This should also include developers doing code review of the code in topic, but also all related code, all testers/QAs and product owner. There isn't one developer that missed that bug.
This should also include developers doing code review of the code in topic, but also all related code, all testers/QAs and product owner. There isn't one developer that missed that bug.
What I do think is that anyone who pretended there wasn't a mistake, downplayed it when they knew it could be causing the prosecutions or even significant reconciliation issues, should be looked at.
First and foremost, in the UK, Fujitsu itself can (and I think should) be prosecuted for corporate manslaughter here if there is any evidence that Fujitsu executives conspired with the Post Office to keep this quiet, ever.
If anyone ever ordered a developer not to go public with their complaints, threatened a whistleblower, deleted evidence, that should crush Fujitsu for good.
But yes, individual executives should be at risk (the corporate veil can be pierced to include directors), and it's difficult to see how it is possible to rule out right now that there is real liability down the chain.
The situation at the Royal Mail is likely to be dramatically more serious, because there's a significant chance they were both covering up serious failings and knowingly directly prosecuting people to do so.
I worked in a highly regulated company, we were under supervision of FDA, EMA and German EMA. We once missed a bug in database migration where a boolean field was false by default in java (non-nullabe), but it could be null in database column. It apparently broke a few reports (NOT running software, just pdf reports) for pharmacological clinics, 2 developers, 2 testers, our PO and out CTO had "disciplinary" actions (don't remember what it was really called) and their actions were under supervision from external consultants our company had to pay for.
It's crazy we don't have such rules in finance, food, data processing and publishing industries.
> The situation at the Royal Mail is likely to be dramatically more serious, because there's a significant chance they were both covering up serious failings and knowingly directly prosecuting people to do so.
Yes, RM decided to start internal investigation that lasted a few years, instead immediately contacting police, this is why it lasted so long and were so many victims.
Yes, but the distinction here is not actually as useful here as you might think.
In this situation, Royal Mail _are_ the police (the USPS has its own police too). But Royal Mail are also the prosecutors in court (they have/had prosecutorial power).
They didn't really delay sending it to the police because they never would have. It wasn't a police matter because definitively it was a Royal Mail matter. (The Royal Mail has had the power to investigate and prosecute since before there even were police.)
Edit to add: it is now a "Post Office" matter as well because they are distinct businesses as of 2013, and Post Office Ltd is an ordinary company. But the key period concerns a time when they were one and the same
It is a longstanding power the Royal Mail had, in fact.
But yes, private prosecutions are protected by law and Royal Mail now prosecutes using the right of an individual RM employee to bring the charge.
So the bit I want to read up on later is exactly who the individuals were in each prosecution. Is it the chief executive?
Any kind of certification in this space have you have the following for developing core functionality regarding financial data:
* Proper definition of hard requirements and acceptance tests. * Developers have to develop and write tests against this specification. * Another developer have to perform a review and sign off that this code indeed lives up to this specification. * QA will run tests that verify the specification is met, and sign off that it met specification.
That is a PM/PO that have responsibility for the specification. At least two developers and a QA person that have verified that the specification was met. A bug like this only goes live due to impossible to meet deadline or incompetency on multiple levels.
The only remotely acceptable explanation would be that this is the result of some really weird edge case or possibly race condition. But in that case we're back to incompetency, since no experienced developers should design financial software without well known patterns and technologies for the core of the application.
In this particular domain there is zero excuse for a bug like this.
The way developers can be at fault here is if they managed to conspire with QA or testing to hide the existence of the bug from their management and continue to deny it when asked. Which implies a pretty toxic workplace, but, then again, Japanese conglomerates are not famous for sunshine and daisies.
And sure enough, that's the claim: https://www.computerweekly.com/news/252496560/Fujitsu-bosses...
The question is how those people who discovered the bug or managed the components in which it exists handled themselves.
There is no way that Fujitsu (or even individual Fujitsu employees and directors) should be considered off the hook just because software is only software, which is the defence I am seeing here and elsewhere. It should depend on how they acted.