
Technology
Hurrah, we get to audit again
Dreading an ISO audit or TISAX assessment? There's another way. Jürgen explains how to get a team excited about it.
Jürgen, let's start with the obvious: you led us successfully through the ISO audit. What's your role in that process?
The first thing is getting the mindset right. When people hear "ISO audit" or "TISAX assessment," the hair on the back of their neck often stands up, and all they want to do is run for the door. It sounds like work, like bureaucracy, like "now I'm being tested." My biggest personal challenge is changing that perspective. What it should really sound like is: hurrah, we get to audit again. This is a huge opportunity to step back, take a systematic look at our everyday work, and actually improve it.
What that comes down to is building a mindset that lets you critically question why you do what you do, and understand how it all fits together. I sit in one part of the business and only ever see a slice of the process, one that started long before me and continues long after. That's the real turning point: establishing that broader view and keeping it alive. The rest is homework. You have to be audit-ready, be able to show that you do what you say you do, and track a few metrics that prove your measures are actually moving things in the right direction. Anyone can have the best process documented on paper, but if it stays just that, a piece of paper, it's worthless. We have to keep it alive.
What exactly is ISO 9001, and how is an audit different from an assessment like TISAX?
ISO 9001 is a certification for a company's quality management. Once you pass the review, you receive an official certificate.
TISAX evaluates how well information is protected, particularly in the automotive industry. There's no classic certificate involved. Instead, your results and TISAX labels get uploaded to the secure ENX platform, where you can share them with customers and business partners.
Fundamentally, both aim at the same thing: an external body checks whether you actually meet the standards you claim to meet. The benefit for the customer is simple. If they know we've been assessed, they know we hold a certain standard, and they don't have to ask about every detail themselves. TISAX has a particularly interesting backstory. The car manufacturers joined forces and defined, together, what they expect from their suppliers and their supply chain. That means no single manufacturer has to check our security standards on their own. If you have the assessment result, you can simply say: I have it, you don't need to dig further, we live up to it. The TISAX catalog, by the way, is publicly available. Anyone can download it and run through their own assessment, even just as a self-audit, to see where they stand. I'd recommend that to anyone.
How long have you been doing this, and what's changed over that time?
I've been doing this for roughly two years now. And I'd say something changes almost daily, because every day something new comes up for review and I get to make it better. Sometimes that means we decide to stop doing something altogether. Clearing out old rituals that no longer serve a purpose is genuinely satisfying. There's honestly nothing better than sitting down with colleagues and figuring out what we can improve. That's the whole point of a management system, whether it's ISO or TISAX: you work on the process systematically and consistently, and that's what keeps it alive. There's no such thing as standing still.
How do you prepare yourself and your colleagues for an audit like this?
The first step is taking away some of the fear. A lot of people worry about saying the wrong thing or not having a document ready when asked. I try to reduce that anxiety by walking through the whole thing beforehand. What can I expect in the audit, what are typical questions? It usually comes down to process understanding: what do you actually do, what does your job look like day to day, is there a documented guideline for it, and where can you find it. We also work out concrete examples we can show, so nothing has to be improvised on the spot. Auditors want to see evidence, and if you've prepared well, it goes smoothly.
You don't get a list of questions in advance, but the audit plan does tell you which topics will be covered. It's always a sample check against the full set of requirements. The relevant departments know beforehand that they're up and roughly which topic area they'll be asked about. If you rehearse that once or twice ahead of time, the actual audit tends to go well.
Which departments were involved this time, and what exactly did they cover?
This was our ISO 9001 recertification, which means every three years we go through the full process again and touch on every topic area. In practice, that means nearly every requirement in the ISO catalog gets pulled up somewhere, and every one of our core processes gets checked on a sample basis.
Sales is a great example. Kevin walked the auditor through the entire process, from first contact through the initial inquiry all the way to handing over a proposal. It shows just how complex pre-sales really is. The whole sales cycle can't run on its own, it needs support from delivery, from software consultants and architects who assess requirements and work out a shared risk evaluation to keep project risk in check. It also needs software developers to help estimate a proposal. One of my favorite parts is planning poker, where a group estimates how much effort a requirement will take, everyone votes, the cards get revealed, and each person explains why they estimated high or low. If you're brave enough, you even do this together with the customer. That's when the customer realizes it's not as simple as it looks, questions come up, and trust starts building right there in the sales process. You see the same thing in every department, in recruiting, in project delivery, in the office functions behind it all. There are interesting processes to dig into everywhere.
What does a certification like this actually mean for our customers? Do they ask about it often?
My sense is that these kinds of proof points matter more and more. On top of ISO and TISAX, there's a growing list of regulatory requirements: NIS2, the Cyber Resilience Act, the EU AI Act, and more. Our customers have to meet these legal requirements themselves, and they pass that obligation down to their suppliers, that's the whole idea behind supply chain due diligence laws. For them to deliver, we have to deliver too.
When a customer knows we hold ISO 9001 and TISAX, they know we run solid processes and that we're a company that can adapt to new demands. That builds more trust with the customer, and in the end, it translates into better quality and higher satisfaction.
Is ISO or TISAX standard in our industry, or does it set us apart?
I wouldn't call it standard. A lot of companies shy away from the effort, even though you really only gain from doing it. The main challenge is still getting leadership to fully buy into that thinking, because there's still a tendency to see a certificate as pure cost with no revenue attached. That mindset has historical roots too. In the past, companies would just appoint a quality manager to handle it, and leadership could step back. But this is a leadership topic, and it needs to sit more firmly in everyone's mind, not just management's. That's something we can keep working on too, ourselves included.
The audit is behind you now, the certification is done. What happens in the three years until the next one?
Every three years brings the big recertification, and in between, ISO 9001 requires an annual surveillance audit. TISAX doesn't work that way, there the review really only happens once every three years. But that doesn't mean things stand still for us. We run our own internal audits, and more importantly, we keep a management system alive that we all work on with common sense. That means stepping back to reflect on what isn't working well, developing new strategies and quality goals, and sometimes defining new metrics to see whether we're actually moving in the right direction. That's our daily job. We're committed to reviewing our processes at least once a year and checking whether our strategy and our actions still hold up.
How relieved are you that the audit is over?
Very, honestly. I'm glad we're on a good path, and the auditor confirmed that too. And at the same time, one thing is done and the next is already waiting: TISAX is our next challenge. We're starting preparations now, even though some of the improvement measures for it have already been underway for a while. We're preparing deliberately so we can walk into the next reassessment with confidence and show, transparently, what we deliver.
Anything else you'd want to tell the outside world about ISO or TISAX?
ISO and TISAX aren't a bureaucracy monster, and they're not busywork. They're genuinely useful, they're best practice, a structured way to hold yourself accountable. My biggest joy would be feeling that same spirit across the team: hurrah, we get to audit ourselves again, we get to figure out what we can improve. That's when my heart really lifts.
Über Jürgen
Jürgen ist unser InfoSec & Quality Navigator. Er unterstützt unsere Teams dabei, Qualität, Informationssicherheit und moderne Technologien praxisnah miteinander zu verbinden. Sein Ziel ist es, aus Vorgaben und Standards echten Mehrwert zu schaffen: verständlich, pragmatisch und immer mit Blick auf Menschen, Prozesse und nachhaltige Verbesserungen.
