Skip to content
Evidence Management4 min read

TISAX Evidence Checklist: What Should You Prepare?

What counts as evidence, what makes a record usable, and a theme-by-theme list of the records that typically demonstrate each readiness activity.

ISAREADY Editorial Team

The most common preparation problem is not weak controls. It is controls that work and leave no trace.

A team performs access reviews. They are thorough. Six months later, asked to produce the record, they find an email thread, a spreadsheet with no date, and a person who has since changed roles. The control was fine. The evidence was not.

This article covers what evidence actually is, what makes a record usable, and which records typically demonstrate each theme.

What counts as evidence

Evidence is a record showing that a specific activity happened, when, and who was responsible.

A policy is evidence that a rule exists. It is not evidence that the rule is followed. That distinction is the whole subject, and it is why document-heavy preparation so often produces a difficult assessment.

Useful evidence has three properties:

  • Dated. When the activity happened, not when the file was last saved.
  • Attributable. Who performed or approved it. "The team" is not attribution.
  • Retrievable. Findable by someone who is not the author, in a reasonable time, without a search operation.

Retrievability is where most evidence quietly fails. It technically exists, in a mailbox or a personal drive, findable only by one person.

The blunt test

Pick one control. Ask for representative, current evidence for it. Time how long it takes.

If the answer is "a few days, and I will need to ask two people", you have found a real finding — and it is not in the control.

Our demanding version is twelve months, retrieved within one working day. Treat that as an ISAREADY stress test rather than a requirement — it is chosen to expose weak spots, not derived from any framework's retention or response-time rule. What counts as representative depends on how often the activity runs.

We use this as a standing check rather than a one-off. It is fast, it is honest, and it is impossible to argue with.

Decide the record before the activity

The structural fix is to decide, in advance, what record each activity will produce. Three questions per activity, answered before it happens:

  1. What record demonstrates this?
  2. Who produces it?
  3. Where does it live?

Write the answers into a table — activity, record, owner, location — and keep it current. We call this an evidence map. No framework requires you to keep one; it is an ISAREADY recommendation, and it is the artefact that converts "we should keep better records" into assignable work.

What to prepare, by theme

The following is ISAREADY guidance on what typically demonstrates each activity. It is not a list of official requirements, and it does not replace the official framework documentation.

Governance

  • Approved scope statement with version and approval date
  • Role assignments naming the person and their remit
  • Management decisions on objectives and allocated resources

Policies

  • Approved documents with owner, version, approval and next review date
  • Distribution or acknowledgement records with names and dates
  • Review records showing what changed, or that no change was needed

Risk management

  • Documented risk method with criteria and scales
  • Register entries with owner, treatment action, target date and status
  • Dated acceptance of residual risk by an authorised person

Access control

  • Authorisation records for access grants
  • Dated review records showing scope, reviewer and resulting changes
  • Leaver checklist completions
  • Separate identification and monitoring of privileged accounts

Asset management

  • Inventory export with an "as at" date and an owner per asset
  • Classification scheme with handling rules people can apply

Awareness

  • Training material, plus participation records by individual
  • Role-specific competence records where a role carries extra responsibility

Incident management

  • A communicated reporting route, and evidence it was communicated
  • Incident records with classification, actions, timeline and closure — including minor ones
  • Change or action records referencing what was learned

Supplier security

  • Third-party register with criticality tiering
  • Agreed security requirements: contract clauses, annexes or signed agreements
  • Completed assessments with dates and outcomes
  • A follow-up log showing findings raised and closed

Business continuity

  • Identification of critical processes and systems
  • Test reports with date, scope, result and follow-up actions

Internal audit

  • Audit programme and checklists
  • Audit reports
  • Findings log with root cause, action, owner, closure date and verification

Management review

  • Agenda and structured input pack
  • Minutes recording decisions and actions
  • Evidence that actions were followed up

Evidence anti-patterns

  • The pre-assessment sprint. Four weeks of records produced in four days. It shows.
  • Screenshots of everything. Undated, unattributed, of a screen nobody else can navigate to. Where a system can export a dated report, use the report.
  • Evidence that only proves existence. A policy proves a rule exists, not that it operates.
  • One person who knows where everything is. A single point of failure dressed up as competence.
  • Retention with no rule. Either everything is kept forever or things vanish unpredictably. Both are awkward to explain.

Where to start

If you have nothing structured today, start with the evidence map for the ten or fifteen activities that matter most. It is a half-day exercise that changes the shape of the next six months.

Our free readiness checklist pairs each activity with its expected evidence in a form you can split by theme and hand to owners. The free self-assessment scores evidence readiness separately from everything else, because it is usually the weakest part of an otherwise reasonable picture.

  • evidence
  • records
  • audit readiness
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.

How ready is your organisation?

The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.

Start Free Assessment

Continue reading

Evidence Management4 min read

How to Organize Assessment Evidence

Evidence that exists but cannot be found is evidence you will reconstruct. A practical structure for organising records so retrieval takes minutes rather than days.

Read
ISA20274 min read

ISA 6 to ISA2027: Preparing for the Transition

A catalogue change is disruptive in proportion to how tightly your programme is coupled to the previous version. How to decouple it, and how to run the transition when it comes.

Read

From requirements to real readiness

The toolkit turns the guidance in these articles into a working programme: gap assessment, risk treatment, evidence, internal audit and management review as one connected system.