{
  "schemaVersion": "artifactDefinition.v2",
  "definitionId": "AUD-ER.artifactDefinition.v2",
  "artifactId": "AUD-ER",
  "title": "Auditor Evidence Request Log",
  "artifactType": "Log",
  "format": "xlsx",
  "productTier": "Premium",
  "definitionRole": "contract",
  "sourceModel": {
    "body": "canonical human-readable body in this Contract and the matching Example JSON",
    "jsonDefinition": "machine-readable contract and validation model",
    "jsonExample": "curated realistic example data fixture"
  },
  "purpose": "Coordinate controlled, timely, and traceable evidence delivery during certification audits.",
  "sections": [
    {
      "order": 1,
      "id": "title_page",
      "title": "Title Page",
      "contentType": "metadata",
      "required": true,
      "hint": null
    },
    {
      "order": 2,
      "id": "abstract",
      "title": "Abstract",
      "contentType": "narrative",
      "required": true,
      "hint": {
        "text": "Use this artifact as an evidence-backed working record. A completed field without an owner, date or source reference is not audit-ready.",
        "bookReference": "Volume 2, S-09-04-00 Certification Strategy"
      }
    },
    {
      "order": 3,
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table",
      "required": true,
      "hint": null
    },
    {
      "order": 4,
      "id": "instructions",
      "title": "Instructions",
      "contentType": "ordered_list",
      "required": true,
      "hint": {
        "text": "Keep the artifact synchronized with its operational system of record and retain review evidence before external use.",
        "bookReference": "Volume 2, S-09-04-00 Certification Strategy"
      },
      "intro": "Complete the Working sheets using the example tabs as a model. Follow the workbook usage rules below."
    },
    {
      "order": 5,
      "id": "auditor_evidence_request_log",
      "title": "Auditor evidence request log",
      "contentType": "register_table",
      "required": true,
      "hint": {
        "text": "Example rows demonstrate the expected level of specificity. Replace them with organization-specific records before operational use.",
        "bookReference": "Volume 2, S-09-04-00 Certification Strategy"
      },
      "columns": [
        {
          "name": "Request ID",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the request id.",
          "example": "AUD-ER-001"
        },
        {
          "name": "Audit stage",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the audit stage.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Request text",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the request text.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Requested by",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the requested by.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Owner",
          "type": "select",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the owner.",
          "example": "ISMS Manager",
          "valueSet": "domain.owner",
          "options": [
            "ISMS Manager",
            "Control Owner",
            "Risk Owner",
            "Process Owner",
            "Asset Owner",
            "IT Security",
            "HR",
            "Legal",
            "Executive Management",
            "Internal Audit"
          ],
          "validation": {
            "allowBlank": false,
            "errorTitle": "Invalid value",
            "error": "Select a value from the list."
          }
        },
        {
          "name": "Due date and time",
          "type": "date",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the due date and time.",
          "example": "2026-08-29"
        },
        {
          "name": "Confidentiality",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the confidentiality.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Internal review",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the internal review.",
          "example": "Defined and evidenced"
        },
        {
          "name": "Delivery status",
          "type": "select",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the delivery status.",
          "example": "Complete"
        },
        {
          "name": "Evidence link",
          "type": "text",
          "required": "yes",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the evidence link.",
          "example": "JIRA-SEC-2026-014"
        },
        {
          "name": "Follow-up",
          "type": "text",
          "required": "conditional",
          "description": "Coordinate controlled, timely, and traceable evidence delivery during certification audits. Record the follow-up.",
          "example": "Defined and evidenced"
        }
      ],
      "minimumExampleRows": 5
    },
    {
      "order": 6,
      "id": "auditor_evidence_request_log_review",
      "title": "Auditor Evidence Request Log review",
      "contentType": "decision_table",
      "required": true,
      "hint": {
        "text": "Close each review with an explicit decision, unresolved actions and a traceable evidence reference.",
        "bookReference": "Volume 2, S-09-04-00 Certification Strategy"
      }
    },
    {
      "order": 7,
      "id": "external_references",
      "title": "References",
      "contentType": "reference_table",
      "required": true
    }
  ],
  "validationRules": [
    {
      "id": "required-sections-present",
      "description": "All required Contract sections must be present in the Example."
    },
    {
      "id": "example-matches-schema-columns",
      "description": "Example table rows should use the Contract column names for schema-backed sections."
    }
  ],
  "generation": {
    "source": "Contract.json",
    "method": "curated-json",
    "note": "Contract.json and Example.json are SSOT."
  },
  "editorialStandard": {
    "isoAnchors": [
      {
        "label": "ISO/IEC 27001:2022",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Normative source this artifact implements or cites."
      },
      {
        "label": "ISO/IEC 27001:2022 8.1",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Operational planning and control this register evidences."
      },
      {
        "label": "ISO/IEC 27001:2022 7.5",
        "href": "https://www.iso.org/standard/82875.html",
        "role": "Documented information: identify, review and cite this workbook by version."
      }
    ],
    "bookSources": [
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-09-04-00",
        "chapterTitle": "Certification Strategy",
        "primary": true,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      },
      {
        "series": "ISO 27001 for Software Companies",
        "volume": 2,
        "volumeTitle": "Implementation & Certification",
        "chapterId": "S-09-05-00",
        "chapterTitle": "Selecting a Certification Body and Internal Auditor",
        "primary": false,
        "role": "Primary operating chapter for this companion artifact.",
        "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
      }
    ],
    "acronyms": [
      {
        "abbr": "ISMS",
        "longForm": "Information Security Management System"
      },
      {
        "abbr": "SaaS",
        "longForm": "Software as a Service"
      },
      {
        "abbr": "CIA",
        "longForm": "Confidentiality, Integrity, and Availability"
      },
      {
        "abbr": "CI/CD",
        "longForm": "Continuous Integration / Continuous Delivery"
      },
      {
        "abbr": "CI",
        "longForm": "Continuous Integration"
      },
      {
        "abbr": "CD",
        "longForm": "Continuous Delivery"
      },
      {
        "abbr": "GRC",
        "longForm": "Governance, Risk, and Compliance"
      },
      {
        "abbr": "JSON",
        "longForm": "JavaScript Object Notation"
      }
    ],
    "must": [
      "Keep one live row per record on Working sheets. Do not merge several cases into one row.",
      "Example sheets must contain realistic Arcfield rows for every required sheet. Empty required cells are not an example."
    ],
    "mustNot": [
      "Do not invent live rows in the renderer. Example data lives in the Example JSON.",
      "Do not treat Ex example tabs as working sheets. Do not put live data on system sheets."
    ],
    "softwareCompanyAdaptations": [
      "Use Arcfield as the worked example (cover variant A).",
      "Name SaaS, CI/CD, privileged access or supplier interfaces in example rows where they affect this register."
    ],
    "exampleWorkbook": {
      "workedExampleOrg": "Arcfield",
      "requiredSheets": [
        "auditor_evidence_request_log",
        "auditor_evidence_request_log_review"
      ],
      "minExampleRows": 5,
      "coverFromExample": true
    }
  },
  "editorialContractId": "editorial.xlsx.register.v1",
  "contentContractId": "content.register.log.v1"
}
