If the entity being assessed is a service provider:
Identify the customer/user documentation that requires non-consumer user passwords to meet minimum length requirements.
Describe how the observed processes confirm that non-consumer user passwords meet minimum password-length requirements.