{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "IAP",
  "title": "Internal Audit Plan",
  "definitionRef": {
    "artifactId": "IAP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "IAP.artifactDefinition.v2",
    "title": "Internal Audit Plan"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Internal Audit Plan",
        "Document ID": "AUDIT-PLAN-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Internal Auditor",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Internal Audit Plan",
        "Document ID: AUDIT-PLAN-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Internal Auditor",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines a risk-based internal audit plan for Arcfield. It documents audit programme linkage, objectives, criteria, scope, independence, sampling, schedule, reporting and corrective-action follow-up before fieldwork begins. This plan is the live Arcfield Platform programme in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "audit_plan_content",
      "title": "Audit plan",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this plan is",
          "level": 1,
          "text": "This document is Arcfield's internal audit plan for the current cycle. It is the freeze of objectives, scope, criteria, independence and sampling before fieldwork. It is not the audit report, not the programme checklist and not management-review minutes. Findings leave this file as corrective actions with owners. Cite this Document Control version from those records."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before fieldwork. If a fact belongs in the report or a checklist, it does not belong in this plan.",
          "rows": [
            {
              "In this plan": "This cycle's objectives, criteria, independence limits, sampling and schedule.",
              "Not in this plan": "Audit findings, ratings or closing comments. Those belong in the audit report.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this plan": "The sample focus for privileged access, CI/CD, suppliers and evidence stores.",
              "Not in this plan": "The working checklists. Those are IAPC and related forms.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this plan": "Follow-up routing into corrective action with owner and due date.",
              "Not in this plan": "Management-review minutes. Those cite this Document Control version.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Independence",
              "Meaning": "Auditors do not audit work they own. A limitation and compensating review must be written before fieldwork if independence is constrained."
            },
            {
              "Term": "Sampling",
              "Meaning": "The pre-agreed set of records, systems and people the auditor will test. It is not chosen during the interview."
            },
            {
              "Term": "Follow-up",
              "Meaning": "A finding becomes a corrective action with owner and due date. It is not closed in this plan."
            }
          ]
        },
        {
          "heading": "Audit programme linkage",
          "level": 1,
          "text": "This audit is part of the Q3 audit-readiness cycle. It focuses on areas with certification relevance, recent changes, open high risks and evidence gaps."
        },
        {
          "heading": "Audit objectives",
          "level": 1,
          "text": "The internal audit evaluates whether the ISMS conforms to ISO/IEC 27001:2022, Arcfield ISMS requirements and evidence-readiness expectations. It also checks whether the ISMS is effectively implemented and maintained.",
          "id": "audit_objectives"
        },
        {
          "heading": "Audit scope",
          "level": 1,
          "text": "The audit covers the approved ISMS scope, including governance, risk management, SoA, operational controls, supplier controls, incident management, business continuity, monitoring, awareness and documented information."
        },
        {
          "heading": "Audit criteria",
          "level": 1,
          "items": [
            "ISO/IEC 27001:2022 Clauses 4-10.",
            "Applicable Annex A controls from the Statement of Applicability.",
            "Approved ISMS policies, procedures and records.",
            "Legal, regulatory, contractual and customer requirements where applicable."
          ],
          "id": "audit_criteria",
          "text": "Use these criteria as the audit test basis. Do not add informal criteria during fieldwork without recording a plan change."
        },
        {
          "heading": "Auditor independence",
          "level": 1,
          "text": "Auditors must not audit work for which they are directly responsible. Where full independence is not possible, the limitation and compensating review must be documented. Technical owners may explain systems, but must not make audit judgments about their own work.",
          "id": "auditor_independence"
        },
        {
          "heading": "Risk-based sampling",
          "level": 1,
          "text": "Samples are selected using risk level, mandatory-document status, recent changes, supplier criticality, prior findings and evidence gaps. Sampling must be defined before fieldwork and retained with the workpapers.",
          "id": "risk_based_sampling"
        },
        {
          "heading": "Audit schedule",
          "level": 1,
          "rows": [
            {
              "Audit Area": "ISMS governance",
              "Planned Date": "2026-09-10",
              "Auditor": "Internal Auditor",
              "Auditee / Owner": "ISMS Manager",
              "Criteria": "Clauses 4-5",
              "Sample focus": "Scope, policy, roles, documented information",
              "Status": "In progress",
              "Evidence reference": "IAP-WP-ISMS-GOVERNANCE-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Audit Area": "Risk management",
              "Planned Date": "2026-09-12",
              "Auditor": "Internal Auditor",
              "Auditee / Owner": "Risk Manager",
              "Criteria": "Clause 6.1",
              "Sample focus": "High risks, treatment plans, risk acceptance",
              "Status": "Planned",
              "Evidence reference": "IAP-WP-RISK-MANAGEMENT-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Audit Area": "Access control",
              "Planned Date": "2026-09-16",
              "Auditor": "Internal Auditor",
              "Auditee / Owner": "IT Operations Manager",
              "Criteria": "A.5.15-A.5.18",
              "Sample focus": "Privileged access, joiner/mover/leaver evidence",
              "Status": "Planned",
              "Evidence reference": "IAP-WP-ACCESS-CONTROL-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Audit Area": "Supplier management",
              "Planned Date": "2026-09-18",
              "Auditor": "Internal Auditor",
              "Auditee / Owner": "Supplier Manager",
              "Criteria": "A.5.19-A.5.23",
              "Sample focus": "Critical supplier due diligence and monitoring",
              "Status": "Planned",
              "Evidence reference": "IAP-WP-SUPPLIER-MANAGEMENT-2026-Q3",
              "Evidence status": "Complete"
            }
          ],
          "id": "audit_schedule",
          "text": "Complete every row before fieldwork. Do not start an area that has no auditor or sample focus."
        },
        {
          "heading": "Audit method",
          "level": 1,
          "text": "The audit may include document review, interviews, sampling of records, walkthroughs, control testing and evidence tracing from requirement to implementation."
        },
        {
          "heading": "Reporting and follow-up",
          "level": 1,
          "text": "The audit report includes scope, criteria, audited areas, evidence sampled, conformities, nonconformities, opportunities for improvement, corrective actions and due dates. Nonconformities are tracked in the Corrective Actions Register until root cause, correction, corrective action, effectiveness check and closure are complete."
        },
        {
          "id": "operating_evidence_sample",
          "heading": "Operating evidence sample",
          "level": 1,
          "text": "These records can be retrieved for the 2026-08-29 Arcfield / Arcfield Platform freeze. They are the sample an auditor can re-perform. They are not a second register grid.",
          "rows": [
            {
              "Sample ID": "IAP-EV-001",
              "What was sampled": "Clause 4–5 workpapers for this programme (IAPC working checklist)",
              "Evidence reference": "IAP-WP-CONTEXT-2026-Q3"
            },
            {
              "Sample ID": "IAP-EV-002",
              "What was sampled": "Risk-management sample pack (high risks, RTP, RAMT) (RR / RTP / RAMT exports)",
              "Evidence reference": "IAP-WP-RISK-MANAGEMENT-2026-Q3"
            },
            {
              "Sample ID": "IAP-EV-003",
              "What was sampled": "Access-control sample pack (privileged access, JML) (UAI / ARR)",
              "Evidence reference": "IAP-WP-ACCESS-CONTROL-2026-Q3"
            },
            {
              "Sample ID": "IAP-EV-004",
              "What was sampled": "Supplier-management sample pack (SINV / SSAQ)",
              "Evidence reference": "IAP-WP-SUPPLIER-MANAGEMENT-2026-Q3"
            },
            {
              "Sample ID": "IAP-EV-005",
              "What was sampled": "Follow-up of open nonconformities (NC-RP pack)",
              "Evidence reference": "IAP-WP-NC-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "audit_plan_sections"
    },
    {
      "id": "independence_and_sampling_model",
      "title": "Independence and sampling model",
      "schemaRef": {
        "definitionId": "IAP.artifactDefinition.v2",
        "sectionId": "independence_and_sampling_model",
        "columnsRef": "sections.independence_and_sampling_model.columns"
      },
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Audit area": "Access control",
              "Independence concern": "Security Lead helped design access review.",
              "Compensating measure": "Internal Auditor makes audit judgment; Security Lead only explains technical context.",
              "Sampling rule": "Sample privileged access, customer-data access and one mover case.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Audit area": "Risk management",
              "Independence concern": "Risk Manager owns the register.",
              "Compensating measure": "Internal Auditor samples scoring rationale and treatment evidence independently.",
              "Sampling rule": "Sample High risks, accepted residual risks and overdue actions.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Audit area": "Supplier management",
              "Independence concern": "Supplier Manager owns supplier records.",
              "Compensating measure": "Auditor samples critical suppliers and checks evidence against policy.",
              "Sampling rule": "Sample largest critical supplier and one low-spend security-critical supplier.",
              "Evidence reference": "IAP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Auditor Evidence Request Log](AUD-ER_Auditor_Evidence_Request_Log.xlsx) — Certification-audit evidence requests: what was asked, when, who delivered it, and the trace to the pack.",
            "[Internal Audit Program & Checklist](IAPC_Internal_Audit_Program_and_Checklist.docx) — The internal-audit programme and the checklist records for each audit.",
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AUD-ER Auditor Evidence Request Log",
              "How this document uses it": "Certification-audit evidence requests: what was asked, when, who delivered it, and the trace to the pack.",
              "href": "AUD-ER_Auditor_Evidence_Request_Log.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CAR_Corrective_Actions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "href": "ISO_Information_Security_Objectives_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "MRART Management Review Agenda & Report Template (Implementation & Certification, Internal Audit & Management Review)",
              "href": "MRART_Management_Review_Agenda_and_Report_Template_Plan.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "href": "RR_Risk_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "MRMT Management Review Minutes Template",
              "href": "MRMT_Management_Review_Minutes_Template.docx",
              "How this document uses it": "Recurring minutes or records this file requires. Cite the approved version; do not keep a second schema here."
            }
          ]
        },
        {
          "id": "linked_templates",
          "heading": "Linked templates",
          "level": 1,
          "text": "Recurring records use these companion templates. Do not keep a second schema in this file.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "IAPC Internal Audit Program & Checklist",
              "How this document uses it": "Recurring audit-programme records this file requires. Use this companion template; do not keep a second checklist schema here.",
              "href": "IAPC_Internal_Audit_Program_and_Checklist.docx"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Plan",
    "role": "Live programme for the surveillance window"
  }
}
