The IT budget benchmark most financial institutions use to plan next year’s spending comes straight from JPMorgan Chase’s 10-K. If your institution has 400 employees instead of 300,000, that benchmark isn’t just unhelpful. It’s actively steering you wrong.
An IT budget benchmark for financial services is the share of revenue, generally 7 to 10 percent, that banks, credit unions, and insurers should allocate to technology, scaled to institution size and regulatory complexity rather than copied from a global bank’s public filings. For a mid-market institution, that number typically narrows to roughly 6 to 9 percent, and should fund a vendor-hosted core banking platform, BSA/AML compliance tooling sized to actual transaction volume, and FFIEC-mandated disaster recovery testing, not the spending pattern of an institution fifty times larger.
Ask a community bank CFO how they landed on this year’s IT number, and you’ll usually hear one of two stories. Either a consultant quoted a percentage from Gartner’s forecast for the banking and investment services market, built entirely on universal-bank data, or someone bumped last year’s line item by whatever inflation felt reasonable. Neither approach reflects what a 500-person regional bank, credit union, or insurance carrier actually needs to spend, or where that money should go.
For the view across every industry, our full breakdown of IT budget benchmarks by industry covers healthcare, manufacturing, legal, and more. This piece stays inside financial services and gets specific about the categories that define a mid-market budget: core systems, compliance tooling, and disaster recovery.
Know Your Real Number
The Benchmark Mismatch
Every industry study agrees that financial services spends more on IT as a percentage of revenue than nearly any other sector, typically in the 7 to 10 percent range against a cross-industry average closer to 5 to 6 percent. Manufacturing runs on 2 to 4 percent. Financial services doesn’t get that option.
According to Gartner’s forecast for the banking and investment services market, global enterprise IT spending in that sector is projected to grow 9.5 percent in 2026, reaching $857.5 billion. That’s a market-wide figure, not a mid-market one, but it confirms the direction: financial services IT budgets keep accelerating, largely on the back of fraud detection and compliance automation spending.
The drivers behind that gap aren’t complicated. The product is digital, whether that’s a loan, a policy, or a trade. Regulators expect specific tooling and specific reports, not general good intentions. An outage doesn’t just annoy customers, it triggers examiner questions. And according to IBM’s 2025 Cost of a Data Breach Report, financial services breaches average $5.56 million each, the second-highest cost of any sector after healthcare, driven largely by customer PII exposure and fraud liability.
What’s missing from most of these studies is the example used to illustrate them. Most published benchmarks describe institutions with $10 billion or more in assets and technology headcounts in the thousands. JPMorgan Chase alone has disclosed roughly 63,000 technology employees and about $17 billion in annual technology spend. A bank with a tech org that size, running a decade-long core system migration, does not budget, staff, or negotiate the way a 500-person institution does, and pretending otherwise is where most benchmark advice quietly falls apart.
Why That Mismatch Actually Costs You
Using a universal-bank benchmark against a mid-market budget doesn’t just produce a wrong number. It produces wrong decisions built on that number.
Mid-market financial institutions run on a different stack than the one most benchmark studies describe. You’re almost certainly on a vendor-hosted core banking or policy administration platform, such as Fiserv, Jack Henry, FIS, or an insurance-specific admin system, not a legacy in-house mainframe. Your compliance load is real but shaped by different rules: the GLBA Safeguards Rule, a BSA/AML program sized to your actual transaction volume, or FFIEC IT Examination Handbook expectations, or state-level insurance and lending regulations. The FFIEC itself is a coordinating body of the Federal Reserve, FDIC, OCC, NCUA, and CFPB, so its handbook reflects what all five agencies expect examiners to check. Basel III capital reporting and the EU’s DORA resilience mandate, effective since January 2025, were built for institutions you’re not.
In a typical IT assessment engagement with a mid-market bank, the first thing we usually find isn't a missing tool. It's a BSA/AML monitoring platform that was sized and configured for a much larger transaction volume years ago, that nobody has retuned since, and that's now generating enough false-positive alerts that a compliance analyst spends several hours a week manually clearing them. The institution is paying full enterprise licensing for a platform doing the work of a much smaller one, while the actual gap, a documented, FFIEC-ready incident response runbook, sits unfunded. That pattern, overbuying in one compliance category while underfunding continuity planning in another, shows up often enough that it's usually the first thing worth checking before touching the topline budget number at all.
That distinction changes where the money should go. A CFO who benchmarks against a global bank’s compliance spend will either overbuy enterprise software sized for an institution ten times larger, or underspend because the percentage looked high enough on paper without accounting for what that percentage was actually funding. Either mistake shows up at the worst possible moment: during a budget defense, or during an FFIEC exam.
What Mid-Market Financial Institutions Should Actually Spend
Generic IT budget breakdowns split spend into personnel, software, infrastructure, security, and “other.” That’s fine for a manufacturer. Financial services needs a version built around the systems that actually define the institution.
The planning ranges below are compiled from published financial services IT budget breakdowns. Treat them as a starting point to validate against your own vendor contracts and staffing costs, not a target to hit exactly.
| IT Budget Category | Typical % of IT Budget | Primary Cost Driver |
|---|---|---|
| Core Banking / Policy Admin Systems | 18–24% | Vendor licensing, system integrations, uptime SLAs |
| Compliance & Regulatory Technology | 20–25% | BSA/AML, KYC/CDD tooling, FFIEC reporting |
| Cybersecurity & Fraud Prevention | 14–18% | Threat detection, PCI DSS compliance, fraud AI |
| Disaster Recovery & Business Continuity | Often under 5%, frequently underfunded | FFIEC-mandated testing, redundant infrastructure |
| Digital Customer Experience & Cloud | 10–14% | Mobile/online banking platforms, cloud migration |
Category ranges are directional estimates drawn from Gartner and Avasant benchmark data compiled by ITBudgetCalculator and cross-referenced against VendorBenchmark’s financial services breakdown. Disaster recovery is frequently folded into general infrastructure spend rather than tracked as its own line, which is part of why it’s chronically underfunded.
What Percentage of Revenue Should Financial Institutions Spend on IT?
According to benchmark data from Avasant’s IT spending research and Gartner IT Key Metrics data, cross-referenced by ITBudgetCalculator, mid-size companies across all industries average 6 to 8 percent of revenue on IT, while financial services specifically runs 7 to 10 percent. For a mid-market financial institution, that overlap puts the realistic planning range at roughly 6 to 9 percent, weighted toward the higher end because of the sector’s regulatory and security load.
If your current spend sits meaningfully below 6 percent, don’t read that as efficiency. Ask instead whether you’re skipping security and compliance tooling that would otherwise show up as its own line, and absorbing that risk somewhere you can’t see it.
Stress-Test Your DR Plan
Spend Per Employee
Per-employee IT spend for financial services broadly runs $14,000 to $25,000 a year, according to ITBudgetCalculator’s financial services benchmark; universal banks sit at the very top of that band. JPMorgan Chase, for example, discloses roughly $17 billion in annual technology spend against approximately 63,000 technology employees, which works out to roughly $55,000 per employee, an outlier driven by its global trading and compliance footprint rather than a typical figure. Mid-market institutions, with leaner staffing and outsourced infrastructure, typically land at or below the lower end of that broader range.
Core Banking or Policy Administration Systems
This is the operational backbone, and for most mid-market institutions, it’s a hosted or managed relationship rather than an in-house build. Budget here covers licensing, integration work, and keeping ancillary systems, online banking, mobile apps, claims processing, loan origination, connected to that core platform without three vendors quietly doing overlapping work.
The negotiation dynamic matters more than the raw dollar figure. Core system vendors know switching is painful, so pricing power sits with them by default. Your leverage comes from consolidating integrations and knowing exactly what you’re using before a renewal conversation starts, not from threatening to switch a platform you have no real intention of leaving.
Compliance and Regulatory Technology
For a mid-market bank or credit union, this typically means BSA/AML transaction monitoring sized to actual volume, KYC and CDD tooling, and reporting infrastructure built for what an FFIEC examiner will ask to see. Insurance firms budget instead for claims compliance systems and state-specific reporting. This category has zero flexibility. It generates no revenue and it isn’t optional.
The common mistake here isn’t underspending, it’s overbuying an enterprise compliance platform sized for a much larger institution, then paying maintenance on features nobody uses, the exact pattern described earlier. Sizing this category to your actual regulatory footprint, not your ambitions, is where the real savings live.
Cybersecurity and Fraud Prevention
Financial institutions hold money and personal data, which makes them a more attractive target than most businesses. Budget here covers threat detection, endpoint protection, and security operations aligned to a recognized framework such as the NIST Cybersecurity Framework, plus fraud detection tooling that can catch a real-time transaction anomaly or a social engineering attempt before it becomes a wire fraud loss. Institutions that process card payments also need to budget for PCI DSS compliance separately, since it carries its own annual assessment and monitoring costs regardless of what else is in the security stack. This is also the category examiners scrutinize hardest, and, per the IBM breach-cost figure cited earlier, the one where a gap becomes measurably expensive fastest when something goes wrong.
What Does FFIEC Require for Disaster Recovery Testing?
The FFIEC’s Business Continuity Management booklet requires institutions to maintain a documented business continuity plan and validate it through regular, scenario-based exercises, not a plan that only exists on paper. It points institutions toward NIST Special Publication 800-34 for contingency planning methodology, and examiners expect testing frequency and scope to match the institution’s size, complexity, and risk profile.
Budget here should cover that real testing cadence, tabletop exercises and full failover tests, redundant infrastructure or cloud-based DR services, and the documentation that shows an examiner you’ve actually done the work. Institutions that treat DR as a checkbox usually find the gap mid-incident, which is a bad time to be doing discovery for the first time.
Digital Customer Experience and Cloud Infrastructure
Customers expect a banking or insurance app that feels like the other apps on their phone. This category covers mobile and online platforms and the cloud infrastructure behind them. Financial institutions have historically moved slower here than other industries, for defensible reasons around regulatory comfort with on-premises core systems. According to benchmark estimates cited by ITBudgetCalculator, roughly 70 percent of bank workloads now have at least some cloud component, though only about 25 to 30 percent of core banking systems run primarily in the cloud, so the shift is real but far from complete.
Quick Diagnostic: Is Your Budget Actually Off?
A benchmark percentage tells you where you sit against peers. It doesn’t tell you whether that’s right for your institution. A few practical signals:
You’re likely underfunded if: your compliance team is manually assembling reports that should be automated, your last DR test happened more than a year ago or never happened, or “next budget cycle” is the standing answer to every security recommendation.
You’re likely overspending, or misallocating, if: you’re paying maintenance on compliance software sized for a much larger institution, your core system has overlapping vendors nobody consolidated after a merger, or no one on staff can explain what a given line item actually buys.
Fixing either problem starts with a category-by-category audit, not a bigger topline number.
Should Financial Institutions Build IT In-House or Outsource to a Managed Partner?
Most mid-market institutions can’t fully staff core system integration, BSA/AML tooling, 24/7 security monitoring, and FFIEC-ready DR testing in-house without significant hiring risk, since specialized financial services IT talent is scarce and expensive to retain. A managed partner already familiar with FFIEC, GLBA, and BSA/AML requirements typically closes that gap faster and more affordably than building an equivalent internal team from scratch.
Hiring a full in-house team to cover core system integration, BSA/AML tooling, 24/7 security monitoring, and FFIEC-ready DR testing is expensive and genuinely hard to staff well at mid-market scale. Specialized financial services IT talent is competitive to hire and harder to retain, and a two-person internal team covering all of that sits one resignation away from a real gap.
That’s the case for a managed partner who already understands the regulatory environment, rather than a generalist MSP learning BSA/AML requirements on your dime. The right partner already works with other financial institutions your size, so your next budget conversation starts from real peer numbers instead of a mega-bank’s investor deck.
Turning This Into a Budget You Can Defend
Industry percentages are a starting point for a board conversation, not a number to defend on their own. The version that actually holds up is specific: here’s what we spend on core systems, here’s what compliance requires given our asset size and regulatory footprint, here’s when DR was last tested and what closing the gap costs, and here’s where a managed partner takes work off our plate instead of adding headcount we can’t hire fast enough anyway.
That’s a budget built around your institution’s actual risk and regulatory profile, not a number borrowed from a bank fifty times your size.