Run internal audits at planned intervals that show whether the system meets the organization's own requirements and this standard and is effectively implemented and maintained (9.2.1). Plan, set up, run and maintain audit programmes that set how often audits happen, how they are done, who is responsible, what planning requires and how results are reported, weighted by how important the processes are and by earlier results; set criteria and scope for each audit; choose competent auditors and conduct audits objectively and impartially; send the results to the managers concerned, to the compliance function, to top management and, where appropriate, to the governing body; and keep evidence of the programme and results (9.2.2). Audits are reasonable, proportionate and risk-based, and look at procedures, controls and systems for bribery, actual or suspected, breaches of the policy or system, business associates' failures to meet the organization's anti-bribery requirements, and weaknesses or improvement opportunities in the system (9.2.3). For objectivity they are done by an independent function or person set up or appointed for the purpose, by the compliance function (except where the audit evaluates the system itself or the function's own work), by a suitable person from another department, by a suitable third party, or by a mix of these, and nobody audits their own work area (9.2.4).
This control maps to 41 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.