By Kevin M. Hyams
Why I wrote this article
Compliance assessment work can place real pressure on the people responsible for it.
Over many years, I have seen capable teams struggle not because they lack commitment or expertise, but because the process around them is too fragmented, too manual or too difficult to evidence.
I wrote this article to explain a practical middle ground: a structured way to assess what applies, support conclusions with evidence and produce outputs that others can rely on, without immediately moving to a heavy enterprise platform.
This is the second of NORVA Solutions’ three fundamental concepts. The first is the core question every assessment must answer. The second is the missing middle that many teams find themselves in. The third is the six-phase approach that turns the work into a connected assessment process.
If this article helps you see a clearer, easier and more defensible way to approach compliance assessment work, it has served its purpose.
Summary
At the heart of every effective compliance assessment is one practical question:
Are we meeting the requirements that apply to us?
That question sounds simple. Answering it properly is not always simple.
Many organisations reach a point where ordinary spreadsheets are no longer enough. They need more structure, consistency, evidence and reporting. But they may not be ready for the cost, complexity, implementation effort and ongoing upkeep of a larger enterprise GRC platform.
That is the missing middle in compliance assessment.
It is the space where many practical compliance teams, internal auditors and advisory firms actually work.
They need a way to:
- Know what applies and where it comes from
- Assess requirements proportionately and consistently
- Capture evidence close to the assessment
- Explain the judgement behind the answer
- Produce outputs without rebuilding the work manually
- Support review, audit, inspection or client reporting with a clearer assessment trail
NORVA Solutions was built for this middle ground: structured and evidence-based enough for defensible compliance assessment work, familiar enough to use without turning the tool into the project.
What is the missing middle in compliance assessment?
The missing middle is the gap between informal spreadsheet-based assessment work and heavier enterprise-level GRC platforms.
On the one hand, ordinary spreadsheets are familiar and flexible. They are often where compliance assessment work begins.
On the other hand, enterprise platforms can offer workflow, dashboards, integration and reporting, but they can also require significant implementation effort, configuration, user adoption and ongoing upkeep.
Between those two options sits a large practical need.
Many teams do not need another blank spreadsheet. But they also do not need to turn every assessment into a major systems project.
They need a structured workflow that helps them answer the question that matters: are we meeting the requirements that apply to us, and can we prove it with evidence?
Why ordinary spreadsheets eventually fall short
Excel remains familiar, flexible and widely used. That is why compliance work often starts there.
But ordinary spreadsheets usually break down when the assessment becomes more serious.
The common weaknesses are easy to recognise:
- Different assessors interpret requirements differently
- The regulatory source material becomes separated from the assessment logic
- Evidence sits in folders, emails or separate systems instead of being linked to the assessed response
- Ratings and status updates are applied inconsistently
- Reports are rebuilt manually after the work is supposedly complete
- The organisation cannot easily explain how it moved from a requirement to an assessed response
At that point, the spreadsheet is no longer just a working document. It can become a risk in its own right.
The problem is not Excel itself. The problem is an unstructured workflow inside Excel.
Why heavier platforms can sometimes disappoint
The opposite problem is assuming that a heavier platform will fix the process.
It rarely works that way.
An enterprise-level platform can centralise, automate and report. But it still needs a clear operating model underneath it.
If requirements are unclear, controls are poorly mapped, evidence is not gathered in context, or reporting logic is inconsistent, the platform may simply scale those weaknesses.
That is why I like the phrase: automation is a force multiplier, not a foundation.
The process must come before the platform.
Why proportionality matters
Compliance assessment is not meant to be a mechanical exercise in which every requirement is treated as equally applicable, material, or urgent.
Most regulatory and oversight environments recognise some form of proportionality, risk-based assessment, materiality, relevance or reasonable assurance.
In practical terms, that means the organisation should assess the requirements that apply to it, and assess them to a depth that reflects:
- Its size and complexity
- Its activities and operating environment
- Its risk profile
- Stakeholder expectations
- The potential harm that non-compliance could cause
- The level of evidence reasonably needed to support the position relied on
That is why the central question is not:
Have we assessed everything?
The better question is:
Are we meeting the requirements that apply to us?
The words “that apply to us” are doing important work. They recognise that compliance assessment is a structured judgement about relevance, risk, evidence and reasonable assurance.
The three judgements every assessment needs
A practical compliance workflow should help users make three linked judgements:
Applicability
Does this requirement apply to us?
Proportionality
If it applies, how deeply should it be assessed?
Evidence
What level of evidence is enough to support a reasonable assessment position?
Without those judgements, teams can easily do too much work, too little work or the wrong work.
With those judgements, the organisation can show not only what it assessed, but why that scope and depth made sense.
What a practical compliance assessment workflow needs to connect
A workable compliance assessment process does not need to begin with a heavy system.
But it does need to connect the essential steps clearly:
- Source requirements — what regulatory or other source materials are the assessment requirements anchored to?
- Applicability — which requirements apply to this organisation?
- Proportionality — how deeply should those requirements be assessed in this organisation’s risk context?
- Controls — what is in place to meet those requirements?
- Assessment — how are maturity, implementation and response being assessed?
- Evidence — what supports the assessed response?
- Validation — how has the assessed response been checked?
- Outputs — what reports, registers and dashboards can be produced without rebuilding the work?
Most teams do not fail because they cannot perform any one of these steps.
They struggle because the steps do not join together.
The gaps between source requirements, applicability, proportionality, assessment responses, evidence and output create rework, uncertainty and inspection anxiety.
Why is this not just a technology gap?
The missing middle is not only a technology gap.
It is also a judgement gap.
Many teams do not need a heavier platform straight away. They need a structured, defensible way to decide what applies, how deeply to assess it, what constitutes enough evidence, and how to explain the answer.
That judgement should not disappear into informal notes or memory.
It should be capable of being recorded, supported, reviewed and reported.
Where NORVA fits
NORVA Solutions’ Compliance Assessment Toolkit is designed to fill the gap between light spreadsheets and heavier GRC platforms.
It is Excel-native because Excel is already part of how many teams work.
But it is not an ordinary spreadsheet.
The programmed functionality, ease of use and efficiency built into NORVA’s smart templates are powered by NORVA’s Assessment Runtime Engine — the underlying logic that turns a familiar workbook environment into a guided compliance assessment workflow.
In practical terms, NORVA helps teams move through the assessment in a more controlled way:
- Requirements are organised for assessment
- Applicability and proportionality can be considered as part of the scoping judgement
- Assessment requirements are anchored in authoritative source materials hyperlinked directly into the relevant smart templates
- Responses are guided through consistent status and rating logic
- Evidence is captured in context through a built-in evidentiary document repository within each template
- Validation is recorded as part of the same workflow
- Outputs such as dashboards, status reporting and risk registers are generated from the work already completed
That source-to-evidence connection matters. It helps users move beyond a loose list of tasks and towards a more defensible assessment trail:
Requirement → applicability → proportionality → assessment → evidence → validation → output
Is this just another spreadsheet?
That is a fair question.
The answer is no — not in the way ordinary spreadsheet assessment work usually operates.
The value is not the file format alone. The value is the programmed assessment logic, guided workflow and output generation powered by NORVA’s Assessment Runtime Engine.
Excel-native should mean familiar and usable. It should not mean unstructured, manual or fragile.
NORVA’s smart templates use the familiar Excel environment to support a structured assessment process. That is the difference.
What does inspection-ready mean in practice?
Inspection-ready should not mean rushing to gather evidence after the assessment is complete.
It should mean the work has been structured so that the source requirement, assessed response, supporting evidence and reporting output are already connected.
It should also mean that scoping and proportionality decisions can be explained.
If an organisation determines that a requirement is key, applicable only to a limited degree, or not applicable, that judgement should be recorded and capable of review.
Reviewers do not usually expect perfection or absolute certainty. They expect a reasonable, risk-based explanation of what was assessed, why it was assessed, what evidence was considered and how the organisation reached its conclusion.
That is what a practical assessment workflow should help produce.
A readiness check before buying a heavier platform
Before committing to a major enterprise-level implementation, I would encourage teams to ask ten practical questions:
- Do we know which requirements apply to us?
- Do we know which requirements do not apply to us, and can we explain why?
- Have we considered proportionality when deciding how deeply each requirement should be assessed?
- Can we see the source material behind the requirements we are assessing?
- Do we have a consistent assessment method?
- Do we capture evidence as part of the work, or chase it afterwards?
- Is the evidence retained close enough to the assessment to support review or inspection?
- Can we explain how each answer was reached?
- Can we produce presentation-ready reports without rebuilding them manually?
- Do we understand the full cost of ownership, including implementation, upkeep and internal capacity?
If the answer to several of these questions is no, the immediate priority may not be a heavier platform.
It may be a clearer workflow — one that helps the organisation define what applies, assess it proportionately, retain the evidence and explain the answer.
How the missing middle connects to NORVA’s three fundamental concepts
The Missing Middle sits between NORVA’s other two fundamental concepts.
1. The Central Question
Are we meeting the requirements that apply to us?
2. The Missing Middle in Compliance Assessment
Many teams need more structure than ordinary spreadsheets can provide, but are not ready for the cost, complexity and upkeep of a heavier GRC platform.
3. The Six Phases of a Compliance Assessment
A practical assessment moves through six connected phases: Scope, Maturity Assessment, Gap Analysis, Risk and Control Matrix Assessment, Documentary Evidence and Inspection-Ready Deliverables.
Together, those concepts create one clearer answer: we know what applies, we are doing what is needed, and we can show the evidence that supports it.
Conclusion: build confidence before adding complexity
The strongest compliance tools do not remove the need for judgement, discipline or evidence.
They depend on those things already being present.
That is why the most valuable first step is often not more software. It is a structured way to answer one simple question:
Are we meeting the requirements that apply to us?
For teams that are frustrated by ordinary spreadsheets but not ready for a heavy GRC platform, the opportunity lies in building the workflow first.
Make the work consistent. Apply proportionality. Keep the evidence close to the assessment. Generate outputs as the work progresses. Then decide whether more tooling is genuinely needed.
That is the space NORVA’s Compliance Assessment Toolkit is built for: practical structure, familiar tools, direct links to source materials, proportionate scoping, built-in evidence repositories, programmed assessment functionality powered by NORVA’s Assessment Runtime Engine, and a clearer path from requirement to answer.
I hope that helps. Whatever the method, the principle is the same:
If it applies, assess it. If you rely on it, prove it.