If due diligence on a given transaction, project or activity, or on a given business associate relationship, shows existing controls cannot manage its bribery risks, and the organization cannot or will not add or strengthen controls or change the arrangement so the risk becomes manageable, it must: for something already under way, take steps suited to the risk and its nature to end, discontinue, suspend or pull out of it as soon as practicable; and for something proposed, delay it or decline to go ahead.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.