What a Compliance Assessment Should Actually Deliver

Published On
September 29, 2026
Share this post
https://www.emrynetworks.com/post/what-a-compliance-assessment-should-deliver

The report comes as a PDF. It is forty pages long, includes a red-amber-green dashboard, gives a score out of one hundred, and lists findings worded so closely to the framework that no one in the room knows what action to take on Monday. You paid for a compliance assessment. All you received was a document.

A compliance assessment should answer a business question: where the exposures lie, how serious they are, and what to address first. Many instead attempt to answer a more limited question, whether a list of controls was in place on the day the inspection took place. The questions are different, and regulated businesses end up wasting money in the gap between them while staying exposed.

Most assessments are a checklist in disguise

Once you know the signs, you can easily spot a poor evaluation. It measures you against a framework you might not even be subject to. It treats a control as in place simply because a policy document exists, without verifying that the control is actually operating in production. It presents your findings according to the assessor's own severity labels rather than the cost each item would have on you. And it ends with just the finding, giving no sequence, no owner, and no indication of what depends on what.

The outcome is thorough and makes no difference. When you file it, you feel briefly responsible, and the same gaps appear again at the next review. The assessment has become the deliverable rather than the decisions it was meant to lead to. Judge a good assessment by what you can do once you have it, not by how heavy the PDF is.

Deliverable one: scope you can actually defend

The first issue a proper assessment settles is which rules apply to you and which ones do not. Frameworks reach a business three ways, by law, by contract, or by choice, and most regulated businesses carry two or more at once. A dental practice that handles health information is governed by HIPAA, whether or not a customer ever asks. Because it accepts card payments, PCI DSS applies through the merchant agreement. A payer might also require HITRUST. We explain how each of these attaches in which compliance framework applies to your business.

Scope is also about what does not apply. When an assessment quietly broadens to include standards you are not required to follow, it is selling you work rather than clarity. The deliverable here is a written scope that lists every applicable framework, explains why it applies, and defines the boundary of the systems and data involved. If you cannot hand that page to a new auditor and have them agree with it, the scope was never really completed.

Deliverable two: gaps where they actually live

A discrepancy on paper is not the same as one in production, and an assessment that cannot tell them apart is close to useless. The policy might state that every laptop is encrypted while three machines in the back office are not. The access list may look clean while a vendor who finished a project two years ago still has an active login. Standard IT checks whether systems are functioning. Defensibility looks at whether a control is operating where it should be and whether you can prove it on any given date, a point we set out in standard IT vs. defensible IT.

So a useful evaluation examines the live environment, not just the binder. It compares what your documentation claims against what your systems are actually doing, then reports the difference in plain language. That difference, the space between the written policy and the running reality, is the actual risk. Everything else is formatting.

Deliverable three: findings ranked by consequence, not by label

Good intentions get wasted in the severity labels. High, medium, and low tell you roughly how the assessor felt about a control in the abstract. They do not tell you that an unpatched internet-facing server is the single thing most likely to take you offline next quarter, or that a missing risk analysis is the first document an auditor will ask to see.

That point is not a guess. Year after year, a missing or inadequate risk analysis is the most frequently cited failure in HHS Office for Civil Rights HIPAA settlements, which makes it one of the highest-consequence gaps a healthcare business can carry. Prioritization means ordering findings by the actual risk each one poses: downtime, a failed audit, a denied insurance claim, or a lost deal. A finding with no consequence attached is trivia. A finding tied to a dollar figure or a named regulatory risk is a decision waiting to be made.

Deliverable four: a path you can hand to someone

Knowing the gaps is not the same as closing them. The next deliverable is a remediation plan, and every line item on it needs three things: a sequence, an owner, and a rough sense of effort. Sequence matters because fixes depend on each other. You enforce multi-factor authentication before you fuss over session timeouts, and you inventory your assets before you can honestly claim any of them are patched.

Owner matters because a finding assigned to IT is a finding assigned to no one. Effort matters because a plan that treats a fifteen-minute configuration change and a six-month tooling rollout as equal line items is not a plan, it is a wish list. The test is simple. Could a competent person pick up the document and start on Monday without a follow-up meeting to decode what it meant.

Deliverable five: evidence you can hand an auditor

The output that quietly saves the most money is evidence. Compliance is not something you achieve once and then stop. You have to demonstrate it again and again. A SOC 2 Type 2 report describes how your controls operated across a period of months, not on a single good day, because the point is continuity. HIPAA goes further and requires you to keep your written documentation for six years. An assessment that leaves you no better able to produce that evidence next cycle has solved nothing lasting.

A decision-grade assessment produces artifacts you can reuse: the scope document, the risk analysis, the control mapping, and the remediation record. When your evidence is a byproduct of running the business, the next audit is mostly paperwork. When it is not, you pay for the same scramble every cycle, which is the audit tax most regulated businesses never put on a spreadsheet.

What a strong assessment will not do

It helps to know the anti-patterns, since that is precisely what you are paying to avoid. A strong assessment will not grade you against a standard you have no obligation to meet, then present the gap as urgent. It will not mark a control satisfied on the strength of a policy document alone. It will not bury the two findings that matter under forty that do not, and it will not leave you to work out which is which. And it will not hand you a number in place of a decision.

It also will not feign certainty it does not have. Where a control is partly in place, or where the evidence is thin, a useful assessment says so plainly rather than rounding up to green. The honesty is the value. A report that tells you everything is fine is comfortable and useless, because the one thing you needed it to find is the thing it smoothed over.

The questions you should be able to answer afterward

A good way to judge an assessment before you commission it is to ask what you will be able to answer once it is done. If the deliverables above are real, a handful of questions that were fuzzy on Monday should have crisp answers by Friday. Which frameworks actually apply to us, and which do not. Where does our written policy disagree with what our systems are doing. Of everything that is open, what should we fix first, and why that one. Who owns each fix, and what does it depend on. What could we hand an auditor today without building it from scratch.

If the report cannot answer those, it does not matter how polished it is. A scored PDF leaves every one of them open and calls the score an answer. A decision-grade assessment closes them, which is the whole reason to commission one instead of running another checklist against yourself and filing the result.

Here is the same split, deliverable by deliverable.

A scored report vs. a decision-grade assessment

DimensionA scored reportA decision-grade assessment
ScopeA framework picked for you.Every framework that applies, and why, in writing.
GapsControls marked present if a policy exists.The space between written policy and live systems.
FindingsSorted by a severity label.Ranked by the cost or regulatory risk each one carries.
Next stepsA list to read.A sequenced plan with owners and effort.
AfterwardA PDF you file.Evidence you can reuse at the next audit.

What this looks like at Emry Networks

Our first engagement focuses on scope and reality, not issuing a certificate. Regulatory Discovery examines your live environment and compares it against the standards that genuinely apply to you: HIPAA, SOC 2, ISO 27001, NIST, PCI DSS, CMMC, and HITRUST. It then produces a Risk Status Report in plain English that names each gap between what your documentation claims and what your systems are doing, and ranks those gaps by consequence. The full service sits on our IT compliance page.

From there, Security Hardening closes the gaps in sequence, while Continuous Management keeps the posture from drifting with monitoring, staff training, backup checks, and periodic reassessment. A healthcare group came to us after a surprise audit, having not done a formal risk assessment in two years. We mapped the gaps, fixed them in order, and got them audit-ready in 90 days. The assessment was not the product. The clarity was.

A compliance assessment should leave you able to make a decision you could not make before you had it. If all it leaves you with is a score, you bought a document. Ask what you will actually be able to do on Monday, and buy the one that answers that.

Find out what applies to you, and what to fix first

Schedule a compliance assessment and we will scope what applies to you, show you the gaps between your policies and your production environment, and hand you a prioritized path, not a scored PDF.

Schedule a compliance assessment

Frequently asked questions

What should a compliance assessment include?

At minimum: a written scope naming every framework that applies to you and why, a comparison of your documented controls against what is actually running in production, findings ranked by the consequence each one carries rather than a generic severity label, a sequenced remediation plan with named owners, and reusable evidence such as a risk analysis and a control mapping. If it stops at a score, it is a report, not an assessment.

What is the difference between a compliance assessment and an audit?

An audit is a formal examination against a standard, usually by an independent party, that ends in an attestation or a certificate. An assessment is the work you do beforehand to find and close gaps so the audit goes well. A good assessment is rehearsal with a map, and the audit is the performance. Treating the assessment as a mini-audit, scored and filed, misses the entire point of doing it early.

How often should we run one?

At least once a year, and again after anything that changes your risk: a new system, a move to the cloud, a contract with new security clauses, a merger, or a material change in the data you handle. Compliance is a state you keep demonstrating, not a milestone you pass once. Between full assessments, lighter drift checks catch the gaps that open quietly in between.

What counts as a risk analysis, and why does it matter so much?

A risk analysis is a documented review of where your sensitive data lives, what threatens it, and how likely and damaging each threat is. It matters because it is the foundation every framework builds on, and because a missing or inadequate one is the single most frequently cited failure in HIPAA enforcement settlements. If your assessment does not produce or update a real risk analysis, it has skipped the part regulators care about most.

Will an assessment tell us which framework we need?

That is one of the first things it should settle. Frameworks apply by law, by contract, or by choice, and most regulated businesses are subject to more than one. A useful assessment names each one that attaches to you and why, and just as importantly rules out the ones that do not, so you are not buying work you do not actually owe.

What do we do with the findings?

Work them in the sequence the plan gives you, starting with the gaps that carry the highest consequence and the ones other fixes depend on. Assign each to a named owner, not a department. The findings are only worth what you do with them, which is exactly why a plan you can act on matters more than the sheer length of the list.

Sources

  • HHS Office for Civil Rights, HIPAA enforcement: a missing or inadequate risk analysis is among the most frequently cited deficiencies in OCR resolution agreements and civil money penalties (HHS OCR newsroom and resolution agreements).
  • HIPAA Security Rule, 45 CFR 164.316: covered entities and business associates must maintain required security documentation in writing and retain it for six years.
  • AICPA, SOC 2: a Type 2 report addresses the operating effectiveness of controls across a defined observation period, not a single point in time.
  • IBM, Cost of a Data Breach Report 2026: global average breach cost $4.99M; United States average $11.5M; healthcare the costliest sector at $6.64M; average breach lifecycle 247 days. Used here as context for the cost of leaving gaps open.

Exact figures above are attributed to their named primary sources. Any other number in this article is presented as reasoning or as an explicit estimate and should not be read as a measured value.

Share this post
https://www.emrynetworks.com/post/what-a-compliance-assessment-should-deliver

Ready to strengthen your compliance?

Get hands-on assessment and guidance from our compliance experts.