top of page

INSIGHTS

Consumer Duty: the 48-hour question every UK FS CTO should be ready for

nipundhiman

.

23 Jun 2025

.

4

Mins

QA Maturity: what UK Financial Services boards actually ask

Jul 1
5 min read

Updated: Jul 3

In 2026 the question on the board agenda is no longer 'is our software quality acceptable' — it is 'can we prove that it is, today, without notice'.


I have spent fifteen years building quality engineering and offshore delivery teams inside regulated firms. In that time I have watched the question that gets asked about software quality in UK Financial Services change shape twice. Ten years ago it was an engineering question — defect counts, test coverage percentages, release cadence. Five years ago it became an operational question — production incidents, MTTR, customer-facing outages. In 2026 it is a board question, and a different one. It is about evidence.

Three forces have tightened simultaneously around UK regulated technology leaders and made quality the topic it is today. The first is regulatory: Consumer Duty under live FCA supervision, PRA Operational Resilience for banks and insurers, Solvency II and IFRS 17 for the actuarial systems behind them. Each of these regimes asks a question whose answer lives in software, and each one supervises that answer. The second is technological: AI-native quality engineering has moved from pilot to production faster than most firms anticipated. The third is commercial: in a market where speed-to-product and trust are both scarce, the quality function is the lever that produces both.


I designed the Enterprise QA Maturity Assessment Framework to give a senior leader in a UK Insurance, Re-Insurance, or Financial Services firm an honest read on where their quality function stands across all three forces at once. It is structured as eight dimensions, scored against forty diagnostic statements, with a result that translates to commercial, regulatory and operational risk in language a board recognises. This post is the short walk-through of what is in it and why it is built the way it is.


The eight dimensions and why these eight

A quality function does not fail in one place. It fails across a shape. The framework's eight dimensions are the eight surfaces on which a UK regulated firm's quality posture either holds or breaks. They are:


  • Quality Strategy & Governance whether the function has an  owned, board-visible strategy.

  • Test Engineering & Automation — coverage, framework health, and whether the automation suite is trusted.

  • CI/CD & Release Quality — whether quality gates sit in the pipeline and releases are predictable.

  • Non-Functional Assurance — performance, security, accessibility, resilience tested systematically.

  • Quality Intelligence & Metrics — whether quality data is collected, trusted, and drives decisions.

  • Regulatory & Compliance Assurance — whether testing produces defensible regulatory evidence.

  • AI-Native Quality Engineering — whether AI is systematically used across the QE workflow.

  • QA Operating Model & Capability — skills, structure, onshore/offshore mix, key-person risk.


Each dimension is scored independently. The headline number — the total out of eighty — is the conversation starter; the shape across the eight is the conversation.


The gating rule

Two dimensions gate the others. For a regulated firm, a Level 1 score in CI/CD & Release Quality or in Regulatory & Compliance Assurance caps the overall maturity at Level 2, regardless of strength elsewhere. The reason is operational, not theoretical: these are the two surfaces where regulatory and business risk concentrates, and the two surfaces where a deficit cannot be papered over by strength in other areas. A firm with excellent automation but a release process that requires a war room every week is not a mature quality function. A firm that scores well on engineering but cannot evidence Consumer Duty test coverage is not a mature quality function.


I have watched senior leadership teams argue against this gating rule in workshops — usually because their firm has invested hard in one dimension and resents being told that investment does not compensate for a deficit elsewhere. The argument is always the same and the answer is always the same: the regulator does not care which dimensions your firm is strong on. The regulator cares whether you can answer the question they are asking. The gating rule is the framework's way of telling you the truth about that.


What a typical UK mid-market firm scores

In RegalTech's engagement experience, most UK regulated mid-market firms self-assess between Level 2 and Level 3 overall. Genuine Level 4 firms are rare. The shape is more uniform than it ought to be: investment has historically concentrated in test engineering and automation (Dimension 2 is usually the strongest), leaving the strategy dimension (Dimension 1), the metrics dimension (Dimension 5), and the AI-native dimension (Dimension 7) under-developed. If a firm's shape matches that typical profile, the firm is not behind — but it is not differentiating either. Differentiation in 2026 happens in two dimensions specifically: AI-Native QE (rising fast across the market) and Quality Intelligence & Metrics (still rare and disproportionately valuable to regulators).


How to use the framework

Score it with two senior colleagues in the room, not alone. The disagreements between you and your team are where the value is — the question is not what your individual scores are, the question is what your scores together reveal. Score against evidence visible today, not what your team intends to complete this quarter; intent is not maturity. Read the shape, not just the number, and pay particular attention to the gating dimensions. If a low score in either of those is your reality, that is the conversation; everything else follows.


The framework is free to download. The full PDF runs to forty-six pages, includes all eight dimensions in depth, the complete forty-statement scorecard, the Quality Risk Exposure read for each maturity band, and a ninety-day prioritisation method that turns the result into a sequenced plan. There is an Excel companion that auto-scores it and produces a radar profile chart. I built it because the leaders I work with consistently arrive at the same point in their thinking: they need an honest read on where they stand before they can decide what to do next.


The next step after a self-assessment

A self-assessment is honest but unverified. Its main limitation is that it relies on what you and your team can see from inside the firm. For leaders who want a validated baseline and a sequenced plan, the natural next step is an independent QA Maturity Audit — a fourteen-day diagnostic at a fixed fee of £6,000, with a written report, a prioritised 90-day roadmap, and a 60-minute leadership readout. The audit fee is credited against a retained partnership signed within thirty days. I do not say this to sell the audit in a blog post. I say it because that is the path most leaders who download the framework end up choosing within a quarter, and the framework itself is built so that you can do most of the work without needing me at all.

Use the framework as a working instrument. Mark it up. Disagree with the descriptors. Change the weightings. Quality, in the end, is a judgement made on evidence — and the value of the framework is the conversation it enables, not the score it produces.


— Nipun Kumar, Founder & CEO, RegalTech Global Delivery Systems


Related Asset
Delivery Risk Audit Template
Download · Free

 
 
 

Recent Posts

See All

Comments


bottom of page