Defining Best Practices Around Cloud Security

FINOS Common Cloud Controls (FINOS CCC) is an open standard project that describes consistent controls for compliant public cloud deployments in the financial services (FS) sector.

This standard is a collaborative project which aims to develop a unified set of cybersecurity, resiliency, and compliance controls for common services across the major cloud service providers (CSPs).

 

Introducing Common Controls for AI Services

An open, collaborative project to create technology-neutral baseline standards for AI usage across cloud and hybrid environments, peer-reviewed governance frameworks and Real-time validation mechanisms (“Regulation-as-Code”).

Read more in the Press Release

FINOS CCC RESOURCES

Explore key FINOS CCC resources including documentation, GitHub repositories, videos, and more to help you understand, implement, and contribute to the project.

FINOS CCC LINKS

 


FINOS CCC VIDEOS

Announcing Common Controls for AI Services (CC4AI)
Announcing Common Controls for AI Services (CC4AI)
An open, collaborative project to create technology-neutral baseline standards for AI usage across cloud and hybrid environments, peer-reviewed governance frameworks and Real-time validation mechanisms (“Regulation-as-Code”).
Before You Build, Check What You Have: Practical Approaches To Assess Compliance Before Enforcement
Before You Build, Check What You Have: Practical Approaches To Assess Compliance Before Enforcement
Rather than prescribing a single solution, the session offers early design perspectives, implementation considerations, and practical observations based on real-world infrastructure patterns. The aim is to support adaptable, insight-driven CCC adoption that reduces risk and accommodates diverse organizational contexts, including hybrid and regionally governed environments.
Declarative by Default, Secure by Design: GitOps as a Control Plane for AI Governance
Declarative by Default, Secure by Design: GitOps as a Control Plane for AI Governance
At the dawn of responsible, auditable, and explainable use of AI in financial services, the FINOS AI Governance Framework (AIGF) and Common Cloud Controls (CCC) define how compliant AI and secure cloud operations must look. However, implementing and preserving these frameworks and standards at scale is impossible, without relentless automation.
The Need for an Open Regulatory Blueprint
The Need for an Open Regulatory Blueprint
On this panel, leaders from Citi, Google Cloud, and BMO will discuss updates on the recently open sourced FINOS CCC project, and the need for a set of open standards that describes consistent controls for compliant cloud deployments to alleviate cybersecurity threats, compliance costs, a fragmented regulatory landscape, cloud concentration, and more.

FINOS CCC DOCUMENTS

 

Contributing to Common Controls for AI
Introducing FINOS CCC
This is a short introduction to FINOS CCC

Want to learn more about FINOS CCC or other FINOS Projects?