done, who performed it, who approved it where applicable, the date, result, evidence reference, and notes.",
      "Use controlled result values: Successful, Failed, Pending, Not applicable.",
      "Treat failed or pending mandatory checks as blockers unless an approved, time-limited exception exists.",
      "Link the checklist outcome to the relevant ISMS register, risk, control, evidence, or lifecycle record."
    ],
    "mustNot": [
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, cloud, CI/CD, privileged access or supplier interfaces where they affect this artifact's function."
    ],
    "exampleBody": {
      "sectionId": "audit_program",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 150,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What this checklist is",
          "mustInclude": [
            "checklist"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "Scope"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "Terms"
          ]
        },
        {
          "id": "audit_program",
          "heading": "Audit program",
          "mustInclude": [
            "Audit",
            "program"
          ]
        },
        {
          "id": "validation_checklist",
          "heading": "Validation checklist",
          "mustInclude": [
            "Validation",
            "checklist"
          ]
        },
        {
          "id": "evidence_reviewed",
          "heading": "Evidence reviewed",
          "mustInclude": [
            "Evidence",
            "reviewed"
          ]
        },
        {
          "id": "validation_decision",
          "heading": "Validation decision",
          "mustInclude": [
            "Validation",
            "decision"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "editorialContractId": "editorial.docx.checklist.v1",
  "contentContractId": "content.checklist.v1"
}
