CiberLATAMbywhalemate

Peru SBS opens EAF and AFP fee consultations

Peru's SBS is consulting new prudential rules for EAFs and AFP payment channels, with cyber, continuity and operational risk requirements.

Whalemate Labs · AI-assisted researchPublished:4 min read

Peru's banking and insurance regulator opened public consultations on a rulemaking update for Fund Administrating Companies and, separately, a proposal to let banks, finance firms and digital wallets process AFP contribution payments under operational risk, continuity, information security and cybersecurity requirements.

Peru's Superintendence of Banking, Insurance and AFPs (SBS) has opened a public consultation on a rulemaking proposal to update the prudential and accounting framework for Fund Administrating Companies (EAF). At the same time, it circulated a separate proposal to allow banks, finance companies and digital wallets to handle AFP contribution payments, with specific obligations on operational risk management, business continuity, information security and cybersecurity.

What changed in the EAF consultation?

The SBS circulated a rulemaking proposal aimed at updating the prudential and accounting framework for EAFs, in a consultation open for comments from the sector and the public until September 1, 2026. The publication was authorized under SBS Resolution No. 02038-2026, which also ties the proposal to the Regulation for the Capital Requirement for Market Risk.

According to El Peruano, the consultation will run for 90 calendar days and the new regulation will replace the one approved under SBS Resolution No. 6328-2009. The official gazette also said the update introduces a more robust, risk-sensitive methodology aligned with Basel III guidelines.

In the same vein, another El Peruano item said the goal is to improve the recognition and measurement of market risks taken on by companies in the financial system. Mercurio Legal summarized the move as two simultaneous public consultations, one for the market risk capital regulation and another to amend the Regulation for Managing Interest Rate Risk in the Banking Book.

What does the AFP contribution proposal require?

The SBS proposed letting banks, finance companies and digital wallets take part in AFP contribution payments, but only under the regulator's existing rules on operational risk, business continuity, information security and cybersecurity, as applied to the services they provide.

La República reported that the SBS project on new ways to pay AFP contributions includes those requirements for the actors involved in the process. Actualidad Penal also noted that the proposal was released for public consultation alongside the update to the prudential and accounting framework for EAFs.

What other deadlines and obligations took effect in August?

The public consultation on the SBS rulemaking proposal was set under a 15-calendar-day deadline, counted from the day after its publication in El Peruano, according to SBS Resolution No. 02051-2026. In parallel, SBS Resolution No. 02037-2026 authorized the release of another proposal that modifies the Regulation for Managing Interest Rate Risk in the Banking Book.

The broader regulatory context also includes other recent references. El Peruano's Jurídica supplement noted that Peru still does not have a General Cybersecurity Law to provide the legal and institutional basis for the National Cybersecurity Strategy, even though it does have digital trust rules, personal data protection, cybercrime laws and sector-specific regulation, especially in the financial system.

There is also progress on the Regulation of Law No. 31814 on artificial intelligence. HazloDigital said companies that develop or deploy AI in sensitive sectors, including the economy and finance, have until September 10, 2026, to implement transparency measures, logs, internal protocols and human oversight for high-risk systems. The same outlet said those systems must inform users in advance, clearly and simply, about their purpose, main functions and the decisions they can make, and keep an updated record of how they work, their data sources, algorithm logic and expected social and ethical impacts.

HazloDigital added that companies must establish internal policies, protocols and procedures to preserve security and privacy, promote transparency and explainability in AI systems, and define responsibilities and accountability mechanisms, with human oversight and trained staff able to stop, correct or void automated decisions when they have a significant financial impact.

What precedent does the abandoned accounts measure add?

Gestión reported that, by late 2025, the SBS issued a rule requiring financial institutions, when assets exceed 10 UIT or their dollar equivalent, to look for contact information in publicly accessible sources and keep records of that search before transferring the funds to the Deposit Insurance Fund.

The outlet also said, citing specialists, that Peruvians leave more than S/ 100 million a year in banks. In another report, Gestión said the requirement covers deposits, securities and assets above 10 UIT, equivalent to about S/ 55,000 in 2026, and that the additional search can include publicly accessible sources such as Reniec or social networks before the transfer to the fund.

Sources

View all