# What is independent verification and validation (IV&V)?

Independent verification and validation (IV&V) is review, analysis, and testing by a party outside the development team, to limit shared assumptions.

Last updated September 29, 2026, 8 min read

## Learning objectives

After reading this article you will be able to:

-   Define independent verification and validation
-   Explain the kinds of independence a check can have
-   Apply the idea to agent-written code

## Related content

-   [How to test AI-generated code](https://specstory.com/learning/verification/ai-generated-code-testing)
-   [What is the difference between verification and validation?](https://specstory.com/learning/verification/verification-vs-validation)
-   [Can AI check its own code?](https://specstory.com/learning/verification/ai-self-verification)
-   [What is a holdout test suite for coding agents?](https://specstory.com/learning/verification/holdout-tests)
-   [What is runtime verification?](https://specstory.com/learning/verification/runtime-verification)

## What is independent verification and validation (IV&V)?

Independent verification and validation (IV&V) is the practice of having a party separate from the developers review, analyze, and test their software. The separation lowers the chance that the check shares the developers' assumptions. IV&V checks that the software meets its requirements and the need behind them. In [software testing](https://specstory.com/learning/testing/software-testing), a narrower form is called independence of testing.

A definition from the Committee on National Security Systems, in [NIST's glossary](https://csrc.nist.gov/glossary/term/independent_verification_and_validation), describes IV&V as review, analysis, and testing by an objective third party. Its purpose is to confirm that the requirements are correctly defined and that the system implements them. The two halves of the name come from [verification and validation](https://specstory.com/learning/verification/verification-vs-validation), and "independent" sets a condition on who does the work.

For teams that [test AI-generated code](https://specstory.com/learning/verification/ai-generated-code-testing), the same condition applies to each change. A [coding agent](https://specstory.com/learning/ai-coding/coding-agent) that writes the code, its tests, and its report is the developer and the checker at once. [Published research](https://arxiv.org/abs/2310.01798) shows that language models struggle to correct their own reasoning without outside feedback.

## How does independent verification work?

An IV&V team works in parallel with the developers from the start of a project and keeps its own plan. A simplified cycle has six steps:

1.  The developers give the independent team the requirements, the design, and each build.
2.  The independent team chooses which parts to analyze and test, and which techniques to use.
3.  The team writes its own expected results from the requirements, so each check has a [test oracle](https://specstory.com/learning/test-quality/test-oracle) that the developers did not supply.
4.  The team reviews the documents, analyzes the code, and runs the software from a [clean checkout](https://specstory.com/learning/environments/clean-checkout-testing) in its own environment.
5.  The team reports each finding with its evidence to the developers and to the people who approve the release.
6.  The developers fix the problems, and the team repeats the failing checks on the next build.

Diagram: How an independent team checks the developers' work

The two sides share the requirements and the build. The expected results come from the independent team's own reading of the requirements.

The work starts with the requirements, before code exists. One benefit that [NASA's IV&V Program](https://www.nasa.gov/ivv-overview/) lists is a better chance of finding errors that carry high risk early in development.

## What is an example of independent verification?

Here is an illustrative example. Acme Co. sells furniture online. A developer asks a coding agent to "Let customers edit their delivery address during checkout." The agent edits the checkout code, adds a test that sets the address, and reports that its tests pass. A [quality assurance](https://specstory.com/learning/testing/qa-testing) (QA) engineer on another team, who never saw the agent's session, checks the change:

1.  The engineer reads the request and the store's written rules, not the agent's plan or summary.
2.  The engineer writes 2 expected results before reading the code. The order shows the edited address, and changing the address keeps the items in the cart.
3.  The engineer starts the store in a [sandbox](https://specstory.com/learning/environments/ai-sandbox) with a fresh database.
4.  The engineer adds 2 items to the cart, starts checkout, changes the address to 12 Elm Street, and continues to payment.
5.  The address saved, but the cart emptied.
6.  The engineer sends the developer the steps, the expected 2 items, and the 0 items on the payment page.

The agent's test passed because it checked only the address. The engineer never read the agent's plan, so the second expected result came from the request and covered the cart. This example is simplified. A full IV&V effort would also review the requirements and the design, not only one workflow.

## What kinds of independence are there?

NASA's program, following the IEEE 1012 standard, describes independence in IV&V with three parameters:

-   **Technical independence.** People other than the developers assess the software and the way it was built, using their own expertise.
-   **Managerial independence.** A separate organization runs the checks and makes its own choices about what to test and how.
-   **Financial independence.** The budget for the checks sits outside the development organization, so the developers cannot cut the checks to save money.

The International Software Testing Qualifications Board (ISTQB) [Foundation syllabus](https://istqb.org/wp-content/uploads/2024/11/ISTQB_CTFL_Syllabus_v4.0.1.pdf) grades independence by who tests the work:

-   **No independence.** The author tests the work.
-   **Some independence.** A peer on the author's team tests it.
-   **High independence.** A tester from another team in the same organization tests it, e.g. a separate QA team.
-   **Very high independence.** A tester from outside the organization tests it.

The syllabus says the main benefit is that independent testers tend to find different kinds of defects, because their backgrounds, technical perspectives, and biases differ from the developers'.

The two sources draw the line in different places. The ISTQB [defines independence of testing](https://glossary.istqb.org/en_US/term/independence-of-testing) as separating testing responsibilities from development, with no condition on who manages or pays for the testers. Its syllabus recommends several levels for most projects, and says that a high level may be needed where a failure can harm people. Full IV&V needs a separate organization and budget, so it tends to be used where a failure would be dangerous or costly, e.g. NASA's missions.

On the same scale, a coding agent's own tests have no independence. When an agent tries to [check its own code](https://specstory.com/learning/verification/ai-self-verification) in a second session, the author is still checking its own work. That session shares the model and whatever its prompt repeats.

## What does independence not guarantee?

Independence changes who checks the software, not how much of it gets checked. Its limits are:

-   **The author still finds many bugs.** The ISTQB syllabus says that independence does not replace familiarity, and that developers can find many defects in their own code efficiently.
-   **Both sides can share a wrong requirement.** If the written requirements leave out a need, a check built from them can miss the same need.
-   **Separation has a cost.** The syllabus warns that independent testers can end up isolated from the developers, and that developers may lose a sense of responsibility for quality.
-   **A separate grader still sees the author's work.** A large language model (LLM) that grades the agent's diff, a setup called [LLM-as-a-judge](https://specstory.com/learning/verification/llm-as-a-judge), is separate from the author, but it judges the text the author produced. A different model gives only a weaker, informal form of the independence that IV&V requires.
-   **An independent check covers only what it ran.** No findings is not the same as complete coverage.

## How is IV&V different from peer review?

Peer review is a check by the author's colleagues, most often [code review](https://specstory.com/learning/code-review/code-review) of a change before it merges. On the ISTQB scale, a peer on the author's team gives some independence. The reviewers share the team's manager, schedule, and goals, and they usually read the change instead of running the software.

Full IV&V separates the checkers in all three parameters and covers the whole project, from the requirements to tests of the finished system. The two overlap, because an IV&V team also reviews documents and code. A project can use both, with peer review on each change and IV&V on the system.

## How independent can a check of agent-written code be?

A check of agent-written code is only as independent as the parts it does not take from the agent. For technical independence, write the expected results from the request before the agent starts. Keep them in a [holdout test suite](https://specstory.com/learning/verification/holdout-tests) that the agent cannot read or edit, and run the software outside the agent's session. For managerial independence, let a person, not the agent, choose what to check and make the release decision.

An agent saying "done" is a claim that needs to be verified. RunStory independently runs the software against your change and returns evidence to the coding agent. It is in private alpha for CLIs and web apps.

[Join the RunStory alpha →](https://specstory.com/runstory#alpha)

## FAQs

### Who performs independent verification and validation?

Independent verification and validation is performed by people who did not build the software and do not report to its developers. In a large program, that is a separate organization with its own budget, e.g. NASA's IV&V Program. The developers still test their own code, because independence does not replace familiarity.

### Is IV&V only for software where a failure is dangerous?

IV&V is not only for software where a failure is dangerous. Its full form needs a separate organization and budget, so it tends to be used where a failure would be dangerous or costly. For most projects, the ISTQB syllabus recommends several levels of independence, from the author's own tests to a tester outside the team.

### Does independent testing need a separate company?

Independent testing does not need a separate company. The ISTQB syllabus counts a tester from another team in the same organization as high independence. An outside company gives the highest level, and full IV&V also separates the management and the budget of the checks.

### When should independent verification start in a project?

Independent verification should start with the requirements, before code exists, because a check of the requirements can find a missing or wrong one early. For a coding agent, the same rule means writing the expected results from the request before the agent starts.

---

Source: [Independent verification and validation (IV&V) | SpecStory](https://specstory.com/learning/verification/independent-verification)
