CiberLATAMbywhalemate

Banxico and CNBV tighten payment rules

Banxico opened consultations on payment clearing and settlement networks, while CNBV called for stronger internal controls at Sofomes.

Whalemate Labs · AI-assisted researchPublished:4 min read

In August 2026, Banco de México opened public consultations on rules for card payment clearinghouses and payment networks, a process aimed at organizing operations and improving system security. At the same time, the CNBV called on Sofomes to strengthen internal controls, corporate governance and compliance culture.

Banco de México opened public consultations in August 2026 on two proposals that directly affect the operation of card payments and payment network infrastructure. At the same time, the CNBV put the spotlight on Sofomes and called for stronger internal controls, better corporate governance and a firmer compliance culture.

What did Banxico put out for consultation?

Banxico opened a public consultation on the draft Rules for the organization, operation and functioning of clearinghouses for card payments, along with another on draft General Provisions Applicable to Payment Networks. In both cases, the central bank said this is a formal process, with the full text available on its institutional website.

According to the central bank’s official notice, the first consultation covers rules for card payment clearinghouses. The second is aimed at payment networks and, based on the coverage published, will likely set important organizational and operational requirements for the security of those networks.

What changes for the payments system?

Beyond organizational and operational requirements, the projects include two areas that affect the business and the secure operation of card payments, a gradual reduction in interchange fees and stronger interoperability between point-of-sale terminals, issuers, acquirers and networks. According to reporting by El Heraldo de México, that also aims to lower processing costs and reduce friction.

As part of the same regulatory package, Banxico is proposing new rules for clearinghouses designed to ensure payment processing takes place with fewer frictions and lower costs. The proposal complements the operational security and payments-system efficiency goals the central bank cited when it opened the consultation.

What did they say about Sofomes?

CNBV president Ángel Cabrera Mendoza said Sofomes need to consolidate internal controls, strengthen corporate governance and promote a stronger culture of comprehensive compliance. His remarks came during discussions about possible improvements to the sector’s regulatory framework.

Gerente.com reported that the statement is part of a broader debate over possible regulatory adjustments for Sofomes, with Mexican financial authorities pointing to the sector’s evolution and the need to improve supervision and compliance standards. The discussion is now tied to a wider review of the control framework.

How does the cybersecurity front fit in?

At the same time, specialized outlets described Banxico as having issued circulars and provisions that strengthen minimum cybersecurity requirements for regulated entities, including IFPEs and IFCs. The points cited include risk management frameworks based on international standards, business continuity plans and mandatory incident reporting schemes within specific deadlines.

Another analysis from Capital Negocios said, based on reporting that was not independently confirmed in the material, that massive and mandatory biometric integration is also being promoted as an authentication method for fintechs regulated by Banxico, with upcoming deadlines to implement robust biometric authentication systems. The same set of references mentioned tighter incident-notification obligations to Mexican financial authorities.

What is happening in Argentina?

In Argentina, a recent analysis of BCRA rules said the current regulatory framework for financial entities already includes requirements for technology risk management, operational continuity, incident response, third-party management, fraud prevention and continuous monitoring. According to ZMA, the logic behind those requirements is to keep operations running even when a security incident occurs.

That same framework sits alongside the BCRA’s reference to cryptoassets, included in the institutional documentation available among the sources, in a context where the Argentine regulatory conversation is also tied to operational controls and technology risk.

Sources

View all