Argentina and Mexico tighten anti-fraud rules
Argentina adds fraud score limits and Mexico changes SMS auth, app deadlines, and incident notices for banks.
Argentina now has mandatory rules to prevent fraud in electronic transfers, with a risk score tied to the CUIL/CUIT for banks, wallets, and instant payment operators. In Mexico, the CNBV and Banxico added changes to SMS authentication, deadlines for banking apps, and standardization rules for SPEI.
Update September 15, 2026: BCRA Communication A 8473/2026 was clarified in the official text, which bans decisions based solely on the fraud score and specifies that deadlines start from publication and from delivery of technical documentation. In Mexico, changes were also added on SMS authentication and deadlines to adapt apps and SPEI transfers.
Argentina now has mandatory rules to prevent and mitigate fraud in electronic funds transfers for financial institutions, payment service providers that offer payment accounts, and administrators of instant transfer schemes. Communication A 8473/2026 from the Central Bank of the Argentine Republic adds a risk assessment based on a fraud score linked to the CUIL/CUIT, which banks and payment-account providers must use.
What does the new BCRA rule require?
The BCRA requires the fraud risk score to be incorporated into customer onboarding, daily transaction monitoring, and the review of account-holder registries, but the official text makes clear that decisions cannot be based solely on that score. According to iProUP and the Official Gazette, the framework covers both senders and recipients of transfers, and will be used to recategorize risk levels within control processes.
Communication A 8473/2026 also sets staggered deadlines. Administrators of instant transfer payment schemes have 120 calendar days from publication to adapt their infrastructure. Financial institutions and PSPCPs have 60 days to add the indicator to customer onboarding and registry review, and 90 days to integrate it into daily transaction monitoring, counted from receipt of the administrators' technical documentation, according to El Destape, iProUP, and the Official Gazette.
In addition, the technical analysis released by The Metal Vortex says the scores will be distributed through monthly files and an API for participating institutions. That same material says the score will be used in onboarding, transaction monitoring, and periodic customer reviews, always with controls that prevent automated decisions based only on that indicator.
How does this compare with Mexico?
In Mexico, the CNBV's Single Banking Circular already sets information security obligations for credit institutions, including an internal control system designed to protect the confidentiality, integrity, and availability of information. That framework also requires appointing an information security officer, or CISO, named by the CEO and reporting directly to him.
Mexican rules also establish a chain of notices after incidents. According to Grupo ACMS Consultores, notification to the commission must be immediate, followed by a detailed incident report within 5 business days, a corrective action plan within 15 business days, and notice to customers within 48 hours when sensitive information is compromised.
Since September 2, 2026, the CNBV has also allowed SMS-delivered codes as a category 3 authentication factor for certain digital financial services carried out through technology-based commission agents, according to iworld.com.mx. That easing sits alongside other security requirements already in force in Mexican banking.
What deadline did Banxico set for apps and SPEI?
Banxico reportedly set December 14, 2026 as the deadline to adjust banking apps and mobile transfers in SPEI, with reference to possible administrative penalties for noncompliance, according to Ruptura 360. Other coverage places that same date as the end of the transition period to standardize how app-based transfers work.
That reference matches reporting by The Rio Times and ClearingPost, which attribute to circulars 9/2026 and 10/2026 the requirement to standardize transfers in apps before December 14, 2026. Those reports cite a 180-day transition period from the effective date and say the adjustment affects banks and SPEI participants, including CoDi and DiMo flows.
What new regulatory front is under discussion in Mexico?
At the same time, Mexico is debating a proposed rule to combat hidden charges and deceptive practices at banks and fintechs. If approved, Condusef, the Bank of Mexico, and the CNBV would have 180 calendar days to issue secondary regulation, and financial institutions would then have another 180 days to adapt their digital platforms, according to El Cronista.
Sources
- Comunicaciones BCRA “A” 8471 y “A” 8473: Gestión y prevención del riesgo de fraudeabogados.com.ar· abogados.com.ar
- El Banco Central exige a billeteras virtuales medidas de prevención de fraude en transferenciaseldestapeweb.com· El Destape
- Cambian las transferencias: cómo es el nuevo puntaje que el Banco Central aplicará a bancos y billeterasiproup.com· iProUP
- México va contra cargos ocultos en bancos y fintech: impactos regulatorios y plazos de adecuacióncronista.com· El Cronista
- Regulación Fintech en Argentina: Guía Legal 2026jfcattorneys.com· JFC Attorneys
- ISO 27001 en México y seguridad de la información en instituciones de créditomexico.grupoacms.com· Grupo ACMS Consultores
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA - Comunicación A 8473/2026korilaw.com· Kori
- Comunicación (BCRA) “A” 8473/2026siap.blogdelcontador.com.ar· Blog del Contador
- Perspectivas de las ciberestafas desde el Derecho de las obligaciones: una mirada particular sobre la jurisprudencia recientealdiaargentina.microjuris.com· Microjuris
- BCRA: ¿Cómo funcionará el nuevo score de fraude?documento.errepar.com· Errepar
- Banxico Sets December Deadline for App Transfer Rulesriotimesonline.com· The Rio Times
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – Comunicación “A” 8473/2026boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Newsletter Semanal - 9/9/2026tg-cq.com· TG-CQ
- La CNBV flexibiliza la autenticación bancaria y vuelve a apostar por una tecnología vulnerable como el SMSiworld.com.mx· iworld.com.mx
- Banxico Gives SPEI Participants Until 14 December to Standardise CoDi and DiMo Flowsclearingpost.com· ClearingPost
- Cambios en transferencias bancarias desde la app | Fecha límiteamp.milenio.com· Milenio
- Banxico fija fecha límite para cambiar las apps bancariasruptura360.mx· Ruptura 360
- Payment Fraud Scores Need Decision Controlsthemetalvortex.com· The Metal Vortex



