Virtuoso QA

Best viewed on a larger screen

This interactive demo mirrors the full Virtuoso QA desktop interface, so it needs a wider screen to be readable.

Open it on a laptop or desktop for the full walkthrough, or continue here and pinch to zoom.

Virtuoso QA

See how Virtuoso QA works

Walk through a guided demo for a bank: load your Knowledge Base and see how an AI Analyst and an AI Architect turn the EU AI Act, SM&CR accountability rules, and PSD2/SCA requirements into requirements and human-approved test journeys covering digital account opening and an SCA-protected payment.

The AI Autopilot then writes a deterministic Virtuoso NLP test, which runs with self-healing selectors - so every AI outcome is owned by a name, not just delivered.

?
Project dashboard
Overview
Tags
Webhooks
Share
Tickets

Project dashboard

From the project dashboard you can create shiny new goals - a testing scope within a project.

?
Knowledge Base beta
๐Ÿ” Search for a source
Tags
Search tags
File type
Search file types
All (0)
Project (0)
๐Ÿ—‚๏ธ

You have no active sources

The Knowledge Base is a centralised repository of sources that our agents can use to build your requirements from.

?
Knowledge Base beta
๐Ÿ” Search for a source
Tags
Search tags
File type
Search file types
All (8)
Project (8)
SourcesTagsLast change
Account Opening & SCA-Protected Payment BRDNEW
ProjectBRD_Account_Opening_SCA_Payment.docx
008/09/2026, 09:14 PM
EU AI Act - High-Risk AI Systems (Annex III: Credit Decisioning)NEW
ProjectEU-AI-Act-Annex-III-Credit.pdf
008/09/2026, 09:14 PM
SM&CR - Senior Managers & Certification RegimeNEW
ProjectSMCR-Accountability.pdf
008/09/2026, 09:14 PM
PSD2 / Strong Customer Authentication (SCA) RequirementsNEW
ProjectPSD2-SCA-Requirements.pdf
008/09/2026, 09:14 PM
DORA - Digital Operational Resilience ActNEW
ProjectDORA-Operational-Resilience.pdf
008/09/2026, 09:14 PM
UK CRR / PRA Rulebook - Prudential RequirementsNEW
ProjectUK-CRR-PRA-Rulebook.pdf
008/09/2026, 09:14 PM
Basel 3.1 Framework - Capital & Liquidity StandardsNEW
ProjectBasel-3.1-Framework.pdf
008/09/2026, 09:14 PM
FCA Consumer Duty - Client Best Interest Guidance (FG22/5)NEW
ProjectFCA-Consumer-Duty-FG22-5.pdf
008/09/2026, 09:14 PM
?
Requirements
Requirements
Requirement directives
RequirementsRiskCoverage
Account Opening Negative ScenariosHIGH100%
Successful Digital Account OpeningCRITICAL-
Successful SCA-Protected PaymentCRITICAL100%

SM&CR - Accountable AI Outcome

Organization-level directiveChanges apply to every project in the organisation unless overridden at the project level.
Content
Core instruction: apply SM&CR accountability principles, EU AI Act high-risk explainability, DORA operational resilience, PSD2/SCA authentication requirements, and UK CRR / PRA and Basel 3.1 prudential standards when generating test requirements, test conditions, journeys, or test cases for any AI-assisted decision or payment in the account-opening journey - using the uploaded regulatory documentation as a primary reference. For every requirement, user story, or business rule provided, the Analyst must: 1. Analyse the source material as a professional aligned to SM&CR, EU AI Act, DORA, PSD2/SCA, and Consumer Duty obligations. 2. Derive clear, testable requirements confirming that every AI-assisted decision (credit, risk, fraud) is attributed to a named accountable senior manager, per SM&CR. 3. For any such decision, require evidence of explainability sufficient to satisfy EU AI Act Annex III high-risk obligations, and require that every payment is protected by PSD2-compliant Strong Customer Authentication. 4. Structure journeys and test cases around observable customer- and regulator-facing outcomes, with clear objectives, preconditions, inputs, and expected results - including operational resilience evidence required by DORA. 5. Justify key decisions with citations from the regulatory knowledge base - never inventing a citation. If none applies, the Analyst must say so explicitly. The Analyst must apply this guidance rather than merely quoting it, must analyse the underlying test basis rather than surface-level acceptance criteria, and must flag any gaps in the source documentation rather than silently filling them in.
AI outcomes - owned by a name.
?
โœจ New Requirements
๐Ÿ’ฌ Chat history

Sources selected:

๐Ÿ“„ Account Opening & SCA Payment BRD ๐Ÿ“„ EU AI Act (Annex III) ๐Ÿ“„ SM&CR Accountability
AI can make mistakes!
?
โœจ New Requirements
๐Ÿ’ฌ Chat history

The existing requirements provide good coverage for the primary success paths. However, I identified three gaps not explicitly covered by the BRD:

  1. Account Opening Input Validation (BR-002, BR-003) - not covered by the existing account-focused negative scenario.
  2. AI Credit Decision Accountability (SM&CR, EU AI Act) - every AI-assisted decision must be owned by a named senior manager and be explainable; not currently tested.
  3. SCA-Protected Payment Compliance and Operational Resilience - PSD2/SCA authentication, DORA resilience, and prudential evidence must be addressed together; not addressed by existing functional tests.

I've generated three new requirements to close these gaps, applying the organisation's SM&CR - Accountable AI Outcome directive throughout.

Requirements preview (3)

?
Requirements
Requirements
Requirement directives
All 6
RequirementsRiskCoverage
SCA-Protected Payment Compliance and Operational ResilienceHIGH-
AI Credit Decision Accountability and TraceabilityCRITICAL-
Account Opening Input ValidationMEDIUM-
Account Opening Negative ScenariosHIGH100%
Successful Digital Account OpeningCRITICAL-
Successful SCA-Protected PaymentCRITICAL100%

SCA-Protected Payment Compliance and Operational Resilience

Overview
Journeys 0
Summary

The purpose of this requirement is to ensure the initial payment made during account opening is protected by PSD2-compliant Strong Customer Authentication, and that the SCA challenge itself completes within the standard's required threshold. It also confirms DORA operational resilience evidence is captured, and that the payment record links back to the accountable AI decision it followed from.

Description

SCA-Protected Payment Compliance and Operational Resilience Validation

This requirement validates that the initial payment made during account opening is protected by PSD2-compliant Strong Customer Authentication, and that operational resilience evidence required by DORA and UK CRR / PRA prudential standards is captured alongside it.

?
๐Ÿงญ New structured journeys
๐Ÿ’ฌ Chat history

Requirement: SCA-Protected Payment Compliance and Operational Resilience

AI can make mistakes!
?
๐Ÿงญ New structured journeys
๐Ÿ’ฌ Chat history

I have designed five test journeys to validate the SCA-protected payment compliance and operational resilience requirement, as specified in this requirement.

These journeys cover:

  1. Response time for the SCA challenge during payment.
  2. The full digital account opening and SCA-protected payment flow end to end.
  3. Existence of an audit trail confirming the AI credit decision is owned by a named accountable senior manager.

I've created corresponding data tables to drive these tests and a new environment for the base URL. Please review the proposed journeys.

Journey structures preview (5)

SM&CREU AI ActPSD2/SCA
Goal
SCA-Protected Payment Compliance and Operational Resilience
Data table
Account Opening & Payment Data
Environment
Financial Services Banking Portal (UAT)
Journey
Account Opening to SCA-Protected Payment
Journey summary
This journey opens a digital account, triggers an AI credit decision, completes an SCA-protected payment, and asserts the AI decision is owned by a named accountable senior manager, within the standard's required threshold.
Checkpoints

Checkpoint 1: Open Digital Account

Assuming the user is already logged in, go to the base URL, open the Account Opening section, and submit an application using the applicant's name, date of birth, and identity document.

    Checkpoint 2: Complete SCA-Protected Payment and Assert Ownership

    Confirm the AI credit decision, then start timing. Click Pay, complete the SCA challenge, and stop timing once it's finished. Assert that the SCA challenge completed within the standard's required threshold, then assert the AI credit decision is owned by a named accountable senior manager.

    โœ“ 1 journey created successfully
    Goal: SCA-Protected Payment Compliance and Operational Resilience
    Financial Services
    โ† Back to journey list
    Journey 1 (Draft) : Account Opening to SCA-Protected Payment
    SM&CREU AI ActPSD2/SCA

    โœจ Autopilot ยท created

    โœจ How can I help with this journey?

    Describe what it should do and I'll write the checkpoints and steps for you to review.

    This journey already has 2 checkpoints. Want to change those instead? Describe changes you wish to make.

    Summary
    Timeline
    Tickets
    Journey summary

    This journey opens a digital account, triggers an AI credit decision, completes an SCA-protected payment, and asserts the AI decision is owned by a named accountable senior manager, within the standard's required threshold.

    NOT EXECUTED
    Assigned to:
    2 checkpoints
    17 steps
    0 extensions
    1 data table
    Journey plans

    There are no plans associated with this journey.

    Execution - SCA-Protected Payment Compliance and Operational Resilience
    08 September 2026, 11:58 PM
    Journey 1: Account Opening to SCA-Protected Payment runningโ€ฆ
    Wait 30 seconds for "Account Opening"
    Click on "Account Opening"
    Wait 18 seconds for button "Apply"
    Click on button "Apply"
    Write $scaPasscode in field "SCA passcode"
    Summary
    Healed
    Journey side effects
    Tickets
    Execution in progress
    Execution is in progressโ€ฆ
    Execution - SCA-Protected Payment Compliance and Operational Resilience
    08 September 2026, 11:58 PM
    Journey 1: Account Opening to SCA-Protected Payment 00:01:05
    Wait 30 seconds for "Account Opening"
    Click on "Account Opening"
    Wait 18 seconds for button "Apply" ๐Ÿฉน healed
    Click on button "Apply" ๐Ÿฉน healed
    Write $scaPasscode in field "SCA passcode"
    Click on "Confirm payment"
    Assert performance measuring "SCA Challenge" is less than 3000
    Summary
    Healed
    Journey side effects
    Tickets
    Summary report
    1 of 1 executions in 00:01:05
    โ—
    1 passed
    Launched by:
    AT
    โŒ˜ Environment: UAT
    Congratulations! All your
    journeys are doing great!