Guidance: an opening meeting, chaired by the team leader and attended by the auditee's management and, where suitable, by the people in charge of the functions being audited, should confirm agreement to the audit plan, introduce the team and their roles and ensure all planned activities can be performed, with an opportunity for questions; its formality should match the auditee's familiarity with auditing, from a simple notice for a small internal audit to a formal meeting with attendance records. As appropriate it introduces observers, guides and interpreters and the methods for managing risks from the team's presence; confirms objectives, scope and criteria, the plan and arrangements including the closing meeting and interim meetings, communication channels, language, progress updates, resources and facilities, confidentiality and information security, access, safety, security and emergency arrangements, and site activities that could affect the audit; and presents the method of reporting findings including grading, the conditions for termination, how findings are handled during the audit, and the auditee's feedback, complaints and appeals route.
This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.