Skip to content
97.5% of teams see value from GC AI before month oneSee how

Policy Gap Analysis With AI: Build a Source-Linked Remediation Register


Josh BertiniPublished

A policy gap analysis gives in-house legal a documented comparison of company policies against selected legal obligations, customer commitments, and internal standards. Its most useful deliverable is a source-linked remediation register: a record of which requirements the policies address, where language or evidence needs attention, and who owns the next decision.

That work connects legal judgment with the teams that carry out the policy. At a technology company, for example, counsel may interpret a customer's security commitment while security and HR confirm the supporting procedures and training records. A useful policy gap assessment gives each team a specific question to resolve and gives legal operations a way to track the answer through approval and follow-up.

GC AI is an enterprise legal AI platform built for in-house legal teams, used by more than 2,200 legal teams as of October 2026. With GC AI, you can organize the selected source documents, ask for a requirement-by-requirement comparison, and inspect the cited policy language. You then use that analysis to prepare policy amendments, request evidence, and give business owners a clear remediation handoff. Counsel approves the requirements and findings; the register preserves the decisions.

What a Policy Gap Analysis Can Establish

A policy gap analysis can support a regulatory compliance tracking workflow by identifying missing language, conflicting instructions, and provisions that no longer address a selected requirement. It can also show where the review needs more evidence. Policy text alone cannot establish that a control operates or that the organization complies with every applicable obligation.

Use separate finding types so the next action follows the evidence:

Finding TypeWhat Supports ItNext Decision
Missing or incomplete policy statementThe reviewed policy set does not address part of a selected requirement.Confirm the document set, then decide whether to amend a policy or add a supporting procedure.
Conflicting statementsTwo identified provisions give inconsistent instructions for the same situation.Resolve the conflict with the owners and identify the governing version.
Missing evidenceThe policy states a requirement, but the materials supplied do not show whether the company carried it out.Request the relevant records or an operational assessment. Keep implementation unresolved.
Confirmed operational failureReviewed evidence and an accountable owner's confirmation establish a specific departure from the policy.Address the failure within the assessed population and period, and define a follow-up check.
Applicability unresolvedA material fact, interpretation, or effective date remains unsettled.Assign the legal or factual question before deciding whether a policy gap exists.

Keep a separate review status, such as evidence requested, accepted for remediation, or awaiting retest, alongside the finding type.

Define the Requirements and Policy Set First

Treat the comparison as one defined task within your legal compliance program. Start with a scope note that another reviewer can reproduce: the legal entities, jurisdictions, business activities, review period, policy versions, and exclusions. Distinguish binding legal and contractual requirements from voluntary standards and company targets.

Assign the decisions before the comparison begins. Counsel confirms applicability and interprets the requirements. Policy owners explain how their teams carry them out and supply the relevant records. Legal operations can coordinate requests, deadlines, and approvals in the team's existing tracker. Name a reviewer who can assess the agreed closure evidence for each finding.

For each requirement, record its original source, section, effective date, and applicability rationale. Break compound requirements into distinct elements while preserving qualifications and exceptions. A customer obligation may depend on whether a particular service processes that customer's data. When that fact remains unknown, assign the question and record it as unresolved.

Then prepare a file manifest with each document's ID, title, version, approval status, effective date, owner, and source link. Include supporting procedures and referenced schedules, and record requested material that remains unavailable. The manifest defines what the policy-to-requirement mapping covers. Counsel should approve the requirement list and document scope before the comparison begins.

NIST's CSF 2.0 Profiles guidance uses side-by-side current and target profiles to help organizations identify gaps. For a policy review, that comparison becomes more useful when each proposed gap also preserves the source and the reviewer's reasoning.

A Synthetic Policy Gap Analysis Example

This is an illustrative exercise. The company, policy excerpts, evidence, dates, and decisions below are fictional.

Assume a U.S. software company voluntarily selects two outcomes from the NIST Cybersecurity Framework 2.0 for a limited review. The exercise covers its approved cybersecurity and awareness policies as of September 1, 2026. It does not assess the full framework, determine legal obligations, or test technical controls.

The selected NIST CSF 2.0 outcomes are:

  • GV.PO-02: Review and update cybersecurity policy to reflect changes in requirements, threats, technology, and organizational mission, with communication and enforcement also addressed. See CSF 2.0, printed page 17.
  • PR.AT-01: Provide personnel with awareness and training that supports cybersecurity-conscious performance of general tasks. See CSF 2.0, printed page 20.

NIST leaves organizations to choose how to achieve its outcomes. For this exercise, fictional internal requirement T-01 directs the company to document additional policy reviews after material system changes. G-01 tests that chosen implementation requirement.

The fictional source packet contains these excerpts:

P-01, Cybersecurity Policy v1.0, Section 4: “The security team reviews this policy each year.”

P-02, Awareness Policy v3.0, Section 2: “All new employees must complete security awareness training within 30 days of their start date.”

The 30-day deadline is this fictional company's own target. NIST's PR.AT-01 outcome does not specify that deadline.

Record the Initial Findings

The reviewer checks the complete fictional policy packet and finds no additional change-triggered review procedure. The packet contains no training completion records.

ID and SourcePolicy EvidenceInitial FindingReviewer Decision
G-01: internal requirement T-01, chosen to support GV.PO-02, p. 17P-01 v1.0, Section 4: annual review statement quoted above.Incomplete policy statement: the reviewed packet does not explain when material system changes trigger an additional review.Accept as a document finding. Ask the Security Director to confirm whether a separate procedure exists. Policy implementation remains unassessed.
G-02: PR.AT-01, p. 20, plus P-02's internal deadlineP-02 v3.0, Section 2: training within 30 days. No completion records supplied.Missing evidence: training delivery and completion within the internal deadline remain unresolved.Request the relevant new-hire roster and completion records. Do not infer that employees missed training.

Both rows need follow-up, but they call for different work. G-01 may require a policy or procedure amendment. G-02 first requires evidence.

In a real register, replace these fictional document IDs with links to the exact retained versions. Keep the section and quoted language alongside each link so the finding remains understandable if access changes.

Turn Accepted Findings Into Assigned Work

Prioritize findings using the company's risk criteria. Consider the consequence, affected activity, deadline, available safeguards, and uncertainty. Record why a finding receives its priority, and identify who can accept any residual risk.

Give each accepted finding an owner, action deadline, and closure check:

Finding and Priority RationaleAction and Accountable OwnerAction Target DateClosure Evidence and Reviewer
G-01: Medium priority for this exercise. The planned system migration creates a foreseeable need to review policy before the annual cycle.Security Director confirms no separate procedure exists, proposes review triggers and responsibilities, and routes the amendment for approval.September 15, 2026Approved P-01 v1.1 and the communication record. Legal reviewer checks the added language against T-01. Operational effectiveness remains a separate assessment.
G-02: High priority after follow-up. Fictional evidence E-01, a roster review and HR owner's signed confirmation dated September 4, establishes that three employees reached day 45 without training.HR Director arranges overdue training and investigates why the onboarding process missed these employees.September 8, 2026Completion records for the three employees and documented process correction. The Security reviewer will check the next onboarding cohort on October 8, 2026, and record its population and result. Status: awaiting retest.

G-02 now records a confirmed failure to meet the internal deadline for the three reviewed employees. Preserve its earlier missing-evidence status and the evidence that changed the decision. The follow-up does not establish how every employee's training operated or whether the training achieved the full selected NIST outcome.

An owner completing an action and a reviewer closing a finding are separate events. Keep the register open until the reviewer checks the agreed closure evidence, or records an authorized exception with its rationale and review date.

Copy This Policy Gap Register Template

Use the fields below as a starting record in your team's approved tracker. Keep an entry for every requirement you reviewed, including requirements for which you propose no gap. Where a requirement produces several findings, give each finding its own ID and link it to the requirement.

Requirement ID:
Requirement source URL, section, and effective date:
Applicable entity, jurisdiction, and rationale:
Policy document URL, version, and section:
Relevant policy quotation:
Requirement elements addressed:
Unresolved elements or questions:
Finding ID and type, if applicable:
Supporting evidence or evidence requested:
Reviewer decision and date:
Priority and rationale:
Remediation action:
Accountable owner:
Action deadline:
Required closure evidence:
Closure reviewer and decision date:
Current status:
Next review or retest date:

Preserve the version history when evidence changes a finding. The register should let a later reviewer reconstruct both the current decision and the evidence that led to it.

How to Run Policy Gap Analysis With GC AI

Start with a policy set and requirement list that counsel has approved. Use GC AI to prepare the comparison and proposed follow-up work, then record accepted decisions in your team's tracker. The following sequence connects the source review to that handoff:

  1. Select the source documents.
  2. Map each requirement to policy language.
  3. Verify the cited passages and coverage.
  4. Prepare the remediation handoff.

Select the Source Documents

Files lets teams save and organize documents for use across chats. Assemble the selected policies, procedures, requirements, and file manifest before asking for the comparison. Include only material your team is authorized to use, with sharing appropriate to the review.

Attach the selected folder to the chat by dragging it from Files or choosing Add from Files in the + menu. Check the file badges, then ask for a list of the files and versions GC AI can identify and compare it with your manifest. Resolve unreadable files, missing schedules, and uncertain versions before relying on a coverage conclusion.

Ask for Policy-to-Requirement Mapping

Give GC AI the counsel-approved requirement list and a defined output format. The following prompt is a starting point for a document review; adapt it to the actual sources and decisions.

Compare only the attached, approved policy set with the attached requirement list and scope note.

First identify the documents and versions available to you. Flag unreadable content, missing referenced documents, and uncertain versions.

For each requirement ID:

  1. Identify the requirement source, section, applicable entity, and date from the scope note.
  2. Quote the relevant policy language with its document ID, version, section, and source citation.
  3. Explain which requirement elements the language addresses and which remain unresolved.
  4. Classify any proposed finding as incomplete policy language, conflicting statements, missing evidence, or applicability unresolved.
  5. Identify the evidence or human decision needed next and propose an action for review.

Keep an entry for every supplied requirement, including those with no proposed gap. State when the supplied material is insufficient. Do not invent sources, infer control operation from policy text, or assign a final compliance conclusion. Keep all findings and proposed priorities subject to reviewer approval.

Review the requirement list against the output as well as the findings. An omitted requirement can disappear from an otherwise polished table. A high-level match can also miss a timing condition, exception, or responsible party.

Rachel Harris described a related discipline on CZ and Friends, GC AI's weekly podcast hosted by Cecilia Ziniti, CEO and founder of GC AI and a three-time general counsel. Each episode brings legal, technology, and business leaders into candid conversations about how modern companies work, scale, and lead with trust. As Suzy's general counsel, she and her colleagues went through their security questionnaire one question at a time, asking: “What is the purpose of this one individual question?” Apply that discipline to each mapping: identify the requirement the row addresses and the evidence needed to decide it.

Open the Sources Before Accepting a Finding

Exact Quote lets you click a citation in chat and inspect the highlighted passage in the source document. Use it to check the proposed policy quotation, then read the surrounding definitions, exceptions, and cross-references.

Source accuracy and substantive coverage need separate checks. A quotation can be exact while addressing only one element of a requirement. For an absence finding, review the relevant document set and references; a citation to one section cannot establish that language is missing everywhere.

Ask GC AI to revise a mapping when the cited text does not support it. Preserve the reviewer's correction and reasoning in the register.

Prepare the Remediation Handoff

Once the reviewer accepts a finding, ask GC AI to draft the proposed policy amendment or evidence request using that finding's ID and sources. Have the policy owner check whether the proposed language describes a process the team can carry out.

Enter the accepted action, accountable owner, deadline, reviewer, and closure criteria in your team's approved tracker. Legal operations can use those fields to identify decisions awaiting counsel, evidence requests awaiting a business owner, and completed actions awaiting review. Retain the source versions and decision history alongside each finding.

When a requirement or policy changes, identify the affected mappings and reassess them against the new source. Record the revised decision and its effective date so the team can explain which version it relied on.

Bring a policy, its selected requirements, and a known finding to a GC AI demo. Use that example to see how document comparison, citation review, and proposed policy language fit your team's existing approval process.

Frequently Asked Questions

Can Legal AI Help With Regulatory Compliance Tracking?
Yes. Legal AI can help organize selected requirements, compare them with policy language, and draft follow-up work for legal review. For regulatory compliance tracking, maintain a dated record of the rules your team has assessed. When counsel accepts a change that affects your policies, use a policy gap analysis to update the relevant mappings and remediation actions. Assign monitoring coverage and legal applicability checks as separate responsibilities.
Can You Compare Policies Across Jurisdictions?
Yes, if counsel defines a separate applicable requirement set for each jurisdiction and entity. Keep the jurisdiction, effective date, and applicability decision on each mapping. A shared policy may address several requirements, but one favorable comparison does not resolve every local obligation.
How Should You Handle Conflicting Policy Versions?
Ask the policy owner to identify the approved version before making a final finding. Preserve the conflicting versions and their dates in the review record. If different teams use different versions, open a separate question about distribution and implementation instead of silently choosing the newest file.
When Should You Repeat a Policy Gap Analysis?
Repeat the affected comparison when a requirement, policy, business activity, or relevant system changes, and follow your organization's scheduled review process. Record the new versions and reassess earlier findings that depend on them. Keep prior decisions available so reviewers can see why a finding changed.
SOC 2 certification badgeSOC 2
SOC 3 certification badgeSOC 3
GDPR badgeGDPR

Take the first step now

Let's explore about how we can make your life as an in-house lawyer a whole lot easier.

What to expect:

  • A walkthrough of the platform, tailored to your team's use cases.
  • Q&A session about security, integrations, and onboarding.
  • A 14-day free trial if the platform looks like a fit for your team.

Book a Demo

Dial code +1 (United States)

By submitting, you agree to our Terms and Privacy Policy.

Keep up with the latest content