CiberLATAMbywhalemate

Peru tightens financial cyber rules

Peru is raising cybersecurity, data, and AI governance requirements for banks, with stricter supervision than Argentina

Whalemate Labs · AI-assisted researchAug 20, 20264 min read

Peru is tightening requirements for its financial system through SBS rules, an updated Personal Data Protection Law 29733 regulation, and new AI governance criteria. The result is a tougher framework for banks and fintechs operating in regional groups, with differences from Argentina and Mexico in authentication, secure communications, penalties, and risk controls.

Peru is adding new layers of cybersecurity, data protection, and artificial intelligence governance requirements for its financial sector, with the SBS at the center of prudential and operational oversight. At the same time, different sources describe a more active supervisory posture on authentication, secure communications, data protection, and risk management, while Argentina and Mexico maintain frameworks with similar touchpoints, but different regulatory nuances.

What is changing in Peru?

Peru’s regulatory architecture has been piling on new requirements for banks and other financial entities, with the SBS as the main prudential and operational supervisor. DocPath identifies SBS Regulation No. 2286-2024 as a key rule, requiring two-factor authentication for card transactions and secure communications in the banking sector. Added to that is the updated regulation under Personal Data Protection Law 29733, in force since March 30, 2025, which introduced the role of Data Protection Officer, or DPO, and the right to data portability, with the ANPDP as the competent authority, according to IA Governance.

OlvidaMisDatos describes the SBS as the institution responsible for supervising and regulating banks, insurers, and pension fund administrators, with the mission of ensuring the stability of the financial system and protecting users’ rights. Under that reading, the enforcement of information security and data protection rules in the financial sector falls within its mandate.

The issue goes beyond customer service channels. NotiPerú quoted SBS statements about the growth of digital financial services in the country and the need to strengthen authentication mechanisms and incorporate technologies that can verify user identity more securely, given the rising risks tied to digital fraud. In the same vein, a GDPRI monitoring report for Peru says the ANPD sanctions financial entities for unlawful personal data processing, including alleged misuse of biometric data.

How does it compare with Argentina and Mexico?

Argentina and Mexico also have relevant frameworks, but the practical scope described in the source material is different. In Argentina, DocPath places the main pillars in BCRA cybersecurity rules and Personal Data Protection Law 25.326, under the supervision of the AAIP and the Central Bank of the Argentine Republic. That framework sets cybersecurity requirements for banking communications and addresses data localization, with fines based on the AAIP penalty scale.

In Mexico, the same regional analysis cites the Federal Data Protection Law, the Fintech Law, and CNBV rules. Those obligations include fraud prevention plans, per-transaction limits, and customer authentication, along with the CNBV’s authority to revoke licenses for noncompliance. For organizations operating across the region, the difference is not whether controls exist, but how they are combined and the level of sanctions each supervisor can impose.

What about AI governance and operational risk?

The AI component is becoming another factor for Peruvian banks that belong to regional groups. Real OneAmerica argues that Peru is building its AI framework in layers, through law, regulation, and strategy, following a proportionality approach similar to the Financial Stability Board and the NIST AI RMF. According to that analysis, this translates into stricter obligations for human oversight, use-case inventories, materiality assessments, and risk management for high-impact AI systems.

The same study says those requirements will be heavier for Peruvian banks and financial entities within regional groups than for lower-risk operations, which means controls will need to be differentiated from the more uniform practices now common in Argentina and Mexico.

The SBS also opened a 15-day public consultation period through Resolution SBS 02051-2026 on a new draft rule, according to ActualidadCivil.pe. That move shows the authority is using participatory processes to refine its prudential and operational framework for risk management, including operational risk and cybersecurity.

Where does the security agenda with the United States fit in?

DLA Piper says the new security agenda between Peru and the United States could affect banks, fintechs, remittance companies, and other financial actors through tighter controls on screening sanctioned persons, identifying beneficial owners, detecting links to criminal networks, and preserving information relevant to investigations. The analysis places a more visible intersection there between cybersecurity, anti-money laundering compliance, and data protection in Peru than in the frameworks of Argentina and Mexico, where alignment with U.S. security requirements is still less explicit.

Sources

View all