Skip to main content
Category: Assessment and Due Diligence

Gap Analysis

Also known as: Gap Assessment, Need-Gap Analysis
Simply put

Gap analysis is a structured way of comparing where an organization currently stands against where it wants or needs to be. By measuring the difference between the present state and a desired future state, it highlights the areas that need improvement to close that gap. It is a general management technique that can be applied to many different parts of a business.

Formal definition

Gap analysis is a formal, structured method for measuring the difference between an organization's current state and a defined target or desired future state, typically to reveal improvement areas and inform remediation planning. It generally proceeds through steps that move from assessing the current state, defining the target state, identifying and analyzing the gaps between them, and developing actions to close those gaps. As a technique, gap analysis is method-agnostic about the reference point being used: the 'target' may be an ideal performance level, a strategic objective, a framework, or a control baseline, and the analysis is only as reliable as the accuracy of the current-state assessment and the appropriateness of the chosen target. It identifies differences but does not by itself validate underlying data, prioritize remediation, or guarantee that identified gaps will be closed.

Why it matters

In third-party and supply chain risk management, gap analysis provides a disciplined way to surface where a program, a control environment, or an individual supplier relationship falls short of a defined target. Rather than relying on impressions, it forces an explicit comparison between the current state and a desired future state, making improvement areas visible and giving remediation planning a factual anchor. This matters because unexamined assumptions about the maturity of a vendor onboarding process, a monitoring capability, or a supplier's control set can leave risk unaddressed until it materializes.

The technique's value is directly tied to the quality of its inputs. A gap analysis is only as reliable as the accuracy of the current-state assessment and the appropriateness of the chosen target. If the current state is drawn from self-reported or stale information, or if the target is poorly defined, the analysis may show gaps that do not exist or, more dangerously, miss gaps that do. Because gap analysis identifies differences but does not itself validate underlying data, it should be paired with mechanisms that verify the current-state picture rather than treated as a conclusion in its own right.

It is equally important to recognize what gap analysis does not do. It highlights where differences exist, but it does not by itself prioritize which gaps matter most, allocate resources, or guarantee that identified gaps will be closed. Those outcomes depend on downstream decisions about risk tiering, remediation ownership, and follow-through. Treating a completed gap analysis as evidence that gaps have been resolved, rather than merely identified, is a common misstep that undermines its usefulness.

Who it's relevant to

Third-Party Risk Managers
TPRM practitioners use gap analysis to compare a supplier's current control environment or a program's current practices against a defined target, revealing improvement areas that inform remediation planning. They should recognize that the exercise identifies gaps but does not validate the source data or prioritize which gaps to address first.
Compliance and Assurance Teams
These teams may apply gap analysis to measure current practices against a framework or control baseline used as the target reference point. It is important to treat the result as an identification of differences rather than confirmation of conformance, since the technique does not independently verify the current-state assessment.
Procurement and Program Leaders
Those responsible for program strategy can use gap analysis to measure the difference between current operations and a strategic objective or desired future state, helping to structure improvement efforts. They should note that closing identified gaps depends on downstream decisions about prioritization and resourcing that the analysis itself does not provide.

Inside Gap Analysis

Current-state assessment
Documentation of a third party's existing controls, processes, or practices as they actually operate, typically gathered through questionnaires, evidence review, or interviews. This baseline reflects a point-in-time view and may become stale as conditions change.
Target-state or reference criteria
The desired condition against which the current state is measured, often anchored to a framework, standard, contractual requirement, or internal policy (for example control expectations drawn from ISO 27036 or NIST SP 800-161). The chosen reference defines the scope of what the analysis can identify.
Gap identification
The comparison output listing discrepancies between current and target states, including missing, partial, or non-conforming controls. Findings are only as complete as the criteria and evidence used, and may not capture risks outside the selected reference set.
Severity or risk rating
A qualitative or tiered characterization of each gap's significance, often weighted by the risk tier of the relationship. Ratings support prioritization but reflect judgment and the scope of the assessment rather than an absolute measure of exposure.
Remediation plan
The set of corrective actions, owners, and timelines assigned to close identified gaps. A gap analysis surfaces deficiencies but does not itself remediate them; closure depends on subsequent action and verification.

Common questions

Answers to the questions practitioners most commonly ask about Gap Analysis.

Is a gap analysis the same as a risk assessment?
No. A gap analysis measures the difference between a current state and a defined target state, such as a control set, framework, or contractual requirement. A risk assessment evaluates the likelihood and impact of adverse events and typically distinguishes inherent from residual risk. A gap analysis can identify where controls are missing or immature, but it does not by itself quantify or prioritize risk unless it is paired with a risk assessment. The two are complementary rather than interchangeable.
Does closing all identified gaps mean a third party is compliant or fully secure?
No. A gap analysis is typically point-in-time and scoped to a specific standard or requirement set, so closing the identified gaps addresses only what was assessed against that benchmark. It does not confer certification, guarantee compliance, or eliminate risk, and gaps outside the chosen scope, such as financial, operational, geopolitical, or ESG dimensions, may remain unexamined. Findings can also become stale as the third party's environment or the applicable requirements change.
What should be defined before starting a gap analysis of a third party?
Depending on the program, the target state should be established first, meaning the specific framework, control baseline, or contractual and regulatory requirements the third party is being measured against. It is also common to define the scope boundaries, the risk tier of the relationship, the evidence expected for each item, and whether findings rely on self-attestation or independent verification. Clarifying these upfront helps prevent ambiguity about what a closed or open gap actually represents.
How does the evidence source affect the reliability of gap analysis findings?
Reliability often depends on whether results are self-reported or independently validated. A gap analysis built solely on a self-completed questionnaire reflects the third party's own attestation and may not be verified. Corroborating evidence, such as an independent assessment report or on-site review, can strengthen confidence, though in many programs the depth of validation is calibrated to the risk tier of the relationship rather than applied uniformly.
How often should a gap analysis be repeated?
Because a gap analysis is typically point-in-time, its findings can become outdated as controls, personnel, or requirements change. In many programs the cadence is tied to the risk tier, with higher-risk relationships reassessed more frequently, and refreshes may also be triggered by contract renewal, material changes at the third party, or changes to the applicable standard. It generally supports, rather than replaces, ongoing monitoring.
What is a common way to translate gap analysis results into action?
Identified gaps are often documented in a remediation or corrective action plan that assigns owners, priorities, and target dates. In many programs the prioritization draws on a separate risk assessment so that gaps are addressed according to their potential impact rather than in the order they were found. Because the analysis is scoped to a defined target state, it is common to note which areas fell outside that scope so they are not mistaken for validated or risk-free.

Common misconceptions

A gap analysis measures a third party's actual risk exposure.
A gap analysis measures the distance between a current state and a selected reference standard. It does not by itself quantify inherent or residual risk, and gaps outside the chosen criteria may go undetected. It should be treated as one input to risk assessment, not a substitute for it.
Completing a gap analysis means the identified gaps are resolved.
The analysis only identifies discrepancies; it does not close them. Remediation, and typically independent verification of that remediation, are separate activities. A self-reported gap analysis without validation reflects attestation rather than confirmed correction.
A single gap analysis provides an ongoing view of compliance.
It captures a point-in-time state and can become stale as the third party's controls, personnel, or environment change. Depending on the risk tier, programs often repeat or supplement gap analyses with ongoing monitoring rather than relying on a one-time exercise.

Best practices

Explicitly define and document the reference criteria before beginning, so stakeholders understand which framework, contractual requirement, or policy the gaps are measured against and what falls outside that scope.
State the scope boundaries in the output, noting whether the analysis covers information security only or also financial, operational, geopolitical, or ESG dimensions, and whether it addresses onboarding or ongoing performance.
Where feasible, corroborate self-reported responses with independent evidence rather than relying on attestation alone, and record which findings were validated versus taken at face value.
Prioritize identified gaps by severity weighted to the risk tier of the relationship, and pair each gap with a remediation owner and timeline so the analysis leads to corrective action.
Treat the analysis as a point-in-time snapshot and schedule periodic reassessment or supplement it with ongoing monitoring, especially for higher-tier relationships whose conditions may change.
Note visibility limitations, such as reduced insight beyond the direct third party into fourth-party or Nth-party arrangements, so gaps in extended dependencies are not assumed to be covered.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps