ACCESS Newswire

FINOS

Share
FINOS Announces Formation of an Open Standard Project for Financial Services Common Cloud Controls to Address Compliance and Cloud Concentration Risks

Championed by Citi and joined by over 10 global financial firms, the project welcomes broad industry participation across financial services, technology and cloud service providers.

NEW YORK, NY / ACCESSWIRE / July 27, 2023 / The Fintech Open Source Foundation (FINOS), the foundation of open innovation in financial services and part of the Linux Foundation, today announced the formation of an open standard project, based upon an approach developed by FINOS Platinum Member Citi, to describe consistent controls for compliant public cloud deployments in the financial services sector.

As the pace of cloud adoption accelerates in a highly fragmented global regulatory landscape, this collaborative project aims to develop a unified set of cybersecurity, resiliency, and compliance controls for common services across the major cloud service providers (CSPs). By developing a unified taxonomy of common services and associated threats, the project also sets out to alleviate the systemic risk of cloud concentration, an issue highlighted in recent reports from the U.S. Department of the Treasury, the UK HMT, the European Council, and the Monetary Authority of Singapore.

The project, initiated by Citi and approved in July by the FINOS Governing Board, has quickly garnered participation from more than 20 FINOS Member firms globally, including Bank of Montreal (BMO), Citi, Goldman Sachs, Morgan Stanley, Royal Bank of Canada (RBC), London Stock Exchange Group (LSEG), Natwest Group, cloud service provider Google Cloud, and leading vendors such as GitHub, Red Hat, Symphony, Adaptive, Container Solutions, ControlPlane, GitLab, and Scott Logic. The project will begin a formation stage in August and become available under the Community Specification License later this year. Firms interested to join can apply here.

Jim Adams, Chief Technology Officer and Head of Technology Infrastructure at Citi, said, "There is a need for a Cloud Standard that will improve certain security and control measures across the Financial Services industry, whilst simplifying and democratizing access for all institutions to operate and benefit by leveraging the public cloud. It is important to collaborate with our peers to ensure consistency across cloud service providers, ensuring the industry can realize true multi-cloud strategies."

"Due to the sheer complexity and economic drivers of this challenge, no single vendor, financial institution, or regulator can define what it means for a financial cloud deployment to be compliant," said Gabriele Columbro, FINOS Executive Director and Linux Foundation Europe's General Manager. "The only way forward is open collaboration across constituents, hence why I'm truly excited to see so many FINOS Members quickly rallying around this project, which has the potential to become one of the most valuable and transformational initiatives in our open source community, and across the industry."

"By aligning the controls specific to a service-focused threat model, we can consistently implement controls that map to the actual threats we need to mitigate," said Jon Meadows, Head of Cloud, Application and Software Supply Chain Security at Citi, Citi Tech Fellow, and Chair of the OpenSSF End User working group.

This open standard is expected to expand on existing efforts like NIST's OSCAL, the MITRE ATT&CK framework, and FINOS' own Compliant Financial Infrastructure project, to build taxonomies on common cloud services, common threat techniques and associated mitigations, logical control descriptions, as well as cloud service specific data flow diagrams to understand common attack vectors in the service.

The project is inviting participation from financial institutions globally, CSPs, fintech and technology vendors, industry associations, and regulators to ensure broad representation of all constituents involved in the shared responsibility model.

For more information or to get involved, please visit https://www.finos.org/common-cloud-controls-project.

About FINOS
The Fintech Open Source Foundation (FINOS) is an independent nonprofit organization focused on promoting open innovation during a period of unprecedented technological transformation within financial services. FINOS believes that organizations that embrace open source software and common standards will be best positioned to capture the growth opportunities presented by this transformation.

About Citi
Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions and individuals with a broad range of
financial products and services.

Additional information may be found at www.citigroup.com | Twitter: @Citi | YouTube: www.youtube.com/citi | Blog: http://blog.citigroup.com | Facebook: www.facebook.com/citi | LinkedIn: www.linkedin.com/company/citi.

SOURCE: FINOS



View source version on accesswire.com:
https://www.accesswire.com/770344/FINOS-Announces-Formation-of-an-Open-Standard-Project-for-Financial-Services-Common-Cloud-Controls-to-Address-Compliance-and-Cloud-Concentration-Risks

To view this piece of content from www.accesswire.com, please give your consent at the top of this page.

About ACCESS Newswire

DK

Subscribe to releases from ACCESS Newswire

Subscribe to all the latest releases from ACCESS Newswire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from ACCESS Newswire

AI and Cybersecurity Leader, SecureAuth, Appoints Geoffrey Mattson to Help Enterprises Secure Complex Human, Machine, and AI-agent Identities10.12.2025 17:30:00 CET | Press release

IRVINE, CALIFORNIA / ACCESS Newswire / December 10, 2025 / SecureAuth, a leader in AI-driven identity security, today announced the appointment of Geoffrey Mattson as Chief Executive Officer. Mattson's appointment marks the beginning of the company's next phase of growth as enterprises confront a rapid rise in AI agents with real authority, a shift that is increasing the complexity of business relationships and driving urgent demand for modern identity security. The Board of Directors thanks outgoing CEO Joseph Dhanapal, who will remain as a strategic advisor. During his tenure, SecureAuth invested heavily in creating a next generation security platform, featuring our market leading, AI-driven risk engine. With this platform in place, SecureAuth is positioned to capture accelerating demand for identity and access management as agentic AI transforms identity from a static access check into a dynamic control plane for managing complex human, machine, and AI-driven relationships. Mattson

Nasdaq Verafin Joins Global Anti-Scam Alliance10.12.2025 15:00:00 CET | Press release

THE HAGUE, NL / ACCESS Newswire / December 10, 2025 / The Global Anti-Scam Alliance (GASA) is pleased to announce that Nasdaq Verafin has joined GASA as a Foundation Member, strengthening the global effort to combat scams, financial crime, and digital fraud. As fraud tactics continue to evolve across borders and digital channels, cross-sector collaboration has become essential to protecting consumers and building safer financial ecosystems. Nasdaq Verafin's participation marks a meaningful step forward in the shared mission to advance trust, transparency, and resilience across the globe. In addition to joining the global effort, Nasdaq Verafin will join both the Brazil and Mexico chapters of GASA to partner with stakeholders across the financial ecosystem in Latin America, bolstering regional initiatives to combat financial crime. "Criminals are innovating at an unprecedented rate, taking advantage of information siloes and the shortcomings of legacy technology to avoid detection. We a

TIS Helps Treasury Teams Navigate the Ongoing ISO 20022 Transition After the 2025 Banking Deadline10.12.2025 14:00:00 CET | Press release

BERLIN, DE / ACCESS Newswire / December 10, 2025 / Treasury Intelligence Solutions (TIS), a leading cloud-based platform for payments and cash management, is future-proofing organizations with specialized translation services in the wake of the recent November 2025 ISO 20022 deadline. A major turning point for the financial industry, SWIFT now requires banks to move their cross-border payment messages to ISO 20022. As a result, treasury teams are already seeing differences in how their banks send and receive payment information. Adapting to these changes will require a strategic approach to modernizing systems and processes. ISO 20022 replaces a patchwork of older standards with a single approach to structuring payment data. The new universal standard is designed to reduce confusion across markets, improve data quality, and support the level of transparency that regulators around the globe now expect. Moving to ISO 20022 payments takes time and strategic vision, especially when legacy

Majority of Australian Parents (65%) and U.S. Parents 58% Support Social Media Ban for Under 16s, but Kids Say It Risks Cutting Them Off from Key Connections9.12.2025 15:00:00 CET | Press release

New survey of 4,000 parents and children in the U.S. and Australia reveals sharp generational divides in support, fears, mental health expectations, and belief in government enforcement. WASHINGTON, DC / ACCESS Newswire / December 9, 2025 / The Family Online Safety Institute (FOSI) released new research today examining how parents and children in the United States and Australia view social media bans for anyone under 16. The findings reveal strong parental support for such bans, in contrast with widespread concern from children who fear losing friendships and support systems that exist primarily online. The research arrives as Australia implements a national under 16 social media ban, placing global attention on how the policy will affect youth and their families. FOSI's study surveyed 4,000 parents and children ages 10 to 17 to understand how both groups feel about restrictions, enforcement, and the broader impact of social media on daily life. Support for the Ban: Parents vs Children

Techmer PM Joins Formerra's Portfolio in North America9.12.2025 15:00:00 CET | Press release

Formerra will distribute Techmer PM color masterbatches, high-performance additives, and pre-colored compounds across the U.S., Canada, and Mexico. ROMEOVILLE, ILLINOIS / ACCESS Newswire / December 9, 2025 / Formerra, a leader in performance materials distribution, today announced the addition of Techmer PM color masterbatches, high-performance additives, and pre-colored compounds to its expansive portfolio of materials. With this partnership, Formerra advances its application-specific lineup, aligning its material portfolio to customers' evolving needs across North America. A U.S.-based plastics compounder, Techmer PM specializes in value-added color and additive masterbatches and engineered compounds for high-performance plastics and fibers. These products are used in various industries such as medical, automotive, packaging, and consumer goods applications. Techmer PM has consistently invested in its optical and color capabilities, including the recent acquisition of OptiColor Inc.

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye