In addition to the annual audit review the institution must ensure the appropriateness, effectiveness and adequacy of its risk management framework is comprehensively reviewed at least every three years by operationally independent, appropriately trained and competent persons who may include external consultants, with results reported to the Board Risk Committee, the senior officer outside Australia or the Compliance Committee as relevant.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.