CiberLATAMbywhalemate

Argentina’s BCRA orders fraud scores for wallets

BCRA orders banks and wallets to add risk scores and anti-fraud controls for instant transfers, with rollout deadlines of 60, 90 and 120 days.

Whalemate Labs · AI-assisted researchPublished:4 min read

Argentina’s central bank has issued a mandatory regime to prevent fraud in electronic transfers. Communication A 8473 applies to banks, virtual wallets, payment service providers and instant transfer scheme administrators, with user risk scores and staggered compliance deadlines.

The Central Bank of Argentina has issued a mandatory regime to prevent and mitigate fraud in electronic funds transfers. Communication A 8473, published in September 2026, applies across Argentina’s retail payments system to financial institutions, payment service providers that offer payment accounts, and administrators of instant transfer schemes.

What does Communication A 8473 require?

The rule requires additional fraud prevention measures, including risk evaluation mechanisms for retail payment operations. According to specialized coverage, that translates into a risk score tied to each user for instant transfers, used both when accounts are opened and when transactions are monitored and customer rosters are reviewed periodically.

The official text published in the Official Gazette also confirms that the annex containing the anti-fraud provisions is not released in full in the public notice. Technical operational details, including scoring parameters, risk models and information exchange formats, must be consulted in the BCRA’s Prebisch Library or in the Legal and Regulatory Framework section of the institution’s website.

The communication itself groups obligations under sections 5.1, 5.2, 5.3 and 7.1.7, which shows the regime is not limited to user scoring. It also includes documentation requirements, information sharing between scheme administrators and participants, and implementation conditions that affect compliance timelines.

Who must comply, and by when?

The regime covers banks, virtual wallets, payment service providers and administrators of instant transfer schemes, with different implementation schedules for each actor. Administrators have 120 calendar days from publication to develop and deploy the infrastructure, while financial institutions have 60 days and PSPs have 90 days to add the risk score for onboarding, roster review and monitoring.

Local coverage notes that, with this communication, banks and wallets no longer set anti-fraud controls on their own and must follow a uniform set of mandatory measures defined by the BCRA. In the same vein, regional outlets highlighted the operational impact on fintech companies that work with payment accounts and will need to adjust their risk engines and monitoring processes.

How does this connect with other digital payments requirements?

The regulatory tightening is not limited to Argentina. In Mexico, an international law firm described a draft Digital Payments Law that would recognize the Digital CURP and the Citizen Digital File for contracting financial services, and would give Banco de México and the CNBV new powers over the acceptance of payment methods and the design of financial apps.

That draft would also authorize Banxico and the CNBV to issue joint general rules requiring digital payments with QR codes at point-of-sale terminals. It would further allow the Ministry of Finance, with input from both agencies, to designate economic sectors where digital payment would be the only accepted method. Mexican media reports add that Banxico and the CNBV are pushing changes to strengthen payments interoperability, although they have not yet detailed the specific regulation.

Meanwhile, legal analyses in Argentina note that, in addition to the mandatory monthly reporting of intra-entity instant transfers created by Communication A 8427, cybersecurity compliance also covers service continuity, incident response, auditability, access controls, encryption, authentication, supplier risk management, event logging and monitoring.

Sources

View all