BCRA Tightens Anti-Fraud Rules for Banks
Argentina’s central bank set an anti-fraud program and timeline through 2027, while tightening controls on instant transfers and risk profiles.
The Central Bank of Argentina added a new section on fraud risk management to its regulatory framework and set a phased timeline that runs through September 2027. It also launched a strategy to tighten monitoring of instant transfers and build per-person fraud risk profiles for banks, PSPs and PSPCPs.
The Central Bank of the Argentine Republic has added Section 6.5, "Fraud Risk Management," to the consolidated text of its "Guidelines for Risk Management in Financial Institutions" through Communication "A" 8471. The rule requires a documented Anti-Fraud Program, coordinated across compliance, legal, cybersecurity and AML/CFT functions, along with whistleblower channels, incident protocols, training and an annual review.
What does the new BCRA regulation require?
Communication "A" 8471 requires financial institutions to formalize a fraud management framework with defined procedures, owners and controls. According to Bruchou & Funes de Rioja, the program must include detection through technology solutions, incident response and an annual review of the framework.
The new regime does not apply only to banks. An analysis by Abogados.com.ar said it also covers Payment Service Providers, and Payment Service Providers that offer Payment Accounts, under a differentiated process for managing internal and external fraud risk that is comprehensive, effective and sustainable.
That framework rests on two organizational pillars. One is a documented Anti-Fraud Program covering prevention, detection, response and resolution of fraud events. The other is a dedicated fraud risk management function, which can sit in a standalone unit or within the operational risk unit.
What does the implementation timeline look like?
The regime will roll out in stages through 2027. According to the Official Gazette, full application begins on 09/01/2027, but several adjustment phases will come first for financial institutions and other covered entities.
Between 09/01/2026 and 12/31/2026, entities must establish the operational risk management framework, including fraud risk prevention, define structure, strategies, policies and anti-fraud practices, assign responsible parties, set risk appetite and tolerance, and identify preliminary risks and critical processes.
Then, from 01/01/2027 to 05/31/2027, they must document processes and procedures for identifying, assessing, monitoring, controlling and mitigating operational and fraud risks in critical processes. From 06/01/2027 to 08/31/2027, they must complete a self-assessment of full compliance with Section 6.
What changed in instant transfers and transfer-based collections?
The BCRA also moved ahead with Communication "A" 8473, which tightens controls on instant transfers to manage fraud risk and detect possible accounts linked to suspicious operations and illegal gambling activity. The measure will be phased in starting in September 2026.
In an official statement in English, the BCRA framed the decision as part of a broader strategy against fraud in electronic payments. It said that beginning in September, instant transfer administrators will receive a set of public data to strengthen their analysis and monitoring tools.
Using that information, they will have to build person-based fraud risk profiles and make them available at no cost to financial institutions and PSPCPs for transaction monitoring, onboarding and periodic KYC reviews. Specialized media outlets and news coverage said the scheme will take several months to fully deploy.
What does this mean for the new Transfer Collection system?
The new Transfer Collection system, which replaces Immediate Debit, was presented as a model designed with fraud prevention in mind. Coverage by La Nación, El Esquiú and Blog del Contador/SIAP said the system aims to improve operational security against electronic scams and bring installment collections under stricter rules.
Those rules include allowing debits only from the account where the loan was disbursed, fixed and identical installments, a cap of 30% of the customer’s declared income, only one collection attempt on the due date and two retries at 48 and 96 hours, advance notice of the debit one business day beforehand, and the option for immediate stop-debit through digital channels.
According to Blog del Contador/SIAP, the operation will not allow reversals and liability for fraud will fall on the institution or provider that initiates the collection. That raises the incentive for those initiating transactions to strengthen their anti-fraud controls.
Sources
- Nueva regulación del BCRA sobre gestión del riesgo de fraude – Comunicación “A” 8471bruchoufunes.com· Bruchou & Funes de Rioja
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – Comunicación vinculada a gestión del riesgo de fraude (Comunicación “A” 8471)boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- BCRA endurece controles y vigilará transferencias por fraude y juego ilegalurgente24.com· Urgente24
- El Banco Central mueve una ficha contra el juego ilegal: por qué la Comunicación «A» 8473 es un paso necesario, pero no suficienteciberseguridadlatam.com· Ciberseguridad LATAM
- The BCRA strengthens fraud prevention strategybcra.gob.ar· Banco Central de la República Argentina (BCRA)
- BCRA: gestión del riesgo de fraude y proveedores de servicios de pagoabogados.com.ar· Abogados.com.ar
- Prestamos: hoy entra en vigencia el Cobro con Transferenciasiap.blogdelcontador.com.ar· Blog del Contador / SIAP
- Implementan el Cobro con Transferencia: bancos y billeteras podrán debitar cuotas de créditos bajo nuevas reglaselesquiu.com· El Esquiú
- Es oficial: así funciona el nuevo sistema de cuotas del BCRA que impacta en los deudores de billeteras virtuales y bancoslanacion.com.ar· La Nación



