The requirements specific to review are set here (text not held). Read with the cross-cutting aspects of 6.1.2 and the requirement pattern of 6.2.4, an auditor would expect review to be conducted by people informed of its purpose and of the criteria and requirements that govern it, planned and set out in a review protocol before it starts, transparent enough to monitor and adjust, supported by appropriate methods and metrics such as quality-control sampling, adapted as the criteria or the data change, and documented, including the privilege determinations made.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.