The service organisation engages an independent service auditor to examine under AT-C 320 (and, where user entities abroad need it, ISAE 3402) a defined system: the services covered and the function the system performs, the user entities served, and either a specified date, for a type 1 report covering the description and how the controls are designed, or a specified period for a type 2 report that adds operating effectiveness and the tests and results. The scope and the description must not be so limited that user entities and their auditors could not use the report, which is a precondition the auditor tests before accepting.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.