The organization sets up and carries out the inspection or other activities required to make sure what it buys meets the purchasing requirements. How much verification is done depends on the results of supplier evaluation and is proportionate to the risk the purchased product carries. When it learns of a change to purchased product, the organization decides whether the change has any effect on the device or on how the product is realized. If the organization, or its customer, plans to carry out verification at the supplier's site, the purchasing information states what verification is planned and how the product will be released. Records of verification are kept.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.