How to Perform a TISAX Readiness Gap Assessment
A gap assessment should end with a small number of owned, dated findings and a defensible sequence. Here is how to run one that does.
Most gap assessments produce a spreadsheet everyone agrees is accurate and nobody acts on. The difference between that and a useful one is not analytical depth — it is the format of the output and the honesty of the input.
Fix the scope before you start
Assessing against an undefined scope produces findings nobody can act on, because the first question about any finding is "where does this apply?"
Write down the sites, legal entities, systems and information types in scope, plus any additional scopes such as prototype protection or data protection. If the scope is genuinely uncertain, that uncertainty is your first finding and it outranks everything else.
Decide what the assessment is for
The purpose is prioritisation. You cannot do everything at once, and the point of the exercise is to decide what to do first with something better than intuition.
That framing has consequences. If the goal is prioritisation, coverage matters more than precision. A rough first pass across the whole scope beats a detailed pass across a third of it, because sequencing needs breadth. Depth comes on the second pass, once you know which themes matter.
Judge current state, not intended state
The single biggest determinant of usefulness is whether people answer about today or about the organisation they are working towards.
Three questions keep it honest:
- Is it defined? Is there something written that says what should happen?
- Is it applied everywhere in scope, or only where someone champions it?
- Could you show a recent record that it happened, without reconstructing anything?
"Yes, mostly, and probably — give me a few days" is a real and common answer. It is also, correctly scored, a partial implementation rather than a completed one.
These three questions are our formulation, not a framework requirement. They map onto the graded scale we use in the free self-assessment: implemented, partially implemented, planned, not implemented.
Who should run it
Someone close enough to know how things actually work, and independent enough to say so.
A process owner assessing their own process scores generously — not dishonestly, but optimistically, because they know the intent and fill in the gaps mentally. Pairing the process owner with someone from outside that area consistently produces a more useful baseline. It also spreads knowledge of the programme, which matters more than it sounds.
What a usable finding looks like
A finding that leads to action has five parts. Most findings have two.
- The gap, stated as a difference rather than a topic. "Access reviews" is a topic. "Access rights are not reviewed for the three production systems in scope" is a gap.
- The impact, in one sentence. Why it matters here specifically.
- An owner — a person, not a department.
- A target date — a real one, agreed with the owner.
- The evidence that would close it, decided now while you are thinking about it rather than in a hurry later.
That last item is the one most often omitted and the one that most reduces total effort, because it prevents the activity being performed once informally and then again properly for the record.
Sequence by dependency, not by score
Starting with the lowest scores is intuitive and often wrong, because some findings are prerequisites for others.
Scope and ownership usually come first — not because they score badly but because everything else depends on them. Risk method precedes risk treatment. Evidence definitions precede the activities that will generate evidence.
A default ordering that generally holds:
- Governance and scope
- Risk method, then register, then treatment
- Lowest-scoring themes that are not blocked
- Evidence structure across everything
- Internal audit to verify
- Management review to record decisions
Scoring: graded, not binary
Binary scoring forces every honest "partly" into either complacency or alarm. A graded scale records real progress between passes — moving a theme from partial to implemented is a genuine result that yes/no cannot express.
What a graded scale must not become is an argument about whether something is a two or a three. The score is a prioritisation aid, not the deliverable. If a scoring discussion runs more than a couple of minutes, the answer is almost always "partial" and the time is better spent on the finding.
Handle "not applicable" carefully: exclude it from both the earned points and the maximum, so declaring something out of scope neither helps nor penalises. See maturity assessment for how to keep grading consistent between passes.
The second pass
Re-run the assessment after the first block of work, using the same scale and the same honesty — which is harder the second time, because now there is something to defend.
If every score improved, be suspicious. Genuine implementation usually reveals new gaps, because doing something properly exposes what it depends on. A second pass with no new findings is more likely to be a sign of an unchallenging review than of an exemplary programme.
What to do with the output
Not a report. A tracked list.
The gap assessment's real output is a set of findings in whatever system your organisation actually uses for work — with owners, dates and a status that someone updates. A findings register that lives in a document attached to an email will be current for approximately two weeks.
For the full method, see gap assessment.
- gap assessment
- readiness
- internal audit
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment