How to Prepare for a TISAX Assessment
A practical sequence for preparing an automotive supplier for a TISAX assessment — what to do first, what takes longest, and the mistakes that cost the most time.
Most preparation advice starts with a list of controls. That is the wrong end. The organisations that find preparation manageable are not the ones with the longest control list — they are the ones that made four or five structural decisions early and then executed against them consistently.
This article describes the sequence we use. It is ISAREADY methodology, not an official requirement, and it does not replace the official documentation published by ENX Association and the VDA.
Start by deciding what is in scope
Before anything else, write down what your preparation covers: which sites, which legal entities, which systems, which information types, and which additional scopes apply — prototype protection or data protection, where relevant.
This sounds administrative. It is the single decision that most affects how much work follows. An undefined scope makes a gap assessment unbounded, makes evidence collection infinite, and makes it impossible to say when preparation is finished. Teams that skip it end up renegotiating the boundary every time a finding is raised.
Have the scope approved by someone with the authority to approve it, date it, and revisit it when the business changes.
Assign ownership that means something
"IT handles it" is not an assignment. What you need is a named role with a written remit and a management decision that allocated time or budget to it.
Two failure modes are common. The first is a security responsibility added to someone's existing full-time job with no corresponding reduction elsewhere — which produces a nominal owner and no actual capacity. The second is an owner with responsibility but no authority to require anything from other departments, which produces a great deal of polite email.
Fix both before starting improvement work, because every finding you raise afterwards will need an owner who can act on it.
Run a gap assessment for breadth first
The purpose of the first gap assessment is prioritisation, not precision. You want a rough view across the entire scope rather than a detailed view of a quarter of it, because sequencing decisions need breadth.
Three questions per theme keep the answers honest:
- Is it defined — is there something written that says what should happen?
- Is it applied everywhere in scope, or only where someone champions it?
- Could you show a recent record that it happened, without reconstructing anything?
A "yes" to the first and a "no" to the third is the most common pattern in automotive suppliers, and it is exactly what a document review misses. See how to run a gap assessment for the mechanics.
Sequence by dependency, not by score
It is tempting to start with the worst scores. Often that is wrong, because some work is prerequisite to other work.
A sequence that generally holds:
- Scope and ownership — everything depends on them.
- Risk method, then the register, then treatment.
- The lowest-scoring themes that are not blocked by anything above.
- Evidence structure across everything.
- Internal audit to verify.
- Management review to record decisions and close the loop.
Doing evidence structure at step four rather than step ten is the change that most reduces total effort, because activities carried out before the evidence is defined tend to get repeated.
Understand what takes elapsed time
Some preparation work is effort-bound: writing a policy, building a register, drafting an audit programme. You can compress it by adding people.
Other work is time-bound. A quarterly access review needs quarters to demonstrate a pattern. An internal audit programme covering the scope needs a period to cover it. Incident records need incidents. Awareness participation needs a cycle to complete.
This is the reason "start now" is not a sales line. The elapsed-time work is the constraint, and no amount of resourcing in the final month buys it back.
Treat suppliers as part of your scope
Information rarely stays inside your perimeter. Identify which suppliers and service providers access, process or store in-scope information — including cloud services and subcontractors reached through another supplier, which is where third-party registers usually turn out to be incomplete.
Then do the part most organisations skip: follow findings to closure. A completed questionnaire in a folder demonstrates that you sent a questionnaire. A follow-up log showing what was raised and when it was closed demonstrates supplier security.
Verify yourself before anyone external does
Internal audit is the cheapest possible way to find out what an assessment will find, and the most commonly treated as a formality.
Run it against a planned programme. Use someone with enough independence to be uncomfortable. Track findings to closure with root cause actually considered — a finding closed on assertion has been recorded rather than resolved. And if an internal audit finds nothing, treat that as a finding about the audit.
Management review then closes the loop with structured input: risk status, incidents, audit results, objectives, supplier performance. Recorded decisions, followed-up actions. A verbal update in a monthly meeting does not produce the record.
The mistakes that cost the most
- Documentation as the whole plan. Writing policies is visible progress; implementing them is not. The visible work finishes first and then everything stalls.
- Evidence decided afterwards. The most expensive mistake and the most avoidable. See evidence management.
- Risks with no owner. A register whose owner column says "IT" has no owners.
- Waiting for a catalogue version. The foundations are stable across versions; waiting costs you the elapsed time you cannot buy back.
- Confusing a policy with a control. A policy states an intention. A control operates.
What preparation can and cannot promise
Preparation changes whether you can demonstrate what you do. It does not guarantee a TISAX assessment result, a TISAX label, an ISO certification or regulatory compliance — no toolkit, ours included, can promise that, and you should be sceptical of anyone who does.
What it does change is the experience of the assessment itself: whether you spend the preceding month reviewing or reconstructing.
If you want an indicative view of where you currently stand, the free readiness self-assessment covers every theme above in about ten minutes.
- TISAX readiness
- preparation
- assessment
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment