For limited assurance the practitioner must get to know how the entity's compliance framework works and what its key parts are, which compliance requirements are in scope and the other engagement circumstances; in a direct engagement the practitioner also asks whether the chosen criteria are fitting; and for both kinds of engagement identify where risks of non-compliance with each requirement are likely to arise and respond to them in designing procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.