CiberLATAMbywhalemate

Chile's CMF tightens bank security rules

Chile’s CMF activates NCG 583, ending coordinate cards and requiring stronger authentication for transfers and digital onboarding.

Whalemate Labs · AI-assisted researchPublished:3 min read

Chile’s Financial Market Commission has put General Rule 583 into force, ending the coordinate card and requiring stronger customer authentication for electronic transfers and digital onboarding. The measure raises the bar for electronic banking payments and transactions.

Chile’s Financial Market Commission has put General Rule No. 583 into force, ending the use of the coordinate card and requiring strengthened customer authentication for electronic transfers and digital onboarding. The rule sets stricter standards for electronic banking payments and transactions.

What does the CMF’s new rule require?

NCG 583 says strengthened authentication must rely on at least two of three elements, something the customer knows, something the customer has, or an inherent characteristic. In practice, the regulation is meant to keep transactions from depending on a single verification factor.

AS Chile reported that the change is now in effect and puts an end to the coordinate card for banking operations. The publication also said the requirement applies to both transfers and digital onboarding.

What background did this change have?

According to AS Chile, the effective date had been pushed back one year from the original date of August 1, 2025, due to the impact it could have on older adults. That helps explain why the transition to the new mechanisms was not immediate.

How does this fit into the broader financial rulebook?

NCG 583 arrives as Chilean rules on banking and cybersecurity are moving on several fronts at once. Cybersecurity Framework Law No. 21,663 is being coordinated by the CMF and the National Cybersecurity Agency under the 2026-2027 Regulatory Plan, with effects on financial actors considered essential service providers.

Within that same framework, recent comments on the law set strict deadlines for reporting incidents with significant impact. Essential service providers must alert the National CSIRT within three hours of learning about the incident, update the information within 72 hours, and deliver a final report within 15 calendar days.

Vital operators must also maintain continuous security management, continuity plans, periodic exercises, training programs, and a cybersecurity officer. Those requirements also apply to financial infrastructure classified as vital.

What other financial obligations were still on the table?

The regulatory discussion does not stop at authentication. A column on financial privacy said the new data protection law turns financial information into sensitive personal data and subjects its processing to the principles of legality, purpose, and proportionality.

On top of that, the CMF pushed back for a second time the effective date of Circular No. 2,364 on loans to bank directors, setting a new date of December 26, 2026. At the same time, the regulator presented a package of proposals to modernize Chile’s financial market, including changes to make it easier for banks to use internal models to measure credit risk.

The same source said those internal models could bring additional governance and model-validation requirements for financial institutions.

Sources

View all