Hazards introduced by the design itself, by the chosen architecture, by failure modes of the selected components or by the interaction of functions, are identified as the design develops, entered in the hazard log and controlled by the same process, so that the risk assessment is revisited rather than assumed complete at the requirements stage.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.