Key Takeaways
- A mitigation gap is the distance between a risk's current score and its target score once measures are fully in place. Closing that gap requires actively tracking it, because documenting that measures exist is not the same as confirming they are working.
- Risk assessment and gap analysis answer different questions. Risk assessment identifies what could go wrong and how badly. Gap analysis measures whether what you have put in place to address it is actually working. Conflating the two produces a register that looks complete but cannot tell you whether your exposure is genuinely reducing.
- A risk register that captures only the inherent risk score and the planned mitigation leaves the gap invisible. Tracking progress requires the current assessment, the target assessment, and the residual score visible together, with the trajectory over time preserved.
- The COSO Enterprise Risk Management framework frames ERM as an ongoing, iterative process embedded in everyday business activities. Gap analysis is what makes that continuity operational, turning the space between current and target into a live management signal reviewed regularly rather than a finding surfaced at year end.
- Every risk sitting above its target score after measures have been in place for more than a quarter deserves a direct question: is the measure being implemented and verified, or is it just documented?
The knowing-versus-doing gap
Risk teams typically have a register, documented mitigations, and assigned owners. The question nobody usually asks out loud is whether those mitigations are actually working.
Gap analysis in risk management mitigations addresses exactly this: the distance between a risk that has been treated on paper and one that has genuinely moved to an acceptable level. That distance is often larger than anyone realises, and it tends to stay invisible until an audit, an incident, or a board presentation forces someone to look.
The regulatory environment has been tightening steadily, and the cost of not knowing whether your mitigations are landing rises with it. When compliance requirements multiply, a register full of planned measures that no one has verified is a liability dressed up as a management process.
Risk assessment and gap analysis are not the same thing
These two terms get used interchangeably, and the conflation causes real problems in practice.
A risk assessment answers: what could go wrong, how likely is it, and how bad would it be? You assign probability and impact scores, you plot the risk on a matrix, and you decide whether to accept, treat, or transfer it. That is the beginning of the process.
Gap analysis answers a different question: are the things we have put in place to address that risk actually working? A risk assessment identifies and quantifies. A gap analysis measures the distance between where you are and where you need to be, and whether that distance is shrinking.
In practice, many risk registers conflate the two: they capture the inherent risk score, document a planned mitigation, and stop there. Months later, the gap between the risk today and the acceptable risk level has become invisible, and nobody can say with confidence whether the measures have made any real difference.
The COSO Enterprise Risk Management framework is direct on this point: ERM is intended to be ongoing and iterative, embedded in everyday business processes. Gap analysis is what makes that continuity visible, converting a periodic documentation exercise into an ongoing discipline with a feedback loop.
What a mitigation gap actually looks like
Consider a construction company that has identified a contract risk: a key subcontractor stretched across three simultaneous projects who may not deliver on time. The inherent assessment puts this at high-impact and high-probability, and the team documents a mitigation covering monthly check-ins with the subcontractor, a clause requiring advance notice of delays, and an identified backup supplier.
Three months later, the measures are marked as in progress, but nobody has checked whether the monthly check-ins are actually happening, the backup supplier was identified but never formally engaged, and the risk score in the register is still exactly where it was at the first assessment.
The mitigation exists on paper, and the gap stays open because nobody is tracking the residual risk score against the target.
A well-structured gap analysis makes this visible by tracking three distinct numbers: the inherent risk score, the target risk score, and the residual risk score.
The inherent risk score is the starting point, the score assigned before any mitigation is in place, reflecting the full, unmanaged exposure.
The target risk score is the level the team expects to reach once all planned measures are fully implemented. This is the risk appetite in operational terms, the point at which the organisation is willing to live with the remaining exposure.
The residual risk score is where the risk actually sits right now, after the measures that have been implemented so far. This is the honest number.
The gap between the residual score and the target score is the work still to be done. If that gap is not shrinking over time, the mitigations are either not being implemented or they are not having the effect that was assumed when they were planned.
Many risk registers show the inherent risk score and the planned measures, but stop short of tracking the current residual score against the target or showing the trajectory over time.
Without that, you cannot tell whether you are on track or whether the risk is sitting exactly where it was six months ago with a set of unimplemented measures attached to it.
How Risk Companion makes the gap visible
In Risk Companion, the gap between current and target is built directly into the risk register. Every risk carries both a current assessment and a target assessment. The current assessment reflects where the risk sits now, after whatever measures have been put in place. The target assessment reflects the score the team is aiming for once all measures are fully implemented.
Risk Companion preserves assessment history across every update, creating a new record each time so the trajectory of a risk over time stays visible and auditable. You can see whether the residual risk is moving toward the target or has been static for three review cycles, giving the gap real meaning over time.
The combination of current assessment, target assessment, and measure status means risk owners and management can answer a question that many registers leave unanswerable: are we actually reducing this risk, or are we just managing the paperwork around it?
The mitigations dashboard adds another layer. It surfaces risks without measures, measures that are overdue, and the overall distribution of measure status across the register.
When a risk is sitting above its target score and the attached measures are all showing low progress, that combination is a direct flag that the gap is not closing.
For teams preparing for audit, the project health check surfaces incomplete data and follow-up items before an auditor finds them. A risk with a large gap between current and target and no progress on its measures will appear here as an item requiring attention, giving the team the chance to act before the review begins.
Why residual risk calculations deserve more honesty
There is a version of this conversation that gets dishonest very quickly. Teams score their inherent risk, document a mitigation, and then immediately reduce the residual risk score on the assumption that the mitigation will work. The register looks clean and the risk appears to have been treated, and nobody checks again until the next audit.
That is optimistic accounting, and it produces a register that looks managed while the actual exposure sits unexamined.
A genuine residual risk score should reflect the actual current state of the risk, considering only the measures that have been implemented and verified to be working. Planned measures that are theoretically in progress do not count until they are confirmed.
The gap between that honest residual score and the target is what tells you whether you are managing the risk or just documenting your intention to do so.
This matters more at scale. A portfolio of fifty risks where every residual score has been adjusted based on planned-but-unverified measures gives a false picture of the organisation's exposure. The board sees amber across the register while the actual exposure may be significantly higher.
The principle is well established in risk management practice: the assessment of a response should include consideration of whether it has been implemented and whether it is actually reducing the risk. Documenting a planned measure and treating the residual risk as already reduced skips that verification entirely.
Making gap analysis a continuous discipline
The gap between current and target is only useful as a management tool if it is reviewed on a regular cycle, not only when an audit is approaching.
Assign a target score to every risk at the point of first assessment. That target should reflect the risk appetite for this category of risk, grounded in what is genuinely achievable with the measures being planned.
If the organisation's framework defines an acceptable level for a financial risk at a low-medium score, that becomes the target.
Review the residual risk score at each review cycle alongside the status of attached measures. If measures are progressing and the residual score is moving toward the target, the gap analysis is confirming that the process is working. If measures are stalled or the residual score has not moved, the gap has widened in practical terms and needs direct management attention.
Use the gap itself to prioritise attention. A risk with a large gap between current and target, where measures are overdue or have not started, is a higher management priority than a risk with a small gap and active measures in progress. This is a more honest prioritisation than sorting by inherent risk score alone.
In Risk Companion, the combination of current and target assessments with measure status and progress gives this view without requiring a separate tracking exercise. The gap is visible at the risk level, the mitigations dashboard surfaces it at the portfolio level, and the assessment history shows whether progress is real or illusory.
This approach works well for operational and financial risks where measures are specific, owned, and time-bound. For emerging or strategic risks, where the path from current state to target is less defined and the measures are harder to verify, gap tracking informs the conversation around those risks and the judgement that drives it.
From measurement to management
A gap analysis that lives in a spreadsheet tends to get updated once before an audit and ignored the rest of the year. The gap between current and target becomes a calculation someone runs in a column, with no mechanism to turn it into a signal someone acts on.
When the gap is visible in the register, attached to a named owner and a set of measures with due dates and progress percentages, it changes from a metric to a management conversation. That shift is what accountability looks like in practice.
The owner knows the gap exists, their manager can see whether it is closing, and the board gets a dashboard view showing overall gap distribution across the portfolio, current at the time it is presented.
If your mitigations are in place but the gap between current and target assessment is not visibly closing, start a free 14-day trial of Risk Companion. A demo project built from your own organisation's profile is ready from day one, so you can see the progression from current to target assessment and whether your measures are actually closing the gap.
Ready to improve your risk management?
See how Risk Companion can help you implement these best practices with powerful, easy-to-use tools. Sign up and we'll prepare a demo project tailored to your company.