Software testing in finance: calculations, resilience and DORA
In finance, a defect is counted in money: a badly rounded rate, a transaction posted twice, a limit ignored. And since January 2025, the resilience of information systems has been subject to explicit European obligations.
- Calculation is the first risk: rates, rounding, value dates, fees.
- A transaction must never go through twice: replay, double click, recovery after an error.
- DORA has applied since 17 January 2025: it requires a digital operational resilience testing programme.
- Permissions are tested like a feature: who can approve, who can only view.
Oussama Belakhdar, QA architect and founder of AutomationDataCamp, has worked on software testing projects in this industry. This page sums up what we check first. Our clients are not named.
Industry figures
Figures published by the organisations cited, not results of our own engagements.
What makes testing hard
- Calculation rules are numerous and change (scales, rates, regulation).
- Batch jobs run overnight and depend on the date: you need to be able to simulate a month end or a public holiday.
- Systems are old and interconnected: a change on one side breaks a flow on the other.
The scenarios we test first
- Calculations with boundary values: zero, maximum amount, rounding, rate change during a period.
- Idempotency: the same transaction replayed produces only one movement.
- Limits, thresholds and multi-level approvals.
- End-of-day and month-end processing, with a simulated date.
- Third-party service unavailable: the system fails cleanly and recovers without loss.
The framework to know
DORA, Regulation (EU) 2022/2554. Applicable since 17 January 2025 to financial entities in the EU. It covers ICT risk management, incident reporting, digital operational resilience testing, third-party risk and information sharing. Some entities must also run threat-led penetration tests (TLPT) at least every three years.
What it changes for the QA team. Testing is no longer just an internal practice: it must be planned, documented and followed by remediation plans.
Our method
- Start from the risks. We rank features by the impact and likelihood of a defect, then test first what would cost the most.
- Automate what comes back in every release. API tests for rules and integrations, Playwright for user journeys, k6 for load, all wired into your CI.
- Controlled test data. Fictitious data sets, created for each run, never copied from production.
- AI with a review. An assistant speeds up writing scenarios and tests; every generated test is reviewed against our 7-question checklist. See our case study: from a PDF specification to Playwright tests.
Start with an audit
A QA audit reviews your application: a written assessment, a test strategy adapted to your industry and a costed action plan, in 5 days, for €1,000 excl. VAT as a fixed fee. Delivered remotely, in English or French, for companies in the US, the UK, Canada, Australia, Europe, the Gulf and the Nordics. The first scoping session is free.
See the QA audit at €1,000 excl. VAT
Frequently asked questions
Does the DORA regulation concern software testing?
Yes. DORA, applicable since 17 January 2025, requires financial entities to run a documented and monitored digital operational resilience testing programme. Functional and performance tests of critical applications are part of it.
What should be automated first in financial software?
Calculations (with boundary values and rounding), transaction idempotency, limits and approvals, and end-of-period processing. These are the tests rerun on every release that protect the most.
How much does a QA audit cost at AutomationDataCamp?
The QA audit and diagnosis costs €1,000 excl. VAT as a fixed fee, over 5 days: a written assessment, a test strategy and a costed action plan. The first scoping session is free.
Other industries: Healthcare · E-invoicing · Blockchain · Logistics · E-commerce · Document management. All industries.
Page signed by Oussama Belakhdar, written with the help of AI. Regulatory references link to the official sources above; they are not legal advice.
Related articles

AI & ML for test automation
What AI concretely changes in test automation.
Read more : AI and ML for test automation
Integrating Automation into CI/CD
Jenkins, GitLab CI, GitHub Actions — practical examples.
Read more : Integrating Automation into CI/CD