The DS validates the ARes or Error message, logs as its rules require and relays the ARes unchanged back to the 3DS Server, which validates it and, for Y or A in a payment authentication, ensures the status, ECI and Authentication Value reach the authorisation process and the requestor environment; for C it evaluates, partly on the challenge indicator preference, whether to go ahead with the challenge, passing the ARes data to the requestor environment if so (further processing after a declined challenge is outside 3DS); for N, U, R or an error it passes the data to the requestor and completes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.