Skip to content
Go to homepageDrova logo
Risk Management

Your core banking platform just got a co-pilot your credit union never hired

AI is layering new failure modes onto an old concentration risk, and the fix is three questions, not a re-platform.

Giovanni Aracu
Giovanni AracuSales Director, EMEA, Drova
30 Jun
An aerial view of dense UK terraced housing at golden hour

Most UK credit unions run on one of a small number of core banking platforms, chosen years ago and rarely revisited. It runs the transactions, the balances and the regulatory returns, and for a small team that single dependence is simply the sensible way to operate. The catch is what you don't control. When your platform vendor builds AI into that engine, fraud screening, decisioning, whatever comes next, you aren't in the room for the decision. You may not even know it happened. And if it goes wrong, you're still the one who answers for it.

In our free AI Disruption Risk Index for UK credit unions, core banking platform concentration scores 71 out of 100. The dependency itself is old news, a paragraph in every board pack. What earns the 71 is what is now running inside it.

 

Leaning on one vendor is old. The three things AI added are not

 

The register entry is the classic one: reliance on a single core banking platform for member transactions, balance management and regulatory reporting creates concentration exposure if that vendor's performance, pricing or solvency slips. True for years, managed for years. AI layered three new pressures on top, and you can't see any of them from the outside.

Lock-in deepens: as AI threads into member-facing workflows, leaving stops being a data migration and becomes the unpicking of decisions the system now makes for you. Opacity grows: vendor AI rarely arrives with model cards, training-data disclosures or governance audits, so you carry accountability for outcomes produced by a process you cannot inspect, and supervisors increasingly expect you to, even for an outsourced model. And failure changes shape: an outage that used to clear in four to eight hours can run longer when an AI subsystem sits in the recovery path. That last one is squarely PRA operational resilience territory, alongside the model-risk expectations in SS1/23, and it is the part you cannot delegate to a supplier relationship.

 

The fix is three questions, not a re-platform

 

The good news is the answer is far smaller than the problem sounds. You do not re-platform. You do not build anything. Your vendor governance was written for a pre-AI relationship and simply needs an AI layer on top: three written questions to the vendor about how it uses AI and how it governs it, put on file, refreshed once a year. What is the model doing. Who is accountable when it gets one wrong. What happens then.

What separates the credit unions getting ahead of this isn't the questions. It's what they do with the answers. A clean answer goes straight into the operational-resilience self-assessment, so a supervisor sees a dependency that is understood rather than assumed. No answer is just as useful: that silence goes onto the register as a known gap and onto the next board agenda. Either way an unknown becomes a managed decision. The only bad version is the one where nobody asked, and the platform answered for you at eight in the morning.

 

This is operational resilience, not procurement

 

It's tempting to file vendor AI under procurement and move on. The frozen account says otherwise. That member's money was locked up overnight with no explanation, and no one at the credit union able to give one, which makes it a continuity failure and a conduct failure in the same breath. Operational resilience expects you to know the important services your members rely on and the resources sitting behind them. An opaque AI subsystem inside your core, in the path of payments and lending, is exactly such a resource, and the fact that a vendor runs it doesn't move the accountability off your board. You can outsource the system. You can't outsource the answer you owe a member, or a supervisor, when it fails at eight in the morning. It is also why those three questions are worth more than they look: they are the difference between a board that can describe how a critical service behaves under its AI, and one that finds out alongside the member.

 

A dependency you can plan around, once you can see it

 

The catch is that this isn't a once-a-year job pretending to be one. The vendor's model will change long before your annual review comes round again, so the AI layer on your governance has to stay live to be worth anything. Drova RunSafe keeps that dependency map and its evidence current as the vendor moves, so concentration becomes a decision you make on purpose rather than one that makes itself overnight.

Get ahead of it and it's a risk you manage on your own terms. Leave it, and the first you hear of it is a member's complaint, after the damage is done.

The full UK edition scores it against the continuity objective it threatens, alongside the three other risks that matter most, worked through an anonymised £28m credit union. It's free.

See where core-platform concentration sits on your register. The Index, UK Credit Unions edition, is a free, board-grade picture of the risks and opportunities AI is reshaping for the sector.

Get the AI Disruption Risk Index