Records requirements are met through records systems, controls, policies and procedures, or a mix, supported by roles, training and monitoring. Methods reflect the business setting, resources and skills, and the information systems in use. Implementation decisions weigh risk against resources, with higher-risk requirements receiving greater investment and monitoring, are tested through monitoring with corrective action stated where unmet, and are documented. A decision not to meet an identified requirement is authorised by a senior manager, and requirements are reviewed regularly as part of re-appraisal.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.