According to the BCI Horizon Scan 2025, 73% of organizations experienced at least one disruption in the past year that activated their business continuity plans. Yet most BCM managers, when asked whether their program would hold up under a different type of disruption, hesitate. That hesitation is the gap.
A gap analysis puts structure around that uncertainty. Instead of guessing where your program is weak, you compare it systematically against a defined standard and document exactly what is missing. The output is not a vague list of concerns. It is a prioritized remediation plan that tells leadership exactly what needs funding, who owns it, and by when.
This guide covers what a gap analysis is, how to run one step by step, and includes a ready-to-use template. The examples focus on business continuity, but the methodology works anywhere you need to measure the distance between where you are and where you need to be.
What is a gap analysis?
A gap analysis is a structured assessment that compares an organization's current performance, capabilities, or compliance against a desired state. The output is a list of gaps: specific areas where the current state falls short of the target, each with enough detail to prioritize and plan remediation.
The concept is simple, but the value depends entirely on how rigorously you define both sides of the comparison. A vague current state assessment compared against a vague target produces vague gaps. A specific, evidence-based assessment compared against a concrete standard produces actionable findings.
Gap analyses are used across industries and disciplines: regulatory compliance, IT security, process improvement, strategic planning, and business continuity management. The methodology is the same in each case. What changes is the framework you measure against.
Why running a gap analysis is harder than it looks
On paper, a gap analysis is straightforward: compare what you have against what you need, write down the differences. In practice, three problems consistently undermine the exercise.
Everyone overrates their own readiness
When you ask a department head whether they have a business continuity plan, they say yes. When you ask to see it, they pull up a document last updated in 2023. When you ask whether it has been tested, the room goes quiet. Self-assessment without evidence review inflates maturity scores and hides the gaps that matter most.
The fix is simple but uncomfortable: the gap analysis must be evidence-based. If you cannot point to a document, a test result, or a sign-off, the capability does not exist for gap analysis purposes. This is especially true for BCM managers working alone. When you are both the assessor and the program owner, the temptation to be generous with yourself is real.
From Checkbox to Proof: Building BCM Exercise Programs That Demonstrate Resilience
A 45-minute session in partnership with the Business Continuity Institute, where our panel of industry experts explore how BCM teams can move beyond checkbox exercises…
The target state is vague
"Improve our BCM program" is not a target state. It is an aspiration. Every person on the team will interpret it differently, and every assessment will produce different results. A useful gap analysis requires a specific, documented standard with individually assessable requirements.
For business continuity, ISO 22301 is the most common benchmark. Its clause-by-clause structure maps directly to gap analysis categories: context, leadership, planning, support, operation, performance evaluation, and improvement. Regulatory frameworks like DORA provide equally specific requirements for regulated industries.
Nobody closes the loop
The most common gap analysis failure is not in the assessment. It is in the follow-through. The analysis produces a report. The report gets presented. Everyone nods. And then the same gaps appear in next year's assessment because nobody tracked remediation. If your organization has conducted gap analyses before and the same findings keep surfacing, the methodology is not the problem. The accountability is.
How to do a gap analysis: step by step
A gap analysis follows five steps. The process is the same whether you are assessing against ISO 22301, DORA, or an internal standard. What changes is the target framework and the evidence you collect.
Step 1: Define the target state
Select the framework, standard, or set of requirements you are measuring against. This could be a formal standard like ISO 22301, a regulatory requirement like DORA or CPS 230, or an internal maturity model. The target must be specific enough that you can assess each requirement individually.
For BCM programs, ISO 22301 provides a clause-by-clause structure that works as a ready-made gap analysis framework. For regulated industries, layer sector-specific requirements on top: DORA for EU financial services, FCA operational resilience for UK firms, APRA CPS 230 for Australian institutions.
Step 2: Assess the current state
Document what you currently have in place for each requirement. This is where most gap analyses go wrong: teams rely on assumptions instead of evidence. Do not assess from memory. Review actual documents, interview process owners, and check whether documented procedures are actually followed in practice.
In a BCM gap analysis, this step typically involves reviewing your business impact analysis (is it current and complete?), your business continuity plans (do they cover all critical functions?), your exercise program (when was the last test and what did it find?), and your governance structure (who owns what and do they know it?).
Step 3: Identify and document gaps
For each requirement, compare current state against target state and record the gap. A gap exists when the current state does not meet the requirement, meets it only partially, or meets it on paper but not in practice. Be specific: "BIA exists but has not been updated since 2024 and covers only 60% of critical functions" is useful. "BIA needs improvement" is not.
Document each gap with enough context that someone who was not in the room can understand what is missing and why it matters. The gap description should make the remediation action obvious.
Step 4: Prioritize gaps
Not all gaps carry equal risk or require equal effort to close. Prioritize using two dimensions: impact (what is the consequence of this gap remaining open?) and effort (what does it take to close it?).
| Priority | Impact | Effort | Action |
|---|---|---|---|
| 1 (quick wins) | High | Low | Close immediately |
| 2 (roadmap) | High | High | Plan and resource for next quarter |
| 3 (schedule) | Medium | Low | Close within current cycle |
| 4 (backlog) | Low | High | Defer unless resources allow |
High-impact, low-effort gaps are your quick wins. They build momentum and demonstrate progress to leadership. High-impact, high-effort gaps go on your roadmap with proper resourcing. Low-impact gaps can wait.
Step 5: Build the remediation plan
Each prioritized gap needs an owner, a target close date, and a defined action. The remediation plan is where gap analysis translates into business continuity strategies: specific initiatives that move the organization from current state to target state.
Track remediation progress in regular review cycles (monthly or quarterly). Gaps that remain open for multiple cycles without progress need escalation, not just a new target date. If the same gap appears in consecutive annual assessments, it is a governance failure, not a planning one.
Gap analysis template
The template below works for any gap analysis but is structured around a business continuity assessment against ISO 22301. Adapt the requirement categories to match your target framework. Each row captures one requirement, the current state, the gap, its severity, and the remediation action.
| Category | Requirement | Current state | Gap | Severity | Remediation | Owner | Target date |
|---|---|---|---|---|---|---|---|
| Policy and governance | BC policy approved by senior leadership | Policy exists, last reviewed 2024 | Policy not reviewed annually as required | Medium | Schedule policy review with executive sponsor | BCM Lead | Q1 2027 |
| Business impact analysis | BIA completed for all critical functions | BIA covers 60% of functions | 40% of critical functions not assessed | High | Extend BIA to remaining departments | BCM Lead | Q4 2026 |
| Recovery strategies | Documented strategy per critical function | Strategies exist for IT only | No strategies for facilities, supply chain, workforce | High | Develop strategies for non-IT domains | BCM Lead | Q1 2027 |
| Plans and procedures | BC plans tested within last 12 months | Last test was 18 months ago | Plans not tested within required frequency | High | Schedule tabletop exercise for all plans | BCM Lead | Q4 2026 |
| Exercise program | Annual program with multiple exercise formats | One tabletop per year | No simulation or functional exercises conducted | Medium | Add simulation exercise to annual program | BCM Lead | Q2 2027 |
| Incident management | Crisis communication plan documented | Informal process, not documented | No formal crisis communication plan | High | Draft crisis communication plan | Comms Lead | Q4 2026 |
| Monitoring and review | Management review of BCM program annually | No formal management review | No evidence of management oversight | Medium | Establish annual management review meeting | BCM Lead | Q1 2027 |
If the gap analysis reveals that your business continuity plans are incomplete or missing, a structured business continuity plan template provides the framework to build them consistently across departments.
Gap analysis examples
The following examples show what gap analysis findings look like in practice. Each illustrates the gap, why it matters, and what remediation looks like.
Example 1: ISO 22301 certification readiness
A mid-market financial services firm wants ISO 22301 certification within 12 months. The gap analysis reveals: BIA is current but only covers head office operations (not branches). Recovery strategies exist for IT but not for customer-facing processes. The exercise program runs one tabletop annually but ISO requires evaluating performance across multiple exercise types.
The remediation roadmap: extend BIA to branches (Q1), develop customer process strategies (Q2), add a simulation exercise (Q3), enter certification audit (Q4). Each gap maps to a specific ISO 22301 clause, making the audit trail clean.
Example 2: DORA compliance
A European bank needs to demonstrate DORA compliance. The gap analysis against DORA's five pillars reveals: ICT risk management framework exists but does not reference critical business services. Third-party risk register is incomplete, covering 60% of ICT providers. Digital operational resilience testing program has no threat-led penetration testing component.
The bank maps each gap to the specific DORA article it violates and builds a compliance roadmap with regulatory deadlines driving prioritization. A broader view of which regulations and standards apply ensures the assessment covers all relevant requirements.
Example 3: Post-incident lessons
After a ransomware incident, a healthcare organization runs a gap analysis against its own BC plans. Backup restoration took 14 hours against a stated RTO of 4 hours. Crisis communication reached only 60% of staff because the contact list was outdated. The incident commander role was undefined, leading to ad-hoc decision-making.
Each gap traces directly to a failure observed during the incident. Improving disaster recovery testing frequency is flagged as the highest priority action, followed by crisis communication plan documentation and incident command role definition.
Gap analysis vs other assessment types
Gap analysis is one of several assessment methods. Understanding how it differs from related approaches prevents you from using the wrong tool.
| Assessment type | Purpose | Output | When to use |
|---|---|---|---|
| Gap analysis | Measure current vs target state | Prioritized gaps with remediation plan | Before certification, after regulation change, or annually |
| Risk assessment | Identify and evaluate threats | Risk register with likelihood and impact scores | Before strategic planning or after significant change |
| Maturity assessment | Rate capability on a scale | Maturity score per domain (1-5) | Benchmarking or tracking year-on-year improvement |
| Audit | Verify conformance with evidence | Conformity/nonconformity findings | Formal assurance for regulators or certification bodies |
| Business impact analysis | Quantify impact of function loss | RTO/RPO per function, dependency maps | Before developing recovery strategies |
A gap analysis often follows a business impact analysis. The BIA tells you what matters and sets the recovery time objectives. The gap analysis then asks: can we actually meet those objectives with what we have today? Where there is a shortfall between stated RTOs and actual recovery capability, you have a gap.
Common gap analysis mistakes
Gap analyses are straightforward in concept but frequently go wrong in execution. These patterns reduce a gap analysis from a strategic tool to a compliance checkbox.
1. Assessing against an unclear target
If your target state is "improve our BCM program," every assessment will produce different results depending on who runs it. The target must be a specific, documented standard with individually assessable requirements. Vague targets produce vague gaps that nobody can act on.
2. Self-assessing without evidence
Teams consistently overrate their own readiness when assessing from memory. The gap analysis must review actual artifacts: the BIA document, the plan itself, the exercise report, the management review minutes. If you cannot point to evidence, the capability does not exist for gap analysis purposes.
3. Documenting gaps without severity
A flat list of 40 gaps with no prioritization is not actionable. Every gap needs a severity rating based on business impact. Without prioritization, leadership cannot make funding decisions and remediation efforts scatter across low-impact items while critical gaps remain open.
4. Never closing the loop
A gap analysis that produces a report but no tracked remediation plan is wasted effort. Every gap needs an owner, a target date, and a review cadence. This is where a mature BCM maturity benchmark helps: it provides the scoring framework to track whether your gap closure is actually moving the needle on program capability.
Related articles
Business impact analysis (BIA): steps and template
ISO 22301: the business continuity standard explained
Business continuity strategies: types and examples

