GDPR gap analysis: finding what is missing before someone else does
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
A risk control matrix maps what could go wrong to what stops it. Most matrices fail because the rows describe processes rather than risks.
A risk control matrix — an RCM — is the document that links each risk in a process to the control that addresses it, and records how that control is performed, by whom, how often, and what evidence it leaves. It is the working core of a control programme: the scoping, the testing plan and the deficiency evaluation all read from it.
The failure mode is almost always the same. The rows describe activities rather than risks: "invoices are processed", "payroll is run". An activity is not a risk, and a matrix built on activities cannot say whether the control is sufficient, because there is nothing for it to be sufficient against.
The evidence column is the one to fill in first when building a matrix, not last. If nobody can name the artefact, the control will fail testing regardless of how well it is described — and the discovery is much cheaper now than during the audit.
A usable risk statement has a cause, an event and a consequence: "a supplier bank account is changed fraudulently, so payments are diverted". That sentence implies its own control — verification of bank detail changes through an independent channel — and implies its evidence, being the record of that verification.
Compare "vendor master data" as a row. It names a topic and controls nothing. Matrices full of topics grow endlessly because nobody can tell when a risk is adequately covered.
Mark key controls sparingly. Every control marked key must be tested every year, with a sample size that follows its frequency. Teams that mark everything key create a testing programme they cannot complete, and an incomplete testing programme is a worse position than a smaller one that finishes.
An RCM is a living spreadsheet with an audit trail attached: many columns, several editors, and a need to prove later what it said in March. Ettex Sheets keeps the matrix with its version history and its review trail, so the row the tester sampled and the row that exists today can be compared rather than confused. Where the internal controls are already documented this way, the balance sheet reconciliation schedules and access reviews they reference are the same records the matrix points at.
A risk register lists risks across the organisation with owners and ratings. An RCM sits inside a process and pairs each risk with the specific control that addresses it and the evidence it produces.
The process owner owns the content; internal control or internal audit usually maintains the format and challenges it. Ownership by the audit function alone produces a document the business does not recognise.
As many as the risks require and no more. A process with twenty controls and four risks is usually describing steps rather than controls.
The claims implicit in reported figures — existence or occurrence, completeness, accuracy, valuation or allocation, rights and obligations, and presentation and disclosure. Mapping controls to assertions is how you tell whether a risk is genuinely covered.
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
The risk assessment is where an ISMS is won or lost. Vague risk statements produce controls nobody can test and a certificate that means little.
A reconciled account is one where the balance is supported by evidence of what makes it up. Most accounts that look reconciled are merely explained.