Invest1 publisher3 min readPublished
Three agencies concede core provider concentration limits what community banks can negotiate
A proposal from four federal agencies would size vendor oversight to the harm a relationship could do, while a separate statement from three of them says a few large core providers leave community banks little negotiating power.
The Investor · Invest desk

What happened
- On Sept. 11 the Fed, FDIC, OCC and NCUA proposed replacing existing third-party risk-management guidance with a principles-based framework letting institutions calibrate oversight to the risk each relationship actually poses.
- The same three agencies called core provider relationships community banks' most material, complex and highest-risk third-party relationships, and said core platform availability is vital to nearly all banking operations.
- PYMNTS Intelligence reported in April that 55% of community bank decision-makers said their technology stacks are fully modernized, while many of the accounts those banks open never become primary relationships.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint An exit strategy priced at a deconversion fee plus rebuilt integrations is a control the bank cannot exercise, so raising oversight on the relationship does not change the contract behind it.
- decision A bank whose own regulators rank core processing as its highest-risk relationship must choose between paying to switch and expanding the assessment of a provider it intends to keep.
- exposure Accountability stays with the institution while operational control sits with the provider, and the proposal's calibration puts the deepest supervisory attention exactly where that gap is widest.
- contradiction PYMNTS treats the actions as making switching costs and interoperability supervisory measures; the agencies' own words describe obstacles to identifying and addressing risk, which is a narrower claim.
The price of a core processing contract is set against what it costs to leave. PYMNTS lists deconversion fees, opaque pricing and integration limits as the items that keep a bank in a relationship it would otherwise end [8]. On the concentration underneath that, the agencies said a "significant percentage of the core provider market is represented by just a few large providers, which limits CBOs' negotiating power" [5]. As PYMNTS describes it, the statement gives no share, provider count or fee level.
The framework proposed the same day would scale oversight to the magnitude and likelihood of potential harm from each relationship instead of treating third parties uniformly [1][2]. Run that against the agencies' own ranking, which calls core provider ties community banks' "most material, complex, and highest-risk third-party relationships" [6], and the heaviest documentation lands on the contract the bank has the least ability to alter. The same statement says a core platform's availability, integrity and security are vital to "nearly all banking operations" [7].
The two documents were signed differently. The National Credit Union Administration joined the proposal to replace the guidance, and the core provider statement came from the other three [14].
Community banks are not short of technology spend by their own account. PYMNTS Intelligence reported in April that 55% of community bank decision-makers said their stacks are fully modernized, leaving 45% who did not say so [10][13]. The same research found many of the accounts these banks open never become primary relationships [10]. Banks confident in their modernization still lack the payments capabilities to support continuous engagement [11]. "It's not about abandoning legacy systems, but modernizing around them intelligently," Garrett Baird, vice president of product, banking and FinTech at Paymentus, told PYMNTS in May [12].
The statement could be a first step toward expectations addressed at the providers themselves, with exit assistance and pricing becoming terms a bank can point to at renewal. Or the calibration works as intended at the small end, cutting questionnaire volume on vendors whose failure would cost a bank little and moving examiner attention to core processing, payments and cloud [15]. Or the concentration the agencies just described stays where it is, the bank writes a longer assessment of a provider it will keep, and the residual risk it records this year is the residual risk it recorded last year.
I'd expect the third. The documents name the constraint on community banking organizations without placing an obligation on the providers [3][5]. A bank that remains accountable for infrastructure it cannot direct [9] is in the same position with better paperwork. I'd be wrong if the final framework tells examiners that provider concentration is an acceptable reason to carry residual risk. A bank could then cite the framework instead of paying to switch.
The substitutability framing belongs to PYMNTS [16]. What the agencies wrote is narrower: business practices and market dynamics "may pose obstacles to a CBO's ability to efficiently and effectively identify, assess and address the attendant risks" [4].
What to watch
- Whether the National Credit Union Administration issues its own statement on credit unions' core providers, having joined only the guidance proposal.
- Whether the final framework tells examiners how to treat concentration when a bank's highest-risk relationship has no realistic alternative.
- Whether any community bank publicly documents its deconversion fee or switches core providers under the new framework.