Banking · Enterprise core banking platforms for regional and large banks
You win on features. The bank keeps its old core.
You sell core banking platforms to regional and large banks, challengers and DACH private banks. They are replacing the system that holds every account, so migration proof outweighs features. Deals that survive the RFP then stall in a greenfield pilot, in audit and exit clauses or between committees.
- Typical deal
- €250k or more a year Illustrative
- Sales cycle to signature
- often over 12 months Illustrative
- Buying panel
- 12 or more people Illustrative
Updated 5 October 2026 · Based on Panelhop research, October 2026
At a regional bank or ECB-supervised group12 or more people Illustrative
The short answer
How do core banking vendors sell to regional and large banks?
Enterprise core banking vendors sell to regional and large banks through long, formal selections. Each runs through an RFP, a proof of concept, parallel risk reviews, DORA contract terms in the EU and approval by several committees and the board. Migration risk weighs more than features, so vendors win by proving the migration path before the demo.
Enterprise core banking platforms for regional and large banks · How a deal really moves
Core banking deals rarely lose on features. They stall on migration fear, pilots, exit terms and committees. The same deal, with every committee mapped. Migration owner, exit terms and every committee date tracked.
One regional bank or banking group, 12 or more people and, by our estimate, more than 12 months to signature.
What opens a deal
- End of support or vendor sold: Technology
- Banking group merger: Consolidation
- DORA re-papering and register: Regulation · EU
- Core contract nearing its end: Contract
- New charter or digital brand: Regulation
Signal Desk · weekly: In-market accounts, scored and mapped
Your buyer and who decides
A regional bank or group
Also challengers and DACH private banks
158 US banks over $10bn · 110 ECB groups
Panel Check · coverage baselined
- COO, CFO or Vorstand, can Veto: A multi-year programme that misses its objectives.
- Boards and committees, can Veto: Reputational and regulatory damage from a failed migration.
- CIO or CTO, can Veto: Implementation overruns and weak vendor support.
- Business line heads: Customers disrupted during the migration.
- Procurement and legal, can Veto: A vendor that won’t accept unrestricted audit rights.
- Outsourcing officer, can Veto: Supervisory findings and concentration risk.
- Information security, can Veto: Examiner findings on third-party controls.
- Internal audit, can Veto: Signing off a programme they never reviewed.
How the deal moves
Strategy and RFI
Long list Typical time: 4–8 weeks
RFP and demos Typical time: 1–3 months
- Where it stalls
- Banks like the features, fear the migration
- With Panelhop: Leak Fix
- IT, outsourcing, security and audit named before the RFP closes
Proof of concept
- Where it stalls
- The pilot goes live; the main book stays
- With Panelhop: Leak Fix
- A named owner for the main migration before the proof of concept
Risk review
Contract terms Typical time: 1–3 months
- Where it stalls
- Audit and exit redlines outlast price talks
- With Panelhop: Leak Fix
- Outsourcing officer mapped at the RFP; audit and exit terms a stage gate
Board approval Typical time: 2–8 weeks each
- Where it stalls
- Each committee meets on its own calendar
- With Panelhop: Panel Ops
- Forecast tracked monthly against each committee’s dates
Migration Typical time: 12–24 months, US
Panel Ops · monthly: Scores and plays tuned against the baseline
Illustrative Source: Stages, seats, triggers and stalls from Panelhop research, October 2026; Nelson Mullins, for the Georgia Bankers Association; FDIC; ECB Banking Supervision; the services as described on the Services page. Note: Durations, panel sizes and cycle lengths are Panelhop estimates from our research, not measurements.
At a glance
| Typical deal | €250k or more a year Illustrative |
|---|---|
| Sales cycle to signature | often over 12 months Illustrative |
| Buying panel | 12 or more people Illustrative |
| Motion | Formal RFP, shaped by integrators and advisers |
Source: Panelhop research, October 2026. Note: Values marked Illustrative are Panelhop estimates from our research, not measurements.
Core deals stall between the pilot and the board.
Where do core banking deals at large banks stall?
Core banking deals at regional and large banks stall at the proof of concept, contract terms and board approval. In Panelhop’s October 2026 sample of 20 vendors, 3 sell enterprise core banking platforms to larger banks and fintechs. Our analysis flags integration with the systems around the core and committee cadence as likely stall points for all 3, and stalled pilots and slow go-lives for 2 of the 3.
Where the pipeline leaks: 5 points across 8 stages.
Migration proof arrives after the bank has decided
- What you see
- Strong feature scores, then a decision to stay with the incumbent core.
- Why it happens
- Integration and migration proof is assembled late, after the bank has formed its view of the risk.
Stage RFP and demos
Your core runs a new brand, never the main book
- What you see
- The greenfield brand is live and stable, but the bank sets no date for moving the main book.
- Why it happens
- No executive owns the main migration decision before the proof of concept starts.
Stage Proof of concept
Audit and exit redlines outlast the commercial talks
- What you see
- Legal redlines on audit rights and exit terms run for weeks after price is agreed, and each EU bank adds its own DORA addendum.
- Why it happens
- The standard contract lacks unrestricted audit rights and an exit plan, and the outsourcing officer joins only at contract stage.
Stage Contract terms
You forecast one approval; the bank has several
- What you see
- Forecasts assume one approval; the deal then meets a risk committee, the management board and the supervisory board in turn.
- Why it happens
- The approval route isn’t captured per account during discovery.
Stage Board approval
Your best references are still mid-migration
- What you see
- Prospects ask for a live reference of their size, and the newest clients are still migrating.
- Why it happens
- Core migrations run for years, and references only appear after go-live.
Stage Migration
End-of-support notices and mergers reopen the core.
What makes a regional or large bank replace its core?
A regional or large bank reopens its core decision when the core contract nears its end, the incumbent’s support or ownership changes or a merger forces one platform. New rules and new charters reopen it too, and most of these events are announced in public.
The 5 events that open or close the window for a deal.
Technology
Legacy core end of support or incumbent sold
- What happens
- The incumbent core’s vendor announces end of support or is acquired, and the bank reviews its roadmap.
- Where to spot it
- Trade press, analyst commentary and the bank’s own investor materials.
- Window
- From the announcement until the incumbent contract can end.
Consolidation
Banking group merger
- What happens
- Merging banks usually move to one core, so the acquirer chooses which platform survives.
- Where to spot it
- Merger announcements, regulators’ approvals and acquirers’ filings.
- Window
- From announcement to systems conversion, while the combined stack is decided.
Regulation
DORA re-papering and register season
- What happens
- EU banks must hold DORA Article 30 clauses in every ICT contract and report their register of information once a year.
- Where to spot it
- National supervisors’ DORA notices and BaFin’s DORA guidance for German banks.
- Window
- Renewals with incumbents turn into renegotiations of audit and exit terms.
Contract
Core contract nearing its end
- What happens
- Core contracts run for years, and banks start evaluating well before expiry, reconsidering the systems around the core at the same time.
- Where to spot it
- Discovery questions, the bank’s investor materials and integrators’ networks.
- Window
- Opens well before expiry; the renewal negotiation itself can take months.
Regulation
New bank charter or digital brand
- What happens
- A new bank, digital brand or specialist lender needs a core from day one and has no legacy data to migrate.
- Where to spot it
- Charter approvals from banking regulators and launch announcements.
- Window
- From licence application to launch, when the core is the first system chosen.
Several committees and the board must all agree.
Who signs off on a core banking replacement at a regional or large bank?
A core banking replacement at a regional or large bank needs the executive sponsor, IT, the business lines, procurement and legal, outsourcing and third-party risk, information security, internal audit and the board. Audit and control functions can stop a project months in, so they belong in the plan from the start. Integrators and selection advisers often shape the RFP, but they hold no veto.
At a regional bank or ECB-supervised group, 12 or more people sit on the panel and 7 seats can stop the deal.
At a regional bank or ECB-supervised group: 12 or more people
Executive sponsor
Can Veto
Chief Operating Officer · Chief Financial Officer · Vorstand member (DACH)
- Cares about
- A migration that protects the bank’s regulatory standing and reputation.
- Worries about
- A multi-year programme that misses its objectives.
Technology and architecture lead
Can Veto
Chief Information Officer · Chief Technology Officer · Leiter IT/Organisation (DACH)
- Cares about
- Integration and migration risk across the systems around the core.
- Worries about
- Implementation overruns and weak vendor support.
Business line heads
Chief Retail Officer · Chief Lending Officer · Head of Fachbereich (DACH)
- Cares about
- New products launched faster on the new core.
- Worries about
- Customers disrupted during the migration.
Procurement and legal
Can Veto
Procurement Manager · General Counsel · Einkauf (DACH)
- Cares about
- Comparable bids, liability caps, exit rights and annual fee increases.
- Worries about
- A vendor that won’t accept unrestricted audit rights.
Outsourcing and third-party risk
Can Veto
Outsourcing Officer (Auslagerungsbeauftragter) · Third-Party Risk Manager · Outsourcing and Third-Party Risk Lead (UK)
- Cares about
- Critical-function classification, DORA Article 30 clauses and the register entry.
- Worries about
- Supervisory findings and concentration risk.
Information security
Can Veto
Chief Information Security Officer · Informationssicherheitsbeauftragter (DACH)
- Cares about
- Security testing, incident response and data location.
- Worries about
- Examiner findings on third-party controls.
Internal audit
Can Veto
Head of Internal Audit · Revision (DACH)
- Cares about
- Control evidence across the whole migration.
- Worries about
- Being asked to sign off on a programme they never reviewed.
Management and supervisory boards
Can Veto
Board of Directors · Board Technology or Risk Committee · Aufsichtsrat
- Cares about
- Strategic fit and the risk of the programme.
- Worries about
- Reputational and regulatory damage from a failed migration.
You sell the system of record for a whole bank.
What do enterprise core banking vendors sell, and to whom?
Enterprise core banking vendors sell deposit, lending and ledger platforms to banks large enough to buy their own stack, often module by module alongside a legacy core. In the euro area, 110 banking groups are supervised directly by the ECB. German Sparkassen and cooperative banks run on their group IT providers’ cores, so in Germany the independent private, specialist and regional banks are the direct buyers.
What vendors of this type sell
- Core banking systems for deposits, lending and the general ledger
- Composable core modules deployed alongside a legacy core
- Greenfield cores for new digital banks and brands
- Country localisation, including regulatory reporting
- Migration services delivered with integrator partners
Which banks and credit unions buy it
- US regional and large banks: 158 with over $10bn in assets
- ECB-supervised banking groups in the euro area
- Challenger, digital and specialist lending banks
- DACH private and specialist banks, among them 129 German regional and other commercial banks
A core decision runs on several calendars at once.
How does a core banking deal move at a regional or large bank?
A core banking deal moves from strategy and RFI through an RFP, a proof of concept, parallel risk reviews, contract terms and board approval, then into a migration measured in years. Each committee works to its own calendar.
Stage by stage: what you do, what the bank does, and what changes at the 4 stages where deals stall.
| Stage | What you do | What the bank does | Today | With Panelhop |
|---|---|---|---|---|
| Strategy and RFI | Publishes gated research and webinars on replacing legacy cores. | Sets a multi-year modernisation plan and issues an RFI. | The vendor hears about the programme when the RFI arrives. | Accounts scored weekly on dated triggers such as an end-of-support notice, a merger or a new CTO. Signal Desk In-market accounts, weekly |
| Long list Typical time: 4–8 weeks | Relies on integrator and partner introductions and analyst recognition. | Builds a long list with integrators and advisers. | Target banks chosen by size alone. | A draft fit model from your own won and lost deals, by bank size, region and incumbent core. Panel Check GTM audit · 2–3 weeks |
| RFP and demos Typical time: 1–3 months | Responds to a formal RFP across many modules. | Scores vendors across business, IT and risk criteria. | IT, risk and audit appear after the demo. Stalls: Integration outweighs features. In Bank Director’s 2026 Technology Survey of US banks under $100bn in assets, 69% of respondents name integration as a top concern, and 58% of those whose project fell short blamed it. | A role map per tier that names IT, outsourcing, security and audit before the RFP closes. Leak Fix We build the fixes |
| Proof of concept | Runs a proof of concept, or a greenfield launch for one brand or product. | Tests the core on a limited scope before committing the main book. | The proof of concept has no owner for what comes next. Stalls: A greenfield pilot that stays small. A new brand or product goes live on the new core, and the main migration never gets a named owner or a date. | A mutual action plan that names the executive owner of the main migration before the proof of concept starts. Leak Fix We build the fixes |
| Risk review | Answers security, resilience and exit questions for a critical function. | Security, outsourcing and audit review the vendor in parallel. | The risk review starts after the vendor is chosen. | A risk review stage with exit criteria, started in parallel with the RFP. Leak Fix We build the fixes |
| Contract terms Typical time: 1–3 months | Negotiates liability caps, audit rights and exit terms, plus a DORA addendum for EU banks. | Legal and the outsourcing or third-party risk officer redline each clause. | Legal and the outsourcing officer first see the deal at contract stage. Stalls: Audit and exit clauses arrive late. In the EU, contracts supporting critical functions must grant unrestricted access, inspection and audit rights, and redlines on audit and exit terms can outlast the commercial talks. | The outsourcing officer and legal named on the role map from the RFP, and a contract stage whose exit criteria include sending your audit and exit terms, with a DORA addendum for EU banks. Leak Fix We build the fixes |
| Board approval Typical time: 2–8 weeks per approval; longer when several committees sit in turn | Prepares material for the management and supervisory boards. | Approves the programme at a scheduled board meeting. | Close dates assume a single sign-off. Stalls: Committees meet on separate calendars. Risk committees, the management board and the supervisory board each meet on their own dates, so approval can span quarters. | Forecast tracked monthly against each committee’s dates and the baseline. Panel Ops We run it monthly |
| Migration Typical time: 12–24 months at a US regional bank; longer at large banking groups | Migrates products and customers in phases with integrator partners. | Moves the book across and logs the contract in its register of information. | What sales promised lives in one rep’s notes. | A handoff document built from the deal, so the migration team inherits what each committee was promised. Leak Fix We build the fixes |
Every committee and clause is tracked on the deal.
How does Panelhop change the way core banking vendors sell to large banks?
Panelhop puts the approval route, the risk seats and the contract clock on every core banking deal, then fixes the stages where those deals stall. A Panel Check (GTM audit · 2–3 weeks) baselines each stage before anything changes, and Panel Ops (we run it monthly) tracks core deals against that baseline.
What we baseline and report
- Days from verbal yes to signature on EU deals, against the baseline
- Seats engaged per open deal across IT, risk, audit and the board
- Qualified pipeline from in-window Tier 1 banks
Other vendor types in banking.
What other vendors sell to banks and credit unions?
The same banks and credit unions buy from these vendor types too, through different panels and pipelines.
- Vendor type
Digital banking and core platforms for community banks and credit unions
Core, online and mobile banking and account opening platforms sold to US community banks and credit unions.
Read the pipeline - Vendor type
Risk, compliance and GRC software for banks and credit unions
Enterprise risk, compliance management, vendor risk and audit software sold to community banks, credit unions and regional banks.
Read the pipeline - Vendor type
Fraud prevention, AML and KYC software for banks
Fraud detection, transaction monitoring, sanctions screening and KYC software sold to banks, credit unions and building societies.
Read the pipeline
The words your buyers use, defined.
What do terms like “Composable core” and “Greenfield launch” mean?
Plain definitions of the terms that come up when you sell enterprise core banking platforms to banks and credit unions.
- Composable core
- A core banking system built from separate modules, such as deposits or lending, that a bank can deploy alongside its legacy core and replace step by step.
- Greenfield launch
- Starting a new bank, brand or product on a new core with no legacy data to migrate. Banks often use one to prove a core before moving the main book.
- Critical or important function
- A DORA term for a function whose disruption would materially impair a bank’s performance or continuity. ICT contracts supporting one must meet the fuller Article 30 requirements.
- Outsourcing officer
- In German banks, the Auslagerungsbeauftragter: the person responsible for outsourcing risk. Core banking contracts cross this desk or the bank’s DORA ICT third-party risk function before signature.
- Exit strategy
- The plan DORA requires for contracts supporting critical or important functions, covering how the bank leaves a provider, including a transition period in which the provider keeps delivering the service.
- Significant institution
- A bank the ECB supervises directly because of its size or importance in its country. The largest euro-area banking groups are significant institutions.
Answers before your next bank deal.
What do vendors of enterprise core banking platforms ask about selling to banks and credit unions?
How long does it take to sell a core banking system to a regional bank?
Selling a core banking system to a regional bank often takes more than 12 months to sign, and up to 36 months by Panelhop’s research estimates. The migration that follows takes 12–24 months at a US regional bank, and longer at large banking groups. The RFP, a proof of concept, parallel security and outsourcing reviews and board approval each add time. In the EU, negotiating DORA audit and exit terms can extend the close further.
How does DORA affect selling core banking software to EU banks?
DORA adds a contract stage to every core banking deal with an EU bank. The bank must put Article 30 clauses into every ICT contract and log each contract in a register of information reported once a year. A core banking contract usually supports critical or important functions, so it must also grant unrestricted access, inspection and audit rights and include an exit strategy. Expect the bank’s outsourcing officer and legal team to redline these terms.
Who signs off on a core banking replacement at a large bank?
A core banking replacement at a large bank needs many sign-offs: the executive sponsor, IT, procurement and legal, the outsourcing officer, information security and internal audit. Several risk committees and the board then approve it. Panelhop estimates buying panels of 12 or more people at large banks. Business line heads champion the change but rarely hold a veto.
Why do core banking pilots and greenfield launches stall?
Core banking pilots and greenfield launches stall when nobody owns the decision that comes after them. A new brand or product goes live on the new core and the technology works, but the bank’s main migration still has no executive owner or date. Agree success criteria and name the owner of the main migration before the proof of concept starts.
Can core banking vendors sell directly to German Sparkassen and cooperative banks?
Core banking vendors rarely sell directly to German Sparkassen and cooperative banks. These banks run on cores provided by their group IT providers, so a core banking vendor reaches them, if at all, through the group. The direct buyers in Germany are independent private, specialist and regional banks, whose management board can decide without group sign-off. Check an account’s group membership before adding it to a target list.
How do core banking vendors get on a regional bank’s long list?
Core banking vendors get on a regional bank’s long list through integrator partnerships, analyst recognition and live references at banks of similar size. Regional and large banks build those long lists with integrators, advisers and analysts. Tracking dated triggers such as an end-of-support notice, a merger or a core contract nearing its end shows which banks are about to reopen the core decision.
Where the numbers come from.
Sources
Sourced figures link to their source below. Figures marked Illustrative, and figures given as estimates, are inferred from Panelhop research. Vendors appear only as types, never by name.
- FDIC, Quarterly Banking Profile, Second Quarter 2026 (2026)
- ECB Banking Supervision, List of supervised banks (2026)
- Deutsche Bundesbank, Bankstellenstatistik 2025: Bestand an Kreditinstituten am 31. Dezember 2025 (2026)
- Bank Director, 2026 Technology Survey (2026)
- Nelson Mullins, for the Georgia Bankers Association, Fear of Commitment: Negotiating core contracts (2020 Ops and Tech Conference presentation) (2020)
- BaFin, Guidance notes on the implementation of DORA for ICT risk management and ICT third-party risk management (2024)
- De Nederlandsche Bank, DORA: Reporting DORA registers of information in March 2026 (2026)
- Panelhop, Services (2026)
- Panelhop research, October 2026: our analysis of the vendors, buying panels, pipelines and triggers for enterprise core banking platforms in banking, from public sources. Vendor names are not published.
Find where your pipeline to banks and credit unions leaks.
