FR EN
Software testing in finance: calculations, resilience and DORA
4 October 2026 Oussama Belakhdar 3 min read

Software testing in finance: calculations, resilience and DORA

In finance, a defect is counted in money: a badly rounded rate, a transaction posted twice, a limit ignored. And since January 2025, the resilience of information systems has been subject to explicit European obligations.

Key takeaways
  • Calculation is the first risk: rates, rounding, value dates, fees.
  • A transaction must never go through twice: replay, double click, recovery after an error.
  • DORA has applied since 17 January 2025: it requires a digital operational resilience testing programme.
  • Permissions are tested like a feature: who can approve, who can only view.

Oussama Belakhdar, QA architect and founder of AutomationDataCamp, has worked on software testing projects in this industry. This page sums up what we check first. Our clients are not named.

Industry figures

£48.65 M Fine imposed on TSB bank by UK regulators after its failed 2018 IT migration, which affected a large share of its 5.2 million customers. Bank of England — TSB fined for operational resilience failings (2022)
$1.15 bn Estimated losses of Fortune 500 banks during the CrowdStrike outage of 19 July 2024, triggered by a faulty software update (insurer estimate). Parametrix, via Insurance Journal (2024)
$4.99 M Global average cost of a data breach in 2026, up 12%, a record. IBM — Cost of a Data Breach 2026

Figures published by the organisations cited, not results of our own engagements.

What makes testing hard

  • Calculation rules are numerous and change (scales, rates, regulation).
  • Batch jobs run overnight and depend on the date: you need to be able to simulate a month end or a public holiday.
  • Systems are old and interconnected: a change on one side breaks a flow on the other.

The scenarios we test first

  1. Calculations with boundary values: zero, maximum amount, rounding, rate change during a period.
  2. Idempotency: the same transaction replayed produces only one movement.
  3. Limits, thresholds and multi-level approvals.
  4. End-of-day and month-end processing, with a simulated date.
  5. Third-party service unavailable: the system fails cleanly and recovers without loss.

The framework to know

DORA, Regulation (EU) 2022/2554. Applicable since 17 January 2025 to financial entities in the EU. It covers ICT risk management, incident reporting, digital operational resilience testing, third-party risk and information sharing. Some entities must also run threat-led penetration tests (TLPT) at least every three years.

What it changes for the QA team. Testing is no longer just an internal practice: it must be planned, documented and followed by remediation plans.

Our method

  1. Start from the risks. We rank features by the impact and likelihood of a defect, then test first what would cost the most.
  2. Automate what comes back in every release. API tests for rules and integrations, Playwright for user journeys, k6 for load, all wired into your CI.
  3. Controlled test data. Fictitious data sets, created for each run, never copied from production.
  4. AI with a review. An assistant speeds up writing scenarios and tests; every generated test is reviewed against our 7-question checklist. See our case study: from a PDF specification to Playwright tests.

Start with an audit

A QA audit reviews your application: a written assessment, a test strategy adapted to your industry and a costed action plan, in 5 days, for €1,000 excl. VAT as a fixed fee. Delivered remotely, in English or French, for companies in the US, the UK, Canada, Australia, Europe, the Gulf and the Nordics. The first scoping session is free.

See the QA audit at €1,000 excl. VAT

Frequently asked questions

Does the DORA regulation concern software testing?

Yes. DORA, applicable since 17 January 2025, requires financial entities to run a documented and monitored digital operational resilience testing programme. Functional and performance tests of critical applications are part of it.

What should be automated first in financial software?

Calculations (with boundary values and rounding), transaction idempotency, limits and approvals, and end-of-period processing. These are the tests rerun on every release that protect the most.

How much does a QA audit cost at AutomationDataCamp?

The QA audit and diagnosis costs €1,000 excl. VAT as a fixed fee, over 5 days: a written assessment, a test strategy and a costed action plan. The first scoping session is free.

Other industries: Healthcare · E-invoicing · Blockchain · Logistics · E-commerce · Document management. All industries.

Page signed by Oussama Belakhdar, written with the help of AI. Regulatory references link to the official sources above; they are not legal advice.

Related articles