Compliant, Not Slow: Shipping Every Day in a Highly Regulated Environment

Thursday Oct 1
14:30 –
15:15
TAP1, Room 1

On a team inside BankID, Norway's biggest authentication scheme, we ship to production several times a day. Inside a heavily regulated corner of software. Compliance usually gets blamed for making that impossible. It doesn't have to.

We recently went through a certification, and the real lesson wasn't the paperwork. It was learning to read past the pages of requirements to what they're actually trying to achieve. Some things aren't worth fighting: we'd love to drop pull requests entirely, but the control they satisfy is real, so we still do them. Other things are worth a second look: our network segmentation control was written with traditional firewalls in mind, but by looking at what needed to be controlled we found more modern and streamlined solutions.

I'll walk you through some of the mechanisms we use and the thought process behind them so you can pick up some tips to apply. The routines must be followed, but they don't have to be complicated. Some requirements can be satisfied in surprising ways, and there's a good chance you can do it with software you already have.

The same controls and routines have also proved extremely valuable with the arrival of AI agents and generated code: we can let them move fast, because the same guardrails and continuous delivery practices that keep us compliant are exactly what stop them from quietly breaking production.