Skip to main content
    Framework assurance

    Framework Gap Assessments & Internal Audits

    Choose the criteria that matter to your organization and the question you need answered. A gap assessment identifies where work is needed. An internal audit evaluates evidence against an agreed scope and criteria, with conclusions limited to what was reviewed and tested.

    Choose the question before the framework

    Gap assessment vs internal audit

    The name alone does not determine the assurance you receive. We agree the depth of review, evidence and testing explicitly. Neither engagement replaces an external certification or attestation process.

    Gap assessment

    Purpose
    Identify gaps and decide what to address next.
    Criteria
    Selected framework requirements or outcomes relevant to your goals.
    Procedures
    Interviews, document review and targeted inspection; testing depth is agreed in scope.
    Evidence
    Policies, inventories, self-reported practices and available implementation records, distinguished in the report.
    Deliverable
    A gap register with evidence needs and prioritized recommendations.
    Limitation
    A gap review is not proof that controls operated effectively.
    Best when
    You are choosing a starting point, preparing for external review or planning improvements.

    Internal audit

    Purpose
    Evaluate controls against agreed criteria and answer a defined assurance question.
    Criteria
    Documented criteria and control expectations agreed before testing.
    Procedures
    Documented procedures, inspection and agreed sample-based control testing.
    Evidence
    Traceable records supporting design, implementation and, where tested, operating effectiveness.
    Deliverable
    An internal audit report with procedures, findings, evidence references and scoped conclusions.
    Limitation
    Conclusions apply only to the scope, period and sample reviewed and tested.
    Best when
    You need a documented evaluation of defined controls, including a management-system internal audit.

    Criteria we assess against

    Choose criteria because they answer a business, risk or contractual question—not because every framework must be assessed at once. Framework mappings are indicative, not equivalence or a substitute for the applicable standard.

    ISO/IEC 27001:2022

    What we evaluate
    Information security management requirements in clauses 4–10 and the Annex A control themes relevant to your scope: organizational, people, physical and technological.
    Typical evidence
    Management-system scope, risk assessment, Statement of Applicability, policies, access records, review minutes and sampled control records.
    What the deliverable means
    A scoped gap assessment or internal audit with findings against agreed requirements; not an ISO certificate or a certification audit.
    ISO information security standard

    ISO/IEC 42001:2023

    What we evaluate
    AI management-system requirements in clauses 4–10 and the Annex A AI controls relevant to your scope, including responsibility, risk assessment and lifecycle oversight.
    Typical evidence
    AI inventory, management-system scope, risk and impact assessments, governance decisions, supplier records and lifecycle review evidence.
    What the deliverable means
    A scoped gap assessment or internal audit of the AI management system; not certification or a substitute for other frameworks.
    ISO AI management-system standard

    NIST CSF 2.0

    What we evaluate
    Agreed cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond and Recover, using profiles appropriate to the organization.
    Typical evidence
    Risk register, governance records, asset inventory, access configuration, monitoring records, incident procedures and recovery-test records.
    What the deliverable means
    A current-state assessment and prioritized outcome gaps; not a NIST certification or a universal compliance score.
    NIST Cybersecurity Framework

    NIST AI RMF 1.0 + Generative AI Profile

    What we evaluate
    AI risk-management practices using NIST AI RMF 1.0 and, for generative AI, the Generative AI Profile (NIST AI 600-1). Scope connects risks to the AI use cases being reviewed.
    Typical evidence
    Use-case inventory, risk decisions, evaluation results, human-oversight records, third-party reviews and incident handling.
    What the deliverable means
    An evidence-based assessment of agreed AI risk practices; not certification, legal classification or an assurance conclusion on untested models.
    NIST AI risk-management resources

    SOC 2 Trust Services Criteria readiness

    What we evaluate
    Readiness against the Trust Services Criteria for the agreed system boundary and selected categories.
    Typical evidence
    System description, control ownership, policies, access reviews, change approvals, vendor reviews and relevant period records.
    What the deliverable means
    A SOC 2 readiness assessment against the Trust Services Criteria. The SOC 2 examination and report are performed by an independent CPA firm; we prepare you for it. Our work is not that examination or report.
    AICPA SOC resources

    CMMC

    What we evaluate
    Readiness for the contract-specified level and assessment type. Applicability follows the actual contract and current program requirements, including the FCI or CUI handled. DoD CIO reports that Phase II was suspended July 13, 2026 and implementation is paused in Phase I, with Phase I self-assessment requirements retained.
    Typical evidence
    Contract requirements, information-flow and boundary records, system security plan, access settings and control evidence; for Level 2, the relevant NIST SP 800-171 Rev. 2 requirements.
    What the deliverable means
    A scoped readiness review and gap register; not a CMMC certification, authorized third-party assessment or government assessment.
    DoD CIO — About CMMC

    HIPAA Security Rule

    What we evaluate
    If you are a covered entity or business associate, agreed safeguards for electronic protected health information. As of October 1, 2026, HHS still lists the January 2025 HIPAA Security Rule update as a proposed rule, not a final rule.
    Typical evidence
    Risk analysis, ePHI inventory and flows, policies, access records, business associate agreements and incident procedures, using appropriately restricted evidence.
    What the deliverable means
    Findings on safeguards within the agreed scope; not a HIPAA certificate, legal advice or a blanket compliance determination.
    HHS Security Rule guidance

    HITRUST CSF

    What we evaluate
    Readiness against agreed requirements of the voluntary HITRUST CSF, which maps to HIPAA and other authoritative sources. HITRUST is not required by HIPAA.
    Typical evidence
    The applicable assessment scope, control documentation, risk decisions and implementation or operation records agreed for review.
    What the deliverable means
    A readiness gap register, not HITRUST certification. Certification is issued by HITRUST through its assessor programme and does not itself establish HIPAA compliance.
    HITRUST programme information

    GovRAMP (formerly StateRAMP) / FedRAMP

    What we evaluate
    Readiness for the applicable programme, boundary and baseline, using NIST SP 800-53 Rev. 5-based requirements. The programmes have distinct processes; one does not substitute for the other.
    Typical evidence
    System boundary, security plan, control descriptions, inventories, risk records and programme-specific evidence requirements.
    What the deliverable means
    An agreed readiness assessment and evidence-gap register; not authorization, certification or an authorized programme assessment.
    FedRAMP programme requirementsGovRAMP programme requirements

    What you receive

    • Scope memo

      The question, criteria, systems, boundaries, period and exclusions agreed before work begins.

    • Evidence request list

      Requests tied to control objectives, with owners, sources, periods and handling needs.

    • Test procedures

      Documented work performed and the sampling or inspection approach, so readers understand the basis of findings.

    • Classified findings

      Design, implementation and operating-effectiveness observations separated from missing or unknown evidence.

    • Prioritized recommendations

      Actions linked to risk and evidence gaps, with suggested ownership for management to consider.

    • Closing readout

      A discussion of findings, limitations and next steps; management remains responsible for its decisions.

    See the assessment method and fictional deliverables

    Who it is for

    Small teams through larger organizations can use a focused assessment. Scope follows your risk, systems and decision—not an employee minimum. It helps when you need to prioritize gaps, plan a management-system internal audit or organize evidence ahead of an external review.

    Bring the framework or contract requirement if you know it. If not, bring the decision you need to make and the systems involved; we can discuss suitable criteria and boundaries.

    The free self-check is preliminary self-reported guidance. It does not inspect evidence or test controls.

    Limitations

    • Conclusions are limited to the agreed scope, criteria, period, available evidence and sample.
    • Missing evidence is reported as unknown or unavailable; it is not treated as a passed control.
    • A checklist or methodology workbook is not proof that customer controls were tested.
    • AuditPartners is not a certification body or CPA firm. This work is not certification, a CPA examination or legal advice.
    • The separately agreed engagement letter defines the work and deliverables. No certification, authorization or external acceptance is guaranteed.

    Agree the criteria, evidence and question first

    Discuss a focused gap assessment or internal audit that fits your systems and risk.