By Gnagna Koné, specialist in public affairs and regulatory strategy
A year ago, seventeen years after the effective commercial launch of the first mobile financial services, the Central Bank of West African States (BCEAO) officially launched its interoperable instant payment infrastructure.
The Interoperable Instant Payment System (PI-SPI), a project that many in the industry thought was an obsolete “machine that would take another century before anyone cared”, materialized into a tangible public good that seeks to break down private proprietary silos by technically placing the rails of digital finance under regional monetary authority.
The BCEAO demonstrates that from a systemic perspective, payment and electronic money services are infrastructures by putting one in place itself.
It is not difficult to almost feel like the regulator is competing with financial services. However, it is doing something even more specific, it is arbitrating by updating the rules of the game in the middle of the match, reshuffling the cards in the process.
From arbitration to the risk of resetting even the existence of certain models or service segments as we have known them in recent decades.
The real infrastructure here, in my opinion, is not so much PI-SPI as the currency itself, what it becomes in its contours and features in the digital space.
Like the fundamental mathematical constant from which it takes its name, PI-SPI transforms monetary sovereignty into digital infrastructure: rails, with their own locomotives and new tracks, which break down the boundaries between issuers as well as payment services. It almost redraws the map of the same currency that heated debates have sought to change or abandon for years.
The supreme financial regulatory authority positions itself simultaneously as the designer, owner, and operator of PI-SPI, combining three roles of sectoral regulator, solution designer, and central manager. Even though this concentration is not unprecedented in the practice of central banks around the world, it nevertheless deserves to be perpetually questioned.
When we remember the very reason for the existence of mobile money in sub-Saharan Africa, financial inclusion that was supposed to provide access to financial services tailored to hundreds of millions of Africans who would never have been able to access formal financial and banking services on favorable terms, we still have questions.
In 2016, it was still difficult to explain the relevance of cashless societies in our predominantly informal ecosystems in their economic structure to a hyper-banked German citizen. The logic was expressed in a question as simple as poignant: what do people do in case of disasters?
Since then, I always remind myself that since ancient times, security as well as trust are first psychosocial before being legal or technological, whether offline or online. In the specific case of our ecosystems, they are the foundation of successful digital governance.
However, it is clear that in governance generally, it can be structurally problematic for a country, a regulator, or an entire political and economic regional bloc, if a majority of financial transactions pass through one or more financial services that do not belong to them and over which they technically have no control.
We are moving away from market shares, investments, shareholders, or penetration rates to enter into what is most embarrassing in sovereignty matters for African countries: ownership.
Regulatory as well as legal void is one thing, it is filled. What is much less obvious is the non-ownership which, at the stage where countries are, has almost become a systemic bug that we find with e-commerce, VTCs, and many other types of digital businesses.
Even Kenya, which is the ultimate African reference in terms of structural transformation in digital economy governance across all sectors, is now revising its strategies at many levels.
Just with the classification and qualification issues, there are many; and regulators see or make companies see green and red with digital companies across sub-Saharan Africa.
This brings us back to the authority of the Central Bank, which makes sense when we read its PI-SPI as a response to the issue of ownership of infrastructures in strategic sectors in general, which specifically for some of them also fall under economic sovereignty for many in the continent. Beyond even a reading of an infrastructure of systemic importance, I admit that it makes me think much more of sectoral sanctuarization.
However, while in principle, the existence of PI-SPI can be understood, in practice and in the way it is deployed and will be managed, there is cause for concern and many questions to be asked.
In the current digital economy, the stakes go far beyond simple technical or technological innovations. The slightest strategic mistake comes at a high price, the rigor of good governance is an absolute requirement.
Thus, regulators, in all their imperturbable and immovable machineries, are also forced to evolve. They must no longer just define the fields of regulation but almost directly move to active arbitration and (re)trace the path.
Services can indeed be private properties with or without shares belonging to the State or other public entities, national or regional authorities still have the power and the latitude to send everyone back to a new start.
When the BCEAO, the supreme financial regulatory authority, positions itself as the designer, owner, and operator of the PI-SPI platform, is there not a risk of sometimes ending up with regulations favoring its own infrastructure at the expense of private services or innovations that are sometimes more agile?
The legitimate question of who would sanction PI-SPI in case of a breach, often posed by Adama Wade, is more than legitimate and necessary to ask. If it is clear that the Court of Justice of the UEMOA or the Council of Ministers of the UMOA among others are the bodies to activate in this case, going to authorities to complain about an authority that in this specific case has not two but three functions: sectoral regulator, solution designer, and central manager… Can you imagine the scenario?
In terms of operational structure and co-management, we are still far from the examples of a non-profit external structure that manages the operations of its unified payment system in India (NPCI); or the public-private framework to co-manage the operating rules of its public instant payment system in Brazil (Pix Forum). It is clear that for these two examples, they are individual countries and that the BCEAO must reconcile stability while respecting the national sovereignties of eight countries and has already opted for execution speed.
Should we hope for a medium-term transition from the technical and commercial consultation framework of PI-SPI to another model of a full-fledged and outsourced structure that would further promote innovation and equity? Or should we expect a subsidiary of the technical infrastructure of PI-SPI, taking a model that already exists, such as GIM-UEMOA for example?
On this 30th of September 2026, the deadline for connecting banks and electronic money institutions to the Platform, I wish a happy birthday to our continental brother, Adama Wade, who is particularly passionate about the structural questions of PI-SPI.
We are eager to see what the BCEAO has in store for us in terms of inclusion, not to mention the accessibility of the aliases themselves (thirty-six alphanumeric characters!) when illiteracy is still at double-digit rates in all countries in the region (in 2025, illiteracy rates were 46.5% in Côte d’Ivoire, 63.5% in Mali, and 33.5% in Togo for individuals aged 15 and over).
When access itself is fragile, the question is no longer just about connectivity, but about remembering that whoever controls the rails also controls the breakdown. Once again, in the case of role overconcentration, there is a systemic issue of critical infrastructure.
Between 2019 and 2025, internet access restrictions (shutdowns, service blocks, and slowdowns) in the UEMOA increased by 500%, going from one affected country in 2019 to five countries per year since 2021, then to six from 2024, according to data from the Shutdown Tracker Optimization Project (STOP) of the #KeepItOn coalition, reports from Access Now, and ISOC Pulse data.
By standardizing compliance circuits in eight countries, overly rigid underlying architecture standards would push towards technical monoculture. In case of a flaw or breakdown, what do we do when the entire financial sector of the entire region is compromised?
In addition to the fragility of access, a fourth role that the regulator will now have to carry is that of guaranteeing the cybersecurity of its own infrastructure.
Between 2021 and 2025, the UEMOA region experienced a significant increase in cyberattacks targeting public infrastructure and services. Just for countries with national reporting mechanisms, the multiplication of incidents is considerable. In Benin, incidents of this nature increased by +269% between 2021 and 2022 alone according to the 2025 National Report on Cyber Vulnerabilities and Incidents in Benin published by the National Agency for Information Systems and Digital and the National Center for Digital Investigations.
In 2022, major attacks targeting public services in Mali compromised the data of 312,000 taxpayers at the Tax Directorate.
Even in 2025, this attack was still considered by INTERPOL as one of the major incidents against a tax administration in West Africa in its Cyber Threat Assessment Report in Africa, while in Senegal high-impact attacks against public institutions have successively made headlines in the same year (Ministry of the Interior, Tax Directorate, Treasury).
After the announcement last July that 40% of the adult population in the region is already connected, PI-SPI has crossed the chasm of public adoption in the UEMOA. It still has to cross the adoption but especially the appropriation by banks, EMIs, and microfinance institutions later on. But the battle for adoption will also be very important at the corporate level.
In this new architecture of judge and party of the BCEAO, would the e-CFA become the only true digital public monetary tool in the long run or the ultimate confirmation that ownership and sovereignty do not overlap as indisputably as assumed?
What about the promotion of PI-SPI? Would the Central Bank, which “strongly encourages partners to intensify their efforts to promote massive use by populations” in its guidelines, end up instructing partners to make in-app promotion communications, push SMS, and others, against the backdrop of an obligation to participate in the commercial success of the regional public good?
This is what can concretely result from the overconcentration of roles: the referee who is also a seller, instructing its partners (the same actors it regulates) to commercially promote its own product.
PI-SPI in its essence, its form as well as its implementation illustrates what contemporary research in public management qualifies as the platformization of sovereign power.
By becoming the architect and the exclusive operator of this infrastructure, the BCEAO grants itself algorithmic ecstasy.
One could write a book of sand with all the questions and interrogations that we would still have for the BCEAO in the years to come.
While waiting to see clearly in the long run, knowing that the Central Bank only has eyes for its currency (the apple of its eye), the infrastructure is currently the “problem” of partners and participants who will have to deal with it.
While financial transactions and regulatory and political negotiations continue to be in full swing, the regulator always holds the currency. One is almost tempted to say that we should now follow the currency and not just the money.
Finally, the question of ownership may simply be poorly posed. What matters is no longer so much who owns the infrastructure as who, by owning it, can still be judged, contradicted, sanctioned.