For a financial institution, the question is not “is AI useful?” but “what happens to my data?”. Banking data protection is a matter of trust towards your clients, and of compliance towards your regulators. A federated architecture answers it by design.
What stays with you
- Your clients’ and their managers’ identity data.
- Statements, transaction flows and repayment histories.
- Credit files and your committees’ decisions.
This data is used to train the model locally, inside your environment. It is never copied to SCORE360 or to any other institution in the network.
With the BCEAO’s PI-SPI, a new category of data comes in: SMEs’ instant payment flows, collections via interoperable QR code and payments. Gathered with the business’s consent, this data is valuable for assessing its real activity. It follows the same rule: it is used inside your environment, never transferred.
What travels, and how
Only model parameters travel: series of numbers describing what the model has learned, which cannot be used to rebuild a file. They are encrypted in transit (TLS 1.3) and combined through secure aggregation: the engine works on the sum of all contributions, not on the details of any client.
Verifiable governance
Trust is not declared, it is verified. That is why every operation is logged and can be audited, and access to sensitive functions is governed by roles (RBAC). The final decision remains subject to human validation inside your institution.
Banking data protection: a regulatory framework that is respected
SCORE360 operates in compliance with BCEAO regulations and under ARTCI oversight for personal data protection, in line with Ivorian Law n° 2013-450. The partner institution remains responsible for obtaining its clients’ consent, as required by the framework governing credit information bureaux in the UMOA. Processed data stays located within the UEMOA region.
Why it is an advantage, not a constraint
Traditional approaches force a choice: either you centralise data to get a better model and accept the risk, or you keep it and settle for a limited model. Federated learning removes that choice. You protect your clients and benefit from a score fed by the whole network. In African economies where trust drives the adoption of financial services, this is a prerequisite for extending credit to SMEs.
FAQ
Does Federated Learning respect banking secrecy?
Yes, by design. Identity data, statements, transaction flows and credit files stay inside the institution’s environment. Only encrypted model parameters travel, and they cannot be used to rebuild a client file. No raw data ever leaves the perimeter of the bank or microfinance institution.
What data is sent to SCORE360?
Only model parameters: series of numbers describing what the model has learned. They are encrypted in transit with TLS 1.3 and combined through secure aggregation, so the engine works on the sum of all contributions and never on the details of an individual client.
Which regulatory framework applies to the data processed?
SCORE360 operates in compliance with BCEAO regulations and under ARTCI oversight for personal data protection, in line with Ivorian Law n° 2013-450. Every operation is logged and auditable, access to sensitive functions is governed by roles (RBAC), and processed data stays located within the UEMOA region.
Who collects client consent?
The partner institution remains responsible for obtaining its clients’ consent, as required by the framework governing credit information bureaux in the UMOA. SMEs’ PI-SPI flows are used with the business’s consent and are processed inside the institution’s own environment, never transferred to SCORE360 or other institutions.
