The organization should keep procedures for handling nonconformities and for corrective and preventive action that set requirements for: finding and correcting nonconformities and limiting their effects; investigating them, finding causes and acting to stop them recurring; judging whether action is needed to prevent nonconformities and taking it; assigning accountable and responsible people to each action; recording results; and reviewing whether the actions worked. It should make sure proposed changes reach the PAPMS documentation and keep evidence of what the nonconformities were, what was done and with what result.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.