Gixo Lex · deterministic analysis
Compliance Readiness Scorer
Score evidence statements against a versioned baseline of common programme controls.
Compliance gap analysis
A compliance gap analysis compares the controls you can actually evidence against a baseline someone expects to see, then names the difference. That is what this scorer does, deterministically: paste your control and evidence statements and it reports which of ten common programme controls it can detect and which it cannot, and scores the share detected out of 100. The not-detected list is the gap.
- Scope and ownership — what the programme covers, and who owns each control
- Asset inventory — the information assets in scope
- Access control — least privilege, joiner-mover-leaver, MFA
- Risk assessment — a documented assessment and a maintained risk register
- Incident response — how an incident or breach is detected, escalated and closed
- Supplier assurance — vendor risk review before and during the relationship
- Business continuity — continuity and disaster-recovery arrangements
- Training — security-awareness training and its records
- Audit evidence — internal audit, and the evidence an auditor will ask to see
- Corrective action — remediation tracked through to closure
Detection is literal: it matches each control's vocabulary against your text, so a control you operate but did not describe reads as missing. That is the useful part — an assessor also reads only what you wrote. It reports coverage of a maintained baseline, never whether you pass, and it is not legal or audit advice.
Reference: the compliance and assurance frameworks these controls trace back to
Input
Details
How Compliance Readiness Scorer works
See what the tool accepts, what it checks, how to read the result, and where human review still matters.| Topic | Details | What to know |
|---|---|---|
| Input | Text input capped at 150,000 characters | The public endpoint rejects input outside its documented bound. |
| Processing | Deterministic rules; no AI model call | The same input and rules produce the same analysis. |
| Output | Complete analysis or attributed portable output | The free result is returned on the page rather than hidden behind an account. |
| Storage | Nothing stored | The submitted material is processed for the request only. |
What is a compliance gap analysis?
A structured comparison between the controls a framework, customer or regulator expects and the ones you can evidence today. It produces two lists — covered and missing — and the missing list becomes the remediation plan. It is the step before an audit, not the audit.
How is a gap analysis different from an audit?
A gap analysis is self-directed: you run it when you like, on your own evidence, and act on it immediately. An audit is performed by an independent party against a defined scope and period and produces a report or opinion you do not control. Clearing your own gap analysis is not an audit result.
Do I need an account to use Compliance Readiness Scorer?
No. The public tool runs without an account.
Does this tool call an AI model?
No. It applies deterministic parsing and validation rules.
Is my input stored?
No. The public tool does not save the submitted input.
What does the paid product add?
Lex turns the gaps into a checklist, evidence matrix, working paper, or governed policy draft through the compliance execution mode you choose.