Guidance: those managing the programme should appoint the audit team including the leader and any technical experts, selected for the competence needed to achieve the audit's objectives within its scope; a sole auditor performs all leader duties. To assure overall competence, identify the competence needed and select members so it is present. Size and composition should consider overall competence against scope and criteria, complexity, combined or joint audits, the methods selected, objectivity and impartiality to avoid conflicts of interest, the ability to interact with the auditee and interested parties, language and social and cultural issues (possibly through experts or interpreters), and the type and complexity of processes. The team leader should be consulted where appropriate, technical experts added where competence is missing, auditors-in-training included only under an auditor's direction, and changes to the team during the audit resolved with the appropriate parties first.
This control maps to 12 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.