Gap Analysis

The process of comparing current AI governance practices against desired standards or regulations to identify areas needing improvement.

Definition

A systematic review that maps existing policies, processes, and tools to target frameworks (e.g., EU AI Act, ISO/IEC 42001). It identifies “gaps” (missing controls, outdated procedures), prioritizes remediation based on risk, and tracks closure of findings. Gap analyses are fundamental to preparing for compliance audits and driving governance maturity.

Real-World Example

Ahead of its first EU AI Act audit, a manufacturer conducts a gap analysis: they discover no privacy-impact-assessment template and missing human-oversight checkpoints. They then develop those artifacts and update workflows, closing critical gaps before regulatory review.