A new framework is offering detailed guidance for QA teams and software testers tackling AI-specific vulnerabilities in banking and fintech environments.
The Open Web Application Security Project (OWASP), a non-profit foundation based in California that works to improve software quality and security, has released an AI Testing Guide aimed at helping financial institutions to assess, integrate and embed artificial intelligence-powered software systems.
With tens of thousands of members worldwide — including major banks, investment firms, and insurance companies —OWASP’s initiative marks “a significant step forward” for QA and DevSecOps teams navigating the risks of AI adoption and integration, the organisation stressed.
“As banks and financial services firms deploy AI in increasingly critical domains — such as fraud detection, credit scoring, and algorithmic trading — the OWASP AI Testing Guide (AITG) delivers urgently needed tools to identify and address AI-specific vulnerabilities that traditional software testing frameworks often overlook,” according to a statement.
The AITG introduces testing protocols for a range of emerging AI threats, including prompt injection attacks targeting large language models, model poisoning that corrupts training data, adversarial examples designed to manipulate machine learning predictions, as well as membership inference attacks, which can expose personal data from training sets.
“AI is probabilistic, sensitive to subtle input shifts, and vulnerable to attacks.”
– OWASP
For QA and software testing teams within the financial sector, the guide provides specialised methodologies to test non-deterministic behavior, monitor data drift, and assess bias in machine learning outputs, risks that could have real-world impacts on fairness, regulatory compliance, and customer trust.
“AI doesn’t behave like traditional software,” the guide explained. “It is probabilistic, sensitive to subtle input shifts, and vulnerable to attacks that exploit its complexity.”
As such, OWASP calls for continuous monitoring and differential privacy techniques to guard against data leakage and performance degradation in production environments.
The guide was developed under the supervision of security experts Matteo Meucci and Marco Morana, who aimed to remain technology-neutral and industry-agnostic, making it broadly applicable across different use cases.
Important for the banking and insurance sectors, the AITG outlines documented evidence protocols that help institutions demonstrate due diligence to regulators and stakeholders, an essential requirement as oversight of AI systems tightens globally.
By extending the principles of OWASP’s well-established Web and Mobile Security Testing Guides, the AITG gives financial QA leaders “a trusted framework to integrate into existing testing pipelines, bridging the gap between software quality engineering and next-generation AI assurance,” the organisation said.
THIS JULY

NEW EVENT

Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW



