DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.

ISO/IEC 27001:2022 — Gap Analysis and Remediation Backlog

Document ID: ISO03 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CISO (interim: CTO) Target Stage 2 readiness date: 31 March 2027


1. Purpose and method

This gap analysis compares BritiAI’s current information security posture (as at 15 June 2026) against the requirements of ISO/IEC 27001:2022 Clauses 4–10 and Annex A. Findings were derived from a desktop review of existing controls, interviews with the CTO and engineering leads, sampling of repository and cloud configuration, and review of supplier contracts with Votee Limited and Beever.

Each gap is rated by severity (Critical / High / Medium / Low), assigned an effort estimate (S ≤ 2 weeks, M ≤ 8 weeks, L ≤ 6 months), an owner, and a target closure date relative to the Stage 2 audit window (Q1 2027).

2. Clause-level findings (Clauses 4–10)

Clause 4 — Context of the organisation

  • Gap 4.1: Interested parties register exists in draft only and does not yet enumerate NHS-specific stakeholders (NHS England, NHS SBS, ICO, NCSC). Severity: Medium. Effort: S. Owner: CTO. Target: 31 Jul 2026.
  • Gap 4.2: ISMS scope statement (ISO01) requires formal approval and inclusion in the document control register. Severity: High. Effort: S. Owner: CTO. Target: 31 Jul 2026.

Clause 5 — Leadership

  • Gap 5.1: Information Security Policy not yet ratified by the Board; no recorded management commitment in minutes. Severity: High. Effort: S. Owner: CTO/Board. Target: 31 Aug 2026.
  • Gap 5.2: CISO role currently held on an interim basis by the CTO; segregation of duties is reduced. Severity: Medium. Effort: M. Owner: CTO. Target: appoint or contract a fractional CISO by 31 Oct 2026.

Clause 6 — Planning

  • Gap 6.1: Information security risk assessment methodology documented but not yet applied consistently; risk register (ISO04) is a first-pass population. Severity: High. Effort: M. Owner: CISO. Target: 30 Sep 2026.
  • Gap 6.2: Risk treatment plan not yet linked to SoA control statuses. Severity: High. Effort: M. Owner: CISO. Target: 30 Sep 2026.
  • Gap 6.3: Information security objectives not quantified at function level (no SMART objectives, no measurable KPIs). Severity: Medium. Effort: S. Owner: CTO. Target: 31 Aug 2026.

Clause 7 — Support

  • Gap 7.1: Competence matrix for security-relevant roles is informal. Severity: Medium. Effort: M. Owner: Head of People. Target: 30 Nov 2026.
  • Gap 7.2: Awareness training exists but completion is not centrally tracked. Severity: Medium. Effort: S. Owner: HoP. Target: 30 Sep 2026.
  • Gap 7.3: Documented information control (versioning, approval, retention, access) is inconsistent across SharePoint/Drive locations. Severity: High. Effort: M. Owner: HoO. Target: 31 Oct 2026.

Clause 8 — Operation

  • Gap 8.1: Change management is operationally sound for code (PR review) but not for cloud infrastructure outside IaC. Severity: High. Effort: M. Owner: HoE. Target: 30 Nov 2026.
  • Gap 8.2: Supplier risk assessment (Votee, Beever, cloud, SaaS) is partial; no annual review cycle in place. Severity: Critical. Effort: M. Owner: HoO. Target: 31 Oct 2026.

Clause 9 — Performance evaluation

  • Gap 9.1: No internal audit programme defined; first internal audit must be completed before Stage 2. Severity: Critical. Effort: M. Owner: CTO. Target: 31 Jan 2027.
  • Gap 9.2: Management Review not yet scheduled. Required quarterly cadence to be established. Severity: High. Effort: S. Owner: CTO. Target: first MR by 30 Sep 2026.
  • Gap 9.3: KPI dashboard for ISMS not yet built. Severity: Medium. Effort: M. Owner: CISO. Target: 31 Dec 2026.

Clause 10 — Improvement

  • Gap 10.1: Nonconformity and corrective action procedure exists in draft but has no recorded use. Severity: Medium. Effort: S. Owner: CISO. Target: 31 Oct 2026.

3. Annex A high-priority gaps

Findings below are the highest-impact controls to close before Stage 2. Lower-impact items are tracked in the SoA (ISO02).

A.5 Organisational

  • A.5.7 Threat intelligence (Planned): No subscription to threat intelligence feeds (NCSC CiSP, commercial). Effort: S. Target: 30 Sep 2026.
  • A.5.19–A.5.23 Supplier security: Inter-company agreements with Votee/Beever need ISO-aligned security schedules and DPAs with NHS-specific flow-down. Critical. Effort: L. Target: 31 Dec 2026.
  • A.5.23 Cloud services security: Cloud security baseline documented but not yet enforced through policy-as-code/SCPs across all accounts. High. Effort: M. Target: 30 Nov 2026.
  • A.5.24–A.5.28 Incident management: Runbooks exist for the top 5 scenarios; lifecycle documentation (triage, evidence, lessons learned) incomplete. High. Effort: M. Target: 31 Oct 2026.
  • A.5.29–A.5.30 ICT readiness for business continuity: No tested DR plan. High. Effort: L. Target: 31 Jan 2027 (with one tested failover).
  • A.5.35 Independent review: Internal audit programme is the gating dependency for Stage 2. Critical. Effort: M. Target: 31 Jan 2027.

A.6 People

  • A.6.1 Screening: BPSS-equivalent screening required for NHS-facing personnel; current process is right-to-work + reference only. High. Effort: M. Target: 30 Nov 2026.
  • A.6.3 Awareness training: Roll out role-specific modules for engineers (secure coding) and operators (incident response). Medium. Effort: M. Target: 31 Oct 2026.

A.7 Physical

  • A.7.4 Physical security monitoring and A.7.14 Secure disposal: Both Planned. Office is small but disposal certs are essential. Medium. Effort: S. Target: 30 Sep 2026.

A.8 Technological — highest-priority cluster

  • A.8.8 Vulnerability management: Scanning is in place but patch SLAs are not enforced and exceptions are not tracked. Critical. Effort: M. Target: 31 Oct 2026.
  • A.8.10 Information deletion and A.8.11 Data masking: Required for any NHS data pipeline; currently unaddressed. Critical. Effort: L. Target: 31 Jan 2027.
  • A.8.12 DLP: No DLP policies in M365/Google tenant; egress controls partial. High. Effort: M. Target: 30 Nov 2026.
  • A.8.15–A.8.16 Logging and monitoring: Centralised SIEM ingest exists, but alerting coverage and on-call rota are incomplete. High. Effort: M. Target: 30 Nov 2026.
  • A.8.22 Network segregation: Tenant isolation between NHS workloads and other workloads needs to be evidenced architecturally and via runtime tests. Critical. Effort: M. Target: 31 Dec 2026.
  • A.8.24 Cryptography: Customer-managed keys (CMK) and key rotation policy needed. High. Effort: M. Target: 31 Dec 2026.
  • A.8.25–A.8.29 Secure development: SDLC documented; threat modelling and secure-coding training not yet rolled out. High. Effort: M. Target: 30 Nov 2026.
  • A.8.33 Test information: Production data prohibited in non-prod; need synthetic data generator and audit. Critical (NHS). Effort: M. Target: 31 Dec 2026.

4. Prioritised remediation backlog (summary table)

PriorityWorkstreamSeverityEffortOwnerTarget
1Internal audit programme + first auditCriticalMCTO31 Jan 2027
2Supplier security overhaul (Votee/Beever DPAs + flow-down)CriticalLHoO/Legal31 Dec 2026
3Vulnerability management with enforced SLAsCriticalMCISO31 Oct 2026
4NHS data segregation: A.8.22 + A.8.33 + A.8.11CriticalLHoE/DPO31 Dec 2026
5Incident management lifecycle (A.5.24–A.5.28)HighMCISO31 Oct 2026
6ICT business continuity with tested DR (A.5.29–A.5.30)HighLHoE31 Jan 2027
7Logging/monitoring (A.8.15–A.8.16) + 24/7 alertingHighMCISO30 Nov 2026
8Information Security Policy + Board ratificationHighSCTO31 Aug 2026
9Risk treatment plan linked to SoAHighMCISO30 Sep 2026
10DLP + data deletion (A.8.10, A.8.12)HighMCISO/DPO30 Nov 2026
11Cryptography uplift (CMK, rotation)HighMHoE31 Dec 2026
12Secure SDLC + threat modelling rolloutHighMHoE30 Nov 2026
13BPSS-equivalent screening for NHS-facing staffHighMHoP30 Nov 2026
14Document control consolidationHighMHoO31 Oct 2026
15Management review cadenceHighSCTO30 Sep 2026
16Fractional CISO appointmentMediumMCTO31 Oct 2026
17Awareness training trackingMediumSHoP30 Sep 2026
18Threat intelligence subscriptionMediumSCISO30 Sep 2026
19Physical disposal certificationMediumSHoO30 Sep 2026
20KPI dashboard for ISMSMediumMCISO31 Dec 2026

5. Effort and resourcing summary

  • S items (≤2 weeks): 7
  • M items (≤8 weeks): 11
  • L items (≤6 months): 2

Recommended resourcing: engage a fractional CISO (1–2 days/week) and an external ISO 27001 consultant for an 8-week intensive remediation sprint (Sep–Oct 2026) and a 4-week pre-audit sprint (Feb 2027).

6. Stage 2 readiness criteria

BritiAI will be deemed ready for Stage 2 when:

  1. All Annex A controls are at least Partial with evidence; all Critical-priority items are Implemented.
  2. Internal audit has been completed end-to-end and findings closed or accepted.
  3. At least one Management Review has been minuted.
  4. A risk treatment plan exists with named owners and review dates.
  5. Supplier flow-down (Votee/Beever) is contractually executed.
  6. A DR test has been performed and lessons captured.

Target Stage 2 readiness: 31 March 2027.


End of document.