The requirements specific to processing are set here (text not held). Part 1 states what processing must be backed by: defensible audit procedures, quality-control measures that include validating the data, and chain-of-custody documentation tracking file changes through the processing stages. Read with the cross-cutting aspects of 6.1.2 and the requirement pattern of 6.2.4, an auditor would also expect processing to be planned and specified in advance, performed by people informed of the requirements, transparent about the filters and reductions applied, supported by metrics, adapted when exceptions appear, and documented so that the reviewed set reconciles to what was collected.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.