Insights

How to Run a Compliance-Ready Policy Gap Analysis

A policy gap analysis tests policies against the standards they face. Learn to close the gaps that count and keep your compliance evidence ready to show.

by Harvey TeamAug 24, 2026

An auditor asks whether every policy still meets the obligations that apply to the organization today. For most compliance leaders, the honest answer requires qualification. Most in-house legal operations teams review policies on a schedule, prioritize those with the greatest exposure, can't always be certain that every policy across the organization still holds. A confident answer is one most compliance functions want to give, and a hard one to give with full certainty.

The gap between confidence and certainty has a clear cause. The volume of regulatory and internal change has outpaced the periodic, sampled reviews on which many teams still rely. New rules take effect, organizations adopt new frameworks, businesses enter new markets, and internal policies multiply across teams and years. Each change can quietly move a policy out of alignment with an obligation it once met.

The cost often becomes visible at the worst possible moment. A latent gap may surface when an enforcement action, audit, or acquisition due diligence uncovers what the organization missed. By then, the finding is on the record, the response is reactive, and the organization has less control over the cost. A policy gap analysis is only as valuable as its coverage and defensibility, and the way most teams run it falls short on both. This article explains what a policy gap analysis measures, which gap most reviews miss, and how to conduct an analysis that holds up under scrutiny.

The Four Gaps a Policy Gap Analysis Finds

A policy gap analysis compares an organization's current policies with a defined benchmark, such as a regulation, standard, or internal target, to identify missing coverage and policies that are outdated, inconsistent, or unenforceable. The output is a prioritized register of gaps, each tied to the specific obligation the relevant policy fails to meet and the action needed to close it.

Within that definition are four kinds of gaps, and a review is only as effective as the types it examines.

1. External gaps

External gaps arise between a policy and an outside requirement, such as a new regulation or a standard the organization has adopted. Most reviews are designed to catch these gaps because the trigger is usually visible when a rule changes. They are also the easiest to scope because the benchmark is written down.

2. Internal-consistency gaps

Internal-consistency gaps arise between one policy and another or between a policy and the contracts intended to carry it out. This is where contract intelligence and policy review meet. These gaps tend to accumulate as different people write policies in different templates over several years. Left unchecked, two policies can commit the organization to conflicting obligations without anyone noticing.

3. Control gaps

Control gaps arise between a policy and the control that is supposed to enforce it. The intent exists in writing, but no operational mechanism makes it happen, so the policy holds in theory and fails in practice. Identifying these gaps requires checking each policy against the control designed to support it so a stated rule counts as implemented only when a control enforces it.

4. Operational gaps

Operational gaps arise between what a policy commits to on paper and what the organization can show it does in practice. A policy can read correctly and map cleanly to its obligation even when the organization lacks evidence that it is followed.

The deliverable is a prioritized gap register that identifies, for each entry, the obligation the policy fails to meet, the evidence supporting the finding, and the action required to close it. This tracker-style structure makes the analysis usable and, later, defensible.

Three of these gap types can emerge from a careful document review. The fourth, the operational gap, is the one most reviews never see.

The Policy Gaps a Document Review Misses

An operational gap is the distance between what a policy commits to and what the organization can prove it does. These gaps can carry substantial risk because they pass every check that examines only wording. The policy exists, reads correctly, and maps cleanly to the obligation. However, the evidence that the commitment holds in daily operation is missing, and that absence is invisible to a document-to-document comparison.

Harvey's research on legal AI governance makes this distinction concrete. In The Legal AI Governance Imperative in Practice, written governance defines what an organization expects, while operational controls determine whether that expectation is met and can be demonstrated. The same distinction applies to policy work. A written policy states the commitment, but whether the organization follows that commitment in practice is a separate question. A benchmark comparison alone does not answer it.

Consider a data-retention policy. It can match its governing regulation clause for clause and still fail when someone asks for proof that retention is enforced in the environments where the data resides. On paper, the policy may appear fully aligned. In practice, if no one can produce that evidence, the organization has not demonstrated that it meets the obligation. A review that stops at the text records the policy as compliant and moves on.

The consequence for scoping is direct. A gap analysis that compares only documents will systematically undercount risk because it cannot see the operational layer. To identify operational gaps, the scope must include an evidence check. Confirming that a written policy exists is only the first step; the analysis must also determine whether the organization follows it in practice.

How Complete Coverage Reveals More Policy Gaps

Even a review designed to identify operational gaps faces a practical limit. A manual policy gap analysis necessarily relies on sampling because comparing every policy with every obligation by hand does not scale. Teams review selected policies against selected obligations on a schedule. The most consequential gaps may remain in policies that were not sampled after a rule changed.

That limit is beginning to lift as legal teams adopt AI-supported workflows. According to The Accelerating Impact of Legal AI: Harvey as Foundational, 68% of surveyed Harvey customers report using agents to support legal workflows. For in-house teams, common applications include contracting, compliance, and regulatory work. That adoption illustrates a broader legal tech shift toward repeatable, agent-run checks in legal workflows.

Bulk analysis can remove much of the sampling constraint by comparing every policy in scope with a benchmark in a single pass. Harvey Vault can perform that type of analysis across a large policy set, shifting the question from which policies the team had time to review to what the complete comparison reveals.

Once a team can review the full policy estate, it can rerun the analysis whenever a benchmark changes. That turns a periodic project into legal workflow automation the organization can use when new requirements or policies arise. Complete coverage does not replace human judgment; it allows people to apply that judgment to a complete comparison rather than a limited sample.

Six Steps in a Defensible Policy Gap Analysis

A defensible policy gap analysis follows a repeatable sequence, and each step should produce evidence a reviewer can verify. Knowing how to use AI as a lawyer means assigning AI the repetitive comparison work while keeping legal judgment with qualified professionals. A qualified lawyer must review every gap the AI identifies and every revision it drafts before the organization relies on the result.

1. Define the benchmark and its obligations

Start by identifying the benchmark the policies must meet, whether it is a regulation, standard, or internal target, and break it into discrete obligations. A dense benchmark may contain dozens of separate requirements, each of which a policy can meet or miss. AI can synthesize the benchmark into a clear, itemized list of obligations that structures the rest of the analysis.

2. Assemble the policy set in scope

Gather every policy the benchmark touches across teams and regions so the comparison covers the full set. Scope has direct consequences because the analysis cannot identify a gap in a policy that was omitted. Any excluded policy limits the completeness of the review.

3. Compare each policy with each obligation

Test every policy against every obligation to identify language that is missing, insufficient, or inconsistent with another policy. AI can perform this comparison across the full set and surface candidate gaps with citations to both the source obligation and the policy language that does not meet it. Harvey brings curated, proprietary content from its data partners into the comparison, grounding each finding in authoritative regulatory sources a reviewer can evaluate.

4. Check whether each obligation is evidenced in practice

The comparison confirms what a policy says. This step determines whether the organization can show that it follows the policy. That operational test identifies the gaps a document review misses. A written commitment counts as met only when evidence supports it.

5. Prioritize the gaps by risk and exposure

Rank the identified gaps by risk and exposure, then determine the appropriate response, whether that involves drafting clauses in legal documents, revising a policy, or fixing a control. Decisions about applicability, materiality, and remediation are legal judgments that a qualified lawyer must make using the analysis as input.

6. Record each finding with an audit trail

Record each finding, its supporting source, and its assigned remediation as the work proceeds. This record becomes the audit trail and the analysis's primary deliverable. It shows what was checked, which sources were used, and what decisions were made—the information a regulator, board, or acquirer may later request.

When the sequence is saved as a repeatable check, the analysis no longer has to be a once-a-year project. Harvey Agents let a team rerun the same gap check when a benchmark changes while preserving the sources and audit trail. At Dentsu, the legal and compliance team uses Harvey to extract and analyze data from contracts, policies, and historical deal terms and to anticipate regulatory shifts. One of its lawyers built a Harvey agent for data protection impact assessments that reduced the time required for the process by roughly 75%.

How to Make Policy Gap Analysis Continuous

The move from a sampled project to a repeatable check changes how an organization can use policy gap analysis. Benchmarks and policy estates change continually, so an analysis conducted once a year may become outdated as soon as a rule changes or a new policy takes effect. When the check is repeatable and its coverage is complete, the organization can run it whenever a benchmark changes, the organization adopts a framework such as ISO 27001 or SOC 2, or an acquisition introduces a new set of policies.

This approach differs from tracking a specific regulatory change and responding to it. Reactive compliance starts with a known change. A standing gap-analysis capability starts with the benchmark and the policy estate, and teams rerun it whenever either changes, regardless of whether a single new regulation triggered the change.

A standing capability is valuable only when it strengthens oversight. At Deutsche Telekom, whose legal function operates across many jurisdictions in a heavily regulated industry, the general counsel describes Harvey as a trusted foundation that allows senior lawyers to focus on strategy, risk, and decisions. A standing policy gap analysis applies the same principle: the technology handles repeatable comparisons, while the team retains the judgment required to turn a flagged gap into a decision.

A repeatable policy gap analysis can keep pace with change, whereas a once-a-year review can become outdated as soon as it is completed.

What Makes a Policy Gap Analysis Audit-Ready

A document-only review can miss the operational evidence that determines whether a policy is actually followed. An audit-ready policy gap analysis therefore needs three elements: complete coverage of the policy estate, evidence testing for each obligation, and source-grounded findings with a preserved audit trail.

Performing that work manually is slow. General-purpose AI tools may summarize individual policies, but a defensible analysis also requires source-grounded comparison across the full policy estate and a record of how each finding was reached. Harvey's Legal AI is built to support those requirements by comparing large policy sets with authoritative sources and keeping reasoning and citations attached to each finding. Lawyers remain responsible for applicability, materiality, remediation decisions, and final approval.

A compliance leader who meets that standard can answer an auditor's question completely and honestly and show the reasoning and source behind each answer when asked. To see how Harvey supports this approach to policy gap analysis, book a demo.

Frequently Asked Questions

How is a policy gap analysis different from a risk assessment?

A policy gap analysis tests whether policies align with a defined benchmark. A risk assessment evaluates the likelihood and potential impact of an exposure. Many organizations use both, often beginning with the gap analysis to identify deficiencies and then using the risk assessment to decide which deficiencies to address first.

How often should you run a policy gap analysis?

Run a policy gap analysis whenever the benchmark or policy estate changes. A fixed annual cycle is not sufficient on its own because obligations and policies can change between scheduled reviews. New rules, adopted frameworks, and acquired policies can each create a gap as soon as they take effect.

What does a policy gap analysis deliverable look like?

The core deliverable is a prioritized gap register. Each row identifies the obligation a policy fails to meet, cites the source supporting the finding, assigns an owner and a remediation action, and preserves the audit trail for the decision. A register is more useful than a static memo because it tracks each gap through closure and records the reasoning behind each decision.

Can a gap analysis account for policies that are followed inconsistently in practice?

Yes, when the scope includes an operational evidence check. A policy can read correctly and still be applied unevenly across teams or regions, which is an operational gap. Testing whether each obligation is evidenced in practice surfaces those inconsistencies before an auditor does.