Per PCAOB AS 2201 paragraphs 4, 22-27, 5: entity-level controls + period-end. Requirements include (a) evaluate Entity-Level Controls including control environment + risk assessment + monitoring + information + communication + COSO components + (b) evaluate the Period-End Financial Reporting Process including procedures used to enter transactions + initiate + authorise + record + process + report period-end financial information + (c) consider IT general controls + IT application controls + (d) consider management override + tone at the top + governance + ethics + (e) document evaluation including significant findings + conclusions + (f) determine extent + nature of further testing based on entity-level conclusions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.