---
name: policy-framework-gap-check
description: Checks a policy framework against its required controls, ownership, review cadence, evidence, exceptions, and related procedures, producing a cited gap register and remediation priorities. Use for governance reviews, policy-library health checks, and control-framework assessments.
license: Apache-2.0
metadata:
  adlass.categories: "legal-compliance/policy-governance"
  adlass.industries: ""
  adlass.tags: "policy,framework,gap-analysis,controls,governance,compliance"
  adlass.adaptation: "reference-doc"
  adlass.source: "original"
  adlass.version: "1"
---

# Policy framework gap check

## Purpose

Assess whether a policy framework contains the required control topics and whether each policy is usable: owned, approved, versioned, review-dated, evidenced, and linked to operating procedures.

## Scope

Review the policy inventory, framework or control catalogue, individual policy documents, approval records, review dates, exception logs, and procedure links.

**Excluded:** declaring legal compliance, approving policies, drafting a full policy suite, and assigning owners without evidence.

## Data basis

- Policy inventory with title, owner, version, status, approval date, review date, and classification.
- Framework or control catalogue with required topic, control objective, evidence, and responsible function.
- Policy text, procedure links, exception register, approval minutes, and review calendar.

## Result

A gap register with requirement, policy coverage, control wording, owner, evidence, review status, severity, and source citations, plus a remediation summary.

## Quality criteria

- Every framework requirement has a covered, partial, missing, or not-applicable status.
- Each gap cites the requirement and the policy clause or missing document.
- Expired, unapproved, ownerless, and unlinked policies are separate issue types.
- Priority follows the supplied rubric and is not invented from document age alone.

## Instructions

Use the framework catalogue as the completeness baseline. Assess presence and operational usability separately. A policy counts as covered only when its control intent, owner, evidence, exception path, and review cadence are identifiable. Treat a procedure link that does not resolve to a named document as missing evidence. Keep legal or regulatory mapping claims out unless the supplied framework explicitly makes them.

## Adapt before use

- Add the authoritative control catalogue and policy inventory.
- Define coverage statuses, priority rubric, review-period rule, and acceptable evidence types.
- Map policy owners, approvers, procedures, and exception-management fields.

## Process detail

### Build the framework baseline

Enumerate each required topic, control objective, evidence type, owner function, and applicability rule.

**Data basis:** Framework or control catalogue and applicability register.

**Result:** Numbered baseline with one row per requirement.

**Acceptance criterion:** Baseline count equals the authoritative catalogue and every row has a source citation.

**Exception:** Mark applicability unresolved when the catalogue gives no rule for an entity or function.

### Map policies to requirements

Match policy titles, scope statements, control clauses, and linked procedures to baseline requirements.

**Data basis:** Policy inventory, full policy text, headings, and procedure register.

**Result:** Requirement-to-policy coverage map.

**Acceptance criterion:** Every baseline row is mapped to one or more policies or marked missing with citations.

**Exception:** Do not treat a similar title as coverage without a clause supporting the control objective.

### Test policy usability

Check owner, approver, version, effective date, review date, evidence, exception route, and procedure link for each mapped policy.

**Data basis:** Policy metadata, approval records, review calendar, evidence register, and exception log.

**Result:** Usability findings by policy and requirement.

**Acceptance criterion:** Each finding identifies the absent or contradictory field and its policy location.

**Exception:** A policy with an expired review date is flagged stale, not automatically invalid.

### Classify framework gaps

Assign covered, partial, missing, stale, duplicate, or not-applicable status and apply the supplied severity rubric.

**Data basis:** Coverage map, usability findings, applicability rules, and prioritization rubric.

**Result:** Gap register with severity and remediation need.

**Acceptance criterion:** All statuses are allowed by the rubric and every non-covered row has a reason.

**Exception:** Use unassessed when the source set cannot establish applicability or policy ownership.

### Prioritize remediation themes

Group gaps by control family, owner function, evidence type, and dependency and summarize the highest-impact themes.

**Data basis:** Gap register, policy inventory, owner map, and procedure links.

**Result:** Remediation summary with counts and cited examples.

**Acceptance criterion:** Theme counts equal gap-register rows and each priority theme names its affected requirements.

**Exception:** Do not assign a target date or owner absent from the supplied governance records.

### Document what could not be assessed

List missing policy text, unresolved applicability, inaccessible approvals, broken procedure links, and absent evidence definitions.

**Data basis:** Open-point log, baseline, and mapping exceptions.

**Result:** Open-points section with requirement and source location.

**Acceptance criterion:** Every unassessed requirement appears once with the exact evidence gap.

**Exception:** State no open points only after the entire baseline is mapped.

