The risk management framework must include at least the risk appetite statement, the risk management strategy, a designated risk management function meeting the required criteria, all risk management policies, procedures and controls to identify, assess, monitor, report on, mitigate and manage each material risk, clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout business operations, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process ensuring the framework remains effective.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.