Control Gap
What is Control Gap?
A deficiency identified when an organisation's existing controls do not fully meet the requirements of a target compliance framework or standard. Control gaps are identified through gap analysis and addressed through remediation plans.
Frameworks that govern control gap
What the standards actually require on control gap
Requirements naming control gap across 3 standards, quoted from the control text.
The entity must remediate material weaknesses in its operational risk management including control gaps, weaknesses and failures, supported by clear accountabilities and assurance, addressing root causes promptly, and must keep identified gaps, weaknesses and...
CPS230-P31 · Remediation of Material Operational Risk Weaknesses →Maintain recordkeeping + communications strategy + post-incident review + board reporting per OAIC guidance and Privacy Act section 26WL recordkeeping expectations.
AUNDB-A7 · Recordkeeping, Communications Strategy, Post-Incident Review, Board Reporting →Operate independent assurance + internal audit + external examination per OSFI B-13 Domain 6. Independent Assurance and Internal Audit must (a) maintain Internal Audit function independence per B-13 + OSFI Corporate Governance Guideline + (b) provide assurance...
OSFIB13-6 · Independent Assurance, Internal Audit, External Examination →Questions people ask about control gap
What is Control Gap?
Why is Control Gap important for compliance?
Which compliance frameworks address Control Gap?
Where can I learn more about Control Gap?
See how Control Gap applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.