Run internal audits at planned intervals to learn whether the EOMS meets the organization's own requirements and this document and is effectively implemented and maintained. Plan, set up and keep an audit programme (frequency, methods, responsibilities, planning, reporting) that reflects EOMS objectives, process importance, interested party feedback and earlier audit results; define criteria and scope per audit; choose auditors so audits stay objective and impartial, with no auditor auditing their own work; report results to relevant management; identify improvement opportunities; take correction and corrective action without undue delay; and retain records of the programme and results (ISO 19011 gives guidance).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.