Home » Enterprise & Corporate » Audit and gap analysis

Audit and gap analysis

An external assessment of where the organisation stands, for the situations where an internal view is either insufficient or won’t be accepted as independent. The output is written to be read by a board, a regulator or a customer’s assurance team.

The problem this addresses

Mature privacy functions usually know roughly where their weaknesses are. What they often can’t do is say so in a form that carries weight internally. A finding raised by the team responsible for the area is heard differently from the same finding raised from outside.

There is also a scope problem. Internal assessment tends to examine what the organisation already knows it does. The value of an outside view is in the processing nobody has documented, running in a business unit that never thought to mention it.

What the engagement covers

  • Assessment against a defined framework — UK GDPR and EU GDPR, the Data Protection Act 2018, ISO 27701, a sector code, or a customer’s own control set
  • Data mapping validation: not whether a record of processing exists, but whether it matches reality
  • Controls testing on the operational side — access, retention, deletion, transfers, supplier oversight
  • The distance between documented process and observed practice, established through interviews rather than questionnaires
  • Governance: decision rights, escalation routes, and whether the privacy function can actually stop something
  • Findings rated by risk, with remediation sequenced and owners identified

How it runs

Scoped against a fixed set of areas and a delivery date, agreed in writing before starting. Fieldwork is conducted through structured conversations with the people doing the work rather than through a document request, because the gap being looked for is precisely the one documents don’t show.

Findings are raised as they emerge. Nothing significant should appear for the first time in a final report. It damages the report’s usefulness and the working relationship at the same time.

What you’re left holding at the end

A report with findings, ratings and a remediation plan that can be worked through by someone who wasn’t in the room. Alongside it, a short summary suitable for a board or an audit committee. A different document with a different job, not a condensed version of the same one.

Where the assessment supports an external claim — a customer assurance pack, a tender response, a regulatory submission. The output is built to be used that way from the start.

Scope and proportionality

This is the deeper, more formal end of the assessment work. Organisations that want a working view of their position rather than something built to withstand external scrutiny are usually better served by a shorter engagement, and we will say so before scoping rather than after.