Why operational resilience testing is becoming a boardroom priority for banks

Prof. Dr. Ekrem Duman, professor in the Industrial Engineering Department at Ozyegin University in Istanbul

As banks become increasingly dependent on digital platforms, cloud infrastructure and interconnected third-party providers, the definition of quality is expanding far beyond traditional software functionality.

For QA, quality engineering and resilience teams, proving that systems work is no longer enough. Institutions are facing growing pressure from regulators and boards to demonstrate that critical services can continue operating during major disruptions, cyber incidents and technology failures.

This shift is driving increased investment in non-functional testing, cyber resilience exercises, controls validation, business continuity testing and operational assurance programmes.

The focus is moving from preventing every incident to proving that banks can withstand disruption, recover quickly and continue delivering services when failures inevitably occur.

The growing importance of resilience testing reflects a broader change in how banks view risk. Technology outages, cyberattacks, failed migrations and third-party disruptions are increasingly treated as enterprise-wide threats rather than isolated IT events.

Prof. Dr. Ekrem Duman, professor in the Industrial Engineering Department at Ozyegin University in Istanbul, expllained that “operational risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.”

Unlike financial risks that arise from lending or trading activities, Duman noted that operational risk is rooted in the day-to-day running of a bank.

“Unlike credit or market risk, which come from taking deliberate financial positions, operational risk is largely the risk of things going wrong in running the business.”

For testing and quality assurance teams, the scope of those risks continues to widen. Duman wrote in a recent analysis that operational risk “spans a huge range: internal and external fraud, processing errors, system failures, legal and compliance breaches, physical disasters, and increasingly, cyberattacks.”

Beyond functional testing

As banking systems become more complex, regulators are placing greater emphasis on operational resilience rather than simply operational risk management. The distinction is important for testing teams.

Prof. Dr. Ekrem Duman

Traditional quality assurance programmes have often focused on validating whether systems perform as expected. Operational resilience programmes, by contrast, require banks to test how systems, processes and people respond when things go wrong.

Duman explained that regulators are increasingly focused on “not just preventing incidents but ensuring the bank can keep delivering critical services through disruption and recover quickly.”

He added: “This shifts the focus from ‘stop everything bad’, impossible, to ‘survive and continue when bad things happen’, [which is] achievable.”

That philosophy aligns closely with the growing use of resilience testing, disaster recovery exercises, failover validation, severe-but-plausible scenario testing and cyber simulation programmes across the banking sector.

New testing priorities

The convergence of operational and cyber risk is becoming a major concern for financial institutions.

Duman argued that “Banking now runs on technology and data, making cyber risk one of the most serious threats a bank faces.”

The potential impact of a successful attack extends far beyond technology systems. According to Duman, “a successful cyberattack can steal customer data, drain funds, disrupt critical services, or hold systems to ransom, and unlike many operational failures, it can do so at scale and at speed, affecting millions of customers in hours.”

This reality is pushing banks to expand cyber testing programmes beyond compliance requirements. Security validation, threat intelligence exercises, attack simulations and operational readiness assessments are increasingly being integrated into broader quality engineering and resilience strategies.

Duman pointed out that “the interconnectedness of the financial system also means a cyberattack on one institution or a shared service can ripple outward, making cyber risk a systemic as well as an individual concern.”


“As banks digitise further, adopt cloud services, and connect through open banking and APIs, the attack surface grows.”

– Prof. Dr. Ekrem Duman

The operational resilience challenge extends beyond a bank’s own technology estate.

As financial institutions continue migrating workloads to cloud platforms and relying on specialist technology providers, testing teams are being asked to validate resilience across increasingly complex supply chains.

Duman observed that “banks rely heavily on third parties, cloud providers, software vendors, payment processors, which extends operational and cyber risk beyond the bank’s own walls.”

He warned that “a failure or breach at a critical supplier can disrupt the bank as surely as an internal one,” while adding that “Managing the extended supply chain is now a central part of operational risk.”

These concerns are prompting greater focus on third-party resilience testing, supplier assurance programmes and contingency planning for critical service providers.

The rise of continuous assurance

The challenge facing banks is compounded by an evolving threat landscape.

Duman stressed that “the cyber threat facing banks intensifies continuously,” with attackers ranging from “opportunistic criminals to organised crime groups and state-sponsored actors.”

At the same time, “As banks digitise further, adopt cloud services, and connect through open banking and APIs, the attack surface grows.”

For QA and resilience teams, this means testing can no longer be viewed as a periodic exercise. Continuous validation of controls, ongoing resilience assessments and regular scenario testing are becoming essential components of operational assurance frameworks.

As Duman concluded: “Banks respond with constantly evolving defences, threat intelligence, and resilience planning, but the reality is an ongoing arms race in which staying ahead requires continuous investment, because the threat never stands still and a single major breach can be devastating.”


WHY not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS