Mexico, Argentina tighten financial controls
Argentina’s BCRA and Mexico’s SHCP and CNBV are pushing new verification, biometrics and cybersecurity rules for banks
Argentina’s central bank has issued a new official notice, while in Mexico the finance ministry and CNBV are advancing changes that affect banks, fintechs and anti-money laundering rules. Facial biometrics, compliance deadlines and tougher technology controls are among the most visible measures.
Mexico and Argentina have published new requirements for banks and financial institutions that tighten identity verification, biometrics, cybersecurity and anti-money-laundering controls. The measures involve the Central Bank of the Argentine Republic, Mexico’s Ministry of Finance and Public Credit, the National Banking and Securities Commission, and financial technology institutions and other vulnerable activities tied to lending outside regulated financial entities.
What did the Central Bank of the Argentine Republic publish?
The Official Gazette of the Argentine Republic published a notice from the Central Bank of the Argentine Republic that is available on its official website and refers readers to the documentation in the Prebisch Library or on the BCRA portal, confirming that the agency issued new rules on that date. Yanapti SRL also summarized that Communication "A" 7370 requires lenders offering preapproved credit to verify users’ identities through questionnaires, official identification documents or two-factor authentication, and to confirm that contact points have not been recently modified.
What changed in Mexico for the banking system?
In Mexico, Imagen Radio reported that new rules promoted by the Ministry of Finance and Public Credit and the National Banking and Securities Commission require the banking system to adapt its biometric verification processes within a maximum of 90 business days. The measure incorporates facial biometrics as an official verification mechanism, supplements fingerprint authentication, and sets a minimum 90% match threshold against official databases. The same coverage added that institutions must establish rules for their own biometric databases under cybersecurity controls and with a ban on selling the information.
Where could biometric implementation move next?
Imagen Radio also said the biometric rollout could shift toward ABIS systems to process large volumes of data and detect duplicate identities within the financial system.
What PLD and KYC obligations do fintechs have?
Separately, Digid México said that know-your-customer and anti-money-laundering obligations for financial technology institutions are based on Article 58 of the Law to Regulate Financial Technology Institutions and on CNBV general rules for AML/CFT, with direct impact on customer identification and verification processes and on information security.
What happens if an ITF uses an outside biometrics provider?
The same analysis added that when an ITF hires an external provider to manage official ID images or users’ biometric data, it must obtain prior authorization from the CNBV or Banxico before integrating it, an additional operational requirement for digital onboarding.
What do the rules require to operate as an IFPE or IFC?
Next Guard Insurance described that, to operate as electronic payment fund institutions or crowdfunding institutions under CNBV supervision, the General Provisions applicable to Financial Technology Institutions require a formal security policy approved by the board, an annual technology risk management program, business continuity and disaster recovery plans tested periodically, multifactor authentication for privileged access and sensitive operations, encryption in transit and at rest, material incident reporting, formal management of critical third parties, and insurance to protect customer funds and civil liability.
What changed in the LFPIORPI?
KPMG Mexico also circulated a flash note on the reform to the general rules under LFPIORPI, saying that due diligence and KYC measures must be proportionate to risk and that customers or users must be classified by risk level, with enhanced measures for high-risk clients. Infobae Mexico reported that the Ministry of Finance published new LFPIORPI rules in the Official Gazette and noted that the reform is being applied gradually, strengthening the national anti-money-laundering regime and also affecting vulnerable activities related to lending outside financial institutions.
Sources
- Nuevas reglas para bancos y sus clientes: Hacienda cambia las normas contra el lavadoinfobae.com· Infobae México
- ¿Cómo funciona el onboarding y la firma digital para fintech IFG e IFPE?digid.com.mx· Digid México
- ARGENTINA: Fraudes bancarios: cambian las medidas de seguridad para los préstamos pre aprobadosyanapti.com· Yanapti SRL
- Comunicación "A" 7370 - Requisitos mínimos de gestión, implementación y control relacionados con tecnología informáticabcra.gov.ar· Banco Central de la República Argentina
- Ahora se podrá usar el celular en el bancoprimerafuente.com.ar· Primera Fuente
- Ley Fintech México: Requisitos Cyber para Autorización CNBV 2026nextguardinsurance.com· Next Guard Insurance
- Flash | Acuerdo por el que se modifican las Reglas de carácter general a que se refiere la Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícitakpmg.com· KPMG México
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINAboletinoficial.gob.ar· Boletín Oficial de la República Argentina
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA - Comunicación “A” 8461/2026boletinoficial.gov.ar· Boletín Oficial de la República Argentina
- Biometría será el mecanismo oficial de verificación en las instituciones financierasimagenradio.com.mx· Imagen Radio México



