SAMMY works best on screens 1024px wide or larger.
Risk Based Planning Assessment
A&A-03: Are independent audit and assurance assessments performed according to risk-based plans and policies?
Independent audit and assurance assessments should be based on risk-based plans that define audit objectives, scope, resources, timeline and deliverables, documentation and reporting requirements, use of relevant technology and data analysis techniques, costs, communication, and escalation protocols.

Both CSPs and CSCs may take guidance from industry standards like the Committee of Sponsoring Organizations (COSO) or the International Organization for Standardization (ISO) 31000 for risk management and risk-based planning.
Control implemented
Control ownership
Description

Perform independent audit and assurance assessments according to risk-based plans and policies.