EDIH, EEN, Interreg: the platform for European programmes.Find out more

Outsourcing Maturity · BCEAO Directive on Outsourcing

Your outsourced services, mapped against the BCEAO directive and turned into an action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Outsourcing Maturity · BCEAO Directive on Outsourcing

Outsourcing policy and governanceN1 → N5
Inventory and qualification of activitiesN1 → N5
Prior analysis and provider selectionN1 → N5
ContractingN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Outsourcing policy and governance6484
Inventory and qualification of activities5379
Prior analysis and provider selection6182
Contracting3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One BCEAO Directive on outsourcing of activities by credit institutions and financial companies of the UMOA assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, one level, the level above, and the action linking the two, is what turns a finding into a trajectory.

Is the audit right provided for in the contract actually exercised on essential services?

  1. N1

    No systematic audit clause in contracts. Monitoring relies on commercial exchanges with the provider.

  2. N2

    The clause appears in recent contracts, but has never been exercised. Provider reports are received without a formal review.

  3. N3

    Essential services are subject to a documented annual review, desk-based or on-site, with a report circulated to the control functions.

  4. N4

    The provider audit programme is planned according to criticality, findings lead to corrective actions tracked to closure and reported to the executive body.

  5. N5

    The programme is revised in light of incidents, changes at the provider and lessons from previous engagements, with a documented record of revisions.

Action to move from L2 to L3

Select the services qualified as essential, plan at least a desk-based annual review for each, and put the reporting of findings on the agenda of the risk committee for the following quarter.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon BCEAO.

What this framework covers

The BCEAO directive on outsourcing sets out the conditions under which a credit institution, payment institution or financial company in the UMOA may entrust an activity it would otherwise carry out itself to a third party. It rests on a simple principle: outsourcing transfers execution, never accountability. The institution remains answerable to the UMOA Banking Commission for the quality of the service, the control of associated risks and the protection of its customers’ data. The text distinguishes essential or important activities, subject to a reinforced regime, from other services.

In practice, the arrangement is hard to steer. The first difficulty is the inventory: how many providers are actually involved, including those contracted directly by a business line without going through procurement? The second is qualification: who decides that an activity is essential, on what criteria, and how often is that classification reviewed? The third is ongoing oversight. Audit clauses appear in the contract, but have they ever been exercised? Are service level indicators tracked, or only looked at after an incident?

Two developments are reshaping the picture. Cloud computing first: hosting banking data with an international provider raises questions of location, reversibility and the supervisor’s actual right of access. Cascading subcontracting second: the main provider itself relies on third parties, often outside the scope of the original contract. One confusion also keeps coming back, that between outsourcing and simple procurement of supplies. The distinction does not rest on the contract amount but on the nature of the activity entrusted and whether it is essential.

A compliance audit ends with a binary finding: the clause is in the contract, or it is not. The maturity assessment asks a different question. What level of control does the arrangement actually reach, provider by provider and theme by theme, and what specific action moves it up a level. An exhaustive but never updated register and a partial register reviewed every quarter are not equivalent, yet an audit can treat them the same way.

In Datamensio, the framework is ready to use and remains yours. You adjust the themes, questions and wording of the levels. The AI refines these levels using the CMMI method, or builds a version tailored to your organisation from your outsourcing policy and standard contracts. Banking groups roll out the same framework across several subsidiaries and compare results between business units.

Reference standard: BCEAO Directive on outsourcing of activities by credit institutions and financial companies of the UMOA

The themes assessed

  • Outsourcing policy and governance

    Existence of a policy approved by the governing body, roles and responsibilities, decision thresholds, alignment with strategy and the risk management framework.

  • Inventory and qualification of activities

    Register of outsourced services, criteria for qualifying essential or important activities, treatment of intragroup services, update frequency.

  • Prior analysis and provider selection

    Opportunity and risk assessment before deciding, due diligence on financial and technical capacity, verification of licences, documented selection criteria.

  • Contracting

    Service level clauses, the institution’s audit right and the supervisor’s access, confidentiality and data protection, cascading subcontracting, termination conditions.

  • Reporting and relations with the supervisor

    Prior notification or declaration of essential outsourcing arrangements, content of the file submitted, traceability of exchanges with the UMOA Banking Commission.

  • Ongoing control and monitoring of the service

    Performance indicators tracked, steering committees, actual exercise of the audit right, handling of incidents and breaches, reporting to the executive body.

  • Information systems and data risks

    Data location and hosting, security and access, cloud computing, integration of the provider into the institution’s security requirements.

  • Business continuity and reversibility

    The provider’s continuity plan and its alignment with the institution’s own plan, joint tests, exit strategy, reversibility plan and conditions for data return.

  • Concentration and dependency

    Identification of critical providers shared across the group, measurement of dependency, alternative solutions identified, monitoring of concentration at group level.

  • Periodic review and improvement

    Annual review of the arrangement, requalification of activities, lessons learned after incidents, inclusion in the internal audit plan.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does the assessment amount to compliance with the BCEAO directive?

No. Datamensio measures the maturity of your arrangement and prepares you for discussions with the UMOA Banking Commission. It does not issue any certification. The assessment identifies gaps and the trajectory, on-site inspection remains the supervisor’s responsibility.

What is the difference between this assessment and a compliance audit?

An audit checks whether a requirement is present and concludes with a gap or a compliant finding. The assessment places each practice on a progressive scale and points to the action that moves it up a level. The two complement each other: the assessment prepares, the audit validates.

How long does the assessment take?

The short version can be completed in a single session. The full version involves several contributors, risk, compliance, IT and procurement, and usually spans one to two weeks. Most of the time goes into gathering contracts and control evidence.

Can the framework be adapted to our institution?

Yes. You can change the questions, levels and themes, or start from your own outsourcing policy. The AI refines the level wording using the CMMI method and builds a version from your documents. The framework is yours.

Are intragroup services within scope?

Yes. A support function shared at the level of a financial company or parent entity remains an activity entrusted to a separate legal third party. The framework includes dedicated questions on their qualification and contractual formalisation.

How should cloud computing contracts be handled?

The information systems theme covers data location, the supervisor’s access, cascading subcontracting and reversibility. These points overlap with the BCEAO directive on managing information systems risk.

Can several subsidiaries of the group be compared?

Yes. The same framework can be rolled out across several business units, with a score by theme and a benchmark between entities as well as against previous campaigns. The AI groups gaps into a cross-cutting roadmap, without duplicating shared actions.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon BCEAO.