Feature Third-Party Risk
Federal Regulators Just Listed the Specific Contract Terms in Your Core System Agreement That Will Draw Examiner Scrutiny. Here's What to Check.
On September 11, 2026, the OCC, Federal Reserve, and FDIC issued a joint statement naming four specific contract practices used by core service providers that regulators intend to scrutinize directly. Deconversion fees, back-billing windows, opaque pricing, and integration restrictions are now on the examiner checklist. Here's how to review your core provider agreement before they do.
Table of Contents
TL;DR
- On September 11, 2026, the OCC, Fed, and FDIC issued a joint statement (OCC Bulletin 2026-47) listing four specific contract practices used by core service providers that will draw direct examiner scrutiny
- Opaque pricing, back-billing windows, unsupported deconversion fees, and integration restrictions are the four named practices
- Core providers (Jack Henry, FIS, Fiserv) may qualify as “institution-affiliated parties” subject to direct regulatory enforcement — a significant escalation from treating vendor risk as purely a bank’s problem
- The statement was issued alongside proposed TPRM guidance (comment deadline November 16) and a companion community bank guide
- The practical action: review your core provider contracts for each of the four categories before your next TPRM examination
Community banks have known for years that their core provider contracts are bad. The fees are opaque. Deconversion costs are enormous and undefined. The billing can include charges from billing periods that ended before the current compliance team was hired. Integration limitations lock them out of fintech partnerships that their examiners expect them to be able to manage.
What changed on September 11, 2026 was that the OCC, Federal Reserve, and FDIC said it in writing.
The joint statement on community banks’ engagement with core service providers — issued as OCC Bulletin 2026-47 alongside the proposed interagency TPRM guidance overhaul — named four specific contract practices that the agencies will scrutinize. Not in a general way. In a named-category, examiners-will-ask-about-this way.
And then it raised the stakes: core providers who engage in these practices may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act and face direct regulatory enforcement.
That’s a change in posture. For the better part of two decades, vendor management examination questions have focused on what the bank did: did you conduct due diligence? Do you have a monitoring program? Do you have an exit plan? The September 2026 statement signals that regulators are now prepared to ask what the vendor did — and act on the answer.
Why Core Providers Are Different From Every Other Vendor
Most third-party risk management frameworks treat vendor relationships on a spectrum by criticality. A payment processor that handles customer transactions is more critical than an office supplies vendor. The assessment depth, the contractual protections, and the ongoing monitoring all scale with the criticality and harm potential of the relationship.
Core banking systems — general ledger, deposit and loan accounting, transaction processing, customer record management — sit at the top of that criticality scale. They are not just important. They are the operational infrastructure through which the bank conducts banking.
A few providers dominate this market. Jack Henry & Associates, FIS, and Fiserv collectively serve a substantial majority of community banks and credit unions in the United States. Market concentration that high creates structural leverage: if a bank’s core provider is one of three realistic options, and each contract has a five- to ten-year term with multi-million-dollar deconversion costs, the bank’s ability to negotiate, challenge pricing, or exit a bad relationship is constrained in ways that don’t apply to ordinary vendor relationships.
The joint statement acknowledged this directly. The agencies noted that the limited market means community banks have “limited negotiating power and limited ability to obtain due diligence information, negotiate contract terms, and monitor their providers.” That market structure reality is the backdrop for why regulators are addressing core provider contracts specifically rather than treating this as just another TPRM matter.
The Four Practices Regulators Called Out
1. Opaque Pricing Structures
Core service contracts typically bundle services into packages with complex fee structures — per-item charges for transactions, monthly minimums, tiered pricing that adjusts based on volume thresholds, and add-on fees for modules that weren’t priced into the base contract. The problem isn’t complexity per se; it’s when the pricing structure is designed to make total cost of ownership difficult to compute and impossible to verify against actual usage.
Opaque pricing means a bank can’t answer the following questions from its own contract documentation:
- What am I paying per transaction for [specific service]?
- How does pricing change if my transaction volume increases or decreases by 20%?
- What services am I contracted for vs. what services am I currently using?
- How would my total cost change if I added [new product]?
If your compliance team or contract owner can’t answer these questions from the contract documentation, you have an opaque pricing structure. That’s the first category regulators named.
2. Opaque Billing Practices Including Extensive Back-Billing Windows
Back billing — invoicing for services rendered in prior billing periods that weren’t invoiced at the time — was called out specifically because it creates unpredictable cost exposure with no practical ability to verify or dispute.
The typical back-billing provision in a core services contract will say something like “Provider may invoice for services rendered in prior billing periods.” It often doesn’t specify a maximum window. In practice, this can mean a bank receives an invoice in Q4 that covers transactions from Q1 or Q2 — a period the bank’s finance and compliance team may not be able to reconstruct.
Back billing also intersects with the examination cycle. If a regulator identifies that a bank paid a substantial unexpected invoice from a prior period, they’ll ask about the bank’s monitoring and invoice reconciliation process. A bank that can’t explain what it’s being billed for — or why — has a vendor management gap regardless of the back-billing limitation.
What the contract should say: a defined maximum back-billing window (30-90 days is typical in well-negotiated agreements) and an explicit provision that charges not invoiced within that window are waived.
3. Unsupported or Contractually Undefined Core Deconversion Fees
This is the one that draws the most attention — and for good reason. Deconversion fees are what a core provider charges when a bank terminates the relationship and migrates to a new system. They cover data extraction, migration support, and the cost of the provider’s transition assistance.
Defined, proportionate, and contractually specified deconversion fees are a legitimate business practice. Undefined deconversion fees — where the contract says the bank will owe “deconversion fees” without specifying how they’re calculated or capped — create leveraged uncertainty. When a bank is considering whether to terminate its core provider, an undefined fee exposure of potentially millions of dollars is a powerful reason not to leave, even if the relationship is failing.
The joint statement highlighted a specific aggravating circumstance: deconversion fees being assessed when the core provider had itself breached the contract, failed to meet SLA commitments, or potentially contributed to the bank’s regulatory violations. Regulators are concerned about providers using undefined fee exposure to extract payment from institutions even when the grounds for termination were the provider’s own failures.
What the contract should say: a defined fee calculation methodology, a fee cap or schedule, and explicit provisions reducing or eliminating deconversion fees when termination is triggered by the provider’s material breach or sustained SLA failure.
4. Excessive Limitations on Third-Party Integrations
Core systems are the authoritative source for most customer and transaction data. A bank’s ability to use fintech partners, digital banking tools, risk management systems, and modern analytical platforms depends on those partners being able to connect to the core via APIs or other interfaces.
Some core providers contractually restrict this. The restrictions take different forms: approval requirements for each integration (with no defined timeline or standard for approval), fees for integration access that make third-party connectivity economically impractical, and technical designs that don’t expose data through standard APIs at all.
These restrictions create direct compliance exposure. Regulators expect banking organizations to maintain robust oversight of fintech partnerships, BSA/AML monitoring, and customer data governance — all of which increasingly depend on modern integration capabilities. If your core provider’s contract prevents you from connecting the tools you need to run your compliance program, that’s not just a business limitation. It’s a vendor risk that affects your ability to meet regulatory expectations.
The Institution-Affiliated Party Risk: What It Means
The legal theory underlying the agencies’ enforcement threat is worth understanding.
Under Section 8 of the Federal Deposit Insurance Act (12 U.S.C. § 1818), the banking agencies can take enforcement action against an “institution-affiliated party” — defined to include any person who participates in the conduct of the affairs of an insured depository institution. This has historically been applied to officers, directors, employees, and sometimes consultants.
The joint statement asserts that certain core providers — given the degree to which they operate critical banking infrastructure and are integrated into the day-to-day conduct of banking operations — may meet this definition. If a core provider’s contract practices or service failures cause a bank to violate regulations or engage in unsafe or unsound banking, the provider’s participation in the conduct of that bank’s affairs could support enforcement authority.
This is not theoretical. The OCC, FDIC, and Federal Reserve have existing authority to examine certain technology service providers directly under the Bank Service Company Act. The institution-affiliated party theory extends enforcement authority beyond examination to cease-and-desist orders, civil money penalties, and removal orders.
For community banks reviewing their core provider relationships: the practical implication is that regulators are prepared to use multiple levers against vendors who create supervisory risk. That changes the negotiating dynamic — a provider that knows it faces potential direct enforcement for its contract practices has a different calculus than one that treats bank unhappiness as the bank’s problem to manage.
How This Connects to the Proposed TPRM Guidance Overhaul
The joint statement was issued alongside the September 11, 2026 proposed interagency TPRM guidance that would replace the 2023 framework — covered in detail in the September 26 post on risk-proportionate vendor oversight. The comment deadline for that proposed guidance is November 16, 2026.
The proposed TPRM guidance’s central concept is risk-proportionate oversight: apply more intensive due diligence and monitoring to higher-risk relationships, and calibrate oversight for lower-risk vendors appropriately. The joint statement on core providers establishes that core banking relationships are unambiguously in the highest-risk category — regardless of the overall move toward risk-proportionate simplification.
For compliance teams building their comment letters on the proposed TPRM guidance: the core provider dynamic is a useful test case for the risk-proportionate framework’s limitations. Even in a risk-based model, some relationships are critical enough that the oversight expectations don’t scale down. The agencies’ own companion statement makes that explicit.
So What? What to Review Before Your Next Examination
The four practices the agencies identified map directly to a contract review checklist. Before your next TPRM examination, pull your core provider agreement and work through these items:
| Contract Element | What to Look For | What to Ask Your Provider |
|---|---|---|
| Pricing schedule | Is every service item defined with a clear unit price? Can you calculate total cost from the contract? | Can you provide a fee schedule that maps to our current usage? |
| Back-billing window | Does the contract specify a maximum back-billing period? | Will you agree to a 30/60-day maximum back-billing window in a contract amendment? |
| Deconversion fees | Is the deconversion fee defined numerically or by formula? Is there a cap? | What would deconversion cost us today, and how is that calculated? |
| Integration terms | What does the contract say about third-party integrations? Are there approval requirements, fees, or technical barriers? | What is your API availability and what integrations have you approved for your client base? |
Document the results of this review. If you find gaps — undefined fees, missing caps, restrictive integration terms — that documentation becomes the basis for a contract renegotiation conversation with the provider and an accurate representation to examiners about what you’ve identified and what you’re doing about it.
The October 1 post on vendor concentration risk and the September 26 TPRM guidance post lay out the broader framework. This joint statement gives you the specific contract terms that regulators will ask about by name.
Your examiner has the same list. Walk through it before they do.
Key Sources
- OCC Bulletin 2026-47: Joint Statement on Community Banks’ Engagement with Core Service Providers
- FDIC: Joint Statement on Community Banks’ Engagement with Core Service Providers
- Mayer Brown: Federal Banking Agencies Issue Proposed Updates to Interagency TPRM Guidance and Joint Statement on Core Service Providers
- Winthrop & Weinstine: Federal Banking Agencies Propose Overhaul of Third-Party Risk Management Guidance, Issue Community Bank Guide, and Heighten Focus on Core Service Providers
- Wallcrest Media: Regulators Have Listed What They Will Look At in Core Provider Contracts
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the September 2026 joint statement on core service providers say?
What is a deconversion fee and why are regulators focused on it?
What is 'back billing' and how should it be addressed in a core services contract?
Can regulators take enforcement action directly against Jack Henry, FIS, or Fiserv?
Does this joint statement apply to fintechs or only banks?
How does this relate to the September 2026 proposed interagency TPRM guidance?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Your TPRM Program Classifies Vendor Risk. It Doesn't Measure Vendor Concentration. Here's What Examiners Are Starting to Ask For.
The September 2026 interagency TPRM proposal and the joint statement on core providers both point toward concentration risk analysis — but most TPRM programs only assess individual vendor risk, not portfolio-level concentration. Here's the analysis gap and what to build.
Oct 1, 2026
Third-Party Risk
Four Agencies Just Proposed to Kill the TPRM Checklist. Here's What 'Risk-Proportionate' Vendor Oversight Actually Means.
On September 11, 2026, the OCC, Federal Reserve, FDIC, and NCUA jointly proposed new interagency TPRM guidance to replace the 2023 framework. The core change: stop treating every vendor the same. Comments are due November 16. Here's what it means for your program.
Sep 26, 2026
Third-Party Risk
The Regulators Just Proposed Scrapping the 2023 TPRM Guidance. Here's What the Replacement Says.
On September 11, 2026, the OCC, Fed, FDIC, and NCUA proposed to rescind and replace the 2023 interagency TPRM guidance. The new framework shifts from prescriptive checklists to a harm-based, risk-tailored standard. Comments due November 16.
Sep 18, 2026