To elaborate slightly::
The CA/B is a standing meeting between two groups with very different objectives that have an ongoing need to reach some sort of agreement: the Certificate Authorities and the Browsers (in reality more or less the Operating System vendors except Mozilla represents the Free Unixes). This meeting must not appear to be a cartel because cartels are illegal, so it mustn't discuss prices or agree what products should or should not be marketed.
m.d.s.policy is de facto the only public oversight for the entire Web PKI. Mozilla as a Browser vendor (and as hinted above, on behalf of all the Free Unixes) gets to insist upon Rules, not only enforcing rules agreed at CAB, but also making its own rules on top for Certificate Authorities in its Trust Store. As a Charity one of its rules is that it insists on doing almost everything in Public using m.d.s.policy, there is no other obligation on a Certificate Authority to engage with the public at all, but Mozilla's rules force them to tell Mozilla important things via this public group and to answer questions impertinent members of the public (like me) ask them on m.d.s.policy.
Mozilla (and other Browser vendors) is entirely free to insist upon whatever rules they want. The CA/B does not bind them, like the UN it is a forum to meet, and to come to agreements, but it cannot force you to agree to anything you don't want. Two recent illustrative examples:
The CA/B took ages to reform the Domain Validation methods, terribly weak methods had been popular for years, with all sorts of stupid design flaws, and after it did finally vote on a reformed list of methods, CA members claimed a bunch of patents needed to be licensed stalling things for months extra. Mozilla cut through the bullshit and said essentially "See that list of ten methods you voted on that's stuck in Lawyer hell? Too bad, our policy now requires you obey the list which we're naming the Ten Blessed Methods"
Google wanted to reduce the maximum lifetime of new certificates. It takes ages to get CAs to introduce a new rule, and then years while the old certificates made under the old rule expire, too long for Google. So they made an ultimatum, fix it or we'll just tell Chrome to reject certificates after 90 days, and that's the new maximum certificate lifetime. The CA/B eventually voted through a compromise 825 days (which goes into effect tomorrow, 1 March 2018) instead of the previous 39 month limit.