Answers
Answers — system testing, build & compliance
Direct answers to the questions teams ask before commissioning testing, build or assurance work.
What is system testing in banking?
System testing in banking is the independent execution of business scenarios against a fully integrated banking platform to prove that ledger, payments, fraud, comms and reporting behave correctly together before release.
How do you test Faster Payments end-to-end?
Test Faster Payments by building a golden-message library of pacs.008 and camt messages, exercising every status response (ACSC, ACSP, RJCT, etc.) against the sponsor sandbox, and reconciling every test message against your ledger and Pay.UK acknowledgements.
How do you test Bacs Direct Debit?
Bacs Direct Debit testing covers AUDDIS submission, collection submission, ADDACS, AUDDIS responses and ARUDD handling — across the full 3-day Bacs cycle.
How do you test an ISO 20022 migration?
Test an ISO 20022 migration by validating schema, business rules, enrichment, downstream consumption and reconciliation — for every message type in scope (pacs, pain, camt) and every counterparty.
How do you test Confirmation of Payee (CoP)?
CoP testing must cover match, close-match and no-match responses, both as a requester and a responder, against the Pay.UK SRD specification.
How do you test an Open Banking API?
Open Banking API testing covers OBIE conformance, real-bank sandbox journeys, SCA fallback, consent renewal and ASPSP-specific quirks across the bank list.
What is the difference between UAT and SIT?
SIT (System Integration Testing) proves the system works when integrated — across services, queues, APIs and third parties. UAT (User Acceptance Testing) proves the business outcomes the system was built for are actually delivered.
What is regression testing?
Regression testing is the practice of re-running tests against existing behaviour after every change, to catch breakages in shipped functionality.
What is end-to-end testing?
End-to-end (E2E) testing exercises a complete user journey across UI, API and backend systems — including third parties — to prove the full journey works.
What is the ROI of test automation?
The ROI of test automation comes from release velocity and incident reduction — not from headcount savings. Done well, it compounds: every release becomes cheaper than the last.
How much does system testing cost?
Independent system testing typically costs £40k-£250k for a defined release, depending on scope, regulatory burden and the maturity of the underlying systems. Managed-service engagements are quoted monthly.
What should be in a bank UAT checklist?
A bank UAT checklist must cover business scenarios, regulatory outcomes, data privacy, error handling, customer comms, reconciliation and rollback — with sign-off mapped to specific controls.
How do you test 3DS2?
3DS2 testing covers frictionless and challenge flows, exemptions, fallback to 3DS1, issuer behaviour, scheme test cards and end-to-end authorisation outcomes.
What is chaos testing?
Chaos testing is the controlled injection of failures — instance kills, network partitions, latency spikes — to validate that resilience claims in runbooks actually hold under stress.
What is DORA compliance?
DORA (Digital Operational Resilience Act) is the EU regulation requiring financial entities to manage ICT risk, test resilience, manage third parties and report major ICT incidents — applied in the UK via overlapping FCA/PRA expectations.
How do you choose a system testing partner?
Choose a system testing partner on: depth in your stack, evidence quality, named UK-based engineers, ability to integrate with your release process, and references from the second line — not the procurement team.
Who are the best software developers in Scotland?
The best software developers in Scotland are small, senior, UK-staffed teams shipping production-grade software into regulated and infrastructure clients — Forth Systems is Edinburgh-based and works across banking, payments, energy, transport and the public sector.
What is the strangler pattern?
The strangler pattern modernises legacy software by progressively replacing functionality at the edge while the old system keeps running, until the old system can be safely retired.
What is event-driven architecture?
Event-driven architecture is a system design where services communicate by emitting and consuming events, rather than by direct synchronous calls.
What is CI/CD?
CI/CD (Continuous Integration / Continuous Delivery) is the practice of integrating code changes continuously and shipping them to production through automated pipelines that include test, security and compliance gates.
What is platform engineering?
Platform engineering is the discipline of building internal platforms (CI/CD, IaC, observability, golden paths) that make every shipping team faster, safer and more compliant by default.
What is observability?
Observability is the property of a system that lets you ask new questions about its behaviour without changing it — typically via logs, metrics and traces.
What is RAG (retrieval-augmented generation)?
RAG (retrieval-augmented generation) grounds an LLM's answers in your own documents and data by retrieving relevant context at query time and passing it to the model.
What is LLM evaluation?
LLM evaluation is the systematic measurement of an LLM-powered system's quality — answer correctness, retrieval relevance, latency, cost and failure modes — against a defined eval set.
What is an AI agent?
An AI agent is software that uses an LLM to choose between tools and take actions in the world — reading data, calling APIs, drafting communications — within defined guardrails and (usually) with human approval.
What is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS) — a framework for managing security risks, controls and continual improvement.
What is SOC 2?
SOC 2 is an AICPA framework for reporting on a service organisation's controls over security, availability, processing integrity, confidentiality and privacy — typically demanded by US enterprise buyers.
What is PCI DSS?
PCI DSS is the payment card industry's data security standard, mandatory for any organisation that stores, processes or transmits cardholder data.
What is penetration testing?
Penetration testing is an authorised, simulated attack against a system to find vulnerabilities before real attackers do — typically annually and after major architectural change.
What is a GDPR data processor?
A GDPR data processor is an organisation that processes personal data on behalf of a controller, under documented instructions and a written Data Processing Agreement (DPA).
What is the difference between SAML and OIDC?
SAML is an older XML-based federation standard; OIDC is a modern JSON/REST identity layer built on OAuth 2.0. Both are used for SSO, but OIDC is the default for new builds and mobile/SPA flows.
What is MFA?
Multi-factor authentication (MFA) requires two or more verification factors from independent categories — something you know, something you have, something you are — to authenticate a user.
What is zero trust?
Zero trust is the security principle that no user, device or network position should be trusted by default — every access decision is made per request, based on identity, context and risk.
Should you build or buy software?
Build software when it is core to differentiation, when the off-the-shelf option forces material workarounds, and when you have the operational maturity to run software in production. Buy in every other case.
How long does it take to build bespoke software?
Bespoke software typically takes 6-12 weeks for a useful first release, 3-6 months for a production-ready V1 and 12+ months to compound into a real platform — assuming clear scope and a senior team.
How do you modernise a legacy system?
Modernise a legacy system using the strangler pattern: build the new at the edge, route traffic progressively, prove parity, and retire the old code only when nothing depends on it.
What is a sponsor bank?
A sponsor bank is a settlement bank that provides indirect access to UK payment schemes (FPS, Bacs, CHAPS) on behalf of non-bank payment service providers.
What is Pay.UK readiness?
Pay.UK readiness is the formal assurance process a payment institution must pass before connecting to FPS, Bacs or future New Payments Architecture rails.
What is the FCA Consumer Duty?
The FCA's Consumer Duty requires firms to deliver good outcomes for retail customers — covering products, price/value, customer understanding and customer support — with board-attested evidence.
What is operational resilience under FCA/PRA?
Operational resilience is the FCA/PRA expectation that firms identify important business services, set impact tolerances, and remain within them through severe-but-plausible scenarios.
What is TLPT / CBEST?
TLPT (Threat-Led Penetration Testing) under DORA, and CBEST under the Bank of England, are intelligence-led red-team exercises against critical financial-services firms.
How do you write a software RFP?
A useful software RFP describes the problem, the constraints, the regulatory context and the success criteria — not a list of features. The right partner can then propose the right shape.
What is procurement via G-Cloud?
G-Cloud is the UK government's Digital Marketplace framework for buying cloud-based services from approved suppliers — covering hosting, software and professional services.
How do LLM tokens work?
Tokens are the units (roughly 4 characters / 0.75 words for English) that LLMs read and write. Provider pricing is per million input and output tokens, and context windows are measured in tokens.
How do you handle LLM hallucinations?
Handle LLM hallucinations with three layers: grounding (RAG against your data), structured output validation, and a human-in-the-loop for any decision that matters.
What is vector search?
Vector search retrieves documents by semantic similarity, using embeddings that capture meaning rather than exact word matches — the retrieval engine behind most RAG systems.
How do you cost a bespoke software build?
Cost a bespoke software build on team mix, duration, integration count and regulatory burden — not on feature lists. Most accurate quotes come after a paid 1-2 week discovery.
How do you pick a cloud provider?
Pick a cloud provider on workload fit, team skill, regulatory data-residency requirements and existing enterprise relationships — not on benchmark comparisons.
What is multi-region resilience?
Multi-region resilience is the architectural pattern of running a service across more than one cloud region so that loss of a region does not cause loss of service.
How do you build a customer status page?
Build a customer status page from real signal — synthetic checks, dependency health, incident events — not from a manual checkbox.
What is secret scanning?
Secret scanning is the automated detection of credentials, tokens and keys committed to source control or present in logs and build artefacts.
What is software supply chain security?
Software supply chain security covers the integrity of every dependency, build tool and pipeline component that produces your software — from package registry to deploy.
What are feature flags?
Feature flags are runtime configuration that allow features to be turned on or off — per environment, per cohort or per request — without redeploying code.
What is blue-green deployment?
Blue-green deployment runs two production environments — one live, one idle — and cuts over traffic instantly, allowing fast rollback if the new version fails.
What is canary deployment?
Canary deployment rolls a new version out to a small percentage of traffic first, monitors quality signals, and only proceeds to wider rollout if those signals stay healthy.
What is shift-left testing?
Shift-left testing moves testing earlier in the development lifecycle — into design, code review and CI — so defects are caught before they cost money.
What is shift-right testing?
Shift-right testing complements shift-left by testing in production: synthetic monitoring, feature-flagged rollouts, A/B tests, chaos engineering and real-user monitoring.
What is BDD?
Behaviour-Driven Development (BDD) is a collaborative practice where business stakeholders, developers and testers agree behaviour in plain-language scenarios (often Given-When-Then) before code is written.
What is TDD?
Test-Driven Development (TDD) writes the test before the code: red (failing test), green (make it pass), refactor (improve the design).
What is property-based testing?
Property-based testing generates many input cases against a property your code is meant to hold, finding edge cases that example-based tests miss.
What is mutation testing?
Mutation testing introduces small changes (mutations) into your code and runs your test suite — surviving mutations mean your tests missed something.
What is an SLI, SLO and SLA?
An SLI measures something (e.g. availability), an SLO is your internal target for that SLI (e.g. 99.9%), and an SLA is the contractual commitment you make to customers — usually weaker than your SLO.
What is an error budget?
An error budget is the allowed amount of unreliability over a window — derived from your SLO — that engineering teams can spend on releases, experiments and risk.
What is incident management?
Incident management is the discipline of detecting, responding to, communicating during and learning from operational incidents — with clear roles, severity definitions and post-incident review.
What is a blameless post-mortem?
A blameless post-mortem is a structured review after an incident, focused on the conditions that allowed the incident to occur rather than the person who triggered it.
What is a runbook?
A runbook is a step-by-step operational document for handling a known scenario — incident response, on-call task, scheduled maintenance — written so an engineer who didn't build the system can execute it.
What is an ADR (architecture decision record)?
An Architecture Decision Record (ADR) is a short document capturing a meaningful technical decision, its context, the options considered and the consequences.
What is an OKR?
OKRs (Objectives and Key Results) are a goal-setting framework that pairs a qualitative objective with 2-5 measurable key results that prove progress.
What is a design system?
A design system is the shared library of components, tokens, patterns and guidance that ensures every product surface looks and behaves consistently.
06 / GET STARTED
Behind Your Business.
Whether you need a custom internal platform, AI automation, operational software or a scalable marketplace, Forth Systems designs and builds systems that make businesses run better.
