On September 11, 2026, the Federal Reserve, FDIC and OCC issued a joint statement on community banks' engagement with core service providers. Regulators have now said explicitly that a core provider's transparency, contract terms and technology will shape how closely that provider is supervised. Community banks gain a clearer basis to push back, and core providers get a clear signal that more scrutiny is coming. That signal may lay the groundwork for stronger oversight later.
Why regulators spoke up
Core providers are a community bank's most important and highest-risk third-party relationships. They run the systems behind transaction processing, account management, payments, online banking and compliance reporting, and many banks couldn't operate without them. The market is highly concentrated: according to the Federal Reserve Bank of Kansas City, the three largest core providers served more than 70% of banks in 2022, and the largest alone served 42%. The OCC cited those figures when it asked the industry for input in November 2025 (90 FR 54882). With that little competition, a single community bank has limited room to negotiate, and banks told regulators they struggle to get due diligence information, fair contracts and effective monitoring. This statement is the agencies' response.
What was already in place
Examining core providers isn't new. Under the Bank Service Company Act, the agencies have long examined technology service providers, and client banks can request those exam reports through their regulator. Those exams have focused on how well the provider runs its own operations: audit, management, development and support. Pricing, billing and contract terms were mostly treated as business decisions between the bank and the provider. The 2023 interagency third-party risk guidance put the burden on banks to get the information and terms they needed.
What the statement changes
The change is in how the agencies decide where to focus supervision. They will now weigh three factors when deciding how often and how deeply to examine a core provider, what goes into the reports shared with client banks, and whether to add a provider to the exam program at all. The first factor is transparency: whether the provider shares due diligence information, commits to measurable service levels, discloses incidents promptly, and bills in a way banks can reconcile. The second is contract terms, including opaque pricing, “back billing” windows that allow retroactive charges, deconversion fees charged even when the provider underperformed, and limits on outside vendors connecting to the core. The third is technology: security incidents, management of end-of-life systems, and operational resilience.
This works in both directions. Providers that restrict what banks can see and lock them into bad contracts should expect more scrutiny. Providers that are open with banks and keep their platforms current have a reason to expect less. That gives the market an incentive to improve before any rule requires it.
The statement also signals a new enforcement route. The agencies say some core providers may qualify as “institution-affiliated parties” under the Federal Deposit Insurance Act. In that case they could be held liable for a bank's unsafe practices or violations. The language is hedged, but the message to providers is clear: when you run the core functions of a bank, regulators may treat you as part of the bank.
What hasn't changed
The bank still owns the risk. The statement says plainly that none of this reduces a bank's responsibility to operate safely and soundly and to comply with the law, even when the work is outsourced. A bank that reads this as “regulators will handle our core provider” is likely to be disappointed at its next exam. The statement gives banks more leverage, not less accountability.
Four steps to take now
- Build the paper trail. Log every due diligence request you make to your core provider, including SOC reports, penetration test results and incident details, and record how the provider responded. That record shows your examiner you did your part, and it documents any lack of transparency by the provider.
- Check your contract before renewal. Compare it against the practices the agencies named: back-billing windows, deconversion fees, vague service levels and limits on outside integrations. Cite the statement when you negotiate. Providers now have a regulatory reason to listen.
- Use your examiner as a channel. Request your provider's exam report through your regulator. Tell your examiner when the provider won't share information. The agencies have said these gaps hurt their supervision as well as yours.
- Test your exit plan. Know what it would really cost to leave your provider, and when your platform will lose support. If leaving isn't realistic, record that as a concentration risk and report it to the board.
The bottom line
This statement is a warning to core providers and a chance for community banks. Regulators have said the balance of power in these relationships matters to safety and soundness, and they plan to use supervision to change it. No new rules have been written yet, but the direction is clear. Banks that document, negotiate and plan now will be in the best position, whatever comes next.
Sources
- Board of Governors of the Federal Reserve System, FDIC and OCC, Joint Statement on Community Banks' Engagement with Core Service Providers (September 11, 2026).
- Julian Alcazar, Sam Baird, Emma Cronenweth, Fumiko Hayashi and Ken Isaacson, Market Structure of Core Banking Services Providers, Federal Reserve Bank of Kansas City (March 27, 2024).
- OCC, Request for Information Regarding Community Banks' Engagement With Core Service Providers and Other Essential Third-Party Service Providers, 90 FR 54882 (November 28, 2025).