The organization makes sure that any output failing to meet its requirements is identified and controlled so that it is not used or delivered by mistake. It acts on the nonconformity in proportion to what the nonconformity is and how it affects whether products and services conform, and this applies also to outputs found to be nonconforming after delivery. Possible actions include: correcting the output; segregating or containing it; returning it or suspending supply; informing the customer; and getting authorization to accept it under concession. When a nonconforming output is corrected, its conformity is verified again. Documented information is retained that describes the nonconformity, what was done about it, any concession obtained, and who decided the action.
This control maps to 7 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.