Assessment Level 1
A suppliers completes the ISA questionnaire. In case the supplier site is not audited as part of a Simplifed Group Assessment thee, no third party audit provider will check self-assessment.
Assessment Level 2
For suppliers that process confidential information and/ or have availability relevance in terms of Information Technology or Production , a remote assessment is are carried out by an approved audit provider.In Phase 1 the plausibility of the self-assessment focusing on the described processes and the supporting documents checked, afterwards in phase 2 potentially, identified ambiguities are reviewed in a remote interview.
Assessment Level 2.5
Assessment Level 2.5 comes into effect if on-site audits (s.below AL3) are not possible due to external circumstances (e.g. contact restrictions due to the COVID-19 pandemic) or if a supplier prefers a more in-depth remote assessment covering the review of all controls..If desired the supplier can upgrade the labels by performing a shortened AL3 on-site assessment, which then only covers the sctricly confidential and/or very high availability control requierement in combination with a site inspection.
Assessment level 3
For Suppliers that process stricly confidential information and/or have very high availability relevance in terms of Information Technology or Production, and in-depth, on-site assessment covering the review of all controls is carried out by an approved audit service provider based on their self-assessment.
Please note: Suppliers can also contract on-site assessments for assessment objectives that do not require such (e.g. performing an assessment for confidential information on-site).