Use this checklist to test whether your certification programme stays ready between audits, or whether it still depends on last-minute evidence collection.

The Audit Readiness Stack has five layers: Scope, Evidence, Ownership, Cadence and Culture. The checklist turns those layers into practical questions for ISO 27001, TISAX and wider certification governance.

Who this is for

This checklist is designed for:

  • CISOs and information security managers
  • Heads of GRC and compliance leads
  • Automotive suppliers preparing for TISAX
  • Security managers responsible for evidence and controls
  • Internal audit leads supporting ISO 27001, TISAX or customer assurance reviews

What problem it solves

Many certification programmes look healthy only when an audit is close. Then the scramble begins: stale evidence, unclear ownership, rushed remediation and policies that no longer match how work is actually done.

This checklist helps you identify those issues early, before they become audit findings or customer-confidence problems.

It is especially useful if your programme is facing:

  • Pre-audit evidence collection pressure
  • Stale or incomplete evidence
  • Unclear control ownership
  • Weak corrective-action closure
  • Post-certification drop-off
  • TISAX or customer assurance questions beyond the formal assessment scope

PDF preview

The PDF includes:

Page 1: The Audit Readiness Stack Canvas

A one-page canvas covering the five layers:

  • Scope
  • Evidence
  • Ownership
  • Cadence
  • Culture

Each layer can be checked against ISO 27001, TISAX, evidence ownership and current status.

Page 2: 10 critical health checks

The checklist covers:

  • Current risk assessment
  • Statement of Applicability alignment
  • Internal audit programme
  • Management review
  • Living policies
  • Access-review evidence
  • Supplier controls
  • Incident records
  • Meaningful objectives
  • Corrective-action closure

Page 3: How to use it

The final page explains how to score your current position, prioritise weak areas, assign owners, run a 30-day pre-audit review and keep the checklist alive quarterly.

Suggested use cases

Use the checklist for:

  • ISO 27001 certification readiness
  • ISO 27001 surveillance or recertification preparation
  • TISAX readiness checks
  • Internal audit planning
  • Evidence-quality reviews
  • Management review preparation
  • Corrective-action clean-up

Next step

Download the checklist directly. No email wall, no form gate.

Then use it in a working session with security, GRC, internal audit and the control owners who will need to explain the programme when the auditor or customer asks.

If you want an outside view, request a 30-minute Audit Readiness Review. GRCForce can help you identify which gaps are likely to matter most before the next audit or customer review.