Compliance Gap Assessment

From "which clauses matter?" to a scored gap report. Asked and answered.

ICMS AI reads your organisation, picks the standards that apply, and runs the gap assessment itself. You score every clause, see where you sit, and get a prioritised list of gaps to close, without opening a spreadsheet.

gap assessment
ISO/IEC 27001
Requirements checked6 clauses
  • A.5.1Information security policiesMet
  • A.5.15Access controlMet
  • A.6.3Awareness & trainingGap
  • A.8.7Malware protectionMet
  • A.8.16Monitoring activitiesGap
  • A.12.3BackupsMet
67%coverage
4 met 2 gaps
4 met·2 gaps67% ready

Traditional ICMS is a workflow. ICMS AI is a conversation.

Traditional workflow

You navigate the app.

  • Compliance lead maps the standard into a spreadsheet by hand
  • Site visits, interviews, and paper checklists to score each clause
  • Weeks of manual consolidation before anyone sees the score
  • The gap register lives in one person's laptop

ICMS AI · agentic

You just ask.

  • Ask: "Run a gap assessment on ISO 27001 for Site A"
  • The assistant reads your existing documents, sites and evidence
  • Every clause is scored automatically with a suggested rationale
  • Gaps are flagged, prioritised by risk, and pushed to the right owner

How it works.

  1. 01

    Select scope

    Pick the standard (ISO 27001, GDPR, HIPAA, DPDP, ISO 9001, ISO 42001 and more) and the site or business unit in scope.

  2. 02

    The assistant reads your context

    It reads your uploaded documents, existing evidence, and previous audit findings to build a picture of where you sit.

  3. 03

    Clause-by-clause scoring

    Each clause is scored Met, Gap or N/A with a rationale you can review. Confidence and evidence links are shown.

  4. 04

    Gap report + next actions

    A prioritised gap register lands with suggested corrective actions, routed to the owner and tracked to closure.

What you get.

Turns weeks of manual scoring into minutes of conversation, without losing the audit trail.

  • Multi-framework coverage: ISO, GDPR, HIPAA, DPDP, SOC 2, PCI DSS, NIST CSF, sector standards
  • Site-scoped and business-unit-scoped assessments
  • Automatic re-scoring when documents or evidence change
  • Rationale + citation to source evidence on every clause
  • Coverage dial and gap register export
  • Chat-first: the same assessment can be re-run by asking a follow-up question

See it on your standards.

Talk to us about running this on your compliance programme.