---
title: "Gap & Risk Analysis"
description: "How to use the real-time gap assessment, risk scoring dashboard, and AI-powered remediation recommendations to monitor assessment progress."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Gap & Risk Analysis

Kliper provides three integrated analysis tools that give assessors a real-time view of assessment health: **Gap Assessment** (what's missing), **Risk Scoring** (what's most dangerous), and **AI Recommendations** (what to do about it). All three are accessible from the assessment workbench tabs.

  <img src="/images/analysis-tabs.webp" srcset="/images/analysis-tabs-768.webp 768w, /images/analysis-tabs.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of Analysis Tabs in Workbench" />

---

## Gap Assessment

The Gap Assessment dashboard identifies which PCI DSS requirements have findings gaps — requirements that are not in place, not tested, or not yet evaluated.

### Accessing Gap Assessment

1. **Open Your Assessment**

   Navigate to the assessment from the Engagement Hub or the Assessment Workbench.
2. **Select the Gap Analysis Tab**

   In the assessment view, click the **Gap Analysis** tab (bar chart icon). The dashboard loads with real-time data calculated from your current assessment answers.

### Dashboard Overview

  <img src="/images/gap-summary-cards.webp" srcset="/images/gap-summary-cards-768.webp 768w, /images/gap-summary-cards.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of Gap Assessment" />

The Gap Assessment is a **master-detail navigator**:

- **Readiness strip** (top) — a compliance ring plus a **Compliant / Pending / Gap** meter summarizing the whole assessment
- **Left rail** — every requirement (R1–R12) with a per-requirement progress meter and **open-gap count**, plus a search box and **All / With gaps / Complete** segments to jump to what needs attention
- **Detail pane** — the selected requirement's subsections, each shown as a **gap-closure card**

### Gap Severity Levels

Each requirement is assigned a gap severity based on its finding status:

| Severity | Condition | Action Required |
|---|---|---|
| **Critical** (red) | Not In Place, or no finding recorded with no justification | Immediate attention — requirement is non-compliant or completely unevaluated |
| **High** (orange) | Has justification but no finding status selected | Assessor has documented observations but not made a determination |
| **Medium** (yellow) | Marked as Not Tested | Control exists but was not evaluated during this assessment |
| **None / Compliant** (green) | In Place or Not Applicable | No gap — requirement is satisfied |

### Filtering and Navigation

Use the **search box** and the **All / With gaps / Complete** segments in the left rail to filter which requirements appear. Within the detail pane, a second **All / Gap / Pending / Compliant** filter narrows which subsections show. Selecting a requirement loads its subsections in the detail pane.

### Gap-closure cards

In the detail pane, each subsection appears as a **gap-closure card** with read-only tiles for the **Finding**, **Justification**, and **Remediation**, plus method badges (Compensating Control / Customized Approach) and a missing-justification warning where applicable. Click a card to **jump to that requirement in the editor** and address it.

  <img src="/images/gap-detail-row.webp" srcset="/images/gap-detail-row-768.webp 768w, /images/gap-detail-row.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of Gap-closure card" />

### Refreshing Data

Click the **Refresh** button to recalculate the gap assessment from the latest assessment answers. The dashboard always computes in real-time — no cached data is used.

---

## Risk Scoring

The Risk Scoring dashboard assigns a quantitative risk score (0–100) to every requirement in the assessment, considering multiple factors beyond just the finding status.

### Accessing Risk Scoring

1. **Open Your Assessment**

   Navigate to the assessment from the Engagement Hub or the Assessment Workbench.
2. **Select the Risk Dashboard**

   Click **Risk Dashboard** (shield icon) in the analysis menu. The dashboard loads with per-requirement risk calculations.

### Overall Risk Score

  <img src="/images/risk-overall-score.webp" srcset="/images/risk-overall-score-768.webp 768w, /images/risk-overall-score.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of Overall Risk Score" />

The dashboard header displays the **Overall Risk Score** — a weighted average of all requirement risk scores, presented as a 0–100 score with a risk level badge.

| Risk Level | Score Range | Color |
|---|---|---|
| **Critical** | 80–100 | Red |
| **High** | 60–79 | Orange |
| **Medium** | 40–59 | Yellow |
| **Low** | 20–39 | Blue |
| **None** | 0–19 | Green |

### How Risk Scores Are Calculated

Each requirement's risk score is computed from four weighted factors:

| Factor | Weight | What It Measures |
|---|---|---|
| **Finding Risk** | 45% | The assessment finding status (Not In Place = 100, Not Tested = 50, In Place = 0) |
| **Documentation Risk** | 25% | Whether the assessor has written a justification (missing justification on a failing requirement = 100) |
| **Completeness Risk** | 15% | Whether testing procedure data has been filled in |
| **Staleness Risk** | 15% | How recently the requirement was last updated (>90 days = 60, >60 days = 40, >30 days = 20) |

**Adjustments:**
- Requirements with a **Compensating Control** receive a 10-point reduction
- Requirements marked **Not Applicable** receive a 0 across all factors

### Summary Cards

Four metric cards appear below the overall score:

| Card | What It Shows |
|---|---|
| **Critical Risk** | Count of requirements with risk score 80+ |
| **High Risk** | Count of requirements with risk score 60–79 |
| **No Risk** | Count of requirements with risk score below 20 |
| **Total Requirements** | Total count of assessed requirements |

### Finding Distribution

A visual breakdown of all requirements by their finding status:

| Finding | Color |
|---|---|
| In Place | Green |
| Not In Place | Red |
| Not Tested | Yellow |
| Not Applicable | Gray |
| No Finding | Orange |

### Requirement Risk Explorer

  <img src="/images/risk-detail-breakdown.webp" srcset="/images/risk-detail-breakdown-768.webp 768w, /images/risk-detail-breakdown.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of Risk Detail Breakdown" />

Requirements are grouped under their **top-level requirement** (R1–R12), collapsed by default with a mini risk-distribution meter — use **Expand / Collapse all** to open everything. Within each, sub-requirements are grouped by **subsection** (1.1, 1.2, …). Prefer a single list? Toggle **Flat View** at the top to switch the grouped explorer to one flat table of every sub-requirement. Expand any control for a detailed breakdown:

- **Risk Factor Bars** — four horizontal progress bars showing each factor's individual contribution:
  - Finding Risk (0–100)
  - Documentation Risk (0–100)
  - Completeness Risk (0–100)
  - Staleness Risk (0–100)

- **Identified Issues** — a bulleted list of specific problems:
  - "Finding: Not In Place"
  - "No assessment finding recorded"
  - "Not yet tested"
  - "Missing justification/evidence"
  - "Testing procedures incomplete"
  - "Data is stale (60+ days)"

- **Go to Section** button — navigate to the requirement in the workbench to address the issues

### Filtering

Filter the requirements list by risk level using the filter buttons: **All**, **Critical**, **High**, **Medium**, **Low**, **No Risk**.

---

> **Note**
>
> When Cortex is enabled, an **advisory finding-review layer** surfaces Cortex's verdicts — with **CRESS** reliability scores — directly on the Risk and Gap views. It's advisory only and never changes your deterministic risk/gap scores. See [Cortex AI](/guides/cortex-ai) for how the advisory layer and CRESS work.

With Cortex enabled, the **Gap** view's readiness strip also adds two actions: **Review all · Cortex** (batch-review every unreviewed or stale control) and **Draft closure plan** (open a remediation plan for the gaps). A **Cortex-flagged** filter and flag counter appear on both views, and the **Risk** view shows a **Cortex Review** distribution card. See [Cortex Review and Triage](/guides/cortex-ai#cortex-review-and-triage).

## AI Remediation Recommendations

The Recommendations panel provides AI-generated suggestions for improving your assessment, identifying weak areas, and strengthening compliance documentation.

### Accessing Recommendations

1. **Open Your Assessment**

   Navigate to the assessment workbench.
2. **Open the Recommendations panel**

   The Recommendations panel renders on the assessment's **AI** view (`?tab=ai`).

> **Note**
>
> The Recommendations panel is currently reachable only via the **AI** view URL (`?tab=ai`) — it is not surfaced as an entry in the assessment's analysis menu (Gap Analysis / Risk Dashboard / Audit Trail / Security Tools).

### Automatic Recommendations

  <img src="/images/recommendations-panel.webp" srcset="/images/recommendations-panel-768.webp 768w, /images/recommendations-panel.webp 1536w" sizes="(min-width: 768px) 768px, 100vw" loading="lazy" decoding="async" alt="Screenshot of the Recommendations panel" />

The platform generates rule-based recommendations based on patterns detected in your assessment data:

| Type | Icon | Example |
|---|---|---|
| **Warning** | Orange alert | "3 field(s) in this section are empty" |
| **Suggestion** | Blue lightbulb | "Once complete, request review from QA team" |
| **Tip** | Purple sparkle | "Ensure all evidence of security controls is documented with screenshots and configuration excerpts" |
| **Improvement** | Green target | Specific text improvements for brief or vague answers |

Each recommendation card displays:

- **Title** — brief summary of the recommendation
- **Description** — detailed explanation and suggested action
- **Reasoning** — why this recommendation was generated (shown in italics)
- **Confidence** — how confident the system is in the recommendation (e.g., "90% confidence")
- **Action Button** — one-click action to navigate to the relevant section or apply suggested text

### AI-Powered Suggestions

For more targeted guidance, use the prompt field at the top of the panel:

1. **Enter a Prompt**

   Type a question or request in the text area. Examples:

   - "How can I improve my security controls documentation?"
   - "What evidence should I collect for Requirement 3.4.1?"
   - "Suggest interview questions for encryption key management"
2. **Submit**

   Click **Ask AI** (it shows "Generating…" while it works). Cortex generates context-aware recommendations based on:

   - The current requirement you are viewing
   - Your existing assessment answers
   - The PCI DSS v4.0.1 framework guidance
   - Your assessor role
3. **Review and Act**

   AI-generated recommendations appear in the list with the same card format. Click action buttons to navigate to relevant sections or apply suggested text directly.

### Text Improvement Suggestions

For individual answer fields, the AI can analyze your written text and suggest improvements:

- **Passive voice detection** — suggests active voice rewrites for clearer findings
- **Date specificity** — suggests adding implementation dates in YYYY-MM-DD format
- **Evidence references** — suggests adding references to uploaded evidence files

Each suggestion includes the original text, the improved version, reasoning for the change, and a confidence score.

---

## Workflow: Using Analysis Tools Together

The three analysis tools are designed to be used in sequence during assessment review:

1. **Identify Gaps**

   Start with the **Gap Assessment** dashboard. Use the **With gaps** segment to surface requirements that need attention — their cards flag **Critical** and **High** severity. Note requirements with no finding recorded or missing justifications.
2. **Assess Risk**

   Switch to the **Risk Dashboard**. Use the risk-level filter chips (Critical / High) to prioritize the highest-risk requirements. Review the risk factor breakdown to understand whether the issue is a missing finding, missing documentation, incomplete testing, or stale data.
3. **Get Recommendations**

   Open the **Recommendations** panel (the **AI** view, `?tab=ai`). Review automatic recommendations for quick wins. Use the prompt field to ask for specific guidance on the highest-risk requirements identified in the previous step.
4. **Address Findings**

   Use the **Go to Section** buttons to navigate directly to each requirement in the workbench. Update testing procedures, upload evidence, set finding statuses, and write justifications.
5. **Re-Check**

   Return to the Gap and Risk dashboards and click **Refresh**. Verify that addressed requirements now show reduced risk scores and resolved gaps.

---

## Linking Jira Issues to Requirements

For remediation tracking across engineering teams, Kliper integrates with Atlassian Jira. Assessors can link Jira issues directly to specific PCI DSS requirements so remediation work stays visible alongside the assessment.

### Connecting Jira

1. **Authorize**

   From the Integrations page, click **Connect Atlassian**. OAuth authorizes Kliper to read and write Jira issues across the projects you select.
2. **Select a project**

   Pick the Jira project that holds your remediation tickets. Kliper will default to this project when creating new issues from within the assessment workbench.

### Linking Issues

  <Accordion>
<AccordionTrigger>Link an existing issue</AccordionTrigger>
<AccordionContent>
    From a requirement in the workbench, open the **Jira** panel and click **Link existing issue**. Search by JQL (e.g., `project = REM AND status != Done`) or by issue key. Select one or more issues to link. The linked issues stay visible on that requirement and update live as their status changes in Jira.
  </AccordionContent>
</Accordion>
  <Accordion>
<AccordionTrigger>Create a new issue</AccordionTrigger>
<AccordionContent>
    Click **Create Jira issue** on the requirement. A form appears with the summary, description, assignee, and priority pre-populated from the requirement's context (requirement number, current finding status, gap severity). Submit to create the issue in Jira and link it to the requirement in one step.
  </AccordionContent>
</Accordion>

### Status Sync

Once linked, Kliper periodically syncs the issue status from Jira. A requirement with a linked **Done** issue visually indicates that remediation is complete, which flows into the Gap Assessment dashboard as a resolved gap.

### Removing a Link

Click the unlink icon next to any linked issue to remove the Kliper ↔ Jira association. The issue itself is not deleted or modified in Jira — only the link is removed.

Source: https://docs.kliper.dev/operations/gap-risk-analysis/index.mdx
