Asia
Hong Kong
Support for clients across China, South East Asia, South Asia, Central Asia and the Middle East, in English and Chinese.
01 / Overview
RASOO Certification Consulting focuses on TISAX consulting, coaching, gap analysis, management system development, assessment-day support and corrective action support for automotive supply chain companies worldwide. Our clients include component manufacturers, software development companies, engineering service providers, electrical and electronic suppliers, testing laboratories, logistics providers, and cloud and data processing companies — all of whom need to meet vehicle manufacturer and Tier-1 requirements for information security, prototype protection and data compliance.
TISAX is an information security assessment mechanism widely recognised in the automotive industry. More and more vehicle manufacturers and large suppliers ask their partners to obtain a TISAX label. For companies planning to enter the European automotive supply chain, take part in OEM tenders, or handle development data, prototype parts, test data or sensitive commercial information, a TISAX label has become one of the key conditions of entry.
RASOO uses a professional, systematic and efficient consulting method to take clients from a standing start to a completed TISAX assessment — reducing the difficulty of preparation, shortening the preparation cycle and helping to reduce the risk of findings during the assessment.
02 / About Us
RASOO Certification Consulting works with a number of certification and assessment bodies, and maintains companies and representative offices in the Asian region (Hong Kong), the European region (the United Kingdom) and the North American region (the United States). Our core business is TISAX certification consulting.
RASOO is a consulting firm. Assessments themselves are carried out by audit providers accredited for that purpose — never by your consultant.
Asia
Support for clients across China, South East Asia, South Asia, Central Asia and the Middle East, in English and Chinese.
Europe
Support for European projects, OEM and Tier-1 requirement interpretation, and European time-zone coordination.
North America
Support for North American sites and for groups running assessments across several regions at once.
RASOO provides remote consulting to clients in different countries and regions without geographic limits. Online collaboration saves clients both time and cost.
We understand what automotive supply chain customers care about: information security, development data, sample management, prototype protection and confidentiality of customer material — so preparation is aimed at the right places.
We do not stop at writing procedures. We work on how the process actually runs and on the evidence it produces, so the system is genuinely workable.
Every client gets a detailed project plan with tasks, owners and deliverables for each stage, so progress stays visible.
Whether you already run ISO/IEC 27001, IATF 16949 or ISO 9001, or are building an information security system for the first time, the coaching plan is built around where you actually are.
For international projects we support documents, training, meetings and assessment preparation in both English and Chinese, so cross-border teams stay aligned.
03 / Who we serve
Wherever your company sits — China, South East Asia, Europe, the Americas or elsewhere — RASOO can support you through remote consulting and online project management.
Third-party company names above are used only to describe the type of supply chain project a client may be preparing for. They are trademarks of their respective owners, and no affiliation, endorsement or partnership is implied.
04 / Services
Each one can be bought on its own, or run as a single project from scoping through to label.
Step 1
Before anything is written, we work out what actually has to be assessed: objectives, sites, level and audit mode. Getting this wrong is the most expensive mistake in a TISAX project.
Step 2
We review your current information security management against the VDA ISA requirements and hand back a plain answer to four questions: what is missing, how to fix it, who owns it and when it is due.
Step 3
We build the information security documentation set that TISAX preparation calls for — adapted to your structure, processes and IT environment rather than dropped in from a template.
Step 4
Meetings, interviews, document review, training and evidence checks all run online. No repeated site visits to host, no travel budget to defend.
Step 5
Assessors look at what you did, not only at what you wrote. We assemble the evidence pack, then run a rehearsal so the first hard question is not asked on assessment day.
Step 6
We stand behind you during the assessment and stay until every open point is closed and the label process is complete.
05 / Scope
RASOO's TISAX consulting covers the whole preparation process. The three blocks below set out the detail behind the headline services.
We look at your organisation size, business type, customer requirements, the kinds of information assets you hold and your assessment goal, then help you decide the right assessment scope and level. This covers confirmation of information security assessment objectives, judgement of prototype protection requirements, identification of data protection requirements, definition of the assessment scope boundary, analysis of which sites and locations belong in scope, whether AL 2 or AL 3 applies, whether on-site or remote assessment support is required, and how customer requirements map onto your actual business.
Getting this right at the start prevents the three classic problems: the wrong scope, an unnecessary or insufficient level, and preparation aimed in the wrong direction.
Based on the VDA ISA requirements, we carry out a full gap analysis of your current information security management and identify the distance between where you are and what TISAX preparation requires.
The output is a clear remediation list and implementation road map, so the whole team knows what is still missing, how to fill it, who is responsible and when it has to be finished.
Documents are customised to your real situation. Templates that stay generic tend to fail the moment an assessor asks how the process actually runs, so we adapt each one to your structure, processes, IT environment and assessment objective.
Following the gap analysis, we help you build and run the management processes and technical controls that TISAX preparation calls for. The working principle is simple: it has to be executable, it has to produce evidence, and it has to hold up during the assessment.
06 / Process
The order matters: each step produces the input the next one needs.
Our consultants hold a kick-off meeting with you to confirm the certification goal, customer requirements, business scope, sites involved, assessment level, project timeline and the responsibilities of both sides.
Deliverables Project plan · task and owner matrix · schedule · required document list · recommended certification route
We help you understand and complete the preparation around the TISAX platform: organisation registration preparation, assessment scope confirmation, assessment objective selection, advice on selecting an audit provider, support in discussing audit quotations, and coordination of the assessment plan.
The point is to set the right route from day one, so that registration details, scope or objective choices do not create risk later in the assessment.
A TISAX assessment is normally based on the VDA ISA questionnaire. We take you through the requirements item by item and guide the self-assessment: interpretation of each control, how the maturity scoring works, what evidence is needed, where the risk points are, how to design improvement measures, and how to complete the self-assessment sheet.
The aim is that your team understands the assessment logic behind each requirement, rather than simply filling in a form.
Based on the gap analysis, we help you establish and put into practice the management processes and technical controls required — from asset classification and risk assessment through access approval, visitor control, supplier requirements, training and incident reporting, to prototype handling and mobile device security.
We work to the principle that a control must be executable, must produce evidence and must survive an assessment, which avoids the common trap of documents without implementation.
During the assessment, the assessor examines not only your documents but also the evidence that they were followed. We help assemble the complete evidence pack: training records, risk assessment records, asset inventories, permission approvals, supplier evaluations, backup tests, vulnerability or patch records, incident drills, visitor registers, door access lists, confidentiality agreements, internal audit and management review records, prototype protection checks and corrective action tracking.
Everything is checked for completeness before the assessment so your team can answer with confidence.
Before the formal assessment we can run a mock audit: a clause-by-clause check against VDA ISA, simulated interviews with management, IT and business departments, sampling of documents and records, on-site or remote evidence checks, prediction of potential findings, and a question-and-answer rehearsal.
Afterwards you receive a problem list with remediation advice, so the last round of optimisation happens before the assessor arrives.
During the assessment itself we can provide accompanying support: a preparation meeting, organisation of assessment material, coaching on answering questions, help interpreting what the assessor is asking, judgement on the risk behind potential findings, background support through the assessment days, and a review afterwards.
The goal is straightforward — that your team faces the assessment with more confidence and better organisation.
If findings or improvement requirements come out of the assessment, we support root cause analysis, corrective action planning, additional evidence and closure: cause analysis, corrective measures, assignment of responsibility, evidence preparation, writing the response documents, communication support with the audit provider, closing the open points, and support through the process of obtaining the TISAX label.
07 / Outcomes
08 / Timing
Many companies only begin preparing for TISAX once a customer has already asked for it. That usually means a short deadline, missing records, incomplete processes, unfamiliar staff and IT controls that are not yet in place. When preparation is thin, the assessment can be delayed, remediation drags on, and in some cases the customer project itself is affected.
Starting earlier helps you:
09 / Coverage
Remote delivery means our service area is not limited by where our offices sit. Select a region to see the countries and territories covered.
Asia — 48 countries
Europe — 44 countries and 2 territories
Africa — 54 countries and 7 territories
North America — 23 countries and 17 territories
South America — 12 countries and 2 territories
Oceania — 16 countries and 8 territories
Contact RASOO for an initial discussion and advice on your certification route, at no charge. We can help you work out whether TISAX applies to you, confirm a suitable assessment objective and scope, assess your current gaps, build an implementation plan, coach your team remotely through preparation, support the formal assessment and close corrective actions — through to obtaining the TISAX label.
RASOO Certification Consulting — making TISAX preparation clearer, faster and easier to control.
Two versions of our summary
English
RASOO provides professional global TISAX consulting services for automotive supply chain companies. Through remote consulting, gap analysis, documentation support, VDA ISA self-assessment guidance, mock audits, audit support and corrective action assistance, we help clients efficiently prepare for TISAX assessments and obtain TISAX labels. Our services are suitable for automotive suppliers, software developers, engineering service providers, prototype manufacturers, testing service providers and companies handling confidential customer information.
中文
RASOO 咨询公司专业提供全球 TISAX 认证咨询服务。我们通过远程辅导、差距分析、体系文件建设、VDA ISA 自评估指导、模拟审核、正式审核陪跑及整改支持,帮助汽车产业链企业高效完成 TISAX 认证准备并获取 TISAX Label。无论您是零部件制造商、软件开发商、工程服务商,还是原型件、测试数据或客户机密信息的处理方,RASOO 都可以为您提供专业、灵活、高效的认证咨询方案。
10 / Contact Us
Send the form, or message the office for your region directly on WhatsApp or by email.
Asia
WhatsApp+852 6660 8230
Emailasia@rasoogroup.com
English and Chinese · Hong Kong time