BlogProduct
Product

How Norman Gap Analysis Works

Norman AI's AI-driven gap analysis maps your current policies and controls against compliance frameworks automatically. Here's what happens under the hood — and why speed matters when you're preparing for a certification audit.

N
Norman
AI Compliance Analyst at Norman AI
2026-01-27
6 min read

A compliance gap analysis sounds deceptively simple: compare where you are to where you need to be, and document the difference. In practice, traditional gap analyses take weeks of consultant time, require extensive interviews with technical staff, and produce reports that are out of date by the time they land in your inbox.

Norman AI approaches gap analysis differently. Here is how it works.

Step 1: Ingest Your Existing Documentation

The first thing Norman AI does is read what you already have. Most organisations — even early-stage ones — have some existing security documentation: an acceptable use policy, a password policy, a data retention policy. These may live in Notion, Confluence, Google Drive, or a shared folder somewhere.

Norma ingests these documents and extracts structured information about the controls and practices they describe. This is not keyword matching. Norman — the AI compliance analyst at the core of Norma — reads the policies the way an experienced auditor would, identifying what claims are being made about your security posture and what evidence would be required to support them.

Step 2: Map Against Framework Controls

Once Norman AI has a structured representation of your existing documentation, it maps those controls against the requirements of your target frameworks — ISO 27001:2022, SOC 2 Trust Services Criteria, GDPR obligations, NIS2 requirements, or others.

Each control in a framework has specific requirements. Some require documented policies. Some require technical implementations. Some require periodic reviews or audits. Norman classifies each requirement and checks whether your existing documentation addresses it, partially addresses it, or is silent on it.

The output is a structured gap register: a list of requirements, your current status against each one, and an assessment of the evidence you have.

Step 3: Prioritise by Risk and Effort

Not all gaps are equal. A missing policy on clean desk procedures is not the same as an undocumented incident response plan. Norman AI prioritises gaps based on two dimensions: risk (how significant is this gap from a compliance and security perspective?) and effort (how much work is required to close it?).

This produces a remediation roadmap that is actually actionable. High-risk, low-effort items — write a policy that codifies something you are already doing — come first. High-risk, high-effort items — implement technical controls that do not currently exist — get sequenced with appropriate lead time.

Step 4: Generate Draft Remediation Artefacts

For gaps that can be closed with documentation, Norman AI does not just tell you what you are missing — it generates first drafts. If your gap register shows that you are missing a change management policy, Norman AI produces a draft policy tailored to your organisation's context: your industry, your size, your existing technology stack.

These drafts are starting points, not finished products. They need to be reviewed, adapted to your specific circumstances, and approved by appropriate stakeholders. But starting from a well-structured draft is significantly faster than starting from a blank page.

Step 5: Track and Update

Compliance is not a one-time project. Controls change, new frameworks emerge, and your product and infrastructure evolve. Norman AI maintains a live view of your compliance posture — as you close gaps and upload new evidence, the gap register updates.

When it is time for your next audit or certification renewal, you are not starting from scratch. You have a current, documented baseline.

Why Speed Matters

The most common reason organisations miss compliance deadlines is not a lack of willingness — it is a lack of visibility. They do not know what they are missing until they engage an external consultant, and by the time the report arrives, there is not enough time to close the gaps before the audit.

Norman AI gives you that visibility immediately. You can run a gap analysis against ISO 27001:2022 in a day, not a month. That means you have more time to do the actual remediation work — the policies, the technical controls, the training — rather than spending that time on assessment.


*Ready to see where your compliance gaps are? Start your free Norman AI gap analysis at trynorma.com. No consultant required.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog