Tero, an Agent Harness Enabling DORA in Banking

Is your banking software ready for DORA? Tero helps you comply with the regulation and build operational resilience without sacrificing delivery speed.

Illustrative image about Tero. Text on image: The evolution of AI agents for software delivery starts here.

In January 2025, a software failure disrupted payments at British bank Barclays on the very day of the UK tax deadline: customers were stranded at supermarkets, and families were unable to complete their home purchases.

Months later, an investigation by the UK Parliament revealed that the country’s leading banks and building societies had accumulated more than 800 hours of unplanned technology outages in just two years, the equivalent of 33 consecutive days of systems being down.

This is exactly the scenario that the European Union’s Digital Operational Resilience Act (DORA) seeks to prevent. The R in DORA stands for Resilience, and the real challenge for a bank is building that resilience without sacrificing delivery speed. Using AI agents to accelerate software quality, as Tero does, is one of the most direct ways to achieve it.

See how Tero brings governed AI agents into real software quality workflows for complex and regulated environments. Explore Tero

What DORA Is and Why It Matters for Your Software

DORA became applicable on January 17, 2025, to banks, insurance companies, investment firms, and their external technology providers. Its objective goes beyond traditional cybersecurity. It focuses on digital operational resilience, meaning that financial entities must be able to withstand, respond to, and recover from any ICT-related disruption, whether a cyberattack or an internal technical failure.

The regulation is organized around five pillars:

  1. ICT risk management: governance framework, identification of critical assets, and continuous risk assessment, with direct responsibility from the management body.
  2. Incident management and reporting: classify, record, and report relevant ICT incidents within strict deadlines.
  3. Digital operational resilience testing: a testing program that includes annual testing of all critical systems and, for the most significant entities, Threat-Led Penetration Testing (TLPT) every three years.
  4. ICT third-party risk management: map provider dependencies and require the same level of control from them.
  5. Information sharing: share threat and vulnerability intelligence across entities in the sector.

The third pillar is the one that is almost never connected to the conversation around AI in QA, and it is precisely the one most closely related to what a software quality team does every day.

Does AI in Testing Break DORA?

When a bank considers incorporating AI agents into its delivery processes, the first reaction from Risk and Compliance is often defensive: does this add a new source of technology risk? It is a reasonable question, but it is framed backward.

DORA doesn’t prohibit the use of AI. Under its regulation (Regulation (EU) 2022/2554), any technology component, including AI, must be governed, traceable, and part of a documented ICT risk management framework, with controls proportional to the size and criticality of the entity. That’s why it is essential for AI agents used in software quality to be designed to operate within that governance framework.

This is where Tero serves as an enabler of DORA compliance, since it actively builds the governance framework required by the regulation.

Tero is an agent harness from Abstracta, meaning a software layer that turns general-purpose AI models into specialized, governed agents for QA workflows.

The model provides the reasoning (it interprets information and generates responses), while Tero provides the context, permissions, human oversight, and evidence those agents need to operate in a controlled way within real software quality processes.

How Tero’s principles Connect with DORA

Tero is organized around four pillars: business context, trust, visibility, and governance. They were designed for regulated companies. Each one addresses, almost point by point, a specific DORA requirement:

Tero Harness CapabilitiesWhat it doesDORA pillar it addresses
Trust: agents treated as software, with output validation, acceptance criteria, and controlled evolutionTurns AI into an auditable component rather than a black boxICT risk management
Governance: BYOC (in your own cloud) deployment, differentiated roles, auditing, and human approval for critical actionsKeeps people in charge of decisions, with complete traceabilityGovernance and management body accountability
Visibility: measurement of usage, cost, adoption, and impact of each agentProvides concrete evidence for reporting to Risk and regulatorsIncident reporting and evidence of control
Business context: agents connected to the client’s real stack, reusable and versionedAccelerates and expands testing coverage across critical systemsOperational resilience testing program
Model-agnostic: agents operate across different model providersAvoids critical dependency on a single AI providerICT third-party risk management

At a technical level, this is supported by Tero’s five components: orchestration, integration, observability, governance, and security. The observability component is especially relevant to DORA because it records every conversation, every tool call, and every decision made by each agent. These actions generate the traceability that Compliance needs to demonstrate control.

Fewer Production Defects Mean Greater Operational Resilience

DORA’s objective is for financial systems to be able to withstand, respond to, and recover from any failure. Banking incidents over the past two years show a pattern: a large share of serious operational failures do not originate from cyberattacks, but from software errors that reach production.

Some recent examples make this clear:

  • Barclays confirmed to the UK Treasury Committee that the January 2025 outage was caused by a software issue in its mainframe, not by a cyberattack, and reported that it would allocate between £5 million and £7.5 million solely to compensate customers affected by that incident (UK Parliament).
  • In October 2025, Commonwealth Bank experienced an outage of nearly three hours that simultaneously affected payments, digital banking, and ATMs across Australia. The bank restored services but did not disclose the cause of the incident (ABC News).
  • The U.S. securities regulator (FINRA) fined a broker $2.25 million after a design flaw in its automated supervision system failed to detect more than 4 million irregular trades over seven years, a problem that originated in a coverage gap within the system itself, not in an external attack (FinanceFeeds).

DORA requires rigorous testing precisely because European regulators understand this relationship: without a solid testing program, operational resilience is an unsupported promise.

This is where Tero comes in: by deploying collaborative agents for regression, impact analysis, test data generation, and logic failure detection, we expand the coverage and speed of QA practices without replacing the human judgment that Compliance still needs.

Put another way: every bug, vulnerability, or logic failure that a Tero agent helps detect before a release is an operational incident that the bank does not have to report to the regulator.

How to Build Resilience without Sacrificing Delivery Speed

Adding Tero to the quality processes of a bank that is already investing in DORA is a concrete way to build resilience without sacrificing delivery speed. It strengthens three areas at the same time:

  • For compliance and risk: concrete evidence and traceability of how critical systems are tested, with human approval for every sensitive decision.
  • For technology and engineering: greater testing coverage across complex and legacy systems, without requiring a rip-and-replace of the existing stack.
  • For the management body: a measurable case to present to the supervisor showing that ICT risk management actively includes preventing defects before production.

This is not a promise of zero incidents: no quality framework, whether human or AI-assisted, can guarantee that. The focus should be on consistently reducing the likelihood that a software failure becomes an incident the bank has to explain to a regulator.

Illustration of a person at a laptop placing a chess piece on the screen and holding a connected-nodes icon, representing strategy and thoughtful decision-making. Faqs section about tero.

FAQs About Tero as a DORA Enabler

What Solutions Are Available for DORA Compliance in Banking?

Solutions for DORA compliance in banking typically cover one of its five pillars: ICT risk management, incident reporting, operational resilience testing, third-party risk management, and information sharing. Tero focuses specifically on the operational resilience testing pillar, with governed AI agents that expand testing coverage across critical systems and generate the traceability that Compliance needs when reporting to the regulator.

Does DORA Prohibit the Use of Artificial Intelligence in Testing Processes?

DORA does not prohibit the use of artificial intelligence in testing processes. What it requires is for any technology component, including AI, to be governed, traceable, and part of the entity’s ICT risk management framework.

Does Using AI Agents in QA Add a New Technology Risk That Must Be Reported Under DORA?

An AI agent without governance can represent an additional risk. Tero is designed to prevent that scenario: each agent has acceptance criteria, human approval for critical actions, and BYOC deployment, allowing it to be incorporated into the ICT risk management framework rather than added as an uncontrolled exception.

What Evidence Does a Bank Need to Provide to Demonstrate Compliance with DORA’s Testing Pillar?

A bank must be able to show a documented testing program, with defined procedures, tools, and methodologies, executed by independent parties, along with the classification, prioritization, and remediation of identified vulnerabilities. Tero’s observability component provides this evidence natively by recording every decision and every action taken by the agents used in the quality process.

How Often Does DORA Require Critical Systems to Be Tested?

DORA requires annual testing of all critical ICT systems and applications, and threat-led penetration testing (TLPT) every three years for the most significant entities.

Why Is Software Testing Part of Operational Resilience and Not Just Cybersecurity?

Because a large share of serious operational incidents in banking originates from software errors that reach production, not from cyberattacks, as shown by the Barclays and Commonwealth Bank cases cited in this article.

About Abstracta

Founded in 2008 and with a global presence, Abstracta is a technology company that helps organizations deliver high-quality software faster through the combination of AI-powered quality engineering and human expertise.

We believe that actively strengthening relationships helps us move forward and improve our clients’ software. That is why, over time, we have established partnerships with industry leaders such as Microsoft, Datadog, Tricentis, Perforce BlazeMeter, Sauce Labs, and PractiTest.

Explore our solutions and let’s discuss how to integrate AI into the software quality cycle.

Contact Us

Stay connected

with Abstracta

News, articles, and resources on building better software.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Read about our privacy policy.

Illustration of two people connected by a bridge, one with a laptop and one with a tablet, representing collaboration and bridging communication. End of article about tero.