Emerald pilot 4: turning continuous compliance into reality for the financial sector

Emerald pilot 4: turning continuous compliance into reality for the financial sector

From Periodic Audits to Continuous Assurance

As financial institutions continue their digital transformation journey, the challenge is no longer simply securing cloud environments. The real challenge lies in maintaining continuous compliance across increasingly complex hybrid infrastructures while keeping pace with evolving regulations and cyber threats.

Traditional audits often provide a point-in-time view of an organization’s security posture. However, regulations such as DORA and emerging cloud certification frameworks require organizations to demonstrate resilience, transparency, and accountability on an ongoing basis. This shift calls for new approaches capable of automating evidence collection, continuously assessing compliance, and reducing the operational burden associated with certification processes.

This is precisely the challenge being addressed by EMERALD.

Within the EMERALD project, Pilot 4 focuses on validating a continuous compliance and certification framework for the financial sector using a hybrid cloud-edge environment led by OpenNebula Systems and validated with CaixaBank as the use-case owner.

Building a Financial-Sector Hybrid Cloud Compliance Platform

Pilot 4 has been designed to reflect the operational reality of large financial organizations. Instead of evaluating a single cloud service, the pilot assesses cloud infrastructures and providers through CaixaBank’s own compliance framework, derived from internationally recognized standards and security frameworks such as ENS, ISO 27001, NIST, and CIS.

At the centre of this environment sits OpenNebula, acting as an Evidence Collection Gateway. The platform orchestrates workloads across different infrastructures while simultaneously collecting compliance evidence that can be automatically assessed within the EMERALD ecosystem.

The pilot integrates resources from multiple providers and environments:

  • CaixaBank private cloud infrastructure.
  • IONOS bare-metal infrastructure.
  • CloudFerro cloud infrastructure.
  • OpenNebula orchestration and evidence collection capabilities.

This architecture demonstrates how financial institutions can maintain a unified compliance posture across a distributed, multi-provider ecosystem.

Automating Evidence Collection at Scale

One of the most significant achievements during the current validation phase has been the implementation of automated evidence collection and assessment workflows.

The OpenNebula frontend continuously gathers technical evidence from infrastructure events such as virtual machine deployments, network changes, image lifecycle events, and resource provisioning activities. This information is then transformed into compliance evidence and automatically submitted to the EMERALD platform for assessment.

In parallel, organizational evidence is collected through AMOE, EMERALD’s document-based evidence extraction component. This enables the platform to assess compliance not only through technical configurations but also through corporate policies, governance procedures, and audit documentation.

Together, these capabilities create an integrated compliance model capable of assessing both technical and organizational controls.

What Has Been Achieved So Far?

During the latest validation cycle, Pilot 4 delivered several important milestones that demonstrate the maturity of the EMERALD approach.

The hybrid cloud infrastructure has been successfully consolidated, integrating OpenNebula-managed environments across CaixaBank, IONOS, and CloudFerro.

The OpenNebula evidence collector was validated end-to-end, successfully generating evidence that was accepted and processed by the EMERALD assessment pipeline. Evidence records were materialized within the Target of Evaluation and made available through the EMERALD user interface.

Pilot 4 also successfully completed Stage Gate 1 and conducted its first informal audit in June 2026 with auditors from DNV/NIXU. The exercise validated key workflows including:

  • Definition of audit scopes.
  • Creation of certification schemes.
  • Evidence collection through AMOE and OpenNebula.
  • Assessment of controls and metrics.
  • Presentation of compliance results through the EMERALD platform.

Additionally, CaixaBank’s custom certification scheme has been successfully modelled within the platform, enabling the organization to map internal security controls directly into EMERALD’s certification framework.

Advancing Towards Continuous Compliance

A key innovation of Pilot 4 is its ability to evaluate infrastructure against security controls continuously rather than during isolated audit exercises.

Current automated assessments cover controls related to:

  • Network exposure and access restrictions.
  • Public IP address usage.
  • Storage visibility and accessibility.
  • Asset inventory management.
  • Logging and monitoring capabilities.
  • Virtual machine configuration and encryption.

This continuous monitoring approach represents an important evolution in how regulated organizations can manage compliance. Instead of collecting evidence manually during audit preparation, compliance data can be generated directly from operational environments and evaluated automatically.

For financial institutions operating under strict regulatory requirements, this capability has the potential to reduce audit effort, improve visibility, and accelerate compliance readiness.

Beyond Technology: Supporting Business Needs

Pilot 4 has also been continuously validated against CaixaBank’s business requirements.

Several requirements have already demonstrated positive progress, including:

  • The ability to support custom certification schemes.
  • Integration with existing evidence collection mechanisms.
  • End-to-end traceability of controls, metrics, and audit evidence.
  • User-friendly compliance workflows through the EMERALD interface.
  • Modular integration capabilities for future adoption within enterprise ecosystems.

These validations ensure that EMERALD is not merely a research platform, but a solution designed to address real operational challenges faced by financial institutions.

The Road Ahead

The next phase of Pilot 4 will focus on completing the remaining integration activities and preparing for the final audit cycle planned for late 2026.

Future work includes:

  • Finalizing operational deployment options within CaixaBank.
  • Completing identity and access management integration through Keycloak.
  • Enhancing the aggregation of assessment results into control-level compliance dashboards.
  • Executing quantitative KPI measurements during the final audit campaign.

A European Vision for Trusted Cloud Certification

Pilot 4 demonstrates how European collaboration between financial institutions, cloud providers, technology vendors, auditors, and research organizations can address one of the most pressing challenges in cybersecurity today: trusted, scalable, and automated compliance.

By combining hybrid cloud orchestration, automated evidence collection, continuous assessment, and customizable certification frameworks, EMERALD is laying the foundations for a future where compliance becomes an integrated part of digital operations rather than a periodic administrative exercise.

For CaixaBank and the wider European financial ecosystem, this means moving closer to a future where trust, resilience, transparency, and regulatory readiness are continuously maintained, enabling innovation without compromising security.

EMERALD is not simply validating technology. It is helping redefine how compliance is achieved in Europe’s increasingly complex digital landscape.

[ TECHNICAL ADVANCEMENTS ]