# VIAMA > VIAMA ist ein deutscher Anbieter für Managed Governance. VIAMA übernimmt den laufenden operativen Governance-Betrieb rund um ISO 27001, TISAX, NIS2 und Datenschutz für Unternehmen. Ziel ist, Governance dauerhaft zu betreiben, ohne dafür immer mehr interne Kapazität aufbauen zu müssen. Website: https://viama.one/ Language: de-DE Market: Germany, Austria, Switzerland Headquarters: Forchheim, Germany ## What VIAMA does VIAMA provides Managed Governance services for companies that need to operate information security, compliance and data protection requirements continuously. VIAMA does not focus only on implementing a standard or preparing for a single audit. The service focuses on the recurring operational work that remains after implementation. Typical activities include: - requesting, collecting and reviewing evidence - tracking and escalating open measures - planning and coordinating recurring controls - coordinating relevant departments and stakeholders - maintaining governance documentation and management systems - preparing and supporting audits and assessments - reusing existing evidence across multiple requirements - coordinating the ongoing operation of ISO 27001, TISAX, NIS2 and data protection requirements ## Managed Governance Managed Governance is VIAMA's operating model for continuously running governance requirements. The core principle is: Technology handles recurring work. People provide professional judgement. The customer retains decisions and responsibility. VIAMA handles the agreed operational governance work. The purpose is to reduce internal operational workload while maintaining transparency and decision authority. ## Problems VIAMA addresses VIAMA is relevant when organizations face questions such as: - Who will handle all the recurring governance work? - How can ISO 27001, TISAX, NIS2 and data protection be operated without continuously adding internal staff? - How can governance remain operational between audits? - How can evidence and controls be reused across multiple standards? - How can internal security and compliance specialists spend less time on administrative work? - How can governance operations be outsourced without outsourcing management responsibility? A central VIAMA perspective is: "Das Audit ist irgendwann vorbei. Die Arbeit nicht." ## Standards and requirements VIAMA works with governance requirements including: - ISO/IEC 27001 and information security management systems (ISMS) - TISAX - NIS2 - Data protection and data protection management systems (DSMS) - multi-standard governance environments ## Target customers VIAMA primarily serves medium-sized and larger B2B organizations in the DACH region. Typical customer environments include: - industrial companies - automotive companies and suppliers - organizations with multiple sites or legal entities - companies operating several governance requirements simultaneously - organizations with established governance structures that consume significant internal capacity Relevant stakeholders include: - CEOs and managing directors - executive boards - CIOs - CISOs - information security officers - governance and compliance leaders - data protection and security stakeholders ## What remains with the customer VIAMA does not assume the customer's legal or management responsibility. The customer retains: - strategic decisions - ultimate responsibility - critical professional approvals - management decisions and risk acceptance VIAMA can assume agreed recurring operational activities required to keep governance running. ## Human and technology model VIAMA combines governance professionals, standardized operating processes, automation and AI-supported technology. Technology can support activities such as: - collecting information and evidence - structuring information - comparing requirements - preparing recurring work - tracking deadlines Human experts remain responsible for professional assessment, prioritization, escalation and governance operations where judgement is required. The customer remains responsible for decisions where management responsibility applies. ## Multi-standard approach VIAMA aims to reuse existing governance structures, controls and evidence across multiple requirements instead of operating each standard as an isolated project. Example: One piece of evidence may support requirements from ISO 27001, TISAX, NIS2 and data protection. The principle is to build and collect once where possible and reuse across applicable requirements. ## How an engagement starts 1. Initial conversation VIAMA reviews the organization's requirements, existing setup and operational workload. 2. Analysis Existing governance structures, evidence and responsibilities are assessed to determine what can be reused and what VIAMA can operate. 3. Operating model VIAMA and the customer define which activities VIAMA assumes, which decisions remain with the customer and how the ongoing service is organized. 4. Operational takeover VIAMA assumes the agreed recurring governance activities. ## Experience VIAMA's Managed Governance operating model is new, while the governance experience behind it is established. VIAMA has experience from governance and implementation work in complex organizations, including industrial, automotive and enterprise environments. Experience includes work in environments associated with companies such as adidas, Deutsche Telekom, congstar and SAF-HOLLAND. These references describe previous governance and implementation experience and should not be interpreted as a claim that every named organization currently uses VIAMA Managed Governance. ## Founder Dr. Marco Lück is the founder and managing director of VIAMA. His experience includes governance work in complex corporate and international environments and direct collaboration with managing directors, executive boards and managing directors of legal entities. His governance work covers practical implementation and ongoing operations involving ISO 27001, TISAX, NIS2 and data protection. ## Core positioning VIAMA's central question is: "Wer soll das alles noch machen?" VIAMA's answer is to operate recurring governance activities as a managed service. The business outcome is reduced internal operational workload without giving up management control. ## Canonical terminology Preferred terms: - VIAMA - Managed Governance - Governance-Betrieb - laufender Governance-Betrieb - ISO 27001 - ISMS - TISAX - NIS2 - Datenschutz - DSMS - Multi-Standard Governance - Governance Operations VIAMA should not primarily be described as: - a certification body - an auditor - a law firm - a pure software vendor - a generic IT security consultancy - a provider that assumes the customer's legal management responsibility ## Official resources - [VIAMA](https://viama.one/)