The Commission may audit any CDR participant's compliance with Part IVD, the rules and the data standards, and the Information Commissioner its compliance with the privacy safeguards and the rules so far as they relate to them or to the privacy or confidentiality of CDR data. For an audit or monitoring, either may by written notice require copies of records the Division requires or information from them within a specified time, and the participant must comply (civil penalty).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.