CiberLATAMbywhalemate

Argentina's BCRA sets fraud score for transfers

Communication A 8473 requires banks, PSPCPs and payment administrators to add a fraud risk score for transfers.

Whalemate Labs · AI-assisted researchPublished:3 min read

Argentina’s Central Bank approved Communication "A" 8473/2026, published in the Official Gazette on Sept. 10, and set new anti-fraud rules for financial institutions, electronic transfer payment scheme administrators and payment service providers that offer payment accounts. The rule sets different deadlines to adapt infrastructure, add the indicator to onboarding and roster review processes, and integrate it into transaction monitoring.

Communication "A" 8473/2026 from Argentina’s Central Bank, published in the Official Gazette on Sept. 10, 2026, introduced new measures to reduce fraud in electronic funds transfers. The rule applies to financial institutions, payment scheme administrators and payment service providers that offer payment accounts, with different deadlines depending on the obligation involved.

What changes for payment scheme administrators?

Payment scheme administrators have 120 days from publication to adapt their infrastructure to the new fraud risk scoring system. According to specialized coverage, that first operational milestone pushes initial implementation to January 2027.

The system will be fed with information the Central Bank will send to those administrators each month. iProUP said the score will cross public data, or data derived from public information, with nonpublic data in minimal or aggregated form, along with the Fraud Prevention Central Registry and the administrators’ own transaction records, to build a profile for each person and assign a risk level linked to a CUIL or CUIT.

How will it apply to banks and PSPCPs?

Banks and PSPCPs have 60 days to incorporate the indicator into customer onboarding and roster review processes, and 90 days to integrate it into daily transaction monitoring, counted from receipt of the technical documentation from the payment scheme administrators. The Central Bank will also share the score at no cost for use in onboarding, monitoring and periodic review.

The Official Gazette and media reports add one important limit, decisions cannot be based solely on the fraud risk score. The assessment must be complementary, and the deadlines for financial institutions and PSPCPs are counted from the official publication and, where applicable, from delivery of the technical documentation.

What other regulatory signals accompanied this measure?

The updated consolidated text of the BCRA’s Foreign Exchange and Currency regime as of Sept. 14, 2026 shows that the latest communication added to the compendium is "A" 8481, reflecting the steady stream of regulatory changes in currency matters. The Official Gazette also includes Communication "A" 8479/2026, dated Sept. 11, although its heading does not provide specific cybersecurity details.

In parallel, an official Argentina.gob.ar notice on payment methods in the capital markets clarified that bank transfer will be the only allowed method for receiving and delivering funds to and from clients in that area. In addition, the CERT.ar repository continues to publish guidance and best practices that serve as a technical reference for the financial sector and complement the BCRA’s information security requirements.

Sources

View all