LIBERATEERPFinancialServices

Core banking in the Middle East: the licence is the smallest line, and the rebuild is 12 months

Sumeet Goenkasaasinator AI10 min read

The licence is not the bill

A mid-sized Middle East bank running on Temenos Transact, Oracle FLEXCUBE, or Finastra Phoenix is staring at an annual licence cost that is a real and material line in the technology budget. The licence is also not the bill that is hurting the CIO.

The bill that is hurting the CIO is the system integrator retainer that keeps the platform running, the per-release certification work that the regulator requires, the parameterisation work that runs into every new product launch, the integration cost back to the channel layer that has been rebuilt twice in the last decade, and the AI-readiness investment the vendor is now pitching on top of the existing relationship. Stack all of those against the original licence number and the platform's true annual cost at a mid-sized Middle East bank typically sits at three to four times the headline licence. That is the number we model when a CIO asks us what a rebuild would actually cost against.

This piece is what we tell board-level audiences when the question of "can we build" lands on the agenda. It is not a recommendation to rebuild. It is the working model we use to compare the rebuild option against the renewal trajectory.

What sits inside the multiplier

Four cost layers compound on top of the licence.

The system integrator retainer. Tier-one core banking platforms are not operated by the bank's own staff. They are operated by the integrator's bench, with the bank's staff in a supervisory and product-ownership role. The retainer is structured as a per-engineer monthly fee at a rate that has grown faster than the bank's own salary bands. The integrator carries the institutional memory of the configuration. The bank carries the cost.

The certification and release cadence. Every Middle East regulator — the Central Bank of the UAE, the Saudi Central Bank, the Central Bank of Bahrain, the Central Bank of Kuwait — has a release certification process that the platform must pass each release cycle. The certification work is partly bank-owned and partly integrator-owned. The integrator's portion is billable. The bank's portion competes with every other priority on the technology calendar.

The parameterisation tax on new products. A new deposit product, a new lending product, a new corporate banking workflow — each is implemented as a parameter set in the core banking platform. The parameter sets are not edited by the bank's product team. They are authored by the integrator's specialists. The lead time from product approval to live deployment is measured in months, and the cost is measured in five-figure dollar amounts per change. The product team has learned to ration product launches against the bill.

The channel integration cost. The mobile banking app, the internet banking surface, the corporate banking portal, the API gateway the regulator's open-banking mandate now requires — all of these read from and write to the core. Each is a separate integration that the integrator has either built or certified. Each is rebuilt at the channel's natural refresh cycle, which is faster than the core's. The channel team carries an integration cost that is structurally tied to the core's release schedule.

Sum those four against the licence. The number that lands at the CFO's desk is the multiplier the rebuild option is being measured against.

What "rebuild in 12 months" actually contains

The rebuild is not a single project. It is a sequence of workflow replacements running against a stable core. The core itself stays in place for the duration of the engagement. The workflows on top of the core retire on a schedule.

The 12-month timeline is the working envelope for a tier-two Middle East bank, defined as a bank with up to several hundred million dirhams in operating cost, a single jurisdiction of primary supervision, and a corporate banking book that is the dominant share of the balance sheet. Tier-one banks operate on a longer timeline. Digital-native banks operate on a shorter one. The 12-month envelope is the middle of the distribution.

The sequence we run:

Quarter one — the channel layer. The mobile and internet banking surfaces retire their dependency on the vendor-recommended channel layer and move to owned software. The integration to the core is a single defined boundary the bank's platform team operates. The cost of the channel team's next refresh cycle drops materially.

Quarter two — the customer-data layer. The customer master record, the relationship hierarchy, the regulatory KYC artifacts, the segmentation model — all of these move from the core's own data model to a customer-data layer the bank owns. The core continues to hold the transactional records. The bank's data team now controls the surface the rest of the estate reads from.

Quarter three — the product origination layer. The deposit and lending product origination flows, the documentation generation, the approval routing, the regulatory-disclosure handling — these move to owned software. The product team can launch new products on the bank's calendar rather than the integrator's. The parameterisation work that funded the integrator's product specialists shrinks at the next renewal.

Quarter four — the analytics and reporting layer. The regulatory reporting, the management reporting, the risk-and-compliance dashboarding, the AML pattern surface — these move from the vendor-extension architecture to owned analytics on the bank's data warehouse. The integrator's reporting retainer shrinks. The regulator's view of the bank is identical because the reports are identical.

What is not in the 12 months

The transactional core — the ledger, the posting engine, the regulatory transaction reporting that the central bank's supervisory team reviews directly — is not in the 12-month envelope. That work is a separate decision on a separate timeline. Banks that have run the rebuild above for 12 months are in a meaningfully better position to make the transactional-core decision in year two, because they own the workflows around it and they have validated the platform team's capability to operate them. The transactional core conversation in year one is the wrong conversation. It is the conversation in year two only if the workflows have moved first.

The regulator's view

Each Middle East regulator has a position on technology change at supervised institutions. None of them, in our experience, has objected to the workflow-replacement sequence above when the bank has presented it correctly. The regulator's interest is in the institution's resilience, the auditability of the transactional record, the cybersecurity posture, and the ability to recover from disruption. The rebuild sequence above improves all four when the bank's platform team owns the workflows that previously lived inside the vendor's perimeter.

What the regulator does not want is a bank that has lost institutional knowledge of how its own systems work. That is the failure mode of the current arrangement, where the integrator owns the configuration and the bank owns the cost. The rebuild moves institutional knowledge back into the bank.

The saasinator perspective

The bank that runs the first quarter of the sequence above has not committed to the full 12 months. The decision in front of the board is whether to authorise the first quarter. The output of the first quarter is a working channel layer running against the existing core, owned by the bank's platform team, with a clean integration boundary back to the core. The decision to authorise the second quarter is a separate decision, made with the benefit of the first quarter's evidence.

This is the pattern that works in regulated environments. Not a multi-year programme funded once. A sequence of one-quarter decisions, each justified on its own.

The board conversation that lands well is the one where the chief technology officer can show that the bank's platform team operates one critical workflow without integrator dependency. Once that proof exists, every subsequent conversation about the rest of the estate is a different conversation. The renewal trajectory bends.

Book a diagnostic

The diagnostic for a Middle East bank is a 15-working-day engagement, not the standard 10. The additional days fund the regulatory and audit conversations that the technology team cannot conclude on its own. The output is a working model of the four cost layers, the rebuild sequence we would recommend against the institution's specific posture, and the first-quarter scope that would constitute the validation step.

Bring the latest vendor renewal sheet, the integrator retainer schedule, the regulatory release calendar, and the channel team's current refresh roadmap. We will tell you which quarter would flip first and what the first 90 days would contain.


Share this insight