
Article
Does Tero Make Sense if Your Team Already Uses Claude Code or Cursor?
Dive into the Article
We use cookies
We use cookies to understand how you found us and improve your experience. You can accept or decline analytics cookies. Learn more in our privacy policy.
Is your banking software ready for DORA? Tero helps you comply with the regulation and build operational resilience without sacrificing delivery speed.

In January 2025, a software failure disrupted payments at British bank Barclays on the very day of the UK tax deadline: customers were stranded at supermarkets, and families were unable to complete their home purchases.
Months later, an investigation by the UK Parliament revealed that the country’s leading banks and building societies had accumulated more than 800 hours of unplanned technology outages in just two years, the equivalent of 33 consecutive days of systems being down.
This is exactly the scenario that the European Union’s Digital Operational Resilience Act (DORA) seeks to prevent. The R in DORA stands for Resilience, and the real challenge for a bank is building that resilience without sacrificing delivery speed. Using AI agents to accelerate software quality, as Tero does, is one of the most direct ways to achieve it.
See how Tero brings governed AI agents into real software quality workflows for complex and regulated environments. Explore Tero
DORA became applicable on January 17, 2025, to banks, insurance companies, investment firms, and their external technology providers. Its objective goes beyond traditional cybersecurity. It focuses on digital operational resilience, meaning that financial entities must be able to withstand, respond to, and recover from any ICT-related disruption, whether a cyberattack or an internal technical failure.
The regulation is organized around five pillars:
The third pillar is the one that is almost never connected to the conversation around AI in QA, and it is precisely the one most closely related to what a software quality team does every day.
When a bank considers incorporating AI agents into its delivery processes, the first reaction from Risk and Compliance is often defensive: does this add a new source of technology risk? It is a reasonable question, but it is framed backward.
DORA doesn’t prohibit the use of AI. Under its regulation (Regulation (EU) 2022/2554), any technology component, including AI, must be governed, traceable, and part of a documented ICT risk management framework, with controls proportional to the size and criticality of the entity. That’s why it is essential for AI agents used in software quality to be designed to operate within that governance framework.
This is where Tero serves as an enabler of DORA compliance, since it actively builds the governance framework required by the regulation.
Tero is an agent harness from Abstracta, meaning a software layer that turns general-purpose AI models into specialized, governed agents for QA workflows.
The model provides the reasoning (it interprets information and generates responses), while Tero provides the context, permissions, human oversight, and evidence those agents need to operate in a controlled way within real software quality processes.
Tero is organized around four pillars: business context, trust, visibility, and governance. They were designed for regulated companies. Each one addresses, almost point by point, a specific DORA requirement:
| Tero Harness Capabilities | What it does | DORA pillar it addresses |
|---|---|---|
| Trust: agents treated as software, with output validation, acceptance criteria, and controlled evolution | Turns AI into an auditable component rather than a black box | ICT risk management |
| Governance: BYOC (in your own cloud) deployment, differentiated roles, auditing, and human approval for critical actions | Keeps people in charge of decisions, with complete traceability | Governance and management body accountability |
| Visibility: measurement of usage, cost, adoption, and impact of each agent | Provides concrete evidence for reporting to Risk and regulators | Incident reporting and evidence of control |
| Business context: agents connected to the client’s real stack, reusable and versioned | Accelerates and expands testing coverage across critical systems | Operational resilience testing program |
| Model-agnostic: agents operate across different model providers | Avoids critical dependency on a single AI provider | ICT third-party risk management |
At a technical level, this is supported by Tero’s five components: orchestration, integration, observability, governance, and security. The observability component is especially relevant to DORA because it records every conversation, every tool call, and every decision made by each agent. These actions generate the traceability that Compliance needs to demonstrate control.
DORA’s objective is for financial systems to be able to withstand, respond to, and recover from any failure. Banking incidents over the past two years show a pattern: a large share of serious operational failures do not originate from cyberattacks, but from software errors that reach production.
Some recent examples make this clear:
DORA requires rigorous testing precisely because European regulators understand this relationship: without a solid testing program, operational resilience is an unsupported promise.
This is where Tero comes in: by deploying collaborative agents for regression, impact analysis, test data generation, and logic failure detection, we expand the coverage and speed of QA practices without replacing the human judgment that Compliance still needs.
Put another way: every bug, vulnerability, or logic failure that a Tero agent helps detect before a release is an operational incident that the bank does not have to report to the regulator.
Adding Tero to the quality processes of a bank that is already investing in DORA is a concrete way to build resilience without sacrificing delivery speed. It strengthens three areas at the same time:
This is not a promise of zero incidents: no quality framework, whether human or AI-assisted, can guarantee that. The focus should be on consistently reducing the likelihood that a software failure becomes an incident the bank has to explain to a regulator.
Solutions for DORA compliance in banking typically cover one of its five pillars: ICT risk management, incident reporting, operational resilience testing, third-party risk management, and information sharing. Tero focuses specifically on the operational resilience testing pillar, with governed AI agents that expand testing coverage across critical systems and generate the traceability that Compliance needs when reporting to the regulator.
DORA does not prohibit the use of artificial intelligence in testing processes. What it requires is for any technology component, including AI, to be governed, traceable, and part of the entity’s ICT risk management framework.
An AI agent without governance can represent an additional risk. Tero is designed to prevent that scenario: each agent has acceptance criteria, human approval for critical actions, and BYOC deployment, allowing it to be incorporated into the ICT risk management framework rather than added as an uncontrolled exception.
A bank must be able to show a documented testing program, with defined procedures, tools, and methodologies, executed by independent parties, along with the classification, prioritization, and remediation of identified vulnerabilities. Tero’s observability component provides this evidence natively by recording every decision and every action taken by the agents used in the quality process.
DORA requires annual testing of all critical ICT systems and applications, and threat-led penetration testing (TLPT) every three years for the most significant entities.
Because a large share of serious operational incidents in banking originates from software errors that reach production, not from cyberattacks, as shown by the Barclays and Commonwealth Bank cases cited in this article.
Founded in 2008 and with a global presence, Abstracta is a technology company that helps organizations deliver high-quality software faster through the combination of AI-powered quality engineering and human expertise.
We believe that actively strengthening relationships helps us move forward and improve our clients’ software. That is why, over time, we have established partnerships with industry leaders such as Microsoft, Datadog, Tricentis, Perforce BlazeMeter, Sauce Labs, and PractiTest.
Explore our solutions and let’s discuss how to integrate AI into the software quality cycle.
News, articles, and resources on building better software.
Read about our privacy policy.

