Chile’s CMF updates REDEC rules
The CMF updated NCG 576 and NCG 540 on REDEC, keeping consent valid for up to 15 banking business days.
Chile’s Financial Market Commission issued NCG No. 576 and amended NCG No. 540 on the operational functioning of the Consolidated Debt Registry. The update adds a technical annex and, according to specialized coverage, strengthens requirements for notice, retention, traceability and consent revocation, while also regulating API interfaces and allowing for phased implementation.
Update September 26, 2026: NCG No. 576 is now also confirmed with a maximum consent validity period of 15 banking business days. If the transaction is granted within that period, the consent remains in force for the life of the obligation and only for risk management.
Chile’s Financial Market Commission issued General Rule No. 576 and amended NCG No. 540 on the operational functioning of the Consolidated Debt Registry. The update adds a technical annex and, according to specialized coverage, strengthens requirements for notice, retention, traceability and consent revocation. It also regulates API interfaces and provides for a phased rollout.
What changes in REDEC?
NCG No. 576 modifies NCG No. 540 and adds a technical annex to organize the registry’s operational functioning. According to Carey’s coverage, the new text strengthens consent management and sets more precise rules for notice, retention, traceability and revocation.
That change focuses on data handling and authorizations inside the Consolidated Debt Registry ecosystem. The same source says rules on API interfaces were also added, expanding the technical scope of the rule and its relationship with the systems connected to the registry.
How will implementation work?
The rule calls for a gradual rollout under the timelines set out in the regulatory text itself. That approach gives entities time to meet the new requirements in stages rather than applying all changes at once.
The available material does not detail those timelines or the full content of the technical annex, so the known coverage remains limited to the regulatory points reported. The reference to NCG No. 576 and its link to NCG No. 540 is the confirmed basis for the change.
What happens to consent validity?
NCG No. 576 keeps the maximum consent validity period at 15 banking business days. According to Carey Abogados, if the transaction is granted within that period, the consent extends for the duration of the obligation solely for risk management purposes.
That point adds precision on how long the authorization lasts and under what conditions it remains valid as the obligation proceeds. The cited source presents it as a continuation of the consent framework within REDEC, with a limited scope tied to risk administration.
What still needs verification?
The available evidence still needs to be checked against the CMF’s official publications, especially regarding NCG No. 538 and the specific implementation timelines for NCG No. 576. At the same time, Portal Metropolitano reported that since August 2026, banks, fintechs and card issuers regulated in Chile must use at least two independent identity verification factors in critical transactions, but that requirement is attributed by that outlet to NCG No. 538 and is not confirmed in the official material provided.
That report says the affected transactions include electronic transfers, new digital customer onboarding and changes to sensitive data. Because there is no official confirmation in the research material, that point should remain pending verification before being presented as a definitive rule.
Sources
- Chile refuerza la seguridad bancaria con doble autenticaciónportalmetropolitano.cl· Portal Metropolitano
- CMF modifica la NCG N°540 y fortalece la administración de consentimientos del REDECcarey.cl· Carey Abogados
- CMF amends NCG No. 540 and strengthens consent management for REDECcarey.cl· Carey Abogados



