As the industry moves into 2026, QA Financial is publishing a forward-looking three-part series examining what lies ahead for software testing and quality assurance in financial services, banking and healthcare.
Drawing on a year of reporting, interviews and event coverage, the series explores how AI, regulation, capital investment and shifting risk appetites are reshaping the role of QA.
Rather than looking back, this series focuses on what senior leaders, regulators and practitioners signal will matter next, and why quality engineering is becoming one of the most strategically important functions in regulated industries.
Part I can be found here. The third instalment will be available on January 14.
Regulation
If artificial intelligence defined the how of quality assurance in 2025, regulation defined the why. As organisations head into 2026, regulatory pressure, particularly around operational resilience, third-party risk and software accountability, is no longer a looming concern but an active force reshaping how QA teams operate.
Coverage throughout 2025 made clear that regulators now view software quality as inseparable from financial stability and patient safety, pushing QA functions to the forefront of governance and risk management.
Nowhere is this more evident than in the impact of the EU’s Digital Operational Resilience Act. During 2025, DORA shifted from a policy discussion to a practical reality for banks, insurers and their technology partners.
Stephanie Phelps, Operational Resilience Specialist at Reinsurance Group of America (pictured at the top), described the scale of this shift when she said: “While up until now resilience has mostly been a voluntary endeavour … the EU decided to … regularise the resilience landscape.”

Her remarks reflected a broader industry realisation that resilience testing, once unevenly applied, is becoming standardised, enforceable and auditable.
For QA teams, DORA’s implications go far beyond documentation. Jens Kunz, partner at Noerr, explained how the regulation fundamentally alters testing expectations when he noted: “The stricter requirements under DORA are leading to a fundamental change in IT penetration testing practices in the financial sector.”
Threat-led penetration testing, resilience validation and third-party assessments are now integral to quality strategies rather than parallel security exercises.
Heading into 2026, QA teams will increasingly be expected to demonstrate not only that systems work, but that they fail safely, recover quickly and remain observable under stress.
Regulatory concern over software risk is not confined to Europe. In 2025, the Financial Stability Board, the G20’s global watchdog, warned explicitly about the systemic implications of AI-driven software.
Its assessment that “AI is reshaping the financial sector … but these benefits sit alongside a widening set of software-related vulnerabilities” reinforced the view that testing failures can propagate risk across institutions and borders.
As a result, 2026 is likely to bring greater convergence between supervisory expectations and internal QA metrics, with boards demanding clearer lines of sight from test results to enterprise risk exposure.

Senior regulators echoed this sentiment at industry forums. Santosh Pandit of the UK’s Prudential Regulation Authority stated bluntly: “Software is the single most important risk that businesses will need to manage in the future.”
That framing places QA teams squarely within the operational risk function, elevating their outputs to the same level of scrutiny as capital adequacy or liquidity stress tests.
In practice, this means that in 2026 QA artefacts, such as test coverage reports, defect trends, resilience scenarios, will increasingly be reviewed by compliance, risk and audit committees.
Financial institutions themselves are already responding to this reality. Citi’s Jason Morris, Head of Developer Pipelines, highlighted how regulation alone is not the main constraint when he said: “It is a cultural barrier, not a regulatory one.”
His observation points to a critical challenge for 2026: aligning development speed with regulatory expectations without creating friction or paralysis.
As Morris put it, organisations need to move “less about test automation, more about software engineering,” reframing QA as an enabler of confident decision-making rather than a bottleneck.
Healthcare firms
Healthcare and insurance firms face parallel pressures, often under different regulatory regimes but with equally high stakes. As testing becomes central to demonstrating patient safety, data privacy and system availability, QA teams in these sectors will encounter increased scrutiny from regulators and partners alike.
The direction of travel is the same: proof of control, proof of resilience and proof that software risk is actively managed.
Another significant signal from 2025 was growing regulatory collaboration across borders. The partnership between the UK’s Financial Conduct Authority and the Monetary Authority of Singapore to advance AI testing standards reflects a move toward global alignment on how complex systems should be validated.
For QA leaders in 2026, this suggests that fragmented, region-specific testing approaches will increasingly give way to harmonised frameworks capable of satisfying multiple regulators simultaneously.
Taken together, the regulatory narrative heading into 2026 is unmistakable. Quality assurance is no longer a downstream technical function; it is a frontline defence against operational failure, regulatory breach and systemic risk.
QA teams that can translate test outcomes into risk language, resilience metrics and governance artefacts will find themselves more visible, and more influential, than ever before.
As the industry moves into 2026, QA Financial is publishing a forward-looking three-part series examining what lies ahead for software testing and quality assurance in financial services, banking and healthcare. Part I can be found here, while the third instalment will be available on January 14.
COMING IN 2026


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- AI adoption strains JPMorgan testing
- Can banks ‘outsource’ AI accountability?
- HDFC Bank raises testing stakes
- Is observability banking QA’s next discipline?
- Barclays on AI testing, telemetry and kill switches
WATCH NOW

QA FINANCIAL PODCASTS

Listen to Sudeepta Guchhait on Nasdaq’s new Mimic AI testing platform
QA Financial sits down with Sudeepta Guchhait, Senior Director of Product Framework & Quality Engineering at Nasdaq
——–
Listen to Wesley Scheffel and Robin Rain on Schroders’ DevOps strategy
We catch up with Wesley Scheffel, Head of Cloud Platform and Product Engineering at Schroders, and Robin Rain, Head of Cloud Platform Architecture
——–
Listen to Citi’s Jason Morris on Lightspeed and the future of continuous delivery
Jason Morris, Head of Developer Pipelines for Securities Markets and Banking at Citi, talks about Lightspeed


