{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "MRMT",
  "title": "Management Review Minutes",
  "definitionRef": {
    "artifactId": "MRMT",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "MRMT.artifactDefinition.v2",
    "title": "Management Review Minutes"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Management Review Minutes",
        "Document ID": "MGT-REV-MIN-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Top Management",
        "Approver": "CISO",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Management Review Minutes",
        "Document ID: MGT-REV-MIN-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Top Management",
        "Approver: CISO",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines how Arcfield records management review minutes so decisions, required inputs, residual-risk acceptance, certification status, resource decisions, owners, due dates and follow-up evidence are traceable. These minutes record a dated review of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "CISO"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit; records ISO/IEC 27001:2022 certificate ARC-ISMS-2025-001 and the first surveillance sitting of 29 August 2026.",
              "Approved by": "CISO"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "minutes_content",
      "title": "Minutes",
      "groups": [
        {
          "id": "introduction",
          "heading": "What these minutes are",
          "level": 1,
          "text": "This document is Arcfield's Management Review Minutes. This sitting (29 August 2026) is in the surveillance after first visit window after ISO/IEC 27001:2022 certificate ARC-ISMS-2025-001 (25 April 2025). Capture management review inputs, decisions, outputs and action items. It is not the Risk Assessment Methodology, the live risk register or a second Document Control table. This minutes applies to Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, EXR, IAP, CA-ARCFIELD-EN-2025-04-10) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In these minutes": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in these minutes": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, EXR, IAP."
            },
            {
              "In these minutes": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in these minutes": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Residual rating",
              "Meaning": "The rating after treatment using the published RAM bands. These minutes record acceptance; they do not recalibrate RAM."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            },
            {
              "Term": "Surveillance cycle",
              "Meaning": "The three-year ISO/IEC 27001:2022 cycle after certificate issue. First surveillance is due April 2026."
            }
          ]
        },
        {
          "id": "meeting_information",
          "heading": "Meeting information",
          "level": 1,
          "text": "Record the meeting date, mode, chair, recorder and who was present before you write conclusions. This is the 29 August 2026 Arcfield Platform management review in the surveillance after first visit cycle, not a second Document Control table.",
          "values": {
            "Meeting date": "2026-08-29",
            "Mode": "Video",
            "Chair": "Top Management",
            "Recorder": "ISMS Manager",
            "Review period": "2026-06-01 to 2026-08-29",
            "Document Control version cited": "1.1"
          },
          "rows": [
            {
              "Role": "Top Management",
              "Present": "Yes",
              "Capacity": "Chair"
            },
            {
              "Role": "ISMS Manager",
              "Present": "Yes",
              "Capacity": "Facilitator and recorder"
            },
            {
              "Role": "Risk Manager",
              "Present": "Yes",
              "Capacity": "Voting"
            },
            {
              "Role": "Internal Auditor",
              "Present": "Yes",
              "Capacity": "Independent observer"
            },
            {
              "Role": "IT Operations Manager",
              "Present": "Yes",
              "Capacity": "Action owner"
            }
          ]
        },
        {
          "id": "required_inputs_reviewed",
          "heading": "Required inputs reviewed",
          "level": 1,
          "text": "Name each Clause 9.3 input that this sitting reviewed, the finding, the companion record cited and what management concluded. Do not copy those files into these minutes.",
          "rows": [
            {
              "Input": "Previous actions",
              "Finding": "8 of 10 actions closed; two access-control actions remain open.",
              "Cited record": "Prior MRMT action log 2026-Q2",
              "Conclusion": "Continue weekly follow-up."
            },
            {
              "Input": "Context changes",
              "Finding": "Backup supplier added to the production recovery chain.",
              "Cited record": "SINV backup supplier row 2026-Q3",
              "Conclusion": "Scope and risk updates required."
            },
            {
              "Input": "ISMS performance",
              "Finding": "Evidence readiness 88% against the 95% target.",
              "Cited record": "IMPL-WB review 2026-Q3",
              "Conclusion": "Add an evidence-quality checkpoint."
            },
            {
              "Input": "Risk treatment",
              "Finding": "Three high-risk items remain open.",
              "Cited record": "RMP review 2026-Q3",
              "Conclusion": "Escalate overdue items."
            },
            {
              "Input": "Audit status",
              "Finding": "Internal audit IA-ARCFIELD-EN-2026-09-11 is the documented-information sample for first surveillance (April 2026).",
              "Cited record": "IAP / IA-ARCFIELD-EN-2026-09-11",
              "Conclusion": "Treat this 9.2 report as surveillance input, not an initial Stage 2."
            },
            {
              "Input": "Certification status",
              "Finding": "Certificate ARC-ISMS-2025-001 issued 25 April 2025; valid until 24 April 2028; surveillance after first visit due April 2026.",
              "Cited record": "CA-ARCFIELD-EN-2025-04-10 certification-audit-report-2025.md",
              "Conclusion": "Maintain the certified ISMS; resource first surveillance."
            },
            {
              "Input": "INC-2026-0822",
              "Finding": "IL-005 High Misconfiguration: controls A.8.9, A.8.32, A.5.15, A.5.37 were less robust than Stage 2 sampled.",
              "Cited record": "IL-005 / SIR-005 / CAR-2026-027",
              "Conclusion": "Keep Implemented counts; re-sample evidence; do not treat as ISMS collapse."
            },
            {
              "Input": "CYB-CLM-2026-001",
              "Finding": "Northbridge Cyber (worked example) Denied 2026-09-03: Unapproved production change (policy requires the documented change process); No evidenced first-party loss (12-minute internal drafts; no confirmed customer data)",
              "Cited record": "RISK-2026-041 / IL-005",
              "Conclusion": "Transfer remains residual risk on Arcfield. Insurance is not a control."
            },
            {
              "Input": "Stalled improvements",
              "Finding": "The 11 Planned Annex A rows from the 2025 improvement programme have not moved. A.5.27 (learning from incidents) is still Planned after INC-2026-0822.",
              "Cited record": "SoA Planned A.5.21, A.5.27, A.5.32, A.6.4…",
              "Conclusion": "Do not mark Planned controls Implemented before first surveillance."
            }
          ]
        },
        {
          "id": "decisions_and_outputs",
          "heading": "Decisions and outputs",
          "level": 1,
          "text": "Write each output as approve, reject, defer or request more evidence. Name the owner, due date and the record that will show the follow-up.",
          "rows": [
            {
              "Decision ID": "MRMT-D001",
              "Decision / Output": "Approve weekly evidence-quality checkpoints until audit freeze.",
              "Owner": "ISMS Manager",
              "Due date": "2026-09-30",
              "Cited record": "IMPL-WB review 2026-Q3"
            },
            {
              "Decision ID": "MRMT-D002",
              "Decision / Output": "Accept the cloud admin exception only until the closure deadline with compensating monitoring.",
              "Owner": "IT Operations Manager",
              "Due date": "2026-09-30",
              "Cited record": "EXR MFA legacy exception 2026-08"
            },
            {
              "Decision ID": "MRMT-D003",
              "Decision / Output": "Require a scope and supplier-risk update for the backup supplier.",
              "Owner": "Supplier Manager",
              "Due date": "2026-09-20",
              "Cited record": "SINV backup supplier row 2026-Q3"
            },
            {
              "Decision ID": "MRMT-D004",
              "Decision / Output": "Confirm the Arcfield Platform ISMS remains in the certified state and resource the surveillance after first visit audit due April 2026.",
              "Owner": "Top Management",
              "Due date": "2026-11-01",
              "Cited record": "CA-ARCFIELD-EN-2025-04-10 / IAP"
            }
          ]
        },
        {
          "id": "action_items",
          "heading": "Action items",
          "level": 1,
          "text": "Assign every follow-up one owner, one due date and the record that will show it closed. Carry open actions into the next review.",
          "rows": [
            {
              "Action ID": "ACT-001",
              "Action": "Close the cloud admin exception or submit residual-risk acceptance.",
              "Owner": "IT Operations Manager",
              "Due date": "2026-09-30",
              "Status": "Open",
              "Cited record": "EXR MFA legacy exception 2026-08"
            },
            {
              "Action ID": "ACT-002",
              "Action": "Add the backup supplier to scope traceability and risk review.",
              "Owner": "Supplier Manager",
              "Due date": "2026-09-20",
              "Status": "Open",
              "Cited record": "ISS traceability 2026-Q3"
            },
            {
              "Action ID": "ACT-003",
              "Action": "Issue internal audit report IA-ARCFIELD-EN-2026-09-11 as 9.2 input to first surveillance.",
              "Owner": "Internal Auditor",
              "Due date": "2026-09-25",
              "Status": "Scheduled",
              "Cited record": "IAP / IA-ARCFIELD-EN-2026-09-11"
            }
          ]
        },
        {
          "id": "resource_and_improvement_decisions",
          "heading": "Resource and improvement decisions",
          "level": 1,
          "text": "Record resource and improvement decisions as named outcomes. A metric without an owner is not an output of this review.",
          "rows": [
            {
              "Item": "Evidence automation pilot",
              "Decision": "Deferred until pilot export quality is verified.",
              "Owner": "ISMS Manager",
              "Cited record": "Evidence-automation pilot 2026"
            },
            {
              "Item": "Access-review remediation",
              "Decision": "Approved as a priority corrective action.",
              "Owner": "IT Operations Manager",
              "Cited record": "CAR from internal audit 2026-Q3"
            }
          ]
        },
        {
          "id": "next_review_tracking",
          "heading": "Next review tracking",
          "level": 1,
          "text": "The next formal management review is scheduled for 2026-12-15. An interim evidence-readiness checkpoint is required by 2026-09-30. Carry ACT-001, ACT-002 and the deferred automation pilot into that sitting.",
          "values": {
            "Next review date": "2026-12-15",
            "Interim checkpoint": "2026-09-30",
            "Carry-over": "ACT-001, ACT-002, evidence automation pilot"
          }
        }
      ],
      "contentType": "minutes_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the approved parent document and the live register this record belongs to. This file cites them; it does not copy their content."
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "EXR Exceptions Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IAP Internal Audit Plan (Implementation & Certification, Internal Audit & Management Review)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IMPL-WB ISMS Implementation Workbook (Implementation & Certification, Implementation Readiness & Planning)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ],
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Minutes",
    "role": "Dated review record of the certified ISMS"
  }
}
