Rails, Not Vaults: The Next Private Bank Won't Build a Core System

Partnership rails — Banking-as-a-Service custody, ISO 20022-native payment messaging, third-party ledgering — let a new house spend its capital on clients rather than clearing. Build-versus-rent stopped being an engineering question some time ago. It is now the strategy itself.

An incumbent private bank carries a core banking system it did not choose, cannot easily replace, and spends a material share of its technology budget maintaining. That system is the reason so many otherwise sensible requests take six weeks: the ledger was designed for a different product set, in a different decade, under different messaging standards.

A house being built now has an advantage that is easy to squander — it can decline to own that problem. The corollary is that it acquires a different one. Renting infrastructure means the operational risk moves from something you control to something you have to diligence, contract for and monitor.

What renting actually buys

Three things, mainly. Regulated custody without building a custody business. Payment messaging that is ISO 20022-native rather than retrofitted onto legacy formats. And a ledger that can be configured for entity structures rather than bent around them.

The strategic consequence is where the capital goes. A house that is not funding a core-system programme can fund relationship depth instead — fewer clients per banker, better structuring work, actual research. That is a different business, not just a cheaper one.

The diligence framework

Renting is only sound if the partner is genuinely better at the thing than you would be. We apply the same framework to every custody, payments and ledger partner, before any client capital touches the rail.

I. Attestation, not assurance

SOC 2 Type II is the baseline, and the distinction from Type I matters: Type I describes controls as designed at a point in time, Type II tests whether they operated over a period. We read the exceptions section first. A report with no exceptions usually means a narrow scope rather than a flawless year — so the scope boundary is the second thing to check.

II. Four-eyes settlement controls

Any instruction that moves value should require two independent authorisations, enforced by the system rather than by policy. The question to ask is not whether four-eyes exists but where it can be bypassed: break-glass procedures, emergency overrides, and administrative accounts are where the control usually has a door in it.

III. Contractual data portability

The most expensive term in an infrastructure contract is the one nobody negotiates. Portability means a documented export format, a defined timeframe, and a contractual obligation that survives termination — including termination for the partner's own failure.

If the exit is not specified in the contract, the relationship is not a partnership. It is a dependency with an invoice attached.

IV. Segregation and the failure case

Client balances should sit in segregated, ring-fenced accounts at tier-one custodians, legally separate from both the house's balance sheet and the rail provider's. The diligence question is specific: in the provider's insolvency, what is the legal mechanism by which client assets are identified and returned, and has it been tested?

V. Concentration across the stack

Three providers is not three points of failure if all three sit on the same underlying cloud region, the same sponsor bank or the same messaging gateway. Dependency mapping has to run to the layer below the contract.

What cannot be rented

Two things. The first is accountability: a client whose payment fails does not have a relationship with the rail provider, and "our partner had an outage" is an explanation, not an answer. The second is the reporting layer. Consolidation across entities, look-through on illiquid holdings and valuation-date discipline are the parts a house should own outright, because they are what the client actually experiences.

Rails underneath, relationship on top. The mistake is renting the part the client can see.