Guidance: an audit ends once every planned activity is done, or at another point agreed with the client, for example where an unexpected situation prevented completion. The parties should agree whether documented information is kept or disposed of, in line with the programme and any requirements that apply. Unless the law requires it, neither the team nor the programme manager should reveal audit information or the report to anyone else without the client's and, where appropriate, the auditee's explicit approval, informing them promptly if disclosure is required. Lessons learned may point to risks and opportunities for both the programme and the auditee.
This control maps to 13 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.