Operators shall establish adequate and appropriate policies, controls, and procedures to effectively reduce and manage the identified risks of non‑compliance of relevant products. These policies, controls, and procedures shall include risk‑management models, reporting, record‑keeping, internal controls, and compliance management, including the appointment of a management‑level compliance officer for non‑SME operators and an independent audit function to review the internal policies, controls, and procedures of all non‑SME operators.