BCRA and CNBV tighten anti-fraud controls
Argentina and Mexico changed financial rules, with the BCRA launching a phased anti-fraud framework and the CNBV allowing SMS banking authentication.
The BCRA issued Communication A 8471 and added a comprehensive fraud risk management framework for banks and payment service providers that offer payment accounts. In Mexico, the CNBV changed authentication rules for certain operations with technology-based brokers and allowed SMS use, while some coverage also mentions tighter cybersecurity controls in the regulated system.
Argentina's central bank issued Communication A 8471 and added a comprehensive fraud risk management framework as part of operational risk management for financial institutions and payment service providers that offer payment accounts. The rule sets a phased rollout with specific milestones through September 2027. In Mexico, the CNBV also changed banking authentication rules and allowed SMS for certain operations with technology-based brokers.
What does the new BCRA regulation require?
Communication A 8471 requires a documented anti-fraud program, with structure, policies, roles, responsibilities, and risk appetite and tolerance criteria, along with preliminary risk identification and critical processes. According to the official notice and specialized legal coverage, it also calls for coordination among compliance, legal, cybersecurity, and AML/CFT teams.
Bruchou & Funes de Rioja said the new section includes detection procedures using technological solutions, reporting channels, incident response protocols, training, and annual review. Marcela Pallero, a specialist in risk in Argentina's financial system, also noted that the rule includes indicators and periodic reports to the board until full enforcement.
How will implementation work?
The BCRA set a first stage from September 1, 2026, to December 31, 2026, to define structure, strategies, anti-fraud policies, roles, responsibilities, risk appetite and tolerance, and preliminary identification of risks and critical processes. There will then be a self-assessment and final report submission period from June 1, 2027, to August 31, 2027, with full enforcement beginning September 1, 2027, according to the Official Gazette.
| Milestone | Date | Scope | Source |
|---|---|---|---|
| First stage | Sep. 1, 2026 to Dec. 31, 2026 | Definition of structure, policies, roles, and risk appetite and tolerance | BCRA, Official Gazette |
| Self-assessment and final report | Jun. 1, 2027 to Aug. 31, 2027 | Submission of the final implementation report | BCRA, Official Gazette |
| Full enforcement | Sep. 1, 2027 | Full application of the framework | BCRA, Official Gazette |
The specialist cited on X added that the framework is strict and will apply to both banks and payment service providers, with formal anti-fraud programs and technology-based monitoring systems.
What changed in Mexico?
The CNBV published a modification in the Official Gazette of the Federation that applies to credit institutions and allows authentication codes to be sent by SMS for certain operations carried out through technology-based brokers. According to MSN Mexico's coverage, the change took effect the day after publication and began applying on September 2, 2026.
That same coverage reported an exception for balance and transaction inquiries, where institutions may require only Authentication Factor Category 2 without also requesting the second Category 3 factor. Startup Researcher added that the update allows SMS to be used as an additional channel for delivering Category 3 authentication factors to the customer's registered mobile number, while keeping the factor scheme in place and strengthening authentication traceability.
Uno TV said the change required operational adjustments in apps and websites, and recommended keeping the registered mobile number updated and enabling notifications to detect unrecognized transactions.
What other controls appear in Mexico's system?
A specialized report on Banxico, attributed to Capital Negocios, said the central bank would have issued circulars and rules to strengthen minimum cybersecurity requirements for regulated entities, including IFPEs and IFCs. The same report said the framework is based on international standards, business continuity, and incident reporting within specific deadlines.
The publication also said the stated goal of those changes is to improve the operational resilience of the payments ecosystem. That part of the material carries uncertain attribution, so it should be read as specialized coverage that was not officially confirmed in the data provided.
Sources
- Fintech: Banxico y el Desafío de la Ciberseguridadcapitalnegocios.mx· Capital Negocios
- CNBV Allows SMS Authentication for Digital Banking Agentsstartupresearcher.com· Startup ResearcherUnverified URL
- Código del banco por SMS: desde mañana cambian estas reglasunotv.com· Uno TV
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA - Comunicación A 8471/2026boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Nueva regulación del BCRA sobre gestión del riesgo de fraude con A 8471bruchoufunes.com· Bruchou & Funes de Rioja
- Te llegará un código del banco: desde mañana cambian estas reglas de autenticaciónmsn.com· MSN México
- 📢🇦🇷BCRA – hilo sobre modificación de Lineamientos de gestión de riesgos para mejorar la gestión del fraudex.com· X (Marcela Pallero)



