CiberLATAMbywhalemate

Brazil Central Bank tightens Pix and Open Finance

Brazil’s central bank updated Pix rules, set Open Finance milestones, and added new security, audit and traceability requirements.

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil’s Central Bank has moved several regulatory pieces at once: it updated the Manual of Standards for Pix Initiation, published the timeline for credit APIs in Open Finance, and consolidated new security, audit and traceability requirements for system participants.

In August 2026, Brazil’s Central Bank updated the operating framework for Pix and Open Finance with a set of measures that require banks, fintechs, and technology providers to adjust processes, testing, auditing, and security controls. The changes include Instrução Normativa BCB nº 769, Instrução Normativa BCB nº 770, Resolução BCB nº 559, and new security rules applied to the instant payments system.

What changed in Pix?

Instrução Normativa BCB nº 769, dated Aug. 19, 2026, updated the Manual de Padrões para Iniciação do Pix, version 2.10.0, which is part of the Regulamento do Pix and took effect upon publication. According to Atlas Público’s analysis, the revision adds the new AUTO initiation method, adjusts recurring-payment fields, and makes textual changes to attributes tied to interest charges and the closure of recurring payments.

That move adds to Resolução BCB nº 559, approved in 2026, which introduced a requirement for independent audits registered with the Securities and Exchange Commission for certain participants. The rule also added a new circumstance for losing participant status and allowed representatives of institutions to be summoned to explain security failures and control gaps.

What deadline did the BCB set for Open Finance?

Instrução Normativa BCB nº 770, dated Aug. 22, 2026, set the checkpoint calendar for implementing the Credit Operations APIs and the Credit Portability API for unsecured personal loans within Open Finance. The schedule requires a 100% success rate in testing through Sept. 14, 2026, and sets production go-live for Nov. 3, 2026 at 7 p.m.

Cadoc.ai also reported that the rule established specific deadlines for the user experience guide and the certification engine to be available. That leaves implementation tied to a sequence of technical deliverables and prior checks that participating institutions will have to meet.

What security and anti-fraud measures were tightened?

In 2026, Brazil’s Central Bank ordered new security rules for Pix focused on expanding value tracing, making it easier to recover funds moved through fraud, scams, or operational inconsistencies, and imposing tougher penalties on authorized institutions with repeated security failures in their systems. The Ministry of Finance said Pix’s recent evolution also includes improvements to the Special Return Mechanism, new requirements for participants, stronger monitoring processes, and greater sharing of security information among institutions.

At the same time, O Globo reported that the Central Bank is weighing whether to require an additional review of up to 72 hours to credit high-value Pix transactions made overnight, as a reinforced anti-fraud measure for higher-risk transfers. If it moves forward, it would add another operational control layer to the system.

How does this connect with data incidents and governance?

Brazil’s financial-sector regulatory demands intersect with a broader framework for governance and incident response. Analyses of Resolução CMN nº 4.893, the LGPD, and standards such as PCI DSS argue that institutions must demonstrate control over sensitive data, with traceability and auditable logs, especially in cloud or AI environments.

In addition, studies on Resolução CD/ANPD nº 15/2024 note that controllers must report security incidents involving personal data within three business days and keep a record of those events for at least five years. Leonardi Advogados said the ANPD has already opened a sanctioning proceeding after a data leak case, reinforcing that the notification obligation can trigger oversight and possible penalties for banks, fintechs, and technology providers.

Those same discussions stress that, in large-scale financial data environments, the lack of a formal, tested response plan makes compliance with the reporting deadline especially critical. In that context, the BCB’s new rules build on a governance baseline that had already been tightening through regulation and enforcement.

Sources

View all