Requirement 0047 (Part Two: Risk, section 6.2 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Security risks arising from contractual arrangements for the provision of goods and services are managed, reassessed and adjusted over the life of a contract. Third-party risk management covers the relationship lifecycle, including offshore and jurisdictional risks and foreign lawful-access exposure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.