Gap Identification

A gap is the difference between what should be happening and what is actually happening.

Gap Identification — Real-Life GRC Process

OrderTabWhat you do in real lifeLondonBuild example
1Start with RequirementReconfirm what the framework requires.ISO 27001 A.5.18 requires access rights to be managed appropriately.
2Review Control ObjectiveConfirm what the control should achieve.Ensure inappropriate access is identified and removed.
3Review ControlLook at the control LondonBuild has implemented.Quarterly user-access review.
4Review EvidenceExamine the evidence collected.Q1 and Q2 access-review reports.
5Review Testing ResultsLook at your control-testing results.20 users tested; 2 had no documented review.
6Compare Expected vs ActualIdentify the difference between the requirement/control expectation and reality.All users should be reviewed → 2 users were not documented as reviewed.
7Document the GapClearly describe exactly what is missing or failing.Two user accounts were not included in the quarterly access review.
8Classify the GapDetermine the type of deficiency.Operating effectiveness deficiency
9Determine Gap SeverityAssess how significant the deficiency is.Medium
10Link Gap to RiskDetermine what risk the gap creates.Inappropriate access may remain undetected.
11Assign Gap OwnerIdentify who is responsible for fixing it.IT Manager
12Create Remediation ActionDefine what needs to be done.Ensure the quarterly review covers 100% of active accounts.
13Set Target DateEstablish when the gap should be fixed.30 September 2026
14Track ClosureVerify the remediation was completed and retest if necessary.Retest next quarterly review.

Your actual LondonBuild Gap Record

FieldExample
Gap IDGAP-001
RequirementISO 27001 A.5.18
ControlAC-002 — Quarterly Access Review
Expected100% of active user accounts reviewed quarterly
Actual18 of 20 sampled users had documented reviews
Gap2 user accounts were not documented as reviewed
Gap TypeOperating effectiveness
SeverityMedium
RiskInappropriate access may remain undetected
Gap OwnerIT Manager
RemediationImplement automated reconciliation of the user population before each review
Target Date30 September 2026
StatusOpen

The key question

When you reach the Gap stage, ask:

“What should be happening according to the requirement/control, and what is actually happening?”

Then:

ExpectedActualDifference = Gap

For example:

Expected: All users reviewed quarterly.
Actual: 18/20 reviewed.
Gap: 2 users were not reviewed.

Don’t confuse these

ItemMeaning
FindingSomething you discovered during your assessment/testing
GapThe specific deficiency between expected and actual
RiskThe potential consequence created by the gap
RemediationWhat the company will do to fix the gap

So your workflow is now:

Framework → Requirement → Control Objective → Control Mapping → Crosswalk → Risk Event → Risk Register → Evidence → Testing → Gap → Risk → Remediation → Reporting

Next: Risk Assessment — this is where you take the identified risk and determine Likelihood × Impact = Risk Rating.