01Define the task
We establish which workflow should change and who uses it.
We start with your specific project. We examine what information people need and which handovers hold up work. That establishes the brief for business and technical planning.
We establish which workflow should change and who uses it.
Business rules are connected to data sources and responsibilities.
An existing module or prototype makes unresolved decisions visible.
Work packages and acceptance criteria provide a basis for commissioning the next stage.
A functional specification defines inputs, workflow steps, roles and results. For a control process, this means identifying which records the responsible person reviews, how exceptions are documented, who approves an action and what reporting needs. Together with your institution, we translate those decisions into data fields, permissions and test cases.
The result must describe what needs to be built or changed.
Our advisory work connects regulatory requirements with daily operations. We structure requirements, link controls and evidence, describe processing and approval routes, and establish the data needed for management and reporting. The following work areas can be addressed individually or as a connected programme.
Connect ICT-related requirements with risks, responsibilities, evidence and practical work packages. Structure technical information for registers and provider management.
Describe control and processing workflows: what is checked, which evidence is produced, who handles a deviation and who approves the result?
Bring services, contracts, dependencies and responsibilities together. Prepare information for assessment, ongoing management and a future provider change.
Inventory AI use cases, data flows, models and responsible people. Define evaluation criteria, usage boundaries and the route from experimentation to approval.
Translate business decisions into data objects, forms, permissions, interfaces and clear test cases. Assess existing modules against the need for extensions.
Support business and IT teams through configuration, testing and acceptance. Work through agreed processes with the future team and hand them over for operation.
Potential deliverables include current and target workflows, a role and permission model, a data and interface inventory, and prioritised work packages with acceptance criteria. Requirements from your GRC framework are mapped to the relevant steps. This provides a basis for the institution’s decisions and the subsequent technical implementation.
| Work area | Deliverable | Use |
|---|---|---|
| Business process | Documented steps and exceptions | Business team review |
| Technical solution | Data model and interface description | Development planning |
| Testing and introduction | Test cases and acceptance criteria | Prepare approval |
Consulting may conclude with a specification or support the introduction of a solution. Configuration and development are included only when explicitly defined in the engagement.
| Starting point | Next step |
|---|---|
| The process is unclear | Business process review and specification |
| Feasibility is uncertain | Plan a limited prototype or AI proof of concept |
| Requirements are agreed | Commission configuration or development |
Our advice concerns business and technical implementation. It does not replace legal advice or an independent audit.
Christoph Gembruch brings experience in GRC process consulting and introducing GRC software. Andreas Unruh works on software architecture and GRC design. Both are managing directors of T-NEX GmbH.
Your project is considered from both business and technical perspectives.
Describe the current workflow and what should change. We will discuss a suitable consulting scope with you.
DORA since 17 January 2025: scope, ICT risk, incident reporting and third parties, with primary sources and implementation checks.
MaRisk under Circular 06/2026: scope, structure and relationship with DORA, including the limited transition and investment-firm distinction.
The DORA register of information: record contracts, identifiers and supply chains using the EU templates and BaFin requirements.