{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SRP",
  "title": "Supplier Relationships Policy",
  "definitionRef": {
    "artifactId": "SRP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SRP.artifactDefinition.v2",
    "title": "Supplier Relationships Policy"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Supplier Relationships Policy",
        "Document ID": "SUP-REL-POL-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Supplier Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Supplier Relationships Policy",
        "Document ID: SUP-REL-POL-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Supplier Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This is a fictional Arcfield worked example of SUP-REL-POL-001. It states operating rules for Supplier Relationships Policy. The cover status is not a real management-team approval and not a certification statement. New numerical and method choices are EXAMPLE_DECISION and pending review. They are not ISO/IEC 27001:2022 obligations and not a recovered Artifact Candidate page.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own."
        },
        {
          "items": [
            "Treat SUP-REL-POL-001 and the rule IDs as the example identity. Cover status Approved is the Arcfield scenario freeze, not a real management-team sign-off of these new rule sentences.",
            "Replace Arcfield names, methods and owners before you adopt the file.",
            "Cite the Document Control version from related records. Do not copy this body into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "policy_content",
      "title": "Policy",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this policy is",
          "level": 1,
          "text": "This document is Arcfield's Supplier Relationships Policy, document ID SUP-REL-POL-001. It binds supplier security classification, due diligence, contracting, monitoring, incidents and exit for suppliers that can affect Arcfield Platform confidentiality, integrity or availability. It is not the ISMS Scope Statement, the Risk Assessment Methodology or the Statement of Applicability. It applies to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records cite this Document Control version. Do not copy these paragraphs into those records."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this policy": "The classified rules SRP-CLS-001, SRP-DD-001, SRP-CTR-001 through SRP-EV-001, roles, the worked Arcfield example and the records this file owns.",
              "Not in this policy": "The ISMS boundary (ISS), Annex A selection (SoA), or live neighbouring registers. Those files keep their own versions."
            },
            {
              "In this policy": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect confidentiality, integrity or availability.",
              "Not in this policy": "Live ISS or SoA decisions. Neighbouring live registers keep their own versions. Those files are named, not copied here."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body. Artefact ID ISO is Information Security Objectives, not the International Organization for Standardization.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control. An expired row does not authorise continued deviation."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The version cited from neighbouring records. Do not copy this body into those records."
            },
            {
              "Term": "Enforcement",
              "Meaning": "The named system rejects the unauthorised attempt for the named population. Registration or capability is not enforcement."
            }
          ]
        },
        {
          "id": "named_registers",
          "heading": "Systems, integrations and data",
          "level": 1,
          "text": "Related inventories live in the companion documents named below. Cite the approved version. Do not copy their content. Availability follows the book pack, not this sentence.",
          "items": [
            "[Asset Inventory](AI_Asset_Inventory.xlsx) — In-scope assets with owner, classification, hosting, personal-data flag and related risk.",
            "[Supplier Inventory](SINV_Supplier_Inventory.xlsx) — Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning.",
            "[Users and Access Inventory](UAI_Users_and_Access_Inventory.xlsx) — Users and accounts with access rights, privileged access, MFA status, reviews and revocations."
          ],
          "ordered": true,
          "relationView": "inventory"
        },
        {
          "id": "supplier_classification",
          "heading": "Supplier classification",
          "level": 1,
          "text": "Read SRP-CLS-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "SRP-CLS-001",
              "Statement": "A supplier that can affect Arcfield Platform customer data, production or identity is classified in the Supplier Inventory before it is used. An unclassified critical supplier is not authorised.",
              "Scope": "Security-relevant suppliers.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected: SINV row with tier. No observation is supplied."
            }
          ]
        },
        {
          "id": "due_diligence",
          "heading": "Due diligence",
          "level": 1,
          "text": "Read SRP-DD-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "SRP-DD-001",
              "Statement": "Due diligence proportionate to the tier is completed before customer data or production access is granted. A logo on a website is not due diligence.",
              "Scope": "New or changed security-relevant suppliers.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected: due-diligence record cited from SINV. No observation is supplied."
            }
          ]
        },
        {
          "id": "contractual_requirements",
          "heading": "Contractual requirements",
          "level": 1,
          "text": "Read SRP-CTR-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "SRP-CTR-001",
              "Statement": "Contracts for security-relevant suppliers name confidentiality, incident notice, subprocessors and exit assistance. A click-through that is silent on incidents is not sufficient for production customer data.",
              "Scope": "Suppliers with production or customer-data access.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected: contract clause record. This rule stays HUMAN_REVIEW. No observation is supplied."
            }
          ]
        },
        {
          "id": "ongoing_monitoring",
          "heading": "Ongoing monitoring",
          "level": 1,
          "text": "Read SRP-MON-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "SRP-MON-001",
              "Statement": "Tier-one suppliers are reviewed at least annually, or after a material incident or ownership change. Silence is not a review.",
              "Scope": "Tier-one suppliers in SINV.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected: review date on the SINV row. No observation is supplied."
            }
          ]
        },
        {
          "id": "supplier_incidents_changes_and_exit",
          "heading": "Supplier incidents, changes and exit",
          "level": 1,
          "text": "Read SRP-EXT-001 as the classified Arcfield rule for this topic. Capability or presence is not enforcement.",
          "rows": [
            {
              "Rule ID": "SRP-EXT-001",
              "Statement": "Supplier incidents that may affect Arcfield Platform are reported under IMP. Exit or replacement has a recorded plan before dependence becomes critical. An expired contract is not an exit plan.",
              "Scope": "Security-relevant suppliers.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected: incident link or exit note. No observation is supplied."
            }
          ]
        },
        {
          "id": "evidence",
          "heading": "Evidence expectations",
          "level": 1,
          "text": "Use this table to see what a named evidence ID can prove. It is not a log of collected observations.",
          "rows": [
            {
              "Rule ID": "SRP-EV-001",
              "Statement": "Each rule above states an evidence expectation. An identifier without a bound dataset is not collected evidence.",
              "Scope": "All SRP rules in this file.",
              "Owner": "Supplier Manager",
              "Evidence expectation": "Expected evidence reference; no evidence supplied. Do not render this row as an observation."
            }
          ]
        }
      ],
      "contentType": "policy_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "These companions hold live records. This policy states what evidence it needs; it does not ship observations. An evidence ID without a dataset is an expectation. The Owner on the cover is accountable for those live records when you adopt the file."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "Availability is by book pack. In-pack files may sit next to this document after unpack. Other-book files are named, not shipped in this Office pack.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory",
              "How this document uses it": "In-scope assets with owner, classification, hosting, personal-data flag and related risk In this book's pack when present.",
              "href": "AI_Asset_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "SINV Supplier Inventory",
              "How this document uses it": "Security-relevant suppliers with tier, due diligence, contract controls, subprocessors and exit planning In this book's pack when present.",
              "href": "SINV_Supplier_Inventory.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "UAI Users and Access Inventory",
              "How this document uses it": "Users and accounts with access rights, privileged access, MFA status, reviews and revocations Another book's pack, not this Office pack.",
              "href": "UAI_Users_and_Access_Inventory.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness Another book's pack, not this Office pack.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location In this book's pack when present.",
              "href": "DR_Document_Register.xlsx",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence Another book's pack, not this Office pack.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "BRPROC Backup & Recovery Procedure (Secure Engineering, Backup, Redundancy & Data Resilience)",
              "href": "BRPROC_Backup_and_Recovery_Procedure.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record Another book's pack, not this Office pack.",
              "availability": "other_volume"
            },
            {
              "Kind": "Artifact",
              "Reference": "CSSAQ Critical Supplier Security Assessment Questionnaire (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "href": "CSSAQ_Critical_Supplier_Security_Assessment_Questionnaire_Form.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record In this book's pack when present.",
              "availability": "in-pack"
            },
            {
              "Kind": "Artifact",
              "Reference": "SSAQ Supplier Security Assessment Questionnaire (Building the ISMS, Supplier Security & Third-party Risk Management)",
              "href": "SSAQ_Supplier_Security_Assessment_Questionnaire_Form.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record In this book's pack when present.",
              "availability": "in-pack"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Supplier Security & Third-party Risk Management",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "crId": "CR-POL-EN-002",
    "dependsOn": [
      106,
      107
    ],
    "family": "Policy",
    "role": "Fictional Arcfield worked example. Not a real management-team approval and not a certification statement.",
    "reviewState": "pending",
    "provenance": "EXAMPLE_DECISION"
  }
}
