CiberLATAMbywhalemate

Chile CMF tightens KYC and fraud reporting

Chile’s CMF raised KYC standards for fintech and ended duplicated semiannual fraud filings, with new obligations for banks

Whalemate Labs · AI-assisted researchPublished:3 min read

Chile’s Financial Market Commission updated its anti-money laundering framework with Circular No. 2,325, tightening due diligence and customer identification requirements for fintech and other supervised entities. It also removed the obligation to submit semiannual fraud information already published on institutional websites, effective with the second-half 2026 report.

Chile’s Financial Market Commission updated its anti-money laundering rules through Circular No. 2,325, tightening due diligence and customer identification requirements for fintech and other supervised entities. It also eliminated the obligation to submit semiannual fraud information that had already been published on institutional websites. The change affects compliance and risk management policies across the financial sector, and the removal of the semiannual filing applies to information for the second half of 2026.

What changed in KYC and anti-money laundering?

Circular No. 2,325 raised the bar for due diligence and customer identification, with a focus on the fintech ecosystem and other entities supervised by the CMF. According to material from Truora, the update is aimed at strengthening compliance and risk management policies in Chile’s financial sector.

The move fits into a broader regulatory framework for banks and fintech, where customer authentication and verification have been gaining importance. In parallel, a technical analysis cited by Diario Financiero linked these decisions to the authentication regime in payment methods and to NCG 538, noting that since 2023 a single Chilean financial institution would have paid nearly US$ 400 million under the Fraud Law.

What happened to the semiannual fraud report?

The CMF removed the obligation to submit semiannual fraud information that was already available on institutional websites, and said the measure applies starting with the report for the second half of 2026. Veredictum said the adjustment changes the periodic reporting duties for incidents and fraud at Chilean financial entities.

The regulator’s public confirmation narrowed the timing of the decision and made clear when the duplicate filing will stop being required. The material provided does not offer further details on any other changes tied to the reporting mechanism.

How do these measures fit into Chile’s broader framework?

The CMF’s changes add to a wider regulatory setup in Chile, where Cybersecurity Law No. 21,663, Data Protection Law No. 21,719, and CMF rules such as NCG 454, NCG 538 and RAN 20-10 also carry weight. Taken together, those rules raise obligations for risk management, authentication, KYC and incident reporting for banks and fintech.

On data protection, the independent guidance cited in the material says that once the Personal Data Protection Agency begins operating, formal records of processing activities, documented breach-response protocols and a reference window of 72 hours to notify security incidents to the authority will be required. Kardu adds that this framework strengthens governance and incident response for financial entities that process personal data.

IA2030 makes a similar point, arguing that any public or private organization that processes personal data, even when using chatbots, CRM systems or AI models in financial services, must maintain a Record of Processing Activities and an internal protocol to report breaches without undue delay. The material also mentions cases in which AI itself could expose data by mistake.

What new compliance requirements appear in personal data?

The new regulation on prevention models for data protection violations requires internal reporting and complaint channels that can preserve the reporter’s identity, reporting mechanisms to the Data Protection Agency or to data subjects when appropriate, and procedures for self-reporting and internal sanctions. According to Liza Márquez Abogados, the framework reinforces a stricter compliance system for banks and fintech under Law No. 21,719.

At the same time, the material from Prido and Saytec, included among the available sources, aligns with that same set of obligations for companies that process personal data in Chile. It does not add specific details on this regulatory change, but it does confirm that compliance has already become a market-wide issue.

What other moves took place in Chile’s financial sector?

The Chilean Association of Banks and Financial Institutions and Microsoft signed a cooperation agreement in September 2026 to strengthen cybersecurity capabilities in Chile’s financial industry. According to La Tercera, the alliance is focused on detection, prevention and response to threats affecting the financial sector.

The agreement came at a time of greater regulatory pressure on authentication, fraud and data handling. During the same period, public debate over payment methods and stronger authentication again tied operational risk management to the CMF’s new requirements for banks and fintech issuers.

Sources

View all