Back to Blog
ComplianceAuditBest Practices

Gap Analysis: What a Conformity Audit Actually Finds

August 2026·6 min read

A conformity audit is not a maturity score. It is a list of specific, defensible gaps between what you do and what a framework requires, whether you lend money or treat patients.


A conformity audit earns its keep when it produces findings you can act on: a named requirement, your current state, the delta between them, and the consequence of leaving it. That is the shape we build it around, and it is why our clients finish the exercise with a work list rather than a slide.

What a gap analysis actually is A gap analysis compares what you do today against what a chosen reference requires, and produces findings. Each finding names a specific requirement, your current state, the delta between them, and the consequence of leaving it. The output is a prioritised work list, not a grade.

Choosing the reference ISO/IEC 42001 gives you an AI management system and a route to certification. The NIST AI RMF gives you a risk-function vocabulary that internal teams often find easier to apply to work already underway. Sector guidance defines what your supervisor actually examines. Most organisations need one primary reference and one secondary, not all three at equal weight, which is how frameworks become theatre.

The same finding, two sectors A finding that no documented approval exists for a model in production reads differently in a bank, where it is a control failure, than in a hospital, where it is a clinical-governance question with a patient-safety dimension. The underlying finding is identical. Only the consequence, and therefore the priority, changes.

Conclusion Do the gap analysis before you buy anything. It is the only way to know what you are buying, and the only version of the exercise that survives contact with a budget committee.

Facing One of These Deadlines?

We start with a gap analysis, the fastest route to knowing exactly what you need.