July roundup of regulatory developments and compliance news

RBI governor Sanjay Malhotra

A monthly roundup of the most important regulatory, legal and supervisory developments shaping QA, software testing, AI governance and digital resilience across banking and financial services.

This month’s regulatory developments show one clear trend emerging across global financial supervision: regulators are moving beyond high-level AI principles and increasingly focusing on how firms test, validate, monitor and govern AI systems in practice.

From Europe to India, Australia and the international capital markets community, supervisory attention is shifting towards continuous testing, operational resilience and evidence-based assurance.

RBI turns AI model risk into a testing challenge

India’s Reserve Bank has proposed comprehensive model risk management rules that would require banks to establish board-approved governance frameworks covering all models, including artificial intelligence and machine-learning systems.

The draft guidance requires ongoing risk assessment, independent validation, enterprise-wide model inventories and stronger oversight of third-party AI models, while also requiring additional cybersecurity controls for customer-facing generative AI applications.

The proposals reinforce a growing global regulatory consensus that AI governance increasingly depends on continuous testing, validation and monitoring rather than one-off model approval exercises.

ECB calls for change to DORA testing

The ECB's headquarters in Frankfurt, Germany
ECB HQ

The European Central Bank has warned that advances in artificial intelligence are creating new operational resilience challenges that require banks to rethink how they approach Digital Operational Resilience Act (DORA) testing.

As AI accelerates software development while simultaneously increasing cyber risks and operational complexity, banks face growing pressure to demonstrate that resilience testing evolves alongside increasingly intelligent technology estates.

For QA and resilience teams, DORA is becoming far more than a compliance exercise. Regulators increasingly expect testing programmes to generate evidence that critical services remain resilient under rapidly changing technology and threat environments.

EU AI Act turns classification into testing exercise

The European Commission’s latest guidance on high-risk AI systems has transformed one of the first practical AI Act compliance challenges into a quality engineering issue.

Financial institutions must now determine which AI systems fall within the regulation’s high-risk classifications before deciding what governance, testing and documentation obligations apply.

That process places software testing, validation and traceability much earlier in the AI development lifecycle. QA teams are increasingly expected to help identify AI use cases, validate system behaviour and produce evidence supporting regulatory classification decisions before applications enter production.

IOSCO pushes markets towards continuous AI assurance

The International Organization of Securities Commissions has published a new supervisory toolkit designed to help securities regulators oversee the growing use of artificial intelligence across capital markets.

The toolkit focuses on governance, oversight, validation and supervisory expectations for AI systems used by regulated firms, reinforcing that AI assurance should extend throughout the technology lifecycle rather than rely solely on pre-deployment testing.

For capital markets firms, the message closely mirrors developments across banking: continuous AI testing is becoming an essential component of regulatory compliance.

CPS 230 reshapes resilience testing in Australia

Australia’s Prudential Regulation Authority continues preparing financial institutions for CPS 230, which significantly raises expectations around operational resilience, service provider oversight and business continuity testing.

The prudential standard requires firms to identify critical operations, strengthen third-party governance and demonstrate through regular testing that they can continue delivering essential services during major disruptions.

The standard is accelerating investment in resilience testing, recovery validation and evidence-based operational assurance across Australian banking and insurance.

UK Parliament calls for AI-specific stress testing

Dame Meg Hillier

The UK Parliament’s Treasury Committee has intensified pressure on financial regulators, concluding that the current “wait-and-see” approach to AI creates unnecessary risks for consumers and financial stability.

Among the recommendations, Committee chair Dame Meg Hillier called on the Bank of England and the FCA to conduct AI-specific stress testing, provide clearer regulatory guidance on AI governance and strengthen oversight of major AI and cloud providers.

The recommendations reinforce growing expectations that AI assurance should extend beyond traditional cybersecurity exercises into dedicated resilience testing focused specifically on autonomous systems.

Supervisory focus shifts from policy to evidence

One of the clearest regulatory themes emerging this month is the growing emphasis on demonstrable evidence rather than high-level governance policies.

Across multiple jurisdictions, supervisors are increasingly asking financial institutions to prove that AI systems remain reliable, resilient and well governed through continuous validation, monitoring, testing and documented assurance activities.

That represents an important evolution for quality engineering teams, whose responsibilities are increasingly expanding beyond software functionality into AI governance, operational resilience and regulatory compliance.

US OCC pushes risk-based technology supervision

The US Office of the Comptroller of the Currency (OCC) is continuing to embed risk-based technology supervision across its oversight of banks, signalling that firms should be able to demonstrate why critical systems receive the greatest testing and assurance.

The approach aligns with a broader global regulatory shift towards evidence-based software testing, AI model validation and operational resilience, placing greater emphasis on proving that testing is proportionate to technology risk rather than simply meeting compliance checklists.

The statement came amid the appointment of Megan Crespi, who will join the OCC as Senior Deputy Comptroller (SDC) for Technology and Information Services. She was previously the COO of Comerica Bank.

Third-party AI risk moves up the supervisory agenda

Regulators are also paying closer attention to third-party technology dependencies as banks accelerate adoption of cloud platforms, foundation models and external AI providers.

Whether through DORA, CPS 230, the RBI’s proposed model risk framework or broader operational resilience initiatives, supervisors increasingly expect financial institutions to validate externally sourced AI capabilities with the same rigour applied to internally developed systems.

For many QA teams, this means software assurance programmes must now extend well beyond the organisation’s own codebase.


16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS