How to Run a Compliance Readiness Assessment (Step-by-Step)
A practical method for mapping requirements to controls, rating gaps by severity, and prioritizing remediation—before the auditor arrives.
Most compliance failures are not caused by ignorance of the rules. They happen because the gap between policy and practice is never clearly measured. A team assumes a control is in place; an auditor finds a document that was last reviewed three years ago; a regulator asks for evidence that does not exist. The gap was always there—it just was not visible until the worst possible moment.
A compliance readiness assessment makes that gap visible on your schedule, not the regulator's. Done well, it gives you a structured picture of where your controls hold up, where they are thin, and which weaknesses carry real risk if left unaddressed. This guide walks through the method: from choosing a standard to presenting a prioritized remediation list your team can act on.
Step 1: Pick Your Standard and Scope It Tightly
Before mapping a single control, decide exactly which standard you are assessing against and which part of your organization is in scope. Common anchors include ISO 27001 (information security), SOC 2 (trust service criteria), GDPR or India's DPDP Act (data protection), POSH (workplace policy), and sector-specific rules such as RBI guidelines for fintechs.
Scope creep is the most common reason assessments stall. If you are a 40-person SaaS company running your first ISO 27001 readiness check, the scope is probably your product infrastructure and the teams that touch it—not your office facilities or your HR system. A tight scope produces findings you can act on. A sprawling scope produces a shelf document.
Step 2: Map Requirements to Controls
Every compliance standard is, at its core, a list of requirements. Your job is to map each requirement to one or more controls your organization either has in place or should have. A control is any policy, procedure, technical mechanism, or organizational practice that addresses the requirement.
Work requirement by requirement. For each one, ask: What is the stated obligation? Then: What do we currently do—or have in writing—that addresses it? The answer to the second question is your existing control. If the answer is nothing, that absence is itself a finding.
At this stage, resist the urge to judge. Just map. A requirement may have multiple controls; a single control may address multiple requirements. Both are fine.
Step 3: Gather Evidence for Each Control
Mapping tells you what should exist. Evidence tells you what actually exists. For each control you have identified, gather the artifact that proves the control is operational—not just written down.
Evidence types vary by control: a policy document is evidence that a rule exists, but it is not evidence the rule is followed. Log data, training completion records, access-review timestamps, and incident response test reports are evidence that controls are operational. A good assessment distinguishes between the two.
When evidence is strong and current, the finding is solid. When evidence is partial, outdated, or inferential, the finding is indicative. When the team believes a control exists but cannot produce documentation, the finding is needs data. These evidence grades matter: they determine how much confidence you can place in any remediation decision that follows.
Step 4: Rate Gap Severity
Once you have mapped requirements and checked evidence, you will have a clear picture of gaps—requirements where the control is absent, incomplete, or unverifiable. The next step is rating each gap by severity so you do not treat a missing data-retention schedule with the same urgency as an unencrypted customer database.
A simple three-level severity scale works well in practice:
- High: The gap creates direct regulatory exposure or operational risk if discovered during an audit or incident. Address within 30 days.
- Medium: The gap is a real deficiency but is unlikely to be the proximate cause of a breach or enforcement action on its own. Address within 90 days.
- Low: Documentation or process polish—the control exists but is not formalized or consistently applied. Address within a quarter or as part of a larger program cycle.
Worked Example: A Quick-Look Compliance Map
The table below shows a simplified readiness snapshot for a company assessing against a data-protection standard. It illustrates how requirements, controls, evidence status, and gap severity sit together in one view.
| Requirement | Control in Place | Evidence Status | Gap Severity |
|---|---|---|---|
| Lawful basis documented for each data processing activity | Records of processing activity (ROPA) register | Indicative — ROPA exists but last updated 14 months ago | High |
| Data subject access requests handled within statutory window | DSAR intake form + assigned owner | Needs data — form exists, no log of requests received or resolved | High |
| Third-party processors bound by data processing agreements | Standard DPA clause in vendor contracts | Solid — reviewed contracts confirm clause present for top 8 vendors | Low (tail vendors unverified) |
| Data breach notification procedure documented and tested | Incident response runbook | Indicative — runbook exists; no tabletop exercise on record | Medium |
| Privacy notice accurate and accessible | Privacy policy page on website | Needs data — policy references a data controller address that has changed | Medium |
Note: This assessment output is decision-support, not legal advice. Regulatory interpretation for your specific context should involve qualified legal counsel.
Step 5: Prioritize Remediation by Risk
With severity ratings in hand, build a remediation backlog ordered by risk, not effort. The natural temptation is to close the easy items first—a quick policy update feels productive. Resist it. High-severity gaps with a credible path to closure should move to the front of the queue regardless of how much work they involve.
For each high-severity item, assign an owner, a target date, and a definition of done that includes the evidence artifact that will confirm closure. Without an explicit evidence target, remediation tasks have a habit of being declared complete before the control is actually operational.
A remediation item is not closed when the policy is written. It is closed when the evidence that the policy is followed can be produced on demand.
Step 6: Track Progress and Repeat the Cycle
A compliance readiness assessment is not a one-time event. Standards change, your product changes, your team changes, and the threat environment changes. Build a cadence—at minimum, an annual full assessment and a quarterly spot-check on your highest-risk controls.
Keep a running register that links each requirement to its current control, evidence status, and any open remediation items. When an item is remediated, update the evidence status. When a standard issues new guidance, add the new requirement and begin the mapping cycle again. The register becomes your institutional memory: the difference between knowing you are compliant and being able to demonstrate it.
What Treeng's Compliance Scanner Does in Under Four Minutes
Walking through this method manually—requirement by requirement, control by control—takes days of focused work and requires someone who knows both the standard and your internal systems well enough to ask the right questions.
Treeng's Compliance Scanner compresses the diagnostic layer into a structured intake that takes under four minutes to complete. It surfaces gaps across your selected standard, assigns a severity rating to each finding, and presents every result with an explicit evidence grade: solid, indicative, or needs data. You get the same structured view as the table above—without the consulting invoice attached to it.
The output is a prioritized gap list ready to hand to your team or your legal counsel. It does not replace the judgment call that qualified advisers bring to complex regulatory questions, but it gives you the clearest possible starting point before you make that call.
Ready to run it on your own data?
Run your Compliance Scanner →