At a glance
A missing access end date is a gap. The possibility that access continues after a supplier engagement ends is a risk. Keeping the two ideas separate makes findings easier to explain and actions easier to assign.
- Describe the missing or insufficient practice as the gap.
- Explain the possible consequence as the risk.
- Do not turn an unverified possibility into a claimed incident.
Start with an observation
In this fictional example, a reviewer selects supplier-access requests for a finance application. Some requests contain no authorised end date. That is the observation. The reviewer should record the selected population and period so the reader understands what was actually examined.
If the expected process requires an end date, the missing information supports a gap finding. It does not yet establish whether the accounts remained active, whether another control removed access or whether any information was misused.
Explain why the gap matters
A risk statement connects a condition with a plausible event and consequence. For example: “Without a reliable expiry process, supplier access may continue after the engagement ends, leaving finance information accessible beyond the approved business need.” The wording explains the concern without inventing an incident.
NIST SP 800-30 considers likelihood and impact as part of risk assessment. The missing practice is therefore one input to a risk judgement, rather than the entire judgement. NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments.
| Part | Illustrative wording |
|---|---|
| Observation | Selected requests lack an end date. |
| Gap | The expected expiry information is not consistently recorded. |
| Risk | Access may continue beyond the approved business need. |
| Next check | Compare engagement end dates with current access and removal records. |
Keep the relationship flexible
One gap can contribute to several risks. Missing ownership may affect approval, removal and exception review. Several gaps can also contribute to one risk. Missing end dates and unverified removal can both increase concern about continuing supplier access.
This is why matching every gap to exactly one risk can oversimplify the assessment. Keep the source evidence visible and explain the relationship. If two findings describe the same underlying condition, consider whether they should be linked or treated as duplicates rather than counted as independent exposures.
Use the distinction to define better work
The corrective action should address the condition that creates the concern. “Reduce risk” gives an owner little direction. “Complete end dates for in-scope supplier accounts and verify removal after completed engagements” describes a change that can be checked.
AssessX separates risk and gap analysis while supporting review of the underlying findings. Use the risk view to discuss exposure and the gap view to understand what needs to improve. Then connect the agreed work to the relevant findings so the roadmap has a clear purpose.
Before closing the work, revisit both questions. Has the missing practice been corrected? Does fresh evidence support the conclusion that the relevant exposure has changed? A published procedure may answer the first question only partly and the second not at all.
References
Primary guidance used for the specific points cited above. The examples, templates and recommended working practices are AIdentX editorial guidance.
Sources reviewed September 2026.
Published by AIdentX Editorial. Illustrative scenarios are fictional and do not represent customer results.
