Knowing which regulations apply to you is one thing. Knowing whether you actually meet them is another entirely. A compliance gap analysis is the structured way to answer the second question: it compares what your obligations require against what your organization currently does, identifies every gap, and turns those gaps into a prioritized remediation plan. Done well, it converts a vague unease about compliance into a concrete, fundable action list.
What You'll Learn
You will learn what a compliance gap analysis is, when to run one, a four-step method from baseline to remediation plan, how to score maturity, how to read a gap table, and how to prioritize which gaps to close first.
What a Compliance Gap Analysis Is
A compliance gap analysis is a structured assessment that compares the requirements an organization must meet (the baseline) against its current state, identifies where the two diverge (the gaps), and produces a plan to close them. The "gap" is the distance between required and actual.
It is the diagnostic that sits between obligation mapping and remediation. Where obligation mapping tells you what you must do, and a compliance register tracks whether you are doing it, a gap analysis is the point-in-time deep dive that establishes the truth and sets the agenda for improvement.
When to Run a Gap Analysis
A gap analysis is a focused exercise, not a continuous one. Common triggers include:
- New regulation: A law takes effect (or a new one is enacted) and you need to know how far you are from compliance.
- Entering a new market: Expanding into a new jurisdiction brings a new obligation set to assess against.
- Pre-certification or pre-audit: Before pursuing an ISO certification or facing a regulatory audit, a gap analysis surfaces problems while you can still fix them.
- After an incident or finding: A breach or audit finding signals that gaps exist; a structured analysis finds the rest.
- M&A due diligence: Acquiring an entity means inheriting its compliance posture, and a gap analysis quantifies the liability.
- Periodic health check: Even without a trigger, a periodic gap analysis keeps a maturing program honest.
Step 1: Establish the Requirements Baseline
You cannot measure a gap without a clear definition of "compliant." The baseline is the complete set of obligations the analysis will assess against, ideally drawn straight from your obligation library and compliance register so the assessment inherits work already done.
For each obligation in scope, state the requirement precisely enough that an assessor can judge whether it is met. "Handle data securely" is not assessable; "encrypt personal data at rest and in transit" is. The quality of the baseline determines the quality of every gap you find.
Step 2: Assess the Current State
With the baseline fixed, examine what the organization actually does against each requirement. This is evidence-gathering, not opinion-collecting. For each obligation, determine:
- Is there a control? A policy, process, or system intended to satisfy the requirement.
- Does it operate? Designed controls that do not actually run are still gaps.
- Is there evidence? Can you demonstrate the control operates, or only assert it?
Gather current-state findings from documents, system configurations, interviews, and direct observation. Lean on compliance evidence rather than verbal assurance. An "assessment" built on what people say they do, rather than what records show, is worthless.
Important
A control that exists on paper but is not operating is a gap, not compliance. The most dangerous gap analyses are the ones that mark an obligation "met" because a policy document exists, without checking whether anyone follows it. Always test operation, not just existence.
Want the full framework with worked examples?
Step 3: Identify and Classify the Gaps
A gap is any obligation where the current state falls short of the requirement. For each gap, capture what is missing, how serious it is, and what closing it would take. Classifying gaps by severity is essential for prioritization later:
| Severity | Definition | Typical Response |
|---|---|---|
| Critical | No control for a high-penalty or high-harm obligation | Immediate remediation; escalate to leadership |
| High | Control absent or failing on a significant obligation | Remediate within the current cycle |
| Medium | Control exists but is partial, inconsistent, or unevidenced | Scheduled improvement |
| Low | Minor weakness; obligation substantially met | Monitor; address opportunistically |
Step 4: Score Maturity
Beyond a binary met/not-met, maturity scoring captures how well an obligation is satisfied. It gives leadership a richer picture and lets you track improvement over time rather than just counting failures. A common five-level scale:
| Level | Maturity | Description |
|---|---|---|
| 0 | None | No control exists; obligation not addressed |
| 1 | Initial | Ad hoc, undocumented, dependent on individuals |
| 2 | Defined | Documented control exists but is inconsistently applied |
| 3 | Managed | Control operates consistently and is evidenced |
| 4 | Optimized | Control is measured, reviewed, and continuously improved |
Scoring each obligation on this scale turns the gap analysis into a maturity baseline you can re-measure later to show progress. That is useful for board reporting and for demonstrating a maturing program to regulators.
A Worked Gap Analysis Table
Bringing the pieces together, a gap analysis table records the requirement, current state, gap, severity, maturity, and remediation in one view:
| Obligation | Current State | Gap | Severity | Maturity |
|---|---|---|---|---|
| Encrypt personal data at rest | Production databases encrypted; backups are not | Backup encryption missing | High | 2 |
| Maintain records of processing | Informal spreadsheet, last updated 14 months ago | No maintained, current record | Medium | 1 |
| Notify breaches within 72 hours | Documented procedure, tested in last drill | None | n/a | 3 |
| Appoint an Information Officer | No appointment made | Role unfilled and unregistered | Critical | 0 |
Reading the table
The Information Officer obligation scores 0 maturity and Critical severity. Nothing exists and the consequence of non-compliance is high, so it goes to the top of the remediation queue. Breach notification scores 3 with no gap, so it is working and needs only monitoring. Backup encryption is a High gap at maturity 2: a real control exists but does not cover everything, so it is a targeted fix rather than a build-from-scratch.
Step 5: Build and Prioritize the Remediation Plan
The deliverable of a gap analysis is not the list of gaps. It is the plan to close them. For each gap, define a remediation action, an owner, a target date, and the resource required. Then prioritize, because you cannot fix everything at once.
Prioritize on two axes: severity (the consequence of leaving the gap open) and effort (what it takes to close). This yields a sensible sequence:
- Critical and high-severity gaps first, regardless of effort, because these carry the real exposure.
- Quick wins next, meaning low-effort medium gaps that improve posture cheaply.
- High-effort, lower-severity gaps scheduled into longer-term roadmaps.
Pro Tip
Feed every remediation action back into your compliance register and link each open gap to a risk in your risk register. That way the gap analysis does not become a one-off report that gathers dust. It becomes live, tracked work with owners and deadlines.
Common Mistakes to Avoid
1. A vague baseline
If the requirement is not stated precisely, the assessor cannot judge whether it is met, and the whole analysis becomes subjective.
2. Confusing existence with operation
Marking an obligation compliant because a policy document exists, without testing whether the control actually runs, produces false assurance.
3. Stopping at the gap list
A gap analysis without a prioritized, owned remediation plan is a diagnosis with no treatment. The plan is the point.
4. Ignoring maturity
Binary met/not-met hides the difference between a barely-working control and an optimized one. Maturity scoring lets you show and track real progress.
5. Treating it as a one-time event
Compliance posture decays. Re-run gap analyses periodically and after major changes, and track remediation to closure rather than declaring victory at the report.
Summary
- A compliance gap analysis measures the distance between what obligations require and what you actually do
- Run one when new regulation lands, before audits or certification, after incidents, during M&A, or as a periodic health check
- The method is: establish a precise baseline, assess the evidenced current state, identify and classify gaps, and build a prioritized remediation plan
- Maturity scoring captures how well each obligation is met and lets you track improvement over time
- Prioritize remediation by severity and effort, and feed actions back into the compliance and risk registers
Frequently Asked Questions
What is the difference between a gap analysis and an audit?
A gap analysis is usually an internal, forward-looking exercise to find and close gaps before someone else does, so it is improvement-oriented. An audit is a formal, often independent evaluation that gives an opinion on compliance at a point in time. Teams frequently run a gap analysis precisely to prepare for an upcoming audit.
How long does a compliance gap analysis take?
It depends on scope and on how much groundwork already exists. With a maintained obligation library and compliance register to draw on, a focused analysis of one regulation can take days. A broad, multi-jurisdiction assessment starting from scratch can take weeks. Reusing existing obligation mapping is the single biggest accelerator.
Do I need maturity scoring, or is met/not-met enough?
Binary met/not-met is enough to find hard failures, but maturity scoring is more useful for a maturing program. It distinguishes a control that barely works from one that is well managed, and it lets you re-measure later to demonstrate improvement to leadership and regulators. For a first pass, even a simple three-level scale adds value.
How do I prioritize which gaps to fix first?
Prioritize by severity first, because critical and high gaps carry the real exposure and should be addressed regardless of effort. Then pursue low-effort quick wins among the remaining gaps, and schedule high-effort, lower-severity items into longer roadmaps. Linking each gap to a risk rating helps make the trade-offs explicit.
What happens to the gaps after the analysis?
Each gap should become a tracked remediation action with an owner and a due date, recorded in the compliance register and linked to a risk. Then you track and report status as gaps close. A gap analysis that ends at the report, with no tracked follow-through, has wasted most of its value.
How often should I run a gap analysis?
Run a full gap analysis on each major trigger, such as new regulation, a new market, pre-audit, post-incident, or M&A, and a lighter periodic health check at least annually. Between full analyses, continuous obligation tracking in your register catches drift, so you are not relying on a single annual snapshot.
Save this guide for later
Download the PDF version to read offline or share with your team.

