Traditional banks increasingly need to modernise their ageing infrastructure in the face of mounting pressure from digital-first challengers, evolving customer expectations and intensifying regulatory scrutiny. In the rapidly evolving sellside landscape, innovation has become a strategic imperative. Ironically, despite their urgent need for innovation, banks’ procurement practices and vendor onboarding processes often actively work against this objective by creating barriers for the firms most likely to deliver innovative solutions: smaller vendors and start-ups.

This article will discuss how:

• The innovation imperative is currently at odds with the procurement reality.
• Banks can weigh the default risk of smaller firms more heavily than the benefits of utilising their innovative technology.
• Forward thinking banks are reducing the default risk by creating ‘innovation labs.’
• Banks can establish best practices for inclusive procurement and onboarding.

By GreySpark’s Theo Ramsdale, Analyst Consultant and Rachel Lindstrom, Head of Capital Markets Intelligence practice

Under increasing regulatory scrutiny, banks are finding existing technology lacking and are realizing that more innovative solutions are needed. Meeting evolving customer demands and staying competitive in a digital-first world is a constantly moving target. Smaller financial technology (fintech) vendors are frequently the source of innovative technologies. Institutions that adopt them do so to transform their operations and customer experiences for the better. However, procurement and onboarding processes at banks produce significant barriers, effectively excluding smaller vendors from consideration.

The scale of this vendor relationship challenge is significant. Recent industry research indicates that 61% of bulge bracket Investment Banks bought half or more of their newly deployed software rather than building it in-house this past year. For boutique investment banks, this number was 55%. Furthermore, 90% of bank executives indicate that these partnerships are critical for driving their institution forward.

Nonetheless, despite this acknowledgement, smaller vendors remain disadvantaged in procurement processes. Banks’ vendor onboarding procedures are often designed for traditional, large suppliers, and not for agile firms or startups with limited resources. Smaller vendors face disproportionate hurdles in security, compliance and contractual requirements, effectively preventing these firms – and their potentially innovative solutions – from reaching implementation. This systematic disadvantage creates a significant innovation bottleneck, limiting banks’ access to ground-breaking technologies and procedures that could transform their business.

The market impact extends beyond banks, however. Smaller vendors lose opportunities for growth and increased revenue due to prohibitive onboarding costs and extended sales cycles. The financial landscape, thus, misses the opportunity to become more competitive and diverse, and instead remains dominated by larger vendors. Consequently, potentially transformative solutions that can reduce costs or enhance services are passed over for more established, but potentially less innovative, solutions.

This innovation bottleneck is seeing growing political recognition. In 2024, the UK Labour Party included “embracing innovation and fintech as the future of financial services” as a key priority its financial services plan. Rationalising this, Labour asserted that, despite the UK’s historic reputation as a leading global fintech hub, the country “is in danger of slipping behind when it comes to innovation in financial services.” Procurement processes, along with regulatory barriers, can be an inhibiting factor to progress across the global banking sector.

Why Banks Are Unfavourable to Smaller Vendors

A range of specific factors in bank procurement processes disproportionately disadvantage smaller vendors. Vendor onboarding lifecycles are lengthy, multi-phase processes, involving a legal review, KYC/AML compliance, security assessments, procurement approvals and more. Not to mention, vendor onboarding is usually the final stage of a lengthy sales cycle. For smaller vendors, constrained by more limited cash reserves than their established competitors, these lengthy cycles, as well as delays in finalising contracts, can be financially devastating. On the other hand, larger vendors can absorb the impact of waiting 6 to twelve months for their onboarding to be completed.

Banks, rightly, mandate comprehensive documentation from vendors to exhibit the robustness of their security measures and the durability of their business. The documents include SOC 2 certification, ISO 27001 compliance, penetration testing reports and detailed disaster recovery plans. Many small vendors simply do not have the resources to meet these requirements. When they do, they do so at a high relative cost. This brings about a paradoxical dilemma for smaller vendors, they need banking clients to grow but cannot secure these investments without the banking clients they can only acquire after achieving growth.

Naturally, banking institutions tend to have a positive bias toward more established vendors, as they are deemed safer in risk assessments. Risk aversion, deeply embedded into the fabric of banking operations and governance, means small, innovative players must work exponentially hard to demonstrate the reliability of their software and the robustness of their business continuity plans. They are often held to standards that even dominant, long-established vendors struggle to meet. Indeed, in 2024, the European Central Bank found that over 10% of contracts covering critical business functions are non-compliant with relevant regulations. Due diligence questionnaires (DDQs) issued by banks during the procurement process can absorb days or weeks of valuable cross-functional staff capacity to develop a response, it often requires input from executive leadership, technical teams and compliance personnel. Figure 1 shows the vendor onboarding process for investment banks.

Even after successfully navigating the initial onboarding process, banks typically mandate that their suppliers maintain extensive cyber liability insurance, professional indemnity insurance and, in certain cases, meet minimum capital thresholds. Again, the cost of adhering to these requirements can be prohibitively expensive for smaller vendors, and startups, operating on limited funding.

Figure 1: Traditional Vendor Onboarding Process at a Banking Institution
Source: GreySpark analysis

‘Innovation Labs’ are Bridging the Gap

Recognising these challenges, many forward-thinking institutions – including leading global banks – have established innovation labs as alternative routes for engagement with smaller vendors. Figure 2 shows the ways in which innovation labs can reduce the timeline for banks to onboard a vendor.

These labs are dedicated initiatives or spaces – either physical or virtual – that test emerging technologies, run proof-of-concepts (PoCs) and foster collaboration between procurement, business and technology groups. These labs are, effectively, safe zones, where solutions can be trialed because of the temporary relaxation of traditional onboarding hurdles. Innovation labs currently operated by global banks (not exhaustive) are shown in Figure 3.

Figure 2: Streamlined Vendor Onboarding Process with Innovation Labs
Source: GreySpark analysis

There is typically a structured selection process for vendors to be accepted into these innovation labs. Initially, banking institutions seek promising vendors through accelerator programmes, pitch days or vendors referred to them by venture capital firms. Banks categorise vendors by business relevance and technical fit. If they are deemed relevant, the vendor is implemented in a small-scale pilot, typically lasting eight to 12 weeks. These small-scale pilots allow a relatively relaxed onboarding process as vendors are provided with ‘sandbox’ permissions, whereby they are granted limited, ring-fenced access to certain systems and software or simply to a test environment with instances of systems. This more relaxed onboarding process also includes lighter security due diligence. Finally, if successful in their pilot, the vendor is passed on to core business or technology teams for rollout into the production environment.

Figure 3: Notable Innovation Labs Established by Leading Financial Institutions
Source: GreySpark analysis

There is a plethora of advantages for a smaller vendor participating in an innovation lab. They can effectively bypass the slow, multi-month procurement cycle (at least in the earlier stages). If they perform well, the lab and pilot schemes are a strong opportunity for them to gain an internal champion within the bank, as well as real user feedback. Most importantly, good performance in a lab initiative is a valuable source of credibility to win over future clients and investors.

Several common characteristics can be observed in successful innovation labs. An important dependency for success is the minimisation of bureaucracy, preserving the nimbleness and quick decision-making that gives smaller firms, and startups, their edge.

An instructive case study from outside banking is BP’s innovation lab, Launchpad. The firm’s innovation lab was created “to take disruptive technologies and business models and grow them fast to become BP’s future business units. Launchpad has since been denoted as a ‘scale-up factory’. The hub’s most prominent venture, Lytt, a manufacturer of fiber optics to detect sand interference in offshore wells, has been credited with saving billions of USD in maintenance. The technology was then marketed to other companies. Lytt, then, is an example of the success of an innovation lab, alleviating Infosec concerns, but also helping the firm to build beneficial relationships successfully.

Best Practices to Avoid Disadvantaging Smaller Innovative Suppliers

Innovation labs are an unconventional pathway to build a bank/vendor relationship that is unequivocally valuable to both parties. Nonetheless, banking institutions must also focus on transforming their wider onboarding and procurement practices to make them more equitable, while maintaining necessary risk controls.

The US Federal Deposit Insurance Corporation (FDIC), and the US Federal Reserve, recommend that all vendor due diligence, risk and contact information be kept in a centralised, easily accessible location. A central repository, as described, benefits smaller vendors by reducing the time taken for various bank teams – e.g., risk, procurement, and legal – to locate and verify documentation, often found in information siloes across different teams. Furthermore, a central repository would streamline audits, which are often a barrier due to the documentation burden. At present, 60% of vendors deemed non-compliant were found to have not been properly audited.

A central repository also facilitates consistent tracking and management of the third-party vendor ecosystem, while creating visibility into the vendors of vendors – commonly referred to as fourth-party vendor risk – to efficiently shield the organisation against cascading risks. Not only does this allow the bank to understand and properly evaluate shared risk exposures but it allows the bank to do so without requiring the vendors to repeatedly show documentation to justify their infrastructure choices.

Banks must ensure they are effectively categorising vendors based upon the level of risk they pose to the business. This allows the proper identification of critical vendors, which is crucial given that approximately 50% of outsourced critical functions concern time-critical activities. The most efficient way to accomplish this is to establish risk-based approval processes where high-risk vendors require board approval and low-risk vendors can proceed through a more streamlined process. Risk-based categorisation ensures smaller vendors are not subjected to the same intensive requirements as high-risk providers, thus preventing disproportionate burdens on companies with limited resources.