The Analyst Note   Financial Services series  ·  piece 1 of 8  ·  Last updated July 2026

How mid-market financial services operators should source technology contracts in 2026.

A community bank, a credit union, a fintech infrastructure company, and a $2B RIA are not sourcing to a market. They are sourcing to an examiner. Every material third-party technology relationship enters the record of the next exam. That reframes the entire buy-side: FS procurement is the assembly of an examinable evidence package with a supplier attached to it.

12 min · Anchor piece · Financial Services series, piece 1 of 8

Questions this article answers

  • What is the dispositive constraint of financial services technology sourcing in 2026?
  • What does the 2023 Interagency Guidance on Third-Party Relationships actually change for mid-market operators?
  • What SOC 2 Type II coverage does an FS operator actually need?
  • How do the 2024 SEC Regulation S-P amendments and the FTC Safeguards Rule change vendor contracts?
  • Why is concentration risk the failure mode regulators are hunting?
  • What is the 10-question pre-commercial FFIEC-readiness gate that closes the shortlist before pricing?
  • What structural failure modes do mid-market FS technology sourcing engagements keep hitting?

The structural fact is this: an FS operator is not sourcing to a market. The operator is sourcing to an examiner, and every material third-party technology relationship enters the record of the next safety-and-soundness exam.

The dispositive constraint of mid-market FS technology sourcing in 2026 is the third-party risk management regime consolidated by the Interagency Guidance on Third-Party Relationships: Risk Management, issued jointly on June 6, 2023 by the OCC, Federal Reserve, and FDIC (OCC Bulletin 2023-17), which rescinded the prior OCC 2013-29 framework and set a single, examinable expectation across the banking agencies. For credit unions, NCUA Letter 07-CU-13 remains active and imposes analogous board-level responsibilities. For non-bank finance — RIAs, broker-dealers, fintech infrastructure, mortgage originators, wealth platforms — the GLBA Safeguards Rule, administered by the FTC, imposes a substantively similar duty. The SEC Regulation S-P amendments adopted May 16, 2024 add a 30-day customer breach-notification obligation on broker-dealers, RIAs, investment companies, and transfer agents.

The functional consequence for procurement: a vendor is not chosen and then documented for the examiner. A vendor's ability to produce examiner artifacts — SOC 2 Type II with specific Trust Services Criteria coverage, penetration test reports, sub-service organization inventories, business continuity test results, right-to-audit provisions, financial condition disclosures, incident-notification windows — is a threshold gate. The technology decision closes at the exam-file level, not the demo level.

The examiner is the third party in every FS technology negotiation.

Every serious mid-market technology buyer talks about ROI, integration, and total cost. An FS operator talks about those too, and then the examiner reads the vendor file. The FFIEC IT Examination Handbook: Outsourcing Technology Services Booklet defines the four-phase lifecycle the file has to satisfy — risk assessment and requirements definition, due diligence in service provider selection, contract negotiation and implementation, ongoing monitoring — and Appendix D specifies the engagement criteria for managed security service providers. That handbook is the operating manual an FS examiner uses. The buyer's job is to produce a file that reads well against it.

Pricing sits downstream. A CIO or CFO who cannot show board-level oversight of the vendor lifecycle — annual review of the information security program to the board under GLBA Safeguards § 314.4(i), written risk assessments, incident response plans, penetration testing cadence, sub-service organization inventories, financial condition disclosures — will find that the commercial terms she negotiated do not matter because the vendor did not clear the gate. This is why FS sourcing engagements that begin with a vendor demo instead of an examiner-file gap analysis run twice.

The 2023 Interagency Guidance made third-party risk management a single, agency-wide bar — and it applies to the smallest community bank the same way it applies to the largest.

OCC Bulletin 2023-17 contains an explicit “Note for Community Banks” that says the guidance applies to all banks with third-party relationships. There is no mid-market carve-out. The prior three-agency variance — OCC 2013-29 and 2020-10, separate Federal Reserve guidance, separate FDIC guidance — is gone. A $600M-asset community bank in Ohio and a $50B regional bank in Texas are examined against the same framework, adjusted for scale.

For a $1B credit union, NCUA Letter 07-CU-13 still governs and imposes the same board-of-directors addressee. For an RIA or fintech, the FTC Safeguards Rule at 16 C.F.R. § 314.4 lays out a nine-element information security program with a Qualified Individual responsible, written risk assessment, multi-factor authentication, encryption in transit and at rest, access controls, secure disposal, annual penetration testing, semi-annual vulnerability scans, written incident response plan, and board reporting. Section 314.4(j) imposes 30-day breach notification to the FTC for security events involving 500 or more consumers.

Buyer-side. Supplier-paid. Buyers pay zero. Compensation has zero weight in the Cardinal Index scoring. We scope the examiner file first under the Cardinal Method, then run vendor fit against the operator's institution type, examiner posture, and existing control set.

The SOC 2 Type II with the right Trust Services Criteria is the artifact that decides most FS vendor shortlists before commercial terms are opened.

Every SOC 2 report covers Security by default. That is baseline. What separates an examiner-relevant report from a marketing artifact is the additional Trust Services Criteria in scope. Availability matters when the vendor is on the critical path for a customer-facing service. Confidentiality matters whenever the vendor touches non-public information. Processing Integrity matters when the vendor participates in transaction handling. Privacy matters when the vendor holds identifiable customer records.

A Type I report attests to the design of controls at a point in time. It is not sufficient for an FS vendor decision at any material scale — the examiner will want a Type II covering an operating period, usually six to twelve months. Common defects the buyer's file has to catch: the report is scoped to a sibling product rather than the one being purchased, Confidentiality is omitted, sub-service organizations are listed as “carve-out” without disclosure of what they cover, or the report contains exceptions the vendor has not remediated. The pattern shows up in the exam workpapers, not the contract.

Adjacent artifacts the file needs: penetration test summary within the last 12 months, business continuity test results, incident notification playbook with a defined window, right-to-audit clause or a pooled-audit reliance model, financial condition evidence for private vendors, and (if the vendor touches cardholder data) a current PCI DSS v4.0.1 Attestation of Compliance — not a self-marketing claim. The future-dated PCI 4.0 requirements became mandatory March 31, 2025, so any AOC dated before that either shows current compliance with all requirements or is stale.

Concentration risk is the failure mode regulators are actively hunting, and mid-market operators are the most exposed.

Two dimensions. First-degree concentration: any single vendor delivering a material share of a function. Nth-degree concentration: multiple direct vendors that ultimately sit on the same sub-service organization — a hyperscaler, a payment-rail intermediary, a data broker, a KYC data provider. Both are on the interagency guidance's radar. Both show up in the systemic FS technology incidents of the last three years.

Mid-market operators are more exposed because their vendor lists are shorter, their contract terms are less bespoke, and they lack the vendor-management staffing to enumerate the nth-party chain. A community bank running Fiserv or Jack Henry as the core, one of the same short list of MDR providers, one of two or three UCaaS vendors, and a single KYC data source may look diversified at the vendor level and be concentrated at the platform layer two hops down. The NIST Cybersecurity Framework 2.0, published February 26, 2024, added a sixth “Govern” function that is now the mapping vocabulary regulators, cyber underwriters, and MSSPs use to describe program maturity. Concentration disclosure sits under Govern.

Run the pre-commercial FFIEC-readiness gate before any pricing conversation.

Ten questions the buyer runs before any pricing call. Each is a gate, not a scoring factor. A vendor that cannot answer in these terms does not advance to commercial negotiation.

The pre-commercial FFIEC-readiness gate

  1. SOC 2 Type II with named TSC. Provide your most recent SOC 2 Type II covering Security, Availability, and Confidentiality at minimum — Processing Integrity and Privacy if you touch transaction data or NPI. Disqualify Type I only or Type II without Confidentiality.
  2. Sub-service organization inventory. List every sub-service organization in scope of the SOC 2 report, and confirm carve-out or inclusive treatment. Disqualify if the sub-service inventory is not producible under NDA.
  3. Financial condition evidence. Audited financials or an equivalent for private vendors, including customer concentration and going-concern disclosures. Required by the FFIEC Outsourcing booklet's ongoing-monitoring section.
  4. Right-to-audit language in the contract. Buyer's and examiner's right to audit — directly or via pooled-audit / SOC-reliance model — with no additional fee. Disqualify vendors who will only offer “SOC 2 delivered annually” as a substitute; the examiner treats it as a downgrade.
  5. Incident notification window in writing. GLBA Safeguards sets a 30-day floor for FTC notification of security events involving 500 or more consumers. SEC Reg S-P sets the same 30-day floor for customer notification. Contract for a shorter inbound window — 24 to 72 hours — so the buyer can meet its own downstream obligations.
  6. MFA and encryption posture. MFA enforced for all workforce and customer access to systems containing buyer data. Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent), with key custody documented.
  7. PCI DSS 4.0.1 attestation, if the vendor touches cardholder data. Current AOC, not a self-marketing claim. Confirm the vendor has closed the March 31, 2025 future-dated requirements.
  8. Business continuity and operational resilience. Most recent BCP test summary, RTO and RPO by service tier, geographically distributed recovery.
  9. Concentration disclosure. Identify any single sub-service organization on which more than 25 percent of service delivery depends — cloud infrastructure, identity, card networks, payment rails, KYC data providers.
  10. Termination and data-return provisions. Written return or verified destruction of NPI within a defined window post-termination, with attestation. Disqualify vendors who will not commit to a defined window in writing.

The gate is the shortlist tool. Vendors that pass are ranked on commercial terms. Vendors that fail are not ranked at all.

What breaks in FS sourcing is procedural, not vendor-specific — and the fix is buyer-side discipline.

Failure mode one: SOC 2 mis-scoping. Community banks and credit unions routinely accept whatever SOC report the vendor sends, without confirming the report covers the Trust Services Criteria the examiner will ask about or the specific system in scope. A vendor's SOC 2 Type II can be genuine and still be irrelevant if the report covers a sibling product or omits Confidentiality. The failure surfaces in exam workpapers, not the contract.

Failure mode two: nth-party blind spot. The buyer diligences the direct vendor, but the direct vendor sits on a hyperscaler, a data-broker feed, a payment-rail intermediary, or a KYC data source that concentrates risk several layers down. The interagency guidance is explicit that the risk-management lifecycle covers subcontractors. Mid-market operators frequently do not enumerate the chain. This is the systemic pattern behind most large FS technology incidents of the last three years.

Failure mode three: right-to-audit stripped in redlines. Vendor legal teams routinely propose to replace a right-to-audit clause with a “SOC 2 delivered annually” clause. That is a downgrade. Mid-market buyers without dedicated vendor-management counsel often accept the swap without knowing it materially weakens the exam file.

What this means for procurement in 2026.

FS technology sourcing is procedural discipline first and vendor selection second. The operators who run the pre-commercial gate before the demo save weeks of sunk time and produce vendor files that clear the exam. The operators who let the vendor lead the process end up with technology that works and paper that does not.

This is the shape of a Cardinal engagement in financial services. We scope the examiner-file requirements against the operator's institution type and its regulator, run the shortlist against the pre-commercial gate, and open commercial negotiations only with vendors that clear it. The buyer's file is what closes the engagement. Coverage across financial services sits on Finance; sister anchors in this Analyst Note series include the healthcare anchor, where the constraint set differs and the discipline is the same. Every vendor named on this page is in The Cardinal Source's active supplier pool.

In short

  • Financial services technology sourcing is not procurement to a market. It is procurement to an examiner. Every material vendor decision enters the exam file.
  • OCC Bulletin 2023-17 consolidated third-party risk management across the OCC, Federal Reserve, and FDIC. There is no community-bank carve-out.
  • The examiner-relevant SOC 2 Type II covers Security, Availability, and Confidentiality at minimum. A Type I or a Type II that omits Confidentiality is often not enough regardless of vendor quality.
  • SEC Reg S-P 2024 amendments impose 30-day customer breach notification on broker-dealers, RIAs, investment companies, and transfer agents. Contract inbound notification windows of 24-72 hours to meet the downstream obligation.
  • Concentration risk is the failure mode regulators are hunting. Mid-market operators are the most exposed because their vendor lists are shorter and their nth-party chains are unmapped.
  • Run the 10-question pre-commercial gate before any pricing call. Vendors that fail are not ranked. The gate is the shortlist.

Sources

  • Federal Financial Institutions Examination Council, FFIEC IT Examination Handbook: Outsourcing Technology Services Booklet. ithandbook.ffiec.gov
  • Office of the Comptroller of the Currency, “Third-Party Relationships: Interagency Guidance on Risk Management,” OCC Bulletin 2023-17, June 6, 2023 (joint issuance with the Federal Reserve and FDIC). occ.gov
  • National Credit Union Administration, Letter to Credit Unions 07-CU-13: Evaluating Third Party Relationships. ncua.gov
  • U.S. Securities and Exchange Commission, “SEC Adopts Rule Amendments to Regulation S-P,” Press Release 2024-58, May 16, 2024. sec.gov
  • Federal Trade Commission, “FTC Safeguards Rule: What Your Business Needs to Know.” ftc.gov
  • PCI Security Standards Council, PCI DSS v4.0.1 document library. pcisecuritystandards.org
  • National Institute of Standards and Technology, Cybersecurity Framework 2.0 (CSWP 29), February 26, 2024. nist.gov

All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.

Want a calibration on your institution's vendor file?

Run the Tier 1 benchmark.

Submit your current technology contracts — core banking, digital banking, MDR, UCaaS, CCaaS, payments, fraud/AML, identity. We return a benchmark PDF in five business days showing where the vendor file has gaps against the examiner-relevant TSCs, where concentration risk is unmapped, and where inbound notification windows are too long to meet your downstream obligations. Free. No follow-up sales drip.

Run the Tier 1 benchmark →

Series  ·  Financial Services deep-dive · 8 pieces

This anchor sets the framing. Companion pieces cover PCI DSS 4.0 for mid-market merchants, FFIEC requirements for mid-market banks, bank branch connectivity at scale, credit union community technology stacks, fintech infrastructure, RIA office stacks, and treasury operations technology — all forthcoming. Sister anchor in this Analyst Note series: How mid-market healthcare operators should source technology contracts in 2026. Coverage: Finance.