EDIH, EEN, Interreg: the platform for European programmes.Find out more

Outsourcing Maturity · COBAC Subcontracting Regulation

Your outsourcing mapped, assessed against the COBAC regulation and turned into an action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Outsourcing Maturity · COBAC Subcontracting Regulation

Outsourcing policy and governanceN1 → N5
Register of outsourced activitiesN1 → N5
Selection and due diligenceN1 → N5
Notification and relations with the supervisorN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Outsourcing policy and governance6484
Register of outsourced activities5379
Selection and due diligence6182
Notification and relations with the supervisor3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Enterprise Europe Network
  • Chambre de commerce et d'industrie
  • EDIH Network
  • Caisse des Dépôts
  • Interreg Danube Region
  • ODA

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One COBAC Regulation on the outsourcing of activities by supervised institutions assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, one level, the level above, and the action linking the two, that turns a finding into a trajectory.

Do you have a register of outsourced activities identifying which ones are essential?

  1. N1

    No register. Service contracts are held by the business lines, with no consolidated view.

  2. N2

    A list exists, maintained by a single department. It is incomplete and the qualification of essential activities is not formalised.

  3. N3

    The register covers all services, with a written criterion for qualifying essential activities. It is updated with each new contract.

  4. N4

    The register is periodically reconciled with vendor accounts, mentions second-tier subcontractors and data location, and feeds into the risk map.

  5. N5

    The register underpins the governing body’s decisions: concentration by provider, dependency, insourcing decisions, with a documented history of revisions.

Action to move from L2 to L3

Formalise in an internal memo the criteria for qualifying an essential activity, list contracts from vendor payments over the last twelve months, then present the consolidated register to the risk committee next quarter.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon COBAC.

What this framework covers

The COBAC regulation on subcontracting sets out a simple principle and a series of demanding obligations. A supervised institution may entrust an activity, including an essential or important one, to a third party, but it retains full responsibility for it towards the supervisor and its customers. In practice, this requires an internal definition of what is essential, prior notification to the Banking Commission for these activities, a written contract covering service levels, confidentiality, data access and supervisor access, and a control mechanism over the provider throughout the relationship.

The difficulty is rarely the text itself, it is keeping the arrangement running over time. Many institutions discover they have no complete register of their outsourcing: IT contracts signed by the information systems department, cash-in-transit providers, ATM management, call centres, and services rendered by the parent company do not appear in the same inventory. Who decides that an activity is essential? Does the contract provide for COBAC access to the provider’s premises and data? What happens if that provider stops the service next week?

Two confusions recur often. The first is treating intragroup outsourcing as an internal matter: a service delivered from a regional group’s head office or from a service centre outside the CEMAC zone remains outsourcing, with additional questions around data location and continuity. The second is confusing commercial vendor monitoring with prudential control of the provider: an annual contract review by procurement does not replace the assessment of the operational risk carried by that outsourcing, nor its integration into internal control and business continuity planning.

The maturity assessment answers a different question than a compliance audit. An audit concludes with a gap or a compliance finding against a given requirement. The assessment locates the practice on a progressive scale: does the register exist, is it exhaustive, is it reconciled with vendor accounts, is it reviewed and used for decisions. It then points to the precise action that moves the practice up a level, with a cost and a timeframe. The assessment prepares for on-site inspections and discussions with the supervisor, it does not deliver any certificate.

In Datamensio, the framework is ready to use and remains yours. You adjust the themes, the questions and the level wording: the AI rephrases according to the CMMI method, and can build a version tailored to your outsourcing policy, your internal control charter or your contract templates from your own documents.

Reference standard: COBAC Regulation on the outsourcing of activities by supervised institutions

The themes assessed

  • Outsourcing policy and governance

    Existence of a policy approved by the governing body, criteria for qualifying essential activities, roles and delegations, decision thresholds, reporting to executive management.

  • Register of outsourced activities

    Consolidated inventory of services, identification of the provider and its subcontractors, criticality, location of processing and data, reconciliation with vendor accounts.

  • Selection and due diligence

    Assessment of the provider’s technical and financial capacity, verification of its reputation and standing, prior risk analysis, formalisation of the decision.

  • Notification and relations with the supervisor

    Identification of cases subject to notification to the Banking Commission, content and timing of filings, traceability of exchanges, notification in case of significant change.

  • Contractual framework

    Written contract, service levels and indicators, confidentiality and banking secrecy, data ownership and access, the institution’s audit rights and supervisor access, control over chain subcontracting.

  • Monitoring and oversight of the service

    Appointment of a monitoring officer, periodic service level reviews, incidents and penalties, provider reports, integration into the permanent and periodic control plan.

  • Operational risk and concentration

    Integration of outsourcing into the risk map, measurement of dependency and concentration on a single provider, risks linked to intragroup and cross-border services.

  • Business continuity and reversibility

    Provider and institution continuity plans, joint testing, exit strategy, reversibility clauses and timeframes, identified fallback solutions.

  • Data protection and system security

    Security of access and exchanges, hosting and location, retention and return of data at contract end, alignment with the information systems security framework.

  • Reporting and continuous improvement

    Periodic reporting to the governing body, portfolio steering indicators for outsourcing, lessons learned from incidents, policy review.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment constitute certification of compliance with the COBAC regulation?

No. Datamensio measures the maturity of practices and produces an action plan. There is no certification against this regulation: verification falls to the Banking Commission, internal control and external audit. The assessment helps prepare for these discussions with documented evidence.

What is the difference between this assessment and a compliance audit?

An audit concludes with a gap or a compliance finding against a requirement. The assessment locates each practice on a five-level scale and points to the action that moves it up a notch. The two complement each other: the assessment prepares and prioritises, the audit verifies.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with permanent control, the information systems department, procurement and the business lines, typically takes one to two weeks. Most of the time goes into retrieving contracts and monitoring evidence.

Does the framework cover intragroup and non-CEMAC services?

Yes. The questions distinguish services rendered by a group entity, particularly from a head office or service centre outside CEMAC, and cover data location, supervisor access and continuity. This is a frequent focus area during inspections.

Can the framework be adapted to our organisation?

Yes. You can modify the questions, levels and themes, or add your own. The AI rephrases the levels according to the CMMI method and can generate a version based on your outsourcing policy and contract templates. The framework is yours.

How do we compare our subsidiaries with each other?

The same framework is rolled out across several business units, with a score per theme and a comparison between entities and against previous campaigns. A cross-entity roadmap consolidates subsidiaries’ action plans and avoids addressing the same provider twice.

How do we go from the score to the action plan?

You set a target per theme. The gap between the score and the target generates actions, which the AI groups into a prioritised roadmap. The service catalogue proposes a solution for each action, with its cost, timeframe and expected effect on the score.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon COBAC.