Zurück zur Bibliothek

Policy framework gap check

Checks a policy framework against its required controls, ownership, review cadence, evidence, exceptions, and related procedures, producing a cited gap register and remediation priorities. Use for governance reviews, policy-library health checks, and control-framework assessments.

von adlass TemplatesVersion 1Nutzt adlass-ToolsUniversell

Veröffentlicht 21. Aug. 2026 · Aktualisiert 26. Aug. 2026

Hilfreich · 0Rohes SKILL.md ansehen

Voraussetzungen

Add the authoritative control catalogue and policy inventory. Define coverage statuses, priority rubric, review-period rule, and acceptable evidence types. Map policy owners, approvers, procedures, and exception-management fields.

Skill-Dokument

Das vollständige SKILL.md, das dein Agent liest und befolgt.

Policy framework gap check

Purpose

Assess whether a policy framework contains the required control topics and whether each policy is usable: owned, approved, versioned, review-dated, evidenced, and linked to operating procedures.

Scope

Review the policy inventory, framework or control catalogue, individual policy documents, approval records, review dates, exception logs, and procedure links.

Excluded: declaring legal compliance, approving policies, drafting a full policy suite, and assigning owners without evidence.

Data basis

  • Policy inventory with title, owner, version, status, approval date, review date, and classification.
  • Framework or control catalogue with required topic, control objective, evidence, and responsible function.
  • Policy text, procedure links, exception register, approval minutes, and review calendar.

Result

A gap register with requirement, policy coverage, control wording, owner, evidence, review status, severity, and source citations, plus a remediation summary.

Quality criteria

  • Every framework requirement has a covered, partial, missing, or not-applicable status.
  • Each gap cites the requirement and the policy clause or missing document.
  • Expired, unapproved, ownerless, and unlinked policies are separate issue types.
  • Priority follows the supplied rubric and is not invented from document age alone.

Instructions

Use the framework catalogue as the completeness baseline. Assess presence and operational usability separately. A policy counts as covered only when its control intent, owner, evidence, exception path, and review cadence are identifiable. Treat a procedure link that does not resolve to a named document as missing evidence. Keep legal or regulatory mapping claims out unless the supplied framework explicitly makes them.

Adapt before use

  • Add the authoritative control catalogue and policy inventory.
  • Define coverage statuses, priority rubric, review-period rule, and acceptable evidence types.
  • Map policy owners, approvers, procedures, and exception-management fields.

Process detail

Build the framework baseline

Enumerate each required topic, control objective, evidence type, owner function, and applicability rule.

Data basis: Framework or control catalogue and applicability register.

Result: Numbered baseline with one row per requirement.

Acceptance criterion: Baseline count equals the authoritative catalogue and every row has a source citation.

Exception: Mark applicability unresolved when the catalogue gives no rule for an entity or function.

Map policies to requirements

Match policy titles, scope statements, control clauses, and linked procedures to baseline requirements.

Data basis: Policy inventory, full policy text, headings, and procedure register.

Result: Requirement-to-policy coverage map.

Acceptance criterion: Every baseline row is mapped to one or more policies or marked missing with citations.

Exception: Do not treat a similar title as coverage without a clause supporting the control objective.

Test policy usability

Check owner, approver, version, effective date, review date, evidence, exception route, and procedure link for each mapped policy.

Data basis: Policy metadata, approval records, review calendar, evidence register, and exception log.

Result: Usability findings by policy and requirement.

Acceptance criterion: Each finding identifies the absent or contradictory field and its policy location.

Exception: A policy with an expired review date is flagged stale, not automatically invalid.

Classify framework gaps

Assign covered, partial, missing, stale, duplicate, or not-applicable status and apply the supplied severity rubric.

Data basis: Coverage map, usability findings, applicability rules, and prioritization rubric.

Result: Gap register with severity and remediation need.

Acceptance criterion: All statuses are allowed by the rubric and every non-covered row has a reason.

Exception: Use unassessed when the source set cannot establish applicability or policy ownership.

Prioritize remediation themes

Group gaps by control family, owner function, evidence type, and dependency and summarize the highest-impact themes.

Data basis: Gap register, policy inventory, owner map, and procedure links.

Result: Remediation summary with counts and cited examples.

Acceptance criterion: Theme counts equal gap-register rows and each priority theme names its affected requirements.

Exception: Do not assign a target date or owner absent from the supplied governance records.

Document what could not be assessed

List missing policy text, unresolved applicability, inaccessible approvals, broken procedure links, and absent evidence definitions.

Data basis: Open-point log, baseline, and mapping exceptions.

Result: Open-points section with requirement and source location.

Acceptance criterion: Every unassessed requirement appears once with the exact evidence gap.

Exception: State no open points only after the entire baseline is mapped.

Verwandte Skills

  • Claim chronology builder

    Builds a dated chronology from claim notices, correspondence, contracts, invoices, incident records, and evidence logs, preserving source citations and disputed dates. Use for insurance claims, commercial disputes, incident files, demand packages, litigation chronologies, and internal fact reviews.

  • Compliance training refresh

    Updates compliance training modules against revised policies, identifies changed learner obligations, and creates source-linked lesson text, scenario questions, and an answer key. Use for annual compliance refreshes, policy changes, code-of-conduct training, and controlled learning-content updates.

  • Contract obligation register

    Extracts dated and recurring duties from signed contracts into an obligation register with parties, triggers, notice windows, service levels, payment terms, evidence, and owners. Use for contract lifecycle management, renewal tracking, vendor obligations, or inherited agreement cleanup.

  • Contract playbook review

    Reviews a commercial contract against a company playbook, records missing or non-standard clauses with exact citations, and proposes fallback positions. Use for procurement, sales, SaaS, services, and contract redline preparation.