Where achieving a control objective depends on controls that user entities themselves must implement (for instance, that user entities authorise their own users or review the reports they receive), the description identifies those complementary user entity controls, the assertion and the report say that the objectives can be achieved only if user entities apply them, and the auditor states that it has not evaluated them.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.