Where an internal audit function exists within the service organisation, its responsibilities and activities are described to the auditor, and internal audit and regulatory examination reports relating to the services and the scope are made available, because the auditor reads them, takes their findings into the risk assessment and may use internal audit work in testing, in which case the tests and results section describes that work.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.