CiberLATAMbywhalemate

BCRA and CNBV tighten anti-fraud controls

Argentina and Mexico changed financial rules, with the BCRA launching a phased anti-fraud framework and the CNBV allowing SMS banking authentication.

Whalemate Labs · AI-assisted researchPublished:3 min read

The BCRA issued Communication A 8471 and added a comprehensive fraud risk management framework for banks and payment service providers that offer payment accounts. In Mexico, the CNBV changed authentication rules for certain operations with technology-based brokers and allowed SMS use, while some coverage also mentions tighter cybersecurity controls in the regulated system.

Argentina's central bank issued Communication A 8471 and added a comprehensive fraud risk management framework as part of operational risk management for financial institutions and payment service providers that offer payment accounts. The rule sets a phased rollout with specific milestones through September 2027. In Mexico, the CNBV also changed banking authentication rules and allowed SMS for certain operations with technology-based brokers.

What does the new BCRA regulation require?

Communication A 8471 requires a documented anti-fraud program, with structure, policies, roles, responsibilities, and risk appetite and tolerance criteria, along with preliminary risk identification and critical processes. According to the official notice and specialized legal coverage, it also calls for coordination among compliance, legal, cybersecurity, and AML/CFT teams.

Bruchou & Funes de Rioja said the new section includes detection procedures using technological solutions, reporting channels, incident response protocols, training, and annual review. Marcela Pallero, a specialist in risk in Argentina's financial system, also noted that the rule includes indicators and periodic reports to the board until full enforcement.

How will implementation work?

The BCRA set a first stage from September 1, 2026, to December 31, 2026, to define structure, strategies, anti-fraud policies, roles, responsibilities, risk appetite and tolerance, and preliminary identification of risks and critical processes. There will then be a self-assessment and final report submission period from June 1, 2027, to August 31, 2027, with full enforcement beginning September 1, 2027, according to the Official Gazette.

Milestone Date Scope Source
First stage Sep. 1, 2026 to Dec. 31, 2026 Definition of structure, policies, roles, and risk appetite and tolerance BCRA, Official Gazette
Self-assessment and final report Jun. 1, 2027 to Aug. 31, 2027 Submission of the final implementation report BCRA, Official Gazette
Full enforcement Sep. 1, 2027 Full application of the framework BCRA, Official Gazette

The specialist cited on X added that the framework is strict and will apply to both banks and payment service providers, with formal anti-fraud programs and technology-based monitoring systems.

What changed in Mexico?

The CNBV published a modification in the Official Gazette of the Federation that applies to credit institutions and allows authentication codes to be sent by SMS for certain operations carried out through technology-based brokers. According to MSN Mexico's coverage, the change took effect the day after publication and began applying on September 2, 2026.

That same coverage reported an exception for balance and transaction inquiries, where institutions may require only Authentication Factor Category 2 without also requesting the second Category 3 factor. Startup Researcher added that the update allows SMS to be used as an additional channel for delivering Category 3 authentication factors to the customer's registered mobile number, while keeping the factor scheme in place and strengthening authentication traceability.

Uno TV said the change required operational adjustments in apps and websites, and recommended keeping the registered mobile number updated and enabling notifications to detect unrecognized transactions.

What other controls appear in Mexico's system?

A specialized report on Banxico, attributed to Capital Negocios, said the central bank would have issued circulars and rules to strengthen minimum cybersecurity requirements for regulated entities, including IFPEs and IFCs. The same report said the framework is based on international standards, business continuity, and incident reporting within specific deadlines.

The publication also said the stated goal of those changes is to improve the operational resilience of the payments ecosystem. That part of the material carries uncertain attribution, so it should be read as specialized coverage that was not officially confirmed in the data provided.

Sources

View all