BCRA and CNBV change anti-fraud rules
Argentina added a formal fraud risk framework, and Mexico authorized SMS confirmation codes for some banking operations.
The BCRA issued Communication A 8471 and added internal and external fraud risk management to its operational risk framework, with a staged compliance plan through year-end. In Mexico, the CNBV changed rules to allow confirmation codes by SMS for certain digital banking operations, effective Sept. 2.
The Central Bank of the Argentine Republic published Communication A 8471 and added a formal framework for managing internal and external fraud risk within operational risk. The rule was published in the Official Gazette on September 1, 2026, with an official notice date of August 27, and it requires a documented anti-fraud program, cross-team coordination, reporting channels, incident protocols, training, and annual review.
What does the BCRA’s new communication require?
Communication A 8471 requires the operational risk framework to specifically address internal and external fraud, tied to risk appetite and tolerance, and to allow an assessment of whether capital is sufficient to absorb those events. It also sets reporting requirements for the Board of Directors, semiannually for operational risk and quarterly for fraud.
The official text also says fraud monitoring must include key indicators, significant incidents, metrics, corrective measures, newly identified methods, and areas for improvement. According to the Official Gazette, the framework is not just a statement of principles, it translates into procedures, responsibilities, and regular follow-up.
What is the compliance timeline?
The rule calls for phased implementation between September 1 and December 31, 2026, with mandatory actions to define structure, policies, and anti-fraud practices, and to preliminarily identify risks tied to products, services, processes, and digital channels. Later stages are also planned, with different deadlines.
That schedule marks a gradual transition, not an immediate rollout of every control at once. The official material in this coverage does not detail each later milestone, but it does establish that compliance will be staggered and that the first part of the year comes with concrete obligations.
What changed in Mexico for banking authentication?
In Mexico, the CNBV published on September 1, 2026, the resolution that amends the general provisions applicable to credit institutions and allows tokens or confirmation codes to be sent by SMS to the customer’s registered mobile phone for certain operations. According to the coverage reviewed, it will take effect the next day, on September 2.
UNO TV reported that the change allows banks to send security codes by SMS to authenticate certain digital transactions. ABC Noticias, meanwhile, said the CNBV authorized sending tokens or confirmation codes by SMS to the customer’s registered mobile phone under the secondary banking authentication regime.
The timing difference is also part of the regulatory move. In Argentina, the BCRA set a phased compliance process through year-end, while in Mexico the resolution began applying immediately the day after publication in the Diario Oficial de la Federación.
Sources
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA - Comunicación “A” 8471/2026boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Nueva regulación del BCRA sobre gestión del riesgo de fraude (Com. A 8471)bruchoufunes.com· Bruchou & Funes
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de créditosidof.segob.gob.mx· Diario Oficial de la Federación (SIDOF)
- Te llegará un código del banco: desde mañana cambian estas reglas de autenticaciónunotv.com· UNO TV
- ¿Tu banco te enviará un código al celular? Esto cambia a partir de mañanaabcnoticias.mx· ABC Noticias



