A gap is the difference between what should be happening and what is actually happening.
Gap Identification — Real-Life GRC Process
| Order | Tab | What you do in real life | LondonBuild example |
|---|---|---|---|
| 1 | Start with Requirement | Reconfirm what the framework requires. | ISO 27001 A.5.18 requires access rights to be managed appropriately. |
| 2 | Review Control Objective | Confirm what the control should achieve. | Ensure inappropriate access is identified and removed. |
| 3 | Review Control | Look at the control LondonBuild has implemented. | Quarterly user-access review. |
| 4 | Review Evidence | Examine the evidence collected. | Q1 and Q2 access-review reports. |
| 5 | Review Testing Results | Look at your control-testing results. | 20 users tested; 2 had no documented review. |
| 6 | Compare Expected vs Actual | Identify the difference between the requirement/control expectation and reality. | All users should be reviewed → 2 users were not documented as reviewed. |
| 7 | Document the Gap | Clearly describe exactly what is missing or failing. | Two user accounts were not included in the quarterly access review. |
| 8 | Classify the Gap | Determine the type of deficiency. | Operating effectiveness deficiency |
| 9 | Determine Gap Severity | Assess how significant the deficiency is. | Medium |
| 10 | Link Gap to Risk | Determine what risk the gap creates. | Inappropriate access may remain undetected. |
| 11 | Assign Gap Owner | Identify who is responsible for fixing it. | IT Manager |
| 12 | Create Remediation Action | Define what needs to be done. | Ensure the quarterly review covers 100% of active accounts. |
| 13 | Set Target Date | Establish when the gap should be fixed. | 30 September 2026 |
| 14 | Track Closure | Verify the remediation was completed and retest if necessary. | Retest next quarterly review. |
Your actual LondonBuild Gap Record
| Field | Example |
|---|---|
| Gap ID | GAP-001 |
| Requirement | ISO 27001 A.5.18 |
| Control | AC-002 — Quarterly Access Review |
| Expected | 100% of active user accounts reviewed quarterly |
| Actual | 18 of 20 sampled users had documented reviews |
| Gap | 2 user accounts were not documented as reviewed |
| Gap Type | Operating effectiveness |
| Severity | Medium |
| Risk | Inappropriate access may remain undetected |
| Gap Owner | IT Manager |
| Remediation | Implement automated reconciliation of the user population before each review |
| Target Date | 30 September 2026 |
| Status | Open |
The key question
When you reach the Gap stage, ask:
“What should be happening according to the requirement/control, and what is actually happening?”
Then:
Expected → Actual → Difference = Gap
For example:
Expected: All users reviewed quarterly.
Actual: 18/20 reviewed.
Gap: 2 users were not reviewed.
Don’t confuse these
| Item | Meaning |
|---|---|
| Finding | Something you discovered during your assessment/testing |
| Gap | The specific deficiency between expected and actual |
| Risk | The potential consequence created by the gap |
| Remediation | What the company will do to fix the gap |
So your workflow is now:
Framework → Requirement → Control Objective → Control Mapping → Crosswalk → Risk Event → Risk Register → Evidence → Testing → Gap → Risk → Remediation → Reporting
Next: Risk Assessment — this is where you take the identified risk and determine Likelihood × Impact = Risk Rating.