For networks and groups
Automotive network audits
Five dealers in one country or fifty in ten — one methodology, one consolidated report for head office.
Who it is for
- An importer or national head office responsible for a network of dealers and workshops that needs to know where the network stands — not dealer by dealer, but as a whole.
- A manufacturer or group with its own requirements for handling customer data and system access that wants them verified across the network.
- An automotive supplier that has to demonstrate information security to its customer — see TISAX.
Automotive today deals at once with customer data protection, supplier information security (TISAX), the cybersecurity of vehicles and their environment (ISO/SAE 21434, UNECE R155) and requirements for products with digital elements (Cyber Resilience Act). The dealer and workshop network is where these topics meet day-to-day operations — and where head office sees the least.
Why it works across countries
An internal audit or supplier audit under the GDPR or ISO/IEC 27001 is not tied to an authorisation in a particular country — unlike an audit under the laws transposing NIS2, where each state decides separately who may audit. That is why we can audit a network across countries with one programme. For NIS2, see the country table on NIS2 by country.
How the programme runs — five steps
- Framework. With head office we define what is verified: GDPR requirements, selected ISO/IEC 27001 controls, manufacturer standards or group policies.
- One checklist and one scale for every entity — so the results can be compared.
- Audits on site or remotely, in the local language or in English.
- A report for each entity and a consolidated report for head office on the same scale — where the network is strong and where findings repeat.
- Verification of corrective actions after an agreed period.
Four modules (can be combined)
- GDPR — customer data in sales and service systems, cameras in the showroom and workshop, marketing consents, processor agreements, information duties.
- ISO/IEC 27001 — internal audit under clause 9.2 or supplier audit against selected Annex A controls.
- Manufacturer standards — manufacturer or group requirements for data handling, system access and operational security.
- Cybersecurity of the automotive environment — access management for diagnostic systems, service technician accounts, access to manufacturer systems, update management and selected requirements of UNECE R155, ISO/SAE 21434 or internal manufacturer standards. We verify processes in the network — not vehicle type approval or product conformity.
What repeats across networks
- active accounts of former employees,
- shared login credentials in the workshop,
- undocumented access by external mechanics and suppliers,
- missing processor agreements,
- customer data stored locally outside the systems,
- different security levels between countries of the same network.
Three levels, one report
The manufacturer sets the standard, the importer is responsible for the network in its country, the dealer processes customer data. Each level has different obligations — the programme verifies them at once and head office sees every country on the same scale.
What head office gets
One programme instead of separate audits: comparable results across countries on one scale, corrective actions planned once for the whole network, and a scope that can be staged — from a sample of dealers to the entire network.
Where we audit
In eight countries — Slovakia, Czechia, Poland, Hungary, Austria, Germany, Romania and Greece — the audit is carried out by a member or partner of the IOSEC group. In other countries it is carried out by a local partner under our programme and our management.
What this programme is not
- It is not a certification audit — an ISO/IEC 27001 certificate is issued by an accredited certification body; a TISAX assessment is performed by an ENX-accredited provider.
- It is not a NIS2 audit — there, authorisation in each country decides; see NIS2 by country.
- We do not assess vehicle type approval or product conformity under the Cyber Resilience Act — we verify processes and access in the network.
- An entity whose system we implemented is not audited by the same team.
The same programme for other networks
The programme is not limited to automotive: it works the same way for franchise networks, retail chains or groups of healthcare providers — wherever head office is responsible for entities in several countries.
Tell us how many entities you have and in which countries — we will propose a programme and scope.
Tell us what you are dealing with.
Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.