
Collegium Auditores GmbH provides in-depth professional expertise in internal audit, IT audit, compliance, data protection and information security. We help clients make risks transparent, design effective controls and implement regulatory and organisational requirements in a traceable manner.
Our approach combines independent assurance, practical advice and clear communication. Clients do not receive standardised solutions, but an approach tailored to their organisation, risk profile and specific areas for action.
Integrated IT audit, data protection and IT/AI compliance expertise
We support clients from risk assessment and audit planning through the evaluation of controls and management systems to the development of appropriate measures. We consider not only individual requirements, but also interfaces, responsibilities and potential follow-on effects. This creates robust decision-making information for executive management, supervisory functions, internal audit, compliance, data protection and information security.
Our professional service areas
- Internal audit and IT audit: risk-based audits, control assessments, IT governance and traceable audit reports
- Compliance and IT compliance: analysis of regulatory requirements and the design and assessment of appropriate compliance structures
- Data protection: privacy management, data protection audits and support as an external Data Protection Officer
- Information security: security governance, ISMS, ISO 27001 and BSI IT-Grundschutz
- Regulation and resilience: NIS2, BSIG, requirements for critical infrastructure and DORA
- AI literacy and AI governance: organisational guardrails, roles, controls and practical training for the responsible use of artificial intelligence
International experience and European requirements
A particular focus of our work is supporting internationally active companies from North America and Asia with their business activities in Europe. We advise clients that operate in the European Union, offer products or services in the European market or process personal data in the EU. We combine an international perspective with in-depth knowledge of European requirements and clear, accessible professional communication.
Professional leadership and extensive practical experience
Collegium Auditores GmbH was founded in 2018 by Andreas H. Schmidt LL.M. Our work is based on more than 25 years of experience in IT audit, internal audit, data protection and IT/AI compliance. This experience is complemented by a professional network of specialised partners and experienced practitioners.
Certifications and qualifications within the company
Our capabilities are supported by recognised certifications and practical qualifications in the specialist areas that matter to our clients.
IT audit, information security and IT governance
- Certified Information Systems Auditor (CISA, ISACA)
- ISO 27001 Auditor
- BSI IT-Grundschutz Practitioner
- Information Security Officer (TÜV)
- ITIL Practitioner
- COBIT Practitioner
Data protection and privacy engineering
- Certified Information Privacy Professional/Europe (CIPP/E, IAPP)
- Certified Data Privacy Solutions Engineer (CDPSE, ISACA)
- Data Protection Auditor (TÜV)
Compliance and AI governance
- IT Compliance Manager (TÜV)
- Compliance Officer (TÜV)
- Compliance Auditor (TÜV)
- AI Manager (Everlast AI Academy)
Sustainability and greenhouse gas verification
- Greenhouse Gases Auditor under ISO 14064-3, ISO 14065 and ISO 14066 (SGS)
- Sustainability Manager
Professional expertise through a specialist network
Complex audit, governance and compliance matters often require different professional perspectives. We therefore involve suitable specialists according to the engagement. Clear responsibilities, coordinated audit procedures and traceable results form the basis of our cooperation.
Clients benefit from the expertise of a specialised professional network combined with reliable, centrally coordinated support.
Discuss your requirements with us
Would you like to assess risks, prepare for an audit, interpret regulatory requirements or improve control and management systems? Contact us. Together, we will determine which support is appropriate for your organisation.
