Skip to content
TISAX Readiness4 min read

Common TISAX Preparation Mistakes

The recurring mistakes in readiness programmes are structural rather than technical. Here are the ones that cost the most time, and what to do instead.

ISAREADY Editorial Team

The mistakes that cost automotive suppliers the most time during preparation are not exotic. They are structural, they repeat across organisations of very different sizes, and most of them are cheap to avoid if you know to look.

Treating documentation as the plan

The most common pattern. A programme starts, policies get written, the folder fills up, and then progress appears to stall.

Nothing has failed. The programme has finished the part that documentation can do. Writing a policy moves a requirement from undefined to defined; it does not make anything operate, and it produces no record that anything operated.

Instead: refuse to mark any policy complete until it has an owner, a review cycle, a communication record, and a named record that will demonstrate it operating. It slows the visible progress and accelerates the real one.

Leaving scope undefined

An undefined scope makes gap assessment unbounded, evidence collection infinite, and "are we ready?" unanswerable.

It also produces a particular kind of circular meeting, in which every finding triggers a discussion about whether that system is really in scope.

Instead: write the scope down early — sites, entities, systems, information types, additional scopes — have it approved, and revisit it deliberately rather than continuously.

Risks without owners

A risk register whose owner column reads "IT" for forty rows is a register with no owners. So is one where the owner is a person who has never been told.

The related failure is residual risk that nobody formally accepts. Risks get identified and treated, and then the question "who decided this remaining level was acceptable?" has no answer.

Instead: a named person per risk, a treatment action with a target date, and dated acceptance of residual risk by someone with the authority to accept it.

Deciding evidence afterwards

The single most expensive mistake, and the most avoidable.

Activities are performed. Nobody decides what record demonstrates them. Months later the records have to be reconstructed from mailboxes and memory, producing weaker evidence at higher cost, during the period when everyone is already busy.

Instead: decide the record before the activity. Three questions per activity — what record, who produces it, where it lives. See from policy to evidence.

Supplier questionnaires with no follow-up

Sent, returned, filed, forgotten. This demonstrates that you send questionnaires.

The findings inside those responses are frequently the most actionable information in the entire programme, and they are frequently unread.

Instead: a follow-up log showing what was raised, who owns it, and when it closed. Assess proportionately to criticality rather than sending everyone the same questionnaire — a hundred generic assessments produce less security than fifteen serious ones.

Internal audit as theatre

An internal audit performed by the person who built the process, finding nothing, closing no findings.

If an internal audit finds nothing, that is a finding about the audit. The purpose is to discover what an external party would discover, at a point where discovering it is still cheap.

Instead: enough independence to be uncomfortable, a planned programme covering the scope over a defined period, and findings tracked to closure with root cause actually considered. A finding closed on assertion has been recorded, not resolved.

Confusing activity with maturity

Programmes sometimes measure themselves by throughput — documents produced, meetings held, controls "addressed". None of that describes whether a practice operates consistently.

Instead: grade honestly against a defined scale, require a record reference for anything graded as fully implemented, and accept that a lower score on an honest scale is more useful than a higher one on a generous scale. See maturity assessment.

Waiting for the next catalogue version

"We will start when the new version is published" is a reasonable-sounding decision that costs the one resource you cannot buy back.

The foundations — scope, ownership, risk method, evidence discipline, internal audit, management review — are stable across catalogue versions. And the time-bound work, such as demonstrating a quarterly cycle, needs elapsed quarters regardless of which version you are eventually assessed against.

Instead: start on the stable foundations, and structure the programme around activities rather than catalogue references so a version change is a mapping update. See ISA2027 transition.

Preparing in a silo

Information security prepared entirely inside the IT department, with no involvement from HR, facilities, purchasing or the business units that actually handle the information.

The consequence appears at assessment time, when a control that IT believes operates turns out to be applied in one department and unheard of in three others.

Instead: distribute themes to their real owners early. Our readiness checklist is organised by theme partly so it can be split up and handed over.

Believing a toolkit guarantees an outcome

Including ours. No toolkit can guarantee a TISAX assessment result, a TISAX label, an ISO certification or regulatory compliance.

What structured preparation changes is whether you can demonstrate what you do — which is the part within your control, and the part that determines whether the final month is spent reviewing or reconstructing.

If you want an indicative view of which of these apply to you, the free self-assessment takes about ten minutes.

  • preparation
  • mistakes
  • readiness
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

How ready is your organisation?

The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.

Start Free Assessment

Continue reading

TISAX Readiness5 min read

How to Prepare for a TISAX Assessment

A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.

Read
ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

Read

From requirements to real readiness

The toolkit turns the guidance in these articles into a working programme: gap assessment, risk treatment, evidence, internal audit and management review as one connected system.