Carry out bribery risk assessments regularly. Each one names the bribery risks that can reasonably be foreseen given the 4.1 factors, analyses, rates and ranks them, and judges whether the controls already in place are suitable and actually reduce them (4.5.1). Set criteria for judging the level of bribery risk in line with what the organization's policies and objectives say (4.5.2). Revisit the assessment regularly, at a timing and frequency the organization sets, and whenever its structure or activities change significantly (4.5.3). Keep documented evidence that the assessment was done and fed into the design or improvement of the system (4.5.4).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.