GSMA Mobile Money Certification
Conditional standard · GSMA Mobile Money Certification (the Code of Conduct principles)
GSMA
International
Certification scheme since 2018
Independent assessment against the GSMA scheme
You operate a mobile money service
Curated, versioned & cross-mapped
The obligation, plainly.
The GSMA's Mobile Money Certification distils the industry's code of conduct into certifiable principles: safeguarding customer funds, AML/CFT capability, fraud prevention, data privacy, security, transparency and fair treatment, assessed independently and renewed.
Across African markets where mobile money is core financial infrastructure, the certification functions as the sector's trust mark, and its principles land on the same financial-crime, privacy and security controls the statutory regimes already demand.
Where programmes are tested.
Safeguarding funds
Customer money segregated, protected and reconciled, the scheme's first principle.
Financial-crime capability
AML/CFT and fraud prevention proportionate to the service's risk.
Privacy, security, fairness
Data protection, service security, transparency of fees and terms, and fair treatment, evidenced for assessment.
Curated once, evidenced continuously.
- The certification's principles are curated and cross-mapped onto the financial-crime, privacy and technical families, so a provider's statutory controls double as its certification evidence.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
GSMA Mobile Money Certification, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Is GSMA certification a legal requirement?
No, it is an industry scheme, but it carries market weight: partners, banks and some regulators treat it as the benchmark of a well-run mobile money service, and it shortens due diligence the way SOC 2 does for SaaS.
How does it interact with central-bank licensing?
It complements rather than replaces it: the licence sets the legal floor, the certification evidences operational quality above it. The overlap, safeguarding, AML, security, is deliberately mapped in the catalog so one control set serves both.
What does the assessment look like?
An independent assessor tests the provider against the scheme's criteria, principle by principle, on documented evidence. The certification renews on a cycle, which makes continuous evidence, not annual scrambles, the economical way to hold it.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.