KITE 2025 New Product Award — Local IT | SACEEC

What Is a Compliance Gap Analysis? Steps, Scoring & Examples

A compliance gap analysis measures the distance between what regulations require and what you actually do, then turns that distance into a remediation plan.

Free PDF GuideDownload this guide as a PDF

Knowing which regulations apply to you is one thing. Knowing whether you actually meet them is another entirely. A compliance gap analysis is the structured way to answer the second question: it compares what your obligations require against what your organization currently does, identifies every gap, and turns those gaps into a prioritized remediation plan. Done well, it converts a vague unease about compliance into a concrete, fundable action list.

Watch: What a compliance gap analysis is and how to run one Watch: How to run a compliance gap analysis (short tutorial)
i

What You'll Learn

You will learn what a compliance gap analysis is, when to run one, a four-step method from baseline to remediation plan, how to score maturity, how to read a gap table, and how to prioritize which gaps to close first.

What a Compliance Gap Analysis Is

A compliance gap analysis is a structured assessment that compares the requirements an organization must meet (the baseline) against its current state, identifies where the two diverge (the gaps), and produces a plan to close them. The "gap" is the distance between required and actual.

It is the diagnostic that sits between obligation mapping and remediation. Where obligation mapping tells you what you must do, and a compliance register tracks whether you are doing it, a gap analysis is the point-in-time deep dive that establishes the truth and sets the agenda for improvement.

When to Run a Gap Analysis

A gap analysis is a focused exercise, not a continuous one. Common triggers include:

  • New regulation: A law takes effect (or a new one is enacted) and you need to know how far you are from compliance.
  • Entering a new market: Expanding into a new jurisdiction brings a new obligation set to assess against.
  • Pre-certification or pre-audit: Before pursuing an ISO certification or facing a regulatory audit, a gap analysis surfaces problems while you can still fix them.
  • After an incident or finding: A breach or audit finding signals that gaps exist; a structured analysis finds the rest.
  • M&A due diligence: Acquiring an entity means inheriting its compliance posture, and a gap analysis quantifies the liability.
  • Periodic health check: Even without a trigger, a periodic gap analysis keeps a maturing program honest.

Step 1: Establish the Requirements Baseline

You cannot measure a gap without a clear definition of "compliant." The baseline is the complete set of obligations the analysis will assess against, ideally drawn straight from your obligation library and compliance register so the assessment inherits work already done.

For each obligation in scope, state the requirement precisely enough that an assessor can judge whether it is met. "Handle data securely" is not assessable; "encrypt personal data at rest and in transit" is. The quality of the baseline determines the quality of every gap you find.

Step 2: Assess the Current State

With the baseline fixed, examine what the organization actually does against each requirement. This is evidence-gathering, not opinion-collecting. For each obligation, determine:

  • Is there a control? A policy, process, or system intended to satisfy the requirement.
  • Does it operate? Designed controls that do not actually run are still gaps.
  • Is there evidence? Can you demonstrate the control operates, or only assert it?

Gather current-state findings from documents, system configurations, interviews, and direct observation. Lean on compliance evidence rather than verbal assurance. An "assessment" built on what people say they do, rather than what records show, is worthless.

!

Important

A control that exists on paper but is not operating is a gap, not compliance. The most dangerous gap analyses are the ones that mark an obligation "met" because a policy document exists, without checking whether anyone follows it. Always test operation, not just existence.

Want the full framework with worked examples?

Step 3: Identify and Classify the Gaps

A gap is any obligation where the current state falls short of the requirement. For each gap, capture what is missing, how serious it is, and what closing it would take. Classifying gaps by severity is essential for prioritization later:

Severity Definition Typical Response
Critical No control for a high-penalty or high-harm obligation Immediate remediation; escalate to leadership
High Control absent or failing on a significant obligation Remediate within the current cycle
Medium Control exists but is partial, inconsistent, or unevidenced Scheduled improvement
Low Minor weakness; obligation substantially met Monitor; address opportunistically

Step 4: Score Maturity

Beyond a binary met/not-met, maturity scoring captures how well an obligation is satisfied. It gives leadership a richer picture and lets you track improvement over time rather than just counting failures. A common five-level scale:

Level Maturity Description
0 None No control exists; obligation not addressed
1 Initial Ad hoc, undocumented, dependent on individuals
2 Defined Documented control exists but is inconsistently applied
3 Managed Control operates consistently and is evidenced
4 Optimized Control is measured, reviewed, and continuously improved

Scoring each obligation on this scale turns the gap analysis into a maturity baseline you can re-measure later to show progress. That is useful for board reporting and for demonstrating a maturing program to regulators.

A Worked Gap Analysis Table

Bringing the pieces together, a gap analysis table records the requirement, current state, gap, severity, maturity, and remediation in one view:

Obligation Current State Gap Severity Maturity
Encrypt personal data at rest Production databases encrypted; backups are not Backup encryption missing High 2
Maintain records of processing Informal spreadsheet, last updated 14 months ago No maintained, current record Medium 1
Notify breaches within 72 hours Documented procedure, tested in last drill None n/a 3
Appoint an Information Officer No appointment made Role unfilled and unregistered Critical 0
Example

Reading the table

The Information Officer obligation scores 0 maturity and Critical severity. Nothing exists and the consequence of non-compliance is high, so it goes to the top of the remediation queue. Breach notification scores 3 with no gap, so it is working and needs only monitoring. Backup encryption is a High gap at maturity 2: a real control exists but does not cover everything, so it is a targeted fix rather than a build-from-scratch.

Step 5: Build and Prioritize the Remediation Plan

The deliverable of a gap analysis is not the list of gaps. It is the plan to close them. For each gap, define a remediation action, an owner, a target date, and the resource required. Then prioritize, because you cannot fix everything at once.

Prioritize on two axes: severity (the consequence of leaving the gap open) and effort (what it takes to close). This yields a sensible sequence:

  • Critical and high-severity gaps first, regardless of effort, because these carry the real exposure.
  • Quick wins next, meaning low-effort medium gaps that improve posture cheaply.
  • High-effort, lower-severity gaps scheduled into longer-term roadmaps.
i

Pro Tip

Feed every remediation action back into your compliance register and link each open gap to a risk in your risk register. That way the gap analysis does not become a one-off report that gathers dust. It becomes live, tracked work with owners and deadlines.

Common Mistakes to Avoid

1. A vague baseline

If the requirement is not stated precisely, the assessor cannot judge whether it is met, and the whole analysis becomes subjective.

2. Confusing existence with operation

Marking an obligation compliant because a policy document exists, without testing whether the control actually runs, produces false assurance.

3. Stopping at the gap list

A gap analysis without a prioritized, owned remediation plan is a diagnosis with no treatment. The plan is the point.

4. Ignoring maturity

Binary met/not-met hides the difference between a barely-working control and an optimized one. Maturity scoring lets you show and track real progress.

5. Treating it as a one-time event

Compliance posture decays. Re-run gap analyses periodically and after major changes, and track remediation to closure rather than declaring victory at the report.

Key Takeaways

Summary

  • A compliance gap analysis measures the distance between what obligations require and what you actually do
  • Run one when new regulation lands, before audits or certification, after incidents, during M&A, or as a periodic health check
  • The method is: establish a precise baseline, assess the evidenced current state, identify and classify gaps, and build a prioritized remediation plan
  • Maturity scoring captures how well each obligation is met and lets you track improvement over time
  • Prioritize remediation by severity and effort, and feed actions back into the compliance and risk registers

Frequently Asked Questions

What is the difference between a gap analysis and an audit?

A gap analysis is usually an internal, forward-looking exercise to find and close gaps before someone else does, so it is improvement-oriented. An audit is a formal, often independent evaluation that gives an opinion on compliance at a point in time. Teams frequently run a gap analysis precisely to prepare for an upcoming audit.

How long does a compliance gap analysis take?

It depends on scope and on how much groundwork already exists. With a maintained obligation library and compliance register to draw on, a focused analysis of one regulation can take days. A broad, multi-jurisdiction assessment starting from scratch can take weeks. Reusing existing obligation mapping is the single biggest accelerator.

Do I need maturity scoring, or is met/not-met enough?

Binary met/not-met is enough to find hard failures, but maturity scoring is more useful for a maturing program. It distinguishes a control that barely works from one that is well managed, and it lets you re-measure later to demonstrate improvement to leadership and regulators. For a first pass, even a simple three-level scale adds value.

How do I prioritize which gaps to fix first?

Prioritize by severity first, because critical and high gaps carry the real exposure and should be addressed regardless of effort. Then pursue low-effort quick wins among the remaining gaps, and schedule high-effort, lower-severity items into longer roadmaps. Linking each gap to a risk rating helps make the trade-offs explicit.

What happens to the gaps after the analysis?

Each gap should become a tracked remediation action with an owner and a due date, recorded in the compliance register and linked to a risk. Then you track and report status as gaps close. A gap analysis that ends at the report, with no tracked follow-through, has wasted most of its value.

How often should I run a gap analysis?

Run a full gap analysis on each major trigger, such as new regulation, a new market, pre-audit, post-incident, or M&A, and a lighter periodic health check at least annually. Between full analyses, continuous obligation tracking in your register catches drift, so you are not relying on a single annual snapshot.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.