Press Releases

Press Releases

FINOS Announces Formation of an Open Standard Project for Financial Services Common Cloud Controls to Address Compliance and Cloud Concentration Risks

July 27, 2023

Championed by Citi and joined by over 10 global financial firms, the project welcomes broad industry participation across financial services, technology and cloud service providers.

NEW YORK, July 27, 2023 – The Fintech Open Source Foundation (FINOS), the foundation of open innovation in financial services and part of the Linux Foundation, today announced the formation of an open standard project, based upon an approach developed by FINOS Platinum Member Citi, to describe consistent controls for compliant public cloud deployments in the financial services sector.

As the pace of cloud adoption accelerates in a highly fragmented global regulatory landscape, this collaborative project aims to develop a unified set of cybersecurity, resiliency, and compliance controls for common services across the major cloud service providers (CSPs). By developing a unified taxonomy of common services and associated threats, the project also sets out to alleviate the systemic risk of cloud concentration, an issue highlighted in recent reports from the U.S. Department of the Treasury, the UK HMT, the European Council, and the Monetary Authority of Singapore

The project, initiated by Citi and approved in July by the FINOS Governing Board, has quickly garnered participation from more than 20 FINOS Member firms globally, including Bank of Montreal (BMO), Citi, Goldman Sachs, Morgan Stanley, Royal Bank of Canada (RBC), London Stock Exchange Group (LSEG), Natwest Group, cloud service provider Google Cloud, and leading vendors such as GitHub, Red Hat, Symphony, Adaptive, Container Solutions, ControlPlane, GitLab, and Scott Logic. The project will begin a formation stage in August and become available under the Community Specification License later this year. Firms interested to join can apply here

Jim Adams, Chief Technology Officer and Head of Technology Infrastructure at Citi, said, “There is a need for a Cloud Standard that will improve certain security and control measures across the Financial Services industry, whilst simplifying and democratizing access for all institutions to operate and benefit by leveraging the public cloud. It is important to collaborate with our peers to ensure consistency across cloud service providers, ensuring the industry can realize true multi-cloud strategies.”

"Due to the sheer complexity and economic drivers of this challenge, no single vendor, financial institution, or regulator can define what it means for a financial cloud deployment to be compliant,” said Gabriele Columbro, FINOS Executive Director and Linux Foundation Europe’s General Manager. “The only way forward is open collaboration across constituents, hence why I’m truly excited to see so many FINOS Members quickly rallying around this project, which has the potential to become one of the most valuable and transformational initiatives in our open source community, and across the industry.”

"By aligning the controls specific to a service-focused threat model, we can consistently implement controls that map to the actual threats we need to mitigate," said Jon Meadows, Head of Cloud, Application and Software Supply Chain Security at Citi, Citi Tech Fellow, and Chair of the OpenSSF End User working group.

This open standard is expected to expand on existing efforts like NIST’s OSCAL, the MITRE ATT&CK framework, and FINOS’ own Compliant Financial Infrastructure project, to build taxonomies on common cloud services, common threat techniques and associated mitigations, logical control descriptions, as well as cloud service specific data flow diagrams to understand common attack vectors in the service.

The project is inviting participation from financial institutions globally, CSPs, fintech and technology vendors, industry associations, and regulators to ensure broad representation of all constituents involved in the shared responsibility model.

For more information or to get involved, please visit  


The Fintech Open Source Foundation (FINOS) is an independent nonprofit organization focused on promoting open innovation during a period of unprecedented technological transformation within financial services. FINOS believes that organizations that embrace open source software and common standards will be best positioned to capture the growth opportunities presented by this transformation.

About Citi

Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions and individuals with a broad range of financial products and services.

Additional information may be found at  | Twitter:  @Citi  |  YouTube:  | Blog:  |  Facebook:  | LinkedIn:




This Week at FINOS Blog - See what is happening at FINOS each week.

FINOS Landscape - See our landscape of FINOS open source and open standard projects.

Community Calendar - Scroll through the calendar to find a meeting to join.

FINOS Slack Channels - The FINOS Slack provides our Community another public channel to discuss work in FINOS and open source in finance more generally.

All FINOS Project Good First Issues - A good place to start contributing to, and making a difference in, open source in financial services is by taking a look at the FINOS Good First Issues (GFI) List on GitHub.

Project Status Dashboard - See a live snapshot of our community contributors and activity.

Events - Check out our upcoming events or email if you'd like to partner with us or have an event idea.

FINOS Open Source in Fintech Podcasts - Listen and subscribe to the first open source in fintech and banking podcasts for deeper dives on our virtual "meetup" and other topics.

Interested in FINOS open source projects? Click the link below to see how to get involved in the FINOS Community.

Get Involved