Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

Bridge letter (gap letter): definition, scope and what it obliges you to do

What "Bridge letter (gap letter)" means in practice, where the definition comes from, and the obligations that attach once the term applies to you.

A bridge letter, also called a gap letter, is a management assertion written by a vendor to cover the period between the end of their previous audit report and a client's specific fiscal or procurement review date. It bridges the time gap when a fresh audit report is not yet issued. Software tools like BizLegal AI provide regulatory research software, not legal advice.

Origin and definition of the gap letter document

The terminology and operational expectations around vendor assurance documents originate from frameworks governing system reliability and controls. Guidance maintained by the American Institute of Certified Public Accountants (AICPA) provides foundational context for evaluating system controls over extended timeframes, as documented in the AICPA — SOC suite of services (https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services). When organizations procure cloud vendors, the timing of annual examinations rarely aligns perfectly with procurement reviews, creating a temporal mismatch.

To address this mismatch, vendors issue a formal letter asserting that their control environment has not materially altered since the last examination period ended. This document acts as a placeholder while the next evaluation cycle finishes processing. Buyers reviewing third-party risk must understand that this letter is self-attested by the vendor's management rather than independently verified by a licensed CPA firm.

Regulatory researchers utilizing the soc2 framework frequently encounter these letters during vendor risk assessments. Because the letter is not an independent audit report, compliance teams must evaluate the underlying risks carefully. Establishing clear verification protocols helps mitigate the inherent uncertainty of unverified operational periods.

Testing for applicability during vendor onboarding

Determining whether a gap letter applies requires calculating the exact time delta between the end date of the prior evaluation window and the date the vendor's services are contracted or reviewed. If the prior examination concluded several months ago, a gap letter becomes necessary to cover the interim period. Organizations can reference the soc-2-type-2 report parameters to establish the precise coverage boundaries.

When evaluating applicability, compliance teams inspect the system description of the vendor to confirm that no major infrastructure overhauls occurred during the unexamined window. If significant organizational or technical changes took place, a standard self-attestation letter may be insufficient to cover the risk exposure. Below is a comparative breakdown of standard assurance artifacts versus interim letters:

| Artifact Type | Independent Verification | Typical Coverage Period | Primary Purpose | |---|---|---|---| | soc-2-type-1 | Yes (CPA Firm) | Point in time | Design of controls | | soc-2-type-2 | Yes (CPA Firm) | 3 to 12 months | Operational effectiveness | | Bridge Letter | No (Management Only) | Interim gap window | Placeholder assurance |

Compliance analysts must check whether the vendor has maintained its control objective baselines throughout the gap period. If the controls lack consistent execution, the bridge letter carries minimal assurance weight during internal audits.

Operational changes triggered by a gap letter

Accepting a bridge letter changes the operational workflow of a compliance team by requiring supplementary due diligence steps. Instead of relying solely on an independent CPA report, the reviewer must perform internal checks regarding the vendor's recent security posture. This process often intersects with complementary-user-entity-controls that the client organization is obligated to enforce.

Once a gap letter is accepted into the vendor risk management file, the compliance team logs the expiration date and schedules a follow-up review for when the new independent examination is published. If any qualified-opinion or adverse finding appeared in the previous report, the bridge letter must explicitly address whether the identified remediation measures remain in effect.

Organizations utilizing automated risk platforms can streamline tracking these interim dates. However, human oversight remains vital to confirm that the management assertions in the letter align with observable security practices. Failing to monitor the expiration of the gap window leaves the customer organization exposed to unverified operational changes.

Common mistakes teams make with interim letters

Compliance teams frequently misinterpret a bridge letter as an extension of an independent audit report. The most critical error is treating management's self-attestation as having the same evidentiary value as an independent CPA examination. Because no testing of controls occurs for the gap period, relying entirely on the letter without additional inquiry creates a false sense of security.

A second frequent mistake involves accepting letters that contain overly broad disclaimers or fail to specify the exact end date of the covered window. Vague wording regarding material changes renders the document practically useless during regulatory scrutiny. Teams should also ensure they understand any complementary-user-entity-controls referenced in the primary report that apply to the gap duration.

A third error is failing to archive the letter alongside the original audit report within the risk management repository. When auditors request documentation for the entire review year, missing the bridge document creates an audit finding for an unverified timeframe. Maintaining organized records prevents these compliance gaps.

Adjacent terms and frequently confused compliance artifacts

Professionals often confuse bridge letters with actual examination reports or system descriptions. A bridge letter is purely a narrative confirmation, whereas a soc-2-type-2 report provides detailed testing results of operating effectiveness over an observation-window. Similarly, a soc-2-type-1 report evaluates control design at a single moment rather than spanning a duration.

Another point of confusion involves mixing up management assertions with a formal qualified-opinion issued by an auditor. If an auditor uncovers severe control failures, the resulting report contains modifications that a simple bridge letter from vendor management cannot erase or override. Security frameworks like those detailed in the NIST SP 800-53 Rev. 5 — security and privacy controls (https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) emphasize continuous monitoring over static point-in-time assurances.

Cloud security architectures frequently reference guidelines from the Cloud Security Alliance — Cloud Controls Matrix (https://cloudsecurityalliance.org/research/working-groups/cloud-controls-matrix/) when evaluating infrastructure integrity. Understanding these distinctions ensures that compliance teams select the correct artifact for third-party risk assessments without misattributing assurance levels to unverified management letters.

Related on BizLegal

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does a bridge letter replace an independent SOC audit report?

No, a bridge letter is a management assertion and does not substitute for independent testing by a licensed CPA firm. It only serves as a temporary placeholder until a fresh audit report is issued.

How long is a typical gap letter valid for procurement reviews?

A gap letter typically covers the interim months between an expired audit report and a new evaluation window, generally lasting no more than a few months depending on the vendor's audit cycle.

Are vendors legally required to provide a gap letter upon request?

There is no universal legal mandate requiring vendors to issue these letters, though commercial contracts often obligate service providers to supply reasonable assurance documentation upon client request.

What should a compliance team do if a vendor experiences a major breach during the gap period?

If a significant security incident or material change occurs during the covered timeframe, a standard bridge letter is rendered invalid, and the compliance team must request detailed incident reports.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-05.

Contact