Enhancing Quality With an IV&V Code Review

Case Study

Enhancing Quality for a Publicly Traded Regional Bank
with an Independent Verification
and Validation (IV&V) Code Review
by i3solutions

Software code review for quality assurance and error detection.

The client is a publicly traded regional bank, a full-service, community-oriented institution offering commercial and business banking, personal banking, and wealth management. A third-party vendor was building the bank’s Paying Agency Application, and the bank engaged i3solutions to perform an independent verification and validation (IV&V) code review of that custom application. Working in an independent analysis and assessment role rather than a development one, i3solutions confirmed the bank’s objectives, milestones, and success criteria, reviewed the code for areas needing optimization, security enhancements, and potential vulnerabilities, and validated the application’s functionality, performance, and security with automated testing tools and manual testing procedures. i3solutions brought more than 25 years of development and testing experience to the work. Objectivity, quality, and adherence to standards are paramount in the financial industry, and the review gave the bank an independent check that a vendor-built banking application was being built to the bank’s own requirements, with risks identified and mitigated and quality and compliance confirmed by a party outside the vendor relationship.

The Customer

And Their Challenge

The client is a publicly traded regional bank, a full-service, community-oriented institution that offers commercial and business banking, personal banking, and wealth management. They are committed to helping their customers grow their personal wealth and finance, real estate investments, equipment, and businesses. Using the latest technology, they provide innovative banking products and superior customer service designed with their customers in mind.

The bank was having a Paying Agency Application developed by a third-party vendor and required an independent verification and validation (IV&V) code review to ensure their objectives were being met. They needed an objective firm like i3solutions to identify and mitigate any risks, ensure quality and compliance and validate that the application was being built based on the bank‘s requirements.

The Solution

Independent Verification and Validation (IV&V) Code Review

i3solutions was engaged to provide an IV&V consultation and code review for the bank’s Paying Agency Application. The team at i3solutions devised a structured approach to address their challenges:

IV&V code review process for quality assurance and software improvement.

Assessment
and Planning

i3solutions initiated the project by conducting a thorough assessment of the bank’s specific requirements. We worked closely with them to confirm objectives, milestones, and success criteria.

Professional IV&V code review for quality assurance in software development.

Code
Review

The i3solutions team utilized state-of-the-art tools and methodologies to perform a comprehensive code review. We identified areas for optimization, security enhancements, and potential vulnerabilities, ensuring the application was robust and reliable.

IV&V Code Review for Quality Assurance in Software Development.

Quality
Assurance

i3solutions implemented a rigorous quality assurance process, conducting thorough testing to validate the application’s functionality, performance, and security. Automated testing tools and manual testing procedures were employed to ensure the highest level of quality.

This crucial process added an independent layer of validation and verification to the application’s development. It helped ensure quality, compliance, risk mitigation, and the successful achievement of the project’s objectives. This was particularly valuable to the bank because objectivity, quality, and adherence to standards are paramount in the financial industry.

 

Software code review on laptop screen for quality assurance and software testing.

Technologies

Used in the Solution

i3solutions relied on over 25 years of development and
testing experience to execute the project effectively:

Professional IV&V code review for quality assurance and software improvement.

The i3solutions team performed a comprehensive code review to identify vulnerabilities and make suggestions on where improvement was needed.

Testing frameworks used in IV&V code review processes for quality assurance.

Testing frameworks were used to systematically evaluate the application’s functionality, performance, and security.

Measurable Benefits
and Business Impact

i3solutions' IV&V code review services played a pivotal role in ensuring the successful development of the bank's Paying Agency Application. Our commitment to quality, security, and efficiency had a measurable and positive impact on the application's development process:

Business analyst reviewing data charts and reports for strategic analysis.

Enhanced Application Quality

The comprehensive code review and quality assurance measures implemented by i3solutions resulted in enhanced application quality, reducing the risk of errors, crashes, and security breaches.

Business team collaborating with digital CRM integration tools.

Heightened
Security

Vulnerabilities and security issues identified during the code review were promptly addressed, significantly reducing the risk of data breaches or unauthorized access.

Data analytics and fusion tools for strategic awareness and analysis.

Improved Customer Satisfaction

The quality of the Paying Agency Application translated to higher customer satisfaction and confidence in the bank’s services.

Modern office environment with integrated Office 365 tools for efficient workflow.

Increased Cost
Savings

By identifying and addressing potential issues early in the project, i3solutions helped the bank avoid costly post-implementation fixes and security breaches.

Frequently Asked Questions

What is an IV&V code review, and why would a bank need one?

Independent verification and validation adds an independent layer of validation and verification to an application’s development. The bank had a Paying Agency Application being built by a third-party vendor and needed an objective firm to identify and mitigate risks, ensure quality and compliance, and confirm the application was being built based on the bank’s requirements. That mattered because objectivity, quality, and adherence to standards are paramount in the financial industry.

Can i3solutions review an application another vendor is building?

Yes. That is what this engagement was. i3solutions did not build the bank’s Paying Agency Application; a third-party vendor did, and i3solutions was engaged as the independent reviewer. The work started with a thorough assessment of the bank’s specific requirements and a joint agreement on objectives, milestones, and success criteria.

What does the review cover?

Two things. A comprehensive code review identifies areas for optimization, security enhancements, and potential vulnerabilities so the application is robust and reliable. A quality assurance process then validates the application’s functionality, performance, and security through thorough testing, using automated testing tools, manual testing procedures, and testing frameworks that evaluate the application systematically.

What did the bank get from the IV&V review?

Enhanced application quality, with less risk of errors, crashes, and security breaches. Heightened security: vulnerabilities and security issues found during the code review were promptly addressed, reducing the risk of data breaches or unauthorized access. Higher customer satisfaction and confidence in the bank’s services, because the quality of the Paying Agency Application carried through to the people using it. And cost savings, because issues found early avoided costly post-implementation fixes and security breaches.

If a vendor is building an application your institution will run on, someone will eventually ask who checked the work independently, and the answer cannot be the vendor. A first conversation covers what is being built, what your objectives and success criteria actually say, and which parts of the code and test coverage an independent review should look at first. You leave with a written scope you can take to your own risk and audit reviewers: what gets reviewed, what evidence comes back, and what happens to the findings. Start the conversation

An outside vendor building your application is a normal arrangement, and it still leaves you accepting code you have no independent read on. A senior architect can review what is being delivered against what you specified and tell you where the quality and security risk actually sits.