CiberLATAMbywhalemate

Argentina’s BCRA adds fraud management to risk rules

The BCRA added fraud risk management to its operational risk framework and ordered quarterly reports to the board.

Whalemate Labs · AI-assisted researchPublished:2 min read

Argentina’s central bank added Section 6.5, "Fraud Risk Management," to its "Guidelines for Risk Management in Financial Institutions" through Communication "A" 8471, published on Sept. 1, 2026. The rule covers internal and external fraud, requires anti-fraud policies, and sets quarterly board reporting.

Argentina’s central bank, the Banco Central de la República Argentina, added Section 6.5, "Fraud Risk Management," to its "Guidelines for Risk Management in Financial Institutions" through Communication "A" 8471, published in the Official Gazette on Sept. 1, 2026. The move brings internal and external fraud into the operational risk framework for financial institutions and reinforces its treatment as part of the system’s broader risk management process.

What does Communication A 8471 require?

Communication "A" 8471 requires financial institutions to define anti-fraud strategies, policies and practices, set their risk tolerance level, and designate a dedicated structure or a responsible person to manage the fraud function. It also brings internal and external fraud into the operational risk scheme, according to the BCRA’s published rule.

The requirement goes beyond general statements. The updated text aims to ensure that each institution has a concrete organization to manage that risk and that the function is formally assigned. At the same time, the BCRA also said it will strengthen controls to detect and prevent fraud and illegal activity in electronic payment systems, using public provisions to improve its transaction analysis and monitoring capabilities.

How does reporting to the board change?

The BCRA told banks to report on fraud management to the board at least quarterly, including metrics, relevant incidents, corrective measures and newly detected fraud methods. That makes supervision a documented, recurring part of risk governance.

The three-month reporting requirement is meant to provide traceability on what is happening inside each institution and how it responds to incidents or new variants. Coverage of the communication also said the full effective date for the new requirements would run until Sept. 1, 2027, with intermediate adaptation stages for financial institutions and other covered agents, although that timeline was attributed by the source and was not fully confirmed.

How does it compare with Mexico’s response?

In Mexico, the public response was communicational and preventive, without cyber-specific regulatory changes comparable to the BCRA’s during the same period. Banco de México reiterated on social media that it never asks for personal or financial information by phone calls, text messages, emails or social networks, and it shared material urging the public to verify the official source whenever it receives suspicious requests.

That institutional warning was amplified by Abril Mejía, an official linked to Banco de México, who repeated the message and reinforced the instruction to verify websites and communications at the official source. At the same time, commercial banks such as Banamex launched specific anti-digital-fraud campaigns in September 2026, warning about app downloads from suspicious links and clarifying that they do not ask users to install apps or download software through messages or calls. Condusef and the Mexican banking sector also circulated recommendations not to open unexpected links, not to share passwords, PINs or verification codes, and to prevent malware from being installed on mobile phones.

Sources

View all