Chile tightens incident reporting rules
Law 21.663, NCG 569 and CMF rulings raise compliance demands for banks and nonbanks in Chile.
Chile added new regulatory pressure points for its financial system in August. Cybersecurity Framework Law 21.663 sets incident reporting deadlines for the National CSIRT, while the CMF adjusted the Open Finance System with technical requirements and a more flexible pilot for smaller entities.
Chile’s Cybersecurity Framework Law No. 21.663 requires essential service providers in the country, including financial firms, to alert the National CSIRT within three hours of learning of a significant incident, update the report within 72 hours, and submit a final report within 15 calendar days. At the same time, the CMF is moving ahead with the Open Finance System, NCG 569 pushed back its effective date, and the Central Bank stepped up warnings about AI-driven fraud.
What changed with Law 21.663?
The law created a staggered reporting scheme for cyber incidents affecting essential service providers. The first notice to the National CSIRT must be filed within three hours, the update within 72 hours, and the final report within 15 calendar days. That framework also covers the financial sector.
Those reporting deadlines come on top of other local requirements. NIVEL4 Labs’ analysis of the ANCI public consultation, "Basic Cybersecurity," notes that several organizations expect high costs and a shortage of specialized staff to meet the six mandatory minimum controls. Those controls include multi-factor authentication, password managers, backups, and device hardening.
How does the Open Finance System stand?
The CMF amended NCG 514 through General Rule No. 569, added Technical Annex No. 3, and extended the Open Finance System’s implementation deadline to 36 months, with an effective date of July 3, 2027. The regulation also establishes a pilot period with simplified participation and specific security requirements for obligated entities.
Ozone API said that the tiered approach lets entities with fewer than 100,000 unique customers follow a simplified track, with a single API, no consent dashboard, and no FAPI 2.0 certificate or incident reporting requirement in that phase. For the rest of the regulated universe, the rule includes technical requirements such as FAPI 2.0 with message signing, OAuth 2.0, OpenID Connect, and TLS 1.3 with mTLS.
Chócale added that the CMF still needs to define specific oversight and reporting mechanisms to monitor how the Open Finance ecosystem works and the risks it creates, including cybersecurity and operational incidents. That points to new information obligations for banks and other participants beyond the APIs.
What did the CMF say about authentication and access?
The CMF clarified through rulings that the Strong Customer Authentication rule set out in NCG 538 applies to all issuers, not just banks. The requirement applies to processes such as changes to personal data, password changes, and the addition or replacement of trusted devices.
In the same regulatory line, Law 21.641 on financial system and infrastructure resilience allowed the Central Bank to issue rules opening direct access to the real-time gross settlement system, or RTGS, to nonbank financial entities such as savings and credit cooperatives, payment system operators, and securities custodians. That regulation took effect on August 20, 2026.
What impact did the Central Bank warning have?
Chile’s Central Bank publicly warned about disinformation and financial fraud involving AI-generated videos that impersonate its officials. Its official advice was to always verify information through the Central Bank’s official channels.
The concern is not abstract. ITSitio Chile cited the Central Bank’s Payment Systems Report and said that in the first half of 2026, complaints over fraudulent digital transactions reached roughly $98 million in losses across the banking sector. That figure appeared in the same context as the institution’s call for caution around fake AI-produced content.
Sources
- Ciberdefensa con IA: alerta de Sam Altmananda.cl· ANDA
- Ley 21.719 y Ley 21.663: dos deberes distintos ante un mismo incidentealayiatrust.com· Alayia Trust
- Chile Opens LBTR Settlement Access to Non-Bank Financial ...clearingpost.com· Clearingpost
- Costos y escaso personal entre los desafíos para cumplir controles básicos de ANCIblog.nivel4.com· NIVEL4 Labs
- La CMF avanza en la implementación del SFA: sandbox "Atena" estará disponible en octubrechocale.cl· Chócale
- Chile's Open Finance System: Your Guide to Get Startedozoneapi.com· Ozone API
- Dictámenes CMFcmfchile.cl· CMF Chile
- Cómo las fintech protegen a Chile del fraude con inteligencia artificialitsitio.com· ITSitio Chile



