{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "MRART",
  "title": "Management Review Agenda & Report",
  "definitionRef": {
    "artifactId": "MRART",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "MRART.artifactDefinition.v2",
    "title": "Management Review Agenda & Report"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Management Review Agenda and Report",
        "Document ID": "MGT-REV-AGENDA-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Management Review Agenda and Report",
        "Document ID: MGT-REV-AGENDA-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines the agenda and report structure for Arcfield ISMS management review. It ensures required ISO 27001 inputs, decision questions, resource decisions, risk acceptance, opportunities and follow-up actions are prepared before the meeting. This plan is the live Arcfield Platform programme in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "management_review_content",
      "title": "Management review",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this plan is",
          "level": 1,
          "text": "This document is Arcfield's Management Review Agenda & Report. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. It is not the governing policy, the live register or the completion record of a later cycle. This plan applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, CAR, IMPL-WB) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this plan": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this plan": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, CAR, IMPL-WB."
            },
            {
              "In this plan": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this plan": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "required_management_review_inputs",
          "heading": "Required management review inputs",
          "level": 1,
          "text": "Required management review inputs is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Required management review inputs states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to ISMS evidence that an auditor can retrieve for Arcfield Platform. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — required management review inputs",
              "Rule applied": "Required management review inputs binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-required_management_review_inputs-PROD"
            },
            {
              "Arcfield case": "Customer data / support — required management review inputs",
              "Rule applied": "Support attachments and tenant configuration inherit this required management review inputs rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-required_management_review_inputs-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — required management review inputs",
              "Rule applied": "Name the shared-responsibility split for required management review inputs on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-required_management_review_inputs-SUP"
            }
          ]
        },
        {
          "id": "management_decision_model",
          "heading": "Management decision model",
          "level": 1,
          "text": "Management decision model is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Management decision model states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — management decision model",
              "Rule applied": "Management decision model binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-management_decision_model-PROD"
            },
            {
              "Arcfield case": "Customer data / support — management decision model",
              "Rule applied": "Support attachments and tenant configuration inherit this management decision model rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-management_decision_model-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — management decision model",
              "Rule applied": "Name the shared-responsibility split for management decision model on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-management_decision_model-SUP"
            }
          ]
        },
        {
          "id": "review_results",
          "heading": "Review results",
          "level": 1,
          "text": "Review results is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Review results states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — review results",
              "Rule applied": "Review results binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-review_results-PROD"
            },
            {
              "Arcfield case": "Customer data / support — review results",
              "Rule applied": "Support attachments and tenant configuration inherit this review results rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-review_results-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — review results",
              "Rule applied": "Name the shared-responsibility split for review results on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-review_results-SUP"
            }
          ]
        },
        {
          "id": "decisions_and_actions",
          "heading": "Decisions and actions",
          "level": 1,
          "text": "Decisions and actions is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Decisions and actions states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — decisions and actions",
              "Rule applied": "Decisions and actions binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-decisions_and_actions-PROD"
            },
            {
              "Arcfield case": "Customer data / support — decisions and actions",
              "Rule applied": "Support attachments and tenant configuration inherit this decisions and actions rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-decisions_and_actions-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — decisions and actions",
              "Rule applied": "Name the shared-responsibility split for decisions and actions on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-decisions_and_actions-SUP"
            }
          ]
        },
        {
          "id": "resource_needs_and_improvement_opportunities",
          "heading": "Resource needs and improvement opportunities",
          "level": 1,
          "text": "Resource needs and improvement opportunities is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Resource needs and improvement opportunities states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — resource needs and improvement opportunities",
              "Rule applied": "Resource needs and improvement opportunities binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-resource_needs_and_improvement_opportunities-PROD"
            },
            {
              "Arcfield case": "Customer data / support — resource needs and improvement opportunities",
              "Rule applied": "Support attachments and tenant configuration inherit this resource needs and improvement opportunities rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-resource_needs_and_improvement_opportunities-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — resource needs and improvement opportunities",
              "Rule applied": "Name the shared-responsibility split for resource needs and improvement opportunities on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-resource_needs_and_improvement_opportunities-SUP"
            }
          ]
        },
        {
          "id": "next_review",
          "heading": "Next review",
          "level": 1,
          "text": "Next review is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Next review states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — next review",
              "Rule applied": "Next review binds the named production system and a named owner. Prepare and report formal ISMS management reviews with decision-grade inputs and assigned outputs.",
              "Evidence": "MRART-next_review-PROD"
            },
            {
              "Arcfield case": "Customer data / support — next review",
              "Rule applied": "Support attachments and tenant configuration inherit this next review rule; they are not out of scope because they are temporary.",
              "Evidence": "MRART-next_review-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — next review",
              "Rule applied": "Name the shared-responsibility split for next review on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "MRART-next_review-SUP"
            }
          ]
        }
      ],
      "contentType": "review_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "CAR Corrective Actions Register (Building the ISMS, Context of the Organization (Clause 4))",
              "href": "CAR_Corrective_Actions_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "IMPL-WB ISMS Implementation Workbook (Implementation & Certification, Implementation Readiness & Planning)",
              "href": "IMPL-WB_ISMS_Implementation_Workbook_Dashboard.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "href": "ISO_Information_Security_Objectives_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "MRMT Management Review Minutes Template (Implementation & Certification, Internal Audit & Management Review)",
              "href": "MRMT_Management_Review_Minutes_Template.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Plan",
    "role": "Live programme for the surveillance window"
  }
}
