Gap assessment vs audit is a distinction that confuses many teams preparing for certification, and mixing them up leads to the wrong expectations and the wrong timing. A gap assessment is a diagnostic exercise that compares what you do today with what a standard or law requires, so that you can plan improvements. An audit is a formal, evidence-based, ideally independent examination that concludes whether requirements are met.
This guide explains how the two differ in purpose, timing, independence, evidence and outputs, when to use each and how to combine them into a sensible path to certification. It is general guidance, and details vary by framework and certification body.
What a gap assessment is
A gap assessment compares your current practices with a target: a standard such as ISO 27001, a regulation or an internal framework. It identifies where you already comply, where you partly comply and where nothing exists, and it sizes the effort needed to close each gap.
Its tone is constructive. The team wants an honest picture so it can plan resources, set priorities and avoid surprises. Because the aim is to learn, the assessor can ask leading questions, suggest fixes and revisit areas without the formal constraints of an audit. For a practical approach, see our guides to gap assessment scoping and gap assessment scoring.
What an audit is
An audit is a systematic, independent and documented process for obtaining evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. That definition follows the approach in ISO 19011:2018 on auditing management systems. Audits can be internal, carried out by your own staff or a service provider, or external, such as a certification audit or a customer audit.
The tone is more formal. Auditors plan, sample evidence, record findings and report against criteria. They should not design your solutions, because that would compromise independence. The result is a conclusion: conforming, minor nonconformity, major nonconformity or opportunity for improvement.
| Feature | Gap assessment | Audit |
|---|---|---|
| Purpose | Find and size gaps to plan improvement | Determine conformity against criteria |
| Timing | Early, before implementation or certification | After the system is running |
| Independence | Can be done by the team or a consultant | Should be independent of the area audited |
| Evidence | Sampled, often interview-led | Systematic, documented sampling |
| Output | Prioritised action plan or roadmap | Findings, nonconformities and an opinion |
Gap assessment vs audit: purpose and mindset
The main difference is why you are doing it. A gap assessment asks “what do we need to do?” An audit asks “have you done what you said and what the standard requires?” The first informs a plan; the second gives assurance.
That difference shapes behaviour. People are more open in a gap assessment because there are no formal consequences, which produces better information. In an audit, the stakes are higher, so people may be more guarded. Use the gap assessment to be candid and the audit to prove the result.
Gap assessment vs audit: timing
Run the gap assessment first. It belongs at the start of a project or before you commit to a certification date, when you still have time to act. Running it too late means you discover major gaps just when you needed to be ready.
Audits come later, once the system has operated long enough to generate records. An internal audit typically precedes a certification audit, and it is often a formal requirement of the standard. Trying to audit a system that has not started operating gives little useful evidence.
Independence and competence in gap assessment vs audit
Independence matters for audits. An internal auditor should not audit their own work, and a certification body must be independent of any consultant who helped you. A gap assessment has no such restriction, so a consultant, a project team member or an outside adviser can carry it out.
Competence matters in both. The assessor needs to understand the standard, the business and the evidence. For internal audits, the standard usually expects documented competence and impartiality, so train and record it.
- Gap assessment: independence is helpful but not required
- Internal audit: independence from the audited area is expected
- Certification audit: independence from any advisers is required
- Both need assessors who understand the criteria
Evidence and method
A gap assessment often relies on interviews, document reviews and workshops, with lighter sampling of records. The goal is to build a broad picture quickly. Our guide to gap assessment interviews explains how to run them effectively.
An audit uses systematic sampling and verification: checking that records exist, are complete and show the process operating over time. Findings must be traceable to specific evidence. Keep working papers so another person can follow how the conclusion was reached. See gap assessment evidence for how to organise proof.
Gap assessment vs audit: outputs and what happens next
A gap assessment produces a prioritised action plan, maturity or compliance ratings and a resource estimate. It feeds project planning, budgets and timelines. A good output is one that leaders can act on, such as the gap analysis remediation plan format.
An audit produces a report with findings and, in many cases, requirements for corrective action within set time limits. Nonconformities must be investigated, corrected and verified. In a certification context the report leads to a decision on whether to grant, maintain or withdraw the certificate.
How to use both on the path to certification
A practical sequence is: run a gap assessment, build or improve the management system, operate it for a period, conduct an internal audit, fix the findings, hold a management review and then undergo the certification audit. Each step has a distinct job, and skipping one usually costs time later.
Repeat the cycle each year. A short gap assessment after major changes or new requirements keeps the system aligned, and regular internal audits show that it keeps operating. Our page on ISO 27001 gap assessment illustrates the sequence for one standard.
Common mistakes in gap assessment vs audit
Common errors are treating the gap assessment as a certification audit and expecting a pass or fail, asking the certification body to do a gap assessment and then relying on it as advice, using the same person to design and audit controls, and skipping the internal audit because the gap assessment looked good.
Another is failing to act on the results. A gap assessment that produces a report nobody uses, or an audit finding that stays open for months, wastes the effort. Assign owners and dates, track closure and report progress to management.
Keeping both processes connected
Record the gap assessment results and use them to plan the internal audit. Areas that were weak at the start deserve closer attention later, and areas that were strong can receive lighter sampling. Feed audit findings back into the risk register and the improvement plan so that lessons carry forward. Treat the two as parts of a cycle rather than separate projects, and both will be easier to explain to management, customers and the certification body.
Keep the documentation tidy: a single evidence library, a shared action tracker and a dated record of who did what. That way the same material supports both the assessment and the audit without being rebuilt each time.
A short worked example
A software company plans to certify against an information security standard in twelve months. In month one, a consultant carries out a gap assessment and finds strong technical controls but weak risk management and no supplier process. The plan closes those gaps over six months.
In month nine, an internal auditor from another department audits the system, finding two minor nonconformities on records, which are corrected. After a management review, the certification audit takes place in month twelve with no major findings. Each activity did its own job, and the sequence saved time and cost.
Structuring the gap assessment
If you want a structured way to record requirements, evidence, ratings and actions, the Gap Assessment Report and Workbook provides a report and workbook for the gap assessment stage, leaving the independent audit to follow. Whatever the format, understanding gap assessment vs audit helps you pick the right tool at the right time and set the right expectations with your team and your certification body.
Gap assessment vs audit FAQ
Is a gap assessment the same as an internal audit?
No. A gap assessment is a diagnostic that plans improvement. An internal audit is a formal, independent check that the system conforms and operates as intended.
Can the same person do both?
Better not for the same area. A person who advised on the design should not audit it, because independence would be compromised.
Do we need a gap assessment before certification?
It is not mandatory, but it is strongly recommended. It shows how much work remains and helps you set realistic timelines.
Does a gap assessment count as an audit for the standard?
Usually not. Standards expect a planned internal audit programme with independent, competent auditors and records of results.
How long before certification should we run the gap assessment?
As early as possible, ideally many months before, so there is time to close the gaps and operate the system long enough to create evidence.