ENFTC Logo
Technology Risk & AI Governance

AI-Driven Regulatory Compliance
& Technology Risk Architecture.

Specialized consultancy for Tier-1 Financial Institutions. Delivering AI-driven DORA compliance, operational resilience, and audit defense strategies.

View Executive Profile View Interactive CV
๐Ÿค– AI-COMPLIANCE PLATFORM ยท JAN 2026 โ€“ PRESENT
EU AI Act, automated: A production-hardened, multi-tenant platform mapping all 55 EU AI Act obligations to 110 ISO/IEC 42001 & NIST AI RMF controls โ€” LLM-assisted evidence review, penalty-tier-weighted scoring, and automated regulatory deadline monitoring.
40% Audit Cost Reduction (UBS)
25+ Years Financial Services Exp
100% Major Audit Success Rate
85% DORA Compliance Automation
55 EU AI Act Obligations Mapped
432 Automated Tests Passing
Emre Tuncoglu

Emre Tuncoglu

Principal Consultant & Director

CRISC CISSP TOGAF 9.1 CISA CISM ISO 27001 LA PRINCE2

A Senior Technology Risk & Security Executive with a 25-year tenure in the Financial Services industry. Emre specializes in leading AI transformations in risk management and navigating the intersection of technical infrastructure and regulatory frameworks (DORA, GDPR, FCA/PRA).

From architecting RAG-model solutions for policy automation to steering multi-skilled teams through regulatory audits, Emre provides hands-on expertise for complex remediation and resilience strategies. He has successfully led remediation programs for global institutions including UBS, Lloyds Banking Group, Deloitte, and Capital.com.

View Full Resume →

"Emre supported our Internal audit team as a subject matter expert in delivering IT audits during my previous role. Emre is highly technical, has a sound knowledge in Mainframe and associated security architecture reviews, where it is scarce to find those expertise these days. He highlighted some key control gaps to management during the mainframe and database audits. He was good at articulating technical and complex issues in a simple business language which helped senior management to effectively understand the business risks and impact."

โ€” Arun Subramanian, Director, Information Security Risk and Controls

Read all recommendations โ†’

Core Competencies

Bridging the gap between C-Suite strategic risk requirements and technical implementation.

๐Ÿค–

AI & LLM Governance

Architecting RAG-model solutions using Large Context Window LLMs for automated policy uplift. Ensuring safe AI adoption aligned with EU AI Act.

โš–๏ธ

Regulatory Remediation

Expert handling of DORA, GDPR, BCBS 239, and HKMA/MAS TRM requirements. Specializing in lifting regulatory restrictions and closing audit findings.

โ˜๏ธ

Cloud Security Architecture

Security design for Azure & GCP migrations. Implementing DevSecOps pipelines and "Compliance-as-Code" controls for automated validation.

๐Ÿ”

Compliance Automation & AI

Building the AI-Compliance Platform โ€” a multi-tenant EU AI Act assessment platform with LLM-assisted evidence review and penalty-tier-weighted scoring. Also delivering RAG-model policy mapping and continuous control monitoring for DORA.

The AI-Compliance Platform

A production-hardened, multi-tenant EU AI Act compliance platform โ€” translating regulation into auditable, automated controls. In development since January 2026, built end-to-end with AI-assisted development workflows.

๐Ÿงญ

Three-Layer Compliance Model

All 55 EU AI Act obligations (incl. Digital Omnibus amendments) mapped to 110 ISO/IEC 42001 & NIST AI RMF controls, then to automated evidence checks and human verdicts.

๐Ÿง 

Deterministic Risk Classification

Full EU AI Act classification pathway โ€” Article 5 prohibited practices, Annex III high-risk domains, GPAI systemic-risk thresholds, Article 50 transparency โ€” via a 20-question assessment.

๐Ÿค–

LLM-Assisted Evidence Review

Structured LLM review of uploaded evidence against mapped obligations โ€” JSON-mode output with validation, prompt-injection defence, and per-review cost telemetry.

โš–๏ธ

Penalty-Tier-Weighted Scoring

Compliance scores weighted by the regulation's actual fine structure โ€” โ‚ฌ35M/7% down to โ‚ฌ7.5M/1.5% โ€” with per-tier and per-article breakdowns.

๐Ÿ›ก๏ธ

Multi-Tenant Security

Role-based access control, PostgreSQL row-level security enforcing tenant isolation, a full audit trail, and deadline monitoring aligned to the EU enforcement timeline (2025โ€“2028).

โœ…

Verified by 432 Automated Tests

CI pipeline validating migrations and multi-tenant isolation against real PostgreSQL on every push โ€” 343 backend, 79 frontend, and 10 end-to-end tests across three browsers.

Trusted by Leading Institutions

UBS Lloyds Banking Group Deloitte Capital.com Aviva Euroclear KPMG