The governing body together with top management shall set a compliance policy that is appropriate to the organization's purpose, provides a framework for setting compliance objectives, includes a commitment to satisfy applicable requirements and a commitment to continual improvement of the CMS. The policy shall be consistent with the organization's values, objectives and strategy; require adherence to the compliance obligations; support the compliance governance principles of 5.1.3; refer to and describe the compliance function; outline the consequences of not complying with obligations, policies, processes and procedures; encourage the raising of concerns and prohibit retaliation in any form; be written in plain language so all personnel understand its principles and intent; be implemented and enforced; be available as documented information; be communicated within the organization; and be available to interested parties as appropriate.
This control maps to 16 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.