{
  "scenarioVersion": 1,
  "id": "D02-2",
  "domain": "executive-risk",
  "title": "Recorded audit readiness \u2014 Enterprise risk & appetite",
  "context": "Annual cloud assurance preparation: scoped controls and recorded passing tests are complete. Complete the domain checks, resolve calculation exceptions, and obtain documented reviewer acceptance. Metadata readiness is not certification or authorization.",
  "reviewInputs": {
    "scope": "Synthetic Enterprise risk & appetite review",
    "owner": "Example risk owner",
    "reviewer": "Example accountable reviewer",
    "evidenceURL": "https://example.com/evidence/D02-2",
    "expires": "2027-01-31",
    "asOf": "2026-10-09",
    "checks": [
      true,
      true,
      true
    ],
    "domainInputs": {
      "population": 0,
      "baseline": 5,
      "approval": "Confirmed"
    }
  },
  "workspace": {
    "version": 1,
    "records": [
      {
        "type": "obligation",
        "id": "D02-2-OB",
        "title": "Enterprise risk & appetite applicability review",
        "domainSlug": "regulatory-obligations",
        "framework": "NIST SP 800-53 RA; ISO/IEC 27001 clause 6",
        "requirement": "Risk appetite and tolerance documented"
      },
      {
        "type": "control",
        "id": "D02-2-CT",
        "title": "Risk appetite exception memo",
        "domainSlug": "executive-risk",
        "owner": "Example risk owner",
        "obligationId": "D02-2-OB",
        "effectiveness": "Effective"
      },
      {
        "type": "test",
        "id": "D02-2-TS",
        "title": "Synthetic Enterprise risk & appetite evidence test",
        "domainSlug": "audit-readiness",
        "controlId": "D02-2-CT",
        "result": "Pass",
        "evidenceURL": "https://example.com/evidence/D02-2",
        "reviewer": "Example accountable reviewer",
        "testedDate": "2026-10-09",
        "expiresDate": "2027-01-31"
      },
      {
        "type": "vendor",
        "id": "D02-2-VD",
        "title": "Example AI supplier",
        "domainSlug": "vendor-risk",
        "service": "LLM support processing",
        "usesAI": false,
        "reviewOutcome": "Approve",
        "owner": "Example supplier reviewer",
        "notes": "Synthetic: subprocessors reviewed"
      },
      {
        "type": "risk",
        "id": "D02-2-DM",
        "title": "Risk appetite exception memo source record",
        "domainSlug": "executive-risk",
        "owner": "Example risk owner",
        "notes": "Synthetic domain-specific inputs",
        "category": "Enterprise risk & appetite",
        "likelihood": 2,
        "impact": 2,
        "treatment": "Reduce",
        "vendorId": "D02-2-VD"
      }
    ],
    "updatedAt": null
  },
  "decisionLab": {
    "schemaVersion": "1.0",
    "asOf": "2026-10-09",
    "provenance": "Synthetic scenario; evidence and passing tests are illustrative assertions",
    "assumptions": {
      "manualMinutes": 0,
      "assistedMinutes": 0,
      "hourlyCost": 0,
      "setupCost": 0
    },
    "records": [
      {
        "id": "D02-2-AI",
        "name": "Example cloud assurance service",
        "owner": "Example service owner",
        "service": "Cloud assurance",
        "criticality": "high",
        "dataSensitivity": "personal",
        "ai": false,
        "approved": true,
        "processor": true,
        "region": "EEA",
        "dpa": true,
        "transfer": true,
        "disclosure": "tested",
        "oversight": "tested",
        "evidence": "current",
        "likelihood": 2,
        "impact": 2,
        "treatment": "mitigate",
        "reviewer": "Example accountable reviewer",
        "rationale": "Synthetic metadata only",
        "parentVendorId": "",
        "controlId": "D02-2-CT",
        "evidenceRef": "https://example.com/evidence/D02-2",
        "testOutcome": "pass",
        "evidenceReviewedAt": "2026-10-09",
        "evidenceExpiresAt": "2027-01-31",
        "question": "Risk appetite and tolerance documented",
        "aiEvalTotal": 0,
        "aiEvalFailed": 0,
        "techniqueId": ""
      }
    ]
  }
}
