CiberLATAMbywhalemate

Argentina's BCRA orders transfer fraud controls

Argentina’s central bank ordered banks and payment wallets to tighten anti-fraud controls and released a risk profiling tool using public data.

Whalemate Labs · AI-assisted researchPublished:4 min read

Argentina’s Central Bank launched a mandatory regime to prevent and reduce fraud in electronic transfers, covering banks, payment service providers with payment accounts, and administrators of instant transfer schemes. The measure, formalized in Communication "A" 8473/2026, is paired with a risk profiling tool to flag accounts linked to fraud or illegal gambling.

Argentina’s Central Bank has launched Communication "A" 8473/2026, a mandatory regime to prevent and reduce fraud in electronic transfers. The rule covers financial institutions, payment service providers that offer payment accounts, and administrators of instant transfer schemes. It sets different compliance deadlines and relies on a risk profiling tool for banks and digital wallets, with a focus on accounts tied to illegal gambling.

What does Communication "A" 8473/2026 require?

The communication requires payment system operators to adopt anti-fraud measures and work with new technical documentation provided by administrators of instant transfer schemes. According to El Destape, the text published in the Official Gazette refers to a technical annex that was not included in the notice, so several obligations cannot be reconstructed precisely from the official version alone.

That missing annex leaves a degree of regulatory uncertainty until institutions receive the technical documentation. Even so, the framework is already mandatory and is designed to strengthen controls over electronic transfers at banks and wallets.

What are the compliance deadlines?

The deadlines depend on the type of operator and the technical documentation they receive. Administrators of instant transfer schemes have 120 calendar days from publication to comply with the new rules, while financial institutions and payment service providers have 60 and 90 days, respectively, to implement different sections once they receive that documentation.

The staggered timeline shows that the regulator split implementation into phases. In practice, that forces banks and fintech firms to adjust internal processes as operational details arrive, instead of working from a single general deadline.

Affected actor Deadline Condition Source
Administrators of instant transfer schemes 120 calendar days From publication El Destape, BCRA
Financial institutions 60 days Once technical documentation is received El Destape, BCRA
Payment service providers 90 days Once technical documentation is received El Destape, BCRA

How does the BCRA's new tool work?

The tool lets banks and digital wallets access public information to build customized risk profiles and identify accounts linked to fraud or illegal gambling. The Central Bank provides it at no cost to financial institutions and payment service providers that offer payment accounts.

El Destape and Yogonet Latinoamérica both said the scheme is part of a broader anti-fraud strategy for electronic payments. Their coverage said expanded use of public data is meant to strengthen internal transaction analysis and monitoring tools, with early detection of suspicious activity.

Rosario Finanzas also reported that the new system was presented as a way to tighten control over illegal gambling transactions, increasing oversight and traceability of payments tied to illicit activity.

What do recent court rulings show?

Recent rulings in Argentina show that courts are looking at both technical security and how digital channels handle incidents and identity management. In a case covered by Infobae, a forensic review concluded that the bank’s electronic banking system met the technical standards required by the BCRA and showed no security failures during the period under review.

Even so, the court ordered the money returned and awarded moral damages to the victim. The ruling voided 17 transfers made within minutes for 176,900 pesos, according to Infobae, and held the bank responsible for customer service and how it handled the fraud complaint.

Noticias NQN reported another case in Cinco Saltos, where a court voided an unsolicited digital loan and ordered the customer’s record removed from the BCRA’s Central Debtors Registry. That precedent suggests judges are also weighing how institutions apply digital onboarding and identity verification processes in remote transactions.

The trend continued with the conviction of ICBC reported by 0264 Noticias, which included the return of funds and a fine equal to 65 total basic baskets, plus nearly 12 million pesos. That case was presented as a sign of severe financial liability for security failures or incident handling in cyberattacks on electronic banking.

Sources

View all