MAP
Compliance centre

You are assessing a regulated supplier. Here is the framework, the funds and the responsibilities.

Before signing, your legal department, your compliance officer and your IT department ask the same questions. Who provides which services? Where are the funds? Who has access to which data? What happens in the event of an incident? How do you exit the programme? We have the solution: one page per question, one document per answer, each dated and versioned.

Your legal team’s questions

Seven questions, seven pages

Each answer fits in one paragraph and points to the page that establishes it. Every statement can be verified, in a document or in the way the service works.

Who provides which services, and under what framework?

MAP is the institutional brand of the project carried by Mon Ami Poto SAS, an electronic money institution authorised by the ACPR. Its authorisation carries number 17698 and the company has been on the Paris trade register since 7 February 2020. We publish what that authorisation covers, and who does what between the parties involved, each with its source and its date.

Regulatory framework
Where are the funds of the programme held?

Funds received in exchange for the electronic money issued are held separately. They are not mixed with the institution’s own operating assets. The flow they follow and the safeguarding adopted are described as they are established, without being likened to a deposit guarantee scheme.

Safeguarding of funds
What is checked before a payment goes through?

You choose who, when, how much, where and what for. 100% of operations are checked before execution, under AI supervision: an operation that falls outside the rules of the programme is blocked, not regularised afterwards.

Compliance
Who has access to which data?

Each role, funder, beneficiary, supplier and MAP, has defined read rights. The access table for your programme is settled at the first discussion, then written into the contract. No personal data is recorded on the blockchain.

Personal data
What happens in the event of an incident?

We describe the security organisation, access management and what makes an incident a declared incident. We also describe how the parties concerned are informed, and the limits of what we describe. No certification and no availability figure is shown without supporting evidence.

Security
How do we exit the programme?

What you take back, in which formats, what happens to balances in circulation: these points are settled before the service goes live. They are written into the contract, along with the outside services MAP depends on.

Continuity and exit
What already works today?

The Poto solidarity programme is the first use in production: earmarked contributions, accounts and cards for beneficiaries, payments at authorised suppliers. Each role sees what concerns it. The case study sets out what is covered, and what is not.

Case study

Entity and services

Who you are contracting with

The identity of the contracting party, as it can be published today.

Brand
MAP
Entity
Mon Ami Poto SAS
Status
Electronic money institution authorised by the ACPR
Product
An earmarkable digital euro, backed by the euro, one for one
Services covered
Set out on the Regulatory framework page, with the authorisation reference
Official reference
Published with the link to the register entry and the date of verification
First use in production
Poto, a solidarity programme

The proof and its limits

What the proof covers, and what it does not

Every payment in the programme is recorded on a tamper-proof blockchain that neither MAP nor the funder can alter. That proof has limits, and we write them down.

What is recorded and what you see

  • The amount of the payment, its date and time.
  • The supplier that received it.
  • The programme rule applied, and the reason for a refusal.
  • The link to the programme and to the budget concerned.

What the proof does not demonstrate

  • The contents of the basket: a supplier category does not say what was bought.
  • Delivery of the goods or services paid for.
  • The social impact of a programme, which is a separate evaluation.
  • The truthfulness of data entered by a third party.

Documentation

Documents available and documents on request

The catalogue states, for each document, its theme, its version and its mode of access. No document is listed if it cannot be provided in that mode.

Regulatory framework and activity covered Framework, entity, services covered
Flow and safeguarding of funds Funds received, mechanism adopted, redemption
Processing of personal data Categories, roles, access, retention
Security organisation Access, monitoring, incidents
Restricted
Contractual documents applicable to your role Provided after the first discussion
Restricted
Supplier assessment

Have your file reviewed

Tell us what your organisation expects. We will specify what is public, what is provided on request and what remains restricted. A MAP expert will get back to you, with no commitment.

Talk to an expert See what already works A MAP expert will get back to you, with no commitment.