Now, why wasn't the requirement enforced? Or why didn't the audit turn this up? Good questions.
But all of those are going to have some kind of requirement, e.g. FedRAMP.