Skip to main content

    Assessment Methods

    Gap Assessment vs. Internal Audit: What Each Covers, What Each Proves and What You Receive

    Buyers often ask for "an audit" when they need a gap assessment, and for "a gap assessment" when the board has asked for an audit. The two engagements can look alike from the outside, since both involve criteria, evidence requests and a report, but they answer different questions, carry different independence expectations and produce different deliverables. Choosing the wrong one wastes money and, worse, produces a document that does not support the decision it was bought for.

    This article sets the two side by side, with fictional examples of what each produces for the same control, and explains why neither is a certification or a SOC 2 examination.

    By
    AuditPartners
    Added
    Reading time
    9 min
    Status
    Educational guide

    Working definitions

    A gap assessment compares an organisation's current practices against a chosen set of criteria (a standard, a framework or the organisation's own policy) to identify where practice falls short, and typically recommends what to do about it. It is forward-looking and advisory. Its depth is negotiable: it may rely on self-report and document review only, or it may include inspection and testing if that is agreed in scope.

    An internal audit is an assurance activity performed by, or on behalf of, the organisation's own internal audit function. For most organisations the applicable professional framework is the IIA's Global Internal Audit Standards, effective 9 January 2025, which set expectations for independence, objectivity, planning, evidence and reporting. For a management system such as ISO/IEC 27001:2022 or ISO/IEC 42001:2023, the standard itself requires internal audits at planned intervals, and ISO 19011 provides guidance on auditing management systems. The IIA Standards and ISO management-system audit guidance are not interchangeable; which one governs depends on who commissions the audit and why.

    Side by side

    Gap assessment and internal audit compared on the dimensions that change the outcome
    DimensionGap assessmentInternal audit
    Primary questionWhere are we short of the criteria, and what should we do first?Do the controls we rely on exist and operate as intended, and can we say so with evidence?
    Who it is forManagement, a programme lead, a buyer deciding whether to pursue certification.The board or audit committee and senior management; sometimes a regulator or parent company.
    CriteriaChosen by the sponsor: a standard, a framework profile or internal policy. May be partial.Agreed in the audit plan and tied to the organisation's risk assessment; expected to be complete for the audited scope.
    IndependenceAdvisory; the assessor may also help remediate afterwards.Required. The IIA Standards expect organisational independence of the function and individual objectivity; ISO 19011 expects auditors not to audit their own work.
    Evidence depth (default)Self-report and documents; inspection and testing only if agreed in scope.Documents, inspection and testing, with sampling proportionate to the conclusion sought.
    ConclusionA prioritised list of gaps and recommendations. Any conclusion on operating effectiveness depends on sufficient reliable operating evidence, including inspection or testing agreed in scope.Findings with condition, criteria, cause, consequence and recommendation; an overall conclusion for the scope, qualified by the evidence obtained.
    Period coveredPoint in time.Point in time or a defined period, stated in the report. Internal audits do not universally conclude on operating effectiveness over a period; the plan says what was tested.
    DeliverablesGap register, prioritised roadmap, optional evidence inventory.Audit report, working papers, management responses and action plan, follow-up tracking.
    Typical follow-onRemediation, then an internal audit or certification audit.Management action tracking; input to the next risk assessment and audit plan.
    The rows describe common practice and the professional frameworks cited; the exact terms of any engagement are set by its agreed scope and procedures, not by its label.

    One control, two outputs

    The clearest way to see the difference is to watch both engagements handle the same control. The example uses access reviews because almost every framework expects them in some form.

    How each engagement treats the Ferncastle access-review control
    StepGap assessment outputInternal audit output
    Evidence requestedPolicy; the most recent review sign-off; a conversation with the security lead.Policy; all four quarterly reviews in the period; the user population at each review date; ticket records for every revocation; evidence of who performed each review.
    Evidence obtainedPolicy (document); Q2 sign-off email (document); lead confirms the process runs each quarter (self-reported).Policy; sign-offs for Q1, Q2 and Q4 only; Q3 reviewer left the company and no Q3 review record could be produced; 31 revocations identified, 26 completed within five days, 3 completed late, 2 outstanding.
    AnalysisControl exists and appears to be designed in line with the criteria. Gap: no evidence that the review covers service accounts; policy does not define 'system owner'.Design adequate. Operation: Q3 performance could not be established from the missing review records; this does not prove the review or revocations never happened. Of the 31 identified revocations, 26 were timely (about 84%), 3 late and 2 outstanding; the two outstanding accounts retained access for over 60 days after the review flagged them.
    OutputGap register entry: 'Extend access review scope to service accounts; define ownership; retain review evidence.' Priority: medium. Owner: security lead.Finding (medium): condition, criteria, cause (reviewer departure with no evidence handover), consequence (Q3 performance unestablished; two accounts over-privileged), recommendation and management response with dates. Conclusion for the control: partially effective on the evidenced population, with Q3 performance not established.
    What the reader can rely onThat the control is probably designed appropriately and where to improve before certification. Not that it operated.That on the evidenced population the control operated with the stated exceptions; Q3 performance could not be established.

    Neither output is wrong. The gap assessment told management what to fix before a certification audit. The internal audit told the audit committee something the gap assessment could not: performance for Q3 could not be established, and the identified revocations included three late and two outstanding cases. Missing Q3 records are not proof that revocation never happened. If the gap assessment had been scoped to include inspection of all four quarters, it could have identified the same evidence gap; depth follows scope, not the engagement label.

    Choosing between them

    Ask three questions before you commission either.

    1. What decision will the report support? 'Should we start a certification programme and what will it take?' points to a gap assessment. 'Can the audit committee rely on these controls?' points to an internal audit.
    2. Who needs to trust it? If the reader is management, advisory independence is acceptable. If the reader is a board, regulator or parent, the independence expectations in the IIA Standards or ISO 19011 apply and the engagement should be commissioned accordingly.
    3. What operating evidence can you provide, and over what population? Inspection of reliable operating records can support operating effectiveness, alongside testing where appropriate. Without sufficient evidence for the population and period, the conclusion must be limited whatever the engagement is called.

    Both engagement types are described, with sample deliverables, on our Framework Assessments & Internal Audits page, and the free guide Gap Assessment vs. Internal Audit: What Each Can and Cannot Tell You is a six-page companion guide for sharing with a sponsor. If the subject is an AI management system, ISO 42001 Internal Audit: An Evidence Request Checklist shows what the evidence request looks like in practice, and IT Risk Assessment: From Risk Register to Control Testing covers how a risk assessment feeds the audit plan. If you are not sure you have enough of a programme to assess yet, the free AI Governance QuickScan gives a preliminary, self-reported view in about ten minutes.

    Key takeaways

    • A gap assessment answers 'where are we short and what first'; an internal audit answers 'do the controls operate, with evidence'.
    • Independence and evidence depth are the real differences; the label is not. Depth follows agreed scope and procedures.
    • Neither engagement issues a management-system certificate or a SOC 2 report; external certification bodies and independent CPA firms respectively do so. Accredited certification adds a competence check; accreditation is not compulsory and ISO does not certify.
    • Internal audits conclude only on the period and population actually tested; read the scope section before relying on a conclusion.
    • Decide by the decision the report must support, who must trust it, and how much testing you can resource.
    Related serviceFramework AssessmentsRelated resourceGap Assessment vs. Internal Audit guideFree toolAI Governance QuickScan

    References

    Primary sources cited above. Standards are referenced by number and year; their text is licensed and is paraphrased, not reproduced.

    1. The IIA, Global Internal Audit Standards (effective 9 January 2025) (opens in a new tab) — Independence, objectivity, evidence and reporting expectations for internal audit.
    2. ISO 19011, Guidelines for auditing management systems (opens in a new tab) — Licensed text; guidance on management-system audit programmes and auditor competence, paraphrased.
    3. ISO/IEC 27001:2022, Information security management systems — Requirements (opens in a new tab) — Licensed text; internal audit requirement referenced, not reproduced.
    4. ISO/IEC 42001:2023, Artificial intelligence management system — Requirements (opens in a new tab) — Licensed text; internal audit requirement referenced, not reproduced.
    5. AICPA, 2017 Trust Services Criteria with Revised Points of Focus (2022) (opens in a new tab)
    6. AICPA, System and Organization Controls (SOC) suite of services (opens in a new tab) — SOC 2 reports are issued by independent CPA firms.

    Need this applied to your environment?

    A scoped assessment follows the agreed criteria, procedures and evidence described here. Findings are reviewed and signed off by accountable professionals.