BCRA and CNBV tighten anti-fraud controls
Argentina and Mexico are updating anti-fraud rules. The BCRA now requires documented programs and risk databases, while the CNBV allows SMS codes.
The Central Bank of Argentina added a specific fraud-risk section and launched a public database to share risk profiles across banks and wallets. In parallel, Mexico's CNBV authorized security codes by SMS and kept combined factors for higher-risk transactions.
The Central Bank of Argentina added Section 6.5 on fraud risk management to its Guidelines for Risk Management in Financial Institutions. At the same time, through Communication A 8473, it launched a public database to detect suspicious activity tied to fraud and illegal gambling. In Mexico, the CNBV revised rules so banks can send security codes by SMS and simplify some balance inquiries.
What does the BCRA require from banks and PSPs?
The new Section 6.5 requires financial institutions to maintain a documented Anti-Fraud Program, with coordination among compliance, legal, cybersecurity, and AML/CFT teams. It also calls for detection procedures supported by technology solutions, reporting channels, incident response protocols, training, and annual reviews. The text further strengthens the link between operational risk management, regulatory compliance, and cybersecurity.
The timeline in Communication A 8471, published in Argentina's Official Gazette, sets a first phase from September 1, 2026, through December 31, 2026. During that period, institutions must define their anti-fraud structure, policies, and practices, along with roles and responsibilities, risk appetite and tolerance, and the operational and fraud risks linked to products, services, digital channels, and critical processes. Starting January 1, 2027, payment service providers registered or authorized by the BCRA that were not previously covered must assign a specific unit or responsible person, complete a self-assessment, develop a mitigation plan, and comply with point 6.4 on technology and information security.
How will the BCRA public database work?
Communication A 8473 calls for immediate transfer operators to use a new public database to detect accounts linked to fraud and illegal gambling, and to warn banks and virtual wallets. According to the reporting cited, the stated goal is to stop online scams and fight illegal gambling by identifying accounts that route funds to unauthorized betting sites.
Based on the published information, Coelsa, NewPay, Red Link, and Interbanking will use that database to build person-level fraud risk profiles. Those profiles will be made available free of charge to financial institutions and PSPs for daily transaction monitoring and customer onboarding.
What changed in Mexico with the CNBV?
The National Banking and Securities Commission changed the rules for credit institutions so they can send security codes, a category 3 authentication factor, by SMS, email, or encrypted instant messaging services. For higher-risk transactions, combined authentication factors remain in place.
The changes to Articles 319 Bis 2, 319 Bis 3, and 319 Bis 5 also allow category 2 authentication alone for balance and transaction inquiries through technology-based commission agents. Specialized Mexican outlets say institutions will need to update apps, security policies, customer notices, authentication traceability, and mechanisms for changing factors and contact methods.
The CNBV resolution says the new rules on authentication-factor delivery and SMS use take effect on September 2, 2026. Expansión and XEU added that, from that date, banks can send by SMS one of the codes used to verify a customer's identity in certain transactions carried out through technology commission agents, such as mobile apps and websites.
What regional impact do these changes have?
The measures in Argentina and Mexico are pushing banks, wallets, and payment service providers to strengthen fraud controls, authentication, and traceability for digital transactions. In Argentina, the focus is on risk governance, internal coordination, and sharing fraud signals. In Mexico, the change expands the channels available to deliver authentication factors and adjusts verification schemes for digital operations.
Sources
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – Aviso sobre disposición con vigencia plena desde el 01/09/27boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Nueva regulación del BCRA sobre gestión del riesgo de fraude – Comunicación “A” 8471bruchoufunes.com· Bruchou & Funes de Rioja
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de créditosdv.com.mx· SDV México
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegallosprimeros.tv· Los Primeros TV
- CNBV abre la puerta a que bancos envíen códigos de seguridad por SMS y simplifica consultas de saldoelceo.com· El CEO
- CFDI falsos: 30 días para proteger deducciones y evitar cancelación del CSDhelp-ai.mx· Help AI
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegaldiariodecuyo.com.ar· Diario de Cuyo
- Los bancos estrenan una nueva forma de confirmar tu identidad por SMS: así funcionaexpansion.mx· Expansión
- A partir de este miércoles, recibirás estos mensajes de SMS que no debes ignorarxeu.mx· XEU
- CNBV Allows SMS Authentication for Digital Banking Agentsstartupresearcher.com· StartupResearcherUnverified URL



