Expertise & method

Compliance that scales instead of slowing you down

I apply proven principles from software engineering to AI governance. The result: compliance becomes testable, verifiable and automatable – instead of disappearing into documents.

The method

Specification-Driven Compliance

Three principles decide whether compliance stays a cost driver – or becomes an enabler.

01 · Testability

Testability over interpretation

Rule-based decision structures instead of vague policies. What is testable is decidable – and can be automated.

02 · Systems

Systems over documents

Automated approvals instead of manual case-by-case review. Compliance runs inside the system instead of gathering dust in folders.

03 · Evidence

Evidence over "trust me"

Every decision traceable and auditable. No blind flying, no AI hallucinations – solid evidence at the push of a button.

Writing documents scales linearly building testable systems scales exponentially

Why this makes the difference

Two ways to run AI compliance

One adds manual work with every AI system. The other keeps paying off once the setup is done.

A
Writing documents
  • Policies get written and outputs are reviewed by hand
  • Every new case means new manual work
  • Effort grows linearly with the number of AI systems
  • Evidence is laborious and full of gaps
B
Building testable specifications
  • Rules are defined as a testable specification
  • The system checks and documents itself
  • Effort is spent once at setup, then it scales
  • Every decision is auditable automatically

TUMAKI works consistently towards class B – and gets you there without stalling your day-to-day operations.

Qualifications

What the method is built on

Certifications & roles

  • TÜV Rheinland Certified AI Consultant
  • Certified Data Protection Officer
  • Compliance Expert, Koerting Institute
  • Lean Six Sigma Master Black Belt
  • Speaker at industry conferences

Regulatory focus

  • EU AI Act (risk classes, Art. 9–15)
  • GDPR for ML/AI (DPIA, training data)
  • MaRisk & BAIT / VAIT for the financial sector
  • BaFin / EBA requirements
  • NIS-2, EU Data Act, Digital Omnibus

More about Carsten Wittmann →

Interested?

Let's look at your AI landscape

In an intro call I show how Specification-Driven Compliance applies concretely to your systems.