Skip to main content
Top expert badge
Recommended expert
Profile header background

Michael S.-Interim CIO, CRO / Head of Compliance & Risk / Head of Governance

Michael S. - Interim CIO, CRO / Head of Compliance & Risk / Head of Governance - profile avatar
Profile header overlay
Available
Hamburg, Germany

Check rate

Experience

Jan 2026 - Present
Roßdorf, Germany
Hybrid

Establishment of Compliance/TPRM

Haftpflichtkasse

Position summary
Establishment of Compliance/TPRM at Haftpflichtkasse
Industries
Banking and Finance
Insurance
Business areas
Project Management

Establishment of Compliance Department & DORA Operationalization

  • Establishment of a complete compliance organization in accordance with DORA
  • Development and operationalization of the SfO
  • Use of AI agents for automation:
  • Evaluation of due diligence questionnaires including risk classification
  • AI-supported contract analysis (DORA/MaRisk compliance)
  • Monitoring of external data sources (cyber incidents, newsfeeds)
  • Establishment of a decentralized risk and action register
  • Preparation of GAP analyses and derivation of measures
  • Establishment and maintenance of the Outsourcing Information Register
  • Use of proprietary TPRM frameworks, checklists and process models

Establishment of Compliance Department & DORA Operationalization

  • Establishment of a complete compliance organization in accordance with DORA
  • Development and operationalization of the SfO
  • Use of AI agents for automation:
  • Evaluation of due diligence questionnaires including risk classification
  • AI-supported contract analysis (DORA/MaRisk compliance)
  • Monitoring of external data sources (cyber incidents, newsfeeds)
  • Establishment of a decentralized risk and action register
  • Preparation of GAP analyses and derivation of measures
  • Establishment and maintenance of the Outsourcing Information Register
  • Use of proprietary TPRM frameworks, checklists and process models
  • Project controlling - presentation and structured measurement of project goals achieved as part of management reporting.
  • Overall responsibility for establishing a Compliance, Governance and Risk organization
  • Establishment of an integrated GRC model and executive reporting for the Management Board.
Sep 2024 - Jan 2026
Hybrid

Project Manager/Outsourcing Management

Bank-Verlag

Position summary
Project Manager/Outsourcing Management at Bank-Verlag
Industries
Banking and Finance
Information Technology
Business areas
Audit
Legal
Procurement
Project Management
  • Establishment of Outsourcing Management
  • Preparation of a new SfO strategy, guideline and work instruction
  • Establishment of the Information Outsourcing Register and definition of critical or important functions and critical service providers
  • Preparation of SLA definitions and KPI
  • Establishment of Service Provider Management and performance of external audits
  • Establishment of a Conflict of Interest Register
  • Establishment of Due Diligence and risk assessments
  • Preparation of Cloud Strategy and AI Strategy
  • Establishment of a Data Protection Coordinator and preparation of the SfO for data protection
  • Conducting DPIAs and data protection audits
  • Preparation of TOM, AVV and maintenance of the VVT and VVT-AV
  • Central Procurement and Outsourcing Management under DORA, NIS2 and PSD2
  • BCM for a KRITIS service provider and handover of the department to line management
Sep 2024 - Mar 2025
Remote

Business Analyst

Stuttgarter Versicherung

Position summary
Business Analyst at Stuttgarter Versicherung
Industries
Banking and Finance
Insurance
Business areas
Information Technology
Legal
Procurement
  • Preparation of the Information Register
  • Contract extensions and definition of critical or important functions and service providers
  • Preparation of the strategy, guideline and process description for third-party service provider management
  • Implementation of third-party service provider management
  • Establishment of risk assessment processes and due diligence processes
  • Role description for «Third-Party Service Provider Manager»
  • Contract reviews and additions of minimum contract contents in accordance with DORA
  • Preparation of exit planning and exit strategy
  • Implementation of ICT incidents
Nov 2023 - May 2024

Compliance Consultant

Zurich Insurance Europe AG

Position summary
Compliance Consultant at Zurich Insurance Europe AG
Industries
Banking and Finance
Insurance
Business areas
Information Technology
  • Consulting on the establishment of the non-life insurer in compliance with and implementation of VAIT/DORA requirements
  • Conducting a GAP analysis and complete preparation of the SfO
  • Preparation of guidelines/policies for all areas covered by VAIT/DORA
  • Preparation for defining the Information Network
  • Preparation of policies for IAM, Information Risk Management, Information Security Management and IDV
  • Preparation of strategy, governance and policies for Critical Infrastructure as well as the outsourcing of IT services and third-party service provider management
  • Contract amendments for outsourcing arrangements
  • Establishment of risk reporting and management and mitigation of risks
  • Preparation of IT Emergency Management and BCM policies with work instructions and process descriptions
  • Professional support in establishing Artemeon as a central Information Register
  • Initial review of the Outsourcing Register and verification of the completeness of the contract database with an initial assessment
  • Introduction of a tool for recording processes in Outsourcing Management
  • Preparation of the Information Register, risk assessment and evaluation as well as Due Diligence
  • Implementation of the SfO in the area of outsourcing service provider management
  • Strategic consulting on VAIT and DORA as well as introduction of a GRC tool
Oct 2022 - Oct 2023

Project Manager, IAM Architect

Fondsdepotbank

Position summary
Project Manager, IAM Architect at Fondsdepotbank
Industries
Banking and Finance
Business areas
Information Technology
Procurement
Project Management
  • Introduction and restart of an IAM software (ORG from FSP), including project monitoring and management (10 employees)
  • C-level stakeholder management and preparation of the implementation strategy
  • Preparation of a new document framework and active implementation as a Business Analyst in the areas of IT Emergency Management, outsourcing of IT services, contract management and risk assessment as well as Information Risk Management
  • Definition of the Information Network and setup of the IDV process
  • Contract negotiations and tenders
  • Professional support in establishing a central Asset Register in ServiceNow
  • Optimization and updating of BCM due to DORA
  • Information Security Management, Critical Infrastructures, Protection Needs Analysis, IT Inventory, IT Operations and Operational Information Security
  • Management of technical implementation taking dependencies into account
  • Professional leadership of a 10-person project team and transformation of the IAM solution to the cloud
Jan 2022 - Sep 2022

Business Analyst

ING Diba AG

Position summary
Business Analyst at ING Diba AG
Industries
Banking and Finance
Business areas
Information Technology
Operations
  • Support with the migration to One Identity
  • Data migration from ServiceNow or Ramon to One Identity
  • Setting up roles and individual permissions
  • Support with HPU accounts and setting up ICS and monitoring in the IAM and IT operations areas
Dec 2021 - Mar 2022

Auditor of Annual Financial Statements

PWC

Position summary
Auditor of Annual Financial Statements at PWC
Industries
Professional Services
Business areas
Audit
Information Technology
  • Performing audit procedures as part of the annual financial statements audit
  • Auditing the areas of IT strategy, IT governance, information risk management and information security management
  • Auditing operational information security, identity and access management, as well as IT projects and application development
  • Auditing IT operations, outsourcing management and external procurement, and IDP
Oct 2021 - Oct 2024

Business Analyst

FI-TS

Position summary
Business Analyst at FI-TS
Industries
Banking and Finance
Information Technology
Business areas
Information Technology
  • Supporting the completion of internal controls as part of the EZB program and updating the SfO for new processes and requirements
  • Defining and coordinating KPI reporting with stakeholders
  • Optimizing and documenting access management processes, as well as reviewing and updating access concepts
  • Checking the completeness of connected components and their documentation, as well as their integration into Garancy
  • Checking SOD conflicts and monitoring the exception and documentation process for SOD conflicts
  • Supporting the introduction of new SOD requirements into the FI-TS structure based on industry recommendations
  • Supporting external audits and special tasks
  • Introducing Garancy and integrating and extending the ITAB tool (LUY) within the access management processes
  • Supporting and preparing audits (WP, §44 KWG, Internal Audit, PS951, TÜV and data protection audits)
  • Implementing the findings from the above-mentioned audits
  • Complete information and outsourcing register, as well as service provider management with SLA/KPI model
  • Handing over the department to the line organization
Apr 2021 - May 2021

Project Manager

Internationale Anwaltskanzlei Hengeler und Müller

Position summary
Project Manager at Internationale Anwaltskanzlei Hengeler und Müller
Industries
Professional Services
Business areas
Information Technology
Project Management
  • Preliminary study for the introduction of access management
  • Preparing the RfP and analyzing the role model to be implemented (RBAC or ABAC)
  • Decision in favor of ABAC
Nov 2020 - Mar 2021

IT Audit Auditor at Banks in Frankfurt

PWC

Position summary
IT Audit Auditor at Banks in Frankfurt at PWC
Industries
Banking and Finance
Business areas
Audit
Information Technology
  • Performing audit procedures as part of the annual financial statements audit
  • Auditing the areas of IT strategy, IT governance, information risk management and information security management
  • Auditing operational information security, identity and access management, as well as IT projects and application development
  • Auditing IT operations, outsourcing management and external procurement, and IDP
Jan 2020 - Sep 2021

Business Analyst

EEX Leipzig

Position summary
Business Analyst at EEX Leipzig
Industries
Energy
Banking and Finance
Business areas
Audit
Information Technology
Project Management
  • Specification and introduction of an in-house IAM solution in compliance with regulatory and supervisory requirements and with a high degree of automation
  • Review and adaptation of authorization concepts for all relevant applications to meet supervisory requirements (role model)
  • Implementation of an RBAC role model
  • Creation of requirements for SOD and introduction of a monitoring process for SOD violations, as well as setup of processes for resolving or accepting SOD violations
  • Agile project execution using Scrum and Kanban
  • Updating of the audit process and SfO
  • Optimization and support of the recertification, ordering, J-M-L and SOD processes
  • Implementation, secure operation and continuous development of the IAM service
  • Integration of applications into the IAM landscape
  • Design, implementation and operation of interfaces to other systems
  • Identification of optimization needs regarding regulatory requirements and development of solution options for continuous improvement
  • Definition and implementation of the operating model with service providers
  • Basic work for the introduction of One Identity and data migration from the legacy system
  • Support of internal and external auditors during audits
  • Preparation of the protection needs analysis and BIA, as well as derivation of further resilience measures
Dec 2018 - Dec 2019
Stuttgart, Germany

Business Analyst/Deputy Project Manager

LBBW

Position summary
Business Analyst/Deputy Project Manager at LBBW
Industries
Banking and Finance
Business areas
Information Technology
Project Management
  • Establishment of a new authorization management system using Garancy in the «Authorization Management-IAM» project
  • Creation of functional concepts for the formation of roles and IT profiles, as well as their customization
  • Definition of the enterprise role and preparation of the UR rollout (modified RBAC-ABAC role model, variable decision matrix)
  • Specification of the «Joiner, Mover, Leaver» process and setup of the ordering process
  • Creation and quality assurance of authorization concepts
  • Establishment of a segregation of duties check (SOD) and resolution of SOD conflicts
  • Support in the area of recertifications
  • Data analysis of the directory services to be integrated and analysis of the integration of OSPlus, Kondor, LDAP, Profis, IDV, OE and project drives
  • Support with system integration and test execution
  • Analysis of the ECB findings and development of an implementation concept to resolve the findings
  • Support in preparing for the ECB audit
Feb 2018 - Nov 2018
Bonn, Germany

IT Architect Treasury

Postbank System

Position summary
IT Architect Treasury at Postbank System
Industries
Banking and Finance
Business areas
Information Technology
  • Development of the new IT architecture for ES Treasury as part of the integration of Postbank into the Deutsche Bank Group
  • Focus on architecture in the areas of ALM and Issuance
Mar 2015 - Jan 2018
Frankfurt, Germany

Deputy Project Manager or Deputy Project Lead

DZBANK

Position summary
Deputy Project Manager or Deputy Project Lead at DZBANK
Industries
Banking and Finance
Business areas
Information Technology
Project Management
Quality Assurance
  • Project to migrate KK accounts from the former WGZ to DZBANK Frankfurt
  • Establishment of risk management and dependency management for the migration project
  • New setup of the communication manager function within the organization
  • Support in test management (Silk and Jira) and deputy project management
  • Participation in migration concepts for SAP-BCA, SAP-CML, SAP-CMS, SAP-CYT and SAP-BP master data migration
  • Functional definition of enhancement requirements in the SAP-CYT area
  • Execution of tests and go-live
  • Stakeholder management and preparation of steering committees
  • Part of the migration team: management of all tasks in the migration cockpit with a focus on SAP applications
  • Test manager: setup and execution of all testing activities and reporting to the PL
Jan 2000 - Dec 2015

Project Manager/Multiproject Manager/Scrum Master

Deka Bank

Position summary
Project Manager/Multiproject Manager/Scrum Master at Deka Bank
Industries
Banking and Finance
Business areas
Accounting
Finance
Information Technology
Procurement
Project Management
  • Preparation of project proposals, project plans, project management, requirements and procurement management, as well as integration management
  • Budget requests and control, status reports, resource management, process analysis, communication and stakeholder management
  • Dependency and risk management, implementation of regulatory requirements and workshop facilitation
  • Methods used: Scrum and agile methods
  • Participation in projects relating to EMIR, Dodd-Frank, MiFID, MiFIR, FATCA, BCBS239, CRR, MaRisk, LQR, OPR, market price risk, FX risk, stress testing, money market statistics, authorization concepts and other regulatory requirements
  • Introduction of a DWH, new payment system PTS, internet FX trading platform, new general and sub-ledger
  • Introduction of an automated margin hedge process with integration of SAP-CML, SAP-CMS and SAP-BCA
  • Implementation of SEPA requirements, customization and integration of UBIX
  • Introduction of the new Pfandbrief legislation, FX management, lean management
  • Setup of new accounting and liquidity management with integration of all SAP applications and Front Arena
  • Profit and loss determination, risk management
  • Establishment of ICS and KPIs, control manual, training and maturity assessment
  • Back office/payment transactions, fixing transactions, retail business, reporting and integration with trading venues
  • Support of external auditors, BaFin and the ECB
  • Introduction of an IAM management system (Omada Identity Suite) with requirements management, role concepts and functional concepts, taking regulatory requirements into account
  • Implementation concept, SOD, recon, resolution of access conflicts and support during external audits
  • Support with process changes, application integration, workshops and creation of an article catalog in OIS
  • Establishment of requirements management (Change Request) and support in creating authorization concepts
  • IT project management: management of rollouts and implementation of optimization measures
Jan 1998 - Dec 2000

Business Analyst

DVG

Position summary
Business Analyst at DVG
Industries
Banking and Finance
Business areas
Information Technology
Legal
  • Functional design to determine the requirements arising from the 6. KWG-Novelle in connection with the Berger & Schier application
Jan 1990 - Dec 1998
Frankfurt, Germany

COO; CIO; Overall Program Manager; Head of Finance and Accounting

Banco di Napoli

Position summary
COO; CIO; Overall Program Manager; Head of Finance and Accounting at Banco di Napoli
Industries
Banking and Finance
Business areas
Finance
Information Technology
Operations
Production
Project Management

Overall responsibility for IT and Operations

  • Nine years of line management responsibility, leading 60 employees.
  • IT budget planning and cost control in the double-digit million range, including the selection and management of external IT service providers as well as contract and SLA negotiations.
  • Staff expansion and stabilization of ongoing IT operations.

Industry experience

See where this freelancer has spent most of their professional time.

Experienced in Banking and Finance, Information Technology, Insurance, Energy, and Professional Services.

Banking and Finance
Information Technology
Insurance
Energy
Professional Services
Profile match chart

Business area experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Project Management, Finance, Procurement, Accounting, and Operations.

Information Technology
Project Management
Finance
Procurement
Accounting
Operations
Profile match chart

Summary

I have spent years building and refining compliance strategies across financial and insurance sectors. My work involves developing outsourcing management and risk assessment processes, creating strategic guidelines for IT security and data protection, and designing IT architectures that meet regulatory demands.

I combine deep technical knowledge with practical project management experience to deliver robust systems for managing third-party risks, IAM, and audit reviews. I continuously drive improvements in regulatory compliance through clear policies and efficient process designs, ensuring reliable and secure operations.

Skills

  • Overall Project Manager; Multi-Project Manager; Project Manager; It Project Manager; Business Analyst; It Architect; Annual Financial Statement Auditor; It Auditor; Test Manager; Scrum Master

  • Finance And Accounting; Annual Financial Statements (Audit-Ready)

  • Securities Trading; Securities Settlement; Treasury

  • Regulatory Requirements; Banking Supervision Law; Marisk; Bait; Bsi; Psd2; Iso 20022; Iso 27001; Isae; Ps951

  • Access Management (Iam And Pam); Sod Processes; Access Concepts; Segregation Of Duties (Sod) And Sod Conflict Management

  • Wealth Management; Fx Risk Management; Interest Rate Risk; Market Risk; Stress Testing; Operational Risks; Liquidity Risk

  • Bcm; It Emergency Management; Liquidity Management

  • Outsourcing Management; Third-Party Service Provider Management; Outsourcing And Service Provider Registers; Service Provider Management; Establishment And Operation Of Payment Systems

  • Data Protection; Dpia; Data Protection Audits; Tom; Avv; Management And Maintenance Of Records Of Processing Activities (Vvt/Vvt-Av)

  • Rollout Planning; Central Management Of It Projects; It Project Management; Establishment Of An Ics; Establishment And Optimization Of Control Manuals And Control Matrices; Kpi Definition And Reporting

  • Business Process Analysis; Requirements Analysis; Business Analysis And Project Management; Preparation Of Project Plans; Npp Processes

  • Annual Financial Statement Auditor; It Auditor; Support For Audits (E.G. Auditors, §44 Kwg, Internal Audit, Ps951, TÜV, Data Protection Audits); Implementation Of Audit Findings

  • Cyt; Compliance; Tenders; Contract Management; Contract Reviews; Creation Of Sla Definitions; Kpi; Exit Planning And Exit Strategy

  • Information Security Management; Information Risk Management; Critical Infrastructures; Protection Needs Analysis; It Inventory; It Operations; Operational Information Security

  • Iam Architecture; Introduction And Operation Of Iam Solutions (E.G. Garancy, One Identity, Omada Identity Suite, Org From Fsp); Integration Of Applications Into Iam Environments

  • Definition And Implementation Of Role Models (Rbac, Abac); Corporate Roles; Joiner-Mover-Leaver Processes; Recertification Processes; Ordering Processes; J-M-L Processes

  • Establishment And Operation Of Asset And Information Registers; Information Network; Idv Processes; Monitoring And Reporting

  • Establishment Of Risk Reporting And Risk Management And Mitigation

  • Support With The Introduction Of Dwh, Payment Systems, Fx Platforms, General And Subsidiary Ledgers, Margin Hedge Processes

  • Goal Orientation

  • Team Orientation

  • Motivation And Team Engagement

  • Dora Implementation: Ict Risk And Ict Incident Management, Information Register, Outsourcing And Service Provider Management, Contract Amendments And Audit Support

  • Mago/Vag Implementation; Outsourcing/Carve-Out In Accordance With At 9 And § 32 Vag; Governance In Accordance With §§ 23 Ff. Vag

  • Nis2 Implementation; Impact Analysis; Governance Of Management Bodies; Supply Chain Security; Reporting Processes; Audit Readiness

  • Interim It Management And It Governance; It Budget And Cost Management; Stabilization Of It Operations; Staff Development And Handover

  • Ai Governance In Accordance With The Eu Ai Act And Dora; Ai-Supported Automation Of Due Diligence Evaluation And Contract Analysis

  • Information Security And Resilience Standards In Accordance With Iso/Iec 27001, 27002, 27005 And Iso 22301; Data Protection Governance In Accordance With Gdpr And Iso 27701

Languages

German
Native
English
Advanced
Italian
Elementary

Education

Business Administration

Training as a Banking Clerk · Banking Clerk

Certifications & licenses

BAIT

BSI

ISAE

ISO 20022

MaRisk

PS951

Statistics

Experience

Total positions 17
Experience in Banking and Finance 36.5 y
Avg length 2 y 6 m
Longest experience 15 y 11 m

Global experience

Countries worked in 1 (Germany)
Primary country Germany

Expertise

Recent roles Establishment of Compliance/TPRM, Project Manager/Outsourcing Management, Business Analyst
Main industries Banking and Finance, Information Technology, Insurance
Main business areas Information Technology, Project Management, Finance

Qualifications

Certifications earned 7

Profile

Member since
Last update
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Have questions? Find more information here.

Michael is based in Hamburg, Germany and can operate in on-site, hybrid, and remote work models.

Michael speaks the following languages: German (Native), English (Advanced), Italian (Elementary).

Michael has at least 37 years of experience. During this time, Michael has worked in at least 13 different roles and for 16 different companies. The average length of individual experience is 2 years and 2 months. Note that Michael may not have shared all experience and actually has more experience.

Based on recent experience, Michael would be well-suited for roles such as: Establishment of Compliance/TPRM, Project Manager/Outsourcing Management, Business Analyst.

Michael's most recent position is Establishment of Compliance/TPRM at Haftpflichtkasse.

In recent years, Michael has worked for Haftpflichtkasse, Bank-Verlag, Stuttgarter Versicherung, Zurich Insurance Europe AG, and Fondsdepotbank.

Michael is most experienced in industries like Banking and Finance, Information Technology, and Insurance. Michael also has some experience in Energy and Professional Services.

Michael is most experienced in business areas like Information Technology, Project Management, and Finance. Michael also has some experience in Procurement, Accounting, and Operations.

Michael has recently worked in industries like Banking and Finance, Information Technology, and Insurance.

Michael has recently worked in business areas like Information Technology, Project Management, and Audit.

Michael attended education in Business Administration.

Michael has 7 certificates. Among them, these include: BAIT, BSI, and ISAE.

Michael is immediately available full-time for suitable projects.

Daily rate distribution

0% 25% 50% 75% 100%
10% of experts charge less than €640 per day.
20% of experts charge between €640 and €800 per day.
60% of experts charge between €960 and €1120 per day.
10% of experts charge €1120 or more per day.
<€640 €640-​800 €960-​1120 €1120+

The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 920 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 980 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 28 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.