
Article
What Is Quality Intelligence? And Why Most Definitions Get It Wrong
Dive into the Article
We use cookies
We use cookies to understand how you found us and improve your experience. You can accept or decline analytics cookies. Learn more in our privacy policy.
Two acronyms, one shared goal. See how DORA DevOps metrics can help banks support the requirements of the European Union’s Digital Operational Resilience Act (DORA) without sacrificing speed.

The global neobanking market reached an estimated USD 210 billion in 2025 and is projected to reach between USD 310 billion and USD 322 billion in 2026, according to Grand View Research and Fortune Business Insights.
This transformation coincides with particularly strong demand for digital financial experiences among millennials and Gen Z. In a 2025 Deloitte survey conducted in the United States, both generations were the most likely to switch banks: a slow transfer or an unintuitive experience can be enough to lose their loyalty.
In many cases, these users choose fintechs for their speed: accounts that can be opened in minutes, new features released every few weeks, and a digital-native experience designed for mobile from day one.
Traditional financial institutions need to keep up with that pace, combining resilience and speed while continuing to be the place where people keep their savings, pay their mortgages, and receive their salaries with the confidence that the system will be available.
What role does automation play in this journey? How can AI help? We cover it all in this article. You can also schedule a call with our specialists.
Trust is the most valuable asset a bank or insurance company has. A data breach, undetected fraud, or an outage lasting several hours on payday can damage that trust in a way no new product release can offset.
That is why the financial sector needs resilient systems that can withstand, respond to, and recover from technological disruptions.
Delivering high-quality products to today’s users also requires constant innovation and delivery speeds as close as possible to those of a fintech. A reliable financial product that remains stagnant, without frequent improvements, also falls short of what the market expects.
The quality of a financial product therefore has two components:
✔️ The reliability of its systems
✔️ The ability to innovate at the pace of the market.
Both are part of the same promise to customers. This dual requirement has a technical name and, coincidentally, shares the same acronym: DORA.
The acronym DORA refers to two different but complementary things.
The first framework establishes the regulatory objective. The second provides a concrete, measurable benchmark, backed by more than a decade of research, for achieving that objective without sacrificing delivery speed.
Using DevOps metrics is one possible technical approach to supporting the regulation’s objectives without turning the bank into a slow, bureaucratic organization.
At Abstracta, we help banking and insurance engineering teams comply with regulation without sacrificing speed through AI-powered quality engineering combined with human expertise.
If your team is considering taking this step, let’s talk about where you are today in terms of maturity and which path makes the most sense to prioritize.
Operational incidents affecting banks aren’t limited to cyberattacks: they can also originate from software failures, infrastructure issues, and technology providers.
The cost of this type of exposure is tangible. Research by Splunk and Oxford Economics estimates that unplanned downtime has an aggregate impact of USD 600 billion per year across Global 2000 companies. On average, each organization loses USD 95 million in annual revenue and sees a 3.4% drop in its stock price after an incident.
Change Failure Rate (CFR), one of the DORA DevOps metrics, measures precisely what drives that risk and what proportion of deployments requires immediate intervention. It also helps assess the stability with which an organization moves changes into production.
It’s not a metric required by the European DORA regulation, but it translates one of its core objectives—reducing the impact of technological disruptions—into a concrete operational signal. A lower CFR reduces the likelihood that a software change will cause a serious disruption, although it doesn’t by itself eliminate incidents or regulatory obligations.
Lowering CFR through rigorous testing provides a useful operational signal for the resilience testing program required by the regulation. Fewer production defects reduce the likelihood of serious disruptions and, with it, exposure to costs and reporting obligations.
Traditionally, increasing controls meant adding manual tasks, approvals, and wait times. Today, advanced automation and AI agents make it possible to expand test coverage without slowing down the deployment pipeline.
Teams can delegate tasks such as regression testing, impact analysis, test data generation, and initial results review to agents. This reduces repetitive work and accelerates Lead Time for Changes while maintaining continuous validation of critical financial systems.
Automation and AI therefore make it possible to advance two goals that once seemed at odds: moving changes into production faster while maintaining the depth of controls required for operational resilience.
For Risk and Compliance to accept AI as an accelerator, AI cannot operate as a black box: it needs a governance framework that defines what information it can use, what actions it can execute, which decisions require human approval, and what evidence must be retained.
Tero is an open-source agent harness: the software layer that turns general-purpose AI models into specialized, governed agents for quality workflows. The model provides the reasoning, while Tero provides the context, permissions, human oversight, and execution evidence.
Abstracta Intelligence is our AI platform for enterprise environments, built on Tero and designed to integrate agents into real QA and engineering workflows with context, governance, and visibility into their impact.
Abstracta Inteligence combines Tero with AI adoption programs, expert guidance, and dashboards that make it possible to measure results and continuously improve. This allows organizations to define what information agents use, what actions they can execute, which decisions require human oversight, and what evidence must be retained.
This approach keeps humans involved in critical actions and creates a reviewable record of every execution: what context the agent used, what rules it applied, what result it generated, and who approved the action.
This helps the bank demonstrate to Audit, Risk, Compliance, and the regulator that it is incorporating AI actively and in a controlled manner within its ICT risk management and defect-prevention processes.
DORA DevOps metrics aren’t part of the European DORA regulation, but they can be used to measure operational capabilities directly related to its resilience objectives.
| DORA DevOps Metric | What It Measures | How It Connects to the DORA Regulation |
|---|---|---|
| Change Fail Rate | Percentage of deployments that require immediate intervention, such as a rollback or hotfix. | Helps assess the stability of changes and reduce the likelihood of software-related incidents. |
| Failed Deployment Recovery Time | Time required to restore service after a failed deployment. | Relates to the ability to respond to and recover quickly from a disruption. |
| Deployment Frequency and Change Lead Time | The frequency and speed at which changes reach production. | Make it possible to deploy security patches, fixes, and regulatory changes quickly and in a controlled manner. |
| Deployment Rework Rate | Percentage of unplanned deployments made to fix failures or production incidents. | Helps identify how much rework failures cause and assess opportunities to strengthen testing and change management. |
A bank that incorporates governed AI agents into its quality processes can improve DORA DevOps metrics in several ways. Agents can reduce change failure rate and recovery time by detecting bugs, vulnerabilities, and logic flaws before they reach production. They can also accelerate regression testing, impact analysis, and test data generation, improving lead time and deployment frequency.
Their impact, however, depends on the quality of the process they are integrated into. The DORA 2025 report describes AI as an amplifier: it can increase throughput, but it can also increase instability when applied to immature pipelines, testing practices, or platforms.
Abstracta Intelligence provides the structure Risk and Compliance teams need to accept AI as an accelerator and integrate agents into regulated quality workflows. The platform combines three components:
This combination makes it possible to treat agents as software: with acceptance criteria, human oversight for critical actions, traceability for every execution, and evolution based on results.
The goal isn’t to promise zero incidents, since no quality framework can guarantee that. The focus should be on steadily reducing the likelihood that a software failure turns into a serious disruption, a reputational crisis, or a regulatory penalty.
To compete, banks need to combine the speed users expect with the operational strength their critical systems require. Banks need to close that gap without sacrificing the resilience required by regulation.
At Abstracta, we help build that roadmap, from maturity assessment to integrating the first governed agents into quality processes.
DORA DevOps metrics are five indicators that measure the speed and stability of software delivery: Change Lead Time, Deployment Frequency, Failed Deployment Recovery Time, Change Fail Rate, and Deployment Rework Rate.
The European Union’s DORA regulation and DORA DevOps metrics are related because both address technological resilience from complementary perspectives.
The regulation establishes what capabilities financial institutions need to develop to prevent, withstand, and recover from incidents, while DevOps metrics make it possible to measure the speed and stability with which they move software changes into production. They are not part of the regulatory requirements, but they can provide useful operational indicators for achieving its objectives.
Artificial intelligence doesn’t automatically improve a team’s delivery metrics. The DORA 2025 report found that AI increases delivery speed and can also increase instability when adopted on top of immature testing practices and pipelines. AI amplifies the capabilities a team already has.
An auditable record of every decision and every action taken by the AI agents used in the quality process, with human approval for critical actions and defined acceptance criteria. Tero’s observability component generates this evidence natively.
Founded in 2008 and with a global presence, Abstracta is a technology company that helps organizations deliver high-quality software faster through the combination of AI-powered quality engineering and human expertise.
We believe that actively strengthening relationships helps us move forward and improve our clients’ software. That is why, over time, we have established partnerships with industry leaders such as Microsoft, Datadog, Tricentis, Perforce BlazeMeter, Sauce Labs, and PractiTest.
Explore our solutions and let’s discuss how to integrate AI into the software quality cycle.
News, articles, and resources on building better software.
Read about our privacy policy.

