Require, through procedures, that every organization under the organization's control either runs the organization's anti-bribery system or operates anti-bribery controls of its own, either way so far as reasonable and proportionate given the bribery risks it is exposed to under the 4.5 assessment (8.5.1). For business associates it does not control that the risk assessment or due diligence shows to carry more than low bribery risk, where their own controls would help reduce it, the procedures must establish whether the associate has controls that manage the relevant risk and, where it has none or they cannot be verified, require it where practicable to put controls in place for the transaction, project or activity concerned or, where that is not practicable, treat the gap as a factor when assessing the relationship's bribery risk (4.5, 8.2) and deciding how to manage it (8.3 to 8.5) (8.5.2).
This control maps to 8 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.