Field note

A core wrapper needs a demolition schedule before it becomes permanent

Large-bank modernization programs increasingly put orchestration, ledgers, and customer-master capabilities around existing cores. That sequence can reduce conversion risk. Without explicit retirement ownership and dates, it creates another permanent layer and extends dual-running cost.

Aug 10, 2026 · Navin Agrawal · Architecture · 3 min read

A core wrapper needs a demolition schedule before it becomes permanent

Visual brief

Visual brief

A core wrapper needs a demolition schedule before it becomes permanent

As of August 2026

Wrapping the core is a rational way to reduce cutover risk. It becomes an architecture failure when the wrapper gets a delivery plan and the displaced core capability gets no retirement plan.

The program needs two roadmaps from day one: construction for the new boundary and demolition for the old one.

Modernization signal

Wrap first

orchestration, ledgers, and customer-master capabilities move around the incumbent core.

Program risk

94%

IBM reported that most core modernization programs exceed their planned timelines.

Control

Retire by date

every duplicated core capability needs an owner, exit condition, and funded removal milestone.

Why wrap-first wins sponsorship

A full core conversion concentrates data migration, product behavior, posting, interfaces, customer servicing, and operational readiness into one risk event. A wrap-first sequence bounds the move. The bank can place orchestration, customer identity, product services, or a new ledger at a defined seam while the incumbent system continues to carry the rest.

Why wrappers become permanent

The new layer has a delivery team, budget, release date, and executive sponsor. Retirement work sits in the future and often loses all four. Dual-running then becomes an operating model. Data is reconciled twice, defects cross two ownership boundaries, and the wrapper accumulates exceptions for behavior that was never removed from the core.

Core banking modernization diagram showing wrap-first sequencing, bounded domain extraction, parallel construction and demolition plans, retirement gates, and the risk of permanent dual-running.
A wrapper is scaffolding only when the demolition milestones are funded and owned.

A wrapper is scaffolding only when the demolition milestones are funded and owned.

A wrapper is scaffolding only when the demolition milestones are funded and owned.

Core banking modernization diagram showing wrap-first sequencing, bounded domain extraction, parallel construction and demolition plans, retirement gates, and the risk of permanent dual-running.

The demolition schedule is an architecture artifact

Each wrapped capability needs a current owner, target owner, authoritative data source, integration seam, migration cohort, exit test, and retirement date. The schedule should also state what happens when the date slips. Without that decision, every delay defaults to keeping both paths alive. If the old path doesn’t have an owner and a date, it stays.

This is where capability mapping earns its place. The map prevents teams from modernizing interfaces while leaving the same business rule active in two systems. It exposes which domains can move independently, which depend on a shared ledger or customer master, and which have no viable exit until a downstream consumer changes.

Wrap-first reduces the size of each move. Retirement governance decides whether those smaller moves ever add up to modernization.

Was this useful?

Choose once.

Related Posts

View All Posts »
The broker pattern is older than the agentic-commerce headline

The broker pattern is older than the agentic-commerce headline

Stripe Shared Payment Tokens are the agentic-commerce headline, but anyone who ran a card tokenization rollout in 2014 recognizes the shape in five seconds. A scoped surrogate credential with a thin stable interface in front and brokered complexity behind is not new. Visa Token Service shipped it twelve years ago, and the architects who see the pattern early build the right systems instead of rebuilding every eighteen months.

Consumer auth patterns fail the bank exam

Consumer auth patterns fail the bank exam

Authentication that works for web scraping becomes a compliance problem the moment an AI agent moves real money. Enterprise payment systems need certificate identity, scoped service accounts, and short-lived tokens - the things a banking examiner expects to see.

Tokenized money is a 2025 architecture problem, not a 2030 one

Tokenized money is a 2025 architecture problem, not a 2030 one

The BIS just blueprinted a tokenized unified ledger and JPMorgan put a deposit token on a public chain - in the same week. The hard part for banks was never the blockchain. It is retrofitting core banking to carry programmable money without a big-bang migration.