How regulation is rapidly altering software testing

If there has been one defining theme running through financial regulation this year, it is that software testing is no longer being treated simply as an engineering discipline.

Whether the discussion centres on operational resilience, artificial intelligence, cloud services or critical third parties, regulators are increasingly placing software quality and testing at the heart of how firms demonstrate that technology risks are understood, managed and controlled.

Taken individually, initiatives ranging from the European Union’s Digital Operational Resilience Act (DORA) and the EU AI Act to guidance from the UK’s Financial Conduct Authority (FCA), the European Central Bank (ECB), IOSCO and Australia’s CPS 230 all focus on different aspects of technology governance.

Viewed together, however, they reveal a much broader shift that is fundamentally changing the role of quality assurance inside financial institutions.

Regulatory control

The biggest trend is that QA is evolving from an engineering function into a regulatory control. For decades, software testing existed primarily to improve software quality. QA teams found defects, validated releases and helped developers deliver more reliable applications.

Today, regulators increasingly view testing as one of the mechanisms through which banks demonstrate operational resilience.

A successful testing programme is no longer simply evidence that software functions correctly. It increasingly serves as proof that an institution understands its technology risks, has validated critical systems, and can demonstrate resilience to supervisors when required.

ECB HQ in Frankfurt

That distinction is becoming increasingly important. DORA requires financial institutions to establish comprehensive testing programmes for critical ICT systems.

Meanwhile, Australia’s CPS 230 similarly places resilience testing at the centre of operational risk management.

Over in Europe, the ECB continues to emphasise technology resilience as financial institutions accelerate digital transformation, while the FCA’s growing work around AI repeatedly stresses the importance of building, testing and deploying AI safely.

Moreover, IOSCO’s recent work on AI governance likewise places increasing emphasis on oversight, validation and effective controls.

Collectively, these developments point in the same direction: testing is becoming part of the control framework through which firms manage operational risk.

Impact on QA

This has significant implications for QA teams. Rather than operating solely within software engineering, quality leaders are increasingly working alongside operational resilience, enterprise risk, compliance and internal audit functions.

Test execution records, resilience exercises, defect histories and validation reports are becoming evidence that organisations may ultimately need to present to regulators.

In many institutions, software testing is gradually becoming part of the evidence layer that underpins regulatory compliance.

Closely linked to this is another defining trend emerging across both regulation and industry: the gradual disappearance of point-in-time testing.

Historically, testing revolved around software releases, annual audits and scheduled compliance exercises. Applications were validated before deployment, evidence collected and archived, and organisations moved on to the next release cycle.

FCA CEO Nikhil Rathi

That model is becoming increasingly difficult to sustain. Modern financial institutions now operate continuous delivery pipelines, cloud-native infrastructures and AI-assisted development environments where software changes daily rather than quarterly. Traditional testing cycles struggle to keep pace with this new reality.

Regulators appear to recognise this. Across DORA, CPS 230, IOSCO guidance and the FCA’s evolving approach to AI, the common expectation is no longer periodic validation but continuous assurance.

Testing increasingly becomes something organisations perform continuously rather than something they complete.

The language appearing across both regulation and industry is strikingly similar: continuous validation, continuous monitoring, continuous resilience testing and continuous assurance.

Testing vendors are evolving in the same direction. Product announcements increasingly focus on real-time monitoring, continuous resilience validation and always-on testing platforms rather than standalone automation tools.

The result is a fundamental change in philosophy. Testing is no longer simply another phase within software development. It is becoming a permanent operational capability that continuously measures whether critical systems remain resilient despite constant change.

Perhaps the most significant driver behind these regulatory developments is artificial intelligence. Much of the wider technology industry continues to speculate about whether AI will replace software testers altogether.

Risks and opps

Financial services increasingly suggests the opposite. Generative AI is dramatically accelerating software development. Developers are producing more code, organisations are releasing software more frequently and engineering productivity continues to increase as AI-assisted development becomes mainstream.

Yet this acceleration also creates new forms of complexity. AI-generated code introduces different patterns of software risk. Autonomous development agents create new governance challenges.

Foundation models require validation, monitoring and oversight. Software supply chains become more difficult to understand. Model risk expands beyond traditional application risk.


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


Rather than reducing the need for quality assurance, AI is significantly expanding its scope. Increasingly, QA teams are expected not only to validate application functionality but also to assess AI behaviour, monitor model performance, verify governance controls, test resilience under changing conditions and generate evidence that increasingly demanding regulatory expectations have been satisfied.

This reflects another broader shift visible across regulatory thinking this year. The conversation is moving away from asking whether organisations have governance frameworks towards asking whether they can demonstrate that those frameworks actually work.

Policies vs evidence

Policies alone are becoming less important than evidence. Supervisors increasingly expect organisations to demonstrate that controls have been tested, resilience has been validated, failures have been identified, remediation has occurred and critical services continue to operate effectively.

Software testing therefore becomes much more than defect detection. It becomes one of the principal mechanisms through which financial institutions generate evidence that technology governance is functioning as intended.

For QA leaders, this changes both priorities and influence. Success is becoming less about defect counts, automation percentages or release readiness and increasingly about demonstrating resilience, maintaining continuous assurance and producing evidence that critical technology controls remain effective.

The implications extend well beyond engineering. Quality assurance is steadily moving into the centre of enterprise risk management.

The strongest message emerging from financial regulation this year is therefore not simply that organisations need more testing. It is that software testing itself is being redefined.

As software becomes increasingly AI-generated, continuously deployed and subject to greater regulatory scrutiny, QA is evolving from a delivery function into one of the core mechanisms through which financial institutions demonstrate trust, resilience and operational control. For software testing teams, that may prove to be the most significant shift of all.


NEXT MONTH

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS