Compliance Gap Analysis
Structured assessment of an organization's compliance posture against one or more regulatory frameworks, producing a gap register with severity ratings, remediation priorities, and estimated effort. Used as input to compliance program design, external audit preparation, board reporting, and regulatory examination preparation.
When to use this
- An organization is entering a new jurisdiction and needs to understand the compliance build required
- A compliance programme is being refreshed after a regulatory change
- An M&A transaction requires compliance due diligence on the target
- A regulator has issued a finding or information request and the organization needs to understand its exposure
- Internal audit is scoping a compliance review and needs a framework
Inputs
| Input |
Why it matters |
Default |
| Organization description (sector, size, geographic footprint) |
Determines which frameworks apply and at what level |
Required |
| Frameworks to assess |
Specify: AML, sanctions, data protection, anti-bribery, ESG, sector-specific, or "all applicable" |
Required or infer from sector + jurisdiction |
| Current-state documentation (policies, procedures, controls, audit reports) |
Enables gap assessment vs a baseline; without it, assessment is hypothetical |
Provide if available |
| Regulatory correspondences or prior findings |
Indicates known gaps already identified by a regulator |
Provide if available |
| Risk appetite / materiality threshold |
Determines what counts as a "blocker" vs a "polish" item |
Default: any regulatory breach = blocker; best-practice gaps = improvement |
Framework coverage
AML / KYC (FATF 40 Recommendations)
Core requirements:
- Customer Due Diligence (CDD): identification, verification, beneficial ownership identification (≥ 25% UBO threshold, per [[research-beneficial-ownership-lookup]])
- Enhanced Due Diligence (EDD): for high-risk customers (PEPs, high-risk jurisdictions, complex structures)
- Ongoing monitoring: transaction monitoring, periodic KYC refresh
- Suspicious Transaction Reporting (STR): to financial intelligence unit (UAEFIU, SAMA/SAFIU, BDL-SIC)
- Record keeping: 5 years minimum (most MENA jurisdictions) from end of relationship
- FATF Travel Rule: for virtual asset transfers ≥ threshold (USD/EUR/AED 1,000 equivalent), originator and beneficiary information must travel with the transfer
MENA-specific AML gaps commonly found:
- Failure to identify/verify beneficial owners beyond the direct account holder
- Inadequate PEP screening (often limited to international lists; missing local PEPs)
- No documented risk appetite for customer types and jurisdictions
- Transaction monitoring rules not calibrated to the customer's expected behavior
- DNFBP (real estate, legal, accounting) obligations often not implemented — UAE Cabinet Decision No. 10 of 2019 extended AML obligations to DNFBPs
Sanctions
Core requirements:
- Screen customers, counterparties, and UBOs against all applicable lists (per [[research-sanctions-screening]])
- Freeze assets of designated parties; file Suspicious Transaction Report
- Maintain a documented screening process, screening frequency, and match-disposition workflow
- Re-screen at meaningful events (transaction trigger, periodic refresh, news alert)
Gap patterns:
- Screening only the direct party, not UBOs
- Using a sanctions screening tool not configured for Arabic-script name matching
- No documented process for handling near-matches (screening produces false positives; the process for clearing them must be documented)
- Not re-screening existing customers when lists are updated (daily updates to OFAC SDN are common)
Data Protection
Multiple overlapping regimes may apply simultaneously:
| Framework |
Trigger |
Key requirements |
| GDPR |
EU personal data processed |
Lawful basis per processing activity; privacy notice; records of processing; DPIAs for high-risk; 72-hour breach notification; DSR handling |
| UAE PDPL (Federal Decree-Law No. 45 of 2021) |
UAE personal data |
Consent or legitimate interest; privacy policy; data controller obligations; 72-hour breach notification |
| KSA PDPL (Royal Decree M/19 of 2021) |
KSA personal data |
Consent required for most processing; cross-border transfer restrictions; NDMO registration |
| Bahrain PDPL |
Bahrain personal data |
Broadly similar to GDPR |
| Egypt PDPL (Law No. 151 of 2020) |
Egypt personal data |
ITIDA registration; consent; 72-hour breach notification |
For a full GDPR-specific review, see [[review-gdpr-readiness]].
Cross-border transfer gap (MENA): Many MENA companies use US-hosted cloud services; cross-border transfer mechanisms under KSA PDPL and UAE PDPL are still developing. Standard Contractual Clauses (SCCs) used for GDPR compliance may not satisfy KSA PDPL Article 29 requirements.
Anti-Bribery
| Framework |
Jurisdictional reach |
Key requirements |
| FCPA (US) |
US persons, US-listed companies, anything in US commerce |
Prohibits bribery of foreign government officials; accounting provisions require accurate books |
| UK Bribery Act 2010 |
UK-incorporated entities, persons carrying on business in UK |
Broadest reach: strict liability for commercial organisations that fail to prevent bribery; extends to private-to-private bribery |
| KSA Anti-Bribery Law (Royal Decree M/36 of 2017) |
KSA entities and persons |
Prohibits both offering and receiving bribes; applies to public sector officials and private sector |
| UAE Federal Law No. 31 of 2021 (Penal Code) |
UAE entities and persons |
Anti-bribery provisions covering public officials; gift policies required for regulated entities |
Common gaps in MENA anti-bribery programs:
- Facilitation payments: illegal under UK Bribery Act (no exception); FCPA has a narrow exception (being narrowed by enforcement); illegal under MENA laws
- Third-party agent diligence: many MENA transactions use intermediaries; inadequate due diligence on agents is the most common FCPA/UKBA enforcement trigger
- No written anti-bribery policy; no training; no speak-up mechanism
ESG / Disclosure
| Framework |
Scope |
Key requirements |
| CSRD (EU Corporate Sustainability Reporting Directive) |
EU companies + non-EU companies with EU operations above threshold |
Mandatory sustainability reporting against ESRS standards; third-party assurance |
| SEC Climate Disclosure Rule (US) |
SEC registrants |
Mandatory disclosure of climate risks, GHG emissions (Scopes 1 and 2) |
| Saudi Green Initiative / ESG |
KSA-listed and large private companies |
Increasing expectation of ESG disclosure aligned with Saudi Vision 2030 |
| Abu Dhabi Net Zero 2050 / Dubai 2040 |
UAE entities |
Voluntary targets; increasingly expected for regulated entities |
Sector-specific frameworks
| Sector |
Additional frameworks |
| Banking |
BCBS Basel III/IV; CRD VI (EU); CBUAE CAR; SAMA Capital Adequacy |
| Insurance |
Solvency II (EU); CBUAE Insurance Authority regulations; SAMA insurance circulars |
| Fintech |
DFSA Innovation Testing Licence; FSRA RegLab; SAMA/CMA sandbox; EU MiCA for crypto assets |
| Healthcare |
HIPAA (US); NMC/DOH/DHA clinical governance standards (UAE); HAAD standards |
| Telecoms |
TRA UAE; CITC KSA; SMEX Lebanon |
Review methodology
Step 1 — Framework scoping
Confirm which frameworks apply based on:
- Sectors in which the organization operates
- Jurisdictions in which it is licensed or operates
- Nature of its customer base (retail, professional, government)
- Whether it handles EU personal data (triggers GDPR)
- Whether it has US or UK operations (triggers FCPA / UK Bribery Act)
Step 2 — Current-state assessment
For each requirement within each framework, assess:
- Is there a documented policy or procedure?
- Are controls implemented in practice (not just on paper)?
- Is there evidence of training and awareness?
- Are there audit results confirming effectiveness?
Step 3 — Gap identification
For each gap, record:
- The specific requirement not met (with framework citation)
- The nature of the gap: complete absence vs partial implementation vs documentation gap vs effectiveness gap
- Evidence reviewed (or absence of evidence)
Step 4 — Severity rating
| Severity |
Definition |
Typical remediation timeline |
| Blocker (Critical) |
Active regulatory breach; regulatory enforcement risk; immediate professional-liability exposure |
Fix within 30 days |
| Material (High) |
Significant gap that would be cited in a regulatory examination; reputational risk if exploited |
60–90 day remediation plan |
| Moderate |
Best-practice gap; unlikely to trigger enforcement but would be noted in audit |
90–180 day improvement plan |
| Minor |
Documentation gap or process improvement; no current regulatory risk |
Next annual cycle |
Materiality principle: distinguish "blockers" (a compliance program that is entirely absent for a mandatory framework) from "polish" (a program that exists but has minor documentation gaps). A regulator assessing a CBUAE examination will weight these very differently.
Output format
{
"organizationProfile": "string",
"frameworksAssessed": ["list"],
"assessmentDate": "ISO date",
"gaps": [
{
"framework": "AML | Sanctions | GDPR | UAE-PDPL | KSA-PDPL | Anti-Bribery | ESG | Sector-specific",
"requirement": "specific requirement description with regulatory citation",
"currentState": "description of what currently exists",
"requiredState": "description of what is required",
"gap": "description of the delta",
"severity": "Blocker | Material | Moderate | Minor",
"remediationAction": "specific action to close the gap",
"owner": "function responsible (Legal | Compliance | IT | HR | Finance)",
"targetDate": "ISO date",
"estimatedEffort": "small (days) | medium (weeks) | large (months)"
}
],
"summary": {
"totalGaps": number,
"blockers": number,
"material": number,
"moderate": number,
"minor": number
},
"prioritizedRoadmap": "Ordered list of top 10 remediation actions by severity + effort"
}
Limits and escalation
- This skill produces a gap register as a starting point, not a completed audit. A formal compliance audit requires on-site testing, document review, and interviews.
- For GDPR, [[review-gdpr-readiness]] provides a more detailed 10-area review.
- For sanctions, [[research-sanctions-screening]] is required for transaction-level screening.
- For AML, [[research-beneficial-ownership-lookup]] is required to complete UBO identification.
- Regulatory enforcement risk assessments require jurisdiction-qualified legal counsel.
Related skills
- [[research-regulator-guidance-lookup]]
- [[research-regulation-lookup]]
- [[research-sanctions-screening]]
- [[research-beneficial-ownership-lookup]]
- [[review-gdpr-readiness]]
1---2name: review-compliance-gap-analysis3description: Use when a compliance officer, legal team, or external adviser needs to map an organization's current compliance posture against applicable regulatory frameworks — identifying gaps, quantifying severity, and recommending remediation. Covers AML/KYC (FATF 40 Recommendations + Travel Rule), sanctions (OFAC, UN, EU, MENA national lists), data protection (GDPR, KSA PDPL, UAE PDPL, Bahrain, Egypt), anti-bribery (FCPA, UK Bribery Act, MENA laws), ESG/disclosure, and sector-specific frameworks (banking, fintech, insurance, healthcare). Outputs a structured gap register with severity tiers.4license: MIT5---67# Compliance Gap Analysis89Structured assessment of an organization's compliance posture against one or more regulatory frameworks, producing a gap register with severity ratings, remediation priorities, and estimated effort. Used as input to compliance program design, external audit preparation, board reporting, and regulatory examination preparation.1011## When to use this1213- An organization is entering a new jurisdiction and needs to understand the compliance build required14- A compliance programme is being refreshed after a regulatory change15- An M&A transaction requires compliance due diligence on the target16- A regulator has issued a finding or information request and the organization needs to understand its exposure17- Internal audit is scoping a compliance review and needs a framework1819## Inputs2021| Input | Why it matters | Default |22|-------|---------------|---------|23| Organization description (sector, size, geographic footprint) | Determines which frameworks apply and at what level | Required |24| Frameworks to assess | Specify: AML, sanctions, data protection, anti-bribery, ESG, sector-specific, or "all applicable" | Required or infer from sector + jurisdiction |25| Current-state documentation (policies, procedures, controls, audit reports) | Enables gap assessment vs a baseline; without it, assessment is hypothetical | Provide if available |26| Regulatory correspondences or prior findings | Indicates known gaps already identified by a regulator | Provide if available |27| Risk appetite / materiality threshold | Determines what counts as a "blocker" vs a "polish" item | Default: any regulatory breach = blocker; best-practice gaps = improvement |2829## Framework coverage3031### AML / KYC (FATF 40 Recommendations)3233**Core requirements**:34- Customer Due Diligence (CDD): identification, verification, beneficial ownership identification (≥ 25% UBO threshold, per [[research-beneficial-ownership-lookup]])35- Enhanced Due Diligence (EDD): for high-risk customers (PEPs, high-risk jurisdictions, complex structures)36- Ongoing monitoring: transaction monitoring, periodic KYC refresh37- Suspicious Transaction Reporting (STR): to financial intelligence unit (UAEFIU, SAMA/SAFIU, BDL-SIC)38- Record keeping: 5 years minimum (most MENA jurisdictions) from end of relationship39- FATF Travel Rule: for virtual asset transfers ≥ threshold (USD/EUR/AED 1,000 equivalent), originator and beneficiary information must travel with the transfer4041**MENA-specific AML gaps commonly found**:42- Failure to identify/verify beneficial owners beyond the direct account holder43- Inadequate PEP screening (often limited to international lists; missing local PEPs)44- No documented risk appetite for customer types and jurisdictions45- Transaction monitoring rules not calibrated to the customer's expected behavior46- DNFBP (real estate, legal, accounting) obligations often not implemented — UAE Cabinet Decision No. 10 of 2019 extended AML obligations to DNFBPs4748### Sanctions4950**Core requirements**:51- Screen customers, counterparties, and UBOs against all applicable lists (per [[research-sanctions-screening]])52- Freeze assets of designated parties; file Suspicious Transaction Report53- Maintain a documented screening process, screening frequency, and match-disposition workflow54- Re-screen at meaningful events (transaction trigger, periodic refresh, news alert)5556**Gap patterns**:57- Screening only the direct party, not UBOs58- Using a sanctions screening tool not configured for Arabic-script name matching59- No documented process for handling near-matches (screening produces false positives; the process for clearing them must be documented)60- Not re-screening existing customers when lists are updated (daily updates to OFAC SDN are common)6162### Data Protection6364Multiple overlapping regimes may apply simultaneously:6566| Framework | Trigger | Key requirements |67|-----------|---------|-----------------|68| GDPR | EU personal data processed | Lawful basis per processing activity; privacy notice; records of processing; DPIAs for high-risk; 72-hour breach notification; DSR handling |69| UAE PDPL (Federal Decree-Law No. 45 of 2021) | UAE personal data | Consent or legitimate interest; privacy policy; data controller obligations; 72-hour breach notification |70| KSA PDPL (Royal Decree M/19 of 2021) | KSA personal data | Consent required for most processing; cross-border transfer restrictions; NDMO registration |71| Bahrain PDPL | Bahrain personal data | Broadly similar to GDPR |72| Egypt PDPL (Law No. 151 of 2020) | Egypt personal data | ITIDA registration; consent; 72-hour breach notification |7374For a full GDPR-specific review, see [[review-gdpr-readiness]].7576**Cross-border transfer gap (MENA)**: Many MENA companies use US-hosted cloud services; cross-border transfer mechanisms under KSA PDPL and UAE PDPL are still developing. Standard Contractual Clauses (SCCs) used for GDPR compliance may not satisfy KSA PDPL Article 29 requirements.7778### Anti-Bribery7980| Framework | Jurisdictional reach | Key requirements |81|-----------|---------------------|-----------------|82| FCPA (US) | US persons, US-listed companies, anything in US commerce | Prohibits bribery of foreign government officials; accounting provisions require accurate books |83| UK Bribery Act 2010 | UK-incorporated entities, persons carrying on business in UK | Broadest reach: strict liability for commercial organisations that fail to prevent bribery; extends to private-to-private bribery |84| KSA Anti-Bribery Law (Royal Decree M/36 of 2017) | KSA entities and persons | Prohibits both offering and receiving bribes; applies to public sector officials and private sector |85| UAE Federal Law No. 31 of 2021 (Penal Code) | UAE entities and persons | Anti-bribery provisions covering public officials; gift policies required for regulated entities |8687**Common gaps in MENA anti-bribery programs**:88- Facilitation payments: illegal under UK Bribery Act (no exception); FCPA has a narrow exception (being narrowed by enforcement); illegal under MENA laws89- Third-party agent diligence: many MENA transactions use intermediaries; inadequate due diligence on agents is the most common FCPA/UKBA enforcement trigger90- No written anti-bribery policy; no training; no speak-up mechanism9192### ESG / Disclosure9394| Framework | Scope | Key requirements |95|-----------|-------|-----------------|96| CSRD (EU Corporate Sustainability Reporting Directive) | EU companies + non-EU companies with EU operations above threshold | Mandatory sustainability reporting against ESRS standards; third-party assurance |97| SEC Climate Disclosure Rule (US) | SEC registrants | Mandatory disclosure of climate risks, GHG emissions (Scopes 1 and 2) |98| Saudi Green Initiative / ESG | KSA-listed and large private companies | Increasing expectation of ESG disclosure aligned with Saudi Vision 2030 |99| Abu Dhabi Net Zero 2050 / Dubai 2040 | UAE entities | Voluntary targets; increasingly expected for regulated entities |100101### Sector-specific frameworks102103| Sector | Additional frameworks |104|--------|----------------------|105| Banking | BCBS Basel III/IV; CRD VI (EU); CBUAE CAR; SAMA Capital Adequacy |106| Insurance | Solvency II (EU); CBUAE Insurance Authority regulations; SAMA insurance circulars |107| Fintech | DFSA Innovation Testing Licence; FSRA RegLab; SAMA/CMA sandbox; EU MiCA for crypto assets |108| Healthcare | HIPAA (US); NMC/DOH/DHA clinical governance standards (UAE); HAAD standards |109| Telecoms | TRA UAE; CITC KSA; SMEX Lebanon |110111## Review methodology112113### Step 1 — Framework scoping114115Confirm which frameworks apply based on:116- Sectors in which the organization operates117- Jurisdictions in which it is licensed or operates118- Nature of its customer base (retail, professional, government)119- Whether it handles EU personal data (triggers GDPR)120- Whether it has US or UK operations (triggers FCPA / UK Bribery Act)121122### Step 2 — Current-state assessment123124For each requirement within each framework, assess:125- Is there a documented policy or procedure?126- Are controls implemented in practice (not just on paper)?127- Is there evidence of training and awareness?128- Are there audit results confirming effectiveness?129130### Step 3 — Gap identification131132For each gap, record:133- The specific requirement not met (with framework citation)134- The nature of the gap: complete absence vs partial implementation vs documentation gap vs effectiveness gap135- Evidence reviewed (or absence of evidence)136137### Step 4 — Severity rating138139| Severity | Definition | Typical remediation timeline |140|----------|-----------|------------------------------|141| **Blocker (Critical)** | Active regulatory breach; regulatory enforcement risk; immediate professional-liability exposure | Fix within 30 days |142| **Material (High)** | Significant gap that would be cited in a regulatory examination; reputational risk if exploited | 60–90 day remediation plan |143| **Moderate** | Best-practice gap; unlikely to trigger enforcement but would be noted in audit | 90–180 day improvement plan |144| **Minor** | Documentation gap or process improvement; no current regulatory risk | Next annual cycle |145146**Materiality principle**: distinguish "blockers" (a compliance program that is entirely absent for a mandatory framework) from "polish" (a program that exists but has minor documentation gaps). A regulator assessing a CBUAE examination will weight these very differently.147148## Output format149150```json151{152 "organizationProfile": "string",153 "frameworksAssessed": ["list"],154 "assessmentDate": "ISO date",155 "gaps": [156 {157 "framework": "AML | Sanctions | GDPR | UAE-PDPL | KSA-PDPL | Anti-Bribery | ESG | Sector-specific",158 "requirement": "specific requirement description with regulatory citation",159 "currentState": "description of what currently exists",160 "requiredState": "description of what is required",161 "gap": "description of the delta",162 "severity": "Blocker | Material | Moderate | Minor",163 "remediationAction": "specific action to close the gap",164 "owner": "function responsible (Legal | Compliance | IT | HR | Finance)",165 "targetDate": "ISO date",166 "estimatedEffort": "small (days) | medium (weeks) | large (months)"167 }168 ],169 "summary": {170 "totalGaps": number,171 "blockers": number,172 "material": number,173 "moderate": number,174 "minor": number175 },176 "prioritizedRoadmap": "Ordered list of top 10 remediation actions by severity + effort"177}178```179180## Limits and escalation181182- This skill produces a gap register as a starting point, not a completed audit. A formal compliance audit requires on-site testing, document review, and interviews.183- For GDPR, [[review-gdpr-readiness]] provides a more detailed 10-area review.184- For sanctions, [[research-sanctions-screening]] is required for transaction-level screening.185- For AML, [[research-beneficial-ownership-lookup]] is required to complete UBO identification.186- Regulatory enforcement risk assessments require jurisdiction-qualified legal counsel.187188## Related skills189190- [[research-regulator-guidance-lookup]]191- [[research-regulation-lookup]]192- [[research-sanctions-screening]]193- [[research-beneficial-ownership-lookup]]194- [[review-gdpr-readiness]]