Productivity
Find your policy gaps
What a framework requires against what you have written.
Fill it in
Whatever exists.
Which framework.
Rather than listing them.
Your prompt
Compare against SOC 2. Map requirement to policy, then read the policy. Most gap analyses check whether a document with the right title exists, which is why organisations pass the analysis and fail the audit: the access-control policy says access is controlled and specifies nothing. A policy needs a scope, an owner, a review date and something an auditor can test. Mark the ones present but unusable separately from the ones missing. Draft the missing policies to the same standard, in the organisation's own language. A borrowed template that describes a company this is not fails the first interview. Say which gaps are documentation and which are the practice actually not happening. Only the second kind is a real finding.
Continue and pick your folderOpens with everything above already filled in.
Why this works
Most gap analyses check whether a document with the right title exists, which is why organisations pass the analysis and fail the audit. This reads the policies, separates present-but-unusable from missing, and distinguishes a documentation gap from the practice not happening.