CiberLATAMbywhalemate

Chile CMF Tightens Cybersecurity Rules

Chile’s CMF issued new rules for exchanges, brokers, insurers and reinsurers, with stronger risk, security and continuity requirements.

Whalemate Labs · AI-assisted researchAug 17, 20263 min read

Chile’s CMF issued General Rule No. 571 for exchanges, brokers and securities agents, and No. 573 for insurance and reinsurance firms, with requirements for risk management, information security, cybersecurity, business continuity and oversight of outsourced services.

Chile’s Financial Market Commission, or CMF, has issued two rules that directly reshape the operating framework for securities intermediaries and the insurance market. General Rule No. 571, dated July 27, 2026, consolidates requirements for stock and commodities exchanges, brokerage firms and securities agents, with obligations covering risk management, information security, cybersecurity and business continuity. General Rule No. 573, meanwhile, sets out how service outsourcing must be handled by insurance and reinsurance companies, adding governance and provider oversight duties.

What changed for exchanges, brokers and securities agents?

NCG 571 brings together and systematizes rules that already affected the sector, but now presents them as part of the authorization and operating requirements. According to Garrigues Chile, the CMF has folded policies for risk management, information security, cybersecurity and business continuity into the regulatory standard for stock and commodities exchanges, brokerage firms and securities agents.

That affects internal compliance structures and the way these entities document their ability to keep operating through incidents, outages or technology failures. The emphasis is no longer only on financial intermediation, but also on the controls that support it.

What does the new rule require for insurance and reinsurance?

NCG 573 sets instructions on outsourcing services and requires companies to organize third-party relationships from a risk and governance perspective. Diario Estrategia reported that the CMF added requirements that also cover technology and information security processes in the insurance sector.

An analysis by SeguroVision adds that the rule explicitly reinforces the principle that the CMF must retain unrestricted access to information linked to outsourced services, even when those services are provided from abroad. For Chilean insurers that rely on technology or cybersecurity capabilities located in Argentina or Mexico, that raises pressure on contracts, data access and operational traceability.

How does this intersect with the new cybersecurity framework?

The CMF’s move comes amid a tougher regulatory environment since the Cybersecurity Framework Law took effect on March 1, 2025, alongside oversight by the National Cybersecurity Agency. At ESET Security Day Chile 2026, speakers stressed that financial organizations need cyber intelligence capabilities, incident management and compliance with reporting obligations to adapt to that framework.

ICARE added that the new map is complemented by Decree 285 on the organic scope and operators of vital importance, which formalizes the classification of critical infrastructure, including financial infrastructure. That framework shapes how business continuity and incident response programs are designed in entities with operational ties to other countries in the region.

TrendConomy said the law requires incident reporting to the ANCI in hours, not months, and that the regulatory reading points to similar expectations for financial actors classified as OIV or PSE. In parallel, Gesintel noted that CMF Circular No. 2,368 aligns banking regulation with UAF Circular No. 62, reinforcing transaction monitoring, internal alerts and documentation of due diligence, a layering that makes compliance more difficult for banks with operations and correspondent relationships in Argentina and Mexico.

What judicial backing did the CMF receive?

Chile’s Supreme Court issued rulings that support the CMF’s authority to request any document, ledger or background material needed for supervision or statistical purposes. The Clinic reported that the standard was reaffirmed even in the Sartor case, strengthening the financial regulator’s supervisory and compliance reach.

At the same time, the CMF delayed the entry into force of the rule that bars banks from extending credit to their directors and to related downstream companies, originally introduced in Circular No. 2,364 in June 2025. The delay came after banks filed illegality claims before the Court of Appeals and kept part of the banking governance and conflict-of-interest framework under review.

Sources

View all