CiberLATAMbywhalemate

BCRA Adds Fraud Management to Risk Rules

Argentina’s central bank expanded fraud rules for payment providers, with phased obligations, governance, controls

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The Central Bank of the Republic of Argentina added Section 6.5, "Fraud Risk Management," to the consolidated text "Guidelines for Risk Management in Financial Institutions" through Communication "A" 8471. The measure folds internal and external fraud into operational risk and also expands requirements for payment service providers.

Update October 2, 2026: the BCRA clarified that Communication A 8471 also strengthens fraud risk management rules for payment service providers. For PSPs that offer payment accounts, it set a phased rollout with governance, anti-fraud policies, responsible officers, monitoring, mitigation and reporting. For other PSPs, it added simplified obligations.

The Central Bank of the Republic of Argentina added Section 6.5, "Fraud Risk Management," to the consolidated text "Guidelines for Risk Management in Financial Institutions" through Communication "A" 8471, published in the Official Gazette on September 1, 2026. The measure brings internal and external fraud into the operational risk framework for financial institutions and reinforces its treatment as part of the system’s broader risk management structure.

What does Communication A 8471 require?

Communication "A" 8471 requires financial institutions to define anti-fraud strategies, policies and practices, set their risk tolerance level and assign a specific structure or a designated person to manage fraud risk. It also folds internal and external fraud into the operational risk scheme, according to the regulations released by the BCRA.

The obligation goes beyond general statements. The updated consolidated text seeks to ensure that each institution has a concrete organization to manage that risk, with the function formally assigned. At the same time, the BCRA said it will strengthen controls to detect and prevent fraud and illegal activity in electronic payment systems, using public-facing rules to improve its transaction analysis and monitoring capacity.

How does the scope change for payment service providers?

Communication A 8471 also strengthens the fraud risk management regime for payment service providers, with different rules depending on the type of provider, according to the central bank’s August 2026 retail payments report. For PSPs that offer payment accounts, it establishes a phased implementation of a comprehensive operational risk framework that includes fraud, governance, policies, designated officers, monitoring, mitigation and reporting.

For other PSPs, the BCRA introduced simplified obligations that include fraud risk officers, self-assessments, mitigation plans and technology and information security controls, according to the same official report. That means the update is not limited to banks or traditional financial institutions, but also reaches different players in the payments ecosystem.

How does reporting to the board change?

The BCRA asked banks to report on fraud management to their boards at least quarterly, including indicators, significant incidents, corrective measures and newly detected fraud patterns. That gives supervision a periodic, documented component within risk governance.

The quarterly reporting requirement is meant to leave a traceable record of what happens inside each institution and how it responds to incidents or new variants. Coverage of the communication also said the full rollout of the new requirements would extend until September 1, 2027, with intermediate adaptation stages for financial institutions and other affected actors, although that timeline was attributed by the source as not fully confirmed.

How does it compare with Mexico’s response?

In Mexico, the public response was communicational and preventive, without cyber-specific regulatory changes comparable to the BCRA’s during the same period. Banco de México reiterated on social media that it never asks for personal or financial information through calls, text messages, emails or social networks, and it shared guidance so the public can always verify the official source when requests look suspicious.

That institutional alert was amplified by Abril Mejía, an official linked to Banco de México, who reposted the message and reinforced the instruction to verify websites and communications through the official source. At the same time, commercial banks such as Banamex launched specific anti-digital-fraud campaigns in September 2026, warning about app downloads from suspicious links and clarifying that they do not ask users to install apps or download software through messages or calls. Mexico’s Condusef and the banking sector also shared advice not to open unexpected links, not to share passwords, PINs or verification codes, and to avoid malware installation on mobile phones.

Sources

View all