Every finding belongs to exactly one of seven types. No overlap. No duplicates.
Classification order: Missing → Ignored → Divergent → Disconnected → Untrusted → Underutilized → Misclassified. Test in this sequence. Stop at first match.
| Gap | Meaning |
|---|---|
| Missing | Required information absent |
| Ignored | Standard exists but not followed |
| Disconnected | Information exists but is isolated |
| Untrusted | Evidence cannot be verified |
| Underutilized | Data collected but unused |
| Misclassified | Wrong classification or taxonomy |
| Divergent | Delivery differs from required standard |
Master Example — The Risk Register
Same artifact. Same standard. Same organization. Only the problem changes:
- Doesn't exist at all → Missing
- Exists, nobody updates it → Ignored
- Not connected to governance → Disconnected
- Data can't be verified → Untrusted
- Updated, but nobody reads it → Underutilized
- Risks categorized wrong → Misclassified
- Uses 3×3 matrix instead of 5×5 → Divergent
1. Missing
Required information absent
Definition. Missing means the required information does not exist. Not "exists but is wrong." Not "exists but is ignored." Does. Not. Exist.
Detection:
- Check all the organization's delivery evidence.
- Review that against declared project management standards.
- Search by function, not by name (an org might call it a "Threat Log" instead of "Risk Register" — that's NOT Missing).
- If zero instances → check the Charter. Was it waived by the human?
- If waived → out of scope, not a finding. If confirmed → Missing.
Example — Risk Register. The Standard for Risk Management §3.2 requires a Risk Register. A search of all declared artifacts finds zero instances — no document, no system record, no spreadsheet, no field set functions as a risk register. The human confirmed this absence during Charter ratification. → Missing.
Common misclassification trap. "The risk register is 8 months out of date → Missing." The register EXISTS. It's stale, not absent. Correct: Ignored.
PMI anchor. Standard for Risk Management §3.2 — risk register as key process output. The basis for Missing: if the process output doesn't exist, the gap is Missing.
2. Ignored
Standard exists but not followed
Definition. The standard/rule/policy/process EXISTS. The practice does not follow it. Not performed. Not enforced. Not applied. Not maintained. Does. Exist. Not. Followed.
Detection:
- Confirm the standard/rule/policy EXISTS in the organization's baseline or knowledge base.
- Compare the registry criterion's expected evidence against the delivery evidence declared in the Charter.
- Examine the delivery evidence for conformance.
- If the practice DEVIATES from the rule, check for a documented tailoring decision or approved waiver.
- Assess the pattern: isolated (one project) vs. systematic (across projects).
Example — Risk Register. The Risk Register exists. It was created 14 months ago at project kickoff. It contains 6 risks, all dated to the initial workshop. No new risks have been added. No status updates appear in any of the last 8 reporting cycles. → Ignored. The standard requires ongoing maintenance; the practice does not follow it.
Common misclassification trap. "Teams use their own format instead of the template → Ignored." Ignored means the practice is NOT PERFORMED. Divergent means the practice IS PERFORMED but produces a different result. Test: is the action being done at all? Correct: if NO → Ignored. If YES but output differs → Divergent.
PMI anchor. PMBOK 8 §2.5 (Tailoring) — deviation must be deliberate and documented. Undocumented deviation = Ignored. Documented tailoring = not a finding.
3. Disconnected
Information exists but is isolated
Definition. The data exists. It is captured correctly. But it lives in a silo — it does not reach the process, person, or system that needs it to make a decision or take action. The gap is not absence; it is broken flow.
Detection:
- Confirm the data EXISTS in the source artifact.
- Identify the downstream consumer of this data per the standard.
- Check whether the data appears in the consumer's artifact, system, or process.
- If the data is present in the source but absent in the consumer → Disconnected.
- Assess scope: one artifact to one consumer (isolated) vs. multiple with no cross-references (systemic).
Example — Risk Register to Issues. The RAID log contains 23 active risks with clear owners and mitigation plans. The Issue Log contains 8 issues, none of which reference a risk ID. The standard requires issues triggered by risks to be linked for traceability. The risk data exists. The issue data exists. The link does not. → Disconnected.
Common misclassification trap. "The risk register isn't updated → Disconnected." The register exists but is stale. The problem is maintenance, not flow. Correct: Ignored.
PMI anchor. PMBOK 8 §3 (Integration Management) — process outputs must feed into other processes. Disconnected gaps violate the integration principle: outputs exist but do not become inputs.
4. Untrusted
Evidence cannot be verified
Definition. The data is present. It is populated. But its source is unknown, its calculation is unverifiable, it contradicts other evidence, or its provenance is questionable. You cannot rely on it for decision-making — not because it is missing, but because it is suspect.
Detection:
- Confirm the data EXISTS.
- Check for provenance — can you trace this data point back to its source?
- Check for consistency — does this data match other evidence of the same fact?
- Check for methodology — is the calculation, derivation, or measurement method documented and standard-compliant?
- If any check fails → Untrusted. Record the specific reason.
Example — SPI Without Earned Value. The status report states SPI = 0.95. The schedule file shows percent complete = 45%, but there is no earned value calculation, no BCWS, no BCWP. When asked, the project manager says "I estimate it." The number exists. It cannot be verified. → Untrusted.
Common misclassification trap. "The data is wrong → Untrusted." Untrusted is about verifiability, not accuracy. If the data is provably wrong but the source and method are clear, the gap is in the process or behavior. Correct: Ignored or Behavior.
PMI anchor. PMBOK 8 §4.5 (Monitor and Control Project Work) — performance data must be accurate, timely, and relevant. Untrusted gaps break the accuracy requirement.
5. Underutilized
Data collected but unused
Definition. The data exists. It is complete. It is accurate. But there is no evidence that anyone uses it to make decisions, steer governance, or control delivery. The organization collects intelligence but acts as if it does not exist. The gap is waste, not absence.
Detection:
- Confirm the data EXISTS and is populated.
- Identify the decision or process this data is supposed to support.
- Examine downstream evidence — are decisions, reports, or actions informed by this data?
- If the data is present but never referenced or acted upon → Underutilized.
- Distinguish from Disconnected: data reaches the consumer, but the consumer does nothing with it.
Example — RAID Log Nobody Reads. The RAID log contains 47 risks, all current, with owners, probabilities, impacts, and mitigations. The last 6 steering packs contain zero references to any risk. The PM says "I update it every week," but the steering committee "has the link." The data exists, is maintained, and is never used in governance. → Underutilized.
Common misclassification trap. "The data is old → Underutilized." Stale data is Ignored (not maintained), not Underutilized. Correct: Ignored.
PMI anchor. PMBOK 8 §4.4 (Manage Project Knowledge) — knowledge must be used to improve outcomes. Underutilized gaps violate the "use" requirement: knowledge exists but does not improve anything.
6. Misclassified
Wrong classification or taxonomy
Definition. The data exists. It is in the right place. But it is labeled, categorized, or typed incorrectly — causing it to be routed to the wrong process, measured by the wrong metric, or invisible to the right governance. The gap is semantic error, not absence or disuse.
Detection:
- Confirm the data EXISTS.
- Examine the taxonomy, classification, or typing applied to the data — does it match the standard's definitions?
- Check downstream effects: wrong process routing, wrong metrics, or governance blind spots.
- If the data is categorized in a way that breaks standard intent → Misclassified.
- Distinguish from Divergent: the practice is correct but the label is wrong.
Example — Risks Categorized as Issues. The issue log contains 15 entries. 8 describe uncertain future events with probability and impact — risks by standard definition. Logged as issues, they bypass risk review, have no mitigation plans, and do not appear in the risk dashboard. → Misclassified.
Common misclassification trap. "They use the wrong template → Misclassified." Template choice is a process/tooling decision, not a taxonomy error. Correct: Divergent or Tooling.
PMI anchor. PMBOK 8 §2.2 (Project Development Approach) — approach must match project characteristics. If a predictive project is classified as agile to avoid governance → Misclassified.
7. Divergent
Delivery differs from required standard
Definition. The organization follows a practice that contradicts the standard. There is no documented tailoring, no approved waiver, no exception. The practice is different and ungoverned. This is the gap of unauthorized deviation.
Detection:
- Confirm the standard EXISTS and is applicable.
- Confirm the practice IS BEING PERFORMED.
- Compare the practice against the standard's requirement — is the output, timing, method, or governance different?
- Check for documented approval: a tailoring decision, waiver, or exception record.
- If the practice differs AND there is no documented approval → Divergent.
Example — 3×3 Risk Matrix. The Standard for Risk Management §4.2 requires a 5×5 probability-impact matrix. The organization uses a 3×3 matrix in all projects, documented in the PMO handbook. There is no tailoring decision, no waiver, no board approval. → Divergent.
Common misclassification trap. "They don't follow the standard → Divergent." First check: is the practice being performed at all? If not, it's a different gap. Correct: Ignored.
PMI anchor. PMBOK 8 §2.5 (Tailoring) — deviation must be deliberate, justified, and documented. Undocumented deviation = Divergent. Documented = not a finding.
Originally published on LinkedIn.