Readiness assessment
Also known as: Gap Analysis, Pre-assessment, Mock Audit
A preliminary evaluation used to determine how closely an organization's current controls align with a specific standard or regulation before a formal audit begins. Its primary goal is to identify "gaps" between existing practices and the requirements of the framework. This allows the entity to remediate deficiencies before an external auditor issues a final report.
Why it matters
Skipping this step often leads to "qualified" reports or failed certifications because critical controls were missing or undocumented. A formal audit failure can result in lost contracts with clients who require specific compliance attestations for vendor risk management. The cost of remediation after a failed official audit is typically higher due to the urgency and potential need for re-audit fees. Ultimately, the CISO or Compliance Manager is held accountable for the lack of preparation and the resulting business disruption.
In practice
An internal auditor or a third-party consultant performs this during the pre-assessment phase, months before the formal audit window. They request evidence such as current policy documents, system configuration screenshots, and access logs to verify control implementation. The process produces a Gap Analysis Report detailing which controls are fully met, partially met, or missing entirely. In a first-year engagement, this is an exhaustive review of every requirement in the standard. For repeat engagements, it focuses on changes to the environment (delta assessment) and previously identified weaknesses. This phase ensures that evidence is "audit-ready" before the external party arrives.
Worked example
FinTechFlow planned for their first SOC 2 audit in October 2023. During the readiness assessment, the consultant requested evidence of quarterly access reviews for their AWS production environment. They found that while reviews occurred, they were not documented with timestamps or manager approvals. The auditor flagged this as a "high" gap and provided a template for an Access Review Log. FinTechFlow spent June through September implementing this process across three departments. Consequently, the formal audit in October resulted in a clean report without exceptions.
Common mistakes
- Treating it as a check-the-box exercise rather than a deep dive into evidence. This leads to surprises during the actual audit when auditors ask for proof of operation.
- Confusing policy existence with control implementation. Having a written password policy does not mean passwords are actually being rotated or enforced by the system.
- Conducting it too late in the compliance cycle. If done weeks before the formal audit, there is insufficient time to remediate gaps that require technical changes.
- Relying solely on verbal assertions from staff without reviewing actual artifacts. "We do this" is not evidence; a signed log or system screenshot is.
Frequently asked questions
What is the main goal of a readiness assessment?
The primary objective is to identify gaps between current operations and a required standard. This allows an organization to fix issues before they are officially recorded as failures in a formal audit report.
How does a readiness assessment differ from a gap analysis?
While often used interchangeably, a gap analysis focuses on what is missing (the difference between state A and B). A readiness assessment is broader, evaluating both the existence of controls and the organization's ability to provide evidence for them.
How do I start a readiness assessment?
Begin by selecting a specific framework—such as ISO 27001 or HIPAA—and mapping your existing policies against its control requirements. Then, interview process owners and sample actual artifacts to verify that the written policy matches reality.
What evidence is typically collected during this phase?
Auditors look for "artifacts" such as system-generated logs, signed approval emails, screenshots of configuration settings, and employee training records. They want to see a representative sample rather than just one perfect example.
When should a company schedule their readiness assessment?
Ideally, it should occur three to six months before the formal audit window begins. This provides enough time for technical remediation (like implementing MFA) and operational habit-building (like performing monthly reviews).
More terms
Audit evidence · SOC 2 Type II · High-risk AI system · Compensating control · Test of controls · Right to be forgotten · CE marking · Conformity assessment