Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Gap assessment evidence log linking requirements to documents interviews and system samples

Gap Assessment Evidence Guide 2026: What to Collect

Gap assessment evidence is the material that shows whether an organization actually meets each requirement of a standard or regulation: policies, records, system settings, interview notes and samples of real work. A gap assessment without evidence is only opinion, and opinions do not survive an audit, a regulator’s question or a sceptical board.

This guide explains what gap assessment evidence to collect, how to test it, how to grade its strength, and how to keep a log that lets anyone trace a score back to what supports it.

Why gap assessment evidence matters

A gap assessment compares what you do against what a framework requires. The result is only as reliable as the proof behind each rating. If a team says a control is in place and nobody checks, the assessment records what people believe, which is often more optimistic than what is true. Good gap assessment evidence protects you in three ways. It makes scores repeatable, so a second assessor reaches the same answer. It exposes overstatement before an external party does. And it gives remediation owners a precise picture of what is missing. Our guide to gap assessment scoring shows how ratings should follow from the proof available.

Types of gap assessment evidence

Evidence comes in several forms, and a strong assessment usually combines more than one for important requirements. ISO 19011, the guidance standard for auditing management systems, describes audit evidence as records, statements of fact or other information that are relevant to the audit criteria and verifiable. You can see the official listing at ISO 19011:2018 on iso.org. The same idea applies to an internal gap assessment.

Evidence typeExamplesWhat it shows
DocumentedPolicies, procedures, standards, plansThat the requirement is defined and approved
RecordsMeeting minutes, risk registers, training logs, approvalsThat the process has actually been run
TechnicalSystem settings, configuration exports, scan resultsThat controls are implemented as stated
TestimonyInterviews, walkthroughs, questionnairesThat people understand and follow the process
ObservationWatching a task or demonstrationThat practice matches the paper

Grading the strength of gap assessment evidence

Not all proof is equal. A policy shows intent, a dated record shows operation, and an independent test shows effectiveness. Grade each item so that scores reflect the strongest reliable proof rather than the easiest to find.

  1. Design only. A document says what should happen. Nothing shows that it does.
  2. Implemented. A record, setting or sample shows it happening at least once.
  3. Operating consistently. Records across a period, such as several months of reviews, show it happening repeatedly.
  4. Independently verified. Someone outside the process has tested it, for example through internal audit or an external assessment.

Set a rule for how each grade maps to a maturity score, and apply it consistently. For example, design-only evidence might cap a requirement at partial compliance, however well written the document is.

Building an evidence request list for the gap assessment

Work from requirements to requests. For each requirement, ask what would convince a sceptical reviewer, then request exactly that. A generic request such as send us your security documents produces piles of files and few answers. A specific request such as the last two quarterly access reviews with evidence of approval produces something you can grade.

Write requests that are easy to answer

State the requirement, the exact item wanted, the period covered, the owner who should supply it and a due date. Ask for samples where volume is high, such as ten recent joiners or five recent changes, and choose the samples yourself so the owner cannot pick only the best cases. Explain that the aim is to find gaps, not to blame anyone, since people who feel judged tend to hide problems.

Testing gap assessment evidence, not just collecting it

Collecting a file is not the same as checking it. Test whether the document is current, approved and actually used. Check that records cover the whole period, not only the last week. Compare what people say with what the system shows. If a procedure says access is reviewed quarterly, look at the last four reviews. If a policy says all laptops are encrypted, ask for a report from the management console and compare the count of devices with the asset list.

Watch for common warning signs: undated documents, drafts with no approval, screenshots with no source, records that all share the same date, templates that were never filled in and policies that cite superseded versions of a standard. Each is a sign that the requirement may exist on paper only.

Sampling and independence in evidence review

Where an activity happens many times, such as onboarding, change approvals or supplier reviews, look at a sample rather than every case. Choose the sample from the full population, for example by taking every tenth record or by picking dates at random, and record how you chose it. A sample picked by the process owner is likely to flatter the result. Where the sample shows failures, widen it to find out whether the problem is an exception or the normal state.

Independence matters as much as sampling. Ask someone who does not run the process to review the items, or at least to confirm a portion of them. This is the reason many organizations tie the assessment to internal audit. When frameworks differ, the approach stays the same, and our guides to ISO 27001 gap analysis and ISO 22301 gap analysis show how the same discipline applies to two management system standards.

Finally, agree in advance how disagreements between assessor and owner will be settled. A short escalation route, with the final decision recorded together with the reasons, keeps the assessment moving and prevents scores from being negotiated privately.

Handling evidence that is sensitive or incomplete

Some proof is itself sensitive. Configuration exports can reveal internal addresses, screenshots can show personal data and contracts can contain confidential terms. Redact what is not needed, restrict who can open the store and record who accessed it. If an owner cannot supply an item, record that as a finding instead of accepting a verbal promise, and note the date it was requested so that delays are visible. A requirement with no supporting proof after a fair request should be scored on that basis, and the reason should be written next to the score.

Keeping an evidence log

An evidence log links each requirement to the items that support its score. Keep it simple and consistent, with the following fields.

  • Requirement reference and short description.
  • Evidence item with a file name, location or ticket reference.
  • Type and grade using the categories above.
  • Date of the evidence and date it was reviewed.
  • Owner who supplied it and the assessor who checked it.
  • Finding and resulting score.

Store the evidence itself in a controlled location, and treat it with the same care as the systems it describes, since screenshots and exports can contain sensitive data. Record the version reviewed so that a later change does not alter the meaning of an earlier assessment.

Gap assessment evidence across different frameworks

The same evidence often supports several frameworks. An access review record can serve an ISO 27001 control, a data protection requirement and a customer audit. Build the log around your own controls and map them to each framework, rather than collecting again for every one. Our ISO 27001 gap assessment and GDPR gap analysis guides show how the requirements differ, while the evidence types remain much the same.

From gap assessment evidence to remediation

Where evidence is missing or weak, the finding should say precisely what is absent: no approved procedure, no records for the last two quarters, control not enabled on part of the estate. That precision lets remediation be planned properly. Feed the findings into a plan with owners, dates and the evidence that will show completion. Our article on the gap analysis remediation plan explains how to structure that step, so that the closing evidence is defined before the work starts.

Using a ready structure

If you want a starting point, the Gap Assessment Report and Workbook provides a structured report, scoring and a working log where requirements, findings and supporting items sit together. Whatever tool you choose, make gap assessment evidence part of the method from the first day, not something gathered in a rush before the results are presented.

Gap assessment evidence FAQ

What counts as gap assessment evidence?

Any verifiable record, document, system output, sample, interview or observation that shows whether a requirement is met. The best assessments combine several types for important requirements.

Is a policy enough evidence?

A policy shows that a requirement is defined and approved, but it does not show that it is followed. Pair it with records or system outputs that show it operating.

How much evidence should I collect?

Enough to be confident in the score. For high-risk requirements collect samples over a period of time, while lower-risk ones may need only a document and a short interview.

Who should review the evidence?

Someone independent of the process owner where possible, such as internal audit, a compliance function or an external adviser, so that the review is not marking its own work.

How long should evidence be kept?

Keep it at least until the next assessment cycle and for any longer period set by your regulators, contracts or retention schedule. Record the version reviewed so results can be reproduced.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.