Banking Internal Control Maturity · BCEAO Instruction on internal control
Your internal control set-up measured against the BCEAO Instruction, translated into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Banking Internal Control Maturity · BCEAO Instruction on internal control
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One BCEAO Instruction on internal control for credit institutions and financial companies of the UMOA assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, the level above, and the action linking the two, is what turns a finding into a trajectory.
Are recommendations from internal controls and from supervisor missions tracked through to closure?
- N1
No centralised tracking. Recommendations circulate in reports, with no arrangement to know which ones have been settled.
- N2
A tracking table exists, updated as deadlines approach. Implementation dates are often missed without any arbitration.
- N3
Each recommendation has an owner, a deadline and a progress status reviewed periodically. Closures are confirmed against evidence.
- N4
Tracking is presented to the audit committee at every meeting, delays are arbitrated with a trace, and closures are checked by internal audit.
- N5
Recurring recommendations are analysed by root cause, feed into the control plan and the risk map, with documented tracking of the effects achieved.
Action to move from L2 to L3
Assign every open recommendation a named owner, a deadline and the closure evidence expected, then put the review of the table on the agenda of the quarterly internal control committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon BCEAO.
What this framework covers
The BCEAO Instruction on internal control applies to credit institutions, financial companies and, in part, to decentralised financial systems of the West African Monetary Union. It calls for a complete set-up: a system for controlling operations and internal procedures, an accounting organisation and information processing framework, measurement and monitoring arrangements for credit, market, liquidity, interest rate and operational risk, a compliance control function, and an independent internal audit function. It also specifies the annual reports expected by the UMOA Banking Commission and the role of the audit committee.
In practice, the set-up is hard to steer because it is distributed. First-line permanent control sits with the business, second-line functions are often understaffed, and third-line internal audit runs a multi-year plan that does not cover everything each year. The practical questions look alike from one institution to another. Are first-line controls actually performed and evidenced, or reconstructed ahead of the mission? Are recommendations from internal audit and from Banking Commission missions tracked through to actual closure? Does the operational risk map genuinely steer the control plan, or does it remain an annual document?
A recurring confusion is that internal control would be the permanent control officer’s job alone. The Instruction places primary responsibility on the deliberative body and the executive body, with reports addressed to them and passed on to the supervisor. The build-up of the Basel II/III prudential framework in the UEMOA, ICAAP and consolidated supervision requirements reinforce this point: internal control now feeds directly into the assessment of an institution’s risk profile and capital adequacy. A weak set-up gets paid for elsewhere.
A compliance audit asks a binary question: is the requirement met, yes or no. A maturity assessment asks a different question: at what level of control does the practice sit, and what precise action moves it up a level. For an internal control set-up, this nuance is decisive: between a written procedure and one that is applied, checked and reviewed, there are three levels of gap and just as many steps to fund.
In Datamensio, the framework is ready to use and remains yours. The AI adjusts themes, questions and level wording to your size and business model, or builds a variant from your procedures, your audit charter and your internal control reports. Assessments run entity by entity, subsidiary by subsidiary, with comparison across business units and over time.
Reference standard: BCEAO Instruction on internal control for credit institutions and financial companies of the UMOA
The themes assessed
Governance and accountability for the set-up
Role of the deliberative body and the executive body, audit committee, internal control charter, resource allocation, independence of control functions.
Organisation of the three lines of defence
First-line controls embedded in processes, second-line permanent control, third-line internal audit, segregation of duties and no combining of incompatible functions.
Control of operations and internal procedures
Procedural corpus, updating, completeness of control points, traceability of controls performed, handling of detected anomalies.
Accounting organisation and financial information
Audit trail, account reconciliations and justification, periodic closing, reliability of data feeding prudential reporting.
Credit risk measurement and monitoring
Origination and delegation set-up, rating and classification of loans, provisioning, exposure monitoring, risk spread and large exposures.
Market, interest rate and liquidity risk
Limits set and validated, monitoring of breaches, measurement of transformation, liquidity indicators, stress scenarios.
Operational risk and continuity
Operational risk mapping, collection and analysis of incidents and losses, business continuity set-up, dependence on outsourced providers.
Compliance, AML/CFT and customer protection
Regulatory monitoring, compliance control of new products, anti-money laundering set-up, complaints handling, transparency of banking terms.
Information systems security
Access rights management, security of sensitive applications, logging, control of developments and changes, backups and restoration tests.
Reporting, tracking of recommendations and improvement
Annual reports to the supervisor, information to governance bodies, tracking through to closure of recommendations from internal audit, statutory auditors and Banking Commission missions.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment count as a compliance attestation for the Banking Commission?
No. Datamensio measures the maturity of the set-up and prepares for control deadlines, it issues no attestation. Only the supervisor assesses compliance, through its off-site and on-site controls. The assessment serves to identify gaps before they are flagged.
How does this differ from a compliance audit conducted by internal audit?
An audit concludes with a finding of compliance or a gap on a given scope. The assessment places practice on a progressive maturity scale and points to the action that moves it up a level. The two complement each other: the assessment steers the audit plan, the audit checks on the ground.
How long does the assessment take?
The short version runs in a single working session. The full version, run collaboratively with permanent control, compliance, risk and internal audit, generally spans one to two weeks, with most of the time spent gathering evidence.
Can the framework be adapted to our institution?
Yes. You can change the questions, level wording and themes, or add your own. The AI also builds a variant from your procedures and internal control reports. The framework remains your property.
Can several group subsidiaries be compared?
Yes. The same framework is deployed across each entity, with a score by theme comparable from one business unit to another and over time. A cross-cutting roadmap consolidates the assessments to identify common gaps and actions that can be shared across the group.
How does the assessment fit with ICAAP and the UEMOA Basel II/III prudential framework?
The quality of internal control determines the reliability of the risk data used in ICAAP and prudential reporting. Assessments run on these frameworks cross-reference into a common roadmap, without duplicating actions already under way.
Is the action plan costed?
Each gap opens an action, and the service catalogue attaches a cost, a timeframe and an expected impact on the score to these actions. You arbitrate on a comparable basis instead of an unvalued list of recommendations.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.



