Approach

Approach

Four stages. Fixed order. Documented output at each step.

The same method is used for TISAX, NIS2 and OT security engagements. Each stage ends with a deliverable your management and your assessor can read. Durations below are typical for a single site.

STAGE 01 · 2–4 WEEKS

Assessment

Scope is fixed: sites, systems, assessment level. Controls are reviewed against the ISA catalogue or NIS2 measures through interviews, document review and a walk of the plant network. Output: assessment record and scope statement.

STAGE 02 · 1–2 WEEKS

Gap Analysis

Each control receives a maturity rating and a finding. Findings are ranked by audit risk and implementation effort. Missing evidence is listed separately from missing controls. Output: gap report reviewed with management.

STAGE 03 · 3–8 MONTHS

Remediation Roadmap

A sequenced plan with owners, milestones and budget. Policies and procedures are written, technical controls implemented with your IT and plant teams, and evidence is collected as work completes. Output: closed findings with evidence.

STAGE 04 · AUDIT WINDOW

Audit Support

The evidence package is assembled and rehearsed with your team. During the assessment the consultant is available on site or on call. Corrective actions after the assessment are tracked to closure. Output: label or compliance record.

Tooling

Tooling

Where AI tooling fits in the method

AI-assisted tooling is used in two places: reading and cross-referencing existing documentation during the assessment, and triaging gap findings against the catalogue during analysis. It shortens document review from weeks to days. It does not replace interviews, plant walks or the assessor’s judgement, and no client data is sent to shared models.

WHY AUDIT WORK COMES FIRST

Audit and compliance work requires deep visibility into a client’s systems, processes and owners. That same visibility is what makes automation safe and accurate to build afterwards: the data sources are known, the controls are defined, and the people who sign off are already involved. A vendor arriving with automation first has none of this and has to guess. Automation Readiness is therefore offered only after the foundation is in place.

Comparison

Comparison

People who have held these roles, not a rotating audit team

BENCHMARK

PURE-AUDIT FIRM

GENERIC IT CONSULTANCY

SOURCEGROUND

Who does the work

Junior auditors with a checklist, partner reviews at the end.

Project staff without plant or assessment experience.

A former Tier-1 Senior IT/OT Lead and a Lead IATF auditor, personally on every engagement.

Output

A findings report. Remediation is your problem.

Technical changes without a mapping to what the assessor checks.

Findings, remediation, evidence package and assessment support in one scope.

Production impact

Not considered.

Office-IT assumptions applied to machine networks.

Changes planned around shifts and maintenance windows, IATF 16949 context understood.

Automation

Not offered.

Offered first, before the controls or data sources are understood.

Offered second, once evidence, owners and systems are already mapped.

Create a free website with Framer, the website builder loved by startups, designers and agencies.