When assessing risks the practitioner must gather enough information to spot where fraud could stop the compliance requirements being satisfied. The practitioner must establish whether the entity operates an internal audit function and, if one exists, ask what it has done and found on compliance; may use its work after evaluating it as ASAE 3000 requires, deciding the planned effect on nature, timing or extent of procedures while considering the nature and scope of the work, its significance, subjectivity and what needs re-performing; and must not use internal auditors to give direct assistance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.