Where the auditor's tests find deviations the service organisation supplies the nature and cause, the expected rate and the compensating or other controls, so that the auditor can decide whether the testing still supports effective operation, whether more testing is needed or whether the control failed; deviations resulting from fraud, and any breach of law, fraud or uncorrected misstatement for which the organisation is responsible and which could affect user entities, are assessed for their effect on the assertion, the description, the objectives and the report, and all deviations are reported in the tests and results even where the objective is concluded achieved.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.