VDA ISA 6 and TISAX are not the same thing
The Information Security Assessment (ISA) is the requirements catalogue provided by the ENX Association. Organizations can use it for self-assessment, and it provides the substantive basis for assessments within TISAX.
TISAX is the standardized mechanism for registering an assessment scope, commissioning an approved audit provider and sharing results selectively with business partners. TrustRespond does not perform TISAX assessments or issue TISAX labels.
ISA 6 is mandatory for new TISAX assessments ordered since 1 April 2024. A new scope should therefore not use ISA 5.1 as its target baseline.
Completing the questionnaire is not the hardest part
The real work happens before an answer is written. One question may involve policy, process, technical implementation and ownership. A positive answer is defensible only when the underlying practice actually applies to the assessed scope.
Automotive suppliers often keep evidence across ISMS policies, access concepts, incident processes, supplier reviews, training records, meeting minutes and old customer questionnaires. Without controlled mapping, teams create contradictions or claims stronger than their evidence.
- Describe the current state, not the intended future state.
- Evidence must apply to the concrete scope and location.
- Similar questions are not automatically equivalent.
- Missing evidence is a work item, not permission to invent plausible language.
A defensible six-step workflow
1. Fix scope and assessment objectives
Clarify locations, processes, protection objects and requested labels before collecting documents.
2. Use the ISA structure as an operating model
Group questions by control, owner and evidence type while preserving the original workbook as the exchange format.
3. Build a source register
Record document, version, applicability, owner and relevant passage. Draft or obsolete policies are not silent evidence.
4. Draft answer and evidence together
Show the proposed statement, supporting source and uncertainty side by side so reviewers assess substance, not only wording.
5. Escalate gaps deliberately
When a source supports only part of a question, route the uncovered part to the responsible expert.
6. Approve and version as a human
Security, IT, privacy or management approves the external claim and records the sources used.
What stronger evidence usually looks like
A policy establishes an expectation but does not automatically prove operating effectiveness. Review-ready answers often need both normative documentation and operational evidence.
- Approved policy plus owner and review cycle
- Process description plus ticket, log or sample
- Access-control concept plus current access review
- Incident-response plan plus exercise evidence or lessons learned
- Supplier process plus documented risk assessment
- Training requirement plus current participation or effectiveness records
Where AI helps — and where it must stop
AI can cluster questions, retrieve relevant passages, suggest previously approved answers and prepare first drafts. The value is less expert time spent searching and repeating work.
It cannot invent missing implementation, define the assessment scope or claim TISAX conformity. Similarity and confidence scores never replace a professional decision about whether a source supports the exact statement.
A controlled workflow therefore presents sources, confidence and missing evidence together. Its strongest behavior is not an automatic yes, but an early and visible not yet evidenced.
Common mistakes before assessment
- Copying old customer answers after systems or providers changed
- Applying a group policy to a location without checking local operation
- Describing planned remediation as an implemented control
- Collecting documents without passages, owners or applicability
- Completing cells while leaving expert decisions unresolved
- Treating software as a substitute for an approved audit provider
A practical definition of done
A question is review-ready only when another person can understand the claim, its evidence, its scope and the person who approved it.
- The answer is precise and avoids unsupported absolutes.
- The source and relevant passage are identified.
- Document version and applicability are current.
- Partial coverage and deviations remain visible.
- Owner and approval status are recorded.
- Export preserves the original workbook structure.
Frequently asked questions
Is TISAX a certification?
ENX describes TISAX as an assessment and exchange mechanism. TISAX labels result from the TISAX process with an approved audit provider; TrustRespond does not issue certificates or labels.
How long are TISAX labels valid?
The current ENX Participant Handbook states that TISAX labels are generally valid for three years. Significant scope changes can affect validity.
Can generative AI complete the VDA ISA questionnaire autonomously?
It can accelerate drafting and source mapping. Scope, actual implementation, gap evaluation and final approval remain human responsibilities.
What should happen when evidence is missing?
Mark the question as missing evidence and route it to the accountable owner. Plausible language must not conceal absent implementation.
Test a real VDA ISA sample with source evidence
The free pilot covers up to 50 anonymized questions. Confidential documents are not requested by ordinary email; secure upload instructions follow separately.
Official sources
Editorial note: checked against the official ENX sources on 24 July 2026.
