PartnerAlly Docs
Compliance Gaps

Understanding Compliance Gaps

Learn what compliance gaps are and how PartnerAlly helps you identify and resolve them.

Understanding Compliance Gaps

Compliance gaps are deficiencies where your organization's practices or documentation don't fully meet compliance framework requirements. PartnerAlly uses AI to automatically identify gaps and helps you systematically address them.

What Is a Compliance Gap?

A gap occurs when:

  • A required control isn't implemented
  • A policy doesn't cover required topics
  • Evidence is missing or insufficient
  • Procedures don't match framework requirements

Example Gaps

FrameworkGap ExampleWhat's Missing
SOC 2"No documented access review process"Periodic access review procedure
ISO 27001"Incident response plan lacks escalation"Escalation procedures in IR plan
HIPAA"No BAA template identified"Business Associate Agreement template
GDPR"Privacy policy missing retention periods"Data retention disclosure

Gaps aren't failures—they're opportunities to improve. Every organization has gaps. What matters is how you identify and address them.

How Gaps Are Identified

AI Document Analysis

When you upload a policy or procedure document, PartnerAlly's AI:

  1. Reads the document - Understands content and context
  2. Maps to frameworks - Compares against control requirements
  3. Identifies gaps - Finds missing or incomplete coverage
  4. Scores confidence - Rates how certain the AI is about each gap
  5. Creates gap entries - Adds gaps to your registry

Manual Gap Entry

You can also add gaps manually:

  • Gaps discovered during internal reviews
  • Auditor findings
  • Risk assessment results
  • Security incidents revealing weaknesses

Gap Properties

Each gap has these attributes:

PropertyDescription
TitleBrief description of the gap
DescriptionDetailed explanation of what's missing
SeverityCritical, High, Medium, or Low
StatusOpen, In Progress, Resolved, Accepted
FrameworkWhich compliance framework it relates to
ControlSpecific control requirement
SourceDocument or assessment that identified it
AI ConfidenceHow certain the AI is (for AI-identified gaps)

Severity Levels

Gaps are categorized by severity:

SeverityColorTypical Criteria
Critical🔴 RedMajor compliance violation, audit failure risk
High🟠 AmberSignificant deficiency, needs prompt action
Medium🟢 GreenModerate issue, reasonable timeline to fix
Low🔵 BlueMinor gap, address when convenient

Severity Assignment

AI assigns severity based on:

  • Framework requirements (mandatory vs. recommended)
  • Control criticality (security-critical vs. administrative)
  • Potential impact if not addressed
  • Auditor focus areas

Gap Lifecycle

Gaps move through these statuses:

Open → In Progress → Resolved

      Accepted

Status Definitions

StatusMeaning
OpenNewly identified, not yet addressed
In ProgressBeing worked on via workflow or task
ResolvedFixed with evidence of remediation
AcceptedRisk accepted (documented and approved)

Gap Locations in PartnerAlly

Access gaps from multiple places:

Why Gap Management Matters

For Audits

  • Auditors expect you to know your gaps
  • Demonstrating awareness and remediation plans is valuable
  • Resolved gaps show control maturity

For Security

  • Gaps often represent real security risks
  • Closing gaps improves your security posture
  • Reduces attack surface

For Compliance Programs

  • Tracking gaps shows program health
  • Gap trends reveal systemic issues
  • Resolution metrics demonstrate improvement

Gap vs. Risk vs. Finding

These terms are related but different:

TermDefinitionSource
GapMissing or incomplete compliance coverageAI analysis, assessments
RiskPotential negative outcomeRisk assessments, gap analysis
FindingAuditor-identified deficiencyExternal audit reports

In PartnerAlly:

  • Gaps can create risks
  • Risks can exist without gaps
  • Findings are typically added as high-severity gaps

Documentation Sections

Common Questions

How many gaps is normal?

This varies widely:

  • New organizations: 50-200+ gaps initially
  • Mature programs: 10-30 open gaps at any time
  • Audit-ready: 0 critical, few high gaps

Can I delete a gap?

Generally no—gaps are part of your compliance record. Instead:

  • Mark as "Resolved" when fixed
  • Mark as "Accepted" if risk-accepting
  • Filter them out of views

What if I disagree with an AI-identified gap?

Review the AI reasoning:

  • If the AI misunderstood, mark as resolved with explanation
  • If partially valid, adjust severity
  • Provide feedback to improve future analysis

Next Steps

On this page