ArticleTransformation

Core modernisation without the big bang: hollowing out the bank's core, one capability at a time

Core replacement programmes have a long record of overruns and outages. A progressive path — data layer first, capabilities peeled off behind APIs and events, AI to read the legacy code — lowers the risk without lowering the ambition.

7 min read By · Article
£48.65m
combined FCA and PRA fine after a bank's 2018 platform migration disrupted services for up to 5.2 million customers1

Key takeaways

  • Big-bang migrations concentrate risk into a single weekend; the UK's TSB case cost £48.65 million in fines and £32.7 million in customer redress after the 2018 cut-over1.
  • Even well-run replacements overrun: one major bank's core programme was announced at around A$580 million over four years and was reported complete after five years and more than A$1 billion23.
  • Progressive modernisation — building the data layer first, then moving capabilities behind APIs and events — lets each step be proven and reversed.
  • AI has changed the economics of the hardest step, understanding legacy code5.

Every bank's strategy deck promises a modern core. Far fewer have one. The reason is not a lack of vendors or ambition; it is that the traditional route — replace the core in one programme and migrate everything at once — concentrates years of change into a single, high-stakes cut-over. When it goes wrong, it goes wrong in front of customers and supervisors.

What big bangs cost

The most cited cautionary tale is the April 2018 migration at TSB in the UK. The data moved, but the new platform failed on contact, disrupting branch, telephone, online and mobile banking. A significant proportion of the bank's 5.2 million customers were affected, and business as usual did not return until December 2018. In December 2022 the FCA and PRA fined the bank a combined £48.65 million, after it had paid £32.7 million in redress; regulators found that it had failed to organise and control the migration adequately and to manage the operational risks of its IT outsourcing1.

Even programmes that land successfully tend to cost more and take longer than planned. When a large Australian bank announced its core banking modernisation in April 2008, it forecast a cost of around A$580 million over four years, and chose a staged migration explicitly to mitigate risk2. It declared the programme complete in October 2012, after five years and more than A$1 billion of investment3. That was a strategic success — and still close to double the original estimate.

Exhibit 1

Core replacement: the plan and the outcome

Australian bank core banking modernisation, A$ million (A$m)

Note: Forecast from the bank's April 2008 release [2]; completion figure reported as 'over $1 billion' [3], so the bar is a lower bound.

Source: Australian bank investor release, “Core banking modernisation (media release)” (2008)

These cases are consistent with broader transformation data. One analysis of digital transformations found that 70% fell short of their objectives: 30% met or exceeded their targets, 44% created some value but missed them, and 26% created little or none4. One of the six success factors it identified was a modular, business-driven technology and data platform4.

Exhibit 2

Most large transformations miss their targets

Outcomes of digital transformations, % of cases (%)

Source: Published research, “Flipping the odds of digital transformation success” (2020)

The progressive alternative

Progressive modernisation accepts that the core will be replaced over years, and designs for that. Instead of one migration, the bank executes a sequence of smaller, reversible moves, each of which delivers value and retires some legacy. The pattern has four elements:

  • Data layer first. Stream data from the legacy core into a governed, real-time data layer with a common model, lineage and quality controls. New products, analytics and AI read from this layer, not from the mainframe — which immediately reduces load on, and dependency upon, the core.
  • Hollow out the core. Move capabilities with the highest change rate — pricing, product configuration, limits, customer servicing — into modern services outside the core, leaving it as a thinner system of record.
  • Integrate through APIs and events. Put a stable API and event layer between channels and the core, so that front-end change stops requiring core change and the core behind the interface can be swapped segment by segment.
  • Migrate by cohort. Move products or customer segments one at a time onto the new platform, running old and new in parallel with automated reconciliation between them, and keep a tested route back.

The data layer also changes the business case. Traditional core programmes deliver most of their benefits at the end, after the final migration. A data-layer-first approach starts paying back early: real-time analytics, regulatory reporting and AI use cases can all run on the new layer long before the last product leaves the legacy core. That early value is what sustains sponsorship through a multi-year journey.

Where AI changes the economics

The most expensive part of legacy modernisation has always been understanding what the old system actually does. Anthropic argued in February 2026 that the discovery and analysis phases — mapping dependencies, tracing execution paths, documenting business logic nobody remembers — can now be substantially automated, and that COBOL, which it estimates handles about 95% of US ATM transactions, can be modernised in quarters rather than years5. Markets took the claim seriously: IBM shares fell 13% on the day, their steepest one-day fall since 2000, although IBM countered that code translation captures little of the real complexity of mainframe estates6.

Early bank evidence is encouraging, if vendor-reported. A Swiss private bank's generative-AI-assisted modernisation with MongoDB reported migrating code 50 to 60 times faster than previous migrations and moving applications off legacy relational databases 20 times faster7.

The right framing is that AI accelerates comprehension, test generation and incremental refactoring — the work that makes progressive modernisation practical — rather than making big-bang replacement safe. A faster translation of the old core into a new language, cut over in one weekend, carries the same operational risk as before.

AI does not remove the need to migrate carefully. It removes the excuse for not knowing what you are migrating. (SCIKIQ view)

Governance for a multi-year journey

Progressive programmes fail differently from big bangs: not in a single outage but in drift, where the bank ends up running old and new cores indefinitely. The antidotes are a fixed decommissioning plan with dates, a business case measured in retired legacy as well as new capability, and operational-resilience testing of every migration step — the discipline whose absence the TSB findings highlighted1.

For executives

What this means for your bank

  1. Reframe the core programme as a sequence of reversible steps, each with its own business case and exit criteria, rather than a single go-live.
  2. Fund the data layer and API/event layer first; they de-risk every later migration and pay back independently through analytics and AI use cases.
  3. Use AI code-comprehension tools to document legacy logic and generate regression tests before any capability is moved.
  4. Run old and new platforms in parallel with automated reconciliation, and rehearse fallback for every cohort migration.
  5. Track decommissioned legacy (applications, MIPS, contracts) as a headline programme metric to avoid permanent dual running.
Put it to work

How SCIKIQ can help

Reference architecture for a data-layer-first modernisation on the SCIKIQ Data Fabric.

Explore the framework

Assess core and data readiness before choosing a migration path.

Take the maturity assessment

Continuous old-versus-new reconciliation during migration with CLARION.

Learn more

Modernisation advisory, engineering and managed services.

See data engineering services

Sources

  1. 1
    TSB fined £48.65m for operational resilience failings (opens in a new tab) Bank of England (PRA) and FCA, 20 December 2022
  2. 2
    Core banking modernisation (media release) (opens in a new tab) Australian bank investor release, 28 April 2008
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7

Figures are drawn from the cited public sources. Opinions labelled “SCIKIQ point of view” are our own.

Stay informed

Get new banking insights in your inbox

New perspectives on AI, data and transformation in banking — a few times a month. Browse all insights.

Subscribe to SCIKIQ Insights Questions about this insight? Talk to the practice
AI
AI Analystagentic

I'm the SCIKIQ AI Analyst, working with tools rather than from memory. I can:

  • Query the live platform APIs (disputes, fraud, AML, recon, revenue…)
  • Report what the digital workforce is doing: runs, approvals, overrides
  • Start an agent run on a real case and hand you the link to watch it

Every answer shows the tools it used.