Guidance: those managing the programme should assign responsibility for each audit to an audit team leader in sufficient time for effective planning, providing the audit objectives, criteria and relevant documented information, scope including the organization, functions and processes to be audited, processes and methods, team composition, auditee contacts, locations, time frame and duration, resources, information for evaluating and addressing risks and opportunities to achieving the objectives, and information supporting interactions with the auditee. As appropriate the assignment also covers the working and reporting language, the reporting output and its distribution, confidentiality and information security, health, safety and environmental arrangements, travel and remote site access, security and authorization, actions to review from previous audits, and coordination with other audits. Joint audits need prior agreement on each party's responsibilities and the leader's authority.
This control maps to 12 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.