Skip to content
TISAX Readiness4 min read

How to Perform a TISAX Readiness Gap Assessment

A gap assessment should end with a small number of owned, dated findings and a defensible sequence. Here is how to run one that does.

ISAREADY Editorial Team

Most gap assessments produce a spreadsheet everyone agrees is accurate and nobody acts on. The difference between that and a useful one is not analytical depth — it is the format of the output and the honesty of the input.

Fix the scope before you start

Assessing against an undefined scope produces findings nobody can act on, because the first question about any finding is "where does this apply?"

Write down the sites, legal entities, systems and information types in scope, plus any additional scopes such as prototype protection or data protection. If the scope is genuinely uncertain, that uncertainty is your first finding and it outranks everything else.

Decide what the assessment is for

The purpose is prioritisation. You cannot do everything at once, and the point of the exercise is to decide what to do first with something better than intuition.

That framing has consequences. If the goal is prioritisation, coverage matters more than precision. A rough first pass across the whole scope beats a detailed pass across a third of it, because sequencing needs breadth. Depth comes on the second pass, once you know which themes matter.

Judge current state, not intended state

The single biggest determinant of usefulness is whether people answer about today or about the organisation they are working towards.

Three questions keep it honest:

  1. Is it defined? Is there something written that says what should happen?
  2. Is it applied everywhere in scope, or only where someone champions it?
  3. Could you show a recent record that it happened, without reconstructing anything?

"Yes, mostly, and probably — give me a few days" is a real and common answer. It is also, correctly scored, a partial implementation rather than a completed one.

These three questions are our formulation, not a framework requirement. They map onto the graded scale we use in the free self-assessment: implemented, partially implemented, planned, not implemented.

Who should run it

Someone close enough to know how things actually work, and independent enough to say so.

A process owner assessing their own process scores generously — not dishonestly, but optimistically, because they know the intent and fill in the gaps mentally. Pairing the process owner with someone from outside that area consistently produces a more useful baseline. It also spreads knowledge of the programme, which matters more than it sounds.

What a usable finding looks like

A finding that leads to action has five parts. Most findings have two.

  • The gap, stated as a difference rather than a topic. "Access reviews" is a topic. "Access rights are not reviewed for the three production systems in scope" is a gap.
  • The impact, in one sentence. Why it matters here specifically.
  • An owner — a person, not a department.
  • A target date — a real one, agreed with the owner.
  • The evidence that would close it, decided now while you are thinking about it rather than in a hurry later.

That last item is the one most often omitted and the one that most reduces total effort, because it prevents the activity being performed once informally and then again properly for the record.

Sequence by dependency, not by score

Starting with the lowest scores is intuitive and often wrong, because some findings are prerequisites for others.

Scope and ownership usually come first — not because they score badly but because everything else depends on them. Risk method precedes risk treatment. Evidence definitions precede the activities that will generate evidence.

A default ordering that generally holds:

  1. Governance and scope
  2. Risk method, then register, then treatment
  3. Lowest-scoring themes that are not blocked
  4. Evidence structure across everything
  5. Internal audit to verify
  6. Management review to record decisions

Scoring: graded, not binary

Binary scoring forces every honest "partly" into either complacency or alarm. A graded scale records real progress between passes — moving a theme from partial to implemented is a genuine result that yes/no cannot express.

What a graded scale must not become is an argument about whether something is a two or a three. The score is a prioritisation aid, not the deliverable. If a scoring discussion runs more than a couple of minutes, the answer is almost always "partial" and the time is better spent on the finding.

Handle "not applicable" carefully: exclude it from both the earned points and the maximum, so declaring something out of scope neither helps nor penalises. See maturity assessment for how to keep grading consistent between passes.

The second pass

Re-run the assessment after the first block of work, using the same scale and the same honesty — which is harder the second time, because now there is something to defend.

If every score improved, be suspicious. Genuine implementation usually reveals new gaps, because doing something properly exposes what it depends on. A second pass with no new findings is more likely to be a sign of an unchallenging review than of an exemplary programme.

What to do with the output

Not a report. A tracked list.

The gap assessment's real output is a set of findings in whatever system your organisation actually uses for work — with owners, dates and a status that someone updates. A findings register that lives in a document attached to an email will be current for approximately two weeks.

For the full method, see gap assessment.

  • gap assessment
  • readiness
  • internal audit
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

How ready is your organisation?

The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.

Start Free Assessment

Continue reading

TISAX Readiness5 min read

How to Prepare for a TISAX Assessment

A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.

Read
TISAX Readiness4 min read

Common TISAX Preparation Mistakes

The recurring mistakes in readiness programmes are structural rather than technical. Here are the ones that cost the most time, and what to do instead.

Read
ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

Read

From requirements to real readiness

The toolkit turns the guidance in these articles into a working programme: gap assessment, risk treatment, evidence, internal audit and management review as one connected system.