The ISO Show
There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It’s estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it’s operational. It’s undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those...
info_outlineThe ISO Show
AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped. So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business. In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some...
info_outlineThe ISO Show
The path towards becoming an ISO consultant is often a meandering one. It’s not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We’re continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification. In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they’ve found their first...
info_outlineThe ISO Show
Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn’t necessarily formally recognised until the 1970’s here in the UK. Health & Safety often gets mocked for overly cautious or seemingly onerous tasks to meet certain regulations and Standards today, however these are in place for a reason. They save lives, plain and simple. In this episode, Ian Battersby makes the case for Health & Safety regulations, including why they were introduced, events that sparked the conversation for workplace safety and the impact regulations have...
info_outlineThe ISO Show
Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There’s a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode...
info_outlineThe ISO Show
Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The drivers for this demand are varied, as is the approach many take for their path towards carbon verification. This can look very different depending on the industry you operate in and can be difficult to tackle for more service based industries, such as today’s guest, Davies Group, who are a service provider for the insurance industry. In this episode Mel is joined by Gillie Fairbrother, Global Responsible Business Officer...
info_outlineThe ISO Show
How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That’s not surprising as it’s quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide. We’re continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification. In this episode we introduce Steve Mason, a Principle isologist® at Blackmores, to share the journey of how he went from...
info_outlineThe ISO Show
Most ISO Standards are designed with implementation flexibility in mind. They set the framework without specifying an exact method to meet requirements, giving businesses the freedom to implement them how they see fit. One of the key requirements you can’t escape, however, is documentation. This is more than a list of key documents you must have in place, it encompasses how you develop, control and store documented information. In this episode, Ian Battersby dispels common myths around documentation in ISO, explains what the requirements actually mean in practice and how you address each...
info_outlineThe ISO Show
Most ISO Standards take what’s known as a ‘risk-based approach’, which focuses on proactively identifying and mitigating potential risks while capitalising on opportunities. The methods for managing risk can be very varied, and many make the mistake of treating it as a separate task rather than as an integrated part of your existing processes. In this episode, Ian Battersby explains what risk management means in regard to ISO management, what this looks like in practice and breaks down different methods you can utilise for effective risk management. You’ll learn ...
info_outlineThe ISO Show
Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year. The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams. Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do...
info_outlineFor those in the automotive industry, namely suppliers working with European OEM’s, you’re likely familiar with TISAX but not necessarily with the Standard that many of its requirements originate from.
ISO 27001 is the leading Information Management Standard, and its Annex A forms the basis of TISAX, however there are many differences between the two.
For Automotive suppliers looking to create a more holistic Information Security Management System, it can be beneficial to implement elements of both even if you don’t intend to certify to both.
In this episode, Ian Battersby is joined by Emma Coxhill, isologist at Blackmores, to explore the differences between TISAX and ISO 27001, how existing ISO 27001 compliant management systems can be leveraged for TISAX compliance and the benefits of implementing both Standards for automotive suppliers.
You’ll learn
· How does TISAX differ from ISO 27001?
· How does the recertification / annual surveillance for TISAX and ISO 27001 differ?
· Can a company have TISAX without ISO 27001 and vice versa?
· How can an existing ISO 27001 certification be leveraged for TISAX?
· What are the additional benefits of implementing both TISAX & ISO 27001?
· What is a reasonable timeframe for implementing TISAX?
· The key role of Internal Audits
· How can Blackmores support companies in implementing TISAX?
Resources
· Register for our TISAX webinar here
· ENX
In this episode, we talk about:
[02:05] Episode Summary – Emma Coxhill joins Ian to dive into the key differences between ISO 27001v Information Security and TISAX, including the benefits of implementing both and how each can be leveraged to assist in the implementation of the other.
[03:10] What is TISAX? TISAX was developed for the automotive industry by the German Association of the Automotive Industry, VDA, and it's managed by the ENX Association.
It’s based on the ISO 27001 Annex A controls, and was created for the automotive industry because they were looking to standardise the framework for assessing and sharing information security results between manufacturers and their suppliers.
[04:20] How does TISAX differ from ISO 27001? ISO 27001 is a general Information Security management Standard, it can be applied to any business, whereas TISAX is only applicable to the automotive industry.
ISO 27001 includes a framework of requirements that everyone must implement, whereas TISAX has a more customisable element. With TISAX you can select an applicable level and relevant subject areas for your operations.
The last main difference is the fact that ISO 27001 certification ends in a certificate which can be shared and displayed wherever you want. TISAX in comparison has Labels, which are only available through the ENX portal where you have control over who can access them.
[05:15] How does the recertification / annual surveillance for TISAX and ISO 27001 differ? The good news is that TISAX is a bit more forgiving than ISO when it comes to a recertification cycle.
TISAX does not require an annual Surveillance like ISO 27001, instead once you’ve earned a Label it remains valid for 3 years.
ISO 27001 in comparison requires an annual Surveillance for each year until the 3rd when you have your Recertification Audit.
If you have a significant change to scope part way through your 3 years of TISAX, you will need to have a chat with your auditor to see if extra work is required. This will depend on your level, with higher levels likely to require some additional work and for you to adjust your scope within the ENX portal.
Overall, a TISAX label is less of a burden than traditional Management System Standards like ISO 27001. However, TISAX is a lot more strict and will require more upfront preparation ahead of earning your Label.
[07:30] Are Internal Audits required for TISAX? They are, but the amount and frequency are a lot more flexible than ISO 27001. You can do as many as you like, but at a bare minimum we recommend you conduct internal audits 6 months ahead of your TISAX label expiring to ensure you’re ready for re-certification.
You can of course carry on with annual internal audits to make sure you’re on track.
This can be handy if specific clients ask for further evidence of you following processes in accordance with TISAX requirements.
[08:35] Can a company have TISAX without ISO 27001 and vice versa? You can! Both are independent Standards, however they do compliment each other.
Organisations that hold both have a competitive advantage, as ISO 27001 applies to all industries and is more widely recognised.
However, if you only operate in the automotive space, TISAX may be sufficient. If you supply to multiple sectors, it’s worth considering implementing both TISAX and ISO 27001.
[09:25] How can an existing ISO 27001 certification be leveraged for TISAX? If you already hold an existing ISO 27001 certification, than you’re already 80% of the way there to TISAX compliance.
As TISAX is based off of ISO 27001’s Annex A controls, a lot of the requirements cross over, so you will already have most of the foundations in place to cover TISAX. It will just be the more automotive specific requirements that will require some additional work. These requirements include considerations for:
· Data Protection
· Prototype protection
· Assets
· 3rd Party Suppliers
The amount of additional work will also depend on the TISAX Level you’re aiming for, with Level 3 being the most demanding for these specific requirements.
[10:55] What are the additional benefits of implementing both TISAX & ISO 27001? Benefits include:
Robust Information Security – Having both TISAX and ISO 27001 forms a strong and versatile information security infrastructure that will cover all of your operations.
Easy Integration – These two Standards complement each other, and can easily be integrated. If you already have ISO 27001 in place, you have already completed a majority of the framework and will be familiar with what’s required to earn and keep both your ISO certificate and TISAX Label.
Customer Trust and Long-Term Resilience – TISAX is desired, if not an outright requirement for European based OEM’s to work with suppliers. They require this because TISAX is a trusted Standard, a Label displays your commitment to information security within the automotive industry. It also helps to put you in a better position to both safeguard data as well as respond in the event of a data / security incident.
Wider market access – If you supply to more than just the automotive industry, than having ISO 27001 in place will grant you access to the wider market that will recognise that Standard over TISAX.
[12:05] What is a reasonable timeframe for implementing TISAX? This will depend on a number of factors including the type of organisation, the number of sites, resources available etc.
The key thing to note is that this is note a 2 week project, it will take a number of months to get everything in place for your external assessment. A good measure of if you’re ready is if you can score at least more than 2.71 on your self-assessment, and have completed a few internal audits to double check.
If you already have ISO 27001 in place, than you’re looking at between 3 – 6 months.
If you do not have ISO 27001 in place than you’re looking at 6 months minimum. For Level 2, you will need proof that ,you have everything in place, it’s all been communicated and the relevant individuals have been trained.
Level 3 requires everything to be in place and operating for a certain amount of time, typically around 3 months is ideal to start building a library of evidence ahead of your external assessment.
Emma’s top tip: Be honest in your self-assessment. It’s there to be a benchmark, and you need to reflect on the reality of your position if you’re to accurately assess what Level you are ready to be assessed against.
[14:20] Core elements for success: As with any Standard, ISO or otherwise, TISAX will require leadership commitment in order to be successful. The requirements of TISAX need to come from the top down, just like with ISO 27001.
The Leadership ultimately drive TISAX’s success, by ensuring the relevant resources are in place, and involved individuals have the necessary time to implement and maintain the Label.
For those within the Automotive Sector, TISAX is becoming an absolute requirement. It’s being pushed as a tender requirement, so you may lose out on business if you opt to not earn a Label.
[16:35] The key role of Internal Audits: As mentioned earlier, Internal Audits are a key part of the process for both TISAX and ISO 27001. It acts as a business health check to ensure you’re on the right path.
They can help identify areas which may be non-conforming or simply highlight opportunities for improvement.
For TISAX, there is not outright requirement for 3rd party audits ahead of your assessment, however we would recommend them as a fresh pair of eyes can reveal things you may have overlooked. An external auditor will also be more unbias and can provide an honest review and feedback as to what TISAX Level you are ready for.
[18:25] How can Blackmores support you with TISAX Implementation?: We can provide as little or as much support as needed. This can include a fully guided implementation where we assist you through each step.
This can apply to both TISAX and ISO 27001 if you wish to certify to both Standards.
Other options include:
· Assisting with your TISAX self-assessment (aka a Gap Analysis)
· Conducting a Maturity Assessment
· Conducting internal audits
· On-site support during your TISAX assessment audit
We are happy to provide whatever level of support you need. Blackmores do not provide a tick-box exercise, we pride ourselves on ensuring an implemented system works for you.
[21:10] Upcoming TISAX Webinar – Join us on the 18th March 2026 at 2pm for a webinar where we’ll dive into TISAX further and provide practical guidance on how to complete the VDA Self-Assessment.
Attendees will also get access to some freebies. So don’t delay, register your place here today.
We’d love to hear your views and comments about the ISO Show, here’s how:
● Share the ISO Show on Twitter or Linkedin
● Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List