CiberLATAMbywhalemate

Peru's SBS moves prudential agenda

Peru's SBS issued new resolutions and advanced prudential measures as the national cybersecurity strategy moves forward.

Whalemate Labs · AI-assisted researchPublished:3 min read

Peru's SBS issued resolutions 02052-2026 and 02040-2026 in August 2026, both administrative and tied to staff travel for technical training. At the same time, the agency added prudential measures on cooperatives, inactive accounts, payments, and reporting, while the government advances a national cybersecurity strategy with no new obligations for banks.

Peru's Superintendency of Banking, Insurance and AFPs (SBS) published resolutions 02052-2026 and 02040-2026 in August 2026. Both were administrative in nature, while the regulator kept its focus on solvency, reporting, and prudential management. During the same period, the PCM's Secretariat of Government and Digital Transformation moved ahead with a National Cybersecurity Strategy, although no new concrete obligations for banks or financial institutions are known yet.

What did resolutions 02052-2026 and 02040-2026 order?

Resolution 02052-2026 authorized a trip to Madrid for three SBS Risk Management staff members, including the Head of Technology Risk, with a requirement to submit a report upon their return. Resolution 02040-2026 did something similar for an analyst from the Deputy Superintendency of Cooperatives, who traveled to San Salvador to take part in a cooperative sector event and later had to report on actions and results.

Based on the public information available, neither resolution sets out new cybersecurity requirements for supervised entities. Instead, they point to training and international engagement within the regulator itself, with an emphasis on technical skills and risk management.

How is the SBS regulatory agenda unfolding in August?

The SBS's recent agenda has been more focused on solvency, accounting, transparency, and financial risk than on specific information security rules. Infobae Peru reported that SBS Resolution 01873-2026 changed provisions in the General Regulation and the Accounting Manual for Coopac, with the goal of strengthening capital soundness and the gradual alignment with regulatory requirements.

That same report said the SBS paired those changes with a training program for savings and credit cooperatives, aimed at reducing risks that could lead them to failure. The emphasis again was on institutional strengthening and comprehensive risk management, not new cybersecurity controls.

El Peruano also reported that the SBS pre-published prudential proposals for financial system and insurance companies with additional business lines, along with changes to accounting manuals and chart-of-accounts plans, in a 90-day public consultation. In another item, the newspaper said the agency set a new accounting treatment for certain payments by supervised entities and reporting obligations starting with December 2026 information.

What other risk and compliance measures did the SBS take?

Gestión reported that the SBS adopted temporary measures to make loan payments more flexible for borrowers affected by El Niño. Financial system companies were allowed to modify the original contract terms under a framework focused on credit risk and payment continuity.

The same theme appeared in another Gestión report on inactive accounts. At the end of 2025, the SBS issued a rule requiring financial institutions to perform additional searches for contact information in publicly accessible sources when inactive customer assets exceed ten tax units, or their dollar equivalent. The aim was to strengthen due diligence in managing those balances.

There was also a significant enforcement action tied to reporting. Infobae Peru and Andina reported that the SBS permanently canceled the registration of the Association of Traffic Accident Funds Unión for repeatedly failing to submit mandatory reports on certificates and claims. The coverage noted that the sanction took immediate effect and that coverage for valid certificates remains in place.

What does the National Cybersecurity Strategy suggest?

The PCM's Secretariat of Government and Digital Transformation is finishing a National Cybersecurity Strategy and working on a digital governance framework in coordination with critical sectors, including finance. Andina added that the plan includes guidelines for incident response capabilities.

For now, no new obligations have been published for banks or financial institutions. Even so, the strategy's design points to future requirements for incident management and digital resilience, while the SBS remains centered on prudential rules and reporting.

Sources

View all