DORA, continuous control testing, and ICT resilience reshape QA/QC priorities
The gist
QA/QC is shifting from release validation to continuous control assurance, with teams now expected to prove resilience, remediation, and evidence under stress.
This week’s developments
DORA and Model Risk Push QA/QC into Continuous Control Testing
EU DORA now makes the next requirement explicit for banks and fintechs: QA/QC must support ongoing ICT resilience testing, remediation of findings, and proof that controls stay effective under stress, with some firms also facing threat-led penetration testing. That moves the standard beyond the lifecycle traceability and reproducibility already in view to continuous evidence that critical services still hold across cloud, third-party, and operational dependencies. Updated model risk guidance from the Federal Reserve, FDIC, and OCC extends the same logic to AI and external models through lifecycle monitoring and ongoing validation, not one-time approval.
The operating model is widening across resilience, AI governance, medical devices, and GMP, with recurring demands for inventory tracking, logging, access restriction, incident response, human oversight, pre-production validation, drift detection, and rollback/version control. The emerging four-pillar AI agent framework captures the shift: identity and scope, authorization and escalation, observability and monitoring, and accountability and audit. Evidence generation is now as important as test execution.
For practitioners, this means more time on control instrumentation, exception handling, remediation tracking, and audit-ready evidence assembly. Teams built around release testing now need people who can prove control effectiveness in production and reconstruct what happened when stress, drift, or compliance failures surface.
How do we prove continuous control effectiveness under DORA?
If you're an individual contributor
- Release testing alone won't protect you; control proof is the new value.
- Build skill in logging, exception handling, and evidence packs so you can prove controls held under stress, not just that tests passed.
Sources
- 5 AI Security Projects That Will Get You Hired in 2026 (and beyond) .. — ☁️ The Cloud Security Guy 🤖, August 9, 2026
Shows how to secure AI agents with least privilege, human approvals, logging, and emergency revocation.
- How AI for Financial Decision Making Works: A Guide for the US Financial Market — TechBullion, July 11, 2026
Shows how banks govern AI models with inventories, validation, monitoring, and traceable compliance controls.
- AI Agents Are Just Distributed Systems Now — Salman Munaf, TikTok — AI Engineer, August 29, 2026
Shows scoped permissions, approval metadata, and observability patterns for reconstructing agent actions and failures.
If you manage a team
- Your team must shift from test execution to continuous control assurance.
- Coach for monitoring, remediation tracking, and audit-ready evidence; people who only run scripts will be less useful fast.
Sources
- TCP #132: Your Control Tower guardrails belong in Terraform, not the console — The Cloud Playbook, July 12, 2026
Shows how to measure coverage, drift, and time-to-evidence while making guardrails auditable and owned.
- How to Build a Continuous Evidence Program — SC Media, August 24, 2026
Shows how to automate evidence collection, track gaps, and assign remediation for audit-ready control assurance.
- DevSecOps Expert: Use 'Stages, Not Gates' to Secure Fast-Moving Pipelines -- Virtualization Review — Virtualization Review, August 14, 2026
Shows how to embed checks throughout delivery, tune noisy findings, and assign ownership for ongoing remediation.
If you lead the organization
- Your QA/QC model is outdated if it can't prove controls in production.
- Invest in control instrumentation, model/third-party monitoring, and evidence ops now, or compliance and resilience gaps will surface in audit.
Sources
- Rethinking Security Investment: From Uniform Control Models to Risk-Weighted Protection — Cxodigitalpulse News, August 3, 2026
Shows how to tier controls by asset criticality, focusing deeper protection and monitoring on the most important systems.
- Continuous testing drives DORA compliance — QA Financial, July 20, 2026
Shows how banks are moving from periodic checks to automated, dependency-aware continuous assurance for operational resilience.
- Achieving Compliance as a Platform Engineering Team by Helping Developers — infoq.com, July 23, 2026
How a platform team simplified governance, used guardrails, and improved developer adoption for continuous compliance.