A green test run proves the code did what the test expected. It does not prove the test was checking what the business depends on: a portfolio screen can render perfectly, every test green, and still show the wrong balance. AI now writes more of that code, faster than any suite can follow, and 2026 is the first year supervisors move from bedding DORA in to enforcing it. The question has moved from whether you test to whether you can prove it.
Coverage & Evidence Audit
An independent, risk-mapped picture of what your tests actually protect, and whether you could hand a supervisor the evidence today. Framed for engineering leadership and the board.
The deeper maturity read
Where it matters, the audit goes further: an eight-dimension read of how your team manages quality, with a regulatory overlay for DORA and FCA-regulated environments.
Advisory Retainer
Ongoing assessment and a monthly check-in. Quality risk, tracked as your systems change.
Certance Aperture. A live map of coverage risk across your systems.
Certance Lens. Enterprise Playwright with an AI agent pipeline.
Certance Field. Token efficiency for AI coding tools.
Coverage where failure costs the most.
We rank every critical path, in the interface or behind it, by what a failure actually costs. Tier 1: failures that move money, expose data, block access, or cannot be undone. Tier 2: failures that stay silent, where the system returns an answer that looks right and is wrong. Tier 3: operational friction. Coverage is judged against this map.
Eight-dimension maturity model
A structured read of how a team manages quality, scored across Change Capability, Test and CI Health, Knowledge Architecture, Engineering Culture, Dependency Health and Learning Culture, plus Regulatory Alignment and Audit Evidence Posture for regulated teams.
Built for regulated environments
In regulated financial services, the test record has to hold up when your risk function, or a supervisor, looks closely. Certance findings are built for exactly that scrutiny.
We speak the language your risk function already uses: DORA Article 25 testing evidence, FCA Important Business Services, test data exposure, and audit-ready release records. Findings land as independent evidence of regulatory risk the business can act on.
A 3-day engagement that maps your test suite to the business journeys it is supposed to protect.
A business-readable report: a journey coverage table mapped to Tier 1, 2, and 3 business risk, the top five gaps ranked by consequence, and an evidence posture check on whether your test records are retained, traceable to a release, and durable enough for a supervisory look-back. Written for a Head of Risk to act on. The assessment is independent. It holds in front of your risk function and your regulator in a way a self-assessment cannot.
It runs on test artefacts your own engineer exports and reviews before anything leaves your environment: test names and assertions, pipeline configuration, recent run summaries, coverage output. No account provisioning, no production data, no customer data. For most vendor-risk frameworks this is the lowest access tier a supplier can occupy. If the audit leads to implementation work, access for that is scoped separately under your own onboarding rules, with a delivered engagement already behind us.
We interview your engineering and QA leads and inventory every test you run, working from an artefact bundle your engineer exports and reviews. The audit never touches your systems.
We map your business-critical journeys and score coverage against Tier 1, 2, and 3 risk.
You receive a business-readable gap report: what is protected, the top gaps, and what to fix first.
Original research and real engagement artefacts. Subscribe to get new work as we publish it.
AI Token Efficiency Guide
How regulated engineering teams cut AI-tool spend without losing capability.
Coverage gap report, redacted
What a client receives: a journey-by-journey map of your coverage and where the gaps are.
AI-Native Quality Engineering
How teams shipping with AI can keep coverage visible, before invisible gaps become delivery or compliance risk.