Payment Services Maturity · UEMOA Regulation on Payment Services
Your payment services practices placed on a maturity scale, and converted into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Payment Services Maturity · UEMOA Regulation on Payment Services
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One UEMOA Regulation on Payment Services (BCEAO) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism (one level, the level above, and the action linking the two) is what turns an observation into a trajectory.
Are funds received from customers subject to verifiable safeguarding and reconciliation?
- N1
No dedicated account identified. Customer funds are not distinguished from the institution’s own resources.
- N2
A safeguarding account exists, but reconciliation with commitments to customers is occasional and carried out manually.
- N3
Safeguarding is in place and reconciliation is carried out at a defined frequency, with any discrepancy documented and justified.
- N4
Reconciliation is daily and automated, discrepancies are subject to an alert threshold and tracked handling through to resolution.
- N5
The mechanism is controlled by an independent function, tested periodically including under a failure scenario, and its results are presented to governing bodies.
Action to move from level 2 to level 3
Set a reconciliation frequency formalised in the procedure, appoint a named owner for each payment service, and put the review of discrepancies on the agenda of the monthly risk committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon UEMOA.
What this framework covers
The UEMOA regulation on payment services sets out the framework applicable to payment service providers across the zone: categories of players and conditions for licensing by the BCEAO, minimum capital and own funds requirements, safeguarding of funds received from customers, information and pricing transparency obligations, transaction security and authentication, complaints handling, and oversight of payment systems and instruments. It ties in with the directive on electronic money issuers and with the anti-money laundering framework applicable across the Union.
In practice, oversight is made difficult by the diversity of players and the pace of roll-outs. Are customer funds genuinely safeguarded in a dedicated account, reconciled daily, with the balance enforceable in the event of failure? Are technical partners, agents and distributors governed by compliant agreements, with effective control over their practices in the field? Do payment incidents and complaints get escalated within measured timeframes, or are they handled ad hoc by support teams?
One common confusion is worth clearing up. Issuing electronic money and providing a payment service do not fall under the same regime. An electronic money institution, a bank, a bank-type financial institution and a technical provider acting as a subcontractor do not carry the same own funds obligations, nor the same liabilities towards the end customer. Many internal set-ups were built on a partial reading of the framework, often inherited from the launch of a first mobile product, then extended without review to services falling under a different regime.
The maturity assessment answers a different question from a compliance audit. An audit concludes with a gap or a pass, at a given date. The assessment places each practice on a progressive scale and points to the precise action that moves it up a level. It therefore lends itself to steering a transformation programme over several quarters, and to comparing business units or subsidiaries established in several member states.
In Datamensio, the framework is ready to use and adaptable. The AI adjusts themes, questions and levels to your status and your offering, or builds a variant from your procedures, partnership agreements and internal control reports.
Reference standard: UEMOA Regulation on Payment Services (BCEAO)
The themes assessed
Status, licensing and scope of activity
Category of player and services actually provided, licensing conditions, extension of scope, notification to the BCEAO when the offering evolves.
Own funds and financial soundness
Minimum capital, own funds requirement relative to business volume, ongoing monitoring of thresholds, alert mechanism when thresholds are breached.
Protection and safeguarding of customer funds
Dedicated safeguarding account, reconciliation between funds received and commitments to customers, frequency of checks, guarantees drawn on.
Governance and internal control of the payment set-up
Roles and responsibilities, first and second line control mechanisms, reporting to governing bodies, annual control plan.
Transaction security and authentication
Payer authentication, channel security, access management, detection of atypical transactions, monitoring and notification of security incidents.
Customer information and pricing transparency
Framework agreement, advance disclosure of fees, information on execution timeframes, blocking and refund conditions, clarity of materials.
Transaction execution and incident management
Execution timeframes and value date, unauthorised or incorrectly executed transactions, refund procedures, traceability of rejections and suspense items.
Complaints and mediation
Filing channels, measured processing times, reasons analysed, reporting to internal bodies, alignment with customer protection mechanisms.
Agents, distributors and outsourcing
Agreements and responsibilities, selection and training of the network, desk-based and on-site controls, oversight of technical providers and critical subcontractors.
Anti-money laundering and reporting
Customer identification and knowledge according to service level, caps, transaction monitoring, suspicious transaction reports, periodic reporting to the BCEAO.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does the assessment amount to a licence or a compliance certificate from the BCEAO?
No. Datamensio measures the maturity of your set-up and prepares you for review by the regulator or your auditors. Licensing and supervision remain the exclusive responsibility of the BCEAO and the UEMOA Banking Commission.
What is the difference between this assessment and a compliance audit?
An audit checks for the presence of requirements and concludes with a gap or a pass. The assessment places each practice on a progressive scale and points to the action that moves it up a level. The two are complementary: the assessment prepares for the audit, the audit validates.
How long does the evaluation take?
The short version can be completed in a single working session. The full version, run collaboratively with several contributors, spans one to two weeks, most of the time being spent gathering input from the card, compliance and internal control teams.
Is the framework suitable for both an electronic money institution and a bank?
Yes, provided the scope is adjusted. The common themes remain the same, while own funds and safeguarding requirements differ according to status. The AI adapts questions and levels to your category of player and the services actually marketed.
Can the framework be adapted to our procedures?
Yes. You can edit questions and levels, add your own themes, or start from a blank base. The AI can also build a variant from your internal procedures and partnership agreements. You retain full control of the framework.
How can several subsidiaries across the Union be compared?
Each subsidiary is assessed on the same framework. The benchmark compares scores by theme across business units and over time. A cross-cutting roadmap consolidates the action plans of the different entities without duplicating shared actions.
Does the assessment also cover electronic money and customer protection?
The framework covers the overlapping points, notably fund safeguarding, customer information and complaints handling. For a full review, it combines with the dedicated frameworks for electronic money and banking customer protection.
Where is the data hosted?
In France, with OVH, backed up at Scaleway. No transfers outside the European Union. The AI models used can be selected, including from European solutions.



