Fintech

Core Banking Contracts Are Becoming a Supervisory Signal

Blackrock Research
September 12, 2026
5 min read

Core Banking Contracts Are Becoming a Supervisory Signal

Key takeaway

Federal banking agencies are separating routine vendor oversight from the handful of relationships that can stop a bank from operating. At the same time, they are signaling that a core provider's transparency, contract terms and technology investment may influence how closely that provider is supervised. For community banks and their vendors, due diligence access and exitability are becoming product features.

What's changing

On September 11, the Federal Reserve, FDIC, OCC and NCUA proposed replacing the 2023 interagency guidance on third-party risk management. The proposal remains principles-based and non-binding. Its practical change is emphasis: a bank should align oversight with the reasonably assessed risk of each relationship and the magnitude and likelihood of harm, rather than run every supplier through the same process-heavy checklist. Comments are due 60 days after publication in the Federal Register. Source: OCC bulletin and proposed guidance, September 11, 2026

The Federal Reserve, FDIC and OCC also issued a separate statement about community banks' relationships with core service providers. The statement covers providers supporting transaction processing, account management, payments, customer relationship management, compliance, reporting and online banking. These are not ordinary software vendors. Their availability, integrity and security can determine whether a bank can serve customers at all.

The agencies acknowledged a commercial constraint that risk frameworks often leave implicit: a significant share of the core-provider market is represented by a few large companies, limiting community banks' negotiating power. Banks reported difficulty obtaining due diligence information, negotiating usable terms and monitoring performance. The agencies said these obstacles can make it harder to hold providers accountable. Source: Joint Statement on Community Banks' Engagement with Core Service Providers, September 11, 2026

Supervisors said they will consider three broad areas when allocating oversight to core providers: transparency, contract features and technology. The detail is unusually operational. It includes timely access to relevant audit and security information; measurable service levels; incident disclosure; billing that can be reconciled; the ability to compare providers; defined deconversion fees; reasonable integration with other services; management of end-of-life technology; cybersecurity; and resilience.

The statement goes further than a procurement reminder. It says agencies may act against a provider, a bank or both when unsafe practices or violations are identified. It also says some core providers may qualify as institution-affiliated parties because they participate in functions integral to the bank. The bank's own accountability does not disappear when work is outsourced, but the provider is no longer treated as commercially invisible to supervision.

Why it matters

The two releases create a useful asymmetry. Oversight of low-risk vendors can become lighter and more tailored. Scrutiny of a core relationship can become sharper because the plausible harm is larger and the bank may have weak bargaining power.

That changes the economics of vendor design. A core platform can no longer treat diligence packages, outage reporting, price clarity, service-level evidence and data portability as compliance attachments produced after the product is sold. They affect a customer's ability to manage risk and may affect supervisory attention directed at the provider.

Exitability is especially important. Community banks rarely change cores casually; conversion is expensive, operationally risky and disruptive. That makes the right to leave valuable even when it is never exercised. Opaque deconversion charges, long back-billing windows or restrictions on third-party integrations can turn contractual dependence into operating risk. A nominally favorable price can be poor value once switching and reconciliation costs are included.

The proposal should not be read as permission to shrink every vendor review. A bank needs a credible way to distinguish a payroll tool from infrastructure that moves money, maintains customer balances or operates digital banking. If the risk tier is wrong, a streamlined process merely hides the exposure.

What operators should do

Banks should rebuild vendor inventories around failure impact. For each relationship, identify which customer journeys, ledger functions, payment flows, compliance controls and recovery processes would stop if the provider failed. Use that map to assign review depth, executive ownership and testing frequency.

For core contracts, turn supervisory concerns into measurable terms. Require delivery schedules for audit and security evidence, incident-notification clocks, service levels tied to customer harm, billing records that reconcile to contracted services, clear integration rights and a tested method for exporting usable data. Deconversion fees should be defined before signing and should distinguish an ordinary switch from an exit caused by provider breach or repeated service failure.

Core providers should publish a standard evidence pack that can be refreshed, not recreated for each customer. It should connect control reports, penetration-test summaries, resilience results, end-of-support roadmaps, incident history and remediation status to the services a bank actually buys. Commercial teams also need a defensible explanation of pricing changes and retroactive charges.

Both sides should test an exit before it is needed. The useful exercise is not a generic business-continuity presentation. It is a timed rehearsal covering data extraction, interface replacement, reconciliation, customer communication, parallel operation and the authority to make decisions during a prolonged outage or conversion.

Finally, boards should track concentration at the business-service level, not only by vendor name. One provider may support deposits, cards, lending and online banking through different modules. Treating those contracts as separate rows can understate the fact that one failure domain serves most of the bank.

Bottom line

The agencies are offering banks room to spend less effort on suppliers that present little harm. They are also making clear that concentrated core relationships deserve evidence, leverage and an executable way out. The winning core platform will not simply promise uptime. It will make its performance inspectable, its charges understandable and its customers capable of leaving without losing control of their own operations.