The scope of the comprehensive review must have regard to the size, business mix and complexity of business operations, the extent of any change to those operations or to risk appetite and any changes in the external environment, and the review must at a minimum cover whether the framework remains appropriate for business operations, the specific resources used to undertake the required risk management activities and whether those activities are adequately resourced, the risk appetite statement, the risk management strategy and whether it accurately documents the framework and the strategy for managing risk, all risk management policies and procedures, and all risk management and internal control systems.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.