CIOPages
All RFP packages

RFP Package · Industry Solutions

Core Banking & Financial Services Platforms RFP questions and template

129 questions, 10 demo scenarios and a five-vendor scorecard for choosing Core Banking & Financial Services Platforms software, in one Excel workbook.

What this package is for

Use it to run a Core Banking & Financial Services Platforms software selection, from the first long list to the final scorecard.

What the category covers. Software that runs a bank's or credit union's system of record: data migration and coexistence with a legacy core, the product engine, the real-time ledger and interest, customer and account relationships, deposit and loan servicing, instant payments and ISO 20022, banking APIs and events, resilience, audit and supervisory data, and extensions and upgrades. Bought by banking technology, operations and finance leaders replacing or modernizing a core.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 28 questions screen out products that lack something you need.
  • RFP, to the shortlist. 68 questions ask how each product does the work.
  • Deep dive, to the finalists. 33 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 110 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Which components of the tooling used to load legacy accounts, balances and transaction history onto your platform are part of your licensed product, as opposed to partner-built or project-specific code?

Why it matters. If the extract, mapping, load and reconciliation tools are rebuilt for each project, the buyer pays for development, testing and defect fixing on the critical path. The buyer also cannot rely on the tooling being maintained across releases.

Good answer
  • Names each component (profiling, transformation, load, control reporting) and states its ownership and license status
  • Licensed components are versioned and documented, with release notes
  • States clearly which parts a partner typically builds per project and why
Red flags
  • Describes a migration 'methodology' or 'accelerator' without naming software components
  • All tooling is owned by an implementation partner, with no vendor support commitment
  • Cannot say whether the tooling is covered by the product support agreement

2. Does your platform support a progressive migration in which it runs in production alongside [legacy core] and takes over accounts in tranches by product line or customer segment?

Why it matters. If the platform can only go live through a single full cutover, the buyer cannot migrate in stages and must move every account at once, with no partial rollback path.

3. Describe how a new deposit or lending product is defined on your platform: through parameter configuration, through product logic written as code, or a combination of the two.

Why it matters. The definition method sets who can change a product and whether each change needs engineers or a vendor release. A buyer who assumes configuration and finds code inherits staffing and release dependencies it did not budget for.

Capability areas

Data Migration & Balance/History Conversion (12)

Covers extracting, profiling, cleansing, mapping and loading legacy accounts, balances, accrued interest, arrangements and transaction history, plus mock-conversion tooling and handling of edge cases such as dormant, charged-off and closed accounts. Running the old and new cores side by side and cutover sequencing belong to COX.

Coexistence, Parallel Run & Cutover (12)

Covers running the new core alongside the legacy ledger: routing by product or segment, dual-run, ledger-to-ledger reconciliation, tranche-by-tranche cutover and tested rollback. Moving the data itself belongs to MIG, and the contractual exit belongs to the migration-exit module.

Product Engine & Product Lifecycle (12)

Covers how deposit, lending and fee products are defined, versioned, tested and changed: parameter configuration versus code or smart contracts, time to launch without a vendor release, and applying changes to products already held by customers. Servicing behavior specific to deposits and loans belongs to DEP and LEN.

Ledger, Accounting & Interest Processing (12)

Covers the posting model, real-time balances, general ledger and chart-of-accounts mapping, multi-entity, multi-currency and multi-accounting-basis support, interest accrual and capitalization, back-dated and value-dated corrections, and subledger-to-GL reconciliation. Supervisory reporting outputs belong to REG.

Customer, Party & Account Relationships (9)

Covers the party records the core holds and how they link to accounts: individual and business parties, account-party roles (owner, joint owner, signer, beneficiary, guarantor), household and corporate hierarchies, and relationship-level views used for pricing and servicing. KYC screening and onboarding decisions belong to upstream systems; only the KYC status and identifiers the core stores are in scope.

Deposits & Account Servicing (11)

Covers current, savings and term deposit servicing: holds, sweeps, overdrafts, maturity handling, dormancy and escheatment flags, account restrictions and joint or business ownership structures. Product definition itself belongs to PRD.

Lending & Credit Servicing (10)

Covers loan booking from origination handoff through disbursement, repayment schedules, rate resets, restructuring, payment holidays, delinquency and arrears staging, write-off and recovery, and early payoff. Loan origination and credit decisioning systems are out of scope except for the handoff into the core.

Payments, Instant Rails & ISO 20022 (14)

Covers how the core stores and uses ISO 20022 data natively compared with translating at the edge, real-time posting from instant payment rails, funds checks and reservations, returns and exceptions, and how the core and the payment hub divide responsibility. Card processing and payment-hub selection are out of scope.

Banking APIs, Event Streams & Open Finance (10)

Covers the banking-domain API and event model: account, balance, posting and product resources, business event streams from the ledger, open-finance and BaaS exposure, and governed access to the system of record for third parties and AI agents. Generic API availability, SDKs and identity integration belong to the integration module.

Real-Time Operations & Ledger Integrity (10)

Covers 24x7 operation with no end-of-day freeze, running accrual and batch work alongside live posting, idempotency and posting consistency under failover, and how the ledger behaves at peak volume. Contractual RTO/RPO commitments and DR testing cadence belong to the business-continuity-dr module.

Regulatory Reporting, Audit & Controls (10)

Covers audit trails on postings and configuration changes, maker-checker controls, data extracts for supervisory, deposit-insurance and statutory reporting, and the ability to trace a reported figure back to individual postings. Third-party certifications and privacy obligations belong to their own modules.

Extensibility & Upgrade Path (7)

Covers how the bank adds bank-specific logic without modifying the vendor core, how its configuration and extensions behave across vendor releases, and the documented path from the vendor's legacy product line to its current platform. The vendor's commercial roadmap belongs to the roadmap-strategic-alignment module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Load our legacy extract and reconcile it
  2. Move one product line while legacy keeps running
  3. Launch a tiered savings product and change its rate
  4. Book a loan and service it through payoff
  5. Send and receive instant payments during end of day
  6. Post a back-dated correction to a deposit account
  7. Fail over the ledger under sustained posting load
  8. Third-party app and AI agent use scoped APIs
  9. Apply your release over our configuration and extensions
  10. Trace a reported figure back to its postings

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Core Banking & Financial Services Platforms RFP questions are there?

129 solution questions in 12 capability areas: 28 for the RFI, 68 for the RFP and 33 deep-dive questions for the finalists. The workbook adds 110 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Core Banking & Financial Services Platforms

For the business side of the same change: