Operators must carry out internal control or audit of compliance of processing of personal data with the law and with their internal documents, with periodicity defined by their internal regulations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.