The anti-bribery compliance function keeps assessing, continually, whether the system is adequate to manage the organization's bribery risks effectively and whether it is effectively implemented. It reports on adequacy and implementation, taking in what audits and investigations have found, both at planned intervals and ad hoc where fitting, to the governing body as well as top management, or to a committee one of them has set up for the purpose; the standard recommends reporting at least once a year and allows a business associate to help with the review provided its observations reach the function, top management and, where appropriate, the governing body.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.