Back to Blog
Business Continuity

Gap analysis: definition, template and examples

Gap analysis: definition, template and examples

According to the BCI Horizon Scan 2025, 73% of organizations experienced at least one disruption in the past year that activated their business continuity plans. Yet most BCM managers, when asked whether their program would hold up under a different type of disruption, hesitate. That hesitation is the gap.

A gap analysis puts structure around that uncertainty. Instead of guessing where your program is weak, you compare it systematically against a defined standard and document exactly what is missing. The output is not a vague list of concerns. It is a prioritized remediation plan that tells leadership exactly what needs funding, who owns it, and by when.

This guide covers what a gap analysis is, how to run one step by step, and includes a ready-to-use template. The examples focus on business continuity, but the methodology works anywhere you need to measure the distance between where you are and where you need to be.

What is a gap analysis?

A gap analysis is a structured assessment that compares an organization's current performance, capabilities, or compliance against a desired state. The output is a list of gaps: specific areas where the current state falls short of the target, each with enough detail to prioritize and plan remediation.

The concept is simple, but the value depends entirely on how rigorously you define both sides of the comparison. A vague current state assessment compared against a vague target produces vague gaps. A specific, evidence-based assessment compared against a concrete standard produces actionable findings.

Gap analyses are used across industries and disciplines: regulatory compliance, IT security, process improvement, strategic planning, and business continuity management. The methodology is the same in each case. What changes is the framework you measure against.

Why running a gap analysis is harder than it looks

On paper, a gap analysis is straightforward: compare what you have against what you need, write down the differences. In practice, three problems consistently undermine the exercise.

Everyone overrates their own readiness

When you ask a department head whether they have a business continuity plan, they say yes. When you ask to see it, they pull up a document last updated in 2023. When you ask whether it has been tested, the room goes quiet. Self-assessment without evidence review inflates maturity scores and hides the gaps that matter most.

The fix is simple but uncomfortable: the gap analysis must be evidence-based. If you cannot point to a document, a test result, or a sign-off, the capability does not exist for gap analysis purposes. This is especially true for BCM managers working alone. When you are both the assessor and the program owner, the temptation to be generous with yourself is real.

Webinar

From Checkbox to Proof: Building BCM Exercise Programs That Demonstrate Resilience

A 45-minute session in partnership with the Business Continuity Institute, where our panel of industry experts explore how BCM teams can move beyond checkbox exercises…

See more

The target state is vague

"Improve our BCM program" is not a target state. It is an aspiration. Every person on the team will interpret it differently, and every assessment will produce different results. A useful gap analysis requires a specific, documented standard with individually assessable requirements.

For business continuity, ISO 22301 is the most common benchmark. Its clause-by-clause structure maps directly to gap analysis categories: context, leadership, planning, support, operation, performance evaluation, and improvement. Regulatory frameworks like DORA provide equally specific requirements for regulated industries.

Nobody closes the loop

The most common gap analysis failure is not in the assessment. It is in the follow-through. The analysis produces a report. The report gets presented. Everyone nods. And then the same gaps appear in next year's assessment because nobody tracked remediation. If your organization has conducted gap analyses before and the same findings keep surfacing, the methodology is not the problem. The accountability is.

How to do a gap analysis: step by step

A gap analysis follows five steps. The process is the same whether you are assessing against ISO 22301, DORA, or an internal standard. What changes is the target framework and the evidence you collect.

Step 1: Define the target state

Select the framework, standard, or set of requirements you are measuring against. This could be a formal standard like ISO 22301, a regulatory requirement like DORA or CPS 230, or an internal maturity model. The target must be specific enough that you can assess each requirement individually.

For BCM programs, ISO 22301 provides a clause-by-clause structure that works as a ready-made gap analysis framework. For regulated industries, layer sector-specific requirements on top: DORA for EU financial services, FCA operational resilience for UK firms, APRA CPS 230 for Australian institutions.

Step 2: Assess the current state

Document what you currently have in place for each requirement. This is where most gap analyses go wrong: teams rely on assumptions instead of evidence. Do not assess from memory. Review actual documents, interview process owners, and check whether documented procedures are actually followed in practice.

In a BCM gap analysis, this step typically involves reviewing your business impact analysis (is it current and complete?), your business continuity plans (do they cover all critical functions?), your exercise program (when was the last test and what did it find?), and your governance structure (who owns what and do they know it?).

Step 3: Identify and document gaps

For each requirement, compare current state against target state and record the gap. A gap exists when the current state does not meet the requirement, meets it only partially, or meets it on paper but not in practice. Be specific: "BIA exists but has not been updated since 2024 and covers only 60% of critical functions" is useful. "BIA needs improvement" is not.

Document each gap with enough context that someone who was not in the room can understand what is missing and why it matters. The gap description should make the remediation action obvious.

Step 4: Prioritize gaps

Not all gaps carry equal risk or require equal effort to close. Prioritize using two dimensions: impact (what is the consequence of this gap remaining open?) and effort (what does it take to close it?).

PriorityImpactEffortAction
1 (quick wins)HighLowClose immediately
2 (roadmap)HighHighPlan and resource for next quarter
3 (schedule)MediumLowClose within current cycle
4 (backlog)LowHighDefer unless resources allow

High-impact, low-effort gaps are your quick wins. They build momentum and demonstrate progress to leadership. High-impact, high-effort gaps go on your roadmap with proper resourcing. Low-impact gaps can wait.

Step 5: Build the remediation plan

Each prioritized gap needs an owner, a target close date, and a defined action. The remediation plan is where gap analysis translates into business continuity strategies: specific initiatives that move the organization from current state to target state.

Track remediation progress in regular review cycles (monthly or quarterly). Gaps that remain open for multiple cycles without progress need escalation, not just a new target date. If the same gap appears in consecutive annual assessments, it is a governance failure, not a planning one.

Gap analysis template

The template below works for any gap analysis but is structured around a business continuity assessment against ISO 22301. Adapt the requirement categories to match your target framework. Each row captures one requirement, the current state, the gap, its severity, and the remediation action.

CategoryRequirementCurrent stateGapSeverityRemediationOwnerTarget date
Policy and governanceBC policy approved by senior leadershipPolicy exists, last reviewed 2024Policy not reviewed annually as requiredMediumSchedule policy review with executive sponsorBCM LeadQ1 2027
Business impact analysisBIA completed for all critical functionsBIA covers 60% of functions40% of critical functions not assessedHighExtend BIA to remaining departmentsBCM LeadQ4 2026
Recovery strategiesDocumented strategy per critical functionStrategies exist for IT onlyNo strategies for facilities, supply chain, workforceHighDevelop strategies for non-IT domainsBCM LeadQ1 2027
Plans and proceduresBC plans tested within last 12 monthsLast test was 18 months agoPlans not tested within required frequencyHighSchedule tabletop exercise for all plansBCM LeadQ4 2026
Exercise programAnnual program with multiple exercise formatsOne tabletop per yearNo simulation or functional exercises conductedMediumAdd simulation exercise to annual programBCM LeadQ2 2027
Incident managementCrisis communication plan documentedInformal process, not documentedNo formal crisis communication planHighDraft crisis communication planComms LeadQ4 2026
Monitoring and reviewManagement review of BCM program annuallyNo formal management reviewNo evidence of management oversightMediumEstablish annual management review meetingBCM LeadQ1 2027

If the gap analysis reveals that your business continuity plans are incomplete or missing, a structured business continuity plan template provides the framework to build them consistently across departments.

Gap analysis examples

The following examples show what gap analysis findings look like in practice. Each illustrates the gap, why it matters, and what remediation looks like.

Example 1: ISO 22301 certification readiness

A mid-market financial services firm wants ISO 22301 certification within 12 months. The gap analysis reveals: BIA is current but only covers head office operations (not branches). Recovery strategies exist for IT but not for customer-facing processes. The exercise program runs one tabletop annually but ISO requires evaluating performance across multiple exercise types.

The remediation roadmap: extend BIA to branches (Q1), develop customer process strategies (Q2), add a simulation exercise (Q3), enter certification audit (Q4). Each gap maps to a specific ISO 22301 clause, making the audit trail clean.

Example 2: DORA compliance

A European bank needs to demonstrate DORA compliance. The gap analysis against DORA's five pillars reveals: ICT risk management framework exists but does not reference critical business services. Third-party risk register is incomplete, covering 60% of ICT providers. Digital operational resilience testing program has no threat-led penetration testing component.

The bank maps each gap to the specific DORA article it violates and builds a compliance roadmap with regulatory deadlines driving prioritization. A broader view of which regulations and standards apply ensures the assessment covers all relevant requirements.

Example 3: Post-incident lessons

After a ransomware incident, a healthcare organization runs a gap analysis against its own BC plans. Backup restoration took 14 hours against a stated RTO of 4 hours. Crisis communication reached only 60% of staff because the contact list was outdated. The incident commander role was undefined, leading to ad-hoc decision-making.

Each gap traces directly to a failure observed during the incident. Improving disaster recovery testing frequency is flagged as the highest priority action, followed by crisis communication plan documentation and incident command role definition.

Gap analysis vs other assessment types

Gap analysis is one of several assessment methods. Understanding how it differs from related approaches prevents you from using the wrong tool.

Assessment typePurposeOutputWhen to use
Gap analysisMeasure current vs target statePrioritized gaps with remediation planBefore certification, after regulation change, or annually
Risk assessmentIdentify and evaluate threatsRisk register with likelihood and impact scoresBefore strategic planning or after significant change
Maturity assessmentRate capability on a scaleMaturity score per domain (1-5)Benchmarking or tracking year-on-year improvement
AuditVerify conformance with evidenceConformity/nonconformity findingsFormal assurance for regulators or certification bodies
Business impact analysisQuantify impact of function lossRTO/RPO per function, dependency mapsBefore developing recovery strategies

A gap analysis often follows a business impact analysis. The BIA tells you what matters and sets the recovery time objectives. The gap analysis then asks: can we actually meet those objectives with what we have today? Where there is a shortfall between stated RTOs and actual recovery capability, you have a gap.

Common gap analysis mistakes

Gap analyses are straightforward in concept but frequently go wrong in execution. These patterns reduce a gap analysis from a strategic tool to a compliance checkbox.

1. Assessing against an unclear target

If your target state is "improve our BCM program," every assessment will produce different results depending on who runs it. The target must be a specific, documented standard with individually assessable requirements. Vague targets produce vague gaps that nobody can act on.

2. Self-assessing without evidence

Teams consistently overrate their own readiness when assessing from memory. The gap analysis must review actual artifacts: the BIA document, the plan itself, the exercise report, the management review minutes. If you cannot point to evidence, the capability does not exist for gap analysis purposes.

3. Documenting gaps without severity

A flat list of 40 gaps with no prioritization is not actionable. Every gap needs a severity rating based on business impact. Without prioritization, leadership cannot make funding decisions and remediation efforts scatter across low-impact items while critical gaps remain open.

4. Never closing the loop

A gap analysis that produces a report but no tracked remediation plan is wasted effort. Every gap needs an owner, a target date, and a review cadence. This is where a mature BCM maturity benchmark helps: it provides the scoring framework to track whether your gap closure is actually moving the needle on program capability.

Business impact analysis (BIA): steps and template

ISO 22301: the business continuity standard explained

Business continuity strategies: types and examples

Business continuity plan template (ISO 22301, free)

RTO meaning: recovery time objective explained

Frequently asked questions

Learn more

See first-hand what AI-native resilience looks like

Fortiv
© Fortiv 2026Legal and Privacy