EDIH, EEN, Interreg: the platform for European programmes.Find out more

Credit Risk Maturity · COBAC Credit Risk Regulation

Your credit risk management, measured against COBAC requirements and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Credit Risk Maturity · COBAC Credit Risk Regulation

Credit policy and governanceN1 → N5
Underwriting and originationN1 → N5
Counterparty rating and segmentationN1 → N5
Exposure monitoring and early detectionN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Credit policy and governance6484
Underwriting and origination5379
Counterparty rating and segmentation6182
Exposure monitoring and early detection3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One COBAC Regulation on the classification, provisioning and management of credit risk at CEMAC credit institutions assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, one level, the level above, and the action linking them, that turns a finding into a trajectory.

Is the downgrading of non-performing receivables triggered systematically and traceably?

  1. N1

    No defined mechanism. Downgrading results from ad hoc findings, usually as period-end approaches.

  2. N2

    Arrears rules are documented, but downgrading remains manual and some files escape treatment depending on the branch.

  3. N3

    The information system calculates arrears and proposes downgrading. Cases not downgraded require written justification.

  4. N4

    Downgrading is automatic, contagion to the client’s other exposures is applied, and exceptions are approved by a committee and logged.

  5. N5

    Rules are reviewed periodically against observed recovery rates, and the framework is checked by permanent control with documented reporting to the governing body.

Action to move from L2 to L3

Configure automatic calculation of arrears in the exposure management system, produce a monthly report of receivables eligible for downgrading, and require written justification from the head of lending for any file kept as performing, reviewed at the monthly risk committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon COBAC.

What this framework covers

COBAC’s credit risk regulation sets out what a CEMAC institution must demonstrate across the whole credit chain: a formalised origination policy approved by the governing body, a documented analysis of repayment capacity, a rating or scoring system for counterparties, ongoing monitoring of outstanding exposures, classification of receivables by quality and arrears, minimum provisioning tied to each category, defined treatment of collateral and its valuation, and regular reporting to the COBAC general secretariat. Large exposure diversification and coverage requirements complete this foundation.

In practice, the difficulty lies not in knowing the text but in actually mastering the chain. Is the downgrading of receivables triggered automatically by the information system, or does it depend on a commercial trade-off at quarter end? Is collateral deducted from the provisioning base revalued, with enforceable and locatable legal instruments? Do credit committees log deviations from the origination policy, and does anyone later measure the performance of those exception files? Most gaps found during inspections arise from these grey areas, not from ignorance of the rule.

One confusion comes up often: prudential classification required by COBAC versus IFRS 9 accounting provisioning applied by groups present in the zone. Both logics coexist, one based on arrears thresholds and floor rates, the other on expected losses and staged classification. Institutions that produce both sets of figures without a formal reconciliation expose themselves to discrepancies that are hard to explain during an inspection. The progressive strengthening of the CEMAC prudential framework, in line with Basel principles, heightens this need for consistency.

A compliance check ends with a yes or no: the provision is calculated, the return is filed. The maturity assessment asks a different question: what level of control does each link in the chain reach, and what concrete action moves it to the next level. An institution can be formally compliant on provisioning while still running origination without performance data. This gap between formal compliance and real control is what the assessment makes visible, theme by theme, entity by entity.

The framework is ready to use in Datamensio. It adapts to your organisation: the AI adjusts themes, rephrases questions to fit your customer segmentation and refines maturity levels, or builds a variant from your credit policy and internal procedures.

Reference standard: COBAC Regulation on the classification, provisioning and management of credit risk at CEMAC credit institutions

The themes assessed

  • Credit policy and governance

    Origination policy formalised and approved by the governing body, limits by counterparty, sector and product, role of credit committees, delegations and treatment of exceptions.

  • Underwriting and origination

    Analysis of repayment capacity, standard credit file, mandatory documents, separation between the commercial function and the lending function, traceability of decisions.

  • Counterparty rating and segmentation

    Internal scoring system, criteria and review frequency, segmentation of retail, corporate and sovereign counterparties, back-testing of ratings.

  • Exposure monitoring and early detection

    Monitoring of excesses and arrears, early warning indicators, periodic review of sensitive files, watch list and dedicated committee.

  • Classification of receivables

    Application of regulatory categories, arrears rules, contagion to the client’s other exposures, automation of downgrading and conditions for reclassification.

  • Provisioning

    Minimum rates by category, calculation basis, deduction of eligible collateral, provision approval, alignment with accounting provisioning and IFRS 9.

  • Collateral and security interests

    Eligibility and legal enforceability, safekeeping of instruments, initial valuation and revaluation, haircuts applied, effective enforceability.

  • Concentration and risk diversification

    Calculation of large exposures, compliance with individual and aggregate limits, exposures to related parties, monitoring of connected counterparty groups.

  • Collections and non-performing receivables

    Amicable and litigation procedures, implementation timelines, write-offs, monitoring of written-off receivables, recovery rates.

  • Prudential reporting and control

    Regulatory returns filed with COBAC, data quality and audit trail, second-line permanent control, follow-up on internal audit and supervisor recommendations.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment replace a COBAC mission?

No. On-site inspection is solely the supervisor’s remit. The assessment measures the maturity of your internal framework and identifies gaps before they are flagged. It prepares, it issues no certification.

What is the difference between a maturity assessment and a compliance check?

A compliance check ends with a binary finding on each requirement. The assessment places each practice on a five-level scale and states the action that moves it up a level. The two complement each other: the assessment builds the trajectory, the check validates the outcome.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with lending, collections, accounting and permanent control, spans one to two weeks, with most of the time spent gathering evidence.

Can the framework be adapted to our institution?

Yes. You can edit questions, levels and themes, or start from your own credit policy. The AI generates a variant from your internal procedures and aligns it with the CMMI method. The framework is yours.

Does it apply to microfinance institutions?

The framework is built on requirements applicable to credit institutions. For an MFI, the template is adapted to the CEMAC framework specific to that sector, with adjusted thresholds, segmentation and classification rules.

How can several subsidiaries in the zone be compared?

Each entity completes the same assessment. Scores by theme can be compared across business units and against previous exercises. A cross-entity roadmap consolidates action plans, and the AI groups recurring actions to avoid addressing the same gap ten times over.

How does the assessment reconcile prudential classification and IFRS 9?

The provisioning theme evaluates both logics and, above all, their reconciliation. An institution can be strong on expected loss calculation and weak on the traceability of the move to prudential categories. The assessment distinguishes between these two situations.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon COBAC.