American Impact ReviewA Peer-Reviewed Multidisciplinary Journal
Journal
JournalGetting StartedSubmission GuidelinesWhat We PublishWhy Publish With UsSubmit a Manuscript
About
AboutAbout the JournalEditorial BoardPeer ReviewersIndexing & RecognitionAuthor GuidelinesFor ResearchersFor ReviewersEthics & PoliciesContact
Explore
ExploreBrowse ArticlesSubmit a Manuscript
Log inSign up
Browse ArticlesSubmit a Manuscript
JournalGetting StartedSubmission GuidelinesWhat We PublishWhy Publish With Us
AboutAbout the JournalEditorial BoardPeer ReviewersIndexing & RecognitionAuthor GuidelinesFor ResearchersFor ReviewersEthics & PoliciesContact
AccountLog inSign up
American Impact Review
Peer-reviewed, open-access
multidisciplinary journal
Published by Global Talent Foundation
a 501(c)(3) nonprofit
Stay updated
Navigate
AboutFor AuthorsFor ResearchersFor ReviewersPoliciesArchive
Legal & Contact
Privacy PolicyTerms of UsePublication EthicsContact Us
Indexed in:Crossref·Google Scholar·OpenAlex·Wikidata·Scilit
CC BY 4.0 · Open Access
ISSN 3071-124X · EIN: 33-2266959 · Verify on IRS.gov© 2026 American Impact Review
Computer ScienceOriginal ResearchPublished 9/22/2026 · 78 views22 downloadsDOI 10.66308/air.e2026079

A model for integrating regulatory requirements into continuous software delivery in financial organizations

Irina TitovaHead of PMO IT, Independent researcher
Received 8/14/2026Accepted 9/22/2026
continuous deliveryfinancial organizationsregulatory requirementsdigital operational resiliencechange managementDevSecOpscompliance-as-codetraceability
Download PDF
Cover: A model for integrating regulatory requirements into continuous software delivery in financial organizations

Abstract

Continuous software delivery requires financial organizations to reconcile frequent changes with regulatory controls. This study develops a model for systematically integrating regulatory requirements into delivery processes to support demonstrable compliance while accounting for delivery-time constraints. The methods combine comparative analysis of published US and European Union regulatory and supervisory documents, analysis of published research, and structural-functional modeling. Sources include the Digital Operational Resilience Act, Commission Delegated Regulation 2024/1774, Federal Financial Institutions Examination Council guidance, and New York State Department of Financial Services cybersecurity requirements. The proposed classification distinguishes the stage at which an action must be completed, the control object, and the status of its source. The methodological contribution connects this classification with rules for translating and measuring controls: applicability, fulfillment, and evidence sufficiency are assessed separately, while the measurement unit follows the control object and frequency. A release-approval comparison identifies evidence that can be shared across sources and assessments that must remain separate. Analysis of software packages, test data, and release approval establishes sequencing constraints and conditions for evidence reuse. Normal and emergency routes are differentiated through prerequisites and follow-up actions. The proposed metrics cover delivery speed and stability, control fulfillment, evidence completeness, and time spent on controls. The result is a theoretical and methodological model supported by analytical reasoning; implementation effects were not measured.

Keywords: continuous delivery, financial organizations, regulatory requirements, digital operational resilience, change management, DevSecOps, compliance-as-code, traceability

Cite asIrina Titova (2026). A model for integrating regulatory requirements into continuous software delivery in financial organizations. American Impact Review. https://doi.org/10.66308/air.e2026079Copy

Sections

    Article metrics

    Views78
    Downloads22

    Declarations

    Data availability

    The study is based on publicly available published sources listed in the References.

    Ethics statement

    No human/animal subjects involved

    Author contributions

    Irina Titova: Conceptualization; Methodology; Investigation; Formal analysis; Writing - original draft; Writing - review and editing.

    Funding

    No external funding

    Competing interests

    The author declares no conflicts of interest.