{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "RAMT.artifactDefinition.v2",
  "artifactId": "RAMT",
  "title": "Risk Acceptance Minutes",
  "artifactType": "Minutes",
  "format": "docx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable body in this Contract and the matching Example JSON",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Document and approve residual risk acceptance decisions with conditions and review dates.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Acceptance without Risk ID, residual rating, expiry and monitoring is not audit-ready.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "change_log",
      "title": "Revision history",
      "contentType": "revision_table",
      "required": true
    },
    {
      "order": 5,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Apply Instructions with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    },
    {
      "order": 6,
      "id": "minutes_template_content",
      "title": "Minutes",
      "contentType": "minutes_sections",
      "required": true,
      "hint": {
        "text": "Apply Minutes with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      },
      "minimumExampleRows": 6
    },
    {
      "order": 9,
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "contentType": "register_table",
      "required": true,
      "hint": {
        "text": "Apply Evidence and records with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    },
    {
      "order": 10,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true,
      "hint": {
        "text": "Apply References with named owners, systems and exportable evidence. Do not leave this chapter as a heading plus a bare table.",
        "bookReference": "Volume 1, S-00-03-00 Planning, Risk & Objectives (Clause 6)"
      }
    }
  ],
  "validationRules": [
    "{'id': 'required-sections-present', 'description': 'All required Contract sections must be present in the Example.'}",
    "{'id': 'example-matches-schema-columns', 'description': 'Example table rows should use the Contract column names for schema-backed sections.'}"
  ],
  "generation": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Contract.json and Example.json are SSOT."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022 9.3",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Primary clause this minutes implements or evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this file by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-00-03-00",
        "chapterTitle": "Planning, Risk & Objectives (Clause 6)",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/dp/9789908983448"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 1,
        "volumeTitle": "Building the ISMS",
        "chapterId": "S-02-01-00",
        "chapterTitle": "Information Security Policies & Risk Management",
        "primary": false,
        "role": "Policy framework and risk-based operation.",
        "href": "https://www.amazon.com/dp/9789908983448"
      }
    ],
    "purpose": "Document and approve residual risk acceptance decisions with conditions and review dates.",
    "requiredEditorialElements": [
      "introduction as purpose prose",
      "scope of this document versus neighbouring records",
      "terms as a first-class group",
      "worked Arcfield example",
      "practical examples, pitfalls, evidence and external references"
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "RAM",
        "longForm": "Risk Assessment Methodology"
      },
      {
        "abbr": "RR",
        "longForm": "Risk Register"
      },
      {
        "abbr": "SoA",
        "longForm": "Statement of Applicability"
      },
      {
        "abbr": "ISP",
        "longForm": "Information Security Policy"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "DPIA",
        "longForm": "Data Protection Impact Assessment"
      },
      {
        "abbr": "RAMT",
        "longForm": "Risk Acceptance Minutes"
      },
      {
        "abbr": "RTP",
        "longForm": "Risk Treatment Plan"
      }
    ],
    "must": [
      "State the golden thread from this file to neighbouring records (RAM, RR, SoA). This file does not duplicate those records."
    ],
    "mustNot": [
      "Do not replace this artifact's function with a shared family skeleton (operating_rules, systems_and_records)."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, cloud, CI/CD, privileged access or supplier interfaces where they affect this artifact."
    ],
    "exampleBody": {
      "sectionId": "minutes_template_content",
      "workedExampleOrg": "Arcfield",
      "minBodyWords": 400,
      "requiredGroups": [
        {
          "id": "introduction",
          "heading": "What these minutes are",
          "mustInclude": [
            "Arcfield"
          ]
        },
        {
          "id": "scope",
          "heading": "Scope",
          "mustInclude": [
            "how-to"
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "mustInclude": [
            "how-to"
          ]
        },
        {
          "id": "attendance",
          "heading": "Attendance and independence",
          "mustInclude": [
            "how-to"
          ]
        },
        {
          "id": "decision_record",
          "heading": "Decision record",
          "mustInclude": [
            "how-to"
          ]
        },
        {
          "id": "conditions",
          "heading": "Conditions and expiry",
          "mustInclude": [
            "how-to"
          ]
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "mustInclude": [
            "how-to"
          ]
        }
      ],
      "requiredSections": [
        {
          "id": "change_log",
          "title": "Revision history",
          "role": "Versioned freeze log with how-to sentence and rows Version, Date, Change, Approved by. Last Version matches title_page.values.Version."
        },
        {
          "id": "external_references",
          "title": "References",
          "role": "ISO clauses, book chapters and companion artifacts. Not a series catalogue."
        }
      ]
    }
  },
  "editorialContractId": "editorial.docx.minutes.v1",
  "contentContractId": "content.minutes.v1"
}
