Resource library

    Expert insight / Risk and gap analysis

    Risk or Gap? How to Tell the Difference

    A plain-language example that connects a missing control to its possible business consequence.

    AIdentX Editorial · · 3 min read

    At a glance

    A missing access end date is a gap. The possibility that access continues after a supplier engagement ends is a risk. Keeping the two ideas separate makes findings easier to explain and actions easier to assign.

    • Describe the missing or insufficient practice as the gap.
    • Explain the possible consequence as the risk.
    • Do not turn an unverified possibility into a claimed incident.

    Start with an observation

    In this fictional example, a reviewer selects supplier-access requests for a finance application. Some requests contain no authorised end date. That is the observation. The reviewer should record the selected population and period so the reader understands what was actually examined.

    If the expected process requires an end date, the missing information supports a gap finding. It does not yet establish whether the accounts remained active, whether another control removed access or whether any information was misused.

    Explain why the gap matters

    A risk statement connects a condition with a plausible event and consequence. For example: “Without a reliable expiry process, supplier access may continue after the engagement ends, leaving finance information accessible beyond the approved business need.” The wording explains the concern without inventing an incident.

    NIST SP 800-30 considers likelihood and impact as part of risk assessment. The missing practice is therefore one input to a risk judgement, rather than the entire judgement. NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments.

    PartIllustrative wording
    ObservationSelected requests lack an end date.
    GapThe expected expiry information is not consistently recorded.
    RiskAccess may continue beyond the approved business need.
    Next checkCompare engagement end dates with current access and removal records.

    Keep the relationship flexible

    One gap can contribute to several risks. Missing ownership may affect approval, removal and exception review. Several gaps can also contribute to one risk. Missing end dates and unverified removal can both increase concern about continuing supplier access.

    This is why matching every gap to exactly one risk can oversimplify the assessment. Keep the source evidence visible and explain the relationship. If two findings describe the same underlying condition, consider whether they should be linked or treated as duplicates rather than counted as independent exposures.

    Use the distinction to define better work

    The corrective action should address the condition that creates the concern. “Reduce risk” gives an owner little direction. “Complete end dates for in-scope supplier accounts and verify removal after completed engagements” describes a change that can be checked.

    AssessX separates risk and gap analysis while supporting review of the underlying findings. Use the risk view to discuss exposure and the gap view to understand what needs to improve. Then connect the agreed work to the relevant findings so the roadmap has a clear purpose.

    Before closing the work, revisit both questions. Has the missing practice been corrected? Does fresh evidence support the conclusion that the relevant exposure has changed? A published procedure may answer the first question only partly and the second not at all.

    References

    Primary guidance used for the specific points cited above. The examples, templates and recommended working practices are AIdentX editorial guidance.

    Sources reviewed September 2026.

    Published by AIdentX Editorial. Illustrative scenarios are fictional and do not represent customer results.

    Continue reading

    See the workflow in practice. Watch the AssessX product demonstrations.