The organization identifies action to remove the causes of nonconformities that could occur, so they do not happen, in proportion to the effects the possible problems would have. A documented procedure sets the requirements for: identifying possible nonconformities and what causes them; deciding whether action is needed to stop them happening; planning, documenting and carrying out the action required, updating documentation where appropriate; checking that the action does not harm regulatory compliance or the device's safety and performance; and, where appropriate, reviewing whether the preventive action worked. Records are kept of any investigation and of the action taken.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.