Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Third-Party Risk

Federal Regulators Just Listed the Specific Contract Terms in Your Core System Agreement That Will Draw Examiner Scrutiny. Here's What to Check.

On September 11, 2026, the OCC, Federal Reserve, and FDIC issued a joint statement naming four specific contract practices used by core service providers that regulators intend to scrutinize directly. Deconversion fees, back-billing windows, opaque pricing, and integration restrictions are now on the examiner checklist. Here's how to review your core provider agreement before they do.

By Rebecca Leung · October 4, 2026 ·
Table of Contents

TL;DR

  • On September 11, 2026, the OCC, Fed, and FDIC issued a joint statement (OCC Bulletin 2026-47) listing four specific contract practices used by core service providers that will draw direct examiner scrutiny
  • Opaque pricing, back-billing windows, unsupported deconversion fees, and integration restrictions are the four named practices
  • Core providers (Jack Henry, FIS, Fiserv) may qualify as “institution-affiliated parties” subject to direct regulatory enforcement — a significant escalation from treating vendor risk as purely a bank’s problem
  • The statement was issued alongside proposed TPRM guidance (comment deadline November 16) and a companion community bank guide
  • The practical action: review your core provider contracts for each of the four categories before your next TPRM examination

Community banks have known for years that their core provider contracts are bad. The fees are opaque. Deconversion costs are enormous and undefined. The billing can include charges from billing periods that ended before the current compliance team was hired. Integration limitations lock them out of fintech partnerships that their examiners expect them to be able to manage.

What changed on September 11, 2026 was that the OCC, Federal Reserve, and FDIC said it in writing.

The joint statement on community banks’ engagement with core service providers — issued as OCC Bulletin 2026-47 alongside the proposed interagency TPRM guidance overhaul — named four specific contract practices that the agencies will scrutinize. Not in a general way. In a named-category, examiners-will-ask-about-this way.

And then it raised the stakes: core providers who engage in these practices may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act and face direct regulatory enforcement.

That’s a change in posture. For the better part of two decades, vendor management examination questions have focused on what the bank did: did you conduct due diligence? Do you have a monitoring program? Do you have an exit plan? The September 2026 statement signals that regulators are now prepared to ask what the vendor did — and act on the answer.


Why Core Providers Are Different From Every Other Vendor

Most third-party risk management frameworks treat vendor relationships on a spectrum by criticality. A payment processor that handles customer transactions is more critical than an office supplies vendor. The assessment depth, the contractual protections, and the ongoing monitoring all scale with the criticality and harm potential of the relationship.

Core banking systems — general ledger, deposit and loan accounting, transaction processing, customer record management — sit at the top of that criticality scale. They are not just important. They are the operational infrastructure through which the bank conducts banking.

A few providers dominate this market. Jack Henry & Associates, FIS, and Fiserv collectively serve a substantial majority of community banks and credit unions in the United States. Market concentration that high creates structural leverage: if a bank’s core provider is one of three realistic options, and each contract has a five- to ten-year term with multi-million-dollar deconversion costs, the bank’s ability to negotiate, challenge pricing, or exit a bad relationship is constrained in ways that don’t apply to ordinary vendor relationships.

The joint statement acknowledged this directly. The agencies noted that the limited market means community banks have “limited negotiating power and limited ability to obtain due diligence information, negotiate contract terms, and monitor their providers.” That market structure reality is the backdrop for why regulators are addressing core provider contracts specifically rather than treating this as just another TPRM matter.


The Four Practices Regulators Called Out

1. Opaque Pricing Structures

Core service contracts typically bundle services into packages with complex fee structures — per-item charges for transactions, monthly minimums, tiered pricing that adjusts based on volume thresholds, and add-on fees for modules that weren’t priced into the base contract. The problem isn’t complexity per se; it’s when the pricing structure is designed to make total cost of ownership difficult to compute and impossible to verify against actual usage.

Opaque pricing means a bank can’t answer the following questions from its own contract documentation:

  • What am I paying per transaction for [specific service]?
  • How does pricing change if my transaction volume increases or decreases by 20%?
  • What services am I contracted for vs. what services am I currently using?
  • How would my total cost change if I added [new product]?

If your compliance team or contract owner can’t answer these questions from the contract documentation, you have an opaque pricing structure. That’s the first category regulators named.

2. Opaque Billing Practices Including Extensive Back-Billing Windows

Back billing — invoicing for services rendered in prior billing periods that weren’t invoiced at the time — was called out specifically because it creates unpredictable cost exposure with no practical ability to verify or dispute.

The typical back-billing provision in a core services contract will say something like “Provider may invoice for services rendered in prior billing periods.” It often doesn’t specify a maximum window. In practice, this can mean a bank receives an invoice in Q4 that covers transactions from Q1 or Q2 — a period the bank’s finance and compliance team may not be able to reconstruct.

Back billing also intersects with the examination cycle. If a regulator identifies that a bank paid a substantial unexpected invoice from a prior period, they’ll ask about the bank’s monitoring and invoice reconciliation process. A bank that can’t explain what it’s being billed for — or why — has a vendor management gap regardless of the back-billing limitation.

What the contract should say: a defined maximum back-billing window (30-90 days is typical in well-negotiated agreements) and an explicit provision that charges not invoiced within that window are waived.

3. Unsupported or Contractually Undefined Core Deconversion Fees

This is the one that draws the most attention — and for good reason. Deconversion fees are what a core provider charges when a bank terminates the relationship and migrates to a new system. They cover data extraction, migration support, and the cost of the provider’s transition assistance.

Defined, proportionate, and contractually specified deconversion fees are a legitimate business practice. Undefined deconversion fees — where the contract says the bank will owe “deconversion fees” without specifying how they’re calculated or capped — create leveraged uncertainty. When a bank is considering whether to terminate its core provider, an undefined fee exposure of potentially millions of dollars is a powerful reason not to leave, even if the relationship is failing.

The joint statement highlighted a specific aggravating circumstance: deconversion fees being assessed when the core provider had itself breached the contract, failed to meet SLA commitments, or potentially contributed to the bank’s regulatory violations. Regulators are concerned about providers using undefined fee exposure to extract payment from institutions even when the grounds for termination were the provider’s own failures.

What the contract should say: a defined fee calculation methodology, a fee cap or schedule, and explicit provisions reducing or eliminating deconversion fees when termination is triggered by the provider’s material breach or sustained SLA failure.

4. Excessive Limitations on Third-Party Integrations

Core systems are the authoritative source for most customer and transaction data. A bank’s ability to use fintech partners, digital banking tools, risk management systems, and modern analytical platforms depends on those partners being able to connect to the core via APIs or other interfaces.

Some core providers contractually restrict this. The restrictions take different forms: approval requirements for each integration (with no defined timeline or standard for approval), fees for integration access that make third-party connectivity economically impractical, and technical designs that don’t expose data through standard APIs at all.

These restrictions create direct compliance exposure. Regulators expect banking organizations to maintain robust oversight of fintech partnerships, BSA/AML monitoring, and customer data governance — all of which increasingly depend on modern integration capabilities. If your core provider’s contract prevents you from connecting the tools you need to run your compliance program, that’s not just a business limitation. It’s a vendor risk that affects your ability to meet regulatory expectations.


The Institution-Affiliated Party Risk: What It Means

The legal theory underlying the agencies’ enforcement threat is worth understanding.

Under Section 8 of the Federal Deposit Insurance Act (12 U.S.C. § 1818), the banking agencies can take enforcement action against an “institution-affiliated party” — defined to include any person who participates in the conduct of the affairs of an insured depository institution. This has historically been applied to officers, directors, employees, and sometimes consultants.

The joint statement asserts that certain core providers — given the degree to which they operate critical banking infrastructure and are integrated into the day-to-day conduct of banking operations — may meet this definition. If a core provider’s contract practices or service failures cause a bank to violate regulations or engage in unsafe or unsound banking, the provider’s participation in the conduct of that bank’s affairs could support enforcement authority.

This is not theoretical. The OCC, FDIC, and Federal Reserve have existing authority to examine certain technology service providers directly under the Bank Service Company Act. The institution-affiliated party theory extends enforcement authority beyond examination to cease-and-desist orders, civil money penalties, and removal orders.

For community banks reviewing their core provider relationships: the practical implication is that regulators are prepared to use multiple levers against vendors who create supervisory risk. That changes the negotiating dynamic — a provider that knows it faces potential direct enforcement for its contract practices has a different calculus than one that treats bank unhappiness as the bank’s problem to manage.


How This Connects to the Proposed TPRM Guidance Overhaul

The joint statement was issued alongside the September 11, 2026 proposed interagency TPRM guidance that would replace the 2023 framework — covered in detail in the September 26 post on risk-proportionate vendor oversight. The comment deadline for that proposed guidance is November 16, 2026.

The proposed TPRM guidance’s central concept is risk-proportionate oversight: apply more intensive due diligence and monitoring to higher-risk relationships, and calibrate oversight for lower-risk vendors appropriately. The joint statement on core providers establishes that core banking relationships are unambiguously in the highest-risk category — regardless of the overall move toward risk-proportionate simplification.

For compliance teams building their comment letters on the proposed TPRM guidance: the core provider dynamic is a useful test case for the risk-proportionate framework’s limitations. Even in a risk-based model, some relationships are critical enough that the oversight expectations don’t scale down. The agencies’ own companion statement makes that explicit.


So What? What to Review Before Your Next Examination

The four practices the agencies identified map directly to a contract review checklist. Before your next TPRM examination, pull your core provider agreement and work through these items:

Contract ElementWhat to Look ForWhat to Ask Your Provider
Pricing scheduleIs every service item defined with a clear unit price? Can you calculate total cost from the contract?Can you provide a fee schedule that maps to our current usage?
Back-billing windowDoes the contract specify a maximum back-billing period?Will you agree to a 30/60-day maximum back-billing window in a contract amendment?
Deconversion feesIs the deconversion fee defined numerically or by formula? Is there a cap?What would deconversion cost us today, and how is that calculated?
Integration termsWhat does the contract say about third-party integrations? Are there approval requirements, fees, or technical barriers?What is your API availability and what integrations have you approved for your client base?

Document the results of this review. If you find gaps — undefined fees, missing caps, restrictive integration terms — that documentation becomes the basis for a contract renegotiation conversation with the provider and an accurate representation to examiners about what you’ve identified and what you’re doing about it.

The October 1 post on vendor concentration risk and the September 26 TPRM guidance post lay out the broader framework. This joint statement gives you the specific contract terms that regulators will ask about by name.

Your examiner has the same list. Walk through it before they do.


Key Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the September 2026 joint statement on core service providers say?
The Federal Reserve, FDIC, and OCC jointly issued a statement on September 11, 2026 (OCC Bulletin 2026-47) identifying four categories of contract practices by core service providers that create supervisory concern: opaque pricing structures, extensive back-billing windows, unsupported deconversion fees, and restrictions on third-party integrations. The agencies stated they will factor a core provider's contract practices into their supervisory resource allocation decisions and noted that core providers may qualify as 'institution-affiliated parties' subject to direct enforcement action under the Federal Deposit Insurance Act.
What is a deconversion fee and why are regulators focused on it?
A core deconversion fee is the charge a core service provider bills when a bank or credit union terminates the contract and migrates to a different core system. Deconversion fees can run into the millions for community banks and are often not clearly defined in the original contract. The joint statement specifically flagged 'unsupported or contractually undefined' deconversion fees — particularly in situations where the core provider had itself breached the contract, failed to meet SLA commitments, or potentially contributed to the bank's regulatory violations. Regulators are concerned that large, undefined deconversion fees effectively trap banks in relationships they would otherwise exit.
What is 'back billing' and how should it be addressed in a core services contract?
Back billing refers to a core provider's practice of charging a banking organization for services rendered in prior billing periods that were not invoiced at the time. The joint statement called out 'extensive back billing windows' as problematic — meaning contracts that allow core providers to submit invoices for services provided months or years earlier. For a community bank operating on tight margins, a surprise invoice for 18 months of historical usage can create material budget disruption. Contracts should define a maximum back-billing window (typically 30-90 days) and require that charges not invoiced within that window are forfeited.
Can regulators take enforcement action directly against Jack Henry, FIS, or Fiserv?
Potentially yes, under the 'institution-affiliated party' theory. Under the Federal Deposit Insurance Act, a person who 'participates in the conduct of the affairs' of an insured institution can be treated as an institution-affiliated party subject to enforcement action by the banking agencies. The joint statement explicitly noted that core providers — given the degree to which they operate core banking infrastructure and participate in the daily conduct of banking operations — may qualify. This is not a new legal authority, but it is a direct regulatory signal that the agencies are prepared to use it against vendors whose contract practices create supervisory risk for the institutions they serve.
Does this joint statement apply to fintechs or only banks?
The statement was specifically addressed to 'community banking organizations' — Federal Reserve-supervised institutions with generally less than $30 billion in assets and similar OCC and FDIC-supervised institutions. Fintechs that operate as bank holding companies, state member banks, national banks, or that are examined by the OCC or FDIC as subsidiaries of banking organizations are within scope. Fintechs operating purely as technology companies without a bank charter or subsidiary structure are not directly covered by this statement, though their bank partners may face examiner questions about core provider contracts that cascade into questions about fintech program oversight.
How does this relate to the September 2026 proposed interagency TPRM guidance?
The joint statement was issued alongside the proposed interagency TPRM guidance that would replace the 2023 framework (comment deadline November 16, 2026). The proposed guidance introduces a risk-proportionate approach to vendor oversight. The joint statement is a companion document that specifically calls out core service providers as a category where the agencies see elevated risk — despite the risk-proportionate framing that might suggest less intense oversight for some vendor relationships. The message: risk-proportionate doesn't mean lower scrutiny for relationships with your core banking system. It means calibrating depth to actual risk, and core systems present actual risk.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.