loader from loading.io

#245 What’s The Difference Between TISAX and ISO 27001?

The ISO Show

Release Date: 03/04/2026

#246 Pedalling Towards Purpose – Forests Journey To B Corp Accreditation show art #246 Pedalling Towards Purpose – Forests Journey To B Corp Accreditation

The ISO Show

Europe is only partially on track to meet its 2030 environment and sustainability objectives, and while some objectives are being scaled back, we are seeing the introduction of more regional regulations that require tangible annual sustainability reporting.  Businesses that have built sustainability into their way of working from the start are leading the charge and defining what it means to operate responsibly. As with today’s guest, Forest, an e-bike provider that is not only 100% powered by renewable energy but has also achieved the coveted B Corp Accreditation. In this episode,...

info_outline
#245 What’s The Difference Between TISAX and ISO 27001? show art #245 What’s The Difference Between TISAX and ISO 27001?

The ISO Show

For those in the automotive industry, namely suppliers working with European OEM’s, you’re likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from. ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two. For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don’t intend to certify to both. In this episode, Ian Battersby is joined...

info_outline
#244 What is TISAX? show art #244 What is TISAX?

The ISO Show

The modern automotive industry faces many new challenges, as vehicles evolve with more complex data requirements and supply chains become increasingly interconnected, major Original Equipment Manufacturers (OEMs) require certain Standards as a mark of trust from potential suppliers. Currently, this trust is codified in TISAX (Trusted Information Security Assessment Exchange). For businesses that have not previously dealt with Standards, TISAX can be seen as a daunting regulatory hurdle. However, a TISAX label is more than a compliance check, it’s a recognised mark that your organisation...

info_outline
#243 How Can You Leverage AI for ESG and Sustainability Reporting show art #243 How Can You Leverage AI for ESG and Sustainability Reporting

The ISO Show

Annual sustainability and ESG reporting is now becoming a necessity for many businesses, whether driven by region specific regulations and legislation, industry expectations or client demand.  However, doing so is definitely easier said than done. It requires a complex network of data being gathered from multiple sources which then needs to be collated, analysed and summarised in a cohesive report for leadership and possible public publication. Thankfully, there have been developments in new AI driven technology that can help ease this annual burden, allowing you to focus on...

info_outline
#242 Surface Print – The Commercial Advantage of ISO 14001 for SME’s show art #242 Surface Print – The Commercial Advantage of ISO 14001 for SME’s

The ISO Show

A Standard like ISO 14001 may seem more appropriate for large enterprises looking to address their environmental footprint, however it can apply to any business no matter the size. All businesses produce waste, and we can all do more to save energy, resources and money in the process. For some SME’s, tackling resource wastage through effective environmental management can make a huge difference. Such is the case for today’s guest, Surface Print, a family owned wallpaper manufacturer managed by its 4th generation. In this episode, Ian Battersby is joined by James Watson, Managing...

info_outline
#241 Raise your Game With The Leadership Powerup Gameplan show art #241 Raise your Game With The Leadership Powerup Gameplan

The ISO Show

An ISO Management System can’t survive without Leadership engagement. It was seen as such an essential aspect that ‘Leadership commitment’ became a key requirement of many ISO Standards back in 2015 when the Annex SL format was adopted. It’s easy to see why. An effective Management System will provide vital information for top management to make decisions on processes, policies and strategic direction. So, how do you get leadership involved with your ISO management system? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to...

info_outline
#240 Revitalise your Audits with the Audit Accelerator Gameplan show art #240 Revitalise your Audits with the Audit Accelerator Gameplan

The ISO Show

Internal Audits are a key part of any ISO Implementation journey, they are also a necessary vehicle to drive continual improvement. For those with more mature ISO Management Systems, it can be easy for Internal Audits to become a bit of a rinse and repeat exercise. This can lead to stagnation of meaningful results, especially if you’re asking the same people the same questions year on year. So how can you revitalise the Audit process? In this episode, Steph Churchman is joined by Sarah Ball, the Service Improvement Manager at Blackmores, to discuss the challenges associated with repeated...

info_outline
#239 2025 ISO Standard Wrap Up and Looking Ahead show art #239 2025 ISO Standard Wrap Up and Looking Ahead

The ISO Show

It’s been a busy year for ISO Standards, with that set to ramp up in 2026 thanks to upcoming Standard transitions. Before we dive into a new year, we’d like to take a step back and highlight some of the key ISO milestones from 2025.  In this episode, Steph Churchman, Communications Manager at Blackmores, looks back at the major Standard updates from 2025, including changes to existing Standards, new ISO’s published and key upcoming changes you need to be aware of for 2026.   You’ll learn ·      What ISO Standards have been updated in 2025? ...

info_outline
#238 Umony's ISO 42001 Journey - Setting the Standard for effective AI Management show art #238 Umony's ISO 42001 Journey - Setting the Standard for effective AI Management

The ISO Show

AI has become inescapable over the past years, with the technology being integrated into tools that most people use every day. This has raised some important questions about the associated risks and benefits related to AI. Those developing software and services that include AI are also coming under increasing scrutiny, from both consumers and legislators, regarding the transparency of their tools. This ranges from how safe they are to use to where the training data for their systems originates from. This is especially true of already heavily regulated industries, such as the financial...

info_outline
#237 Gap Analysis – The First Step In ISO Implementation show art #237 Gap Analysis – The First Step In ISO Implementation

The ISO Show

When embarking on your ISO journey, a crucial first step is evaluating your current level of compliance and identifying what gaps need to be filled to gain certification or fully align with a Standard. This is typically done by conducting a Gap Analysis. This exercise sets the foundations for your ISO Implementation project, from setting key actions and objectives, to resourcing and establishing a project timeline.   In this episode, Ian Battersby dives into the purpose of a Gap Analysis, who should be involved in the exercise and what inputs and outputs you should expect to have from...

info_outline
 
More Episodes

For those in the automotive industry, namely suppliers working with European OEM’s, you’re likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from.

ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two.

For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don’t intend to certify to both.

In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers.

You’ll learn

·      How does TISAX differ from ISO 27001?

·      How does the recertification / annual surveillance for TISAX and ISO 27001 differ?

·      Can a company have TISAX without ISO 27001 and vice versa?

·      How can an existing ISO 27001 certification be leveraged for TISAX?

·      What are the additional benefits of implementing both TISAX & ISO 27001?

·      What is a reasonable timeframe for implementing TISAX?

·      The key role of Internal Audits

·      How can Blackmores support companies in implementing TISAX?

Resources

·      Register for our TISAX webinar here

·      ENX

·      Isologyhub

 

In this episode, we talk about:

[02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.  

[03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association.

It’s based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers.

[04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry.

ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations.

The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them.

[05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle.

TISAX does not require an annual Surveillance like ISO 27001, instead once you’ve earned a Label it remains valid for 3 years.

ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit.

If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal.

Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label.

[07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you’re ready for re-certification.

You can of course carry on with annual internal audits to make sure you’re on track.

This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.  

[08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other.

Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised.

However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it’s worth considering implementing both TISAX and ISO 27001.

[09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you’re already 80% of the way there to TISAX compliance.

As TISAX is based off of ISO 27001’s Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for:

·      Data Protection

·      Prototype protection

·      Assets

·      3rd Party Suppliers

The amount of additional work will also depend on the TISAX Level you’re aiming for, with Level 3 being the most demanding for these specific requirements.

[10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include:

Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations.

Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what’s required to earn and keep both your ISO certificate and TISAX Label.

Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM’s to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident.

Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX.

[12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc.

The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you’re ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check.

If you already have ISO 27001 in place, than you’re looking at between 3 – 6 months.

If you do not have ISO 27001 in place than you’re looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it’s all been communicated and the relevant individuals have been trained.

Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment.

Emma’s top tip: Be honest in your self-assessment. It’s there to be a benchmark, and you need to reflect on the reality of your position if you’re to accurately assess what Level you are ready to be assessed against.

[14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001.

The Leadership ultimately drive TISAX’s success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label.

For those within the Automotive Sector, TISAX is becoming an absolute requirement. It’s being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label.

[16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you’re on the right path.

They can help identify areas which may be non-conforming or simply highlight opportunities for improvement.

For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.  

[18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step.

This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards.

Other options include:

·      Assisting with your TISAX self-assessment (aka a Gap Analysis)

·      Conducting a Maturity Assessment

·      Conducting internal audits

·      On-site support during your TISAX assessment audit

We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you.

[21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we’ll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment.

Attendees will also get access to some freebies. So don’t delay, register your place here today.

We’d love to hear your views and comments about the ISO Show, here’s how:

     Share the ISO Show on Twitter or Linkedin

     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List