Guidance: those managing the programme should ensure records of audits are created, managed and kept so that they show the programme has been put into effect, with processes addressing their information security and confidentiality. Records relate to the programme (schedule, objectives and extent, risks and opportunities and issues, effectiveness reviews), to each audit (plans and reports, findings with their evidence, reports of nonconformities, corrections, corrective actions and reports on follow-up) and to the audit team (competence and performance evaluations, selection criteria and team formation, competence maintenance). Their form and detail should demonstrate the programme's objectives were achieved.
This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.