Argentina BCRA sets anti-fraud rules for banks
The BCRA sets staggered anti-fraud duties for banks and payment providers under Communication A 8471, with deadlines through 2027.
The Central Bank of Argentina published the rollout schedule for Communication A 8471, which adds a specific fraud risk management section and sets obligations for financial institutions and other payment service providers. The rule requires documented anti-fraud programs, dedicated functions, self-assessments and periodic reports, with stages running from 2026 into 2027.
The Central Bank of Argentina published the implementation schedule for its operational risk management framework, which now includes fraud prevention. Communication A 8471 requires financial institutions and other payment service providers to assign specific functions, document anti-fraud programs and meet stages that begin in 2026 and continue through 2027.
What does the BCRA's new regulation add?
Communication A 8471 adds a specific Fraud Risk Management section for the first time under the Guidelines for Risk Management in Financial Institutions. According to Bruchou & Funes de Rioja, it requires a documented Anti-Fraud Program covering coordination among compliance, legal, cybersecurity and AML/CFT teams, as well as detection through technology tools, whistleblower channels, incident response protocols, training and annual review.
The law firm also outlines a three-stage rollout. Stage 3, from June 1, 2027 through August 31, 2027, is reserved for self-assessing full compliance with the applicable requirements and submitting a final report by the entities.
Who does it apply to, and what must they do?
The official text published in the Official Gazette makes clear that, in addition to financial institutions, other registered and or BCRA-authorized payment service providers must assign a fraud risk management function starting January 1, 2027. They must also carry out a fraud risk self-assessment, develop a mitigation plan and align with the technology risk and information security rules in point 6.4.
Bruchou & Funes de Rioja adds that financial institutions will have to designate a Fraud Risk Management Function, either as a dedicated unit or within operational risk. That function must develop and implement the anti-fraud program, manage the full risk lifecycle, coordinate with outside bodies, maintain a centralized incident database and lead internal training.
What kind of oversight does the BCRA want?
Specialized commentary says the framework is meant to bring prevention and detection of illicit activity into operational risk management. It also indicates that institutions will have to report fraud indicators periodically to the Board of Directors, with a focus on digital fraud and institutional coordination against new criminal tactics.
How does this connect to digital wallets and Open Finance?
At the same time, the BCRA updated its technology risk management rules and added two-factor authentication for high-risk operations in digital wallets, along with fraud mitigation measures and customer consent management, according to coverage by El Cronista, Examedia and other specialized outlets.
The regulatory agenda also includes the Open Finance model. According to El Cronista, the decree promoting that scheme names the BCRA as the implementing authority responsible for defining the parameters, standards and requirements under which individuals may share their information, with express consent, with registered financial institutions. That opens an additional compliance front in privacy and information security.
What happens with loan collection and wallets?
Communication A 8406, which creates the Transfer Collection scheme as a replacement for scheduled DEBIN, also affects fraud management and user protection. According to Mario Vadillo, the credit issuer may only debit the installment from the same bank account where the loan was credited, limiting the possibility of surprise debits from other accounts or wallets.
Econoblog added that the new scheme allows loan collection with virtual wallets at banks, but limits its use to financial institutions and non-financial credit providers authorized by the BCRA. That adds information security and fraud mitigation requirements for those operating automatic debits on accounts and wallets.
Sources
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – establecimiento del marco de gestión del riesgo operacional incluyendo prevención del fraudeboletinoficial.gob.ar· Boletín Oficial de la República Argentina
- ¿Tu billetera virtual es segura? Expertos revelan lo que hay que saber para blindarse frente a robos y estafascronista.com· El Cronista / Infotechnology
- Nueva regulación del BCRA sobre gestión del riesgo de fraude – Comunicación A 8471bruchoufunes.com· Bruchou & Funes de Rioja
- ¿Tu billetera virtual es segura? Expertos revelan lo que hay detrás de las nuevas exigencias del BCRAexamedia.com.ar· ExamediaUnverified URL
- Comentario sobre la Comunicación A 8471 del BCRA y su impacto en la gestión del fraudex.com· Marcela Pallero (X)
- Comunicación A 8406: el límite del 30% de tu sueldo y el nuevo Cobro con Transferencia (CCT)mariovadillo.com.ar· Mario Vadillo
- Habilitaron cobro de créditos con billeteras virtuales en bancoseconoblog.com.ar· Econoblog
- Mercado Pago retiene tu saldo o cobra de más: cómo reclamarmariovadillo.com.ar· Mario Vadillo
- El modelo Open Finance se abre paso y tiene fecha de salida: ¿cuándo será unna realidad en la Argentina?cronista.com· El Cronista



