Chile's CMF launches Atena and updates consent rules
The CMF unveiled Atena for Open Finance testing, updated debt registry consent rules, and ANCI opened a multifactor authentication consultation.
Chile’s Financial Market Commission unveiled Atena, a sandbox for testing Open Finance integrations before the system begins phased rollout in July 2027. At the same time, an analysis of changes to the Consolidated Debt Registry outlined updates to how consent evidence must be retained, and ANCI announced a public consultation on multifactor authentication.
Chile’s Financial Market Commission has launched Atena, a technology sandbox that will let institutions test Open Finance System developments and integrations, check them against technical standards, and prepare for the system’s gradual rollout starting in July 2027. In parallel, an analysis of the reform to the Consolidated Debt Registry detailed changes to how consent evidence must be retained, and Nivel4 reported that ANCI opened a public consultation on multifactor authentication.
What can Atena test?
Atena lets institutions test Open Finance System components before the gradual deployment begins. According to Chocale's coverage, the testable elements include the CMF participant directory, actor identification, and digital credential management.
Access to the sandbox requires requesting authorization from the environment itself and from the directory, along with uploading a certificate and configuration settings. According to the CMF presentation, the goal is for institutions to arrive with their integrations aligned to technical standards when the system starts going into effect in phases from July 2027.
What changed in the Consolidated Debt Registry?
The update adopted a technology-neutral approach for preserving evidence of consent and dropped the original requirement to use a hash. Instead, the obligation is now framed around confidentiality, integrity, and documentary verifiability, according to the analysis published by Buk.
That same analysis adds that the rule requires debtors to be notified immediately after consent is granted or revoked. The notice must include the date, time, channel used, and an internal traceability code, along with APIs for queries and for sending consent evidence.
What did ANCI announce about multifactor authentication?
Nivel4 reported that the National Cybersecurity and Information Security Agency announced a public consultation on the use of multifactor authentication. According to that report, the goal is to prepare a mandatory, cross-cutting standard for institutions subject to Framework Cybersecurity Law No. 21,663.
The same coverage added, without confirmation for now, that the consultation was scheduled for October and is part of initiatives tied to the citizen portal and the Information Technology Training Center. For now, that point does not show adoption of a mandatory standard, only the opening of the consultation process.
Sources
- ANCI lanza portal ciudadano, consulta sobre MFA y CTF nacionalblog.nivel4.com· Nivel4
- CMF presentó Atena, el sandbox para la implementación del Sistema de Finanzas Abiertaschocale.cl· Chocale
- Registro de Deuda Consolidada: nueva norma de la CMFbuk.cl· Buk
- Fraude digital pone a prueba la verificación de identidad en la industria financieramundoenlinea.cl· Mundo en Línea
- CMF Amends NCG No. 540 And Strengthens Consent Management For REDEClegal500.com· Legal 500



