EDIH, EEN, Interreg: the platform for European programmes.Find out more

Business Continuity Plan Maturity · BCEAO BCP Directive

Your business continuity framework, measured against the BCEAO directive and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Business Continuity Plan Maturity · BCEAO BCP Directive

Governance and continuity policyN1 → N5
Business impact analysisN1 → N5
Disaster scenarios and risk assessmentN1 → N5
Fallback strategies and solutionsN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Governance and continuity policy6484
Business impact analysis5379
Disaster scenarios and risk assessment6182
Fallback strategies and solutions3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One BCEAO Directive on the business continuity plan of credit institutions in the WAMU assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (a level, the level above, and the action that connects the two) is what turns a finding into a trajectory.

Is the business continuity plan tested, and are the results acted upon?

  1. N1

    No test has been carried out. The plan exists as a document and has never been put to the test.

  2. N2

    Ad hoc tests have taken place, limited to a tabletop exercise or an isolated technical component. Findings are not formalised.

  3. N3

    An annual test programme is defined and applied to critical activities. Each exercise produces a report and identified corrective actions.

  4. N4

    Tests include an actual switchover to the fallback site with the relevant users and involve essential providers. Corrective actions are tracked through to closure and presented to the governing body.

  5. N5

    Test scenarios evolve based on incidents that have occurred and changes to the information system. Results feed into the impact analysis and the review of recovery objectives, with a documented history from one exercise to the next.

Action to move from Level 2 to Level 3

Add a test programme to the annual control plan covering the activities deemed critical by the impact analysis, appoint an owner and set a date for each exercise, and formalise a standard report whose corrective actions are reviewed at the following risk committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon BCEAO.

What this framework covers

The BCEAO directive on the business continuity plan requires credit institutions and bank-type financial institutions in the WAMU to maintain a written framework, approved by the governing body, that ensures the continuation of essential activities in the event of a major disruption. It sets out four obligations: identify critical activities through a business impact analysis, define recovery objectives, formalise fallback and recovery procedures, then test the framework and report on the results. Internal control and internal audit have an explicit role in this.

In practice, the BCP is one of the most declarative frameworks in the prudential body of rules. The document exists almost everywhere; its vitality is far more uneven. Are recovery objectives, RTO and RPO, drawn from a business impact analysis validated by the business lines, or copied from a template? Has the fallback site ever hosted a team under real conditions, with access to production applications? Are essential service providers, hosting company, telecom operator, card switch supplier, contractually bound to verifiable continuity commitments? Many institutions discover the gap at the first full-scale test.

Two developments make the subject more demanding. The growth of payment services, electronic money and regional interoperability has shifted criticality towards largely outsourced technical chains: a provider’s unavailability becomes the institution’s unavailability. In addition, the BCEAO texts on information system security and on outsourcing overlap with the BCP. A common confusion is reducing continuity to the IT disaster recovery plan, whereas the directive targets the continuity of banking activities: tellers, payment instruments, credit, regulatory accounting, customer relations.

A compliance audit concludes with a binary answer: the plan exists, it is approved, it is tested. The maturity assessment asks a different question. What level of control does each component sit at, and what concrete action moves it to the next level. An institution whose BCP is tested once a year on a theoretical scenario and an institution that actually switches over to its fallback site are both "compliant". They are not at the same maturity level, and they will not react the same way.

In Datamensio, the framework is ready to use and adapts to your organisation. The AI adjusts themes, questions and level wording according to your size, your model and your activities, or builds a variant from your own documents: continuity policy, impact analysis, test reports. A banking group present in several countries of the Union can roll out the same framework across each subsidiary and compare results.

Reference standard: BCEAO Directive on the business continuity plan of credit institutions in the WAMU

The themes assessed

  • Governance and continuity policy

    Formal policy approved by the governing body, roles of the BCP manager and business line correspondents, steering committee, alignment with the internal control framework, dedicated budget.

  • Business impact analysis

    Inventory of activities and processes, criticality criteria, determination of maximum tolerable outage periods, recovery objectives RTO and RPO, validation by business lines, update frequency.

  • Disaster scenarios and risk assessment

    Scenarios covered (unavailability of premises, information system, staff, a provider, power or telecom outage), consistency with the operational risk map, periodic review.

  • Fallback strategies and solutions

    User fallback site, IT and data backup, resourcing, documented degraded modes for tellers, payment instruments and accounting, manual substitution procedures.

  • Crisis management arrangements

    Crisis unit and backups, activation criteria and authority, incident log, backup communication means, return-to-normal procedures.

  • Essential providers and outsourcing

    Identification of critical providers, contractual continuity clauses and service levels, provider continuity plans, joint testing, reversibility and substitution strategies.

  • Tests and exercises

    Annual test programme, types of exercise (tabletop, technical switchover, exercise with users), scope covered, success criteria, reporting, follow-up of corrective actions through to closure.

  • Training, awareness and documentation

    Training of the crisis unit and fallback teams, staff awareness, accessibility and version control of procedures outside the main information system, up-to-date crisis directories.

  • Continuity of customer relations and payments

    Maintaining customer services in degraded mode, availability of ATMs and card processing, customer information, continuity of interbank exchanges and regional systems.

  • Control, reporting and continuous improvement

    Permanent and periodic controls over the framework, indicators tracked, reporting to the governing body and the supervisory authority, post-incident lessons learned, plan updates.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment amount to a certificate of compliance with the BCEAO directive?

No. Datamensio measures the maturity of your framework and prepares you for inspection; it does not issue any certificate. Compliance is a matter for the Commission Bancaire de l’UMOA and your own internal control work. The assessment tells you where you stand and what remains to be done.

How is this different from a BCP compliance audit?

An audit checks that the required elements exist and concludes with a gap or a pass. The assessment positions each component on a progressive scale and points to the action that moves it to the next level. The two complement each other: the assessment prepares for the audit, the audit validates it.

How long does the assessment take?

The short version can be completed in a single session by the BCP manager. The full version, run collaboratively with internal control, IT and the business lines, generally takes one to two weeks, most of the time going into gathering evidence from the teams.

Can the framework be adapted to our institution?

Yes. You can modify the questions, levels and themes, or start from your own documents: the AI then builds a variant suited to your model, universal bank, payment institution or decentralised financial system. You retain full control of the framework.

Can several subsidiaries of the group be compared?

Yes. The same framework is rolled out across each business unit, with a score per theme and a benchmark between entities and against previous campaigns. A cross-entity roadmap consolidates the action plans of the various subsidiaries and avoids duplicating the same work.

How does the BCP link with information system security and outsourcing?

The three BCEAO texts overlap on critical providers, availability and incident management. A solid BCP assessment provides a reusable foundation for these two other frameworks, and the cross-entity roadmap allows them to be cross-referenced without addressing the same action twice.

What does the assessment actually produce?

A score per theme, a target, and the gap between the two that generates the action plan. The AI groups actions into a prioritised roadmap, and the service catalogue matches each item with a solution, its cost, timeframe and impact on the score. The readout is shared with general management in a space carrying your own branding.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon BCEAO.