A payment service provider must not send customers payment instruments they did not request, except on expiry or replacement, and before executing an electronic fund transfer must clearly identify the customer and re-authenticate the transfer.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.