EDIH, EEN, Interreg: the platform for European programmes.Find out more

Governance Maturity for Credit Institutions · UEMOA Banking Law and BCEAO Circulars

Your bank’s governance assessed against BCEAO requirements, translated into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Governance Maturity for Credit Institutions · UEMOA Banking Law and BCEAO Circulars

Board composition and operationN1 → N5
Specialised committeesN1 → N5
Fitness and propriety of executivesN1 → N5
Executive body and delegationsN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Board composition and operation6484
Specialised committees5379
Fitness and propriety of executives6182
Executive body and delegations3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One UEMOA Banking Law (2008) and BCEAO Circular No. 001-2017/CB/C on the governance of credit institutions and financial companies assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, a level, a higher level, and the action linking them, is what turns a finding into a trajectory.

Does the board examine the reports of control functions and follow up on recommendations?

  1. N1

    Reports from control functions are not presented to the board. Follow up on recommendations remains internal to executive management.

  2. N2

    Reports are forwarded to the board for information. Review is occasional and follow up on recommendations is not formalised.

  3. N3

    Reports are placed on the agenda, examined in session and lead to recorded decisions. A tracking log of recommendations is maintained.

  4. N4

    The audit committee reviews the reports beforehand, hears control function heads without executive management present, and the tracking log shows owner, deadline and status for each recommendation.

  5. N5

    The framework is reviewed periodically: analysis of recurring recommendations, escalation into the board’s priorities, and integration of Banking Commission findings into the annual work programme.

Action to move from L2 to L3

Place the review of compliance, risk and internal audit reports as a standing item on the board’s agenda, and open a recommendations tracking log reviewed at each session, with owner and deadline.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon BCEAO.

What this framework covers

Governance of credit institutions in the UEMOA rests on a set of interlinked texts: the Banking Law, the annex to the convention establishing the Banking Commission, and the circulars issued by the BCEAO in 2017, including the one devoted to governance. These texts define the composition and operation of the board, the role of its specialised committees, fitness and propriety criteria for executives, the independence of control functions, remuneration policy, conflict of interest management and the treatment of related party transactions.

In practice, the framework is hard to steer because it concerns behaviours as much as documents. Does the audit committee meet at the required frequency, with its own agenda, or does it merely validate files prepared elsewhere? Are directors described as independent actually independent under the circular’s criteria, or only by internal convention? Does the compliance officer report to the board, or does the reporting line place them under the authority of those they are meant to control? These questions are not settled by minutes of a meeting.

A common misconception persists: that governance is a matter of statutes and appointments. The 2017 circulars shifted the requirement towards effectiveness. The board must demonstrate that it exercises oversight, sets risk appetite, examines the reports of control functions and follows up on Banking Commission recommendations. Consolidated supervision also extends these expectations to financial companies and cross-border groups, requiring consistency between the parent company and subsidiaries established in several member states.

A compliance check ends with a finding: the requirement is met, or it is not. The maturity assessment answers a different question: at what level of control does each practice sit, and what specific action moves it up a level. This distinction is what turns a list of gaps into a transformation programme, and allows entities within the same group to be compared on a common scale.

The framework is ready to use within Datamensio. You can adapt it: the AI adjusts the themes, questions and levels to your size, status and scope, or builds a tailored version from your own documents, governance charter, committee bylaws and internal control reports.

Reference standard: UEMOA Banking Law (2008) and BCEAO Circular No. 001-2017/CB/C on the governance of credit institutions and financial companies

The themes assessed

  • Board composition and operation

    Size and diversity of the board, independence criteria for directors, frequency and conduct of meetings, quality of board papers, periodic evaluation of the board and its members.

  • Specialised committees

    Existence and remit of audit, risk, nomination and remuneration committees, bylaws, composition, frequency of work, reporting to the board.

  • Fitness and propriety of executives

    Eligibility criteria, selection procedure, approval and notification files to the BCEAO, ongoing training, management of multiple mandates, succession plans.

  • Executive body and delegations

    Division of powers between the board and executive management, formalisation of delegations, collective decision making, coordination of management committees.

  • Risk appetite and risk culture

    Formalisation of risk appetite, board approval, cascading into operational limits, escalation mechanism in case of breach, embedding of risk culture across business lines.

  • Control functions and independence

    Organisation of the three lines of control, reporting lines and independence of compliance, risk and internal audit, resources allocated, direct access to the board and its committees.

  • Conflicts of interest and related parties

    Conflict of interest prevention policy, declarations of interest, authorisation procedure for related party transactions, regulatory ceilings, traceability of abstentions from voting.

  • Remuneration policy

    Remuneration principles for executives and control functions, alignment with performance and risks taken, role of the relevant committee, transparency of variable components.

  • Information, reporting and relationship with the supervisor

    Quality and frequency of information provided to the board, annual internal control report, submission of regulatory returns, follow up on recommendations from the Banking Commission and statutory auditors.

  • Group governance and consolidated supervision

    Consistency of policies between the parent company and subsidiaries, oversight of cross-border entities, consolidated risk reporting, governance of outsourced activities.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment constitute a certificate of compliance with the BCEAO?

No. Datamensio measures the maturity of your practices and prepares discussions with the supervisor. Verification of compliance is the responsibility of the UEMOA Banking Commission, statutory auditors and your own internal audit work.

What is the difference between this assessment and a compliance check?

A compliance check ends with a gap or a compliance finding on each requirement. The assessment positions each practice on a progressive scale and indicates the action that moves it up a level. The two complement each other: the assessment prepares and prioritises, the check validates.

How long does the assessment take?

The short version is completed in a single working session. The full version, run collaboratively with the company secretary, compliance, risk and internal audit, takes one to two weeks, with most of the time spent gathering supporting evidence.

Can the framework be adapted to our status and size?

Yes. Questions, levels and themes can be modified, and the AI produces a version tailored to a small institution, a financial company or a decentralised financial system. You can also start from your own governance documents.

How can several subsidiaries of the same group be compared?

The assessment is run entity by entity on a common framework, making scores comparable by theme. A cross-entity roadmap consolidates the results and groups together actions that recur from one subsidiary to another.

Who should answer the questions?

The questions concern governance organisation and practices, not technical points. The company secretary, compliance, risk and internal audit cover most of the scope. Collaborative mode allows each question to be assigned to the right contributor.

How are readouts produced for the board?

Scores by theme, gaps and the action plan are presented in a branded reporting space. The AI groups gaps into a prioritised roadmap and the built-in assistant answers directors’ questions on the results.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon BCEAO.