Skip to main content
🇩🇪GDPR-compliant
Find the perfect

ISO 31000 Experts in Germany

in minutes with vetted specialists matched by AI

Hire experts who shape risk frameworks, align ISO 31000 with governance and controls, and turn risk workshops into clear action. Get fast, precise matching with vetted, available freelancers.

Meet FRATCH Experts in Germany, who have recently used ISO 31000

Verified expert

Günther Eufinger

View profile

Senior Consultant

Offenbach am Main
Günther Eufinger

Last position:

Senior Consultant at ISMS Rollout – Information Security Certification (ISO 27001)

  • Built and successfully certified the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
  • Full implementation of the ISMS from kick-off phase to certification, including defining the governance structure and process landscape.
  • Developed and delivered target-group-specific trainings, workshops, and coaching sessions for local responsible persons on the basics of information security and ISMS operations.
  • Designed and continuously improved training concepts and content to increase understanding and acceptance.
  • Identified and implemented improvements in processes and tools, including risk management for international projects.
  • Optimized central ISMS core processes from the idea through pilot operation and fine-tuning to global rollout.
  • Optimized knowledge management, as well as work aids and methods for the global ISMS team.
  • Built and moderated cross-functional coordination with key interfaces to the ISMS.
  • Microsoft Teams, Excel, SharePoint Lists, Power Apps.
Verified expert

Alexander Sänn

View profile

Owner and Managing Director

Bayreuth
Alexander Sänn

Last position:

Lead Audit Conformity & IT Security Catalog at DAX group energy provider in the renewable energy sector

  • Supported the implementation of §8a requirements of the BSI Act for critical infrastructures.
  • Systematically prepared and supported internal and external audits, resolving previous deviations (HA, NA, VP)
  • Implemented the specific requirements of the IT security catalog
  • Developed training, created run books, and conducted assessments to ensure operational effectiveness.
Verified expert

Serdar Colak

View profile

Consultant

Cologne
Serdar Colak

Last position:

Consultant at Freelance

  • ISO 27001 implementation & audit readiness
  • NIS2 & DORA compliance support
  • Interim / fractional CISO services
  • IT risk & controls (ITGC, SOX, COBIT, BAIT)
  • M&A and IT due diligence for startups/ventures
  • Business continuity management (BCM, ISO 22301)
  • Cybersecurity framework development (NIST, ISO, BSI)
  • GRC tool advisory (Archer, ServiceNow)
Verified expert

Robert Vattig

View profile

Freelance Consultant Information Security and Business Continuity

Lauta
Robert Vattig

Last position:

Freelance Consultant Information Security and Business Continuity at Freelance business consulting

  • Provide consulting services nationwide in both private and public sectors
  • Advise on information security management systems, IT-Grundschutz, KRITIS compliance, TISAX, business continuity and crisis management
  • Support the introduction of policies, risk management methods, asset registers and supplier management
  • Conduct internal audits, training workshops and support audit preparations
Verified expert

Thomas Arends

View profile

Interim Assignment

Wernau (Neckar)
Thomas Arends

Last position:

Interim Management at Vincorion Power Systems GmbH

  • Process and project management to optimize products and development processes for energy systems
  • Technical risk management
  • Requirements engineering and system architecture
  • System FMEA of power generator units and energy storage modules aiming for generic structures
  • Claims management according to Section 313 of the German Civil Code
  • Regulatory environment: military and NATO standards, AQAP, VG norms
Verified expert

Thomas Müller

View profile

Chief Risk Officer, Member of the Executive Board

Bonn
Thomas Müller

Last position:

Chief Risk Officer, Member of the Executive Board at BWI GmbH

  • Built and led the Group Risk & Compliance organization (ERM, IKS, Compliance, Information Security, Data Protection, Classified Information Protection, Project Assurance).
  • Integrated previously fragmented control functions into a single, performance-oriented GRC framework.
  • Served as member of the steering committee in all top projects, from the sales phase until handover to delivery operations.
  • Developed and implemented a new project assurance function to ensure top management attention and an early warning system for top 20 projects.
  • Led 120 employees with 9 direct reports, managing a business volume of €1.8bn.
Verified expert

Daria Beck

View profile

Senior Consultant Strategy, Risk & Resilience Management

Berlin
Daria Beck

Last position:

Senior Consultant Strategy, Risk & Resilience Management at Antharas

  • Creating guidelines
  • Conducting Business Impact Analyses (BIAs), assessing risks and identifying time-critical business processes
  • Process management
  • Creating emergency and crisis management plans, including cyber response and IT recovery plans with a special focus on cyber attacks
  • Conducting awareness training
  • Planning and conducting tests and exercises
  • Developing tailored solutions to minimize risks and ensure business continuity
Verified expert

Volkmar Jaekel

View profile

Consultant

Todtmoos
Volkmar Jaekel

Last position:

Consultant at Bedia Motorentechnik GmbH & Co. KG

  • Consulting on effort estimation for VDA ISA / TISAX certification
  • Conducting a 2-day workshop including preparation and follow-up
  • Skills: TISAX 5.1, ISO 27001:2022, auditing, information security, consulting, facilitation, presentation
Verified expert

Anette Göbel

View profile

Managing Director

Munich
Anette Göbel

Last position:

Managing Director at promismanagement services GmbH

  • Leading and building integrated management systems (IMS) for quality (QMS), data protection and information security (ISMS), risk (GRC), and artificial intelligence (AI) in accordance with ISO 9001, ISO 27001, ISO 42001, ISO 21500, ISO 21502, ISO 37301, ISO 31000
  • Governance, project, and transformation management nationally and internationally incl. enterprise and project governance
  • Process development, optimization, and business process reengineering according to BPMN 2.0, Kaizen, IATF 16949, VDA, BPMN 2.0
  • Compliance and risk management in the company and project context as well as connection to internal control systems (ICS) and Group Risk Compliance (GRC)
  • Carrying out and leading internal audits and lead audits according to ISO 19011; audit management and test equipment / special equipment management
  • Methodical and systemic coaching (IFS, Hakomi) as well as conflict moderation and change management
  • Designing and delivering AI trainings, prompt engineering, and AI literacy workshops
  • Advising on data protection impact assessments (DPIA), implementing EU GDPR, BDSG, and IT-SiG as well as NIS-2 and DORA
  • Building and leading Program Management Offices (PMO) and introducing Project Management Office structures
  • Contract management, clause-by-clause analyses, and project controlling according to PMI® standards incl. Earned Value Management
  • Building knowledge, document, and content management systems (Confluence, SharePoint, EY iManage)
Verified expert

Norbert Stilling

View profile

Self-Employed Consultant and Project Manager

München
Norbert Stilling

Last position:

Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager

  • 21 projects ≥ 6 months at large and medium-sized companies
  • 13 projects as project or subproject manager
  • 6 international projects with English as project language
Verified expert

Jörg Hoffmann

View profile

Managing Director; Data Protection Officer; Information Security Officer

Berlin
Jörg Hoffmann

Last position:

Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)

  • Drafting company agreements related to data protection
  • Acting as a mediator between business interests and data subject rights in a corporate context
  • Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
  • Support for information security audits according to ISO 27001
  • Implementation of change management processes
  • Analysis of IT infrastructure and deriving recommendations
  • Expert support in legal proceedings and communication with supervisory authorities
  • Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
  • Training on corporate data protection and information security
  • Cooperation with law firms in legal proceedings
Verified expert

Lucas Löcken

View profile

Consultant in Information Security, Data Protection and Business Continuity Management

Nordwalde
Lucas Löcken

Last position:

Consultant in Information Security, Data Protection and Business Continuity Management

  • Consulting and support in gathering information security requirements (IT-SIG 2.0, KRITIS, TISAX, industry standards, ISO 27001, A-960/1)

  • Acting as data protection officer and auditor as well as information security auditor

  • Conducting employee training

  • Updating risk analyses with risk treatment

  • Designing information security concepts based on BSI IT Baseline Protection, KRITIS, ISO 27001, A-960/1 and TISAX

  • Identifying information security requirements for IT systems (WAN, LAN, clouds) and overseeing implementation

  • Administering the ISMS using Verinice and SAVe

  • Integrating security concepts into existing management systems according to ISO 9001 and ISO 27001

  • Process management and modeling according to ITIL

  • Management consulting for integrating an ISMS into integrated management systems

  • Advising on data protection (GDPR, BDSG)

  • Planning and conducting data protection audits

  • Designing risk management processes and methodologies according to ISO 27005, ISO 31000 and BSI 200-3

  • Developing and setting up training programs for employees

Verified expert

Manfred Liebetrau

View profile

Senior Consultant Information Security

Dortmund
Manfred Liebetrau

Last position:

Senior Consultant Information Security at Creditplus Bank AG

  • Designing the information security process based on ITIL 4
  • Designing the ITIL 4 incident and change management processes
  • Creating information security policies for the bank
  • Support in the project for internal audit findings
  • Advising on the setup of the bank's internal control systems (ICS)
  • Advising on setting up ICS processes
  • Advising and supporting security architecture and risk analysis of the existing IT landscape, including IT security architecture, data management, data compliance & physical security
  • Advising and project leadership for the security concept of the bank's assets
  • Advising and support in contracts with external service providers to meet the bank's regulatory (BAIT; MaRisk; DORA; NIS2; GDPR) and information security requirements
  • Support in planning and implementing a SOC/SIEM and risk management
  • Support for the spam email team in analyzing and handling incidents
Verified expert

Stephan Selnerat

View profile

IT-Security Manager

Saarlouis
Stephan Selnerat

Last position:

IT-Security Manager at Large industrial corporation with multiple international locations

  • Planning and managing all projects in the context of IT security
  • Establishing a Cyber Security Incident Response procedure according to ISO/IEC 27035
  • NIS2 readiness: impact analysis, planning and implementation of NIS2 compliance
  • Management reporting based on KPIs

Discover over 15,000 top freelancers

Statistics of experts using ISO 31000

Aggregated from the professional profiles of matched freelancers.

Experience

26 years

Position duration

4.5 years

Positions per freelancer

14

Top business areas

Information Technology, Project Management, Quality Assurance

Top industries

Professional Services, Information Technology, Manufacturing

Certification focus areas

Information Technology, Quality Assurance, Audit

Bachelor's degree or higher

93%

Master's degree or higher

57%

Doctorate

14%

Certifications per freelancer

8

Most common languages

German, English, French

Speak two or more languages

100%

Based on our profile pool as of 30 Aug 2026.

Daily rate distribution

0 3 6 9 12
<€960 €960-​1120 €1120-​1280 €1440+

The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Germany using ISO 31000

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Daily rate avg. 1048 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1200
900
600
300
Rate comparison chart
Median rate 1000 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

About the technology

Risk framework

ISO 31000 is the main reference for risk management. It helps companies build a clear framework for identifying, assessing, treating, and monitoring risk across projects, operations, and strategy. Strong specialists adapt it to the business instead of forcing a fixed template.

Where it fits

  • Enterprise risk management and governance
  • Risk appetite and risk criteria
  • Risk registers and treatment plans
  • Workshops with leadership and process owners
  • Audit support and control alignment

Core skills

A good ISO 31000 expert understands risk language, decision-making, and practical documentation. They know how to connect the standard with internal policies, compliance duties, and reporting lines. They also need strong facilitation skills, because the work often depends on structured discussions, not just documents.

Typical engagements

Companies bring in freelance specialists when a framework needs to be created, repaired, or explained to stakeholders. Common tasks include reviewing an existing risk process, mapping gaps against ISO 31000:2018, preparing templates, and coaching internal teams. In Germany, this is often useful for larger groups with complex operations and mixed local and international reporting needs.

Good deliverables

  • Risk framework and methodology documents
  • Risk matrix and assessment criteria
  • Risk register structure and ownership model
  • Treatment tracking and reporting packs
  • Workshop outputs and implementation notes

What strong specialists show

Strong ISO 31000 professionals do more than quote the standard. They translate it into working routines, clear roles, and measurable follow-up. They know when to keep the model simple, when to add detail, and how to make risk work across teams without slowing the business down.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

The facts hiring teams ask for most often when it comes to ISO 31000.

ISO 31000 is used to build a structured way to manage risk across the business. It helps teams identify risks, assess their impact, choose treatments, and review them in a repeatable process. Companies often use it to support governance, planning, and informed decisions.

ISO 31000 is a broad risk management guideline that focuses on principles, framework, and process. COSO ERM is more tightly connected to enterprise risk management and internal control language. A strong specialist can help you choose the model that fits your governance style and reporting needs.

A strong ISO 31000 specialist usually brings adjacent skills in governance, internal audit support, compliance, and facilitation. They should be comfortable with risk registers, control mapping, workshop design, and stakeholder interviews. For many projects, clear writing matters as much as technical knowledge.

Not always, but ISO 31000 work benefits from someone who has already built or improved a framework before. If you only need a review, template refresh, or workshop support, a mid-level expert may be enough. If the work affects multiple functions or reporting lines, deeper experience helps.

Yes, most ISO 31000 work can be done remotely because it often involves interviews, document review, and workshop preparation. On-site time can still help when leadership alignment is difficult or when teams need hands-on facilitation. In Germany, many companies prefer a mix of remote planning and local sessions.

If your ISO 31000 process is inconsistent, hard to explain, or only exists on paper, outside help is usually useful. Other signs are unclear ownership, weak follow-up on treatments, and risk reporting that does not support decisions. A freelance specialist can reset the process without a long internal project.

Look for a ISO 31000 expert who can explain how the framework will work in your company, not just describe the standard. Good signs are clear examples, practical templates, and a calm way of handling stakeholder disagreement. The best specialists leave you with a process your team can actually run.

ISO 31000 is the common name people use for the risk management standard, and ISO 31000:2018 is the current version most searchers mean. When you hire a specialist, make sure they understand the current wording and how it affects your internal method. That avoids confusion when updating policy or training material.

The average hourly rate of freelancers in Germany who have used ISO 31000 in their recent projects is 131 €, which corresponds to a daily rate of about 1,048 € based on an 8-hour working day.

Of the freelancers in Germany who have used ISO 31000 in their recent projects, 93% hold at least a Bachelor's degree, 57% hold at least a Master's degree, and 14% hold a doctorate.

On average, freelancers in Germany who have used ISO 31000 in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 4.5 years.

The most common languages among freelancers in Germany who have used ISO 31000 in their recent projects are German (100%), English (100%), and French (24%).

The most common industries among freelancers in Germany who have used ISO 31000 in their recent projects are Professional Services (82%), Information Technology (71%), and Manufacturing (47%).

The most common business areas among freelancers in Germany who have used ISO 31000 in their recent projects are Information Technology (88%), Project Management (88%), and Quality Assurance (76%).

Main locations of FRATCH Experts, who have recently used ISO 31000

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH