Where the service organisation is responsible for fraud, for uncorrected misstatements or for breaches of laws or regulations that are more than clearly trivial and could affect user entities, the service organisation communicates the matter appropriately to the affected user entities; if it does not, the auditor takes appropriate action, which the auditor's engagement letter and the report's other communication responsibilities anticipate.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.