{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RR",
  "title": "Risk Register",
  "definitionRef": {
    "artifactId": "RR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RR.artifactDefinition.v2",
    "title": "Risk Register"
  },
  "organization": "Arcfield",
  "examplePurpose": "Realistic curated risk register data aligned with AI, RTP, and SOA.",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Risk Register",
        "Register ID": "RR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Risk Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Risk Register",
        "Register ID: RR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Risk Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example provides a Arcfield risk register aligned with assets, risk owners, CIA impacts, threats, vulnerabilities, inherent and residual scoring, treatment IDs, SoA linkage, evidence and review dates. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Track, assess, prioritize, treat, and review information security risks."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Risk Manager, Risk Owners, Asset Owners, Control Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Risk Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory ISO 27001 risk assessment record"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clauses 6.1, 8.2, 8.3 and supporting controls A.5.36, A.8.8"
        },
        {
          "Property": "Review cadence",
          "Value": "Monthly for high/open risks, after material changes, before management review, and before certification audit"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Create one row per meaningful risk scenario, not one row per generic threat.",
        "Link every risk to an affected asset, process, supplier, or ISMS requirement.",
        "Score likelihood and impact before treatment and after planned controls.",
        "Assign a role-based risk owner and treatment owner.",
        "Link each treatment decision to the Risk Treatment Plan and, where relevant, the SoA.",
        "Record evidence references and review dates.",
        "Escalate overdue high risks and residual risks above tolerance to management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose.",
        "Keep stable Risk IDs and link Treatment ID / SoA / Evidence references so the Traceability sheet can follow the chain."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "register_schema",
      "title": "Register schema",
      "schemaRef": {
        "definitionId": "RR.artifactDefinition.v2",
        "sectionId": "register_schema",
        "requiredColumnsRef": "sections.register_schema.requiredColumns"
      },
      "rows": [
        {
          "Column": "Risk ID",
          "Type": "text",
          "Required": "yes",
          "Description": "Stable unique risk identifier.",
          "Example": "RISK-2026-014"
        },
        {
          "Column": "Risk title",
          "Type": "text",
          "Required": "yes",
          "Description": "Short risk name.",
          "Example": "Unauthorized privileged access to production platform"
        },
        {
          "Column": "Asset / process at risk",
          "Type": "text",
          "Required": "yes",
          "Description": "Affected asset, process, supplier, or ISMS requirement.",
          "Example": "AST-001 Production platform"
        },
        {
          "Column": "Risk owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Accountable role for risk decision.",
          "Example": "Service Owner"
        },
        {
          "Column": "CIA affected",
          "Type": "multi-select",
          "Required": "yes",
          "Description": "Affected confidentiality, integrity, and/or availability.",
          "Example": "Confidentiality; Integrity"
        },
        {
          "Column": "Threat",
          "Type": "text",
          "Required": "yes",
          "Description": "Threat source or event.",
          "Example": "Compromised admin account"
        },
        {
          "Column": "Vulnerability / cause",
          "Type": "text",
          "Required": "yes",
          "Description": "Weakness or condition enabling the risk.",
          "Example": "Quarterly privileged access review not yet evidenced"
        },
        {
          "Column": "Consequence",
          "Type": "text",
          "Required": "yes",
          "Description": "Business or ISMS consequence.",
          "Example": "Unauthorized production changes and customer-data exposure"
        },
        {
          "Column": "Existing controls",
          "Type": "text",
          "Required": "yes",
          "Description": "Controls already in place.",
          "Example": "MFA, SSO, admin approval workflow"
        },
        {
          "Column": "Likelihood",
          "Type": "number",
          "Required": "yes",
          "Description": "1-5 inherent likelihood score.",
          "Example": "3"
        },
        {
          "Column": "Impact",
          "Type": "number",
          "Required": "yes",
          "Description": "1-5 inherent impact score.",
          "Example": "5"
        },
        {
          "Column": "Inherent score",
          "Type": "number",
          "Required": "yes",
          "Description": "Likelihood multiplied by impact.",
          "Example": "15"
        },
        {
          "Column": "Inherent rating",
          "Type": "select",
          "Required": "yes",
          "Description": "Critical, High, Medium, Low.",
          "Example": "High"
        },
        {
          "Column": "Treatment option",
          "Type": "select",
          "Required": "yes",
          "Description": "Mitigate, Avoid, Transfer, Accept.",
          "Example": "Mitigate"
        },
        {
          "Column": "Treatment ID",
          "Type": "text",
          "Required": "conditional",
          "Description": "Linked treatment action.",
          "Example": "RTP-2026-014"
        },
        {
          "Column": "Related control(s)",
          "Type": "text",
          "Required": "conditional",
          "Description": "ISO or internal controls.",
          "Example": "A.5.15, A.5.16, A.8.2"
        },
        {
          "Column": "SoA linkage",
          "Type": "text",
          "Required": "conditional",
          "Description": "SoA row or control justification reference.",
          "Example": "SOA-A.5.15"
        },
        {
          "Column": "Residual likelihood",
          "Type": "number",
          "Required": "conditional",
          "Description": "1-5 likelihood after treatment.",
          "Example": "2"
        },
        {
          "Column": "Residual impact",
          "Type": "number",
          "Required": "conditional",
          "Description": "1-5 impact after treatment.",
          "Example": "4"
        },
        {
          "Column": "Residual score",
          "Type": "number",
          "Required": "conditional",
          "Description": "Residual likelihood multiplied by residual impact.",
          "Example": "8"
        },
        {
          "Column": "Residual rating",
          "Type": "select",
          "Required": "conditional",
          "Description": "Critical, High, Medium, Low.",
          "Example": "Medium"
        },
        {
          "Column": "Status",
          "Type": "select",
          "Required": "yes",
          "Description": "Open, In treatment, Accepted, Closed.",
          "Example": "In treatment"
        },
        {
          "Column": "Last review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Most recent risk review.",
          "Example": "2026-08-29"
        },
        {
          "Column": "Next review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Next planned review.",
          "Example": "2026-10-31"
        },
        {
          "Column": "Evidence reference",
          "Type": "text",
          "Required": "yes",
          "Description": "Evidence record, ticket, or register reference.",
          "Example": "RR-RISK-2026-014-Q3"
        },
        {
          "Column": "Notes",
          "Type": "text",
          "Required": "no",
          "Description": "Assumptions, decisions, or escalation notes.",
          "Example": "Pending effectiveness check after access review."
        }
      ],
      "contentType": "schema_table"
    },
    {
      "id": "risk_register_entries",
      "title": "Risk register entries",
      "schemaRef": {
        "definitionId": "RR.artifactDefinition.v2",
        "sectionId": "risk_register_entries",
        "columnsRef": "sections.risk_register_entries.columns"
      },
      "rows": [
        {
          "Risk ID": "RISK-2026-014",
          "Risk title": "Unauthorized privileged access to production platform",
          "Asset / process at risk": "AST-001 Production platform",
          "Risk owner": "Service Owner",
          "CIA affected": "Confidentiality; Integrity",
          "Threat": "Compromised admin account",
          "Vulnerability / cause": "Quarterly privileged access review not yet evidenced",
          "Consequence": "Unauthorized production changes and customer-data exposure",
          "Existing controls": "MFA, SSO, admin approval workflow",
          "Likelihood": "3",
          "Impact": "5",
          "Inherent score": "15",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-014",
          "Related control(s)": "A.5.15, A.5.16, A.8.2",
          "SoA linkage": "SOA-A.5.15",
          "Residual likelihood": "2",
          "Residual impact": "4",
          "Residual score": "8",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-014-Q3",
          "Notes": "Effectiveness check required after Q3 access review."
        },
        {
          "Risk ID": "RISK-2026-018",
          "Risk title": "Customer Portal outage affects onboarding commitments",
          "Asset / process at risk": "AST-002 Customer Portal",
          "Risk owner": "Head of Customer Success",
          "CIA affected": "Availability",
          "Threat": "SaaS platform outage",
          "Vulnerability / cause": "Recovery expectations not fully tested with supplier",
          "Consequence": "Delayed onboarding and support commitments",
          "Existing controls": "Supplier SLA, incident process, status-page monitoring",
          "Likelihood": "2",
          "Impact": "4",
          "Inherent score": "8",
          "Inherent rating": "Medium",
          "Treatment option": "Transfer / Mitigate",
          "Treatment ID": "RTP-2026-018",
          "Related control(s)": "A.5.19, A.5.20, A.5.23, A.8.14",
          "SoA linkage": "SOA-A.5.23",
          "Residual likelihood": "2",
          "Residual impact": "3",
          "Residual score": "6",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-08-29",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-018-Q3",
          "Notes": "Supplier exit support confirmation pending."
        },
        {
          "Risk ID": "RISK-2026-021",
          "Risk title": "ISMS evidence repository loses integrity",
          "Asset / process at risk": "AST-003 ISMS evidence repository",
          "Risk owner": "ISMS Manager",
          "CIA affected": "Integrity; Availability",
          "Threat": "Accidental deletion or uncontrolled editing",
          "Vulnerability / cause": "Workspace backup and permission review not independently verified",
          "Consequence": "Audit evidence incomplete or unreliable",
          "Existing controls": "Workspace permissions, export backup",
          "Likelihood": "2",
          "Impact": "5",
          "Inherent score": "10",
          "Inherent rating": "Medium",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-021",
          "Related control(s)": "A.5.33, A.8.13",
          "SoA linkage": "SOA-A.5.33",
          "Residual likelihood": "1",
          "Residual impact": "4",
          "Residual score": "4",
          "Residual rating": "Low",
          "Status": "Open",
          "Last review date": "2026-08-28",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-021-Q3",
          "Notes": "Add quarterly evidence repository export check."
        },
        {
          "Risk ID": "RISK-2026-027",
          "Risk title": "Source repository secret exposure",
          "Asset / process at risk": "AST-004 Customer Portal source repository",
          "Risk owner": "Engineering Lead",
          "CIA affected": "Confidentiality; Integrity",
          "Threat": "Developer commits secret or token",
          "Vulnerability / cause": "Secret scanning coverage not yet validated for all repositories",
          "Consequence": "Unauthorized access to production or supplier APIs",
          "Existing controls": "Branch protection, code review, SSO",
          "Likelihood": "3",
          "Impact": "4",
          "Inherent score": "12",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-027",
          "Related control(s)": "A.8.4, A.8.5, A.8.28",
          "SoA linkage": "SOA-A.8.28",
          "Residual likelihood": "2",
          "Residual impact": "3",
          "Residual score": "6",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-08-27",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-027-Q3",
          "Notes": "Link to S-SDLC release evidence."
        },
        {
          "Risk ID": "RISK-2026-031",
          "Risk title": "Identity provider misconfiguration",
          "Asset / process at risk": "AST-005 Identity provider tenant",
          "Risk owner": "IT Operations Manager",
          "CIA affected": "Confidentiality; Integrity; Availability",
          "Threat": "Misconfigured conditional access or emergency account",
          "Vulnerability / cause": "Monthly privileged-access and configuration review not fully evidenced",
          "Consequence": "Unauthorized access or account lockout",
          "Existing controls": "MFA, conditional access, break-glass procedure",
          "Likelihood": "2",
          "Impact": "5",
          "Inherent score": "10",
          "Inherent rating": "Medium",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-031",
          "Related control(s)": "A.5.15, A.5.17, A.8.2",
          "SoA linkage": "SOA-A.5.17",
          "Residual likelihood": "1",
          "Residual impact": "5",
          "Residual score": "5",
          "Residual rating": "Low",
          "Status": "In treatment",
          "Last review date": "2026-08-29",
          "Next review date": "2026-09-30",
          "Evidence reference": "RR-RISK-2026-031-Q3",
          "Notes": "Monthly review cadence required."
        },
        {
          "Risk ID": "RISK-2026-033",
          "Risk title": "HR personnel data retained beyond requirement",
          "Asset / process at risk": "AST-006 HR personnel file repository",
          "Risk owner": "HR Manager",
          "CIA affected": "Confidentiality",
          "Threat": "Retention period exceeded",
          "Vulnerability / cause": "Retention schedule not mapped to HR repository folders",
          "Consequence": "Privacy breach or contractual nonconformity",
          "Existing controls": "HR access restriction, retention policy",
          "Likelihood": "2",
          "Impact": "4",
          "Inherent score": "8",
          "Inherent rating": "Medium",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-033",
          "Related control(s)": "A.5.31, A.5.34, A.8.10",
          "SoA linkage": "SOA-A.5.34",
          "Residual likelihood": "1",
          "Residual impact": "3",
          "Residual score": "3",
          "Residual rating": "Low",
          "Status": "Open",
          "Last review date": "2026-08-20",
          "Next review date": "2026-11-20",
          "Evidence reference": "RR-RISK-2026-033-Q3",
          "Notes": "Link retention schedule to folder review."
        },
        {
          "Risk ID": "RISK-2026-041",
          "Risk title": "Customer health records exposed from misconfigured object storage",
          "Asset / process at risk": "AST-001 Production platform (customer-data object store)",
          "Risk owner": "Cloud Service Owner",
          "CIA affected": "Confidentiality",
          "Threat": "Public or cross-tenant bucket policy",
          "Vulnerability / cause": "Object-storage policy review is not evidenced after every change",
          "Consequence": "Unauthorised disclosure of customer health and configuration data",
          "Existing controls": "Private buckets, SCP deny-public, access logging",
          "Likelihood": "2",
          "Impact": "5",
          "Inherent score": "10",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-041",
          "Related control(s)": "A.5.12, A.5.33, A.8.3",
          "SoA linkage": "SOA-A.5.33",
          "Residual likelihood": "1",
          "Residual impact": "4",
          "Residual score": "4",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-12-11",
          "Evidence reference": "RR-RISK-2026-041-Q3",
          "Notes": "Linked to ICP Restricted handling and CSP shared-responsibility split. CYB-CLM-2026-001 denied 2026-09-03: insurance Transfer is not effective until the documented change process is followed."
        },
        {
          "Risk ID": "RISK-2026-042",
          "Risk title": "Unreviewed CI/CD change reaches Arcfield Platform production",
          "Asset / process at risk": "AST-011 CI/CD",
          "Risk owner": "Engineering Lead",
          "CIA affected": "Integrity; Availability",
          "Threat": "Malicious or accidental pipeline change",
          "Vulnerability / cause": "Production deploy can proceed without two-person review on the release branch",
          "Consequence": "Integrity loss in customer tenants and downtime against onboarding commitments",
          "Existing controls": "Branch protection, signed images, change tickets",
          "Likelihood": "3",
          "Impact": "4",
          "Inherent score": "12",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-042",
          "Related control(s)": "A.8.25, A.8.28, A.8.32",
          "SoA linkage": "SOA-A.8.28",
          "Residual likelihood": "2",
          "Residual impact": "3",
          "Residual score": "6",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-042-Q3",
          "Notes": "Cite SSDP and the production change record; do not copy pipeline YAML into RR."
        },
        {
          "Risk ID": "RISK-2026-043",
          "Risk title": "Hosting supplier cannot evidence the shared-responsibility split",
          "Asset / process at risk": "AST-001 Production platform (hosting supplier)",
          "Risk owner": "Supplier Manager",
          "CIA affected": "Confidentiality; Availability",
          "Threat": "Supplier control failure or opaque subcontracting",
          "Vulnerability / cause": "Contract and assurance pack do not name the split for backups, identity and logging",
          "Consequence": "Unauditable boundary for customer data and delayed incident response",
          "Existing controls": "Supplier register, annual assurance request, incident clause",
          "Likelihood": "3",
          "Impact": "4",
          "Inherent score": "12",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-043",
          "Related control(s)": "A.5.19, A.5.21, A.5.23",
          "SoA linkage": "SOA-A.5.19",
          "Residual likelihood": "2",
          "Residual impact": "3",
          "Residual score": "6",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-30",
          "Evidence reference": "RR-RISK-2026-043-Q3",
          "Notes": "Linked to SRP and CSP. Exit clause follow-up is ISO-006."
        },
        {
          "Risk ID": "RISK-2026-044",
          "Risk title": "Privileged cloud-console session without recording",
          "Asset / process at risk": "AST-001 Production platform / cloud console",
          "Risk owner": "IT Operations Manager",
          "CIA affected": "Confidentiality; Integrity",
          "Threat": "Misuse of break-glass or admin role",
          "Vulnerability / cause": "Console sessions for production accounts are not recorded end to end",
          "Consequence": "Unauditable privileged change in customer tenants",
          "Existing controls": "MFA, PAM approval, time-bound roles",
          "Likelihood": "2",
          "Impact": "5",
          "Inherent score": "10",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-044",
          "Related control(s)": "A.8.2, A.8.5, A.8.15",
          "SoA linkage": "SOA-A.8.2",
          "Residual likelihood": "1",
          "Residual impact": "4",
          "Residual score": "4",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-044-Q3",
          "Notes": "Complements RISK-2026-014. Evidence is the PAM session export, not this row."
        },
        {
          "Risk ID": "RISK-2026-045",
          "Risk title": "Arcfield Platform backup restore untested for customer configuration",
          "Asset / process at risk": "AST-013 Backup and restore",
          "Risk owner": "Operations Lead",
          "CIA affected": "Integrity; Availability",
          "Threat": "Restore failure after ransomware or region loss",
          "Vulnerability / cause": "Restore tests cover infrastructure snapshots, not tenant configuration and attachments",
          "Consequence": "RPO/RTO missed for onboarding and support evidence",
          "Existing controls": "Daily backups, off-site copy, BRP restore drill on infrastructure",
          "Likelihood": "3",
          "Impact": "5",
          "Inherent score": "15",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-045",
          "Related control(s)": "A.5.29, A.5.30, A.8.13",
          "SoA linkage": "SOA-A.8.13",
          "Residual likelihood": "2",
          "Residual impact": "4",
          "Residual score": "8",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-12-11",
          "Evidence reference": "RR-RISK-2026-045-Q3",
          "Notes": "Cite BRP restore evidence. Linked to BCP/BIA recovery objectives."
        },
        {
          "Risk ID": "RISK-2026-046",
          "Risk title": "Support attachment with health data copied into an unapproved SaaS tool",
          "Asset / process at risk": "AST-014 Support platform",
          "Risk owner": "Incident Manager",
          "CIA affected": "Confidentiality",
          "Threat": "Shadow IT paste or unsanctioned file share",
          "Vulnerability / cause": "Support workflow allows download without a Restricted-handling check",
          "Consequence": "Customer health data leaves the approved Arcfield Platform boundary",
          "Existing controls": "ICP labels, DLP on email, approved support platform",
          "Likelihood": "3",
          "Impact": "4",
          "Inherent score": "12",
          "Inherent rating": "High",
          "Treatment option": "Mitigate",
          "Treatment ID": "RTP-2026-046",
          "Related control(s)": "A.5.10, A.5.12, A.8.12",
          "SoA linkage": "SOA-A.5.10",
          "Residual likelihood": "2",
          "Residual impact": "3",
          "Residual score": "6",
          "Residual rating": "Medium",
          "Status": "In treatment",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Evidence reference": "RR-RISK-2026-046-Q3",
          "Notes": "Linked to ICP handling rules and DSAR/DPIA records. Do not paste attachments into RR."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "register_completeness_decision",
      "title": "Register completeness decision",
      "values": {
        "Completeness result": "Complete",
        "Reviewed by": "Risk Manager",
        "Risks without owner": 0,
        "High risks without treatment": 0,
        "Risks without evidence reference": 0,
        "Risks without next review date": 0,
        "Residual risks above tolerance": 0,
        "Final status": "Audit-ready",
        "Decision date": "2026-09-11",
        "Evidence reference": "RR-COMPLETE-2026-Q3"
      },
      "rows": [
        {
          "Field": "Completeness result",
          "Value": "Complete",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Reviewed by",
          "Value": "Risk Manager",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Risks without owner",
          "Value": "0",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "High risks without treatment",
          "Value": "0",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Risks without evidence reference",
          "Value": "0",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Risks without next review date",
          "Value": "0",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Residual risks above tolerance",
          "Value": "0",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Final status",
          "Value": "Audit-ready",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-11",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Evidence reference",
          "Value": "RR-COMPLETE-2026-Q3",
          "Evidence reference": "RR-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Risk Assessment Methodology](RAM_Risk_Assessment_Methodology.docx) — Scales, thresholds and residual-acceptance rules this register cites.",
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — Asset IDs named on each live risk.",
            "[Risk Treatment Plan](RTP_Risk_Treatment_Plan.xlsx) — Treatment rows for every live Risk ID.",
            "[Risk Acceptance Minutes](RAMT_Risk_Acceptance_Minutes.docx) — Residual acceptance for this freeze."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Risk Assessment & Risk Treatment Process",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "SOA Statement of Applicability (SoA) (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
