SEC, OCC Tighten LatAm Oversight
SEC cyber disclosure rules remain in force, while the OCC is intensifying third-party oversight. The reach extends to Argentina.
U.S. SEC cyber disclosure rules remain in force and unchanged as of August 2026, while the OCC has stepped up its focus on third parties and fintechs, with implications for value chains that include operations and services in Argentina and Mexico when they are part of supervised financial groups or are listed in the U.S.
U.S. Securities and Exchange Commission cyber disclosure rules remain in force and unchanged as of August 2026. The framework covers Regulation S-K Item 106, Form 10-K Item 1C and Item 1.05 of Form 8-K, and applies to both domestic issuers and foreign private issuers that list securities on U.S. markets, including international financial entities with operations in Argentina and Mexico when they are listed or issue in the U.S.
Third parties under closer scrutiny
In parallel, recent analysis of OCC supervision points to a reinforced application of the agency's 2023 interagency guidance on third parties, with a sharper focus on fintechs and critical vendors. That approach requires banks to document the strategic rationale for the relationship, the vendor's financial strength, its cyber resilience, exposure to subcontractors and business continuity plans.
Those criteria extend to services provided from or to jurisdictions such as Argentina and Mexico when those services are part of the value chain of U.S.-regulated banking entities. The regulator's view is not limited to the direct vendor, but also the operating environment and the dependencies that support service delivery.
Technical controls and incident reporting
The technical guidance for financial institutions in the U.S. also sets a broad standard. The sector's cybersecurity framework, which includes the GLBA Safeguards Rule, FFIEC examination guidance and rules such as NYDFS Part 500, requires formal information security programs with independent testing. That scope extends to banks, insurers and asset managers, including branches and data centers located outside the United States when they support services for U.S. customers.
In third-party risk management, the specialized analyses cited in the material also note that U.S. regulators' rules expressly treat material incidents at external providers as part of the regulated entity's reporting obligations. That includes incidents at vendors or subsidiaries located in Latin America that significantly affect financial institutions supervised in the United States.
For the market, the picture is consistent. SEC disclosure obligations, OCC supervision, and the technical requirements of the FFIEC, GLBA and NYDFS converge on one point, controls and reporting do not stop at the U.S. border, including when the relevant operation or vendor is in Argentina or Mexico.
Sources
- OCC's new approach to vendor oversight intensifies scrutiny of fintech and critical activitiesnoah-news.com· Noah News
- How Vendor Risk Management Actually Works Under FFIEC: The CFO Governance Viewblog.fivenines.com· FiveNines Risk Consulting
- SEC Cybersecurity Disclosure Rules: A Compliance Guide for ...compyl.com· Compyl
- Penetration Testing for Financial Institutions: 2026 Guide - CYBRIcybri.com· CYBRI
- OCC Third‑Party Risk Management360factors.com· 360factors
- Third-Party Risk Management (TPRM): Lifecycle, Frameworks, and ...cloudsek.com· CloudSEK
- Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Final Rule)sec.gov· U.S. Securities and Exchange Commission
- FIL-29-2023: Interagency Guidance on Third-Party Relationships: Risk Managementfdic.gov· Federal Deposit Insurance Corporation
- IT Examination Handbook: Outsourcing Technology Servicesithandbook.ffiec.gov· Federal Financial Institutions Examination CouncilUnverified URL
- OCC Bulletin 2023-17: Third-Party Relationships - Interagency Guidance on Risk Managementocc.gov· Office of the Comptroller of the Currency
- Amgen Breach Exposed Patient Data in Third Party Cloudsgblock.app· GBlock
- BaaS Enforcement, Synapse Fallout, and Contract Terms: Who Owns Compliance Failure?natlawreview.com· The National Law Review



