Skip to content

Evidence request lists

ISO 37000:2021

Evidence request list. 59 controls, 59 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Enabling

GOV-ACCOUNT
Accountability Mechanisms

Establish clear accountability across governing body, executive, and operational layers with documented authorities.

Artefacts an auditor will ask for
  • Delegation of authority schedule
  • Role descriptions
  • Performance review records
  • Consequence framework
Where this commonly fails
  • Authority limits exceeded without escalation
  • No upward reporting on delegated decisions
  • Consequences inconsistent
GOV-DATA
Data Informed Decisions

Use accurate, reliable, and relevant data to inform governance decisions with documented decision trails.

Artefacts an auditor will ask for
  • Board paper standard
  • Data quality assessment
  • Decision register
  • Information policy
Where this commonly fails
  • Late or incomplete papers
  • Decisions not formally recorded
  • No data lineage
GOV-LEAD
Ethical Leadership

Demonstrate ethical leadership and tone from the top that drives values-based behaviour throughout the organization.

Artefacts an auditor will ask for
  • Values statement
  • Leadership messages
  • Culture assessment
  • Behavioural standards documentation
Where this commonly fails
  • Values not lived by leaders
  • No behavioural measurement
  • Ethical breaches not visible to board
GOV-OVERSIGHT
Governing Body Oversight

Provide structured oversight of management execution, performance, and risk by the governing body.

Artefacts an auditor will ask for
  • Board and committee charters
  • Annual board calendar
  • Management reports
  • Action tracker
Where this commonly fails
  • Committee remits overlap
  • No dedicated risk oversight
  • Management reports lack assurance
GOV-RISK
Risk Appetite and Tolerance

Establish risk appetite and tolerance aligned with strategy and oversee risk holistically.

Artefacts an auditor will ask for
  • Risk appetite statement
  • Risk dashboard
  • Emerging risk register
  • Board risk committee minutes
Where this commonly fails
  • Risk appetite qualitative only
  • No emerging risk scanning
  • Appetite not cascaded
GOV-SOCIAL
Social Responsibility Integration

Integrate social, environmental, and economic responsibilities into governance and decisions.

Artefacts an auditor will ask for
  • ESG strategy
  • Sustainability KPIs
  • Annual ESG disclosure
  • Independent assurance over ESG data
Where this commonly fails
  • ESG strategy disconnected from core strategy
  • Metrics unverified
  • No board ESG accountability
GOV-STAKE
Stakeholder Identification and Engagement

Identify, prioritize, and engage stakeholders to inform decisions and maintain legitimacy.

Artefacts an auditor will ask for
  • Stakeholder register
  • Engagement strategy
  • Materiality outputs
  • Decision papers citing stakeholder input
Where this commonly fails
  • Stakeholders identified but not engaged
  • No prioritization criteria
  • Feedback ignored by board
GOV-VIABLE
Long-Term Viability

Govern for long-term viability including financial, operational, and reputational resilience.

Artefacts an auditor will ask for
  • Viability statement
  • Stress test results
  • BCP and crisis plans
  • Reputational risk register
Where this commonly fails
  • Stress testing financial only
  • No reputational scenarios
  • Resilience siloed in operations

Enabling Principles

ISO37000-5.1
Oversight

Governing body exercises effective oversight over management's execution of strategy, risk, and performance.

Artefacts an auditor will ask for
  • Board charter
  • Board meeting agendas and minutes
  • Management reporting pack
  • Independent director attestations
Where this commonly fails
  • Board acts as rubber stamp
  • No structured oversight calendar
  • Management reports lack assurance
ISO37000-5.2
Accountability

Establish clear accountability for decisions, actions, and outcomes at governing body, management, and operational levels.

Artefacts an auditor will ask for
  • Delegation of authority matrix
  • Role descriptions
  • Board and executive evaluation reports
  • Accountability statements
Where this commonly fails
  • Authority limits unclear
  • No upward accountability for delegated decisions
  • Performance not tied to governance outcomes
ISO37000-5.3
Stakeholder Engagement

Identify, prioritize, and engage stakeholders to inform governance decisions and maintain trust.

Artefacts an auditor will ask for
  • Stakeholder register
  • Engagement calendar
  • Materiality assessment
  • Stakeholder feedback log
Where this commonly fails
  • Stakeholder list static and outdated
  • One-way communication only
  • No feedback into board decisions
ISO37000-5.4
Leadership

Demonstrate ethical leadership and tone from the top that reflects organizational values and purpose.

Artefacts an auditor will ask for
  • Board and executive code of ethics
  • Tone-from-the-top communications
  • Culture assessment results
  • Leadership development records
Where this commonly fails
  • Code exists but unenforced
  • Culture surveys not actioned
  • Leadership behaviour not measured
ISO37000-5.5
Data and Decisions

Base governance decisions on accurate, timely, and relevant data with documented decision processes.

Artefacts an auditor will ask for
  • Board information pack standards
  • Decision register
  • Data quality controls
  • Source documentation
Where this commonly fails
  • Board papers too voluminous to absorb
  • No data lineage to decisions
  • Verbal decisions undocumented
ISO37000-5.6
Risk Governance

Govern risk holistically including risk appetite, tolerance, and integration with strategy execution.

Artefacts an auditor will ask for
  • Risk appetite statement
  • Enterprise risk register
  • Board risk committee charter
  • Risk reporting pack
Where this commonly fails
  • Risk appetite not quantified
  • Risks managed in silos
  • No emerging risk scanning
ISO37000-5.7
Social Responsibility

Account for social, environmental, and economic impacts in governance decisions consistent with sustainable development.

Artefacts an auditor will ask for
  • Sustainability policy
  • ESG materiality matrix
  • Annual sustainability report
  • Impact measurement framework
Where this commonly fails
  • ESG treated as compliance not strategy
  • No board ESG competence
  • Greenwashing risk uncontrolled
ISO37000-5.8
Viability and Performance

Govern for long-term viability balancing performance, resilience, and adaptability over time.

Artefacts an auditor will ask for
  • Long-term viability statement
  • Scenario analysis outputs
  • Business continuity plan
  • Capital adequacy assessment
Where this commonly fails
  • Viability assessed only annually
  • No stress testing of strategy
  • Resilience treated as IT only

Foundational

GOV-PURPOSE
Organizational Purpose

Articulate a clear purpose that anchors governance choices and explains why the organization exists for stakeholders.

Artefacts an auditor will ask for
  • Written purpose statement
  • Board resolution
  • Internal and external communications
  • Onboarding materials referencing purpose
Where this commonly fails
  • Purpose conflated with vision or mission
  • Purpose not used in decisions
  • No periodic reaffirmation
GOV-STRATEGY
Strategy Setting and Review

Set, approve, and periodically review strategy that translates purpose into measurable objectives and resource decisions.

Artefacts an auditor will ask for
  • Approved strategy document
  • Objective cascade
  • Annual strategy review minutes
  • Resource allocation plan
Where this commonly fails
  • Strategy not refreshed
  • No link to capital allocation
  • Cascade stops at executive level
GOV-VALUE
Value Generation Across Horizons

Generate and protect value for the organization and stakeholders over short, medium, and long-term time frames.

Artefacts an auditor will ask for
  • Value generation framework
  • Multi-year plan
  • Stakeholder value mapping
  • Integrated KPI set
Where this commonly fails
  • Annual financial focus only
  • No long-term value indicators
  • Stakeholder value undefined

Foundational Principles

ISO37000-4.1
Purpose

Define and articulate the organization's purpose as the primary driver of governance decisions and value generation for stakeholders.

Artefacts an auditor will ask for
  • Documented organizational purpose
  • Board minutes approving purpose
  • Purpose communication plan
  • Stakeholder mapping to purpose
Where this commonly fails
  • Purpose treated as marketing slogan rather than governance anchor
  • No linkage between purpose and capital allocation
  • Purpose not refreshed after material business change
ISO37000-4.2
Value Generation

Generate value for the organization and its stakeholders over short, medium, and long-term horizons through sustainable governance.

Artefacts an auditor will ask for
  • Multi-horizon value model
  • Stakeholder value map
  • Integrated reporting outputs
  • Capital allocation policy
Where this commonly fails
  • Short-term financial focus only
  • No non-financial value measurement
  • Stakeholder value undefined
ISO37000-4.3
Strategy

Establish strategy that operationalizes purpose, allocates resources, and addresses risks and opportunities across time horizons.

Artefacts an auditor will ask for
  • Board-approved strategy document
  • Strategic objectives cascade
  • Strategy-risk register linkage
  • Annual strategy review minutes
Where this commonly fails
  • Strategy disconnected from purpose
  • No periodic strategy refresh
  • Risk appetite not aligned with strategy

Governance Foundations

ISO37000-GF-01
Cl. 6.9 Ethical behavior - Acting with integrity, honesty, equity, and social responsibility

Ethical behavior - acting with integrity, honesty, equity, and social responsibility. Control from ISO 37000:2021 framework, domain: Governance Foundations.

Artefacts an auditor will ask for
  • Code of ethics
  • Accountability charter
  • Disclosure policy
  • Stakeholder rights register
Where this commonly fails
  • Code not enforced at executive level
  • Disclosures not timely
  • Stakeholder rights not mapped
ISO37000-GF-02
Cl. 6.5 Accountability - Being answerable for decisions and actions to stakeholders

Accountability - being answerable for decisions and actions to stakeholders. Control from ISO 37000:2021 framework, domain: Governance Foundations.

Artefacts an auditor will ask for
  • Code of ethics
  • Accountability charter
  • Disclosure policy
  • Stakeholder rights register
Where this commonly fails
  • Code not enforced at executive level
  • Disclosures not timely
  • Stakeholder rights not mapped
ISO37000-GF-03
Cl. 6.7 Transparency - Disclosing information to enable informed decision-making by stakeholders

Transparency - disclosing information to enable informed decision-making by stakeholders. Control from ISO 37000:2021 framework, domain: Governance Foundations.

Artefacts an auditor will ask for
  • Code of ethics
  • Accountability charter
  • Disclosure policy
  • Stakeholder rights register
Where this commonly fails
  • Code not enforced at executive level
  • Disclosures not timely
  • Stakeholder rights not mapped
ISO37000-GF-04
Cl. 5 Rule of law - Compliance with applicable laws, regulations, and governance codes

Rule of law - compliance with laws, regulations, and governance codes. Control from ISO 37000:2021 framework, domain: Governance Foundations.

Artefacts an auditor will ask for
  • Code of ethics
  • Accountability charter
  • Disclosure policy
  • Stakeholder rights register
Where this commonly fails
  • Code not enforced at executive level
  • Disclosures not timely
  • Stakeholder rights not mapped
ISO37000-GF-05
Cl. 6.6 Stakeholder rights - Respecting and protecting stakeholder rights across governance decisions

Rights of stakeholders - respecting and protecting stakeholder rights. Control from ISO 37000:2021 framework, domain: Governance Foundations.

Artefacts an auditor will ask for
  • Code of ethics
  • Accountability charter
  • Disclosure policy
  • Stakeholder rights register
Where this commonly fails
  • Code not enforced at executive level
  • Disclosures not timely
  • Stakeholder rights not mapped

Operational

GOV-ASSURE
Assurance Arrangements

Obtain independent assurance over governance, risk, controls, and reported information through combined assurance.

Artefacts an auditor will ask for
  • Internal audit plan
  • External audit reports
  • Combined assurance map
  • Assurance findings tracker
Where this commonly fails
  • Assurance silos
  • Findings unresolved
  • No combined view to board
GOV-COI
Conflicts of Interest

Identify, declare, and manage conflicts of interest with transparent recusal and decisioning.

Artefacts an auditor will ask for
  • COI policy
  • Disclosure register
  • Recusal minutes
  • Related party register
Where this commonly fails
  • Disclosures stale
  • Recusals undocumented
  • Related party transactions not approved
GOV-COMP
Governing Body Composition

Maintain a governing body with appropriate skills, independence, diversity, and tenure for current and future needs.

Artefacts an auditor will ask for
  • Skills matrix
  • Independence assessment
  • Succession plan
  • Diversity policy
Where this commonly fails
  • Composition static
  • No board renewal plan
  • Diversity treated as gender only
GOV-EVAL
Governing Body Evaluation

Evaluate governing body and committee performance to drive continuous improvement.

Artefacts an auditor will ask for
  • Evaluation methodology
  • Annual evaluation outputs
  • Triennial external review
  • Director development plans
Where this commonly fails
  • Self-assessment only
  • Findings not actioned
  • No external benchmarking
GOV-REM
Remuneration Governance

Govern executive and board remuneration aligned to purpose, strategy, performance, and stakeholder expectations.

Artefacts an auditor will ask for
  • Remuneration policy
  • Scorecards
  • Committee minutes
  • Annual remuneration disclosure
Where this commonly fails
  • Short-term focus
  • No malus or clawback
  • Disclosure incomplete
GOV-REPORT
Reporting and Transparency

Provide balanced, transparent, and timely reporting on performance, prospects, and governance to stakeholders.

Artefacts an auditor will ask for
  • Integrated annual report
  • Disclosure controls policy
  • Materiality assessment
  • Reporting calendar
Where this commonly fails
  • Selective disclosure
  • No materiality process
  • Reports lack forward-looking content
ISO37000-6.1
Governance Body Composition

Compose governing body with appropriate skills, independence, diversity, and capacity to discharge duties.

Artefacts an auditor will ask for
  • Board skills matrix
  • Independence declarations
  • Diversity policy and metrics
  • Succession plan
Where this commonly fails
  • Skills matrix not refreshed
  • Independence assessed by tenure only
  • No diversity targets
ISO37000-6.2
Governing Body Effectiveness

Evaluate and continuously improve governing body effectiveness through structured reviews and development.

Artefacts an auditor will ask for
  • Annual board evaluation report
  • Director induction program
  • Continuing education log
  • Evaluation action plan
Where this commonly fails
  • Self-assessment only no external review
  • Evaluation findings not actioned
  • No induction for new directors
ISO37000-6.3
Conflict of Interest

Identify, disclose, and manage conflicts of interest at all governance levels.

Artefacts an auditor will ask for
  • Conflicts of interest policy
  • Annual disclosure declarations
  • Recusal records in minutes
  • Related party transactions log
Where this commonly fails
  • Annual disclosure only
  • No mid-year update process
  • Recusals not documented
ISO37000-6.4
Remuneration

Govern remuneration to align with purpose, strategy, performance, and stakeholder interests over appropriate horizons.

Artefacts an auditor will ask for
  • Board-approved remuneration policy
  • Performance scorecards
  • Remuneration committee charter
  • Annual remuneration report
Where this commonly fails
  • Short-term metrics dominate
  • No clawback provisions
  • Pay ratios undisclosed
ISO37000-6.5
Assurance

Obtain independent assurance over governance arrangements, controls, and reported information.

Artefacts an auditor will ask for
  • Internal audit charter and plan
  • External audit reports
  • Combined assurance map
  • Assurance findings tracker
Where this commonly fails
  • No combined assurance view
  • Internal audit lacks independence
  • Findings not tracked to closure
ISO37000-6.6
Reporting and Transparency

Provide transparent, balanced, and timely reporting on governance, performance, and prospects to stakeholders.

Artefacts an auditor will ask for
  • Annual integrated report
  • Disclosure controls policy
  • Materiality determination
  • Stakeholder communication log
Where this commonly fails
  • Reporting emphasises positives only
  • No materiality process
  • Late or inconsistent reporting

Organizational Culture and Capability

ISO37000-CC-01
Cl. 5.2 Governance culture - Tone at the top promoting integrity, accountability, and transparency

Governance culture - tone at the top promoting integrity, accountability, and trust. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.

Artefacts an auditor will ask for
  • Tone at the top statement
  • Resilience plan
  • Leadership development plan
  • Data governance framework
Where this commonly fails
  • Tone not measured at working level
  • Resilience plan untested
  • Data quality not governed
ISO37000-CC-02
Cl. 7.6 Organizational resilience - Capacity to anticipate, respond to, and recover from disruptions

Organizational resilience - capacity to anticipate, respond to, and recover from disruptions. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.

Artefacts an auditor will ask for
  • Tone at the top statement
  • Resilience plan
  • Leadership development plan
  • Data governance framework
Where this commonly fails
  • Tone not measured at working level
  • Resilience plan untested
  • Data quality not governed
ISO37000-CC-03
Cl. 4.3.2 Competence - Leadership development, succession planning, and talent management for governance

Human governance - leadership development, succession, and talent management. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.

Artefacts an auditor will ask for
  • Tone at the top statement
  • Resilience plan
  • Leadership development plan
  • Data governance framework
Where this commonly fails
  • Tone not measured at working level
  • Resilience plan untested
  • Data quality not governed
ISO37000-CC-04
Cl. 6.8 Data and decisions - Data governance and information management for informed decision-making

Data governance and information management for informed decision-making. Control from ISO 37000:2021 framework, domain: Organizational Culture and Capability.

Artefacts an auditor will ask for
  • Tone at the top statement
  • Resilience plan
  • Leadership development plan
  • Data governance framework
Where this commonly fails
  • Tone not measured at working level
  • Resilience plan untested
  • Data quality not governed

Oversight and Assurance

ISO37000-OA-01
Cl. 4.3 Governing body - Composition, independence, competence, and commitment of the governing body

Governing body effectiveness - composition, independence, competence, and commitment. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.

Artefacts an auditor will ask for
  • Board composition matrix
  • Delegation of authority
  • Internal control framework
  • Board evaluation report
Where this commonly fails
  • Independence criteria not enforced
  • Delegation thresholds unclear
  • Board evaluation light
ISO37000-OA-02
Cl. 4.2.2 Delegation - Clear mandates with accountability for delegated oversight of management

Delegation and oversight of management - clear mandates with accountability. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.

Artefacts an auditor will ask for
  • Board composition matrix
  • Delegation of authority
  • Internal control framework
  • Board evaluation report
Where this commonly fails
  • Independence criteria not enforced
  • Delegation thresholds unclear
  • Board evaluation light
ISO37000-OA-03
Cl. 6.4 Oversight - Internal control and assurance systems for managing risks and ensuring compliance

Internal control and assurance - systems for managing risks and ensuring compliance. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.

Artefacts an auditor will ask for
  • Board composition matrix
  • Delegation of authority
  • Internal control framework
  • Board evaluation report
Where this commonly fails
  • Independence criteria not enforced
  • Delegation thresholds unclear
  • Board evaluation light
ISO37000-OA-04
Cl. 7.5 Monitoring and evaluation - Regular review of governance effectiveness and performance

Monitoring and evaluation - regular review of governance effectiveness. Control from ISO 37000:2021 framework, domain: Oversight and Assurance.

Artefacts an auditor will ask for
  • Board composition matrix
  • Delegation of authority
  • Internal control framework
  • Board evaluation report
Where this commonly fails
  • Independence criteria not enforced
  • Delegation thresholds unclear
  • Board evaluation light

Performance

GOV-ADAPT
Adaptive Governance

Adapt governance arrangements in response to context changes, performance feedback, and emerging issues.

Artefacts an auditor will ask for
  • Horizon scan
  • Lessons learned register
  • Governance change log
  • Crisis after-action reviews
Where this commonly fails
  • Reactive change only
  • Lessons not captured
  • No systematic scanning
GOV-OUTCOME
Governance Outcomes Measurement

Measure governance outcomes including value, ethics, and stakeholder trust to drive accountability and improvement.

Artefacts an auditor will ask for
  • Governance KPI set
  • Annual outcome report
  • Improvement plan
  • Trust indicators
Where this commonly fails
  • No outcome metrics
  • Improvement reactive only
  • Trust not measured
ISO37000-7.1
Governance Outcomes

Define, measure, and review governance outcomes to demonstrate value creation and continuous improvement.

Artefacts an auditor will ask for
  • Governance KPI dashboard
  • Annual governance review
  • Benchmarking studies
  • Improvement action log
Where this commonly fails
  • No outcome metrics defined
  • Improvement actions not tracked
  • No external benchmarking
ISO37000-7.2
Adapting Governance

Adapt governance arrangements in response to internal changes, external context, and lessons learned.

Artefacts an auditor will ask for
  • Governance change log
  • Lessons learned register
  • Horizon scan reports
  • Board reflection notes
Where this commonly fails
  • Governance reviewed only after incident
  • No structured horizon scanning
  • Lessons not captured

Purpose and Value Generation

ISO37000-PV-01
Cl. 6.1 Purpose - Defining organizational purpose aligned with stakeholder expectations

Defining organizational purpose aligned with stakeholder expectations. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.

Artefacts an auditor will ask for
  • Purpose statement
  • Value creation model
  • Stakeholder engagement plan
  • Sustainability report
Where this commonly fails
  • Purpose not operationalized
  • Value model not integrated with strategy
  • Stakeholder engagement reactive
ISO37000-PV-02
Cl. 6.2 Value generation - Creating and preserving value for the organization and stakeholders over time

Value generation for the organization and stakeholders over time. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.

Artefacts an auditor will ask for
  • Purpose statement
  • Value creation model
  • Stakeholder engagement plan
  • Sustainability report
Where this commonly fails
  • Purpose not operationalized
  • Value model not integrated with strategy
  • Stakeholder engagement reactive
ISO37000-PV-03
Cl. 6.6 Stakeholder engagement - Understanding and responding to stakeholder interests and expectations

Stakeholder inclusiveness - understanding and responding to stakeholder interests. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.

Artefacts an auditor will ask for
  • Purpose statement
  • Value creation model
  • Stakeholder engagement plan
  • Sustainability report
Where this commonly fails
  • Purpose not operationalized
  • Value model not integrated with strategy
  • Stakeholder engagement reactive
ISO37000-PV-04
Cl. 6.10 Social responsibility - Integrating economic, social, and environmental considerations into governance

Sustainable development - integrating economic, social, and environmental considerations. Control from ISO 37000:2021 framework, domain: Purpose and Value Generation.

Artefacts an auditor will ask for
  • Purpose statement
  • Value creation model
  • Stakeholder engagement plan
  • Sustainability report
Where this commonly fails
  • Purpose not operationalized
  • Value model not integrated with strategy
  • Stakeholder engagement reactive

Strategy and Direction

ISO37000-SD-01
Cl. 6.3 Strategy - Formulating strategy aligned with organizational purpose and stakeholder expectations

Strategy formulation aligned with organizational purpose and stakeholder expectations. Control from ISO 37000:2021 framework, domain: Strategy and Direction.

Artefacts an auditor will ask for
  • Strategic plan
  • Risk governance charter
  • Resource allocation framework
  • Performance scorecard
Where this commonly fails
  • Strategy not stress-tested
  • Risk governance not board-led
  • Resource allocation opaque
ISO37000-SD-02
Cl. 7.3 Risk governance - Identifying and managing risks to strategic objectives through risk-based thinking

Risk-based thinking - identifying and managing risks to strategic objectives. Control from ISO 37000:2021 framework, domain: Strategy and Direction.

Artefacts an auditor will ask for
  • Strategic plan
  • Risk governance charter
  • Resource allocation framework
  • Performance scorecard
Where this commonly fails
  • Strategy not stress-tested
  • Risk governance not board-led
  • Resource allocation opaque
ISO37000-SD-03
Cl. 7.4 Resource governance - Ensuring resources are deployed to achieve strategic priorities and generate value

Resource allocation - ensuring resources are deployed to achieve strategic priorities. Control from ISO 37000:2021 framework, domain: Strategy and Direction.

Artefacts an auditor will ask for
  • Strategic plan
  • Risk governance charter
  • Resource allocation framework
  • Performance scorecard
Where this commonly fails
  • Strategy not stress-tested
  • Risk governance not board-led
  • Resource allocation opaque
ISO37000-SD-04
Cl. 6.11 Viability and performance - Setting measurable objectives and monitoring outcomes for sustained performance

Performance-based governance - setting measurable objectives and monitoring outcomes. Control from ISO 37000:2021 framework, domain: Strategy and Direction.

Artefacts an auditor will ask for
  • Strategic plan
  • Risk governance charter
  • Resource allocation framework
  • Performance scorecard
Where this commonly fails
  • Strategy not stress-tested
  • Risk governance not board-led
  • Resource allocation opaque
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.