Skip to main content
Category: Issue and Incident Management

Gap Identification

Also known as: Gap Analysis, Gap Assessment
Simply put

Gap identification is the process of comparing where an organization currently stands against where it wants or needs to be, and pinpointing the differences between the two. Those differences, or gaps, show what is missing or needs improvement to reach the desired state. Organizations commonly use this exercise to make better use of their resources and to plan the steps needed to close the gaps.

Formal definition

Gap identification, commonly conducted through a gap analysis, is a structured method for measuring and evaluating the difference between an organization's current state and a defined desired or target state. Practitioners typically characterize the exercise in stages, articulating the current state, defining the desired state, and identifying the discrepancies between them, which may then inform a remediation roadmap or resource allocation decisions. It is distinct from a risk assessment: gap identification compares an entity against a benchmark, target, or requirement to surface differences, whereas a risk assessment evaluates uncertainty against objectives. This entry does not cover specific methodologies, tooling, or the criteria selected as the desired-state benchmark, which vary by organization and context.

Why it matters

Gap identification gives organizations a disciplined way to see the distance between their current state and a defined target, rather than relying on assumption or intuition about how well they are performing. In a governance, risk, and compliance context, this matters because obligations, controls, and expectations shift over time, and an organization may drift out of alignment with a standard, policy, or strategic objective without a structured comparison to surface the difference. Making the gap explicit is often the necessary first step before resources can be allocated or remediation planned.

Without gap identification, organizations risk directing effort and capital toward areas that are already adequate while leaving genuine deficiencies unaddressed. Because the exercise compares the current state against a chosen benchmark or target, it helps firms use their resources, capital, and technology more efficiently by focusing attention where the differences are greatest. The output commonly informs a remediation roadmap, giving decision-makers a documented basis for prioritization.

It is important not to overstate what gap identification delivers. It surfaces differences against a defined desired state; it does not, by itself, evaluate uncertainty against objectives the way a risk assessment does, and it does not guarantee that the chosen benchmark is the right one. The quality of the result depends heavily on how accurately the current state is characterized and how appropriately the target state is defined.

Who it's relevant to

Compliance officers
Compliance functions may use gap identification to compare current policies, controls, and practices against applicable laws, regulations, or internal policy requirements, surfacing where adherence falls short of the defined benchmark and informing where remediation is needed.
Risk managers
Risk managers may draw on gap identification to compare current capabilities against a target state. It is worth noting that gap identification is distinct from a risk assessment: the former compares an entity against a benchmark to surface differences, while the latter evaluates uncertainty against objectives.
Internal auditors and assurance functions
Assurance functions may reference the results of gap identification when evaluating whether management has recognized and is addressing differences between current and desired states, while maintaining independence from the management activities that define the target and carry out remediation.
Governance professionals and leadership
Those responsible for direction and resource allocation can use the documented differences from a gap identification exercise to prioritize investment of resources, capital, and technology, and to structure a roadmap of steps needed to close identified gaps.

Inside Gap Identification

Current-state assessment
A structured review of existing controls, policies, processes, or capabilities as they operate in practice, establishing the baseline against which gaps are measured.
Reference criteria
The benchmark used for comparison, such as an applicable regulation, a standard (for example ISO 31000 or ISO 37301), an internal policy, or a control framework. The relevance of the criteria depends on jurisdiction, industry, and organizational scope.
Gap analysis
The comparison of current state against reference criteria to surface discrepancies, typically expressed as missing, partial, or ineffective controls or requirements not yet met.
Gap characterization
Description of each identified gap, commonly including its nature, the requirement or control objective affected, and the pillar involved (governance, risk, or compliance).
Prioritization inputs
Contextual information, such as potential exposure or significance, that may inform how gaps are ranked. Prioritization criteria vary by organization and should be defined explicitly.
Remediation linkage
A connection from each gap to subsequent treatment or action planning, though the design and execution of remediation typically fall outside gap identification itself.

Common questions

Answers to the questions practitioners most commonly ask about Gap Identification.

Is gap identification the same as a full risk assessment?
No. Gap identification typically focuses on the difference between a current state and a defined target state, such as a control framework, standard, or regulatory requirement. A risk assessment, by contrast, concerns identifying, analyzing, and evaluating uncertainty against objectives, including likelihood and impact. A gap may inform risk assessment inputs, but the two activities are distinct in purpose and method. Treating a gap analysis as a substitute for risk assessment can leave the significance and prioritization of identified gaps unexamined.
Does identifying a gap mean the gap has been remediated or the associated risk resolved?
No. Identification only surfaces the difference between the current and target states; it does not close the gap or treat any related risk. Remediation, control design, and implementation are separate management activities that follow identification, and the effectiveness of any remediation would typically require its own validation. A gap that has been documented but not addressed generally remains an open exposure.
How should identified gaps be prioritized when resources are limited?
Prioritization commonly considers factors such as the significance of the requirement or objective affected, the potential exposure associated with the gap, and any applicable regulatory or contractual context. Organizations often relate gaps to their risk appetite and tolerance to determine sequencing. Prioritization approaches vary by organization, sector, and jurisdiction, and this entry does not prescribe a specific scoring method.
Who is typically responsible for identifying and addressing gaps under the three lines model?
In many organizations, first line functions that own and operate processes and controls may identify and address gaps as part of day-to-day management. Second line functions, such as risk and compliance, commonly facilitate, review, or oversee gap identification against frameworks and obligations. Independent assurance from the third line, such as internal audit, may identify gaps through its work but generally does not own remediation, preserving its independence and objectivity.
What reference points are commonly used to define the target state against which gaps are measured?
Target states are frequently drawn from external frameworks and standards, applicable laws and regulations, and internal policies, standards, and procedures. The appropriate reference depends on the objective of the exercise and on jurisdictional and sectoral context. Selecting an authoritative and current reference is important, as measuring against an outdated or inapplicable baseline can produce misleading results.
How are the results of gap identification typically documented and tracked over time?
Results are commonly captured in a form that records the requirement or objective, the observed current state, the nature of the gap, and any assigned ownership. Many organizations track gaps through to their treatment using registers or remediation plans, with periodic review to reflect changes in requirements or the environment. Specific tooling and documentation formats vary and are out of scope for this entry.

Common misconceptions

Gap identification is the same as risk assessment.
Gap identification compares a current state against defined criteria to find discrepancies, whereas risk assessment evaluates uncertainty against objectives in terms of likelihood and impact. A gap may or may not correspond to a significant risk, and the two activities use different reference points.
Identifying a gap means the gap has been closed or remediated.
Gap identification is a diagnostic activity. It surfaces and characterizes discrepancies but does not itself resolve them; remediation, control design, and validation are separate management activities that typically follow.
Gap identification is an assurance function that can be performed the same way regardless of who conducts it.
Gap identification may be performed as a management activity by first or second line functions or as part of an independent assurance review by internal audit. The independence and objectivity of the party conducting it affect how the results should be relied upon, so the distinction should be preserved.

Best practices

Define and document the reference criteria before beginning, and confirm they are applicable to the organization's jurisdiction, industry, and size rather than assuming universal requirements.
Base the current-state assessment on how controls and processes operate in practice, using evidence rather than solely on documented intent.
Characterize each gap clearly, noting which pillar it affects and whether the requirement or control is missing, partial, or ineffective, to avoid blurring governance, risk, and compliance concerns.
Establish explicit, documented prioritization criteria so that ranking of gaps is transparent and repeatable rather than ad hoc.
Maintain clear separation between the identification of gaps and the design or execution of remediation, and record ownership for follow-up actions.
Where gap identification is intended to serve as assurance, ensure the party conducting it has appropriate independence and objectivity, and document that basis.
Promotional banner for the Penetration Report Template Kit