The entity must report actionable scam intelligence to the general regulator in the time, manner and form the Rules prescribe, with the information prescribed, including through any designated gateway. It must also report a scam when an SPF regulator asks in writing, in the time and form requested, with details of loss, disruptive steps taken and steps to prevent similar scams; personal information is de-identified unless the regulator reasonably believes otherwise.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.