The entity must have an accessible way for a person to report a scam or possible scam connected to the regulated service, and an accessible and transparent internal dispute resolution mechanism for complaints about a scam or about the entity's conduct relating to it. They extend to people to whom the service was only purportedly provided.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.