CiberLATAMbywhalemate

Chile Tightens Financial Cyber Rules

Chile’s CMF and Central Bank move on outsourcing, risk, stablecoins and data protection, with new compliance pressure for finance firms.

Whalemate Labs · AI-assisted researchAug 19, 20262 min read

Chile’s Financial Market Commission published General Regulation No. 573 on outsourced services in insurance and reinsurance, tying it directly to corporate governance, operational risk management and cybersecurity. At the same time, the Central Bank outlined a framework for stablecoins, and the future Data Protection Agency will expand oversight powers starting in December.

Chile’s Financial Market Commission has published General Regulation No. 573, which governs outsourced services in insurance and reinsurance companies and explicitly links them to corporate governance, operational risk management and cybersecurity. The CMF had already issued General Regulation No. 571 for exchanges and intermediaries, with requirements covering risk, information security, cybersecurity and business continuity.

What does the new outsourcing rule require?

General Regulation No. 573 sets prudential requirements for contracting outside services and requires firms to treat outsourcing under the frameworks of General Regulation No. 309, General Regulation No. 325 and General Regulation No. 454. According to Diario Estrategia, the rule also adds minimum principles and requirements for identifying, assessing, monitoring and controlling the risks that come with outsourced services.

Latino Insurance added that the regulation includes a transitional provision so companies can adjust their outsourcing contracts before full entry into force. That matters because the rule goes beyond broad principles and places outsourcing squarely within operational risk management and control.

What changed for exchanges, brokers and agents?

General Regulation No. 571, issued on July 27, 2026, consolidated and organized the rules that apply to securities and commodity exchanges, stockbrokers and securities agents, and required them to demonstrate risk management policies, information security, cybersecurity and business continuity in order to operate before the CMF.

Garrigues said the text strengthens risk standards as part of authorization and operating requirements. In practice, the measure leaves financial market participants with more formal obligations to show that their technology and continuity controls are documented and working.

What did the Central Bank say about stablecoins?

The Central Bank of Chile said in its Payment Systems Report that it will put a new regulatory framework for stablecoins out for consultation, with conditions for issuance in Chile when they can be used as a means of payment. Chócale added that Claudio Raddatz, head of the Financial Policy Division, set the target as a draft rule for consultation by late 2026 and a final regulation in 2027.

That timeline gives banks and payment service providers a clearer adjustment window for working with these instruments. The Central Bank said the scope of the framework will carry compliance implications for financial institutions and payment providers.

What does the personal data agenda add?

An analysis of Chile’s future Personal Data Protection Agency said that, starting December 1, 2026, the authority will be able to issue binding instructions, interpret the law, carry out ex officio inspections and impose sanctions without needing a civil trial. That expands oversight over banks, insurers and other financial market players in how they process and secure data.

Together, the rules on outsourcing, risk, stablecoins and personal data leave Chilean financial institutions facing stricter compliance requirements, with a focus on operational controls, cybersecurity and information management.

Sources

View all