Technical and business analysis
End-to-end requirements analysis, as-is / to-be analysis, solution concepts, functional and technical specifications, and verification that the delivered solution meets the requirements.
Over 5 years of experience in financial markets – across banking, fintech and insurance – and in building applications and integrations aligned with regulatory guidelines such as PSD2/PSD3, AML/KYC, DORA and the Polish FSA (KNF).
Sectors I work in – click to see typical challenges:
Three areas that connect business with technology and lead from an idea to unambiguous requirements.
End-to-end requirements analysis, as-is / to-be analysis, solution concepts, functional and technical specifications, and verification that the delivered solution meets the requirements.
BPMN 2.0 and UML, process mapping and optimization (Lean, Six Sigma), UX/IA mock-ups and documentation ready to hand over to delivery teams.
Business and technical workshops, alignment of expectations and translation of business needs into requirements and a backlog.
Four steps that structure an implementation and limit costly rework.
I start with the goal, the people and the current way of working, not with technology.
I describe the as-is and to-be states in BPMN/UML and point out risks, dependencies and regulatory requirements.
I agree the scope with business, IT and compliance until the requirements are unambiguous.
I hand documentation and the backlog over to teams and verify that delivery matches the agreed assumptions.
A mindset focused on understanding the process and the change is key to a successful implementation – technology comes next.
Payment regulations and standards I work with when analyzing and designing solutions.
PSD2 introduced strong customer authentication and third-party provider access, while PSD3 with the PSR tightens fraud prevention, for example by verifying that the payee name matches the IBAN.
Rules under which a bank, with the customer's consent, shares account data and enables third-party providers to initiate payments through secure APIs.
The obligation to know the customer and monitor their transactions to prevent money laundering – in practice onboarding, risk scoring and reporting of suspicious activity.
An EU regulation applicable since 17 January 2025 that requires financial entities to manage ICT risk, report incidents, test resilience and oversee ICT third-party providers.
Recommendations and announcements from the Polish financial supervisor covering, among other things, IT management and security of IT environments, which I turn into system requirements.
A structured, XML-based payment messaging standard that replaces older formats, including those used in SWIFT, and demands careful data mapping and validation.
SEPA handles euro transfers, SWIFT international payments and Elixir domestic interbank settlement in Poland; each has its own formats and settlement windows.
Cards and wallets such as Google Pay or Apple Pay rely on tokenization and strong authentication, and integrating them requires a consistent description of flows and error handling.
Integrations, data, monitoring and team tooling – without them a change cannot be designed well.
Three ways systems communicate: REST is lightweight and ubiquitous, SOAP is formal and contract-based, and GraphQL lets you fetch exactly the data you need.
A message broker that decouples systems with queues, so a brief failure of one component does not block the whole process and synchronous communication can become asynchronous.
A distributed event-streaming platform that durably stores streams and delivers them in real time to many consumers – a good fit for high data volumes.
Tools for documenting and manually testing APIs, which let me check the contract, error codes and edge cases before a solution reaches production.
SQL is for analyzing relational data, NoSQL for flexible data models and Hive for querying Hadoop data warehouses – together they let me assess data quality and consistency.
Prometheus collects metrics, Grafana visualizes them, and Splunk and Graylog aggregate logs – together they show system health and shorten root-cause analysis.
Kubernetes manages containers, OpenShift adds an enterprise layer and CI/CD automates building and deployment, giving repeatable and safe releases.
Jira organizes tasks, Confluence documentation and Git change history; a consistent workflow reduces requirements chaos and makes decisions auditable.
I deliberately use AI agents and tools to shorten the path from an idea to solid documentation – while keeping expert control and accountability for the result.
Have a process to streamline, an implementation to analyze or a workshop to run? Send a few sentences of context – I will reply with proposed next steps.