Gap analyses
What is missing, what is partial, and what is already satisfied, with the evidence checked rather than assumed.
Service line 04
For FFIEC and HIPAA regulated organizations preparing for exams, audits, and customer diligence. The work covers requirement to policy to control mapping, exam readiness, risk registers, third party risk, and business continuity planning.
Who this is for
Banks, credit unions, and healthcare organizations answer to examiners on a cycle. Businesses selling into regulated buyers answer to customer diligence questionnaires instead. The work is the same.
Engagements map controls to the frameworks clients face, including FFIEC, HIPAA, PCI DSS, SOC 2, HITRUST, CSA STAR, NIST 800-53, and ISO 27001.
What the work includes
Deliverables
What is missing, what is partial, and what is already satisfied, with the evidence checked rather than assumed.
A single map from requirement to policy to control to the record that proves it.
Risks with owners, ratings, treatment decisions, and review dates, kept current instead of rebuilt annually.
Written updates that a board can act on and an examiner can read.
Where each record lives, how often it appears, and who reviews it.
Fixed-scope starting point
A practitioner-led review of one defined security or compliance boundary. It tests whether an agreed sample of controls has named owners and current records showing that the controls operate.
Choose one examiner request, customer diligence cycle, business process, system, or security-program area. Record what is in scope, what is excluded, and who owns it.
Trace the agreed sample from the requirement or question to the policy, control, owner, and operating record. Separate verified evidence from missing, stale, and unassessed items.
Receive a prioritized action list, with decision owners where the organization names them, then choose whether to fix the gaps internally or continue into implementation work.
Deliverables include a scope and assumptions record, evidence inventory, findings list, prioritized action list, and a closeout session with the accountable owner.
There is no maturity score and no claim that the work is an audit, assessment opinion, or certification. The baseline reports what the agreed evidence supports, what is missing, and what was not assessed.
How it supports audit readiness
The purpose of this service line is simple. The next exam should be a review of records that already exist. Readiness work that only happens in the weeks before an exam produces a reconstruction, and a reconstruction is what findings are written about.
The full evidence chain is on audit-ready IT.
What this is not