The practitioner must obtain the responsible party's agreement, in writing, that it understands its responsibility: for evaluating the compliance activity and giving a statement on the outcome (attestation), identifying suitable compliance requirements, and giving the practitioner full access to records, other requested information and unrestricted access to the people needed. The terms must identify the scope, whether assurance is reasonable or limited, whether the engagement is attestation or direct (and how the statement is made available), the period or date, the compliance requirements, the intended users, the content of the report (short or long form) and any legally required matters such as reporting every non-compliance to a regulator.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.