Asset Liability Management Software: Build Custom or Buy Off the Shelf?
Two thresholds decide this. Below roughly $700M in assets with a conventional balance sheet, no derivatives and a simple deposit book, buy: Abrigo, ZM Financial Systems or an outsourced modelling service will produce a package an examiner accepts for a fraction of a build.
On this page
Two thresholds decide this. Below roughly $700M in assets with a conventional balance sheet, no derivatives and a simple deposit book, buy: Abrigo, ZM Financial Systems or an outsourced modelling service will produce a package an examiner accepts for a fraction of a build. Above roughly $2B, where non maturity deposits carry most of your funding and nobody can reproduce last quarter's run from data, build. A first release covering instrument level cash flows, a versioned assumption registry and simulation across the standard shock set runs $95,000 to $210,000 in 16 to 22 weeks, with a full platform at $250,000 to $650,000 over 9 to 16 months. Between the two thresholds the right answer is usually neither, and the section on hybrids below is the one to read.
When is off the shelf genuinely the right call here?
More often than this category's marketing suggests. Empyrean Solutions, ZM Financial Systems, Quantitative Risk Management, Abrigo and Moody's Analytics all build capable interest rate risk engines, and the engine is rarely where institutions actually get hurt. The mathematics of discounting a cash flow under a shocked curve is settled. Nobody needs a bespoke version of it.
Buy if you are under roughly $700M in assets with a conventional balance sheet, no derivatives, a simple deposit book and no acquisitions pending. A vendor model or an outsourced modelling service produces a defensible package for a fraction of a build, and an examiner will be satisfied with it. At that size the analytical questions your treasurer faces are answerable inside a standard shock set, and the marginal value of instrument level detail does not yet cover its cost.
Buy if your constraint is people rather than software. This is the case institutions talk themselves out of most often, and it deserves saying plainly. A model you cannot staff is worse than a service you can. If your treasury function is one person and a part time analyst, owning a system nobody in the building can explain line by line is a worse supervisory position than renting one a vendor will explain on your behalf. Buy the commodity pieces even if you build the rest: structured securities need external cash flow projections, and market data is a subscription.
When does a custom build actually pay off?
Build when two or more of these hold. Your loan book has embedded options that your current model buckets away. Non maturity deposits are more than half your funding and your betas are borrowed rather than estimated from your own history. You cannot reproduce a prior run from data, only show the file that was distributed. Your last validation or examination produced findings on assumption documentation or the absence of back testing. Or your treasurer needs the model to answer strategy questions about funding and pricing rather than to produce a compliance table each month.
The first of those is the most concrete. Cores will happily give you balance, rate and maturity. They are far less willing to give you the rate floor written into the note, the reset index and lookback convention, the amortisation type on a balloon, the ceiling that binds at plus 200 basis points on 300 commercial loans, or the prepayment penalty schedule that steps down over five years. So the model buckets loans by rate band and repricing bucket and treats each bucket as one synthetic instrument. Every embedded option in the portfolio disappears at that moment, and a book with binding caps looks more asset sensitive than it is, in exactly the scenario you built the model to warn you about.
The second is where most of the return sits. For a community or mid sized institution the shock result is decided almost entirely by non maturity deposit beta, decay, and how much of the balance you treat as core. Your core system holds years of account level balance and rate history through a real tightening and easing cycle. A build turns that into an assumption you own, estimated by product and segment, with the estimation window, method, owner and approval date attached. When a validator asks where a money market beta of 0.45 came from, you show a regression on your own accounts rather than a citation. That single artefact changes the tone of a validation review more than any other feature in this category.
How do they compare on the things that matter in this industry?
- The calculation engine. Vendors win. Do not build a discounting engine to prove a point.
- Instrument detail. Every platform models what you feed it. The difference is that a build starts by fixing the input, holding floors, caps, index, reset schedule, lookback and penalty terms as a proper instrument record and generating contractual cash flows per instrument before behaviour is applied. Aggregation then becomes a reporting choice rather than a modelling compromise, and you can name the specific loans driving a shock result.
- Assumption provenance. Vendors give you a capable engine and a field to type a beta into. They do not give you a defensible answer to where the beta came from, and that is the question a model validator opens with. This gap is identical across every product in the category, which is why it is the most common reason institutions build.
- Reproducibility. Ask whether a run is stored as an immutable artefact capturing the instrument snapshot, assumption set version, scenario definitions, code version and outputs. Without that there is no back testing, and without back testing you cannot show the one thing that makes a model credible: evidence that when it was wrong, you found out and adjusted.
- Scenario composition. Standard parallel shocks are table stakes and also the least likely scenarios. What matters is whether your treasurer can compose a scenario as a first class object: a rate path, behavioural overrides, a growth strategy, and an assumption about what management would actually do. A model that says economic value falls 22 percent prompts nothing. One that says it falls 22 percent unless you extend funding by 18 months at current spreads, at a stated cost in net interest income, is a decision.
- Validation evidence. A technical specification of every calculation, estimation evidence, back test results and a limitations statement. Produced as a by product of a build, or assembled after a validator asks. The second route is a second project.
What does total cost of ownership look like at your scale?
A first release covering instrument extraction and contractual cash flow generation, an assumption registry with versioning and approval, and net interest income plus economic value simulation across the standard shock set with instrument level drill down runs $95,000 to $210,000 and ships in 16 to 22 weeks in Digital Heroes delivery experience. A full platform adding behavioural deposit estimation, back testing with variance decomposition, liquidity and funding concentration scenarios, committee reporting and a validation evidence pack runs $250,000 to $650,000 phased over 9 to 16 months.
A worked case: a community bank with roughly $2.6B in assets, one core, a conventional investment portfolio, no derivatives, non maturity deposits carrying a majority of funding. Discovery, instrument extraction, cash flow generation, the assumption registry, simulation and two committee cycles of parallel running come to about $152,000, with extraction and cash flow generation carrying nearly half of it. An institution whose core exposes the full attribute set cleanly lands nearer $100,000. Adding behavioural estimation, back testing, liquidity, reporting and the validation pack takes the same bank to roughly $330,000 to $420,000 in total.
Running costs are modest and specific. Compute is spiky rather than steady, typically $400 to $1,500 a month at this asset size, and it scales with scenario count rather than balance sheet size. Immutable run storage grows every cycle by design, because reproducibility means never overwriting. Market data continues as a subscription. Support and enhancement runs 12 to 18 percent of build cost annually, with a spike in any year you add a charter, a derivative programme or a new product type.
Compare that against your renewal plus four things the renewal does not cover: the treasurer or analyst days spent rebuilding the committee package each month, the consultant fee for your last deposit study, the cost of your last validation, and any remediation it triggered. If your answer to whether you can reproduce the package from two quarters ago is a distributed file rather than a rerun, the renewal is not addressing your actual weakness.
What does the hybrid look like, and when is it the honest answer?
Between $700M and about $2B, the hybrid is usually right and it is the cheapest credible move in this category.
Keep your vendor engine. Build the assumption registry and behavioural deposit estimation beside it, feeding it rather than replacing it. That runs $45,000 to $85,000 over ten to thirteen weeks and produces exactly the artefact a validator opens with: beta and decay estimated by product and segment from your own account level history through a real rate cycle, held with the estimation window, the method, the owner and the approval date. The engine keeps doing the arithmetic. You stop borrowing the inputs.
That order matters because validators and examiners rarely question the discounting. They question where the deposit assumptions came from, and buying an engine does not answer that on any platform.
Segment before you sophisticate. A single blended beta across all money market accounts hides that your top 50 relationships behave very differently from the retail tail, and in a stress those relationships move first and largest. Segmentation is cheap and it is where the analytical value is.
The hybrid runs out when instrument detail becomes the binding problem. If your loan book carries embedded options your engine cannot represent, better assumptions on the deposit side will not fix an asset side that is wrong by construction, and the first release band applies.
Which should you choose, by operator size and stage?
Under $700M with a plain balance sheet: buy, and spend the difference on the deposit study rather than the software.
$700M to $2B: hybrid. Keep the vendor engine, build the assumption registry and behavioural estimation at $45,000 to $85,000. Do this before your next validation cycle, because closing a finding costs more than preventing one.
Above $2B with material embedded options in the loan book: the first release build at $95,000 to $210,000. Protect the discovery, and insist it includes a real data availability assessment. Pull an actual extract, check which attributes are present, and count how many loans are missing a floor or a reset convention. That count sets the price of everything after it, and finding it out in month four is expensive.
Multiple charters, a recent acquisition, structured securities or a derivative programme: the full platform at $250,000 to $650,000, phased, with the understanding that two cores means two extraction pipelines plus a reconciliation between them, and the reconciliation is usually harder than either pipeline.
At every size, two rules hold. Do loans and non maturity deposits properly first and take vendor cash flows for the investment portfolio until later. And do not reimplement your core's amortisation logic if you can extract the schedule, because reproducing it from terms produces small persistent differences that consume weeks for no analytical gain.
When the shortlist is down to two and you need a tiebreaker, Digital Heroes has delivered more than 2,000 projects with a named team you can speak to before you sign, rather than a bench you meet in month two. Nothing about that commits you to the build.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- The performance gap between digital and AI leaders and laggards is widening: McKinsey reports leaders pull ahead on shareholder returns, and the average maturity spread between top and bottom performers jumped ~60% (from 10 points in 2016-19 to 16 points in 2020-22), reinforcing that the returns to transformation concentrate among top performers. Source: McKinsey & Company (2023) →
- McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
- Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
- Poor software quality cost the US economy an estimated $2.41 trillion in 2022, including roughly $1.52 trillion in accumulated technical debt, driven partly by unsuccessful development projects and low-quality legacy systems. Source: Consortium for Information & Software Quality (CISQ) - Herb Krasner (2022) →
Frequently asked questions
What does it actually cost to leave Abrigo or ZM Financial Systems?
The engine itself is not the hard part to replace, because the calculations are standard and the outputs are comparable. What is expensive is everything you configured inside it: product mappings, assumption sets, scenario definitions and any historical runs you rely on for back testing.
Before signing or renewing, ask for a full export of assumption sets, scenario definitions and prior run outputs in a machine readable format, and check whether historical runs leave with you at all. An institution that cannot take its own back test history out is starting its model monitoring evidence from zero on the day it switches.
What if our vendor changes pricing or discontinues our module?
Model the exposure by asking what you would have to rebuild in the first 90 days. If the vendor holds the engine and you hold the instrument data and the assumption registry, the answer is a licence swap. If the vendor holds all three, the answer is your entire committee package.
That asymmetry is the strongest practical argument for the hybrid. Building the assumption layer costs $45,000 to $85,000 once and permanently reduces how much of your supervisory position depends on one vendor's commercial decisions.
How long does a first release take, and can we run it alongside the current model?
Sixteen to 22 weeks, then parallel running for at least two committee cycles. Two cycles is enough. Each additional cycle is duplicated staff effort with diminishing returns.
Parallel running is where you discover the old model was quietly excluding a loan category or applying a prepayment vector nobody can source. Reconciling the two is genuinely useful rather than overhead, and it becomes part of your validation evidence. Do not schedule the cutover in the same quarter as an examination.
Can we build only the deposit assumption work and keep everything else?
Yes, and for institutions between roughly $700 million and $2 billion it is usually the right move. An assumption registry plus behavioural estimation from your own account level history, feeding your existing model rather than replacing it, runs $45,000 to $85,000 over ten to thirteen weeks.
The practical requirement is account level balance and rate history through an actual tightening and easing cycle. If your core only retains two years, that constrains the estimation window and should be established in the first week rather than the fourth month.
Why does the core extract drive so much of the price?
Because balance, rate and maturity are easy and everything that shapes a real cash flow is not. Floors, caps, reset index, lookback convention, amortisation type and prepayment penalty schedules are what separate a projection from an approximation, and some cores will not release them through a standard extract.
If yours will not, you are funding a data acquisition project before any modelling starts, and it can be a quarter of the budget. Pull a real extract in discovery and count the loans missing a floor or a reset convention rather than assuming the attribute exists.
Will a custom model make validation harder or easier?
Easier if the evidence is a by product, harder if it is an afterthought. A serious build produces a technical specification detailed enough for an independent party to reimplement the calculations, the estimation evidence and data window behind each behavioural assumption, back test results with variance decomposition, a change log of assumption and code versions, and a written limitations statement.
If a development partner treats validation support as documentation to write later, budget for a second project. Ask to see a specification from a previous engagement before you commit.
Should liquidity risk be in scope from the start?
No, in most cases. It shares most of the plumbing with interest rate risk, so building it in phase two is efficient rather than wasteful. Instrument level cash flows feed both a repricing view and a maturity ladder, and deposit behaviour assumptions serve both.
What liquidity adds, typically $50,000 to $110,000, is funding concentration analysis and contingency scenarios, including what happens if your largest depositors move a meaningful share of balances in a month. For many institutions that is the more relevant stress, so sequence by which one your board actually asks about.
Who owns the model and the code if an agency builds it?
You should own the repository, the model specification, the assumption estimation code and the cloud accounts, written into the contract before kickoff. At Digital Heroes the client owns all of it from the first commit.
This matters unusually much here. A model you cannot open, explain line by line and modify is not defensible in a validation review or an examination, regardless of how good the underlying mathematics happens to be. The same test applies to a vendor: if you cannot obtain a calculation specification, you are relying on their reputation rather than your own documentation.
Why do agencies charge for a discovery phase instead of quoting for free?
Because an accurate quote requires real work: mapping your workflows, finding the edge cases, and writing a specification, which typically takes 1 to 3 weeks and costs $2,000 to $10,000 at Digital Heroes depending on system complexity. You leave discovery owning a written spec and a fixed price you can take to any vendor, so the money is not locked into one agency. Free estimates are guesses, and the guess usually becomes your budget overrun six months later.
What do I need to prepare before contacting an agency about a dashboard project?
Bring three things: a list of your data sources with who controls access to each, the 5 to 10 recurring decisions the dashboard should support, and examples of the reports or spreadsheets it will replace. That package lets an agency quote in days instead of weeks, and in our discovery work it cuts the audit phase roughly in half. You do not need wireframes or a technical spec; a good agency produces those with you.
When is it time to move from Excel reports to an actual dashboard?
The reliable signal is when someone spends more than a few hours a week copying data between spreadsheets, or when two teams arrive at a meeting with different numbers for the same metric. At that point the spreadsheet is acting as an unversioned, single-person database, and a costly error is a matter of time. A first dashboard that automates those recurring reports typically pays for itself in recovered hours within the first year.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
Is custom software more secure than off-the-shelf SaaS?
Neither is secure by default; security tracks the practices of whoever builds and operates the system, not the model. SaaS gives you the vendor's certifications and patching but puts your data in a shared multi-tenant platform on their terms, while custom gives you full control over data residency, access rules, and compliance requirements like HIPAA, with the responsibility sitting with you and your agency. Before hiring anyone for a system holding sensitive data, ask for their security checklist: encryption at rest and in transit, an OWASP Top 10 review, role-based access, and a penetration test before launch.
Should I embed Power BI or Tableau in my SaaS product, or build custom charts?
Embed first if you need analytics inside your product within weeks, but treat it as a bridge rather than the destination. Embedded licensing meters your customer traffic, so your analytics cost grows with your user count, and the look and feel never fully matches your product. In Digital Heroes projects, SaaS teams usually switch to custom charts built in React with a library like ECharts or Recharts once analytics becomes a selling point instead of a checkbox.
How do I vet an agency or developer for a BI dashboard project?
Ask them to walk you through the data model of a past project, not a portfolio of pretty charts, because dashboard failures are almost always data modeling failures. Good answers mention specifics like star schemas, dbt, incremental refresh, and how they handled a source schema change after launch. Then ask for a fixed-scope discovery phase with a written data audit as the deliverable, so you judge their real work for a small spend before committing to the build.
How does a custom dashboard handle compliance requirements like SOC 2, HIPAA, or GDPR?
A custom build gives you direct control over the controls auditors ask about: single sign-on, role-based access, audit logs, encryption, data residency, and deletion workflows. For HIPAA specifically, you can keep protected health information inside your own cloud account under a business associate agreement with your host instead of trusting a third-party BI vendor's handling. Expect compliance work to add 2 to 4 weeks and roughly 10 to 15 percent to the build, so raise it in the first conversation, not after design is done.
Does it matter which tech stack the agency wants to use?
Yes, but not in the way most buyers expect: the goal is boring, popular technology such as React, Node.js or Python, and PostgreSQL, because any future team can maintain it and hiring a replacement developer takes days, not months. The red flag is an agency-proprietary framework or an unusual language, which welds you to that one vendor no matter what your contract says about code ownership. A useful test: could you find three freelancers fluent in this stack within a week? If not, push back.
How long does it take to build a custom BI dashboard?
A working first version usually ships in 4 to 8 weeks, and a full production build with multiple integrations and permissions takes 3 to 6 months. In Digital Heroes delivery experience, schedules slip on data access, meaning credentials, API approvals, and cleanup of source data, far more often than on the dashboard screens themselves. Lining up access to every data source before kickoff routinely saves 2 to 3 weeks.
Why do BI dashboard quotes range from $25k to $200k for what sounds like the same project?
Four variables move the price: how many data sources you connect and how messy they are, real-time versus daily refresh, permission complexity, and whether outside customers will log in. A three-source internal dashboard with daily refresh sits near the bottom of that range, while a customer-facing product with row-level security and live data sits near the top. Wildly different quotes are usually pricing different assumptions about those four things, so pin them down in writing before comparing.
Will a custom dashboard stay fast once our data hits millions of rows?
Yes, if it aggregates before it displays; no dashboard should scan millions of raw rows on every page load. The standard techniques are pre-aggregated summary tables, incremental refresh, and caching, which keep typical page loads under 2 seconds even on datasets in the hundreds of millions of rows. Ask your vendor how the dashboard behaves at 10 times your current data volume; a good one gives a specific answer about aggregation, not just a bigger server.
Who can build a custom business intelligence dashboards system?
Digital Heroes builds custom business intelligence dashboards systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other business intelligence dashboards companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .