THE QUESTION
Can a registrant use compliance and/or risk-assessment tools provided by its audit firm to document and assess internal controls? And if so, under what circumstances (i.e., if part of audit or attestation agreement; if done with management, etc.)?

