Selling to banks and credit unions
Your champion said yes. The rest of the bank hasn’t.
You sell software to banks and credit unions, and every one sits in a public register. After the demo, vendor management, security and the board review you on their own clock. Close dates slip to the next board meeting, and renewal windows open before you hear of them.
- US FDIC-insured banks
- 4,238
- US federally insured credit unions
- 4,214
- US banks’ core providers, 2022
- over 70% on 3 providers
Updated 5 October 2026 · Based on Panelhop research, October 2026
The short answer
How do software vendors sell to banks and credit unions?
Software vendors sell to banks and credit unions through committee-run deals. A business owner champions the product, then IT, information security, vendor management and often the board must agree. Banking is a finite, named market. Vendors win by timing core contract renewals and mergers and by engaging the whole buying panel early.
Banking · How a deal really moves
Banks rarely say no. They say ‘not yet’. Then the deal waits on the core, due diligence and the board. The same deal, with the whole bank on it. Core, renewal date, risk seats and board dates on every deal.
One bank or credit union, 5–12 people and an estimated 2–12 months for add-ons or 9–24 months for platforms.
What opens a deal
- Core renewal window opens: Contract · US
- Bank or credit union merger: Consolidation · US
- BSA/AML consent order: Regulation · US
- New CIO, CISO or retail chief: Leadership
- DORA register and re-papering: Regulation · EU
- PRA register, March 2027: Deadline · UK
Signal Desk · weekly: In-market accounts, scored and mapped
Your buyer and who decides
A bank or credit union
Community, regional, mutual or cooperative
4,238 banks · 4,214 credit unions in the US
Panel Check · coverage baselined
- CEO, CFO or COO, can Veto: A contract whose deconversion fees block a future merger.
- Board or committee, can Veto: Large spend nobody can explain to examiners or members.
- CIO or CTO, can Veto: An integration that runs late on the core provider’s schedule.
- Business owner: Low adoption, and members or customers hit at conversion.
- Information security, can Veto: A breach at a vendor that exposes member or customer data.
- Vendor management, can Veto: Annual re-reviews the team can’t keep up with.
- Compliance and privacy, can Veto: An enforcement action traced back to a tool they approved.
- Selection consultant: A vendor that over-promises or hides fees.
How the deal moves
Targeting Typical time: Sep–Nov plan
- Where it stalls
- You call just after the bank renewed
- With Panelhop: Leak Fix
- Core and renewal date required on every account, re-tiered quarterly
Demand generation Typical time: 4–8 weeks
First meeting
Discovery Typical time: 2–8 weeks
- Where it stalls
- One friendly banker can’t move the bank
- With Panelhop: Leak Fix
- A role map per tier, with IT, security and vendor management tracked
Evaluation Typical time: 1–3 months
- Where it stalls
- ‘Come back when you’re live on our core’
- With Panelhop: Leak Fix
- Accounts on cores you can’t serve stop becoming opportunities
Pilot
Due diligence Typical time: often 3–9 mo
- Where it stalls
- Risk and IT meet you after the verbal yes
- With Panelhop: Leak Fix
- Vendor management on the deal from discovery, with stage exit criteria
Commercial close Typical time: 1–3 months
- Where it stalls
- Close dates slip to the next board
- With Panelhop: Leak Fix
- Approval route and board dates on every deal; the forecast follows them
Onboarding
Renewal and expansion
Panel Ops · monthly: Scores and plays tuned against the baseline
Illustrative Source: Stages, seats, triggers and stalls from Panelhop research, October 2026; Bank Director; FDIC; NCUA; the services as described on the Services page. Note: Durations, panel sizes and cycle lengths are Panelhop estimates from our research, not measurements.
At a glance
| Typical deal | €25–150k a year for add-on software at smaller US banks; platform deals run larger Illustrative |
|---|---|
| Sales cycle | 2–12 months for add-ons; 9–24 months for digital banking platforms Illustrative |
| Buying panel | 5–12 people Illustrative |
| How deals start | A demo request or an event conversation; Panelhop classed 13 of 20 vendors it analysed as inbound-led |
| Main triggers | Core contract expiry, mergers, enforcement orders, new executives and budget season |
| Segments | Community banks, credit unions, regional banks, building societies, Sparkassen and cooperative banks |
Source: Panelhop research, October 2026. Note: Values marked Illustrative are Panelhop estimates from our research, not measurements.
The pipeline leaks before the market runs dry.
Where do software deals with banks get stuck?
Bank deals get stuck at core integration, board approval and due diligence. In Panelhop’s October 2026 analysis of banking vendors’ websites, core integration is a likely stall point for 14 of 20 vendors, board cadence for 13 of 20 and late due diligence for 9 of 20. Most of these stalls trace back to data the vendor’s CRM never held.
Where the pipeline leaks: 6 points across 10 stages.
‘We just renewed’ ends the first call
- What you see
- Prospects say they have just renewed with the incumbent, or an RFP arrives from a consultant with a short deadline.
- Why it happens
- Contract dates are private, and discovery never records the incumbent or its expiry date.
Stage Targeting
Deals with one friendly banker end in ‘no decision’
- What you see
- Opportunities have one contact role and end as “no decision” instead of won or lost.
- Why it happens
- Discovery never establishes the problem owner, the budget path or the risk category.
Stage Discovery
Reps demo to banks your product can’t serve yet
- What you see
- Good first meetings end with “come back when you’re live on our core”.
- Why it happens
- Targeting ignores which core an account runs, so reps chase institutions the product can’t serve yet.
Stage Evaluation
Vendor management meets you after the verbal yes
- What you see
- Deals sit in a security review stage for months, and close dates slide after a verbal yes.
- Why it happens
- Vendor management, security and compliance meet the vendor only after the business line says yes, and no evidence pack is ready.
Stage Due diligence
Miss the board pack and lose a quarter
- What you see
- Close dates slip in steps that match the bank’s board and committee calendar.
- Why it happens
- The approval route and meeting dates aren’t fields on the opportunity, so the forecast assumes the rep’s date.
Stage Commercial close
Acquired clients move to the acquirer’s stack, not yours
- What you see
- Churn clusters in client institutions that were acquired.
- Why it happens
- Merger announcements aren’t matched against client and prospect lists, so the acquirer picks its stack first.
Stage Renewal and expansion
Dated events open and close bank buying windows.
What makes a bank or credit union start buying software?
Banks and credit unions start buying when a contract nears expiry, a merger is announced, a regulator acts or a new executive arrives. Most of these events are public and dated. A vendor can see them coming.
The 8 events that open or close the window for a deal.
Contract
Core renewal window
- What happens
- Some community banks start looking 18–24 months before a core contract expires, leaving time to compare providers before the notice date.
- Where to spot it
- Discovery questions, selection consultants’ networks and core conversion announcements that date the next renewal.
- Window
- Opens 18–24 months before expiry; most core contracts need non-renewal notice at least 180 days ahead.
Consolidation
Bank or credit union merger
- What happens
- An acquirer converts the target to its own systems after closing; 36 US institutions merged with other banks in the second quarter of 2026.
- Where to spot it
- FDIC and NCUA data, trade press deal roundups and acquirers’ SEC filings.
- Window
- From announcement to systems conversion; reach the acquirer before it chooses its stack.
Regulation
BSA/AML enforcement action
- What happens
- A US regulator issues a consent order that names failures in transaction monitoring, alert triage or customer due diligence.
- Where to spot it
- The OCC’s monthly enforcement releases and law-firm summaries.
- Window
- One recent OCC order required a compliance committee and an action plan within 90 days, then months of remediation.
Leadership
New CIO, CISO or chief retail officer
- What happens
- A new technology or retail leader arrives with a modernisation brief and reviews the vendor stack.
- Where to spot it
- Bank and credit union press releases and trade press people moves.
- Window
- The new leader’s first months, while the roadmap is still being set.
Budget cycle
Annual budget season
- What happens
- Calendar-year banks and credit unions plan next year’s technology spend from September to November and approve it in December.
- Where to spot it
- The institution’s fiscal year-end and its own planning calendar.
- Window
- Engage from August; after December, an unbudgeted purchase competes with items already funded.
Regulation
US third-party risk guidance rewrite
- What happens
- On 11 September 2026 the FDIC, OCC, Federal Reserve and NCUA proposed new third-party risk guidance, and the bank agencies flagged core providers’ fees and integration limits in a joint statement.
- Where to spot it
- FDIC financial institution letters and agency press releases.
- Window
- Comments close 60 days after Federal Register publication; until the guidance is final, banks still work to the 2023 interagency guidance.
Regulation
DORA register and contract re-papering
- What happens
- EU banks report a register of their ICT third-party contracts once a year and re-paper contracts that lack DORA Article 30 clauses.
- Where to spot it
- National supervisors’ DORA reporting notices; De Nederlandsche Bank’s 2026 deadline was 20 March.
- Window
- Register work early in the year competes with new purchases, and renewals turn into renegotiations.
Regulation
UK material third-party register
- What happens
- From 18 March 2027, UK banks, building societies and other in-scope PRA-regulated firms keep a structured register of material third-party arrangements and notify the PRA on a standard template.
- Where to spot it
- The PRA’s policy statement PS7/26 on third-party reporting.
- Window
- Inventories and contract reviews run in the months before the start date; the notification is not an approval.
Most seats on a bank’s buying panel hold a veto.
Who signs off on a software deal at a bank or credit union?
A software deal at a bank or credit union needs a yes from the business owner, IT, information security, vendor management, compliance and usually a steering committee or the board. The champion who asked for your demo rarely has the standing to carry the deal through all of them.
At a mid-size bank or credit union, 5–12 people sit on the panel and 6 seats can stop the deal.
At a mid-size bank or credit union: 5–12 people
Executive sponsor and economic buyer
Can Veto
President and CEO · Chief Financial Officer · Chief Operating Officer
- Cares about
- Efficiency, standing with examiners and total cost, including core-integration fees.
- Worries about
- A contract whose deconversion fees block a future merger.
Business owner and champion
Chief Lending Officer · SVP or Head of Digital Banking · BSA/AML Officer
- Cares about
- Account growth, staff time saved and speed to live.
- Worries about
- Low staff adoption and members or customers disrupted at conversion.
Technology lead
Can Veto
Chief Information Officer · Chief Technology Officer · VP Information Technology
- Cares about
- Integration with the core, and who fixes it when it breaks.
- Worries about
- An integration that fails or runs late on the core provider’s schedule.
Information security officer
Can Veto
Chief Information Security Officer
- Cares about
- A current SOC 2 Type II report, penetration test results and the subprocessor list.
- Worries about
- A breach at a vendor that exposes members’ or customers’ data.
Vendor management and third-party risk
Can Veto
Vendor Management Officer · Third-Party Risk Manager · Outsourcing Officer (DACH)
- Cares about
- Risk tiering, exit plans and contract terms that satisfy examiners.
- Worries about
- Annual re-reviews the team can’t keep up with.
Compliance and data protection
Can Veto
Chief Compliance Officer · Money Laundering Reporting Officer (UK) · Data Protection Officer
- Cares about
- Regulatory fit, an audit trail and data residency.
- Worries about
- An enforcement action traced back to a tool they approved.
Board and supervisory body
Can Veto
Board of Directors · Board Technology or Risk Committee · Volunteer board (credit unions)
- Cares about
- Strategic fit, risk and cost, set out in a plain-language proposal.
- Worries about
- Large spend nobody can explain to examiners or members.
Independent selection consultant
Fractional CIO · Core Contract Adviser
- Cares about
- An objective selection and contract terms they can defend to the client.
- Worries about
- A vendor that over-promises or hides fees.
The reachable list is smaller than the charter count.
Who buys software in banking?
Banking software buyers include community banks, credit unions, regional and large banks, private and challenger banks, UK building societies and, in Germany, the group IT providers behind Sparkassen and cooperative banks. Every segment sits in a public register you can tier by assets and charter; the core platform usually has to come from discovery or technographic data. Mergers remove names every quarter, so the list needs a quarterly refresh.
US credit unions are the largest group we could count: 4,214, including 748 complex credit unions.
US community banks
Locally focused banks that rent a bundled stack from one core provider and buy add-ons around it. Most are small: 75% of US banks hold under $1bn in assets.
- US3,818
US credit unions
Member-owned, not-for-profit institutions insured by NCUA. Size varies widely, so vendors tier by assets; each credit union in NCUA’s complex tier holds over $500M.
- US4,214, including 748 complex credit unions
Regional and large banks
Banks that buy their own stack through formal procurement and several risk committees. In the euro area, the largest groups are supervised directly by the ECB.
- US158 with over $10bn in assets
- EU110 ECB-supervised groups
UK building societies and banks
Mutual savings and mortgage lenders, plus UK banks supervised by the PRA. The society list is short and peer-networked, so one society’s platform choice becomes the next one’s reference.
- UK42 building societies and 284 banks
Sparkassen and cooperative banks (DACH)
German savings and cooperative banks buy core and most core-adjacent software through their group IT providers. For that software, the account is the group IT provider rather than the local bank.
- DACH342 Sparkassen and 634 cooperative banks in Germany
Private, specialist and challenger banks
Newer licensed banks, neobanks and specialist lenders that build more of their own stack and buy components. Also DACH private banks, whose management board decides without group sign-off.
- DACH129 German regional and other commercial banks
Data behind this chart
| Segment | Region | Accounts |
|---|---|---|
| US community banks | US | 3,818 |
| US credit unions | US | 4,214, including 748 complex credit unions |
| Regional and large banks | US | 158 with over $10bn in assets |
| Regional and large banks | EU | 110 ECB-supervised groups |
| UK building societies and banks | UK | 42 building societies and 284 banks |
| Sparkassen and cooperative banks (DACH) | DACH | 342 Sparkassen and 634 cooperative banks in Germany |
| Private, specialist and challenger banks | DACH | 129 German regional and other commercial banks |
Banks ask about integration, evidence and contract terms.
What do banks and credit unions ask vendors during a deal?
Banks and credit unions ask whether a product integrates with their core, whether the vendor’s security evidence satisfies vendor management and whether the contract meets DORA or PRA rules. These questions come from our research into how banks and credit unions buy.
CIO or IT lead
Will it integrate cleanly with our core, and who fixes it when it breaks?
Our core provider already offers something similar. Does our contract even allow a third-party integration?
CISO or vendor management
Is your security evidence enough for our vendor management programme?
You’re a small vendor. What happens if you fail or get acquired?
Compliance, legal or outsourcing officer
Does the contract meet DORA Article 30, or the PRA’s outsourcing rules in the UK?
How do you govern the AI in your product?
CEO, CFO, Vorstand or board
What return can we show the board, and when?
The last vendor under-supported us and the implementation ran long. Why would you be different?
Our Verbund already provides this. Why would we buy it separately?
Most of a bank deal happens after the demo.
How does a software deal with a bank move from first contact to contract?
A bank deal moves from annual planning through discovery, evaluation, due diligence and board approval before onboarding starts. Add-ons close faster than platforms, and every stage can stall on a gate the vendor never tracked.
Stage by stage: what you do, what the bank does, and what changes at the 5 stages where deals stall.
| Stage | What you do | What the bank does | Today | With Panelhop |
|---|---|---|---|---|
| Targeting Typical time: about 3 months of annual planning | Waits for inbound; few vendors tier accounts by core platform, asset band or contract date. | Plans next year’s technology spend from September to November and approves it in December. | Reps learn the renewal date when the bank says it just renewed. Stalls: Contract clocks nobody tracks. Some community banks start looking 18–24 months before a core contract expires, so a vendor without that date on the account arrives mid-term. | The core platform and an estimated renewal date required on every account and filled from discovery, with accounts re-tiered quarterly by asset band, charter and core. Leak Fix We build the fixes |
| Demand generation Typical time: 4–8 weeks | Gates content, runs webinars and buys booths at banking and credit union conferences. | Runs a market scan through peers, core user groups, consultants and trade press. | Booth scans and webinar sign-ups counted as pipeline. | Weekly scored accounts with the signal that fired, such as a merger, a new CIO or an enforcement order. Signal Desk In-market accounts, weekly |
| First meeting | Takes a demo request from a business owner who has already started shopping. | Judges whether the vendor looks able to survive due diligence before agreeing to meet. | Reps wait for a demo request. | A research brief on each in-window account, so your rep opens with the trigger and owns the first touch. Signal Desk In-market accounts, weekly |
| Discovery Typical time: 2–8 weeks | Works one friendly contact, often the head of digital banking, lending or operations. | Forms a committee once a budget path and a risk category are clear. | One friendly contact on the opportunity. Stalls: One friendly banker. The first contact likes the product but can’t bring in risk, IT or the executive team, so the deal stays “interesting” for quarters. | A role map per tier, with missing seats such as IT, security and vendor management found and tracked per account. Leak Fix We build the fixes |
| Evaluation Typical time: 1–3 months | Answers the RFP, runs scripted demos and lines up references. | Scores vendors, calls peers on the same core and, for core and digital banking, often hands the selection to a consultant. | Demos for institutions on cores you don’t integrate with. Stalls: The core decides first. Without a live integration on the bank’s own core configuration, a strong demo ends with “come back when you’re live on our core”. | A qualification model that reads the core field, so accounts on unsupported cores don’t become opportunities. Leak Fix We build the fixes |
| Pilot | For AI, fraud and lending tools, offers a pilot or proof of concept on sandbox data. | Tests the product, often without a named executive owner or agreed success criteria; platform selections usually go straight to references. | Pilots start without an owner or a success test. | A mutual action plan that names the executive owner and the success criteria before the pilot starts. Leak Fix We build the fixes |
| Due diligence Typical time: under 3 months for 28% of US bank respondents; 9 months or longer for 18% | Answers security questionnaires and evidence requests, often from scratch for each bank. | Vendor management, security, compliance and audit run their own review after the business line says yes. | Risk and IT meet you after the business case. Stalls: Due diligence on the bank’s clock. Risk and IT teams never saw the demo, so their review starts late and the rep can’t forecast when it ends. | A due diligence stage with exit criteria, and vendor management on the deal from discovery. Leak Fix We build the fixes |
| Commercial close Typical time: 1–3 months to negotiate, then 2–8 weeks to approve | Negotiates liability caps, fee increases and termination terms, plus DORA Article 30 clauses in the EU. | Takes the contract to a steering committee or the board, which meets on a fixed calendar. | Close dates set without the board calendar. Stalls: Board dates the forecast ignores. A business case that misses the board pack waits for the next meeting, so close dates slip by a month or a quarter. | The approval route and board dates captured on every opportunity, with the forecast tracked against them. Leak Fix We build the fixes |
| Onboarding Typical time: weeks for add-ons; 9–24 months for platforms | Implements the product and builds the core integration. | Goes live, records the contract in its vendor register and starts annual re-reviews. | What sales promised lives in one rep’s notes. | A handoff document built from the deal, and a health score from go-live. Leak Fix We build the fixes |
| Renewal and expansion | Waits for the renewal date or a request for another module. | Renegotiates at contract end, or moves to the acquirer’s stack after a merger. | Renewals handled by whoever remembers the term date. | Merger and renewal alerts on client accounts, with unactioned alerts raised in the weekly signal review. Panel Ops We run it monthly |
Panelhop tracks every account and seat at each stage.
How does Panelhop change the way vendors sell to banks?
Panelhop adds the core platform, the incumbent’s renewal date and the buying panel to every account record, filled from discovery, then fixes the stages that leak. A Panel Check (GTM audit · 2–3 weeks), fixed-scope and quoted on the scoping call, baselines every stage of the bank deal. Leak Fix (we build the fixes), Signal Desk (in-market accounts, weekly) and Panel Ops (we run it monthly) act on what the Panel Check finds.
What we baseline and report
- Buying-panel coverage per tiered account, against the baseline
- Qualified pipeline from in-window Tier 1 and Tier 2 accounts
- Median days in due diligence and board approval
Read the pipeline for your vendor type.
Which vendor types sell to banks and credit unions?
These are the vendor types we map in banking, each with its own buying panel, pipeline and triggers.
- Vendor type
Digital banking and core platforms for community banks and credit unions
Core, online and mobile banking and account opening platforms sold to US community banks and credit unions.
Read the pipeline - Vendor type
Enterprise core banking platforms for regional and large banks
Core banking systems, from composable cores to greenfield builds, sold to regional, large, challenger and DACH private banks.
Read the pipeline - Vendor type
Risk, compliance and GRC software for banks and credit unions
Enterprise risk, compliance management, vendor risk and audit software sold to community banks, credit unions and regional banks.
Read the pipeline - Vendor type
Fraud prevention, AML and KYC software for banks
Fraud detection, transaction monitoring, sanctions screening and KYC software sold to banks, credit unions and building societies.
Read the pipeline
The words your buyers use, defined.
What do terms like “Core provider” and “Core conversion” mean in banking?
Plain definitions of the terms that come up when you sell to banks and credit unions.
- Core provider
- The company that runs a bank’s or credit union’s core system of accounts, deposits, loans and the ledger. Most add-on software has to integrate with it.
- Core conversion
- Moving an institution from one core system to another, or onto the acquirer’s core after a merger. Systems around the core are often re-decided at the same time.
- Deconversion fee
- A fee the incumbent provider charges to release data and end service when an institution leaves. With early termination fees, it can change a merger’s economics.
- Asset band
- A size bracket by total assets, read from call reports. Vendors use it to tier banks and credit unions, because budgets, IT teams and cycle lengths track size.
- Call report
- The quarterly financial filing every US bank and credit union submits to its regulator. It is free public data for building and tiering a target account list.
- Community bank
- The FDIC’s term for a bank focused on local lending and deposit-taking, defined by tests on its size, loans, deposits and branch footprint. Most US banks are community banks.
- Vendor management
- The bank function that runs third-party due diligence, risk tiering, contract review and annual re-reviews. It can stop a deal the business line wants.
- Steering committee
- The management committee that approves technology investments at a bank or credit union. In Bank Director’s 2026 Technology Survey of US banks, most respondents gave a management-level team or steering committee the final say.
- DORA register of information
- The record every EU bank keeps of its ICT third-party contracts under the Digital Operational Resilience Act, reported to its supervisor once a year.
- Verbund
- The German group structure of savings banks or cooperative banks, with shared IT providers, associations and central institutions. The group often decides which third-party software local banks can use.
Answers before your next bank deal.
What do vendors ask about selling to banks and credit unions?
How long does it take a software or fintech vendor to sell to a bank or credit union?
Selling software to a bank or credit union takes 2–12 months for an add-on and 9–24 months for a digital banking platform, by Panelhop’s research estimates. A core replacement can take up to 36 months by the same estimates. Due diligence alone took 9 months or longer for 18% of respondents to Bank Director’s 2026 Technology Survey of US banks. Deals that run through German group IT providers can take longer still, because the group must release the product first.
Who is on the buying committee when a bank or credit union buys software?
A bank or credit union’s buying panel for software involves an estimated 5–12 people. The panel includes an executive sponsor, a business owner, the CIO, the information security officer, vendor management, compliance and often the board. For 65% of respondents to Bank Director’s 2026 Technology Survey of US banks, a management team or steering committee gives final approval. In the same survey, 30% said their board is directly involved in major technology decisions.
Do you need a core integration before selling to community banks?
Most products that touch account data need a live core integration before they sell to community banks. In a Federal Reserve Bank of Kansas City study, over 70% of US banks surveyed in 2022 ran on 3 core providers. Without a live integration on the bank’s own core configuration, deals stall at evaluation or lose to the core provider’s own module. Tier your target list by core so reps work accounts you can serve.
How do you find out when a bank’s core contract expires?
Banks rarely publish core contract dates, so ask for the core and digital banking renewal dates in the first meeting and record them on the account. Some community banks start looking 18–24 months before a core contract expires. Most core contracts need non-renewal notice at least 180 days ahead. Where the date stays private, estimate it from the institution’s last core conversion or renewal announcement plus a typical term, and watch merger filings and consultant RFPs.
Why do software deals with banks slip to the next quarter?
Bank deals slip because due diligence and board approval run on the bank’s calendar while the forecast assumes the rep’s date. Vendor management and security often start their review only after the business line says yes. Steering committees and boards meet on fixed dates. A business case that misses the board pack waits for the next meeting.
How do fintech and software vendors sell to German Sparkassen and cooperative banks?
Software vendors usually reach German Sparkassen and cooperative banks through the group IT provider that runs each group’s platform, with the regional associations as gatekeepers. Core-adjacent software must be integrated and released on the group platform before a local bank can buy it, so the decisive account is the group. Independent private and specialist banks in Germany can still decide on their own. When Sparkassen or cooperative banks merge, core IT stays with the group, and the merged bank is likely to re-plan peripheral services ahead of the technical merger.
What are the buying signals that a bank or credit union is about to buy software?
The strongest buying signals at a bank or credit union are dated events: a core contract nearing expiry, a merger, an enforcement order, a new CIO or CISO and the annual budget season. Some community banks start looking 18–24 months before a core contract expires, and the contract date usually comes from discovery. Mergers, enforcement orders and leadership changes show up in FDIC and NCUA data, regulators’ releases and trade press. A vendor can map each of them to named accounts.
How do software vendors get meetings with bank and credit union executives?
Software vendors get meetings with bank and credit union executives by arriving with a dated reason. Good reasons include a contract window, a merger, an enforcement order or a new leader. Peers on the same core, user groups, credit union leagues, state banking associations and selection consultants carry more weight than cold email. Engage IT, information security and vendor management early, as well as the business owner who asked for a demo.
Where the numbers come from.
Sources
Sourced figures link to their source below. Figures marked Illustrative, and figures given as estimates, are inferred from Panelhop research. Vendors appear only as types, never by name.
- FDIC, Quarterly Banking Profile, Second Quarter 2026 (2026)
- NCUA, Quarterly Credit Union Data Summary, 2026 Q2 (2026)
- Bank of England, Prudential Regulation Authority, PRA Business Plan 2026/27 (2026)
- Deutsche Bundesbank, Bankstellenstatistik 2025: Bestand an Kreditinstituten am 31. Dezember 2025 (2026)
- ECB Banking Supervision, List of supervised banks (2026)
- Federal Reserve Bank of Kansas City, Market Structure of Core Banking Services Providers (2024)
- Bank Director, 2026 Technology Survey (2026)
- ICBA (Independent Community Bankers of America), Helpful tips for streamlining the core conversion process (2024)
- Nelson Mullins, for the Georgia Bankers Association, Fear of Commitment: Negotiating core contracts (2020 Ops and Tech Conference presentation) (2020)
- FDIC, Proposed Interagency Third-Party Risk Management Guidance and Issuance of Joint Statement on Community Banks’ Engagement with Core Service Providers (2026)
- Bank of England, Prudential Regulation Authority, PS7/26 Operational resilience: Operational incident and third-party reporting (2026)
- De Nederlandsche Bank, DORA: Reporting DORA registers of information in March 2026 (2026)
- Panelhop, Services (2026)
- The National Law Review, The OCC’s Recent Consent Order Is a Warning for Community Banks in the Fintech Partnership Space (2026)
- Federal Reserve Board, FDIC and OCC, Joint Statement on Community Banks’ Engagement with Core Service Providers (2026)
- Panelhop research, October 2026: our analysis of the vendors, buying panels, pipelines and triggers in banking, from public sources. Vendor names are not published.
Find where your pipeline to banks and credit unions leaks.
