CiberLATAMbywhalemate

BCRA and CNBV tighten bank controls

Argentina updates minimum capital and market risk rules, while Mexico expands biometric validation and cybersecurity controls for banks.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The Central Bank of the Argentine Republic published Communication A 8461/2026, which updates the Monthly Accounting Reporting Regime with changes to minimum capital and market risk. In Mexico, the CNBV amended the Single Banking Circular to broaden biometric validation and keep stricter rules on the databases banks use.

Update, August 21, 2026: the BCRA added Communication A 8461/2026, which amends the Monthly Accounting Reporting Regime with adjustments to minimum capital and market risk. In Mexico, the CNBV revised the Single Banking Circular to expand biometric validation and tighten controls over the databases banks may create.

The Central Bank of the Argentine Republic published Communication A 8461/2026, which updates the Monthly Accounting Reporting Regime and took effect in August 2026 with changes tied to the calculation and composition of minimum capital, as well as the market risk section for financial institutions. In Mexico, the CNBV revised the Single Banking Circular to broaden biometric validation, while the SHCP and the commission kept stricter rules on the use and protection of biometric data in banks.

What changed in Argentina with Communication A 8438/2026?

Communication A 8438/2026, published in Official Gazette No. 35,970 and recorded in the national regulatory portal, changes the rules of the National Payments System for the electronic processing of checks and other compensable instruments, adding new operational and compliance requirements for financial entities and certain technology providers.

The consolidated text available on the official portal says the rule is part of the BCRA's series of communications on financial entities and sets specific obligations for the electronic processing of checks and other compensable instruments, including information requirements and participant responsibilities. The official reference also confirms that the rule has validity recorded in the national regulatory system.

The latest development in Argentina is Communication A 8461/2026, which updates the Monthly Accounting Reporting Regime, known as Circular CONAU 1-1731. According to the BCRA notice, it introduces changes to minimum capital requirements and composition, as well as the market risk section, and applies to financial institutions starting in August 2026.

How does it connect with the UIF?

The BCRA and the Financial Information Unit relaunched the UIF-BCRA Working Group in 2026 and presented a Guide for the Interpretation and Application of the concept of "Client of the Client" for jointly supervised financial institutions.

According to the BCRA's official statement, the guide aims to align anti-money laundering and compliance best practices, with an emphasis on periodic monitoring, detection, and timely handling of unusual activity. The goal is to strengthen expectations for transaction-monitoring schemes at supervised entities.

What does the new regulatory wave require in Mexico?

In Mexico, a resolution published in 2026 changed the general rules applicable to credit institutions to incorporate facial biometrics as an official complementary mechanism to fingerprints, and to allow banks to build their own biometric databases under strict security and information-governance requirements.

According to Periodismo y Ambiente, the rule gives banks 90 business days to adjust identity-verification processes and requires encryption, segregation in dedicated infrastructure, access controls, secure deletion of biometric databases, and periodic cybersecurity audits. AMITI adds that mandatory biometric validation is concentrated in Level 3 and Level 4 accounts, and that before adding a record, banks must verify it against an authorized official source such as the INE, the Ministry of Foreign Affairs, or another authorized federal agency. The same source says biometric databases must stay updated and under strengthened security controls.

The CNBV's latest update revised the Single Banking Circular to expand biometric validation, with changes to Articles 51 Bis through 51 Bis 5 and the replacement of Annex 71 of the rules applicable to credit institutions.

An analysis by FIDO Alliance and Biometric Update adds that the July 2026 amendments require liveness detection within the 90-day period and facial verification with at least 90% match against government identity records.

What cybersecurity controls does the CNBV require for IFPEs and IFCs?

The CUITF rules, according to NextGuard Insurance, require TLS 1.2 or higher for data in transit, AES-256 for personal and financial data at rest, strict segregation between production, development, and testing, and a 24/7 in-house or outsourced SOC with SIEM and event correlation.

The same source adds that the CNBV also requires material incident notification within specific deadlines, formal management of critical third parties, and insurance coverage to protect customer funds and civil liability. Taken together, that framework conditions fintech operating approval on full compliance with those controls.

For banks, specialized coverage on biometrics and cybersecurity describes the new rules published by the SHCP and the CNBV in the Official Gazette as allowing banks to create their own biometric databases, but prohibiting the sale of that data and requiring periodic cybersecurity audits, along with encryption, infrastructure segregation, access controls, and secure deletion of stored information.

What changed in sanctions and transparency for banks and financial firms in Mexico?

In 2026, Mexico's Supreme Court upheld broad powers for CONDUSEF to sanction financial institutions that hide relevant information from customers and to oversee compliance with transparency and registration obligations.

According to El Cronista México, the ruling also upheld rules that allow sanctions for bad debt-collection practices, even in cases where institutions fail to register contracts or properly report their products. That strengthened the sanctioning reach beyond the mere hiding of information from customers.

How does virtual asset regulation fit into this picture?

A legal and technical analysis of Mexico's Fintech Law and Banxico Circular 4/2019 argues that virtual asset transactions authorized for credit institutions and fintech firms must be limited to internal operations, described precisely in terms of processes, personnel, and responsibilities, and justified as not constituting a direct public offering or shifting risk to customers.

The same source says Banxico must consider how the public uses virtual assets as a medium of exchange, store of value, and unit of account when deciding which ones fintech firms may use. That defines the universe of cryptoassets allowed under supervision.

Sources

View all