The organization should keep procedures for PAPMS audits at planned intervals and at other times top management decides. Audits should check whether the PAPMS meets this standard, meets the legal and regulatory requirements of the jurisdiction, has been properly put in place and kept up, and has been effective in reaching the PAP policy and objectives. The audit procedures should set responsibilities and requirements for planning, conducting, reporting and keeping records; set the audit criteria and scope, how often and by what methods audits run, and the competence, accountability and responsibility of those involved; make sure results reach the management of the audited area; and keep documented evidence of results. Auditors should be chosen and audits run so the process is objective and impartial.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.