Video by FINOS via YouTube

George Kichukov (Field CTO at GitLab) and Michael Long (CEO at Kosli) present the Open SDLC Controls Framework, an open-source industry project developed within FINOS. They address the massive inefficiency of banks independently building, maintaining, and defending redundant SDLC policies to auditors and regulators. This session breaks down how financial institutions like Morgan Stanley, Deutsche Bank, NatWest, and major Canadian banks are collaborating to build a standardized, open catalog of SDLC controls, risk mappings, and automated evidence mechanisms.
🗽 Catch Us in New York! Ready to streamline software governance, eliminate developer friction, and standardize SDLC compliance?
Join global technology leaders at OSFF New York on November 4–5, 2026.
🎟️ Register Now: https://hubs.ly/Q04n_bZL0
🔥 20% OFF DISCOUNT CODE: 26YTOSFFNY20C
🕒 Timestamps:
0:00 Introduction & Speaker Backgrounds (Kosli & GitLab)
0:57 What Are SDLC Controls & Why Do They Exist?
2:36 Concrete Example: Code Reviews, Separation of Duties & AI-Generated Code
3:56 Regulatory Ambiguity: OSFI, SOC 2, and Non-Prescriptive Rules
4:30 Mapping Controls Back to Specific Risks & Mitigations
5:27 How SDLC Controls Are Created & Operationalized Today
6:45 The Problem: Redundant Island Engineering Across Financial Institutions
8:03 Terminology Chaos: Standardizing Separation of Duties & Peer Reviews
9:03 The Solution: An Open Industry SDLC Control Catalog in FINOS
10:00 Active Community Contributors (Morgan Stanley, Deutsche Bank, NatWest)
11:53 Audience Q&A: Evolving from Text Policies to Automated Evidence & Code
13:39 Audience Q&A: Aligning SDLC Control Frameworks with AI Governance
15:03 Audience Q&A: Addressing Regulatory Vagueness with Industry Consensus
17:03 Audience Q&A: Distributing & Socializing the Open Framework
📊 The Problem: The High Cost of Isolated Control Engineering
Every bank, insurance carrier, and financial institution currently solves software compliance in isolation. Engineering, risk, and platform teams spend thousands of hours in meetings interpreting vague, non-prescriptive regulations (such as OSFI in Canada, NIST, or SOC 2) and defending their custom control implementations to internal and external auditors. Furthermore, inconsistent terminology (e.g., "separation of duties" vs. "code review") and overly restrictive manual gates introduce severe developer friction, slowing down delivery pipelines without measurably improving security.
🏗️ The Solution: The FINOS Open SDLC Controls Catalog
Inspired by the FINOS AI Governance Framework, the Open SDLC Controls Framework provides a standardized, open-source reference library: Common Taxonomy & Risk Mapping: Establishes a unified vocabulary across financial engineering. Every control in the catalog explicitly maps back to specific risk categories—operational, reliability, cybersecurity, insider threat, quality, and regulatory compliance. Pre-Defined Mitigations & Evidence Standards: Defines clear mitigation steps and standardizes the exact evidence artifacts required to prove compliance, preparing teams for automated evidence collection. Industry Alignment: Created in collaboration with major financial institutions (Morgan Stanley, Deutsche Bank, NatWest, Canadian banks) and DevOps vendors (GitLab, Kosli) to ensure broad regulatory and audit acceptance.
⚙️ Why This Matters for Financial EngineeringRemoving Developer Friction:
Replaces clumsy, manual approval gates with well-defined, automated control specifications that integrate directly into modern CI/CD pipelines. Unified Regulatory Voice: Gives financial institutions a defensible, industry-backed framework to present during regulatory audits, eliminating the need to repeatedly re-justify standard DevSecOps practices.
🌐 More about FINOS: https://www.finos.org/
📧 Join our newsletter: https://www.finos.org/sign-up
🎙️ Listen to our Open Source in Finance Podcast: https://www.youtube.com/@FINOS/podcasts
LinkedIn: https://www.linkedin.com/company/finosfoundation
#FINOS #OSFFNewYork #GitLab #Kosli #DevSecOps #SDLC #SoftwareGovernance #FinTech #Compliance #RegTech