Vendor sprawl just got a new roommate: AI agents

In my work with some of the world’s largest financial institutions, I’ve seen that vendor sprawl rarely means hundreds of applications. At that scale, hundreds would be a good problem to have. Once you count core banking platforms, third-party vendor software, free and open source tools, and decades of in-house builds, the real number runs into the thousands. And now a new category is moving in: AI agents that show up faster than any procurement process can register them.
Working directly with the teams responsible for these portfolios has made one thing clear: vendor sprawl in financial services is not simply a procurement problem. It is a visibility, data, and governance problem shaped by decades of technology decisions.
Let’s dig into why vendor sprawl hits financial institutions differently than it hits the average enterprise.
Banks don't have hundreds of applications. They have thousands.
A typical enterprise sprawl story starts with "we run too many SaaS tools." A bank's story starts decades earlier. Core banking platforms, payments rails, lending systems, risk and regulatory reporting tools, trading infrastructure, and decades of mergers and acquisitions all stack on top of each other, and very little ever gets fully retired. When Citi recently completed a multiyear IT transformation effort, the headline number was striking on its own: 2,000 legacy applications retired, and that was just the cleanup, not the starting inventory.
Layer onto that the sources most enterprise sprawl conversations leave out entirely:
- Third-party vendor software licensed through enterprise agreements that can span multiple products, each with its own versioning, support lifecycle, and contract terms to track.
- Freeware and free-tier tools that individuals or teams pick up to solve a problem quickly.
- Open source components, which are no longer a fringe choice in banking. JPMorgan Chase, Morgan Stanley, and Citi all now contribute to and rely on open source infrastructure through FINOS, the Fintech Open Source Foundation. Accenture projects that by 2028, 83% of global servers will run on Linux, up from under three quarters in 2020.
- In-house builds frequently written and maintained by teams that have long since moved on, with documentation that ranges from thin to nonexistent.
None of these four categories show up the same way in a CMDB. None of them get discovered by the same audit.
In the portfolios I work with, the challenge is rarely a lack of inventory. Most organizations already have extensive technology catalogs, but those records often tell only part of the story. Ownership, commercial context, lifecycle status and business capability information may all be managed differently across teams, making it difficult to build a consistent view of the technology estate. The bigger challenge is turning all of that existing information into something teams can actually trust and use to make decisions.
At enterprise scale, thousands of applications across all four categories means thousands of separate answers to “what is this, who owns it, and is it still supported?”
The agent layer doesn't wait for your approval process
If thousands of existing applications weren't enough, AI agents are now arriving inside many of them. Gartner projects that by 2028, the average Fortune 500 company will run more than 150,000 AI agents, up from fewer than 15 in 2025. Agents don't wait for a vendor review or a security questionnaire. They show up as a feature toggle inside a SaaS contract you already signed, a no-code workflow built by a lending operations analyst, or an "agent mode" inside a developer tool that quietly gains access to production systems.
For banking specifically, the regulatory stakes are sharper. Freddie Mac's AI governance mandate, which took effect in March 2026, requires lenders to answer which vendors use AI, how it's deployed, what data feeds it, and who's accountable. That's a hard question to answer when an agent arrived through a feature update rather than a procurement ticket, and even harder when it's layered on top of an open source component or an in-house tool nobody's reviewed in years.
Why financial institutions can't just adopt the generic playbook
Most vendor sprawl advice assumes a SaaS-first stack and a security team that can ban what it doesn't like. Neither assumption holds cleanly in banking. Across the large financial institutions I support, technology decisions must account for legacy infrastructure, complex ownership models, regulatory obligations, regional differences, and critical systems that cannot simply be replaced. The problem is not a lack of discipline. It is that the standard playbook was not designed for portfolios of this scale and complexity.
Third-party risk management makes every vendor a standing obligation
It isn't enough to know a tool exists. Examiners expect ongoing monitoring of vendor changes, certification expirations, and emerging risks, not an annual checkbox. That's a different bar than "do we still use this," and it applies to every third-party solution in the portfolio.
Shadow IT carries explicit regulatory weight
The FFIEC's IT Examination Handbook calls out shadow IT directly, and storing customer financial data on an unapproved tool isn't just an internal policy violation, it's a potential compliance finding. A loan officer using a personal cloud drive over the weekend is a familiar story in banking precisely because the stakes of an unmanaged tool are so much higher than they are elsewhere.
Open source and in-house solutions don't come with a vendor to call
When a SaaS tool breaks, you open a support ticket. When an open source library or a fifteen-year-old in-house system breaks, the fix depends entirely on whether anyone still understands it. Inventory has to capture not just that these solutions exist, but what they depend on and who, if anyone, still maintains them.
The volume changes the nature of the work
A 300-app enterprise can run a manual rationalization sprint and make real progress in a quarter. A financial institution with thousands of applications across four different sourcing categories cannot clean that up with a spreadsheet and good intentions. The scale itself rules out most generic sprawl-management advice.
What "in control" looks like for a financial institution in 2026
The institutions making the most progress are not trying to solve the entire portfolio through a single cleanup exercise. From my work with their teams, four practices consistently make the difference
- One inventory, every sourcing category. Third-party, freeware, open source, and in-house all need to live in the same view. This does not necessarily mean replacing every existing system, but it does require creating a consistent intelligence layer across them.
- Vendor monitoring that's continuous, not annual. Examiners increasingly expect documentation that's current at the moment they ask, not refreshed once a year before the exam.
- AI governance built on top of accurate inventory, not instead of it. You can't answer Freddie Mac's "which vendors use AI" question, or similar questions from other regulators, without first knowing every vendor and every internal system in scope.
- Open source treated as a managed asset, not an exception. If JPMorgan and Citi are formalizing their open source governance through FINOS, that's a signal the rest of the industry should be doing the same, not treating open source components as somehow outside the inventory.
How Entrio helps financial institutions see the whole portfolio
This is the gap I help financial institutions address through Entrio. The work starts with cleansing and bringing together fragmented portfolio data, but the real value comes from helping architecture, ITAM, governance, procurement, risk and technology teams use that information to make better decisions across the estate.
What matters is not creating another inventory. It is establishing a shared view of the technology portfolio that connects products, vendors, ownership, lifecycle, cost and business context in a way that supports the decisions each institution is trying to make, whether that is rationalization, governance, risk management, technology ownership or evaluating where existing solutions can be reused.
One canonical record, regardless of where the solution came from
Whether it's a core banking platform from a major vendor, an open source library three teams depend on, or an in-house system built a decade ago, it gets the same visibility.
A living inventory, not a point-in-time snapshot
When vendor metadata updates automatically, including certification status, M&A history, end-of-life notices, AI usage, your decisions are made from current information. Stop assuming the data is still accurate or manually updating it before every project or audit.
Consolidation opportunities at the scale of your portfolio
In portfolios with thousands of applications, redundancy can easily hide in plain sight. Entrio’s robust classification system reveals overlap across the entire portfolio, including the commodity solutions that account for roughly 30% of technology spend. Unlike core platforms, these less-visible tools are often easier to decommission, creating faster paths to consolidation and savings. In practice, these opportunities become actionable only when teams can see which capabilities overlap, where each solution is used, and who needs to be involved in the decision.
Audit and exam prep starts from one source of truth
When an examiner asks where customer data lives or which vendors touch AI-driven decisioning, the answer comes from a current, governed inventory, not a scramble across CMDBs, contract systems, and a few people's memories.
The bottom line
For a financial institution, vendor sprawl was never a few hundred overlapping SaaS tools. It is thousands of applications across third-party vendors, freeware, open source, and in-house builds, accumulated over decades and now joined by an agent layer moving faster than traditional governance processes.
After working with the teams responsible for some of the industry’s largest technology portfolios, my biggest takeaway is that control does not come from having the strictest purchasing policy or completing another one-time inventory exercise. It comes from building the ability to answer, continuously and consistently, what the organization has, what each solution does, where it is used, and who is accountable for it.
That is the idea behind Entrio’s Live Technology Catalog: check the pantry before you shop, even when the pantry has thousands of items.

About the author
Kim is a Senior Customer Success Manager at Entrio, where she works directly with architecture and technology teams at some of the world’s largest financial institutions. She helps customers turn complex, fragmented portfolio data into the technology intelligence needed to improve governance, identify optimization opportunities, and make more confident decisions.



