Available for consulting & interim mandates

AI Compliance Architect for regulated industries

I build AI compliance systems that work – so your AI projects become compliant with the EU AI Act & GDPR. One person who understands both the technology and the regulation.

TÜV-certified
Financial sector
Hands-on, not paperwork
Carsten Wittmann, AI Compliance Architect at TUMAKI
Carsten Wittmann
🏆 TÜV Rheinland Certified AI Consultant
🔒 Certified Data Protection Officer
📋 Compliance Expert, Koerting Institute

The problem

Anyone can do AI. Making it compliant is the hard part.

Your CAIO knows AI but not compliance. Your compliance team knows the GDPR but not AI. TUMAKI closes exactly that gap.

Without a specialist
  • AI projects stall because nobody takes regulatory ownership
  • Consultants deliver paper, but no working implementation
  • AI Act deadlines approach without a clear roadmap
  • Double the cost for AI and compliance expertise bought separately
With TUMAKI
  • One person who thinks technology and regulation together
  • Testable compliance systems instead of mountains of paper
  • Clear risk classification and a prioritised roadmap
  • Audit-ready in weeks, not years

Specialisation

What I do for you

Three focus areas, one goal: your AI becomes legally sound, verifiable and ready to run.

📋

AI Act Readiness

Your AI systems classified, documented and prepared for the EU AI Act.

  • Risk classification of all AI systems
  • Gap analysis & compliance roadmap
  • Technical documentation
  • BaFin / EBA conformity
🛡️

AI Governance

Policies, roles and committees that actually hold up in day-to-day operations.

  • AI policies & guidelines
  • Risk management framework
  • Establishing roles and committees
  • Stakeholder management
🔒

Data Protection for AI

GDPR conformity from the training data through to live operation.

  • DPIA for AI/ML projects
  • GDPR assessment of AI services
  • Training data compliance
  • Privacy by design

All services & engagement models →

The method

Specification-Driven Compliance

Three principles from software engineering, applied to governance – so compliance scales instead of slowing you down.

Testability over interpretation

Rule-based decision structures instead of vague policies.

⚙️

Systems over documents

Automated approvals instead of manual case-by-case review.

🔎

Evidence over "trust me"

Every decision traceable and auditable.

The method in detail →

Frequently asked

Short & clear answers

Who does the EU AI Act apply to? +
The EU AI Act applies to providers and deployers of AI systems placed on the market or used in the EU – regardless of where the company is based. Companies outside the EU are also affected as soon as their AI systems are used within the EU. The specific obligations depend on the risk class of the system.
How long does an AI Act assessment take? +
An assessment covering risk classification, gap analysis and a roadmap typically takes 2 to 4 weeks. Building a complete compliance framework takes 6 to 12 weeks.
What sets TUMAKI apart from traditional consultancies? +
TUMAKI combines technical AI understanding with regulatory depth in one person. Instead of documents alone, the result is testable, verifiable compliance systems – implemented hands-on, not just on paper.
Do you also work as an interim manager? +
Yes. Alongside project-based assessments and framework design, I take on interim mandates of 3 to 12 months at 2 to 4 days per week – including hands-on project support, team enablement and preparation for BaFin audits.

Ready?

Let's talk about your AI compliance

A short intro call – free and without obligation. We clarify where you stand and what comes next.