The practitioner must consider whether anything must be communicated to the responsible party, evaluator, engaging party, governance or others, and must tell an appropriate level of management on a timely basis about non-compliance other than clearly trivial matters, and those charged with governance about material non-compliance. Where law and the terms require it, all non-compliance is reported to the regulator. Identified or suspected fraud must be promptly communicated to management or governance and the practitioner decides whether there is a duty to report outside the entity. Procedures are designed to gather evidence for the conclusion within the terms; there is no duty to hunt for matters outside scope.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.