Skip to content

Control Gap

What is Control Gap?

A deficiency identified when an organisation's existing controls do not fully meet the requirements of a target compliance framework or standard. Control gaps are identified through gap analysis and addressed through remediation plans.

Compliance

What the standards actually require on control gap

Requirements naming control gap across 3 standards, quoted from the control text.

The entity must remediate material weaknesses in its operational risk management including control gaps, weaknesses and failures, supported by clear accountabilities and assurance, addressing root causes promptly, and must keep identified gaps, weaknesses and...

CPS230-P31 · Remediation of Material Operational Risk Weaknesses

Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations.

AUNDB-A7 · Recordkeeping, Communications Strategy, Post-Incident Review, Board Reporting
OSFI B-131 control

Operate independent assurance + internal audit + external examination per OSFI B-13 Domain 6. Independent Assurance and Internal Audit must (a) maintain Internal Audit function independence per B-13 + OSFI Corporate Governance Guideline + (b) provide assurance...

OSFIB13-6 · Independent Assurance, Internal Audit, External Examination

Questions people ask about control gap

What is Control Gap?
A deficiency identified when an organisation's existing controls do not fully meet the requirements of a target compliance framework or standard. Control gaps are identified through gap analysis and addressed through remediation plans.
Why is Control Gap important for compliance?
Control Gap is a key concept in Compliance. Understanding control gap helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Control Gap?
Control Gap appears in the requirement text of APRA CPS 230 Operational Risk Management, Notifiable Data Breaches Scheme (Australia), OSFI B-13. Across these standards we have identified 3 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Control Gap?
Explore our compliance framework pages to see how control gap applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Control Gap applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.