AfriScore Trust

Compliance

How AfriScore aligns with OHADA, CEMAC, and GDPR-inspired data protection frameworks.

AfriScore operates in jurisdictions where financial regulation, data protection, and cross-border data flow are governed by overlapping regional and national frameworks. This page documents how we align with each of them.

We are not yet a certified entity under any of the frameworks below. This page documents the alignment of our architecture, practices, and documentation with each framework — not a certification status. Certifications are targeted for the roadmap described below.

OHADA Uniform Act

The Organization for the Harmonization of Business Law in Africa (OHADA) provides a common legal framework for business operations across 17 member states, including Cameroon.

AfriScore aligns with OHADA requirements in the following ways:

  • Data handling: All borrower data is handled in accordance with the OHADA Uniform Act on data processing, and the model's SHAP-based explainability ensures decisions can be audited.
  • Audit trail: Every credit decision is logged with timestamp, input vector, and feature contributions, in a format suitable for regulatory audit.
  • Contractual frameworks: Pilot and commercial agreements are structured to comply with OHADA contract law.
  • Corporate structure: Our HoldCo-subsidiary structure is designed with OHADA compliance as a first principle.

CEMAC / BEAC

The Central African Economic and Monetary Community (CEMAC) and its central bank, BEAC, impose specific requirements on financial institutions operating in the region — particularly around cross-border data flow and foreign exchange controls.

AfriScore aligns with CEMAC/BEAC requirements in the following ways:

  • Data residency: On-premise deployment ensures borrower data never leaves the institution's jurisdiction under BEAC rules.
  • Foreign exchange: Our planned AfriScore HoldCo structure is designed to route foreign investment through a non-CEMAC holding entity, in compliance with BEAC foreign exchange controls.
  • Reporting: Where the institution is subject to BEAC reporting obligations, AfriScore's audit logs are structured to support those reports.

GDPR-inspired data protection

Many African jurisdictions have adopted data protection frameworks influenced by the EU General Data Protection Regulation (GDPR). AfriScore aligns with GDPR principles even where not strictly required.

  • Right to explanation: Every credit decision includes a SHAP-based explanation in human-readable form.
  • Data minimization: We collect only the data required to produce a credit decision.
  • Purpose limitation: Data is used only for credit assessment and model calibration.
  • Retention: Borrower data is retained only as long as operationally necessary.
  • Deletion: Data is deleted upon request or at the end of the retention period.
  • Breach notification: Affected institutions are notified within 72 hours of a confirmed security incident.

Regional and national frameworks

AfriScore operates across jurisdictions with distinct data protection regimes. Our alignment by country:

  • Cameroon — Aligned with Law No. 2010/012 on Cybersecurity and Cybercriminality, and Law No. 2019/020 on Data Protection.
  • Kenya — Aligned with the Data Protection Act, 2019, which was influenced by GDPR.
  • Nigeria — Aligned with the Nigeria Data Protection Regulation (NDPR) and the new Nigeria Data Protection Act.
  • Other CEMAC/ECOWAS jurisdictions — Aligned with relevant national frameworks where AfriScore operates.

Certifications on the roadmap

AfriScore is an early-stage company. Certification timelines reflect that reality.

Targeted after first paying CEMAC contract

  • SOC 2 Type II readiness
  • ISO 27001 readiness

Targeted after first institutional enterprise customer

  • Full SOC 2 Type II certification
  • Third-party penetration testing (annual)

Certifications are not yet in place. Any institution requiring SOC 2 or ISO 27001 certificates today should be aware that AfriScore has not yet completed those audits. We are transparent about this and will update this page as certifications are completed.

Regulatory engagement

AfriScore is committed to engaging proactively with regional regulators rather than avoiding them. Where regulatory sandboxes exist (such as those in Ghana, Kenya, and Rwanda), we will pursue formal participation as part of our expansion roadmap.

For inquiries about regulatory engagement, contact legal@afriscore.africa.

Documentation available on request

The following documents are available to institutional partners under NDA:

  • Data Processing Agreement (DPA) — available publicly here
  • Subprocessor list — available publicly here
  • Security controls documentation
  • Model card (documenting the scoring model, features, and known limitations)
  • Incident response playbook

To request any of these, contact security@afriscore.africa.