By Kevin M. Hyams
Compliance assessment work can place real pressure on the people responsible for it.
Over many years, I have seen capable teams struggle not because they lack commitment or expertise, but because the process around them is too fragmented, too manual or too difficult to evidence.
I wrote this article to explain a practical middle ground: a structured way to assess what applies, support conclusions with evidence and produce outputs that others can rely on, without immediately moving to a heavy enterprise platform.
This is the second of NORVA Solutions’ three fundamental concepts. The first is the core question every assessment must answer. The second is the missing middle that many teams find themselves in. The third is the six-phase approach that turns the work into a connected assessment process.
If this article helps you see a clearer, easier and more defensible way to approach compliance assessment work, it has served its purpose.
At the heart of every effective compliance assessment is one practical question:
Are we meeting the requirements that apply to us?
That question sounds simple. Answering it properly is not always simple.
Many organisations reach a point where ordinary spreadsheets are no longer enough. They need more structure, consistency, evidence and reporting. But they may not be ready for the cost, complexity, implementation effort and ongoing upkeep of a larger enterprise GRC platform.
That is the missing middle in compliance assessment.
It is the space where many practical compliance teams, internal auditors and advisory firms actually work.
They need a way to:
NORVA Solutions was built for this middle ground: structured and evidence-based enough for defensible compliance assessment work, familiar enough to use without turning the tool into the project.
The missing middle is the gap between informal spreadsheet-based assessment work and heavier enterprise-level GRC platforms.
On the one hand, ordinary spreadsheets are familiar and flexible. They are often where compliance assessment work begins.
On the other hand, enterprise platforms can offer workflow, dashboards, integration and reporting, but they can also require significant implementation effort, configuration, user adoption and ongoing upkeep.
Between those two options sits a large practical need.
Many teams do not need another blank spreadsheet. But they also do not need to turn every assessment into a major systems project.
They need a structured workflow that helps them answer the question that matters: are we meeting the requirements that apply to us, and can we prove it with evidence?
Excel remains familiar, flexible and widely used. That is why compliance work often starts there.
But ordinary spreadsheets usually break down when the assessment becomes more serious.
The common weaknesses are easy to recognise:
At that point, the spreadsheet is no longer just a working document. It can become a risk in its own right.
The problem is not Excel itself. The problem is an unstructured workflow inside Excel.
The opposite problem is assuming that a heavier platform will fix the process.
It rarely works that way.
An enterprise-level platform can centralise, automate and report. But it still needs a clear operating model underneath it.
If requirements are unclear, controls are poorly mapped, evidence is not gathered in context, or reporting logic is inconsistent, the platform may simply scale those weaknesses.
That is why I like the phrase: automation is a force multiplier, not a foundation.
The process must come before the platform.
Compliance assessment is not meant to be a mechanical exercise in which every requirement is treated as equally applicable, material, or urgent.
Most regulatory and oversight environments recognise some form of proportionality, risk-based assessment, materiality, relevance or reasonable assurance.
In practical terms, that means the organisation should assess the requirements that apply to it, and assess them to a depth that reflects:
That is why the central question is not:
Have we assessed everything?
The better question is:
Are we meeting the requirements that apply to us?
The words “that apply to us” are doing important work. They recognise that compliance assessment is a structured judgement about relevance, risk, evidence and reasonable assurance.
A practical compliance workflow should help users make three linked judgements:
Does this requirement apply to us?
If it applies, how deeply should it be assessed?
What level of evidence is enough to support a reasonable assessment position?
Without those judgements, teams can easily do too much work, too little work or the wrong work.
With those judgements, the organisation can show not only what it assessed, but why that scope and depth made sense.
A workable compliance assessment process does not need to begin with a heavy system.
But it does need to connect the essential steps clearly:
Most teams do not fail because they cannot perform any one of these steps.
They struggle because the steps do not join together.
The gaps between source requirements, applicability, proportionality, assessment responses, evidence and output create rework, uncertainty and inspection anxiety.
The missing middle is not only a technology gap.
It is also a judgement gap.
Many teams do not need a heavier platform straight away. They need a structured, defensible way to decide what applies, how deeply to assess it, what constitutes enough evidence, and how to explain the answer.
That judgement should not disappear into informal notes or memory.
It should be capable of being recorded, supported, reviewed and reported.
NORVA Solutions’ Compliance Assessment Toolkit is designed to fill the gap between light spreadsheets and heavier GRC platforms.
It is Excel-native because Excel is already part of how many teams work.
But it is not an ordinary spreadsheet.
The programmed functionality, ease of use and efficiency built into NORVA’s smart templates are powered by NORVA’s Assessment Runtime Engine — the underlying logic that turns a familiar workbook environment into a guided compliance assessment workflow.
In practical terms, NORVA helps teams move through the assessment in a more controlled way:
That source-to-evidence connection matters. It helps users move beyond a loose list of tasks and towards a more defensible assessment trail:
Requirement → applicability → proportionality → assessment → evidence → validation → output
That is a fair question.
The answer is no — not in the way ordinary spreadsheet assessment work usually operates.
The value is not the file format alone. The value is the programmed assessment logic, guided workflow and output generation powered by NORVA’s Assessment Runtime Engine.
Excel-native should mean familiar and usable. It should not mean unstructured, manual or fragile.
NORVA’s smart templates use the familiar Excel environment to support a structured assessment process. That is the difference.
Inspection-ready should not mean rushing to gather evidence after the assessment is complete.
It should mean the work has been structured so that the source requirement, assessed response, supporting evidence and reporting output are already connected.
It should also mean that scoping and proportionality decisions can be explained.
If an organisation determines that a requirement is key, applicable only to a limited degree, or not applicable, that judgement should be recorded and capable of review.
Reviewers do not usually expect perfection or absolute certainty. They expect a reasonable, risk-based explanation of what was assessed, why it was assessed, what evidence was considered and how the organisation reached its conclusion.
That is what a practical assessment workflow should help produce.
Before committing to a major enterprise-level implementation, I would encourage teams to ask ten practical questions:
If the answer to several of these questions is no, the immediate priority may not be a heavier platform.
It may be a clearer workflow — one that helps the organisation define what applies, assess it proportionately, retain the evidence and explain the answer.
The Missing Middle sits between NORVA’s other two fundamental concepts.
Are we meeting the requirements that apply to us?
Many teams need more structure than ordinary spreadsheets can provide, but are not ready for the cost, complexity and upkeep of a heavier GRC platform.
A practical assessment moves through six connected phases: Scope, Maturity Assessment, Gap Analysis, Risk and Control Matrix Assessment, Documentary Evidence and Inspection-Ready Deliverables.
Together, those concepts create one clearer answer: we know what applies, we are doing what is needed, and we can show the evidence that supports it.
The strongest compliance tools do not remove the need for judgement, discipline or evidence.
They depend on those things already being present.
That is why the most valuable first step is often not more software. It is a structured way to answer one simple question:
Are we meeting the requirements that apply to us?
For teams that are frustrated by ordinary spreadsheets but not ready for a heavy GRC platform, the opportunity lies in building the workflow first.
Make the work consistent. Apply proportionality. Keep the evidence close to the assessment. Generate outputs as the work progresses. Then decide whether more tooling is genuinely needed.
That is the space NORVA’s Compliance Assessment Toolkit is built for: practical structure, familiar tools, direct links to source materials, proportionate scoping, built-in evidence repositories, programmed assessment functionality powered by NORVA’s Assessment Runtime Engine, and a clearer path from requirement to answer.
I hope that helps. Whatever the method, the principle is the same:
If it applies, assess it. If you rely on it, prove it.