EDIH, EEN, Interreg: the platform for European programmes.Find out more

Customer protection · CEMAC consumer protection regulation

Your customer protection obligations, measured by theme and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Customer protection · CEMAC consumer protection regulation

Customer protection governanceN1 → N5
Transparency of banking terms and conditionsN1 → N5
Precontractual information and duty to adviseN1 → N5
Agreements and contractual documentsN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Customer protection governance6484
Transparency of banking terms and conditions5379
Precontractual information and duty to advise6182
Agreements and contractual documents3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One CEMAC Regulation on the protection of consumers of financial products and services (No. 04/18/CEMAC/UMAC/COBAC) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, one level, the level above, and the action that connects the two, that turns a finding into a trajectory.

Are customer complaints logged, handled within a defined timeframe and used to drive improvement?

  1. N1

    No complaints register. Complaints are handled by the branch or department concerned, with no centralised record or defined timeframe.

  2. N2

    A procedure exists and a register is kept, but it does not cover all channels and response times are not measured.

  3. N3

    All complaints, regardless of channel, are logged in a single register. An acknowledgement of receipt is sent and response time is tracked.

  4. N4

    Response times are reported monthly by entity, appeal routes are systematically communicated, and overdue cases are escalated.

  5. N5

    The root causes of complaints are analysed periodically, leading to corrections in products or procedures, and the arrangement itself is reviewed based on this feedback.

Action to move from L2 to L3

Link complaints received at the counter, by phone and through digital channels to a single register, generate an acknowledgement of receipt with a due date, and check the completeness of the register at the monthly permanent control committee meeting.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon CEMAC.

What this framework covers

The CEMAC regulation on the protection of consumers of financial products and services governs the relationship between the regulated institution and its customers throughout the life of the product. It covers precontractual and contractual information, advertising of banking terms and conditions, free provision of certain basic services, mandatory content of account agreements, notice periods for pricing changes or account closure, complaints handling, confidentiality of customer information and the duty to advise. The COBAC supervises its application and the framework provides for sanctions.

In practice, these obligations are difficult to manage because they are spread across the branch network, marketing, compliance, legal and information systems. Are the banking terms and conditions displayed in branches identical to those configured in the core banking system and published on online channels? Do complaints received at the counter, by phone and through digital channels feed into a single register, with response times measured? Is the actual handover of the account agreement and pricing brochure tracked case by case, or only provided for in the procedure?

Two developments are reshaping the issue. First, the rise of mobile money and payment services across the zone, which multiplies points of contact with customers who are less familiar with financial mechanisms and makes clear information and fee transparency far more concrete. Second, the growing weight given to financial education and complaints handling in the regional supervisor’s priorities. A confusion often arises: customer protection is not a subset of AML/CFT compliance, it has its own requirements and its own oversight arrangements.

A compliance audit ends with a binary finding: the obligation is met or it is not. The maturity assessment answers a different question. What level of control does each practice sit at, between the absence of any arrangement, a written procedure applied unevenly, generalised and monitored application, and periodic review supported by indicators. Each level carries the action that moves it up to the next. The two approaches complement each other: the assessment prepares the on-site inspection, the inspection validates it.

In Datamensio, the framework is ready to use and adaptable. The AI adjusts the themes, questions and wording of the levels according to your status, bank, microfinance institution or payment service provider, or builds a custom version based on your internal procedures and your banking terms and conditions.

Reference standard: CEMAC Regulation on the protection of consumers of financial products and services (No. 04/18/CEMAC/UMAC/COBAC)

The themes assessed

  • Customer protection governance

    Formalised policy approved by the governing body, appointment of a responsible officer, coordination with compliance and permanent control, resources allocated, reporting to senior management.

  • Transparency of banking terms and conditions

    Publication and display of pricing in branches and on digital channels, consistency between displayed pricing, marketing materials and system configuration, updates after each change.

  • Precontractual information and duty to advise

    Handover of information documents before commitment, explanation of total cost and exit conditions, gathering of customer needs, traceability of advice given, treatment of vulnerable customers.

  • Agreements and contractual documents

    Mandatory content of the account agreement, clarity of clauses, language used, handover of a copy to the customer, retention of proof of handover, prohibited clauses.

  • Basic banking services and accessibility

    Services provided free of charge, conditions for account access, refusal to open an account and justification, continuity of service, accessibility for rural customers and people with disabilities.

  • Changes, closure and mobility

    Compliance with notice periods for pricing or contractual changes, account closure procedure, return of funds and payment instruments, associated fees.

  • Complaints handling

    Identified entry point by channel, single register, acknowledgement of receipt, measured response times, appeal routes communicated to the customer, root cause analysis and feedback to business lines.

  • Advertising and commercial practices

    Accuracy and clarity of promotional messages, disclosure of terms and cost, internal validation before publication, controls on bundled sales and sales incentives.

  • Confidentiality and protection of customer data

    Banking secrecy, access rights to customer files, controls on disclosure to third parties and service providers, retention and destruction of data, incident management.

  • Financial education and oversight of the arrangements

    Customer information initiatives, training of front-line staff, second-line controls on commercial practices, indicators tracked, follow-up on findings.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment count as a certificate of compliance with the COBAC?

No. Datamensio measures the maturity of your practices and produces an action plan; it issues no certificate. The result is used to prepare for an on-site inspection and to document the compliance trajectory for the governing body.

What is the difference between this assessment and a compliance audit?

The audit checks each requirement individually and concludes with a gap or a pass. The assessment places each practice on a maturity scale and identifies the action that moves it up a level. The assessment prepares the audit, the audit validates it.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with the network, compliance and legal teams, typically spans one to two weeks, with most of the time spent gathering evidence.

Is the framework suitable for microfinance institutions and payment service providers?

Yes. The regulation covers all regulated entities in the zone. The AI adjusts the questions and the wording of the levels according to your status, ruling out points that do not apply and refining those that do.

Can the framework be adapted to our procedures?

Yes. You can modify the themes, questions and levels, or build a custom version based on your banking terms and conditions and internal procedures. You retain full ownership of the framework.

How can we compare our subsidiaries with each other?

Each entity completes the same assessment and gets its own score by theme. The benchmark compares business units and tracks progress over time. A cross-entity roadmap consolidates subsidiaries’ action plans without duplicating common actions.

How does this assessment fit with AML/CFT and internal control?

The three areas share control points, notably customer due diligence, documentary traceability and the permanent control arrangements. Cross-framework roadmaps allow you to cross-reference frameworks and link a single action to several obligations.

Where is the data hosted?

In France, with OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon CEMAC.