30th Meeting
AI Governance and Open Source Compliance in Finance
Practical cases on open source governance in the AI era and audit-readiness checkpoints for the financial sector.
Registration is announced via the OpenChain KWG mailing list. Subscribe to receive the sign-up link.
- OpenChain
- AI Governance
- Financial Audit
- OSS Compliance
Who Should Attend
- Practitioners managing open source compliance policies in finance and regulated industries
- Organizations redefining open source governance scope after AI adoption
- Teams preparing checklists and evidence for audits and inspections
Sponsor

Agenda
Speakers

Leads OpenChain Project standards and the global community.

Open source governance, DevSecOps, and CMDB operations at KakaoBank.

Team Lead of the Research Infrastructure Team at AhnLab. He designs and operates R&D development-support environments — CI/CD infrastructure, OSS (Open Source Software) verification, static analysis, development-process standardization, build and signing, and patent and external-project management. His main focus is open source compliance and security-vulnerability response for security products, and building a static-analysis-centered CI/CD pipeline spanning development through release.

Open source governance at KakaoBank, in-house IT policy, and internal/external audit response.
OpenChain Updates: Global Highlights
Highlights Mary Wang shared during the OpenChain Updates segment. She positioned OpenChain as a key foundation linking compliance with the EU Cyber Resilience Act (CRA) and AI regulation.
- OpenChain maintains two international standards, ISO 5230 and ISO 18974, adopted by more than 100 companies worldwide. It runs a 25-member governance board, and in 2026 Renesas joined as a new board member. The OpenChain China Work Group is set to launch, and new partners including OSCHINA have joined.
- Under ISO rules, every standard must be renewed every five years. ISO 5230:2020 has been officially renewed without any change, and the project decided at its Q2 board meeting to submit version 3.0, which reflects minor modifications made over the past three years, to ISO. The designation 5230 will be retained, with a revision label applied only if necessary.
- The EU Cyber Resilience Act (CRA) requires Secure by Design, transparency over all open source components, continuous vulnerability management, and rapid reporting of security incidents. OpenChain formed a Business Operation Work Group to research CRA-compliance gaps across organizations and identify how it can help.
- In the AI space, OpenChain is addressing the EU AI Act, integrating with ISO 42001, 42002, and 42003, running the OpenChain AI Work Group, and advancing the OpenChain AI SBOM Self Certification.
- An OpenChain introduction video is planned for OCS (Open Compliance Summit) in December, and the “Adopt our standards” webpage has been updated. The OpenChain and Friends webinar series is ongoing. Organizations looking to adopt the standards can refer to the OpenChain get-started page.
![[2026 June] OpenChain Korea Work Group in Kakao Bank](https://live.staticflickr.com/65535/55324287806_9c07d82ddc_h.jpg)