CiberLATAMbywhalemate

Mexico Tightens Biometrics, Argentina Updates Payments

Mexico mandates facial biometrics, owned databases and audits. Argentina updates BCRA SINAP 1-248 on the national payments system.

Whalemate Labs · AI-assisted researchAug 18, 20262 min read

Mexico has set new biometric requirements for banks and fintechs, including facial verification against official records, in-house databases and a 90-business-day deadline. In Argentina, the BCRA published Communication A 8438, which updates SINAP 1-248 on the National Payments System and adds replacement pages to the consolidated text.

Mexico and Argentina moved in the same regulatory direction, but with different priorities. In Mexico, the new biometric framework requires financial institutions to adopt facial recognition as an official verification method, with at least 90% matching against records from the INE, the SRE, or other federal authorities, while also building their own biometric databases under each entity’s control. In Argentina, the Central Bank (BCRA) published Communication A 8438, confirming SINAP 1-248 on the National Payments System and updating the consolidated text with replacement pages.

What changes in Mexico for banks and fintechs?

The Mexican rule requires facial biometrics to complement fingerprints and be used as an official verification tool, with retention rules, information governance and technical controls over bank biometric databases. Research material also says those databases cannot be shared or sold to third parties and must undergo periodic cybersecurity audits.

The regulation also calls for encryption, segregation in dedicated infrastructure, access controls and secure deletion. Institutions have 90 business days to make the required changes, according to the specialized report from Periodismo y Ambiente.

The available documentation adds more detail on Mexico’s digital identity ecosystem. Shufti Pro says the CNBV structures KYC controls in four tiers, with Level 3 covering full identification using biometrics and official source validation, and Level 4 covering enhanced identification with biometric checks equivalent to a traditional bank account. The same guide says that since 2020 the CNBV has allowed non-face-to-face opening of Level 3 and Level 4 accounts through video-based processes, using an INE photo, a selfie and a live video call of at least 30 seconds, with verification against the INE and confirmation through RENAPO.

Digid México adds that when a third-party provider handles official ID images or biometric data, the fintech institution must obtain prior approval from the CNBV or Banco de México before integrating that service. The same guide says biometric schemes with facial recognition must include certified liveness detection and the ability to detect deepfakes, masks, static photos and injection attacks. It also says some higher-risk deployments may require matches of up to 98% against INE records.

What is the scope for traditional banking?

Financial coverage outlets reported that, starting July 1, 2026, all banking institutions in Mexico will be required to request biometric data, fingerprint or facial recognition, to authorize transactions. At the same time, international coverage said the CNBV requires liveness testing in facial authentication for in-person transactions.

The political response has already begun. PVEM lawmakers asked the CNBV and Banco de México to strengthen alternative identification and authentication methods for older adults and people with disabilities who have difficulty using biometrics to access their accounts.

What did the BCRA decide in Argentina?

The Central Bank of the Argentine Republic published Communication A 8438 in Official Gazette 35970 and confirmed that the referenced circular is SINAP 1-248 on the National Payments System, aimed at financial institutions and other nonfinancial credit providers. The rule adds replacement pages to the circular’s consolidated text, based on prior measures released through Communication A 8299 and CIMPRA Bulletins 537, 538, 542 and 545.

That framework points to a staged update of Argentina’s payments and clearing system, with an impact on checks and other compensable instruments. At the same time, the BCRA remains focused on payment and clearing processes, in a line that runs alongside its technology and security rules.

How does this connect to fraud and compliance?

In Mexico, the line between cyber fraud and regulatory compliance shows up in the day-to-day operations of banks and fintechs. NextGuard says certain incidents involving payments infrastructure can lead to regulatory defense processes before the CNBV, Banco de México and CONDUSEF, while fraud against end customers through social engineering is usually handled under CONDUSEF rules and Banxico’s Special Refund Mechanism.

That framework helps explain why the new rules are not limited to checking an image. The available material shows that Mexico’s regulatory system is pushing stricter identity controls, with ownership of biometric data kept in-house, limits on third-party involvement and higher technical demands depending on the risk level of the product and the type of account.

Sources

View all