Argentina and Mexico tighten bank controls
Argentina and Mexico are tightening cybersecurity, biometrics and data governance rules for banks and fintechs, with stricter deadlines
Argentina’s central bank issued Communication A 8438/2026 and relaunched, with the UIF, a guide on "Client of the Client," while in Mexico the CNBV and Hacienda expanded biometric validation in banks and the Supreme Court strengthened CONDUSEF’s sanctioning power over financial institutions.
The Central Bank of the Argentine Republic issued Communication A 8438/2026, updating the National Payments System and the electronic clearing of checks and other instruments, while also relaunching a guide with the UIF to align anti-money laundering practices. In Mexico, the CNBV and the Ministry of Finance expanded biometric validation in banks, and the Supreme Court upheld CONDUSEF’s sanctioning powers over financial institutions.
What changed in Argentina with Communication A 8438/2026?
Communication A 8438/2026, published in Official Gazette No. 35,970 and recorded in the national regulatory portal, changes the rules of the National Payments System for the electronic processing of checks and other compensable instruments, adding new operational and compliance requirements for financial entities and certain technology providers.
The consolidated text available on the official portal says the rule is part of the BCRA’s series of communications on financial entities and sets specific obligations for the electronic processing of checks and other compensable instruments, including information requirements and participant responsibilities. The official reference also confirms that the rule has validity registered in the national regulatory system.
How does it connect with the UIF?
The BCRA and the Financial Information Unit relaunched the UIF-BCRA Working Group in 2026 and presented a Guide to Interpretation and Application of the concept "Client of the Client" for financial entities under joint supervision.
According to the BCRA’s official statement, the guide is intended to align anti-money laundering and compliance best practices, with emphasis on periodic monitoring, detection and timely handling of unusual activity. The goal is to reinforce expectations around transaction monitoring schemes at supervised entities.
What does the new regulatory wave require in Mexico?
In Mexico, a resolution published in 2026 amended general provisions applicable to credit institutions to add facial biometrics as an official complementary mechanism to fingerprint authentication, while also allowing banks to build their own biometric databases under strict security and information governance requirements.
According to Periodismo y Ambiente, the rule gives banks 90 business days to adapt identity verification processes and requires encryption, segregation in dedicated infrastructure, access controls, secure deletion of biometric databases and periodic cybersecurity audits. AMITI adds that mandatory biometric validation is concentrated in level 3 and level 4 accounts, and that before adding a record, banks must verify it against an authorized official source such as INE, the Ministry of Foreign Affairs or another enabled federal agency. The same source says biometric databases must be kept up to date and protected by stronger security controls.
An analysis by FIDO Alliance and Biometric Update adds that the July 2026 amendments require liveness detection within the 90-day period and that facial verification reach at least a 90% match against government identity records.
What cyber controls does the CNBV require from IFPEs and IFCs?
The CUITF provisions, according to NextGuard Insurance, require TLS 1.2 or higher for data in transit, AES-256 for personal and financial data at rest, strict segregation between production, development and testing environments, and a 24/7 in-house or outsourced SOC with SIEM and event correlation.
The same source adds that the CNBV also requires material incident reporting within specific timeframes, formal management of critical third parties and insurance coverage to protect customer funds and civil liability. Taken together, the framework ties operating approval for fintech institutions to full compliance with those controls.
What changed in sanctions and transparency for banks and financial firms in Mexico?
In 2026, the Supreme Court of Justice of the Nation upheld broad CONDUSEF powers to sanction financial institutions that hide relevant information from their customers and to oversee compliance with transparency and registration obligations.
The ruling, according to El Cronista México, also confirmed the validity of rules allowing penalties for bad debt collection practices, even in cases where institutions fail to register contracts or properly report their products. That expanded the scope of sanctions beyond the mere concealment of information from customers.
How does virtual asset regulation fit into this picture?
A legal and technical analysis of Mexico’s Fintech Law and Banxico Circular 4/2019 says that authorized virtual asset operations for credit institutions and financial technology firms must be limited to internal operations, precisely described in processes, personnel and responsibilities, and justified as not amounting to a direct offer to the public or shifting risk to customers.
The same source says Banxico must consider how the public uses virtual assets as a medium of exchange, store of value and unit of account when defining which ones financial technology institutions may use. That sets the boundaries for which cryptoassets can be operated under supervision.
Sources
- Ley Fintech y criptoactivos en la empresa mexicana: CNBV, Banxico y SATsoulbit.io· Soulbit
- La nueva regulación biométrica en México: más allá del cumplimientoperiodismoyambiente.com.mx· Periodismo y Ambiente
- Comunicación A 8438 / 2026 - ENTIDADES FINANCIERASargentina.gob.ar· Gobierno de la República Argentina
- ARGENTINA: Fraudes bancarios: cambian las medidas de seguridad para los préstamos pre aprobadosyanapti.com· Yanapti SRL
- Acciones conjuntas del BCRA y la UIF para alinear buenas prácticasbcra.gob.ar· Banco Central de la República Argentina
- La norma que iguala condiciones para bancos y fintechscronista.com· El Cronista
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – Comunicación A 8438/2026boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- La reforma de la CNBV a la Circular Única de Bancos amplía la validación biométrica en Méxicoamiti.org.mx· AMITIUnverified URL
- Ley Fintech México: Requisitos Cyber para Autorización ...nextguardinsurance.com· NextGuard Insurance
- Mexico's new banking rules signal a new era for biometric identity verificationfidoalliance.org· FIDO Alliance / Biometric Update
- Golpe a los bancos: la Suprema Corte le otorgó poder absoluto a la CONDUSEF para penalizar a financieras que oculten información de sus clientescronista.com· El Cronista México
- ley fintech mexico — Insurance Blog | NextGuard Insurance Florida & New York Coverage Guides — NextGuard Insurancenextguardinsurance.com· NextGuard Insurance



