Argentina, Mexico tighten anti-fraud rules
Argentina adds a documented anti-fraud program and risk base, while Mexico’s CNBV expands SMS authentication.
The Central Bank of Argentina launched a public database to detect fraud- and illegal gambling-linked accounts, while Mexico’s CNBV expanded SMS authentication and clarified the scope of technology-based commission agents.
Update September 5, 2026: Mexico’s CNBV not only authorized codes by SMS, it also clarified the scope of technology-based commission agents and the range of operations they can offer. In Argentina, the BCRA has already launched the public database to detect accounts linked to fraud and illegal gambling.
The Central Bank of the Argentine Republic added Section 6.5, "Fraud Risk Management," to its Guidelines for Risk Management in Financial Institutions, and at the same time launched, through Communication "A" 8473, a public database to identify suspicious activity tied to fraud and illegal gambling. In Mexico, the CNBV amended rules so banks can send security codes by SMS and simplify certain balance inquiries.
What does the BCRA require from banks and PSPs?
The new Section 6.5 requires financial institutions to maintain a documented anti-fraud program, with coordination among compliance, legal, cybersecurity, and AML/CFT teams, as well as detection procedures supported by technology solutions, reporting channels, incident response protocols, training, and annual reviews. The text also strengthens the link between operational risk management, regulatory compliance, and cybersecurity.
The timetable in Communication "A" 8471, published in Argentina’s Official Gazette, sets that from September 1, 2026 through December 31, 2026, institutions must define their anti-fraud structure, policies and practices, roles and responsibilities, risk appetite and tolerance, and identify operational and fraud risks tied to products, services, digital channels, and critical processes. Starting January 1, 2027, payment service providers registered with or authorized by the BCRA that were not previously covered must assign a specific unit or officer, perform a self-assessment, develop a mitigation plan, and comply with point 6.4 on technology and information security.
How will the BCRA public database work?
Communication "A" 8473 provides that instant transfer operators will use a new public database to detect accounts linked to fraud and illegal gambling, and that they can alert banks and digital wallets. According to the cited coverage, the stated goal is to curb online scams and fight illegal gambling by detecting accounts early when they channel funds to unauthorized betting sites.
According to the published information, Coelsa, NewPay, Red Link, and Interbanking will use that database to build person-level fraud risk profiles. Those profiles will be made available at no cost to financial institutions and PSPs for daily transaction monitoring and customer onboarding.
What changed in Mexico with the CNBV?
The National Banking and Securities Commission changed the rules for credit institutions to allow security codes, a category 3 authentication factor, to be sent by SMS, email, or encrypted instant messaging services. For higher-risk transactions, combined authentication factors remain in place.
The changes to Articles 319 Bis 2, 319 Bis 3, and 319 Bis 5 also allow, for balance and transaction inquiries made through technology-based commission agents, the use of only category 2 authentication. Specialized media in Mexico say institutions will need to update apps, security policies, customer notices, authentication traceability, and mechanisms for changing factors and contact methods.
The resolution modifying Articles 319 Bis 2, 319 Bis 3, and 319 Bis 5 explicitly incorporates technology-based commission agents and defines the range of operations they may carry out, including low-level account openings, related transfers, loans of up to 3,000 UDIs, payments for goods and services, and balance and transaction inquiries.
The text released through the Official Gazette underscores the regulatory goal of creating a differentiated authentication scheme for lower-risk operations, such as inquiries made through technology-based commission agents, which points to a risk-based approach by transaction type within digital banking and fintech.
The CNBV resolution sets in its sole transitional provision that the new rules for sending authentication factors and using SMS take effect on September 2, 2026. Expansión and XEU added that, from that date, banks can send by SMS one of the codes used to verify a customer’s identity in certain transactions conducted through technology agents, such as mobile apps and websites.
What regional reach do these changes have?
The measures in Argentina and Mexico are pushing banks, wallets, and payment service providers to strengthen fraud controls, authentication, and traceability across digital transactions. In Argentina, the focus is on risk governance, internal coordination, and the sharing of fraud signals. In Mexico, the change centers on expanding channels for delivering authentication factors and adjusting verification schemes for digital operations.
Sources
- BANCO CENTRAL DE LA REPÚBLICA ARGENTINA – Aviso sobre disposición con vigencia plena desde el 01/09/27boletinoficial.gob.ar· Boletín Oficial de la República Argentina
- Nueva regulación del BCRA sobre gestión del riesgo de fraude – Comunicación “A” 8471bruchoufunes.com· Bruchou & Funes de Rioja
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de créditosdv.com.mx· SDV México
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegallosprimeros.tv· Los Primeros TV
- CNBV abre la puerta a que bancos envíen códigos de seguridad por SMS y simplifica consultas de saldoelceo.com· El CEO
- CFDI falsos: 30 días para proteger deducciones y evitar cancelación del CSDhelp-ai.mx· Help AI
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegaldiariodecuyo.com.ar· Diario de Cuyo
- Los bancos estrenan una nueva forma de confirmar tu identidad por SMS: así funcionaexpansion.mx· Expansión
- A partir de este miércoles, recibirás estos mensajes de SMS que no debes ignorarxeu.mx· XEU
- CNBV Allows SMS Authentication for Digital Banking Agentsstartupresearcher.com· StartupResearcherUnverified URL
- Monitoreo de medios y redes sociales – 3 de septiembre de 2026 (referencia a nuevas autenticaciones SMS bancarias)unifimex.org.mx· UNIFIMEX
- Dan luz verde a mensajes SMSeluniversal.com.mx· El Universal
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de créditovlex.com.mx· vLex México
- CNBV flexibiliza autenticación para comisionistas fintech y permite SMSmsn.com· MSN México
- CNBV revoca autorización a Superdigital, vinculada a Santander, para operar en Méxicoelceo.com· EL CEO
- ¿Código SMS del banco? Así funcionan las nuevas reglas de seguridad en Méxicovanguardia.com.mx· Vanguardia



