
As financial firms grapple with increasingly complex technology chains and tighter resilience expectations from regulators around the world, The Dutch Central Bank (DNB) and the sector’s financial services watchdog, the Dutch Authority for the Financial Markets (AFM), are urging banks, insurers and pension funds to take scenario-based testing far beyond traditional QA.
DNB’s Melanie Lohuis and Hans Brits frame the challenge as one of digital dependence and systemic vulnerability, underscoring the need for more rigorous chain testing, real-life simulations and resilience exercises that mirror the real threats firms face.
DNB said the core infrastructure of financial services is now so intertwined with external technology that many institutions rely on the same small group of providers.
“Today’s financial sector runs almost entirely on digital infrastructure. From customer service to risk management, institutions rely heavily on external IT providers,” explained Melanie Lohuis, an Amsterdam-based policy adviser at DNB, in a recently published report.
“Think cloud platforms or developers of AI models. This dependence has grown rapidly in recent years.”

For QA and software testing teams, often responsible for ensuring system reliability when components fail, this growing dependency fundamentally changes the scope of assurance.
With regulators from the EU’s Digital Operational Resilience Act (DORA) to the Bank of England pushing firms towards evidence-based resilience, the Dutch central bank’s findings reinforce a broader regulatory shift: resilience must be proven through testing, not assumed through controls.
Hans Brits, co-author of the report and supervisory strategist at DNB, highlighted the strategic risks that arise when digital concentration meets geopolitical uncertainty.
“What makes this issue even more urgent is the current geopolitical climate. Most major tech companies are non-European, which increases the vulnerability of institutions that rely on them.”
For banks, that vulnerability increasingly shows up in extreme but plausible disruption scenarios, precisely the conditions that scenario-based testing is designed to explore.
From functional to scenario-based testing
The DNB and AFM report explicitly calls on financial institutions, technology providers and supervisors to collaborate more closely on resilience testing.
Brits recommends “conducting scenario-based chain testing, including real-life simulations” that stress digital dependencies across organisational and contractual boundaries.
For QA teams, this represents a clear move away from isolated functional validation towards multi-layered testing that reflects how financial services actually operate.
Rather than testing applications in isolation, firms are expected to examine entire service chains, from front-end channels and core banking platforms to cloud infrastructure and third-party software, under severe disruption.
“Financial institutions are developing detailed exit strategies and continuity plans.”
– Melanie Lohuis
Brits described the near-term priority for firms facing an increasingly volatile threat landscape.
“In the short term, it’s crucial for institutions to prepare for disruptive scenarios, such as sanctions or hybrid cyber attacks. This means working together to develop threat scenarios, share information, and conduct chain tests.”
These exercises closely resemble red-team testing and continuity drills, exposing hidden dependencies and validating whether recovery assumptions hold up under pressure.
Such testing also places new demands on test environments. Regulators increasingly expect simulations that resemble production realities, rather than idealised lab conditions.
For QA teams, this means building environments that incorporate external providers, degraded services and recovery workflows, and ensuring that results can be translated into credible assurance for senior management and supervisors.

Resilience testing as supervisory evidence
The report makes clear that resilience is not just about avoiding incidents, but about how firms recover and adapt when disruption occurs. Lohuis pointed to the growing focus on contingency planning and exit strategies.
“Financial institutions are developing detailed exit strategies and continuity plans to ensure they can recover quickly in a crisis,” said Lohuis. “They’re also working to map out their dependencies as precisely as possible.”
This emphasis aligns closely with regulatory expectations under DORA and similar regimes, where firms must demonstrate, through testing, that critical services can remain within acceptable impact tolerances even when key technology providers fail. For QA teams, that elevates testing artefacts, results and remediation plans into supervisory evidence.
The report also highlights architectural choices that can support resilience over time. Lohuis noted that “using open software standards, containerisation, and working with multiple vendors can help reduce dependence, though these solutions aren’t always simple or cheap.”
For testing functions, such approaches enable more flexible, repeatable resilience testing and make it easier to simulate failures across different technology stacks.
Even so, the authors stress that firm-level testing can only go so far. Brits pointed to the longer-term challenge of reducing systemic dependency.
“The long-term solution lies in building strategic autonomy. To achieve that, we need a strong European tech sector. Right now, Europe is lagging behind,” he stated.
“Closing that gap will require investment, innovation, and coordinated action at the European level. Only then can we reduce our dependence on non-European providers and strengthen our digital resilience,” Brits concluded.
COMING IN 2026


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW

QA FINANCIAL PODCASTS



