Independent advisory · Luxembourg & international

Finance, risk, compliance and audit. Connected and put into practice.

I connect finance, operations, governance, risk and compliance to help leaders see where they want to go, what stands in the way and how to make change work in practice.

For boards and management, and heads of risk, compliance and internal audit seeking practical change with business teams.

Discuss your challenge
The challenge

When functions work in silos, decisions become harder and more costly.

Teams may be busy producing evidence while processes, emerging risks, financial consequences and ownership remain unclear. I start with the business model and objectives, compare actual ways of working with regulatory expectations and relevant practice, and help decide what to improve, what to monitor and where controls add value.

What I help you solve

Six connected disciplines. One business view.

Choose a focused assignment in one area, or connect the functions around a decision, transformation or regulatory change.

For financial services and fintech, insurers and captives, and industrial groups.

01

Governance

When responsibilities and follow-up are unclear, decisions can stall between committees and teams.

Clarify responsibilities, decision information and follow-up so oversight leads to action.

02

Finance & insurance

When reporting, costs and insurance flows are disconnected, management may lack a clear financial picture.

Connect controlling, consolidation and insurance operations to management decisions.

03

Risk & internal controls

As risk maps and control libraries grow, priorities can become harder to see.

Identify and challenge risk scenarios; assess likelihood and financial, reputational, regulatory and operational impacts; prioritise risk exposures and agree responses. Separately, strengthen internal control design, implementation and effectiveness.

Two connected disciplines, distinct responsibilities

Risk management — four practical stages

  1. Identify risks and challenge scenarios against business objectives.
  2. Assess likelihood and financial, reputational, regulatory and operational impacts; prioritise exposures against risk appetite.
  3. Agree responses: avoid, reduce, share or accept risks, with accountable owners.
  4. Monitor and report indicators, emerging risks, actions and residual exposures; adapt responses.

Internal control — four delivery stages

  1. Map objectives, risks, existing controls and responsibilities.
  2. Design or improve controls, procedures and evidence requirements.
  3. Implement controls with owners, frequency and documentation.
  4. Test design and operating effectiveness, report deficiencies and follow remediation.

These are practical delivery stages, not COSO’s component count. The internal control review draws on COSO’s five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Management owns risks and controls; risk and compliance provide oversight and challenge, while internal audit provides independent assurance.

04

Compliance

When obligations are treated as checklists, their connection to business processes can be lost.

Map obligations to risks, controls, owners and evidence, then test whether they work.

05

Internal audit

When findings recur, the underlying process may need a closer look.

Perform risk-based operational and finance reviews and turn findings into feasible action.

06

AI-assisted monitoring

Risk, compliance and audit need timely evidence as processes and requirements change.

Use approved AI to support mapping, testing and documentation, with professional validation and each line’s independence preserved.

AI-assisted testing in practice

A focused pilot can map applicable regulatory requirements to the internal governance framework—policies, procedures and processes—then review controls, assess evidence and draft completed testing templates and findings. A pilot can connect these steps through AI agents, with reviewer checkpoints. Professionals assess which tasks can be automated and validate every conclusion against evidence.

Explore four practical AI use cases
Use caseInputAI assistanceHuman validationOutput
Regulatory mapping to the internal governance frameworkApplicable regulation and supervisory guidance; domain-specific policies, procedures and process documentation; relevant market practices and standardsMap requirements to policies and flag gaps; then assess whether procedures and documented processes reflect the required policy provisions and relevant practices and standardsConfirm applicability and source versions; validate policy coverage and gaps, and the alignment of procedures and processes. Distinguish mandatory requirements from recommended practicesTraceable requirements-to-policy-to-process mapping and a gap register with owners
Control review and testing readinessRisk to be mitigated, control objective and description, testing criteria and expected evidenceAssess whether the objective addresses the risk and whether the description provides clear, testable steps; flag missing owners, frequency or evidence requirementsValidate risk–objective alignment, control wording and testing readiness before proceedingReviewed control descriptions and agreed testing requirements
AI-assisted control testingReviewed control objective and description; evidence collected for design and operating-effectiveness testing; testing templates and criteriaAssess which test steps can be automated; use AI agents to compare evidence with the control requirements and draft completed design and operating-effectiveness templates, citing evidence and flagging gapsCheck evidence relevance and sufficiency, review every template requirement and validate exceptions and conclusions before sign-offDraft completed testing templates with traceable evidence, exceptions and conclusions for reviewer approval
Finding draftingTest notesStructure condition, criteria, cause, risk and actionCheck accuracy and wordingFindings for discussion with owners

Regulatory mapping to the internal governance framework

Input
Applicable regulation and supervisory guidance; domain-specific policies, procedures and process documentation; relevant market practices and standards
AI assistance
Map requirements to policies and flag gaps; then assess whether procedures and documented processes reflect the required policy provisions and relevant practices and standards
Human validation
Confirm applicability and source versions; validate policy coverage and gaps, and the alignment of procedures and processes. Distinguish mandatory requirements from recommended practices
Output
Traceable requirements-to-policy-to-process mapping and a gap register with owners

Control review and testing readiness

Input
Risk to be mitigated, control objective and description, testing criteria and expected evidence
AI assistance
Assess whether the objective addresses the risk and whether the description provides clear, testable steps; flag missing owners, frequency or evidence requirements
Human validation
Validate risk–objective alignment, control wording and testing readiness before proceeding
Output
Reviewed control descriptions and agreed testing requirements

AI-assisted control testing

Input
Reviewed control objective and description; evidence collected for design and operating-effectiveness testing; testing templates and criteria
AI assistance
Assess which test steps can be automated; use AI agents to compare evidence with the control requirements and draft completed design and operating-effectiveness templates, citing evidence and flagging gaps
Human validation
Check evidence relevance and sufficiency, review every template requirement and validate exceptions and conclusions before sign-off
Output
Draft completed testing templates with traceable evidence, exceptions and conclusions for reviewer approval

Finding drafting

Input
Test notes
AI assistance
Structure condition, criteria, cause, risk and action
Human validation
Check accuracy and wording
Output
Findings for discussion with owners

The pilot uses only an environment authorised by your organisation, such as your enterprise AI tools. Sources remain traceable; professional judgment and the distinct roles of risk, compliance and internal audit guide the conclusions.

Ways to engage

A focused first step, then hands-on delivery.

A first assignment could examine one important process: map how it actually runs, identify its obligations and material risks, test the relevant controls and agree a short action plan with owners. An assignment may also focus on financial reporting, insurance operations or board and committee effectiveness.

Reference frameworks include AML/CFT and the EU AML package, DORA, CSSF and Commissariat aux Assurances expectations, and the EU AI Act. Applicable requirements and scope are agreed for each assignment.

Selected experience

Three examples behind the offer.

Board and executive perspective. Director and executive approved by the Commissariat aux Assurances, Luxembourg’s insurance regulator, at ArcelorMittal Insurance Consultants; director and CFO of a captive reinsurer, and manager of its captive holding company.
Finance and transformation. Coordinated IFRS group reporting across four captives through their merger into one entity, and implemented a group insurance system connecting programme data, premiums, claims and reporting.
Regulated services and industrial operations. Developed a Copilot-assisted control-testing method at EIF; assessed operational and ICT risk and DORA readiness at bitFlyer Europe, and risk appetite and solvency capital at MS Amlin; served as Group Fixed Cost Controller at ArcelorMittal headquarters; worked in cost controlling at Volvo and financial control and site audit at Guardian.

These assignments and roles were undertaken in employment; they are presented as Nadine’s experience, not as UMN client work.

Bridge to Africa

For a market-entry or partnership project, I can coordinate an initial feasibility and risk review: map stakeholders, test financial and operational assumptions, identify local constraints and plan execution with relevant contacts.

Explore my network

My network spans Senegal, The Gambia, Benin, Burkina Faso, Côte d’Ivoire, Cameroon, Republic of the Congo, DR Congo, Rwanda, Ethiopia, Uganda, Kenya, Zambia and South Africa. Local partners and scope are agreed for each mandate.

Nadine Mugema
Your advisor

Nadine Mugema

Executive MBA (Vlerick Business School) · Master’s in Finance (IUP Finance) · Master’s in Management & Business Development (INSEEC) · Associate in Risk Management – ARM (The Institutes) · AML/KYC/Compliance certificate (EBU)

An independent advisor with more than 17 years across finance, insurance, regulated services and industry. My work in controlling, operations, second-line risk and compliance, and audit helps me connect strategic objectives to processes, financial impact and workable change. Board and insurance leadership experience informs the decisions I help clients make.

Available for non-executive director and risk, audit or compliance committee mandates, subject to independence and conflict-of-interest considerations.

Languages: English, French and Kinyarwanda (fluent) · Spanish (conversational) · Dutch (elementary)

Contact

What is taking effort without giving you clarity?

Tell me the decision, change or control challenge you are facing. We can define a focused first step.

Connect on LinkedIn

contact@umn-consulting.com · +352 691 83 86 34

umn-consulting.com