Banks should choose a CRM managed services provider the same way they choose any third party that touches customer data: run due diligence scaled to the risk, write the controls into the contract, and monitor the provider after go-live. In practice that means scoring each candidate on banking regulatory fit, core integration skill, security and access controls, support model and evidence they can hand an examiner, then checking references at banks of a similar size. The June 2023 Interagency Guidance on Third-Party Relationships from the FDIC, Federal Reserve and OCC is the best frame for that process.
A managed services provider takes ongoing responsibility for the health and change of your CRM under a monthly agreement. For a bank, the scope usually covers six areas.
Administration. User provisioning and deprovisioning, profiles and permission sets, page layouts, reports and dashboards, and the daily tickets that pile up when branch staff, relationship managers and the contact center all share one system.
Release management. Salesforce ships three major releases a year. Each one needs a sandbox preview, regression testing of your automations and integrations, and a decision about which new features to switch on.
Data quality. Duplicate households, orphaned accounts, stale officer assignments and mismatched product records. A managed provider should run scheduled data quality checks and fix the root cause (usually an integration mapping or a missing validation rule) as well as the bad records.
Integrations. Monitoring the connections between the CRM and your core, loan origination system, digital banking platform and marketing tools, and owning the triage when a sync fails.
Change control. A documented process for every change: request, risk rating, build and test outside production, approval, deployment and record. This is the part examiners care about most.
Roadmap. A quarterly review of what's working, what users are asking for, and what the bank wants the CRM to do next year, such as a treasury management pipeline or a deposit retention program.
A proposal that covers only administration is a help desk contract.
On June 6, 2023, the Board of Governors of the Federal Reserve System, the FDIC and the OCC finalized the Interagency Guidance on Third-Party Relationships: Risk Management, published in the Federal Register on June 9, 2023 (88 FR 37920). It replaced each agency's earlier third-party guidance, including the FDIC's 2008 Guidance for Managing Third-Party Risk (FIL-44-2008).
Two principles matter most for CRM vendor selection. First, using a third party "does not diminish or remove banking organizations' responsibilities." Your bank owns the outcome whether your admin is on payroll or at a consulting firm. Second, oversight should be proportionate. The guidance says "not all relationships present the same level of risk," and asks for more comprehensive oversight of relationships that support higher-risk or critical activities.
The guidance organizes third-party risk management around a life cycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination.
The guidance lists due diligence considerations that you can map directly to a CRM managed services provider:
| Guidance factor | What to ask a CRM managed services provider |
|---|---|
| Legal and regulatory compliance | Which banks do you support today, and how do you handle changes touching customer data or communications? |
| Financial condition | Can you share financial statements or a credit reference appropriate to the contract size? |
| Business experience | How long have you supported banks, and can we speak with two of them? |
| Qualifications of key personnel | Who exactly will work in our org, at what seniority, and from which locations? |
| Risk management and internal controls | Show us your change control procedure and a sample change log. |
| Information security | How are your staff's credentials, devices and access to our org controlled? |
| Operational resilience | What happens to our support if our named consultant leaves or is out? |
| Incident reporting and management | How fast do you notify us of a security incident involving our data? |
| Reliance on subcontractors | Do you subcontract any work, and where are those people based? |
| Insurance coverage | What cyber and professional liability coverage do you carry? |
For contracts, the guidance's list of provisions includes performance measures, right to audit and require remediation, responsibility for compliance with laws and regulations, ownership and license, confidentiality and integrity, subcontracting, foreign-based third parties, default and termination, and regulatory supervision. Your CRM agreement should address each one.
The guidance's monitoring factors include contract performance, key personnel and subcontractor changes, incident response and data integrity. For a CRM provider, a practical package is a monthly usage and activity report, a quarterly governance review, an annual review of the provider's security practices, and a record of every access to your production org.
Section 501(b) of the Gramm-Leach-Bliley Act is implemented for banks through the Interagency Guidelines Establishing Information Security Standards (for FDIC-supervised banks, Appendix B to 12 CFR Part 364). (The FTC's Safeguards Rule covers non-bank financial institutions.)
The guidelines require banks to exercise "appropriate due diligence" in selecting service providers, require them by contract to implement appropriate safeguards, and, where the risk assessment calls for it, monitor them through audits or test summaries. The security measures banks must consider include access controls, encryption of customer information in transit and at rest, change control procedures consistent with the security program, dual control and segregation of duties, and monitoring to detect intrusions. Management reports to the board at least annually, including on service provider arrangements.
The FFIEC IT Examination Handbook is what examiners use to assess technology risk. Two booklets are most relevant to CRM operations. The Development, Acquisition, and Maintenance booklet, issued in August 2024 (FDIC FIL-60-2024) to replace the 2004 Development and Acquisition booklet, covers change management and maintenance processes. The Architecture, Infrastructure, and Operations booklet (June 2021) covers how systems are run and monitored day to day.
Typical requests in an IT exam or vendor management review:
Ask each candidate for a redacted sample of each.
Most bank CRMs connect to a core (Fiserv, Jack Henry, FIS or Finastra are common), a loan origination system such as nCino (which is built on the Salesforce platform), and a digital banking platform such as Q2. The common design keeps the core as the system of record and the CRM as the system of engagement, with data moving through middleware like MuleSoft, a nightly batch with event-driven updates for key changes, or a vendor connector where one exists. Our core banking integration page and nCino integration page describe these patterns in more detail.
Sync failures are routine: a core upgrade changes a field, a token expires, or a batch file arrives late. Ask whether your provider has a defined way to handle them:
Ask candidates to walk you through the last integration failure they handled for a bank, step by step.
Permissions. Least-privilege profiles and permission sets, role hierarchy and sharing rules that reflect who should see which households, and restricted access to fields like SSNs and account numbers.
Encryption and audit. Salesforce Shield adds Platform Encryption for data at rest, Event Monitoring for user activity, and Field Audit Trail for longer field history retention. Your provider should know how to configure it without breaking search, reports or integrations.
MFA and SSO. Salesforce requires multi-factor authentication for logins to its products. Most banks route logins through single sign-on with their identity provider and enforce MFA there.
Provider access. Named accounts for each consultant (never shared logins), MFA on those accounts, access removed when people roll off, and production changes limited to the deployment process.
| Model | Best for | Watch out for |
|---|---|---|
| In-house admin | Banks with steady demand and budget for at least one full-time admin plus backup | Single point of failure, release testing and integrations often exceed one person's skills |
| Retainer | Banks with a capable internal admin who needs senior help each month | Usually fewer governance deliverables; check what reporting is included |
| Managed services | Banks that want one accountable provider for admin, releases, integrations, change control and roadmap | Confirm business hours, response targets and who owns the core side of integrations |
| Vendor professional services | Specific projects or product questions from the CRM vendor itself | Typically project-scoped, not day-to-day administration |
| Offshore admin hours | Banks with high volumes of simple, well-defined tasks | Foreign-based third parties need explicit treatment under the 2023 guidance; check data access and time zone coverage |
Many banks pair an in-house admin with a managed provider for releases, integrations and governance. For a side-by-side look at firms, see Best Banking CRM Service Providers Compared.
At selection time, the agreement should define priority levels, a response target for each, the hours the targets apply to, an escalation path, and the monthly reporting you'll receive. Our post What Is a Bank CRM Managed Services SLA covers the terms and metrics in depth.
Weight the criteria to fit your bank, then score each provider from 1 to 5. Here is a starting point.
| Criterion | Weight | What a 5 looks like |
|---|---|---|
| Banking regulatory fit | 20% | Supports several banks now; produces change logs, access reviews and due diligence documents on request |
| Core and LOS integration skill | 20% | Has handled your core and LOS; can describe its error handling and reconciliation process |
| Security and access control | 15% | Named accounts with MFA, Shield experience, documented offboarding of its own staff |
| Change control and release management | 15% | Written procedure, sandbox testing, client approval before production, three-release-a-year plan |
| Team seniority and continuity | 10% | Named lead and backup, low turnover, senior people doing the work |
| Support model and coverage | 10% | Response targets and hours stated plainly and matched to your operating hours |
| Cost transparency | 5% | Published or clearly quoted pricing, overage approved in advance |
| Roadmap and advisory | 5% | Quarterly review tied to the bank's business goals |
A sensible onboarding plan for a bank runs about 60 to 90 days:
Plan the exit at the start too. The 2023 guidance expects banks to consider transition options, data retention and destruction, and system access when a relationship ends.
Cost depends on org complexity, integrations, user count and roadmap volume. An in-house admin costs a salary plus benefits, training and backup coverage; offshore hours cost less per hour but need more internal oversight.
As one data point, Vantage Point publishes its prices on its support packages page. Managed services are billed monthly on a 12-month term, with licences not included:
| Package | Senior hours per month | Salesforce | HubSpot |
|---|---|---|---|
| Essentials | 30 | $5,850 | $4,800 |
| Professional | 50 | $9,500 | $7,750 |
| Enterprise | 80+ | Quote-based | $12,000 |
Overage is $225 an hour for Salesforce and $175 for HubSpot, approved in advance. Every managed tier includes a named account lead, a 2-hour P1 response target during business hours with the issue worked the same day, a monthly health check, release readiness for each Salesforce release, a quarterly roadmap and governance review, user administration and documentation. Support runs during US Central or Eastern European business hours, with no 24/7 coverage. Banks that need less can buy monthly retainers (from $2,000 a month for 10 Salesforce hours) or prepaid blocks of hours (from $2,500 for 10 Salesforce hours).
Our change control works the way examiners expect: every change is logged, risk-rated, built and tested outside production, approved by the bank's named approver (compliance or infosec for changes touching customer data, permissions or client communications), then deployed and recorded. We configure the controls and your compliance team approves them.
Vantage Point is a senior-led Salesforce, HubSpot and AI consulting firm founded in 2018, with 700+ engagements, 175+ clients and 79 managed services and retainer clients. Our banking practice includes a $2.25B community bank's wall-to-wall Financial Services Cloud rollout across retail, mortgage and commercial lending, with MuleSoft integrations designed alongside a core migration. The bank reported 93% less manual data entry and 50% faster processing. For a $2B community bank serving the Dakotas, senior-led data cleanup, integration fixes and ongoing managed services took data errors from more than 50,000 to 120. You can browse other anonymized bank engagements on our banking clients page. For SEC and FINRA rules in a wealth affiliate, see our CRM compliance guide for regulated industries.
We aren't the right fit if you need 24/7 coverage, want the lowest-cost offshore admin hours, or are a global bank looking for a large systems integrator.
CRM managed services for banks are an ongoing, monthly arrangement where an outside provider administers, maintains and improves the bank's CRM. Scope typically includes user administration, release management, data quality, integration monitoring, change control and roadmap planning. The provider is a third party under banking regulators' guidance, so the bank remains responsible for oversight.
Yes. The guidance covers business arrangements between a banking organization and another entity, and a CRM provider with access to customer data fits that description. The depth of due diligence and monitoring should match the risk, so a provider with production access to customer records warrants more scrutiny than a one-time trainer.
Most banks review CRM access quarterly, with a business owner signing off on each user's permission level. Terminations should trigger same-day removal outside that cycle.
It can, if the bank's third-party risk program addresses foreign-based third parties, which the 2023 guidance lists as a contract consideration. Check where data is accessed from, how the provider's staff are vetted, and whether support hours overlap your operations.
Field changes or new APIs in a core upgrade can break mappings and stop records from syncing. Your managed provider should review the core vendor's release notes, test the integration in a sandbox before the upgrade date, and reconcile record counts afterward. Agree up front on who owns fixes on each side of the integration.
Plan for 60 to 90 days, covering due diligence, access setup, an org health check, integration documentation and knowledge transfer. Include termination assistance in every contract so the next switch is easier.
If you're evaluating CRM managed services for your bank, start with a free CRM assessment. We'll review your org's security settings, integrations and change history and tell you what a support model should cover. You can also compare our published managed services and support pricing or read more about our banking work.