DORA is reshaping the way finance firms approach resilience, says RGA

London-based Stephanie Phelps

The European Union’s Digital Operational Resilience Act (DORA) is reshaping the way financial institutions approach operational resilience, introducing a regulatory framework that directly affects banks, insurers, and investment firms.

London-based Stephanie Phelps, Operational Resilience Specialist for Reinsurance Group of America, one of the world’s largest global life and health reinsurance companies, said the regulation has marked a decisive shift in expectations.

“While up until now resilience has mostly been a voluntary endeavour for many organisations, think about the honour an ISO 22301 certification brings, the EU decided to do what it does best and regularise the resilience landscape with its Digital Operational Resilience Act,” Phelps said.

For quality assurance and testing teams working in financial services, the impact is significant.

Phelps explained in a recent BCI analysis that DORA “focusses on areas of high societal impact by targeting the financial industry, including banks, insurers, investment firms, and even crypto service providers, and its dependency on Information and Communication Technology assets.”

She added that the regulation, which came into earlier this year, sets clear expectations around digital resilience.

“DORA came in force in January 2025 and is structured around five key pillars, ICT Risk Management, Incident Reporting, Testing, 3rd Party Risk Management, and Information Sharing, to provide direct regulatory oversight to uphold one solid goal: ensuring that financial institutions can withstand, respond to, and recover from ICT-related disruptions.”

For QA teams, the “Testing” pillar is particularly important, Phelps continued, pointed out it elevates what has traditionally been seen as a best-practice activity into a compliance requirement.

Regular, structured testing of ICT systems, controls, and resilience strategies now needs to be documented, repeatable, and integrated into wider governance frameworks.


“The EU decided to do what it does best and regularise the resilience landscape.”

– Stephanie Phelps

For teams already embracing continuous integration and continuous delivery, this will mean demonstrating not only that software works, but that it can stand up to disruption scenarios, cyber threats, and unexpected outages without exposing customers or breaching regulatory requirements.

Phelps emphasised that business continuity and resilience professionals should see the regulation as more than just a compliance checklist.

“For business continuity professionals, DORA is more than a regulation, it’s an invitation to rethink resilience and bring it into the digital age,” she said.

Phelps concluded that the regulation provides a broader opportunity for the industry. “If one can see past the lengthy bureaucratic articles, the spirit of DORA has what it takes to inspire organizations to be not only compliant, but truly resilient.”

For QA and testing specialists in banks and financial services firms, that “spirit” translates into embedding resilience testing into day-to-day quality assurance practices. From automated failover tests and penetration simulations to sandboxed customer journeys, the testing function is now positioned at the heart of both compliance and customer trust.

Looking ahead

Looking ahead, the DORA framework is likely to accelerate the shift-left trend in software testing. By pushing resilience considerations earlier in the development lifecycle, banks can catch risks before they enter production environments — reducing not only operational vulnerabilities but also regulatory exposure.

AI-driven testing is also becoming essential. Intelligent automation can generate test cases that simulate complex, real-world disruption scenarios at scale, providing regulators with the evidence they increasingly demand. This allows QA teams to move beyond box-ticking exercises and into continuous assurance that systems are resilient under stress.

At the same time, regulatory technology (regtech) is being adopted to map QA and testing outputs directly to compliance obligations.

This integration means test results, incident logs, and resilience metrics can flow seamlessly into compliance dashboards, reducing the reporting burden while increasing transparency.

For banks and insurers, the convergence of DORA, AI-driven testing, and regtech adoption signals a new reality: quality assurance is no longer just about software delivery, but about proving to regulators, customers, and shareholders that resilience is engineered into every digital service.


NEW EVENT


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY



REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW