Gap assessment: what it is, and why it is faster now

The distance between the requirements and reality, measured, drawn and prioritised. The documented part now takes days. The big job is still changing how people work.

A gap assessment answers one question: what separates the organisation as it is today from the requirements it has to meet? The answer is not a grade, but a list of concrete distances, sorted by urgency.

The assessment measures two things at once, and it matters to keep them apart. The first is whether the requirement is met at all. The second is whether it is possible to show that it is met. An organisation can do everything correctly and still fail an audit, because none of it leaves a trace. Conversely, a well-written document archive can conceal that practice looks entirely different.

What a gap assessment actually is

The requirements come from a standard, a regulation or a customer. They state what must be in place, and rarely how. The gap assessment translates the requirements into something observable in this particular organisation, and assesses each point against what actually exists.

The work has four parts. We clarify the scope, so that the assessment addresses the right part of the organisation. We review the documentation. We talk to the people who carry out the work, because the document rarely tells the whole story. Finally we assess maturity per area, prioritise and set out a road map.

The result has to serve two readers with different needs. Leadership needs a picture of risk and resource requirements. Those who will do the work need a list of concrete tasks, an owner per task and a sequence that makes sense.

Why the assessment has become faster

The document-based part of the work has changed in recent years. Previously the first weeks went into collecting, sorting and reading. That work can now be done in a few days, and the analyst's time goes into assessment rather than searching. What has not become faster is observing practice and changing behaviour.

The gap, drawn

A maturity profile shows where the organisation stands in each governance area, and where the requirements expect it to stand. The distance between the shapes is the gap.

GovernanceRiskDocumentationControls in useCompetenceSuppliersMeasurementIncidentsLevel expectedToday
Figure 1, illustrative example: a typical starting point measured against the level the requirements expect. The numbers are constructed to show the shape of a gap, not taken from a client.
GovernanceRiskDocumentationControls in useCompetenceSuppliersMeasurementIncidentsDocumentedPractice
Figure 2, illustrative example: the difference between what is written down and what is actually done. This distance is the most common surprise in a gap assessment, and it is also the most expensive one to close.

Six steps from nothing to improvement

Maturity is graded to make the assessment verifiable. Without a scale the answer becomes "it varies a bit", and then nobody can prioritise. The steps below are a common way to grade. In an engagement the scale is fitted to the standard and the organisation.

Level 0: Not in place

The area is not handled. Nobody finds anything when asked for it.

Level 1: Ad hoc

Something is done, but it depends on individuals and is not repeated consistently.

Level 2: Described

A document exists. Practice follows it only in part.

Level 3: Implemented

The process is used day to day, and those who carry it out know it.

Level 4: Verifiable

Carrying it out leaves evidence. An auditor can see that it happened.

Level 5: Improving

Results are measured, and the measurements lead to changes that are followed up.

What we look for, and what we look at

A gap assessment considers two things at once: whether the requirement is met, and whether it is possible to show that it is met. The second is often what is missing.

Area What is assessed What counts as evidence
Governance Mandate, roles, decision lines, management commitment Minutes, decisions, approved policies
Risk Method, completed assessments, treatment and ownership Risk register, treatment plans, named owners
Documentation Governance and operational documents, version control Current documents, review dates, approvals
Controls in use Whether the controls are implemented and working Logs, settings, samples, test results
Competence Training, awareness, role-specific knowledge Training records, tests, participation
Suppliers Critical dependencies, requirements in contracts, follow-up Supplier list, agreements, assessments
Measurement Objectives, indicators, reporting to management Reports, trends, management review inputs
Incidents Detection, handling, learning, notification duties Incident log, evaluations, exercises

What is fast now, and what still takes time

Gap assessments have traditionally started with weeks of gathering documents. Somebody had to find the policies, somebody had to find the latest version, and somebody had to read through it all. That part is no longer the bottleneck.

Days

The documented part

Policies, procedures, registers, agreements and reports. With Berigo's own tooling the material is made ready for analysis, and the assessment against the requirements lands in a few days rather than weeks.

Weeks

The part that must be observed

Whether the controls work, whether people do as described, and whether the evidence exists. This requires interviews, sampling and access to the systems, and it cannot be rushed.

Months

The change in the organisation

New behaviour, new habits and a new view of how the work should be done. This is where the real work lies, and it is the same as it was before the tooling arrived.

The time indications are orders of magnitude for a bounded scope, not a promised delivery time. What is realistic in a specific engagement is clarified before the work starts.

The tooling behind the pace

Berigo uses its own tooling under AI Data Optimizer to prepare the organisation's documentation for analysis. The document base is mapped quickly, what is missing becomes visible early, and the analyst's time goes into professional judgement rather than into collecting and sorting. Judgement is what the client is paying for, and it improves when the basis is complete from day one.

The findings are entered into TrustAlign, Berigo's own portal for governance, risk, compliance and audit support. There the requirements, gaps, actions, ownership and deadlines get a fixed home, and status can be followed by leadership and by those doing the work. The portal by itself provides neither certification nor compliance. It makes the work visible and verifiable while it is under way.

Tooling moves the bottleneck, it does not remove it. When the overview arrives in a few days rather than a few weeks, it becomes clearer what is actually in the way, and that is rarely a shortage of documents.

Positive and negative friction

Every security control costs something. It costs time, attention or an extra step. The question is not whether the control creates friction, because it always does. The question is whether the friction pays for itself.

The brakes on a car are the simplest picture. The quality check before the car leaves the factory takes time, and it delays production. It is still positive friction, because the brakes work when somebody needs them. A control that merely requires a signature confirming that somebody looked at the brakes costs the same time and delivers nothing. That is negative friction.

«It should be hard to cheat, it should be hard to steal.»

Robert I. Sutton, Professor Emeritus of Management Science and Engineering at Stanford School of Engineering, asked whether a friction-free workplace is the ideal. His answer was no.

Huggy Rao, Professor of Organizational Behavior at Stanford Graduate School of Business, has researched this with Sutton for seven years, and they gathered the work in The Friction Project from 2024. Rao describes friction as obstacles, and his point is that obstacles work both ways: they can disable, and they can enable. Good friction makes people pause and think. Bad friction overwhelms, exhausts and confuses.

Rao ties good friction to decisions that cannot be undone. Where something is to be deleted, published, purchased or given away, it is worth adding a step that forces a moment of reflection. Decisions that are easily reversed deserve the opposite. The leadership task then has two halves: remove the friction that makes the right thing cumbersome, and add friction where the wrong thing should be hard.

Control What it costs What it delivers Verdict
Four eyes on an irreversible change Minutes of delay per change Catches the error while it can still be undone Positive
Restore test of the backup A few hours, a few times a year Turns an assumption into a documented capability Positive
Access review before renewal An hour per manager per quarter Removes access that outlived its purpose Positive
Password change every 90 days Everyone, four times a year Produces predictable variants of the same password Negative
Approval form nobody reads A signature per request Documents that somebody signed, nothing else Negative
Blocking a tool without offering an alternative A daily obstacle Moves the work to a private account instead Negative

The examples above are chosen to show the distinction, not to pass judgement on a particular organisation. The same control can be positive in one place and negative in another, and that depends on what it actually catches in your specific case.

Does deliberate slowness work? The evidence is mixed, and the nuance is the point

Surgical checklists are the most studied example of a control that deliberately slows things down. In the World Health Organization pilot study, published in the New England Journal of Medicine in 2009, mortality at eight hospitals fell from 1.5 to 0.8 percent, and complications from 11.0 to 7.0 percent.

When the same checklist was made mandatory at 101 hospitals in Ontario, the researchers found no statistically significant reduction in either mortality or complications. The result was published in the same journal in 2014. The checklist was the same. What differed was how it was adopted.

Where the control genuinely changed how the work was done, the effect was large and lasting. A five-point checklist for central line insertion at 103 intensive care units in Michigan produced up to 66 percent fewer bloodstream infections, and the effect held for eighteen months. Boeing’s own review of the checklist’s history in aviation reaches the same conclusion: checklists work best as part of a wider safety effort, and the effect fades when they are used routinely without understanding.

The lesson for security work is uncomfortably precise. A control does not become positive friction by being introduced. It becomes positive when it changes what people actually do, and that is exactly why change management is the big job after a gap assessment.

Negative friction is not free

A control that costs without delivering does not simply disappear into the statistics. It has a price that surfaces somewhere else.

The American NIST has described the phenomenon as security fatigue, meaning weariness or reluctance to deal with security at all. The striking thing about the study was that the theme surfaced on its own in the interviews, without the researchers having asked about it. The symptoms they found were resignation, a sense of losing control, fatalism, risk minimisation and decision avoidance. Their main advice is to reduce the number of security decisions the user has to make, rather than making each decision more insistent.

The British NCSC puts it even more directly: if you force people to, they will work around security to get the job done. They treat shadow IT as a symptom of badly designed policy rather than as disloyal staff, and they use the word friction themselves when explaining that cumbersome products make people find a lower friction route around the control.

This is why a gap assessment should not merely count missing controls. Filling a gap with a control that is negative friction makes compliance worse rather than better. It looks right in the documentation, and it teaches the organisation that security is something to get past.

We therefore ask three questions of every control we recommend. What does it catch that would otherwise get through? What does it cost the person who has to do it, every single time? And what will people do instead if it becomes too heavy? The answers decide whether the control belongs in the action plan.

Typical findings, and what they lead to

The findings below are typical situations we recognise from the field. They are not taken from a named client, and no numbers are attributed to them.

Finding What lies behind it Typical action
Policy approved four years ago The document exists and looks fine. Nobody has reviewed it since, and it refers to systems that were replaced. Set a review cycle with a named owner, and review it as part of the management review.
Risk assessment without owners Risks are identified, but no name is attached, so nothing moves. Assign an owner and a deadline to every risk that is to be treated.
Access rights nobody revokes Leavers keep accounts, and suppliers keep access after the project ended. Introduce a periodic access review, and tie revocation to the offboarding process.
Backups that are never restored Backups run, and the log says success. Nobody has tried to restore from them. Test a restore, document what it took, and repeat it on a schedule.
Training that was held once Everyone attended in the spring. New employees since then have had nothing. Make the training part of onboarding, and record participation.
Supplier requirements in the contract only The agreement says the right things. Nobody has checked whether the supplier does them. Risk-classify the suppliers, and follow up the critical ones with evidence.

Would you like to know where you stand?

A gap assessment is bounded, it commits you to nothing further, and it gives leadership a basis for decisions. Scope and price are set after an initial clarification.

Get in touch