Guidance: operational controls exist to manage significant aspects, make sure compliance obligations are met, reach objectives and policy commitments, avoid or minimise adverse impacts and effects, and maximise opportunities. Starting from the scope and from the actions decided under 6.1 and 6.2, it should identify the controls it needs, taking a life cycle perspective and covering functions such as design, research and development, procurement, marketing, sales and facility management, and should set out within the system how far, and by what kind of control or influence, it will act at every life cycle stage. A life cycle perspective should be applied as early as design and development to avoid transferring impacts to other stages; where significant aspects lie in the use phase, influence can be exercised through education, accessible information and user groups. The organization should consider what outsourced processes and external providers mean for its ability to manage aspects and meet obligations, put the necessary controls in place (procedures, contracts, supplier agreements, instructions for end users) and tell contractors, suppliers and users about them. An outsourced process is one central to how the organization works, needed for the intended outcomes, for which the organization retains liability, and which interested parties perceive as carried out by the organization.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.