Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Gap assessment report structure showing executive summary, scope, method, findings, roadmap and appendices

Gap Assessment Report Structure: A 2026 Guide

A clear gap assessment report structure is what turns weeks of interviews and document review into decisions. A report that is too long, too vague or organised around the assessor’s process rather than the reader’s needs will be skimmed and shelved, and the gaps it found will remain open. A well-organised report tells leaders what the situation is, why it matters and what to do next.

This guide sets out a proven gap assessment report structure, explains what belongs in each section, shows how to present findings and ratings and offers advice on tone, length and follow-up. It is general guidance that you can adapt to your framework and audience.

Start with the reader

Before writing, decide who will read the report and what they need to decide. A sponsor needs to know whether the target is achievable and what it will cost. A programme manager needs actions and dates. Control owners need to know what is expected of them. Different readers should be able to find what they need quickly.

Design the gap assessment report structure around those needs: a short front section for executives, a main section for detail and appendices for evidence. Avoid organising the report by the order in which you ran interviews; organise it by what the reader must understand.

The executive summary in a gap assessment report structure

The summary is the most read part of the report, and often the only part some readers see. Keep it to a page. State the scope, the overall position, the three to five most important gaps, the recommended approach and the decisions or resources required. Use plain language and avoid technical detail.

Include a simple graphic if it helps, such as a maturity heat map. Write the summary last, once you know what the findings really say, and check that a reader who reads nothing else would still understand the main message.

  • Scope and objective in one or two sentences
  • Overall position, using the agreed rating scale
  • Top gaps and why they matter
  • Recommended next steps and decisions needed

Scope, method and limitations

State exactly what was assessed: the standard or framework, the organizational units, the systems and the period. Describe how you worked: documents reviewed, people interviewed, evidence sampled and the rating scale used. See gap assessment scoping for how to define scope and gap assessment interviews for interview practice.

Be open about limitations, such as areas not covered, evidence not available or claims not verified. This protects the credibility of the report and stops readers assuming more assurance than the work provides. The approach mirrors good audit practice, where the basis of conclusions is stated, as in ISO 19011:2018 on auditing management systems.

SectionPurposeTypical length
Executive summaryGive leaders the headline and the decisions neededOne page
Scope and methodShow what was assessed and howOne to two pages
Results overviewSummarise ratings by domainOne to two pages
Detailed findingsExplain each gap, evidence and recommendationBulk of the report
RoadmapSequence actions with owners and datesOne to two pages
AppendicesEvidence list, interview log, scale definitionsAs needed

Results overview

Give a one- or two-page summary of ratings by domain or requirement group, for example a table or heat map showing current level, target level and gap. This lets readers compare areas at a glance. Use the scale explained in gap assessment maturity levels or the approach in gap assessment scoring.

Add a short commentary on patterns. For example, technical controls may be strong while governance and supplier management are weak. Patterns are often more useful to leaders than individual findings.

Detailed findings within the gap assessment report structure

Each finding needs a consistent format so it can be read quickly. A reliable structure is: requirement, current state, evidence, gap, impact and recommendation. Reference the source of the requirement, describe what was seen and say why the gap matters in terms the business cares about.

Keep each finding short, ideally half a page or less. Rate the severity and effort so findings can be sorted. Link to evidence in the appendix rather than pasting it into the text. Our guide to gap assessment evidence explains how to organise what supports each finding.

Recommendations and the roadmap

Recommendations should be actionable: what to do, who should own it, roughly when and how success will be measured. Group them into phases such as quick wins, foundational work and longer-term improvements. Use the ordering methods in gap assessment prioritization and the format in the gap analysis remediation plan.

Explain dependencies. Some actions cannot start until others are done, and showing this avoids unrealistic timelines. Give cost and effort estimates as ranges, with assumptions stated.

Appendices and the working file

Put supporting detail in appendices: the requirement checklist, the interview log, the list of documents reviewed, the rating scale definitions and any raw scores. Keep the working file organised so that another assessor could follow the trail from a finding back to its evidence.

This is where the workbook complements the report. The report tells the story; the workbook holds the data. Readers who want to check a rating can do so without cluttering the main document.

Tone, length and review

Write in plain, neutral language. Describe facts and evidence rather than blame, and avoid words that provoke defensiveness. A report that people can accept is one they will act on.

Aim for a length that matches the scope: most reports fit within fifteen to thirty pages plus appendices. Have a colleague read it cold and tell you what they took from it. Share a draft with control owners to correct factual errors before issuing the final version.

Common mistakes in a gap assessment report structure

Frequent problems include an executive summary that is a list of findings, findings without evidence, recommendations that are too vague to act on, ratings with no explanation of the scale, no roadmap and no owner for any action. Another is delivering the report and walking away, with no plan to track progress.

Avoid these by planning the structure before you start, using consistent finding templates and agreeing the follow-up process with the sponsor when the report is delivered.

Following up after delivery

Agree how progress will be tracked before you hand over the report. A simple tracker with action, owner, due date and status is enough. Review it monthly with the sponsor, and schedule a reassessment after the first phase of the roadmap to confirm that ratings have improved. A report that leads to a visible follow-up cycle builds credibility for the whole programme.

Choosing charts and visuals

Use visuals sparingly and only where they clarify. A heat map of ratings by domain, a bar chart of gaps by severity and a simple timeline for the roadmap are usually enough. Label every chart clearly, state the scale and avoid decoration that distracts from the message. Provide the underlying numbers in the workbook so readers who want to check can do so.

Consistency also helps. Use the same colours for the same ratings throughout, and keep terminology the same in the summary, the findings and the roadmap. Small inconsistencies make readers doubt the rigour of the analysis, while a tidy, predictable layout makes the report feel trustworthy and easy to use.

A short worked example

A retail company asks for a gap assessment against a payment security framework. The report opens with a one-page summary: overall maturity is level two of five, strong network controls, weak documentation and no supplier oversight. Three decisions are requested: fund a policy rewrite, appoint an owner for supplier management and approve a six-month plan.

The results overview shows ratings by domain, and each finding uses the same format. The roadmap has three phases with owners and dates. A tracker is set up, and a follow-up review is scheduled at three months. The CFO approves the plan in a single meeting because the report made the decision easy.

Using a ready structure

If you want the sections, finding templates, ratings and roadmap already laid out, the Gap Assessment Report and Workbook provides a report and working workbook that follow this kind of gap assessment report structure. Whatever tool you use, a report that is readable, evidence-based and actionable will be used, and that is the real test.

Gap assessment report structure FAQ

How long should a gap assessment report be?

Most fit within fifteen to thirty pages plus appendices, depending on scope. The executive summary should be a single page.

What must the executive summary include?

The scope, the overall position, the most important gaps, the recommended approach and the decisions or resources required.

Should findings include evidence?

Yes. Each finding should reference the evidence seen, ideally by linking to an appendix, so readers can verify the conclusion.

Who should review the draft?

Control owners and the sponsor. They can correct factual errors and confirm that recommendations are realistic before the final version is issued.

Do we need a roadmap in the report?

Yes. A roadmap with owners, dates and dependencies turns findings into a plan and makes the report far more likely to be acted on.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.