I build end-to-end process architectures for financial institutions and regulated firms, then wire AI into them — so the same model that satisfies MaRisk, BAIT and internal audit is the one that drives the automation.
Process architecture, BPMN 2.0 modelling standards, internal control system, written order integration and strategic architecture — built as one connected landscape rather than six disconnected documents.
AI transformation initiatives and compliant agentic process design: redesign the process first, then let agents run it — with controls, evidence and audit trail attached to every step.
This is the plan for the engagement clients ask for most often: process mapping and the information requirements behind it. Five phases, with change communication planned in the first half and executed in the second. Duration depends on resources, prioritisation, the size of the operating model and the number and complexity of processes. Select a phase to see what it delivers.
{{ active.detail }}
The AI-assisted workflow is not a separate tool bolted onto the operation. It is change-management automation that runs on the process documentation — and on the information embedded in that documentation. No architecture, no automation.
{{ b.body }}
“A process architecture is built with models as a house is built with stones — but a collection of models is no more an architecture than a heap of stones is a house.”
A 45-minute call to look at your landscape and the regulatory pressure you are working under, and to establish whether this approach fits — before either of us commits to anything.
Six layers, one landscape. Each layer is delivered as a working artefact in your own tooling — Signavio, Camunda or equivalent — not as a slide deck.
{{ ctaLabel }}{{ l.body }}
Where process management sits decides whether standards hold. We pick the model against your size, your project load and your existing centres of excellence.
| Model | Works when | Advantage | Cost |
|---|---|---|---|
| {{ m.name }} | {{ m.when }} | {{ m.pro }} | {{ m.con }} |
Most regulated firms I meet sit between level 2 and 3. Level 4 is where AI enablement stops being a pilot.
Most organisations have more documentation than they think, and less structure than they need. A short call is usually enough to see which of these layers are in place and which are missing.
Digital initiatives rarely fail for lack of ambition. They stall when process ownership, risk controls, information requirements and change delivery pull in different directions.
{{ ctaLabel }}Industry research on why AI programmes underperform — and it is almost never the model.
This runs on both project and product management methods, because it is both. The solution is designed like a product — technical documentation, requirements, iterations, an owner after go-live — while delivery is governed like an internal IT project under MaRisk, with a business case, defined roles and documented decisions. Skip either half and the initiative either fails the audit or stalls after the pilot.
Designing for agents that cannot afford to be wrong. In a regulated institution the question is not whether an agent can complete the task — it is whether it understood why the task exists, and whether anyone can reconstruct its reasoning afterwards.
{{ c.body }}
Under the EU AI Act, deployers of high-risk systems are expected to monitor risk continuously and keep mitigating controls in place — which makes auditability a design requirement, not a reporting exercise.
In most cases the constraint sits in the process rather than the model. A short call is usually enough to tell which one you are dealing with.
Leader in business process management and business architecture
Ten years in operations, eight of them leading — multicultural teams of 15 to 35 people, with first- and second-line responsibility. My work sits where Lean Six Sigma, business architecture, regulatory compliance and automation meet: scalable frameworks that hold up under a BaFin audit and still make the day job faster.
45 minutes, no deck. Bring one process that hurts — approvals, onboarding, incident handling, third-party risk — and we will map where the architecture is missing and what an AI-assisted version would actually change.