The banking sector is one of the world’s largest investors in digital transformation and innovation, yet part of its operations still relies on obsolete software, often embedded precisely in the core systems on which accounts, payments, customer records, lending and back-office processes depend.
The figures help illustrate the scale of the problem. According to recent findings, 63% of banks still rely on code written before 2000, while 77% report having just one or two people within the organization with the skills required to manage legacy systems. More than a technical anomaly, banking legacy is therefore a structural constraint, a factor that absorbs budgets, slows down change and increases dependence on increasingly scarce expertise.
In this article, we will focus on the often underestimated cost of keeping legacy systems running in the core areas of banking operations.
Key points
- Despite investments in innovation, many banks continue to base their operations on legacy systems that are increasingly difficult to maintain and evolve.
- Many banks continue to assess these systems only partially, limiting their calculations to the visible costs of licenses, renewals, and infrastructure, without including hidden costs.
- Skills shortages, slower innovation, technical debt, regulatory complexity and operational inefficiency are some of the consequences.
The importance of the Total Cost of Ownership (TCO) of legacy systems
Many companies consider the cost of legacy systems to be what appears on the balance sheet, namely licenses, fees, maintenance, and the costs of the underlying infrastructure. However, this is only a partial view of the issue, because the real question is not the cost required to keep legacy systems running, but the burden of continuing to use them in the most critical areas of banking operations.
When the perspective is broadened to include the Total Cost of Ownership (TCO), a different reality emerges: financial institutions tend to underestimate the overall cost of legacy systems by between 70% and 80% (Digital Bank Expert), because they exclude from their calculations a long list of hidden costs spread across IT, operations, compliance, business, and customer service.
The fundamental mistake many organizations make is to consider these systems as depreciated assets and therefore, at least apparently, inexpensive. In reality, they cost much more than they seem to.
Below are some of the areas that should be included in the cost perimeter.
The skills shortage and the hope placed in AI
The skills shortage is probably the most insidious hidden cost of banking legacy systems. Many platforms still in operation are based on languages and architectures that belong to another era of IT, such as COBOL.
- The first problem is that professionals capable of understanding, modifying and maintaining these systems are progressively leaving the labor market. The risk is not only having to pay more for scarce expertise, but also losing critical institutional knowledge.
- Another closely related problem is that a significant amount of knowledge is not fully documented, but is held exclusively by those who have built, fixed, adapted and kept the software running for years. This brings us back to the previous point.
In this scenario, AI can be of great help. Not because it eliminates the need for specialized expertise, but because it helps reduce the pressure: code analysis tools, automated documentation and contextual assistance now make it possible to read legacy code, reconstruct its logic more quickly and support teams that do not consist exclusively of long-standing specialists. These tools do not replace the expert, but they amplify their analytical capabilities and help make a dependency that, for many banks, has already become a major cost less fragile.
Legacy holds back competitiveness
Some analysts refer to this as an innovation tax. Keeping legacy platforms running is not only a direct cost, but diverts resources away from business evolution. In other words, the bank is not simply spending money to keep obsolete systems running; it is spending to continue living with a constraint that slows down its ability to innovate, launch new services, and respond to market expectations.
This is where the legacy issue intersects with competitiveness. Customers, accustomed to seamless, real-time digital experiences across many sectors, expect the same level of simplicity and immediacy from their bank. But when the heart of operations rests on monolithic architectures, batch processes, and outdated application logic, introducing new features inevitably becomes slower and riskier.
The result is a time-to-market that is incompatible with that of new players: where a neobank or fintech can experiment, fix issues, and release new products within weeks, a bank built on legacy systems may take months, if not years, to achieve the same result.
It is no coincidence, therefore, that much of the competitive pressure exerted by challenger banks and fintechs stems precisely from this. The advantage of these players does not depend solely on a better interface or a more contemporary brand, but on the fact that they are built on modern, modular and API-first stacks, designed to operate in real time, communicate and evolve rapidly.
Technical debt: every change becomes a risk
Another component of the TCO of legacy systems concerns the technical debt they generate over time.
Customization has always been a major strength of core systems: each bank adapted the software to its own needs, tailoring it to products, processes, regulatory constraints and operational logic. Over the decades, however, this flexibility has generated complexity, and today every update, regulatory change or integration can trigger effects that are difficult to predict.
Testing cycles become longer, dependencies between modules increase, the risk of introducing regressions grows, and the cost of any intervention rises far beyond the apparent value of the requested change. It is therefore not surprising that some banks choose to stand still: if the system continues to work, touching it may seem riskier than continuing to live with it.
In the banking sector, this problem is compounded by other factors, such as the presence of redundant systems inherited from mergers and acquisitions, as well as the persistence of infrastructure models typical of the pre-cloud era, based on dedicated hardware and over-provisioned capacity to handle peaks or continuity requirements.
Rising compliance costs
Banks must comply with a dense, constantly evolving regulatory framework, with increasingly detailed requirements for control, traceability, data protection and reporting. The problem is that adapting rigid, layered and highly customized platforms to regulations such as GDPR, NIS 2, DORA and many others requires considerably more effort than is needed on more modern architectures designed to evolve.
The cost is not limited to the compliance project itself. The real economic burden is reflected in the proliferation of tactical interventions, workarounds, add-on components and temporary solutions introduced to bring systems into compliance with new regulatory requirements. Every patch and parallel process built to produce a piece of data increases the complexity of the IT ecosystem, makes maintenance more difficult and introduces new points of fragility.
Security and business continuity: the cost of fragility
In a context such as banking, where service continuity, transaction reliability and the availability of digital channels are essential elements of the customer relationship, even a limited outage or performance degradation can generate high economic and reputational costs.
The problem is that legacy systems, precisely because of their age, the level of customization accumulated over time, and the complexity of the dependencies surrounding them, tend to be more difficult to monitor and secure without introducing side effects.
Security is a key issue. Systems designed in eras very different from today were not built with security by design principles, and often have to be protected through additional layers of controls, segmentation, monitoring and risk mitigation. This does not mean that legacy systems are inherently insecure, but that keeping them aligned with current requirements requires greater economic and operational effort than a modern platform. When this is compounded by inflexible architectures, data distributed across multiple environments and application dependencies that are difficult to map, it is easy to understand why business continuity and cybersecurity represent a significant part of the cost of banking legacy systems.
Kirey: modernizing banking legacy systems to unlock competitiveness and innovation
At Kirey, we support companies throughout their digital transformation journeys and can rely on a well-established specialization in the finance sector.
One of our key activities is supporting banks through the complex processes involved in modernizing application systems, from core banking to the platforms that support operational, decision-making, and customer-facing functions. Our goal is to reduce the complexity accumulated over time, overcome the constraints imposed by legacy systems, and restore to IT a truly enabling role in the institution’s innovation and competitiveness.
Contact us to find out how to reduce the burden of legacy systems, optimize their costs and build a banking infrastructure ready for the future.
