Records of access to and provision of personal credit information shall be maintained for at least three years with prescribed details including identity of accessor, purpose, items accessed, and disclosure recipients, supporting investigation and audit.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.