Banking outsourcing in the WAMU: the step projects discover too late
Between commercial agreement and go-live sits a regulatory step. Knowing it reshapes a project's timeline; ignoring it pushes that timeline back by months.
The obligation
Circular no. 04-2017/CB/C of the WAMU Banking Commission, on risk management in credit institutions and financial companies, provides that any draft outsourcing contract must be submitted for prior review to the General Secretariat of the Banking Commission before it is implemented.
It further states that outsourcing does not release the institution from its regulatory obligations, nor from its responsibility towards its customers, its statutory auditors and the supervisory authorities.
In other words: the bank remains accountable for everything, including what it hands over.
Why the step takes projects by surprise
A vendor arriving with a standard contract drafted for another legal framework discovers the obligation at the worst possible moment: after commercial agreement, before deployment, when the timeline has already been announced internally.
The contract then has to be reworked to satisfy a review that examines specific points: audit rights, data location, subcontracting chain, continuity plan, reversibility, service levels. Each of those points can require a technical change, not merely a contractual one.
The resulting delay is not administrative. It is structural.
What a pre-assembled file changes
A vendor arriving with the outsourcing file already assembled moves the step upstream. The file covers the provider's identity, the exact scope of what is outsourced, the responsibility matrix, data location, the subcontracting chain, security arrangements, the continuity plan, audit rights, the reversibility plan, service levels and the incident notification procedure.
The responsibility matrix deserves particular attention: it is what establishes unambiguously that the credit decision remains the bank's, and that the provider supplies a decision-support tool. That distinction is structural, legally and technically.
The reversibility plan is the most scrutinised piece and the most frequently absent. It describes how the institution retrieves its data and continues operating if the relationship ends: formats, timescales, assistance. A credible reversibility plan presupposes an architecture designed to be left.
A constraint that sorts vendors
The security requirements applying to WAMU institutions are precise: a security policy approved by the governing body, a named security officer, an IT risk map, continuity plans tested in real conditions, incident notification.
A vendor whose solution can only run on one particular infrastructure has nothing to offer a security committee that refuses that infrastructure. Hosting, often treated as an operational detail, in fact decides access to an entire class of customers.
The answer is not commercial but architectural: the same codebase must be deployable at the vendor, in a dedicated instance, or inside the institution's own infrastructure, through configuration alone.
Sources
- WAMU Banking Commission — Circular no. 04-2017/CB/C on risk management in credit institutions and financial companies of the WAMU.
- Republic of Senegal — Law no. 2008-12 of 25 January 2008 on the protection of personal data.