Independent Testing & IT Assurance
Case Study
About Our Client
Overview
Our client is a national not-for-profit healthcare association undertaking a significant modernisation of one of Australia’s most important clinical datasets — a national registry capturing device performance and patient outcomes across all hospitals nationally. The program replaces a 25-year-old platform with a modern, cloud-hosted web application, built by an external technical vendor and structured across four modules delivered in two releases. As an organisation of roughly 60 people with no internal IT testing function, and with a registry holding qualified-privilege data carrying significant clinical and reputational consequences if released in error, the client needed an independent testing partner it could trust to get a nationally significant project right.
The Challenge
Independent assurance on a fast-moving, high-stakes build
The client was modernising a nationally significant registry with no internal testing capability of its own, relying on an external vendor to build and test the new platform. It needed an independent voice on its side of the table — not a vendor marking its own homework — to confirm the platform was built to requirements before go-live.
Key challenges included:
- No in-house IT testing function, meaning any solution had to build the client’s own capability rather than create a dependency.
- A vendor working to a fast two-week sprint cadence, creating the risk that testing could fall behind the build and lose its value.
- Complex and under-documented role-based access control spanning 12 user roles, with differing visibility across clinical studies, procedures, commercial data, and internal administration — a high-risk area given the sensitivity of the data.
- A regulated environment with qualified-privilege obligations, where accuracy, data integrity, and controlled data exports were non-negotiable.
- Non-technical researchers and bio-statisticians who understood the clinical domain but had no testing background, and who needed hands-on support to participate in user acceptance testing confidently.
- A hard requirement for an onshore-only Australian delivery team, given the nature of the health data.
Services:
- Independent Test Strategy Review & Vendor Assurance
- Sprint & System Integration Testing (SIT) Execution
- Role-Based Access Control (RBAC) Testing Across 12 User Roles
- Compliance-Aligned Testing (Qualified Privilege Export Controls, OCR/ICR Pipeline, System Integrations)
- UAT Facilitation & Execution for Non-Technical Users
- Defect Lifecycle Management on the Client’s Behalf
Sector
Healthcare / Medical Technology
Independent QA that builds lasting capability
Avocado embedded directly into the client’s delivery program as an independent, client-side testing function — working alongside the technical vendor while representing the client’s interests throughout. The engagement was structured around vendor assurance, hands-on execution, UAT facilitation, and capability uplift:
- Vendor assurance: Independent review of and formal input on the vendor’s test strategy and test cases across all modules, identifying gaps — particularly in role-based access — and holding the vendor accountable to agreed quality standards.
- Sprint & SIT execution: An independent execution layer aligned to the vendor’s two-week sprint cadence, testing features as they landed in the test environment and validating end-to-end workflows across modules. Regression testing was run across sprints and between releases to ensure new builds did not break previously validated functionality, giving the client confidence that what was built actually worked as required.
- Role-based access control testing: Independent RBAC testing across all 12 user roles at field and module level, underpinned by a clear RBAC test matrix established up front, to confirm each user type could access only what they were permitted to see.
- Compliance-aligned testing: Independent testing of qualified-privilege export controls, the OCR/ICR form-processing pipeline, and integrations with external systems, alongside verification of the platform against the client’s non-functional requirements.
- UAT facilitation & execution: Coordinating and hand-holding the client’s researchers, bio-statisticians, and SMEs through two defined UAT windows — translating technical requirements into plain-language test scenarios, sitting with business users, and converting vague feedback into properly articulated defects. Avocado’s testers executed structured test cases alongside the SMEs during peak periods, freeing domain experts to focus on the business validation where their expertise added the most value.
- Defect management: Managing the full defect lifecycle on the client’s behalf — logging, prioritising, chasing the vendor, and verifying resolution — with weekly status reporting and go/no-go recommendations at each milestone.
- Deployment readiness: Deployment readiness assessment and post-deployment smoke testing at each production release, confirming the platform was ready to go live and behaving as expected once deployed.
- Knowledge transfer: Coaching embedded throughout rather than left to a handover document, including a documented defect-management process the client could run independently, a full test artefact library, and plain-language testing guides written for a non-technical audience.
The Result
Collaboration designed to enable independence
The engagement was designed to move the client from having no internal testing capability to a structured, independent quality function covering its highest-priority risk areas — role-based access, workflow integrity, and controlled data exports — throughout a fast-moving vendor build.
- The delivery model was structured to give the client’s internal team hands-on testing capability through UAT coaching and structured knowledge transfer, rather than a dependency it couldn’t sustain.
- Aligning testing to the vendor’s two-week sprint cadence was designed to keep assurance moving in step with the build, so the client would never approach go-live with an untested backlog.
- Independent RBAC and qualified-privilege export testing was built in from the outset to support the client’s clinical accuracy and data-protection obligations.
- The engagement was set up to be delivered entirely by a local Australian team, meeting the client’s onshore-only requirement without offshore resourcing.
- A forward-looking roadmap was included to guide the client’s next steps — extending assurance into areas such as data migration and IT governance as the wider registry modernisation program progresses.
Overall, the engagement was designed to give the client both an immediate, independent check on a nationally significant build and a documented foundation its team could build on with confidence across future registry projects.