Software Quality & Risk Assessment for UWV's e-Dossier Application
The Issue at hand
UWV outsources much of its IT to specialized external suppliers, who typically manage code quality with tools like SonarQube — but UWV lacked one clear, objective, management-level view of the risk in what those suppliers delivered. An earlier high-level review had flagged relatively high issue counts in one newly delivered application, so UWV asked Metri for a deep-dive.
The Service Provided
We ran its Software Quality & Risk Assessment on the flagged application, using CAST AIP to assess the code, the architecture, and the third-party components against more than 1,800 international rules and best practices.
The outcomes achieved
Quality came back lower, and risk higher, than expected for a newly delivered application: Robustness, Efficiency, Security, Changeability, Transferability, and the overall Total Quality Index all scored below target, and the number of critical violations was too high — including some outdated third-party components with known, already-patched vulnerabilities. The good news: resolving a manageable list of issues would bring every health factor back above the norm. We delivered a Management Dashboard and an Engineering Dashboard with a concrete Action Plan, giving UWV management the evidence it needed to raise the issues directly with the supplier.
Deliverables
A Software Quality & Health Assessment report covering Robustness, Efficiency, Security, Changeability, and Transferability, delivered together with a Management Dashboard, an Engineering Dashboard, and a concrete Action Plan for resolving the identified violations.

