{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SINV",
  "title": "Supplier Inventory",
  "definitionRef": {
    "artifactId": "SINV",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SINV.artifactDefinition.v2",
    "title": "Supplier Inventory"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Supplier Inventory",
        "Register ID": "SINV-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Supplier Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Supplier Inventory",
        "Register ID: SINV-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Supplier Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield security-relevant suppliers with tiering, criticality, data or asset access, personal-data exposure, due diligence, contractual safeguards, subprocessors, exit planning, review cadence and evidence. This inventory is the in-scope Arcfield Platform set on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001. The operating set is about 35 vendors with about 10 critical subprocessors; this Example samples the critical rows, not the full vendor list.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain a controlled inventory of security-relevant suppliers."
        },
        {
          "Property": "Used by",
          "Value": "Supplier Manager, Service Owners, ISMS Manager, Legal Counsel, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Supplier Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Supplier relationship security and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.19, A.5.20, A.5.21, A.5.22 and A.5.23"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly for critical suppliers; semi-annually or annually for lower-tier suppliers"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Register suppliers that affect information security, privacy, service continuity or audit evidence.",
        "Assign a supplier owner, tier and criticality.",
        "Record data or assets accessed, personal-data relevance and due diligence status.",
        "Confirm contract security schedules, subprocessor visibility and exit plans.",
        "Link current evidence and next review date.",
        "Escalate missing evidence or contractual gaps before renewal or management review.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "supplier_inventory",
      "title": "Supplier inventory",
      "schemaRef": {
        "definitionId": "SINV.artifactDefinition.v2",
        "sectionId": "supplier_inventory",
        "columnsRef": "sections.supplier_inventory.columns"
      },
      "rows": [
        {
          "Supplier ID": "SINV-001",
          "Supplier Name": "CloudHost Analytics",
          "Service": "Hosted analytics platform",
          "Owner": "Supplier Manager",
          "Supplier Tier": "Tier 1",
          "Criticality": "Critical",
          "Data or Assets Accessed": "Customer analytics metadata and service availability dependencies",
          "Personal Data": "Limited customer contact metadata",
          "Due Diligence Status": "Current with action open",
          "Contract Security Schedule": "Security addendum active; breach-notification update pending",
          "Subprocessors": "Subprocessor list reviewed quarterly",
          "Exit Plan": "Export customer metadata and migrate dashboards within 30 days",
          "Review Cadence": "Quarterly",
          "Next Review Date": "2026-09-10",
          "Status": "Action open",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Notes": "Linked to EXR-002 and LRR-005."
        },
        {
          "Supplier ID": "SINV-002",
          "Supplier Name": "CloudDesk Support",
          "Service": "Customer support ticketing",
          "Owner": "Support Operations Manager",
          "Supplier Tier": "Tier 1",
          "Criticality": "High",
          "Data or Assets Accessed": "Confidential support tickets and customer contact details",
          "Personal Data": "Yes",
          "Due Diligence Status": "Current",
          "Contract Security Schedule": "DPA and security schedule approved",
          "Subprocessors": "Reviewed; EU hosting subprocessors documented",
          "Exit Plan": "Ticket export and support workflow migration plan approved",
          "Review Cadence": "Quarterly",
          "Next Review Date": "2026-10-15",
          "Status": "Active",
          "Evidence Reference": "SINV-CLOUDDESK-2026-Q3",
          "Notes": "Added after support operations entered ISMS scope."
        },
        {
          "Supplier ID": "SINV-003",
          "Supplier Name": "Arcfield Identity Provider",
          "Service": "Identity and access management",
          "Owner": "IT Operations Manager",
          "Supplier Tier": "Tier 1",
          "Criticality": "Critical",
          "Data or Assets Accessed": "User identity data, access logs and authentication configuration",
          "Personal Data": "Yes",
          "Due Diligence Status": "Current",
          "Contract Security Schedule": "Security schedule and MFA commitments approved",
          "Subprocessors": "Reviewed through supplier trust portal",
          "Exit Plan": "Federation migration and account export runbook maintained",
          "Review Cadence": "Quarterly",
          "Next Review Date": "2026-09-30",
          "Status": "Active",
          "Evidence Reference": "ARR-2026-08",
          "Notes": "Privileged access review follow-up tracked separately."
        },
        {
          "Supplier ID": "SINV-004",
          "Supplier Name": "SecureBuild CI",
          "Service": "Build and deployment pipeline",
          "Owner": "Engineering Lead",
          "Supplier Tier": "Tier 2",
          "Criticality": "High",
          "Data or Assets Accessed": "Source code, build secrets and deployment metadata",
          "Personal Data": "No customer personal data",
          "Due Diligence Status": "Current",
          "Contract Security Schedule": "Security terms and support SLA approved",
          "Subprocessors": "Reviewed annually",
          "Exit Plan": "Repository and runner migration documented",
          "Review Cadence": "Semi-annual",
          "Next Review Date": "2026-11-15",
          "Status": "Active",
          "Evidence Reference": "CIL-2026-Q3",
          "Notes": "Supports secure development evidence."
        },
        {
          "Supplier ID": "SINV-005",
          "Supplier Name": "EvidenceHub",
          "Service": "Audit evidence collection pilot",
          "Owner": "Internal Auditor",
          "Supplier Tier": "Tier 3",
          "Criticality": "Medium",
          "Data or Assets Accessed": "Internal audit evidence and control metadata",
          "Personal Data": "Limited employee identifiers",
          "Due Diligence Status": "Pilot review approved",
          "Contract Security Schedule": "Pilot terms approved; full schedule required before production",
          "Subprocessors": "Initial list reviewed",
          "Exit Plan": "Export evidence index and delete pilot tenant",
          "Review Cadence": "Monthly during pilot",
          "Next Review Date": "2026-10-01",
          "Status": "Pilot",
          "Evidence Reference": "ELAI-AUTO-2026-PILOT",
          "Notes": "Effectiveness review after first access-review cycle."
        },
        {
          "Supplier ID": "SINV-006",
          "Supplier Name": "SecureMail Services",
          "Service": "Email security gateway",
          "Owner": "Security Lead",
          "Supplier Tier": "Tier 2",
          "Criticality": "High",
          "Data or Assets Accessed": "Email metadata and malicious message samples",
          "Personal Data": "Limited message metadata",
          "Due Diligence Status": "Current",
          "Contract Security Schedule": "Security schedule and incident notice route approved",
          "Subprocessors": "Reviewed annually",
          "Exit Plan": "DNS cutover and message-filter rollback plan maintained",
          "Review Cadence": "Semi-annual",
          "Next Review Date": "2026-12-01",
          "Status": "Active",
          "Evidence Reference": "ICL-004",
          "Notes": "Supports phishing reporting and incident response."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "supplier_review_decision",
      "title": "Supplier review decision",
      "values": {
        "Review result": "Six suppliers reviewed; one critical supplier has a contractual action open and all critical suppliers have evidence references.",
        "Suppliers reviewed": 6,
        "Critical suppliers": 2,
        "Open supplier actions": "Complete CloudHost breach-notification addendum and update LRR evidence.",
        "Next review focus": "CloudHost addendum, EvidenceHub pilot readiness and identity-provider access evidence.",
        "Reviewed by": "Supplier Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "SINV-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Six suppliers reviewed; one critical supplier has a contractual action open and all critical suppliers have evidence references."
        },
        {
          "Field": "Suppliers reviewed",
          "Value": "6"
        },
        {
          "Field": "Critical suppliers",
          "Value": "2"
        },
        {
          "Field": "Open supplier actions",
          "Value": "Complete CloudHost breach-notification addendum and update LRR evidence."
        },
        {
          "Field": "Next review focus",
          "Value": "CloudHost addendum, EvidenceHub pilot readiness and identity-provider access evidence."
        },
        {
          "Field": "Reviewed by",
          "Value": "Supplier Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "SINV-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Supplier Security & Third-party Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "LRR Legal, Regulatory and Contractual Requirements Register (Building the ISMS, Legal, Regulatory & Contractual Requirements)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Inventory",
    "role": "In-scope Arcfield Platform inventory on the freeze"
  }
}
