{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "RRS",
  "title": "Records Retention Schedule",
  "definitionRef": {
    "artifactId": "RRS",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "RRS.artifactDefinition.v2",
    "title": "Records Retention Schedule"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Records Retention Schedule",
        "Register ID": "RRS-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Legal Counsel",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Records Retention Schedule",
        "Register ID: RRS-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Legal Counsel",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines Arcfield retention rules for ISMS, security, privacy, audit and operational records, including legal or business drivers, retention periods, triggers, storage locations, owners, access restrictions, disposal and evidence. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Define retention and disposal rules for ISMS records."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Legal Counsel, Privacy Lead, HR Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "Legal Counsel"
        },
        {
          "Property": "Evidence role",
          "Value": "Documented information, retention and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 7.5, A.5.31, A.5.32 and A.5.34"
        },
        {
          "Property": "Review cadence",
          "Value": "Annual and after legal, contractual or scope changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "List each ISMS-relevant record class.",
        "Record examples, driver, retention period and retention trigger.",
        "Identify the storage location, owner and access restrictions.",
        "Define disposal method and review frequency.",
        "Link evidence for the current review.",
        "Check legal holds before disposal.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "records_retention_schedule",
      "title": "Records retention schedule",
      "schemaRef": {
        "definitionId": "RRS.artifactDefinition.v2",
        "sectionId": "records_retention_schedule",
        "columnsRef": "sections.records_retention_schedule.columns"
      },
      "rows": [
        {
          "Record Class ID": "RRS-001",
          "Record Class": "ISMS policies and scope records",
          "Record Examples": "Information security policy, scope statement, SoA",
          "Legal or Business Driver": "ISO 27001 certification and governance evidence",
          "Retention Period": "Current version plus 3 years",
          "Retention Trigger": "Superseded or scope changed",
          "Storage Location": "Controlled ISMS workspace",
          "Owner": "ISMS Manager",
          "Access Restriction": "Internal restricted",
          "Disposal Method": "Archive then secure deletion",
          "Review Frequency": "Annual",
          "Evidence Reference": "MDR-2026-Q3",
          "Status": "Active",
          "Notes": "SoA retained with approval history."
        },
        {
          "Record Class ID": "RRS-002",
          "Record Class": "Risk assessment and treatment records",
          "Record Examples": "Risk register, treatment plan, ROAR",
          "Legal or Business Driver": "Risk management and audit trail",
          "Retention Period": "Current cycle plus 3 years",
          "Retention Trigger": "Risk cycle closed",
          "Storage Location": "Risk evidence folder",
          "Owner": "Compliance Lead",
          "Access Restriction": "Risk owners and management",
          "Disposal Method": "Secure deletion after approval",
          "Review Frequency": "Annual",
          "Evidence Reference": "RR-2026-Q3",
          "Status": "Active",
          "Notes": "High-risk decisions retained for management review."
        },
        {
          "Record Class ID": "RRS-003",
          "Record Class": "Incident records",
          "Record Examples": "Incident log, incident reports, lessons learned",
          "Legal or Business Driver": "Incident response, customer commitments and regulatory traceability",
          "Retention Period": "5 years after closure",
          "Retention Trigger": "Incident closed",
          "Storage Location": "Incident evidence folder",
          "Owner": "Incident Manager",
          "Access Restriction": "Security and legal restricted",
          "Disposal Method": "Legal hold check then secure deletion",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "IL-REVIEW-2026-08",
          "Status": "Active",
          "Notes": "Supplier incident records retained until final report received."
        },
        {
          "Record Class ID": "RRS-004",
          "Record Class": "Training and awareness records",
          "Record Examples": "Training completions, acknowledgements, reminders",
          "Legal or Business Driver": "Competence and awareness evidence",
          "Retention Period": "Employment or contract period plus 2 years",
          "Retention Trigger": "Employee or contractor offboarding",
          "Storage Location": "HR training system",
          "Owner": "HR Manager",
          "Access Restriction": "HR and ISMS restricted",
          "Disposal Method": "HR retention workflow",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "TR-2026-Q3",
          "Status": "Active",
          "Notes": "Contractor completion reminders open."
        },
        {
          "Record Class ID": "RRS-005",
          "Record Class": "Supplier assurance records",
          "Record Examples": "Supplier assessments, contracts, security evidence",
          "Legal or Business Driver": "Supplier relationship security and contractual due diligence",
          "Retention Period": "Contract term plus 3 years",
          "Retention Trigger": "Supplier offboarding or contract end",
          "Storage Location": "Supplier evidence folder",
          "Owner": "Supplier Manager",
          "Access Restriction": "Supplier management and legal",
          "Disposal Method": "Contract-retention review then secure deletion",
          "Review Frequency": "Quarterly for critical suppliers",
          "Evidence Reference": "SINV-CLOUDHOST-2026-Q3",
          "Status": "Action open",
          "Notes": "CloudHost addendum pending."
        },
        {
          "Record Class ID": "RRS-006",
          "Record Class": "Audit and management review records",
          "Record Examples": "Audit programme, findings, management review minutes",
          "Legal or Business Driver": "Certification and continual improvement evidence",
          "Retention Period": "Current certification cycle plus 3 years",
          "Retention Trigger": "Certification cycle closed",
          "Storage Location": "Audit evidence pack",
          "Owner": "Internal Auditor",
          "Access Restriction": "Internal restricted",
          "Disposal Method": "Archive then secure deletion",
          "Review Frequency": "Before each audit cycle",
          "Evidence Reference": "ELAI-2026-Q3",
          "Status": "Active",
          "Notes": "Evidence freeze pending."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "retention_review_decision",
      "title": "Retention review decision",
      "values": {
        "Review result": "Retention schedule reviewed; one supplier record class has an open contractual follow-up.",
        "Record classes reviewed": 6,
        "Rules active": 6,
        "Rules needing update": 1,
        "Disposal actions due": 0,
        "Reviewed by": "Legal Counsel",
        "Decision date": "2026-08-29",
        "Evidence reference": "RRS-REVIEW-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Retention schedule reviewed; one supplier record class has an open contractual follow-up."
        },
        {
          "Field": "Record classes reviewed",
          "Value": "6"
        },
        {
          "Field": "Rules active",
          "Value": "6"
        },
        {
          "Field": "Rules needing update",
          "Value": "1"
        },
        {
          "Field": "Disposal actions due",
          "Value": "0"
        },
        {
          "Field": "Reviewed by",
          "Value": "Legal Counsel"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "RRS-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 7.5",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Audit Process",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "IL Incident Log (Secure Engineering, Incident Response & Security Monitoring)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
