CiberLATAMbywhalemate

Peru's SBS tightens financial data access

The SBS and prosecutors signed a deal to expand access to financial records and strengthen cooperation against fraud

Whalemate Labs · AI-assisted researchPublished:3 min read

Peru's SBS and the Public Ministry signed an agreement on Aug. 27, 2026, to expand prosecutors' access to financial information and strengthen cooperation against money laundering, cyber fraud, extortion and cybercrime. At the same time, the regulator has been adjusting rules on digital channels, pension contribution payments and cash limits, with tighter security and business continuity requirements for supervised entities.

Peru's Superintendence of Banking, Insurance and AFPs, or SBS, and the Public Ministry signed an interinstitutional cooperation agreement on Aug. 27, 2026, to strengthen investigations into money laundering, terrorist financing, extortion, cyber fraud and other forms of organized crime. The deal expands prosecutors' access to financial information and adds consultation services from the Web Risk Center, the Web Pension Consultation Module and data linked to the private pension system.

What does the agreement between the SBS and the Public Ministry enable?

The agreement gives the Public Ministry broader access to SBS financial and pension data for its investigations, with an explicit focus on cyber fraud and other financial crimes. It also includes joint training programs for staff from both institutions in banking, insurance, money laundering, terrorist financing, asset forfeiture and cybercrime.

That mix of data sharing and training is meant to improve response capabilities in complex investigations, where cross-checking financial information is often essential. In the official announcement, the scope was not limited to a single crime category. It instead covers a broader organized crime agenda.

What regulatory changes are accompanying this line of work?

The SBS is also adjusting rules that raise security, operational continuity and information protection requirements for supervised entities. A draft rule presented by the regulator would allow banks, finance companies and digital wallets to serve as channels for AFP contribution payments, as long as they comply with current rules on operational risk management, business continuity, information security and cybersecurity.

Along the same lines, SBS rules for supervised entities establish authentication requirements for digital services designed to prevent fraud in the financial sector. The legal analysis cited on Peru's framework also notes that, although the country still does not have a General Cybersecurity Law, it does have digital trust rules, personal data protection, cybercrime laws and sector-specific regulations that impose information security obligations.

What changed with cash limits and basic operations?

SBS Resolution No. 02116-2026, in force since Aug. 27, 2026, adjusted cash limits and operating conditions for financial establishments and electronic money issuers. The rule sets a daily cash limit per person of up to 6 UIT for withdrawals and deposits tied to credit operations, up to 2 UIT for other operations, and a standard cash-on-hand cap of 10 UIT for basic operations establishments.

If an institution wants to exceed that standard limit, it may hold up to 30 UIT in cash on hand, but it must implement controls appropriate to the higher risk level and send the SBS a detailed report. That report must identify the risks of the change, the controls in place, the geographic location of the establishments and the justification for raising the limit.

The regulation itself requires custody, handling and transport measures for cash, physical security, video surveillance, anti-money laundering and counterterrorism financing controls, and business continuity. HazloDigital and LP Derecho agree that the scheme forces institutions to strengthen internal controls as operational exposure rises.

What does the reform include for new finance and insurance firms?

According to an Infobae Peru report, the SBS would have formalized in August 2026 a comprehensive reform of the rules governing authorization for new finance and insurance companies. The same report says these entities could, for the first time, temporarily access an anonymized Consolidated Credit Report during the authorization process, with security measures and a requirement to delete the information if approval is not granted.

The report also says the new rule is organized into three authorization modes depending on each company's type and risk profile. It also describes maximum review periods that would include up to 120 days for organization and 180 days for operation in standard applications, along with a mandatory prequalification stage of up to 15 days.

Sources

View all