{
  "scenarioVersion": 1,
  "id": "D13-2",
  "domain": "data-governance",
  "title": "Recorded audit readiness \u2014 Data classification & retention",
  "context": "Annual cloud assurance preparation: scoped controls and recorded passing tests are complete. Complete the domain checks, resolve calculation exceptions, and obtain documented reviewer acceptance. Metadata readiness is not certification or authorization.",
  "reviewInputs": {
    "scope": "Synthetic Data classification & retention review",
    "owner": "Example processing owner",
    "reviewer": "Example accountable reviewer",
    "evidenceURL": "https://example.com/evidence/D13-2",
    "expires": "2027-01-31",
    "asOf": "2026-10-09",
    "checks": [
      true,
      true,
      true
    ],
    "domainInputs": {
      "population": 0,
      "baseline": 5,
      "approval": "Confirmed"
    }
  },
  "workspace": {
    "version": 1,
    "records": [
      {
        "type": "obligation",
        "id": "D13-2-OB",
        "title": "Data classification & retention applicability review",
        "domainSlug": "regulatory-obligations",
        "framework": "GDPR Article 5; NIST SP 800-53 MP, PT",
        "requirement": "Data classification and inventory recorded"
      },
      {
        "type": "control",
        "id": "D13-2-CT",
        "title": "Retention and disposal exception register",
        "domainSlug": "data-governance",
        "owner": "Example processing owner",
        "obligationId": "D13-2-OB",
        "effectiveness": "Effective"
      },
      {
        "type": "test",
        "id": "D13-2-TS",
        "title": "Synthetic Data classification & retention evidence test",
        "domainSlug": "audit-readiness",
        "controlId": "D13-2-CT",
        "result": "Pass",
        "evidenceURL": "https://example.com/evidence/D13-2",
        "reviewer": "Example accountable reviewer",
        "testedDate": "2026-10-09",
        "expiresDate": "2027-01-31"
      },
      {
        "type": "vendor",
        "id": "D13-2-VD",
        "title": "Example AI supplier",
        "domainSlug": "vendor-risk",
        "service": "LLM support processing",
        "usesAI": false,
        "reviewOutcome": "Approve",
        "owner": "Example supplier reviewer",
        "notes": "Synthetic: subprocessors reviewed"
      },
      {
        "type": "processing",
        "id": "D13-2-DM",
        "title": "Retention and disposal exception register source record",
        "domainSlug": "data-governance",
        "owner": "Example processing owner",
        "notes": "Synthetic domain-specific inputs",
        "purpose": "LLM support / customer PII",
        "lawfulBasis": "Declared; requires privacy validation",
        "dataCategories": "Customer PII",
        "retentionDays": 30,
        "transferMechanism": "Declared SCC review complete",
        "vendorId": "D13-2-VD"
      }
    ],
    "updatedAt": null
  },
  "decisionLab": {
    "schemaVersion": "1.0",
    "asOf": "2026-10-09",
    "provenance": "Synthetic scenario; evidence and passing tests are illustrative assertions",
    "assumptions": {
      "manualMinutes": 0,
      "assistedMinutes": 0,
      "hourlyCost": 0,
      "setupCost": 0
    },
    "records": [
      {
        "id": "D13-2-AI",
        "name": "Example cloud assurance service",
        "owner": "Example service owner",
        "service": "Cloud assurance",
        "criticality": "high",
        "dataSensitivity": "personal",
        "ai": false,
        "approved": true,
        "processor": true,
        "region": "EEA",
        "dpa": true,
        "transfer": true,
        "disclosure": "tested",
        "oversight": "tested",
        "evidence": "current",
        "likelihood": 2,
        "impact": 2,
        "treatment": "mitigate",
        "reviewer": "Example accountable reviewer",
        "rationale": "Synthetic metadata only",
        "parentVendorId": "",
        "controlId": "D13-2-CT",
        "evidenceRef": "https://example.com/evidence/D13-2",
        "testOutcome": "pass",
        "evidenceReviewedAt": "2026-10-09",
        "evidenceExpiresAt": "2027-01-31",
        "question": "Data classification and inventory recorded",
        "aiEvalTotal": 0,
        "aiEvalFailed": 0,
        "techniqueId": ""
      }
    ]
  }
}
