CiberLATAMbywhalemate

Peru SBS Unifies Operational Incident Reports

Peru’s SBS opened a public consultation on a single incident-reporting scheme for finance, insurance and pensions, with deadlines of up to two hours.

Whalemate Labs · AI-assisted researchPublished:2 min read

Peru’s SBS authorized a public consultation on a draft rule that merges operational outages and cybersecurity incident reporting into one scheme for the financial, insurance and pension systems. The proposal sets initial, interim and final reports, and opens 30 calendar days for comments.

Peru’s Superintendency of Banking, Insurance and AFPs, known as SBS, has authorized a public consultation on a draft rule that would replace two notification regimes with a single operational incident reporting framework for entities in the financial, insurance and pension systems. The resolution also adds guidance for initial, interim and final reports, and opens 30 calendar days for comments starting the day after it is published in El Peruano.

What changes under the new framework?

The draft brings together reporting for significant operational disruptions and significant cybersecurity incidents under one regulation, with standardized information for each stage of the incident. According to coverage by Infobae and Actualidad Civil, the goal is to bring more order to how supervised entities report when an event affects their operations.

Revista Gan@Más said the new framework defines operational incident broadly, covering people, processes, technology, facilities, third parties or external events that generate, or could generate, financial, legal, regulatory, business continuity, customer or reputational impacts. The same report said the draft includes five categories of operational incidents and a centralized, updated register of significant and non-significant incidents.

What reporting deadlines does it set?

The proposal sets different initial reporting deadlines, with up to 2 hours for companies with high market concentration, 5 hours for banks, finance companies, municipal savings banks, rural savings banks and CMCP, and one business day for the rest of the supervised firms. Infobae added that the first interim report must be sent within 24 hours of the initial report, and the final report must be filed within 20 business days after the incident is resolved.

NotiPerú said the categories covered by the new framework include non-disruptive compromise of information systems, data breach, financial fraud and information disorder. The same outlet reported that the maximum deadlines for the initial notice vary depending on the type of supervised entity.

When would it take effect, and what happens to earlier incidents?

Revista Gan@Más said the new regulation would take effect on January 1, 2027. It also said incidents that occur through December 31, 2026, would remain subject to the rules in force at the time they occurred.

The draft was published by the SBS on its digital site and also covered by El Peruano and the Andina news agency as a public consultation already authorized. At the same time, the agency is moving forward with other regulatory measures, including SBS Resolution No. 02275-2026, which changes market conduct and fee rules, and SBS Resolution No. 02292-2026, which sets staggered compliance deadlines for savings and credit cooperatives.

That regulatory backdrop also sits alongside other requirements already in force. PressPerú recalled that since 2021 the SBS has had a specific information security and cybersecurity management framework for financial entities, with strengthened authentication mechanisms for certain digital transactions. Microfinanzas, meanwhile, said fintech firms must manage operational risk, anti-money laundering controls, information security and cybersecurity in line with SBS requirements.

Outside the traditional financial segment, the SBS also published a draft aimed at preventing money laundering and terrorist financing on technology platforms for remote games and sports betting, defining them as entities required to report to the SBS Financial Intelligence Unit. On the digital payments side, BiPay was authorized to operate as an e-money issuer and was also cleared to provide issuance, transfers, payments and top-up services, expanding the digital wallet offering in Peru.

Sources

View all