Banks are beginning to talk openly about a new phase in technology delivery: one in which artificial intelligence does not merely assist developers, but materially compresses the time it takes to clear backlogs, build tools and move projects through the technology stack.
That shift could become a major challenge for software testing, quality engineering and operational resilience teams across financial services.
Deutsche Bank declared proudly this week AI is already helping it cut the time needed for some technology projects from years to months, while also helping clear internal backlogs more quickly. The German lender is using AI for tasks including data extraction, analysis and linking external market events to portfolio exposures.
The Deutsche Bank statement illustrates that the productivity case is obvious. AI-assisted engineering can help reduce delivery bottlenecks, improve developer output and speed up internal modernisation work that might otherwise sit in the backlog for months or years.
But the faster banks move, the more important the control environment becomes, with testing taking centre stage.
The central question for testing and resilience teams is no longer whether AI can help banks build faster. It is whether banks can prove that what is being built, changed or deployed remains safe, tested, resilient and explainable.
The testing gap
The risk is that AI accelerates the front end of the software delivery lifecycle faster than banks can modernise the back end of assurance.
If code, configuration, test cases, documentation and data analysis can all be generated or accelerated by AI, then traditional testing gates may come under pressure. Release cycles may shorten.
Regression packs may need to run more frequently. Test evidence may need to be produced faster. Controls may need to operate closer to real time.

That creates a new version of an old banking technology problem: speed on one side, assurance on the other.
For years, banks have invested in DevOps, automation, continuous testing and risk-based testing to improve release quality without slowing delivery. AI now raises the stakes. It has the potential to make the development process faster again, but also more opaque.
AI-generated code may look correct while still introducing subtle defects. AI-assisted workflows may rely on incomplete assumptions.
AI systems embedded in customer service, fraud detection, sanctions screening, lending or compliance monitoring may behave unpredictably when data, context or market conditions change.
That means the quality challenge is moving beyond functional testing. Banks will need stronger approaches to AI testing, model validation, adversarial testing, data quality checks, prompt and output evaluation, resilience testing and human-in-the-loop controls.
Regulators demand answers
Supervisors are also sharpening their focus. US bank regulators reportedly increased scrutiny of how financial firms use AI, including in areas such as data governance, third-party risk, system controls, kill switches, vendor oversight and contingency planning.
That is significant because it suggests AI assurance is becoming part of mainstream bank supervision, rather than a niche technology-governance topic.
For QA and resilience teams, this creates a practical challenge. Banks may increasingly need to demonstrate not only that an AI system was approved, but that it was properly tested, monitored and controlled throughout its lifecycle.
That includes evidence of how systems behave under failure conditions, how exceptions are escalated, how third-party AI tools are governed, how model drift is monitored, and how banks can safely shut down or override AI-enabled processes when required.
In other words, regulators are beginning to ask the same question testing teams have been asking internally: where is the proof?
DORA raises the resilience bar
In Europe, the Digital Operational Resilience Act has already pushed financial firms towards a more formal approach to ICT risk, incident response, third-party oversight and resilience testing.

DORA’s threat-led penetration testing requirements are especially relevant. The regime requires selected financial entities to test their ability to withstand realistic cyber threats, while regulatory technical standards set out requirements around scope, methodology, results, closure and remediation.
That matters because AI is changing the threat landscape at the same time as banks are trying to accelerate technology delivery.
AI-enabled attackers may be able to identify vulnerabilities more quickly, automate reconnaissance, generate more convincing social engineering attacks and probe complex systems at scale.
For banks, that raises the importance of threat-led penetration testing, red teaming, purple teaming, chaos testing and recovery testing.
The testing agenda is therefore expanding in two directions at once. On one side, banks need to test the AI systems they are building and deploying.
On the other, they need to test whether their wider technology estate can withstand AI-enabled attacks and faster-moving cyber threats.
ECB links AI and resilience
The European Central Bank has also been drawing a clearer line between AI, cyber risk and operational resilience.
ECB supervisors have warned that banks need to adapt their defences to the age of AI, particularly as newer AI models could help attackers find and exploit software weaknesses more quickly.
The ECB’s recent cyber resilience work has already put pressure on banks to show they can respond to and recover from severe cyber incidents.

For bank technology teams, this points to a broader supervisory direction. Resilience will not be judged only by policy documents, governance committees or static controls. It will increasingly depend on evidence from testing.
Can a critical service fail over? Can a bank recover from a destructive cyber event? Are dependencies mapped? Are third-party ICT providers included in realistic testing? Are remediation items closed quickly enough? Are AI-enabled systems covered by the same resilience discipline as other critical platforms?
Those are testing questions as much as risk-management questions.
Rethink of release governance
The next phase of bank technology governance may therefore be less about whether AI is allowed, and more about whether AI-accelerated delivery is matched by AI-strengthened assurance.
That could mean more automated test generation, but also stricter validation of those tests. It could mean AI-assisted code review, but also independent checks on hallucinated logic, insecure patterns and untested edge cases. It could mean faster release pipelines, but with stronger controls around evidence, traceability and rollback.

Banks may also need clearer policies on when AI can be used in the software delivery lifecycle. The controls required for an internal productivity tool will not be the same as those needed for customer-facing banking systems, credit decisions, market-risk tools or sanctions screening.
The direction of travel is clear: as AI becomes embedded in bank technology, QA and quality engineering teams will need to move closer to AI governance, cyber resilience, model risk management and regulatory compliance.
For now, much of the public discussion around AI in banking remains focused on productivity. Banks are using AI to help engineers work faster, reduce backlogs, automate analysis and improve operational efficiency.
But the more important story may be assurance. If AI allows banks to compress delivery timelines from years to months, then testing and controls cannot remain on yesterday’s timetable. They will need to become faster, more automated, more risk-based and more closely tied to operational resilience.
That may create a major opportunity for QA and testing teams. In an AI-enabled bank, quality engineering is no longer just about finding defects before release. It is about proving that faster, more automated and more intelligent systems can still be trusted under regulatory, operational and cyber pressure.
THIS SEPTEMBER IN LONDON



REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Goldman puts AI coding to the test
- How to test AI models that banks do not control
- OpenAI, Filigran and SunTec: the latest vendor and product news
- Sygnum: Testing AI is ‘a measurement problem’
- Banks’ ‘code for all’ push raises testing risks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



