Certance Advisory · Quality Engineering
Certance makes quality measurable where it matters most: whether your tests actually protect the business, whether a green pipeline is real evidence, and whether you could prove it to a supervisor today. Independent, fixed scope, built for financial services and other regulated environments.
Most quality work still asks "did the tests pass?" We ask a harder question: "do the tests prove the things the business depends on still work, and can you show that to someone who wasn't in the room?"
That shift, from checking code to producing evidence, is the whole discipline. And it matters more every quarter: AI agents now write a large share of production code, delivery speed has outrun verification, and quality engineering has become the accountability layer that proves software built at machine speed still deserves trust. We set out the full argument in The Certance Standard.
However mature your quality practice is today, the work follows the same discipline. What changes is where we start.
Map. Identify the business journeys that carry the money, the data, and the regulatory exposure, and tier them by what failure actually costs. Quality effort follows risk, not folder structure.
Measure. Read the current state honestly: what the existing tests prove, what they only appear to prove, and where the silent gaps are. This is evidence work, not opinion work.
Prove. Turn coverage into artifacts a third party can inspect: gap reports framed as business risk, coverage mapped to journeys, audit-ready evidence rather than dashboard percentages.
Build. Close the gaps that matter, in priority order: test architecture, coverage of the critical journeys, CI that produces evidence on every run, and AI-assisted generation where it holds up under enterprise conditions.
Sustain. Leave behind a practice, not a dependency: documented standards, a knowledge base your team owns, and quality signals leadership can read without an interpreter.
Behind the method sits a five-level maturity model, from Reactive Testing through Structured QA and Quality Engineering to AI-Native QE and Autonomous Quality Systems. Every engagement starts by locating you honestly on that ladder, and every recommendation is sized to the next level, not to a fantasy end state.
Certance is founded and run by Ivan Stepantsov, a quality engineering leader with more than ten years improving software quality across investment banking, life sciences, and defence systems.
His day-to-day work is quality leadership inside a global investment bank, where as a Chapter Lead and engineer he leads a team of quality engineers, owns the craft standard for the discipline, and assesses engineering quality across delivery streams. That is the environment Certance's method comes from: one where a missed test is a business and regulatory risk, not a bug, and where "trust me" has never been acceptable evidence.
Certance brings that standard to teams that need it, in fixed scope: the same rigour, the same evidence discipline, sized for a three-day audit instead of a headcount line. More about Ivan and Certance
Building quality engineering from scratch. For teams with little or no structured quality practice: scale-ups hitting enterprise or regulatory expectations for the first time, or new products in regulated domains. We start at Map, define the quality policy and evidence model before any tooling, and stand up the practice in risk order, so the first tests written are the ones protecting the journeys that could hurt you.
Enhancing the quality setup you already have. For teams with an established suite and an uneasy feeling about it. We start at Measure: an independent read of what your current coverage actually proves, delivered as a gap report your leadership can act on. Most engagements start here, because most teams don't need more tests, they need to know which of their tests matter.
Not sure which applies? A scoping call settles it in 30 minutes.
Fixed-scope engagements, so you know the cost and the deliverable before you start.
Coverage Audit. A three-day, independent read that maps your test suite to the business journeys that carry the risk, and tells you where your coverage evidence would hold up in front of a regulator. Artifacts, not access: it runs on what you export, not on credentials into your systems. See the audit
AI Maturity Assessment. A structured assessment of how your team's quality practice is holding up as AI enters the delivery pipeline, with a regulatory overlay for DORA and FCA-regulated environments. See the assessment
Coverage Implementation. The follow-on when the audit finds gaps worth closing: we build the missing coverage with your team, in risk order, leaving standards and documentation your engineers own from day one.
Advisory Retainer. Ongoing quality assurance for leadership: a quarterly independent audit plus a monthly check-in, so release risk and audit evidence stay visible as your systems and your AI adoption change. For teams that want the discipline without hiring for it.
This is not a general QA practice with a compliance page. Regulated delivery is the design constraint we start from.
2026 is DORA's first real supervisory year. Financial entities are being asked to evidence operational resilience, and "our pipeline is green" is not an answer a supervisor accepts. We frame coverage as evidence from the start, so the artifacts exist before anyone asks. We advise on the engineering evidence; your compliance function owns the regulatory interpretation, and we'll say so every time it matters.
Data minimisation by default. Engagements run on exported artifacts: test code, reports, pipeline output. No production access, no client PII, synthetic data only. That's not a limitation; it's what makes an independent read possible inside your third-party risk appetite.
Evidence a third party can inspect. Every deliverable is written to be shown onward: to an auditor, a supervisor, a board. If a claim can't be traced to an artifact, it doesn't go in the report.
AI now writes a large share of production code. The teams in trouble are not the ones using AI; they're the ones whose verification hasn't kept up with their generation. Certance runs an AI-native practice with the discipline regulated environments demand.
AI under governance, not on autopilot. We use an agent pipeline in which AI plans, generates, and heals tests, and every output passes a review gate before it ships. The same standard we hold clients to, we hold ourselves to: AI output is a draft until verified.
A written standard, not a slogan. Certance maintains a versioned engineering standard for AI-assisted delivery: hard merge gates covering provenance, test integrity, behavioral evidence, contract checks, and blast radius, plus a barrier stack that assumes every gate before it can leak. Its first principle: nothing merges on trust, only on behavioral evidence. A green pipeline is a claim, not a fact. Clients adopting it get the standard itself, unbranded, with a phased adoption plan their team runs without us.
A knowledge base, not tribal knowledge. Our framework decisions, patterns, and per-client judgment live in a versioned, documented knowledge architecture. It's why the practice survives team turnover, ours and yours, and why every engagement makes the next one sharper.
Tooling chosen for evidence, not fashion. Modern stack, web-first assertions, coverage mapped to journeys and reported with a taxonomy leadership can read. We're happy to go as deep on the engineering as your team wants; we just never open there, because the conversation that matters is about risk.
CTOs and Heads of Engineering get release risk in business language: which journeys are protected, which are exposed, and what that exposure costs.
Heads of Risk and compliance-adjacent leaders get testing evidence they can put in front of a regulator, mapped to DORA and operational-resilience expectations.
QA leads and engineering managers get an independent read that strengthens their case for investment, and a framework their team owns rather than rents. An audit is evidence for your roadmap, not an audit of you.
Here is what we can show you today: a sample gap report, anonymised, so you see the exact artifact you'd receive; the Certance engineering standard for AI-assisted delivery, written, versioned, and reviewed, so you can judge the thinking before you buy the engagement; the Certance Lens framework, open source on GitHub, so you can read the test architecture we bring before anyone signs anything; and the founder's record above.
What we will never show you: logos we haven't earned or metrics we can't trace. That's the standard we audit against; it would be strange not to hold it ourselves.
QA asks whether the software passed its tests. Quality engineering asks whether the tests prove what the business needs proven, and builds the systems that keep that true as the software changes. One is a phase; the other is an engineering discipline.
No. Engagements run on exported artifacts: test code, coverage reports, CI output. Data minimisation is the default, which also keeps the engagement inside most third-party risk appetites without a heavy onboarding process.
Suite size tells you nothing about protection. Most suites are dense where the code is easy and thin where the business risk is. An independent read tells you which of your tests matter, and which journeys are silently unprotected.
A 30-minute scoping call: we identify your critical journeys and agree a fixed scope and fee before you commit to anything.
A 30-minute scoping call: we identify your critical journeys and agree a fixed scope and fee before you commit to anything. Or start with the flagship engagement, the three-day Coverage Audit.
Book a scoping callSee the Coverage Audit