Business Key Consult logo
Business Key Consult
Resources / ISO 27001 gap assessment
ISO/IEC 27001:2022GAP analysisISO 19011

What does an ISO 27001 gap assessment include?

A gap assessment turns the broad question “Are we ready?” into clear evidence, priorities, and sequenced actions.

It is useful when an organisation is preparing for ISO/IEC 27001:2022, already has documentation in place, or needs an independent review before an internal or certification audit.

1. Define scope and criteria

The review begins with ISMS boundaries: services, locations, processes, information assets, suppliers, and applicable requirements. Without a clear scope, even good documentation can fail to reflect the actual environment.

2. Review evidence

The review covers more than policies and procedures. It considers evidence of operation, such as risk assessments, the Statement of Applicability, training records, access records, logs, management reviews, and corrective actions.

3. Compare against requirements

Observations are compared with relevant ISO/IEC 27001:2022 clauses and selected controls. The aim is not to complete a checklist mechanically, but to understand whether controls work in the organisation’s business and technology context.

4. Sequence the priorities

Gaps are not equal. A useful assessment distinguishes critical risks, dependencies, and quick improvements so the team can plan realistically instead of working through an arbitrary list.

5. Create a practical plan

A useful outcome identifies next steps, responsible roles, and required evidence. This enables leadership to decide on the resources and timeline for readiness.

What to prepare in advance

  • ISMS scope and key service description
  • current risk assessment and treatment plan
  • Statement of Applicability, if available
  • policies, procedures, and registers
  • sample records showing controls in operation
  • your objective and preferred timeline

A gap assessment is a consulting review, not a certification audit. It does not replace a planned internal audit, but provides a strong basis for one.

View the gap assessment service