The RSE licensee must have a designated risk management function that assists the Board, board committees and senior management to develop and maintain the framework, is proportionate to the size, business mix and complexity of business operations and operationally independent of the business units, is staffed by people with clearly defined roles and appropriate experience and qualifications, has access to every part of business operations capable of generating material risk including information technology systems and systems development resources, has the authority and reporting structure to act effectively and independently, and is required to notify the Board of any material deviation from or material breach of the framework.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.