TISAX Evidence Checklist: What Should You Prepare?
What counts as evidence, what makes a record usable, and a theme-by-theme list of the records that typically demonstrate each readiness activity.
The most common preparation problem is not weak controls. It is controls that work and leave no trace.
A team performs access reviews. They are thorough. Six months later, asked to produce the record, they find an email thread, a spreadsheet with no date, and a person who has since changed roles. The control was fine. The evidence was not.
This article covers what evidence actually is, what makes a record usable, and which records typically demonstrate each theme.
What counts as evidence
Evidence is a record showing that a specific activity happened, when, and who was responsible.
A policy is evidence that a rule exists. It is not evidence that the rule is followed. That distinction is the whole subject, and it is why document-heavy preparation so often produces a difficult assessment.
Useful evidence has three properties:
- Dated. When the activity happened, not when the file was last saved.
- Attributable. Who performed or approved it. "The team" is not attribution.
- Retrievable. Findable by someone who is not the author, in a reasonable time, without a search operation.
Retrievability is where most evidence quietly fails. It technically exists, in a mailbox or a personal drive, findable only by one person.
The blunt test
Pick one control. Ask for representative, current evidence for it. Time how long it takes.
If the answer is "a few days, and I will need to ask two people", you have found a real finding — and it is not in the control.
Our demanding version is twelve months, retrieved within one working day. Treat that as an ISAREADY stress test rather than a requirement — it is chosen to expose weak spots, not derived from any framework's retention or response-time rule. What counts as representative depends on how often the activity runs.
We use this as a standing check rather than a one-off. It is fast, it is honest, and it is impossible to argue with.
Decide the record before the activity
The structural fix is to decide, in advance, what record each activity will produce. Three questions per activity, answered before it happens:
- What record demonstrates this?
- Who produces it?
- Where does it live?
Write the answers into a table — activity, record, owner, location — and keep it current. We call this an evidence map. No framework requires you to keep one; it is an ISAREADY recommendation, and it is the artefact that converts "we should keep better records" into assignable work.
What to prepare, by theme
The following is ISAREADY guidance on what typically demonstrates each activity. It is not a list of official requirements, and it does not replace the official framework documentation.
Governance
- Approved scope statement with version and approval date
- Role assignments naming the person and their remit
- Management decisions on objectives and allocated resources
Policies
- Approved documents with owner, version, approval and next review date
- Distribution or acknowledgement records with names and dates
- Review records showing what changed, or that no change was needed
Risk management
- Documented risk method with criteria and scales
- Register entries with owner, treatment action, target date and status
- Dated acceptance of residual risk by an authorised person
Access control
- Authorisation records for access grants
- Dated review records showing scope, reviewer and resulting changes
- Leaver checklist completions
- Separate identification and monitoring of privileged accounts
Asset management
- Inventory export with an "as at" date and an owner per asset
- Classification scheme with handling rules people can apply
Awareness
- Training material, plus participation records by individual
- Role-specific competence records where a role carries extra responsibility
Incident management
- A communicated reporting route, and evidence it was communicated
- Incident records with classification, actions, timeline and closure — including minor ones
- Change or action records referencing what was learned
Supplier security
- Third-party register with criticality tiering
- Agreed security requirements: contract clauses, annexes or signed agreements
- Completed assessments with dates and outcomes
- A follow-up log showing findings raised and closed
Business continuity
- Identification of critical processes and systems
- Test reports with date, scope, result and follow-up actions
Internal audit
- Audit programme and checklists
- Audit reports
- Findings log with root cause, action, owner, closure date and verification
Management review
- Agenda and structured input pack
- Minutes recording decisions and actions
- Evidence that actions were followed up
Evidence anti-patterns
- The pre-assessment sprint. Four weeks of records produced in four days. It shows.
- Screenshots of everything. Undated, unattributed, of a screen nobody else can navigate to. Where a system can export a dated report, use the report.
- Evidence that only proves existence. A policy proves a rule exists, not that it operates.
- One person who knows where everything is. A single point of failure dressed up as competence.
- Retention with no rule. Either everything is kept forever or things vanish unpredictably. Both are awkward to explain.
Where to start
If you have nothing structured today, start with the evidence map for the ten or fifteen activities that matter most. It is a half-day exercise that changes the shape of the next six months.
Our free readiness checklist pairs each activity with its expected evidence in a form you can split by theme and hand to owners. The free self-assessment scores evidence readiness separately from everything else, because it is usually the weakest part of an otherwise reasonable picture.
- evidence
- records
- audit readiness
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment