Present identified risks in a structured form, such as the standard's table: name; scope (the events, size, type, number and dependencies); nature (strategic, operational, financial, knowledge or compliance); stakeholders and their expectations; quantification (significance and probability); tolerance or appetite (loss potential, financial impact, value at risk, the likelihood and scale of possible losses or gains, control objectives); current treatment and controls with confidence in them and monitoring protocols; recommended improvements; and who develops strategy and policy. Considering consequence and probability lets key risks be prioritised; risks may be strategic, project or tactical, or operational, and belong in projects from concept onward.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.