PatrickUpmann
Autor · The AI Governance Operating Series Founder & Architect · AIGN.Global · AIGN OS 4.0
Author · The AI Governance Operating Series
Sechs Formate.
Ein roter Faden: kritische Systeme.Six formats.
One throughline: critical systems.
Von der kompakten Standortbestimmung bis zum vollständig dokumentierten Betriebsmodell für maschinelle Autorität — mit besonderem Fokus auf Energie, Finanzinfrastruktur, Mobilität, Telekommunikation und Defence/Dual-Use.From a compact briefing to a fully documented operating model for machine authority — with a particular focus on energy, financial infrastructure, mobility, telecommunications, and defence/dual-use.
Der Nachweis hinter
dem Anspruch.The evidence behind
the claim.
„KI-Governance kann keine reine Policy-Übung mehr bleiben. Die nächste Ära wird durch Nachweise, Klassifizierung, Berechtigung, Laufzeitkontrolle und Vorstands-Assurance definiert.“„AI governance can no longer remain a policy exercise. The next era will be defined by evidence, classification, permission, runtime control, and board-level assurance.“— Patrick Upmann · The AI Governance Operating Series, 2026
30+ Mandate seit 2014 — von Interim Governance Lead bis Fractional CAIO, immer mit belegbaren Ergebnissen: prüfungssichere Strukturen, regulatorische Prüfbereitschaft, operative Kontrollsysteme. Die folgende Auswahl zeigt die sechs profiliertesten Mandate im Umfeld kritischer Infrastruktur — KRITIS markiert sie durchgehend.30+ engagements since 2014 — from Interim Governance Lead to Fractional CAIO, always with verifiable outcomes: audit-ready structures, regulatory readiness, operational control systems. The selection below highlights the six most significant engagements in critical-infrastructure contexts — all flagged KRITIS.
| ZeitraumPeriod | KundeClient | RolleRole | ErgebnisseOutcomes |
|---|---|---|---|
| 2024 | E.ON KRITIS | Data Governance & Controls Architect (Interim)Data Governance & Controls Architect (Interim) | Kundendatenplattform mit Consent-Automatisierung (+30 % Effizienz); Data Ownership & ZugriffskontrolleCustomer data platform with consent automation (+30% efficiency); data ownership & access control |
| 2024 | BSR KRITIS | Regulatory Governance Lead – DSGVO/NIS2 (Interim)Regulatory Governance Lead – GDPR/NIS2 (Interim) | SAP-Lösch-/Aufbewahrungskonzept; NIS2-Readiness & S/4HANA-Migration begleitetSAP deletion/retention concept; NIS2 readiness & S/4HANA migration support |
| 2023 | MEAG (Munich Re) KRITIS | Risk & Audit Readiness Lead – DORA/NIS (Interim)Risk & Audit Readiness Lead – DORA/NIS (Interim) | ISMS + Risiko-Framework; DORA-/NIS2-Anforderungen operationalisiertISMS + risk framework; DORA/NIS2 requirements operationalised |
| 2023 | Viridium KRITIS | Governance & Access Control Lead – DSGVO/ICT (Interim)Governance & Access Control Lead – GDPR/ICT (Interim) | Datenschutz-Audit; Governance-Rollenmodell für KernsystemeData protection audit; governance role model for core systems |
| 2021–23 | Mobility Inside KRITIS | ISMS & Datenschutz & Governance Lead (Interim)ISMS & Data Protection & Governance Lead (Interim) | Governance-Betriebsmodell für Mobilitätsplattform; Deutschlandticket DSGVO-konformGovernance operating model for mobility platform; Deutschlandticket GDPR-compliant |
| 2023 | Uniper KRITIS | Data Governance & DatenschutzData Governance & Data Protection | Umsetzbares Aufbewahrungskonzept im M365-KontextActionable retention concept in the M365 context |