This site measures reach exclusively on its own server, without cookies and without third parties.

COMPLIANCE & AUDIT

An attestation does not come from documents, but from decisions

Advertised as: IT Compliance Manager · Project Manager ISO 27001 / BSI C5 · IT Compliance Consultant

On the cloud platform of an international retail group I led the organisation's BSI C5 programme through to audit readiness, with a Big Four audit firm as external auditor – working through the complete criteria catalogue criterion by criterion with the auditor, clarifying interpretation, agreeing test conditions and evidence expectations for each control. The attestation was achieved, after my handover in the final phase.

Discuss a programme

The combination that is usually missing

Compliance programmes rarely fail on the regulation. They fail on the translation: the consultant knows the catalogue but not the platform. The engineer knows the platform but not what the auditor actually wants to see. In between, a ping-pong of criteria tables and queries develops that costs months.

I stand at that point. Twenty years of infrastructure and network practice mean I can discuss a logging, segmentation or hardening control with the person responsible, rather than sending them a line from the catalogue and waiting for an answer. And I know the other side of the table: an auditor does not want a collection of policies but evidence that a control actually works.

What sets me apart is judgement: in a programme with a hundred open items, seeing immediately what genuinely sits on the critical path to attestation.

Services

BSI C5

gap analysis against the criteria catalogue, agreement of interpretation and test conditions with the auditor, mapping against existing control sets, translation into technical requirements, evidence governance through to audit readiness.

ISO 27001 / 27002

ISMS development, control design and implementation, internal audit processes, preparation for certification audits.

GDPR

DSMS development, policy framework, record of processing activities, technical and organisational measures, training, audit documentation. Eight years of practice as an external data protection officer for several companies.

Audit management

interface between the technical organisation and the external auditor, evidence collection and management, enablement of control owners, preparation and support during the audit.

NIS2, CER/KRITIS, EU AI Act

regulatory assessment, applicability analysis, derivation of what needs to be done. Worked through, without prior project reference – I say that up front, not in the meeting.

How a programme runs with me

Establish the gap position.

What already exists, where existing controls apply, where there is genuinely a gap. Where an ISO 27001 control set is in place, the route to C5 is shorter than most assume – provided someone does the mapping properly.

Clarify interpretation with the auditor before work begins.

The most expensive mistake in an attestation programme is evidence that is not accepted at the end. I agree test conditions and evidence expectations for each control in advance.

Translate into technical requirements.

Not "control X is to be implemented", but specifically what the platform, infrastructure or security team has to do – in their language and with the reasoning behind it.

Enable and lead the control owners.

Compliance does not work by assignment. Those responsible have to understand why something is required, otherwise paper is produced instead of effect.

Govern the evidence, one interface to the auditor.

I am the single point of contact externally. That protects your teams from direct queries and the auditor from contradictory answers.

Hand over repeatably.

An attestation is not a project with an end but a state that has to be confirmed annually. I build in the routines that carry that – otherwise your successor is at the same point in twelve months.

Who this is for

Cloud and platform providers

who need a C5 attestation because their customers in the public sector or in regulated industries ask for one.

Companies facing ISO 27001 certification

who find that policies alone are not enough.

Organisations with an audit coming up

and no one to drive the programme through to the result.

Companies under NIS2 or within the scope of the EU AI Act

who first need to know whether and how far they are affected at all.

Framework

AVAILABLE

SCOPE
According to programme scope
DEPLOYMENT
DACH region, remote with presence at audit dates and critical phases
LANGUAGES
German and English – audit communication in both languages

Short profile compliance & audit – PDF Full CV – German and English

Do you need an ongoing data protection officer? An external DPO mandate is a standing obligation, not a project – for that, falocon Ltd (www.falocon.com) is the right address. This site is about fixed-term work with a clear result.

What is coming up for you?

Tell me the framework and the deadline. In a first conversation I will tell you whether that is realistic – even if the answer is uncomfortable.

Request a conversation