DORA is turning compliance into new QA battleground for banks

Jens Kunz

The regulatory tide has turned. For QA leaders in banking and financial services, 2025 is the year when compliance became the defining measure of quality.

The EU’s Artificial Intelligence Act and Digital Operational Resilience Act (DORA) are not advisory frameworks or long-term roadmaps; they are binding law. That shift has elevated software testing from a technical safeguard to the frontline of regulatory resilience.

The implications are profound. No longer is QA about proving that systems work; it is about proving that systems are trustworthy, explainable, resilient, and continuously validated. Regulators want evidence, not assurances. That makes testing pipelines not just engineering assets but compliance infrastructure.

Those banks that fail to adapt risk fines, reputational damage, and operational disruption. Those that succeed will turn regulation into competitive advantage.

Daryl Elfield
Daryl Elfield

The AI Act illustrates this new reality. Elisabetta Righini, partner at Latham & Watkins in Brussels, described it as “a holistic set of risk-based rules applicable to all players in the AI ecosystem, from developers, to exporters to deployers.”

Meanwhile, Daryl Elfield, partner at KPMG in London, underlined the consequences for testers: “For software testing standards, this means that AI systems deemed high-risk will need to comply with strict standards concerning risk management, data quality, transparency, human oversight, and robustness.”

In other words, validation now extends beyond performance and functionality into areas QA teams have not traditionally owned: bias detection, fairness, data traceability, algorithmic explainability.

“AI requirements must be validated through comprehensive testing across functional, performance, security, and stress layers, but also in algorithmic integrity,” warned Paul Mowat of Infinity Tech Consulting.

In addition, Tendü Yoğurtçu, CTO at Precisely, made clear that “vendors and providers must demonstrate that their test data practices are transparent and aligned with regulatory expectations.” For banks, this means investing in trusted data foundations as much as in automation frameworks.


“I personally have not met a CIO or CISO who thought the DORA deadline was realistic.”

– James Johnston

If the AI Act is changing the ‘what’ of testing, DORA is redefining the ‘how often’. It requires banks to run regular resilience programmes and adopt threat-led penetration testing.

Jens Kunz, partner at Noerr, put it bluntly: “The stricter requirements under DORA are leading to a fundamental change in IT penetration testing practices in the financial sector. After all, hacking is now mandatory under the DORA regulation.”

Yet here lies the problem: financial institutions are still struggling to meet the standard. James Johnston, vice president of EMEA at Azul, pointed out that “it’s no surprise to me that financial services organisations missed the 17 January 2025 deadline… I personally have not met a CIO or CISO who thought the DORA deadline was realistic.”

Richard Lindsay of Orange Cyberdefense added that “given the complexity of the regulation and the ongoing pressure to balance security needs with broader business goals, it’s no surprise that many financial institutions are falling behind.”

This gap is not just about deadlines; it is about culture. Too many institutions still treat compliance as a legal hurdle rather than an engineering discipline.

Roberto Vigo, head of QA at Nordea, captured the opportunity when he said: “DORA compliance has also become a marketing opportunity. We can brand ourselves as embracing the regulation and doing what it requires us to do.”

But Vigo also acknowledged the challenge: “The most challenging aspect of compliance is the uplift and the education of the wider community within the firm.”

Bridges Smith

That cultural shift is where QA leaders must now focus. Continuous testing, automation, and integration of compliance into the development pipeline are no longer optional.

“Continuous performance testing is a match to the requirements of DORA,” argued Michael Kissel of Tricentis, while Puneet Kohli of Rocket Software insisted that “compliance today is inseparable from testing. Continuous testing is the only way to stay ahead of both threats and regulators.”

And far from slowing innovation, compliance can accelerate it, as Bridges Smith of SmartBear observed: “The more effective approach is to shift compliance left and automate it from the start. AI makes this possible by embedding compliance into the development workflow to ensure consistency without slowing teams down.”

He added that “compliance has long been viewed as a necessary slowdown in the development process. But with AI, it’s becoming something else entirely: a built-in advantage.”

That is the lesson of 2025: regulation has made QA unavoidable, but it has also made QA strategic. For banks, the battleground is no longer whether compliance applies but how it is operationalised. Most industry insiders firmly belief that the future belongs to those QA teams who can produce continuous, auditable proof that their systems are not only reliable but compliant by design.


QA FINANCIAL PODCASTS

Listen to Sudeepta Guchhait on Nasdaq’s new Mimic AI testing platform
QA Financial sits down with Sudeepta Guchhait, Senior Director of Product Framework & Quality Engineering at Nasdaq

——–

Listen to Wesley Scheffel and Robin Rain on Schroders’ DevOps strategy
We catch up with Wesley Scheffel, Head of Cloud Platform and Product Engineering at Schroders, and Robin Rain, Head of Cloud Platform Architecture

——–

Listen to Citi’s Jason Morris on Lightspeed and the future of continuous delivery
Jason Morris, Head of Developer Pipelines for Securities Markets and Banking at Citi, talks about Lightspeed


NEXT MONTH


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW