Payment Services Maturity · CEMAC Payment Services Regulation
Your CEMAC payment services compliance, measured by theme and turned into an action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Payment Services Maturity · CEMAC Payment Services Regulation
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One CEMAC Regulation No. 04/18/CEMAC/UMAC/COBAC on payment services in CEMAC assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism, one level, the level above, and the action linking the two, that turns a finding into a trajectory.
Are funds received from customers safeguarded and reconciled against outstanding electronic money?
- N1
No dedicated safeguarding account identified. Customer funds pass through accounts also used for other purposes.
- N2
A safeguarding account exists. Reconciliation with outstanding electronic money is performed irregularly and discrepancies are not formally recorded.
- N3
Reconciliation is daily, documented, and discrepancies are justified and logged before close of day.
- N4
Reconciliation is checked by a function independent of operations, with alert thresholds, a defined escalation path and periodic reporting to the board.
- N5
The set-up is tested by internal audit on a defined cycle, stress-tested against default scenarios, and revised after every change to the offer or the banking partner.
Action to move from L2 to L3
Introduce a daily reconciliation between the safeguarding account balance and outstanding electronic money, with a discrepancy justification file signed by the head of operations, built into the existing daily closing routine.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon CEMAC.
What this framework covers
The CEMAC regulation on payment services sets the framework applicable to payment institutions, electronic money institutions and banks that issue or distribute payment instruments across the six member states of the Community. It defines the services covered (electronic money issuance, fund transfers, transaction acquiring, payment initiation), the licensing conditions set by COBAC, minimum capital requirements, rules for safeguarding funds received from customers, contractual disclosure obligations and liability in cases of unauthorised transactions. It interlinks with the AML-CFT framework and with CEMAC foreign exchange regulation.
In practice, the set-up is hard to steer because it runs across several departments and several partners. Are customer funds genuinely safeguarded in a dedicated account, reconciled daily, with the safeguarding position checked by an independent function? Are distributors and retail agents recorded and monitored, and does the contract set out the institution’s liability for their acts? Are complaint handling and refund timelines for unauthorised transactions actually measured, or merely stated in the terms and conditions? Most institutions have procedures. Few can prove they were applied over twelve months.
The regional context has moved fast. The rise of electronic money driven by telecom operators, interoperability promoted by BEAC, and tighter controls on foreign exchange flows have shifted the supervisor’s focus towards transaction traceability and the operational resilience of providers. One common confusion is worth clearing up: an electronic money institution licence does not exempt a provider from the internal control, information systems security and business continuity obligations expected of a regulated entity. A partnership with a bank does not transfer regulatory liability to that bank either.
A compliance check ends with a binary finding: the requirement is met or it is not. A maturity assessment asks a different question. At what level of control does each practice sit, and what specific action moves it up a level. Safeguarding performed but not reconciled, an agent register maintained but not checked, an audit trail that exists but is incomplete: these are the situations a score by theme reveals, and that a simple compliance opinion flattens.
In Datamensio, the framework is ready to use. You can adapt it to your business model: the AI adjusts the themes, questions and levels following the CMMI method, or builds a variant from your internal procedures, partnership agreements and control reports.
Reference standard: CEMAC Regulation No. 04/18/CEMAC/UMAC/COBAC on payment services in CEMAC
The themes assessed
Licensing and scope of activity
Payment services actually carried out, alignment with the licence held, minimum capital and its permanence, notification of changes to the supervisor, ancillary activities.
Governance and organisation
Composition and role of governing bodies, fitness and propriety of management, segregation of duties, internal control and compliance set-up, reporting to the board.
Safeguarding of customer funds
Safeguarding in a dedicated account, reconciliation between outstanding electronic money and guarantee funds, independent check of the position, prohibition on using the funds, treatment in case of default.
Customer relations and contractual disclosure
Framework contract and terms and conditions, prior disclosure of fees and timelines, pricing transparency, transaction statements, termination and closure of payment accounts.
Execution of payment transactions
Payer consent and authentication, execution and fund availability timelines, value dates, unauthorised or incorrectly executed transactions, refund and liability.
Distribution network and agents
Recording and approval of distributors and retail agents, contracts and the institution’s liability, training, on-site control of the network, activity caps and limits.
Anti-money laundering and customer due diligence
Identification and verification of identity, service levels based on the degree of customer knowledge, transaction monitoring, suspicious transaction reports, alignment with the CEMAC AML-CFT regulation.
Systems and transaction security
Authentication, protection of payment data, access rights management, logging and audit trail, security incident management and notification.
Business continuity and outsourcing
Continuity plan and testing, dependence on technical providers and banking partners, contractual clauses, reversibility, control of subcontractors.
Prudential reporting and traceability
Periodic returns submitted to COBAC and BEAC, activity and incident statistics, record keeping, response to supervisor requests, follow-up on recommendations.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment amount to a licence or a compliance certificate from COBAC?
No. Datamensio measures the maturity of your set-up and prepares the discussion with the supervisor. Licensing and compliance decisions rest exclusively with COBAC. The assessment gives you a documented record of gaps and the related action plan.
What is the difference between a compliance check and a maturity assessment?
A check verifies whether a requirement is present and ends with a binary finding. An assessment places each practice on a progressive scale and points to the action that moves it up a level. The two are complementary: the assessment prepares for the inspection, the check validates it.
How long does the evaluation take?
The short version can be completed in a single working session. The full version, run collaboratively with compliance, operations and payments teams, typically takes one to two weeks, with most of the time spent gathering evidence from the teams.
Can the framework be adapted to our business model?
Yes. An electronic money institution backed by a telecom operator, a distributing bank and a standalone payment institution do not share the same pressure points. You can edit the questions, levels and themes, or the AI can build a variant from your procedures and partnership agreements.
Can several CEMAC subsidiaries be compared?
Yes. The same framework applies to each business unit and the benchmark compares scores by theme, as well as each entity’s progress over time. A cross-entity roadmap consolidates subsidiary action plans and groups common actions together.
How does this framework relate to the AML-CFT set-up and internal control?
The requirements partly overlap on customer due diligence, transaction monitoring and permanent control. A solid payment services assessment forms a reusable base. The cross-entity roadmap allows frameworks to be cross-referenced without duplicating actions.
What does the assessment actually produce?
A score by theme, a target, and the gap between the two that generates the action plan. The AI then groups these actions into a prioritised roadmap, and the service catalogue offers a costed solution with a timeframe and a score impact against each item.
Where is the data hosted?
In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.



