Skip to the main content.

2 min read

No more audit risk: How a reinsurer has made its test management audit-proof

Sector

Insurance / Reinsurance

Background

A leading international reinsurer operates a central Insurance Analytics Platform that consolidates data-driven use cases across multiple organisational units. As part of the regulated IT landscape, the platform is subject to the requirements of the German Insurance Supervision Act (VAG) and BaFin’s Supervisory Requirements for IT in Insurance Undertakings (VAIT).

Challenge

Although testing activities were already in place, they lacked a cross-unit, standardised approach. The different interpretations of testing among the various teams, combined with the stringent regulatory requirements regarding traceability and documentation, necessitated a fundamental restructuring.

Services provided

Our experts were responsible for developing, documenting and implementing a comprehensive, VAIT-compliant testing strategy in Microsoft Azure DevOps. This involved designing test cases, coaching the teams, and coordinating test execution and reporting throughout the project.

Benefit

A consistent and sustainable foundation for test management. The reinsurer can now face audits and BaFin reviews with confidence, thanks to a fully documented and auditable test strategy that does not cause any operational disruption. This strategy has been integrated into agile delivery processes and is consistently adopted by all participating teams.

shutterstock_2235038519_edited

 

When a platform supports the core analytical processes of an international reinsurer, software testing is much more than just a formality. It is both a regulatory obligation and an operational necessity. BaFin’s VAIT sets out clear requirements regarding traceability, documentation and the integration of quality assurance into IT operations. The objective was therefore to develop a comprehensive, auditable testing strategy for the insurance analytics platform and integrate it into the agile development organisation.

 

Heterogeneous knowledge and a lack of a common framework

The teams involved each brought their own experiences and ideas about good software testing to the project. While this knowledge is valuable, without a common framework, inconsistencies can arise in processes, coverage and communication.

The first step was therefore to consolidate this dispersed knowledge through structured coordination, conceptual workshops and close collaboration with stakeholders from multiple departments. This resulted in a comprehensive testing strategy that clearly defines the phases of testing, responsibilities and processes throughout the entire development process. It meets both regulatory requirements and agile working practices.

Rather than being stored as a document on a drive, the strategy was implemented in Microsoft Azure DevOps (Azure Test Plans) as a dynamic test management system.

 

From Strategy to Practice

A test strategy only realises its value when it is applied by the teams. This is why coaching was a central component of the project, as it empowered the reinsurer’s teams to develop test cases independently and cover new requirements themselves.

Meanwhile, manual and automated test cases were established across all relevant testing phases, including component, integration, system and regression testing. Test execution was coordinated via sprints and the results were systematically documented in Azure DevOps. Additionally, a structured defect management system and automated reporting for the team and management were implemented.

This provides transparency regarding the test status at all levels, from developer to governance function.

 

Audit-ready from the first sprint onwards

The central outcome of this project is more organisational than technical in nature. Each team member brings their own experiences, best practices and fresh perspectives developed over the years. This is precisely why it is worthwhile to exchange ideas in a structured manner. The goal is not to talk differences away, but to create a stable, common foundation from diversity.

A framework for structured exchange, established as early as the first sprint, makes all the difference.

  • Without such a framework, gaps arise in areas such as the process, coverage and traceability with regard to oversight and governance.

  • Where such a framework exists, individual knowledge can be put to effective use.

This is particularly true in a regulated environment, where structured dialogue is not a soft measure. It forms the basis for any test strategy that not only stands up on paper, but also in an audit.


 

Are you working in the regulated insurance sector and in need of a test management system that can withstand an audit?

Let’s talk. We look forward to discussing this with you.

Case Studies
Software testing in the aviation industry: Insights

Software testing in the aviation industry: Insights

Effective software testing in the aviation industry Innovation and technology are essential in the aviation industry to improve passenger comfort...

Mehr lesen
Optimization of the testing process in the aviation industry

Optimization of the testing process in the aviation industry

Optimizing the testing process in the aviation industry: An end-to-end testing strategy for complex systems

Mehr lesen
Ensuring Seamless Airline Crew Management Transitions with Software Testing

Ensuring Seamless Airline Crew Management Transitions with Software Testing

An airline's crew management system was replaced by a modern, enterprise-capable solution. A project that goes far beyond a standard software project...

Mehr lesen