{
      "name": "dora-roi-annual-cycle",
      "domain": "DORA / NIS2 / ICT Resilience",
      "title": "DORA RoI Annual Cycle",
      "description": "DORA (EU 2022/2554) Art. 28/30 Register of Information annual build in one artifact: criticality designations for ICT third-party providers and functions are recorded as review_required approval records (a judgment call, not kernel-decided); the annual RoI release itself requires a dual_control(2) gate with a management-body-role approver before submission, reflecting the Art. 5 personal management-body accountability for ICT risk management -- both recorded now via the §27 Human Accountability vocabulary, enforced once HA-RETRO-1's runtime gating is wired to this chain. Each annual cycle's approvals and gate outcome export as one evidence bundle citing the Art. 5 accountability basis. Never a filed submission.",
      "composer_url": "https://ainumbers.co/chaingraph/chains/dora-roi-annual-cycle.html",
      "steps": [
        {
          "tool_id": "art-466-dora-roi-builder",
          "handoff": "Constructs and cross-validates the RoI template set -- final stage. Criticality designations on functions/providers route as review_required approval records (judgment, not kernel-decided). The annual release requires a dual_control(2) gate (preparer + management-body-role approver, Art. 5 personal accountability) before submission, recorded now and runtime-gated once HA-RETRO-1 is wired to this chain; the cycle's approvals and gate outcome export as one evidence bundle citing that Art. 5 basis."
        }
      ]
    }
