An accredited person must take the Schedule 2 steps protecting CDR data from misuse, interference and loss and from unauthorised access, modification or disclosure; meet the internal dispute resolution requirements for one or more designated sectors and the external dispute resolution requirements for each sector it operates in; have addresses for service and, if a foreign entity, a local agent with addresses for service; and ensure it is licensed or otherwise authorised to use any CDR logo, including as the data standards require (civil penalty). It must also remain a fit and proper person for its level having regard to rule 1.9, and have adequate insurance or a comparable guarantee against consumers not being properly compensated for loss from breaches of the Act, its regulations or the rules (an unrestricted ADI need not meet the insurance requirement, clause 7.4 of Schedule 3). The Schedule 2 steps and controls themselves are carried in the companion framework 'Australia Consumer Data Right - Banking (CDR)' (AUCDR-IS-STEP1 to STEP5 and AUCDR-IS-1 to 6).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.