Michael S.-Interim CIO, CRO / Head of Compliance & Risk / Head of Governance

Check rate
Experience
Establishment of Compliance/TPRM
Haftpflichtkasse
Establishment of Compliance Department & DORA Operationalization
- Establishment of a complete compliance organization in accordance with DORA
- Development and operationalization of the SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, newsfeeds)
- Establishment of a decentralized risk and action register
- Preparation of GAP analyses and derivation of measures
- Establishment and maintenance of the Outsourcing Information Register
- Use of proprietary TPRM frameworks, checklists and process models
Establishment of Compliance Department & DORA Operationalization
- Establishment of a complete compliance organization in accordance with DORA
- Development and operationalization of the SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, newsfeeds)
- Establishment of a decentralized risk and action register
- Preparation of GAP analyses and derivation of measures
- Establishment and maintenance of the Outsourcing Information Register
- Use of proprietary TPRM frameworks, checklists and process models
- Project controlling - presentation and structured measurement of project goals achieved as part of management reporting.
- Overall responsibility for establishing a Compliance, Governance and Risk organization
- Establishment of an integrated GRC model and executive reporting for the Management Board.
Project Manager/Outsourcing Management
Bank-Verlag
- Establishment of Outsourcing Management
- Preparation of a new SfO strategy, guideline and work instruction
- Establishment of the Information Outsourcing Register and definition of critical or important functions and critical service providers
- Preparation of SLA definitions and KPI
- Establishment of Service Provider Management and performance of external audits
- Establishment of a Conflict of Interest Register
- Establishment of Due Diligence and risk assessments
- Preparation of Cloud Strategy and AI Strategy
- Establishment of a Data Protection Coordinator and preparation of the SfO for data protection
- Conducting DPIAs and data protection audits
- Preparation of TOM, AVV and maintenance of the VVT and VVT-AV
- Central Procurement and Outsourcing Management under DORA, NIS2 and PSD2
- BCM for a KRITIS service provider and handover of the department to line management
Business Analyst
Stuttgarter Versicherung
- Preparation of the Information Register
- Contract extensions and definition of critical or important functions and service providers
- Preparation of the strategy, guideline and process description for third-party service provider management
- Implementation of third-party service provider management
- Establishment of risk assessment processes and due diligence processes
- Role description for «Third-Party Service Provider Manager»
- Contract reviews and additions of minimum contract contents in accordance with DORA
- Preparation of exit planning and exit strategy
- Implementation of ICT incidents
Compliance Consultant
Zurich Insurance Europe AG
- Consulting on the establishment of the non-life insurer in compliance with and implementation of VAIT/DORA requirements
- Conducting a GAP analysis and complete preparation of the SfO
- Preparation of guidelines/policies for all areas covered by VAIT/DORA
- Preparation for defining the Information Network
- Preparation of policies for IAM, Information Risk Management, Information Security Management and IDV
- Preparation of strategy, governance and policies for Critical Infrastructure as well as the outsourcing of IT services and third-party service provider management
- Contract amendments for outsourcing arrangements
- Establishment of risk reporting and management and mitigation of risks
- Preparation of IT Emergency Management and BCM policies with work instructions and process descriptions
- Professional support in establishing Artemeon as a central Information Register
- Initial review of the Outsourcing Register and verification of the completeness of the contract database with an initial assessment
- Introduction of a tool for recording processes in Outsourcing Management
- Preparation of the Information Register, risk assessment and evaluation as well as Due Diligence
- Implementation of the SfO in the area of outsourcing service provider management
- Strategic consulting on VAIT and DORA as well as introduction of a GRC tool
Project Manager, IAM Architect
Fondsdepotbank
- Introduction and restart of an IAM software (ORG from FSP), including project monitoring and management (10 employees)
- C-level stakeholder management and preparation of the implementation strategy
- Preparation of a new document framework and active implementation as a Business Analyst in the areas of IT Emergency Management, outsourcing of IT services, contract management and risk assessment as well as Information Risk Management
- Definition of the Information Network and setup of the IDV process
- Contract negotiations and tenders
- Professional support in establishing a central Asset Register in ServiceNow
- Optimization and updating of BCM due to DORA
- Information Security Management, Critical Infrastructures, Protection Needs Analysis, IT Inventory, IT Operations and Operational Information Security
- Management of technical implementation taking dependencies into account
- Professional leadership of a 10-person project team and transformation of the IAM solution to the cloud
Business Analyst
ING Diba AG
- Support with the migration to One Identity
- Data migration from ServiceNow or Ramon to One Identity
- Setting up roles and individual permissions
- Support with HPU accounts and setting up ICS and monitoring in the IAM and IT operations areas
Auditor of Annual Financial Statements
PWC
- Performing audit procedures as part of the annual financial statements audit
- Auditing the areas of IT strategy, IT governance, information risk management and information security management
- Auditing operational information security, identity and access management, as well as IT projects and application development
- Auditing IT operations, outsourcing management and external procurement, and IDP
Business Analyst
FI-TS
- Supporting the completion of internal controls as part of the EZB program and updating the SfO for new processes and requirements
- Defining and coordinating KPI reporting with stakeholders
- Optimizing and documenting access management processes, as well as reviewing and updating access concepts
- Checking the completeness of connected components and their documentation, as well as their integration into Garancy
- Checking SOD conflicts and monitoring the exception and documentation process for SOD conflicts
- Supporting the introduction of new SOD requirements into the FI-TS structure based on industry recommendations
- Supporting external audits and special tasks
- Introducing Garancy and integrating and extending the ITAB tool (LUY) within the access management processes
- Supporting and preparing audits (WP, §44 KWG, Internal Audit, PS951, TÜV and data protection audits)
- Implementing the findings from the above-mentioned audits
- Complete information and outsourcing register, as well as service provider management with SLA/KPI model
- Handing over the department to the line organization
Project Manager
Internationale Anwaltskanzlei Hengeler und Müller
- Preliminary study for the introduction of access management
- Preparing the RfP and analyzing the role model to be implemented (RBAC or ABAC)
- Decision in favor of ABAC
IT Audit Auditor at Banks in Frankfurt
PWC
- Performing audit procedures as part of the annual financial statements audit
- Auditing the areas of IT strategy, IT governance, information risk management and information security management
- Auditing operational information security, identity and access management, as well as IT projects and application development
- Auditing IT operations, outsourcing management and external procurement, and IDP
Business Analyst
EEX Leipzig
- Specification and introduction of an in-house IAM solution in compliance with regulatory and supervisory requirements and with a high degree of automation
- Review and adaptation of authorization concepts for all relevant applications to meet supervisory requirements (role model)
- Implementation of an RBAC role model
- Creation of requirements for SOD and introduction of a monitoring process for SOD violations, as well as setup of processes for resolving or accepting SOD violations
- Agile project execution using Scrum and Kanban
- Updating of the audit process and SfO
- Optimization and support of the recertification, ordering, J-M-L and SOD processes
- Implementation, secure operation and continuous development of the IAM service
- Integration of applications into the IAM landscape
- Design, implementation and operation of interfaces to other systems
- Identification of optimization needs regarding regulatory requirements and development of solution options for continuous improvement
- Definition and implementation of the operating model with service providers
- Basic work for the introduction of One Identity and data migration from the legacy system
- Support of internal and external auditors during audits
- Preparation of the protection needs analysis and BIA, as well as derivation of further resilience measures
Business Analyst/Deputy Project Manager
LBBW
- Establishment of a new authorization management system using Garancy in the «Authorization Management-IAM» project
- Creation of functional concepts for the formation of roles and IT profiles, as well as their customization
- Definition of the enterprise role and preparation of the UR rollout (modified RBAC-ABAC role model, variable decision matrix)
- Specification of the «Joiner, Mover, Leaver» process and setup of the ordering process
- Creation and quality assurance of authorization concepts
- Establishment of a segregation of duties check (SOD) and resolution of SOD conflicts
- Support in the area of recertifications
- Data analysis of the directory services to be integrated and analysis of the integration of OSPlus, Kondor, LDAP, Profis, IDV, OE and project drives
- Support with system integration and test execution
- Analysis of the ECB findings and development of an implementation concept to resolve the findings
- Support in preparing for the ECB audit
IT Architect Treasury
Postbank System
- Development of the new IT architecture for ES Treasury as part of the integration of Postbank into the Deutsche Bank Group
- Focus on architecture in the areas of ALM and Issuance
Deputy Project Manager or Deputy Project Lead
DZBANK
- Project to migrate KK accounts from the former WGZ to DZBANK Frankfurt
- Establishment of risk management and dependency management for the migration project
- New setup of the communication manager function within the organization
- Support in test management (Silk and Jira) and deputy project management
- Participation in migration concepts for SAP-BCA, SAP-CML, SAP-CMS, SAP-CYT and SAP-BP master data migration
- Functional definition of enhancement requirements in the SAP-CYT area
- Execution of tests and go-live
- Stakeholder management and preparation of steering committees
- Part of the migration team: management of all tasks in the migration cockpit with a focus on SAP applications
- Test manager: setup and execution of all testing activities and reporting to the PL
Project Manager/Multiproject Manager/Scrum Master
Deka Bank
- Preparation of project proposals, project plans, project management, requirements and procurement management, as well as integration management
- Budget requests and control, status reports, resource management, process analysis, communication and stakeholder management
- Dependency and risk management, implementation of regulatory requirements and workshop facilitation
- Methods used: Scrum and agile methods
- Participation in projects relating to EMIR, Dodd-Frank, MiFID, MiFIR, FATCA, BCBS239, CRR, MaRisk, LQR, OPR, market price risk, FX risk, stress testing, money market statistics, authorization concepts and other regulatory requirements
- Introduction of a DWH, new payment system PTS, internet FX trading platform, new general and sub-ledger
- Introduction of an automated margin hedge process with integration of SAP-CML, SAP-CMS and SAP-BCA
- Implementation of SEPA requirements, customization and integration of UBIX
- Introduction of the new Pfandbrief legislation, FX management, lean management
- Setup of new accounting and liquidity management with integration of all SAP applications and Front Arena
- Profit and loss determination, risk management
- Establishment of ICS and KPIs, control manual, training and maturity assessment
- Back office/payment transactions, fixing transactions, retail business, reporting and integration with trading venues
- Support of external auditors, BaFin and the ECB
- Introduction of an IAM management system (Omada Identity Suite) with requirements management, role concepts and functional concepts, taking regulatory requirements into account
- Implementation concept, SOD, recon, resolution of access conflicts and support during external audits
- Support with process changes, application integration, workshops and creation of an article catalog in OIS
- Establishment of requirements management (Change Request) and support in creating authorization concepts
- IT project management: management of rollouts and implementation of optimization measures
Business Analyst
DVG
- Functional design to determine the requirements arising from the 6. KWG-Novelle in connection with the Berger & Schier application
COO; CIO; Overall Program Manager; Head of Finance and Accounting
Banco di Napoli
Overall responsibility for IT and Operations
- Nine years of line management responsibility, leading 60 employees.
- IT budget planning and cost control in the double-digit million range, including the selection and management of external IT service providers as well as contract and SLA negotiations.
- Staff expansion and stabilization of ongoing IT operations.
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Insurance, Energy, and Professional Services.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Finance, Procurement, Accounting, and Operations.
Summary
I have spent years building and refining compliance strategies across financial and insurance sectors. My work involves developing outsourcing management and risk assessment processes, creating strategic guidelines for IT security and data protection, and designing IT architectures that meet regulatory demands.
I combine deep technical knowledge with practical project management experience to deliver robust systems for managing third-party risks, IAM, and audit reviews. I continuously drive improvements in regulatory compliance through clear policies and efficient process designs, ensuring reliable and secure operations.
Skills
Overall Project Manager; Multi-Project Manager; Project Manager; It Project Manager; Business Analyst; It Architect; Annual Financial Statement Auditor; It Auditor; Test Manager; Scrum Master
Finance And Accounting; Annual Financial Statements (Audit-Ready)
Securities Trading; Securities Settlement; Treasury
Regulatory Requirements; Banking Supervision Law; Marisk; Bait; Bsi; Psd2; Iso 20022; Iso 27001; Isae; Ps951
Access Management (Iam And Pam); Sod Processes; Access Concepts; Segregation Of Duties (Sod) And Sod Conflict Management
Wealth Management; Fx Risk Management; Interest Rate Risk; Market Risk; Stress Testing; Operational Risks; Liquidity Risk
Bcm; It Emergency Management; Liquidity Management
Outsourcing Management; Third-Party Service Provider Management; Outsourcing And Service Provider Registers; Service Provider Management; Establishment And Operation Of Payment Systems
Data Protection; Dpia; Data Protection Audits; Tom; Avv; Management And Maintenance Of Records Of Processing Activities (Vvt/Vvt-Av)
Rollout Planning; Central Management Of It Projects; It Project Management; Establishment Of An Ics; Establishment And Optimization Of Control Manuals And Control Matrices; Kpi Definition And Reporting
Business Process Analysis; Requirements Analysis; Business Analysis And Project Management; Preparation Of Project Plans; Npp Processes
Annual Financial Statement Auditor; It Auditor; Support For Audits (E.G. Auditors, §44 Kwg, Internal Audit, Ps951, TÜV, Data Protection Audits); Implementation Of Audit Findings
Cyt; Compliance; Tenders; Contract Management; Contract Reviews; Creation Of Sla Definitions; Kpi; Exit Planning And Exit Strategy
Information Security Management; Information Risk Management; Critical Infrastructures; Protection Needs Analysis; It Inventory; It Operations; Operational Information Security
Iam Architecture; Introduction And Operation Of Iam Solutions (E.G. Garancy, One Identity, Omada Identity Suite, Org From Fsp); Integration Of Applications Into Iam Environments
Definition And Implementation Of Role Models (Rbac, Abac); Corporate Roles; Joiner-Mover-Leaver Processes; Recertification Processes; Ordering Processes; J-M-L Processes
Establishment And Operation Of Asset And Information Registers; Information Network; Idv Processes; Monitoring And Reporting
Establishment Of Risk Reporting And Risk Management And Mitigation
Support With The Introduction Of Dwh, Payment Systems, Fx Platforms, General And Subsidiary Ledgers, Margin Hedge Processes
Goal Orientation
Team Orientation
Motivation And Team Engagement
Dora Implementation: Ict Risk And Ict Incident Management, Information Register, Outsourcing And Service Provider Management, Contract Amendments And Audit Support
Mago/Vag Implementation; Outsourcing/Carve-Out In Accordance With At 9 And § 32 Vag; Governance In Accordance With §§ 23 Ff. Vag
Nis2 Implementation; Impact Analysis; Governance Of Management Bodies; Supply Chain Security; Reporting Processes; Audit Readiness
Interim It Management And It Governance; It Budget And Cost Management; Stabilization Of It Operations; Staff Development And Handover
Ai Governance In Accordance With The Eu Ai Act And Dora; Ai-Supported Automation Of Due Diligence Evaluation And Contract Analysis
Information Security And Resilience Standards In Accordance With Iso/Iec 27001, 27002, 27005 And Iso 22301; Data Protection Governance In Accordance With Gdpr And Iso 27701
Languages
Education
Business Administration
Training as a Banking Clerk · Banking Clerk
Certifications & licenses
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Michael is based in Hamburg, Germany and can operate in on-site, hybrid, and remote work models.
Michael speaks the following languages: German (Native), English (Advanced), Italian (Elementary).
Michael has at least 37 years of experience. During this time, Michael has worked in at least 13 different roles and for 16 different companies. The average length of individual experience is 2 years and 2 months. Note that Michael may not have shared all experience and actually has more experience.
Based on recent experience, Michael would be well-suited for roles such as: Establishment of Compliance/TPRM, Project Manager/Outsourcing Management, Business Analyst.
Michael's most recent position is Establishment of Compliance/TPRM at Haftpflichtkasse.
In recent years, Michael has worked for Haftpflichtkasse, Bank-Verlag, Stuttgarter Versicherung, Zurich Insurance Europe AG, and Fondsdepotbank.
Michael is most experienced in industries like Banking and Finance, Information Technology, and Insurance. Michael also has some experience in Energy and Professional Services.
Michael is most experienced in business areas like Information Technology, Project Management, and Finance. Michael also has some experience in Procurement, Accounting, and Operations.
Michael has recently worked in industries like Banking and Finance, Information Technology, and Insurance.
Michael has recently worked in business areas like Information Technology, Project Management, and Audit.
Michael attended education in Business Administration.
Michael has 7 certificates. Among them, these include: BAIT, BSI, and ISAE.
Michael is immediately available full-time for suitable projects.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 28 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Establishment of Compliance/TPRM
Nearby freelancers
Professionals working in or nearby Hamburg, Germany
