Argentina BCRA tightens fraud controls on transfers
The Argentine central bank issued Communications A 8471 and A 8473, adding new obligations and a public fraud score for instant transfers.
The Central Bank of Argentina released the schedule for Communication A 8471 and moved forward with A 8473, which adds a fraud risk profile system for instant transfers and a public database to spot suspicious movements linked to fraud and illegal gambling. The measure covers financial institutions, instant transfer operators, and payment service providers.
The Central Bank of the Argentine Republic has published the timeline for Communication A 8471 and, in parallel, advanced Communication A 8473, which adds a dedicated fraud risk management section and creates a risk profiling system for instant transfers. The framework applies to financial institutions, instant transfer administrators, and payment service providers that offer payment accounts.
What changes with Communication A 8471?
Communication A 8471 adds a specific section on fraud risk management within the "Guidelines for Risk Management in Financial Institutions." According to Ciberseguridad Latam's summary of the BCRA communication, that addition sets obligations for financial institutions and other payment service providers.
The official publication places the measure within a broader risk management policy. In that same line, the BCRA said on its English-language site that the strategy is intended to strengthen fraud prevention in electronic payments.
How does the new fraud score work?
Communication A 8473 establishes a fraud risk profile system for instant transfers and a public database that instant transfer administrators will use to detect suspicious activity tied to fraud and illegal gambling. According to the BCRA, from September 2026 the central bank will make public information available so those administrators can build risk profiles by person.
Bruchou & Funes de Rioja said the new score must be used as a mandatory input in new customer onboarding, account opening, and transaction monitoring processes. Los Primeros TV added that administrators, including Coelsa, NewPay, Red Link, and Interbanking, will be able to use the database to alert banks and digital wallets.
Urgente24 also reported that implementation will be gradual and that the goal is to detect accounts linked to suspicious transactions and illegal gambling. The BCRA, for its part, framed the measure as part of a broader strategy against fraud in electronic payments.
What control requirements does the rule impose?
Bruchou & Funes de Rioja said instant transfer administrators, financial institutions, and PSPCPs must apply security, confidentiality, integrity, availability, and safeguarding measures so BCRA information and the score are used only for their intended purposes. The analysis also calls for controls and traceability over access, use, transfers, and incidents, with evidence available to the Superintendency of Financial and Exchange Institutions.
That regulatory tightening is backed by concrete audit and compliance obligations for the covered entities. In practice, the rule pushes transaction monitoring, customer onboarding, and periodic KYC reviews to incorporate the new risk input.
What does the Mexico case show about this regulatory pressure?
A private regulatory compliance case study reported that a CNBV audit of a Mexican financial group found no formal vulnerability management program, manual security reporting, and 47 critical vulnerabilities left unremediated. According to that case, the group accelerated the rollout of a cybersecurity program with vulnerability management, a 24/7 SOC, and automated regulatory reporting.
The same case says the 47 critical vulnerabilities were remediated within 90 days and that the audit was later approved. In parallel, Xataka México reported that the CNBV changed authentication rules for banking operations carried out through third-party apps or websites, with publication on September 1, 2026 and enforcement starting the next day.
ZTC Cyber Intelligence added that Mexican regulations allow SMS to be used for certain authentication factors in schemes with technology-based agents, a detail that helps explain the technical context of the regulatory change in that country.
Sources
- The BCRA strengthens fraud prevention strategybcra.gob.ar· Banco Central de la República Argentina (BCRA)
- Nuevo score de riesgo de fraude del BCRA para transferencias inmediatas (Com. “A” 8473)bruchoufunes.com· Bruchou & Funes de Rioja
- Si tu banco te manda un código por SMS, no te asustes, es ...xataka.com.mx· Xataka México
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegallosprimeros.tv· Los Primeros TV
- ZTC Cyber Intelligence 003 | 7 de septiembre de 2026zerotrust.consulting· ZTC Cyber Intelligence
- Grupo financiero: 47 vulnerabilidades remediadas y SOC operativo en 30 díasscram2k.com· Scram2k
- Garantizando la ciberseguridad de los bancos en Argentina: Comunicación «A» y gestión de riesgosciberseguridadlatam.com· Ciberseguridad Latam
- BCRA endurece controles y vigilará transferencias por fraude y juego ilegalurgente24.com· Urgente24



