Gap assessment: what it is, and why it is faster now
The distance between the requirements and reality, measured, drawn and prioritised. The documented part now takes days. The big job is still changing how people work.
A gap assessment answers one question: what separates the organisation as it is today from the requirements it has to meet? The answer is not a grade, but a list of concrete distances, sorted by urgency.
The assessment measures two things at once, and it matters to keep them apart. The first is whether the requirement is met at all. The second is whether it is possible to show that it is met. An organisation can do everything correctly and still fail an audit, because none of it leaves a trace. Conversely, a well-written document archive can conceal that practice looks entirely different.
What a gap assessment actually is
The requirements come from a standard, a regulation or a customer. They state what must be in place, and rarely how. The gap assessment translates the requirements into something observable in this particular organisation, and assesses each point against what actually exists.
The work has four parts. We clarify the scope, so that the assessment addresses the right part of the organisation. We review the documentation. We talk to the people who carry out the work, because the document rarely tells the whole story. Finally we assess maturity per area, prioritise and set out a road map.
The result has to serve two readers with different needs. Leadership needs a picture of risk and resource requirements. Those who will do the work need a list of concrete tasks, an owner per task and a sequence that makes sense.
Why the assessment has become faster
The document-based part of the work has changed in recent years. Previously the first weeks went into collecting, sorting and reading. That work can now be done in a few days, and the analyst's time goes into assessment rather than searching. What has not become faster is observing practice and changing behaviour.
The gap, drawn
A maturity profile shows where the organisation stands in each governance area, and where the requirements expect it to stand. The distance between the shapes is the gap.
Six steps from nothing to improvement
Maturity is graded to make the assessment verifiable. Without a scale the answer becomes "it varies a bit", and then nobody can prioritise. The steps below are a common way to grade. In an engagement the scale is fitted to the standard and the organisation.
Level 0: Not in place
The area is not handled. Nobody finds anything when asked for it.
Level 1: Ad hoc
Something is done, but it depends on individuals and is not repeated consistently.
Level 2: Described
A document exists. Practice follows it only in part.
Level 3: Implemented
The process is used day to day, and those who carry it out know it.
Level 4: Verifiable
Carrying it out leaves evidence. An auditor can see that it happened.
Level 5: Improving
Results are measured, and the measurements lead to changes that are followed up.
What we look for, and what we look at
A gap assessment considers two things at once: whether the requirement is met, and whether it is possible to show that it is met. The second is often what is missing.
| Area | What is assessed | What counts as evidence |
|---|---|---|
| Governance | Mandate, roles, decision lines, management commitment | Minutes, decisions, approved policies |
| Risk | Method, completed assessments, treatment and ownership | Risk register, treatment plans, named owners |
| Documentation | Governance and operational documents, version control | Current documents, review dates, approvals |
| Controls in use | Whether the controls are implemented and working | Logs, settings, samples, test results |
| Competence | Training, awareness, role-specific knowledge | Training records, tests, participation |
| Suppliers | Critical dependencies, requirements in contracts, follow-up | Supplier list, agreements, assessments |
| Measurement | Objectives, indicators, reporting to management | Reports, trends, management review inputs |
| Incidents | Detection, handling, learning, notification duties | Incident log, evaluations, exercises |
What is fast now, and what still takes time
Gap assessments have traditionally started with weeks of gathering documents. Somebody had to find the policies, somebody had to find the latest version, and somebody had to read through it all. That part is no longer the bottleneck.
The documented part
Policies, procedures, registers, agreements and reports. With Berigo's own tooling the material is made ready for analysis, and the assessment against the requirements lands in a few days rather than weeks.
The part that must be observed
Whether the controls work, whether people do as described, and whether the evidence exists. This requires interviews, sampling and access to the systems, and it cannot be rushed.
The change in the organisation
New behaviour, new habits and a new view of how the work should be done. This is where the real work lies, and it is the same as it was before the tooling arrived.
The time indications are orders of magnitude for a bounded scope, not a promised delivery time. What is realistic in a specific engagement is clarified before the work starts.
The tooling behind the pace
Berigo uses its own tooling under AI Data Optimizer to prepare the organisation's documentation for analysis. The document base is mapped quickly, what is missing becomes visible early, and the analyst's time goes into professional judgement rather than into collecting and sorting. Judgement is what the client is paying for, and it improves when the basis is complete from day one.
The findings are entered into TrustAlign, Berigo's own portal for governance, risk, compliance and audit support. There the requirements, gaps, actions, ownership and deadlines get a fixed home, and status can be followed by leadership and by those doing the work. The portal by itself provides neither certification nor compliance. It makes the work visible and verifiable while it is under way.
Tooling moves the bottleneck, it does not remove it. When the overview arrives in a few days rather than a few weeks, it becomes clearer what is actually in the way, and that is rarely a shortage of documents.
Positive and negative friction
Every security control costs something. It costs time, attention or an extra step. The question is not whether the control creates friction, because it always does. The question is whether the friction pays for itself.
The brakes on a car are the simplest picture. The quality check before the car leaves the factory takes time, and it delays production. It is still positive friction, because the brakes work when somebody needs them. A control that merely requires a signature confirming that somebody looked at the brakes costs the same time and delivers nothing. That is negative friction.
«It should be hard to cheat, it should be hard to steal.»
Robert I. Sutton, Professor Emeritus of Management Science and Engineering at Stanford School of Engineering, asked whether a friction-free workplace is the ideal. His answer was no.Huggy Rao, Professor of Organizational Behavior at Stanford Graduate School of Business, has researched this with Sutton for seven years, and they gathered the work in The Friction Project from 2024. Rao describes friction as obstacles, and his point is that obstacles work both ways: they can disable, and they can enable. Good friction makes people pause and think. Bad friction overwhelms, exhausts and confuses.
Rao ties good friction to decisions that cannot be undone. Where something is to be deleted, published, purchased or given away, it is worth adding a step that forces a moment of reflection. Decisions that are easily reversed deserve the opposite. The leadership task then has two halves: remove the friction that makes the right thing cumbersome, and add friction where the wrong thing should be hard.
| Control | What it costs | What it delivers | Verdict |
|---|---|---|---|
| Four eyes on an irreversible change | Minutes of delay per change | Catches the error while it can still be undone | Positive |
| Restore test of the backup | A few hours, a few times a year | Turns an assumption into a documented capability | Positive |
| Access review before renewal | An hour per manager per quarter | Removes access that outlived its purpose | Positive |
| Password change every 90 days | Everyone, four times a year | Produces predictable variants of the same password | Negative |
| Approval form nobody reads | A signature per request | Documents that somebody signed, nothing else | Negative |
| Blocking a tool without offering an alternative | A daily obstacle | Moves the work to a private account instead | Negative |
The examples above are chosen to show the distinction, not to pass judgement on a particular organisation. The same control can be positive in one place and negative in another, and that depends on what it actually catches in your specific case.
Does deliberate slowness work? The evidence is mixed, and the nuance is the point
Surgical checklists are the most studied example of a control that deliberately slows things down. In the World Health Organization pilot study, published in the New England Journal of Medicine in 2009, mortality at eight hospitals fell from 1.5 to 0.8 percent, and complications from 11.0 to 7.0 percent.
When the same checklist was made mandatory at 101 hospitals in Ontario, the researchers found no statistically significant reduction in either mortality or complications. The result was published in the same journal in 2014. The checklist was the same. What differed was how it was adopted.
Where the control genuinely changed how the work was done, the effect was large and lasting. A five-point checklist for central line insertion at 103 intensive care units in Michigan produced up to 66 percent fewer bloodstream infections, and the effect held for eighteen months. Boeing’s own review of the checklist’s history in aviation reaches the same conclusion: checklists work best as part of a wider safety effort, and the effect fades when they are used routinely without understanding.
The lesson for security work is uncomfortably precise. A control does not become positive friction by being introduced. It becomes positive when it changes what people actually do, and that is exactly why change management is the big job after a gap assessment.
Negative friction is not free
A control that costs without delivering does not simply disappear into the statistics. It has a price that surfaces somewhere else.
The American NIST has described the phenomenon as security fatigue, meaning weariness or reluctance to deal with security at all. The striking thing about the study was that the theme surfaced on its own in the interviews, without the researchers having asked about it. The symptoms they found were resignation, a sense of losing control, fatalism, risk minimisation and decision avoidance. Their main advice is to reduce the number of security decisions the user has to make, rather than making each decision more insistent.
The British NCSC puts it even more directly: if you force people to, they will work around security to get the job done. They treat shadow IT as a symptom of badly designed policy rather than as disloyal staff, and they use the word friction themselves when explaining that cumbersome products make people find a lower friction route around the control.
This is why a gap assessment should not merely count missing controls. Filling a gap with a control that is negative friction makes compliance worse rather than better. It looks right in the documentation, and it teaches the organisation that security is something to get past.
We therefore ask three questions of every control we recommend. What does it catch that would otherwise get through? What does it cost the person who has to do it, every single time? And what will people do instead if it becomes too heavy? The answers decide whether the control belongs in the action plan.
Typical findings, and what they lead to
The findings below are typical situations we recognise from the field. They are not taken from a named client, and no numbers are attributed to them.
| Finding | What lies behind it | Typical action |
|---|---|---|
| Policy approved four years ago | The document exists and looks fine. Nobody has reviewed it since, and it refers to systems that were replaced. | Set a review cycle with a named owner, and review it as part of the management review. |
| Risk assessment without owners | Risks are identified, but no name is attached, so nothing moves. | Assign an owner and a deadline to every risk that is to be treated. |
| Access rights nobody revokes | Leavers keep accounts, and suppliers keep access after the project ended. | Introduce a periodic access review, and tie revocation to the offboarding process. |
| Backups that are never restored | Backups run, and the log says success. Nobody has tried to restore from them. | Test a restore, document what it took, and repeat it on a schedule. |
| Training that was held once | Everyone attended in the spring. New employees since then have had nothing. | Make the training part of onboarding, and record participation. |
| Supplier requirements in the contract only | The agreement says the right things. Nobody has checked whether the supplier does them. | Risk-classify the suppliers, and follow up the critical ones with evidence. |
Sources
- Sutton og Rao: Fixing Bad Friction, Finding Good Friction (Stanford GSB Insights)
- Rao: The Function of Friction, How to Use Obstacles to Your Advantage (Stanford GSB)
- Sutton: Workplace Friction, How to Make the Right Things Easier (Stanford GSB, Grit and Growth)
- The Friction Project (Stanford GSB, bokside)
- NIST: Security Fatigue (IT Professional, 2016)
- NCSC: Shadow IT
- NCSC: Accessibility as a cyber security priority
- Haynes et al.: A Surgical Safety Checklist to Reduce Morbidity and Mortality (NEJM, 2009)
- Urbach et al.: Introduction of Surgical Safety Checklists in Ontario (NEJM, 2014)
- Pronovost et al.: An Intervention to Decrease Catheter-Related Bloodstream Infections in the ICU (NEJM, 2006)
Would you like to know where you stand?
A gap assessment is bounded, it commits you to nothing further, and it gives leadership a basis for decisions. Scope and price are set after an initial clarification.
Get in touch