User entities receive the report, evaluate whether the objectives and tested controls cover the transactions they outsource, implement the complementary user entity controls the description assumes and keep evidence of them, and pass the report to their auditors, who use it under AU-C 402 (ISA 402) as evidence about the service organisation's controls after considering the auditor's competence and independence, the period, the tests and results, the deviations and the carve-outs; the held practice aid walks a user auditor's review through those points. The user entity, not the service organisation, remains responsible for its own financial reporting.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.