Per PCAOB Auditing Standard AS 2201 paragraphs 4-14: plan the audit + scale + apply risk assessment + integrate with financial statement audit. Requirements include (a) integrate the audit of Internal Control Over Financial Reporting (ICFR) with the audit of financial statements + (b) scale the audit appropriate to the company including size + complexity + nature + risk + (c) apply risk assessment to identify accounts + disclosures + assertions presenting reasonable possibility of material misstatement + (d) consider entity-level controls + fraud risks + significant risks + risk of misstatement due to error or fraud + (e) document planning decisions including scaling + risk assessment + audit approach + integration decisions + (f) use the work of others (internal audit + others including third-party assurance) where appropriate per AS 2201 + AS 1205 / AS 2605.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.