Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked

The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.

Table of Contents

In November 2025, the OCC published Bulletin 2025-39, an unusual document. Rather than issuing guidance or announcing an examination priority, the agency asked questions — specifically, hard questions about community banks’ relationships with the three companies that run most of their core banking operations.

The RFI (published as Federal Register Document 2025-21333) asked community banks to explain their experiences with core service providers: how pricing and contract terms work, what barriers exist to switching, how much visibility banks have into subcontracting decisions, and how vendors are integrating AI into platforms that banks use.

The questions weren’t academic. The OCC doesn’t publish RFIs about things it doesn’t plan to supervise. And the OCC Fall 2025 Semiannual Risk Perspective published the same month was explicit: concentration risk from third-party vendor reliance is an elevated supervisory concern.

If your TPRM program doesn’t address core provider concentration specifically — not cloud concentration, not AI vendor concentration, but the Fiserv/FIS/Jack Henry layer of your stack — you should read this before your next examination.

TL;DR

  • OCC Bulletin 2025-39 (November 2025) asked community banks direct questions about concentration risk, switching ability, and AI integration with core service providers — signaling examiner focus
  • Core provider concentration risk is structurally different from cloud or AI concentration: switching timelines are 12–24 months, data portability is legally and technically constrained, and these vendors increasingly bundle AI capabilities that import new fourth-party risks
  • OCC Bulletin 2023-17 requires written agreements for critical activities to include specific terms most core provider contracts predate — substitutability analysis, exit assistance, and regulator access rights are commonly missing
  • The FSB’s October 2025 AI monitoring report flagged that technology vendors bundling hardware, cloud, and AI together are increasing switching costs and limiting interoperability — making substitutability analysis harder every year

Why the OCC Is Asking About This Now

Community banks have long relied on a small number of core processing vendors. Three providers — Fiserv, FIS, and Jack Henry & Associates — serve the substantial majority of community and mid-size U.S. banks. This concentration has existed for years. Why is it an elevated supervisory concern in 2025–2026?

Two structural shifts have made the concentration more acute.

First, the AI bundling problem. Core providers are integrating AI capabilities directly into platforms: fraud detection models, loan origination scoring, deposit analytics, customer service automation. When a bank uses its core provider’s AI-enabled fraud flagging, it’s not just relying on the core banking system. It’s relying on whatever AI models the provider has trained, whatever third-party AI APIs the provider is calling (OpenAI, Google, Anthropic), and whatever data handling decisions the provider has made about customer information.

The Financial Stability Board’s October 2025 AI monitoring report made this point explicitly: technology providers are bundling hardware, cloud, and AI services together in ways that increase switching costs and limit interoperability. The bank didn’t sign up for a multi-layer AI dependency — it signed up for core banking software that quietly added one.

Second, the TPRM gap. Most community bank TPRM programs were built to assess new vendors as they’re onboarded. But core providers have been in place for a decade or more. Their TPRM files reflect the relationship as it existed when they were initially reviewed — before AI bundling, before sub-vendor relationships that didn’t exist five years ago, before the interagency guidance issued in June 2023 required specific contract provisions most of those contracts don’t contain.


Core Provider Concentration Is Not the Same as Cloud Concentration

The existing supervisory focus on cloud concentration risk (AWS, Azure, GCP) created useful frameworks, but those frameworks don’t translate directly to core provider risk. The risk profile is different in ways that matter for your TPRM program.

DimensionCloud ConcentrationCore Provider Concentration
What they controlCompute, storage, networkingCore banking operations, general ledger, payment rails, deposit processing
Realistic switching timeline6–18 months12–24 months minimum; often 2–3 years in practice
Data portabilityRegulated under contracts; standard formats existProprietary formats common; legal and financial barriers to extraction
Regulatory visibilityCloud providers are well-known to regulatorsCore providers often have regulatory examination relationships through bank service provider authority
AI integration depthSeparate AI vendors typically usedAI bundled into core banking platform; bank may not know which models are in use
Contract vintageOften negotiated recentlyMany contracts predate 2023 interagency TPRM guidance
Fourth-party riskSub-processors disclosed in DPACore provider sub-vendor arrangements often opaque

The most important distinction is substitutability. OCC Bulletin 2023-17 requires banks to assess whether “adequate alternatives are available” if a critical third party cannot perform. For cloud providers, there’s a credible (if expensive) substitution path. For core providers, the realistic substitution path is so long and resource-intensive that for most community banks, “transition to an alternative” in a crisis is not actually a viable option. That changes the risk calculus for the ongoing monitoring requirements.


What the OCC RFI Questions Reveal About Examination Focus

The OCC’s RFI questions are unusually direct. Reading them as a practitioner — knowing that regulators use RFIs to signal examination priorities — several themes emerge about what examiners are going to ask.

Switching ability. The RFI explicitly asked about “factors that make it difficult to change core service providers, including the financial and operational burden of switching.” Examiners will ask: has your bank documented a realistic transition plan, and does that plan account for the actual timeline and resource requirements rather than a theoretical one?

Pricing and contract terms. The RFI asked about “core service providers’ pricing practices, including any changes in pricing and the factors driving those changes.” This is asking whether banks have negotiating leverage and whether contract terms are fair. Examiners are likely to start reviewing whether banks have meaningful SLA remedies, whether price increases are constrained, and whether data portability costs are reasonable.

AI integration transparency. The OCC specifically asked about the “pace of innovation in AI” and how banks are “keeping pace.” For TPRM programs, this translates to: does your due diligence process capture AI capabilities being added to existing platforms, and do you have visibility into the AI sub-vendors your core provider is using?

Subcontracting. The RFI asked about banks’ visibility into “service providers’ subcontracting arrangements.” This directly maps to the fourth-party risk requirements in the 2023 interagency guidance. For core providers, this means understanding which payment networks, data centers, fraud model providers, and AI vendors your core provider depends on.


What TPRM Programs Are Missing on Core Providers

If you review your current core provider TPRM documentation against the 2023 interagency guidance, most programs will show gaps in four areas.

Written agreement terms. OCC Bulletin 2023-17 requires that agreements for critical activities include: business continuity and contingency plans, data ownership and the bank’s right to access data in usable formats, subcontracting provisions requiring notification and approval, the bank’s and regulators’ right to audit, and adequate notice before service termination or significant changes. Most core provider contracts — particularly those signed before 2023 — don’t contain all of these provisions. The next contract renewal is the opportunity to negotiate them in; waiting is not a compliance strategy.

Substitutability analysis. The guidance requires an assessment of whether the bank could transition if needed. This analysis should be realistic — based on the actual timeline it would take your bank to convert core systems, the cost, the staff required, and whether the bank has documented a transition plan. A two-sentence substitutability assessment that says “alternatives exist in the market” doesn’t satisfy the guidance.

Critical activity re-assessment. If your core provider has added AI-powered services since you last reviewed the relationship, that’s a material change that may expand the criticality scope. Adding a fraud detection model built on a third-party AI API introduces a fourth-party AI dependency that wasn’t in your original assessment. The interagency guidance requires re-assessment when “the nature of the relationship changes materially.”

Board-level concentration reporting. The guidance requires ongoing monitoring that escalates concentrated risk to senior management and the board. Core provider dependency is rarely reported as a standalone concentration risk — it’s buried in a vendor inventory. Boards should see an explicit statement of which providers represent existential dependencies and what the bank’s options are if those relationships fail.


The Fourth-Party AI Problem Inside Core Providers

The FSB’s concern about bundled hardware, cloud, and AI services creating lock-in deserves specific attention for TPRM programs.

When your core provider deploys an AI fraud detection model, several things may be happening without your knowledge:

  • The model may be calling external AI APIs (OpenAI, Google Vertex, Anthropic Claude) to generate risk scores
  • Customer transaction data may be transmitted to third-party model providers as part of scoring
  • The model may be updated without notification, changing its behavior in ways that affect your regulatory outcomes
  • The subcontracting chain for AI components may extend multiple layers beyond your direct vendor

GAO Report GAO-25-107197, published May 2025, highlighted an analogous problem: the NCUA lacks authority to examine technology service providers despite credit unions’ increasing reliance on them for AI-driven services — meaning there’s regulatory coverage gap for exactly this kind of embedded AI risk.

Your TPRM due diligence questionnaire for core providers needs to include: what AI capabilities are in the platform, which third-party AI vendors are used to deliver those capabilities, how customer data is handled when third-party AI is called, and what the vendor’s notification obligation is when AI sub-vendors change.


What to Do Now

Step 1: Pull your core provider TPRM files and identify gaps. Compare written agreements against the required elements in OCC Bulletin 2023-17 (data portability, audit rights, subcontracting notification, regulator access, business continuity provisions). Document what’s missing and flag for the next contract renewal.

Step 2: Run a substitutability analysis. Be realistic. What would it actually take your institution to convert core systems? Document the timeline, cost estimate, and staffing requirements. If the honest answer is “2+ years and significant capital outlay,” document that — it changes how you characterize the risk.

Step 3: Map AI bundling. Ask your core provider in writing: which AI capabilities are included in the platform, which third-party AI vendors are involved, and how is customer data handled when those AI calls are made? Get the answers in writing before your next examination.

Step 4: Update concentration risk reporting. Board and management reporting should explicitly identify core providers as concentration risks, document the bank’s current options if those relationships fail, and note any gaps between current contract terms and the interagency guidance requirements.

Step 5: Track the OCC’s response to the RFI. The comment period closed January 27, 2026. The OCC’s guidance, rulemaking, or supervisory letter that follows from Bulletin 2025-39 is likely to shape examination expectations in 2026–2027. When it’s published, it will need to be incorporated into your TPRM program.


So What?

The OCC’s RFI is not routine. Agencies don’t publish requests for information about vendor relationships unless they intend to do something about what they learn. For community banks and the fintechs that partner with them, the signal is clear: concentration in core providers — and the AI bundling that’s deepening those dependencies — is moving up the examination priority list.

The gap between what most TPRM programs say about core providers and what the 2023 interagency guidance actually requires is real and documentable. Contract terms, substitutability analysis, fourth-party AI mapping, and board-level reporting are the areas examiners will check first.

If you’re a compliance practitioner reviewing your TPRM program for core provider gaps, a structured due diligence questionnaire and documented concentration risk analysis is the starting point. The TPRM Kit includes due diligence templates and concentration risk documentation frameworks built to the 2023 interagency guidance requirements.

Also worth reading: what TPRM examiners are finding three years into the interagency guidance, how fourth-party risk applies after Synapse, and what cloud provider concentration risk looks like under OCC examination.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is OCC Bulletin 2025-39 about?
OCC Bulletin 2025-39, published November 28, 2025 (Federal Register Document 2025-21333), is a Request for Information asking the public — particularly community banks — to comment on their relationships with core service providers and other technology vendors. The OCC specifically raised concerns about concentration risk from reliance on a small number of core providers, difficulty keeping pace with AI innovation, the ability to switch providers when needed, and whether current contract terms adequately protect banks. The comment period closed January 27, 2026.
How is core provider concentration risk different from cloud concentration risk?
Cloud concentration risk (covered under OCC/FDIC guidance for AWS, Azure, GCP) is about infrastructure hosting and compute. Core provider concentration risk is about the banking operating system itself — the platform that runs loan origination, deposit accounts, payments, general ledger, and increasingly AI-driven services. A cloud outage affects availability. A core provider failure or forced transition affects operational continuity, regulatory reporting, and customer-facing operations at the most fundamental level. Switching a cloud provider takes months; switching a core banking system realistically takes 12–24 months or longer, during which both systems must run in parallel.
What does the OCC TPRM interagency guidance say about concentration risk?
OCC Bulletin 2023-17 and the interagency guidance (June 2023) explicitly require banking organizations to assess concentration risk — including situations where a significant number of institutions rely on the same third party, or where a single third party supports multiple critical functions. The guidance directs institutions to consider whether adequate alternatives are available if the third party is unable to perform and whether the bank could transition smoothly if needed. For core providers, this substitutability analysis is particularly challenging.
What TPRM documentation gaps do examiners find on core providers?
The most common gaps identified in examination findings include: (1) no documented criticality designation for core providers — or a designation made years ago that hasn't been revisited since the vendor added AI services; (2) no substitutability analysis that accounts for realistic transition timelines; (3) written agreements that predate the 2023 interagency guidance and are missing required elements on business continuity, subcontracting, and regulator access; (4) no process for re-assessment when a core provider is acquired, changes its service architecture, or bundles new third-party AI models into the platform; and (5) no board-level reporting on core provider concentration as a standalone risk.
What should financial institutions actually review in core provider contracts?
The interagency TPRM guidance identifies specific contract provisions required for critical activities. For core providers, the highest-priority terms to review are: (1) exit assistance and data portability — can you actually extract your data in a usable format on a reasonable timeline at reasonable cost?; (2) notification and transparency obligations when the provider experiences a security incident or subcontracts core functions to a new sub-vendor; (3) audit rights — both the bank's right to audit and the regulator's access rights; (4) change-in-control provisions — what happens to your terms and service levels if the provider is acquired?; (5) SLA remedies that are meaningful, not nominal.
Does the OCC RFI mean core provider concentration is being examined differently?
Yes. The OCC's publication of Bulletin 2025-39 signaled that examiners are moving beyond checking whether a bank has a TPRM program to checking whether the program adequately addresses the bank's most material concentration exposures. The OCC Fall 2025 Semiannual Risk Perspective specifically highlighted concentration risk from third-party vendor reliance as an elevated supervisory concern. Expect examiners to ask community banks specifically: which vendors are you most dependent on, what happens if they fail, and how long would it actually take you to transition.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.