Invent an answer
The text sounds right, the assessor accepts it, and eighteen months later an auditor asks for the procedure it described. What was a commercial shortcut becomes a finding, and a misrepresentation.
A question with no supporting document has no good answer. Inventing one is dangerous; leaving it blank loses the deal. There is a third option, and it is the reason most of our clients choose us.
A documentary gap analysis identifies, for a given set of requirements, which ones your existing documents cannot evidence. It distinguishes a missing document from an out-of-date one, and ranks the gaps by the risk they create.
The problem
The text sounds right, the assessor accepts it, and eighteen months later an auditor asks for the procedure it described. What was a commercial shortcut becomes a finding, and a misrepresentation.
Honest, and expensive: a blank field is read as an absence of control. On a scored question it costs points; on a mandatory requirement it can disqualify the bid.
The gap is declared, an owner named, and the document drafted with you from what you actually do, then the answer is produced from that approved document, like any other.
This is not a template library. A generic policy that does not describe your practice is worse than no policy: it is a document an auditor will test against reality.
Not just "no answer found": which requirement is uncovered, why the existing documents do not evidence it, and what a compliant document would need to contain.
The gap is assigned to the person who holds the knowledge, CISO, DPO, quality manager, operations, with a due date tied to the submission deadline.
A first draft is produced from your existing documents, your terminology and your actual organisation, then corrected by your expert. We do not describe a control you do not operate.
Once your expert has approved it, the document enters the repository and the answer is generated from it, with its page, its version and a named approver, like any other answer.
The next client asking the same question gets an answer from an existing document. The cost is paid once.
A gap found by a client questionnaire in March is a non-conformity avoided in September. It is the cheapest audit preparation there is.
Because the draft comes from your material and is corrected by your expert, it describes what you do, which is the only kind of document that survives an audit.
Access control, cryptography, secure development, supplier security, acceptable use.
Backup and restore, patch management, vulnerability management, change management, logging and monitoring.
Incident response plan, notification procedure, business continuity and disaster recovery plans, test records.
Records of processing, retention schedule, data subject request procedure, transfer register.
Supplier assessment procedure, subcontractor register, roles and responsibilities, awareness programme.
Frequently asked
Yours. The first draft is built from your existing material, your terminology and your organisation, then corrected by your expert. A generic policy that does not match your practice is a liability, not an asset.
Your expert, the CISO, DPO or quality manager. Nothing enters the repository without a named human approval, and the approval is timestamped.
Yes: once approved it becomes a citable source like any other, with its version history. That is how a questionnaire stops being pure cost.
No. That would be manufacturing evidence. We describe what you do; where the control itself is missing, the gap stays declared until you implement it.
A first usable draft in hours rather than weeks, because the material already exists in fragments across your organisation. Your expert’s review is the real constraint.
We show you the gap, the owner, and the first draft of the document that closes it, on your material, in your environment.