Skip to main content

Evidence Gaps

Identify and resolve missing compliance evidence

evidencegapscomplianceremediation

Evidence Gaps

Evidence gaps identify controls lacking sufficient documentation. Systematically address gaps to ensure complete compliance evidence.

Understanding Gaps

What Creates a Gap?

A gap exists when:

  • No evidence linked to a control
  • Evidence is expired or outdated
  • Evidence doesn't match requirements
  • Manual evidence is required but not uploaded

Gap Severity

SeverityDefinition
CriticalRequired evidence missing for critical control
HighImportant control lacks sufficient evidence
MediumEvidence exists but may be insufficient
LowMinor documentation gap

Viewing Gaps

Gap Dashboard

Navigate to Evidence > Gaps to see:

  • Total gaps by severity
  • Gaps by framework
  • Recently identified gaps
  • Gap trends over time

Gap List

View all gaps:

ColumnDescription
ControlControl with gap
FrameworkAssociated framework
Gap TypeMissing, expired, insufficient
SeverityCritical, high, medium, low
IdentifiedWhen gap was detected
StatusOpen, in progress, resolved

Filtering Gaps

Filter by:

  • Severity - Focus on critical/high first
  • Framework - Specific frameworks
  • Gap Type - Missing, expired, etc.
  • Status - Open, in progress, resolved

Gap Types

Missing Evidence

No evidence exists for the control:

Resolution: Upload appropriate evidence or run assessment

Expired Evidence

Evidence exists but is outdated:

Resolution: Collect fresh evidence (run assessment or upload current documentation)

Insufficient Evidence

Evidence exists but doesn't fully satisfy the control:

Resolution: Upload additional supporting evidence

Manual Required

Control requires evidence that can't be auto-collected:

Resolution: Manually upload required documentation

Resolving Gaps

Basic Workflow

  1. Review gap details
  2. Determine evidence needed
  3. Collect or upload evidence
  4. Link to control
  5. Mark gap as resolved

Gap Resolution Actions

ActionUse When
Upload EvidenceYou have documentation to add
Run AssessmentAutomatic evidence can be collected
Link ExistingEvidence exists but isn't linked
Mark N/AControl doesn't apply
Accept RiskGap is acknowledged exception

Uploading Evidence

  1. Click Resolve on the gap
  2. Select Upload Evidence
  3. Upload appropriate file(s)
  4. Add description
  5. Confirm resolution

Running Assessment

  1. Click Resolve on the gap
  2. Select Run Assessment
  3. Assessment collects evidence
  4. Gap auto-resolves if evidence found

Linking Existing Evidence

If evidence already exists:

  1. Click Resolve on the gap
  2. Select Link Existing
  3. Search for artifact
  4. Confirm link

Gap Management

Assigning Gaps

Assign gaps to team members:

  1. Select gap(s)
  2. Click Assign
  3. Select team member
  4. Add optional note
  5. Assignee is notified

Gap Status

Track resolution progress:

StatusMeaning
OpenNot yet addressed
In ProgressBeing worked on
Pending ReviewEvidence submitted
ResolvedGap closed with evidence
Accepted RiskGap acknowledged

Due Dates

Set resolution deadlines:

  1. Open gap details
  2. Click Set Due Date
  3. Select date
  4. Optional: Add to calendar

Overdue gaps are highlighted in the dashboard.

Gap Reports

Gap Summary Report

Generate a report of current gaps:

  1. Go to Evidence > Gaps
  2. Click Generate Report
  3. Select scope (all or filtered)
  4. Download PDF/Excel

Gap Trend Report

Track gaps over time:

  1. Go to Evidence > Analytics
  2. Select Gap Trends
  3. Set date range
  4. View/download report

Shows:

  • Gaps opened vs. resolved
  • Average resolution time
  • Gap sources

Best Practices

Prioritization

Address gaps in order:

  1. Critical - Immediate attention
  2. High - Within 1 week
  3. Medium - Within 1 month
  4. Low - Scheduled cleanup

Prevention

Reduce new gaps:

  • Schedule regular assessments
  • Set evidence refresh reminders
  • Establish upload workflows
  • Train team on documentation

Bulk Resolution

For multiple similar gaps:

  1. Filter to specific type
  2. Select all applicable
  3. Take bulk action
  4. Resolve efficiently

Gap Exceptions

When to Accept Gaps

Some gaps may be acceptable:

  • Control truly doesn't apply
  • Compensating controls exist
  • Business decision with approval
  • Temporary during implementation

Documenting Exceptions

For accepted gaps:

  1. Click Accept Risk
  2. Provide justification
  3. Select approval (who approved)
  4. Set review date
  5. Gap moves to "Accepted" status

Notifications

Gap Alerts

Configure notifications for gaps:

  • New critical gaps
  • Gaps approaching due date
  • Gaps past due date
  • Gap trend changes

Email Digest

Receive regular gap summaries:

  1. Go to Settings > Notifications
  2. Enable Evidence Gap Digest
  3. Select frequency

What's Next?

Global Search

Search for pages, settings, and documentation