{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RACI",
  "title": "ISMS RACI Matrix",
  "definitionRef": {
    "artifactId": "RACI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RACI.artifactDefinition.v2",
    "title": "ISMS RACI Matrix"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Matrix Title": "ISMS RACI Matrix",
        "Matrix ID": "RACI-MTX-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Matrix Title: ISMS RACI Matrix",
        "Matrix ID: RACI-MTX-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example assigns Arcfield ISMS responsibilities and authorities with one accountable role per activity, responsible roles, consulted and informed stakeholders, confirmation status and evidence. This matrix is the mapping used by the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Make ISMS roles, responsibilities and authorities explicit and auditable across the usual ISMS processes."
        },
        {
          "Property": "Used by",
          "Value": "Top Management, ISMS Manager, Process Owners, Control Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory Clause 5.3 roles and responsibilities evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 5.3, supported by Clauses 4–10 and relevant Annex A operating processes"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after major role, scope or process changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Define one row per usual ISMS process or recurring activity.",
        "Assign exactly one Accountable role per row.",
        "Add Responsible, Consulted and Informed roles.",
        "Add the named individual or group currently holding the assignment.",
        "Record backup owner, confirmation status, confirmation date and evidence.",
        "Update the change-log reference whenever responsibilities change.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "raci_matrix",
      "title": "RACI matrix",
      "schemaRef": {
        "definitionId": "RACI.artifactDefinition.v2",
        "sectionId": "raci_matrix",
        "columnsRef": "sections.raci_matrix.columns"
      },
      "rows": [
        {
          "Process or Activity": "Define and maintain ISMS scope",
          "ISO Reference": "Clause 4.3",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Compliance Lead",
          "Consulted Roles": "Support Operations Manager; IT Operations Manager; Legal Counsel",
          "Informed Roles": "Top Management; Internal Auditor",
          "Named Individual or Group": "ISMS Office",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-12",
          "Evidence Reference": "ISS-SCOPE-2026-Q3",
          "Change Log Reference": "ISMS-CHG-001",
          "Notes": "Support operations scope extension in progress."
        },
        {
          "Process or Activity": "Maintain information security policy",
          "ISO Reference": "Clause 5.2",
          "Accountable Role": "CEO",
          "Responsible Role": "ISMS Manager",
          "Consulted Roles": "Legal Counsel; HR Manager; IT Manager",
          "Informed Roles": "All employees and contractors",
          "Named Individual or Group": "Top Management",
          "Backup Owner": "COO",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-01",
          "Evidence Reference": "ISP-001",
          "Change Log Reference": "DAL-2026-001",
          "Notes": "Policy communication tracked in awareness evidence."
        },
        {
          "Process or Activity": "Assign ISMS roles, responsibilities and authorities",
          "ISO Reference": "Clause 5.3",
          "Accountable Role": "Top Management",
          "Responsible Role": "ISMS Manager",
          "Consulted Roles": "Process Owners; HR Manager",
          "Informed Roles": "Control Owners; Internal Auditor",
          "Named Individual or Group": "ISMS Governance Board",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "RACI-REVIEW-2026-Q3",
          "Change Log Reference": "DAL-2026-006",
          "Notes": "One accountable role enforced for each activity."
        },
        {
          "Process or Activity": "Plan ISMS objectives and improvement targets",
          "ISO Reference": "Clause 6.2",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Process Owners",
          "Consulted Roles": "Top Management; Data Protection Lead; Security Operations Lead",
          "Informed Roles": "Internal Auditor",
          "Named Individual or Group": "ISMS Office",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "ISO-REVIEW-2026-Q3",
          "Change Log Reference": "OBJ-CHG-2026-Q3",
          "Notes": "Two objectives flagged for management attention."
        },
        {
          "Process or Activity": "Perform information security risk assessment",
          "ISO Reference": "Clause 6.1.2; Clause 8.2",
          "Accountable Role": "Compliance Lead",
          "Responsible Role": "Risk Owners",
          "Consulted Roles": "System Owners; Supplier Manager; Data Protection Lead",
          "Informed Roles": "ISMS Manager; Top Management",
          "Named Individual or Group": "Risk Committee",
          "Backup Owner": "ISMS Manager",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-20",
          "Evidence Reference": "RR-2026-Q3",
          "Change Log Reference": "DAL-2026-004",
          "Notes": "Supplier concentration scoring added."
        },
        {
          "Process or Activity": "Maintain risk treatment plan",
          "ISO Reference": "Clause 6.1.3; Clause 8.3",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Risk Owners; Control Owners",
          "Consulted Roles": "Risk Committee; IT Manager; Supplier Manager",
          "Informed Roles": "Top Management; Internal Auditor",
          "Named Individual or Group": "ISMS Office",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed with action open",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "RTP-STATUS-2026-Q3",
          "Change Log Reference": "RTP-CHG-2026-Q3",
          "Notes": "One high-risk treatment overdue."
        },
        {
          "Process or Activity": "Maintain Statement of Applicability",
          "ISO Reference": "Clause 6.1.3 d",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Control Owners",
          "Consulted Roles": "Risk Committee; Internal Auditor",
          "Informed Roles": "Top Management",
          "Named Individual or Group": "ISMS Manager",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "SOA-FULL-93-2026",
          "Change Log Reference": "SOA-CHG-2026-Q3",
          "Notes": "All Annex A controls covered."
        },
        {
          "Process or Activity": "Control documented information",
          "ISO Reference": "Clause 7.5",
          "Accountable Role": "Document Control Owner",
          "Responsible Role": "Document Owners",
          "Consulted Roles": "ISMS Manager; Internal Auditor",
          "Informed Roles": "Process Owners",
          "Named Individual or Group": "Document Control Function",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "DOC-LIST-2026-Q3",
          "Change Log Reference": "DOC-CHG-2026-Q3",
          "Notes": "Controlled document repository reconciled with MDR."
        },
        {
          "Process or Activity": "Manage competence, awareness and training",
          "ISO Reference": "Clause 7.2; Clause 7.3",
          "Accountable Role": "HR Manager",
          "Responsible Role": "Training Coordinator",
          "Consulted Roles": "ISMS Manager; Process Owners",
          "Informed Roles": "Top Management",
          "Named Individual or Group": "HR and Training Team",
          "Backup Owner": "ISMS Manager",
          "Confirmation Status": "Confirmed with action open",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "TRAIN-REC-2026-188",
          "Change Log Reference": "TR-CHG-2026-Q3",
          "Notes": "Contractor reminders open."
        },
        {
          "Process or Activity": "Operate asset inventory and ownership",
          "ISO Reference": "A 5.9",
          "Accountable Role": "Asset Manager",
          "Responsible Role": "System Owners; Service Owners",
          "Consulted Roles": "IT Operations Manager; ISMS Manager",
          "Informed Roles": "Internal Auditor",
          "Named Individual or Group": "Asset Management Function",
          "Backup Owner": "IT Operations Manager",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "ASSET-INV-2026-Q3",
          "Change Log Reference": "AAR-CHG-2026-Q3",
          "Notes": "Cloud service inventory reconciliation pending."
        },
        {
          "Process or Activity": "Manage supplier security and third-party risk",
          "ISO Reference": "A 5.19-A 5.23",
          "Accountable Role": "Supplier Manager",
          "Responsible Role": "Service Owners",
          "Consulted Roles": "Legal Counsel; Compliance Lead; Data Protection Lead",
          "Informed Roles": "ISMS Manager; Top Management",
          "Named Individual or Group": "Supplier Management",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed with action open",
          "Confirmation Date": "2026-08-15",
          "Evidence Reference": "SINV-REVIEW-2026-Q3",
          "Change Log Reference": "LRR-005",
          "Notes": "CloudHost addendum pending."
        },
        {
          "Process or Activity": "Manage identity and access lifecycle",
          "ISO Reference": "A 5.15-A 5.18; A 8.2-A 8.3",
          "Accountable Role": "IT Operations Manager",
          "Responsible Role": "IT Operations; System Owners",
          "Consulted Roles": "HR Manager; Security Lead; ISMS Manager",
          "Informed Roles": "Internal Auditor",
          "Named Individual or Group": "IT Operations",
          "Backup Owner": "Security Lead",
          "Confirmation Status": "Partially confirmed",
          "Confirmation Date": "2026-08-28",
          "Evidence Reference": "JOINER-MOVER-LEAVER-2026-Q3",
          "Change Log Reference": "EXR-001",
          "Notes": "Cloud admin review pending."
        },
        {
          "Process or Activity": "Operate security monitoring and event logging",
          "ISO Reference": "A 8.15-A 8.16",
          "Accountable Role": "Security Operations Lead",
          "Responsible Role": "Security Analysts; Platform Lead",
          "Consulted Roles": "IT Operations Manager; Incident Manager",
          "Informed Roles": "ISMS Manager",
          "Named Individual or Group": "Security Operations",
          "Backup Owner": "IT Operations Manager",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "SIEM-LOG-REVIEW-2026-Q3",
          "Change Log Reference": "SOC-CHG-2026-Q3",
          "Notes": "Critical alert review cadence confirmed."
        },
        {
          "Process or Activity": "Coordinate incident management and response",
          "ISO Reference": "A 5.24-A 5.28",
          "Accountable Role": "Incident Manager",
          "Responsible Role": "Security Lead; IT Operations Manager",
          "Consulted Roles": "Legal Counsel; Supplier Manager; Communications Owner",
          "Informed Roles": "Top Management; Data Protection Lead",
          "Named Individual or Group": "Incident Response Team",
          "Backup Owner": "Security Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "SIR-REVIEW-2026-08",
          "Change Log Reference": "IRRT-REVIEW-2026-08",
          "Notes": "Supplier incident final report pending."
        },
        {
          "Process or Activity": "Manage business continuity and ICT readiness",
          "ISO Reference": "A 5.29-A 5.30; A 8.14",
          "Accountable Role": "Business Continuity Manager",
          "Responsible Role": "IT Operations Manager; Process Owners",
          "Consulted Roles": "ISMS Manager; Supplier Manager",
          "Informed Roles": "Top Management",
          "Named Individual or Group": "Continuity Working Group",
          "Backup Owner": "Operations Manager",
          "Confirmation Status": "Scheduled",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "BIA-BCP-2026-Q3",
          "Change Log Reference": "BCP-CHG-2026-Q3",
          "Notes": "Recovery exercise scheduled for Q4."
        },
        {
          "Process or Activity": "Manage vulnerability and technical change control",
          "ISO Reference": "A 8.8; A 8.9; A 8.32",
          "Accountable Role": "IT Manager",
          "Responsible Role": "Platform Lead; Engineering Lead",
          "Consulted Roles": "Security Operations Lead; Change Advisory Group",
          "Informed Roles": "ISMS Manager; Service Owners",
          "Named Individual or Group": "Technology Operations",
          "Backup Owner": "Platform Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "VULN-CHANGE-2026-Q3",
          "Change Log Reference": "CAB-2026-Q3",
          "Notes": "Linux baseline exceptions approved."
        },
        {
          "Process or Activity": "Monitor ISMS performance and KPIs",
          "ISO Reference": "Clause 9.1",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Compliance Lead; Process Owners",
          "Consulted Roles": "Internal Auditor; Top Management",
          "Informed Roles": "Control Owners",
          "Named Individual or Group": "ISMS Office",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "MME-DASH-2026-Q3",
          "Change Log Reference": "KPI-CHG-2026-Q3",
          "Notes": "Dashboard SLA chart pending."
        },
        {
          "Process or Activity": "Plan and perform internal audit",
          "ISO Reference": "Clause 9.2",
          "Accountable Role": "Internal Auditor",
          "Responsible Role": "Audit Team",
          "Consulted Roles": "ISMS Manager; Evidence Owners",
          "Informed Roles": "Top Management; Process Owners",
          "Named Individual or Group": "Internal Audit Function",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Scheduled",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "IAP-PLAN-2026-Q4",
          "Change Log Reference": "AUDIT-FREEZE-2026-Q3",
          "Notes": "Evidence freeze planned."
        },
        {
          "Process or Activity": "Conduct management review",
          "ISO Reference": "Clause 9.3",
          "Accountable Role": "Top Management",
          "Responsible Role": "ISMS Manager",
          "Consulted Roles": "Internal Auditor; Process Owners; Risk Committee",
          "Informed Roles": "Control Owners",
          "Named Individual or Group": "Management Review Board",
          "Backup Owner": "COO",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-12",
          "Evidence Reference": "MRART-2026-Q3",
          "Change Log Reference": "MR-DEC-2026-Q3",
          "Notes": "Quarterly cadence approved."
        },
        {
          "Process or Activity": "Manage nonconformities and corrective actions",
          "ISO Reference": "Clause 10.1",
          "Accountable Role": "ISMS Manager",
          "Responsible Role": "Process Owners",
          "Consulted Roles": "Internal Auditor; Top Management",
          "Informed Roles": "Affected Control Owners",
          "Named Individual or Group": "Corrective Action Owners",
          "Backup Owner": "Compliance Lead",
          "Confirmation Status": "Confirmed",
          "Confirmation Date": "2026-08-29",
          "Evidence Reference": "CAPA-EFF-2026-Q3",
          "Change Log Reference": "NC-CAPA-2026-Q3",
          "Notes": "Effectiveness review scheduled."
        }
      ],
      "contentType": "matrix_table"
    },
    {
      "id": "raci_review_decision",
      "title": "RACI review decision",
      "values": {
        "Review result": "Twenty usual ISMS processes reviewed; every row has one accountable role and four confirmations need follow-up.",
        "Activities reviewed": 20,
        "Rows with one accountable role": 20,
        "Confirmations pending": 4,
        "Open role conflicts": 0,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "RACI-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Twenty usual ISMS processes reviewed; every row has one accountable role and four confirmations need follow-up."
        },
        {
          "Field": "Activities reviewed",
          "Value": "20"
        },
        {
          "Field": "Rows with one accountable role",
          "Value": "20"
        },
        {
          "Field": "Confirmations pending",
          "Value": "4"
        },
        {
          "Field": "Open role conflicts",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "RACI-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 5.3",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Team, Roles & Responsibilities",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "DAL Decision and Action Log (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "BCP Business Continuity Plan (BCP) (Building the ISMS, Business Continuity & Disaster Recovery)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Matrix",
    "role": "Mapping or selection used by the certified ISMS"
  }
}
