Skip to main content
🇩🇪GDPR-compliant
Find experienced

MaRisk Experts in Frankfurt

for compliant risk management, matched in minutes by AI

Hire experts who design risk-management frameworks, align governance with BaFin expectations and prepare institutions for audits. FRATCH matches you quickly and precisely with vetted, available freelancers who fit your MaRisk project.

Meet FRATCH Experts in Frankfurt, who have recently used MaRisk

Verified expert

Firas J.

View profile

IT Governance & IT Compliance Expert

Friedberg
Firas J.

Last position:

Interim Management Group Head of IT Governance & IAM at French-German Private Bank

  • Head of the group-wide, international, and cross-functional IT Governance & IAM department within the central IT division of a large French-German private banking group. Disciplinary management of around 30 employees at five different locations within the group (Frankfurt, Paris, Tunis, Saarbrücken, Düsseldorf). Head of IT committees and key role in direct communication with management, the supervisory board, external stakeholders, and regulators.
  • Definition and establishment of a state-of-the-art IT strategy process and related IT governance structures for the group's IT department with more than 600 employees (testified by the German Federal Financial Supervisory Authority and the ACPR) and successful process run.
  • Establishment of a new future-oriented process framework for IT and necessary governance structures (process squads) for the continuous improvement of IT processes with regard to new regulatory requirements (including DORA, EU AI Act, etc.).
  • Establishment of stringent processes to close a historical backlog of findings (> 100 IT findings, 40 overdue findings in 2022) from internal and external auditors (WP, ACPR, BaFin). Successful reduction of stock of overdue findings to 0 at the end of 2025.
  • Supporting more than 20 IT audits per year and establishment of regulatory monitoring processes. Introduction of ServiceNow to revolutionize regulatory change and IT compliance processes with advanced AI functionalities.
  • Realignment of IT control processes in conjunction with the newly established ICT risk function under DORA and the three lines of defense concept using the TopEase GRC solution.
  • Reduction of the application landscape, by systematically analysing the purpose with application and business owners, identifying duplicates while implementing a One-Tool Strategy throughout the group. Successful reduction of one third of the application landscape within the CMDB.
  • Onboarding of all group applications into One Identity's group-wide IAM solution, as well as operation and further development of the solution in connection with segregation of duties (SoD), role-based access management (RBAC), etc.
Verified expert

Dustin D.

View profile

Regulatory Risk Executive | Risk Governance & 2nd LoD in Banking | EU AI Act, DORA, MaRisk, NFR | CEO Secori Advisors GmbH

Bad Homburg
Dustin D.

Last position:

External consultant at Deutsche Leasing

2nd LoD/Change the Bank (CtB)

  • CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Verified expert

Justina K.

View profile

Data Management & Governance Manager

Oberursel
Justina K.

Last position:

Freelance Consultant for Change & Data Transformation at Freelance Fast Data Consulting

Project, Strategic Consulting – building the Data Strategy and Data Governance Policy for the German branch, client (private bank Julius Bär, headquarters Zurich), March 2026 – present

  • Design and negotiation of the data strategy with key stakeholders, including obtaining board sign-off (strategic consulting) – in this context, regulatory advice on data regulations in the EU and specifically for Germany. The data strategy includes: Data Lifecycle Management: data capture, data storage, data usage, data retention policy, data quality incident management
  • Definition of milestones and technical feasibility for implementing TOM for the data strategy, data quality checks, metrics, and a metadata inventory to ensure the bank’s compliance with DORA, BCBS239, and MaRisk requirements.

Core project data change, client: (ING Bank, Frankfurt am Main), March – December 2025

  • Concept development and solution design for new end-to-end processes including technical interfaces
  • Definition of synchronization logic and data flows between legacy and target systems (decommissioning of legacy systems)
  • Analysis and validation of data models
  • Stakeholder communication with product owners, feature engineers, UX designers, and operational teams for decision-making
  • Analytics and impact assessments, e.g. to assess downstream effects and regulatory requirements
  • Documentation and comments on technical and business requirements to support implementation in agile squads

Project digitalization of a user group, client: (ING Bank, Frankfurt am Main), as Interim Product Owner, Jan 2025 – present

  • Co-shaping key decisions on data architecture and process logic in the context of historized data and user login functionality
  • Development of business solution concepts for migration to the target system, including system integration and data flows
  • Support with analytics and impact analyses, especially regarding the ability to provide information to law enforcement authorities
  • Active coordination with stakeholders from different squads to support decision-making and ensure regulatory requirements are met
  • Creation of test scenarios for operational teams and backend systems in the area of API management using Postman and Bruno.
Verified expert

Noel L.

View profile

Founder & Lead Engineer

Frankfurt
Noel L.

Last position:

Founder & Lead Engineer at ausbildung-in-der-it.de

  • Platform established and running stably; deliberately reducing my involvement to refocus on an engineering mandate in the financial sector.
  • Built an own SaaS learning platform from the ground up and scaled it to over 20,000 users (over 6,000 courses sold, B2C and B2B); end-to-end ownership from development through infrastructure to operations.
  • Built a lab environment that provisions an isolated Linux container per user (Docker, Traefik, Go), including automatic provisioning and a dedicated subdomain per user.
  • Integrated LLM features into the product and accelerated development end-to-end with AI-assisted workflows (Claude Code, Codex); CI/CD with automated tests.
Verified expert

Achim K.

View profile

Portfolio Manager, Consultant, Leadership Coach

Hofheim am Taunus
Achim K.

Last position:

Portfolio Manager, Consultant, Leadership Coach at Abbvie Deutschland GmbH &Co. KG

  • Management and optimization of a portfolio of about 100 projects (launches, in-field solutions, data & analytics, digital solutions, digital products)
  • Optimization of the existing project standard (playbook) and alignment with the European and global organization (USA)
  • Coaching project managers on setup, planning, cooperation with business, GDPR, GxP, data security and launches
  • Preparing projects for works council information and project closeout communication
  • Optimization of resource management (tracking, allocation, prioritization)
  • Taking over individual project leads (off-/transboarding, event management, checking whether WhatsApp is allowed on a business smartphone)
  • Supporting the hiring of external project managers
  • Optimization of meeting structure, project controlling (KPIs), change and demand management
  • Optimization of risk, issue, dependency and quality management and support during internal audits (GxP)
  • Optimization of the portfolio steering tool (Smartsheet) on national, European and global level
  • Design and implementation of a Business Value Complexity Scoring
  • Building a strategic PMO with a sister department and optimizing cross-functional teams
  • Reporting, communication and escalation at management level
  • Leadership coaching for several future leaders (short-time assignment)
  • Development of the concepts "PPM as a Service" and "Internal Customer Approach"
  • Development and review of a concept "AI Data Governance" including roles and processes
  • Selection and onboarding of the successor
Verified expert

Christine M.

View profile

Freelance specialist in regulatory affairs & IT in banks

Frankfurt am Main
Christine M.

Last position:

Management consultant at Freelance

  • Delivery of ICT / DORA management training under DORA Article 5(4) at various banking institutions

  • Teaching the key content of DORA requirements with a focus on ICT risks, third-party risk management, incident and problem management, and the information register

  • Deriving implementation measures and recommendations for management and business units

Verified expert

Eric B.

View profile

Quality Manager / Test Manager / Senior Test Analyst / Senior Data Analyst / Statistical Programmer

Kelkheim (Taunus)
Eric B.

Last position:

Quality Assurance Lead (QSV) at Federal Employment Agency

  • Supported the International Web Presence project of the Federal Employment Agency (IntWeb) in quality management, taking on responsibility for the quality of processes and project deliverables while adhering to BA standards. The project's main goals are to give professionals abroad a quick overview of their chances to move to Germany and to enable them to take the necessary steps in a consistently digital way.

  • Set the fundamental guidelines using the QA handbook

  • Summarized test results in QA reports for PLA

  • Analyzed project outcomes for improvement opportunities

  • Quality management of requirements analysis (especially processes, methods and tools)

  • Ensured compliance with SERA guidelines

  • Created a cross-project test concept

  • Agreed on sprint completion reports

  • Conducted formal reviews of deliverables according to guidelines and/or project plan

  • Acted as contact person for internal audit and external audits by auditors or the Federal Audit Office (BRH)

  • Technologies: JIRA, Confluence, MS Office, GitLab, Kubernetes

Verified expert

Richard R.

View profile

Vice President– Head of Claims Operations, Europe

Langen (Hessen)
Richard R.

Last position:

Vice President– Head of Claims Operations, Europe at SOMPO International

  • Managing TPA Manager and a team of 10 Claims Operation Assistants.

  • Designing and implementing processes and workstreams using Guidewire from the ground up with European claims teams across all lines of business.

  • Establishing service level agreements (SLAs) and detailed key performance indicators (KPIs) with new business intelligence (BI) reporting, payment and performance analysis.

  • Developing, steering and analysing 50+ strategic, operational and IT initiatives, driving digital change and AI automation in payments while meeting DORA, GDPR, ACM and BAIT MaRisk regulatory compliance.

  • Increasing customer satisfaction scores by 80%.

  • Attracting and mentoring market-leading operational and TPA talent.

  • Demonstrating strong stakeholder leadership and swift decisional influence.

Verified expert

Markus M.

View profile

Project Manager / Senior Consultant (multiple projects)

Frankfurt am Main
Markus M.

Last position:

Project Manager / Senior Consultant (multiple projects) at gkv informatik

  • Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
  • Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
  • Regular reporting to management on progress and risks.
  • Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
  • Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
  • Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
  • Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
  • Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Verified expert

Dmitrii S.

View profile

IT Regulatory Compliance & GRC (BCM, IT Risk, DORA, ISO 22301, Outsourcing)

Frankfurt
Dmitrii S.

Last position:

IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH

Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.

  • Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
  • Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
  • Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
  • Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
  • Aligned 10+ intra-group agreements with DORA regulatory standards.
  • Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Verified expert

Peter W.

View profile

Program and Project Manager / Internal Auditor / CISO

Frankfurt am Main
Peter W.

Last position:

ISO 27001 Auditor for health insurance archive system at Health insurance company

  • The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.

  • The internal audit is meant to ensure the company's quality standards.

  • GDPR

  • ISO 27001 ff.

  • BSI

  • DORA

  • Patient data regulations

  • Host / Cloud / S3 / Container / highly scalable / Nuxeo

  • Budget: 50,000

  • Team: 1

Verified expert

Jörn B.

View profile

Project Management and PMO

Frankfurt
Jörn B.

Last position:

Project Management and PMO at TANKKARTEN | PAYMENT

  • Close collaboration with development teams to ensure alignment with project goals
  • Assessment of in-scope assets, requirements definition and support of the public tender process up to vendor selection
  • Creation and maintenance of UML sequence diagrams to document system interactions
  • Intensive use of Agile/Scrum methodology and the Spotify model
  • Development and implementation of cutover and rehearsal plans together with the application managers
Verified expert

Alexander M.

View profile

Managing Director & Senior Project Manager

Eschborn
Alexander M.

Last position:

Managing Director & Senior Project Manager at Mendelson GmbH

  • Interim project manager and requirements engineer in various client projects
Verified expert

Markus G.

View profile

Master Candidate

Frankfurt am Main
Markus G.

Last position:

Master Candidate at Universidad de Málaga

  • Final preparation for the defense to graduate with a Master's in Computer Science for the PhD

Discover over 15,000 top freelancers

Statistics of experts using MaRisk

Aggregated from the professional profiles of matched freelancers.

Experience

22 years (Germany: 24 years)

MaRisk experts in Frankfurt have 22 years of professional experience on average. It is 2 years less than in Germany, where the average stands at 24 years.

Position duration

2.5 years

MaRisk experts in Frankfurt stay in a single position for 2.5 years on average.

Positions per freelancer

15 (Germany: 17)

MaRisk experts in Frankfurt have completed 15 positions on average over the course of their careers. It is 2 fewer than in Germany, where the average stands at 17.

Top business areas

Information Technology, Operations, Project Management

MaRisk experts in Frankfurt have gathered most of their hands-on project experience in Information Technology, Operations, and Project Management.

Top industries

Banking and Finance, Information Technology, Professional Services

MaRisk experts in Frankfurt are most in demand in Banking and Finance, Information Technology, and Professional Services.

Certification focus areas

Information Technology, Project Management, Quality Assurance

MaRisk experts in Frankfurt earn their certifications most often in Information Technology, Project Management, and Quality Assurance.

Bachelor's degree or higher

93% (Germany: 91%)

93% of MaRisk experts in Frankfurt hold at least a Bachelor's degree. It is 2% higher than in Germany, where the rate stands at 91%.

Master's degree or higher

60% (Germany: 56%)

60% of MaRisk experts in Frankfurt hold at least a Master's degree. It is 4% higher than in Germany, where the rate stands at 56%.

Doctorate

7% (Germany: 11%)

7% of MaRisk experts in Frankfurt have a doctorate (PhD). It is 4% lower than in Germany, where the rate stands at 11%.

Certifications per freelancer

6

MaRisk experts in Frankfurt hold 6 professional certifications on average.

Most common languages

German, English, French

MaRisk experts in Frankfurt most often speak German, English, and French.

Speak two or more languages

100% (Germany: 98%)

100% of MaRisk experts in Frankfurt speak two or more languages. It is 2% higher than in Germany, where the rate stands at 98%.

Based on our profile pool as of 19 Sep 2026.

Daily rate distribution

0 3 6 9 12
One of the MaRisk experts in Frankfurt charges less than €800 per day.
9 of the MaRisk experts in Frankfurt charge between €800 and €960 per day.
5 of the MaRisk experts in Frankfurt charge between €960 and €1120 per day.
One of the MaRisk experts in Frankfurt charges between €1120 and €1280 per day.
2 of the MaRisk experts in Frankfurt charge €1280 or more per day.
<€800 €800-​960 €960-​1120 €1120-​1280 €1280+

The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Frankfurt using MaRisk

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 927 €
Germany avg. 921 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 900 €
Germany median 920 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

MaRisk experts industry focus

See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.

  • Banking and Finance (95%)
  • Information Technology (79%)
  • Professional Services (58%)
  • Insurance (47%)
  • Automotive (37%)
  • Energy (37%)
  • Telecommunication (32%)
  • Government and Administration (26%)

Please note that freelancers can work across multiple industries, so percentages overlap.

About the technology

Regulatory foundation

MaRisk, short for Minimum Requirements for Risk Management, is a BaFin circular for German credit institutions and financial services firms. It sets expectations for governance, risk-bearing capacity, internal controls, documentation and the organisation of risk management. Companies use it as a practical framework for meeting supervisory requirements.

What MaRisk supports

MaRisk shapes how institutions manage material risks and connect business strategy with risk strategy. It affects lending, market risk, liquidity, operational risk, outsourcing and internal audit. Strong implementation turns regulatory expectations into clear responsibilities, controls, reporting paths and evidence.

  • Risk-bearing capacity and risk appetite frameworks
  • Credit processes, limits and concentration controls
  • Risk reporting and management information
  • Outsourcing governance and service-provider oversight
  • Internal control and audit preparation

Ecosystem and methods

MaRisk work sits alongside German and European banking rules, including the German Banking Act, EBA guidelines and supervisory review practices. Specialists often use governance, risk and compliance tools, policy repositories, control libraries, workflow systems and reporting platforms. The work also connects closely with data quality, model governance and information security.

When expertise matters

Companies bring in freelance specialists when a regulatory review exposes gaps, a new business model changes the risk profile or an operating model needs to scale. External expertise is also useful during remediation, acquisitions, outsourcing changes and the rollout of new risk systems.

  • Review existing policies against current MaRisk expectations
  • Map processes, controls, roles and evidence
  • Prepare remediation plans and audit materials
  • Support risk committees and supervisory discussions

What strong specialists deliver

A capable professional combines regulatory understanding with hands-on process design. They can interpret a MaRisk requirement, trace it to a responsible function, define usable controls and test whether evidence is complete. They communicate clearly with risk, compliance, operations, finance, technology and executive stakeholders.

The best fit depends on the institution’s size, licence, risk profile and project stage. Practical experience with governance and documentation matters as much as knowledge of the circular itself.

Working in Frankfurt

Frankfurt’s banking and financial-services environment creates demand for MaRisk expertise across institutions, service providers and regulated technology teams. Local collaboration may help when workshops, committee meetings or supervisory preparation require presence on site. Remote delivery can work well for document reviews, control mapping and reporting design, provided communication and access arrangements are clear.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

Not sure where to start with MaRisk? These answers cover the essentials.

MaRisk defines supervisory expectations for the organisation of risk management at German credit institutions and financial services firms. It covers governance, risk strategy, internal controls, reporting, outsourcing and the treatment of material risks.

MaRisk translates supervisory expectations into concrete requirements for risk-management organisation and processes. It works alongside the German Banking Act, European Banking Authority guidance and other applicable rules rather than replacing them.

A strong MaRisk specialist usually understands risk governance, internal control systems, audit preparation and regulatory documentation. Depending on the assignment, useful adjacent skills include credit risk, liquidity risk, outsourcing management, data governance and GRC tooling.

A MaRisk assignment should match the institution’s licence, business model and risk profile. A professional reviewing policies may need a different background from one leading remediation, redesigning risk reporting or preparing management for supervisory dialogue.

MaRisk work can often be delivered remotely when documents, systems and stakeholders are accessible. On-site sessions in Frankfurt may still be valuable for control workshops, committee preparation and sensitive discussions, while German-language communication is commonly important.

Ask how the MaRisk professional has converted regulatory expectations into processes, controls and evidence. Look for clear examples of stakeholder coordination, audit or supervisory preparation, and practical documentation that business teams can maintain.

A MaRisk freelancer can add focused capacity during remediation, regulatory reviews, system changes or temporary leadership gaps. External specialists bring an independent view and can work across policy, process and evidence without becoming tied to one internal function.

MaRisk is both a supervisory framework and an operating model for risk management. Compliance confirms that expectations are addressed, while effective implementation makes responsibilities, decisions, controls and reporting work in daily business.

The average hourly rate of freelancers in Frankfurt, Germany who have used MaRisk in their recent projects is 116 €, which corresponds to a daily rate of about 927 € based on an 8-hour working day.

Of the freelancers in Frankfurt, Germany who have used MaRisk in their recent projects, 93% hold at least a Bachelor's degree, 60% hold at least a Master's degree, and 7% hold a doctorate.

On average, freelancers in Frankfurt, Germany who have used MaRisk in their recent projects have 22 years of professional experience, with a single engagement typically lasting around 2.5 years.

The most common languages among freelancers in Frankfurt, Germany who have used MaRisk in their recent projects are German (100%), English (100%), and French (37%).

The most common industries among freelancers in Frankfurt, Germany who have used MaRisk in their recent projects are Banking and Finance (95%), Information Technology (79%), and Professional Services (58%).

The most common business areas among freelancers in Frankfurt, Germany who have used MaRisk in their recent projects are Information Technology (95%), Operations (89%), and Project Management (89%).

Main locations of FRATCH Experts, who have recently used MaRisk

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH