Defect penalties eliminated within two monthly releases
A state transport department paying around $1 million a year in penalties had every defect tested, fixed and retested, and no longer incurs penalties.
Read more
Audit and compliance assurance for regulated organisations that must prove IT change was tested properly. PinnacleQM reviews testing independently and automates compliance validation with evidence auditors can rely on.
30+years of international
IT experience
Regulators, auditors and boards increasingly ask for proof that changes were tested against requirements and controls. Evidence scattered across spreadsheets, emails and screenshots is slow to assemble and easy to challenge. Late evidence also slows audits.
PinnacleQM provides independent reviews of test processes and evidence, and uses Authorise to automate compliance validation against a guidebook of requirements, capturing consistent evidence for every run. Evidence is organised and ready when auditors ask.
Good compliance evidence is a by-product of good testing. We design processes and automation that produce audit-ready evidence as work happens, not afterwards.
Automated compliance validation with video proof.
An objective assessment of whether testing met its obligations, free from delivery pressure. Findings are reported plainly with recommended actions.
Requirements, risks, tests, results and decisions linked end to end for auditors. Nothing needs to be reconstructed from memory.
Authorise runs compliance checks from a guidebook, so validation is consistent and repeatable. Every run records what was checked and the result.
Automation replaces much of the manual collection of screenshots and sign-off records. Teams spend their time on testing, not paperwork.
Methods align with ISO/IEC/IEEE 29119 and ISO 9001, 27001 and 27701 practices. This gives auditors a recognised frame of reference.
Evidence is organised and retrievable, so audit requests are answered in hours, not weeks. Leaders spend less time chasing evidence across teams.
Independent review and automation that together give auditors, regulators and boards confidence.
We independently review test strategy, coverage, execution and evidence for a project or release, and report whether testing met its obligations and where gaps remain. Recommendations are prioritised so the most serious gaps are closed first.
We design traceability from requirements and risks through tests, results, defects and release decisions, maintained as work progresses, so evidence is complete, retrievable for auditors and gaps are visible early.
Authorise validates processes against a compliance guidebook, either built with you or taken from an existing one, and records video evidence for each check. Each check produces evidence that auditors can review directly.
We automate validation of user access rights and key controls after changes, confirming roles and permissions still match policy, flagging exceptions before release and retaining the results as audit evidence.
We assess vendors' quality and compliance evidence against contract obligations, set the evidence standard each supplier must meet, and raise gaps before deliverables are accepted, so accountability stays clear throughout.
We review how personal data is handled in test environments and recommend obfuscation, access and retention controls aligned with privacy obligations. Controls are documented so they can be evidenced during audits.
We start with your regulatory and contractual obligations, then design processes and automation that produce audit-ready evidence continuously, rather than scrambling to assemble it later.
Identify regulatory, contractual and policy obligations that testing must evidence. We confirm which of them apply to each system.
Assess current evidence, traceability and controls against those obligations. Gaps are ranked by exposure.
Set evidence standards, traceability and a compliance guidebook for automation. Everyone knows what good evidence looks like.
Configure Authorise and QMFactory to validate and record evidence as work happens. Evidence is captured without extra manual effort.
Run periodic independent reviews and report compliance status to leadership. Findings drive continuous improvement.
A state transport department paying around $1 million a year in penalties had every defect tested, fixed and retested, and no longer incurs penalties.
Read more
HealthTest obfuscated production records, created full test condition variations and tested more than 5 million transactions per day, without exposing any patient information along the way.
Read more
A state health integration re-platforming was delivered by 7 testers in 12 months against competitor estimates of 40 to 46 testers over 36 months.
Read more
7 min read
What independence adds to testing on multi-vendor programmes, what it does not, and the signs a programme needs it.
7 min read
The evidence, residual risks and conditions a credible go-live recommendation must include for decision-makers to rely on it.
7 min read
How to give teams realistic test data while meeting privacy obligations, including obfuscation, synthetic data and residency.
Tell us about the obligations your IT change must meet and how evidence is gathered today. We will show how independent review and automation can make compliance routine.
Mention the regulations, standards or audits that apply to you.