← All use cases
Legal · Regulation gap check

See where your policies fall short of a new regulation before the auditor does

A new set of rules arrives, DORA for example. Each requirement is lined up against what your policies already say, so the gaps are on one page instead of in an audit finding.

Why it matters

When a regulation like DORA lands, someone has to read a few hundred pages of requirements, then read every internal policy, then work out where the two do not meet. In a company of eighty people that someone is usually the compliance lead, on top of their normal week, and the result is a spreadsheet that is out of date the moment a policy changes.

Plugs into

The regulation textYour policy folderYour shared driveYour compliance tracker

These are examples. Every use case is built around the tools you already run, whatever they are, and you keep using them exactly as before.

Then it runs on its own

  1. 1

    Breaks the regulation down into individual requirements, each with its article

  2. 2

    Reads every policy, procedure and register in your folder

  3. 3

    Lines each requirement up against the document that should cover it

  4. 4

    Marks each one covered, partly covered or missing, with the evidence

Delivered where you already work

When a new regulation or an update to one lands, and again when a policy changes, in whichever channel your team already uses. We set the timing around how you work, not the other way round.

EmailWhatsAppSlackTeams

What you get back

  • Every requirement, with the policy that covers it or a note that none does
  • The gaps ranked by how much work closing them will take
  • A draft list of policy changes for your compliance lead to review

What it actually looks like

An example of the output, using sample data.

Gap check · DORA, ICT risk management

Gap check · DORA, ICT risk management

42 requirements read against 17 internal documents
Covered
  • ICT risk framework reviewed yearly: Information Security Policy, section 3. (Art. 6)
  • Incident classification: Incident Response Procedure, appendix A. (Art. 18)
  • 26 more, each with the document and section.
Partly covered
  • Third-party register exists but has no exit plan per critical provider. (Art. 28)
  • Testing programme is described, but no evidence of the last test run. (Art. 24)
Missing
  • No procedure for reporting major incidents to the regulator within the set deadlines. (Art. 19)
  • No record of who approved the ICT risk framework at board level. (Art. 5)
Several days
saved per regulation, typically
Once it's running

Your compliance lead starts from the gaps, not from page one

We build it with your team

Every workshop is built around the use cases you pick. This one is usually covered in the Accelerator, on your own tools and your own data.

  • We run it on a regulation your company actually has to meet
  • Your compliance lead decides what counts as covered
  • The output is a working document for your team and your auditor, not legal advice

Want it extended, maintained and connected to more of your systems afterwards? Let's discuss →

Want this running in your team?

30 minutes. Tell us what your team spends its week on and we'll tell you which of these would save the most time.