Feature Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Table of Contents
In November 2025, the OCC published Bulletin 2025-39, an unusual document. Rather than issuing guidance or announcing an examination priority, the agency asked questions — specifically, hard questions about community banks’ relationships with the three companies that run most of their core banking operations.
The RFI (published as Federal Register Document 2025-21333) asked community banks to explain their experiences with core service providers: how pricing and contract terms work, what barriers exist to switching, how much visibility banks have into subcontracting decisions, and how vendors are integrating AI into platforms that banks use.
The questions weren’t academic. The OCC doesn’t publish RFIs about things it doesn’t plan to supervise. And the OCC Fall 2025 Semiannual Risk Perspective published the same month was explicit: concentration risk from third-party vendor reliance is an elevated supervisory concern.
If your TPRM program doesn’t address core provider concentration specifically — not cloud concentration, not AI vendor concentration, but the Fiserv/FIS/Jack Henry layer of your stack — you should read this before your next examination.
TL;DR
- OCC Bulletin 2025-39 (November 2025) asked community banks direct questions about concentration risk, switching ability, and AI integration with core service providers — signaling examiner focus
- Core provider concentration risk is structurally different from cloud or AI concentration: switching timelines are 12–24 months, data portability is legally and technically constrained, and these vendors increasingly bundle AI capabilities that import new fourth-party risks
- OCC Bulletin 2023-17 requires written agreements for critical activities to include specific terms most core provider contracts predate — substitutability analysis, exit assistance, and regulator access rights are commonly missing
- The FSB’s October 2025 AI monitoring report flagged that technology vendors bundling hardware, cloud, and AI together are increasing switching costs and limiting interoperability — making substitutability analysis harder every year
Why the OCC Is Asking About This Now
Community banks have long relied on a small number of core processing vendors. Three providers — Fiserv, FIS, and Jack Henry & Associates — serve the substantial majority of community and mid-size U.S. banks. This concentration has existed for years. Why is it an elevated supervisory concern in 2025–2026?
Two structural shifts have made the concentration more acute.
First, the AI bundling problem. Core providers are integrating AI capabilities directly into platforms: fraud detection models, loan origination scoring, deposit analytics, customer service automation. When a bank uses its core provider’s AI-enabled fraud flagging, it’s not just relying on the core banking system. It’s relying on whatever AI models the provider has trained, whatever third-party AI APIs the provider is calling (OpenAI, Google, Anthropic), and whatever data handling decisions the provider has made about customer information.
The Financial Stability Board’s October 2025 AI monitoring report made this point explicitly: technology providers are bundling hardware, cloud, and AI services together in ways that increase switching costs and limit interoperability. The bank didn’t sign up for a multi-layer AI dependency — it signed up for core banking software that quietly added one.
Second, the TPRM gap. Most community bank TPRM programs were built to assess new vendors as they’re onboarded. But core providers have been in place for a decade or more. Their TPRM files reflect the relationship as it existed when they were initially reviewed — before AI bundling, before sub-vendor relationships that didn’t exist five years ago, before the interagency guidance issued in June 2023 required specific contract provisions most of those contracts don’t contain.
Core Provider Concentration Is Not the Same as Cloud Concentration
The existing supervisory focus on cloud concentration risk (AWS, Azure, GCP) created useful frameworks, but those frameworks don’t translate directly to core provider risk. The risk profile is different in ways that matter for your TPRM program.
| Dimension | Cloud Concentration | Core Provider Concentration |
|---|---|---|
| What they control | Compute, storage, networking | Core banking operations, general ledger, payment rails, deposit processing |
| Realistic switching timeline | 6–18 months | 12–24 months minimum; often 2–3 years in practice |
| Data portability | Regulated under contracts; standard formats exist | Proprietary formats common; legal and financial barriers to extraction |
| Regulatory visibility | Cloud providers are well-known to regulators | Core providers often have regulatory examination relationships through bank service provider authority |
| AI integration depth | Separate AI vendors typically used | AI bundled into core banking platform; bank may not know which models are in use |
| Contract vintage | Often negotiated recently | Many contracts predate 2023 interagency TPRM guidance |
| Fourth-party risk | Sub-processors disclosed in DPA | Core provider sub-vendor arrangements often opaque |
The most important distinction is substitutability. OCC Bulletin 2023-17 requires banks to assess whether “adequate alternatives are available” if a critical third party cannot perform. For cloud providers, there’s a credible (if expensive) substitution path. For core providers, the realistic substitution path is so long and resource-intensive that for most community banks, “transition to an alternative” in a crisis is not actually a viable option. That changes the risk calculus for the ongoing monitoring requirements.
What the OCC RFI Questions Reveal About Examination Focus
The OCC’s RFI questions are unusually direct. Reading them as a practitioner — knowing that regulators use RFIs to signal examination priorities — several themes emerge about what examiners are going to ask.
Switching ability. The RFI explicitly asked about “factors that make it difficult to change core service providers, including the financial and operational burden of switching.” Examiners will ask: has your bank documented a realistic transition plan, and does that plan account for the actual timeline and resource requirements rather than a theoretical one?
Pricing and contract terms. The RFI asked about “core service providers’ pricing practices, including any changes in pricing and the factors driving those changes.” This is asking whether banks have negotiating leverage and whether contract terms are fair. Examiners are likely to start reviewing whether banks have meaningful SLA remedies, whether price increases are constrained, and whether data portability costs are reasonable.
AI integration transparency. The OCC specifically asked about the “pace of innovation in AI” and how banks are “keeping pace.” For TPRM programs, this translates to: does your due diligence process capture AI capabilities being added to existing platforms, and do you have visibility into the AI sub-vendors your core provider is using?
Subcontracting. The RFI asked about banks’ visibility into “service providers’ subcontracting arrangements.” This directly maps to the fourth-party risk requirements in the 2023 interagency guidance. For core providers, this means understanding which payment networks, data centers, fraud model providers, and AI vendors your core provider depends on.
What TPRM Programs Are Missing on Core Providers
If you review your current core provider TPRM documentation against the 2023 interagency guidance, most programs will show gaps in four areas.
Written agreement terms. OCC Bulletin 2023-17 requires that agreements for critical activities include: business continuity and contingency plans, data ownership and the bank’s right to access data in usable formats, subcontracting provisions requiring notification and approval, the bank’s and regulators’ right to audit, and adequate notice before service termination or significant changes. Most core provider contracts — particularly those signed before 2023 — don’t contain all of these provisions. The next contract renewal is the opportunity to negotiate them in; waiting is not a compliance strategy.
Substitutability analysis. The guidance requires an assessment of whether the bank could transition if needed. This analysis should be realistic — based on the actual timeline it would take your bank to convert core systems, the cost, the staff required, and whether the bank has documented a transition plan. A two-sentence substitutability assessment that says “alternatives exist in the market” doesn’t satisfy the guidance.
Critical activity re-assessment. If your core provider has added AI-powered services since you last reviewed the relationship, that’s a material change that may expand the criticality scope. Adding a fraud detection model built on a third-party AI API introduces a fourth-party AI dependency that wasn’t in your original assessment. The interagency guidance requires re-assessment when “the nature of the relationship changes materially.”
Board-level concentration reporting. The guidance requires ongoing monitoring that escalates concentrated risk to senior management and the board. Core provider dependency is rarely reported as a standalone concentration risk — it’s buried in a vendor inventory. Boards should see an explicit statement of which providers represent existential dependencies and what the bank’s options are if those relationships fail.
The Fourth-Party AI Problem Inside Core Providers
The FSB’s concern about bundled hardware, cloud, and AI services creating lock-in deserves specific attention for TPRM programs.
When your core provider deploys an AI fraud detection model, several things may be happening without your knowledge:
- The model may be calling external AI APIs (OpenAI, Google Vertex, Anthropic Claude) to generate risk scores
- Customer transaction data may be transmitted to third-party model providers as part of scoring
- The model may be updated without notification, changing its behavior in ways that affect your regulatory outcomes
- The subcontracting chain for AI components may extend multiple layers beyond your direct vendor
GAO Report GAO-25-107197, published May 2025, highlighted an analogous problem: the NCUA lacks authority to examine technology service providers despite credit unions’ increasing reliance on them for AI-driven services — meaning there’s regulatory coverage gap for exactly this kind of embedded AI risk.
Your TPRM due diligence questionnaire for core providers needs to include: what AI capabilities are in the platform, which third-party AI vendors are used to deliver those capabilities, how customer data is handled when third-party AI is called, and what the vendor’s notification obligation is when AI sub-vendors change.
What to Do Now
Step 1: Pull your core provider TPRM files and identify gaps. Compare written agreements against the required elements in OCC Bulletin 2023-17 (data portability, audit rights, subcontracting notification, regulator access, business continuity provisions). Document what’s missing and flag for the next contract renewal.
Step 2: Run a substitutability analysis. Be realistic. What would it actually take your institution to convert core systems? Document the timeline, cost estimate, and staffing requirements. If the honest answer is “2+ years and significant capital outlay,” document that — it changes how you characterize the risk.
Step 3: Map AI bundling. Ask your core provider in writing: which AI capabilities are included in the platform, which third-party AI vendors are involved, and how is customer data handled when those AI calls are made? Get the answers in writing before your next examination.
Step 4: Update concentration risk reporting. Board and management reporting should explicitly identify core providers as concentration risks, document the bank’s current options if those relationships fail, and note any gaps between current contract terms and the interagency guidance requirements.
Step 5: Track the OCC’s response to the RFI. The comment period closed January 27, 2026. The OCC’s guidance, rulemaking, or supervisory letter that follows from Bulletin 2025-39 is likely to shape examination expectations in 2026–2027. When it’s published, it will need to be incorporated into your TPRM program.
So What?
The OCC’s RFI is not routine. Agencies don’t publish requests for information about vendor relationships unless they intend to do something about what they learn. For community banks and the fintechs that partner with them, the signal is clear: concentration in core providers — and the AI bundling that’s deepening those dependencies — is moving up the examination priority list.
The gap between what most TPRM programs say about core providers and what the 2023 interagency guidance actually requires is real and documentable. Contract terms, substitutability analysis, fourth-party AI mapping, and board-level reporting are the areas examiners will check first.
If you’re a compliance practitioner reviewing your TPRM program for core provider gaps, a structured due diligence questionnaire and documented concentration risk analysis is the starting point. The TPRM Kit includes due diligence templates and concentration risk documentation frameworks built to the 2023 interagency guidance requirements.
Also worth reading: what TPRM examiners are finding three years into the interagency guidance, how fourth-party risk applies after Synapse, and what cloud provider concentration risk looks like under OCC examination.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is OCC Bulletin 2025-39 about?
How is core provider concentration risk different from cloud concentration risk?
What does the OCC TPRM interagency guidance say about concentration risk?
What TPRM documentation gaps do examiners find on core providers?
What should financial institutions actually review in core provider contracts?
Does the OCC RFI mean core provider concentration is being examined differently?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Fourth-Party Risk After Synapse: What OCC and FDIC Now Expect from Your Subcontractor Oversight Program
Synapse collapsed and 100,000+ customers lost access to $265M in deposits they thought were FDIC-insured. The cause wasn't fraud — it was middleware risk nobody was watching. Here's what OCC and FDIC now expect from your fourth-party and subcontractor oversight program.
Jul 20, 2026