CiberLATAMbywhalemate

Chile CMF sets SFA rules, Atena sandbox date

Chile’s CMF sets October 2026 for the Atena regulatory sandbox and adds technical requirements for Open Finance participants.

Whalemate Labs · AI-assisted researchPublished:3 min read

Chile’s Financial Market Commission is advancing the Open Finance System and set October 2026 for the Atena regulatory sandbox. The framework adds technical demands for participating financial institutions, including availability, performance, contingencies and security.

Chile’s Financial Market Commission is moving ahead with the Open Finance System and has set the Atena regulatory sandbox, tied to that framework, for October 2026. The rollout also comes with new technical requirements for participating financial institutions, covering availability, performance, contingencies and security.

What did the CMF set for the Open Finance APIs?

General Rule No. 514 established technical standards for the Open Finance System APIs under Fintech Law No. 21,521, with a minimum daily availability of 95% and processing times below 4,000 milliseconds for data requests, according to Buk. Those requirements apply to banks, card issuers and other covered financial institutions.

Ozone API’s separate technical guide adds that the CMF sets different service targets for information APIs and payment APIs. Information APIs must reach 95% daily availability and 99% monthly availability, with processing times below 4,000 ms at the 95th percentile. Payment APIs face stricter thresholds, with 95% daily availability, 99.5% monthly availability and responses under 800 ms.

Ozone API also details a specific security stack for the required APIs. The framework includes FAPI 2.0 with message signing for nonrepudiation, OAuth 2.0, OpenID Connect, TLS 1.3 with mTLS, and extended-validation X.509 v3 certificates under a two-tier certification infrastructure. The same guide says the CMF rules out alternative mechanisms such as DPoP or private_key_jwt.

How did the implementation timeline change?

In 2026, the CMF amended General Rule No. 514 through General Rule No. 569, added Technical Annex No. 3 and extended the Open Finance System’s entry into force from 24 to 36 months, according to Ozone API. It also established a pilot period with simplified participation and eased enforceability for covered financial institutions.

The same amendment set the Open Finance System’s effective date for July 3, 2027. For Group 1 entities, which include established banks in Chile, branches of foreign banks and credit or prepaid card issuers, registration requests must be filed within 60 days after that date, with later deadlines of five to 18 months to comply with the API requirements.

What other operational obligations does the framework impose?

Ozone API says the Chilean framework adds traffic, consent, monitoring and reporting rules that tighten day-to-day operations for institutions. These include initial limits of 10 transactions per second for information APIs and 10 TPS per minute for payment APIs, along with a maximum consent term of 36 months and 90 days for one-time scheduled payments.

The framework also requires a free consent management dashboard for customers with five years of visibility, bans prechecked boxes and manipulative designs, and requires revocation to reach the third party within five minutes through a webhook. On top of that, institutions must file monthly reports to the CMF on availability, activity and maintenance, report incidents within 30 minutes of detection and conduct annual data-quality tests.

What changes in fraud prevention and personal data?

Law No. 20,009 requires payment card issuers to adopt security measures and monitoring systems capable of detecting transactions that do not match the user’s normal behavior, managing alerts and identifying fraud patterns, according to EstadoDiario. That analysis broadens the duty to monitor, trace, block and assess risk across the financial sector.

The same analysis says that, to detect unusual transactions, institutions must process movements, amounts, times, recipients, phone numbers, devices, IP addresses, authentication events and behavioral patterns. They must also consider frequency, amounts, devices and the relationship to the customer’s historical behavior, beyond static rules.

Separately, the expected entry into force of Law No. 21,719 in December 2026 will allow banks and card issuers to base personal data processing for bank fraud prevention on legal obligations, contract performance or legitimate interests, without needing fresh consent each time a transfer is analyzed. That must be done while respecting the data subject’s rights and limiting processing to specific, lawful purposes.

What transparency obligations does the CMF keep in place?

The CMF requires any legal entity that is a controller, or a controlling member, of a bank to submit audited financial statements prepared by an external audit firm registered with the Commission. The requirement is part of Chile’s broader transparency and governance obligations for the banking sector.

Taken together, the measures set a defined timeline for the SFA, a testing platform such as Atena for October 2026, and a compliance model built around availability, security, anti-fraud monitoring and personal data processing rules.

Sources

View all