Guidance: the team leader should see that the auditee is contacted in order to confirm how communication will work and that there is authority for the audit to go ahead; to explain the objectives, scope, criteria and methods and who is on the team, technical experts included; to ask for access to the information needed for planning, including the auditee's identified risks and opportunities and how they are addressed; determine applicable statutory, regulatory and other requirements; confirm agreement on disclosure and treatment of confidential information; arrange the audit and schedule; establish the arrangements each location has for access, health and safety, security and confidentiality; agree on observers, guides and interpreters; determine areas of interest, concern or risk to the auditee; and resolve team composition issues with the auditee or client.
This control maps to 12 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.