Help Centre

Compliance Scanner & Gap Analysis

The Compliance Scanner maps your existing policies against recognised regulatory and industry frameworks, giving you an instant view of where you stand and what you're missing. Instead of manually cross-referencing spreadsheets, the scanner automates the entire gap analysis process in seconds.

1. What the scanner does

The scanner analyses every published policy in your organisation and matches its content against the controls and requirements defined by your chosen framework. It produces three key outputs:

The scanner uses your policy content and framework tags to build these mappings. Policies that are tagged with the relevant framework will be matched first, followed by content-based analysis of untagged policies.

2. How to run a scan

Running a compliance scan takes just a few clicks:

  1. Navigate to Compliance > Scanner in the left sidebar
  2. Select the framework you want to scan against from the dropdown (e.g. ISO 27001, SOC 2 Type II, GDPR)
  3. Click Run Scan
  4. The scan typically completes within a few seconds, depending on the number of published policies in your organisation

You can run scans against multiple frameworks — each scan is saved independently, so you can compare your posture across different regulatory requirements at the same time.

Tip: Tag your policies with the relevant compliance frameworks when creating or editing them. This significantly improves scan accuracy, because the scanner can match tagged policies directly to framework controls rather than relying solely on content analysis.

3. Reading your results

After a scan completes, you'll see a results dashboard with several sections:

You can export the full scan report as a PDF for sharing with auditors, leadership, or external assessors. The export includes the scan date, framework version, and a complete control-by-control breakdown.

4. Acting on gaps

Once you've identified gaps, there are two ways to close them:

Prioritise gaps by risk level. High-risk gaps — typically those related to data protection, access control, and incident response — should be addressed first. Medium and low-risk gaps can be scheduled into your regular policy review cycle.

5. Supported frameworks

PolicySuite supports 110+ compliance frameworks across eight jurisdictions:

New frameworks are added regularly. If you need a framework that isn't listed, contact us at support@policy-suite.com and we'll prioritise it.

Still need help?

Email our support team at support@policy-suite.com — we typically respond within 24 hours.

Related Articles