Every record kept for audit purposes is stored securely, readily accessible and current, retained for at least two years or longer where customers or regulations require it, valid and backed up if electronic, covers at least the three months before the first certification body audit or runs from the registration date if that is longer, and references every area and activity within the registration. A missing individual record makes the principle it belongs to non-compliant: one spray record without an application date is a non-conformance against that principle.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.