CiberLATAMbywhalemate

Argentina Tightens Oversight of Virtual Wallets

Virtual wallets and payment service providers in Argentina now fall under a regulatory structure that combines BCRA oversight

Whalemate Labs · AI-assisted researchPublished:2 min read

In Argentina, PSPCPs that operate virtual wallets must register with the BCRA, have a sponsor bank and comply with information, security, KYC and operational continuity requirements. If they offer QR code payments, they also have to enroll in the Interoperable Digital Wallets Registry.

A regulatory structure split between the BCRA, CNV and UIF

In Argentina, fintech activity tied to payments and digital financial services operates under a multiagency model. The BCRA supervises Payment Service Providers and virtual wallets, the National Securities Commission regulates Virtual Asset Service Providers and the crowdfunding regime, and the Financial Information Unit imposes anti-money laundering and counterterrorism financing obligations, according to Lexar's study on fintech regulation in the country.

For PSPCPs, meaning Payment Service Providers that offer Payment Accounts and run virtual wallets, the framework requires registration with the BCRA, a sponsor bank, and compliance with information and security requirements. They must also implement KYC and anti-money laundering policies, ensure operational continuity, and enroll in the Interoperable Digital Wallets Registry if they offer QR code payments.

Compliance obligations that extend to security

The same framework places fintech companies operating as PSPs or PSPCPs under Law 25,246 as obliged entities. That requires them to maintain an anti-money laundering program with customer identification, a risk matrix, a compliance officer, suspicious transaction reporting and record retention for 10 years.

Those obligations are added to self-assessment reports and independent external reviews on the timelines set by the UIF. In practice, compliance is not limited to financial or legal processes, it also affects internal security procedures and access controls over information.

Professionals working with PSPs in Argentina also note that these companies face specific obligations before the BCRA, the UIF and the data protection authority, identified in the material as ARCA, with direct impact on their security and compliance processes. The reference points to a regulatory environment where oversight is no longer limited to payment operations, but also covers operational continuity, document retention and the traceability of customers and transactions.

Sources

View all