A core banking platform is, for most institutions, a critical or important function's ICT dependency. That places the provider, and the provider's own sub-processors and model providers, inside the institution's third-party risk framework: due diligence, contractual provisions, the register of information, concentration assessment and exit planning. Separately, the EU framework allows certain critical ICT providers to be designated for direct European-level oversight; whether a given provider is designated is a supervisory decision, not a vendor claim. Below is what an institution should expect to be able to ask for. CoreFi's own posture against each item is summarised in the Trust Center, with the detailed documentation available on request under NDA.
Contractual provisions
Ask for service descriptions, availability commitments, data-location terms, incident-notification commitments and sub-processor change notification in the contract, not in marketing material. CoreFi documents these in the service agreement and the Data Processing Agreement.
Audit and access rights
Ask for the right to audit, the documentation set that supports it and audit-log extracts on request. CoreFi supports customer audits and supervisory requests with documentation and extracts from the append-only audit record.
Exit and portability
Ask how customer, account, ledger and audit data leave the platform, in what formats, and what the off-boarding terms are. CoreFi's adoption paths each carry a defined exit posture, with data exportable in standard formats.
Incident cooperation
Ask who detects, who notifies, on what severity scale and with what evidence. CoreFi detects, notifies and remediates at the platform layer; the customer classifies and reports at the regulatory layer, with hand-off points defined in the DPA.
Resilience testing support
Ask whether the provider will participate in your testing programme. CoreFi documents business-continuity and disaster-recovery procedures in the trust pack, and participation in a customer's resilience-testing exercises, including scenario walkthroughs of platform failure modes, is available on request.
Sub-processor transparency
Ask for the sub-processor chain, including model providers, with regions and roles. CoreFi publishes the categories publicly and shares named vendors in the evidence pack; the audit log records which model produced each agent action.