โ† Back to Site ๐Ÿ–จ๏ธ Print / Save as PDF ๐Ÿ“ง Email Me

EMRE TUNCOGLU

Technology Risk & AI Governance Executive
CRISC CISSP TOGAF 9.1 CISA CISM ISO 27001 LA PRINCE2
๐Ÿ“ London, UK
๐Ÿ“ง contact@enftc.co.uk
๐Ÿ”— https://linkedin.com/in/emretuncoglu
๐ŸŒ enftc.co.uk

Key Achievements

Regulatory Restrictions Lifted
Closed critical audit with no major findings for Capital.com, enabling removal of new client onboarding restrictions
Compliance-by-Design
Designed and implemented a regulatory and policy compliance enforcement system integrated within change management and SDLC methodology at UBS
EU AI Act Compliance Platform
Designed and built a multi-tenant platform mapping 55 EU AI Act obligations against 110 ISO/IEC 42001 & NIST controls, with LLM-assisted evidence review and PostgreSQL-level tenant isolation (Jan 2026 โ€“ present)

Professional Summary

A Senior Technology Risk & Security Executive with a 25-year tenure in the Financial Services industry. Specializes in leading AI transformations in risk management and navigating the intersection of technical infrastructure and regulatory frameworks (EU AI Act, DORA, GDPR, FCA/PRA). From architecting RAG-model solutions for policy automation to building production-grade AI compliance platforms and regulation-to-control mapping engines, and steering multi-skilled teams through regulatory audits, provides hands-on expertise for complex remediation and resilience strategies.

Core Competencies

Regulatory Compliance
EU AI Act, DORA
BCBS 239, HKMA/MAS TRM
SOX, FCA/PRA
GDPR, MIFID II
Technical Architecture
AI/LLM Governance
RAG-Model Solutions
Azure & GCP Security
DevSecOps, IaC Validation (Checkov/Rego)
IAM/PAM
Risk Management
Operational Resilience
IT Audit & Assurance
Control Frameworks
Leadership
C-Suite Engagement
Audit Defense
Crisis Management
Team Coaching & Mentoring

Professional Experience

ENFTC Dec 2014 โ€“ Present
Director / Principal Consultant Greater London, UK ยท Hybrid
  • Founder of a specialist consultancy providing security architecture, technology risk management, and AI transformation services to clients in Fintech, Banking, and Insurance. All subsequent contract roles from March 2015 onward were delivered through ENFTC.
  • AI-Compliance Platform โ€” Founder & Product Lead (Jan 2026 โ€“ Present): Designed and built a multi-tenant EU AI Act compliance assessment platform mapping 55 EU AI Act obligations against 110 ISO/IEC 42001 & NIST AI RMF controls โ€” with deterministic risk classification, LLM-assisted evidence review, penalty-tier-weighted scoring, and automated regulatory deadline monitoring. 55 obligations ยท 110 controls ยท 48 API endpoints
  • Compliance Engine โ€” Regulation-to-Control Mapping (2026): Built a CLI/database engine mapping 2,167 regulatory requirements across 15 frameworks โ€” DORA with all 6 Level 2 RTS, PCI DSS 4.0.1, NIST CSF 2.0, ISO 27001:2022, UK FCA/PRA โ€” to 487 implementation controls (CIS Controls v8.1.2, NIST SP 800-53r5) with 4,679 verified mappings, dual-engine automated validation (1,359 Checkov + 916 Rego/OPA policies), and auditor-ready evidence mapping. 2,167 reqs ยท 487 controls ยท 2,275 policies
  • LLM-Assisted Review Engineering: Engineered a structured LLM review pipeline with JSON-mode output validation, prompt-injection defence, and per-review cost telemetry; developed end-to-end using AI-assisted development workflows (Claude Code).
  • Production Hardening: Led the production hardening cycle โ€” repairing PostgreSQL row-level security, migration-chain, and async-worker defects that SQLite-only testing had masked; delivered 430 automated tests and a CI pipeline verifying multi-tenant isolation against real PostgreSQL on every push. 430 automated tests
  • Architected RAG-model solutions using Large Context Window LLMs to automate policy uplift and regulatory compliance mapping, achieving up to 85% automation rates.
  • Delivered Compliance-as-Code frameworks integrating regulatory checks into CI/CD pipelines for major financial institutions.
Capital.com Sep 2024 โ€“ Dec 2025
Technology Risk & Regulatory Compliance SME City of Westminster, London, UK ยท Hybrid
  • DORA Compliance Programme: Spearheaded the DORA implementation programme by architecting a RAG-model solution (using Large Context Window LLMs) to automate policy uplift, ensuring accurate coverage of IT Asset, Change, Access Management, and Vulnerability Management standards. Automated 85% of compliance mapping
  • Compliance as Code: Designed a full set of automated controls, working with DevOps teams to integrate regulatory compliance checks early in the CI/CD pipeline for all major projects.
  • Regulatory Remediation (PAM): Remediated critical, long-standing Privileged Access Management (PAM) non-compliance, bridging Technical/CISO teams and Regulatory Auditors to close a multi-year audit finding. The external auditor validated the remediation and the regulator subsequently lifted all new client onboarding restrictions. โœ… Restrictions lifted
  • Resilience Strategy: Partnered with the CIO to map key business services and dependencies, delivering a prioritized Business Continuity Planning (BCP) and Technology Resilience strategy. BCP & Resilience plan delivered
Bupa Nov 2023 โ€“ Feb 2024
Technology Risk Consultant City of London, UK
  • Led validation of a major risk remediation programme, ensuring all critical findings were properly addressed and control gaps closed.
  • Conducted a comprehensive technology risk and controls framework review, identifying areas for improvement in the control environment.
  • Assessed policy compliance against regulatory requirements and internal standards, providing actionable remediation recommendations.
Deloitte Consulting Feb 2022 โ€“ Jul 2023
Subject Matter Expert โ€” Technology Risk & Architecture Greater London, UK ยท Remote
  • Cloud Security Architecture: Conducted end-to-end security architecture and control assessments for a large insurance firm's migration to Microsoft Azure (2,500+ VMs), identifying and remediating compliance gaps.
  • Challenger Bank Resilience: Defined data management strategies and cyber resilience scenario testing for a challenger bank, ensuring protection against insider threats and compliance with GDPR.
  • Algorithmic Trading Audit: Performed a comprehensive cybersecurity review of a Fintech trading firm to ensure IP protection and MIFID II compliance.
UBS Jun 2020 โ€“ Sep 2021
Technology Risk & Security Architecture SME Greater London, UK / Zurich, Switzerland ยท Hybrid
  • Cost Reduction: Coordinated external audit efforts throughout Group Technology, implementing a standardized audit response framework that reduced overall audit costs to UBS by ~40%. ~40% cost reduction
  • Cloud Migration Risk: Performed risk assessments for file transfer technologies migrating to cloud (Azure, AWS), identifying 23 compliance gaps and defining remediation roadmaps.
  • Regulatory Change Management: Managed requirements for MAS TRM and HKMA TPRM, defining remediation roadmaps for non-production environments and insider threat monitoring.
  • Control Implementation: Validated the sustainability of data protection controls for internal auditors and closed critical risk issues related to data corruption detection.
Aviva Group Mar 2020 โ€“ Jun 2020
Interim Head of IT Audit โ€“ CIO Global Greater London, UK ยท Hybrid
  • Led the global audit function for the CIO domain, covering infrastructure, architecture, strategy, and resilience across all business units.
  • Defined the IT Audit universe and developed a risk-based multi-year audit plan, ensuring comprehensive coverage of critical technology risks.
  • Coached and developed the audit team to improve delivery quality and strengthen stakeholder relationships across the organization.
UBS Jan 2019 โ€“ Mar 2020
Infrastructure & Security Architect Greater London, UK ยท Hybrid
  • Designed and implemented a technology infrastructure compliance framework integrated into the SDLC, ensuring security controls were embedded from design through deployment.
  • Enforced compliance across ~800 on-premise and MS Azure assets across US, UK, Switzerland, and Singapore, covering Access Control, Cryptography, and Vulnerability Management.
UBS ยท Group Internal Audit Feb 2018 โ€“ Dec 2018
Core IT Audit Director โ€” Technology Risk SME Greater London, UK ยท On-site
  • Executed high-profile audits within Cyber Security Governance, Data Governance (BCBS 239), and Middleware, delivering actionable findings to senior management.
  • Assessed the "Cyber Security by Design" framework, reviewing secure development controls for infrastructure and applications to ensure alignment with regulatory expectations.
Lloyds Banking Group Mar 2015 โ€“ Dec 2017
Infrastructure Security Architecture & Audit SME (via ENFTC) Greater London, UK ยท On-site
  • Delivered end-to-end audits of security architecture design across the Group's infrastructure, including Linux, Windows, IBM Mainframe, and HPE Non-Stop platforms.
  • Identified critical gaps in privileged access, event logging, and patch management, driving significant improvements in the Group's overall security posture.
KPMG UK Oct 2013 โ€“ May 2014
Technology Risk Advisory London, UK
  • Delivered technology risk advisory services to financial services clients, focusing on IT controls assessment and regulatory compliance.
Euroclear Group Aug 2008 โ€“ Jan 2013
Senior IT Audit Manager Belgium ยท On-site
  • Managed complex IT audit engagements across the Euroclear Group, covering critical financial market infrastructure and settlement systems.
  • Developed audit methodologies and mentored junior team members, building a high-performing audit function.
Dexia Banking Group & Denizbank Jul 2005 โ€“ Jul 2008
Head of IT Risk & Controls Brussels Region, Belgium
  • Established and led the IT risk and controls function, designing control frameworks aligned with regulatory requirements for banking operations.
Tekstilbank Oct 2004 โ€“ Jul 2005
IT Controls Director Istanbul, Turkey
  • Directed IT controls operations, ensuring compliance with banking regulations and internal control standards.
Pamukbank Apr 2001 โ€“ Sep 2004
Senior IT Auditor Istanbul, Turkey
  • Conducted IT audits across banking systems and infrastructure, identifying control weaknesses and providing practical remediation recommendations.

Education

BSc, Electrical & Electronics Engineering
Middle East Technical University (METU), Ankara, Turkey โ€ข 1995 โ€“ 2000
METU is ranked among the top universities worldwide by Times Higher Education, World University Rankings.

Detailed Project Experience Appendix

AI-COMPLIANCE PLATFORM (ENFTC) | Founder & Product Lead
January 2026 โ€“ Present London, UK
EU AI Act Compliance Assessment Platform
Designed and built a multi-tenant compliance assessment platform translating the EU AI Act (Reg. 2024/1689) into an operational control framework. A three-layer model maps the EU AI Act's 55 obligations (including Digital Omnibus amendments) against 110 ISO/IEC 42001 and NIST AI RMF controls, then to automated evidence checks and human verdicts. 55 obligations โ†’ 110 controls
Deterministic Risk Classification Engine
Implemented the full EU AI Act classification pathway โ€” a structured assessment covering Article 5 prohibited practices, Annex III high-risk domains, GPAI systemic-risk thresholds, and Article 50 transparency โ€” with penalty-tier-weighted compliance scoring aligned to the regulation's fine structure (โ‚ฌ35M/7% down to โ‚ฌ7.5M/1.5%).
LLM-Assisted Evidence Review
Engineered a structured LLM review pipeline (JSON-mode output, Pydantic-validated with retry, prompt-injection defence) that assesses uploaded evidence against mapped obligations and controls, with per-review token and cost telemetry. ~$0.0007 per review
Production-Grade Multi-Tenant Architecture
Full-stack platform (FastAPI, React 19, PostgreSQL, Redis, Celery, S3/MinIO) with role-based access control, PostgreSQL row-level security enforcing tenant isolation, a full audit trail, and rate limiting. 48 REST endpoints across 10 modules; evidence management with SHA-256 integrity and upload validation; six report types including FRIA and EU Declaration of Conformity templates; automated deadline monitoring aligned to the EU enforcement timeline (Feb 2025 โ€“ Aug 2028).
Production Path Hardening & Test Discipline
Led a hardening cycle that found and fixed defects SQLite-only testing had masked โ€” a broken migration chain, unexecutable row-level security DDL, and multi-tenant context leaks in the async worker โ€” verified against real PostgreSQL. Delivered 430 automated tests (341 backend, 79 frontend, 10 E2E) with a CI pipeline that validates migrations and tenant isolation on every push. Built end-to-end using AI-assisted development workflows (Claude Code). 430 automated tests
COMPLIANCE ENGINE (ENFTC) | Founder & Product Lead
2026 London, UK
Regulation-to-Control Mapping at Scale
Mapped 2,167 regulatory requirements across 15 frameworks โ€” DORA with all 6 Level 2 RTS, PCI DSS 4.0.1, NIST CSF 2.0, ISO 27001:2022, UK FCA/PRA โ€” to 487 implementation controls (CIS Controls v8.1.2, NIST SP 800-53r5) with 4,679 typed requirement-to-control mappings. 2,167 reqs โ†’ 487 controls
Dual-Engine Automated Validation
Automated validation proving controls are deployed, not just documented: 1,359 Checkov IaC policies and 916 Rego/OPA policies (13 custom, all passing) evaluated via OPA CLI and Kubescape.
Auditor-Ready Evidence & Gap Analysis
Evidence bridge transforming process controls into auditable artifacts (1,126 tool-to-evidence mappings), per-framework audit runbooks, cross-framework gap analysis, and a tooling atlas of 356 products with ranked procurement recommendations.
CAPITAL.COM | Technology Risk & Regulatory Compliance SME
September 2024 โ€“ December 2025 London, UK
DORA Compliance Programme
Spearheaded DORA implementation using RAG-model solution with Large Context Window LLMs to automate policy uplift. Ensured accurate coverage of IT Asset, Change, Access Management and Vulnerability Management standards. Automated 85% of compliance mapping
Compliance as Code Pipeline Integration
Designed a full set of automated controls, working with DevOps teams to integrate regulatory compliance checks early in the CI/CD pipeline for all major projects.
Regulatory Onboarding Restrictions Lifted
Successfully closed critical audit with no major findings after remediating long-standing Privileged Access Management (PAM) non-compliance. Acted as primary translator between Technical/CISO teams and Regulatory Auditors.
โœ… REMOVAL OF NEW CLIENT ONBOARDING RESTRICTIONS
Technology Resilience Strategy
Partnered with the CIO to map key business services and dependencies, delivering a prioritized Business Continuity Planning (BCP) and Technology Resilience strategy.
UBS | Technology Risk & Security Architecture SME
June 2020 โ€“ September 2021 London, UK / Zurich, Switzerland
Audit Cost Optimization
Coordinated external audit efforts throughout Group Technology, implementing standardized audit response framework that reduced overall audit costs to UBS by ~40%.
Cloud Migration Risk Assessment
Performed risk assessments for file transfer technologies migrating to cloud (Azure, AWS), identifying 23 compliance gaps and defining remediation roadmaps.
Regulatory Change Management
Managed requirements for MAS TRM and HKMA TPRM, defining remediation roadmaps for non-production environments and insider threat monitoring.
DELOITTE UK | Technology Risk & Architecture SME
February 2022 โ€“ July 2023 London, UK
Cloud Security Architecture Assessment
Conducted end-to-end security architecture and control assessments for a large insurance firm's migration to Microsoft Azure (2,500+ VMs), identifying compliance gaps and recommending remediation measures.
Challenger Bank Resilience Programme
Defined data management strategies and cyber resilience scenario testing for a challenger bank, ensuring protection against insider threats and GDPR compliance.
Algorithmic Trading Cybersecurity Review
Performed comprehensive cybersecurity review of a Fintech trading firm to ensure IP protection and MIFID II compliance, identifying key vulnerabilities in the trading platform architecture.
BUPA UK | Technology Risk Consultant
November 2023 โ€“ February 2024 London, UK
Risk Remediation Programme Validation
Led independent validation of a major technology risk remediation programme, verifying that all critical findings were properly addressed and control gaps sustainably closed.
Technology Risk & Controls Framework Review
Conducted comprehensive review of the technology risk and controls framework, assessing policy compliance and identifying areas for control environment enhancement.
AVIVA GROUP | Interim Head of IT Audit โ€“ CIO Global
March 2020 โ€“ June 2020 London, UK
Global Audit Function Leadership
Led the global audit function for the CIO domain, covering infrastructure, architecture, strategy, and resilience. Defined the IT Audit universe and developed a risk-based multi-year audit plan.
Team Development & Stakeholder Engagement
Coached the audit team to improve delivery quality and strengthened stakeholder relationships across the organization, enhancing the function's strategic value.
LLOYDS BANKING GROUP | Infrastructure Security Architecture & Audit SME
March 2015 โ€“ December 2017 London, UK
Cross-Platform Security Architecture Audits
Delivered end-to-end audits of security architecture design across the Group's entire infrastructure estate โ€” Linux, Windows, IBM Mainframe, and HPE Non-Stop โ€” identifying critical gaps in privileged access, event logging, and patch management.
Security Posture Improvement
Drove significant improvements in the Group's overall security landscape by highlighting key control gaps to senior management and articulating complex technical issues in accessible business language.
Last Updated: August 2026 โ€ข London, United Kingdom โ€ข www.enftc.co.uk