Skip to Content
Event SECURinsights 2026 starts on Sep 3, 2026, 12:00:00 PM (Europe/Berlin)
Compliance on Autopilot: From Policies to Auditable AI Controls – A Practical Approach Using AI Agents & SSDLC

Compliance on Autopilot: From Policies to Auditable AI Controls – A Practical Approach Using AI Agents & SSDLC

Crossfunctional
9/3/26, 3:00 PM - 9/3/26, 3:30 PM (Europe/Berlin) (30 minutes)
Compliance on Autopilot: From Policies to Auditable AI Controls – A Practical Approach Using AI Agents & SSDLC
Thomas Punz
CEO at SECURNITE
Thomas Punz
CEO at SECURNITE

Thomas Punz is a cybersecurity and governance expert with a strong focus on operationalizing compliance and making regulatory requirements practically actionable. As CEO of SECURNITE, he works closely with organizations across regulated industries to translate frameworks such as NIS2, DORA, and ISO 27001 into sustainable, auditable, and scalable solutions.

With a background in Physics, IT and Governance, Risk, and Compliance (GRC), Thomas specializes in bridging the gap between strategic requirements and technical implementation. His work focuses on building resilient control systems, integrating security into software development lifecycles, and leveraging modern technologies such as AI to increase efficiency and auditability.

He is particularly known for his pragmatic approach: reducing complexity, enabling automation in compliance processes, and designing governance models that work in real organizational environments, not just on paper.


This session demonstrates how regulatory requirements and internal policies (e.g., NIS2, DORA, ISO 27001) can be systematically translated into measurable and auditable controls, bridging the gap from policy definition to evidence generation.

Using an audited Secure Software Development Lifecycle (SSDLC) and generative AI, we illustrate how organizations can operationalize compliance in a scalable and repeatable way.

The result: significantly reduced manual effort in audit preparation, consistent and reproducible audit trails, and reliable KPIs for both auditors and executive management.

Participants will understand a proven blueprint for AI-supported control testing and evidence generation and learn how to effectively integrate AI into compliance and control workflows. In the end, everyone will take away governance artifacts and structures that meet auditor expectations.