Regulators Have Listed What They Will Look At in Core Provider Contracts. Deconversion Fees and Back-Billing Are on It.
A joint statement from the four banking agencies says a small number of firms run the core systems of most community banks, which leaves those banks little to negotiate with. It also raises the possibility of treating providers as institution-affiliated parties.

The short answer
- The OCC, Federal Reserve, FDIC and NCUA issued a joint statement on September 11 on community banks' relationships with core service providers.
- The agencies describe the core provider market as highly concentrated, with a small number of large firms serving the majority of community banks, limiting those banks' negotiating power.
- The statement names three areas of supervisory focus: transparency, contract features, and technology - with deconversion fees, back-billing windows and restrictions on third-party integrations called out by name.
- The agencies indicate core providers may qualify as institution-affiliated parties under 12 U.S.C. 1813(u)(3), which would bring them within federal banking enforcement authority.
A community bank's core system is the ledger: the software that holds account balances, posts transactions, and connects to payment networks. Most small banks do not build one. They rent one, from a short list of firms, on a long contract. On September 11 the four federal banking agencies published a joint statement about that arrangement.
The concentration point
The agencies state that the core provider market is highly concentrated, with a small number of large providers serving the majority of community banks. The consequence they draw from that is about bargaining: a bank negotiating a core contract has few alternatives, and the cost of moving is high, so the terms it is offered are close to the terms it accepts.
The statement does not name any provider.
The three things examiners will look at
The statement sets out the considerations the agencies say they will weigh in supervisory and enforcement determinations involving these relationships. They fall into three groups.
- Transparency: whether a bank can actually get the due diligence information it needs, how clearly service level agreements are written, how promptly incidents are disclosed to the bank, and whether billing is intelligible.
- Contract features: opaque pricing, deconversion fees the agencies characterise as excessive, back-billing windows that allow a provider to invoice retroactively, and contract terms restricting a bank from integrating software from other vendors.
- Technology: security incidents, the management of end-of-life and legacy systems, and operational resilience.
Three of those - deconversion fees, back-billing and integration restrictions - are contract terms rather than risk practices. They are the terms that make a core relationship expensive to leave and expensive to build around, which is the mechanism by which concentration turns into cost.
The enforcement hook
The statement raises the possibility that core service providers may qualify as institution-affiliated parties under 12 U.S.C. 1813(u)(3). That definition matters because it is the door through which federal banking enforcement authority reaches someone who is not a bank. An institution-affiliated party can be the subject of a cease-and-desist order, a civil money penalty, or a prohibition from the industry.
Core providers are already examinable under the Bank Service Company Act. The institution-affiliated party framing is a different and broader instrument, and the statement is the agencies signalling that they have read it.
The companion documents
The statement was published alongside the four agencies' proposed replacement for the 2023 third-party risk management guidance, which Wallcrest covers separately. The Federal Reserve also proposed its own third-party risk management guide for traditional community banking organisations, organised around operational resilience, system and information security, regulatory compliance, and financial resilience, and applied across eight categories of vendor - from core processors through to fraud prevention providers.
Sources
- Agencies seek comment on proposed third-party risk management guidance and issue statement on community bank engagement with core service providers — Board of Governors of the Federal Reserve System
- US Federal Banking Agencies Propose Revised Third-Party Risk Management Guidance — Skadden, Arps, Slate, Meagher & Flom LLP
- Banking Agencies Propose Replacing 2023 Third-Party Risk Guidance — Securities.io
Spotted an error? Tell our corrections desk.
How this article was produced
- Responsible desk:
- Tech & Fintech
- Published:
- 18 Sept 2026, 05:20 UTC
- Last updated:
- 18 Sept 2026, 05:20 UTC
- Verification:
- Figures and quotations checked against primary sources under our fact-checking policy and editorial standards.
- Independence:
- No advertiser or affiliate partner had any involvement in this article — see editorial independence and how we make money.
- Corrections:
- Report a factual error.
This article is general financial information and journalism, not personalised financial, investment, tax or legal advice.
