{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RAMT",
  "title": "Risk Acceptance Minutes",
  "definitionRef": {
    "artifactId": "RAMT",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RAMT.artifactDefinition.v2",
    "title": "Risk Acceptance Minutes"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Risk Acceptance Minutes",
        "Document ID": "RISK-ACCEPT-MIN-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Risk Owner / Top Management (as required by appetite)",
        "Classification": "Confidential",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Risk Acceptance Minutes",
        "Document ID: RISK-ACCEPT-MIN-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Risk Owner / Top Management (as required by appetite)",
        "Classification: Confidential",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "These minutes record formal decisions to accept residual information-security risk that remains after treatment, or to accept risk temporarily with conditions. They capture the risk ID, residual rating, rationale, conditions, expiry, approver authority and monitoring requirements. They are not a risk-assessment methodology. These minutes record a dated review of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Risk Owner / Top Management (as required by appetite)"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Risk Owner / Top Management (as required by appetite)"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "minutes_template_content",
      "title": "Minutes",
      "groups": [
        {
          "id": "introduction",
          "heading": "What these minutes are",
          "level": 1,
          "text": "These minutes are Arcfield's Risk Acceptance Minutes (RAMT). They freeze one residual-risk acceptance against the published Risk Assessment Methodology (RAM): risk identity, inherent and residual ratings, treatment already taken, compensating controls, authority, expiry and reassess triggers. They are not RAM, not the live Risk Register (RR) row and not the Statement of Applicability (SoA). Top Management, the Risk Manager and audit use this Document Control version to show who accepted what, until when. Cite this version from RR. Do not copy the method into these minutes."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In these minutes": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in these minutes": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in RAM, RR, SoA."
            },
            {
              "In these minutes": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in these minutes": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Residual rating",
              "Meaning": "The RAM band after treatment. These minutes record acceptance; they do not recalibrate scales."
            },
            {
              "Term": "Condition",
              "Meaning": "A time-bound limit on the acceptance. Expiry without review withdraws the acceptance."
            },
            {
              "Term": "RAMT",
              "Meaning": "Risk Acceptance Minutes. One acceptance decision per freeze."
            },
            {
              "Term": "RR",
              "Meaning": "Risk Register. The live row cites this Document Control version."
            }
          ]
        },
        {
          "id": "attendance",
          "heading": "Attendance and independence",
          "level": 1,
          "text": "Record who sat this freeze, who chaired it and who took the minutes. The risk owner must not be the sole approver for residual High or Critical. Independence is a named role, not a team inbox.",
          "rows": [
            {
              "Role": "Risk owner",
              "Name": "Supplier Manager",
              "Present": "Yes",
              "Independence": "Cannot be the sole approver for residual High or Critical"
            },
            {
              "Role": "Acceptance authority",
              "Name": "Top Management",
              "Present": "Yes",
              "Independence": "Approves residual Medium and above under RAM"
            },
            {
              "Role": "Second assessor / recorder",
              "Name": "ISMS Manager",
              "Present": "Yes",
              "Independence": "Not the risk owner"
            }
          ],
          "values": {
            "Meeting date": "2026-08-29",
            "Mode": "Video",
            "Chair": "Top Management",
            "Recorder": "ISMS Manager",
            "Document Control version cited": "1.1",
            "Decision": "Accepted with conditions"
          }
        },
        {
          "id": "decision_record",
          "heading": "Decision record",
          "level": 1,
          "text": "Copy these fields into RR. Do not accept a residual rating that RAM has not published.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Accepted with conditions"
            },
            {
              "Field": "Expiry",
              "Value": "2026-12-15 unless a new RAMT freeze is approved"
            },
            {
              "Field": "Risk ID",
              "Value": "R-021"
            },
            {
              "Field": "Risk title",
              "Value": "Supplier DPIA gaps for imaging SaaS on Arcfield Platform"
            },
            {
              "Field": "Inherent rating",
              "Value": "High"
            },
            {
              "Field": "Residual rating",
              "Value": "Medium"
            },
            {
              "Field": "Treatment taken",
              "Value": "Contractual clauses and compensating monitoring"
            },
            {
              "Field": "Related SoA controls",
              "Value": "A.5.19, A.5.21"
            }
          ]
        },
        {
          "id": "conditions",
          "heading": "Conditions and expiry",
          "level": 1,
          "text": "Expiry without review withdraws the acceptance. Do not wait for the quarterly cycle when the supplier's DPIA status changes.",
          "items": [
            "Acceptance expires 2026-12-15 unless a new RAMT freeze is approved.",
            "Reassess immediately after a supplier incident, DPIA refusal or Arcfield Platform architecture change that widens imaging data flow.",
            "Compensating control: weekly access review of the supplier's production connector, evidence in the supplier register."
          ]
        },
        {
          "id": "cadence_and_triggers",
          "heading": "Cadence and triggers",
          "level": 1,
          "text": "These minutes are a freeze. A changed residual band is a new RAMT version and a new RR citation. Do not edit an approved decision in place."
        }
      ],
      "contentType": "minutes_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the approved parent document and the live register this record belongs to. This file cites them; it does not copy their content."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Planning, Risk & Objectives (Clause 6)",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "DPIA Data Protection Impact Assessment (Dual Compliance, ISO 27001 & EU Data Act)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ],
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Minutes",
    "role": "Dated review record of the certified ISMS"
  }
}
