CEMAC internal control · COBAC internal control regulation
Your internal control, measured against the COBAC framework and turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
CEMAC internal control · COBAC internal control regulation
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One COBAC Regulation R-2016/04 on the internal control of credit institutions assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, the level above, and the action linking the two, is what turns an observation into a trajectory.
Are recommendations from periodic control and from the supervisor’s missions followed through to closure?
- N1
Recommendations appear in mission reports. No organised follow up exists between missions.
- N2
A tracking table is kept by internal audit. It is updated irregularly and overdue deadlines do not trigger a follow up.
- N3
Each recommendation has an owner, a deadline and a status. Tracking is reviewed periodically and delays are flagged to senior management.
- N4
Closure is only granted after internal audit has verified effectiveness. The audit committee reviews the status of recommendations at every meeting, including those from the supervisor.
- N5
Recurring root causes are analysed and feed into the revision of the permanent control plan and the audit plan. The effectiveness of the follow up process is itself assessed.
Action to move from L2 to L3
Assign each open recommendation a named owner and a deadline, and add a review of progress to the monthly management committee agenda, with explicit flagging of overdue deadlines.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon COBAC.
What this framework covers
The COBAC regulation on internal control sets out the organisational requirements that CEMAC credit institutions and financial holdings must apply to their control framework. It distinguishes permanent control, exercised at first level by operational staff and at second level by dedicated functions, from periodic control, which falls to internal audit. It requires independent risk management and compliance functions, a system for measuring and monitoring credit, market, liquidity, interest rate and operational risk, an audit trail, and an annual internal control report submitted to the supervisor and presented to the deliberative body.
The difficulty is not knowing the text, it is demonstrating that the framework works. The questions raised in the boardroom are concrete ones. Does the second level permanent control plan cover the processes that actually carry risk, or only those the teams know how to control? Are recommendations from internal audit and from the supervisor’s missions followed through to closure, with evidence of effectiveness? Does the head of compliance report to the deliberative body without filtering by senior management? On these points, statements of intent rarely suffice.
A confusion recurs often: equating internal control with internal audit. Internal audit is periodic control, one link in the framework, not the framework itself. An institution can have an active inspection function while its permanent control is effectively non existent, its risk maps unrevised, and its reporting cycle to the board reduced to a formality. Another point of context: the growing weight of regional prudential requirements, ICAAP, information systems security, outsourcing, all rest on the same foundation, and a weak internal control undermines every other workstream.
A compliance audit asks a binary question: is the requirement met or not. A maturity assessment asks a question of trajectory: at what level of control does each component of the framework stand, and what specific action moves it up a level. A control plan that exists but is applied unevenly across branches is neither compliant nor absent, it sits at an intermediate level, and it is that position which lets you cost the remaining effort and schedule it over a financial year.
In Datamensio, the framework is ready to use and remains yours. The AI adjusts themes, questions and levels to your size, your branch network structure or your status as a subsidiary of a regional group. It can also build a version from your own documents: audit charter, control plan, annual internal control report, supervisor’s follow up letters.
Reference standard: COBAC Regulation R-2016/04 on the internal control of credit institutions
The themes assessed
Overall organisation of the framework
Architecture of the three control levels, separation between functions that commit the institution and those that control them, formalisation in a charter, adequacy of resources.
Role of the executive and deliberative bodies
Deliberative body’s responsibility for the framework, audit committee, frequency and content of reporting, documented decisions, approval of the annual internal control report.
Permanent control
First level controls built into procedures, identified second level function, control plan, scope covered, formalisation and use of results.
Periodic control and internal audit
Audit charter, independence and reporting line, risk based multi year plan, coverage of activities and branches, quality of reports, follow up of recommendations through to closure.
Risk management
Independent risk function, risk map and its updating, measurement systems for credit, market, liquidity, interest rate and operational risk, limit setting and handling of breaches.
Compliance and AML/CFT
Identified compliance function, control of non compliance risks, anti money laundering and counter terrorist financing framework, screening, reporting, relations with the FIU.
Information systems and audit trail
Data security and integrity, access rights management, traceability of transactions from origin to posting, business continuity plan and testing.
Accounting control and prudential reporting
Account reconciliation and substantiation, control over the production of regulatory returns, reliability of submissions to the supervisor, filing deadlines.
Outsourcing and essential services
Inventory of outsourced activities, contractual control and access clauses, oversight of providers, reversibility.
Malfunctions, incidents and continuous improvement
Recording and reporting of incidents and operational losses, thresholds, corrective plans, lessons learned, periodic review of the framework.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment amount to a certificate of compliance with the COBAC regulation?
No. Datamensio measures the maturity of the framework and prepares for supervisory deadlines. Compliance judgement rests with COBAC and, for assurance work, with statutory auditors. The assessment tells you where you stand before they do.
What is the difference between this assessment and the annual internal audit?
Internal audit checks processes and concludes with findings and recommendations. The assessment places each component of the framework on a maturity scale and points to the action that moves it up a level. The two complement each other: the assessment frames the audit plan, the audit provides evidence from the field.
How long does the assessment take?
The short version takes 20 to 30 minutes for a head of permanent control or internal audit to complete. The full version, run collaboratively with compliance, risk, accounting and information systems, generally spans one to two weeks, most of the time going into gathering evidence.
Can the framework be adapted for a microfinance institution or a small structure?
Yes. Questions, levels and themes can be changed, and the AI produces a version adapted to the institution’s size and status, including for microfinance institutions whose requirements differ. You can also start from your own internal documents.
Can several subsidiaries or branches be compared?
Yes. The same framework can be rolled out to several business units, with a score by entity and by theme, a benchmark across entities and a comparison with previous campaigns. Action plans are consolidated into a single cross cutting roadmap, avoiding the same gap being addressed ten times over.
How is the action plan produced?
The gap between the score achieved and the target set generates the actions. The AI groups them into coherent workstreams and prioritises them. The service catalogue links each action to a solution with its cost, timeframe and expected impact on the score, allowing decisions to be made before budgeting.
How does this framework fit with governance, AML/CFT or ICAAP?
These frameworks share the same organisational foundation and the same governing bodies. A solid internal control assessment can largely be reused. The cross cutting roadmap connects several audits without duplicating common actions.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.



