Research · Financial Press

Back to sweep

Research sweep · deep · 2022 – 2026

Engineering Maturity Models for Regulated Financial Services

Which engineering maturity models and capability frameworks large financial services technology organisations use to drive an engineering hygiene uplift (automated releases, regression test automation, CI/CD, observability) and how they roll out, monitor and govern the programme at scale, September 2022 to September 2026: DORA capabilities and metrics, CMMI and TMMi, ITIL 4 change enablement, SAFe and Team Topologies, the CNCF Platform Engineering Maturity Model, engineering scorecards (Backstage, Cortex, OpsLevel), and regulator expectations from the EU Digital Operational Resilience Act, PRA SS1/21 and the FCA operational resilience regime

  • Claude Fable 5
  • tech
  • financial
  • academic
  • blogs
  • vc
  • frontier

Synthesised 2026-09-21

Narrative

Financial press coverage of engineering hygiene uplift in banking clusters around three threads: regulatory deadlines, the cost of not being resilient, and AI-driven productivity claims that are reshaping the underlying economics of the engineering workforce that any maturity programme has to work with.

On regulation, the EU's Digital Operational Resilience Act moved from adoption by the Council in November 2022 to full application on 17 January 2025, and now applies to more than 22,000 EU financial entities and their ICT providers, with five pillars covering ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. In the UK, the equivalent pressure comes from the PRA and FCA's operational resilience regime under SS1/21 and PS21/3, which reached its transitional deadline on 31 March 2025, and from a fresh wave of 2026 policy statements (PS7/26, PS26/2, new SS1/26) creating a single UK incident and third-party reporting framework. None of this directly mandates DevOps practices, but it forces firms to produce evidence of resilience testing and incident recovery capability that DORA-metric-style telemetry is increasingly used to satisfy.

The evidentiary case for why this matters is concrete and largely came through Reuters, Bloomberg and UK parliamentary reporting rather than vendor material. The House of Commons Treasury Committee found that nine of the UK's largest banks and building societies accumulated at least 803 hours, or more than 33 days, of unplanned IT outages between January 2023 and February 2025, across at least 158 incidents, with Barclays alone expecting to pay between £5 million and £7.5 million in customer compensation for a single January 2025 mainframe-degradation outage. The July 2024 CrowdStrike incident, though not a banking-specific event, gave regulators and insurers a live case study: analytics firm Parametrix estimated banking sector direct losses at roughly $1.15 billion to $1.4 billion out of a $5.4 billion Fortune 500 total, with cyber insurance covering only 10 to 20 percent of losses, a data point since cited repeatedly in FCA and industry commentary on third-party concentration risk.

On the delivery side, Reuters and Bloomberg reporting through 2025 and 2026 documents banks treating AI coding tools as the primary lever for engineering productivity rather than classical DevOps maturity programmes per se. Reuters reported that tens of thousands of JPMorgan software engineers increased productivity 10 to 20 percent using an internally built coding assistant, against a $17 billion 2024 technology budget and 63,000-strong tech workforce, a figure that later reporting put at roughly $19.8 billion with over 40,000 engineers using AI coding assistants. Goldman Sachs CEO David Solomon told Bloomberg's Odd Lots podcast that AI could halt the decade-long rise in banks' engineer headcounts, and an internal "OneGS 3.0" memo seen by Reuters in October 2025 tied AI-driven efficiency directly to headcount constraints and limited role reductions. Citigroup's CFO cited a 9 percent productivity improvement in software development and about 100,000 developer hours saved weekly through automated code review. This is a live tension for any central standards capability: AI adoption is being reported as a headcount and efficiency story by banks' own executives to investors, which is a different frame from the reliability and change-failure-rate frame that operational resilience regulation demands, and financial press coverage has not yet reconciled the two.


Sources

ID Title Outlet Date Significance
f1 JPMorgan engineers' efficiency jumps as much as 20% from using coding assistant Reuters (via Investing.com) 2025-03 Reuters reporting on measured productivity gains from an internally built AI coding tool at JPMorgan, with technology budget and workforce figures, illustrating how banks now frame engineering productivity primarily through AI rather than classical DevOps maturity metrics.
f2 Goldman Sachs eyes layoffs and hiring slowdown amid AI push, memo shows Reuters 2025-10 Reuters obtained an internal Goldman Sachs memo tying its OneGS 3.0 AI initiative directly to headcount constraints and limited job cuts, evidence of AI-productivity framing colliding with engineering workforce planning.
f3 Billions in Damages From CrowdStrike Outage to Go Uninsured Bloomberg 2024-08 Bloomberg's coverage of independent insurance-analytics estimates of the CrowdStrike outage's sector-by-sector cost, including banking's roughly $1.15 billion exposure, used across regulatory and industry discussion of operational resilience.
f4 Britain's top banks clocked up 33 days' worth of IT glitches in two years Reuters (via Cyprus Mail) 2025-03 Reuters wire report on the UK Treasury Committee's findings of 803 hours and 158 incidents of unplanned bank IT downtime between January 2023 and February 2025, the key independent evidence base for UK banking operational resilience failures.
f5 More than one month's worth of IT failures at major banks and building societies in the last two years UK Parliament, Treasury Committee 2025-03 Primary parliamentary source for the Treasury Committee's outage data (803 hours, 158 incidents), including bank-by-bank breakdowns, that underpins nearly all subsequent financial press coverage of UK bank resilience.
f6 CrowdStrike disruption direct losses to reach $5.4B for Fortune 500, study finds Cybersecurity Dive 2024-07 Independent Parametrix analysis breaking out banking-sector losses (~$1.15bn) from the CrowdStrike incident, widely cited by insurers, regulators and press as quantifying third-party concentration risk in operational resilience.
f7 Financial institutions told to get their house in order before the next CrowdStrike strikes The Register 2024-11 Reports the FCA's direct warning to UK financial institutions after CrowdStrike, naming operational disruption from unregulated third parties as the leading cause of incidents in 2022-2023 and linking this to incoming critical-third-party rules.
f8 US banks report productivity surge as AI reshapes operations CeFPro 2025-12 Summarises earnings-call statements from JPMorgan, Wells Fargo, Citigroup, Goldman Sachs and Bank of America executives on measured AI productivity gains in coding and operations, showing how banks report engineering efficiency to investors.
f9 How AI Is Impacting Productivity at JPM, BAC, C & Others Yahoo Finance (bank earnings call reporting) 2025-12 Reports specific bank-disclosed productivity figures (JPMorgan's productivity doubling from 3% to 6%, Citigroup's 100,000 developer hours saved weekly) drawn from Q4 2025 earnings calls, key quantitative data points for AI's role in engineering throughput.
f10 US bank executives say AI will boost productivity, cut jobs Reuters 2025-12 Reuters coverage of JPMorgan's Marianne Lake stating productivity doubled from 3% to 6% with AI and Goldman Sachs' OneGS 3.0 memo linking AI to job cuts, direct evidence of how banks are recalibrating engineering headcount around AI tooling.
f11 Banks report operational changes driven by AI adoption CIO Dive 2026-07 Reports Bank of America, Wells Fargo and Citigroup Q2 2026 earnings-call disclosures on AI coding and productivity tool adoption at scale (200,000+ BofA employees, 400,000 daily prompts), evidence of enterprise-scale AI rollout inside regulated banks.
f12 Banks fire up coding assistants as AI costs plummet CIO Dive 2025-01 Reports Citigroup arming 30,000 developers with generative AI coding tools and Goldman Sachs' companywide AI assistant rollout, alongside claimed accuracy improvements in legacy COBOL code migration relevant to regression and modernization sequencing.
f13 Digital finance: Council adopts Digital Operational Resilience Act Council of the European Union 2022-11 Official EU Council press release marking DORA's formal adoption in November 2022, the primary regulatory dating source for the EU operational resilience regime referenced throughout the lane.
f14 FCA, PRA and BoE issue Policy Statements on operational resilience Global Regulation Tomorrow (Norton Rose Fulbright) 2026-03 Details the 2026 UK regulatory overhaul (PS7/26, PS26/2, new SS1/26) consolidating incident and third-party reporting across FCA, PRA and Bank of England, showing operational resilience regulation is still actively evolving, not settled by the 2025 deadline.
f15 UK Operational Resilience Rules: Are You Ready for 31 March 2025? Sidley Austin (legal insight) 2025-01 Confirms the 31 March 2025 transitional deadline for PRA SS1/21 and FCA PS21/3 compliance, the binding UK date equivalent to DORA's January 2025 application date.
f16 Operational resilience of the financial sector Bank of England 2026-07 Bank of England's own description of its operational resilience programme including STAR-FS threat-led penetration testing, the regulator's primary framework for assessing firm resilience distinct from engineering maturity models.
f17 Operational resilience | FCA Financial Conduct Authority 2017 FCA's own regulatory page describing its operational resilience regime and critical third-party oversight, a primary source for what UK regulation actually requires of software delivery and testing.
f18 JFrog helps financial industry meet DORA software regulations jfrog.com May 4, 2026 Retrieved by this lane's web search.
f19 Digital Operations Resilience Act (DORA) hyperproof.io January 26, 2026 Retrieved by this lane's web search.
f20 DORA Squared? The Banking Formula for Resilience and Speed | Abstracta abstracta.us 3 weeks ago Retrieved by this lane's web search.
f21 DORA: Operational Resilience in Financial Services rbinternational.com September 18, 2025 Retrieved by this lane's web search.
f22 What Is the Digital Operational Resilience Act (DORA)? | IBM ibm.com December 17, 2024 Retrieved by this lane's web search.
f23 The Ultimate Guide to DORA Compliance for the Financial Sector | Fortra fortra.com Retrieved by this lane's web search.
f24 DevOps in Banking: Compliance, Security & Faster Releases | Purrweb purrweb.com July 27, 2026 Retrieved by this lane's web search.
f25 Transforming Banking with DevOps – DevOps Online devopsonline.co.uk Retrieved by this lane's web search.

We use analytics cookies to understand site usage and improve the service. We do not use marketing cookies.