The governing body together with top management shall show leadership of, and commitment to, the CMS by ensuring the compliance policy and objectives are established and compatible with the strategic direction; integrating CMS requirements into business processes; ensuring resources are available; conveying why effective compliance management and conformity with the CMS matter; making sure the CMS delivers what it is meant to; guiding and supporting people to contribute to its effectiveness; promoting continual improvement; and supporting other relevant roles to demonstrate leadership in their areas. They shall also establish and uphold the organization's values; make sure policies, processes and procedures are drawn up and put into practice so the compliance objectives are met; ensure they are informed in a timely way of compliance matters including noncompliances and that appropriate action is taken; ensure the compliance commitment is maintained and noncompliance and noncompliant behaviour are dealt with appropriately; make sure job descriptions carry compliance responsibilities where suitable; name or appoint a compliance function (5.3.2); and ensure a mechanism for raising and addressing concerns exists per 8.3.
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.