THE EVOLUTION OF TEST AUTOMATION IN HIGH REGULATORY CRITICALITY FINANCIAL ENVIRONMENTS: A SYSTEMATIC LITERATURE REVIEW
Abstract
Context: The accelerating digitization of the financial sector, combined with increasingly stringent regulatory requirements, particularly the PCI DSS 4.0.1 standard, has created an environment where software quality transcends technical excellence and encompasses legal compliance and large-scale data protection. Objective: This systematic literature review (SLR) synthesizes the state of the art on test automation in financial systems with high regulatory criticality, examining dominant frameworks, strategies for integrating with CI/CD pipelines, and measurable impacts on pre-production defect reduction. Method: Following the PRISMA protocol, we searched IEEE Xplore, ACM Digital Library, Scopus, Web of Science, and SpringerLink for publications from 2015 to 2024. After applying inclusion/exclusion criteria and conducting a critical quality appraisal, 47 primary studies were selected for qualitative and quantitative synthesis. Results: Cypress and Selenium lead adoption in regulated financial environments, with Cypress demonstrating significant advantages in asynchronous execution stability and evidence traceability. Organizations implementing automated test suites integrated into CI/CD pipelines reported average reductions of 63% in defects escaping to production and a 47% acceleration in delivery time. PCI DSS 4.0.1 compliance emerges as a critical driver requiring dedicated test extensions for encryption, access control, and log traceability. Conclusion: Test automation in regulated financial contexts goes beyond operational efficiency; it constitutes a risk governance mechanism that must be embedded in quality architectures from system inception.