What Happens in a TISAX Audit: What to Expect, Step by Step
A TISAX audit checks whether your controls actually hold up under scrutiny. It’s not enough to say they do on paper. An accredited third-party audit provider reviews your completed VDA ISA self-assessment, examines your evidence, and talks to the people who run your day-to-day processes.
What that review looks like depends on your Assessment Level. This guide walks through it step by step, from the opening meeting to what your auditor is actually checking for.
If you need the background first, our guide to what TISAX and the VDA ISA standard are covers the basics. Here, we assume you already know you need a TISAX label and want to know what audit day looks like.
This Guide Is for Businesses Being Audited, Not People Becoming Auditors
Let’s clear up a common mix-up first. This page is for a business that has been asked by a customer to get a TISAX label. It is not for someone who wants to become an accredited TISAX audit provider themselves.
Becoming an accredited audit provider is a separate process. ENX Association runs that accreditation for audit firms, not for individual businesses. It is not covered on this page.
If you’re a supplier, engineering firm, or IT vendor preparing for your own assessment, keep reading. Everything below covers what your auditor will actually do, and when.
Your Assessment Level Decides What Actually Happens
There is no single script for a TISAX audit. What happens depends on your Assessment Level, which your customer sets based on how sensitive the information is. TISAX defines three levels, but only two involve an outside auditor actively verifying your work: AL 2 and AL 3.
At Assessment Level 2, an accredited auditor runs what ENX Association calls a plausibility check. They review your self-assessment answers, examine your supporting evidence, and interview the person responsible for information security, usually by web conference. AL 2 is the level most often required for handling confidential information.
At Assessment Level 3, the audit provider runs something far more thorough: a comprehensive on-site verification. That means document examination, planned interviews with process owners, and direct observation of how your processes actually run day to day. AL 3 applies when strictly confidential information or prototype protection is in scope.
Before the Audit Starts: What Your Audit Provider Needs From You
Your audit provider can’t do their job until you’ve done yours. Three things need to happen first.

- Register your assessment scope on the ENX platform, then choose an accredited audit provider early. Wait times vary, and picking a provider is one step in the full certification process.
- Complete your VDA ISA self-assessment honestly, chapter by chapter, before your auditor ever contacts you. Our VDA ISA checklist walks through this self-assessment step.
- Gather the evidence behind each answer: policies, access logs, training records, and proof the process is actually followed, not just written down.
That second step matters more than it sounds. Your auditor isn’t grading a form. They’re checking whether what you wrote is plausible given the evidence.
If your self-assessment claims a maturity level your evidence doesn’t back up, that gap doesn’t stay hidden. It surfaces during the audit itself, and it becomes a finding your auditor has to document.
The Opening Meeting Sets the Ground Rules
Every TISAX audit, at either level, starts with a formal opening meeting. Nothing gets reviewed before this happens.

The opening meeting confirms the basics both sides need to agree on. Your auditor walks through the assessment scope you registered, the specific assessment objectives being evaluated, and the logistics for the day (or days) ahead: who they’ll need to talk to, what evidence they’ll need pulled, and how the process will run.
Think of it as a shared checklist before the real work starts. Once it’s confirmed, the evidence review and interviews begin. TISAX audits also close with a formal closing meeting, which we cover further down.
What an AL 2 Audit Actually Looks Like
If your assessment is AL 2, here’s what the actual review looks like. Your auditor is not re-testing every control from scratch. They’re checking whether your self-assessment holds up.
That happens mainly through one structured conversation. The auditor interviews the person responsible for information security at your company, generally over a web conference rather than in person.
During that interview, the auditor reviews the evidence you gathered alongside your self-assessment answers. They’re running a plausibility check: does what you documented match what you can actually show them?
This is narrower than a full independent audit by design. AL 2 exists for information sensitive enough to require outside verification, but not sensitive enough to require the on-site, multi-interview process AL 3 requires instead. An on-site inspection can be requested at AL 2, but it isn’t the default.
What an AL 3 Audit Actually Looks Like
AL 3 is the deep-verification level. It applies when strictly confidential information or prototype protection is in scope.
Where AL 2 leans on one structured conversation, AL 3 leans on direct observation. The audit provider spends real time on-site, not just on a call.
That on-site time covers four things:
- Document and evidence examination. The auditor reviews policies, logs, and records in person, not just what you uploaded beforehand.
- Planned interviews with process owners. These are scheduled in advance, one process owner at a time, covering the chapter they’re responsible for.
- Observation of local conditions. The auditor watches how a process actually runs day to day.
- Unplanned interviews with process participants. These aren’t scheduled ahead of time. They exist to catch daylight between what a policy says and what people actually do day to day.
That last point is what makes AL 3 harder to game than AL 2. A well-rehearsed answer from a process owner doesn’t always hold up. If the person actually running the process describes something different when caught off guard, that gap becomes a finding.
What Auditors Are Actually Checking For, Chapter by Chapter
The VDA ISA catalogue is organized into nine chapters, covering everything from access management to incident response.
Every objective your auditor checks gets scored on a six-point maturity scale, not a pass/fail check.
| Maturity Level | What It Means |
|---|---|
| 0. Incomplete | No suitable process exists, or nobody follows it |
| 1. Performed | An informal process exists, with some evidence it works, but it isn’t well documented |
| 2. Managed | A documented process is followed, with evidence it’s actually implemented |
| 3. Established | A standard process is integrated into your overall management system |
| 4. Predictable | The process is measured and controlled |
| 5. Optimizing | The process improves continuously, tied to business goals |
To pass, you need a consistent Maturity Level 3 or higher on every MUST requirement. A policy sitting in a drawer somewhere isn’t enough.
Every MUST requirement needs a Maturity Level of 3 or higher to pass a TISAX audit, backed by real evidence, not just documentation.
Not every requirement carries the same weight if you miss it:
| Requirement Type | If You Meet It | If You Don’t |
|---|---|---|
| MUST | Counts toward your required Maturity Level 3+ score | Major Non-Conformity, blocking the label until it’s fixed |
| SHOULD | Strengthens your overall maturity | Minor Non-Conformity, documented but doesn’t block passing |
The Closing Meeting: What You Learn Before You Leave
Every TISAX audit ends the way it began: with a formal meeting, this time to close things out.
At the closing meeting, your auditor walks through preliminary findings. You’ll hear whether any Non-Conformities were identified, and at what severity.
A Minor Non-Conformity, tied to a SHOULD requirement, gets documented but doesn’t block your label. A Major Non-Conformity, tied to a MUST requirement, does.
If you have a Major Non-Conformity, you’re not out. You get a remediation window, commonly cited as up to nine months, to fix the gap and provide new evidence.
Once every Major Non-Conformity is resolved, the label can be issued. Skip that step, and it can’t.
After the Audit: Your Report, Your Label, and No Fixed Timeline
Once everything checks out, your audit provider issues two things. You get the official TISAX assessment report, plus the TISAX label or labels for the objectives you were evaluated on.
Those labels become visible to the business partners you choose to share them with, through the ENX platform. Each label stays valid for three years before the full process has to run again.
One thing ENX Association won’t give you is a standard timeline. Their own participant handbook says so directly:
“We would certainly like to tell you how long it will take you to get your TISAX assessment result, we kindly ask for your understanding that it is not possible for us to forecast this in a reliable way.”
That’s not a dodge. Your timeline depends on three things: your Assessment Level, how ready your evidence was, and how many Non-Conformities need fixing.
For the fuller picture, from registration through exchange, our complete TISAX compliance guide covers the whole journey.
See Where You Stand
Walk into audit day with a plan instead of a guess. Take the free 2-minute TISAX Readiness Check to see where you stand today, chapter by chapter. It shows your maturity scale before your auditor does.
Take the free 2-minute TISAX Readiness Check
Related Guides
- What Is TISAX? The VDA ISA Standard Explained for Automotive Suppliers
- TISAX Assessment Levels (AL1, AL2, AL3) and Maturity Levels Explained
- The TISAX Certification Process: Step by Step
- VDA ISA Checklist: How to Self-Assess Before Your TISAX Audit
- The Complete TISAX Compliance Guide for Automotive Suppliers
Frequently Asked Questions
ENX Association says it can’t give a reliable standard timeline. Duration depends on your Assessment Level, how complete your evidence is going in, and how many Non-Conformities need fixing afterward. AL 2 audits, built around one interview and an evidence review, generally move faster than AL 3’s on-site, multi-interview process.
AL 2 is a plausibility check: an auditor reviews your self-assessment and evidence and interviews your security lead, usually over web conference. AL 3 is a full on-site verification, with document review, planned and unplanned interviews, and direct observation of how your processes actually run.
There’s no simple pass or fail. A gap on a MUST requirement becomes a Major Non-Conformity, which blocks your label until it’s fixed. You typically get a remediation window, commonly cited as up to nine months, to close the gap and resubmit evidence.
An accredited third-party audit provider conducts the audit, not ENX Association itself and not your IT provider. You choose and hire that audit provider directly, separate from any technical readiness work you do beforehand.
You need a consistent Maturity Level 3 or higher on every MUST requirement in scope. That means a standard process integrated into your management system and actually followed day to day, not just a written policy sitting in a folder.
A TISAX label stays valid for three years. After that, you have to go through registration, assessment, and exchange again to renew it.
AL 2 audits are usually conducted remotely, over web conference, with an on-site inspection available on request. AL 3 audits are built around on-site verification, though temporary video-supported remote assessment has been permitted with a required on-site follow-up.
Get Your Controls Audit-Ready Before Assessment Day
Most of what a TISAX auditor checks isn’t built the week before assessment day. It’s built months in advance, spanning several VDA ISA chapters:
- Identity and Access Management (Chapter 5)
- IT security and operations (Chapter 6)
- Detection and response to security incidents (Chapter 7)
- Business continuity (Chapter 8)
We help automotive suppliers build and document these controls ahead of an AL 2 or AL 3 audit.
Take a look at our compliance-readiness IT services, or book a call to talk through where your environment stands today.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
