Skip to content

Gap & Risk Analysis

How to use the real-time gap assessment, risk scoring dashboard, and AI-powered remediation recommendations to monitor assessment progress.

Updated View as Markdown

Kliper provides three integrated analysis tools that give assessors a real-time view of assessment health: Gap Assessment (what’s missing), Risk Scoring (what’s most dangerous), and AI Recommendations (what to do about it). All three are accessible from the assessment workbench tabs.

Screenshot of Analysis Tabs in Workbench

Gap Assessment

The Gap Assessment dashboard identifies which PCI DSS requirements have findings gaps — requirements that are not in place, not tested, or not yet evaluated.

Accessing Gap Assessment

Open Your Assessment

Navigate to the assessment from the Engagement Hub or the Assessment Workbench.

Select the Gap Analysis Tab

In the assessment view, click the Gap Analysis tab (bar chart icon). The dashboard loads with real-time data calculated from your current assessment answers.

Dashboard Overview

Screenshot of Gap Assessment

The Gap Assessment is a master-detail navigator:

  • Readiness strip (top) — a compliance ring plus a Compliant / Pending / Gap meter summarizing the whole assessment
  • Left rail — every requirement (R1–R12) with a per-requirement progress meter and open-gap count, plus a search box and All / With gaps / Complete segments to jump to what needs attention
  • Detail pane — the selected requirement’s subsections, each shown as a gap-closure card

Gap Severity Levels

Each requirement is assigned a gap severity based on its finding status:

Severity Condition Action Required
Critical (red) Not In Place, or no finding recorded with no justification Immediate attention — requirement is non-compliant or completely unevaluated
High (orange) Has justification but no finding status selected Assessor has documented observations but not made a determination
Medium (yellow) Marked as Not Tested Control exists but was not evaluated during this assessment
None / Compliant (green) In Place or Not Applicable No gap — requirement is satisfied

Filtering and Navigation

Use the search box and the All / With gaps / Complete segments in the left rail to filter which requirements appear. Within the detail pane, a second All / Gap / Pending / Compliant filter narrows which subsections show. Selecting a requirement loads its subsections in the detail pane.

Gap-closure cards

In the detail pane, each subsection appears as a gap-closure card with read-only tiles for the Finding, Justification, and Remediation, plus method badges (Compensating Control / Customized Approach) and a missing-justification warning where applicable. Click a card to jump to that requirement in the editor and address it.

Screenshot of Gap-closure card

Refreshing Data

Click the Refresh button to recalculate the gap assessment from the latest assessment answers. The dashboard always computes in real-time — no cached data is used.


Risk Scoring

The Risk Scoring dashboard assigns a quantitative risk score (0–100) to every requirement in the assessment, considering multiple factors beyond just the finding status.

Accessing Risk Scoring

Open Your Assessment

Navigate to the assessment from the Engagement Hub or the Assessment Workbench.

Select the Risk Dashboard

Click Risk Dashboard (shield icon) in the analysis menu. The dashboard loads with per-requirement risk calculations.

Overall Risk Score

Screenshot of Overall Risk Score

The dashboard header displays the Overall Risk Score — a weighted average of all requirement risk scores, presented as a 0–100 score with a risk level badge.

Risk Level Score Range Color
Critical 80–100 Red
High 60–79 Orange
Medium 40–59 Yellow
Low 20–39 Blue
None 0–19 Green

How Risk Scores Are Calculated

Each requirement’s risk score is computed from four weighted factors:

Factor Weight What It Measures
Finding Risk 45% The assessment finding status (Not In Place = 100, Not Tested = 50, In Place = 0)
Documentation Risk 25% Whether the assessor has written a justification (missing justification on a failing requirement = 100)
Completeness Risk 15% Whether testing procedure data has been filled in
Staleness Risk 15% How recently the requirement was last updated (>90 days = 60, >60 days = 40, >30 days = 20)

Adjustments:

  • Requirements with a Compensating Control receive a 10-point reduction
  • Requirements marked Not Applicable receive a 0 across all factors

Summary Cards

Four metric cards appear below the overall score:

Card What It Shows
Critical Risk Count of requirements with risk score 80+
High Risk Count of requirements with risk score 60–79
No Risk Count of requirements with risk score below 20
Total Requirements Total count of assessed requirements

Finding Distribution

A visual breakdown of all requirements by their finding status:

Finding Color
In Place Green
Not In Place Red
Not Tested Yellow
Not Applicable Gray
No Finding Orange

Requirement Risk Explorer

Screenshot of Risk Detail Breakdown

Requirements are grouped under their top-level requirement (R1–R12), collapsed by default with a mini risk-distribution meter — use Expand / Collapse all to open everything. Within each, sub-requirements are grouped by subsection (1.1, 1.2, …). Prefer a single list? Toggle Flat View at the top to switch the grouped explorer to one flat table of every sub-requirement. Expand any control for a detailed breakdown:

  • Risk Factor Bars — four horizontal progress bars showing each factor’s individual contribution:

    • Finding Risk (0–100)
    • Documentation Risk (0–100)
    • Completeness Risk (0–100)
    • Staleness Risk (0–100)
  • Identified Issues — a bulleted list of specific problems:

    • “Finding: Not In Place”
    • “No assessment finding recorded”
    • “Not yet tested”
    • “Missing justification/evidence”
    • “Testing procedures incomplete”
    • “Data is stale (60+ days)”
  • Go to Section button — navigate to the requirement in the workbench to address the issues

Filtering

Filter the requirements list by risk level using the filter buttons: All, Critical, High, Medium, Low, No Risk.


With Cortex enabled, the Gap view’s readiness strip also adds two actions: Review all · Cortex (batch-review every unreviewed or stale control) and Draft closure plan (open a remediation plan for the gaps). A Cortex-flagged filter and flag counter appear on both views, and the Risk view shows a Cortex Review distribution card. See Cortex Review and Triage.

AI Remediation Recommendations

The Recommendations panel provides AI-generated suggestions for improving your assessment, identifying weak areas, and strengthening compliance documentation.

Accessing Recommendations

Open Your Assessment

Navigate to the assessment workbench.

Open the Recommendations panel

The Recommendations panel renders on the assessment’s AI view (?tab=ai).

Automatic Recommendations

Screenshot of the Recommendations panel

The platform generates rule-based recommendations based on patterns detected in your assessment data:

Type Icon Example
Warning Orange alert “3 field(s) in this section are empty”
Suggestion Blue lightbulb “Once complete, request review from QA team”
Tip Purple sparkle “Ensure all evidence of security controls is documented with screenshots and configuration excerpts”
Improvement Green target Specific text improvements for brief or vague answers

Each recommendation card displays:

  • Title — brief summary of the recommendation
  • Description — detailed explanation and suggested action
  • Reasoning — why this recommendation was generated (shown in italics)
  • Confidence — how confident the system is in the recommendation (e.g., “90% confidence”)
  • Action Button — one-click action to navigate to the relevant section or apply suggested text

AI-Powered Suggestions

For more targeted guidance, use the prompt field at the top of the panel:

Enter a Prompt

Type a question or request in the text area. Examples:

  • “How can I improve my security controls documentation?”
  • “What evidence should I collect for Requirement 3.4.1?”
  • “Suggest interview questions for encryption key management”

Submit

Click Ask AI (it shows “Generating…” while it works). Cortex generates context-aware recommendations based on:

  • The current requirement you are viewing
  • Your existing assessment answers
  • The PCI DSS v4.0.1 framework guidance
  • Your assessor role

Review and Act

AI-generated recommendations appear in the list with the same card format. Click action buttons to navigate to relevant sections or apply suggested text directly.

Text Improvement Suggestions

For individual answer fields, the AI can analyze your written text and suggest improvements:

  • Passive voice detection — suggests active voice rewrites for clearer findings
  • Date specificity — suggests adding implementation dates in YYYY-MM-DD format
  • Evidence references — suggests adding references to uploaded evidence files

Each suggestion includes the original text, the improved version, reasoning for the change, and a confidence score.


Workflow: Using Analysis Tools Together

The three analysis tools are designed to be used in sequence during assessment review:

Identify Gaps

Start with the Gap Assessment dashboard. Use the With gaps segment to surface requirements that need attention — their cards flag Critical and High severity. Note requirements with no finding recorded or missing justifications.

Assess Risk

Switch to the Risk Dashboard. Use the risk-level filter chips (Critical / High) to prioritize the highest-risk requirements. Review the risk factor breakdown to understand whether the issue is a missing finding, missing documentation, incomplete testing, or stale data.

Get Recommendations

Open the Recommendations panel (the AI view, ?tab=ai). Review automatic recommendations for quick wins. Use the prompt field to ask for specific guidance on the highest-risk requirements identified in the previous step.

Address Findings

Use the Go to Section buttons to navigate directly to each requirement in the workbench. Update testing procedures, upload evidence, set finding statuses, and write justifications.

Re-Check

Return to the Gap and Risk dashboards and click Refresh. Verify that addressed requirements now show reduced risk scores and resolved gaps.


Linking Jira Issues to Requirements

For remediation tracking across engineering teams, Kliper integrates with Atlassian Jira. Assessors can link Jira issues directly to specific PCI DSS requirements so remediation work stays visible alongside the assessment.

Connecting Jira

Authorize

From the Integrations page, click Connect Atlassian. OAuth authorizes Kliper to read and write Jira issues across the projects you select.

Select a project

Pick the Jira project that holds your remediation tickets. Kliper will default to this project when creating new issues from within the assessment workbench.

Linking Issues

From a requirement in the workbench, open the Jira panel and click Link existing issue. Search by JQL (e.g., project = REM AND status != Done) or by issue key. Select one or more issues to link. The linked issues stay visible on that requirement and update live as their status changes in Jira.

Click Create Jira issue on the requirement. A form appears with the summary, description, assignee, and priority pre-populated from the requirement’s context (requirement number, current finding status, gap severity). Submit to create the issue in Jira and link it to the requirement in one step.

Status Sync

Once linked, Kliper periodically syncs the issue status from Jira. A requirement with a linked Done issue visually indicates that remediation is complete, which flows into the Gap Assessment dashboard as a resolved gap.

Click the unlink icon next to any linked issue to remove the Kliper ↔ Jira association. The issue itself is not deleted or modified in Jira — only the link is removed.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close