
TISAX
Case Study
Find out how AKRUP helped a leading automotive logistics company achieve a TISAX AL3 Label across 2 sites in the UK.
Achieve trusted information security compliance for the automotive industry.
Build a robust information security management system and achieve certification.
Implement effective governance and controls for artificial intelligence systems.
Meet cybersecurity requirements for defence contractors and supply chains.
+442037377611
Project Overview
Rudolph & Hellmann got requested to achieve TISAX AL3 in the next 12 months and contacted AKRUP for help. Over a 12-month engagement, AKRUP partnered with R & H Automotive to design and implement a TISAX-compliant Information Security Management System (ISMS). Working alongside senior management, IT, HR and operational teams, we successfully prepared the organisation for an AL3 audit, resulting in the achievement of TISAX AL3 labels for two UK locations.

Project Duration: 12 months
Industry: Automotive Logistics
Framework: TISAX AL3
Outcome: Successfully achieved TISAX AL3 Labels Across 2 Locations.
The Challenge
Achieving TISAX isn't just about writing a few policies or passing an audit. It means putting the right security measures in place across the whole business, making sure employees understand their responsibilities, and being able to prove everything with evidence.
RH Automotive wanted to achieve TISAX Assessment Level 3 for two UK locations, so they needed support building the right processes, improving security where required, and preparing for a detailed audit.
Over the course of the project, we worked closely with their teams to make sure everything was implemented properly and that they were fully prepared when the audit arrived.
Our Approach
We worked alongside RH Automotive throughout the project rather than simply handing over templates or documents. Our role was to guide the business step by step, helping different departments understand what was needed and putting practical solutions in place that worked for the way they already operated.
This included working with the IT team to improve technical security, supporting HR with employee processes, helping management understand their responsibilities, delivering staff awareness training, carrying out risk assessments, and preparing all of the evidence needed for the final audit.
By the time the assessment took place, the business had everything in place to confidently demonstrate that it met the requirements for TISAX Assessment Level 3 across both UK locations.
What we delivered
Information Security Management System
Designed and implemented an ISMS aligned with TISAX requirements.
Risk Management
Performed organisation-wide risk assessments and produced a detailed risk treatment plan to address identified risks.
Security Awareness
Produced a bespoke TISAX security awareness training video and delivered training sessions to relevant employees.
Physical Security
Reviewed existing physical security arrangements and recommended improvements to meet AL3 requirements.
Asset Management
Developed and documented a comprehensive asset register with ownership, classification and lifecycle controls.
Information Classification
Supported internal projects with information classification and risk assessments aligned to TISAX expectations.
Security Best Practice
Provided ongoing consultancy on implementing effective information security controls throughout the organisation.
Human Resources
Aligned HR processes with TISAX controls, including employee lifecycle, onboarding and offboarding requirements.
IT Security
Worked closely with the IT department to ensure systems, infrastructure and technical controls met TISAX expectations.
Data Protection
Supported GDPR compliance and advised on privacy controls required alongside the TISAX implementation.
Internal Audit
Performed a full TISAX internal audit to verify readiness before the external assessment.
On-site Audit Support
Provided on-site support throughout the Assessment Level 3 audit, helping R & H Automotive successfully achieve AL3 labels at both UK locations.
Supplier Security
Provided guidance on supplier due diligence, vendor risk assessments and ongoing supplier management.
Executive Engagement
Delivered regular management briefings and worked closely with key stakeholders throughout the project lifecycle.
Audit Preparation
Collected and organised audit evidence while producing a complete documentation package for the external assessor.
Project Outcome
Following twelve months of collaborative work, RH Automotive successfully achieved TISAX Assessment Level 3 labels for two UK locations.
The project delivered more than certification. RH Automotive now benefits from:
-
A mature Information Security Management System
-
Improved organisational risk management
-
Stronger technical and physical security controls
-
Increased employee security awareness
-
Better supplier governance
-
Improved GDPR alignment
-
Greater confidence when working with automotive manufacturers and supply chain partners
-
A sustainable framework for continual improvement

Why AKRUP?
AKRUP has built a proven track record of helping organisations achieve successful compliance outcomes across recognised security and assurance standards. With experience supporting clients worldwide, we understand what it takes to move from uncertainty to audit-ready confidence.
Our 100% project success rate reflects the quality of our delivery, the strength of our expertise and our commitment to getting results right the first time. Businesses choose AKRUP because we provide clear direction, practical guidance and reliable support that helps turn compliance into a competitive advantage.
What our clients say

Speak With Our Experts
Discuss your TISAX requirements with one of our specialists. Complete the form below and we'll help you plan your route to successful TISAX implementation.
Looking to achieve TISAX? Complete the form and one of our consultants will contact you to discuss your requirements and next steps.
Strategic cybersecurity leadership without the cost of a full-time CISO.
DPO
Data protection expertise to help manage privacy obligations and regulatory compliance.
Internal Audits
Independent audits to assess compliance, identify gaps, and support continual improvement.
Training
Practical security and compliance training to build awareness and strengthen organisational capability.
Policy Development
Consultancy
Develop clear, effective policies and procedures aligned with industry standards and business needs.
Expert guidance and hands-on support for cybersecurity, compliance, and governance initiatives.
+442037377611


