Management-system readiness

ISO 27001 and TISAX Operating Model

Build an information-security operating model that can run between audits instead of relying on a last-minute documentation exercise.

Trigger situations

Trigger situations

  • Customer requirement
  • Upcoming audit or assessment
  • Certificate renewal
  • Failed readiness review
  • Evidence scramble
  • Automotive or industrial customer expectations

Problems addressed

Problems addressed

  • Scope does not match assurance needs
  • Control ownership is unclear
  • Evidence is hard to find
  • Policies do not match operating reality
  • Management review and remediation cadence is weak

Engagement outcomes

Engagement outcomes

Clear scope and context

Control ownership model

Evidence-management approach

Internal-audit readiness

Management-review cadence

Post-assessment improvement path

Assessment and advisory scope

  • Initial readiness or maturity assessment
  • Scope and context
  • Governance
  • Risk treatment
  • Policy architecture
  • Evidence management
  • Internal audit readiness
  • Management review

Implementation and delivery scope

  • ISMS operating model
  • TISAX readiness support
  • Control ownership
  • Evidence cadence
  • Remediation tracking
  • Operational governance routines

Typical deliverables

  • Readiness assessment
  • Scope and evidence map
  • Control ownership matrix
  • Roadmap
  • Management review structure
  • Internal-audit readiness plan

Engagement process

Engagement process

  1. Clarify certification, TISAX or customer-assurance drivers.

  2. Review scope, controls, risks, evidence and cadence.

  3. Design the ownership and evidence model.

  4. Support remediation and ongoing governance routines.

Follow-on work can include implementation support, internal-audit readiness, evidence remediation or ongoing ISMS/TISAX governance cadence.

Client responsibilities

Client responsibilities

  • Provide scope context and asset/process information.
  • Provide current policies and evidence.
  • Nominate accountable control owners.
  • Engage authorised assessment bodies where certification or labels are required.

GRCForce responsibilities

GRCForce responsibilities

  • Design the operating model.
  • Support implementation and evidence readiness.
  • Prepare improvement roadmap and governance cadence.
  • Keep readiness support separate from certification decisions.

Exclusions

Exclusions

  • Certification issuance
  • TISAX label issuance
  • ENX assessment provider role
  • Guaranteed certificate
  • Guaranteed TISAX label
  • Legal advice

Important boundaries

Important boundaries

  • GRCForce does not issue ISO certifications.
  • GRCForce does not issue TISAX labels.
  • Certification and label decisions are made by authorised independent assessment bodies.
  • Readiness support does not guarantee certification or label achievement.

Related thinking

Related thinking

The Audit Readiness Stack

Audit Readiness Stack Checklist

Supporting capabilities

Supporting capabilities

  • OT and industrial cybersecurity
  • Operational resilience
  • GRC tooling and programme delivery
  • Vulnerability and application-security assurance

Other flagship offers

Other flagship offers

NIS2 and DORA Readiness

Separate NIS2 and DORA workstreams, or connect both into one practical governance, control and evidence model where that is the right fit.

Fractional CISO and GRC Leadership

Controlled senior security and GRC direction for organisations that need leadership capacity without presenting it as unlimited access or a substitute for client accountability.