The controller is accountable for complying with the Act and must use contractual or other reasonable means to provide a comparable level of protection while the personal information is being processed by a third party, domestically or internationally, subject to cross-border arrangement and cooperation; the IRR (section 50) restates this for information outsourced or transferred to a processor or third party.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.