
Building a World-Class OSPO: Lessons from the Financial Industry
On this episode of the Open Source in Finance Podcast, host Rob Moffat (Chief Architect at FINOS) is joined by an executive panel featuring Mimi Flynn (Vice President & Open Source Developer Advocate at Morgan Stanley), Elspeth Minty (Managing Director at RBC Capital Markets), and Mark Paulsen (Head of Open Source Program Office at TD Bank). Together, they explore the operational realities of open-source adoption in regulated banking. The panel breaks down the hidden costs and security risks of internal code forking, strategies for measuring OSPO Return on Investment (ROI), automated contribution controls via GitProxy, and how to prepare engineering teams for the convergence of open source, rising global regulations, and generative AI. 🗽 Catch Us in New York! Ready to scale your Open Source Program Office (OSPO), mitigate supply chain risks, and streamline enterprise contribution workflows? Join us at OSFF New York on November 4–5, 2026.🎟️ Register Now: https://hubs.ly/Q04n_bZL0🔥 20% OFF DISCOUNT CODE: 26YTOSFFNY20C
📊 The Problem: The Hidden Trap of Internal Code Forks & Governance DragRegulated financial institutions face exponential increases in regulatory oversight, open-source dependency trees, and CVE vulnerabilities. When engineering teams bypass contribution approvals by creating private internal code forks, they incur severe technical debt, untracked security risks (such as missing upstream CVE patches), and long-term maintenance overhead. 🏗️ The Solution: Enterprise OSPOs, GitProxy & Standardized Maturity ModelsThe panel details how financial institutions build mature OSPOs using FINOS Open Source Readiness (OSR) frameworks: Developer Training & Maturity Roadmaps: Mandating foundational developer training (such as Linux Foundation’s FSOSD) to educate engineers on licensing, IP, and risk management. Automated Guardrails (GitProxy): Implementing automated commit controls at push time to screen outgoing code for secrets, proprietary logic, and licensing compliance without disrupting developer velocity. Standardized Maturity Benchmarks: Utilizing the FINOS OSR Maturity Model as a competitive roadmap to transition from passive software consumption to active open-source sponsorship and code contribution. ⚙️ Why This Matters for Financial EngineeringMeasuring True ROI: Demonstrating OSPO value through hard metrics (Evident AI indicators) alongside soft metrics like recruiting appeal, developer career progression, and talent retention. Collaborative Industry Security: Mutualizing open-source governance tools allows banks to solve shared compliance challenges together rather than re-inventing the wheel in isolation. 🌐 More about FINOS: https://www.finos.org/📧 Join our newsletter: https://www.finos.org/sign-up🎙️ Listen to our Open Source in Finance Podcast: https://www.youtube.com/@FINOS/podcastsLinkedIn: https://www.linkedin.com/company/finosfoundation
More episodes from "FINOS Open Source in Finance Podcast"



Don't miss an episode of “FINOS Open Source in Finance Podcast” and subscribe to it in the GetPodcast app.








