Management identifies the risks that threaten each stated control objective and designs, implements and documents controls suitably designed and, for a type 2 report, operating effectively to give reasonable assurance that the objectives are achieved; the auditor evaluates the completeness and accuracy of the risk identification and the linkage of each control to the risks, so the risk analysis must exist as a record, not only in the auditor's file.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.