TISAX - Trusted Information Security Assessment Exchange
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Assessment
Per TISAX VDA ISA: assessment levels + process. Requirements include (a) Assessment Levels AL1 + AL2 + AL3 per scope + risk + (b) Assessment Process via TISAX-approved audit provider + (c) Results Exchange via ENX Portal + (d) cooperate with auditor.
- TISAX evidence for TISAXASS-1
- AL3 + prototype + GDPR partial
Assessment Scope, Levels and Exchange
Conduct internal audits of the information security management system at planned intervals and management reviews to evaluate effectiveness, identify improvements, and drive corrective actions.
- Internal audit programme and reports
- Auditor qualifications and independence
- Management review minutes with inputs and outputs
- Corrective action tracking
- Continual improvement plan
- Internal audit covers only documentation, not effectiveness
- Auditor independence not demonstrated
- Management review held annually as ceremony
- Corrective actions overdue
Use the TISAX result exchange portal to share assessment results with customers at the appropriate engagement level (Tier 1, Tier 2, Tier 3) and maintain ENX participant status throughout the validity period.
- ENX participant agreement
- Result release records to specific customers
- Engagement tier configuration
- Validity expiry tracking
- Renewal plan and timeline
- Results not shared with customers requesting them
- Engagement tier set too restrictive or too permissive
- Validity lapses without renewal plan
- Participant fees not paid
Define the TISAX scope including locations, processes, data classifications, and select the appropriate Assessment Level (AL 1, AL 2, or AL 3) based on the highest protection need of information processed for OEM customers.
- Scope description document with location list
- Assessment level justification memo
- Customer requirement letters specifying labels
- Information asset inventory with classification
- ENX registration confirmation
- Scope excludes locations that process OEM data
- AL selected below the highest customer requirement
- Customer letters not on file
- Information asset inventory missing
Select the appropriate TISAX labels (Information Security with confidentiality levels, Prototype Protection, Data Protection) corresponding to the categories of information processed and customer obligations.
- Label selection rationale
- Prototype Protection requirement evidence
- Data Protection scope inclusion analysis
- Customer label requests
- ENX scope confirmation
- Prototype Protection omitted despite handling prototypes
- Data Protection label scoped only to GDPR processors
- High vs Very High confidentiality boundary unclear
- Customer requested labels missing
Data Protection
Per TISAX ISA: data protection per GDPR including processing of personal data + cross-border transfer + accountability.
- TISAX evidence for TISAXASS-4
- AL3 + prototype + GDPR partial
Data Protection Module
Apply the TISAX Data Protection module controls aligned with GDPR Article 28 obligations including processor agreements, technical and organisational measures, transfer mechanisms, and data subject rights handling.
- Article 28 data processing agreements
- Records of processing activities
- TOM documentation
- International transfer mechanisms (SCCs, adequacy)
- Data subject request handling procedures
- DPAs in legacy format without Article 28 clauses
- TOMs lifted from generic templates
- Transfer mechanisms outdated post-Schrems II
- DSR procedures untested
ISA
Per TISAX VDA ISA Catalog: implement controls aligned to ISO 27001 + automotive specifics including prototype protection + supplier data + connected vehicle.
- TISAX evidence for TISAXASS-2
- AL3 + prototype + GDPR partial
Information Security Management
Establish information security policies, organizational structure, roles, and responsibilities. Top management must demonstrate commitment to information security.
- Information security policy approved by management
- Risk register with treatment plans and owners
- Background screening procedures for personnel
- Supplier assurance evidence register
- Risk treatment owners not actively tracking actions
- Joiner-mover-leaver process gaps for contractors
- Limited supplier reassessment after onboarding
Implement a systematic approach to information security risk management including asset identification, threat and vulnerability analysis, risk evaluation, and treatment.
- Information security policy approved by management
- Risk register with treatment plans and owners
- Background screening procedures for personnel
- Supplier assurance evidence register
- Risk treatment owners not actively tracking actions
- Joiner-mover-leaver process gaps for contractors
- Limited supplier reassessment after onboarding
Implement security measures for the employment lifecycle including screening, security awareness training, and responsibilities upon termination or change of employment.
- Information security policy approved by management
- Risk register with treatment plans and owners
- Background screening procedures for personnel
- Supplier assurance evidence register
- Risk treatment owners not actively tracking actions
- Joiner-mover-leaver process gaps for contractors
- Limited supplier reassessment after onboarding
Manage information security risks in supplier relationships including security requirements in contracts, monitoring, and assessment of supplier security posture.
- Information security policy approved by management
- Risk register with treatment plans and owners
- Background screening procedures for personnel
- Supplier assurance evidence register
- Risk treatment owners not actively tracking actions
- Joiner-mover-leaver process gaps for contractors
- Limited supplier reassessment after onboarding
People and Third Parties
Implement personnel security controls covering pre-employment screening, confidentiality obligations, security awareness, and processes for change of role or termination, applied to employees, contractors, and temporary staff.
- Background screening records (where lawful)
- Signed confidentiality agreements
- Awareness training completion records
- Termination checklist with access revocation evidence
- Contractor security clauses
- Screening not performed where lawful and required
- Awareness training rate below target
- Termination access revocation delayed
- Contractor clauses missing or weak
Information security requirements for suppliers and service providers. Assessment of third-party security posture. Contractual security requirements. Supply chain risk management for automotive data.
- Third-party security assessment reports
- Contractual security schedule
- Supply chain risk register
- Reassessment evidence
- Assessments not annual
- Contractual clauses inconsistent
- Register stale
Manage information security across the supply chain through supplier classification, contractual security clauses, onboarding due diligence, ongoing monitoring, and offboarding controls.
- Supplier inventory with classification
- Contract templates with security and TISAX flowdown clauses
- Onboarding due diligence reports
- Ongoing monitoring evidence (questionnaires, attestations)
- Offboarding checklists
- Supplier classification not refreshed
- Contracts pre date current security requirements
- Monitoring is annual checkbox
- Offboarding does not certify data return or destruction
Prototype
Per TISAX ISA: Prototype Protection including physical + IT controls for high-confidentiality prototypes + vehicle parts.
- TISAX evidence for TISAXASS-3
- AL3 + prototype + GDPR partial
Prototype Protection
Implement the prototype protection controls covering physical protection of vehicles, parts, components, and test data, including location requirements, transport, vehicle tests, and events with the public.
- Prototype zone designation documents
- Camouflage and disguise procedures
- Trial drive approval logs and route plans
- Event security plans for public exposure
- Transport security and carrier vetting records
- Camouflage absent for public trial drives
- Trial drive routes near competitor facilities
- Transport carriers not vetted
- Photography prevention controls weak
Manage test vehicles and prototype components throughout their lifecycle including check in or out, secure storage when not in use, parts return or destruction, and chain of custody documentation.
- Vehicle check in or out logs
- Prototype storage zone records
- Parts disposal certificates (shredding, destruction)
- Chain of custody forms
- End of project destruction sign offs
- Disposal certificates missing or self issued
- Storage zones shared with non prototype assets
- Chain of custody breaks during transport
- End of project parts not destroyed timely
Technical and Operational Security
Maintain business continuity and IT disaster recovery capabilities for in-scope processes with documented plans, recovery objectives aligned with customer expectations, and regular testing.
- Business impact analysis
- BCM and DR plans
- RTO and RPO definitions aligned with customer agreements
- Test plans and execution reports
- Management review of BCM
- BIA outdated
- RTO and RPO not tied to customer agreements
- DR tests cover only happy path
- BCM not exercised at executive level
Protect information in networks through segmentation, secure transmission protocols, firewall and intrusion detection, secure remote access, and protection against eavesdropping and tampering.
- Network architecture diagrams with security zones
- Firewall rule reviews
- TLS configuration evidence and cipher inventory
- VPN policies and MFA requirements
- Intrusion detection alerts and triage records
- Flat network across protection zones
- Firewall rules accumulated without review
- TLS configurations include weak ciphers
- Remote access without MFA
Apply secure software development practices including secure design reviews, secure coding standards, static and dynamic testing, dependency management, and separation of environments.
- Secure SDLC procedure
- Threat modelling outputs
- SAST and DAST results
- SBOM and dependency vulnerability reports
- Environment access matrices
- Threat modelling skipped for fast track features
- SAST findings carried over indefinitely
- SBOM absent for third party components
- Developers with production access without controls
Maintain an incident management capability covering detection, classification, response, communication with affected parties, post incident analysis, and reporting to customers and authorities as required.
- Incident response plan
- Incident classification and severity matrix
- Sample incident records with timeline
- Customer notification templates and history
- Post incident review reports
- No 24 by 7 detection capability
- Customer notifications delayed beyond contractual SLA
- Lessons learned not captured
- Severity classification inconsistent
Operate IT systems securely with documented hardening baselines, patch management, change management, logging, malware protection, and capacity management for all in-scope infrastructure.
- Hardening baselines for OS, middleware, network devices
- Patch management process and evidence
- Change management tickets
- SIEM or log aggregation evidence
- Malware protection coverage reports
- Hardening baselines outdated or not applied to all systems
- Patch SLAs missed for critical vulnerabilities
- Logs not centralised
- Malware coverage below 100 percent
Establish physical security perimeters, access controls, surveillance, and environmental protection for all in-scope locations, with controls scaled to the highest protection need within each zone.
- Site security plans and zone maps
- Access control system reports
- CCTV coverage diagrams and retention policies
- Environmental monitoring logs (fire, water, climate)
- Visitor management records
- High security zones lack secondary controls
- CCTV blind spots near critical assets
- Visitor management informal
- Environmental alerting not tested
Implement access control policies, user access management, privileged access controls, and secure authentication mechanisms for all information systems.
- Identity and access management standard with reviews
- Cryptographic standard and key management procedures
- Vulnerability and patch management evidence
- Incident handling runbook with escalation paths
- Privileged access not reviewed at required cadence
- Cryptographic exceptions accumulating without remediation
- Patch SLAs missed for plant and engineering systems
Implement cryptographic controls for data protection including encryption policies, key management, and protection of data in transit and at rest.
- Identity and access management standard with reviews
- Cryptographic standard and key management procedures
- Vulnerability and patch management evidence
- Incident handling runbook with escalation paths
- Privileged access not reviewed at required cadence
- Cryptographic exceptions accumulating without remediation
- Patch SLAs missed for plant and engineering systems
Implement operational procedures, change management, capacity management, malware protection, backup, logging, and network security controls.
- Identity and access management standard with reviews
- Cryptographic standard and key management procedures
- Vulnerability and patch management evidence
- Incident handling runbook with escalation paths
- Privileged access not reviewed at required cadence
- Cryptographic exceptions accumulating without remediation
- Patch SLAs missed for plant and engineering systems
Establish incident management procedures including reporting, classification, response, and lessons learned processes for information security incidents.
- Identity and access management standard with reviews
- Cryptographic standard and key management procedures
- Vulnerability and patch management evidence
- Incident handling runbook with escalation paths
- Privileged access not reviewed at required cadence
- Cryptographic exceptions accumulating without remediation
- Patch SLAs missed for plant and engineering systems
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TISAX - Trusted Information Security Assessment Exchange framework page.