mh2
Talent
Open Source Compliance Consultant & Independent Auditor
Expert
Summary
Consultant and independent auditor for open source compliance and OSPO. Establishes policies, SBOM/license workflows, and supplier assurance that fit real engineering and delivery pipelines.
Detailed profile
Available hourly or fractionally as a consultant and independent auditor for open source compliance. I help organizations define governance that works in practice and holds up under review.
Support areas: OSPO setup and operating model, open source policy and process design, license risk management, SBOM governance, supplier open source assurance, and integrating compliance checks into CI/CD.
Also supports EU Cyber Resilience Act readiness where open source and software supply chain transparency are in scope.
Audit credentials: ISO/IEC 19011 PRO, ISO/IEC 27001 PRO (method and rigor for structured reviews).