Christoph Gembruch is Managing Director of T-NEX GmbH. He advises on IT governance and information security, as well as implementing business requirements in GRC software. Before T-NEX, he worked in consulting at Tricept and Sopra Steria. He holds an MSc in International Financial Markets from the University of Southampton and a Diplom in Economics from the University of Bonn. His personal qualifications include ISO 27001:2022 Practitioner and BCM Practitioner under BSI Standard 200-4. His work connects financial-sector requirements with the practical implementation of software.
Areas of focus
- IT Governance, Risk & Compliance
- MaRisk
- BAIT
- DORA
- Information Security (ISMS / ISO 27001)
- Cybersecurity
- Business Continuity Management
- Banking Supervisory Law
- GRC Tool Implementation
Education
- MSc International Financial Markets, University of Southampton
- Diplom (Economics), University of Bonn
Certifications
- ISO 27001:2022 Practitioner – Information Security Officer (APMG, 2024)
- ISO/IEC 27001:2022 Foundation (APMG)
- Certified BCM Practitioner under BSI Standard 200-4 (2026)
- PRINCE2 Practitioner
- ITIL V4 Foundation
Articles
T-NEX articles on these topics
- NIS2 vs DORA: what applies to banks and their IT?Regulation · 9 min read
- RAG chatbots for banks: sources and answer qualityAI & Governance · Reading time: about 9 minutes
- AI agents in banking: operating limits and controlAI & Governance · Reading time: about 8 minutes
- EU AI Act for banks: classification and dutiesAI & Governance · Reading time: about 11 minutes
- EU AML package: AMLR, AMLD6 and AMLARegulation · Reading time: about 10 minutes
- GRC software for banks: selection criteriaTechnology & Operations · Reading time: about 15 minutes
- Regulatory roadmap for banks: dates from 2026 to 2028Regulation · Reading time: about 16 minutes
- Ninth MaRisk amendment: changes and implementationRegulation · Reading time: about 15 minutes
- MaRisk 2026: current version and requirementsRegulation · Reading time: about 15 minutes
- DORA register of information: content and submissionRegulation · Reading time: about 11 minutes
- DORA for financial entities: duties and implementationRegulation · Reading time: about 13 minutes
- Using ICAAP and ILAAP to manage a bankRegulation · 6 min read
- Understanding P2R and P2GRegulation · 6 min read
- MaRisk AT 9 and DORA in third-party managementRegulation · 7 min read
- Planning for CRR III, the output floor and FRTBRegulation · 7 min read
- IReF: prepare data and reporting processes earlyRegulation · 7 min read
- Which EBA guideline belongs to which task?Regulation · 3 min read
- Introducing GRC software: migrating registers and evidence from ExcelRegulation · 3 min read
- DORA TLPT: who needs testing and how is it prepared?Regulation · 3 min read
- ICAAP and SREP: processes and decision foundations at a glanceRegulation · 3 min read
- COREP and FINREP: differences and a shared data foundationRegulation · 3 min read
- The business case for GRC software: calculating costs and benefitsRegulation · 3 min read
- Solvency II: understanding capital requirements, ORSA and reportingRegulation · 4 min read
- AML sanctions screening: reviewing matches and documenting decisionsRegulation · 3 min read
- ISO 27001 and IT-Grundschutz: which approach fits your ISMS?Regulation · 3 min read
- GDPR retention periods in banks: classifying records correctlyRegulation · 4 min read
