{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RMP",
  "title": "Risk Management Plan",
  "definitionRef": {
    "artifactId": "RMP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RMP.artifactDefinition.v2",
    "title": "Risk Management Plan"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Workflow Title": "Risk Management Plan",
        "Workflow ID": "RMP-WF-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Risk Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Workflow Title: Risk Management Plan",
        "Workflow ID: RMP-WF-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Risk Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example shows the operating workflow for information security risk management at Arcfield. It connects risk criteria, scenario identification, assessment, treatment, residual-risk approval, evidence tracking and management reporting so that the risk process is auditable end to end. This is the operating method sampled on the 11 September 2026 freeze during the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "workflow_schema",
      "title": "Workflow schema",
      "steps": [
        "Define risk context and criteria",
        "Identify risk scenarios",
        "Assess likelihood and impact",
        "Evaluate risk against appetite",
        "Select treatment option",
        "Approve residual risk",
        "Track treatment evidence",
        "Report and review risk status"
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Risk Management Plan. Define the information security risk management approach, scope, roles, methodology, risk appetite, treatment process, review cadence and reporting model. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (RR, ISO, ROAR) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in RR, ISO, ROAR."
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status RMP-STEP-001 Quarterly risk review or material change Confirm scope, context, criteria and review population. Risk Manager Context changes, asset updates and interested-party requirements Risk review scope RMP-SCOPE-2026-Q3 Complete RMP-STEP-002 Review scope confirmed Identify new or changed information security risk scenarios. Risk Owner Asset inventory, incidents, supplier changes and vulnerability results Updated risk scenarios RR-2026-Q3 Complete RMP-STEP-003 Risk scenarios updated Assess likelihood, impact and inherent risk. Risk Manager Risk methodology and risk scenario details Assessed risk register RR-2026-Q3 Complete RMP-STEP-004 Risk assessment complete Select treatment option and assign treatment owner. Risk Owner Assessed risk and acceptance criteria Risk treatment plan update RTP-REVIEW-2026-Q3 Complete RMP-STEP-005 Treatment plan updated Map treatments to controls and update Statement of Applicability. ISMS Manager Treatment plan and control selection rationale Updated SoA coverage SOA-FULL-93-2026 Complete RMP-STEP-006 Residual risks require decision Review and accept or reject residual risk. Top Management Residual risk summary and treatment evidence Residual risk decision ROAR-REVIEW-2026-Q3 Open follow-up RMP-STEP-007 Quarterly reporting cycle Report high risks, overdue treatments and accepted residual risks. Risk Manager Risk register, treatment plan and KRI results Management review risk input MME-REVIEW-2026-08 Scheduled Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "RMP-STEP-001",
              "Trigger": "Quarterly risk review or material change",
              "Activity": "Confirm scope, context, criteria and review population.",
              "Responsible Role": "Risk Manager",
              "Input": "Context changes, asset updates and interested-party requirements",
              "Output": "Risk review scope",
              "Evidence Reference": "RMP-SCOPE-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-002",
              "Trigger": "Review scope confirmed",
              "Activity": "Identify new or changed information security risk scenarios.",
              "Responsible Role": "Risk Owner",
              "Input": "Asset inventory, incidents, supplier changes and vulnerability results",
              "Output": "Updated risk scenarios",
              "Evidence Reference": "RR-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-003",
              "Trigger": "Risk scenarios updated",
              "Activity": "Assess likelihood, impact and inherent risk.",
              "Responsible Role": "Risk Manager",
              "Input": "Risk methodology and risk scenario details",
              "Output": "Assessed risk register",
              "Evidence Reference": "RR-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-004",
              "Trigger": "Risk assessment complete",
              "Activity": "Select treatment option and assign treatment owner.",
              "Responsible Role": "Risk Owner",
              "Input": "Assessed risk and acceptance criteria",
              "Output": "Risk treatment plan update",
              "Evidence Reference": "RTP-REVIEW-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-005",
              "Trigger": "Treatment plan updated",
              "Activity": "Map treatments to controls and update Statement of Applicability.",
              "Responsible Role": "ISMS Manager",
              "Input": "Treatment plan and control selection rationale",
              "Output": "Updated SoA coverage",
              "Evidence Reference": "SOA-FULL-93-2026",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-006",
              "Trigger": "Residual risks require decision",
              "Activity": "Review and accept or reject residual risk.",
              "Responsible Role": "Top Management",
              "Input": "Residual risk summary and treatment evidence",
              "Output": "Residual risk decision",
              "Evidence Reference": "ROAR-REVIEW-2026-Q3",
              "Status": "Open follow-up"
            },
            {
              "Step ID": "RMP-STEP-007",
              "Trigger": "Quarterly reporting cycle",
              "Activity": "Report high risks, overdue treatments and accepted residual risks.",
              "Responsible Role": "Risk Manager",
              "Input": "Risk register, treatment plan and KRI results",
              "Output": "Management review risk input",
              "Evidence Reference": "MME-REVIEW-2026-08",
              "Status": "Scheduled"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility Top Management Approves risk criteria and accepts significant residual risks. Risk Manager Operates the risk workflow and maintains methodology, reporting and review cadence. Risk Owner Owns risk assessment input, treatment decision and residual-risk acceptance proposal. Control Owner Implements assigned controls and provides treatment evidence. ISMS Manager Ensures risk treatment and SoA alignment. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "Top Management",
              "Responsibility": "Approves risk criteria and accepts significant residual risks."
            },
            {
              "Role": "Risk Manager",
              "Responsibility": "Operates the risk workflow and maintains methodology, reporting and review cadence."
            },
            {
              "Role": "Risk Owner",
              "Responsibility": "Owns risk assessment input, treatment decision and residual-risk acceptance proposal."
            },
            {
              "Role": "Control Owner",
              "Responsibility": "Implements assigned controls and provides treatment evidence."
            },
            {
              "Role": "ISMS Manager",
              "Responsibility": "Ensures risk treatment and SoA alignment."
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks. Risks reviewed 18 High risks 3 Treatments overdue 1 Residual risks accepted 2 Open actions 3 Reviewed by Risk Manager Decision date 2026-08-29 Evidence reference RMP-REVIEW-2026-Q3 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks."
            },
            {
              "Field": "Risks reviewed",
              "Value": "18"
            },
            {
              "Field": "High risks",
              "Value": "3"
            },
            {
              "Field": "Treatments overdue",
              "Value": "1"
            },
            {
              "Field": "Residual risks accepted",
              "Value": "2"
            },
            {
              "Field": "Open actions",
              "Value": "3"
            },
            {
              "Field": "Reviewed by",
              "Value": "Risk Manager"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "RMP-REVIEW-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "workflow_schema"
    },
    {
      "id": "workflow_steps",
      "title": "Workflow steps",
      "schemaRef": {
        "definitionId": "RMP.artifactDefinition.v2",
        "sectionId": "workflow_steps"
      },
      "steps": [
        {
          "Step ID": "RMP-STEP-001",
          "Trigger": "Quarterly risk review or material change",
          "Activity": "Confirm scope, context, criteria and review population.",
          "Responsible Role": "Risk Manager",
          "Input": "Context changes, asset updates and interested-party requirements",
          "Output": "Risk review scope",
          "Evidence Reference": "RMP-SCOPE-2026-Q3",
          "Status": "Complete"
        },
        {
          "Step ID": "RMP-STEP-002",
          "Trigger": "Review scope confirmed",
          "Activity": "Identify new or changed information security risk scenarios.",
          "Responsible Role": "Risk Owner",
          "Input": "Asset inventory, incidents, supplier changes and vulnerability results",
          "Output": "Updated risk scenarios",
          "Evidence Reference": "RR-2026-Q3",
          "Status": "Complete"
        },
        {
          "Step ID": "RMP-STEP-003",
          "Trigger": "Risk scenarios updated",
          "Activity": "Assess likelihood, impact and inherent risk.",
          "Responsible Role": "Risk Manager",
          "Input": "Risk methodology and risk scenario details",
          "Output": "Assessed risk register",
          "Evidence Reference": "RR-2026-Q3",
          "Status": "Complete"
        },
        {
          "Step ID": "RMP-STEP-004",
          "Trigger": "Risk assessment complete",
          "Activity": "Select treatment option and assign treatment owner.",
          "Responsible Role": "Risk Owner",
          "Input": "Assessed risk and acceptance criteria",
          "Output": "Risk treatment plan update",
          "Evidence Reference": "RTP-REVIEW-2026-Q3",
          "Status": "Complete"
        },
        {
          "Step ID": "RMP-STEP-005",
          "Trigger": "Treatment plan updated",
          "Activity": "Map treatments to controls and update Statement of Applicability.",
          "Responsible Role": "ISMS Manager",
          "Input": "Treatment plan and control selection rationale",
          "Output": "Updated SoA coverage",
          "Evidence Reference": "SOA-FULL-93-2026",
          "Status": "Complete"
        },
        {
          "Step ID": "RMP-STEP-006",
          "Trigger": "Residual risks require decision",
          "Activity": "Review and accept or reject residual risk.",
          "Responsible Role": "Top Management",
          "Input": "Residual risk summary and treatment evidence",
          "Output": "Residual risk decision",
          "Evidence Reference": "ROAR-REVIEW-2026-Q3",
          "Status": "Open follow-up"
        },
        {
          "Step ID": "RMP-STEP-007",
          "Trigger": "Quarterly reporting cycle",
          "Activity": "Report high risks, overdue treatments and accepted residual risks.",
          "Responsible Role": "Risk Manager",
          "Input": "Risk register, treatment plan and KRI results",
          "Output": "Management review risk input",
          "Evidence Reference": "MME-REVIEW-2026-08",
          "Status": "Scheduled"
        }
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Risk Management Plan. Define the information security risk management approach, scope, roles, methodology, risk appetite, treatment process, review cadence and reporting model. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (RR, ISO, ROAR) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in RR, ISO, ROAR."
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status RMP-STEP-001 Quarterly risk review or material change Confirm scope, context, criteria and review population. Risk Manager Context changes, asset updates and interested-party requirements Risk review scope RMP-SCOPE-2026-Q3 Complete RMP-STEP-002 Review scope confirmed Identify new or changed information security risk scenarios. Risk Owner Asset inventory, incidents, supplier changes and vulnerability results Updated risk scenarios RR-2026-Q3 Complete RMP-STEP-003 Risk scenarios updated Assess likelihood, impact and inherent risk. Risk Manager Risk methodology and risk scenario details Assessed risk register RR-2026-Q3 Complete RMP-STEP-004 Risk assessment complete Select treatment option and assign treatment owner. Risk Owner Assessed risk and acceptance criteria Risk treatment plan update RTP-REVIEW-2026-Q3 Complete RMP-STEP-005 Treatment plan updated Map treatments to controls and update Statement of Applicability. ISMS Manager Treatment plan and control selection rationale Updated SoA coverage SOA-FULL-93-2026 Complete RMP-STEP-006 Residual risks require decision Review and accept or reject residual risk. Top Management Residual risk summary and treatment evidence Residual risk decision ROAR-REVIEW-2026-Q3 Open follow-up RMP-STEP-007 Quarterly reporting cycle Report high risks, overdue treatments and accepted residual risks. Risk Manager Risk register, treatment plan and KRI results Management review risk input MME-REVIEW-2026-08 Scheduled Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "RMP-STEP-001",
              "Trigger": "Quarterly risk review or material change",
              "Activity": "Confirm scope, context, criteria and review population.",
              "Responsible Role": "Risk Manager",
              "Input": "Context changes, asset updates and interested-party requirements",
              "Output": "Risk review scope",
              "Evidence Reference": "RMP-SCOPE-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-002",
              "Trigger": "Review scope confirmed",
              "Activity": "Identify new or changed information security risk scenarios.",
              "Responsible Role": "Risk Owner",
              "Input": "Asset inventory, incidents, supplier changes and vulnerability results",
              "Output": "Updated risk scenarios",
              "Evidence Reference": "RR-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-003",
              "Trigger": "Risk scenarios updated",
              "Activity": "Assess likelihood, impact and inherent risk.",
              "Responsible Role": "Risk Manager",
              "Input": "Risk methodology and risk scenario details",
              "Output": "Assessed risk register",
              "Evidence Reference": "RR-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-004",
              "Trigger": "Risk assessment complete",
              "Activity": "Select treatment option and assign treatment owner.",
              "Responsible Role": "Risk Owner",
              "Input": "Assessed risk and acceptance criteria",
              "Output": "Risk treatment plan update",
              "Evidence Reference": "RTP-REVIEW-2026-Q3",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-005",
              "Trigger": "Treatment plan updated",
              "Activity": "Map treatments to controls and update Statement of Applicability.",
              "Responsible Role": "ISMS Manager",
              "Input": "Treatment plan and control selection rationale",
              "Output": "Updated SoA coverage",
              "Evidence Reference": "SOA-FULL-93-2026",
              "Status": "Complete"
            },
            {
              "Step ID": "RMP-STEP-006",
              "Trigger": "Residual risks require decision",
              "Activity": "Review and accept or reject residual risk.",
              "Responsible Role": "Top Management",
              "Input": "Residual risk summary and treatment evidence",
              "Output": "Residual risk decision",
              "Evidence Reference": "ROAR-REVIEW-2026-Q3",
              "Status": "Open follow-up"
            },
            {
              "Step ID": "RMP-STEP-007",
              "Trigger": "Quarterly reporting cycle",
              "Activity": "Report high risks, overdue treatments and accepted residual risks.",
              "Responsible Role": "Risk Manager",
              "Input": "Risk register, treatment plan and KRI results",
              "Output": "Management review risk input",
              "Evidence Reference": "MME-REVIEW-2026-08",
              "Status": "Scheduled"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility Top Management Approves risk criteria and accepts significant residual risks. Risk Manager Operates the risk workflow and maintains methodology, reporting and review cadence. Risk Owner Owns risk assessment input, treatment decision and residual-risk acceptance proposal. Control Owner Implements assigned controls and provides treatment evidence. ISMS Manager Ensures risk treatment and SoA alignment. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "Top Management",
              "Responsibility": "Approves risk criteria and accepts significant residual risks."
            },
            {
              "Role": "Risk Manager",
              "Responsibility": "Operates the risk workflow and maintains methodology, reporting and review cadence."
            },
            {
              "Role": "Risk Owner",
              "Responsibility": "Owns risk assessment input, treatment decision and residual-risk acceptance proposal."
            },
            {
              "Role": "Control Owner",
              "Responsibility": "Implements assigned controls and provides treatment evidence."
            },
            {
              "Role": "ISMS Manager",
              "Responsibility": "Ensures risk treatment and SoA alignment."
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks. Risks reviewed 18 High risks 3 Treatments overdue 1 Residual risks accepted 2 Open actions 3 Reviewed by Risk Manager Decision date 2026-08-29 Evidence reference RMP-REVIEW-2026-Q3 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks."
            },
            {
              "Field": "Risks reviewed",
              "Value": "18"
            },
            {
              "Field": "High risks",
              "Value": "3"
            },
            {
              "Field": "Treatments overdue",
              "Value": "1"
            },
            {
              "Field": "Residual risks accepted",
              "Value": "2"
            },
            {
              "Field": "Open actions",
              "Value": "3"
            },
            {
              "Field": "Reviewed by",
              "Value": "Risk Manager"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "RMP-REVIEW-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "workflow_steps"
    },
    {
      "id": "roles_and_responsibilities",
      "title": "Roles and responsibilities",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Role": "Top Management",
              "Responsibility": "Approves risk criteria and accepts significant residual risks."
            },
            {
              "Role": "Risk Manager",
              "Responsibility": "Operates the risk workflow and maintains methodology, reporting and review cadence."
            },
            {
              "Role": "Risk Owner",
              "Responsibility": "Owns risk assessment input, treatment decision and residual-risk acceptance proposal."
            },
            {
              "Role": "Control Owner",
              "Responsibility": "Implements assigned controls and provides treatment evidence."
            },
            {
              "Role": "ISMS Manager",
              "Responsibility": "Ensures risk treatment and SoA alignment."
            }
          ]
        }
      ],
      "contentType": "role_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "review_and_decision",
      "title": "Review and decision",
      "values": {
        "Decision": "Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks.",
        "Risks reviewed": 18,
        "High risks": 3,
        "Treatments overdue": 1,
        "Residual risks accepted": 2,
        "Open actions": 3,
        "Reviewed by": "Risk Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "RMP-REVIEW-2026-Q3"
      },
      "groups": [
        {},
        {
          "rows": [
            {
              "Field": "Decision",
              "Value": "Risk workflow approved for Q3 operation with management follow-up on residual supplier and access risks."
            },
            {
              "Field": "Risks reviewed",
              "Value": "18"
            },
            {
              "Field": "High risks",
              "Value": "3"
            },
            {
              "Field": "Treatments overdue",
              "Value": "1"
            },
            {
              "Field": "Residual risks accepted",
              "Value": "2"
            },
            {
              "Field": "Open actions",
              "Value": "3"
            },
            {
              "Field": "Reviewed by",
              "Value": "Risk Manager"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29"
            },
            {
              "Field": "Evidence reference",
              "Value": "RMP-REVIEW-2026-Q3"
            }
          ]
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RR Risk Register (Building the ISMS, Planning, Risk & Objectives (Clause 6))",
              "href": "RR_Risk_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ROAR ISMS Risks and Opportunities Register (Implementation & Certification, Asset Management & Information Classification)",
              "href": "ROAR_ISMS_Risks_and_Opportunities_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "href": "RTP_Risk_Treatment_Plan_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "MME Monitoring and Measurement Evidence (Implementation & Certification, Monitoring, Measurement & Performance Metrics)",
              "href": "MME_Monitoring_and_Measurement_Evidence_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Information Security Policies & Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Procedure",
    "role": "Operating method used on the 11 September 2026 freeze"
  }
}
