{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "LRR",
  "title": "Legal, Regulatory and Contractual Requirements Register",
  "definitionRef": {
    "artifactId": "LRR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "LRR.artifactDefinition.v2",
    "title": "Legal, Regulatory and Contractual Requirements Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Legal, Regulatory and Contractual Requirements Register",
        "Register ID": "LRR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Legal Counsel",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Legal, Regulatory and Contractual Requirements Register",
        "Register ID: LRR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Legal Counsel",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield legal, regulatory, contractual, privacy and intellectual-property requirements with applicability, ISMS relevance, satisfaction approach, ownership, evidence and review cadence. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Document legal, regulatory, contractual, privacy and IP obligations relevant to the ISMS."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Legal Counsel, Privacy Lead, Supplier Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Legal Counsel"
        },
        {
          "Property": "Evidence role",
          "Value": "Compliance obligation and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 4.2, Clause 6.1, A.5.31, A.5.32 and A.5.34"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after legal, market, supplier or contract changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Record obligations that are relevant to the ISMS.",
        "Identify the requirement source and why it applies.",
        "Explain how the organization satisfies the obligation.",
        "Assign an owner and review cadence.",
        "Link evidence or action records.",
        "Review changed obligations before management review and after major scope, legal, supplier or contract changes.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "requirements_register",
      "title": "Requirements register",
      "schemaRef": {
        "definitionId": "LRR.artifactDefinition.v2",
        "sectionId": "requirements_register",
        "columnsRef": "sections.requirements_register.columns"
      },
      "rows": [
        {
          "Requirement ID": "LRR-001",
          "Requirement Type": "Privacy",
          "Requirement Source": "GDPR",
          "Requirement Summary": "Personal data processing must be lawful, transparent and documented.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Customer support data and employee data are processed in the ISMS scope.",
          "How We Satisfy It": "Maintain DPAR, processor register, access controls and incident handling evidence.",
          "Owner": "Privacy Lead",
          "Affected Process or Control": "A.5.34, A.8.11, DPAR",
          "Evidence Reference": "DPAR-2026-Q3",
          "Review Frequency": "Annual and after service changes",
          "Status": "Active",
          "Notes": "Retention review linked to RRS."
        },
        {
          "Requirement ID": "LRR-002",
          "Requirement Type": "Contractual",
          "Requirement Source": "Enterprise customer security addendum",
          "Requirement Summary": "Security controls and incident communication commitments must be evidenced.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Drives customer assurance evidence, incident reporting and access review expectations.",
          "How We Satisfy It": "Map commitments to SoA, ELAI, ICL and incident records.",
          "Owner": "Compliance Lead",
          "Affected Process or Control": "A.5.20, A.5.24, ELAI",
          "Evidence Reference": "ELAI-2026-Q3",
          "Review Frequency": "Before contract renewal",
          "Status": "Active",
          "Notes": "Notification addendum follow-up tracked in EXR-002."
        },
        {
          "Requirement ID": "LRR-003",
          "Requirement Type": "Regulatory",
          "Requirement Source": "Sector customer due-diligence expectations",
          "Requirement Summary": "Critical service availability and resilience evidence must be available for assurance reviews.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Supports continuity, supplier and operational control evidence.",
          "How We Satisfy It": "Maintain CSR, BCP, DRP and supplier resilience evidence.",
          "Owner": "Operations Lead",
          "Affected Process or Control": "A.5.30, A.5.19, CSR",
          "Evidence Reference": "CSR-REVIEW-2026-Q3",
          "Review Frequency": "Quarterly",
          "Status": "Active",
          "Notes": "Restore test scheduled."
        },
        {
          "Requirement ID": "LRR-004",
          "Requirement Type": "Intellectual property",
          "Requirement Source": "Software licensing terms",
          "Requirement Summary": "Third-party software must be used within license rights and tracked.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Supports compliant asset and software inventory management.",
          "How We Satisfy It": "Maintain software inventory, ownership and license evidence.",
          "Owner": "IT Operations Manager",
          "Affected Process or Control": "A.5.32, SI",
          "Evidence Reference": "SI-2026-Q3",
          "Review Frequency": "Quarterly",
          "Status": "Active",
          "Notes": "Open-source review included in engineering workflow."
        },
        {
          "Requirement ID": "LRR-005",
          "Requirement Type": "Supplier contractual",
          "Requirement Source": "CloudHost service agreement",
          "Requirement Summary": "Supplier must maintain security commitments and incident notification route.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Critical cloud dependency for analytics service.",
          "How We Satisfy It": "Supplier inventory, security review, exception tracking and periodic evidence request.",
          "Owner": "Supplier Manager",
          "Affected Process or Control": "A.5.19-A.5.23",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Review Frequency": "Quarterly",
          "Status": "Action open",
          "Notes": "Breach-notification addendum pending renewal."
        },
        {
          "Requirement ID": "LRR-006",
          "Requirement Type": "ISO 27001",
          "Requirement Source": "ISO/IEC 27001:2022 Clause 4.2",
          "Requirement Summary": "Interested-party requirements relevant to information security must be determined.",
          "Applicability": "Applicable",
          "ISMS Relevance": "Foundational requirement for scope, risk assessment and controls.",
          "How We Satisfy It": "Maintain IPR and link requirements to processes and evidence expectations.",
          "Owner": "ISMS Manager",
          "Affected Process or Control": "Clause 4.2, IPR",
          "Evidence Reference": "IPR-REVIEW-2026-Q3",
          "Review Frequency": "Quarterly",
          "Status": "Active",
          "Notes": "Reviewed before management review."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "requirements_review_decision",
      "title": "Requirements review decision",
      "values": {
        "Review result": "Requirements register reviewed; one supplier contractual action remains open.",
        "Requirements reviewed": 6,
        "New or changed requirements": "Customer addendum and CloudHost notification addendum",
        "Open actions": "Complete CloudHost breach-notification addendum and update evidence packet",
        "Reviewed by": "Legal Counsel",
        "Decision date": "2026-08-29",
        "Evidence reference": "LRR-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Requirements register reviewed; one supplier contractual action remains open."
        },
        {
          "Field": "Requirements reviewed",
          "Value": "6"
        },
        {
          "Field": "New or changed requirements",
          "Value": "Customer addendum and CloudHost notification addendum"
        },
        {
          "Field": "Open actions",
          "Value": "Complete CloudHost breach-notification addendum and update evidence packet"
        },
        {
          "Field": "Reviewed by",
          "Value": "Legal Counsel"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "LRR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 4.2",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Legal, Regulatory & Contractual Requirements",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CSR Critical Services Register (Dual Compliance, Multi-framework Operating Model)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "DPAR Data Processing Activities Register (GDPR) (Secure Engineering, Data Lifecycle & Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
