The institution must ensure that compliance with and the effectiveness of the risk management framework is reviewed by internal or external audit at least annually, with results reported to the Board Audit Committee, the senior officer outside Australia or the Compliance Committee as relevant.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.