Readiness practice
How to run a gap assessment that actually produces action
A gap assessment is the step that converts a requirement list into a plan. Done well, it ends with a small number of owned, dated findings and a defensible sequence. Done badly, it ends with a colour-coded spreadsheet that everyone agrees is accurate and nobody does anything with.
Last updated 4 August 2026 · ISAREADY Editorial Team
What the assessment is for
The purpose is prioritisation. You almost certainly cannot do everything at once, and the point of the exercise is to decide what to do first with something better than intuition.
That framing changes how you run it. If the goal is prioritisation, precision matters less than coverage and honesty. A rough score across the whole scope beats a precise score across a third of it.
Fix the scope before you start
Assessing against an undefined scope produces findings nobody can act on, because the first question about any finding is “where does this apply?”
Write down the sites, legal entities, systems and information types in scope, and the additional scopes that apply — prototype protection or data protection, where relevant. If the scope is genuinely uncertain, that uncertainty is your first finding.
Judge current state, not intended state
The single biggest determinant of whether a gap assessment is useful is whether people answer about today or about the version of the organisation they are working towards.
Three questions that keep the answers honest:
- Is it defined? Is there something written that says what should happen?
- Is it applied everywhere in scope, or only where someone champions it?
- Could you show a recent record that it happened, without reconstructing anything?
An affirmative on the first and a negative on the third is the most common pattern we see, and it is exactly the pattern a document review will miss.
ISAREADY recommendation These three questions are our formulation, not a framework requirement. They map onto the graded scale used in our self-assessment: implemented, partially implemented, planned, not implemented.
What a usable finding looks like
A finding that leads to action has five things. Most findings have two.
- The gap — stated as a difference, not as a topic. “Access reviews” is a topic. “Access rights are not reviewed for the three production systems in scope” is a gap.
- The impact — why it matters here, in a sentence.
- An owner — a person, not a department.
- A target date — a real one.
- The evidence that would close it — decided now, while you are thinking about it, rather than in a hurry later.
Sequence by dependency, not by score
It is tempting to start with the lowest scores. Often that is wrong, because some findings are prerequisites for others.
Scope and ownership usually come first — not because they score badly, but because everything else depends on them. Risk method comes before risk treatment. Evidence definitions come before the activities that will generate evidence, otherwise you run the activities twice.
A practical ordering we use: governance and scope, then risk method and register, then the themes with the lowest scores, then evidence structure across everything, then internal audit to verify, then management review to close the loop.
The second pass
Re-run the assessment after the first block of work. Two things matter about the re-run: it uses the same scale so the comparison is meaningful, and it is done with the same honesty, which is harder the second time because now there is something to defend.
If every score improved, be suspicious. Genuine improvement usually reveals new gaps, because implementing something properly exposes what it depends on.
For the mechanics of grading consistently between passes, see maturity assessment.