Skip to content

Evidence request lists

TISAX - Trusted Information Security Assessment Exchange

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Assessment

TISAXASS-1
Assessment Levels and Process

Per TISAX VDA ISA: assessment levels + process. Requirements include (a) Assessment Levels AL1 + AL2 + AL3 per scope + risk + (b) Assessment Process via TISAX-approved audit provider + (c) Results Exchange via ENX Portal + (d) cooperate with auditor.

Artefacts an auditor will ask for
  • TISAX evidence for TISAXASS-1
Where this commonly fails
  • AL3 + prototype + GDPR partial

Assessment Scope, Levels and Exchange

TISAX-AUDIT-01
Internal Audit and Management Review

Conduct internal audits of the information security management system at planned intervals and management reviews to evaluate effectiveness, identify improvements, and drive corrective actions.

Artefacts an auditor will ask for
  • Internal audit programme and reports
  • Auditor qualifications and independence
  • Management review minutes with inputs and outputs
  • Corrective action tracking
  • Continual improvement plan
Where this commonly fails
  • Internal audit covers only documentation, not effectiveness
  • Auditor independence not demonstrated
  • Management review held annually as ceremony
  • Corrective actions overdue
TISAX-EXCH-01
Result Exchange and Customer Engagement Levels

Use the TISAX result exchange portal to share assessment results with customers at the appropriate engagement level (Tier 1, Tier 2, Tier 3) and maintain ENX participant status throughout the validity period.

Artefacts an auditor will ask for
  • ENX participant agreement
  • Result release records to specific customers
  • Engagement tier configuration
  • Validity expiry tracking
  • Renewal plan and timeline
Where this commonly fails
  • Results not shared with customers requesting them
  • Engagement tier set too restrictive or too permissive
  • Validity lapses without renewal plan
  • Participant fees not paid
TISAX-SCOPE-01
TISAX Scope Definition and Assessment Level Selection

Define the TISAX scope including locations, processes, data classifications, and select the appropriate Assessment Level (AL 1, AL 2, or AL 3) based on the highest protection need of information processed for OEM customers.

Artefacts an auditor will ask for
  • Scope description document with location list
  • Assessment level justification memo
  • Customer requirement letters specifying labels
  • Information asset inventory with classification
  • ENX registration confirmation
Where this commonly fails
  • Scope excludes locations that process OEM data
  • AL selected below the highest customer requirement
  • Customer letters not on file
  • Information asset inventory missing
TISAX-SCOPE-02
TISAX Labels Selection

Select the appropriate TISAX labels (Information Security with confidentiality levels, Prototype Protection, Data Protection) corresponding to the categories of information processed and customer obligations.

Artefacts an auditor will ask for
  • Label selection rationale
  • Prototype Protection requirement evidence
  • Data Protection scope inclusion analysis
  • Customer label requests
  • ENX scope confirmation
Where this commonly fails
  • Prototype Protection omitted despite handling prototypes
  • Data Protection label scoped only to GDPR processors
  • High vs Very High confidentiality boundary unclear
  • Customer requested labels missing

Data Protection

TISAXASS-4
Data Protection (GDPR Alignment)

Per TISAX ISA: data protection per GDPR including processing of personal data + cross-border transfer + accountability.

Artefacts an auditor will ask for
  • TISAX evidence for TISAXASS-4
Where this commonly fails
  • AL3 + prototype + GDPR partial

Data Protection Module

TISAX-DP-01
Data Protection Module Controls

Apply the TISAX Data Protection module controls aligned with GDPR Article 28 obligations including processor agreements, technical and organisational measures, transfer mechanisms, and data subject rights handling.

Artefacts an auditor will ask for
  • Article 28 data processing agreements
  • Records of processing activities
  • TOM documentation
  • International transfer mechanisms (SCCs, adequacy)
  • Data subject request handling procedures
Where this commonly fails
  • DPAs in legacy format without Article 28 clauses
  • TOMs lifted from generic templates
  • Transfer mechanisms outdated post-Schrems II
  • DSR procedures untested

ISA

TISAXASS-2
ISA Catalog Implementation

Per TISAX VDA ISA Catalog: implement controls aligned to ISO 27001 + automotive specifics including prototype protection + supplier data + connected vehicle.

Artefacts an auditor will ask for
  • TISAX evidence for TISAXASS-2
Where this commonly fails
  • AL3 + prototype + GDPR partial

Information Security Management

TISAX-ISM-01
IS Policies and Organization

Establish information security policies, organizational structure, roles, and responsibilities. Top management must demonstrate commitment to information security.

Artefacts an auditor will ask for
  • Information security policy approved by management
  • Risk register with treatment plans and owners
  • Background screening procedures for personnel
  • Supplier assurance evidence register
Where this commonly fails
  • Risk treatment owners not actively tracking actions
  • Joiner-mover-leaver process gaps for contractors
  • Limited supplier reassessment after onboarding
TISAX-ISM-02
Risk Management

Implement a systematic approach to information security risk management including asset identification, threat and vulnerability analysis, risk evaluation, and treatment.

Artefacts an auditor will ask for
  • Information security policy approved by management
  • Risk register with treatment plans and owners
  • Background screening procedures for personnel
  • Supplier assurance evidence register
Where this commonly fails
  • Risk treatment owners not actively tracking actions
  • Joiner-mover-leaver process gaps for contractors
  • Limited supplier reassessment after onboarding
TISAX-ISM-03
Human Resources Security

Implement security measures for the employment lifecycle including screening, security awareness training, and responsibilities upon termination or change of employment.

Artefacts an auditor will ask for
  • Information security policy approved by management
  • Risk register with treatment plans and owners
  • Background screening procedures for personnel
  • Supplier assurance evidence register
Where this commonly fails
  • Risk treatment owners not actively tracking actions
  • Joiner-mover-leaver process gaps for contractors
  • Limited supplier reassessment after onboarding
TISAX-ISM-04
Supplier and Third-Party Management

Manage information security risks in supplier relationships including security requirements in contracts, monitoring, and assessment of supplier security posture.

Artefacts an auditor will ask for
  • Information security policy approved by management
  • Risk register with treatment plans and owners
  • Background screening procedures for personnel
  • Supplier assurance evidence register
Where this commonly fails
  • Risk treatment owners not actively tracking actions
  • Joiner-mover-leaver process gaps for contractors
  • Limited supplier reassessment after onboarding

People and Third Parties

TISAX-HR-01
Human Resources Security

Implement personnel security controls covering pre-employment screening, confidentiality obligations, security awareness, and processes for change of role or termination, applied to employees, contractors, and temporary staff.

Artefacts an auditor will ask for
  • Background screening records (where lawful)
  • Signed confidentiality agreements
  • Awareness training completion records
  • Termination checklist with access revocation evidence
  • Contractor security clauses
Where this commonly fails
  • Screening not performed where lawful and required
  • Awareness training rate below target
  • Termination access revocation delayed
  • Contractor clauses missing or weak
TISAX-IS-03
Third-Party Risk Management

Information security requirements for suppliers and service providers. Assessment of third-party security posture. Contractual security requirements. Supply chain risk management for automotive data.

Artefacts an auditor will ask for
  • Third-party security assessment reports
  • Contractual security schedule
  • Supply chain risk register
  • Reassessment evidence
Where this commonly fails
  • Assessments not annual
  • Contractual clauses inconsistent
  • Register stale
TISAX-SUPP-01
Supplier and Third Party Information Security

Manage information security across the supply chain through supplier classification, contractual security clauses, onboarding due diligence, ongoing monitoring, and offboarding controls.

Artefacts an auditor will ask for
  • Supplier inventory with classification
  • Contract templates with security and TISAX flowdown clauses
  • Onboarding due diligence reports
  • Ongoing monitoring evidence (questionnaires, attestations)
  • Offboarding checklists
Where this commonly fails
  • Supplier classification not refreshed
  • Contracts pre date current security requirements
  • Monitoring is annual checkbox
  • Offboarding does not certify data return or destruction

Prototype

TISAXASS-3
Prototype Protection and Confidentiality

Per TISAX ISA: Prototype Protection including physical + IT controls for high-confidentiality prototypes + vehicle parts.

Artefacts an auditor will ask for
  • TISAX evidence for TISAXASS-3
Where this commonly fails
  • AL3 + prototype + GDPR partial

Prototype Protection

TISAX-PROTO-01
Prototype Protection Requirements

Implement the prototype protection controls covering physical protection of vehicles, parts, components, and test data, including location requirements, transport, vehicle tests, and events with the public.

Artefacts an auditor will ask for
  • Prototype zone designation documents
  • Camouflage and disguise procedures
  • Trial drive approval logs and route plans
  • Event security plans for public exposure
  • Transport security and carrier vetting records
Where this commonly fails
  • Camouflage absent for public trial drives
  • Trial drive routes near competitor facilities
  • Transport carriers not vetted
  • Photography prevention controls weak
TISAX-PROTO-02
Test Vehicle and Component Handling

Manage test vehicles and prototype components throughout their lifecycle including check in or out, secure storage when not in use, parts return or destruction, and chain of custody documentation.

Artefacts an auditor will ask for
  • Vehicle check in or out logs
  • Prototype storage zone records
  • Parts disposal certificates (shredding, destruction)
  • Chain of custody forms
  • End of project destruction sign offs
Where this commonly fails
  • Disposal certificates missing or self issued
  • Storage zones shared with non prototype assets
  • Chain of custody breaks during transport
  • End of project parts not destroyed timely

Technical and Operational Security

TISAX-BCM-01
Business Continuity and IT Disaster Recovery

Maintain business continuity and IT disaster recovery capabilities for in-scope processes with documented plans, recovery objectives aligned with customer expectations, and regular testing.

Artefacts an auditor will ask for
  • Business impact analysis
  • BCM and DR plans
  • RTO and RPO definitions aligned with customer agreements
  • Test plans and execution reports
  • Management review of BCM
Where this commonly fails
  • BIA outdated
  • RTO and RPO not tied to customer agreements
  • DR tests cover only happy path
  • BCM not exercised at executive level
TISAX-COMMS-01
Communications and Network Security

Protect information in networks through segmentation, secure transmission protocols, firewall and intrusion detection, secure remote access, and protection against eavesdropping and tampering.

Artefacts an auditor will ask for
  • Network architecture diagrams with security zones
  • Firewall rule reviews
  • TLS configuration evidence and cipher inventory
  • VPN policies and MFA requirements
  • Intrusion detection alerts and triage records
Where this commonly fails
  • Flat network across protection zones
  • Firewall rules accumulated without review
  • TLS configurations include weak ciphers
  • Remote access without MFA
TISAX-DEV-01
Secure Software Development

Apply secure software development practices including secure design reviews, secure coding standards, static and dynamic testing, dependency management, and separation of environments.

Artefacts an auditor will ask for
  • Secure SDLC procedure
  • Threat modelling outputs
  • SAST and DAST results
  • SBOM and dependency vulnerability reports
  • Environment access matrices
Where this commonly fails
  • Threat modelling skipped for fast track features
  • SAST findings carried over indefinitely
  • SBOM absent for third party components
  • Developers with production access without controls
TISAX-IM-01
Incident Management and Reporting

Maintain an incident management capability covering detection, classification, response, communication with affected parties, post incident analysis, and reporting to customers and authorities as required.

Artefacts an auditor will ask for
  • Incident response plan
  • Incident classification and severity matrix
  • Sample incident records with timeline
  • Customer notification templates and history
  • Post incident review reports
Where this commonly fails
  • No 24 by 7 detection capability
  • Customer notifications delayed beyond contractual SLA
  • Lessons learned not captured
  • Severity classification inconsistent
TISAX-OPS-01
IT Operations and System Hardening

Operate IT systems securely with documented hardening baselines, patch management, change management, logging, malware protection, and capacity management for all in-scope infrastructure.

Artefacts an auditor will ask for
  • Hardening baselines for OS, middleware, network devices
  • Patch management process and evidence
  • Change management tickets
  • SIEM or log aggregation evidence
  • Malware protection coverage reports
Where this commonly fails
  • Hardening baselines outdated or not applied to all systems
  • Patch SLAs missed for critical vulnerabilities
  • Logs not centralised
  • Malware coverage below 100 percent
TISAX-PHYS-01
Physical Security and Environmental Controls

Establish physical security perimeters, access controls, surveillance, and environmental protection for all in-scope locations, with controls scaled to the highest protection need within each zone.

Artefacts an auditor will ask for
  • Site security plans and zone maps
  • Access control system reports
  • CCTV coverage diagrams and retention policies
  • Environmental monitoring logs (fire, water, climate)
  • Visitor management records
Where this commonly fails
  • High security zones lack secondary controls
  • CCTV blind spots near critical assets
  • Visitor management informal
  • Environmental alerting not tested
TISAX-TECH-01
Access Control and Identity Management

Implement access control policies, user access management, privileged access controls, and secure authentication mechanisms for all information systems.

Artefacts an auditor will ask for
  • Identity and access management standard with reviews
  • Cryptographic standard and key management procedures
  • Vulnerability and patch management evidence
  • Incident handling runbook with escalation paths
Where this commonly fails
  • Privileged access not reviewed at required cadence
  • Cryptographic exceptions accumulating without remediation
  • Patch SLAs missed for plant and engineering systems
TISAX-TECH-02
Cryptography

Implement cryptographic controls for data protection including encryption policies, key management, and protection of data in transit and at rest.

Artefacts an auditor will ask for
  • Identity and access management standard with reviews
  • Cryptographic standard and key management procedures
  • Vulnerability and patch management evidence
  • Incident handling runbook with escalation paths
Where this commonly fails
  • Privileged access not reviewed at required cadence
  • Cryptographic exceptions accumulating without remediation
  • Patch SLAs missed for plant and engineering systems
TISAX-TECH-03
Operations and Communications Security

Implement operational procedures, change management, capacity management, malware protection, backup, logging, and network security controls.

Artefacts an auditor will ask for
  • Identity and access management standard with reviews
  • Cryptographic standard and key management procedures
  • Vulnerability and patch management evidence
  • Incident handling runbook with escalation paths
Where this commonly fails
  • Privileged access not reviewed at required cadence
  • Cryptographic exceptions accumulating without remediation
  • Patch SLAs missed for plant and engineering systems
TISAX-TECH-04
Incident Management

Establish incident management procedures including reporting, classification, response, and lessons learned processes for information security incidents.

Artefacts an auditor will ask for
  • Identity and access management standard with reviews
  • Cryptographic standard and key management procedures
  • Vulnerability and patch management evidence
  • Incident handling runbook with escalation paths
Where this commonly fails
  • Privileged access not reviewed at required cadence
  • Cryptographic exceptions accumulating without remediation
  • Patch SLAs missed for plant and engineering systems
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TISAX - Trusted Information Security Assessment Exchange framework page.