Guidance: a closing meeting chaired by the team leader and attended by the auditee's management and, as applicable, those responsible for audited functions, the client, the team and other interested parties should present the findings and conclusions. The leader should advise of situations that may reduce confidence in the conclusions, and where defined, participants agree by when an action plan is to be produced. Detail should reflect the system's effectiveness against the auditee's objectives, context and risks, and the auditee's familiarity with auditing; formality ranges from minutes with attendance to a simple communication of findings. As appropriate the meeting explains that evidence was sampled and may not represent overall effectiveness, the reporting method, how findings are to be addressed under the agreed process, the consequences of not addressing them, the findings and conclusions in a form management understands and acknowledges, and post-audit activities such as corrective action review, complaints and appeals. Diverging opinions should be discussed and resolved or recorded, and any improvement recommendations presented as non-binding.
This control maps to 12 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.