Changes to design and development are controlled through documented procedures. For each change the organization judges how significant it is for the device and its intended use, looking at function, performance, usability, safety and the regulatory requirements that apply. Every change is identified, then reviewed, verified, validated where appropriate and approved before it is put into effect. The review of a change weighs its effect on constituent parts, on product being made or already delivered, on the inputs and outputs of risk management, and on the processes used to realize the product. The organization keeps records of each change, of its review and of any actions the review found necessary.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.