Skip to content
Connecting live market data
Full board

Tech & Fintech

Regulators Have Listed What They Will Look At in Core Provider Contracts. Deconversion Fees and Back-Billing Are on It.

A joint statement from the four banking agencies says a small number of firms run the core systems of most community banks, which leaves those banks little to negotiate with. It also raises the possibility of treating providers as institution-affiliated parties.

Wallcrest Fintech DeskPublished 18 Sept 2026, 05:20 UTCUpdated 18 Sept 2026, 05:20 UTC3 min read
Regulators Have Listed What They Will Look At in Core Provider Contracts. Deconversion Fees and Back-Billing Are on It. — Wallcrest Media cover image
Photo: Photo by cookiecutter / Pexels · Pexels License — free to use, no attribution legally required (credited above as good practice).

The short answer

  • The OCC, Federal Reserve, FDIC and NCUA issued a joint statement on September 11 on community banks' relationships with core service providers.
  • The agencies describe the core provider market as highly concentrated, with a small number of large firms serving the majority of community banks, limiting those banks' negotiating power.
  • The statement names three areas of supervisory focus: transparency, contract features, and technology - with deconversion fees, back-billing windows and restrictions on third-party integrations called out by name.
  • The agencies indicate core providers may qualify as institution-affiliated parties under 12 U.S.C. 1813(u)(3), which would bring them within federal banking enforcement authority.

A community bank's core system is the ledger: the software that holds account balances, posts transactions, and connects to payment networks. Most small banks do not build one. They rent one, from a short list of firms, on a long contract. On September 11 the four federal banking agencies published a joint statement about that arrangement.

The concentration point

The agencies state that the core provider market is highly concentrated, with a small number of large providers serving the majority of community banks. The consequence they draw from that is about bargaining: a bank negotiating a core contract has few alternatives, and the cost of moving is high, so the terms it is offered are close to the terms it accepts.

The statement does not name any provider.

The three things examiners will look at

The statement sets out the considerations the agencies say they will weigh in supervisory and enforcement determinations involving these relationships. They fall into three groups.

  • Transparency: whether a bank can actually get the due diligence information it needs, how clearly service level agreements are written, how promptly incidents are disclosed to the bank, and whether billing is intelligible.
  • Contract features: opaque pricing, deconversion fees the agencies characterise as excessive, back-billing windows that allow a provider to invoice retroactively, and contract terms restricting a bank from integrating software from other vendors.
  • Technology: security incidents, the management of end-of-life and legacy systems, and operational resilience.

Three of those - deconversion fees, back-billing and integration restrictions - are contract terms rather than risk practices. They are the terms that make a core relationship expensive to leave and expensive to build around, which is the mechanism by which concentration turns into cost.

The enforcement hook

The statement raises the possibility that core service providers may qualify as institution-affiliated parties under 12 U.S.C. 1813(u)(3). That definition matters because it is the door through which federal banking enforcement authority reaches someone who is not a bank. An institution-affiliated party can be the subject of a cease-and-desist order, a civil money penalty, or a prohibition from the industry.

Core providers are already examinable under the Bank Service Company Act. The institution-affiliated party framing is a different and broader instrument, and the statement is the agencies signalling that they have read it.

The companion documents

The statement was published alongside the four agencies' proposed replacement for the 2023 third-party risk management guidance, which Wallcrest covers separately. The Federal Reserve also proposed its own third-party risk management guide for traditional community banking organisations, organised around operational resilience, system and information security, regulatory compliance, and financial resilience, and applied across eight categories of vendor - from core processors through to fraud prevention providers.

Sources

Spotted an error? Tell our corrections desk.

How this article was produced

Responsible desk:
Tech & Fintech
Published:
18 Sept 2026, 05:20 UTC
Last updated:
18 Sept 2026, 05:20 UTC
Verification:
Figures and quotations checked against primary sources under our fact-checking policy and editorial standards.
Independence:
No advertiser or affiliate partner had any involvement in this article — see editorial independence and how we make money.

This article is general financial information and journalism, not personalised financial, investment, tax or legal advice.

Share

core service providerscommunity banksvendor riskbank technologyconcentrationinstitution-affiliated party