Based on the understanding gained, the practitioner must perform procedures that respond to assessed risks to support the conclusion, plus further procedures responsive to the risk of material deficiency in the framework or non-compliance, with regard to whether assurance is limited or reasonable. Assessed fraud risks must be treated as significant risks and responded to with procedures on the controls meant to mitigate them. The practitioner must evaluate those compliance activities needed to meet the requirements and assess compliance throughout the period or at the date.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.